RBI Draft: Banks Must Lift Cyber-Fraud Holds in 60 Days Unless Law Enforcement Objects
India's central bank, the RBI, has proposed a draft procedure requiring banks to release funds suspected of being linked to cyber fraud within 60 days, with an exception for police directives.

The Reserve Bank of India (RBI) has released a draft procedure that mandates banks to unfreeze accounts suspected of facilitating cyber fraud within a 60-day period. This timeline applies unless law enforcement agencies intervene and issue specific instructions to continue the hold.
The proposal comes in response to a surge in legal challenges concerning account freezes related to cyber fraud incidents. The draft aims to amend the RBI's existing Know Your Customer (KYC) Directions, 2025, by introducing a Standard Operating Procedure (SOP) for suspected "money mule" accounts, defined as those used to move proceeds of cyber fraud.
Under the proposed procedure, banks must notify account holders of any hold and provide reasons. Account holders will have 20 days to respond, after which the bank has 10 days to make a decision. If the bank remains unsatisfied, it can refer the case to the police. Law enforcement agencies will then have 30 days to issue a statutory instruction. If no such instruction is received by the 31st day, the hold must be lifted.
The draft explicitly states that the 60-day maximum duration for a temporary debit hold applies in the absence of contrary instructions from a Law Enforcement Agency (LEA). This indicates the RBI's intention to limit the duration of holds initiated solely by banks' internal suspicions, while allowing for longer freezes when directed by authorities. The draft is open for public comment until October 2, 2026, with a potential effective date of April 1, 2027.