Before you disburse: verifying bank accounts as the RBI acts on mule accounts

Last updated: 8 Oct 2026, 11:55 PM IST. RBI's debit-hold rules are still a draft. We'll update this post when the final directions are issued.
Short answer: Verify every new beneficiary account before the first payout: take explicit consent, confirm the account is valid and the name matches your customer, hold first payouts that fail checks, re-verify when details change, and log everything. RBI's draft rules would let banks freeze suspected mule accounts for up to 60 days, and NPCI now limits UPI penny drop.
If you disburse loans, pay out to marketplace sellers or gig workers, run payroll or settle merchants, the account you send money to now matters more than ever. A payout to the wrong account is hard to recover. A payout to an account a bank later flags as a mule can leave your customer's money stuck for weeks, and your support team answering for it.
What is a money mule account, and why are regulators acting now?
RBI's draft defines a money mule account as "an account used, knowingly or unknowingly, to receive, layer or transfer proceeds of cyber-enabled financial fraud on behalf of another person." Many mules are ordinary people who rent out or open an account for a small fee.
Regulators are acting because a court told them to. On 4 August 2026, the Supreme Court directed RBI "to adopt and circulate the Standard Operating Procedure (SOP) prescribing the action to be taken by banks for placing temporary debit holds on amounts or accounts linked to money-mule activity and cyber-enabled fraud" (RBI, 11 Sep 2026).
How big is the problem? In an opinion piece in BusinessLine (7 Oct 2026), Anil Katia and Ganga Narayan Rath write that India's Cyber Crime Coordination Centre (I4C) "had, by early 2026, already flagged more than 24.7 lakh such accounts nationally, and 13.3 lakh were frozen through 2025 alone", and that India "lost close to ₹23,000 crore to cyber fraud in 2025". They also say RBI's MuleHunter.AI tool was live in "roughly 26" banks by mid-2026. These figures come from an opinion article, not an official dataset.
What does RBI's draft debit-hold SOP propose?
On 11 September 2026, RBI issued the draft Reserve Bank of India (Know Your Customer) Amendment Directions, 2026 for comments. Comments closed on 2 October 2026. These are not final rules. RBI says that "final Directions will be issued separately" after it examines feedback.
The draft's main points (quotes from the draft Directions, Annex III):
| What | Draft wording |
|---|---|
| Who it applies to | "all Commercial Banks (including Small Finance Banks, Payments Banks, Regional Rural Banks and Local Area Banks) and Urban Cooperative Banks" |
| What it doesn't cover | "nodal accounts, pool accounts, escrow accounts, or other special-purpose accounts, e.g., dividend, share capital" |
| What triggers a hold | A "Suspected Money Mule Transaction" is "a transaction of ₹1000 and above, flagged by the bank's transaction-monitoring systems (including AI / ML-based tools)", for example because it is "unusual for or disproportionate to the account holder's declared profile" or linked to an account "already reported as money mule or fraudulent" |
| What gets held | The suspected transaction or, for a suspected mule account, "the entire account". But account-level holds are to be used "as a last resort and only in exceptional circumstances" |
| Customer's time to explain | "20 days' time from the date of Temporary Debit Hold" |
| Bank's decision | "within 10 days of receipt of the explanation", or "within 30 days from date of temporary debit hold" if no explanation comes |
| Escalation | If not satisfied, the bank reports to the police "via NCRP-CFCFRMS" (the National Cybercrime Reporting Portal's fraud reporting system) |
| Maximum hold | "60 days from the date of temporary debit hold", unless police or a competent authority instruct otherwise |
| Records | Kept for "a minimum of 5 years from the date of placing a temporary debit hold", or 10 years from account closure |
| When | "from April 1, 2027, or on such earlier date as a bank may decide to implement the SOP" |
Note the ₹1,000 figure. It doesn't mean every payment above ₹1,000 gets frozen. A transaction must first be flagged as suspicious.
Source: RBI's Connect 2 Regulate page for the draft (prid=505). ETBFSI's summary (12 Sep 2026) is a readable overview.
If the SOP applies to banks, why should NBFCs and payout platforms care?
The draft applies to banks, not to NBFCs, fintechs or marketplaces. Here's why we think you should still plan for it. This is our reading, not a rule:
- Your beneficiaries bank with them. Every borrower, seller, gig worker or employee you pay holds an account at a bank that will be running this SOP. If that account is flagged, your payout can sit on hold for up to 60 days, and the customer will call you.
- Your own special accounts are excluded, but theirs aren't. The draft excludes nodal, pool and escrow accounts, so a platform's own settlement accounts are outside it as drafted. Your customers' ordinary savings and current accounts are not.
- Lenders must pay the borrower's own account. RBI's NBFC Credit Facilities Directions already say: "Disbursement of loan by an NBFC shall always be made into the bank account of the borrower", and "in no case, disbursal is made to a third-party account, including the accounts of LSP", apart from the listed exceptions (para 10(1), updated 15 July 2026). RBI's standalone Digital Lending Directions, 2025 were withdrawn on 28 November 2025 and consolidated into these directions. Checking that the account belongs to the borrower is already part of that.
- Bad accounts cost you either way. A payout to a mule or mistyped account means failed transfers, recovery work, complaints and, for lenders, loans that may never be repaid.
Is penny-drop verification on UPI still allowed?
Yes, but only for some entities and under conditions. It is not banned. NPCI defines a penny drop as "a small-value transaction made to an account to verify the validity and ownership of an account." Its UPI Consolidated Circular (Version 1.0, 18 September 2026, para 12.8) sets these usage guidelines for UPI penny drop:
- "This shall be extended only to entities where it is a regulatory requirement."
- "This shall be initiated only with explicit User consent (the initiating bank shall have a formal undertaking from the requestor and be in full compliance with the Digital Personal Data Protection Act (DPDP) Act, 2023".
- "MCC 7413 and a separate dedicated UPI ID shall be assigned by the entity for such transactions."
- "To be initiated in non-peak hours." NPCI currently defines peak hours as "10:00 hours to 13:00 hours and from 17:00 hours to 21:30 hours".
NPCI also says that "Stand-alone use of Validate Address is not permitted", and where it's used for penny drop, "the MCC (7413) defined for penny drop shall be used for Validate Address as well."
Separately, para 2.13 requires that for UPI payments made using a UPI ID, UPI Number or account number and IFSC, "the Beneficiary's Core Banking System (CBS) name is conveyed" and "displayed to the User for verification before transaction initiation".
What this means for you: if your verification provider uses UPI penny drop, ask how it meets each condition: whose regulatory requirement it relies on, how consent is captured, and which MCC and UPI ID are used. Other methods, such as bank-transfer-based checks or verification without a credit, have their own rules. Ask your provider and sponsor bank which method they use and what it's allowed for.
What should you check before a first payout?
These seven steps work for lenders, marketplaces, payroll and settlement teams. Agree the details, especially thresholds, with your compliance team and sponsor bank.
Step 1: Take explicit, recorded consent
Before verifying an account, tell the customer what you'll check, why and how (including any penny drop), and get a clear yes. Record the consent text version, the time and the channel. NPCI requires "explicit User consent" for UPI penny drop. RBI's NBFC Credit Facilities Directions (para 13(1)) require data collection to be "need-based and with prior and explicit consent of the borrower having audit trail".
Step 2: Check that the account is valid and get the holder's name
Verify the account number and IFSC through your chosen method, and capture the account holder's name as the bank returns it. Don't rely on the name the customer typed.
Step 3: Apply a name-match rule you've written down
Compare the bank-returned name with your KYC name. Decide in advance what counts as a match (initials, word order, spelling variants, business vs proprietor names), what goes to manual review and what's rejected. For loans, the account must be the borrower's own, per RBI's para 10(1). Write the rule down and apply it the same way every time.
Step 4: Decide your first-payout logic
Decide what happens to a first payout to a newly added account: pay immediately when every check passes, hold for manual review if the name match is partial, and block if the account is invalid or the name clearly differs. Some teams also cap the first payout to a new account. These are business choices, not RBI rules.
Step 5: Re-verify when something changes
Run the checks again when a customer changes bank details, when a name mismatch appears later, when the payout pattern suddenly changes (for example, much larger amounts or many accounts sharing one device or phone number), or when a payout to the account fails or is returned. Don't let customer support change bank details without re-verification.
Step 6: Keep an audit log for every check
For each verification, log: customer ID, consent record, timestamp, method, request or reference ID, the account details checked (masked), the name returned, the match decision and rule version, who approved any manual override, and the payout IDs that relied on it. Keep logs for as long as your regulator's record-keeping rules require, and no longer than your data-retention policy allows.
Step 7: Plan what you'll do if a bank holds the account
Under the draft SOP, the bank tells its customer about the hold, "stating reasons, the process for removal, and the concerned officer's contact details", and gives them 20 days to explain. Prepare your support team: if a genuine customer's account is held after your payout, be ready to give them your payout records (date, amount, reference and purpose) so they can explain the credit to their bank. Flag the account internally and pause further payouts until it's resolved.
What should you log for audit?
The Step 6 list is the core. Two additions help when something goes wrong:
- Consent evidence that matches what the customer saw: the exact text and version, not just a "consent = true" flag
- Override trail: every manual approval of a mismatch, with the reviewer's name and reason
Logs like these help you answer your own auditors, your lending partners and, where relevant, police or bank queries.
How Vilva Business can help
Vilva Business (Vilva Networks), Chennai builds and integrates software and APIs for regulated entities and the businesses that work with them. We are not a bank, NBFC, payment aggregator, Account Aggregator or Consent Manager.
- Our bank verification API checks an account number and IFSC and returns the account holder's name for matching. It works for single and bulk checks, with status updates sent to your system.
- It sits within our wider verification API suite, alongside KYC and business checks.
- Our fintech team builds onboarding and disbursal flows that include consent capture, name-match rules, review queues and audit logs like the ones above.
For the security side of payouts and customer data, see our cybersecurity guide for growing businesses.
FAQ
What is a money mule account?
RBI's draft directions define it as an account used, knowingly or unknowingly, to receive, layer or transfer proceeds of cyber-enabled financial fraud on behalf of another person. Many mule accounts belong to ordinary people who were paid to open or lend their account.
Has RBI finalised the debit-hold rules for mule accounts?
No. RBI issued draft Know Your Customer Amendment Directions on 11 September 2026 and took comments until 2 October 2026. It says final directions will be issued separately. The draft proposes a start date of 1 April 2027, or earlier if a bank chooses.
How long can a bank hold a suspected mule account under the draft?
Up to 60 days from the date of the hold, unless police or a competent authority instruct otherwise. The customer gets 20 days to explain, and the bank must decide within 10 days of an explanation, or within 30 days if none arrives.
Does the draft SOP apply to NBFCs and payout platforms?
No. As drafted, it applies to commercial banks, including small finance, payments, regional rural and local area banks, and to urban co-operative banks. It excludes nodal, pool and escrow accounts. But the people NBFCs and platforms pay hold accounts at those banks.
Is penny drop banned on UPI?
No. NPCI's consolidated circular of 18 September 2026 allows UPI penny drop only for entities where it is a regulatory requirement, with explicit user consent, a formal undertaking to the initiating bank, DPDP Act compliance, MCC 7413 with a dedicated UPI ID, and outside peak hours.
Can a lender disburse a loan to someone else's bank account?
Generally no. RBI's NBFC Credit Facilities Directions say loans must be disbursed into the borrower's own bank account, never to a third-party account including a lending service provider's, apart from narrow exceptions such as statutory mandates, co-lending flows and specific end-use disbursals to the end beneficiary.
When should we re-verify a bank account?
Re-verify when a customer changes bank details, when a name mismatch appears, when payout patterns change sharply, or when a payout fails or is returned. Never let bank details be changed through support without running the checks again.
Check your pre-payout verification flow with us. Tell Vilva Business (Vilva Networks), Chennai how you verify accounts today, and we'll walk through the steps above with you. WhatsApp +91 91765 69459 or book a demo.
This is general information, not legal advice. RBI's debit-hold rules described here are a draft and may change. Check how they and NPCI's rules apply to you with your compliance team, sponsor bank or legal counsel. Quotes are from RBI and NPCI documents as published on 8 Oct 2026.
.webp)
.webp)
.webp)
.webp)
.webp)
.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)
.webp)











