Friday, October 2, 2026
19.4 C
Los Angeles

Former Georgian Defense Minister Juansher Burchuladze Receives Reduced Sentence in Plea Deal

A high-profile criminal case involving former Georgian...

New Zealand Moves to Overhaul AML/CFT Framework, Balancing Regulatory Relief With Stronger Enforcement

New Zealand’s proposed Anti-Money Laundering and Countering...

Singapore Moves to Strengthen Stablecoin Regulation Under Proposed Payment Services Act Amendments

Singapore is moving to formalise and strengthen...

RBI Tightens Framework for Suspected Money Mule Accounts, Introduces Time-Bound Debit Holds to Combat Cyber Fraud

Recent Regulations & NewsRBI Tightens Framework for Suspected Money Mule Accounts, Introduces Time-Bound Debit Holds to Combat Cyber Fraud

The Reserve Bank of India (RBI) has introduced a new Standard Operating Procedure (SOP) for banks to identify and manage suspected money mule accounts, strengthening the banking system’s response to cyber-enabled financial fraud. The framework provides banks with a uniform, time-bound mechanism to temporarily restrict debit transactions in accounts or amounts suspected to be linked to fraudulent activity, while also setting out safeguards intended to protect genuine customers from prolonged or unwarranted restrictions.

The move follows the Supreme Court’s order of August 4, 2026, which directed the RBI to formulate and circulate an SOP specifying the action banks should take when amounts or accounts are linked to money-mule activity and cyber-enabled financial fraud. The RBI has now incorporated the SOP into the Know Your Customer (KYC) framework through the Reserve Bank of India (Know Your Customer) Amendment Directions, 2026.

The amended provisions will take effect from April 1, 2027, although banks may choose to implement the SOP earlier.

Greater responsibility on banks to identify money mule activity

Under the revised framework, banks are required to strengthen their monitoring of accounts that could potentially be used as conduits for the proceeds of fraud. Money mule accounts are accounts used knowingly or unknowingly to receive, layer or transfer money obtained through cyber-enabled financial fraud on behalf of another person.

The RBI has specifically highlighted fraudulent schemes such as phishing, identity theft and smurfing, where criminals may recruit third parties to receive or move illicit funds through their bank accounts.

Banks will therefore be expected to conduct appropriate due diligence and closely monitor transactions to identify accounts exhibiting characteristics associated with money mule activity. Where an account is established to be a money mule account, the bank must take action in accordance with the new SOP and continue to meet its existing obligations to report suspicious transactions to the Financial Intelligence Unit-India (FIU-IND).

Importantly, the amended KYC Directions make the reporting obligation explicit. If it is established that an account was opened and operated as a money mule account but the concerned bank did not file a Suspicious Transaction Report (STR), the bank will be considered non-compliant with the KYC Directions.

Temporary debit holds become a formalised intervention

At the centre of the new framework is the introduction of a defined process for placing a Temporary Debit Hold on suspected money mule transactions or accounts.

A suspected money mule transaction is defined under the SOP as a transaction of ₹1,000 or more that has been flagged by the bank’s transaction-monitoring systems, including AI/ML-based tools, as potentially involving proceeds of money mule activity or cyber-enabled financial fraud.

The transaction may be flagged because it is unusual or disproportionate to the customer’s declared profile, or because it has a connection with an account that has already been reported as a money mule or fraudulent account.

Once a bank identifies such a transaction or account, it can place a temporary debit hold suo moto, without waiting for an instruction from a law enforcement agency. Where only a particular transaction is suspected, the hold can be placed on the suspected amount. Where the entire account is identified as a suspected money mule account, the bank may place the hold at the account level.

However, the RBI has specifically stated that an account-level temporary debit hold should be used only as a last resort and in exceptional circumstances.

Customers must be informed when a hold is imposed

The framework also introduces a notification requirement aimed at ensuring that customers are informed when restrictions are placed on their accounts.

When a temporary debit hold is imposed, the bank must notify the account holder, explain the reasons for the action and provide information on the process for getting the restriction removed. Contact details of the concerned bank officer must also be provided.

Where the customer has a registered mobile number or email address, the notification should be sent digitally immediately. Where communication is made through physical means, the bank must notify the customer by the end of the following day.

This requirement creates a formal communication trail around the restriction rather than leaving customers without information about why their account or funds have been temporarily restricted.

Customers receive 20 days to explain the transaction

The SOP establishes a defined opportunity for the account holder to demonstrate that the transaction or account activity is genuine.

After imposing the temporary debit hold, the bank must seek an explanation or justification from the account holder regarding the genuineness of the transaction or account. The customer is given 20 days from the date of the temporary debit hold to submit the explanation.

The bank must then examine the explanation, where one is received, or conduct its own due diligence if the customer does not respond.

If the bank is satisfied with the explanation, it must remove the temporary debit hold and notify the customer.

If the explanation is not satisfactory, or if the bank determines that further action is required, the hold may continue and the matter must be reported to the Jurisdictional Police Authority through the National Cybercrime Reporting Portal’s Citizen Financial Cyber Fraud Reporting and Management System (NCRP-CFCFRMS).

A maximum 60-day framework in the absence of further legal directions

The RBI has also attempted to establish clear outer limits around the temporary restriction process.

Where the customer submits an explanation, the bank must make its decision within 10 days of receiving the explanation. If the customer does not provide an explanation, the bank must make a decision within 30 days from the date on which the temporary debit hold was imposed.

If the bank continues the hold and refers the matter to the jurisdictional police authority, the relevant law enforcement agency or competent authority has a further period to issue instructions requiring continuation of the restriction.

If an appropriate statutory direction is received within the prescribed period, the bank must comply immediately.

Conversely, if no such direction is received within 30 days from the date of reference to the law enforcement agency, the bank must remove the temporary debit hold on the 31st day from the date of reference.

Taken together, the SOP provides for a maximum temporary debit-hold period of 60 days, in the absence of a contrary instruction from a law enforcement agency or competent authority.

The timeline is therefore designed to balance two competing requirements: allowing banks and authorities sufficient time to investigate potentially fraudulent transactions while preventing suspected accounts from remaining indefinitely restricted without further legal or investigative action.

Technology and AI/ML systems to play a greater role in detection

The new framework also places emphasis on banks’ transaction-monitoring capabilities.

Banks’ internal policies must specify the technology solutions they will use to identify suspected money mule activity and cyber-enabled financial fraud. The SOP expressly recognises transaction-monitoring systems, including AI and machine-learning-based tools, as mechanisms through which suspicious transactions may be identified.

However, the framework also requires banks to establish objective parameters designed to minimise the risk of genuine customers or legitimate transactions being incorrectly flagged.

This places greater emphasis on the quality of transaction monitoring, risk-based detection and the ability of banks to distinguish unusual activity from genuinely fraudulent behaviour.

Banks must establish detailed internal policies

Every bank will be required to formulate an internal policy governing the implementation of the SOP.

The policy must cover the technology used to detect suspected money mule and cyber-fraud transactions, the circumstances in which a temporary debit hold can be placed, and the conditions under which it can be removed.

It must also define customer communication processes and templates, establish mechanisms for connecting with the Ministry of Home Affairs’ NCRP-CFCFRMS portal, and provide a customer grievance-redressal mechanism.

The RBI has further required banks to analyse identified transactions at an appropriate level using objective parameters, with the specific aim of reducing the possibility of genuine accounts and transactions being incorrectly flagged.

Stronger record-keeping and continued STR obligations

The framework also introduces detailed record-keeping requirements.

Banks will have to maintain a centralised management information system (MIS) containing information on each temporary debit-hold case. This includes the date and reasons for the hold, correspondence with the customer, notifications issued at different stages, references and reports submitted to law enforcement agencies, directions received from authorities, and the eventual release or continuation of the hold.

The SOP does not replace or reduce banks’ existing obligations under the Prevention of Money Laundering Act, 2002, or the RBI’s KYC framework.

Banks must continue to file STRs with FIU-IND wherever required.

Records relating to temporary debit holds must generally be retained for at least five years from the date of the hold. Where an account is subsequently closed, the relevant records must be retained for at least 10 years from the date of closure. These records must also be made available for supervisory review.

Banks are additionally required to undertake enhanced monitoring of accounts subject to such action, as well as other active accounts or relationships maintained by the same account holder.

Dedicated grievance mechanism for affected customers

Recognising that temporary restrictions can affect legitimate customers, the SOP requires banks to establish a formal grievance-redressal mechanism.

Banks must designate nodal officers at appropriate regional, zonal or head-office levels to coordinate cases and handle complaints arising from action taken under the SOP.

Details of these officers—including their names, telephone numbers, addresses and email addresses—must be prominently displayed on the bank’s website and at its branches.

Complaints received under the framework must be acknowledged and resolved within 30 days, with banks required to maintain an MIS to track and monitor such complaints.

Framework excludes certain specialised accounts

The SOP applies to commercial banks—including Small Finance Banks, Payments Banks, Regional Rural Banks and Local Area Banks—as well as Urban Cooperative Banks.

However, it does not apply to certain specialised accounts, including nodal accounts, pool accounts, escrow accounts and other specified special-purpose accounts, such as dividend and share-capital accounts.

The new framework also does not alter the existing statutory and regulatory obligations of banks under the Prevention of Money Laundering Act, 2002, or the RBI’s KYC Directions, 2025.

A more structured approach to cyber-fraud response

The RBI’s amendment effectively formalises the process banks must follow when they detect suspected money mule activity. Instead of relying solely on existing transaction-monitoring and suspicious-transaction reporting mechanisms, banks will have a defined procedure covering detection, immediate temporary restriction, customer notification, customer response, internal review, referral to law enforcement and eventual removal or continuation of the hold.

The framework also establishes specific accountability points for banks, particularly around monitoring, STR filing, documentation, customer communication and grievance handling.

With implementation mandated by April 1, 2027, the amendment gives banks a defined period to build or update their transaction-monitoring technology, internal policies, NCRP-CFCFRMS connectivity, notification processes and governance mechanisms.

Overall, the revised KYC framework represents a move toward a more standardised and time-bound banking response to accounts suspected of facilitating cyber-enabled financial fraud, while retaining the requirement for banks to distinguish genuine customer activity from potentially fraudulent transactions and providing a formal process for customers to challenge temporary restrictions.

By FCCT Editorial Team

Disclaimer: The views expressed in this article are independent views solely of the author(s) expressed in their private capacity.

Check out our other content

Ad


Check out other tags:

Most Popular Articles