Need Expert Accounting Outsourcing Services? Click here to Get Started!

Contact Us  |  RFP  |  Careers

IPPC logo
RBI Draft KYC Amendment Directions, 2026 A New SOP to Tackle Suspected Money Mule Accounts - Regulatory Update - IPPC GROUP I.P. Pasricha & Co CA Firm Chartered Accountant

RBI’s Draft KYC Amendment Directions, 2026: A New SOP to Tackle Money Mule Accounts

The Reserve Bank of India (RBI) has released the Draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026 [Ref: DOR.AML.REC.No./14-01-001/2026-27], introducing a formal Standard Operating Procedure (SOP) for banks to identify, act on, and report Suspected Money Mule Accounts used to facilitate cyber-enabled financial fraud.

For banks, NBFCs, and compliance teams, this draft is more than a routine update — it lays down concrete timelines, accountability triggers, and documentation requirements that will need to be built into internal AML/KYC frameworks well before the implementation deadline.

Why This Amendment Was Introduced

The SOP has been framed in response to a directive from the Hon’ble Supreme Court, dated August 4, 2026, which instructed RBI to adopt and circulate a uniform procedure for banks to place temporary debit holds on accounts or amounts linked to money-mule activity and cyber-enabled fraud.

The objective is twofold: to give banks a fast, standardised mechanism to intercept fraud proceeds, while also ensuring genuine customers are not inconvenienced by prolonged or unwarranted restrictions on their accounts. The Directions are issued under Section 35A of the Banking Regulation Act, 1949.

What Is a “Money Mule Account”?

Under the draft SOP, a Money Mule Account is one that is used — knowingly or unknowingly — to receive, layer, or transfer proceeds of cyber-enabled financial fraud (such as phishing, identity theft, or smurfing) on behalf of another person. Notably, the account holder’s intent is not a precondition — even an unwitting participant’s account can attract this classification and the resulting action.

Who Does This Apply To?

The SOP applies to:

  • All Commercial Banks, including Small Finance Banks, Payments Banks, Regional Rural Banks, and Local Area Banks
  • All Urban Cooperative Banks

It does not apply to nodal accounts, pool accounts, escrow accounts, or other special-purpose accounts such as dividend or share capital accounts.

What Triggers Action Under the SOP?

A “Suspected Money Mule Transaction” is defined as a transaction of ₹1,000 or above, flagged by a bank’s transaction-monitoring systems — including AI/ML-based tools — where the activity is:

  • Unusual or disproportionate to the account holder’s declared profile, or
  • Linked to an account already reported as fraudulent or mule-operated

The Step-by-Step Procedure and Timelines

The SOP lays out a structured, time-bound process banks must follow once a suspected transaction or account is flagged:

StepActionTimeline
1Bank places a temporary debit hold on the transaction, or the entire account if warrantedImmediately
2Bank notifies the account holder — stating reasons, removal process, and officer contact detailsImmediately (digital) / EOD next day (physical)
3Account holder submits explanation or justificationWithin 20 days of the hold
4Bank decides to release the hold, continue it and report to the Jurisdictional Police Authority via NCRP-CFCFRMS, or follow an LEA/Competent Authority directionWithin 10 days of receiving explanation, or 30 days from the hold if none is received
5Bank acts on any LEA/Competent Authority instruction receivedWithin 30 days from the date of reference
6Bank automatically lifts the hold if no LEA/Competent Authority instruction is receivedOn the 31st day from the date of reference

Maximum hold duration: 60 days from the date of the original hold (30 days for Steps 3–4, plus a further 30 days for Steps 5–6), unless extended by a specific direction from a Law Enforcement Agency or court.

What Banks Need to Build Into Their Internal Policies

The SOP requires each bank’s internal policy to address:

  • Technology and AI/ML solutions for detecting suspected mule transactions
  • Clear norms distinguishing transaction-level holds from account-level holds — with account-level holds to be used only as a last resort, in exceptional circumstances
  • Standardised communication templates for notifying customers at each stage
  • A defined process for linkage with the Ministry of Home Affairs’ NCRP-CFCFRMS portal
  • A customer grievance redressal mechanism

Record-Keeping and Ongoing Obligations

Banks will be required to:

  • Maintain a centralised MIS capturing the date and reasons for each hold, correspondence with the account holder, references and directions from LEAs, and the final status of every case
  • Continue filing Suspicious Transaction Reports (STRs) with FIU-IND as per existing obligations — this SOP does not replace or dilute that requirement. Notably, failure to file an STR on a confirmed mule account will be deemed non-compliance with the Directions
  • Retain records for a minimum of 5 years from the date of the hold, or 10 years if the account is subsequently closed
  • Extend enhanced monitoring to the account holder’s other active accounts and relationships

Grievance Redressal

Banks must designate Nodal Officers at the Regional, Zonal, or Head Office level to handle coordination and complaints arising from action taken under this SOP. Officer contact details must be displayed on the bank’s website and at all branches, and complaints must be acknowledged and resolved within 30 days.

Implementation Timeline

Banks are required to implement the SOP on or before April 1, 2027, though they may choose to adopt it earlier. It’s worth noting that this is currently a draft circular, open for stakeholder comments as per RBI’s usual consultative process — the final version may see some refinements before it takes effect.

Our Perspective

This draft signals a clear shift in regulatory expectation: from passive transaction monitoring to active, time-bound accountability on the part of banks. The tight timelines — a 20-day customer response window, a 10–30 day decision cycle, and a hard 60-day cap — leave little room for delay or ambiguity in how banks structure their fraud-response systems.

For banks and NBFCs, this means internal AML/KYC policies, AI/ML-based detection systems, customer communication protocols, and grievance mechanisms will all need review and, in many cases, redesign well ahead of the April 2027 deadline.

At IPPC Group, we work closely with banking and financial-sector clients on AML/KYC policy design, internal audit checkpoints for transaction monitoring, and compliance documentation. If your organisation is assessing how this draft SOP will affect your existing processes, we’d be glad to help you get ahead of it.


Written by IPPC Group | www.ippcgroup.com For queries, reach out to us at sailfreely(Replace this parenthesis with the @ sign)capasricha.com

Subscribe Our Newsletter


I.P. Pasricha & Co – ISO Certified Firm
ISO/IEC 27001:2022
ISO 9001:2015

Copyright © 2023 I.P. Pasricha & Co. | All Rights Reserved 

Scroll to top