Customer liability is not decided by a call-centre phrase such as ‘OTP was used.’ The cause, reporting time and evidence must be examined.
RBI’s framework provides zero liability in specified bank-deficiency and timely third-party-breach situations.
Where loss is due to customer negligence, such as sharing payment credentials, the customer generally bears the loss until reporting; loss after reporting is borne by the bank.
Banks must provide round-the-clock reporting channels and acknowledge the complaint.
The framework requires a shadow reversal within ten working days of notification and resolution within ninety days, subject to the circular.
What the customer or business should understand
- RBI’s framework provides zero liability in specified bank-deficiency and timely third-party-breach situations.
- Where loss is due to customer negligence, such as sharing payment credentials, the customer generally bears the loss until reporting; loss after reporting is borne by the bank.
- Banks must provide round-the-clock reporting channels and acknowledge the complaint.
- The framework requires a shadow reversal within ten working days of notification and resolution within ninety days, subject to the circular.
- The burden of proving customer liability lies on the bank.
The five-point review
| Check | What to examine |
|---|---|
| Transaction | Merchant, channel, amount, date and authentication. |
| Cause | Bank deficiency, third-party breach or customer negligence. |
| Notice | When the customer received alert, noticed and reported. |
| Containment | Card block, token removal and credential reset. |
| Decision | Provisional credit, investigation evidence and final liability. |
Practical example
A cardholder reports an overseas online purchase two hours after the SMS alert. The bank rejects it solely because an OTP appears in its system. The bank should still examine device, merchant, authentication and customer evidence under the RBI framework.
How to apply the framework
Ask the issuer to identify the precise liability category and evidence relied upon. Preserve call recordings or written responses where available.
Check whether card tokens, add-on cards, recurring mandates or compromised email accounts remain active after the card is blocked.
Dispute workflow
Classify the problem before choosing the remedy
Identify the regulated entity, transaction or loan account, date, amount, contractual document and exact failure. Review transaction, cause and notice together. A failed transaction, authorised mistake, unauthorised fraud, merchant dispute, credit-report error and lawful account freeze require different remedies.
Create one written chronology
Record the event, alert, discovery, first report, complaint number, response and financial impact in date order. Attach only the documents that prove each step. Phone calls can stop urgent harm, but a written acknowledgement creates the escalation record.
Escalate to the correct authority
Start with the bank, card issuer, lender, credit institution, app or other regulated entity responsible for the service. Use cybercrime or law-enforcement channels for suspected fraud. Use RBI CMS only after the regulated entity process satisfies the Scheme’s timing or rejection condition and the issue is within Ombudsman scope.
Implementation checkpoint
Before treating the case as closed, verify the actual bank statement, loan ledger, credit report, account status or merchant refund rather than relying only on a ticket message. Record who confirmed the financial outcome, the date, remaining open amount and the next escalation deadline. This final check prevents a complaint from being marked resolved while the money, lien, overdue status or credit record remains unchanged.
Action checklist
- Block the card and tokens.
- Report through the issuer’s official channel.
- Record the complaint time.
- Preserve SMS, statement and device evidence.
- Request provisional-credit status.
- Escalate an unsupported rejection through the grievance route.
Evidence to keep
- Card statement and alert
- Complaint acknowledgement
- Merchant and authentication data requested
- Device/login evidence
- Issuer’s written liability decision
Warning signs
- Waiting for statement generation
- Calling only the merchant
- Assuming OTP proves negligence
- No written complaint
- Destroying the device evidence
Finin2min takeaway
Banking disputes are resolved through classification, speed, written evidence and the correct escalation route. No legitimate bank, regulator or recovery process requires disclosure of an OTP, UPI PIN or remote-control access.
Frequently asked questions
Is customer liability always zero?
No.
Who proves customer liability?
The bank under the RBI circular.
When should the bank shadow-reverse?
Within ten working days of notification under the framework.
How long is the resolution period?
The circular provides up to ninety days.