RBI Proposes Targeted Freeze on Only Disputed Amounts in Suspected Cyber Fraud Cases — September 14, 2026
Published: 2026-09-14 11:02 IST | Category: Markets | Author: Abhi AI
The Reserve Bank of India (RBI) has unveiled a draft framework aimed at putting an end to blanket account freezes triggered by cybercrime probes. Under the proposed draft amendment directions to the Master Direction on Know Your Customer (KYC), banks will be instructed to apply temporary debit holds strictly to the disputed transaction amount rather than freezing an individual's or business's entire account.
The draft rules follow an order from the Supreme Court of India issued on August 4, 2026, which directed the central bank to formulate and circulate a standard operating procedure (SOP) governing temporary debit restrictions on accounts suspected of involvement in money-mule operations and cyber-enabled financial fraud. The new directions are scheduled to formally take effect from April 1, 2027, though banks have been permitted to adopt them earlier.
Proportionate Restraints Over Blanket Freezes
In recent years, thousands of bank customers across India—including legitimate retail investors, traders, and small business owners—have found their bank accounts suddenly frozen following cyber complaints registered in distant states. Often, receiving an inadvertent or disputed secondary payment led law enforcement agencies and automated banking protocols to lock down whole accounts, cutting off access to legitimate savings and working capital.
Under the RBI's proposed standard operating procedure, total account-level freezes will be reserved strictly as a measure of last resort in exceptional circumstances. Instead, banks will place a targeted debit hold only on the specific flagged sum of Rs 1,000 or more that is identified as potentially linked to money mule activity or cyber fraud proceeds.
Time-Bound Mechanism and Clear Deadlines
To prevent open-ended financial paralysis, the central bank has proposed a time-bound workflow capping temporary debit holds at a maximum duration of 60 days.
Key Timelines Established in the Proposed Framework:
- Customer Response Period: The bank must immediately notify the account holder regarding the hold, providing specific details and the reasons for the restraint. The customer will have 20 calendar days to furnish proof of identity, transaction context, or legitimate source of funds.
- Bank Evaluation Window: Once the documentation is received, the bank will have 10 calendar days to evaluate the customer's explanation. If the justification is found satisfactory, the bank must lift the debit hold immediately.
- Law Enforcement Referral: If the customer fails to respond within 20 days or the explanation fails to clear suspicions, the bank will refer the matter to jurisdictional law enforcement through the National Cybercrime Reporting Portal (NCRP) or CFCFRMS platform.
- Statutory Restraint Limit: Police authorities will then have 30 days from the referral date to obtain and serve a formal statutory restraint order, failing which the hold cannot continue indefinitely.
Implementation and Technology Requirements
The central bank has mandated that commercial lenders implement artificial intelligence (AI) and machine learning (ML)-powered transaction monitoring systems to identify anomalous activity. Rather than initiating arbitrary blocks, banks must evaluate transactions against clear behavioral markers, such as transfers that are sudden, vastly disproportionate to the declared customer profile, or linked to verified fraud networks.
For Indian market participants, businesses, and banking customers, this regulatory shift introduces necessary safeguards against arbitrary account disruption while ensuring law enforcement retains the ability to track down illicit flows.
Tags: Reserve Bank of India Indian Banking Sector Supreme Court of India National Cybercrime Reporting Portal Digital Banking