The Reserve Bank of India has unveiled draft amendments enabling banks to impose temporary debit holds on accounts suspected of being used for illicit funds, aiming to strengthen cybersecurity and fraud prevention measures.
The Reserve Bank of India has proposed new rules that would allow banks to place temporary debit holds on suspected money mule accounts, in a move aimed at curbing cyber-enabled fraud and illicit fund transfers.
The draft amendments to the central bank’s Know Your Customer framework were issued after the Supreme Court on 4 August directed the RBI to draw up a standard operating procedure for such cases. The proposal would require banks to act quickly when a transaction is flagged by their monitoring systems as suspicious, including tools based on artificial intelligence and machine learning.
Under the plan, a hold could be placed on an individual transaction of ₹1,000 or more, or, in more serious cases, on an entire account identified as a suspected money mule account. The RBI said account-level restrictions should be used only as a last resort and in exceptional circumstances.
Banks would have to tell customers immediately when a hold is imposed, explain why it happened and set out how it can be challenged. Customers would then have 20 days to justify the transaction or account activity. If a bank receives an explanation, it must decide within 10 days; if no response is received, it would have 30 days from the date of the hold to reach a decision.
If the explanation is accepted, the hold must be lifted at once. If not, the bank would keep the restriction in place and report the matter to the local police through the National Cybercrime Reporting Portal’s citizen financial cyber fraud reporting and management system. In the absence of any instruction from law enforcement or another competent authority within 30 days of referral, the hold would have to be removed on the 31st day. The maximum period for any temporary debit hold would be 60 days.
The RBI also wants banks to strengthen internal controls around the detection and removal of holds, customer communication, grievance redress and integration with the cybercrime reporting portal. Institutions would need centralised records of such cases, including correspondence with customers and law-enforcement agencies, and would have to retain them for at least five or 10 years after an account is closed.
The draft further states that banks would still need to file Suspicious Transaction Reports with the Financial Intelligence Unit-India. If a bank concludes that an account is being used as a money mule but has not filed such a report, it would be treated as having failed to comply with know-your-customer rules. Banks would also need to step up monitoring of the affected account and any other active relationships held by the customer.
For complaints, banks would be required to appoint nodal officers, publish their details on websites and at branches, and resolve grievances within 30 days. According to reports on the draft, the proposed rules are open for public comment until 2 October 2026 and could take effect from 1 April 2027, or earlier if banks choose to adopt them sooner.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





