The Reserve Bank of India’s Fraud Risk Management Directions, 2026 significantly strengthen the responsibilities of commercial banks, including Small Finance Banks, across the complete fraud risk lifecycle, from early detection through classification, reporting, and post fraud credit decisions. For risk, compliance, and credit teams, the framework is built around a set of precise timelines and thresholds that determine exactly when an alert must be examined, when an account must be reported, and how long a process can be allowed to run before it is considered non compliant.
Understanding these numbers is not optional. Missing a deadline under this framework does not just create an internal control gap, it creates a documented compliance failure that examiners can point to directly. This blog sets out the seven critical timelines and thresholds every banking professional working in fraud risk, credit monitoring, or compliance needs to track, along with the broader system these numbers sit within.
The 7 Critical Numbers Banks Must Track
21 days. A person, entity, or promoter must ordinarily receive at least 21 days to respond to a show cause notice before their account or facility is classified as fraud. This requirement builds natural justice directly into the classification process, meaning banks cannot rush a fraud tag through without giving the borrower a genuine opportunity to respond.
30 days. Banks should preferably complete the examination of an Early Warning Signal alert within 30 days of it being generated. Early Warning Signals are the frontline detection mechanism under this framework, and a 30 day examination window means EWS monitoring cannot be treated as a background process that gets attention only when convenient.
3 crore rupees. Red Flagged Accounts involving exposure of 3 crore rupees and above must be reported through the Central Repository of Information on Large Credits, commonly known as CRILC. This threshold determines which accounts fall under the more intensive Red Flagged Account monitoring regime rather than standard EWS tracking alone.
7 days. Once an account meets the prescribed threshold and criteria for Red Flagged Account status, that status must be reported to CRILC within 7 days. This is a tight window that requires credit monitoring and fraud risk teams to have a clear, fast internal escalation path from identification to formal reporting.
180 days. The process of classifying a Red Flagged Account as fraud, or removing its RFA status if the concerns are not substantiated, should ordinarily be completed within 180 days. This timeline is meant to prevent accounts from sitting indefinitely in an ambiguous RFA status without a final determination, which had been a recurring criticism of the earlier framework.
14 days. A Fraud Monitoring Return must be filed with the RBI within 14 days from the date of fraud classification. This reporting obligation feeds directly into the RBI’s system level view of fraud incidents across the banking sector and needs to be built into standard post classification workflow rather than handled as an afterthought.
5 years. Persons or entities classified as fraud become eligible for fresh credit facilities only after a minimum period of five years from full repayment or settlement, and even then, extending credit remains subject to the bank’s own commercial judgement. This long exclusion period reinforces that a fraud classification carries consequences well beyond the immediate account in question.
The Systems Banks Need to Build Around These Numbers
Meeting these timelines consistently requires more than awareness of the numbers themselves. The Directions require banks to strengthen board approved fraud risk management policies that clearly define roles, thresholds, and escalation paths. A Special Committee is required to provide dedicated oversight of fraud cases, ensuring that classification decisions are not left entirely to individual credit or risk officers without senior review. Early Warning Signal and Red Flagged Account systems need to function as genuinely integrated monitoring tools, not parallel, disconnected checklists. Data analytics capability for identifying unusual transaction patterns has become a baseline expectation rather than an advanced capability. Clear staff accountability and structured root cause analysis are required once a fraud is identified, so that institutions learn from each incident rather than simply closing the file. And reporting obligations, both to law enforcement agencies and to the RBI, along with active use of the Central Fraud Registry, need to be embedded into standard operating procedure.
Why This Matters Beyond Compliance
For banks, the real requirement running through this framework is that policies, systems, investigation procedures, employee responsibilities, and escalation mechanisms all need to work together as a coordinated whole. A bank can have a technically compliant EWS system and still fail the 30 day examination window if the team reviewing alerts is understaffed or untrained. A bank can have an accurate CRILC reporting process and still miss the 7 day RFA reporting deadline if internal sign offs are slow. Each of these seven numbers is really a proxy for whether the underlying operational machinery, people, process, and technology, is actually working as designed.
Conclusion
Is your bank’s fraud risk framework ready to meet these requirements? These seven numbers are only the visible surface of a much larger operational discipline that spans detection, escalation, investigation, and reporting, and institutions that build the underlying systems well will find the timelines far easier to meet.
Build This Capability with RMAI
The Risk Management Association of India supports banks and financial institutions through specialised courses and customised corporate training relevant to this framework. The Online Certificate Course in Fraud Risk Management covers fraud risk assessment, red flag identification, investigation procedures, and reporting practices directly aligned with these Directions.
For institutions building the credit monitoring and Early Warning Signal capability this framework depends on, the Online Certificate Course in Credit Risk Management strengthens portfolio monitoring and default risk identification skills.
For teams responsible for board level policy, Special Committee oversight, and governance structures, the Online Certificate Course on Governance, Risk and Compliance (GRC) connects regulatory obligation to practical board oversight design.
And for professionals building the internal controls, escalation processes, and root cause analysis capability this framework requires, the Online Certificate Course in Operational Risk Management rounds out the practical skill set needed.
Explore RMAI’s complete suite of risk management courses or visit the risk management courses page for a programme matched to your team’s needs. For institutional training enquiries, connect with RMAI at info@rmaindia.org.