Delhi consumer commission rules bank responsible for unblocked card fraud losses

A Delhi consumer commission has awarded Rs 90,000 to a customer after ruling that the bank failed to act promptly following a card compromise, highlighting the shifting responsibility in card fraud cases.

A Delhi consumer commission has drawn a sharp line around when responsibility for card fraud shifts from the customer to the bank, ordering a lender to pay Rs 90,000 after withdrawals continued even after the account holder said he had reported the card compromise. The ruling means the customer is to recover the Rs 60,000 taken after his complaint, plus Rs 30,000 in compensation.

The order was signed on 17 August by a North District bench comprising president Divya Jyoti Jaipuriar and members Harpreet Kaur Charya and Ashwani Kumar Mehta. The commission gave the bank 30 days to comply. What stands out is that the bench did not treat the entire episode as a single instance of customer carelessness. Instead, it separated the first suspicious withdrawal from the later debits and asked what the bank did once it had been alerted.

The dispute goes back to 22 October 2018, when the complainant said he received his ATM card and went to a machine outside the branch to activate it and set a PIN. He told the commission that, after he struggled with the machine, two unidentified men inside the ATM cabin offered assistance. According to his account, they learnt the PIN during that exchange, swapped his debit card for another one and returned the wrong card to him without his realising it.

The next day, he received an SMS saying Rs 25,000 had been withdrawn from his account. He then telephoned the bank’s card helpline, obtained a complaint reference and says he was told the card had been blocked. Yet later the same evening, two more alerts arrived, this time for Rs 50,000 and Rs 10,000. The customer later learnt, according to the reports of the case, that four debit cards had been issued against the same account, even though he maintained that he had only ever been given one. He then moved to disable the remaining cards and filed a police complaint.

The bank’s defence was that the fraud began with the customer’s own lapse. It argued that he had disclosed card details and his PIN to strangers despite repeated warnings not to do so, and that any later misuse flowed from that negligence rather than from a service failure by the bank. That argument was not brushed aside entirely. The complainant himself did not ask the commission to reimburse the first Rs 25,000, effectively accepting that he bore responsibility for the loss up to that point.

Where the bank lost the case was on what happened next. The bench held that once the customer had raised the alarm and been given a complaint number, the bank was expected to stop further use of the compromised card. NewsDive reported that the commission said: “We find that the operational party (the bank) exhibited a deficiency in service by failing to block the card, resulting in an unauthorized withdrawal of Rs 60,000 from the complainant’s account.” In other words, the commission treated the later withdrawals not as an inevitable consequence of the original mistake, but as a separate failure in the bank’s response.

That approach broadly matches the Reserve Bank of India’s framework on unauthorised electronic banking transactions, issued on 6 July 2017. The RBI says that where a customer’s own negligence causes the breach, the customer bears the loss only until the unauthorised transaction is reported to the bank; any loss after that point is to be borne by the bank. The regulator also says banks must provide round-the-clock channels for reporting fraud or loss of a card, acknowledge the complaint with a registered number and take immediate steps to prevent further unauthorised transactions.

The same RBI rules say the burden of proving customer liability rests with the bank. They also require banks to credit the amount involved in an unauthorised transaction within 10 working days of notification, pending final resolution, and to settle complaints within a period set out in board-approved policy, not exceeding 90 days. Those rules help explain why the commission focused so closely on timing: when the first SMS arrived, when the helpline was called and whether the bank acted at once.

The case is also a reminder that consumer fora may not accept a bank’s attempt to rely solely on general warnings about keeping PINs secret. Once a customer has reported that a card may have been stolen, swapped or compromised, the legal question can change from how the fraud began to whether the bank’s control systems worked when it mattered most. Here, the ruling suggests the answer was no, and that failure proved costly.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.