Differences
This shows you the differences between two versions of the page.
| — | golden-hour-zero-liability-cyber-fraud-rbi-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | {{htmlmetatags> | ||
| + | |||
| + | ====== Golden-hour zero liability: the exact RBI math for cyber fraud ====== | ||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP info> | ||
| + | **Quick Reply:** If you report an unauthorised electronic banking transaction to your bank **within 3 working days** of receiving the bank's communication, | ||
| + | </ | ||
| + | |||
| + | If you are short on time, jump to **[[#the liability matrix in one table|the liability matrix in one table]]** and the **[[#sample notice to your bank citing the circular|sample notice to your bank]]**. Copy both, paste into a new email to your bank, send before the third working day ends. | ||
| + | |||
| + | ===== Why this article exists ===== | ||
| + | |||
| + | You have just lost money in a cyber fraud. You called **1930** and filed at **NCRP**. The next 72 hours decide whether you get every rupee back, get a partial cap, or carry the full loss. Most citizens do not know India has a statutory zero-liability rule. They wait two weeks while the bank " | ||
| + | |||
| + | This article is the math: the exact circular, the words that count as a report, the timing, the escalation if the bank stalls. For the call script, see the [[1930-helpline-cyber-fraud-script|1930 helpline script]]. For the freeze on the fraudster' | ||
| + | |||
| + | ===== What " | ||
| + | |||
| + | The phrase **golden hour** in cyber-fraud writing carries two meanings with different clocks. The **first golden hour** is the 60 minutes after the fraud. It is the window in which **1930** can ask the beneficiary bank to place a lien on the fraudster' | ||
| + | |||
| + | The **second golden hour**, the one this article covers, is **3 working days** wide. It is the RBI's zero-liability window. You are not racing the fraudster, you are racing the clock the regulator set for your own bank. Report inside those 3 working days, the bank carries the loss. Miss by one day, your cap jumps from zero to thousands. Both clocks start the moment you become aware of the fraud, usually the debit SMS. Run them in parallel; the 1930 call and the bank email are two separate actions. | ||
| + | |||
| + | ===== The RBI circular in plain English ===== | ||
| + | |||
| + | The instrument that creates the zero-liability rule is RBI circular **DBR.No.Leg.BC.78/ | ||
| + | |||
| + | In one paragraph, the circular says this. If money leaves your account in an electronic transaction you did not authorise, your liability depends on **who was at fault** and **how fast you told the bank**. If the bank caused the loss, you owe nothing regardless of timing. If a third party caused it and you reported inside 3 working days, you still owe nothing. If you reported between 4 and 7 working days, your liability is capped by account type. If you reported after 7 working days, the bank's board-approved policy decides. If **you** caused the loss by sharing your OTP or PIN, the protection does not apply until you tell the bank, after which the same clock starts. | ||
| + | |||
| + | The " | ||
| + | |||
| + | ===== The 3 liability scenarios ===== | ||
| + | |||
| + | The circular sets out three buckets. Drop your own situation into one of them before you write to the bank, the bucket determines your tone and your cap. | ||
| + | |||
| + | ==== Scenario A: zero liability ==== | ||
| + | |||
| + | You owe nothing in any of these three situations. | ||
| + | |||
| + | - **Bank' | ||
| + | - **Third-party breach, you reported inside 3 working days.** Someone phished, vished or SIM-swapped you. The contributory cause is outside both you and the bank. As long as you tell the bank inside the 3-working-day window, you owe zero. | ||
| + | - **Bank failed to register your alert.** You tried to call the helpline or the branch refused to log the complaint. The clock pauses on you and resumes on them. | ||
| + | |||
| + | ==== Scenario B: capped liability ==== | ||
| + | |||
| + | If the third-party fraud is the cause and you reported between **4 and 7 working days** of the bank's communication, | ||
| + | |||
| + | ==== Scenario C: open liability ==== | ||
| + | |||
| + | If you reported **after the 7-working-day window**, the cap is gone. Your liability is whatever the bank's **board-approved customer-grievance policy** decides. Most banks will negotiate, very few will refund the full amount, all will demand the police FIR and the NCRP printout before they sit down. This is the worst place to be. The matrix and the notice template are designed to keep you out of it. | ||
| + | |||
| + | ===== The liability matrix in one table ===== | ||
| + | |||
| + | This is the annex to the 2017 circular, restated in rupees. Confirm against the version your bank cites in its **board-approved policy on customer protection**, | ||
| + | |||
| + | ^ Account type ^ Report within 3 working days ^ Report between 4 and 7 working days ^ Report after 7 working days ^ | ||
| + | | BSBDA (Basic Savings Bank Deposit Account, Jan Dhan) | ₹0 | ₹5,000 cap | Bank board policy | | ||
| + | | All other savings accounts | ₹0 | ₹10,000 cap | Bank board policy | | ||
| + | | Pre-paid payment instruments and gift cards | ₹0 | ₹10,000 cap | Bank board policy | | ||
| + | | Current accounts of MSME and individuals with limit up to ₹25 lakh | ₹0 | ₹10,000 cap | Bank board policy | | ||
| + | | Credit cards with limit up to ₹5 lakh | ₹0 | ₹10,000 cap | Bank board policy | | ||
| + | | Current and cash-credit accounts above ₹25 lakh limit | ₹0 | ₹25,000 cap | Bank board policy | | ||
| + | | Credit cards with limit above ₹5 lakh | ₹0 | ₹25,000 cap | Bank board policy | | ||
| + | |||
| + | Three things to read off this table. | ||
| + | |||
| + | - The cap is **on you**, not on the loss. A ₹4,70,000 fraud on a regular savings account, reported on day 5, costs **you** ₹10,000 and costs the **bank** ₹4, | ||
| + | - The cap is the **maximum** the bank can charge you. If the actual transaction value is lower than the cap, you pay the transaction value. A ₹3,000 fraud on a regular savings account, reported on day 5, costs you ₹3,000, not ₹10,000. | ||
| + | - **BSBDA accounts** carry the strongest protection. If a Jan Dhan account holder is the victim, the cap drops to ₹5,000 in scenario B. Most public-sector banks process these refunds without resistance. | ||
| + | |||
| + | ===== What counts as " | ||
| + | |||
| + | The circular is silent on the exact channel, but the **RBI Ombudsman has consistently held** that a citizen has reported the moment they sent a written communication that the bank received. Three channels qualify, in descending order of evidential weight. | ||
| + | |||
| + | - **Email to the bank's published cyber-fraud or customer-care address**, with the disputed transaction details and the words " | ||
| + | - **Branch visit with a written letter**, stamped received with date and time by the branch staff. Demand the stamp; do not leave with an unstamped acknowledgement. | ||
| + | - **Call to the bank's 24x7 customer-care number** with the call reference number written down. Banks log every call; ask the agent to read out the **service request number** and quote the circular by name. This works on its own only if you also send an email within 24 hours pointing back to the call ref. | ||
| + | |||
| + | What does **not** count, on its own. | ||
| + | |||
| + | - A **phone call without a written follow-up**. The call log alone has been rejected by ombudsmen when the bank claimed it was a routine enquiry. | ||
| + | - A **WhatsApp message** to a relationship manager. Personal-chat channels are not the bank's record-keeping system. | ||
| + | - A **complaint filed only at 1930 or NCRP**. The 1930 channel triggers freeze action on the **fraudster' | ||
| + | - The bank's **mobile-app " | ||
| + | |||
| + | Send the email **and** call the branch **and** raise the in-app ticket. Three records, three timestamps. If the bank later disputes the date, you have triple proof. | ||
| + | |||
| + | ===== The shadow-credit rule: 10 working days ===== | ||
| + | |||
| + | This is the half of the circular that most citizens do not read past the liability table. The bank's obligation does not end at "we accept your complaint" | ||
| + | |||
| + | In plain English, the bank must put the money back in your account first, while it investigates whether the transaction was genuinely unauthorised. You get to use the money during the investigation. If the bank later concludes the transaction was authorised, it can claw the shadow credit back. If it concludes the transaction was unauthorised, | ||
| + | |||
| + | The 10-working-day clock starts on the date you reported, not on the date the bank chose to begin its enquiry. A bank that says "we will refund after our 90-day investigation" | ||
| + | |||
| + | If the shadow credit does not appear by working day 10, you have two next moves. File a **first-level complaint with the bank's nodal officer for customer protection**, | ||
| + | |||
| + | ===== The " | ||
| + | |||
| + | The single way to lose the zero-liability protection by your own hand is **sharing your secrets**. The circular carves out an exception for cases of " | ||
| + | |||
| + | - Reading out your **OTP** to a caller claiming to be from the bank. | ||
| + | - Sharing your **UPI PIN** with a relative who then transferred funds. | ||
| + | - Letting a " | ||
| + | - Approving a **collect request** on a UPI app without reading what you were approving. | ||
| + | - Writing the **debit-card PIN** on the back of the card and losing the card. | ||
| + | |||
| + | In each of these, the circular allows the bank to argue **contributory negligence** and refuse the zero-liability protection. But, and this is the part the bank does not volunteer, **the moment you tell the bank**, a fresh clock starts. From that moment forward, any further unauthorised debits are at zero liability, even if the original fraud was your own OTP slip. The protection is not extinguished, | ||
| + | |||
| + | The bank will still pressure you to admit the OTP share in writing. Do not. State the facts neutrally in your notice: "On dd-mm-2026 at hh:mm, an unauthorised debit of ₹X occurred. I report it under the circular." | ||
| + | |||
| + | For the OTP-sharing fact patterns specifically, | ||
| + | |||
| + | ===== Step-by-step claim workflow ===== | ||
| + | |||
| + | Twelve actions, in order. Each action has a clock. | ||
| + | |||
| + | ==== Step 1: Note the time of the fraud SMS ==== | ||
| + | |||
| + | The debit alert SMS or push notification is your **reporting clock starter**. Screenshot it. Note the exact timestamp on the SMS itself, not on your phone' | ||
| + | |||
| + | ==== Step 2: Call 1930 within 60 minutes ==== | ||
| + | |||
| + | This protects the **first golden hour**, the freeze on the beneficiary' | ||
| + | |||
| + | ==== Step 3: File the NCRP complaint within 24 hours ==== | ||
| + | |||
| + | Go to https:// | ||
| + | |||
| + | ==== Step 4: Email your bank within 3 working days ==== | ||
| + | |||
| + | Use the sample notice in the next section. Send it to the bank's published cyber-fraud email **and** to the branch manager **and** to the nodal officer for customer protection. CC yourself. This is the action that triggers the zero-liability protection. | ||
| + | |||
| + | ==== Step 5: Call the branch and capture the service request number ==== | ||
| + | |||
| + | While the email is in the outbox, call the branch and read out the email. Ask for the **service request number**. Write it on the same screenshot you took in step 1. | ||
| + | |||
| + | ==== Step 6: Visit the branch within 48 hours ==== | ||
| + | |||
| + | Carry a printed copy of the email, the 1930 complaint number, the NCRP acknowledgement and your ID. Get the branch to stamp a copy of the email as **received**. Most banks will ask you to fill **Form 15G** for dispute, fill it on the spot. | ||
| + | |||
| + | ==== Step 7: Wait for the shadow credit ==== | ||
| + | |||
| + | The bank has 10 working days from step 4 to put the disputed amount back as a shadow credit. Check your statement on working day 8, 9 and 10. Take a screenshot of the credited entry. | ||
| + | |||
| + | ==== Step 8: If no shadow credit by day 10, send a reminder ==== | ||
| + | |||
| + | Email the same chain with subject " | ||
| + | |||
| + | ==== Step 9: Escalate to the bank's nodal officer ==== | ||
| + | |||
| + | Every bank publishes a **principal nodal officer for customer protection** under the **Grievance Redressal** section of its website. Email the officer; the response window is 30 days under the bank's own policy. | ||
| + | |||
| + | ==== Step 10: File with RBI Ombudsman under RB-IOS 2021 ==== | ||
| + | |||
| + | After 30 days from step 9, or earlier if the bank has rejected the complaint in writing, file at https:// | ||
| + | |||
| + | ==== Step 11: Consider a consumer commission complaint ==== | ||
| + | |||
| + | For losses above ₹50,000, parallel-file at the **District Consumer Disputes Redressal Commission** under the **Consumer Protection Act 2019**. The bank is a service provider, the dispute is a deficiency-in-service. Fee is nominal. | ||
| + | |||
| + | ==== Step 12: File RTIs to RBI, NPCI and your bank PIO ==== | ||
| + | |||
| + | To squeeze out the bank's internal file movement, file three parallel RTI applications. To **RBI** asking for the inspection-report compliance on customer protection at your bank. To **NPCI** asking for the UPI dispute SLA log for your transaction ID. To your **bank' | ||
| + | |||
| + | ===== Sample notice to your bank citing the circular ===== | ||
| + | |||
| + | Copy this verbatim. Replace the bracketed fields. Send by email to the bank's cyber-fraud address, the branch manager and the nodal officer. Print, sign, hand-deliver at the branch within 48 hours. | ||
| + | |||
| + | < | ||
| + | Subject: Unauthorised electronic transaction reported under RBI circular | ||
| + | DBR.No.Leg.BC.78/ | ||
| + | |||
| + | To, | ||
| + | The Branch Manager | ||
| + | [Bank name], [Branch name and address] | ||
| + | And, | ||
| + | The Nodal Officer, Customer Protection | ||
| + | [Bank name], [Head office address] | ||
| + | |||
| + | Date: [dd-mm-2026] | ||
| + | |||
| + | Sir/Madam, | ||
| + | |||
| + | I am [your full name], holder of account number [account no.] at your | ||
| + | [branch name] branch. I am writing under the captioned RBI circular to | ||
| + | report an unauthorised electronic banking transaction. | ||
| + | |||
| + | 1. Transaction details | ||
| + | Date and time of debit: [dd-mm-2026, | ||
| + | | ||
| + | | ||
| + | UTR or transaction ID: [12-digit string] | ||
| + | | ||
| + | |||
| + | 2. I did not authorise this transaction. I became aware of the | ||
| + | | ||
| + | a copy of which is enclosed. | ||
| + | |||
| + | 3. I have, on [date], registered the matter with the National Cyber | ||
| + | Crime Helpline 1930 (complaint reference [number]) and at the | ||
| + | | ||
| + | | ||
| + | |||
| + | 4. The present notice is delivered to you on [date], which is within | ||
| + | 3 working days of my receipt of the bank's communication about the | ||
| + | | ||
| + | is zero. | ||
| + | |||
| + | 5. I require the bank to: | ||
| + | a. Shadow-credit the disputed amount of Rs. [figure] to my account | ||
| + | within 10 working days of this notice, as mandated by the | ||
| + | circular. | ||
| + | b. Reverse all consequent charges, including any minimum-balance | ||
| + | penalties or return charges that arose from the disputed debit. | ||
| + | c. Confirm in writing the date on which the shadow credit is | ||
| + | applied and the final disposal of the dispute. | ||
| + | |||
| + | 6. Failure to comply will be escalated to the principal nodal officer, | ||
| + | the Banking Ombudsman under the Reserve Bank-Integrated Ombudsman | ||
| + | | ||
| + | | ||
| + | |||
| + | 7. Service of this notice may be acknowledged by reply email and by | ||
| + | | ||
| + | |||
| + | Yours faithfully, | ||
| + | |||
| + | [Signature] | ||
| + | [Full name] | ||
| + | [Address] | ||
| + | [Registered mobile] | ||
| + | [Email] | ||
| + | |||
| + | Enclosures: | ||
| + | - Debit SMS screenshot | ||
| + | - 1930 helpline complaint slip | ||
| + | - NCRP acknowledgement PDF | ||
| + | - Account passbook last page | ||
| + | - Aadhaar and PAN copies | ||
| + | </ | ||
| + | |||
| + | ===== When the bank refuses or stalls ===== | ||
| + | |||
| + | The most common bank tactics, and the answer to each. | ||
| + | |||
| + | **"We need 90 days to investigate before we can credit you." | ||
| + | |||
| + | **"You shared the OTP, so the circular does not apply." | ||
| + | |||
| + | **" | ||
| + | |||
| + | **"The matter is with our cyber-fraud team in Mumbai, we cannot give a timeline." | ||
| + | |||
| + | **"You have not given us the FIR yet." | ||
| + | |||
| + | The formal escalation ladder is **RBI Ombudsman**, | ||
| + | |||
| + | ===== Three real-world calculation examples ===== | ||
| + | |||
| + | Numbers make the rule stick. Each example is anonymised but the calculation is the same one you will do tonight. | ||
| + | |||
| + | ==== Example 1: ₹4,70,000 UPI fraud, reported day 1, regular savings ==== | ||
| + | |||
| + | **[Resident A]** runs a textile shop in Surat. On Monday 11 May 2026 at 11:47 PM, three UPI debits of ₹1, | ||
| + | |||
| + | She called 1930 at 11:54 PM the same night, filed NCRP at 9:00 AM Tuesday 12 May, and emailed the bank at 9:30 AM citing the circular. Tuesday 12 May was **working day 1**. She reported well inside the 3-day window. Under the circular, **her liability is zero**. The bank shadow-credited ₹4,70,000 on Friday 22 May, within the 10-working-day shadow-credit clock. | ||
| + | |||
| + | ==== Example 2: ₹85,000 card-not-present fraud, reported day 3, BSBDA ==== | ||
| + | |||
| + | **[Resident B]** is a daily-wage labourer in Patna with a Jan Dhan account at SBI. On Friday 1 May 2026, a ₹85,000 international card debit cleared. He noticed on Tuesday 5 May when the ATM showed insufficient balance and reached the branch on Wednesday 6 May with a written letter. | ||
| + | |||
| + | Counting working days, Friday is day 0, Monday is day 1, Tuesday is day 2, Wednesday is day 3. He reported on **working day 3**, just inside the zero-liability window. **Liability: | ||
| + | |||
| + | ==== Example 3: ₹12,000 IMPS fraud, reported day 9, current account ==== | ||
| + | |||
| + | **[Resident C]** runs a kirana shop with a current account at Bank of Baroda, limit ₹15 lakh. On Tuesday 14 April 2026, ₹12,000 vanished via IMPS. He assumed his accountant had paid a supplier. He realised it was fraud on Friday 24 April and emailed on Saturday 25 April. Saturday is not a working day, the email was received Monday 27 April. 14 April to 27 April is **9 working days**. He missed the 7-day window by 2 days, landing in **Scenario C, open liability**. | ||
| + | |||
| + | The bank's board policy capped refunds at 50% beyond the 7-day window. He recovered ₹6,000 and absorbed ₹6,000. Two days of confusion cost half the loss. | ||
| + | |||
| + | The pattern in all three examples is the same. **Working days, not calendar days, decide the cap.** Send the email the same day you spot the debit. Do not wait for Monday. | ||
| + | |||
| + | ===== Things to do in the next 30 minutes ===== | ||
| + | |||
| + | If you have just lost money in a cyber fraud, do these in order. | ||
| + | |||
| + | - **Save the debit SMS** and the bank push notification. Screenshot both. | ||
| + | - **Call 1930** and complete the [[1930-helpline-cyber-fraud-script|7-minute script]]. | ||
| + | - **File at NCRP** at https:// | ||
| + | - **Email your bank** using the sample notice above. Cc yourself. | ||
| + | - **Call the branch** and capture the service request number. | ||
| + | - **Diarise working day 10** in your phone for the shadow-credit deadline. | ||
| + | - **Pull the bank's nodal officer email** off the bank's website and keep it ready. | ||
| + | - **Forward this article** to every family member who banks online. | ||
| + | |||
| + | ===== Frequently asked questions ===== | ||
| + | |||
| + | ==== Is the 2017 RBI circular still in force in 2026? ==== | ||
| + | |||
| + | Yes. The circular **DBR.No.Leg.BC.78/ | ||
| + | |||
| + | ==== Does the zero-liability rule cover UPI fraud? ==== | ||
| + | |||
| + | Yes. UPI is an electronic banking channel and the circular covers all electronic banking transactions, | ||
| + | |||
| + | ==== What if my account is jointly held with my spouse? ==== | ||
| + | |||
| + | The protection attaches to the account, not the individual holder. Either joint holder can serve the notice, both should sign if available. The bank cannot demand both signatures to register the report, the law treats either signature as sufficient. Document who signed and store a copy in the joint cloud folder. | ||
| + | |||
| + | ==== Does AEPS Aadhaar-enabled fraud get the same protection? ==== | ||
| + | |||
| + | Yes, AEPS transactions are electronic banking transactions for the purpose of this circular. The zero-liability test, the 3-working-day window and the 10-working-day shadow credit all apply identically. AEPS frauds carry an additional Aadhaar-biometric-lock remedy at the UIDAI side. See [[aeps-aadhaar-fraud-recovery|AEPS Aadhaar fraud recovery]]. | ||
| + | |||
| + | ==== My account is frozen due to a lien from another fraud. Does the shadow credit still happen? ==== | ||
| + | |||
| + | Yes, but the bank may credit the shadow amount and then immediately apply the lien to the credited amount. To free the shadow credit, you must also work on the lien removal. See [[lien-amount-bank-account-removal|lien amount in bank account, how to remove]]. The two processes run in parallel. | ||
| + | |||
| + | ==== I shared my OTP and the bank says the circular does not apply. Is the bank right? ==== | ||
| + | |||
| + | Partly. The OTP share gives the bank a contributory-negligence argument, but only for transactions **before** you reported. The moment you tell the bank in writing, the protection resets for all transactions after that point. Also, courts have read down the contributory-negligence exception when the bank's own systems failed to detect obvious red flags (multiple high-value debits to a new beneficiary in minutes). Do not concede the share in writing; let the bank prove it. | ||
| + | |||
| + | ==== Can the bank refuse the shadow credit if the police FIR is not filed? ==== | ||
| + | |||
| + | No. The circular does not condition the shadow credit on an FIR. NCRP acknowledgement is sufficient. Banks routinely ask for the FIR to slow the process. Reply that the FIR is being pursued in parallel but is not a precondition under the circular. Cite paragraph 9 of the circular by name. | ||
| + | |||
| + | ==== What is the difference between shadow credit and a final refund? ==== | ||
| + | |||
| + | A **shadow credit** is a provisional reversal that lets you use the money while the bank investigates. A **final refund** is the settlement after the investigation. If the bank concludes the transaction was unauthorised, | ||
| + | |||
| + | ==== I missed the 7-working-day window. Is recovery impossible? ==== | ||
| + | |||
| + | Recovery is harder, not impossible. In Scenario C the bank's board policy controls the cap. Most banks settle for 50% to 70% of the loss after pressure from the nodal officer or the ombudsman. File the complaint, parallel-file at the consumer commission, and use the [[https:// | ||
| + | |||
| + | ==== Where do I find my bank's board-approved customer-protection policy? ==== | ||
| + | |||
| + | On the bank's website under " | ||
| + | |||
| + | ===== Sources and further reading ===== | ||
| + | |||
| + | - **RBI circular DBR.No.Leg.BC.78/ | ||
| + | - **RBI circular DCBR.BPD.(PCB/ | ||
| + | - **RBI Master Direction on Digital Payments Security Controls (DoS.CO.CSITE.SEC.No.1852/ | ||
| + | - **Reserve Bank-Integrated Ombudsman Scheme 2021**, complaint portal https:// | ||
| + | - **National Cyber Crime Reporting Portal**, https:// | ||
| + | - **National Cyber Crime Helpline**, dial **1930**. | ||
| + | - **Information Technology Act 2000, §66C** (identity theft) and **§66D** (cheating by personation using computer resource). | ||
| + | - **Bharatiya Nyaya Sanhita 2023, §318** (cheating) and **§319** (cheating by personation). | ||
| + | - **Bharatiya Nagarik Suraksha Sanhita 2023, §106** (FIR registration for cognisable offences). | ||
| + | - **Consumer Protection Act 2019**, the deficiency-in-service ground for parallel relief at the District Commission. | ||
| + | |||
| + | ===== Related articles on RTI Wiki ===== | ||
| + | |||
| + | - [[1930-helpline-cyber-fraud-script|1930 cyber fraud helpline, the exact 7-minute script]] | ||
| + | - [[bank-freeze-cyber-fraud-india|Bank freeze process after cyber fraud]] | ||
| + | - [[lien-amount-bank-account-removal|Lien amount in bank account, how to remove]] | ||
| + | - [[upi-deducted-not-received-action-plan-india|UPI deducted but not received, action plan]] | ||
| + | - [[recover-money-upi-fraud-2026|Recover money from UPI fraud, 2026 walkthrough]] | ||
| + | - [[banking-ombudsman-rbios-2021-walkthrough|RB-IOS 2021 banking ombudsman walkthrough]] | ||
| + | - [[aeps-aadhaar-fraud-recovery|AEPS Aadhaar fraud recovery]] | ||
| + | - [[sim-swap-fraud-recovery|SIM swap fraud recovery]] | ||
| + | - [[citizen-rti-playbook|Citizen RTI playbook, the pillar guide]] | ||
| + | - [[https:// | ||
| + | - [[https:// | ||
| + | |||
| + | ---- | ||
| + | |||
| + | //Last reviewed: 15 May 2026. RTI Wiki editorial team. Verify the RBI circular reference is current on rbi.org.in before citing in a legal notice.// | ||
| + | |||
| + | {{tag> | ||