What Changed
In July 2024, RBI issued consolidated Master Directions on Fraud Risk Management for commercial banks (including RRBs) and AIFIs, rescinding a large number of standalone circulars issued over nearly two decades. The Directions bring prevention, early warning, classification, reporting, investigation, board and senior-management oversight, and corrective action under one framework, with a companion set of directions issued for NBFCs on the same date.
Why It Matters
A consolidated framework changes fraud risk management from a set of disconnected compliance obligations into a single lifecycle that a bank's FRM function is expected to operate end to end. It also raises the bar on documentation: institutions need to be able to demonstrate, not merely assert, that each stage of the lifecycle — from an early-warning signal to a closed investigation — is functioning and governed.
Who Is Impacted
The Directions apply directly to all banking companies, State Bank of India, subsidiary banks, Regional Rural Banks, Small Finance Banks, Payments Banks, and All India Financial Institutions (EXIM Bank, NABARD, NaBFID, NHB, SIDBI). A parallel set of directions covers NBFCs and Housing Finance Companies. Fraud, risk, compliance, internal audit and technology functions are all directly affected, as is the Board's Special Committee structure.
What Institutions Should Review
- Whether existing fraud risk management policy documents map cleanly onto the consolidated Directions, or still reference rescinded circulars.
- Early-warning signal (EWS) frameworks — coverage, ownership, and escalation timelines against the Directions' expectations.
- Fraud classification and reporting workflows, including timelines for reporting to RBI and law-enforcement agencies.
- The Board-level Special Committee on frauds — composition, meeting cadence, and the quality of information placed before it.
- Root-cause and corrective-action tracking for previously identified frauds — is there evidence controls were actually strengthened?
What This Means for FRM Technology and Controls
A single consolidated framework is easiest to operate when a bank's underlying fraud risk platform mirrors its lifecycle directly — the same case record carrying a signal from early-warning through investigation, classification, reporting and corrective action, rather than separate tools and spreadsheets for each stage with manual hand-offs between them.
Translating a lifecycle-based regulatory framework into an enterprise FRM capability checklist works best when the checklist maps one-to-one onto a single case record — prevention, detection, reporting, investigation and corrective action as stages of one workflow, not five separate systems that have to be reconciled after the fact.
Sources & References
- RBI — Master Directions on Fraud Risk Management in Commercial Banks (incl. RRBs) and All India Financial Institutions, 2024 (RBI/DOS/2024-25/118, 15 Jul 2024)
- RBI — Monitoring of Large Value Frauds by the Board of Directors (RBI/2004.15, 14 Jan 2004)
External links open in a new tab. RBI is used as the primary source wherever an RBI regulation or direction is discussed; NPCI and MHA/I4C are used where directly applicable. A third-party article is never used as the principal source where the official circular or direction is available.