To UIDAI:
Authentication logs for my Aadhaar number on dates X-Y; AUA / Sub-AUA names; OTP / biometric flag; outcome./
* To your bank (public sector): Status of complaint number Z; date NPCI dispute raised; reply received from acquirer bank; reason for delay if past 90 days.
* To Police: FIR number A — investigating officer, date of next investigation step, action taken on banking correspondent.
Use the RTI Drafter — drafts these 3 RTIs from your case description.
===== Documents Required =====
| Document | Purpose |
| Aadhaar card + masked Aadhaar | ID proof (use masked for FIR/online filings). |
| PAN card | KYC at bank. |
| Bank statement — 90 days | Proof of unauthorised debits. |
| Mobile number registered with Aadhaar| For OTPs during UIDAI lock. |
| NCRP acknowledgement | Generated when filed at cybercrime.gov.in. |
| FIR copy | After cyber police station registration. |
| NPCI dispute reference | Once bank raises chargeback to acquirer. |
| m-Aadhaar lock screenshot | Evidence biometrics were locked at time T. |
===== Common Mistakes to Avoid =====
- Waiting “to see if money comes back” — every day costs you the zero-liability ceiling.
- Calling bank on a non-registered number from Google search — can be a scam helpline. Use the number on your debit card / passbook.
- Sharing OTP with “bank verification officer” — banks never ask for OTP. Hang up.
- Going to a “cyber cell agent” who promises 100% recovery for a fee — they are second-stage scammers.
- Not locking biometrics — fraud continues even while complaint is pending.
- Skipping NPCI dispute — bank handles chargeback only via NPCI for AePS.
- Settling for partial refund — RBI 3-day rule mandates full refund. Push back.
===== FAQs =====
==== Can the bank refuse refund saying “you must have shared biometrics”? ====
No. Under RBI Customer Liability Framework §6.3, the burden of proof is on the bank to demonstrate customer negligence. Mere assertion is not enough. If the fraud was via leaked sub-registrar biometric, courts have held this to be zero-liability even at 7+ days. Citation: Banking Ombudsman Order Mumbai 2024-073
.
==== Should I close my bank account? ====
Don't close immediately — refund depends on the same account. Freeze AePS only by writing to your bank (Disable AePS-out facility on my account
). Switch to a Jan Dhan account ONLY for AePS-needed benefits.
==== How does Aadhaar locking affect my regular life? ====
It only blocks biometric authentication (AePS, eKYC). Your Aadhaar OTP, demographic verification, ration card, IT filings all work normally. You can unlock temporarily for genuine eKYC.
==== What if I'm a senior citizen / illiterate / from a village? ====
Your Banking Correspondent or Common Service Centre (CSC) can lock Aadhaar for you. Or call UIDAI helpline 1947. The local District Legal Services Authority (DLSA) can help file FIR + bank complaint for free.
==== My biometric was leaked from a sub-registrar office. Who is liable? ====
The State Government (Stamp & Registration Department) is liable under Article 21 (privacy) + DPDP §8 + §40. Class action is possible. Several PILs are pending in Maharashtra and Telangana High Courts.
==== Can the BC operator be arrested? ====
Yes — IT Act §66C + §66D + BNS §318 + §321 are cognisable + non-bailable for organised cases. NCRB data shows 1,200+ BC operators were charged in 2024 specifically for AePS fraud.
==== What's the difference between AePS fraud and UPI fraud? ====
UPI: needs your OTP / device + UPI PIN. Loss reverses through 1930 → bank freeze. AePS: needs only your Aadhaar + biometric. Loss reverses through bank complaint → NPCI dispute. The 3-day rule applies to both.
==== Will RBI compensate me directly? ====
RBI is the regulator, not the payer. Your bank pays — RBI orders it. Banking Ombudsman can award up to ₹1 lakh for mental harassment in addition to refund.
==== Can I claim mental distress? ====
Yes — through Consumer Court (District Commission) under Consumer Protection Act §2(47) + Banking Ombudsman award. Typical: ₹25,000-₹2,00,000.
==== I haven't filed FIR but I want to. Am I too late? ====
No deadline for FIR filing under §175 BNSS. But every day weakens evidence. File even at Day 60 — the FIR triggers police investigation that may still recover money via inter-bank reversals.
==== What if my bank ignores my complaint? ====
After 30 days of silence: file at RBI Banking Ombudsman (https://cms.rbi.org.in) → Mobile or Internet Banking
→ Customer Liability Framework violation
. Order compels bank action.
==== Is AePS being phased out? ====
NPCI is upgrading to AePS 2.0 with liveness detection and mandatory SMS to customer — rolling out across 2025-2026. Until then, lock biometrics by default is the safest stance.
==== Can NRIs use AePS / be affected? ====
NRIs can have NRO/NRE accounts. AePS uses Aadhaar — if you don't have Aadhaar, no exposure. If you do, lock biometrics. Same RBI rules apply.
===== Internal Linking Suggestions =====
* Cyber Crime Complaint in India — full process
* UPI Fraud Recovery — Dial 1930 + RBI 3-day rule
* RTI Drafter — file an RTI to UIDAI / Bank / Police
* Loan App Harassment Recovery
* Digital Arrest Scam — 7-minute rescue plan
* Aadhaar Status Check — update mobile, verify biometric lock
* Consumer Court — file online via e-Daakhil
* Aadhaar Validator — Verhoeff offline check
===== External References =====
* RBI Customer Liability Framework, 2017 — https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11040
* NPCI AePS Dispute Management — https://www.npci.org.in/what-we-do/aeps
* UIDAI Lock/Unlock Biometric — https://uidai.gov.in
* National Cyber Crime Reporting Portal — https://cybercrime.gov.in
* RBI Banking Ombudsman (CMS) — https://cms.rbi.org.in
* m-Aadhaar app — Google Play / App Store (UIDAI official).
===== Conclusion =====
AePS fraud is preventable: lock your Aadhaar biometric today, even before any incident. If you've been hit, the 3-day window to bank + 24-hour window to NCRP is what determines whether you get 100% back or 0%. The law is unambiguously on your side — RBI, UIDAI, NPCI, NALSA all converge on protecting the citizen. The only failure mode is delay.
If your bank stalls, file an RTI to extract the AePS terminal log + BC ID — that single document forces internal action. The RTI Drafter auto-generates this.
===== Sources =====
* RBI Customer Liability Framework, 2017 (RBI/2017-18/15).
* NPCI Master Direction on AePS Dispute Management.
* Aadhaar Act, 2016 — §7, §8, §29(4), §38, §39.
* Information Technology Act, 2000 — §43A, §66C, §66D.
* Bharatiya Nyaya Sanhita, 2023 — §318, §321, §336.
* Banking Ombudsman Scheme, 2021.
* Digital Personal Data Protection Act, 2023.
Last reviewed: 5 May 2026 — RTI Wiki editorial team.