Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.
"An OTP was used, so the transaction was authorised by you"
high likelihoodThe bank treats successful two-factor authentication as conclusive.
What answers it
The circular puts the burden of proving customer liability on the bank. An OTP record shows a code was entered; it does not show who entered it or how they came by it, and where the code was obtained through a compromise of the bank's systems or a SIM-swap the bank permitted, the deficiency is the bank's and the zero-liability limb applies whatever the delay.
RBI/2017-18/15 — Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (6 July 2017) — Paras 6-9 (zero liability, limited liability, reversal timelines) and para 12 (burden of proof)
"You reported late, so you bear the loss"
high likelihoodThe bank applies the beyond-seven-working-days limb and offers nothing.
What answers it
The tiers apply only to third-party breaches where the deficiency lies with neither party. Zero liability under the first limb has no time limit at all where there was contributory fraud, negligence or deficiency on the bank's part. Ask which limb the bank says applies and why, and ask for its Board-approved policy.
RBI/2017-18/15 — Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (6 July 2017) — Paras 6-9 (zero liability, limited liability, reversal timelines) and para 12 (burden of proof)
"We will credit you once the investigation finishes"
high likelihoodThe bank defers the credit until it has concluded, often well beyond 90 days.
What answers it
The credit within ten working days is expressly independent of the investigation and of any insurance claim the bank may make. And if the complaint is not resolved within 90 days, the bank must compensate you as though it had been decided in your favour.
RBI/2017-18/15 — Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (6 July 2017) — Paras 6-9 (zero liability, limited liability, reversal timelines) and para 12 (burden of proof)