New Delhi. Bank customers could get significant relief in cases involving cyber fraud and money mule accounts. The Reserve Bank of India has proposed that banks should not freeze an entire account in such cases, but temporarily block only the amount suspected to be linked to cyber fraud or a disputed transaction. If implemented, the proposed framework would allow the rest of the account balance and normal banking activities to continue.
Under the RBI proposal, if an unusual transaction of ₹1,000 or more indicates that an account may be linked to money mule activity or cyber fraud, the bank may temporarily block the amount concerned. Money mule accounts are used to receive and transfer proceeds of fraud or other criminal activities. The proposed framework aims to secure suspicious funds while protecting customers whose legitimate banking activities may otherwise be disrupted when their entire accounts are frozen.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
AI to identify suspicious transactions
Under the proposed framework, banks will be required to use artificial intelligence-based transaction monitoring systems to identify suspicious transactions. These systems will analyse a customer’s normal transaction patterns and detect sudden or unusual activity. Transactions that are significantly higher than a customer’s declared income or profile will also be monitored.
Accounts or transactions linked to previously identified cyber fraud networks will also come under scrutiny. This approach would allow banks to assess transactions based on the customer’s usual activity, the size of the transaction and possible links with suspicious networks, rather than relying only on an individual transaction.
Customers will get 20 days to respond
The proposed framework sets out a clear process for customers as well. If an amount is temporarily blocked, the bank will give the customer 20 calendar days to establish the legitimacy of the transaction. During this period, the customer can provide documents related to their identity, the purpose of the transaction and the source of the funds.
After receiving the customer’s response, the bank will have 10 calendar days to examine the explanation and supporting documents. If the transaction is found to be legitimate and the suspicion of cyber fraud is cleared, the bank will have to remove the hold on the amount immediately. This could reduce situations in which customers are deprived of access to legitimate funds for an extended period without sufficient justification.
Case to be referred to police if no response is received
If the customer does not respond within 20 days, or the information provided fails to clear the suspicion of cyber fraud, the bank will refer the case to the relevant law enforcement agency. The National Cyber Crime Reporting Portal and the Centralised Financial Cyber Fraud Reporting and Management System will be used for the process.
Once the case has been referred to the police or the relevant investigating agency, the bank will not be able to keep the amount frozen indefinitely on its own. The police will have to issue a formal statutory restraint within 30 days of receiving the referral. Further legal action concerning the suspicious amount will then come under the jurisdiction of the law enforcement agency.
Proposed to take effect from April 1, 2027
The RBI has issued the proposed changes for public comments. The new directions are proposed to come into effect from April 1, 2027. Banks may, however, adopt them earlier if they choose. The proposed amendments will modify existing provisions relating to the operation of bank accounts and money mule accounts under the KYC Directions, 2025.
Framework prepared after Supreme Court order
According to the RBI, the proposal was prepared following the Supreme Court’s August 4, 2026 order. The top court had directed the RBI to formulate and issue a standard operating procedure for imposing temporary debit restrictions on funds or accounts linked to money mule activities and cyber-enabled fraud.
Targeted action instead of freezing the entire account
The key change under the proposed framework is that action in suspected cyber fraud cases would be limited to the suspicious amount rather than the entire account. This could help prevent fraudulently obtained funds from being transferred further while allowing customers to continue using legitimate money in their accounts. By establishing separate timelines for identifying suspicious funds, obtaining the customer’s explanation, conducting the bank’s review and initiating police action, the framework seeks to make the process more transparent, structured and accountable.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics