Quick Take
- The Reserve Bank of India proposes debit holds of up to 60 days on accounts linked to money mules and cyber fraud.
- The rules are proposed to start on April 1, 2027, or earlier if a bank adopts them.
- Comments are open until October 2, 2026, giving fintechs a narrow window to respond.
The Reserve Bank of India has proposed letting banks freeze debits on suspected money mule accounts for up to 60 days. The draft was issued on September 11, 2026. It applies to every category of bank.
A money mule account is one used to move stolen or illegal money through the banking system. The draft would let a bank block outgoing transactions while it checks a flagged account. Incoming money is not stopped the same way.
The Reserve Bank of India acted on an order from the Supreme Court of India dated August 4, 2026. The court told the central bank to write a standard operating procedure for handling mule and cyber-fraud accounts. The draft is that procedure.
What is the RBI actually proposing?
The draft lets a bank place a temporary debit hold on an account it suspects of mule activity or cyber fraud. A debit hold stops money leaving the account. It is narrower than a full freeze, which locks the whole account.
The hold can run for up to 60 days. The Reserve Bank of India frames this as the outer limit, not a default. The idea is to stop fraudsters draining an account before police can act.
The draft names the trigger sources too. Banks can act on their own fraud-detection tools. They can also act on complaints filed through the National Cybercrime Reporting Portal.
The rules are proposed to apply from April 1, 2027. A bank may adopt them earlier if it is ready. That gives the sector about 18 months of lead time from the draft date.
Which banks and platforms are covered?
The draft covers all commercial banks. That includes small finance banks, payments banks, regional rural banks and local area banks. Urban cooperative banks are covered as well.
This is a wide net. Payments banks sit behind many fintech wallets and neobank front ends. So a rule aimed at banks reaches the startups built on top of them.
The Reserve Bank of India issued one consolidated draft for all these entities. It said final directions will be issued separately for each type later. The signature on the release is Brij Raj, Chief General Manager.
| Item | Detail |
|---|---|
| Draft issued | September 11, 2026 |
| Maximum debit hold | Up to 60 days |
| Proposed start date | April 1, 2027 |
| Comment deadline | October 2, 2026 |
| Supreme Court order | August 4, 2026 |
| Grievance response window | 30 days |
What must Indian fintechs build to comply?
Fintechs and their bank partners must build real-time fraud scoring. The draft expects banks to flag suspect accounts fast, not days later. Detection has to run at the speed of a transfer.
They also need a link to the National Cybercrime Reporting Portal. A complaint on that portal can trigger a hold. Systems must read those alerts and act on them.
Customer notification is the third piece. A blocked customer must be told, and told clearly. This means an alert system tied to the hold event.
A grievance process is the fourth piece. The draft sets a 30-day window for a bank to respond to a complaint. If the reply is late or poor, the customer can escalate to the RBI Ombudsman.
None of this is optional wiring. It is the cost of running an account product in India after April 2027. Start scoping it now.
What happens next?
The comment window closes on October 2, 2026. Banks, fintechs and the public can file feedback through the Reserve Bank of India website or by email. The central bank will read the feedback before writing final rules.
Final directions will come after that review. The Reserve Bank of India will issue them separately for each bank type. The April 1, 2027 date is the proposed start, not a confirmed one.
The draft is public and open. This is the moment to shape it. A fintech that waits for the final rule has skipped its only say.
StartupFeed Insight
The 60-day number will grab headlines, but the real work sits in the plumbing. A debit hold is only as good as the fraud score that triggers it and the alert that tells the customer why. Fintechs that already run transaction monitoring have a head start. Those relying on a partner bank’s stack should ask hard questions this quarter, because the bank’s compliance gap becomes theirs. Watch for the final directions in the first quarter of 2027. Expect the biggest friction not in building holds, but in releasing money wrongly held without angering good customers.
— Avinash Mishra, Business Correspondent
What this means for you: If you run an account or wallet product, budget this quarter for fraud scoring, cybercrime-portal alerts, customer notifications and a 30-day grievance flow before April 2027.
Frequently Asked Questions
Have a tip? Write to us at editorial@startupfeed.in.



