RBI New Customer Liability Rules 2027 — What JAIIB & CAIIB Candidates Must Know
- What: RBI (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026 — a new, expanded customer-liability and compensation framework for fraudulent electronic banking transactions
- Issued: 24 June 2026 (final; parallel amendments issued the same day for SFBs, RRBs, UCBs, RCBs, LABs and Payments Banks)
- Applies from: 1 January 2027 — the existing 2017 “Customer Protection — Limiting Liability” circular remains in force until then
- Biggest change: a new 85% compensation mechanism (capped at ₹25,000) for small-value fraud, once in a customer’s lifetime, plus a shift of the burden of proof onto the bank
- Exam relevance: banking-awareness/current-affairs content for JAIIB PPB & RBWM and CAIIB BFM & BRBL — expect this to start appearing in exams from the May 2027 JAIIB cycle and June 2027 CAIIB cycle onward, once it is actually in force
Why This Replaces the 2017 Circular
Every JAIIB and CAIIB candidate currently learns the RBI’s July 2017 circular on Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions: zero liability if the bank is negligent, limited liability (₹5,000/₹10,000/₹25,000 tiers depending on account type) if the customer reports within 3–7 working days, and full liability beyond that — with a 10-working-day reimbursement timeline. That circular is still the law today and will remain so for every exam cycle through 2026. But RBI has now finalised its replacement, and because IIBF papers (especially PPB, RBWM, BFM and BRBL) regularly test “recent RBI guidelines,” this is worth learning now rather than scrambling in late 2026.
Old (2017 Circular) vs New (Third Amendment Directions, 2026) — Compare
| Feature | 2017 Circular (current, until 31-Dec-2026) | Third Amendment Directions, 2026 (from 1-Jan-2027) |
|---|---|---|
| Bank-negligence cases | Zero customer liability | Zero customer liability — retained, now explicitly defined (system failure, missing alerts, inadequate reporting channels) |
| Third-party breach, reported promptly | Tiered limited liability: ₹5,000 / ₹10,000 / ₹25,000 depending on account/card type, based on days taken to report (3–7 working days) | Zero liability if reported within 5 calendar days of a defined “third-party breach” (payment gateway, telecom, aggregator) |
| Small-value fraud compensation | Not a separate category — falls under the standard liability tiers above | New: losses up to ₹50,000 get 85% of net loss or ₹25,000, whichever is lower — once in a customer’s lifetime, funded mostly by RBI with smaller bank contributions |
| Burden of proof | Effectively on the customer to show they weren’t negligent, in practice | Explicitly placed on the bank to prove customer liability |
| Reimbursement/resolution timeline | Provisional credit within 10 working days of reporting | Complaint resolved within 30 calendar days per the bank’s board-approved policy (a full resolution timeline, not just provisional credit) |
| Coverage | Unauthorised electronic banking transactions | Expanded to broader categories of fraudulent electronic banking transactions, with formal definitions of bank negligence, customer negligence, and third-party breach |
| Entities covered | Banks generally | Commercial Banks, SFBs, RRBs, UCBs, RCBs, LABs, Payments Banks — each with its own parallel direction issued the same day |
The Five Things Worth Remembering
Where This Fits in the JAIIB & CAIIB Syllabus
| Exam | Paper / Module | Why it’s tested there |
|---|---|---|
| JAIIB | Retail Banking & Wealth Management (RBWM) | Customer protection and digital-banking risk are core RBWM topics |
| JAIIB | Principles & Practices of Banking (PPB) | PPB’s case-study MCQs frequently draw on recent RBI customer-protection circulars |
| CAIIB | Bank Financial Management (BFM) | Digital banking risk and RBI regulatory updates are examined here |
| CAIIB | Banking Regulations & Business Laws (BRBL) | KYC/AML & Consumer Protection module directly covers the predecessor 2017 circular |
Practice MCQs
Q1. Under the RBI Third Amendment Directions, 2026, the maximum compensation available under the new small-value fraud mechanism is:
- A) 100% of the net loss, uncapped
- B) 85% of the net loss or ₹25,000, whichever is lower, once in a customer’s lifetime ✓
- C) A flat ₹50,000 per incident
- D) 50% of the net loss, twice per financial year
Answer: B. The new mechanism applies to losses up to ₹50,000 and pays out 85% of the net loss (after recoveries) or ₹25,000, whichever is lower — available only once in the customer’s lifetime, and funded predominantly by RBI rather than the customer’s own bank.
Q2. From what date do the RBI Third Amendment Directions, 2026 on customer liability for fraudulent electronic banking transactions apply?
- A) 24 June 2026 (date of issue)
- B) 1 July 2026
- C) 1 January 2027 ✓
- D) They are still in draft and have no effective date
Answer: C. RBI finalised the Directions on 24 June 2026, but they apply only to electronic banking transactions undertaken on or after 1 January 2027. Until then, the 2017 circular’s liability tiers continue to govern.
Q3. Under the 2026 framework, if a customer reports a third-party breach fraud within the prescribed window, their liability is:
- A) Capped at ₹10,000
- B) Zero, if reported within 5 calendar days ✓
- C) Capped at ₹25,000 regardless of reporting time
- D) Determined solely by the transaction amount
Answer: B. This replaces the 2017 circular’s working-day-based tiered structure with a flat 5-calendar-day zero-liability window for reported third-party breaches — a simpler, more customer-favourable rule.
Q4. Under the new Directions, the burden of proving that a customer was liable for a fraudulent electronic transaction lies with:
- A) The customer
- B) The bank ✓
- C) The RBI Ombudsman, in all cases
- D) A third-party arbitrator appointed jointly
Answer: B. The Third Amendment Directions, 2026 explicitly place the burden of proof on the bank in complaints involving fraudulent electronic banking transactions — a reversal from the practical position under the 2017 circular.
Q5. Which of the following entities is NOT covered by the RBI’s 24 June 2026 Third Amendment Directions on customer liability for electronic banking fraud?
- A) Regional Rural Banks
- B) Urban Co-operative Banks
- C) Payments Banks
- D) NBFCs (they are covered under a separate RBI framework, not this set of Directions) ✓
Answer: D. RBI issued parallel Third Amendment Directions the same day for Commercial Banks, SFBs, RRBs, UCBs, RCBs, LABs and Payments Banks — all deposit-taking, RBI-regulated entities under the Responsible Business Conduct framework. NBFCs are regulated separately and are not covered by this specific set of Directions.
Related Chapters
- JAIIB RBWM Paper Guide — Retail Banking & Wealth Management syllabus and strategy
- CAIIB BRBL — KYC, AML & Consumer Protection Laws — covers the 2017 circular and the wider Consumer Protection Act 2019 framework this update sits alongside
- CAIIB BFM Complete Guide — Bank Financial Management paper hub
- JAIIB 2026 Complete Hub
- CAIIB 2026 Complete Guide Hub
0 Comments