Magazine

Are RBI’s New Rules Enough To Curb Frauds?

RBI’s new customer protection rules are a step in the right direction, but whether they will prove to be a gamechanger will depend on implementation and whether the regulator is able to plug gaping loopholes

Illustration: Ashvin Chitroda
info_icon

When Netflix’s Jamtara: Sabka Number Ayega first aired in 2020, it introduced millions of Indians to the world of phishing scams, where unsuspecting people were tricked into sharing banking credentials over phone calls. Six years later, the scams have become far more sophisticated. Scammers now use fake job offers on social media, fraudulent investment groups, spoofed customer care numbers, deepfake videos, and more.

The deception does not end online. A routine visit to the bank to renew a fixed deposit (FD) or apply for a loan can also end with a customer unknowingly buying an insurance policy or investment product they neither wanted nor fully understood.

To tackle these growing risks, the Reserve Bank of India (RBI), between February and March 2026, proposed two major consumer protection frameworks, effective January 1, 2027. One aims to curb the mis-selling of financial products by banks and other regulated entities. The other proposes a compensation framework for victims of certain digital payment frauds. RBI’s move is in the right direction as it moves the conversation from telling the consumers to “be careful” to asking banks to sell and handle fraud complaints responsibly. But the big question is: will it make a difference?

1 July 2026

Get the latest issue of Outlook Money

amazon

Growing Risk

Data tabled by the Ministry of Home Affairs in Parliament on March 24, 2026, shows that 2.40 million financial cybercrime complaints were registered on the National Cyber Crime Reporting portal in 2025, compared with 1.92 million in 2024. The amount involved crossed `33,000 crore, although a significant portion was frozen or recovered through timely intervention. Separately, RBI’s Annual Report 2024-25 recorded 13,516 card and Internet fraud cases involving nearly Rs 520 crore.

For 55-year-old Alka Sharma, a social sector professional from New Delhi, the scam began with what looked like a genuine work-from-home opportunity on a social media channel. She was initially assigned small online tasks and received payments, which convinced her the job was legitimate. The fraudsters then asked her to transfer larger sums through Unified Payments Interface (UPI), promising higher returns and bonuses. By the time she realised it was a scam, she had lost nearly Rs 1 lakh.

Banks cannot force customers to buy an insurance policy or another product for getting a loan or another service, unless such a requirement is mandated by law

She immediately reported the fraud to the police and her bank. “Losing money was not only stressful for me, but also psychologically taxing,” she says. “Unfortunately, I was not able to recover any of the money. By the time I reported the fraud, the funds had already been moved through multiple accounts, making recovery extremely difficult.”

While digital fraud is tracked through official databases and there are cases of recovery, the true scale of financial product mis-selling is harder to measure.

“The most common form of mis-selling in India is packaging insurance as an investment,” says Prashant Mishra, Securities and Exchange Board of India-registered investment advisor (Sebi RIA) and founder of Bengaluru-based Agnam Advisors. “A customer walks in to renew an FD and walks out with a unit-linked insurance plan or an endowment policy, pitched as a ‘guaranteed return scheme better than an FD’. The lock-in, surrender charges and multi-year premium commitments are rarely explained. Senior citizens are disproportionately targeted because they hold the deposits and trust banks.”

Another common practice is forcing customers to buy one product to get another. Says Mishra: “This is forced bundling by making a home loan, locker or even a current account conditional on buying an insurance policy or opening an investment account. Legally, the customer always has a choice. In practice, the loan file simply doesn’t move until the policy is signed.”

Something similar happened with Minati Adhikari (42), a tailor from Jalpaiguri, West Bengal. She went to a private sector bank for a `8 lakh personal loan, with 11 per cent interest, over a 5-year tenure and ended up with an insurance policy she never intended to buy along with the loan. Since she didn’t know English and had studied only till Class VII, she trusted the relationship manager. She signed a life insurance policy presented as part of the loan process, completely unaware that this policy was optional.

Three months later, while reviewing her loan statement with a relative, Minati discovered that Rs 70,000 had been added to her loan as the insurance premium. Her loan was effectively Rs 8.70 lakh. She escalated the matter through the bank’s principal nodal officer and the insurer’s grievance mechanism. Fortunately, that worked and triggered a dual refund process. First, the full Rs 70,000 premium was deducted directly from her outstanding loan balance, reducing her debt and lowering her future equated monthly instalments (EMIs). Second, the bank calculated the excess EMIs she had paid and credited a cash refund.

What RBI Has Proposed

RBI’s new frameworks deal with two distinct problems—mis-selling of financial products and digital fraud—and place responsibility on banks.

Mis-selling: The Responsible Business Conduct Directions framework changes the way banks and other regulated entities are expected to sell third-party financial products, such as insurance, mutual funds and pension products.

The biggest change is that getting a customer’s signature alone will no longer be enough. “A sale can be classified as mis-selling even where the customer signed and gave explicit consent, if the product was unsuitable for their profile or the disclosure was incomplete or misleading. A signature obtained without suitability, proper disclosure, and genuine understanding is not a defence,” says Tanya Prasad, chief investment officer and head of legal at LegalPay.

Banks will first have to assess whether a product is actually suitable for the customer, instead of simply selling what generates the highest commission.

They must also clearly explain important details, such as charges, lock-in periods, surrender value, recurring premium commitments, returns, and risks in simple language before the sale is completed.

It also addresses bundling. Banks cannot force customers to buy an insurance policy or another financial product for getting a loan or another service, unless such a requirement is mandated by law. They also cannot use “dark patterns”, such as pre-ticked boxes, misleading buttons or false urgency, to influence purchasing decisions. Most importantly, if mis-selling is established, the bank may have to cancel the sale, refund the money, and compensate the customer, for the loss suffered.

For Prasad, this is where the framework marks a real shift. “Most of these obligations existed only as advisories, RBI speeches, or vague ‘fair practice code’ language. Converting these into binding directions with mandatory refund/compensation obligations is a structural change, not just a restatement.”

Digital Fraud: RBI’s second proposal deals with customers who lose money in fraudulent electronic banking transactions (EBT), including cases where they are tricked into authorising a payment. For years, many customers who shared a one-time password (OTP) or approved a transaction after being deceived found it difficult to recover their money. In several cases, the transaction itself was treated as proof that the customer was responsible for the loss.

The proposed framework changes this approach. Sameer Mathur, managing director and founder of Roinet Solution, a financial inclusion-focused fintech company, says, “The new proposal shifts the test from ‘was OTP shared?’ to ‘was there an intent to authorise?’”

Banks will have to look at the circumstances surrounding the transaction instead of relying only on the fact that an OTP was shared. They will have to investigate every complaint and establish whether the fraud happened because of the bank’s deficiency, a third-party breach, or customer negligence. Importantly, the burden of proving customer liability will rest with the bank.

The proposal also introduces compensation for bona fide victims of small-value fraudulent transactions. Those who lose up to `50,000 may receive compensation of 85 per cent of their net loss, subject to a maximum of `25,000 and a fixed reporting timeline.

The framework also strengthens the complaint process. Banks will have to provide 24x7 channels for reporting fraud, including mobile banking apps, Internet banking, SMS, email, and branch visits. Every complaint must receive an acknowledgement with a complaint number and timestamp. Once it is reported, banks must immediately take steps to prevent the transaction.

Where a customer is found eligible for reversal, no additional interest or penalty can be imposed because of the disputed transaction. In the case of credit cards, customers will also receive a temporary shadow reversal, where the bank temporarily credits the fraudulent transaction amount back to the customer’s account while it investigates the complaint.

info_icon

Will The Rules Work?

The new RBI frameworks undoubtedly address long-pending issues, but experts believe implementation will decide whether they succeed. Ashwini Kumar, advocate and founder of My Legal Expert, says the guidelines formally recognise principles such as suitability, informed consent and fair disclosure, but “the effectiveness of these guidelines will ultimately depend upon implementation rather than intent”.

Kanan Bahl, chartered accountant, documentary filmmaker and founder of Fingrowth Media, a digital marketing and advertising agency, says: “(Product) ‘suitability’ has not been defined so it’ll take some time (and case laws) for the term to be established.” He adds that RBI, in consultation with Sebi and the Insurance Regulatory and Development Authority of India (Irdai), should keep releasing examples of establishing what is suitable for whom and what is not.”

Prasad points to another problem. “The refund/compensation remedy is triggered once mis-selling is ‘established’, but establishing it requires the customer to raise a complaint and bank or ombudsman find fault in those cases.”

Says Bahl: “Very few customers have the know-how and the means to fight their case against institutions like banks. As per a research by John A. Goodman, vice chairman, Customer Care Measurement & Consulting (CCMC), fewer than 5 per cent of dissatisfied individuals file formal reports. So, asking the banks to refund only the amount involved in mis-selling may not be fair.”

Mathur also believes the framework will need regular updates.

What Should You Do?

If you have been mis-sold a product, first file a written complaint with the bank and keep copies of documents, account statements, emails, SMSes and any communication relating to the sale. Says Kumar: “The initial burden will lie on the consumer to raise an allegation of mis-selling. However, once the allegations are raised, the financial institution will also have to show its compliances.”

If the complaint is not resolved within 30 days or you are dissatisfied with the response, you can escalate the matter through RBI’s complaint management system (CMS) under the Integrated Ombudsman Scheme. If the dispute involves an insurance policy, you can also approach Irdai’s Bima Bharosa portal and the Insurance Ombudsman.

If you become a victim of digital fraud, inform your bank immediately, contact the National Cyber Crime Helpline at 1930, or file a complaint on the National Cyber Crime Reporting portal within five days as compensation is linked to the reporting timeline. If the bank rejects your claim or does not respond within the prescribed time, you can escalate the matter through CMS.

Until the RBI measures stand the test of time, you will need to be careful about what you buy and how you transact digitally.

priyanka.debnath@outlookindia.com

SUBSCRIBE
Tags

Click/Scan to Subscribe

qr-code