When does the bank have to refund an unauthorised transaction?

In two situations you owe nothing at all: where the fault lay with the bank, and where it lay with neither of you but you reported within three working days. Report inside that window and your liability is zero — whatever the amount.

This comes from a Reserve Bank of India circular of 6 July 2017 on limiting customer liability in unauthorised electronic banking transactions. It binds every commercial bank, small finance bank and payments bank, with matching circulars for cooperative banks and for wallets and prepaid instruments.

Most people never learn it exists. They call the bank, are told the transaction was authenticated by OTP so nothing can be done, and give up. That answer is often wrong — and the rest of this page is about why.

Who has to prove the customer was at fault?

The bank does. This is the pivot the whole framework turns on, and it is the opposite of what most people assume when a branch tells them the transaction was authenticated and therefore theirs.

The sentence worth remembering

The RBI circular states that the burden of proving customer liability in an unauthorised electronic banking transaction lies on the bank. Not on you. You are not required to prove you were careful — the bank is required to prove you were not.

Who bears the loss — the three situations

The framework sorts every case into one of three boxes, and which box you are in decides everything.

What happenedWho pays
The bank was at fault — its own fraud, negligence or a deficiency in its systemsZero liability. It does not matter when you report
Nobody's fault, or a third-party breach — the failure sits somewhere else in the systemZero if you report within 3 working days. Capped between 4 and 7 working days. After that, your bank's board-approved policy decides
You were negligent — you shared your PIN, password or OTPYou bear the loss until you report it. Everything after you report is the bank's

That last line is the one people miss, and it matters even when you know you slipped up. Sharing a credential does not sign away everything that follows. Once you have told the bank, further losses are on them — which is why reporting stays urgent even when you are embarrassed about how it happened.

How much can you be made to pay?

If you report between four and seven working days in a third-party breach, your liability is capped by account type — ₹5,000, ₹10,000 or ₹25,000. It is never the whole amount, and the cap applies per transaction.

Account or instrumentMaximum you can be charged
Basic Savings Bank Deposit (BSBD) account₹5,000
Other savings accounts · prepaid instruments and gift cards · current and overdraft accounts of MSMEs · current accounts of individuals below the prescribed limit · credit cards with a limit up to ₹5 lakh₹10,000
Other current, cash-credit and overdraft accounts · credit cards with a limit above ₹5 lakh₹25,000

Compare that with what usually happens. Someone loses ₹80,000, reports on day five, is told nothing can be done — and pays the entire ₹80,000. On the framework above, in a third-party breach, the most they should bear is ₹10,000. The rest belongs to the bank.

Working days, and counted from when

The clock runs in working days, not calendar days, and it starts from when the bank communicated the transaction to you — not from when you happened to notice. A debit on Friday evening that you report on Tuesday morning may well be inside three working days. Do not assume you are late.

Not sure which situation yours falls into?

Ask Legal Setu — free, no account needed.
Ask Legal AI — free

What must the bank do after you report an unauthorised transaction?

Two deadlines bind the bank once you report. It must credit the disputed amount to your account within 10 working days, and it must resolve the complaint within 90 days.

The 10-day credit is the part almost nobody claims. It is a shadow reversal — the money goes back into your account, usually marked with a lien, while the investigation continues. The bank does not get to hold your money hostage until it finishes deciding. The obligation applies from the date you notify, whether or not the investigation is complete.

How to report, and what to say

Banks are required to give you a 24x7 channel for this, and to send transaction alerts you can reply to in order to register a dispute. The date you report is the date that counts, so create a record of it.

1
Report to the bank immediately — and in writing
Phone the 24x7 helpline, then follow it with an email or an entry in the app's complaint section so there is a timestamp you can produce later. Ask for the complaint reference number and keep it. A phone call alone leaves you arguing about dates.
Starts your clock
2
Report on 1930 or cybercrime.gov.in
The national cyber crime helpline is a separate track from the bank and it works fast. Reporting quickly gives the best chance of the money being frozen further down the chain before it is withdrawn.
The sooner the better
3
Say the words "unauthorised transaction"
Use the framework's own language. You are reporting an unauthorised electronic banking transaction and asking for the customer-liability framework to be applied. That framing is harder to brush aside than "some money is missing".
4
Block the instrument and secure the account
Block the card, change the net banking password, and check for any new payee or device registered against the account. If your phone was involved, deal with the SIM too.

What if the bank refuses to refund you?

Complain to the bank in writing first and give it 30 days. If it does not resolve the matter or you are unhappy with the reply, take it to the RBI Ombudsman — free, online, at cms.rbi.org.in.

The Ombudsman route matters because a branch's opening position is often simply wrong. Points worth putting in writing when you escalate:

Complaints go online at cms.rbi.org.in, and there is no fee. Keep to the timeline: you generally need to have complained to the bank and waited 30 days, and there is a limitation period for approaching the Ombudsman after the bank's reply — so do not let it drift.

Bank refusing to apply the framework?

₹99* books a verified lawyer, briefed on your case before the call.
Book a Lawyer — ₹99*

What if you approved the payment yourself?

This is treated differently, and it is important to be straight about it. If you entered the OTP or approved the UPI request yourself — even though you were deceived into doing it — that is not an "unauthorised" transaction under the current framework, and the zero-liability protection above does not automatically apply.

This is the hardest thing on this page and most articles gloss over it. The scam where a caller talks you into approving a payment is, in the framework's terms, a transaction you authorised. Consumer groups have criticised this gap for years. It does not mean you have no options — report to the bank and on 1930 regardless, because speed still matters for freezing funds, and your bank's own compensation policy may cover something — but it does mean the automatic protections are weaker.

Three situations that look similar and are governed differently:

What happenedWhere you stand
Money left without you doing anything — card cloned, account accessed, SIM swappedUnauthorised transaction. The framework on this page applies in full
You were tricked into approving it — a caller, a fake link, a fake refundWeaker position under the current rules. Report anyway, and see the 2027 change below
You sent it to the wrong person by mistakeNot a bank-liability matter at all. The bank cannot simply reverse it without the recipient's consent — separate process

What changes on 1 January 2027?

The RBI finalised a revised framework in June 2026 which takes effect on 1 January 2027. It broadens the cover beyond strictly "unauthorised" transactions towards fraudulent ones more generally — which is aimed squarely at the gap described above.

Two things to be clear about, because the timing matters:

From reports of the revised framework, the new protection is expected to take the form of capped compensation for certain fraud losses, subject to prompt reporting to both the bank and the national cyber crime channel — not a blanket zero-liability rule. Because the operative detail matters enormously here and the framework has not yet commenced, check the position on rbi.org.in when it takes effect rather than relying on a summary written before it did.

Two things that protect you before anything goes wrong

Keep transaction alerts switched on and actually read them — the clock runs from when the bank tells you, so an unread SMS costs you days. And never treat an OTP as something to be read out. No bank, no delivery agent and no "bank official" ever needs it; a request for one is the request itself, not the verification of anything.

Official sources

RBI — Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions

The circular of 6 July 2017 that governs this. It contains the three liability categories, the liability caps and the burden-of-proof rule.

RBI Complaint Management System

Where to file an Ombudsman complaint once you have complained to the bank and waited 30 days. Free, and entirely online.

National Cyber Crime Reporting Portal

Report financial cyber fraud here or on the 1930 helpline. This runs in parallel with your bank complaint, not instead of it.