Context: The Reserve Bank of India (RBI) has issued final amendments to its Limiting Customer Liability in Digital Transactions framework.
- Effective January 1, 2027, the one-year pilot expands protection against social engineering scams and introduces monetary compensation for victims of small-value digital fraud.

About The RBI Scam Compensation Framework:
What It Is?
- The framework is a regulatory financial safety net designed to protect bank customers from digital payment frauds. It upgrades the RBI’s 2017 circular, which only protected against unauthorised hacking hacks.
- The modern mechanism introduces Fraudulent Electronic Banking Transactions (EBTs) as a legal concept, making individuals eligible for reimbursement even if they accidentally shared credentials due to deception or coercion.
Regulator: The Reserve Bank of India (RBI).
Aim:
- To provide economic relief to victims of modern digital scams, including digital arrests, phishing, and fraudulently stolen One-Time Passcodes (OTPs).
- To shift the legal burden of proof onto the bank, forcing financial institutions to actively prove customer negligence rather than automatically denying fraud claims.
Key Features and Rules of the Policy:
- The Payout Matrix:
-
- The Payout Formula: Individual victims (including sole proprietors) suffering scam losses up to ₹50,000 can claim 85% of their net loss, capped at a maximum of ₹25,000.
- The Breakpoint: For losses below ₹29,412, victims get exactly 85% of the amount. For losses between ₹29,412 and ₹50,000, the payout is capped at a flat ₹25,000.
- The Cap: Scams exceeding ₹50,000 are completely excluded from this specific reimbursement track.
- Frequency: This financial remedy can be claimed only once in a customer’s lifetime. For joint accounts, only one holder may file the claim.
- The Three-Way Cost-Sharing Model:
The compensation cost does not fall solely on the customer’s bank. Instead, it is co-funded across a multi-party ledger:
-
- The RBI Share: Contributes roughly 75% of the payout amount.
- The Remitter (Customer’s) Bank: Contributes half of the remaining balance.
- The Beneficiary (Receiver’s) Bank: Contributes the other half of the remaining balance. For cross-border scams, the remitter bank covers this share.
- Defining Customer vs. Bank Negligence:
-
- Customer Negligence (Exclusions): Customers are ineligible for compensation if they ignore clear, directed security alerts or fail to link their current phone number/email address with the bank, which blocks real-time fraud warnings.
- Bank Negligence (Inclusions): Deemed to occur if a bank fails to send mandatory transaction alerts, lacks a 24×7 fraud-reporting infrastructure, or fails to act promptly once notified.
- Third-Party Breaches: Customers are not held liable for security leaks occurring elsewhere in the ecosystem, such as at a payment gateway, aggregator, or telecom provider.
- Mandatory Timelines and Grievance Tracks:
-
- The 5-Day Reporting Rule: To qualify for a payout, the customer must report the fraud within 5 calendar days of its occurrence to both their bank and the National Cyber Crime Helpline (1930).
- Resolution Turnaround: Banks must resolve domestic digital fraud cases within 45 calendar days and cross-border cases within 60 calendar days. Reversals must be value-dated to the original transaction date so the customer loses no interest.
- Credit Card Shadow Reversal: For credit card fraud, banks must issue a temporary shadow reversal of the disputed funds within 5 calendar days of the report so the user does not incur interest charges while the investigation is underway.
- The ₹500 Alert Rule: Banks are required to send instant, cost-free SMS alerts for all electronic transactions exceeding ₹500 to maintain a reliable communication channel for users without internet connectivity.








