Electronic Evidence in Banking Fraud Cases: Collection and Admissibility
When a customer disputes a fraudulent debit, the bank's defence rests on evidence, not opinion. Electronic evidence in banking fraud cases decides whether a disputed transaction stands up before a court, the Banking Ombudsman, or a police cyber cell. Staff who handle CCTV footage, ATM logs, or SMS alerts without the right procedure can turn strong proof into worthless paper. This article explains how to collect, certify, and preserve electronic evidence in banking fraud cases so it survives legal scrutiny.
📜 The Certificate Requirement for Electronic Records
India's evidence law was recast in 2024. The Bharatiya Sakshya Adhiniyam, 2023 (BSA) replaced the Indian Evidence Act, 1872. The new law carries forward a rule every banker must know: a computer-generated record needs a signed certificate before a court will admit it. This requirement was earlier found under section 65B of the 1872 Act, and the BSA preserves the same underlying principle for electronic and digital records.
The certificate must describe the device that produced the record, confirm the record was generated during ordinary business activity, and confirm no unauthorised change occurred. A responsible bank officer, usually someone who manages the system in question, signs it. Without this certificate, a printout of a core banking log or a CCTV still is just paper. Courts routinely reject unsigned or vague certificates, even when the underlying data is accurate.
This is why banks train branch and IT staff together. A fraud investigation that starts well but skips the certificate step collapses at trial. The Computer Fraud Protection chapter covers this certification workflow in more depth, including who within the bank is authorised to sign.
💡 Exam Tip: Remember that the certificate requirement is about the process of generating the record, not the content of the record itself.

🔗 Chain of Custody: From Server to Court
Chain of custody means an unbroken, documented trail from the moment evidence is collected to the moment it is produced in court. Every person who touches the evidence, and every action taken on it, must be logged. A gap in this trail lets the opposing side argue the record was altered.
Good practice starts with identifying the exact source: a specific ATM, switch, or server. The investigator then makes a forensic copy, never working on the original. A cryptographic hash value is calculated and recorded at the point of collection, so any later change to the file is instantly detectable. Every handover between officers, forensic teams, or the police is logged with date, time, and signature.
Storage matters as much as collection. Copies sit in tamper-evident storage with restricted access, and the original device or drive is sealed wherever possible. Banks that skip this discipline often find their own IT team unable to explain, months later, who accessed a disputed log and when.
⚠️ Common Mistake: Investigators open the original file to "just check" the content, and that single action can break the chain of custody.

📹 Preserving CCTV, ATM and Switch Logs
CCTV footage, ATM transaction logs, and switch logs are the backbone of most banking fraud investigations. Switch logs record every card transaction as it passes through the payment network, and they often show details the customer-facing statement does not.
Most banks retain ATM CCTV footage and switch logs for a fixed minimum period under RBI guidance, commonly cited as around ninety days. That default period is not enough once a dispute is raised. The moment a complaint is logged, the bank must issue an internal preservation instruction so the specific footage and logs tied to that transaction are held indefinitely, separate from the routine overwrite cycle.
Audit trails and system-generated records inside the core banking system matter just as much. These logs show login timestamps, IP addresses, and every field an operator changed. Fraud investigators cross-reference switch logs, CCTV timestamps, and audit trails to build a single timeline. Any mismatch between these sources, such as a transaction logged on the switch but missing from the audit trail, becomes a lead worth chasing. The Electronic Card Frauds chapter walks through how switch and card logs are read during an investigation.
📌 Remember: Once a dispute is logged, standard retention periods no longer apply to that specific record.

🚨 Preservation Notices and Coordination with Police, CERT-In
Once a bank confirms a transaction is fraudulent, it must move fast on two fronts: preserving evidence and reporting the incident. A preservation notice, often called a litigation hold, goes out to every internal team holding relevant data, so nothing is deleted on a routine schedule. The same notice may go to a payment gateway, telecom operator, or another bank if the fraud touched their systems.
Significant cyber security incidents also require reporting to CERT-In, the national nodal agency for responding to computer security incidents. Banks report qualifying incidents within the prescribed timeline and follow up with any additional detail CERT-In requests. This reporting duty runs alongside, not instead of, the bank's internal investigation.
Coordination with the police cyber cell usually follows once the bank has assembled its certified electronic records. A clear, well-indexed evidence package, complete with certificates and chain-of-custody logs, speeds up the FIR process and improves the odds of tracing the money before it moves further. The Incident Management chapter sets out the full escalation sequence banks follow after detection.
Handled well, this stage also protects genuine customers. A bank that can show it preserved and reported evidence correctly is in a far stronger position when a customer liability dispute reaches the Banking Ombudsman.
The table below summarises how common evidence sources differ in retention, certification, and the trigger for special preservation.
| Evidence Source | Standard Retention | Certificate Needed? | Preservation Trigger |
|---|---|---|---|
| CCTV footage (branch/ATM) | ~90 days under RBI guidance | ✅ Yes | Fraud complaint or dispute logged |
| Switch/network transaction logs | Set by bank policy | ✅ Yes | Transaction flagged as disputed |
| Core banking audit trail | Long-term, system-defined | ✅ Yes | Any internal fraud investigation |
| SMS/email fraud alerts | Varies by service provider | ✅ Yes | Customer reports unauthorised debit |
| Customer's informal screenshot | Not bank-controlled | ❌ No certificate possible | Supporting detail only, not primary proof |
🧠 Practice MCQs: Electronic Evidence in Banking Fraud Cases
Q1. Under Indian law, what must accompany a computer-generated record for a court to admit it as evidence? (a) A notarised photocopy (b) A signed certificate describing the device and process (c) A verbal statement from the branch manager (d) Nothing, computer records are always admissible
Answer: (b) — A signed certificate covering the device and process used is a mandatory requirement carried forward under the Bharatiya Sakshya Adhiniyam, 2023.
Q2. What does "chain of custody" refer to in an electronic evidence investigation? (a) The bank's organisational hierarchy (b) A documented, unbroken trail of who handled the evidence and when (c) The list of customers affected by fraud (d) The software used to detect fraud
Answer: (b) — Chain of custody is the documented record of every person and action involved in handling the evidence from collection to production.
Q3. Once a transaction dispute is logged, what should happen to the related CCTV footage and switch logs? (a) They follow the normal overwrite schedule (b) They are preserved beyond the standard retention period (c) They are deleted immediately for privacy (d) They are handed only to the customer
Answer: (b) — A preservation instruction must hold the specific footage and logs tied to that dispute, overriding the routine retention cycle.
Q4. Which agency is the designated national body for reporting significant cyber security incidents in India? (a) SEBI (b) CERT-In (c) IRDAI (d) NPCI
Answer: (b) — CERT-In is the national nodal agency for responding to and receiving reports of computer security incidents.
Q5. Why might an investigator's action of opening an original evidence file directly cause a problem in court? (a) It uses too much storage (b) It can break the chain of custody and raise doubts about tampering (c) It is faster than using a copy (d) It has no legal impact
Answer: (b) — Working on the original instead of a verified copy breaks the documented chain of custody and invites challenge to the evidence.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
❓ Frequently Asked Questions
Why does electronic evidence in banking fraud cases need a certificate?
Indian evidence law treats computer-generated records as needing extra proof of reliability. A signed certificate confirms the device and process used, without which courts can refuse to admit the record.
What happens if a bank fails to preserve CCTV footage in time?
Once routine retention periods lapse without a preservation instruction, the footage is usually overwritten and lost, which can seriously weaken the bank's position in a dispute or investigation.
Who signs the certificate for an electronic record?
A responsible officer familiar with the system that generated the record, typically someone managing that device or application, signs the certificate.
Does CERT-In reporting replace filing a police complaint?
No. CERT-In reporting is a separate regulatory duty. Banks still coordinate with the police cyber cell to pursue an FIR and criminal investigation.
🎯 Building an Evidence-Ready Fraud Response
Electronic evidence in banking fraud cases only holds up when three things happen together: a valid certificate, an unbroken chain of custody, and timely preservation before logs are overwritten. Bank staff who understand all three protect the institution and genuine customers alike.
Study the certificate rule, the retention windows, and the CERT-In reporting duty together, since exam questions often test how these pieces connect. Revisit the Computer Fraud Protection and Incident Management chapters together, and pair this topic with related reading on channels of cyber crime in banking, the RBI cybersecurity framework for banks, and the digital arrest scam mechanics, since all three feed into how a bank builds its evidence file. For a broader view of how staff readiness supports this work, see our note on information security awareness training in banks. Browse more chapters in the Prevention of Cyber Crime tag hub to revise the full topic list.
Ready to test yourself? Take a free chapter-wise mock test and see how well you can apply these rules under exam conditions.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.