RBI Proposes Draft Rules to Standardize Account Freezing in Cyber Fraud Cases
India's central bank has proposed a new framework to establish uniform procedures for banks handling accounts and transactions suspected of involvement in cyber fraud.

The Reserve Bank of India (RBI) has proposed new draft rules aimed at standardizing the procedures banks must follow when dealing with accounts and transactions linked to cyber fraud. The draft norms, open for public comment until October 2, are set to take effect from April 1, 2027.
This initiative follows a Supreme Court directive in June, which mandated the central bank to create a time-bound protocol for managing accounts implicated in cyber fraud. The proposed framework requires banks to use automated tools, including AI and machine learning, to flag suspicious transactions of ₹1,000 or more, leading to a temporary debit freeze on the account.
Under the draft rules, banks will be required to notify account holders digitally on the same day or physically by the end of the next day. A key change is the focus on freezing suspected transaction amounts rather than entire accounts, with full account freezes reserved for suspected money mule accounts. The maximum duration for a temporary debit hold will be 60 days, unless further orders are received from legal authorities.
Account holders will have 20 days to provide an explanation after their account is frozen. Banks must review this explanation within 10 days. If unsatisfactory, the case can be escalated to law enforcement within 30 days. Otherwise, the hold will be lifted. The rules also mandate grievance redressal measures, including appointing nodal officers to resolve customer complaints within 30 days.
The proposed regulations come as India grapples with a significant rise in cyber fraud. In 2025, financial losses to cyber fraud were estimated at ₹22,495 crore, a slight decrease from ₹22,845 crore in 2024, indicating a persistent challenge for consumers and financial institutions.