An unauthorised card transaction should be reported immediately. RBI’s framework links customer liability to the cause of the breach and reporting time; it is not a universal promise that every disputed card payment will be refunded.
Finin2min takeaway: Act from primary records, use the official channel and keep a dated evidence trail. A portal message, screenshot, dashboard or verbal assurance is not a substitute for the governing rule and underlying documents.
Current position in plain English
Bank deficiency can create zero liabilityWhere the unauthorised transaction arises from contributory fraud, negligence or deficiency by the bank, the customer has zero liability regardless of reporting time.
Third-party breach has a three-working-day windowWhere the fault lies neither with the bank nor customer, reporting within three working days of the bank’s communication can result in zero liability.
Four to seven working days means limited liabilityThe customer’s liability is capped by the transaction value or the applicable board-approved limit, whichever is lower.
Customer negligence changes the ruleIf the customer shared credentials, liability generally remains until the bank is notified; subsequent loss should be borne by the bank.
The bank must act after notificationThe framework provides for shadow credit within 10 working days and resolution within 90 days, subject to the applicable circular and facts.
Decision table
| Cause/reporting | General RBI framework | Customer action |
|---|
| Bank deficiency | Zero liability | Report and preserve evidence |
| Third-party breach, within 3 working days | Zero liability | Report immediately |
| Third-party breach, 4–7 working days | Limited liability | Check card type and bank policy |
| Beyond 7 working days | Bank board-approved policy | Escalate with evidence |
| Customer shared credentials | Loss until reporting may fall on customer | Block card and report immediately |
How to apply the rule
Customer-liability rules depend on facts. Record the first alert, reporting time, authentication method and whether any credential was shared. These details determine which part of the framework applies.
Continue to comply with undisputed obligations while the complaint is pending. For a card or loan, seek written instructions about the disputed amount rather than ignoring the entire account.
Escalation should identify the service deficiency and the relief requested. A timeline with acknowledgements is more effective than repeated calls.
For credit card fraud liability RBI, first identify the legal or contractual relationship, then separate the amount, event and deadline. Use one chronology across the portal, institution and supporting records. This prevents a correct fact from being submitted under the wrong year, account, policy clause or complaint route.
Practical example
A ₹48,000 online card transaction occurs without OTP or customer participation. The customer reports it within hours. The bank should register an unauthorised-transaction complaint and assess liability under RBI rules; it should not reject the case solely because the merchant says the transaction was approved.
Action checklist
- Block the card and connected token/wallet.
- Report the unauthorised transaction to the issuer immediately.
- Obtain a complaint number and reporting timestamp.
- Submit the transaction dispute form and evidence.
- Check email, device and SIM for compromise.
- Pay the undisputed bill amount and follow issuer instructions for the disputed amount.
- Escalate non-resolution through the issuer and RBI Ombudsman.
Evidence and document checklist
- Card statement and transaction details
- SMS/email alert and reporting time
- Issuer complaint and dispute form
- Device, travel and location evidence where relevant
- Merchant communication
- Proof of card possession
- RBI CMS complaint if escalated
Common mistakes
- Waiting for the monthly statement
- Calling the merchant but not the issuer
- Sharing OTP/CVV in a follow-up 'verification' call
- Assuming chargeback and RBI liability are identical
- Ignoring the undisputed card bill
- Filing a false fraud complaint for a forgotten subscription
Red flags
- SIM or email compromise
- Multiple low-value test transactions
- Issuer refuses to block tokenised cards
- A transaction marked card-present while card is held by customer
- Collections activity on a properly disputed amount
- No written complaint acknowledgement
Escalation route
Use the issuer’s grievance hierarchy first. If no satisfactory reply is received within 30 days, or the reply is unsatisfactory, file a maintainable complaint on RBI CMS within the scheme’s limitation period.
When escalating, include the original complaint, acknowledgement, concise chronology, disputed amount, rule or clause relied upon and the exact relief requested. Do not send passwords, PINs, OTPs or unrelated identity documents.
Frequently Asked Questions
What is the three-day rule? ▼
For a qualifying third-party breach, reporting within three working days of the bank’s communication can result in zero liability.
What if I shared the OTP? ▼
Customer negligence can shift liability until the transaction is reported. Still report immediately and provide the full facts.
When should shadow credit happen? ▼
The RBI framework provides for credit within 10 working days after notification, subject to the applicable facts and process.
How long can resolution take? ▼
The framework refers to resolution within 90 days.
Can I go directly to RBI? ▼
Normally complain to the issuer first; approach RBI after 30 days without a satisfactory resolution or after an unsatisfactory reply.