Cyber Law (India)

RBI digital fraud compensation from 2027: what Indian customers must know

RBI digital fraud rules from 1 Jan 2027: ₹50,000 / ₹25,000 compensation, 5-day reporting, zero liability vs customer liability, and official RBI links for India.

CyberSathi DeskAI-assisted · editorially reviewed
RBI digital fraud compensation from 2027: what Indian customers must know

If your loss was in 2026 or earlier, read this first: Lost money to fraud in 2026? Why RBI’s 2027 compensation cut-off matters.

Why this matters before 1 January 2027

From 1 January 2027, RBI’s revised framework on limiting customer liability in digital transactions takes effect. It is not just a tweak to the old “unauthorised transaction” rules. It expands protection to many fraudulent electronic banking transactions (fraudulent EBTs) — including cases where someone tricked you into sharing credentials, or pressured you into approving a payment — and adds a small-value compensation route for bona fide individual victims.

This is a public-awareness guide for ordinary bank and UPI users in India. It is based on RBI’s Amendment Directions and press materials issued in June 2026. Always check your own bank’s published policy and the latest text on rbi.org.in before you act.

Complete claim guide

For the full step-by-step process, timeline table, sample bank message, and eligibility checklist, use our companion guide: How to claim RBI digital fraud compensation in 2027: steps and timelines.

What changed versus the older rules

Earlier, many victims heard: “You authorised the OTP / UPI PIN, so the bank is not liable.” The 2017-style limited-liability framework focused heavily on unauthorised electronic banking transactions.

The 2026 Amendment Directions (effective for EBTs on or after 1 January 2027) introduce a clearer idea of a fraudulent EBT: a payment executed by a third party using credentials obtained through fraudulent means, or approved by the customer under coercion or duress, and/or an unauthorised EBT (including bank negligence or certain third-party breaches).

In plain language: some scam-led transfers that previously fell into a grey zone are now explicitly inside the fraud framework — subject to the bank’s examination and the conditions below.

RBI summarised the package in its press release on the Amendment Directions. The commercial-bank text is published under RBI’s circular index (for example Notification Id=13543).

The small-value compensation people are asking about

This is the part families should remember.

If you are a bona fide individual victim (including a sole proprietor) and your complaint involves gross loss up to ₹50,000 from eligible fraudulent EBTs that fall under the customer-negligence / compensation pathway in the Directions, you may receive:

  • 85% of the net loss, or
  • ₹25,000,

whichever is less — and only once in your lifetime.

Net loss means gross loss minus recoveries credited back. So if ₹40,000 left and ₹15,000 comes back before compensation, net loss is ₹25,000 and 85% is ₹21,250.

Conditions that matter in practice:

  1. The bank’s process must establish the loss as bona fide.
  2. You must report to both your bank and the National Cyber Crime Reporting Portal / helpline 1930 within five calendar days of the fraudulent EBT.
  3. The compensation mechanism in the Directions is framed as applying for fraudulent EBTs occurring for up to one year from the effective date (a pilot-style window banks and RBI will operate and review).

This is not automatic full refund of every scam. Losses above ₹50,000, delayed reporting, or cases where liability is decided differently can fall outside this small-value pocket.

Zero liability is still the stronger path when it applies

Compensation under the small-value mechanism is one track. Separately, the Directions still provide for zero liability and reversal when:

  • the fraudulent EBT is due to bank negligence / deficiency, or
  • it is a third-party breach style unauthorised fraudulent EBT reported to the bank within five calendar days.

If you report late after a third-party breach, liability can shift under the bank’s policy. After you report, further unauthorised loss on that trail is generally for the bank to bear.

Banks must examine liability and respond within 45 calendar days for domestic fraudulent EBTs and 60 calendar days for cross-border ones (unless their policy sets a stricter internal clock, which cannot exceed these outer limits).

What you should do in the first five days

Speed is the difference between a claimable case and a lecture.

  1. Freeze risk — use your bank’s 24x7 fraud / card block channels from the official app or the number on your debit card.
  2. Report to the bank — keep the complaint number, date, and time from the acknowledgement.
  3. Report on 1930 / cybercrime.gov.in — RBI’s framework expects this for the small-value compensation path.
  4. Save evidence — SMS alerts, UTR, screenshots, call recordings if any, UPI chat, fake “bank” numbers.
  5. Do not install remote-access apps because a caller promises a refund — see Bank asked you to install AnyDesk for a UPI refund? That call is a scam.

For the wider reporting map in India, use How to Report a Cyber Crime in India: Where to Go, What to Expect.

How UPI and online banking frauds fit this story

Most household losses still begin the same way: fake KYC links, “refund” calls, WhatsApp investment tips, or a rushed UPI collect request. The new framework does not make those scams safe. It changes what happens after you are hit — if you report fast and the case fits the definitions.

Learn the attack patterns here:

What this law is not

Be careful with viral forwards.

  • It is not a promise that every UPI mistake will be refunded in full.
  • It is not a reason to share OTP “because RBI will pay.”
  • It does not replace vigilance: customer negligence (sharing PIN/OTP, ignoring clear bank scam warnings, malicious apps, stale registered mobile numbers) still affects outcomes.
  • Joint accounts: only one holder may claim under the compensation route, and that claim counts against lifetime eligibility.

A simple household checklist for 2027

Print this or save it in your family WhatsApp group:

  • Keep your bank-registered mobile number updated.
  • Treat every unexpected debit SMS as an emergency, not a puzzle for tomorrow.
  • Call the bank from the card / official website — never from a number that called you.
  • File on 1930 / cybercrime.gov.in within five calendar days.
  • Ask the bank in writing whether your case is zero-liability reversal or small-value compensation under the 2027 Directions.
  • Keep copies of every acknowledgement.

Official sources to bookmark

Frequently asked questions

When do the RBI digital fraud compensation rules start?

They apply to electronic banking transactions undertaken on or after 1 January 2027, as stated in RBI’s Amendment Directions.

How much compensation can I get for small-value fraud?

For eligible bona fide individual victims with gross loss up to ₹50,000, compensation is 85% of net loss or ₹25,000, whichever is less — once in a lifetime.

What is the reporting deadline?

Report to your bank and to 1930 / cybercrime.gov.in within five calendar days of the fraudulent transaction for the small-value compensation path (and for key zero-liability third-party-breach cases).

Is every UPI scam fully refunded?

No. Outcomes depend on liability classification. Some cases get zero-liability reversal; some get capped small-value compensation; some may be rejected if eligibility fails.

Where can I read the official rules?

Start with the RBI press release and the Commercial Banks Amendment Directions notification. Also bookmark CERT-In and MeitY for broader cyber guidance.

Read next