From 1 January 2027, RBI's Third Amendment Directions remove the mandatory SMS alert for transactions of ₹500 or less and prohibit banks from charging customers for compliance SMS. Industry estimates put the resulting fee-income loss at around ₹300 crore a year. The savings on the hand that banks expect are smaller than it looks, because the same circular expands what every alert must contain, which makes each mandatory SMS longer and often more expensive to send.
The mechanism is a three-channel obligation with different rules per value band. SMS stays mandatory above ₹500, email becomes mandatory for every electronic banking transaction where an address is on file, and push, in-app, and instant messaging are formally recognised as additional channels rather than substitutes. Alongside this, the burden of proving customer liability moves to the bank, and the bank's systems must record the delivery time of every alert and the receipt of any customer response.
TLDR
This article walks through the circular in the order a bank has to act on it, and each section answers one question a CIO, compliance head, or communications owner is already asking.
What changed: a ₹500 floor for mandatory SMS, email made mandatory for every transaction, and push notifications named for the first time.
What you can no longer charge for: compliance, promotional, marketing, and awareness SMS, which closes a fee line worth roughly ₹15 to ₹18 per customer per quarter.
What every alert must carry: account or card number, amount, date, time, transaction channel, beneficiary, and an objection number inside the SMS itself.
What that does to cost: a compliant English alert runs 140 to 159 characters, one character from billing as two segments, and bills as three in Hindi.
What you must be able to prove: that the alert was delivered and when, because the burden of proving customer liability now sits with the bank.
What a bank now has to be able to do: produce a delivery-time record across every messaging vendor it uses, validate template length and encoding before a template goes live, and re-verify that its customers are still reachable on a defined cycle.
The circular takes effect for transactions undertaken on or after 1 January 2027.
What changed in RBI's Third Amendment Directions?
Formally titled the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026, the circular was issued on 24 June 2026. The obligations apply to electronic banking transactions undertaken on or after 1 January 2027. Parallel Directions were issued the same day for Small Finance Banks, Payments Banks, Local Area Banks, Regional Rural Banks, Urban Co-operative Banks and Rural Co-operative Banks.
The circular amends the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Directions, 2025 and rewrites the customer-alert and customer-liability framework that previously sat in the 2017 instructions on limiting liability in unauthorised electronic banking transactions. Four changes matter operationally.
A ₹500 threshold is introduced for mandatory SMS alerts, where previously none existed.
Email alerts become mandatory for all electronic banking transactions where an address is on file.
Push, in-app and instant messaging are named for the first time as legitimate additional alert channels.
Banks may no longer levy charges for SMS sent in compliance with regulations, or for promotional, marketing and customer awareness SMS.
Alert obligations by channel and transaction value
ATM cash withdrawals sit outside this alerting requirement (para 76C).
Source: RBI Notification, Third Amendment Directions, 2026, RBI Press Release, 24 June 2026
Does RBI still require SMS alerts for transactions below ₹500?
No. From 1 January 2027, instant SMS alerts are mandatory only for electronic banking transactions exceeding ₹500. For transactions of ₹500 or less, paragraph 76D allows a bank to decide whether to send an SMS as a matter of internal policy, and if it does, it cannot charge the customer for it.
This is a genuine change rather than a clarification. Under the previous framework there was no value threshold at all, and SMS alerts were mandatory for every electronic banking transaction regardless of size.
Two things do not change with it. Email alerts remain mandatory for those same sub-₹500 transactions wherever an address is on file, so the transaction is still alerted, just not by SMS. And dropping the SMS does not reduce the bank's liability exposure, which is dealt with separately below.
Can banks still charge customers for SMS alerts?
No, not for compliance, promotional, marketing or customer awareness messages. Paragraph 85 as substituted reads: "A bank shall not levy any charges on its customers for SMS sent in compliance to extant regulations or those sent for promotional / marketing / customer awareness purposes. In case of SMS sent for other purposes, the bank may levy or waive charges as per its internal policy."
This is the single largest commercial change in the circular, and it is wider than the ₹500 threshold that has drawn most of the attention. It applies to the mandatory above-₹500 alerts too.
Industry estimates reported in the trade press place the aggregate income impact at approximately ₹300 crore a year.
Source: RBI/2013-14/381, Charges Levied by Banks for Sending SMS Alerts, ET Telecom, RBI's SMS order may dent banks' income by ₹300 crore
What must a transaction alert contain under the new RBI rules?
Paragraph 76F specifies the content: "such transaction alerts shall contain relevant details pertaining to the EBT such as account/card number, amount, date, time, transaction channel, beneficiary/point of transaction, etc."
Separately, paragraph 76G(2) requires the bank to "provide a number in the transaction alert SMS itself, to which the customer can immediately send an SMS to notify her / his objection, if any."
Together, these two requirements make the compliant alert materially longer than many banks send today, which has a direct and under-appreciated cost consequence.
How can enterprises accurately measure the true cost of their customer communications?

By counting segments, not messages. An SMS is billed per segment, and the segment size depends on the character set used. Plain-Latin messages encode as GSM-7, giving 160 characters in a single segment and 153 per segment once a message splits. A single non-GSM character, which includes any Indian-language script, most emoji, and curly quotation marks, forces the whole message into UCS-2, which gives 70 characters in a single segment and 67 per segment when split.
Applied to a compliant alert under paragraphs 76F and 76G(2), the arithmetic is uncomfortably tight.
A fully compliant English alert therefore lands between roughly 140 and 159 characters, which is one long beneficiary name away from billing as two segments. In any of the Indian languages a bank is expected to serve, the same alert bills as two or three from day one.
The net position for a bank is a squeeze from both directions. The recovery from customers goes to zero under paragraph 85, while the unit cost of the mandatory above ₹500 alert rises because paragraph 76F made it longer. A bank that implements this circular, switches off every sub-₹500 SMS and changes nothing else, can still finish the year with a higher SMS bill than it started with.
Measuring this accurately requires three things most banks do not have in one place: segment counts recorded at dispatch rather than at submission, per-destination reconciliation against every vendor invoice, and cost attribution by line of business so that the impact can be owned by the team that generates it.
What are the trade-offs between using email, SMS, and WhatsApp for critical alerts?
Each channel now carries a different regulatory weight, a different cost profile and a different reliability profile, and the circular removes the option of treating them as interchangeable.
The practical reading is that push and in-app are the engagement channel, email is the newly mandatory channel that most banks have not scaled for per-transaction volume, and SMS is the channel a bank cannot exit above ₹500 no matter how good the alternatives are.
Routing is therefore an optimisation lever rather than an escape route.
What are best practices for sending regulatory and compliance alerts to banking customers?
The commonly cited practices, plain language, clear sender identity and no embedded credentials or links, remain correct. The Third Amendment adds a set of practices that are specific to it and that most existing guidance does not cover.
Separate the compliance alert from the marketing message. Paragraph 85 removes the ability to charge for either, but keeping the regulatory notice clean of offers protects the alert's credibility and keeps the DLT categorisation defensible.
Keep the compliant template inside one segment. Draft against a 160-character GSM-7 budget for English and check the encoding before the template goes to DLT, because a single stray character silently drops the whole template to a 70-character limit.
Preserve the objection path when you change channel. Paragraph 76G(2) puts the objection-reporting number inside the alert. If the alert moves to push, the equivalent one-tap dispute action has to move with it.
Verify contactability on a cycle, not once. Paragraph 76C requires the bank to verify the customer's mobile number and email address at onboarding and subsequently at pre-defined intervals prescribed in its policy.
Record delivery, not dispatch. Paragraph 76H requires the bank's communication systems to record the date and time of delivery of the message and the receipt of the customer's response.
Send email as though it matters. Paragraph 76E makes email mandatory for every transaction where an address is held, which for most banks is a step change in transactional email volume and a new deliverability problem rather than a formality.
What is the role of audit trails and message history for regulated sectors?

For an Indian bank after 1 January 2027, the audit trail stops being a governance nicety and becomes the evidence on which liability is calculated. Paragraph 76K states: "The burden of proving customer liability in complaints involving fraudulent EBTs shall lie on the bank."
Paragraph 76H sets the corresponding record-keeping obligation: "The bank's communication systems, deployed for sending alerts and receiving the responses thereto, shall record the date and time of delivery of the message and receipt of customer's response, if any."
Those two paragraphs read together mean that when a customer disputes a transaction, the bank has to produce proof that the alert was delivered and when, and the absence of that proof runs against the bank rather than the customer. The clocks are short. A customer reporting a third-party breach within five calendar days is entitled to zero liability and reversal of the transaction (para 76M). Credit card disputes require a shadow reversal within five calendar days (para 76R). Complaints must be resolved within a period the bank specifies, but not exceeding 30 calendar days (para 76Q).
The structural problem is that most large banks run four to six messaging vendors, and each vendor's console shows only its own traffic. A per-vendor delivery report cannot answer the question the circular asks, which is whether this alert to this customer was delivered at this time, when the alert may have gone out through any one of them, or through a different channel entirely. The audit trail has to sit above the vendors to be usable as evidence.
How can organizations audit message logs for compliance and dispute resolution?
The workable pattern has four properties, and the circular effectively requires all four.
Cross-vendor by default. One log covering every provider and every channel, so a dispute can be answered without reconciling several vendor exports.
Delivery-time, not submission-time. Paragraph 76H asks for the time of delivery. A record of when a message was handed to a vendor does not satisfy it.
Response-linked. The same record should carry the customer's response, since 76H covers receipt of the customer's response and 76G(2) creates a reply path that produces one.
Immutable and retained. Paragraph 76U requires records relating to the compensation mechanism to be retained for two years from the closure of that mechanism, and RBI IT audits generally expect logs that cannot be edited after the fact.
What makes a messaging platform suitable for high-risk and highly regulated use cases?
Four capabilities distinguish a platform that can carry regulated alert traffic from one that simply delivers messages.
These sit at the orchestration layer rather than at the delivery layer. A CPaaS provider owns its own channel and reports on its own traffic. A customer communications management platform owns composition and journeys. Neither is positioned to produce a single evidentiary record across four to six vendors, because neither sees the others.
Fyno operates at that layer. It sits between a bank's core systems and its existing messaging vendors, without replacing any of them, and consolidates routing, template governance, delivery evidence and cost reconciliation into one record. It is deployed by banks and NBFCs including Federal Bank, AU Small Finance Bank, Kerala Gramin Bank, Shriram Finance and Protium, and can run fully inside the institution's own cloud or on-premise environment.
What role does intelligent routing play in minimizing messaging costs for large enterprises?
Routing reduces cost in three distinct ways, and after this circular only two of them remain available on transaction alerts.
The first is channel selection, moving traffic that does not have to travel by SMS onto a channel with a lower marginal cost. After 1 January 2027 this applies to the sub-₹500 band and to non-mandatory communications, and not to alerts above ₹500.
The second is vendor selection, routing each message to the provider with the best delivery performance and price at that moment rather than to a single contracted default. This applies to all traffic including the mandatory alerts, and it is the larger of the two levers for most banks.
The third is waste elimination, which is the least discussed and often the most immediately recoverable: messages billed as multiple segments because a template drifted over the character limit, messages sent to destinations that can no longer receive them, and invoiced volumes that exceed delivered volumes. On a mandatory alert stream that the bank can no longer charge for, every one of those is a pure loss.
What should banks do before 1 January 2027?
Quantify the fee income that closes under paragraph 85, per account and per line of business.
Re-draft every transaction alert template against paragraphs 76F and 76G(2), then measure the segment count and encoding of each one before DLT submission.
Size the new mandatory email volume under paragraph 76E and test deliverability at that volume.
Establish a cross-vendor delivery record that satisfies paragraph 76H before the reversed burden of proof in paragraph 76K takes effect.
Set the paragraph 76C re-verification cycle for mobile numbers and email addresses, and identify unreachable destinations already in the base.
Note that the compensation mechanism under paragraph 76T is time-boxed by paragraph 76U to fraudulent transactions occurring up to one year from the effective date.