RBI Draft Rules Propose 60-Day Limit on Cyber Fraud-Related Account Holds

The RBI has recommended a 60-day restriction on temporary bank account holds in relation to cyber-enabled financial theft in its draft KYC Amendment Directions, 2026. Banks would have to say to clients look at what they say and pass on suspicions of money mule activity to the authorities.

RBI draft rules propose 60-day limit on cyber fraud-related account holds
RBI draft rules propose 60-day limit on cyber fraud-related account holds

A time-bound framework has been proposed by the Reserve Bank of India (RBI) for banks to freeze transactions or accounts that are suspected of being associated with cyber-enabled financial fraud. Typically, temporary debit holds are limited to 60 days.

Bank customers caught up in cyber-fraud investigations often face the same dilemma, and the proposed guidelines try to fix it. While banks must move swiftly to prevent fraudulent activities from funding accounts, legitimate consumers may be left without access to their money if account freezes are in place for too long.

The New Drafted Guidelines by RBI

Specified timeframes for the placement of temporary debit holds would be enforced by banks in accordance with the proposed RBI (Know Your Customer) Amendment Directions, 2026. Additionally, financial institutions should notify clients, review their explanations, and report instances to the appropriate authorities. This draft is in response to a Supreme Court decision dated August 4, which required the RBI to create and disseminate a standard operating procedure (SOP) for financial institutions to follow when dealing with accounts associated with money-mules and cyber-enabled fraud.

Victims of cyber fraud should have their funds returned to them as soon as possible, according to the court's order. When a bank's transaction-monitoring systems detect a possible money-mule account or transaction, the bank might autonomously put a temporary debit hold under the proposed framework. Machine learning and artificial intelligence capabilities may be included in the systems. A suspected transaction is defined in the draft as a transaction that involves INR 1,000 or more and is recognised as potentially associated with the proceeds of cyber-enabled financial fraud or money-mule activity.

Nevertheless, not all transactions exceeding INR 1,000 would be immediately stopped. There should be red flags with the transaction before it may proceed. Such instances may involve a customer's profile being out of the ordinary, a transaction involving a suspected mule account or an account that has already been flagged as fraudulent, or both.

Dos and Don’ts of the Banks as Per RBI

The bank has 10 days from the date of receipt to review the customer's response and make a determination. Within 30 days of implementing the temporary debit hold, the bank must make a decision if no answer is received. Through the NCRP-CFCFRMS, the National Cybercrime Reporting Portal's Citizen Financial Cyber Fraud Reporting and Management System, the bank will escalate the issue to the relevant police authority if it is dissatisfied with the customer's explanation.

Additionally, the consumer has a right to know from the bank the reasons for the referral and continuation of the hold. The bank would be obligated to comply with any directives made by law enforcement or competent authorities on the continuation of the restriction. The bank is required to release the hold on the 31st day if no such directive is received within 30 days after the referral. Additionally, unless otherwise directed by a competent authority, the proposed regulations cap the total duration of a temporary debit hold to 60 days from the date it was imposed.