Reserve Bank of India (All India Financial Institutions – Fraud Risk Management) Directions, 2026
UR
- Applies toAll India financial institutions
- StatusIn force
- ImportanceMUST READ
- IssuedJul 31, 2026
- Amendmentsnone tracked
- Length62 points in 4 sections · 6 min read
The four dates on this rule
- PublishedJul 31, 2026The day RBI put this document out.
- Starts to applyNot statedNot stated separately in this document. Read the rule itself before you assume a start date.
- Time to get readyNot statedCannot be worked out until the day it starts to apply is known.
- Last date to actNot statedNo date to act by was found in this document. Other dates may sit inside single paragraphs.
Kept in your browser only. Your desk
Show me the points for
Nothing is removed from the page.
Numbers to remember
| 21 days | The notice must give the person at least 21 days to reply. RBI Para 6(2) |
| three years | The Board must look at the fraud policy at least once in three years. RBI Para 7 |
| thirty days | The risk committee sets the time to examine an alert, preferably no more than thirty days. RBI Para 14 |
| ₹3 crore | An account of ₹3 crore or more, once red flagged, is reported on CRILC within seven days. RBI Para 22 |
| 180 days | Red flag to a final answer should take no more than 180 days. RBI Para 31 |
| 14 days | A fraud must be reported to RBI at once, and never later than 14 days from classification. RBI Para 49 |
| ₹5 crore | Title deeds for credit of ₹5 crore and above face a periodic legal audit until repayment. RBI Para 59 |
What it says
Chapter I. Preliminary
1. Fraud rules
This paper sets how all India financial institutions must handle fraud.
2. Start date
These Directions came into effect immediately upon issuance.
BankPulse example. There is no gap here between issue and effect. The Directions come into effect immediately upon issuance. A bank cannot wait for a separate start date, because there is none.
3. Who is covered
These Directions apply to every all India financial institution.
Chapter II. Governance and Oversight
Must know
1. Twenty-one days to reply
The notice must give the person at least 21 days to reply.
BankPulse example. Suppose the notice is served on 1 September. The person must be given at least 21 days to reply, so the reply is due no earlier than 22 September. A notice allowing 14 days would fall short.
2. Review it every three years
The Board must look at the fraud policy at least once in three years.
Do it
3. A Board policy on fraud
The Board must approve a fraud risk policy setting out who does what.
4. What the policy covers
The policy must cover prevention, early catching, enquiry, staff responsibility, watching, recovery and reporting of frauds.
5. Give the full grounds
The notice must set out every transaction and event the fraud finding rests on.
6. A reasoned order, served
A reasoned order must be served, setting out the facts, the reply and the reasons.
7. It reviews every case
That committee must review fraud cases, find the root cause and suggest fixes.
8. Board sets the money line
The Board decides the size of fraud case that must go to that committee.
9. Senior staff run the policy
Senior management must put the Board's fraud policy into practice.
10. Report cases upward
Senior management must place a regular review of frauds before the Board or its audit committee.
11. Take whistle blowers seriously
Whistle blower complaints about possible fraud must be examined and closed properly.
12. A team for fraud risk
A proper unit for fraud risk must sit inside the wider risk function.
13. A General Manager owns it
An officer of at least General Manager rank must own fraud watching and reporting.
Background
14. Weigh the outside director
A nominee or independent director is normally not in charge of the business, and that counts.
15. A committee on fraud
A special committee, headed by an independent director, oversees fraud work.
Chapter III. Early Detection of Frauds - Framework for Early Warning Signals and Red Flagging of Accounts
Must know
1. Thirty days to look
The risk committee sets the time to examine an alert, preferably no more than thirty days.
2. Three crore, seven days
An account of ₹3 crore or more, once red flagged, is reported on CRILC within seven days.
Do it
3. Early warning and red flags
There must be a framework for early warning signals and red flagging accounts.
4. Risk committee oversees it
The Board's risk committee must oversee how well that framework works.
5. It approves the signals
The risk committee must approve the warning signals used on loan accounts.
6. Test the framework
The warning framework must be validated so its results stay sound and steady.
7. Both kinds of signal
The warning system must use both numbers and judgement to be of use.
8. A data unit for it
A dedicated data and market intelligence unit must be set up, sized to the business.
9. Test the system often
The warning system must be tested from time to time to see that it works.
10. Watch mule accounts
Accounts that fail KYC and money mule accounts must be watched closely.
Background
11. An alert means a look
Every alert must lead to a check on whether the account should be red flagged.
Chapter IV. General Instructions
Must know
1. A hundred and eighty days
Red flag to a final answer should take no more than 180 days.
2. Longer must be explained
A case still red flagged past 180 days must go to the fraud committee with reasons.
3. Three crore goes to CVC
A public sector bank refers every fraud of ₹3 crore and above for a role check.
4. They must leave the room
Such executives must not sit in the meeting where their own conduct is weighed.
Do it
5. Audit a red flagged loan
A red flagged loan must be investigated by an external or internal audit.
6. Put the deadline in writing
The auditor's contract must fix a time to finish the audit and hand in the report.
7. Put the audit in writing
The loan agreement must allow such an audit once the account is red flagged.
8. Report the professionals
Third parties and professionals involved in a fraud must be reported to the banks' association.
9. Settle staff responsibility in time
Staff accountability must be examined and finished within a set time in every fraud case.
Background
10. A policy for outside auditors
A policy is needed on hiring outside auditors, covering their record and fitness.
11. Hear before you brand
Natural justice must be followed strictly before any account is called a fraud.
12. RBI looks at those too
Such cases are also open to supervisory review by RBI.
13. Group accounts get checked
Where one account is a fraud, group companies sharing a promoter are examined too.
14. Police action means red flag
If a law enforcement agency starts an enquiry, the account must be red flagged at once.
15. Public banks follow the CVC
A public sector bank examines staff accountability by the Central Vigilance Commission's rules.
16. The audit committee judges seniors
Where very senior executives are involved, the audit committee examines their part.
17. A person pulls firms in
Every firm a named person promotes or directs is treated as tied to him.
18. Lending after is a choice
After the bar ends, whether to lend again is the lender's own commercial call.
19. New owner, bar lifts
The bar stops applying to a firm once a rescue plan under the insolvency code is in place.
20. Not for the old owner
The bar stays on the old promoters and directors who ran the firm.
Chapter V. Reporting of Frauds to Law Enforcement Agencies
1. Name a police contact
A nodal officer must be named to report frauds to the law enforcement agencies.
2. Each lender may complain
In a consortium each member may file its own complaint for its own loss.
Chapter VI. Reporting to Reserve Bank of India
Must know
1. Fourteen days to report
A fraud must be reported to RBI at once, and never later than 14 days from classification.
2. Report the group entities
Frauds in group entities RBI does not supervise must be reported to RBI separately.
3. Do not name the innocent
People and firms not involved in the fraud must not appear in the report.
Do it
4. Use the fraud registry
Systems must make real use of the Central Fraud Registry for credit and fraud risk.
5. Blame the delay too
Staff accountability must also be fixed for delay in spotting or reporting a fraud.
6. Keep the closed papers
Details of every closed fraud case must be kept for the auditors to see.
Background
7. No monthly certificates now
The monthly fraud certificate, registry certificate and flash report are no longer needed.
8. Close only when done
A fraud case is closed only when the court or police case ends and staff responsibility is settled.
Chapter VII. Other Instructions
1. Five crore, legal audit
Title deeds for credit of ₹5 crore and above face a periodic legal audit until repayment.
2. Report before you sell
Where fraud is found, it must be reported to RBI before the account is sold.
3. Investigate before you sell
A loan account must be investigated for fraud before it is sold to another lender.
The same subject for other kinds of institution
The same subject for other kinds of institution.
Other RBI rules for all India financial institutions
RBI capital adequacy rules for all India financial institutions 2025
RBI credit bureau reporting rules for all India financial institutions 2025
RBI credit risk rules for all India financial institutions 2025
RBI customer service and fair conduct rules for all India financial institutions
RBI cyber security rules for all India financial institutions 2026
RBI exposure limit rules for all India financial institutions 2025
RBI financial services business rules for all India financial institutions 2025
RBI financial statement and disclosure rules for all India financial institutions
RBI income recognition and provisioning rules for all India financial institutions
RBI investment portfolio rules for all India financial institutions 2025
Every rule page on BankPulse · Questions bankers ask, answered