
Loading...
Law Update
Quick note
Below is the official summary and the reference document preview. Use āOpen PDFā for full screen view.
The Reserve Bank of India (RBI) has sought public feedback on a proposed adjustment to the operation of accounts and funds deemed potentially related to money mule activity and cyber-enabled financial fraud.
On 11 September 2026, RBI issued the Draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026 for consultation. The draft amendment relates to the Know Your Customer (KYC) Directions, 2025, which currently contain instructions relating to the operational aspects of banks' accounts and money mules.
The draft follows an order passed by the Supreme Court on 4 August 2026. The Court directed the central bank to set up and circulate a Standard Operating Procedure (SOP) which explains what measures banks should take in the event that a temporary debit hold is required to be placed on an amount or account associated with suspected money mule activity or cyber-enabled fraud.
However, it should be noted that the legal standing of the document is important for banks and other interested parties. This is a draft directive that is issued for consultation rather than an order that has been implemented.
RBI has invited comments from regulated entities and members of the public on or before 2 October 2026. Following the review of feedback, RBI will issue the final Directions separately.
| Particular | Details |
| Issuing authority | Reserve Bank of India |
| Document | Draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026 |
| Press release date | 11 September 2026 |
| Press release number | 2026-2027/1109 |
| Nature of document | Draft issued for public consultation |
| Existing framework referred to | RBI Know Your Customer Directions, 2025 |
| Existing subject area | Operations of Bank Accounts and Money Mules |
| Supreme Court order referred to | 4 August 2026 |
| Main issue | Temporary debit holds linked to money-mule activity and cyber-enabled financial fraud |
| Entities covered by consultation | Commercial Banks and Urban Cooperative Banks, including specified categories of commercial banks |
| Feedback deadline | 2 October 2026 |
| Feedback route | Connect 2 Regulate or email with the prescribed subject line |
| Final effective date | Not stated in the press release |
| Final Directions | To be issued separately after RBI examines comments |
This release by RBI makes the process clear but still does not announce a final date for implementation. 2 October 2026 is just the deadline for comments, not implementation.
These Directions will seek to solve the following specific problem in the banking sector: how to react where there is an assumption that a bank account or the balance therein might have been affected by mules and cyber-fraud.
Currently, RBIās existing KYC guidelines have a section dealing with āOperations of Bank Accounts and Money Mules.ā The 2026 Direction Proposal will try to modify these guidelines based on an SOP approach.
That means this is not being presented as a completely new KYC law. Rather, RBI is proposing to modify an existing part of its KYC framework. The press release does not contain the entire operational procedure. For example, it does not state:
Those details cannot safely be filled in from assumptions.
"The immediate explanation from the RBI is the order from the Supreme Court regarding the need for a standard procedure for temporary debit blocks."
Existing Instructions Already Deal With Money-Mule Activity
The RBI has particularly cited current KYC instructions related to the use of bank accounts and money mules.
So the issue is not about whether or not the RBI has ever taken care of mule accounts. It has done so. The current consultation is on revising that particular regulatory area and making connections between them and temporary debit blocks."
Supreme Court Order Dated 4 August 2026
As per RBI, it was directed by the Hon'ble Supreme Court to implement and disseminate the SOP regarding the action to be taken by banks in the event of temporary holds on the amount/ account linked to money laundering and frauds via cybernetics.
As for the RBI statement attached, it does not contain the entire order passed by the Court. Therefore, the reasoning behind the Court's verdict should not be interpreted based on the single-page RBI statement.
Why an SOP Could Matter
An SOP is meant to provide a uniform way of addressing a certain situation for operational teams. In the case of banking, an SOP might facilitate understanding of:
It is a purely practical comment on the relevance of an SOP. The exact RBI process will depend on the actual regulations.
While the press release of the RBI uses the concept of money-mule activity, the definition of a money-mule account has not been defined.
In laymanās terms, the concept normally implies the use of a bank account for the purposes of receiving, transferring, or transmitting money that has anything to do with suspicious activity.
The individual who uses their bank account for such activities normally does not perform the same task each time. This is one of the reasons why banks have to conduct an assessment before considering something as fraudulent.
For this article, that general explanation should not be read as the exact statutory or RBI definition. The attached press release itself does not provide one.
A temporary debit hold can be understood, at a basic level, as a restriction on debits from an amount or account for a limited period while the suspected fraud-linked activity is dealt with.
The concept differs from that of detecting suspicious transactions, as it involves placing a hold on the transactions, affecting the customers' ability to conduct their transactions.
According to the press release by the Reserve Bank of India, it is clear that the proposed SOP relates to debit holds on amounts/accounts for money mules and cyber-fraud. However, there are some things that the RBI press release doesn't reveal.
From the press release, we cannot find any mention of:
Until all this information becomes available from an official source, it should not be considered a requirement by RBI.
The regulatory structure can be better explained with the help of four tiers.
| Regulatory Layer | What It Means |
| KYC Directions, 2025 | Existing RBI KYC framework referred to in the press release |
| Operations of Bank Accounts and Money Mules | Existing area within that framework |
| Draft KYC Amendment Directions, 2026 | Proposed changes now under consultation |
| SOP for temporary debit holds | Operational approach referred to following the Supreme Court direction |
| Final Directions | Separate RBI Directions expected after consultation |
This is important for the compliance division of the bank since the regulations need to be read in conjunction with the existing KYC regulations. They cannot be looked at as a separate regulation for cyber fraud.
According to RBI, the following kinds of banks are covered under the consolidated draft consultation.
The consultation applies to the Commercial Banks that include the following:
Also covered are the Urban Cooperative Banks.
Applicability Matrix
| Entity | Covered by This Consultation? | Position |
| Commercial Banks | Yes | Directly covered |
| Small Finance Banks | Yes | Included within Commercial Banks |
| Payments Banks | Yes | Included within Commercial Banks |
| Regional Rural Banks | Yes | Included within Commercial Banks |
| Local Area Banks | Yes | Included within Commercial Banks |
| Urban Cooperative Banks | Yes | Directly covered |
| NBFCs | Not expressly stated | Do not assume coverage |
| Fintech companies | Not separately listed | May have indirect relevance depending on relationship with banks |
The last two rows are important. The press release should not be stretched to cover every financial-sector business simply because cyber fraud is involved.
The one-page press release gives us the direction of the proposed change, but not every clause of the amendment.
| Regulatory Area | Existing Position Referred To | Proposed Development | Status |
| Bank-account operations | Existing KYC Directions contain instructions | Existing instructions proposed to be amended | Draft |
| Money-mule activity | Already addressed under existing KYC framework | Proposed revision/strengthening | Draft |
| Temporary debit holds | SOP directed by Supreme Court | Banks to be advised on the action to be taken | Draft |
| Cyber-enabled financial fraud | Identified as part of the problem | Proposed SOP-linked response | Draft |
This is the safest way to describe the change from the available source.
An in-depth āold versus new clauseā comparison will need the full text of the draft amendment.
If the Directions adopt the approach outlined above, it may be necessary to examine whether the bankās process of handling such accounts needs to be changed.
1. Detection of Suspicious Activity
Fraud detection and KYC units might need to take into consideration how suspicious activity in the account could be detected.
The problem here is that not only can a fraudulent transaction be recognized, but a suspicious transaction by a genuine customer might also be legitimate.
2. Internal Escalation
A case that is suspected of being fraudulent may need to escalate rapidly from monitoring functions to fraud, compliance, legal, and other areas.
Otherwise, either action will be postponed or inconsistent.
3. Debit Restrictions
If the proposed framework allows the imposition of a debit block temporarily, then banks may require well-defined controls on when to impose it and how to document the decision.
4. Customer Handling
Account blocks are not just an anti-fraud control measure. They are also going to be a customer service issue in no time.
Customers may wish to find out:
The above details will depend on the final RBI framework.
The KYC (Know Your Customer) and Anti-Money Laundering departments would most certainly be amongst those which will have to read the final Directions carefully. They might have to check if there is any change required in the following areas:
⢠account-monitoring practices,
⢠suspicious-activity escalation,
⢠customer-risk assessment,
⢠policy wording,
⢠record-keeping, and
⢠internal reporting.
That does not mean every one of these items has already been mandated by the current press release. They are areas that banks may reasonably need to review once the final framework is available.
The draft explicitly mentions cyber-based financial fraud; hence, the fraud risk teams are expected to play an important operational role in this regard. They might be required to determine whether the current systems are capable of gathering information on:
Cybersecurity teams may also become involved where the underlying incident involves compromised credentials, phishing, unauthorised access or another cyber-enabled event.
The RBI Directions will determine which of the above become specific compliance obligations.
Legal and compliance teams have a different task: they need to separate what is legally required from what is merely an internal fraud-control practice.
This becomes crucial when dealing with the restriction of an account. Internal teams should be careful about considering all of the following as the same thing:
Different actions may arise from different legal or regulatory grounds.
The current press release does not collapse these categories into one.
The RBI press release uses the term temporary debit hold. It should not automatically be replaced with the broader expression āaccount freeze.ā
Usage of the two terms can differ based on the type of legal document that uses them, the extent of the limitation, and the jurisdiction under which the measure is being enacted.
Since this information does not explain the difference between the two terms, it would not be wise to make a definitive legal comparison.
For banks, the practical lesson is simple: use the terminology contained in the applicable RBI Directions, SOP, or legal instruction instead of treating similar-sounding terms as interchangeable.
For customers, the biggest concern is access to funds.
Where a debit hold is applied, the customer may be unable to move the affected money until the matter is dealt with according to the applicable process.
This can actually make a difference because a genuine customer might require the money to fulfill such obligations as:
On the other hand, a bank that suspects an occurrence of fraud will have to move fast so as not to lose the funds.
This dilemma of acting promptly and properly will definitely prove to be one of the key practical problems within any resulting framework.
This type of framework needs to cover both aspects of this issue.
From the Fraud-Control Side
The imposition of an account block can assist because it:
From the Customer Side
The enclosed press release does not list the safeguards that would be employed. That would have to be verified later in the final Directions.
| Bank Function | Possible Area of Impact | Why It Matters |
| KYC/AML | Policy and account-monitoring review | Existing controls may need alignment |
| Fraud Risk | Case identification and escalation | Suspected fraud may require fast response |
| Cybersecurity | Cyber-fraud incident coordination | Some cases may begin with cyber events |
| Legal | Legal basis for restrictions | Actions must rest on proper authority |
| Compliance | Regulatory interpretation | Draft and final requirements must be separated |
| Operations | Execution of account-level action | Front-line processes may need clarity |
| Customer Service | Handling affected customers | Restrictions can trigger immediate queries |
| Internal Audit | Review of controls | Implementation may need later testing |
The proposal is not simply an issue for the KYC team. These figures represent operational implications rather than RBIās obligations.
RBI has widened the consultation process to include non-regulated banks as well. Comments or feedback may be submitted by:
That gives banks, industry bodies and other interested persons an opportunity to point out practical issues before the text is finalised.
Consultation responses might concentrate on issues like:
Will there be major changes to the system for implementation?
RBI has provided two ways.
Through Connect 2 Regulate
Feedback may be sent using Connect 2 Regulate on the RBI website.
Through Email
RBI has also made provision for feedback to be sent by email under the subject line:
āFeedback on Draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026ā.
The release that is attached mentions the procedure and subject line for sending feedback. Please do not use the unverified email ID for sending feedback to RBI.
The consultation closes on or before 2 October 2026.
Regulatory Timeline
| Bank Function | Possible Area of Impact | Why It Matters |
| KYC/AML | Policy and account-monitoring review | Existing controls may need alignment |
| Fraud Risk | Case identification and escalation | Suspected fraud may require fast response |
| Cybersecurity | Cyber-fraud incident coordination | Some cases may begin with cyber events |
| Legal | Legal basis for restrictions | Actions must rest on proper authority |
| Compliance | Regulatory interpretation | Draft and final requirements must be separated |
| Operations | Execution of account-level action | Front-line processes may need clarity |
| Customer Service | Handling affected customers | Restrictions can trigger immediate queries |
| Internal Audit | Review of controls | Implementation may need later testing |
The latter two rows are of particular significance from a compliance point of view. There is nothing in the above press release to suggest that 2 October marks the beginning of a new debit-holding policy.
The banks should prepare for change in regulation without confusing a work in progress as being set in stone.
The process is very straightforward as follows:
It is clearly stated by the RBI that the final directions will be issued separately.
Next comes the review of feedback by the RBI.
Then, the RBI will finalize its Directions for the regulated entities under consultation.
There are certain things, however, which have not been revealed in the press release:
This situation will remain like this until such clarifications from the Reserve Bank of India are provided.
The fact that this proposal is not yet final does not imply that banks should pay no attention to it.
Internal assessment during the period of consultations is helpful indeed.
Existing KYC Policies
Banks may evaluate if their policies contain procedures to handle misuse of accounts, suspicion of money mules, and fraud escalations.
Fraud-Monitoring Process
The teams may review the process through which fraud alerts get escalated to action. Things to be reviewed include:
Internal SOPs
The existing SOPs can be compared to the topic of the RBI proposal. It is not necessary to rewrite everything before the finalization of the Directions, but identifying potential gaps now would save time later.
Decision-Making Authority
The banks can check which individuals currently have the power to give approvals on matters that may affect customer transactions.
The press statement by the RBI does not outline a new approval process, and therefore, no new power structure is implied by the press statement.
Customer Communication
Banks can examine how customers are currently informed when transactions or account access are restricted for fraud-related reasons.
Clear internal ownership may help prevent customers from being passed repeatedly between teams.
Audit Trail
A decision affecting a customer's money should be capable of later review. Banks may therefore want to assess whether existing records show:
These are sensible preparatory checks. They are not being presented as final RBI-mandated record formats.
Distinguishing Fraud From Unusual but Genuine Activity
Not all odd payments are frauds. A huge payment to the bank account can take place due to a property deal, business payments, insurance payments, or any other genuine reason.
Hence, banks must have some controls that will be able to assess the risk without considering all odd transactions as evidence of fraud.
Speed Versus Accuracy
Fraud response often needs to be fast.
But a rushed decision can create a different problem if legitimate funds are restricted without a sufficient basis.
The final framework will need to be read carefully to understand how RBI expects banks to manage this balance.
Multiple Teams Handling One Case
A cyber-fraud case can move through:
Weak coordination can lead to delays or inconsistent handling.
False Positives
Indeed, a customer can be flagged by the anti-fraud system. Therefore, banks must have a good review process in place in order to prevent automatic restrictions from occurring.
Customer Communication
Account restrictions are stressful for customers, particularly when they do not understand why they cannot access funds.
Banks may need clear internal communication routes, though the exact customer-notice requirements cannot be taken from the press release alone.
Potentially, yes.
The use of a standard framework can simplify the management of fraud response decisions. Advantages that could potentially arise include:
These are possible benefits. The actual outcome will depend on the final design and implementation of the Directions.
A new operational process can require time, people, and technology. Depending on the final Directions, banks may have to review:
1. Technology
Changes may be required in systems to accommodate fraud warning capabilities, account-level restrictions, or internal processes.
2. Monitoring
Transaction monitoring guidelines may need adjustment to conform to the chosen regulatory approach.
3. Training
Branch personnel, fraud personnel, operations personnel, and customer service personnel may need training.
4. Documentation
There might be a need for revision of regulations, SOPs, escalation matrices, and internal documentation.
5. Customer Service
More account activity might mean more customer complaints and queries.
6. Audit and Monitoring
An internal audit or compliance monitoring exercise may need to verify whether the process is being adhered to properly.
RBI has not stated any implementation cost in the attached release. Therefore, no rupee estimate should be attached to these possible changes.
Neither cancels out the other.
A procedure can serve the purpose where rapid action must be taken against the proceeds of cyber fraud. The banks cannot keep reinventing the wheel each time an account is identified as potentially being used by a mule.
On the other hand, limitations on bank accounts are imposed on real customers and real firms. An overly wide, vague, or lengthy procedure may have its own drawbacks.
Potential Regulatory Value
The recommendation could assist with:
Possible Burden on Banks
Banks might encounter:
Therefore, the concluding evaluation will have to take into account the real Directions, especially regarding RBIās approach to triggers, scope, protections, reviews, and releases of debits.
Consultation is another piece of regulatory content that is one of the most vulnerable to misinterpretations. Banks should refrain from:
Instead, it is advisable to examine the draft, determine the issues that can arise for the operations of banks, and submit comments if needed.
The consultation is directed at specified banks, but ordinary businesses can still be affected indirectly.
Businesses Maintaining Bank Accounts
If any firm is queried regarding suspected fraud in cases of transactions involving disputes in relation to money deposited in the companyās bank account, then proper accounting books will serve their purpose.
Where there are proper accounting books, firms need to maintain books for:
This is just proper finance management and not something new that RBI has recently communicated in its press release.
Fintechs and Digital Payment Companies
There is no mention of Fintechs as specific coverage in the press release. However, companies dealing with covered banks may face future changes in partner bank procedures in case the ultimate Directions demand some different fraud management procedures.
Corporate Finance Teams
Finance teams may want to pay particular attention to unexplained credits, unusual counterparties and requests to receive or transfer money on behalf of third parties.
Again, these are practical fraud-risk measures rather than new duties expressly imposed by this draft announcement.
Practical action at this stage would include:
| Priority | Action | Relevant Team | Timing |
| High | Read the complete draft and identify affected policies | Compliance/Legal | During consultation |
| High | Map current fraud and money-mule handling process | Fraud/KYC/AML | During consultation |
| High | Identify operational concerns for feedback | Compliance/Operations | Before 2 October 2026 |
| High | Submit comments where required | Authorised regulatory team | On or before 2 October 2026 |
| Medium | Review current SOPs and escalation routes | Fraud/Operations | Preparatory |
| Medium | Assess possible technology impact | Technology/Fraud | Preparatory |
| High | Track RBI for final Directions | Compliance/Legal | Ongoing |
| High | Implement final requirements only after verification | Relevant functions | After final Directions |
The bottom line is that you do not want to begin the process until you know what is required.
Where the bank is concerned, a short regulatory announcement may become quite an involved compliance activity. The announcement may be only a few pages, but compliance staff will need to determine what policy, department, system, or process could be impacted.
Corpseed can support organisations through relevant banking regulatory compliance services and regulatory review.
1. RBI Regulatory Applicability Assessment
Corpseed can assist in examining whether a particular RBI direction, amendment, or compliance requirement applies to the organisation's regulated activity.
The review can cover:
2. KYC Compliance Consulting
With KYC compliance consulting, organizations have the opportunity to assess if their existing KYC policy and internal controls comply with the RBI regulations.
This could be done by analyzing:
3. AML Compliance Services
If AML regulations apply, Corpseed can help your organization assess the existing compliance controls and documentation. The focus should remain on requirements that are actually applicable to the entity rather than on using a generic AML checklist.
4. Compliance Gap Assessment
Gap analysis is useful in determining the gap between current internal procedures and regulatory standards.
In case of regulatory changes like:
5. Review of Internal Policies and SOPs
After RBI issues the Direction, there may be a requirement to review the internal policies and SOPs in light of the new regulatory requirements.
Corpseed can assist in reviewing and restructuring the compliance documentation according to the final regulatory requirements.
6. Regulatory Change Management
A new Direction can affect more than the compliance team. Corpseed can assist organisations in mapping a regulatory change across:
It may assist companies in realizing where internal actions have to be taken.
7. Continuous Compliance Assistance
Financial laws keep evolving due to amendments, circulars, clarifications, and directions.
The continuous compliance assistance provided by Corpseed's regulatory compliance consulting will be useful for tracking any changes in laws, assessing the applicability of these laws, and evaluating their impact on the documents already in place.
The idea is not to consider each RBI directive as a mandatory requirement. The idea is to find out what really matters, what remains under proposal, and what needs action upon finalization of the rule.
The RBI's notification dated 11 September 2026 commences a consultation on modifications being proposed to the KYC guidelines in relation to money mules and financial fraud.
For the banks, the important step now is to go through the draft proposal, raise any issues, and implement the final RBI Directions.
Document Preview
Embedded reference document
Related
Explore more updates from the same department.