HomeCirculars › RBI/2009-10/159

RBI mandates CEO-led fraud risk management overhaul

Current · Source: Reserve Bank of India · RBI/2009-10/159 · issued 16 Sep 2009 · ~2 min read
Quick answerRBI directs banks to make CEOs and board committees directly accountable for fraud prevention and investigation, especially for high-value frauds above ₹1 crore, following rising fraud trends in retail and traditional banking.
The rule, in the simplest words
How it plays out — a real example

A payments & clearing officer in Indore notices a pattern of small frauds in cash credit accounts. Remembering the new rule, she reports it to her branch manager, who escalates to the CEO-led special committee. The committee investigates the ₹1.5 crore fraud, tightens controls, and ensures the RBI gets the report on time, making the CEO personally answerable for any control gaps.

What changed

RBI reinforced that the Special Committee of the Board, chaired by the CEO, must own the fraud investigation and monitoring function for high-value frauds (₹1 crore and above). Banks are now required to frame board-approved internal policies for fraud risk management and investigation, with clear ownership and accountability for systemic control failures.

What it means for you

Banks must elevate fraud risk management to a board-level priority, with CEOs personally accountable for control weaknesses that enable large frauds. This shifts focus from reactive investigation to proactive prevention, requiring stronger internal controls and timely reporting to regulators. Lenders face increased scrutiny on governance standards and may need to restructure their fraud oversight committees.

What you must do

Who it affects

Chairmen and CEOs of all scheduled commercial banks (excluding RRBs), Audit Committees of the Board, Special Committees of the Board for monitoring large frauds, Fraud risk management and investigation teams, Branch-level operating staff handling retail and traditional banking products

❓ Common questions

Regulatory timeline

Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).

What is the threshold for 'high-value frauds' under this circular?

The circular refers to frauds involving amounts of ₹1 crore and above, as per the earlier January 2004 directive, which the Special Committee of the Board must monitor.

Does this circular apply to Regional Rural Banks (RRBs)?

No, the circular explicitly excludes RRBs from its scope, as it is addressed to all scheduled commercial banks excluding RRBs.

What happens if a bank fails to comply with these fraud risk management requirements?

The circular does not specify penalties, but it emphasizes that CEOs and board committees own accountability for systemic control failures, implying regulatory action or supervisory scrutiny for non-compliance.

📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Clarified by Forensic Scrutiny Findings: Fraud Prevention Guidelines for Banks
RBI’s words: “attention is invited to our circular DBS.CO. FrMC.BC.No. 7/23.04.001/2009-10 dated September 16, 2009”
📜 Read the original circular — full text as issued by RBI
RBI/2009-10/159 DBS. CO. FrMC. BC. No. 7 /23.04.001/2009-10 September 16, 2009 The Chairman / Chief Executives of All Scheduled Commercial Banks (excluding RRBs) Dear Sir / Madam, Fraud Risk Management System in banks – Role of Chairmen / Chief Executive Officers As you are aware, the incidence of frauds in the banks has been showing an increasing trend over the recent years, both in terms of number of frauds and the amounts involved. It has been observed that the trend is more disquieting in retail  segment especially in housing and mortgage loans, credit card dues, internet banking, etc. Moreover, it is a matter of concern that instances of frauds in the traditional areas of banking such as cash credit, export finance, guarantees, letters of credit etc remain unabated. While certain structural factors in the banks' operating environment could account for this rising trend in general, adoption of aggressive business strategies and processes by the banks for quick growth and expansion without ensuring that adequate / appropriate internal controls are in place could, in specific, incentivize operating staff to lower the standards of control while attempting to meet business targets. Also, a continuously rising trend in the cases of frauds is indicative of the fact that the steps taken by banks in investigating the frauds and identifying the fraudsters for eventual criminal prosecution and appropriate internal punitive action for the staff members involved in the frauds have not been adequate. While discussing certain cases of frauds of exceptionally large amounts, the Board for Financial Supervision (BFS) has expressed grave concern that fraudsters with the involvement of bank officials could engineer system wide break down of controls across months while putting through fraudulent transactions. 2. Taking into consideration the concern expressed by Central Vigilance Commission and Central Bureau of Investigation, banks were advised in January 2004 to constitute a Special Committee of the Board for monitoring and follow up of large value frauds involving amounts of Rs 1.00 crore and above. However, the feedback received by us in the recent times and growing incidence of frauds indicate that in matters of large value frauds, the Committee headed by the CEO of the bank might not have played the role as envisaged in our circular DBS.FGV(F)No. 1004/23.04.01A/2003-04 dated January 14, 2004. 3. Taking into account the above position the BFS has felt that the Chief Executive Officers (CEOs) of the banks must provide singular focus on the "Fraud Prevention and Management Function" to enable, among others, effective investigation in fraud cases and prompt as well as accurate reporting of fraud cases to appropriate regulatory and law enforcement authorities including Reserve Bank of India. The Board has observed that in terms of higher governance standards, the fraud risk management and fraud investigation function must be owned by the bank's CEO, its Audit Committee of the Board and the Special Committee of the Board, atleast in respect of high value frauds. And accordingly, they should own responsibility for systemic failure of controls or absence of key controls or severe weaknesses in existing controls which facilitate exceptionally large value frauds and sharp rises in frauds in specific business segments leading to large losses for the bank.   4. In view of the above observations made by the BFS, banks are advised to initiate necessary action at their end at the earliest. Banks may, with the approval of their respective Boards, frame internal policy for fraud risk management and fraud investigation function, based on the above governance standard relating to the ownership of the function and accountability for malfunctioning of the fraud risk management process in their banks. The broad governance framework dictated by the above standard for ownership and accountability may rest on defined and dedicated organizational set up and operating processes, some of which have been set out in the following paragraphs: 5. The banks' Special Committee of the Board, which is chaired by the CEO, should own the Fraud Investigation and Monitoring Function and discharge the relative oversight responsibility in a pro-active manner. Presently, the Special Committees are apprised by the banks' Senior Management of the occurrence of the large value frauds. It has been observed that the said Committees give routine instructions on follow up actions. Essentially, the Committees' directions are not mandated to be implemented by any dedicated operating unit of the banks. The banks may, therefore, delineate in the policy document the processes for implementation of the Committee's directions and the document may enable a dedicated outfit of the bank to implement the directions. In this regard, the banks may have to review the roles and responsibilities of the Vigilance Function, Internal Audit Function and Risk Management Function. On the basis of the review, it may be decided as to what realignments and modifications are needed to ensure that "monitoring and investigation of large value frauds" are recognized as a distinct 'function' and the dedicated unit which is adequately enabled and free from potential conflict of interest is assigned the responsibility to undertake the function. 6. From the operational point of view, banks may take certain measures as detailed below in order to ensure effective quick investigation, monitoring and follow up of frauds: The above operating unit should own specialized fraud monitoring, investigation and follow up function for large value frauds or frauds which occur across the bank. The function will have to be, therefore, discharged in a centralized manner instead of leaving it to the Regional Office where such specialization may not be available. Fraud investigation requires competence in 'forensic audit' and also technical / transactional expertise. In this regard, banks may take immediate steps to identify staff with proper aptitude and provide necessary training to them in forensic audit so that only such skilled staff are deployed for investigation of large value frauds. The banks may build up a data / information pool of large value frauds and analyse them periodically which may act as knowledge repository for policy responses. Detection of serious irregularities with systemic and system-wide implications, as also post facto "Fraud Investigation", gathering of information / data / evidences and creation of credible records that are useful for internal management action or legal prosecution against the 'wrong doers' require typical skills. The skills range from expertise in analysis of transaction through audit trail to competence in "forensic audit" supported by specialization in IT based data abstraction, data filtering and data sanitization. While banks may have certain manpower with such skills / competence / expertise, their systematic and organized utilization to detect serious irregularities and frauds has apparently not been ensured in many banks. In some banks, the above skills / competence / expertise are scarce or nearly absent. In view of the increasing incidence of frauds in banks, it is necessary that the banks set up dedicated and well organized "Special Surveillance and Investigation Function", which would, on continuous basis, exercise surveillance over potentially fraud prone areas and investigate into large value frauds with the help of skilled manpower for internal punitive action against the staff and external legal prosecution of the fraudsters and their abettors. 7. Given the thin line of difference between serious wrongdoings and frauds, the bank should immediately put in place an adequately enabled and efficient 'internal oversight framework' that can prevent the wrongdoings and take the punitive measures against the wrongdoers. Please acknowledge receipt. Yours faithfully, (P. K. Panda) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2009-10/159 · issued 16 Sep 2009. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (Chairmen and CEOs of all scheduled commercial banks (excluding RRBs), Audit Committees of the Board, Special Committees of the Board for monitoring large frauds, Fraud risk management and investigation teams, Branch-level operating staff handling retail and traditional banking products), your first concrete step on “RBI mandates CEO-led fraud risk management overhaul” is: “Review and update your bank's fraud risk management policy with board approval, ensuring CEO and Special Committee ownership of high-value fraud cases.” (RBI issued this 16 Sep 2009).

  1. Circular: RBI/2009-10/159 -- RBI mandates CEO-led fraud risk management overhaul
  2. Issued: 16 Sep 2009
  3. Action required: Review and update your bank's fraud risk management policy with board approval, ensuring CEO and Special Committee ownership of high-value fraud cases.
  4. Action required: Strengthen internal controls in retail segments (housing loans, credit cards, internet banking) and traditional areas (cash credit, export finance, guarantees, LCs) to prevent fraud.
  5. Action required: Ensure prompt and accurate reporting of all fraud cases to RBI and law enforcement, with clear accountability for delays or misreporting.
  6. Action required: Conduct a gap analysis of your current fraud investigation function against the governance framework outlined in the circular.
  7. Action required: Train operating staff to balance business targets with control standards, avoiding incentives that lower control quality.
  8. Owner: ____________ Target date: ____________
  9. Board/committee approval needed? Y / N
  10. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=5273&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗