RBI Draft Amendments Report – 11th September 2026 | (Know Your Customer) Amendment Directions, 2026

Pursuant to the Supreme Court order dated August 4, 2026, the Reserve Bank of India has issued the Draft RBI (Know Your Customer) Amendment Directions, 2026 (Ref: DOR.AML.REC.No./14-01-001/2026-27). This mandate introduces a strict Standard Operating Procedure (SOP) to combat cyber-enabled financial frauds and money mule accounts. The directions come into effect on or before April 1, 2027.

1. Applicable Entities

The new directions and the SOP are applicable to a broad spectrum of the banking sector, while providing specific exemptions to prevent disruption of corporate operations.

  • Fully Applicable To:
    • All Commercial Banks (including Small Finance Banks, Payments Banks, Regional Rural Banks, and Local Area Banks).
    • All Urban Cooperative Banks (Primary Co-operative Banks).
  • Explicitly Exempted Accounts:
    • Nodal accounts and Pool accounts.
    • Escrow accounts.
    • Special-purpose accounts (e.g., dividend distribution, share capital accounts).

2. Detailed Analysis of Amendments & Management Action Plan

The draft directions introduce two major amendments to the existing KYC Directions, 2025. Below is a detailed breakdown of the specific changes, the required management action plan, and practical real-world scenarios.

Amendment 1: Stricter Liability for “Operation of Bank Accounts and Money Mules”

Specific Change Required: Paragraph 1 of the amendment replaces existing guidelines to mandate meticulous transaction monitoring. The most critical regulatory shift is the introduction of deemed non-compliance: “If it is established that an account opened and operated is that of a Money Mule, but STR (Suspicious Transaction Report) was not filed by the concerned bank, it shall then be deemed that the bank has not complied with these Directions.”

Management Action Plan:

  1. Rule Engine Overhaul: The IT and Compliance teams must update the Anti-Money Laundering (AML) transaction monitoring systems to proactively identify typologies of phishing, smurfing, and identity theft.
  2. Zero-Leakage STR Policy: Establish a secondary audit layer for alerts generated by the system to ensure no valid money mule alert is closed without filing an STR with FIU-IND.
  3. Staff Sensitization: Conduct mandatory training for branch managers and account opening staff on the latest behavioral indicators of third-party account operators (mule recruiters).
Real-World Example: A college student opens a zero-balance savings account. Over three days, the account receives incoming transfers of ₹50,000 from four different states, which are immediately withdrawn via ATMs at midnight. Previously, a bank might have missed this. Under the new rule, if the police later identify this as a mule account and the bank had failed to file an STR, the RBI will automatically penalize the bank for regulatory non-compliance.

Amendment 2: Implementation of Annex III (SOP on Suspected Money Mule Accounts)

Specific Change Required: Banks must now follow a uniform, time-bound Standard Operating Procedure (SOP) to place “Temporary Debit Holds” on suspected transactions of ₹1,000 and above, or on entire accounts. The SOP dictates strict turnaround times (TATs) to balance fraud prevention with customer convenience. The maximum duration of a hold, absent law enforcement instructions, is capped at 60 days.

A. Procedural Timeline for Debit Holds

Stage Action Required by Bank Mandatory Timeline
1. Detection & Hold Place temporary debit hold on the transaction (or full account). Immediately upon detection.
2. Notification Notify customer with reasons, removal process, and officer contact details. Immediately (digital) or by EOD next day (physical).
3. Customer Rebuttal Allow customer to provide justification for the transaction. 20 days from the date of the hold.
4. Bank Decision Examine explanation and either (a) remove hold, or (b) report to Police via NCRP-CFCFRMS. Within 10 days of receiving explanation (or within 30 days of hold if no explanation).
5. LEA Coordination Act on instructions from Law Enforcement Agencies (LEA) or Competent Authority. Immediately upon receipt within 30 days of reporting.
6. Auto-Release Remove hold if no LEA instruction is received requiring continuation. On the 31st day from reporting to LEA (Max 60 days total).

Management Action Plan for SOP Procedural Changes:

  • Core Banking System (CBS) Upgrades: IT must configure the CBS to allow transaction-level debit holds (freezing specific amounts rather than the whole account, to minimize customer friction) and automate the 60-day auto-release trigger.
  • AI/ML Integration: Deploy AI/ML-based tools to flag suspected transactions (≥₹1000) that are disproportionate to the customer’s declared KYC profile.
  • Portal Linkage: Integrate internal systems with the Ministry of Home Affairs (MHA) NCRP-CFCFRMS portal for seamless, API-driven reporting to Jurisdictional Police Authorities.
Real-World Example: An AI tool flags a sudden ₹25,000 credit in a rural laborer’s account as suspected cyber-fraud proceeds. The bank immediately places a debit hold only on that ₹25,000, allowing the customer to use their existing ₹2,000 balance. The customer is notified via SMS. If the customer ignores the message for 20 days, the bank automatically reports the transaction to the Cyber Police on day 21. If the police do not issue a formal freeze order within the next 30 days, the bank’s system automatically lifts the hold on the 60th day.

B. Internal Policy, Record Keeping, and Grievance Redressal

Specific Change Required: Banks are required to draft an overarching Internal Policy for this SOP. Additionally, strict record-keeping and grievance mechanisms must be instituted.

Management Action Plan:

  • Board-Approved Policy: Draft a comprehensive policy detailing tech solutions, scenarios for debit hold removals, communication templates, and parameters to minimize flagging genuine accounts. (Target Completion: Q4 2026).
  • Centralized MIS & Data Retention: Develop an MIS to track the lifecycle of every temporary hold. Ensure related records are retained for a minimum of 5 years from the hold date, or 10 years post account closure.
  • Grievance Redressal Mechanism:
    • Appoint dedicated Nodal Officers at Regional, Zonal, and Head Office levels.
    • Display Nodal Officer contact details prominently on the bank website and branch notice boards.
    • Ensure all complaints related to temporary holds are resolved within a strict 30-day TAT.
Real-World Example: A legitimate small business owner has their account frozen due to a false-positive AI flag. Frustrated, they visit the bank’s website, easily locate the designated Zonal Nodal Officer’s details, and file a complaint with their invoices attached. Because the bank has a centralized MIS tracking the dispute, the Nodal Officer quickly verifies the documents and lifts the hold within 3 days, easily meeting the 30-day grievance resolution mandate and retaining a satisfied customer.

3. Conclusion & Strategic Next Steps

The RBI’s draft directions signal a shift towards technology-driven, highly accountable fraud prevention. The shift from account-level freezing to transaction-level debit holds, combined with strict timelines, requires an immediate overhaul of IT infrastructure and compliance workflows. Management should initiate a cross-functional task force (IT, Compliance, Operations, and Legal) to ensure full system readiness well before the April 1, 2027 deadline.

RBI Press Release

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top