Three separate Reserve Bank of India moves are about to change the experience of holding a credit card in India, and they pull in the same direction: more control for the cardholder, less room for the bank. The first is a tightening of how banks sell. The second is a quiet acceleration of how fast credit behaviour shows up on a bureau file. The third, added in late June 2026, rewrites who carries the loss when a card transaction turns out to be fraud. None of the three has made the headlines a rate cut would, yet all of them will be felt by anyone who carries a card.
The selling rules arrive first in importance. On 15 June 2026 the RBI issued the Commercial Banks (Responsible Business Conduct) Second Amendment Directions, 2026, with effect from 1 January 2027. They take direct aim at two practices most cardholders have run into without quite naming them: being pushed into add-on products to get the thing they actually came for, and discovering, too late, that what they were sold was never right for them.
The end of "buy this to get that"
The headline provision is a ban on compulsory bundling. The RBI defines it plainly, as the practice of making one product or service conditional on taking another, whether the bank's own or a third party's. The familiar version is the home-loan applicant nudged into a term-insurance policy from the bank's sister company, sometimes financed by a fresh loan on top of the original one. On the cards side it shows up as the "your card upgrade comes with this insurance add-on" pitch, or the protection plan that appears on a statement after a hard-sell phone call.
From 2027 that conditionality is not allowed. Where a product genuinely is needed as a risk mitigant, the customer must be free to buy it from any provider, not only the one the bank prefers. Bundling stays legal when it is voluntary or genuinely free of extra cost, so a complimentary add-on is fine. What ends is the version where the answer to "do I have to take this?" was effectively yes.
A refund becomes mandatory when mis-selling is proven
The second pillar is what happens after a bad sale. Until now, getting money back for a mis-sold financial product meant a grievance process with an uncertain outcome. The new directions make the refund mandatory once mis-selling is established. The bank must return the entire amount paid, cancel the sale where that applies, and compensate the customer for any loss caused by the mis-selling under its approved policy.
Three supporting mechanics give that teeth. Banks must set up a way to take feedback within 30 days of selling any financial product, to confirm the customer actually understood its features and risks. A customer can lodge a mis-selling complaint within the timeline set by the relevant regulator, or within 30 days of receiving the signed terms where no timeline is specified. And banks cannot fund the purchase of a product, their own or a third party's, out of a sanctioned loan without the customer's explicit consent. The RBI has also moved against "dark patterns", the interface tricks that steer people into choices they did not intend, across bank websites and apps.
For a cardholder, the practical shift is in bargaining power. The protection plan you never asked for, the insurance quietly added to a limit-enhancement call, the cover sold on a promise it did not keep: each of these now sits inside a framework where a proven mis-sale has to be unwound and refunded, not argued over indefinitely.
The 11 dark patterns RBI actually named, and the date that keeps getting reported wrong
The dark-patterns ban deserves more than a mention. RBI's final directions name 11 specific patterns banks and NBFCs can no longer use in an app or on a website: false urgency (fake countdown timers), basket sneaking (charges added at checkout without consent), confirm shaming, forced action, subscription traps, interface interference (burying the "no" option), bait and switch, drip pricing, disguised advertisements, nagging, and trick wording such as double-negative consent checkboxes. The default on any consent toggle must now be "No" or "I do not agree", not a pre-ticked "Yes" a customer has to notice and undo.
One date is worth pinning down, because two different numbers are circulating for the same rule. A February 2026 draft proposed 1 July 2026 as the effective date, and several July news reports have repeated that date as though it were final. It is not. The RBI's final Responsible Business Conduct (Second Amendment) Directions, 2026, issued 15 June 2026, push the effective date to 1 January 2027. If a headline tells you banks must already have stopped bundling or dark patterns as of July 2026, treat it as reporting on the superseded draft. The obligations are real; the deadline is six months later than the version still being shared.
Bank accountability does not stop at the point of sale, either. A mis-sale by a relationship manager, a call-centre agent, or a third-party DSA is the bank's liability, not a pass-the-blame moment. Banks must publish the list of their authorised agents so a customer can verify a caller is genuine, and sales calls are restricted to a fixed daytime window, with anyone on the Do Not Disturb registry off-limits entirely.
Your credit file now moves in days, not weeks
Running alongside the conduct rules is a change to credit reporting that has been arriving in stages. Until 2025, banks updated the bureaus once a month, so a payment cleared early in a cycle could take until month-end to register. The RBI shortened that to a fortnightly cycle, every fifteen days, from 1 January 2025. Through 2026 the cadence has tightened further towards weekly reporting, with lenders submitting data on a near-weekly schedule rather than twice a month.
The effect cuts both ways, and for a careful cardholder it cuts favourably. A full, on-time payment lifts your file faster. A closed card or a cleared default drops off sooner. A wrongly reported late payment can be disputed and corrected on a tighter loop, and the directions on dispute handling require resolution within set timelines. The flip side is that a genuine miss also surfaces quickly, so the cushion that monthly reporting once gave a late payer is gone. The discipline that builds a strong score is the same as it always was, and we have written the full playbook for that in our guide to building a 780-plus CIBIL score on a single card. What has changed is the speed at which that discipline, or its absence, becomes visible.
The fraud rules: the burden of proof moves to the bank
On 24 June 2026 the RBI issued amendment directions overhauling customer protection in fraudulent electronic banking transactions, effective for transactions from 1 January 2027 at commercial banks. The structural change sits in one sentence of the directions: the bank must establish the customer's liability in a fraud complaint, not the other way around. Until now the practical burden fell on the victim to prove they had not been careless. From 2027 the default flips.
The directions then draw the liability map. Where the fraud results from the bank's own negligence (a missed mandatory transaction alert, no working 24x7 reporting channel, a security breach, internal fraud, or failing to act once fraud is reported), the customer has zero liability no matter when the fraud is reported. Where the failure sits with a third party (a payment gateway, payment aggregator, app provider, or telecom operator), zero liability applies if the customer reports the transaction within five calendar days. Where the customer's own negligence caused the loss (a shared OTP or PIN, a malicious app, ignoring a specific scam warning from the bank), the customer bears losses only up to the moment of reporting; everything after the report is the bank's. Banks must resolve fraud complaints within 45 calendar days for domestic transactions and 60 for cross-border ones, and every reversal is value-dated back to the original transaction date.
Two supporting duties matter day to day. Banks must send an instant SMS alert for every electronic transaction above ₹500 (email alerts wherever an address is on file), and must run round-the-clock reporting channels that acknowledge a complaint immediately with a number and timestamp. The alert is not a courtesy; a missed mandatory alert is itself bank negligence under the definitions.
Card fraud gets a five-day shadow credit
For credit cards specifically, the directions introduce the shadow reversal: once a cardholder reports a fraudulent transaction, the bank must post a temporary credit equal to the disputed amount within five calendar days of notification. The cardholder cannot spend that provisional credit while the investigation runs, but no interest or charges accrue on the disputed sum. The practical pain this removes is familiar to anyone who has disputed a card transaction: the amount sitting on the statement, attracting interest and eating the credit limit, while the case crawls. From 2027 the disputed amount is neutralised within a week of the report.
A one-time payout for small scam losses
The directions also create something Indian banking regulation has not had before: a compensation mechanism for scam victims whose own negligence let the fraud happen. A bona fide individual customer (including a sole proprietor) who loses up to ₹50,000 in a fraudulent electronic transaction can claim 85 percent of the net loss or ₹25,000, whichever is lower. The conditions are strict: the fraud must be reported to both the bank and the National Cyber Crime Reporting Portal (or helpline 1930) within five calendar days, the benefit can be used exactly once in a customer's lifetime, and the mechanism runs for one year from the date the directions take effect. The bank must pay within five calendar days of receiving a completed application.
The caveats belong next to the headline. The ceiling is low relative to the problem (fraud losses in India ran to an estimated ₹22,495 crore in 2025), larger losses get no relief from this mechanism, and the once-in-a-lifetime cap makes it a safety net for a first mistake, not insurance. But for the most common scam sizes, a UPI-linked card drained a few thousand rupees at a time, it converts a total loss into a mostly recovered one, provided the report goes in fast.
What this means in practice
Put the three together and the cardholder of 2027 is better protected and more exposed at the same time. Better protected because the bank can no longer make an add-on the price of admission, and can no longer keep the proceeds of a sale it should not have made. More exposed because the credit file that lenders price you on refreshes almost in real time, so there is nowhere for a slip to hide for three weeks.
None of this is a reason to change which card you hold. It is a reason to change three habits. First, treat every add-on pitch, on a call, in an app, at a branch, as optional until proven otherwise, and say no to anything presented as a condition of the product being applied for. Keep the signed terms, because the complaint window runs from the day they arrive. Second, assume the bureau file is current within the week, and run the card accordingly: full payment on the statement date, utilisation under 30 percent, no scramble for fresh credit that serves no purpose. Third, make five days the number that lives in memory: report any suspect transaction to the bank and to helpline 1930 inside five calendar days, because that single deadline decides zero liability in a third-party breach, starts the shadow-credit clock, and preserves eligibility for the compensation route.
The RBI has spent two years shifting the balance of a credit-card relationship toward the person holding the card. The 2027 rules are the clearest move yet. The cardholders who benefit most will be the ones who know the rules exist and use them.
Sources
- Reserve Bank of India, Commercial Banks (Responsible Business Conduct) Directions, 2025 and amendments
- Business Standard, RBI tightens norms on bundled products; lenders to refund for mis-selling (15 June 2026)
- Upstox, New RBI rules to stop mis-selling and compulsory bundling by banks from January 2027 (15 June 2026)
- Outlook Business, RBI's New Mis-Selling Rules Explained: What Changes for Bank Customers from 2027
- Business Standard, RBI's new 15-day credit reporting rule: what it means for your credit score
- MediaNama, RBI issues final amendment directions on limiting customer liability in digital transactions, effective from 2027 (25 June 2026, with the directions PDF)
- Press Information Bureau, RBI Strengthens Framework on Unauthorised Electronic Banking Transactions
- Business Standard, RBI asks banks to provide shadow reversal in 5 days for credit card frauds (24 June 2026)
- MediaNama, Compulsory bundling, dark patterns banned: Why the RBI wants banks to stop mis-selling financial products (17 June 2026)
- taxguru.in, Draft RBI (Commercial Banks – Responsible Business Conduct) Amendment Directions, 2026 (the superseded July 2026 draft date)
Frequently asked
When do the new RBI mis-selling rules take effect?
The Reserve Bank of India issued the Commercial Banks - Responsible Business Conduct Second Amendment Directions, 2026 on 15 June 2026, and the new mis-selling and bundling provisions come into force from 1 January 2027. Banks have until then to align their sales processes, complaint mechanisms, and refund policies with the directions.
What is compulsory bundling, and is it banned under the new rules?
Compulsory bundling is when a bank makes one product conditional on buying another, such as requiring a term-insurance policy from its own group company to sanction a home loan. From 1 January 2027 the RBI prohibits a bank from making the availment of any product conditional on a third-party product or service. Where a product is genuinely needed as a risk mitigant, the customer must be free to buy it from any provider.
Will I get a refund if a bank is found to have mis-sold me a product?
Yes. The directions make a refund mandatory once mis-selling is established. The bank must refund the entire amount paid for the product or service, cancel the sale where applicable, and compensate the customer for any loss arising from the mis-selling as per its approved policy.
How often is my credit score updated now?
Since January 2025 banks and NBFCs report credit data to the bureaus fortnightly, every fifteen days, instead of monthly. The RBI has moved the cycle shorter still, towards weekly updates through 2026, so a payment, a closed card, or a settled default reflects on your file in days rather than weeks.
What is a shadow reversal on a fraudulent credit card transaction?
A shadow reversal is a temporary, provisional credit a bank must post within five calendar days of a customer reporting a fraudulent credit card transaction. The amount cannot be spent while the complaint is investigated, but no interest or charges accrue on the disputed sum. It applies to electronic banking transactions from 1 January 2027.
When do I have zero liability for a fraudulent card transaction?
Always, when the fraud results from the bank's own negligence, regardless of when it is reported. In a third-party breach (a failure at a payment gateway, aggregator, app provider, or telecom operator), zero liability applies if the transaction is reported within five calendar days. The burden of proving customer liability now sits with the bank, not the customer.
How much compensation can a scam victim claim under the 2027 framework?
A bona fide individual victim who loses up to ₹50,000 in a fraudulent electronic transaction involving their own negligence can claim 85% of the net loss or ₹25,000, whichever is lower, once in a lifetime. The fraud must be reported to both the bank and the National Cyber Crime Reporting Portal (or helpline 1930) within five calendar days, and the bank must pay within five days of a completed application.
Do these rules apply to credit cards specifically?
The Responsible Business Conduct directions apply to commercial banks across their retail products, which includes credit cards. The faster credit-reporting cycle applies to every credit account on your bureau file, cards included. So both changes touch a typical cardholder directly: how their data is reported, and how add-on products are sold alongside the card.
Do the RBI mis-selling and dark-pattern rules already apply from July 2026?
No, not yet. A February 2026 draft proposed 1 July 2026 as the effective date, and that number is still being repeated in some July 2026 news coverage. The RBI's final directions, issued 15 June 2026, set the effective date at 1 January 2027. Banks are expected to build toward that date, but the legal obligation to stop compulsory bundling and dark patterns does not begin until 1 January 2027.
Card devaluations, reward maths, and rate changes the day they land.
Follow on X

Reader comments
No comments yet. Share your experience with this card below — the first useful comment helps every reader after you.
Comments are moderated before they appear. Share your real experience with a card — what worked, what didn't, what the bank told you. We don't publish promotional content, referral links, or personal financial details. Keep it useful for other readers.