The RBI Scam Compensation Framework

Source: TH

Subject: Economy

Context: The Reserve Bank of India (RBI) has issued final amendments to its Limiting Customer Liability in Digital Transactions framework.

  • Effective January 1, 2027, the one-year pilot expands protection against social engineering scams and introduces monetary compensation for victims of small-value digital fraud.

The RBI Scam Compensation Framework
The RBI Scam Compensation Framework

About The RBI Scam Compensation Framework:

What It Is?

  • The framework is a regulatory financial safety net designed to protect bank customers from digital payment frauds. It upgrades the RBI’s 2017 circular, which only protected against unauthorised hacking hacks.
  • The modern mechanism introduces Fraudulent Electronic Banking Transactions (EBTs) as a legal concept, making individuals eligible for reimbursement even if they accidentally shared credentials due to deception or coercion.

Regulator: The Reserve Bank of India (RBI).

Aim:

  • To provide economic relief to victims of modern digital scams, including digital arrests, phishing, and fraudulently stolen One-Time Passcodes (OTPs).
  • To shift the legal burden of proof onto the bank, forcing financial institutions to actively prove customer negligence rather than automatically denying fraud claims.

Key Features and Rules of the Policy:

  • The Payout Matrix:
    • The Payout Formula: Individual victims (including sole proprietors) suffering scam losses up to ₹50,000 can claim 85% of their net loss, capped at a maximum of ₹25,000.
    • The Breakpoint: For losses below ₹29,412, victims get exactly 85% of the amount. For losses between ₹29,412 and ₹50,000, the payout is capped at a flat ₹25,000.
    • The Cap: Scams exceeding ₹50,000 are completely excluded from this specific reimbursement track.
    • Frequency: This financial remedy can be claimed only once in a customer’s lifetime. For joint accounts, only one holder may file the claim.
  • The Three-Way Cost-Sharing Model:

The compensation cost does not fall solely on the customer’s bank. Instead, it is co-funded across a multi-party ledger:

    • The RBI Share: Contributes roughly 75% of the payout amount.
    • The Remitter (Customer’s) Bank: Contributes half of the remaining balance.
    • The Beneficiary (Receiver’s) Bank: Contributes the other half of the remaining balance. For cross-border scams, the remitter bank covers this share.
  • Defining Customer vs. Bank Negligence:
    • Customer Negligence (Exclusions): Customers are ineligible for compensation if they ignore clear, directed security alerts or fail to link their current phone number/email address with the bank, which blocks real-time fraud warnings.
    • Bank Negligence (Inclusions): Deemed to occur if a bank fails to send mandatory transaction alerts, lacks a 24×7 fraud-reporting infrastructure, or fails to act promptly once notified.
    • Third-Party Breaches: Customers are not held liable for security leaks occurring elsewhere in the ecosystem, such as at a payment gateway, aggregator, or telecom provider.
  • Mandatory Timelines and Grievance Tracks:
    • The 5-Day Reporting Rule: To qualify for a payout, the customer must report the fraud within 5 calendar days of its occurrence to both their bank and the National Cyber Crime Helpline (1930).
    • Resolution Turnaround: Banks must resolve domestic digital fraud cases within 45 calendar days and cross-border cases within 60 calendar days. Reversals must be value-dated to the original transaction date so the customer loses no interest.
    • Credit Card Shadow Reversal: For credit card fraud, banks must issue a temporary shadow reversal of the disputed funds within 5 calendar days of the report so the user does not incur interest charges while the investigation is underway.
    • The ₹500 Alert Rule: Banks are required to send instant, cost-free SMS alerts for all electronic transactions exceeding ₹500 to maintain a reliable communication channel for users without internet connectivity.