When does the bank have to refund an unauthorised transaction?
In two situations you owe nothing at all: where the fault lay with the bank, and where it lay with neither of you but you reported within three working days. Report inside that window and your liability is zero — whatever the amount.
This comes from a Reserve Bank of India circular of 6 July 2017 on limiting customer liability in unauthorised electronic banking transactions. It binds every commercial bank, small finance bank and payments bank, with matching circulars for cooperative banks and for wallets and prepaid instruments.
Most people never learn it exists. They call the bank, are told the transaction was authenticated by OTP so nothing can be done, and give up. That answer is often wrong — and the rest of this page is about why.
Who has to prove the customer was at fault?
The bank does. This is the pivot the whole framework turns on, and it is the opposite of what most people assume when a branch tells them the transaction was authenticated and therefore theirs.
The RBI circular states that the burden of proving customer liability in an unauthorised electronic banking transaction lies on the bank. Not on you. You are not required to prove you were careful — the bank is required to prove you were not.
Who bears the loss — the three situations
The framework sorts every case into one of three boxes, and which box you are in decides everything.
| What happened | Who pays |
|---|---|
| The bank was at fault — its own fraud, negligence or a deficiency in its systems | Zero liability. It does not matter when you report |
| Nobody's fault, or a third-party breach — the failure sits somewhere else in the system | Zero if you report within 3 working days. Capped between 4 and 7 working days. After that, your bank's board-approved policy decides |
| You were negligent — you shared your PIN, password or OTP | You bear the loss until you report it. Everything after you report is the bank's |
That last line is the one people miss, and it matters even when you know you slipped up. Sharing a credential does not sign away everything that follows. Once you have told the bank, further losses are on them — which is why reporting stays urgent even when you are embarrassed about how it happened.
How much can you be made to pay?
If you report between four and seven working days in a third-party breach, your liability is capped by account type — ₹5,000, ₹10,000 or ₹25,000. It is never the whole amount, and the cap applies per transaction.
| Account or instrument | Maximum you can be charged |
|---|---|
| Basic Savings Bank Deposit (BSBD) account | ₹5,000 |
| Other savings accounts · prepaid instruments and gift cards · current and overdraft accounts of MSMEs · current accounts of individuals below the prescribed limit · credit cards with a limit up to ₹5 lakh | ₹10,000 |
| Other current, cash-credit and overdraft accounts · credit cards with a limit above ₹5 lakh | ₹25,000 |
Compare that with what usually happens. Someone loses ₹80,000, reports on day five, is told nothing can be done — and pays the entire ₹80,000. On the framework above, in a third-party breach, the most they should bear is ₹10,000. The rest belongs to the bank.
The clock runs in working days, not calendar days, and it starts from when the bank communicated the transaction to you — not from when you happened to notice. A debit on Friday evening that you report on Tuesday morning may well be inside three working days. Do not assume you are late.
Not sure which situation yours falls into?
Ask Legal Setu — free, no account needed.What must the bank do after you report an unauthorised transaction?
Two deadlines bind the bank once you report. It must credit the disputed amount to your account within 10 working days, and it must resolve the complaint within 90 days.
The 10-day credit is the part almost nobody claims. It is a shadow reversal — the money goes back into your account, usually marked with a lien, while the investigation continues. The bank does not get to hold your money hostage until it finishes deciding. The obligation applies from the date you notify, whether or not the investigation is complete.
- Within 10 working days of your report — the disputed amount is credited to your account
- Within 90 days of your report — the complaint is resolved and liability determined
- If the bank misses either — compensation follows its board-approved policy, and the failure itself is a ground for escalation
How to report, and what to say
Banks are required to give you a 24x7 channel for this, and to send transaction alerts you can reply to in order to register a dispute. The date you report is the date that counts, so create a record of it.
What if the bank refuses to refund you?
Complain to the bank in writing first and give it 30 days. If it does not resolve the matter or you are unhappy with the reply, take it to the RBI Ombudsman — free, online, at cms.rbi.org.in.
The Ombudsman route matters because a branch's opening position is often simply wrong. Points worth putting in writing when you escalate:
- The burden of proof is on the bank. Ask it to state, in writing, the evidence on which it says you were negligent
- An OTP is not the end of the argument. Authentication having occurred does not by itself establish that you authorised the transaction, which is the thing the bank must prove
- Ask which of the three categories it has placed your case in, and why. Making the bank commit to a category in writing tends to sharpen its thinking
- Cite the 10-working-day credit if it has not been made
Complaints go online at cms.rbi.org.in, and there is no fee. Keep to the timeline: you generally need to have complained to the bank and waited 30 days, and there is a limitation period for approaching the Ombudsman after the bank's reply — so do not let it drift.
Bank refusing to apply the framework?
₹99* books a verified lawyer, briefed on your case before the call.What if you approved the payment yourself?
This is treated differently, and it is important to be straight about it. If you entered the OTP or approved the UPI request yourself — even though you were deceived into doing it — that is not an "unauthorised" transaction under the current framework, and the zero-liability protection above does not automatically apply.
This is the hardest thing on this page and most articles gloss over it. The scam where a caller talks you into approving a payment is, in the framework's terms, a transaction you authorised. Consumer groups have criticised this gap for years. It does not mean you have no options — report to the bank and on 1930 regardless, because speed still matters for freezing funds, and your bank's own compensation policy may cover something — but it does mean the automatic protections are weaker.
Three situations that look similar and are governed differently:
| What happened | Where you stand |
|---|---|
| Money left without you doing anything — card cloned, account accessed, SIM swapped | Unauthorised transaction. The framework on this page applies in full |
| You were tricked into approving it — a caller, a fake link, a fake refund | Weaker position under the current rules. Report anyway, and see the 2027 change below |
| You sent it to the wrong person by mistake | Not a bank-liability matter at all. The bank cannot simply reverse it without the recipient's consent — separate process |
What changes on 1 January 2027?
The RBI finalised a revised framework in June 2026 which takes effect on 1 January 2027. It broadens the cover beyond strictly "unauthorised" transactions towards fraudulent ones more generally — which is aimed squarely at the gap described above.
Two things to be clear about, because the timing matters:
- It is final, not a draft. The draft was issued in March 2026 and the amendment directions were issued on 24 June 2026
- It is not in force yet. Until 1 January 2027 the 2017 framework described on this page is what governs your transaction. Anything that happened before that date is decided under the current rules
From reports of the revised framework, the new protection is expected to take the form of capped compensation for certain fraud losses, subject to prompt reporting to both the bank and the national cyber crime channel — not a blanket zero-liability rule. Because the operative detail matters enormously here and the framework has not yet commenced, check the position on rbi.org.in when it takes effect rather than relying on a summary written before it did.
Keep transaction alerts switched on and actually read them — the clock runs from when the bank tells you, so an unread SMS costs you days. And never treat an OTP as something to be read out. No bank, no delivery agent and no "bank official" ever needs it; a request for one is the request itself, not the verification of anything.
Official sources
The circular of 6 July 2017 that governs this. It contains the three liability categories, the liability caps and the burden-of-proof rule.
RBI Complaint Management SystemWhere to file an Ombudsman complaint once you have complained to the bank and waited 30 days. Free, and entirely online.
National Cyber Crime Reporting PortalReport financial cyber fraud here or on the 1930 helpline. This runs in parallel with your bank complaint, not instead of it.