RBI regulations provide specific protections against unauthorized credit card transactions. Customers face zero liability if they report the incident within three working days. Delays of four to seven days result in capped losses, while proven negligence can void protection. Understanding these rules is essential to safeguarding your personal finances.
Unauthorized electronic transactions are a major concern for credit card users, but the Reserve Bank of India (RBI) has established clear guidelines to protect customers. The central bank’s framework, detailed in its Master Direction on Credit and Debit Card issuance, balances the responsibility between the issuing bank and the cardholder. When a card is lost, stolen, or compromised, the financial burden placed on the customer depends entirely on the speed of reporting the incident to the bank.
The most critical window for any credit card holder is the three-working-day period after a transaction alert is received. If a customer notifies the bank of an unauthorized transaction within this three-day window, they face zero liability. The responsibility to reverse the fraudulent transaction lies entirely with the bank, provided the account is not compromised due to customer negligence. This makes registering for SMS and email alerts mandatory for every cardholder, as the timeline for reporting often hinges on when the customer receives these notifications.
If a customer reports the incident between four and seven working days, the liability is not zero but is capped. The RBI has set specific limits for this period based on the credit card's authorized limit. For cards with limits up to ₹5 lakh, the customer’s liability is capped at ₹10,000. For cards with higher limits, the cap is set at ₹25,000. It is important for users to check their card’s specific terms, as exceeding the seven-day reporting window shifts the liability entirely to the bank’s internal policy, which can be significantly more punitive for the cardholder.
A significant nuance in these regulations is the concept of customer negligence. The protection offered by the RBI is not absolute. If the bank can prove that a loss occurred because the customer shared sensitive details like One-Time Passwords (OTPs), Personal Identification Numbers (PINs), or passwords with third parties, the liability protection may be voided. The burden of proof to establish this negligence rests with the bank, meaning they must provide evidence that the transaction occurred due to the user's lapse.
Once a report is filed, the regulatory timeline requires banks to act swiftly. The issuer is obligated to provide a shadow reversal—a temporary credit of the disputed amount—within 10 working days of the official complaint. The bank then has up to 90 days to investigate and resolve the matter fully. If the investigation confirms the transaction was unauthorized, the temporary credit becomes permanent. If the investigation concludes otherwise, the temporary credit may be reversed, which is why maintaining detailed records of transaction alerts and communication with the bank is essential for every credit card user.
