A Parliamentary Standing Committee on Finance has delivered a sharp rebuke of the Central Government’s approach to tackling cyber-enabled financial fraud, describing existing measures as largely procedural and inadequate to address operational gaps that allow fraudulent funds to escape the banking system. The panel’s 44th report on action taken by the government calls for stronger accountability for banks hosting mule accounts, faster real-time coordination with law enforcement, and quicker mechanisms to freeze stolen funds before they disappear.
The committee’s findings arrive as digital arrest scams, phishing operations and investment fraud continue to grow more sophisticated, exploiting structural weaknesses in how banks and enforcement agencies communicate once a fraud is reported. Central to the panel’s criticism is its assessment that fraudsters have adapted faster than the institutional response designed to stop them, particularly in how stolen money moves through networks of mule accounts before it can be traced or recovered.
Compensation Framework Draws Sharp Criticism
The Department of Financial Services had cited several existing safeguards in its response to the committee, including AI and machine learning systems deployed by banks, the RBI’s MuleHunter.AI tool for flagging suspicious accounts, NPCI’s UPI fraud monitoring mechanism, the National Cyber Crime Reporting Portal and the 1930 helpline. The committee acknowledged these tools exist but concluded they do not resolve the underlying operational weaknesses that let fraudulent funds pass through the banking system largely unchecked.
Its sharpest objection concerned a proposed compensation framework under which the Reserve Bank of India would absorb 65 per cent of the compensation burden in fraud cases, while beneficiary banks, those actually hosting the mule accounts receiving stolen funds, would bear only 10 per cent. The committee warned this allocation risks creating a serious moral hazard, effectively insulating the banks best positioned to detect suspicious account activity from the financial consequences of failing to do so.
The Golden Hour Problem
The panel devoted considerable attention to what it termed the Golden Hour, the three-to-four-hour window immediately following a fraudulent transaction during which stolen funds are most traceable and recoverable before being layered across multiple accounts. According to the committee, this window is routinely lost, both because victims frequently delay reporting fraud and because local law enforcement, particularly at the district level, often lacks the specialised technical capacity to coordinate swiftly with banks.
The committee was equally critical of the government’s reliance on retrospective Suspicious Transaction Reports and general advisories, arguing that such after-the-fact measures cannot substitute for the real-time intervention the Golden Hour demands. It also flagged persistent weaknesses in Know Your Customer verification at the branch level, holding that lax KYC checks remain a significant contributor to the creation and survival of mule accounts within the formal banking system.
Toward a Penal Framework for Negligent Branches
To address this, the committee has recommended that the Department of Financial Services and the RBI jointly establish a dedicated penal framework targeting bank branches where multiple mule accounts are detected or serious KYC lapses are established. Such a framework would mark a significant shift from the current largely advisory approach towards one carrying direct financial consequences for negligent branches.
The recommendation lands amid an expanding toolkit the RBI has already begun deploying. MuleHunter.AI, developed by the Reserve Bank Innovation Hub, is reportedly capable of flagging around twenty thousand suspicious mule accounts every month, and the Ministry of Home Affairs has directed all financial institutions to integrate with the platform by December 2026. The RBI has also incorporated the Indian Digital Payment Intelligence Corporation to strengthen real-time fraud detection across the digital payments ecosystem, alongside revised customer-liability directions issued in June this year.
Even so, the committee’s underlying message is that technology and helplines alone will not close the accountability gap unless matched with clear consequences for institutional negligence. With mule accounts continuing to underpin a large share of cyber fraud losses nationally, the panel’s recommendations, if adopted, could meaningfully reshape how liability is distributed between the RBI, beneficiary banks and the branches where these accounts originate.
