RBI has released the Draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026, proposing a detailed Standard Operating Procedure (SOP) requiring banks to place temporary debit holds on accounts or transactions suspected of money-mule activity or cyber-enabled financial fraud. The draft follows a Supreme Court order dated August 4, 2026 directing RBI to adopt and circulate such an SOP. It applies to all Commercial Banks (including Small Finance Banks, Payments Banks, Regional Rural Banks and Local Area Banks) and Urban Cooperative Banks. The maximum duration of a temporary debit hold, absent a contrary instruction from a Law Enforcement Agency or Competent Authority (such as a court or tribunal), is 60 days. Public comments are invited until October 2, 2026, and the proposed effective date is April 1, 2027, or earlier if a bank chooses to implement the SOP sooner.
Background: Why RBI Is Amending the KYC Directions
RBI's existing Know Your Customer (KYC) Directions, 2025 already contain instructions on 'Operation of Bank Accounts and Money Mules,' advising banks to undertake diligence measures and monitor transactions to identify accounts operated as money mules. These instructions have now been reviewed following a Supreme Court order dated August 4, 2026, which directed RBI to adopt and circulate a Standard Operating Procedure prescribing the action banks must take to place temporary debit holds on amounts or accounts linked to money-mule activity and cyber-enabled fraud.
In response, RBI has formulated the SOP titled "Suspected Money Mule Accounts to Prevent Cyber-enabled Financial Frauds" and proposes inserting it as Annex III to the KYC Directions, 2025, alongside a substituted paragraph on money mules that makes adherence to the SOP a compliance requirement.
What Does the Draft Propose?
The draft makes two changes to the KYC Directions, 2025:
- It substitutes the existing paragraph on 'Operation of Bank Accounts and Money Mules' to require banks to identify money-mule accounts, take action per the new SOP (Annex III), and report suspicious transactions to FIU-IND. Notably, if a money-mule account is established but the bank did not file a Suspicious Transaction Report (STR), the bank shall be deemed non-compliant with the KYC Directions.
- It inserts a new Annex III containing the full SOP on Suspected Money Mule Accounts, covering scope, definitions, procedure and timelines for temporary debit holds, internal policy requirements, record-keeping and grievance redressal.
📝 In Plain English: A "money mule" account is one used — knowingly or unknowingly by its holder — to receive and pass on money that is actually proceeds of fraud, like phishing scams or identity theft. The SOP gives banks a clear rulebook on when they can freeze (hold) suspicious money in an account, for how long, and what they must tell the customer and law enforcement while doing so.
Scope and Applicability
The SOP explicitly does not modify a bank's existing obligations under the Prevention of Money Laundering Act, 2002 or RBI's KYC Directions, 2025 — it operates alongside them, not in place of them. The SOP is also to be read together with any instructions issued by the Ministry of Finance or the Ministry of Home Affairs on this subject.
Key Definitions
- Money Mule Account: an account used, knowingly or unknowingly, to receive, layer or transfer proceeds of cyber-enabled financial fraud on behalf of another person.
- Suspected Money Mule Transaction: a transaction of ₹1,000 or more, flagged by a bank's transaction-monitoring system (including AI/ML-based tools) as potentially linked to money-mule activity or cyber-enabled fraud — for instance, where it is unusual for or disproportionate to the account holder's declared profile, or linked to an account already reported as fraudulent.
- Temporary Debit Hold: a temporary restriction placed by a bank on debits from suspected amounts or an account, pending verification.
- Days: all timelines in the SOP (20 days, 10 days, 30 days, 60 days) are counted in calendar days, not business days.
- Law Enforcement Agency (LEA): State, Union Territory or Central Government police authorities investigating cyber-enabled financial frauds.
- Jurisdictional Police Authority: the police/cyber police station to which a case is routed under NCRP-CFCFRMS, or, if unavailable, the station with jurisdiction over the servicing branch.
- Competent Authority: any authority other than an LEA, including a court or tribunal, empowered to issue instructions regarding an account or transaction under investigation.
- NCRP-CFCFRMS: the National Cybercrime Reporting Portal's Citizen Financial Cyber Fraud Reporting and Management System.
Procedure and Timeline: Placing the Temporary Debit Hold
Procedure and Timeline: Removal of the Hold
In the absence of any contrary LEA/Competent Authority instruction, the maximum duration of a temporary debit hold is 60 days from the date it was first placed — up to 30 days for Steps 3–4, plus up to a further 30 days for Steps 5–6.
Practical Example: If a bank places a hold on an account on Day 1, gives the customer 20 days to respond, and the customer replies on Day 15, the bank must decide within 10 days of that reply (by around Day 25) whether to release the funds, escalate to police, or await an LEA order — illustrating how the 60-day ceiling is built from sequential, not parallel, timelines.
Internal Policy Requirements
Each bank's internal policy under the SOP must address:
- The technology solutions used to identify suspected money-mule and cyber-enabled fraud transactions;
- Norms for placing a temporary debit hold at the amount or account level, and the scenarios for removing it — with account-level holds treated as a last resort, used only in exceptional circumstances;
- Modes and templates for communicating with account holders;
- The process for linking to the Ministry of Home Affairs' NCRP-CFCFRMS portal; and
- A customer grievance redressal mechanism.
The policy must also provide for analysis of flagged transactions using objective parameters designed to minimise the risk of wrongly flagging genuine transactions or accounts.
Record-Keeping Requirements
- Banks must maintain a centralised MIS recording the date and reasons for each temporary debit hold, correspondence and notifications to the account holder, LEA references and orders received, and the eventual release or continuation status of each case.
- Existing Suspicious Transaction Report (STR) filing obligations to FIU-IND continue unchanged.
- Records must be retained for a minimum of 5 years from the date the hold was placed, or 10 years from account closure if the account is closed.
- Records must be available for supervisory review, and banks must apply enhanced monitoring to the flagged account and other active accounts/relationships of the same account holder.
Grievance Redressal Mechanism
- Banks must designate Nodal Officer(s) at Regional/Zonal/Head Office level for coordination and to handle complaints arising from action taken under the SOP.
- Nodal Officer contact details (name, phone, address, e-mail) must be prominently displayed on the bank's website and at all branches.
- Complaints must be acknowledged on receipt and resolved within 30 days.
- Banks must maintain an MIS to log, track and monitor complaints received under the SOP.
Who Is Affected?
- All Commercial Banks — including Small Finance Banks, Payments Banks, Regional Rural Banks, Local Area Banks, corresponding new banks and the State Bank of India.
- Urban Cooperative Banks.
- Bank AML/KYC compliance, fraud risk and IT/transaction-monitoring teams — who will need to build or upgrade detection systems, internal policies and MIS infrastructure to meet the SOP's requirements.
- Customers whose accounts are flagged — who will be entitled to defined notice periods, an opportunity to explain, and a grievance mechanism.
- Nodal accounts, pool accounts, escrow accounts and special-purpose accounts (e.g., dividend or share capital accounts) are excluded from the SOP's scope.
RBI has clarified that this consolidated draft applies across all covered entity types for the purpose of consultation; final Directions will be issued separately for each type of regulated entity after comments are examined.
What Should Practitioners Watch?
This is a draft, and no compliance obligation arises from it as of now. Practitioners should track:
- Comment deadline: Feedback must be submitted by October 2, 2026, through RBI's 'Connect 2 Regulate' section on its website, or by e-mail with the subject line "Feedback on Draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026."
- Separate final Directions per entity type: Since RBI intends to issue distinct final Directions for each regulated-entity category, provisions may be calibrated differently for, say, Urban Cooperative Banks versus large commercial banks in the final version.
- Deemed non-compliance clause: The provision deeming a bank non-compliant with the KYC Directions if an established money-mule account was not reported via STR is likely to draw significant comment, given its potential severity.
- The ₹1,000 transaction threshold and AI/ML flagging criteria: Given the low threshold, the practical burden of the SOP on transaction-monitoring systems and false-positive rates is likely to be a focal point of industry feedback.
- Preparatory action that does not assume finalisation: Banks may find it useful to begin gap-assessing current transaction-monitoring and account-freeze capabilities against the SOP's proposed timelines, without treating this as a compliance deadline yet.
Frequently Asked Questions
What triggered this draft amendment?
A Supreme Court order dated August 4, 2026 directed RBI to adopt and circulate a Standard Operating Procedure for banks to place temporary debit holds on accounts linked to money-mule activity and cyber-enabled fraud.
What is a Money Mule Account under the draft SOP?
An account used, whether knowingly or unknowingly by the account holder, to receive, layer or transfer proceeds of cyber-enabled financial fraud on behalf of another person.
How long can a bank hold funds under a temporary debit hold?
A maximum of 60 days from the date the hold is placed, in the absence of a contrary instruction from a Law Enforcement Agency or Competent Authority.
What transaction value triggers scrutiny under the SOP?
Transactions of ₹1,000 or more flagged by a bank's transaction-monitoring system, including AI/ML-based tools, as potentially linked to money-mule activity or cyber-enabled fraud.
Which accounts are excluded from the SOP?
Nodal accounts, pool accounts, escrow accounts, and other special-purpose accounts such as dividend or share capital accounts.
When would these Directions come into effect?
As proposed in the draft, from April 1, 2027, or earlier if a bank chooses to implement the SOP sooner — subject to finalisation after the comment period.
By when must comments be submitted?
On or before October 2, 2026, via RBI's 'Connect 2 Regulate' section or by email with the specified subject line.
What happens if a bank fails to file an STR for a confirmed money-mule account?
Under the draft, this is deemed non-compliance with the KYC Directions, even if the bank otherwise followed the debit-hold procedure.
CorpLawUpdates Analysis
For bank compliance and fraud-risk functions, the most operationally demanding part of this draft is not the debit-hold mechanic itself but the sequencing discipline it imposes: banks must track parallel notification and decision clocks — immediate notification, a 20-day customer response window, a 10-or-30-day decision window, and a further 30-day LEA-response window — across potentially large volumes of flagged low-value transactions given the ₹1,000 threshold. The requirement that account-level holds (as opposed to transaction-level holds) be used only as a last resort suggests RBI is trying to balance fraud prevention against the risk of over-freezing genuine customer accounts, a tension banks will need to resolve carefully in their internal policies. The deemed non-compliance clause for missed STR filings on confirmed money-mule accounts raises the stakes materially, effectively linking SOP execution quality to a bank's broader AML compliance standing.
Document 1: Draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026
Reference: DOR.AML.REC.No. /14-01-001/2026-27
Signatory: Veena Srivastava, Chief General Manager
Document 2: Press Release — "RBI invites comments on the Draft 'Reserve Bank of India (Know Your Customer) Amendment Directions, 2026'"
Reference: Press Release 2026-2027/1109, dated September 11, 2026
Signatory: Brij Raj, Chief General Manager
Comment Channels: RBI's 'Connect 2 Regulate' section, or email with subject line "Feedback on Draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026"
Comment Deadline: October 2, 2026
This article is for informational and educational purposes only and does not constitute legal or regulatory advice. Readers should verify the applicable primary regulatory source before taking action.


