Last reviewed: 1 September 2026.
Quick Reply: Stop AePS fraud: UIDAI biometric-lock, bank-side liability, BNSS FIR timelines, Banking Ombudsman escalation & full recovery tactics.
RBI Ombudsman as of 1 July 2026: Bank, certain NBFC, prepaid-instrument and credit-information complaints go under the Reserve Bank - Integrated Ombudsman Scheme, 2026, which replaced RB-IOS 2021 from 1 July 2026. First complain to the entity. If there is no reply in 30 days (or the longer NPCI/card-network window, if it applies) or you reject the reply, file free at cms.rbi.org.in within 90 days. The Ombudsman can award up to Rs 30 lakh for consequential loss and up to Rs 3 lakh for time, expenses and harassment. Complaints received before 1 July 2026 stay under the 2021 scheme. Source: RBI FAQ, updated 1 July 2026 and the RB-IOS 2026 FAQ PDF dated 1 July 2026.
An illustrative case (not a named person): a Pune resident checked her bank SMS and found three unauthorized AePS withdrawals totaling ₹47,000 — transactions she never authorized, from a Business Correspondent outlet 340 km away, her biometric authentication replicated through a cloned fingerprint device.
Citizen Crisis Response Network
AePS fraud strikes without warning; this guide arms you with UIDAI biometric-lock protocols, bank liability rules under RBI's 6 July 2017 customer-protection circular, BNSS, 2023 FIR timelines, and multi-channel recovery pathways for unauthorized Aadhaar-enabled withdrawals.
1. Report unauthorized AePS transactions to your bank within 3 working days to trigger zero-liability protection under RBI's 6 July 2017 circular. 2. Register a police complaint citing BNS, 2023 Section 318(4) (cheating) and Section 319(2) (cheating by personation). 3. Activate UIDAI biometric-lock (resident.uidai.gov.in or the mAadhaar app) immediately. 4. File a Banking Ombudsman complaint once the bank rejects your complaint or 30 days pass without a response. 5. Demand transaction logs, Device ID and BC operator details in writing from your bank and NPCI. 6. Escalate to RBI Ombudsman (cms.rbi.org.in) and NPCI grievance portal simultaneously. 7. Pursue civil recovery under CPA 2019 for deficiency in service if criminal process stalls.
Aadhaar Enabled Payment System (AePS) allows bank customers to transact using only their Aadhaar number and biometric authentication—no debit card, no PIN. RBI annual reports and replies tabled in Parliament have repeatedly flagged a sharp rise in AePS-related fraud complaints. The surge stems from three systemic vulnerabilities: weakly supervised proliferation of Business Correspondent (BC) outlets, availability of cheap biometric cloning kits from overseas suppliers, and delayed liability attribution between banks, BCs, and NPCI.
AePS fraud typically involves a fraudster obtaining your Aadhaar number (often leaked from KYC databases or telecom records), replicating your fingerprint through lifted prints or high-resolution photographs, and executing withdrawals at complicit or poorly monitored BC outlets. Unlike UPI fraud, where OTP provides a secondary check, AePS authentication is single-factor: biometric match triggers instant debit.
The Payment and Settlement Systems Act 2007 (PSS Act) governs NPCI operations. Liability for unauthorized transactions is set by RBI's circular on Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (6 July 2017), read with RBI's digital payment security controls framework: if a customer reports an unauthorized transaction within three working days and did not contribute to the fraud, the customer bears zero liability and the bank must credit the amount within ten working days, unless the bank can establish customer negligence.
Warning — AePS fraud often surfaces in bulk: fraudsters execute multiple small withdrawals (₹5,000-₹10,000 each) within minutes to stay below single-transaction scrutiny thresholds; always check transaction history daily.
UIDAI's Biometric Locking feature lets you pre-emptively disable biometric authentication on your Aadhaar number, which blocks AePS transactions on your Aadhaar-linked bank accounts. It is accessible through the UIDAI resident portal and the mAadhaar app.
Biometric cloning has become disturbingly accessible: silicone fingerprint molds and 3D-printed finger caps capable of fooling standard AePS devices have been seized in multiple cyber-crime investigations, and such kits are advertised on encrypted messaging platforms and dark-web forums. Fraudsters lift fingerprints from everyday surfaces—door handles, mobile screens, ATM keypads—or capture high-resolution images during staged “government survey” visits.
The second attack vector is BC outlet collusion. Business Correspondents, authorized by banks to offer basic banking services in underserved areas, operate under thin oversight. Inspections and press reports have repeatedly flagged BC outlets with non-functional CCTV and incomplete transaction logs. Complicit BC operators either actively participate in fraud or turn a blind eye in exchange for cash kickbacks.
A typical fraud sequence:
Under BNS, 2023 Section 318(4) (cheating — punishable with up to seven years) and Section 319(2) (cheating by personation — punishable with up to five years), both the fraudster and a complicit BC operator face imprisonment and fine. Yet convictions remain rare due to jurisdictional confusion, delayed forensic analysis, and victims' lack of awareness about multi-channel escalation.
Most citizens miss this — NPCI logs include Device ID, BC operator code, GPS coordinates, and timestamp; demand these details in writing from your bank within 48 hours to strengthen your FIR and Ombudsman complaint.
The Unique Identification Authority of India (UIDAI) provides a Biometric Locking feature that disables biometric authentication for your Aadhaar number. When activated, it prevents AePS transactions on your Aadhaar-linked accounts until you unlock it through authenticated channels.
Three ways to activate biometric-lock:
Biometric-lock does NOT affect UPI, IMPS, NEFT, debit card, or net banking. It blocks Aadhaar-based biometric authentication, which is what AePS depends on. You can temporarily unlock it when you genuinely need Aadhaar authentication, and re-lock it afterwards.
RBI and UIDAI have both publicly advised customers who do not use Aadhaar-based authentication to keep their biometrics locked.
Do this immediately — Activate biometric-lock today; if you never use AePS (most urban customers don't), there is no practical downside, and cloned-biometric AePS withdrawals are blocked.
RBI's circular on Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (6 July 2017) governs liability for unauthorized AePS transactions. Key provisions:
Zero liability for customer if:
Bank must credit the amount within 10 working days of its decision, unless it demonstrates, with evidence, that customer negligence caused the fraud.
Limited liability if the customer reports 4-7 working days after the SMS: the customer's share is capped at ₹5,000 (basic savings bank deposit accounts), ₹10,000 (other savings accounts) or ₹25,000 (current/cash-credit/overdraft accounts).
Beyond 7 working days, the liability split is decided by the bank's board-approved policy.
Trust signal — Send your complaint in writing (email plus registered post), quote the 6 July 2017 circular by name, and attach your FIR copy; a dated paper trail is what forces the 10-working-day credit.
Hour 0-2 (immediately upon discovering fraud):
Hour 2-12:
Hour 12-48:
Hour 48-72:
Citizen tip — Print and hand-deliver a physical copy of your complaint to the branch manager; take receipt with date-stamp; banks often “miss” emails but cannot deny physical delivery with acknowledgment.
Visit your nearest police station or cybercrime cell. Under BNSS, 2023 Section 173, police cannot refuse to register an FIR for a cognizable offense. AePS fraud qualifies under BNS, 2023 Section 318(4) (cheating) and Section 319(2) (cheating by personation), both cognizable.
If police resist, send the substance of your complaint in writing and by post to the Superintendent of Police, who can direct an investigation under BNSS, 2023 Section 173. Most police officers comply when you demonstrate legal literacy.
Sample FIR text:
To, The Station House Officer, [Police Station Name], [City, State, PIN] Subject: FIR for Cheating, Cheating by Personation, and Theft under BNS, 2023 Respected Sir/Madam, I, [Your Full Name], son/daughter/spouse of [Parent/Spouse Name], aged [Age], residing at [Full Address], holding Aadhaar No. [XXXX-XXXX-1234] and maintaining Savings Account No. [Account Number] with [Bank Name, Branch], hereby lodge a complaint regarding unauthorized fraudulent AePS transactions executed on my bank account. FACTS: 1. On [Date] at [Time], I received SMS alerts from my bank notifying three AePS cash withdrawal transactions totaling ₹[Amount]. 2. Transaction details: [List each transaction with date, time, amount, and BC reference number if available]. 3. I did not authorize these transactions. I did not visit any Business Correspondent outlet on the stated dates. I did not share my biometric data (fingerprint/iris) with any person or entity. 4. I immediately contacted my bank on [Date, Time], received complaint reference [Number], and requested account freeze and AePS disablement. 5. I have activated biometric-lock on my Aadhaar-linked accounts on [Date]. NATURE OF OFFENSE: The fraudster(s) unlawfully obtained my Aadhaar number and replicated my biometric authentication through cloning or insider access, then executed unauthorized cash withdrawals at a Business Correspondent outlet located at [Address if known, else mention "BC outlet details to be obtained from bank"]. This constitutes: - Cheating by personation under BNS, 2023 Section 319(2) (fraudulent impersonation to cause wrongful gain). - Cheating under BNS, 2023 Section 318(4) (dishonestly inducing bank to deliver cash by deception). - Theft under BNS, 2023 Section 303(1) (taking of money without the owner's consent). I request you to: A. Register FIR under BNSS, 2023 Section 173 against unknown accused. B. Obtain transaction logs, Device ID, BC operator details, GPS coordinates, and CCTV footage from [Bank Name] and NPCI. C. Investigate the BC outlet involved and identify complicit operators. D. Forward the case to the Cyber Crime Investigation Cell for forensic analysis of biometric cloning. I am willing to cooperate fully with the investigation. Kindly provide me a copy of the FIR as mandated under BNSS, 2023 Section 173(2). Date: [Date] Place: [City] [Your Signature] [Your Full Name] [Mobile Number] [Email Address] Enclosures: 1. Copy of Aadhaar card 2. Bank statement (last 30 days) 3. SMS alerts (printout) 4. Bank complaint acknowledgment email
Police are required to provide FIR copy instantly (BNSS, 2023 Section 173). If they delay, escalate to Superintendent of Police via email the same day.
The Reserve Bank - Integrated Ombudsman Scheme (RB-IOS) 2026 provides free, quasi-judicial redressal for banking grievances. Complaints are received centrally by RBI's Centralised Receipt and Processing Centre (CRPC) at https://cms.rbi.org.in.
Eligibility:
How to file:
What happens next:
Award enforceability: If the bank does not appeal within 30 days, the Award becomes final. If the bank still fails to implement it, escalate the non-compliance to RBI and pursue the refund through the Consumer Court route below.
Most citizens miss this — If your bank fails to comply with the Ombudsman Award, you can file a complaint with RBI's Department of Supervision citing non-compliance; RBI imposes monetary penalties on errant banks, which often triggers immediate compliance.
Channel-wise AePS success rates are not published; RBI reports only aggregate ombudsman statistics in its annual reports. Do not treat a bank rejection as final — ombudsman escalation is free and regularly reverses unauthorized-transaction debits where the bank cannot show customer negligence.
NPCI governs AePS infrastructure, including BC onboarding standards, device certification, and transaction logging. Under NPCI Operating Circular AEPS-2026/03, customers have the right to demand forensic audit of BC outlet transaction logs if fraud is suspected.
How to escalate to NPCI:
NPCI's response time varies; chase in writing if there is no reply within a few weeks. Their forensic team cross-references transaction timestamps, Device IDs, and biometric authentication logs. If discrepancies emerge (e.g., same Device ID used for multiple fraud complaints, GPS mismatch, device de-certified post-facto), NPCI suspends the BC outlet and flags the issuing bank for liability.
Attach NPCI's findings to your Banking Ombudsman complaint — they carry evidentiary weight on device and BC-outlet questions the bank cannot easily dispute.
Warning — NPCI does not directly refund money; their role is technical audit and BC oversight. Refund liability rests with the bank. Use NPCI findings as leverage in your Ombudsman and Consumer Court proceedings.
If criminal investigation stalls or Banking Ombudsman outcome is unsatisfactory, approach the Consumer Court under the Consumer Protection Act 2019. Banking services qualify as “service” under CPA 2019 Section 2(42), and unauthorized AePS debits constitute “deficiency in service” under Section 2(11).
Jurisdiction:
Most AePS fraud cases fall under District Forum jurisdiction.
How to file:
CPA 2019 timelines:
Precedent: Consumer fora routinely hold banks liable for unauthorized AePS debits where the bank cannot show that the customer authorised the transaction or contributed to the fraud; the burden of proving customer negligence rests on the bank. Awards typically include the debited amount with interest plus compensation for deficiency in service.
Citizen tip — Mention CPA 2019 Section 2(11) (deficiency in service) and Section 2(42) (service) explicitly in your complaint; Consumer Fora are sympathetic to digital fraud victims when statutory language is correctly cited.
Key judgments:
Regulatory framework:
Regulatory bodies:
Trust signal — Ask your bank in writing whether it can block Aadhaar-based (AePS) debits on request for accounts you do not actively use; a written block request plus UIDAI biometric-lock removes the cloned-fingerprint risk.
Channel-by-channel AePS success statistics are not published; the table below sets practical expectations from how each channel actually works — treat it as strategy, not audited data:
| Recovery Channel | Typical Timeline | Cost to Citizen |
| Direct Bank Resolution | 10 working days for the credit once a zero-liability complaint is accepted | ₹0 |
| Banking Ombudsman (RB-IOS) | Weeks to a few months after the 30-day bank window | ₹0 |
| Consumer Court (District Commission) | Several months to over a year | NIL up to ₹5 lakh claim; ₹200 for ₹5-10 lakh |
| Police Investigation → Recovery | Slow; treat the FIR as supporting evidence, not the recovery route | ₹0 (but time-intensive) |
| NPCI escalation | A few weeks for written findings; supports bank liability claims | ₹0 |
Multi-channel strategy (recommended):
In practice most refunds come through the bank complaint and ombudsman routes; the FIR and NPCI findings are leverage. A multi-channel strategy protects you if any single channel stalls.
Do this immediately — Maintain a dated, indexed dossier (physical + cloud backup) of every SMS, email, FIR copy, acknowledgment, and response; organized documentation is what keeps Ombudsman and Court proceedings moving.
Yes, but the burden of proof shifts. Under RBI guidelines, reporting beyond 7 working days leaves the liability split to your bank's board-approved policy. However, you can still succeed if you demonstrate extenuating circumstances (hospitalization, lack of mobile access, travel, etc.). Cite CPA 2019 deficiency in service in your Banking Ombudsman and Consumer Court complaints — consumer fora have refunded unauthorized AePS debits where the bank failed to prove customer negligence.
No. Biometric-lock exclusively disables AePS (Aadhaar-based fingerprint/iris authentication at BC outlets). UPI, debit card, net banking, IMPS, NEFT, and RTGS continue to function normally. You should activate biometric-lock unless you regularly use AePS services.
Fingerprint authentication logs only confirm that a fingerprint matching your Aadhaar was presented—not that YOU presented it. Demand forensic analysis of Device ID, GPS coordinates, transaction velocity (multiple transactions in seconds indicates cloning), and BC outlet CCTV footage. In cloning cases these secondary checks often reveal anomalies (device flagged previously, GPS mismatch, etc.).
Yes. Under CPA 2019, Consumer Fora routinely award compensation for mental agony, harassment, and litigation costs, typically ranging from ₹10,000 to ₹1,00,000 depending on case severity. Under the RB-IOS 2026 scheme, the Ombudsman can award up to ₹30 lakh for actual loss plus up to ₹3 lakh compensation. Cite the fraud's impact—loss of savings for medical emergency, educational fee delay, etc.—with supporting documents.
Request transaction logs from the BC outlet for the fraud date via NPCI (see NPCI escalation section). If logs show multiple high-value withdrawals in quick succession, or the same Device ID appears in other fraud complaints, complicity is likely. Police can then investigate the BC operator under BNS, 2023 Section 61 (criminal conspiracy) in addition to Sections 318 and 319.
Under CPA 2019 Section 69, you must file within 2 years from the date when the cause of action arose (i.e., the fraud date). There is no statutory pause for a parallel Banking Ombudsman proceeding, so if you take the Ombudsman route first, file the consumer complaint well within two years of the fraud.
Yes, but with caveats. Banks are generally not “public authorities” under the RTI Act 2005, and NPCI's status under the Act has been contested — RBI is the more reliable addressee. File RTI with RBI seeking AePS fraud data, directions issued to banks on unauthorized-transaction liability, and enforcement action, and a separate application to NPCI asking for BC-outlet audit and device-certification records. This data strengthens your case. Use the AI RTI Drafter tool at https://righttoinformation.wiki/tools/rti-assistant for precision drafting.
Submit written complaint at the police station; insist on a written acknowledgment with date-stamp. If refused, immediately email scanned copy to the Superintendent of Police and Commissioner of Police with subject “Non-registration of FIR – BNSS, 2023 Section 173 Violation.” Under BNSS, 2023 Section 173, the SP can order an investigation. If still no action within 7 days, approach the Judicial Magistrate with a private complaint under BNSS, 2023 Section 223 (examination of complainant).
No public BC-outlet blacklist database is available to citizens. However, you can file an RTI application with NPCI requesting disclosure of BC outlet [Outlet Code]'s suspension/blacklist status, number of fraud complaints received, and audit findings. An RTI application must be answered within 30 days; if NPCI refuses on the ground that it is not a public authority, direct the same application to RBI.
Related: Scams — the Citizen Crisis Desk: every fraud-recovery guide on RTI Wiki