The Reserve Bank of India (RBI) has introduced a set of draft guidelines titled 'Customer Protection in Electronic Banking Transactions' to strengthen the safety net for digital payment users. These proposed rules aim to mitigate financial losses for customers falling prey to online banking scams and to establish a clear framework for bank accountability. According to the central bank, the rapid expansion of the digital payment ecosystem has necessitated more stringent regulatory measures to counter the evolving nature of cybercrimes and financial fraud.
Compensation Structure for Small-Scale Frauds
Under the proposed RBI draft, customers who suffer financial losses due to online banking fraud involving amounts up to ₹50,000 may be eligible for compensation. The guidelines state that a victim can receive up to 85% of the total loss or a maximum of ₹25,000, whichever is lower. This specific provision is designed to provide a safety cushion for individual account holders who are often the targets of phishing and other digital scams, while however, the RBI has specified that this compensation benefit will be a one-time lifetime facility for any individual user.
Mandatory Reporting Protocols and Timelines
To qualify for the proposed compensation, customers must adhere to strict reporting timelines. The draft rules mandate that the victim must report the fraudulent transaction to their respective bank and the National Cyber Crime Reporting Portal or the helpline 1930 within five days of the incident. A bank-led investigation must subsequently verify that the fraud was genuine and didn't involve any intentional negligence or collusion on the part of the customer. Failure to report within the stipulated five-day window may disqualify the customer from claiming the compensation.
Zero Liability and Bank Accountability
A significant highlight of the draft rules is the 'Zero Liability' clause for customers. If an online fraud occurs due to a security breach or technical deficiency within the bank's own systems, the customer will bear no liability. In such instances, the bank is required to refund the entire amount lost by the customer. Also, if the fraud is perpetrated by a third party and the customer reports it within five days, the customer's liability will remain zero. This move is intended to compel financial institutions to invest more heavily in strong cybersecurity infrastructure.
Enhanced Transaction Alerts and Communication
The RBI has proposed stricter communication standards for banks to ensure real-time monitoring by customers. It will be mandatory for banks to send immediate SMS and email alerts for all electronic banking transactions. Specifically, for any transaction exceeding ₹500, an SMS alert is compulsory. The objective is to enable customers to instantly detect unauthorized activities and take immediate action. Banks are also expected to provide a simplified mechanism, such as a single-click reporting tool, for customers to flag suspicious transactions directly from the alert message.
Exclusions Due to Customer Negligence
The central bank has clearly outlined exceptions where the compensation rules won't apply. If the investigation reveals that the customer shared sensitive banking credentials such as OTP, PIN, or passwords with unauthorized persons, it will be categorized as customer negligence. Similarly, losses resulting from the installation of suspicious or unverified mobile applications won't be covered under the compensation scheme. The RBI emphasizes that while regulatory protections are being enhanced, individual vigilance remains a critical component of digital financial security.
