Resources

RBI transaction alert rules from 1 January 2027: what changes for banks

SMS above ₹500, email for every transaction, no customer charges, and the burden of proof on the bank. What RBI changes on 1 January 2027...

From 1 January 2027, RBI's Third Amendment Directions remove the mandatory SMS alert for transactions of ₹500 or less and prohibit banks from charging customers for compliance SMS. Industry estimates put the resulting fee-income loss at around ₹300 crore a year. The savings on the hand that banks expect are smaller than it looks, because the same circular expands what every alert must contain, which makes each mandatory SMS longer and often more expensive to send.

The mechanism is a three-channel obligation with different rules per value band. SMS stays mandatory above ₹500, email becomes mandatory for every electronic banking transaction where an address is on file, and push, in-app, and instant messaging are formally recognised as additional channels rather than substitutes. Alongside this, the burden of proving customer liability moves to the bank, and the bank's systems must record the delivery time of every alert and the receipt of any customer response.

RBI transaction alert rules from 1 January 2027: what changes for banks

TLDR

This article walks through the circular in the order a bank has to act on it, and each section answers one question a CIO, compliance head, or communications owner is already asking.

  • What changed: a ₹500 floor for mandatory SMS, email made mandatory for every transaction, and push notifications named for the first time.

  • What you can no longer charge for: compliance, promotional, marketing, and awareness SMS, which closes a fee line worth roughly ₹15 to ₹18 per customer per quarter.

  • What every alert must carry: account or card number, amount, date, time, transaction channel, beneficiary, and an objection number inside the SMS itself.

  • What that does to cost: a compliant English alert runs 140 to 159 characters, one character from billing as two segments, and bills as three in Hindi.

  • What you must be able to prove: that the alert was delivered and when, because the burden of proving customer liability now sits with the bank.

  • What a bank now has to be able to do: produce a delivery-time record across every messaging vendor it uses, validate template length and encoding before a template goes live, and re-verify that its customers are still reachable on a defined cycle.

The circular takes effect for transactions undertaken on or after 1 January 2027.

What changed in RBI's Third Amendment Directions?

Formally titled the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026, the circular was issued on 24 June 2026. The obligations apply to electronic banking transactions undertaken on or after 1 January 2027. Parallel Directions were issued the same day for Small Finance Banks, Payments Banks, Local Area Banks, Regional Rural Banks, Urban Co-operative Banks and Rural Co-operative Banks.

The circular amends the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Directions, 2025 and rewrites the customer-alert and customer-liability framework that previously sat in the 2017 instructions on limiting liability in unauthorised electronic banking transactions. Four changes matter operationally.

  • A ₹500 threshold is introduced for mandatory SMS alerts, where previously none existed.

  • Email alerts become mandatory for all electronic banking transactions where an address is on file.

  • Push, in-app and instant messaging are named for the first time as legitimate additional alert channels.

  • Banks may no longer levy charges for SMS sent in compliance with regulations, or for promotional, marketing and customer awareness SMS.

Alert obligations by channel and transaction value

Channel

Transactions above ₹500

Transactions of ₹500 or less

SMS

Mandatory (para 76D)

Optional, and free to the customer if sent (para 76D)

Email

Mandatory wherever an address is on file (para 76E)

Mandatory wherever an address is on file (para 76E)

Push / in-app / instant messaging

Permitted in addition, per bank policy (para 76F)

Permitted in addition, per bank policy (para 76F)

Customer charges

Not permitted for compliance SMS (para 85)

Not permitted (paras 76D and 85)

ATM cash withdrawals sit outside this alerting requirement (para 76C).

Source: RBI Notification, Third Amendment Directions, 2026, RBI Press Release, 24 June 2026

Does RBI still require SMS alerts for transactions below ₹500?

No. From 1 January 2027, instant SMS alerts are mandatory only for electronic banking transactions exceeding ₹500. For transactions of ₹500 or less, paragraph 76D allows a bank to decide whether to send an SMS as a matter of internal policy, and if it does, it cannot charge the customer for it.

This is a genuine change rather than a clarification. Under the previous framework there was no value threshold at all, and SMS alerts were mandatory for every electronic banking transaction regardless of size.

Two things do not change with it. Email alerts remain mandatory for those same sub-₹500 transactions wherever an address is on file, so the transaction is still alerted, just not by SMS. And dropping the SMS does not reduce the bank's liability exposure, which is dealt with separately below.

Can banks still charge customers for SMS alerts?

No, not for compliance, promotional, marketing or customer awareness messages. Paragraph 85 as substituted reads: "A bank shall not levy any charges on its customers for SMS sent in compliance to extant regulations or those sent for promotional / marketing / customer awareness purposes. In case of SMS sent for other purposes, the bank may levy or waive charges as per its internal policy."

This is the single largest commercial change in the circular, and it is wider than the ₹500 threshold that has drawn most of the attention. It applies to the mandatory above-₹500 alerts too.

Before

From 1 January 2027

Governing text

Paragraph 85, RBI (Commercial Banks – Responsible Business Conduct) Directions, 2025, consolidating RBI/2013-14/381

Paragraph 85 as substituted by the Third Amendment

What it said

Charges for SMS alerts must be levied "on all customers on actual usage basis"

No charges permitted for compliance, promotional, marketing or awareness SMS

Practical effect

Banks commonly recovered roughly ₹15 to ₹18 per customer per quarter

That recovery line closes

Industry estimates reported in the trade press place the aggregate income impact at approximately ₹300 crore a year.

Source: RBI/2013-14/381, Charges Levied by Banks for Sending SMS Alerts, ET Telecom, RBI's SMS order may dent banks' income by ₹300 crore

What must a transaction alert contain under the new RBI rules?

Paragraph 76F specifies the content: "such transaction alerts shall contain relevant details pertaining to the EBT such as account/card number, amount, date, time, transaction channel, beneficiary/point of transaction, etc."

Separately, paragraph 76G(2) requires the bank to "provide a number in the transaction alert SMS itself, to which the customer can immediately send an SMS to notify her / his objection, if any."

Together, these two requirements make the compliant alert materially longer than many banks send today, which has a direct and under-appreciated cost consequence.

How can enterprises accurately measure the true cost of their customer communications?

Fyno billing summary showing 10,90,395 messages sent against 10,27,923 delivered, 62,472 undelivered and 3,094 invalid requests blocked, with reasons including numbers not on WhatsApp and invalid numbers
Reconciliation across vendors turns a billing total into an answerable question: what was submitted, what actually arrived, and what was blocked before it cost anything.

By counting segments, not messages. An SMS is billed per segment, and the segment size depends on the character set used. Plain-Latin messages encode as GSM-7, giving 160 characters in a single segment and 153 per segment once a message splits. A single non-GSM character, which includes any Indian-language script, most emoji, and curly quotation marks, forces the whole message into UCS-2, which gives 70 characters in a single segment and 67 per segment when split.

Applied to a compliant alert under paragraphs 76F and 76G(2), the arithmetic is uncomfortably tight.

Alert

Characters

Encoding

Billed segments

76F fields only, English

112

GSM-7

1

76F fields plus the 76G(2) objection number, English

159

GSM-7

1

Card transaction with merchant name as point of transaction

142

GSM-7

1

Fund transfer with a longer beneficiary name and reference

149

GSM-7

1

The same full alert in Hindi

185

UCS-2

3

A fully compliant English alert therefore lands between roughly 140 and 159 characters, which is one long beneficiary name away from billing as two segments. In any of the Indian languages a bank is expected to serve, the same alert bills as two or three from day one.

The net position for a bank is a squeeze from both directions. The recovery from customers goes to zero under paragraph 85, while the unit cost of the mandatory above ₹500 alert rises because paragraph 76F made it longer. A bank that implements this circular, switches off every sub-₹500 SMS and changes nothing else, can still finish the year with a higher SMS bill than it started with.

Measuring this accurately requires three things most banks do not have in one place: segment counts recorded at dispatch rather than at submission, per-destination reconciliation against every vendor invoice, and cost attribution by line of business so that the impact can be owned by the team that generates it.

What are the trade-offs between using email, SMS, and WhatsApp for critical alerts?

Each channel now carries a different regulatory weight, a different cost profile and a different reliability profile, and the circular removes the option of treating them as interchangeable.

SMS

Email

Push / in-app

WhatsApp / RCS

Regulatory status

Mandatory above ₹500 (76D)

Mandatory for all EBTs where an address is held (76E)

Permitted in addition only (76F)

Permitted in addition only (76F)

Cost driver

Per segment; rises with length and non-Latin scripts

Near-zero marginal cost; deliverability is the constraint

Near-zero marginal cost; token coverage is the constraint

Per conversation or per template

Reachability risk

Number ported, revoked or inactive

Address stale, bouncing or filtered

App uninstalled or notifications off

Number not registered on the service

Evidentiary value

Operator delivery receipt

Delivery and open events

Push service delivery confirmation

Delivery and read receipts

The practical reading is that push and in-app are the engagement channel, email is the newly mandatory channel that most banks have not scaled for per-transaction volume, and SMS is the channel a bank cannot exit above ₹500 no matter how good the alternatives are.

Routing is therefore an optimisation lever rather than an escape route.

What are best practices for sending regulatory and compliance alerts to banking customers?

The commonly cited practices, plain language, clear sender identity and no embedded credentials or links, remain correct. The Third Amendment adds a set of practices that are specific to it and that most existing guidance does not cover.

  • Separate the compliance alert from the marketing message. Paragraph 85 removes the ability to charge for either, but keeping the regulatory notice clean of offers protects the alert's credibility and keeps the DLT categorisation defensible.

  • Keep the compliant template inside one segment. Draft against a 160-character GSM-7 budget for English and check the encoding before the template goes to DLT, because a single stray character silently drops the whole template to a 70-character limit.

  • Preserve the objection path when you change channel. Paragraph 76G(2) puts the objection-reporting number inside the alert. If the alert moves to push, the equivalent one-tap dispute action has to move with it.

  • Verify contactability on a cycle, not once. Paragraph 76C requires the bank to verify the customer's mobile number and email address at onboarding and subsequently at pre-defined intervals prescribed in its policy.

  • Record delivery, not dispatch. Paragraph 76H requires the bank's communication systems to record the date and time of delivery of the message and the receipt of the customer's response.

  • Send email as though it matters. Paragraph 76E makes email mandatory for every transaction where an address is held, which for most banks is a step change in transactional email volume and a new deliverability problem rather than a formality.

What is the role of audit trails and message history for regulated sectors?

Audit Trail by Fyno
Audit trail showing logs of sent, delivered, opened

For an Indian bank after 1 January 2027, the audit trail stops being a governance nicety and becomes the evidence on which liability is calculated. Paragraph 76K states: "The burden of proving customer liability in complaints involving fraudulent EBTs shall lie on the bank."

Paragraph 76H sets the corresponding record-keeping obligation: "The bank's communication systems, deployed for sending alerts and receiving the responses thereto, shall record the date and time of delivery of the message and receipt of customer's response, if any."

Those two paragraphs read together mean that when a customer disputes a transaction, the bank has to produce proof that the alert was delivered and when, and the absence of that proof runs against the bank rather than the customer. The clocks are short. A customer reporting a third-party breach within five calendar days is entitled to zero liability and reversal of the transaction (para 76M). Credit card disputes require a shadow reversal within five calendar days (para 76R). Complaints must be resolved within a period the bank specifies, but not exceeding 30 calendar days (para 76Q).

The structural problem is that most large banks run four to six messaging vendors, and each vendor's console shows only its own traffic. A per-vendor delivery report cannot answer the question the circular asks, which is whether this alert to this customer was delivered at this time, when the alert may have gone out through any one of them, or through a different channel entirely. The audit trail has to sit above the vendors to be usable as evidence.

How can organizations audit message logs for compliance and dispute resolution?

The workable pattern has four properties, and the circular effectively requires all four.

  • Cross-vendor by default. One log covering every provider and every channel, so a dispute can be answered without reconciling several vendor exports.

  • Delivery-time, not submission-time. Paragraph 76H asks for the time of delivery. A record of when a message was handed to a vendor does not satisfy it.

  • Response-linked. The same record should carry the customer's response, since 76H covers receipt of the customer's response and 76G(2) creates a reply path that produces one.

  • Immutable and retained. Paragraph 76U requires records relating to the compensation mechanism to be retained for two years from the closure of that mechanism, and RBI IT audits generally expect logs that cannot be edited after the fact.

What makes a messaging platform suitable for high-risk and highly regulated use cases?

Four capabilities distinguish a platform that can carry regulated alert traffic from one that simply delivers messages.

Requirement created by the circular

Why a single CPaaS or CCM vendor cannot meet it

What the orchestration layer does

Prove the alert was delivered, and when (76H, 76K)

Each vendor logs only its own traffic; banks run four to six

One immutable delivery-time record across every vendor and channel

Keep the mandated alert inside one billed segment (76F)

Vendors bill segments, they do not prevent them

Character-overrun and encoding validation before the template goes live

Re-verify customer contactability on a cycle (76C)

A single vendor cannot see failures on the others

Unreachable destinations consolidated from delivery evidence across all vendors

Handle account, amount and beneficiary data in every alert (76F)

Multi-tenant SaaS processes the payload outside the bank

Deployment inside the bank's own cloud or on-premise environment

These sit at the orchestration layer rather than at the delivery layer. A CPaaS provider owns its own channel and reports on its own traffic. A customer communications management platform owns composition and journeys. Neither is positioned to produce a single evidentiary record across four to six vendors, because neither sees the others.

Fyno operates at that layer. It sits between a bank's core systems and its existing messaging vendors, without replacing any of them, and consolidates routing, template governance, delivery evidence and cost reconciliation into one record. It is deployed by banks and NBFCs including Federal Bank, AU Small Finance Bank, Kerala Gramin Bank, Shriram Finance and Protium, and can run fully inside the institution's own cloud or on-premise environment.

What role does intelligent routing play in minimizing messaging costs for large enterprises?

Routing reduces cost in three distinct ways, and after this circular only two of them remain available on transaction alerts.

The first is channel selection, moving traffic that does not have to travel by SMS onto a channel with a lower marginal cost. After 1 January 2027 this applies to the sub-₹500 band and to non-mandatory communications, and not to alerts above ₹500.

The second is vendor selection, routing each message to the provider with the best delivery performance and price at that moment rather than to a single contracted default. This applies to all traffic including the mandatory alerts, and it is the larger of the two levers for most banks.

The third is waste elimination, which is the least discussed and often the most immediately recoverable: messages billed as multiple segments because a template drifted over the character limit, messages sent to destinations that can no longer receive them, and invoiced volumes that exceed delivered volumes. On a mandatory alert stream that the bank can no longer charge for, every one of those is a pure loss.

What should banks do before 1 January 2027?

Frequently Asked Questions

When do RBI's new transaction alert rules come into effect?
They apply to electronic banking transactions undertaken on or after 1 January 2027. The Directions are titled 2026 because that is the year RBI issued them, not the year they take effect. The commencement is tied to the transaction date rather than the complaint date, which means transactions in 2026 continue to be governed by the previous framework even if the dispute is raised in 2027. Banks should expect to operate both rulesets in parallel through much of 2027.
Is an email alert mandatory for every bank transaction?
Yes, wherever the customer has provided an email address. Paragraph 76E requires a bank to send email alerts for all electronic banking transactions where an email address is on file, with no minimum transaction value. This is a broader obligation than the SMS requirement, which applies only above ₹500, and it is a change from the earlier position where email alerts were sent wherever registered but were not framed as mandatory for every transaction.
Can a bank replace SMS transaction alerts with push notifications?
Not above ₹500. Paragraph 76F states that SMS and email alerts shall be in addition to any other form of alerts, for example in-app or push notifications and instant messaging. Push and in-app are recognised as legitimate additional channels, not as substitutes. For transactions of ₹500 or less, where SMS is discretionary under paragraph 76D, push can carry the alert, but the email obligation under paragraph 76E still applies.
Who bears the loss if a customer reports a fraudulent transaction?
It depends on cause and timing, and the burden of proving customer liability sits with the bank under paragraph 76K. Where the fraud arises from bank negligence, the customer has zero liability and the transaction is reversed regardless of whether it was reported (para 76L). In a third-party breach reported within five calendar days, the customer again has zero liability (para 76M). Losses occurring after the customer reports are borne by the bank (para 76O).
What compensation is available for small-value transaction fraud?
For losses up to ₹50,000, paragraph 76T provides compensation of 85 per cent of the net loss amount or ₹25,000, whichever is less, once in a customer's lifetime, provided the complaint is filed within five calendar days with both the bank and the National Cyber Crime Reporting Portal or Helpline 1930. Paragraph 76U limits the mechanism to fraudulent transactions occurring up to one year from the effective date.
Why do transaction alert SMS costs go up when the rules reduce the number of alerts?
Because the content requirement in paragraph 76F makes each remaining alert longer. SMS is billed per segment, at 160 characters for plain English and 70 characters once any Indian-language script is used. A compliant alert carrying account number, amount, date, time, channel, beneficiary and an objection number typically runs to 140 to 159 characters in English and bills as two or three segments in an Indian language. The mandatory above-₹500 stream, which cannot be switched off, is the stream that gets more expensive.
How can a bank prove it sent a transaction alert?
By keeping a delivery-time record rather than a dispatch record. Paragraph 76H requires the bank's communication systems to record the date and time of delivery and the receipt of the customer's response. Because most banks route alerts through several messaging vendors, a record held by any one vendor covers only part of the traffic, which is why the evidentiary log needs to sit above the vendor layer rather than inside it.
Do these rules apply to NBFCs?
Not through this circular. The Directions issued on 24 June 2026 cover Commercial Banks, Small Finance Banks, Payments Banks, Local Area Banks, Regional Rural Banks, Urban Co-operative Banks and Rural Co-operative Banks. NBFCs are governed by their own Responsible Business Conduct Directions and are not among the seven entity types amended here.

Join our 2K+ readers

Get one actionable email a week on managing your notification infrastructure – no spam.

Fyno

Fyno is a modern infrastructure for product and engineering teams to build and manage their notification or communications service with minimum effort.