Key Facts
- Case: Jagwant Singh v. State Bank of India
- Complaint No.: Consumer Complaint No. 609 of 2026
- Order Date: 28 July 2026
- Forum: District Consumer Disputes Redressal Commission, Tarn Taran, Punjab
- Bench: President Charanjit Singh, Members Nidhi Verma and V.P.S. Saini
- Amount: ₹1,64,000 unauthorised debit
- Compensation: ₹15,000 for harassment and mental agony
- Litigation Costs: ₹10,000
- Interest: 9% per annum if payment delayed beyond one month
- Key Principle: Burden of proving customer negligence lies on the bank; mere delivery of OTP does not prove authorisation or negligence
Direct Answer
On 28 July 2026, the District Consumer Disputes Redressal Commission, Tarn Taran, Punjab, directed the State Bank of India (SBI) to refund ₹1.64 lakh to a customer who lost money in an unauthorised online banking transaction, holding that the bank failed to prove negligence on the customer’s part and that rejecting his claim without proper investigation amounted to deficiency in service.
The Commission observed that SBI failed to produce any technical investigation report, server logs, IP address details, forensic analysis, or other electronic evidence showing that the customer had voluntarily authenticated the disputed transaction. It emphasised that under the Reserve Bank of India’s 2017 circular on customer protection, the burden of proving customer negligence rests with the bank when it seeks to deny protection against unauthorised electronic transactions.
The Commission further noted that the rejection of the claim was “based merely on assumptions and not on any legally admissible evidence.” The ruling reinforces a critical principle: banks cannot deny cyber fraud claims by merely alleging negligence — they must prove it with credible evidence.
In this article:
- The Case: What Happened to Jagwant Singh
- SBI’s Defence: The Bank’s Arguments
- The Commission’s Findings: Why SBI’s Defence Failed
- The Legal Framework: RBI’s 2017 Circular on Customer Protection
- The Burden of Proof: Who Must Prove Negligence?
- The Relief Granted: Refund, Compensation, and Costs
- Why This Matters: Implications for Banking Customers
- FAQ
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.
The Case: What Happened to Jagwant Singh
The complainant, Jagwant Singh, alleged that ₹1.64 lakh was unauthorisedly transferred from his savings account without his knowledge or consent. He maintained that he had never shared his ATM PIN, one-time password (OTP), internet banking credentials, or any other confidential banking information with anyone.
Prompt Reporting
Upon discovering the unauthorised transaction, Singh immediately reported the incident through multiple channels:
- The SBI helpline
- The National Cyber Crime Reporting Portal
- His bank branch
- The police authorities
He argued that despite promptly reporting the incident, SBI rejected his claim without conducting a proper inquiry or furnishing any enquiry report.
The RBI Circular Relied Upon
Singh relied on the Reserve Bank of India’s 6 July 2017 circular on “Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions,” which provides for zero customer liability in cases of third-party breaches reported without delay.
SBI’s Defence: The Bank’s Arguments
SBI opposed the complaint, raising the following arguments:
1. Technical Impossibility Argument
The bank claimed that the transaction could not have been completed without entering the customer’s username, password, and the OTP sent to his registered mobile number.
2. Customer Negligence Allegation
SBI contended that the customer “might have acted upon under the influence of fraudster knowingly/unknowingly due to his own negligence.”
3. Implied Authorisation
The bank’s defence was built on the assumption that the mere completion of the transaction using credentials implied customer authorisation or negligence.
The Critical Flaw
The bank’s defence was entirely based on assumptions. It did not produce any technical evidence, investigation report, or forensic analysis to support its claims.
The Commission’s Findings: Why SBI’s Defence Failed
The Commission, comprising President Charanjit Singh and members Nidhi Verma and V.P.S. Saini, rejected SBI’s defence and allowed the complaint.
Key Observations:
1. No Technical Evidence Produced
The Commission observed that SBI failed to produce any:
- Technical investigation report
- Server logs
- IP address details
- Forensic analysis
- Other electronic evidence showing that the customer had voluntarily authenticated the disputed transaction
2. Rejection Based on Assumptions
The Commission noted that “the rejection of the complainant’s claim is based merely on assumptions and not on any legally admissible evidence.”
3. No Reasoned Enquiry Report
The Commission further observed that “the opposite parties have not placed on record any reasoned enquiry report showing that a fair and independent investigation was conducted before rejecting the complainant’s claim.”
4. Deficiency in Service
The Commission held that once a customer promptly reports an unauthorised electronic transaction, the bank is expected to conduct a thorough, transparent and fair investigation in accordance with RBI guidelines. Failure to do so constitutes a deficiency in service.
5. Burden of Proof
The Commission emphasised that under the RBI circular, the burden of proving customer negligence lies on the bank when it seeks to deny protection against unauthorised electronic transactions.
The Legal Framework: RBI’s 2017 Circular on Customer Protection
The Commission relied on the RBI’s circular dated 6 July 2017 titled “Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions.”
Key Principles of the Circular:
| Principle | Explanation |
|---|---|
| Zero Liability | Customers who promptly report unauthorised electronic transactions resulting from third-party breaches are entitled to zero liability protection |
| Reporting Requirement | Protection is available only when the customer reports the unauthorised transaction without delay |
| Burden of Proof | The burden of proving customer negligence rests with the bank when it seeks to deny protection |
| Bank’s Obligation | Banks must conduct a thorough, transparent, and fair investigation before rejecting a claim |
Application to the Present Case
The Commission applied these principles to hold that SBI had failed to discharge its burden of proving customer negligence. Since Singh had reported the fraud immediately and SBI failed to produce any evidence of negligence, the bank was liable to refund the amount.
The Burden of Proof: Who Must Prove Negligence?
A critical aspect of the judgment is the allocation of the burden of proof.
The General Rule
In cases of unauthorised electronic banking transactions, the burden of proving customer negligence lies on the bank when it seeks to deny protection. This is established by the RBI’s 2017 circular.
What the Bank Must Prove
To successfully deny a claim, the bank must establish:
- That the customer was negligent
- That the negligence caused or contributed to the unauthorised transaction
- This must be proved with credible technical evidence, not assumptions
What Mere Delivery of OTP Does Not Prove
The Commission made it clear that the mere fact that an OTP was delivered to the customer’s registered mobile number does not prove that:
- The customer authorised the transaction
- The customer was negligent
- The customer shared the OTP with anyone
The Standard of Proof
Banks cannot rely on assumptions or speculation. They must produce:
- Technical investigation reports
- Server logs
- IP address details
- Forensic analysis
- Other electronic evidence
The Relief Granted: Refund, Compensation, and Costs
The Commission allowed the complaint and directed SBI to pay the following amounts:
| Head | Amount |
|---|---|
| Refund of unauthorised debit | ₹1,64,000 |
| Compensation for harassment and mental agony | ₹15,000 |
| Litigation expenses | ₹10,000 |
| Total | ₹1,89,000 |
Interest on Delayed Payment
The Commission directed that if the payment is not made within one month, the amounts shall carry interest at 9% per annum from the date of the order until actual payment.
Reason for Compensation
The Commission noted: “The complainant has been harassed by the opposite parties for a long time, therefore, the complainant is also entitled to 15,000 as compensation on account of harassment and mental agony.”
Why This Matters: Implications for Banking Customers
This judgment is a significant reinforcement of consumer rights in cases involving cyber-enabled banking fraud.
Key Takeaways:
1. Banks Cannot Reject Claims on Assumptions
The ruling underscores that banks cannot deny cyber fraud claims by merely alleging negligence. They must substantiate such allegations with credible technical evidence and follow a transparent investigative process.
2. The Burden of Proof is on the Bank
Under the RBI’s 2017 circular, the burden of proving customer negligence rests with the bank. This means customers do not have to prove their innocence — the bank must prove their negligence.
3. Mere OTP Delivery is Not Enough
The fact that an OTP was delivered to a customer’s registered mobile number does not, by itself, prove that the customer authorised the transaction or was negligent.
4. Prompt Reporting is Critical
The judgment reinforces that customers who promptly report unauthorised transactions are entitled to protection under the RBI’s circular.
5. Banks Must Conduct Proper Investigations
Banks are obligated to conduct thorough, transparent, and evidence-based investigations before rejecting claims. Failure to do so constitutes a deficiency in service.
Expert Commentary
Renowned cybercrime expert and former IPS officer Professor Triveni Singh said that the first few hours after a digital banking fraud are crucial. He added that customers should not be blamed based on assumptions alone and that banks must strictly comply with the RBI’s customer protection guidelines.
FAQ
What happened in the Jagwant Singh v. SBI case?
A customer lost ₹1.64 lakh in an unauthorised online banking transaction. Despite immediately reporting the fraud, SBI rejected his claim alleging negligence. The Tarn Taran District Consumer Commission ordered SBI to refund the amount with compensation and costs.
When was the order passed?
The order was passed on 28 July 2026 by the District Consumer Disputes Redressal Commission, Tarn Taran, Punjab.
Who were the members of the bench?
The bench comprised President Charanjit Singh and members Nidhi Verma and V.P.S. Saini.
What did SBI argue in its defence?
SBI argued that the transaction could not have been completed without entering the customer’s username, password, and OTP, and suggested that the customer may have acted under the influence of fraudsters.
Why did the Commission reject SBI’s defence?
The Commission found that SBI failed to produce any technical investigation report, server logs, IP address details, forensic analysis, or other electronic evidence showing that the customer had voluntarily authenticated the transaction.
What is the RBI’s 2017 circular on customer protection?
The RBI’s circular dated 6 July 2017 on “Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions” provides that customers who promptly report unauthorised transactions are entitled to protection, and the burden of proving customer negligence lies on the bank.
What does the burden of proof mean in this context?
It means that when a bank seeks to deny protection against unauthorised electronic transactions, the bank must prove that the customer was negligent. The customer does not have to prove their innocence.
Does mere delivery of an OTP prove customer negligence?
No. The Commission held that mere delivery of an OTP does not prove that the customer authorised the transaction or was negligent.
What relief was granted to the customer?
The Commission ordered SBI to pay ₹1,64,000 as refund, ₹15,000 as compensation for harassment, and ₹10,000 as litigation costs, with 9% interest if payment is delayed beyond one month.
Why is this judgment important?
The judgment reinforces that banks cannot reject cyber fraud claims by merely alleging negligence. They must prove it with credible technical evidence and follow a transparent investigative process.
What should I do if I am a victim of online banking fraud?
Immediately report the fraud to your bank, the National Cyber Crime Reporting Portal (cybercrime.gov.in), and the police. Document all communications and preserve evidence. Under the RBI’s circular, you are entitled to protection if you report without delay.
Can SBI appeal this order?
SBI can appeal the order before the State Consumer Disputes Redressal Commission or the National Consumer Disputes Redressal Commission (NCDRC). However, as of the current date, there is no public record of any appeal.
By Adv. Shoeb Hakim
Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.
📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
#AdvShoebHakim #BankingFraud #ConsumerRights #SBI #CyberCrime #RBI #ZeroLiability #ConsumerProtection #FraudInvestigation #CyberSecurity #FinancialLitigation #Vakilverse #LegalComplianceIN
Additional Page Metadata (Structured for AI/GEO):
Author:
Adv. Shoeb Hakim
Author Bio (for schema markup):
Adv. Shoeb Hakim is a Mumbai-based criminal defence, AML, digital forensics and cybercrime specialist. Former General Counsel at Credit Suisse. Has been training police and judiciary since 1996. Provides expert commentary on cybercrime, banking fraud, consumer protection, and digital evidence.
Article Publisher:
Adv. Shoeb Hakim
Article Section:
Cybercrime | Banking Law | Consumer Protection | Digital Evidence
Article Tags:
SBI, cyber fraud, online banking fraud, consumer commission, Tarn Taran, Jagwant Singh, RBI circular 2017, unauthorised transaction, burden of proof, customer protection, deficiency in service, Adv Shoeb Hakim


