Skip to main content

Clari5

RBI’s New Fraud Liability Rules Aren’t About Fraud. They’re About Evidence

RBI’s New Fraud Liability Rules Aren’t About Fraud. They’re About Evidence.

When the Reserve Bank of India released the Third Amendment Directions on Responsible Business Conduct in June 2026, much of the discussion focused on one question: Who pays when a customer loses money through digital fraud?

It’s an understandable reaction. The new framework expands the definition of fraudulent electronic banking transactions, introduces clearer tests around customer and bank negligence, and standardises resolution timelines.

But that’s only the visible part of the change. The more significant shift is operational.

For the first time, every disputed digital transaction effectively becomes an evidentiary exercise. Banks won’t simply be expected to investigate fraud. They’ll be expected to demonstrate within defined regulatory timelines why a particular liability decision was reached and support that conclusion with an auditable chain of evidence.

That distinction may appear subtle. In practice, it changes almost everything.

A New Standard for Liability

The earlier framework largely revolved around unauthorised electronic banking transactions. The revised directions recognise that digital fraud has evolved.

Today’s losses often arise through social engineering, authorised push payment scams, coercion, compromised credentials, or failures involving third-party participants within the wider payments ecosystem.

The regulation acknowledges this reality by broadening the situations that fall within its scope. It also introduces greater clarity around liability.

Where the loss results from factors beyond the direct control of both the customer and the bank, customers who report the incident within five calendar days bear no liability.

Where customer negligence contributes to the fraud — for example, by sharing credentials or authentication details — the customer remains liable only until the incident is reported. Any subsequent loss shifts to the bank.

Domestic cases are expected to be resolved within 45 days, while cross-border transactions have a 60-day timeline. Viewed individually, none of these provisions appears revolutionary.

Taken together, however, they create a new operational expectation. Banks must now explain — not simply decide.

The Real Challenge Begins After the Fraud

Fraud detection has traditionally been measured by prevention:

  • Did the system identify suspicious activity?
  • Was the transaction blocked?
  • Was financial loss avoided?

Those questions remain important. They are no longer sufficient.

Every disputed transaction now requires a second capability that many organisations have never built with the same level of maturity:

  • Can the institution reconstruct exactly what happened?
  • Can investigators show which risk indicators were present?
  • Can they demonstrate which controls were triggered, what actions followed, and why the final liability determination was appropriate?
  • Can they produce that evidence quickly enough to satisfy regulators, auditors, ombudsmen and customers alike?

These questions shift fraud management beyond detection. It becomes a discipline centred equally on investigation, documentation and defensible decision-making.

Why Scale Changes Everything

This challenge cannot be viewed in isolation. India’s digital payments ecosystem operates at extraordinary scale.

UPI alone processed more than 228 billion transactions during the past year. Fraud remains only a tiny proportion of overall transaction volumes. Yet even a fraction of one percent translates into thousands of disputes that may require investigation, documentation and formal liability assessment. Every one of those investigations now runs against a regulatory clock.

Unlike transaction monitoring systems, regulatory timelines don’t scale automatically. If investigations depend on manual evidence gathering across disconnected systems, volume becomes the enemy.

Forty-five days disappears surprisingly quickly when investigators spend much of that time collecting information that already exists elsewhere.

The Hidden Risk Isn’t Fraud. It’s Fragmentation.

Many banks already operate sophisticated fraud detection platforms. Many also operate capable investigation teams.

The problem is that these capabilities often exist independently.

Transaction monitoring, fraud analytics, customer complaints, investigation workflows and case management frequently sit across different applications owned by different teams. That separation may have been manageable when disputes were relatively infrequent. It becomes a liability when every investigation requires a regulator-defensible explanation.

Investigators shouldn’t have to reconstruct history. Evidence should already exist. The strongest operating models won’t create documentation after a complaint arrives — they’ll generate it automatically as decisions are made.

The difference may appear procedural. In reality, it’s the difference between proving a conclusion and attempting to justify one.

This Is Now an Operational Capability

It is tempting to interpret these directions as another compliance exercise. That would be a mistake. Compliance teams don’t investigate fraud. Operations teams do. Fraud analysts do. Case managers do. Customer service teams do. Technology platforms support all of them.

Success therefore depends less on policy documents than on whether these functions operate as one connected system. Institutions preparing for January 2027 should be asking practical questions:

  • Can we explain why a transaction was or wasn’t flagged?
  • Can we demonstrate exactly when customer behaviour changed our liability position?
  • Can investigators access every relevant decision without searching multiple systems?
  • Can supervisors review an entire investigation from beginning to end without requesting additional evidence?

Most importantly: could we answer all of those questions tomorrow? Or would we begin assembling the evidence only after receiving the complaint?

The answer reveals far more about operational readiness than any policy manual.

Evidence Becomes the Competitive Advantage

Much has been written about artificial intelligence transforming fraud detection. Equally important is explainability.

An accurate decision that cannot be explained creates operational risk. A well-documented decision creates confidence. Customers trust outcomes they understand. Regulators trust institutions that can demonstrate consistency. Senior management gains better visibility into operational performance.

Evidence therefore becomes more than a compliance requirement. It becomes a trust asset.

Looking Ahead

The Third Amendment Directions do not require banks to eliminate every fraudulent transaction. No regulation can. What they require is something different.

Banks must consistently determine liability, complete investigations within prescribed timelines, and demonstrate — through evidence rather than opinion — how each conclusion was reached.

That represents a meaningful evolution in how digital fraud will be managed.

The institutions that begin strengthening those capabilities now will be better positioned not only for regulatory compliance but also for faster investigations, more consistent decisions and stronger customer confidence.

Ultimately, the most important question is no longer whether a fraud occurred. It is whether the bank can prove, clearly and consistently, how it reached its conclusion. That is the standard the new framework establishes. And that is where the industry’s attention should now be focused.

How Clari5 Helps Accelerate the Journey

Building a fully integrated anti-fraud capability internally can take years. Many institutions face resource constraints, integration complexity, and aggressive timelines.

Clari5 helps banks accelerate that journey through a unified enterprise fraud management platform supporting real-time fraud detection, cross-channel monitoring, watchlist management, centralized investigations, behavioral intelligence, and fraud-AML collaboration. Typical deployment for a standard-scope implementation runs four to six months, though timelines vary based on integration complexity and data readiness.

Rather than treating detection, investigations, and intelligence sharing as separate initiatives, Clari5 connects them into a single operating environment. The result is faster detection, better analyst productivity, stronger customer protection, and a more scalable fraud prevention capability.

How Prepared Is Your Bank?

We have developed a practical readiness assessment based on the five architectural decisions in this guide. In a 20-minute working session, we will help you identify likely implementation gaps, discuss proven operating models, and benchmark your approach against regional practices. Whether you choose Clari5 or not, you will leave with a clearer roadmap for building a resilient anti-fraud capability.

Like this article? Share it!

LinkedIn
Twitter
Facebook
WhatsApp
Email

About the author