Core Demand of the Question
- RBI’s regulatory framework on fraudulent electronic banking transactions (EBTs)
- Gaps in adequacy and Structural limitations
- Way Forward
|
Answer
Introduction
Cyber frauds in India have increasingly shifted from technical breaches to social engineering-based manipulation, exploiting human trust, coercion, and digital illiteracy. RBI’s revised framework on fraudulent electronic banking transactions (2026) seeks to address this shift, but its adequacy remains contested given rising sophistication of fraud ecosystems.
UPSC Online Courses
Strengths of RBI’s regulatory framework (protective architecture)
- Expanded definition of fraud : It now includes coercion-based transactions. Covers OTP theft, “digital arrest” scams, and coerced approvals.
Eg: Fraudsters impersonating law enforcement agencies forcing UPI transfers under “digital arrest” narratives
- Partial liability shift towards banks and RBI-backed compensation : Up to 85% reimbursement (capped at ₹25,000) for eligible victims under ₹50,000 losses.
Eg: Small-ticket UPI fraud victims can now recover partial losses without litigation burden.
- Strengthened reporting and grievance timelines : Mandatory reporting within 5 days via cybercrime helpline (1930).
Eg: Faster reporting enables freezing of suspicious UPI-linked accounts.
- Extension of liability to negligence and third-party breaches : Banks held accountable for failure in alerts or verification systems.
Eg: Failure to update registered mobile/email leading to missed fraud alerts is now classified under shared liability.
Gaps in adequacy for protecting vulnerable customers
- Over-reliance on customer vigilance in a high-deception environment : Framework still penalises “negligence” such as ignoring warnings or delayed reporting.
Eg: Elderly users repeatedly targeted via fake KYC or “police call” scams may fail compliance timelines.
- Exclusion of high-value frauds from full protection : Losses above ₹50,000 not fully covered under compensation framework.
Eg: Large-scale phishing or account takeover cases remain inadequately addressed.
- High evidentiary and procedural burden on victims : Strict reporting window and documentation requirements disadvantage digitally illiterate users.
Eg: Rural users lacking cyber literacy face delays in reporting via the 1930 system.
- Institutional gap in proactive fraud prevention : Framework is largely ex-post compensation-driven rather than ex-ante prevention-focused.
Eg: Real-time AI-based transaction blocking is not uniformly mandated across banks
Structural limitations in addressing human-centric cyber frauds
- Social engineering outpaces regulatory updates : Fraudsters adapt faster than compliance frameworks.
Eg: Deepfake voice scams mimicking bank officials or relatives
- Uneven digital literacy across customer base : Vulnerable groups (elderly, rural users) disproportionately affected.
Eg: OTP-sharing scams continue despite repeated RBI advisories
- Fragmented institutional coordination : Limited integration between banks, telecoms, and cybercrime units.
Eg: Delay in freezing mule accounts reduces recovery rates
Way Forward
- Shift from compensation-based to prevention-centric framework : Mandate real-time fraud detection systems using AI/ML across all banks and payment gateways
- Strengthen “liability without burden” for vulnerable users : Introduce differentiated protection for elderly, rural, and low-literacy users with relaxed compliance conditions
Eg: Automatic reimbursement for first-time digital fraud victims below a defined threshold without strict reporting deadlines
- Integrated cyber fraud command architecture : Establish unified coordination between RBI, CERT-In, banks, telecom operators, and cybercrime cells
- Mandatory digital literacy + behavioural nudges : Large-scale awareness campaigns and in-app warning redesigns to reduce cognitive manipulation
Eg: UPI apps using “forced pause screens” before high-risk transactions involving unknown beneficiaries
- Stronger accountability of intermediaries : Penal framework for banks/fintechs failing to implement fraud alerts or KYC updates
Click to Know UPSC Coaching Centres in India
Conclusion
RBI’s framework marks a progressive shift from system-security to human-risk recognition, but remains primarily reactive. A more robust approach requires real-time fraud prevention systems, stronger cross-institutional coordination, and differentiated protection for vulnerable users, ensuring financial inclusion does not translate into digital exploitation.