Imagine a Thursday morning in the third week of the month. Salaries are due on Saturday. You open your banking app to release the payroll file and find that a ₹38,000 payment that arrived yesterday from a new customer has a small tag beside it, and the money cannot be moved. Nobody has accused you of anything. A monitoring system at the bank has decided that the payment looks suspicious, and the rule it is following says it may stop that money from leaving your account until the matter is cleared.
That scene is not yet reality. It is where a draft from the Reserve Bank of India, released on 11 September 2026, could lead for a small firm that is careless about its own paper trail. The draft deserves a careful reading from every proprietor with a current account, because it is a rare moment when a cyber-fraud rule is written to protect the account holder at the same time as it restrains him.
How a Supreme Court order became a bank procedure
The background is the digital arrest scam, in which a victim is told by a caller posing as an officer that she is under investigation and must move money to a "safe" account. The stolen money does not stay where it lands. It is passed quickly through other accounts, often those of ordinary people who were recruited, deceived or paid a small fee to lend theirs. These are called mule accounts.
On 4 August 2026, in a suo motu matter on digital arrest victims, the Supreme Court directed the Reserve Bank to prepare a standard operating procedure for accounts involved in cyber fraud and mule accounts within four weeks, according to a summary of the order published by IndianPayCalculator. Medianama reports that the RBI answered with a consultation draft on 11 September, comments closed on 2 October, and the proposed effective date is 1 April 2027, although banks may adopt it earlier.
I have not seen a final version as of today, 6 October, so everything below describes a draft that may change.
What the draft says, in the words a shopkeeper needs
Reading Medianama's analysis and the TaxGuru summary of the draft side by side, these are the points that matter to a small business.
- A bank may place a temporary debit hold when its monitoring flags a suspected mule transaction of ₹1,000 or more, or a suspected mule account, using tools such as AI and machine learning, transaction patterns out of line with the customer's profile, or links to accounts already reported as fraudulent.
- A debit hold stops money going out. Credits still come in.
- The default is a hold on the disputed transaction. Holding the entire account is described as a last resort in exceptional circumstances.
- The bank must tell the account holder immediately by SMS or email, or by physical notice by the end of the next working day, with reasons and the process for removing the hold.
- The holder gets about twenty days to explain. If the bank remains concerned it reports to the police through the National Cybercrime Reporting Portal.
- A bank-initiated hold cannot run beyond 60 days unless law enforcement or a competent authority instructs otherwise.
- Nodal, pool and escrow accounts are left out.
The commercial banks and urban cooperative banks that serve most small businesses fall within scope. The reports I read do not address business current accounts specifically, so I will not claim the draft treats them differently from savings accounts. That silence is itself part of the problem.

Why a legitimate business can be caught
The useful way to think about this is to ask how a small firm's account can look wrong to a machine when the owner has done nothing wrong. There are at least three ways.
The first is a payer who is himself a victim. Your customer in another city pays you ₹38,000 for a machine part. Unknown to you, the money came from an account that a scammer had just emptied. To the bank, the trail leads from a reported fraud into your account.
The second is a payment that does not fit your profile. A workshop that normally receives ₹5,000 to ₹15,000 a week gets a ₹4 lakh advance for a large order. That is a good week for you. It is also a disproportion that a model trained on mule behaviour may flag.
The third is a borrowed account. Small firms are sometimes asked by a friend, a supplier or a relative to "receive a payment on my behalf, just this once". Every such favour is an invitation to a freeze, because that is exactly how mule networks operate, and the person doing the favour often does not realise it.
None of these requires a cyber attack on your own systems. That is what makes the rule a data-protection and fraud-risk issue for a small firm, not only a banking one.
What I like in the draft, and where it falls short
My view is that a time-limited, transaction-first hold with a duty to notify is a real improvement on the present position, in which holds placed after a police request can run for long periods and the holder often learns of them only when a payment fails. A cap of 60 days, a default of freezing only the disputed amount, and a written reason are all steps toward predictability.
But Medianama's analysis flags gaps that a small employer should care about. It reports that the draft provides no compensation or interest for wrongful holds, no mandatory human review before an AI-flagged hold takes effect, and no requirement on banks to report their false-positive rates. It also says the draft does not carve out essential needs during a hold, and that holds ordered by the police remain outside this framework.
For a salaried individual, a week of frozen funds is an inconvenience. For a firm with a payroll date, a GST payment date and a supplier waiting at the gate, a week is a crisis. A hold on ₹38,000 could be tolerable. A hold on the whole account is not. I would want the final text to say, at minimum, that an account-level hold cannot block statutory dues and wages, and that a bank must show a human officer reviewed the flag before an account-level action. That is my argument, not something the draft contains. The comment window closed on 2 October, but trade bodies and chambers can still write to the Reserve Bank, and the final text is not yet out.
Five habits that make a hold shorter or less likely
- Keep the bank's contact details alive. The draft's clock starts with the notice. If the mobile number linked to the account is that of a former accountant, you will find out late and have less of your twenty days left. Make one named person responsible for watching bank alerts.
- Build a payment file for every large or first-time receipt. A purchase order, a quotation, an invoice, a delivery note and the customer's GST number. If the bank asks you to explain, you attach the file instead of drafting a story from memory.
- Collect only from the person you billed. If a customer wants a relative or another company to pay, put that on the invoice or in writing beforehand. Never accept money for someone else's account.
- Do not lend your account. Not to a relative, not to a friend who has "a small business but no current account yet", not to staff who need a place to receive an order.
- Keep a backup route. A second account, preferably at a different bank, with enough balance to run a week of wages and statutory dues. This costs a little in idle money. It is cheaper than a missed payroll.
If a hold does arrive
Respond in writing on the first day, not the nineteenth. Attach the payment file. Ask the bank in the same message what has been held, the transaction or the account, and which clause it relies on. Use the bank's designated nodal officer for the grievance, and keep a copy of every acknowledgement. If you believe a customer paid you with stolen money, report it yourself through the national helpline 1930 or the portal at cybercrime.gov.in, and do so early, because a report you file yourself shows good faith before anyone asks.
The wider lesson is one I have repeated to small enterprises for thirty years in other forms. A business relationship with a bank is built before the trouble, not during it. The proprietor who shows the bank clean statements, consistent invoices and a named contact is believed faster when something looks odd. As cyber-fraud rules tighten, that credibility is quietly becoming a form of working capital, and unlike cash, it costs nothing to build.
📬 Join 49,000+ Indian Professionals
The Inner Circle newsletter delivers curated MSME intelligence, leadership wisdom, and strategic insights every week — completely free. Plus receive the 20 Gita Lessons PDF as a welcome gift.
Subscribe Free →Ready to Go Further?
Is your MSME cyber-ready? I offer focused digital-risk assessments to help small businesses protect their data and reputation.
Book a Cyber-Risk ReviewPublished 8 October 2026 · dibyenduchoudhury.com