Income Tax

Credit-Card Fraud: RBI Customer-Liability Rules in Plain English

Credit-Card Fraud: RBI Customer-Liability Rules in Plain English
CA Nikhil Gupta·June 2026·3 min readIncome Tax Practical Guides (2025-26)

An unauthorised card transaction should be reported immediately. RBI’s framework links customer liability to the cause of the breach and reporting time; it is not a universal promise that every disputed card payment will be refunded.

Finin2min takeaway: Act from primary records, use the official channel and keep a dated evidence trail. A portal message, screenshot, dashboard or verbal assurance is not a substitute for the governing rule and underlying documents.

Current position in plain English

Bank deficiency can create zero liabilityWhere the unauthorised transaction arises from contributory fraud, negligence or deficiency by the bank, the customer has zero liability regardless of reporting time.
Third-party breach has a three-working-day windowWhere the fault lies neither with the bank nor customer, reporting within three working days of the bank’s communication can result in zero liability.
Four to seven working days means limited liabilityThe customer’s liability is capped by the transaction value or the applicable board-approved limit, whichever is lower.
Customer negligence changes the ruleIf the customer shared credentials, liability generally remains until the bank is notified; subsequent loss should be borne by the bank.
The bank must act after notificationThe framework provides for shadow credit within 10 working days and resolution within 90 days, subject to the applicable circular and facts.

Decision table

Cause/reportingGeneral RBI frameworkCustomer action
Bank deficiencyZero liabilityReport and preserve evidence
Third-party breach, within 3 working daysZero liabilityReport immediately
Third-party breach, 4–7 working daysLimited liabilityCheck card type and bank policy
Beyond 7 working daysBank board-approved policyEscalate with evidence
Customer shared credentialsLoss until reporting may fall on customerBlock card and report immediately

How to apply the rule

Customer-liability rules depend on facts. Record the first alert, reporting time, authentication method and whether any credential was shared. These details determine which part of the framework applies.

Continue to comply with undisputed obligations while the complaint is pending. For a card or loan, seek written instructions about the disputed amount rather than ignoring the entire account.

Escalation should identify the service deficiency and the relief requested. A timeline with acknowledgements is more effective than repeated calls.

For credit card fraud liability RBI, first identify the legal or contractual relationship, then separate the amount, event and deadline. Use one chronology across the portal, institution and supporting records. This prevents a correct fact from being submitted under the wrong year, account, policy clause or complaint route.

Practical example

A ₹48,000 online card transaction occurs without OTP or customer participation. The customer reports it within hours. The bank should register an unauthorised-transaction complaint and assess liability under RBI rules; it should not reject the case solely because the merchant says the transaction was approved.

Action checklist

Evidence and document checklist

Common mistakes

Red flags

  • SIM or email compromise
  • Multiple low-value test transactions
  • Issuer refuses to block tokenised cards
  • A transaction marked card-present while card is held by customer
  • Collections activity on a properly disputed amount
  • No written complaint acknowledgement

Escalation route

Use the issuer’s grievance hierarchy first. If no satisfactory reply is received within 30 days, or the reply is unsatisfactory, file a maintainable complaint on RBI CMS within the scheme’s limitation period.

When escalating, include the original complaint, acknowledgement, concise chronology, disputed amount, rule or clause relied upon and the exact relief requested. Do not send passwords, PINs, OTPs or unrelated identity documents.

Frequently Asked Questions

What is the three-day rule?
For a qualifying third-party breach, reporting within three working days of the bank’s communication can result in zero liability.
What if I shared the OTP?
Customer negligence can shift liability until the transaction is reported. Still report immediately and provide the full facts.
When should shadow credit happen?
The RBI framework provides for credit within 10 working days after notification, subject to the applicable facts and process.
How long can resolution take?
The framework refers to resolution within 90 days.
Can I go directly to RBI?
Normally complain to the issuer first; approach RBI after 30 days without a satisfactory resolution or after an unsatisfactory reply.

Source and review trail

Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.

Primary category
Income Tax
Official starting point
www.incometax.gov.in
Editorial review date
2026-07-19
Content status
Finin2min explanation; official source controls where facts, law, rates, forms or procedures can change.

Page source links

Home / Insights / Markets & Economy Insights
More on Markets & Economy Insights
Browse all Markets & Economy Insights articles →
Related Articles
SIM-Swap Fraud: Warning Signs, Immediate Steps and Bank Protection RBI Ombudsman: When and How to Escalate a Financial Complaint Cybercrime Evidence Checklist: What to Save Before It Disappears Health Insurance Claim Rejected: Reasons, Appeal Steps and Evidence Cashless vs Reimbursement Health Claims: Process, Timelines and Risks