The Reserve Bank of India’s proposed framework for fraudulent digital banking transactions could allow compensation in certain small-value fraud cases even when a customer has shared an OTP or other credentials after being deceived.
Can You Get Compensation After Sharing an OTP?
Under the proposed framework, sharing an OTP would not automatically take away a customer’s right to seek compensation.
The rules would distinguish between someone deliberately authorising a transaction and someone being manipulated into doing so. The proposed protection would apply to eligible small-value digital frauds involving total losses of up to ₹50,000.
This could become important in scams where fraudsters pose as bank officials, delivery agents or even relatives and persuade victims to share credentials or approve transactions.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
How Will Banks Know You Were Tricked?
Banks would have to examine the circumstances surrounding the disputed transaction to determine whether the customer was deceived or acted intentionally.
They could look at whether money was sent to a new payee, whether the transaction happened after a call from an unfamiliar number, whether there was unusual urgency or repeated failed attempts, and whether the transaction differed from the customer’s normal spending pattern.
Transaction history, call records, messages, screenshots and the timing of the complaint could also become important evidence.
How Soon Must You Report the Fraud?
Victims would still have to report the fraud within the prescribed five-day period and provide information supporting their claim.
This could create difficulties for customers who discover the fraud late or are unable to collect evidence quickly.
The proposed framework therefore does not remove the need for victims to act promptly after discovering an unauthorised or fraudulent transaction.
How Much Compensation Can You Get?
The proposed protection has clear financial limits.
The eligibility ceiling is ₹50,000. Compensation would be capped at 85% of the net loss or ₹25,000, whichever is lower.
The framework also provides for a lifetime one-time benefit. These conditions mean compensation would not be available automatically in every digital fraud case.
Can Banks Reject Your Claim?
Banks would still need to decide whether the customer was genuinely manipulated or had acted negligently or intentionally.
A customer who shares an OTP after being deceived through a convincing script or spoofed caller ID could therefore be assessed differently from someone who knowingly carries out a fraudulent transaction.
However, the absence of a fixed test for determining intent could leave banks making judgement calls when reviewing individual claims.
What Evidence Should Victims Keep?
Messages, screenshots, call records, transaction history and other information surrounding the fraud could become important when a customer disputes a transaction.
The timing of the complaint may also help a bank understand the sequence of events and assess whether the customer was manipulated.
Victims would therefore need to report the incident quickly and preserve information that could support their account of how the fraud happened.
Does This Make Sharing OTPs Safe?
No. The proposed framework should not be treated as permission to share OTPs or other sensitive banking credentials.
Its significance is that sharing a credential after being manipulated may be treated differently from deliberately participating in a transaction. Compensation would still depend on eligibility, reporting deadlines, evidence and the bank’s assessment of the circumstances.
An OTP Is Meant Only for You
Even if the proposed rules may provide compensation in some cases where a victim was manipulated, never share an OTP, PIN or banking credential with anyone. If you are tricked into approving a transaction, report it immediately, save call records, messages and screenshots, and keep all evidence that can help establish how the fraud occurred.
The420 View
The proposed rules could provide some protection to customers who are genuinely manipulated by fraudsters, but they do not guarantee compensation after an OTP is shared. Victims would still need to act quickly, preserve evidence and meet the eligibility conditions for their claim to be considered.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics