Home » Money & Consumer » Unauthorized Bank Transaction: RBI Refund and Liability Rules

Unauthorized Bank Transaction: RBI Refund and Liability Rules

Indian bank customer checking a phone alert against a transaction statement

Published:

· Updated:

Short answer: If money leaves your bank account through an electronic transaction you did not authorize, report it to the bank immediately through an official channel. Under the Reserve Bank of India customer-protection framework, your liability can be zero or limited depending on why the transaction occurred and how quickly you report it. The bank should provide a shadow reversal within 10 working days after your notification and resolve the complaint and liability within 90 days.

Author: Ajit Naskar | Draft date: 26 September 2026 | Updated: 26 September 2026 | Last verified: 26 September 2026

Unauthorized bank transaction refund: what to do first

Speed matters. As soon as you notice an unfamiliar card payment, net-banking transfer, UPI payment, wallet load, ATM withdrawal or other electronic debit, take a screenshot or download the account statement and note the date, amount, reference number and merchant or beneficiary shown. Do not wait to investigate the recipient before telling the bank. Reporting starts the bank’s liability process and can prevent further loss.

  1. Use the bank’s official app, website, helpline, branch or fraud-reporting address. Avoid phone numbers found in social posts or unsolicited messages.
  2. Block or temporarily disable the affected card, UPI handle, net-banking access or other channel if the bank offers that control.
  3. Change passwords from a trusted device. Remove unknown devices and review transaction limits and beneficiaries.
  4. Ask for a complaint or service-request number and preserve the acknowledgement, SMS and email.
  5. If fraud is suspected, also call the national cybercrime helpline 1930 promptly and submit details at cybercrime.gov.in. This supports fund tracing; it does not replace the complaint to your bank.

If someone is pressuring you on a video call, claiming to be police, RBI, CBI, customs or a court, stop the call and review our guide to the digital arrest scam in India. Government agencies do not conduct a legitimate “digital arrest” that requires you to transfer money for verification.

How RBI decides customer liability

The RBI circular on limiting customer liability in unauthorised electronic banking transactions separates cases by cause and reporting time. It applies to eligible electronic banking transactions such as remote payments and face-to-face electronic transactions. The exact result depends on evidence, account type, the bank’s policy and whether the customer shared credentials or otherwise acted negligently.

Zero liability when the bank is at fault

You have zero liability when the unauthorized transaction results from contributory fraud, negligence or deficiency on the part of the bank. This protection applies regardless of how quickly you report the transaction. Still, report it immediately so the bank can secure the account and begin the formal process.

Zero liability for a third-party breach reported within three working days

When the problem lies neither with the bank nor with you but elsewhere in the system, and you notify the bank within three working days of receiving the bank’s communication about the transaction, the RBI framework provides zero liability. The three-day period is counted in working days, not merely 72 clock hours. Do not assume weekends and bank holidays are treated the same by every bank; notify the bank at once.

Limited liability when reported in four to seven working days

For a third-party breach reported between four and seven working days after the bank’s communication, liability is limited to the transaction value or the maximum amount prescribed for the relevant account category, whichever is lower. The circular lists different caps for basic savings accounts, other savings accounts, prepaid instruments, current or cash-credit accounts of qualifying entities, and certain credit cards. Your bank should apply the correct category rather than a single cap to every customer.

Bank policy applies after seven working days

When notice arrives after seven working days, customer liability is determined under the bank’s board-approved policy. That makes delay risky. The bank must make its policy public, transparent and available to customers, but the outcome can be less favourable than a prompt report.

When the customer shared credentials or acted negligently

If the loss is attributed to the customer’s negligence—such as voluntarily sharing a password, PIN or one-time password—the customer bears the loss until the unauthorized transaction is reported to the bank. Any loss occurring after the report should be borne by the bank. A fraudster’s manipulation can make facts complicated, so provide an accurate timeline rather than guessing whether you were “at fault.” Do not delete chats, call logs or messages that may help establish what happened.

RBI refund timeline after you notify the bank

The bank should credit a shadow reversal of the amount involved within 10 working days from the date of your notification. The credit should be value-dated to the date of the unauthorized transaction, so the complaint process should not leave you worse off merely because the investigation takes time. The bank should not wait for an insurance claim to be settled before providing the prescribed credit.

The complaint must be resolved and customer liability established within the period set by the bank’s approved policy, but not later than 90 days from receipt of the complaint. If the bank cannot resolve the complaint or determine liability within 90 days, the compensation specified by the RBI framework should be paid. In debit-card or bank-account cases, the customer should not lose interest because of the unauthorized debit. In credit-card cases, the customer should not bear an additional interest burden on the disputed amount.

A shadow reversal is a provisional credit while the bank investigates; it is not automatically the final decision. Keep the acknowledgement and monitor the account until you receive a written resolution. If a provisional credit is later reversed, ask for the reason and the evidence supporting the liability decision.

How to report the transaction and build a clear record

In your complaint, state plainly that you dispute an unauthorized electronic transaction. Include the account’s last four digits, transaction reference, amount, date and time, when the bank alert reached you, when you noticed it and when you reported it. Never send a full PIN, password, CVV or OTP. Attach only the necessary statement or alert and redact unrelated transactions where appropriate.

Ask the bank to confirm four things in writing: the complaint number and report time; the immediate security action taken; whether a shadow reversal will be provided within the applicable timeline; and the date by which the bank expects a final liability decision. Record each follow-up with its date and channel.

If the bank rejects the complaint, delays beyond its stated timeline, or gives only a generic answer, use its grievance escalation path and approach the principal nodal officer. If the bank does not resolve the complaint satisfactorily within 30 days, or rejects it earlier, you may consider the RBI Integrated Ombudsman route. Follow our step-by-step RBI Ombudsman complaint guide. The Ombudsman is an escalation channel, not a substitute for first filing a complaint with the regulated entity.

For a failed UPI transaction that you did authorize, the issue may be a technical failure rather than unauthorized fraud. Use the separate UPI failed transaction refund and complaint guide so you cite the correct dispute type and timeline.

What does not change

  • The RBI framework does not make every disputed payment an automatic final refund. The bank may investigate authorization, device and authentication records.
  • Reporting to police or the cybercrime portal does not replace notice to the bank.
  • Blocking a card does not automatically block net banking, UPI or other linked channels.
  • A merchant dispute over quality or non-delivery is different from a transaction you never authorized.
  • No bank employee should ask you to share an OTP, PIN, password or screen-control access to process a refund.

Examples of how the reporting window works

Example 1: quick report after a system breach

Riya receives an SMS for a card-not-present purchase she did not make. She reports it through her bank’s official app the same evening. She did not share her credentials, and the breach is found elsewhere in the system. Because she notified the bank within three working days, the framework supports zero customer liability.

Example 2: customer reveals an OTP

Arun is tricked by a caller into sharing an OTP. Two unauthorized transfers occur before he contacts the bank. Under the framework, losses before his report may be assigned to him if the bank establishes customer negligence, while a transaction after his recorded report should be borne by the bank. This is why the exact report time is important.

Example 3: delayed discovery

Meena ignores transaction alerts and reports a third-party breach more than seven working days later. Her liability is decided under the bank’s approved policy. The example does not predict the result; it shows why customers should keep alerts active and review accounts regularly.

Action checklist

  • Report through an official bank channel immediately.
  • Secure every affected payment channel and change compromised credentials.
  • Save the complaint number, alerts, statements and timeline.
  • Ask about the 10-working-day shadow reversal and final resolution date.
  • Escalate within the bank, then use the RBI Ombudsman route when eligible.
  • Never pay a “release,” “verification” or “refund processing” fee to an unknown caller.

Frequently asked questions

Is the three-working-day rule counted from the transaction date?

The RBI wording ties the window to receipt of the bank’s communication about the unauthorized transaction. Because alerts and facts vary, report immediately rather than calculating a last possible day.

Does zero liability mean the money appears instantly?

No. The framework requires a shadow reversal within 10 working days of notification in covered cases, while final complaint resolution and liability determination can take longer, up to the prescribed maximum.

Can the bank ask for a police complaint?

A bank may seek information required for investigation, and a cybercrime or police report can be useful. However, the bank should provide customers 24/7 reporting channels and cannot treat silence as notice. Ask for any document requirement in writing.

What if I approved a payment because a scammer threatened me?

Tell the bank exactly what happened and report the coercion to cybercrime authorities. Whether the transaction is treated as unauthorized under the banking framework can depend on the evidence and authentication record. Do not describe it inaccurately as a technical failure.

Where can I read the official rule?

Read the RBI notification Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions. Your bank’s current board-approved customer-liability policy also matters.

Conclusion

For an unauthorized bank transaction refund, the safest approach is simple: notify the bank immediately, secure the account and preserve evidence. RBI rules can provide zero or limited liability, a shadow reversal within 10 working days and a resolution framework of up to 90 days, but reporting time and the cause of the loss are central. Use official channels, follow up in writing and escalate methodically if the bank does not apply its policy.

Financial and independence disclaimer: This article explains a general regulatory framework and is not legal or financial advice. Bank findings depend on the facts, account type and current policy. Check the RBI notification and your bank’s official policy. CheckMatter is independent and is not affiliated with RBI or any bank.

Verification metadata:
_cm_verified_source_url: https://www.rbi.org.in/commonman/English/scripts/Notification.aspx?Id=2623
_cm_source_authority: Reserve Bank of India
_cm_effective_date: 2017-07-06

Correction history: 26 September 2026 — First draft created from the RBI customer-liability notification; no correction recorded.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *