Forensic Scrutiny Findings: Fraud Prevention Guidelines for Banks
No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2010-11/555 · issued 31 May 2011 · ~2 min read
Quick answerRBI issued guidelines based on forensic scrutiny findings to strengthen fraud prevention frameworks. Banks must revamp policies for detection, reporting, and corrective action, focusing on high-risk areas like loan frauds, forged documents, and housekeeping gaps.
The rule, in the simplest words
Banks must have a clear plan with three parts: (1) find and tell about frauds, (2) fix what went wrong, and (3) stop future frauds and punish bad people.
Watch extra carefully for frauds in loans for houses, loans against things like stock in a warehouse, fake papers, and mistakes in bank records.
Banks must decide if a mistake was just an accident (negligence), a team effort to cheat (collusion), or a planned refusal to pay back (willful default), and report it the same way every time.
Train all staff on the new rules so they know how to spot and report frauds, especially in risky areas like fake letters of credit or over-invoicing exports.
How it plays out — a real example
A credit & lending officer in Indore reviews a suspicious housing loan file where the property value seems too high. Using the new three-track framework, she first flags it for detection, then works with the team to correct the loan amount, and finally reports the borrower for possible fraud if the documents are forged, ensuring consistent action across the bank.
What changed
RBI shared findings from forensic scrutinies at banks with large frauds, revealing weak, inconsistent policies for fraud detection and reporting. Banks are now advised to adopt a structured three-track framework covering detection, corrective action, and preventive/punitive measures. The circular also clarifies distinctions between negligence, collusion, and willful default.
What it means for you
Banks must overhaul their fraud management systems to ensure consistency in identifying and reporting frauds. Lenders need tighter controls in high-risk areas like housing loans, stock hypothecation, and export bills. The guidelines push for clearer differentiation between staff negligence and intentional fraud, impacting how banks handle willful default cases.
Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.
What banks were required to do at the time
Review and update fraud detection policies to align with RBI's three-track framework (detection, corrective action, preventive/punitive measures).
Implement stricter monitoring and controls in high-risk areas: loans against stock, housing loans, forged documents, over-invoicing, and housekeeping gaps.
Establish clear criteria to distinguish fraud from negligence, collusion, and willful default, ensuring consistent reporting to competent authorities.
Train staff on revised fraud identification and reporting procedures, focusing on typical fraud events and systemic weaknesses.
Who it affects
All Scheduled Commercial Banks (excluding RRBs), All India Select Financial Institutions, Bank fraud monitoring and compliance teams, Credit and loan sanction departments
❓ Common questions
Regulatory timeline
Decoded by BankPulse2026-06-19 01:16 IST
repealed_by — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
What triggered these fraud prevention guidelines?
RBI conducted forensic scrutinies at banks with large frauds or rising fraud numbers, identifying policy gaps and control weaknesses. The guidelines aim to address these systemic issues.
What are the key areas of fraud recurrence highlighted?
Common fraud areas include loans against stock hypothecation, housing loan frauds, forged documents (e.g., LCs, FDRs), property overvaluation, export bill over-invoicing, and housekeeping deficiencies.
How should banks differentiate willful default from fraud?
Willful default occurs when a borrower has capacity to pay but defaults, diverts funds, siphons off funds, or disposes of collateral. Banks must separate this from staff negligence or collusion in fraud cases.
📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Repealed byRBI/2025-26/100 — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
RBI’s words: “Official withdrawal register entry #121: DBS.CO.FrMC.BC.No.10/23.04.001/2010-11 — "Findings of Forensic Scrutiny - Guidelines for prevention of frauds" dated May 31, 2011”
📜 Read the original circular — full text as issued by RBI
RBI/2010-11/555
DBS. CO.FrMC.BC.No. 10/23.04.001/2010-11
May 31, 2011
The Chairmen & Chief Executive Officers of
All Scheduled Commercial Banks (excluding RRBs) and
All India Select Financial Institutions
Dear Sir,
Findings of Forensic Scrutiny- Guidelines for prevention of frauds
In the recent past, we had conducted forensic scrutinies at certain identified banks due to occurrence of large value frauds or sharp increase in number of frauds at such banks. The scrutinies were undertaken to primarily identify the policy gaps, if any, and adequacy of controls. During the scrutinies, systemic factors were also sought to be identified.
2. Based on the findings of the scrutinies, further study has been made across banks to ascertain the policy and operating framework in place for detection, reporting and monitoring of frauds as also the surveillance/ oversight process in operation so as to prevent the perpetration of frauds. The study has shown that while the banks do have certain policies and processes in this regard, they are not well structured and systematic to ensure proper focus on typical fraud events. Besides, there is lack of consistency in treatment of such transactions having characteristics of fraud as also in their reporting to the “Competent Authority”. The banks are, therefore, advised to suitably modify their policy and streamline the operating framework in the matter keeping in view certain indicative guidelines set out below :
3. The reported frauds show recurrence or rising trend in the following areas :-
loans/ advances against hypothecation of stocks
housing loans cases
submission of forged documents including letters of credit
escalation of overall cost of the property to obtain higher loan amount
over valuation of mortgaged properties at the time of sanction
grant of loans against forged FDRs
over-invoicing of export bills resulting in concessional bank finance , exemptions from various duties etc.
frauds stemming from housekeeping deficiencies
The above list is only illustrative and not exhaustive.
The banks need to introduce closer monitoring and tighter controls in the above areas, as also in other such areas where there is typically certain degree of concentration of occurrence. In this connection, select list of circulars issued by RBI in the past in respect of frauds in the above areas is enclosed as Annex .
4. The operating framework for tracking frauds and dealing with them should be structured along the following three tracks:
(i) Detection and reporting of frauds
(ii) Corrective action and
(iii) Preventive and punitive action
Detection and reporting : The banks should have a set of prescribed procedures and criteria with which the events or transactions having serious irregularities are analysed and assessed to establish occurrence of fraud.
For this purpose, the banks may define a ‘fraud’ based on the guidelines issued by RBI. While doing so, they may clearly demarcate/ distinguish the occurrence of an event on account of negligence ‘in conduct of duty’ from ‘collusion’ by the bank staff (with the borrowers and with an intention to cheat the bank). Further, care may be exercised while dealing with instances of ‘willful default’. In this connection, a willful default would be deemed to have occurred if any of the following events is noted:
(a) The unit has defaulted in meeting its payment / repayment obligations to the lender even when it has the capacity to honour the said obligations.
(b) The unit has defaulted in meeting its payment / repayment obligations tothe lender and has not utilised the finance from the lender for the specific purposes for which finance was availed of but has diverted the funds for other purposes.
(c) The unit has defaulted in meeting its payment / repayment obligations to the lender and has siphoned off the funds so that the funds have not been utilised for the specific purpose for which finance was availed of, nor are the funds available with the unit in the form of other assets.
(d) The unit has defaulted in meeting its payment / repayment obligations to the lender and has also disposed off or removed the movable fixed assets or immovable property given by him or it for the purpose of securing a term loan without the knowledge of the bank / lender.
Further, the banks may also examine the ‘ intent ’ to defraud, irrespective of whether or not actual loss takes place. Keeping these key factors in mind, any action taken in collusion to derive undue/ unjust benefit or advantage should be termed as fraud.
Following such a protocol of identification, once a fraud is detected, a report must be prepared and submitted to the “Competent Authority”. As a part of their overall policy and operating framework, the banks should identify and designate the Competent Authority to whom such reports should be submitted. The fraud report should be a diagnostic assessment, clearly bringing out the causes of the fraud and identify whether the fraud occurred due to ‘system failure’ or ‘human failure’.
Corrective Action : An important corrective step in a fraud is recovery of the amount siphoned off through the fraud. Often, during course of investigation and enquiry into the events/ transactions, the need to track the flow of defrauded amount does not get due priority or the exercise undertaken in that direction does not lead to material results. This may be primarily attributable to the following : -
The lack of ability on the part of the operating staff to sift through the layered/ interlocked transactions, determine the ultimate destination of the defrauded amounts and track the investment of the amounts in assets/ properties and/ or use of the amounts for the expenditures.
In case where the operating staff is not in a position to do it, because of complexities involved, considerable time is spent in undertaking this type of investigation and often the task is completed in a routine manner.
A structured scrutiny/ examination of events or transactions would lead to quick conclusion whether a fraud has occurred and the bank’s funds have been siphoned off. Therefore, this exercise is the first critical step towards corrective action in the sense that it would lead to expeditious filing of police complaints, blocking/ freezing of accounts and salvaging funds from the blocked/ frozen accounts in due course. Besides, once a set of transactions is explicitly identified as fraudulent, the mandate for seizing and taking possession of related documents, issuance of suspension order/ order to proceed on leave to identified/ suspected employees would be easier thereby preventing them from destroying/ manipulating evidences or obstruction of investigations. In this connection, attention is invited to our circular DBS.CO. FrMC.BC.No. 7/23.04.001/2009-10 dated September 16, 2009 wherein it has been advised that they should provide singular focus on the “Fraud Prevention and Management Function” to enable among others, effective investigation in fraud cases and prompt as well as accurate reporting of fraud cases to appropriate regulatory and law enforcement agencies.
Preventive and Punitive Action : As per the diagnostic analysis, preventive action as deemed necessary to address the ‘system failure’ and/ or punitive action as prescribed internally for ‘human failure’ should be initiated immediately and completed expeditiously.
Generally, in the current system driven environment in banks, wherever transactions occur in breach of/ overriding “ Controls ”, they get reflected in the “end of day exception report”. Accordingly, all such exception reports should be perused by the designated officials and a post facto authorization for the transactions accorded. However, it has been observed in certain cases that the process often does not get duly implemented reflecting the poor internal control mechanisms. Therefore, banks should ensure that they bring in the needed refinement in this process and also specify the levels/ authority to whom the exception reports will be invariably submitted and the manner in which the authority will deal with the exception reports. The entire gamut of the manner in which the exception reports are generated, transactions contained in the reports are examined/ scrutinised, and the reports submitted to higher authorities for necessary authorizations for breaches should be periodically subjected to review and oversight by the bank’s management/ Board of Directors.
5. In addition to the above, banks should immediately take steps to put in place following controls and disincentives in their HR processes and internal inspection/ audit processes as part of their fraud risk management framework :
For key and sensitive posts such as those in dealing rooms, treasury, relationship managers for high value customers, heads of specialized branches, etc. the banks should select only such officers who satisfy the “Fit and Proper” criteria. For the purpose, the banks should draw up a list of critical as well as sensitive positions or areas of operation and evolve well defined “Fit and Proper” criteria for applying them to determine the suitability of the staff/ officers to those posts/ areas of operations. The appropriateness of such postings should be subjected to periodical review.
The banks should immediately put in place “staff rotation” policy and policy for “mandatory leave” for staff. The internal auditors as also the concurrent auditors must be specifically required to examine the implementation of these policies and point out instances of breaches irrespective of apparent justifications for non-compliance, if any. The decisions taken / transactions effected by officers and staff not rotated/ availing leave as per policy should be subjected to comprehensive examination by the internal auditors/ inspectors including concurrent auditors. The findings thereon should be documented in a separate section of the audit/ inspection reports.
The banks should build up a database of officers/ staff identified as those having aptitude for investigation, data analysis, forensic analysis, etc. and expose them to appropriate training in investigations and forensic audit. For investigation of frauds, only such officers/ staff should be deployed through the “fraud investigation unit/ outfit”.
6. Please acknowledge receipt .
Yours faithfully,
(A.Madasamy )
Chief General Manager
Annex
2011
Date
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2010-11/555 · issued 31 May 2011. The plain-English explanation above is BankPulse’s own independent summary.
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6449&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.