The Reserve Bank of India (RBI) has released the Draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026 [Ref: DOR.AML.REC.No./14-01-001/2026-27], introducing a formal Standard Operating Procedure (SOP) for banks to identify, act on, and report Suspected Money Mule Accounts used to facilitate cyber-enabled financial fraud.
For banks, NBFCs, and compliance teams, this draft is more than a routine update — it lays down concrete timelines, accountability triggers, and documentation requirements that will need to be built into internal AML/KYC frameworks well before the implementation deadline.

Why This Amendment Was Introduced
The SOP has been framed in response to a directive from the Hon’ble Supreme Court, dated August 4, 2026, which instructed RBI to adopt and circulate a uniform procedure for banks to place temporary debit holds on accounts or amounts linked to money-mule activity and cyber-enabled fraud.
The objective is twofold: to give banks a fast, standardised mechanism to intercept fraud proceeds, while also ensuring genuine customers are not inconvenienced by prolonged or unwarranted restrictions on their accounts. The Directions are issued under Section 35A of the Banking Regulation Act, 1949.
What Is a “Money Mule Account”?
Under the draft SOP, a Money Mule Account is one that is used — knowingly or unknowingly — to receive, layer, or transfer proceeds of cyber-enabled financial fraud (such as phishing, identity theft, or smurfing) on behalf of another person. Notably, the account holder’s intent is not a precondition — even an unwitting participant’s account can attract this classification and the resulting action.
Who Does This Apply To?
The SOP applies to:
- All Commercial Banks, including Small Finance Banks, Payments Banks, Regional Rural Banks, and Local Area Banks
- All Urban Cooperative Banks
It does not apply to nodal accounts, pool accounts, escrow accounts, or other special-purpose accounts such as dividend or share capital accounts.
What Triggers Action Under the SOP?
A “Suspected Money Mule Transaction” is defined as a transaction of ₹1,000 or above, flagged by a bank’s transaction-monitoring systems — including AI/ML-based tools — where the activity is:
- Unusual or disproportionate to the account holder’s declared profile, or
- Linked to an account already reported as fraudulent or mule-operated
The Step-by-Step Procedure and Timelines
The SOP lays out a structured, time-bound process banks must follow once a suspected transaction or account is flagged:
| Step | Action | Timeline |
|---|---|---|
| 1 | Bank places a temporary debit hold on the transaction, or the entire account if warranted | Immediately |
| 2 | Bank notifies the account holder — stating reasons, removal process, and officer contact details | Immediately (digital) / EOD next day (physical) |
| 3 | Account holder submits explanation or justification | Within 20 days of the hold |
| 4 | Bank decides to release the hold, continue it and report to the Jurisdictional Police Authority via NCRP-CFCFRMS, or follow an LEA/Competent Authority direction | Within 10 days of receiving explanation, or 30 days from the hold if none is received |
| 5 | Bank acts on any LEA/Competent Authority instruction received | Within 30 days from the date of reference |
| 6 | Bank automatically lifts the hold if no LEA/Competent Authority instruction is received | On the 31st day from the date of reference |
Maximum hold duration: 60 days from the date of the original hold (30 days for Steps 3–4, plus a further 30 days for Steps 5–6), unless extended by a specific direction from a Law Enforcement Agency or court.
What Banks Need to Build Into Their Internal Policies
The SOP requires each bank’s internal policy to address:
- Technology and AI/ML solutions for detecting suspected mule transactions
- Clear norms distinguishing transaction-level holds from account-level holds — with account-level holds to be used only as a last resort, in exceptional circumstances
- Standardised communication templates for notifying customers at each stage
- A defined process for linkage with the Ministry of Home Affairs’ NCRP-CFCFRMS portal
- A customer grievance redressal mechanism
Record-Keeping and Ongoing Obligations
Banks will be required to:
- Maintain a centralised MIS capturing the date and reasons for each hold, correspondence with the account holder, references and directions from LEAs, and the final status of every case
- Continue filing Suspicious Transaction Reports (STRs) with FIU-IND as per existing obligations — this SOP does not replace or dilute that requirement. Notably, failure to file an STR on a confirmed mule account will be deemed non-compliance with the Directions
- Retain records for a minimum of 5 years from the date of the hold, or 10 years if the account is subsequently closed
- Extend enhanced monitoring to the account holder’s other active accounts and relationships
Grievance Redressal
Banks must designate Nodal Officers at the Regional, Zonal, or Head Office level to handle coordination and complaints arising from action taken under this SOP. Officer contact details must be displayed on the bank’s website and at all branches, and complaints must be acknowledged and resolved within 30 days.
Implementation Timeline
Banks are required to implement the SOP on or before April 1, 2027, though they may choose to adopt it earlier. It’s worth noting that this is currently a draft circular, open for stakeholder comments as per RBI’s usual consultative process — the final version may see some refinements before it takes effect.
Our Perspective
This draft signals a clear shift in regulatory expectation: from passive transaction monitoring to active, time-bound accountability on the part of banks. The tight timelines — a 20-day customer response window, a 10–30 day decision cycle, and a hard 60-day cap — leave little room for delay or ambiguity in how banks structure their fraud-response systems.
For banks and NBFCs, this means internal AML/KYC policies, AI/ML-based detection systems, customer communication protocols, and grievance mechanisms will all need review and, in many cases, redesign well ahead of the April 2027 deadline.
At IPPC Group, we work closely with banking and financial-sector clients on AML/KYC policy design, internal audit checkpoints for transaction monitoring, and compliance documentation. If your organisation is assessing how this draft SOP will affect your existing processes, we’d be glad to help you get ahead of it.
Written by IPPC Group | www.ippcgroup.com For queries, reach out to us at sailfreely(Replace this parenthesis with the @ sign)capasricha.com
