Advertisement
X

RBI’s Digital Fraud Compensation Rules Explained: What Happens If You Share An OTP After Being Tricked

RBI’s proposed fraud rules could give consumers compensation after deceptive transactions, but reporting deadlines and eligibility limits may restrict protection in some cases

RBI Digital Fraud Compensation Rules Photo: AI generated
Summary
  • RBI framework covers compensation for eligible small-value digital frauds.

  • Banks must assess whether customers were deceived or negligent.

  • Five-day reporting deadline and lifetime limit restrict protection.

Advertisement

Imagine you get a call from someone claiming to be from your bank. The caller creates an urgent situation, convinces you to share an OTP, and Rs 40,000 is transferred from your account. Under the new framework, simply sharing the OTP would not automatically mean that you lose the right to seek compensation.

This is one of the important changes in the Reserve Bank of India’s (RBI's) proposed framework for fraudulent digital banking transactions. The rules draw a distinction between a customer deliberately authorising a transaction and a customer being manipulated into doing so, applicable only for total losses up to Rs 50,000, and are scheduled to be implemented on January 1, 2027.

For consumers, the distinction matters because fraudsters often use social engineering rather than directly breaking into bank accounts. They may pose as bank officials, delivery agents or even relatives to persuade victims to share credentials or approve transactions.

Advertisement

Why Has RBI Changed Existing Rules

Hitesh Agrawal, Founder and Managing Director, Them Consulting, explains that the proposed approach separates the act of sharing a credential from the intention behind it.

"RBI is separating the act of sharing credentials from the intent behind it. Legally, that's a meaningful distinction. Negligence has always implied some failure of care on the customer's part. But if a person is actively deceived through a well-constructed script or a spoofed caller ID, calling that negligence stretches the word past what it should mean."

In other words, a customer sharing an OTP after being manipulated would have to be assessed differently from someone who knowingly carries out a fraudulent transaction.

How Will A Bank Decide What Happened

The difficult part comes after the fraud. A bank has to determine whether the customer was deceived or acted intentionally.

Agrawal explains that banks are likely to examine the circumstances surrounding the transaction rather than relying only on whether an OTP or other credential was used. He explains, "Was this a new payee the customer had never transacted with before? Did the transaction happen right after a call from an unfamiliar number, especially one that shows patterns matching known scam operations? Was there unusual urgency, multiple failed attempts, or a transaction size that breaks from the customer's normal spending pattern?"

This means transaction history, call records, messages, screenshots and the timing of the complaint could become important when a customer disputes a fraudulent transaction.

Advertisement

The Customer Still Has To Report The Fraud Quickly

The proposed framework does not remove the need for customers to act quickly. A victim has to report the fraud within the prescribed five-day period and provide information that supports the claim.

Agrawal points out that this could become difficult when a person discovers the fraud late or struggles to collect evidence. He adds, "The honest answer is that proving pure intent is genuinely difficult, and that's exactly why the framework doesn't require conclusive proof. It requires a plausible, well-documented case that the loss wasn't deliberate, and banks are expected to give reasonable benefit of the doubt rather than reject claims outright on the technicality that credentials were shared."

Where Could Consumers Still Face Problems

The proposed protection has limits. The Rs 50,000 eligibility ceiling (with compensation capped at 85 per cent of net loss or Rs 25,000, whichever is lower),five-day reporting window, and lifetime one-time benefit could restrict access to compensation in some cases.

Agrawal also points to the absence of a fixed test for determining intent as a potential gap: "Without a clearer evidentiary standard, this becomes a judgment call, and judgment calls tend to favour whoever is making them."

The broader question, therefore, is not only whether RBI recognises manipulated consent, but how consistently banks apply that distinction when investigating actual fraud complaints.

Advertisement
Show comments
Published At: