Unauthorised Banking Transaction Liability in India: Who Really Bears the Loss and How to Protect Your Money Now

Legal note: This article is for educational purposes and does not replace advice from a qualified lawyer.
Table of Contents
1. Introduction
You wake up to an SMS that says Rs. 45,000 has been debited from your account — but you made no such transaction. Your heart races. Someone has stolen your money. But who is responsible? Do you have to bear this loss, or is your bank liable?
This is the central question of unauthorised banking transaction liability in India. The answer depends on critical factors: Where did the fault lie? How quickly did you report it? Was it your negligence or the bank’s failure?
This blog explains the law on unauthorised banking transaction liability in India in simple language, with clear rules, real examples, and the steps to protect yourself.
2. What Is an Unauthorised Banking Transaction?
An unauthorised banking transaction is any financial transaction on your bank account that you did not authorize — whether online banking, ATM transaction, credit/debit card use, UPI payment, NEFT, RTGS, or any other mode.
Common causes include:
- Phishing attacks — you are tricked into sharing OTP or banking credentials
- Malware or keyloggers on your device that steal your credentials
- SIM swap fraud — fraudster convinces your telecom operator to issue a new SIM
- Card cloning — your debit or credit card details are copied
- Vishing — voice call scams where you are manipulated into sharing OTP
- Data breach at the bank or payment processor
- Insider fraud at the bank
3. The RBI’s Framework: Who Pays?
The landmark RBI Circular on Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (2017) is the governing framework for unauthorised banking transaction liability in India. It divides liability clearly based on where the fault lies.
3.1 Scenario 1: Fault Lies with the Bank or Third Party (No Customer Negligence)
If the unauthorised transaction happened due to a bank system failure, bank employee fraud, third-party hack of the bank’s systems, or any reason entirely outside the customer’s control — and the customer is not negligent — then:
- Customer’s liability = ZERO. The bank must refund the full amount.
- This applies regardless of when the customer reports it (though faster is better).
3.2 Scenario 2: Shared Fault (Both Bank and Customer)
If the fraud happened partly due to bank negligence and partly due to customer negligence (for example, the bank had weak security AND the customer also shared their PIN verbally), the customer’s liability is limited based on the table below:
| Maximum Transaction Limit | Reported Within 4–7 Days (Limit per RBI) | Customer Liability Cap |
| Basic Savings (BSBDA) / Savings up to Rs. 25,000 transactions | Within 4–7 working days of the fraud | Rs. 5,000 |
| Savings, Pre-paid, Credit Card up to Rs. 5 lakh limit | Within 4–7 working days of the fraud | Rs. 10,000 |
| Above Rs. 5 lakh credit limit / all other accounts | Within 4–7 working days of the fraud | Rs. 25,000 |
Note: The above slab applies only when the fault is shared. In cases of sole bank/third-party fault, zero liability applies regardless of amount.
3.3 Scenario 3: Sole Negligence of the Customer
If the fraud happened entirely because of the customer’s own negligence — for example, the customer voluntarily shared their OTP, PIN, or card details with a fraudster — then the bank is not liable. The customer bears the full loss.
However, even in this case, you should report the fraud immediately. If you report promptly, the bank may be able to block further transactions and limit your loss.
3.4 The Most Critical Rule: Report Within 3 Working Days
Under the RBI’s 2017 circular on unauthorised banking transaction liability in India, the time you take to report the fraud determines your liability:
| Reporting Timeline | Fault with Bank/Third Party | Shared Fault Liability |
| Within 3 working days | ZERO liability — full refund | Full refund (no customer liability) |
| 4–7 working days | ZERO liability — full refund | Limited liability per RBI slab (max Rs. 25,000) |
| Beyond 7 working days | Depends on board-approved policy | As per bank policy — more risk to customer |
3.5 Bank’s Obligation to Resolve Quickly
Once you report an unauthorised transaction, the bank must:
- Credit the amount to your account within 10 working days (as a provisional credit) even while investigation is ongoing.
- Complete the investigation and resolve the complaint within 90 days.
- If the investigation is in the customer’s favour, retain the provisional credit. If not, they can reverse the provisional credit after 90 days.
4. Key Legal Provisions
| Legal Provision | How It Governs Unauthorised Banking Transaction Liability |
| RBI Circular — Customer Liability (2017) | Zero liability for bank/third-party fault reported in 3 days; slabs for shared fault |
| RBI IOS, 2021 (Clause 8) | Ombudsman handles unauthorised transaction disputes; up to Rs. 20 lakh award |
| IT Act, 2000 (S. 43A, 66C) | Bank liable for data breach; identity theft is criminal offence |
| Consumer Protection Act, 2019 | Unauthorised transaction = deficiency in service; consumer court remedy |
| Bharatiya Nyaya Sanhita, 2023 (S. 316, 318) | Fraud using your banking credentials = criminal offence; FIR can be filed |
| Information Technology (Intermediary Guidelines) Rules, 2021 | Banks as intermediaries must have data protection safeguards |
5. Important Case Laws
5.1 RBI Ombudsman Awards on Unauthorised Transactions
Multiple published Ombudsman Award summaries (available in RBI’s Annual Reports on Ombudsman Scheme) confirm the zero-liability principle: where banks fail to maintain adequate cybersecurity or fraud detection systems, they are held liable for 100% of customer loss from unauthorised transactions.(RBI Annual Report on Ombudsman)
5.2 Consumer Forum Cases on Bank Account Fraud
State Consumer Commissions (Maharashtra, Delhi, Bengaluru) have consistently held that when a customer’s account is drained through fraud and the bank fails to proactively detect or prevent the fraud despite having the technical capability to do so, it constitutes deficiency in service. Full compensation has been awarded.(Verify at NCDRC)
5.3 SIM Swap Fraud Cases
Courts and consumer forums have held that banks are responsible for fraud losses arising from SIM swap attacks where the bank failed to implement two-factor authentication properly. The telecom operator also shares liability in such cases.
⚠ Always verify specific case citations at indiankanoon.org or ncdrc.nic.in before formal use.
6. Practical Examples
Example 1: Phishing Attack (Customer Shared OTP)
Rajesh received a call from someone claiming to be from his bank and was convinced to share his OTP. Rs. 70,000 was transferred from his account. Since Rajesh shared the OTP (his negligence), this is Scenario 3 — full liability on the customer. However, Rajesh reported within 3 hours. The bank, applying its internal fraud detection, was able to partially recover Rs. 30,000. Lesson: never share OTP, ever.
Example 2: Bank Data Breach (No Customer Fault)
Priya’s bank’s servers were hacked. Rs. 1,50,000 was fraudulently transferred from her account without her knowledge or any OTP/PIN sharing on her part. This is Scenario 1 — zero liability for Priya. She reported within 2 days. The bank provisionally credited Rs. 1,50,000 within 10 working days. Priya got full refund after investigation.
Example 3: SIM Swap Fraud
Mohan’s SIM was swapped by a fraudster who used fake documents. Rs. 85,000 was drained via UPI. Mohan reported to both his telecom operator and his bank within 1 working day (within 3 days). Since the fault lay with the telecom operator and the bank’s failure to detect the fraudulent SIM swap — and Mohan had no fault — zero liability applies. Bank refunded full Rs. 85,000.
7. How to Protect Yourself From Unauthorised Transactions
- Never share OTP, PIN, card number, CVV, or net banking password with anyone — ever.
- Register for instant transaction SMS/email alerts on all your bank accounts.
- Check your bank statements regularly — at least weekly.
- Enable UPI transaction limits and daily withdrawal limits on your account.
- Use strong, unique passwords for net banking and change them every 3 months.
- If you lose your phone, immediately call your telecom operator to block the SIM and call your bank to block mobile banking.
- Be wary of all incoming calls claiming to be from your bank asking for sensitive information.
8. Key Takeaways
- Zero liability applies when the fraud is entirely the bank’s or a third party’s fault — report within 3 days.
- Shared fault results in limited liability (max Rs. 5,000 to Rs. 25,000) if reported within 4–7 days.
- If you shared OTP/PIN yourself, you bear full liability.
- Banks must provisionally credit you within 10 working days of your complaint.
- Report unauthorised transactions immediately — every hour matters.
- Banking Ombudsman at cms.rbi.org.in handles these disputes for free.
- For cyber fraud, also file at cybercrime.gov.in or call 1930.
9. Conclusion
Unauthorised banking transaction liability in India is a carefully constructed legal framework that protects genuinely victimized customers while distinguishing those who were negligent. The key rule is simple: act fast, report immediately, and never share sensitive banking information with anyone.
The law gives you powerful protection. A bank that fails to prevent fraud or fails to follow the RBI’s zero-liability rules can be held accountable through the Banking Ombudsman, Consumer Courts, and civil/criminal courts. Your money has legal protection — know your rights and use them.
10. FAQs
Q1. What is unauthorised banking transaction liability in India?
It is the legal framework, primarily under the RBI’s 2017 circular, that determines who bears the financial loss — the customer or the bank — when an unauthorised transaction occurs in a bank account.
Q2. If my bank account is hacked and money is stolen, do I have to pay?
Not if you were not negligent. Under the RBI’s 2017 circular, if the fraud is due to the bank’s or a third party’s fault and you had no hand in it, your liability is zero — provided you report within 3 working days.
Q3. What if I shared my OTP with a fraudster — am I liable?
If you voluntarily shared your OTP, PIN, or password, the bank’s liability is generally excluded and the loss falls on you. However, always report immediately — the bank may be able to reverse some transactions.
Q4. Within how many days must I report an unauthorised transaction?
Report within 3 working days for zero liability (when fault is with bank or third party). Reporting between 4–7 working days may result in limited liability. Reporting after 7 days may increase your liability.
Q5. What is the bank’s obligation after I report an unauthorised transaction?
The bank must provisionally credit the disputed amount to your account within 10 working days and complete its investigation within 90 days.
Q6. Where do I report unauthorised banking transactions?
Immediately call your bank. Also file at cms.rbi.org.in (Banking Ombudsman) if the bank fails to act. For cyber fraud, file at cybercrime.gov.in or call 1930.
Q7. Can I file a criminal complaint for an unauthorised banking transaction?
Yes. If a fraudster stole your banking credentials or conducted an unauthorised transaction, you can file an FIR under Section 66C of the IT Act, 2000 (identity theft) and Sections 316/318 of the Bharatiya Nyaya Sanhita, 2023 (criminal breach of trust/cheating).
11. Legal References
- RBI Circular — Customer Liability in Unauthorised Electronic Banking Transactions, 2017
- RBI Integrated Ombudsman Scheme, 2021
- IT Act, 2000 — India Code
- Consumer Protection Act, 2019
- RBI Annual Report on Ombudsman
- National Cybercrime Reporting Portal
- RBI CMS Portal
- NCDRC Portal
At The Law School Hub, we simplify case laws, legal acts, and legal concepts for law students and legal readers.
Want to read more useful legal blogs? Visit The Law School Hub