🏹 Happy Dussehra — victory of good over evil!

Customer Liability in Unauthorised Transactions: RBI Rules (IIBF)

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 19 August 2026 · Updated 01 Oct 2026 · 12 min read · 46 views
Customer Liability in Unauthorised Transactions: RBI Rules (IIBF)

One OTP read out over a phone call, one card cloned at a petrol-pump terminal, and an account is emptied before the alert SMS is even opened. Who absorbs that loss is not a matter of negotiation. The rules on customer liability in unauthorised transactions are laid down by the Reserve Bank of India, and they are among the most heavily examined items in the IIBF Prevention of Cyber Crime paper. Learn the reporting clock, the zero-liability triggers and the graded limits, and you can answer almost anything the paper asks on this topic.

This guide follows the order an examiner reads the framework in: scope first, then the three-way classification of fault, then the numbers, then the operational duties the bank cannot escape.

🛡️ Who Is Covered and Which Transactions Qualify

The anchor instruction is the RBI circular of 6 July 2017, Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (DBR.No.Leg.BC.78/09.07.005/2017-18), addressed to all scheduled commercial banks including regional rural banks. A companion circular dated 14 December 2017 extended the same discipline to urban cooperative banks, state cooperative banks and district central cooperative banks. A parallel framework issued in January 2019 by the Department of Payment and Settlement Systems applies to prepaid payment instruments issued by authorised non-bank PPI issuers, so a wallet customer enjoys broadly the same protection as a savings account holder.

The framework bites only on unauthorised electronic transactions — those the customer neither initiated nor authorised, whether remote (internet banking, mobile banking, UPI, card-not-present) or proximity based (ATM, point of sale, contactless card). That distinction is where most candidates slip. If a customer is talked into voluntarily pushing money to a fraudster, as happens in QR code and payment link fraud, the transaction is technically authorised and the liability grid does not automatically award a refund; the customer's remedy runs through the bank's grievance machinery instead.

Every bank must put in place a board-approved policy on customer protection that spells out the rights and obligations of customers, and it must be displayed and communicated in plain language. Understanding how these losses originate helps you apply the rule set faster — revise the chapter on Electronic Card Frauds alongside this article, because card-present skimming and card-not-present abuse fall on opposite sides of the evidence question. Correctly fixing customer liability in unauthorised transactions begins with correctly classifying the transaction itself.

Scope of the RBI customer protection framework across banks, cooperative banks and PPI issuers
Scope of the RBI customer protection framework across banks, cooperative banks and PPI issuers

⚖️ The Three-Way Split That Decides Who Bears the Loss

The circular sorts every dispute into one of three buckets, and the entire exam value of this topic sits in telling them apart.

One — contributory fraud, negligence or deficiency on the part of the bank. Here the customer's liability is zero, and crucially it is zero irrespective of whether the customer reported the transaction or not. A failed second-factor authentication, an internal staff fraud, a system that kept authorising after a card was hot-listed: all of it lands on the bank. The words "irrespective of reporting" are the tested phrase, so memorise them exactly.

Two — third-party breach where the deficiency lies neither with the bank nor with the customer but elsewhere in the system. This is the largest bucket in practice: a compromised merchant switch, a cloned SIM, a telecom-side interception. The customer's liability is zero only if the bank is notified within three working days of receiving the bank's communication about the transaction. Beyond that, liability is graded. Losses arising from SIM swap fraud in banking typically sit here, which is exactly why the three-day window matters so much to the customer.

Three — customer negligence, such as sharing payment credentials. The customer bears the entire loss until the transaction is reported to the bank. Any loss occurring after the report is borne by the bank, even in a negligence case. Banks also retain discretion to waive customer liability entirely. Studying the Channels Of Cyber Crimes chapter makes the second and third buckets far easier to separate, because the channel usually reveals where the compromise occurred. Applying customer liability in unauthorised transactions is therefore a fault-location exercise before it is a numbers exercise.

💡 Exam Tip: "Zero liability irrespective of reporting" belongs only to bank fault. "Zero liability if reported within three working days" belongs to third-party breach. Swapping those two phrases is the single most common way candidates lose this mark.
Three-way liability split: bank deficiency, third-party breach and customer negligence
Three-way liability split: bank deficiency, third-party breach and customer negligence

📊 Graded Limits and the Reporting Clock

Where the breach is third-party and the customer takes four to seven working days to report, the loss is capped by account type. Working days are counted as per the working schedule of the customer's home branch, excluding the date on which the bank's communication was received — another detail examiners like to hide inside a scenario question.

Quick reference: customer liability in unauthorised transactions by fault type and reporting delay
SituationWho bears the lossCustomer's maximum liabilityZero liability?
Contributory fraud, negligence or deficiency of the bankBank, irrespective of reportingNil✅ Yes
Third-party breach, reported within 3 working daysBankNil✅ Yes
Third-party breach, reported on the 4th to 7th working dayShared, by account type₹5,000 for BSBD accounts; ₹10,000 for other savings accounts, prepaid instruments and gift cards, current/cash credit/overdraft accounts of MSMEs, current accounts of individuals with annual average balance up to ₹25 lakh and credit cards with limit up to ₹5 lakh; ₹25,000 for all other current, cash credit and overdraft accounts and credit cards with limit above ₹5 lakh❌ No
Third-party breach, reported beyond 7 working daysAs per the bank's board-approved policyDetermined by that policy❌ No
Customer negligence, credentials sharedCustomer up to the date of reporting; bank thereafterEntire loss till reported❌ No

For prepaid payment instruments issued by authorised non-banks, the corresponding cap for reporting on the fourth to seventh day is ₹10,000 per transaction, with the same zero-liability rule for reporting within three days. Cooperative banks follow the commercial-bank grid under the December 2017 extension. Note that the caps are ceilings, not automatic deductions: a bank may absorb more, never less. You can cross-check the source text in the RBI notifications archive, which remains the only citation an examiner will accept.

Graded maximum customer liability by account type for delayed reporting
Graded maximum customer liability by account type for delayed reporting

⏱️ Bank Obligations, Burden of Proof and the Escalation Route

The liability grid only works if the customer is told a transaction happened, so the circular loads the bank with hard operational duties. Banks must insist on registration of mobile numbers for SMS alerts and, where available, e-mail identifiers for e-mail alerts. SMS alerts are mandatory for electronic transactions; e-mail alerts go to registered addresses. The alert must be capable of being replied to, so the customer can report a disputed debit without composing a fresh complaint.

Reporting channels must be available round the clock through multiple routes — website, phone banking, SMS, e-mail, IVR, a dedicated toll-free helpline and the home branch. A direct link on the home page of the bank's website, with a specific option for reporting unauthorised electronic transactions, is expressly required. The system must send an immediate response, including an automatic acknowledgement carrying the registered complaint number, and the bank cannot insist that the customer walk into a branch to lodge the complaint.

On being notified, the bank must credit the amount involved — the shadow reversal — to the customer's account within ten working days from the date of notification, with value date as of the date of the unauthorised transaction, and without waiting for settlement of any insurance claim. For credit cards the customer must not end up bearing interest on the disputed amount. The complaint must be resolved and liability established within the period set by the bank's board-approved policy, and in no case beyond ninety days from receipt of the complaint. If the bank cannot resolve it in ninety days, it must still compensate the customer as if it were a third-party breach.

⚠️ Common Mistake: Ten working days for the shadow credit, but ninety calendar days for resolution. Candidates routinely mix the units, and scenario questions are built precisely to catch that.

These duties dovetail with the bank's wider incident response obligations; read the Incident Management chapter and our companion piece on IT security threats in banks to see how a single reported debit escalates into a full incident. In practice, weak alert hygiene is the commonest reason customer liability in unauthorised transactions ends up disputed at all.

One sentence in the circular changes the balance of power completely: the burden of proving customer liability in case of unauthorised electronic banking transactions lies on the bank. The customer does not have to prove innocence. The bank must produce logs, device fingerprints, authentication trails and channel evidence to show negligence. Absent that proof, the customer is treated as blameless.

That said, a customer who preserves evidence resolves the claim far faster. Retain the alert SMS and e-mail exactly as received, note the date and time the bank's communication was actually received because the three-day clock runs from there, keep the automatic acknowledgement carrying the complaint number, save the bank's written replies, take screenshots of the app or netbanking statement, and lodge a complaint on the National Cybercrime Reporting Portal or the 1930 helpline where a criminal element exists. If a card was in the customer's possession throughout, say so in writing — it materially shifts the argument in a card-present dispute, a point developed further in the Computer Fraud Protection chapter.

If the bank does not comply — no shadow credit, no resolution, or a liability finding without proof — the customer may escalate to the Reserve Bank's Integrated Ombudsman once the bank has failed to reply within thirty days or has replied unsatisfactorily, filing online through the RBI's complaint management portal, by post or by e-mail. Frontline staff who follow a written control routine, such as our cyber crime prevention checklist for bankers, rarely reach that stage.

🧠 Practice MCQs: Customer Liability in Unauthorised Transactions

Q1. Under the RBI framework, in which situation is the customer's liability zero irrespective of whether the transaction is reported? (a) Third-party breach reported on the fifth working day (b) Contributory fraud, negligence or deficiency on the part of the bank (c) Customer sharing the OTP with a caller (d) Transaction reported after seven working days

Answer: (b) — Where the loss arises from the bank's own fraud, negligence or deficiency, liability is nil whether or not the customer reports it.

Q2. In a third-party breach where the deficiency lies neither with the bank nor with the customer, the customer bears zero liability only if the bank is notified within (a) two working days (b) three working days (c) seven working days (d) ten calendar days

Answer: (b) — Notification within three working days of receiving the bank's communication gives the customer zero liability.

Q3. A BSBD account holder suffers a third-party breach and reports it on the fifth working day. The maximum liability that can be fastened on the customer is (a) ₹5,000 (b) ₹10,000 (c) ₹25,000 (d) Nil

Answer: (a) — For BSBD accounts the cap in the four-to-seven working day band is ₹5,000.

Q4. On being notified of an unauthorised electronic transaction, the bank must give shadow credit of the amount involved within (a) five working days of notification (b) ten working days of notification (c) ninety days of the complaint (d) only after the insurance claim is settled

Answer: (b) — The shadow reversal is due within ten working days of notification, value-dated to the transaction date, without waiting for any insurance settlement.

Q5. In a dispute over an unauthorised electronic banking transaction, the burden of proving customer liability lies on (a) the customer (b) the bank (c) the Ombudsman (d) the card network

Answer: (b) — The circular places the burden of proving customer liability squarely on the bank.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

Does the framework apply to wallets and prepaid cards?

Yes. A parallel RBI framework issued in January 2019 applies the same zero-liability and graded-liability logic to prepaid payment instruments issued by authorised non-bank issuers, with a cap of ₹10,000 per transaction for reporting on the fourth to seventh day.

What if the customer reports after seven working days?

Liability is then determined by the bank's board-approved policy. The circular does not fix a number, so the answer in an exam is always "as per the board-approved policy of the bank", and that policy must be disclosed to customers.

Is the customer protected if the credentials were shared?

Only partially. The customer bears the entire loss until the transaction is reported, but every rupee lost after the report is borne by the bank. The bank may also waive liability at its discretion.

What happens if the bank misses the ninety-day resolution deadline?

The bank must compensate the customer on the same basis as a third-party breach, that is, without fastening negligence on the customer merely because the enquiry was not completed in time.

🎯 Key Takeaways and Your Next Step

Reduce the whole topic to four moves. Classify the fault — bank, third party, or customer. Count the working days from the date the bank's communication was received. Apply the cap for the account type if the report lands in the four-to-seven day band. Then check the bank's process duties: alerts, a 24x7 reporting channel with a home-page link, an auto-acknowledgement with a complaint number, shadow credit in ten working days, resolution in ninety days, and the burden of proof on the bank throughout.

Questions on customer liability in unauthorised transactions reward precision, not paraphrase, so drill the phrases rather than the gist. Work through more articles in the Prevention of Cyber Crime tag hub, revisit the COMPUTER INSECURITY chapter for the underlying vulnerabilities, and then put yourself under exam conditions with a full-length paper on iibf.store mock tests. If you are also preparing the professional papers, the same customer-protection logic recurs across the CAIIB course syllabus.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading