Why in News?
The Reserve Bank of India (RBI) has finalised a revised framework on limiting customer liability in fraudulent electronic banking transactions (EBTs), introducing a one-time compensation mechanism for small-value digital fraud. A bona fide individual or sole proprietor who suffers a loss of up to ₹50,000 can recover 85% of the net loss, or ₹25,000, whichever is lower — once in a lifetime.
Originally slated for 1 July 2026, the directions were deferred by six months to 1 January 2027 to let banks upgrade their systems, and apply to transactions undertaken on or after that date. The central bank will bear the major share of the payout, and critically, the burden of proving customer negligence now lies with the bank, not the customer — a genuine structural shift in consumer protection.
The reform lands amid a noisy data backdrop. The RBI's FY26 Annual Report shows total bank-fraud value rising to ₹48,021 crore even as the number of cases fell sharply — but that surge is driven by loans and advances, not digital payments. The episode is a textbook GS-3 case on cyber security, the digital economy and consumer rights, and a Mains lesson in reading statistics carefully.
Key Takeaways
The 85% / ₹25,000 Formula
Compensation is 85% of the net loss (after any recovery) or ₹25,000, whichever is lower. Below a net loss of ₹29,412 the 85% rule applies in full; at or above it, the ₹25,000 cap bites. The benefit is one-time per customer.
Five-Day Reporting Window
To qualify, the victim must report the fraud to both the bank and the National Cyber Crime Reporting Portal / Helpline 1930 within five calendar days of the transaction. Prompt reporting also triggers zero-liability protection for third-party breaches.
Burden of Proof Shifts
The bank must now prove customer liability to deny relief. Customers retain zero liability where loss arises from the bank's negligence, deficiency, system failure or internal fraud — regardless of when it is reported.
Tougher Bank Obligations
Banks must send instant SMS alerts for every EBT above ₹500, offer 24×7 reporting channels, give a complaint number with timestamp, issue a shadow reversal within 5 days for disputed card transactions, and resolve cases in 45 days (domestic) / 60 days (cross-border).
RBI Bears the Major Share
For losses below ₹29,412, the RBI funds 65% and the remitting and beneficiary banks 10% each. In the capped band the RBI pays ₹19,118 and each bank ₹2,941 — making the scheme strongly pro-consumer.
The Coverage Gap
Relief is confined to losses up to ₹50,000; victims of large-value scams get nothing under these directions. With an estimated ₹22,495 crore lost to cyber fraud in 2025 and 2.81 million complaints, critics call the ceiling modest relative to the problem.
UPSC GS-3 Metadata
Quick Facts Box
- RBI's revised EBT compensation framework is effective 1 January 2027 (deferred from 1 July 2026).
- Victims can recover 85% of net loss or ₹25,000, whichever is lower, for losses up to ₹50,000.
- The benefit is available once in a lifetime for bona fide individuals and sole proprietors.
- Fraud must be reported to the bank and Helpline 1930 / NCRP within 5 calendar days.
- Below a net loss of ₹29,412, full 85% applies; above it the ₹25,000 cap operates.
- The RBI funds 65% (₹19,118 in the capped band); remitting and beneficiary banks share the rest.
- Burden of proof of customer negligence now rests on the bank.
- Banks must resolve complaints in 45 days (domestic), 60 days (cross-border).
- Mandatory SMS alerts for every EBT above ₹500; alerts ≤₹500 are optional.
- Banks must give a shadow reversal within 5 days for disputed card transactions.
- FY26 total bank fraud value rose 46.4% to ₹48,021 crore; cases fell 57.4% to 10,114.
- That surge was driven by loans & advances (~85%) and re-classified legacy cases — not digital payments.
- RBI-reported card/internet/digital-payment fraud fell to 293 cases / ₹29 crore in FY26.
- I4C blocked 1,700+ Skype IDs, 59,000 WhatsApp accounts, 6.69 lakh SIMs, 1.32 lakh IMEIs (to 15 Nov 2024).
- The Citizen Financial Cyber Fraud Reporting System saved ₹3,431 crore across 9.94 lakh complaints.
Evolution of Customer Protection in Digital Banking
Reading the Numbers — Total Fraud vs Digital Fraud
The Headline (Easily Misread)
Total bank fraud, FY26: ₹48,021 crore — up 46.4% from ₹32,803 crore in FY25.
- Cases fell 57.4% to 10,114 (from 23,722).
- ~85% of the value was in loans & advances (₹40,774 crore).
- 314 legacy cases worth ₹30,199 crore — old frauds re-classified after a March 2023 Supreme Court ruling — inflate the figure.
- Public-sector banks accounted for 74.5% of the value.
Trap: ₹48,021 crore is not the digital-fraud number.
The Digital Reality
RBI-reported card/internet/digital-payment fraud, FY26: just 293 cases / ₹29 crore.
- Down from 13,332 cases (₹517 crore) in FY25 and 28,836 (₹1,452 crore) in FY24.
- Share of cases fell from 80.4% (FY24) to 2.9% (FY26).
- But this counts only frauds of ₹1 lakh and above reported by banks.
- Citizen-reported cyber fraud tells a harsher story: ~₹22,495 crore lost in 2025 across 2.81 million complaints.
Takeaway: small-value retail fraud is widespread — exactly what the new framework targets.
Constitutional & Legal Foundations
RBI Act, 1934
Establishes the RBI and its powers to regulate banking and the monetary system — the source of authority for directions binding on commercial banks.
PSS Act, 2007
The Payment and Settlement Systems Act lets RBI authorise and supervise payment systems and define an "electronic banking transaction", including card-present and card-not-present modes.
IT Act, 2000
Provides the cybercrime, data-security and intermediary framework; rules under it make reporting of cyber-security incidents to CERT-In legally mandatory for specified entities.
Consumer Protection Act, 2019
Codifies the rights to safety, information and redressal, covers electronic and banking services, creates the CCPA and introduces product liability — strengthening recourse for fraud victims.
Article 21 & DPSP
Article 21's right to life, read with privacy (Puttaswamy, 2017), extends to secure financial data; Directive Principles task the State with promoting economic welfare and protecting the vulnerable.
FATF Standards
Financial Action Task Force recommendations on anti-money-laundering and counter-terror-financing shape India's insistence on traceable, accountable digital-payment channels.
Key UPSC Facts & Figures
India's Cyber-Fraud Response Architecture
RBI EBT Compensation Framework, 2027
Overview: Revised directions limiting customer liability for fraudulent electronic banking transactions, applicable to commercial-bank customers.
Key Features
- 85% / ₹25,000 one-time compensation up to ₹50,000.
- Burden of proof on banks; zero liability for bank negligence.
- SMS alerts >₹500, 24×7 channels, shadow reversal in 5 days.
- 45/60-day resolution; compensation paid within 5 days of a complete application.
Significance
Reduces the financial shock on small users and forces banks to internalise security costs.
Indian Cyber Crime Coordination Centre (I4C)
Overview: The Ministry of Home Affairs' nodal mechanism to coordinate India's response to all forms of cybercrime.
Functions & Wins
- Coordination among states, central agencies, banks and telcos.
- Blocked 1,700+ Skype IDs, 59,000 WhatsApp accounts, 6.69 lakh SIMs, 1.32 lakh IMEIs.
- Runs the CyberDost awareness outreach and capacity-building.
- Launched a Suspect Registry and "Report & Check Suspect" on cybercrime.gov.in.
Significance
Converts scattered policing into a single, data-driven national response.
Citizen Financial Cyber Fraud Reporting System & 1930
Overview: A 2021 platform under I4C enabling immediate reporting and rapid freezing of funds in transit.
What It Does
- Toll-free helpline 1930 and the National Cyber Crime Reporting Portal.
- Real-time alerts to banks/wallets to halt fraudulent transfers.
- Saved ₹3,431 crore across 9.94 lakh+ complaints.
Why It Matters
The five-day reporting window in RBI's framework plugs directly into this channel — speed is everything.
CFMC, MuleHunter & Telecom Shields
Overview: A cluster of newer tools hardening the system against mule accounts and spoofing.
Components
- Cyber Fraud Mitigation Centre (CFMC) at I4C — co-located banks, PSPs, telcos, LEAs.
- MuleHunter.AI (RBIH) — AI detection of money-mule accounts.
- System to block international spoofed calls showing Indian numbers.
- Cyber Range at IDRBT for simulated cyber-drill exercises.
Significance
Shifts the posture from post-fraud redressal to upstream prevention.
The Supporting Ecosystem
Digital India & UPI
The Digital India Programme and UPI/Aadhaar-enabled payments power inclusion but make robust fraud-protection essential to sustain public trust.
PMJDY & Inclusion
Pradhan Mantri Jan Dhan Yojana brought crores of first-time users into formal banking — a population especially vulnerable to scams and central to the framework's intent.
International Cooperation
UNODC guidance, FATF standards and bilateral cyber pacts with the US, UK and EU support cross-border investigation and information-sharing.
Quality Quotes (for Mains/Essay)
1. "The burden of proving customer liability in complaints involving fraudulent EBTs shall lie on the bank." — RBI revised directions, 2026.
2. "Trust is the currency of the digital economy." — a widely used aphorism in fintech and policy discourse.
3. "Citizens must be protected, not just policed" — the spirit animating victim-centric reforms like the 1930 helpline and the compensation framework.
UPSC Prelims Practice — 10 Questions
Covers the 2027 compensation framework, the cost-sharing structure, the total-vs-digital fraud distinction, I4C and CERT-In, and two PYQ-pattern cyber questions. Tap any option for instant feedback, then open the explanation.
Under RBI's revised framework, a bona fide victim reporting a fraudulent EBT with a net loss up to ₹50,000 within five days can receive compensation of:
The framework provides 85% of the net loss (after any amount already recovered) or ₹25,000, whichever is lower, for net losses up to ₹50,000, available once in a lifetime to individuals and sole proprietors. Below a net loss of ₹29,412 the 85% rule applies fully; at or above it the ₹25,000 cap operates. The other percentages and caps are not part of the notified directions.
The revised RBI compensation framework for fraudulent electronic banking transactions comes into effect from:
The directions were originally to apply from 1 July 2026 but were deferred by six months to 1 January 2027 to give banks time to align their systems. They apply to electronic banking transactions undertaken on or after that date. The other dates are distractors.
With reference to the framework, consider the following statements:
2. Banks must send SMS alerts for every electronic banking transaction above ₹500.
3. The compensation may be claimed by a customer multiple times in a year.
Which of the statements given above are correct?
1 ✓: A core reform is the shift of the burden of proof onto the bank.
2 ✓: Instant SMS alerts are mandatory for every EBT above ₹500 (alerts ≤₹500 are optional).
3 ✗: The compensation is a once-in-a-lifetime benefit, not a repeated annual claim.
As per the RBI's FY26 Annual Report, the sharp rise in the value of total bank fraud to ₹48,021 crore was driven primarily by:
Roughly 85% of the FY26 fraud value was in advances (₹40,774 crore), concentrated in public-sector banks, and the figure was inflated by 314 legacy cases (₹30,199 crore) re-classified after a March 2023 Supreme Court judgement. Notably, RBI-reported digital-payment fraud actually fell to just 293 cases / ₹29 crore. Conflating the headline number with digital fraud is a common error.
The Indian Cyber Crime Coordination Centre (I4C) functions under which Ministry?
I4C operates under the Ministry of Home Affairs to coordinate the national response to cybercrime. A frequent confusion is with CERT-In (the national agency for cyber-security incident response, under MeitY) — keep the two distinct.
In 2024, as part of anti-cybercrime efforts, the government reported blocking which of the following?
2. WhatsApp accounts
3. SIM cards
4. IMEIs
Select the correct answer using the codes given below:
To 15 November 2024, the government reported blocking over 1,700 Skype IDs, 59,000 WhatsApp accounts, 6.69 lakh SIM cards and 1.32 lakh IMEIs linked to digital fraud and "digital arrest" scams. All four categories are correct.
Match Column I with Column II:
A. RBI 1. Regulates payments; issues the compensation framework
B. I4C 2. Coordinates the national response to cybercrime
C. CERT-In 3. National agency for cyber-security incidents
D. UIDAI 4. Issues Aadhaar; enables Aadhaar-based payments
Select the correct match:
RBI regulates payment systems and issued the EBT compensation framework; I4C (MHA) coordinates the cybercrime response; CERT-In (MeitY) is the national incident-response agency; UIDAI issues Aadhaar and underpins Aadhaar-enabled payments.
In India, it is legally mandatory for which of the following to report cyber-security incidents?
2. Data centres
3. Body corporate
Select the correct answer using the code given below:
This is the UPSC Prelims 2017 question. Under the rules framed pursuant to the IT Act, 2000, service providers, intermediaries, data centres and body corporate are all required to report cyber-security incidents to CERT-In. All three listed entities qualify.
Under cyber-insurance for individuals in India, which of the following are generally covered, in addition to payment for the loss of funds and other benefits?
2. Cost of a new computer if some miscreant wilfully damages it, if proved so.
3. Cost of hiring a specialised consultant in case of cyber-extortion.
4. Cost of defence in a court of law if sued by a third party.
Select the correct answer using the code given below:
This is the UPSC Prelims 2020 question. Cyber-insurance for individuals typically covers system restoration (1), consultant costs for extortion (3) and third-party legal defence (4). The cost of a new computer for wilful physical damage (2) is not ordinarily covered.
Assertion (A): RBI's revised compensation framework for digital fraud victims is a pro-consumer measure.
Reason (R): It shifts the burden of proof to banks and incentivises them to strengthen security.
Both statements are true and R explains A. By placing the burden of proof on banks and tying liability to negligence (weak alerts, no 24×7 channels, system failures), the framework incentivises better security — which is precisely what makes it pro-consumer. The cost-sharing design, with the RBI bearing the major share, reinforces the consumer-first orientation.
Model Question — GS-3 (15 Marks, ~250 words)
"RBI's revised compensation framework for victims of digital payment fraud marks a significant step in safeguarding India's digital economy." Critically examine its implications for consumer protection and cyber security.
Marks Breakdown
Introduction
The Reserve Bank of India's revised directions on customer liability in fraudulent electronic banking transactions (effective 1 January 2027) introduce a one-time compensation of 85% of net loss or ₹25,000 for losses up to ₹50,000, and — crucially — shift the burden of proving customer negligence onto banks. Framed as a consumer-protection and cyber-resilience measure, the reform reshapes the bank–customer relationship in a fast-digitising economy.
The Consumer-Protection Gains
- Reduced financial shock: small-value victims — often first-time, rural or elderly users — recover a meaningful share, advancing financial inclusion.
- Rights reinforced: the move operationalises the Consumer Protection Act, 2019 rights to safety, information and redressal.
- Time-bound certainty: a five-day reporting window plus 45/60-day resolution and a five-day shadow reversal reduce limbo.
- Cost mutualised: the RBI bears the major share, signalling systemic responsibility rather than placing the loss solely on the victim.
The Cyber-Security Incentives
- Skin in the game: tying liability to negligence — weak alerts, missing 24×7 channels, system failures — pushes banks to invest in authentication and monitoring.
- Ecosystem linkage: the framework dovetails with I4C, the 1930 helpline, the CFMC and tools like MuleHunter.AI to freeze funds and trace mules.
- Behavioural nudge: mandatory alerts above ₹500 sharpen early detection by customers themselves.
Limitations & Critique
The ₹50,000 ceiling leaves victims of large-value scams without recourse under these directions — a real gap given an estimated ₹22,495 crore lost to cyber fraud in 2025 across 2.81 million complaints. "Negligence" remains contestable, the digital divide impedes timely reporting, and a once-in-a-lifetime cap may under-protect repeat victims. Enforcement against smaller banks and cross-border tracing stay hard.
Way Forward & Conclusion
A maturing regime would periodically revise the cap for inflation and fraud trends, codify clear negligence standards with an appeal path, mandate tiered minimum security protocols, and deepen assisted-reporting for the digitally excluded. Consumer protection and cyber security are not rivals but reinforcing goals: by mutualising small-value risk while hardening institutional accountability, the framework strengthens the trust on which India's digital economy ultimately rests.
Value Addition
- Framework data: 85% / ₹25,000 up to ₹50,000 · RBI bears 65% (₹19,118 in capped band) · 5-day reporting · 45/60-day resolution · ₹500 alert threshold.
- Fraud data: total bank fraud FY26 ₹48,021 cr (mostly advances) · digital-payment fraud 293 cases/₹29 cr · ~₹22,495 cr cyber-fraud losses (2025).
- Institutions: I4C (MHA) · CERT-In (MeitY) · CFMC · 1930 helpline · MuleHunter.AI (RBIH) · Cyber Range (IDRBT).
- Legal: RBI Act 1934 · PSS Act 2007 · IT Act 2000 · Consumer Protection Act 2019 · Article 21 read with Puttaswamy (2017).
- Reports/Indices: RBI Annual Report & Digital Payments Index · Global Cybersecurity Index · Economic Survey (digital economy).
- Global frames: US Reg E · UK Contingent Reimbursement Model · EU PSD2 strong customer authentication · FATF NPO standards.
Relevant UPSC PYQs
GS-3, 2022: "What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy." — directly maps to I4C and this framework.
GS-3, 2017: "Discuss the potential threats of cyber attack and the security framework to prevent it." — provides the institutional scaffolding for the answer.
GS-2, 2020: "There is a need for simplification of procedure for disqualification of persons found guilty of corrupt practices…" — connects to due-process and accountability arguments relevant to dispute resolution.
More Mains Angles (Multi-GS)
GS-3 · Economy
Examine the trust–inclusion link: predictable redressal lowers the "fear cost" of digital payments and sustains UPI-led formalisation, while compliance costs and mule-account risks fall hardest on small banks and fintechs. Argue for tiered, capacity-building obligations.
GS-4 · Ethics
Discuss the duty of care and procedural fairness. Shifting the burden of proof embodies the ethic that the stronger party (the bank) should bear the risk it is best placed to manage; victim-blaming without evidence violates fairness and erodes institutional trust.
GS-3 · Internal Security
Analyse fraud proceeds as a feeder for money-laundering and terror-financing. Traceable channels, the CFMC and FATF-aligned monitoring are legitimate, but must pair with due process so security does not crowd out civil liberties.
GS-2 · Governance
Evaluate citizen-centric governance: the 1930 helpline and one-window reporting show service delivery improving, yet the digital divide demands assisted access via CSCs and post offices so the most vulnerable are not excluded from redress.
Essay Tips for This Theme
Anchor the essay in a historical sweep (cash → UPI → cyber fraud → victim-centric regulation); deploy precise data (₹22,495 cr losses; 85%/₹25,000 relief); engage theory (trust as social capital — Putnam, Fukuyama; the State's protective duty); and resolve toward a balance of inclusion, security and dignity rather than a technology-versus-risk binary.
Thesis
A digital economy runs not on bandwidth but on belief; every transaction is an act of trust, and the State's task is to make that trust rational rather than reckless.
Opening Hook
"Money is a matter of belief — and the digital rupee asks us to believe at the speed of a tap." When that belief is betrayed by fraud, the whole edifice wobbles.
Body Structure
- Part I: From physical trust (signatures, cash) to coded trust (UPI, tokens).
- Part II: The fraud shock — phishing, vishing, mule accounts, the ₹22,495 cr leakage.
- Part III: Rebuilding trust — RBI's compensation framework, the 1930 helpline, I4C.
- Part IV: Trust as infrastructure — predictable rules lower the cost of participation.
Counterargument
"Compensation breeds carelessness." Concede the moral-hazard risk, then show the once-in-a-lifetime cap and negligence tests calibrate protection without inviting recklessness.
Conclusion
Trust nurtured through accountability endures; trust taken for granted erodes. A confident digital nation invests in both security and redress.
Thesis
Firewalls fail where institutions are fragmented; cyber security is ultimately a test of coordination, accountability and law — not of code alone.
Opening Hook
"The weakest link in any system is rarely the silicon; it is the seam between agencies." India's fraud fight is a story of stitching those seams.
Body Structure
- Governance lens: who is responsible — RBI, MHA, telcos, banks, the citizen?
- The coordination turn: I4C, CFMC, suspect registries, the 1930 channel.
- Accountability via regulation: burden of proof, alerts, resolution timelines.
- The privacy guardrail: data-sharing for security must respect Puttaswamy.
Conclusion
Secure systems are governed systems — clear duties, swift coordination and rights-respecting oversight matter more than any single technology.
Thesis
Inclusion without protection is a trap; protection without inclusion is a privilege. The goal is a floor of safety beneath every new user.
Opening Hook
"We invited millions onto the digital highway; we owe them seatbelts." PMJDY and UPI opened the road — safety must keep pace.
Body Structure
- The inclusion surge: Jan Dhan, UPI, Aadhaar-enabled payments.
- The vulnerability of the newly included — low digital literacy, high trust.
- Protective design: the ₹50,000 floor, alerts, assisted reporting.
- Bridging the divide: CSCs, post offices, vernacular awareness.
Conclusion
Inclusive security — safety designed for the least-equipped user — is the true measure of a humane digital state.
Thesis
The social contract migrates online: a State that issues digital rails must also guard those who travel on them.
Opening Hook
"Every new power the State grants itself in the digital realm is also a new duty." Enabling payments creates an obligation to protect payers.
Body Structure
- The protective State: from consumer law to cyber-fraud redress.
- Rights and remedies: Article 21, privacy, the CPA 2019.
- Instruments: RBI directions, I4C, helplines, telecom shields.
- Balancing freedom, security and privacy.
Conclusion
A rights-based, accountable State turns digital power into public good — protection is the price and proof of legitimacy.
Thesis
Each leap in the form of money — barter, coin, note, code — buys convenience at the price of new vulnerabilities; wisdom lies in pricing that risk honestly.
Opening Hook
"We dematerialised money and, with it, dematerialised theft." The pickpocket became a phisher; the vault became a server.
Body Structure
- The long arc: barter → cash → cards → UPI → CBDC.
- New discontents: anonymity, speed, scale of fraud.
- Regulatory response: compensation, traceability, the e-rupee pilot.
- Ethical design: security, privacy and dignity by default.
Conclusion
Money's future is code — and code, well-governed, can be both efficient and just.
Additional Essay Angles
Risk-Mutualisation as Social Insurance
Can a regulator-funded compensation pool act like social insurance for the digital age — spreading small-value risk so no single user is ruined? What are its limits and incentives?
AI: Both Weapon and Shield
Deepfakes and AI-driven social engineering escalate fraud, while AI fraud-detection and mule-hunting defend against it. How should regulation manage this arms race ethically?
Transparency vs Surveillance
Traceability fights fraud but disclosure can curdle into surveillance. Where should the line sit between accountability and the citizen's right to privacy?
UPSC Personality Test Preparation
Questions here test your factual precision (the 85%/₹25,000 formula, who runs I4C), your ability to read data critically (total vs digital fraud), and your judgment in balancing consumer protection, security and privacy. The Board values calibrated, evidence-based answers over slogans.
The framework, effective 1 January 2027, offers a bona fide individual or sole proprietor compensation of 85% of the net loss or ₹25,000, whichever is lower, for losses up to ₹50,000 — once in a lifetime. To qualify, the victim must report the fraud to both the bank and the National Cyber Crime Reporting Portal or helpline 1930 within five calendar days.
Its most significant element, in my view, is structural rather than monetary: the burden of proving customer negligence now rests with the bank, and the RBI itself bears the major share of the payout. Banks must also resolve complaints within 45 days (domestic) or 60 days (cross-border) and provide shadow reversals for disputed card transactions. Together these shift responsibility toward the institution best placed to manage risk.
It would be a misreading to say so. The ₹48,021 crore figure in the RBI's FY26 Annual Report is total bank fraud, and around 85% of that value sits in loans and advances, concentrated in public-sector banks. The number was further inflated by 314 legacy cases worth ₹30,199 crore re-classified after a 2023 Supreme Court ruling.
Digital-payment fraud reported by banks actually fell sharply — to about 293 cases and ₹29 crore. That said, the bank-reported series counts only frauds of ₹1 lakh and above, so it understates retail harm. Citizen-reported data tells a tougher story: roughly ₹22,495 crore lost to cyber fraud in 2025 across 2.81 million complaints. So the honest answer is: high-value loan fraud drives the headline, while small-value retail cyber fraud — the very thing the new framework targets — remains widespread.
I think it is both fair and sensible. The ethical principle is that risk should fall on the party best able to prevent and absorb it. A bank controls the authentication systems, fraud-monitoring tools and alert infrastructure; an ordinary customer controls very little of the technical chain. Asking the customer to prove a negative — that they were not negligent — often left genuine victims without recourse.
Placing the onus on banks also creates the right incentive: institutions now have "skin in the game" to invest in security, because weak alerts or absent 24×7 channels translate directly into liability. There is a moral-hazard counterpoint, but the once-in-a-lifetime cap and the negligence test keep it in check. On balance, it corrects a long-standing power asymmetry in favour of the consumer.
The Indian Cyber Crime Coordination Centre, under the Ministry of Home Affairs, provides a coordinated national response to cybercrime — linking state police, central agencies, banks and telecom operators. It runs the Citizen Financial Cyber Fraud Reporting System and the 1930 helpline, which together have helped save over ₹3,431 crore by freezing funds in transit, and it has blocked lakhs of fraudulent SIMs, IMEIs and accounts. Newer additions include the Cyber Fraud Mitigation Centre and a suspect registry.
CERT-In is different. It is the national agency for cyber-security incident response — handling threats, vulnerabilities and breaches — and functions under MeitY, with statutory backing from the IT Act. In short: I4C is crime-and-coordination focused under MHA; CERT-In is incident-and-infrastructure focused under MeitY. Keeping the two distinct is important both analytically and for Prelims.
There is a genuine case on both sides. In favour: large-value frauds can be devastating — wiping out savings — and the ₹50,000 ceiling leaves such victims without recourse under these directions, which feels inadequate against ₹22,495 crore of annual losses. Against: a high or open-ended cap raises moral hazard, imposes large contingent costs on the system, and could divert protection from the small users who most need a floor.
My calibrated view is to retain a focused floor for small-value fraud but build in a periodic review of the cap, indexed to inflation and fraud trends, and complement it with promoted cyber-insurance for higher-value exposure and SMEs. Protection should be layered: a guaranteed public floor plus market instruments above it, rather than one cap trying to do everything.
Several. First, procedural fairness — investigate promptly and impartially, and never resort to victim-blaming without evidence, especially now that the burden of proof lies with the bank. Second, transparency — give the customer a complaint number, a timestamp and clear reasons for any decision, with an accessible escalation path to the Ombudsman.
Third, data protection — fraud handling involves sensitive financial data, which must be safeguarded consistent with privacy principles from Puttaswamy. Fourth, empathy and accessibility — many victims are elderly or first-time users in distress, so processes should be humane and available in vernacular languages. Ultimately the guiding ethic is a duty of care: the institution holds the power and the information, and with that comes responsibility.
My immediate priority would be harm reduction and rapid recovery. I would publicise the 1930 helpline and the five-day reporting window aggressively — through banks, panchayats, SHGs, post offices and local media — so victims act fast enough to freeze funds. I would coordinate with the district's lead bank and the cyber cell to ensure complaints are registered and escalated without friction.
In parallel, I would invest in prevention tailored to the elderly: simple vernacular messaging that "no real official ever arrests you over a video call or demands money to a personal account", camps at banks during pension days, and a buddy system involving younger family members. I would also flag recurring scam patterns to I4C and telecom authorities for blocking. Throughout, I would keep the vulnerable resident — not procedure — at the centre, acting within my remit and coordinating with the agencies that own the cyber mandate.
Yes — technology cuts both ways. It enables fraud through AI-driven social engineering, deepfake voices and faces, automated phishing and rented mule networks operating at scale. The same technology defends against fraud: AI anomaly-detection, mule-account hunting tools, device and SIM intelligence, and real-time transaction-blocking via systems like the 1930 channel.
Policy should therefore be capability-led and principle-bound. On capability, invest in AI defence, public-private data-sharing through the CFMC, and continuous upskilling of law enforcement. On principles, insist on privacy-by-design, proportionality in data use, algorithmic transparency and human oversight of automated decisions. The aim is to win the arms race technically without sacrificing the civil liberties that make the digital economy worth protecting in the first place.
Interview Strategy — Do's & Don'ts
- ✅ Be precise: 85% / ₹25,000 / ₹50,000 / 1 Jan 2027 / five-day window — accurate figures signal real preparation.
- ✅ Read data critically: distinguish total bank fraud (loans) from digital-payment fraud — it shows analytical maturity.
- ✅ Balance values: weigh consumer protection, security and privacy before taking a calibrated position.
- ✅ Centre the citizen: in situational questions, keep the vulnerable victim, not procedure, at the heart of your answer.
- ⚠️ Avoid extremes: neither "all regulation stifles fintech" nor "compensate everything" — sophistication is in the proportionate middle.
- ⚠️ Don't confuse institutions: I4C (MHA) ≠ CERT-In (MeitY) ≠ UIDAI — mixing them up undercuts credibility.
Key Actors & Stakeholders
Reserve Bank of India
Issues the EBT framework, funds the major share of compensation, supervises banks' fraud-response.
I4C (MHA)
Coordinates cybercrime response; runs the 1930 helpline, CFMC and suspect registry.
CERT-In (MeitY)
National agency for cyber-security incident response and threat advisories.
Consumers
Individuals and sole proprietors — especially first-time, rural and elderly users — the framework protects.
Banks & PSPs
Bear the burden of proof and security obligations; remitting and beneficiary banks share payouts.
Telecom Operators
Block spoofed international calls, fraudulent SIMs and IMEIs in coordination with I4C.
Quick Revision Tags
GS-3 Concepts
Friction Points
Essay & Interview Angles
📚 Explore More UPSC Editorial Analyses
Daily, exam-ready breakdowns across Polity, Economy, IR, Environment and Ethics — each with Prelims MCQs, Mains answers, Essay frameworks and Interview prep.
View All Editorials