“Fraud Moves at the Speed of an API Call”: What RBI’s Governor Said, and What 89% of Consumers Want
Indian banking fraud now settles in seconds. Real-time fraud detection APIs are how banks keep pace, and what the regulator and consumers expect from them.

Indian banking fraud now runs on fast scripts and instant payment rails. These attacks settle in seconds. To stop them, banks must replace slow batch monitoring with real-time fraud detection APIs. These APIs check identity, device, and telecom signals during payment authorization. This shift matches user demand. Survey data shows that 89% of active digital banking users in India expect immediate alerts on suspicious charges.
Where things stand (October 2026)
- The Reserve Bank of India mandates real-time transaction monitoring and anomaly detection across all digital payment channels under its Master Direction on Digital Payment Security Controls.
- The Department of Telecommunications provides the Financial Fraud Risk Indicator via real-time APIs to over 1,000 financial institutions, helping prevent over ₹5,000 crore in cyber fraud losses as of August 2026.
What RBI Governor Sanjay Malhotra Said at FIBAC 2026
At the FIBAC 2026 conference in Mumbai on 11 August 2026, Reserve Bank of India Governor Sanjay Malhotra gave an address titled “Winning in the AI Era: The New Playbook for Indian Banks”[1]. Governor Malhotra stated that fraud today moves at the speed of an API call. He explained that static rules-based engines stay one step behind attackers. Because modern attackers use automated tools, Governor Malhotra noted that it is AI alone that can help limit AI-driven fraud. This defense requires continuous pattern recognition and real-time anomaly detection.
Governor Malhotra outlined five key areas where AI can help Indian banks:
- 1.
Credit and risk assessment using alternative data.
- 2.
Customer service and grievance redressal.
- 3.
Financial inclusion through voice tools and early stress detection.
- 4.
Operational efficiency in routine processing.
- 5.
Real-time fraud prevention across payment channels.
Governor Malhotra also warned against the loss of human judgment. He directed that banks cannot use automated tools to avoid accountability. The RBI, external auditors, and consumers will never accept “the model decided” as a valid defense for institutional decisions. To manage this risk, banks must set board-approved AI governance policies. They must also keep complete inventories of third-party systems. Industry conference records published by FICCI and the Indian Banks’ Association[2] confirm that operational oversight must stay with human risk officers.
What 89% of Indian Consumers Expect from AI Fraud Detection
Consumer demand for real-time security matches the regulator’s focus on automated defenses. In a July 2026 nationwide survey of 480 credit-active Indian consumers published in Experian India’s GFF 2026 white paper[3], 89% of respondents ranked immediate fraud alerts as very important or important. The top-ranked AI feature for personalization was detecting unusual charges across payment methods and notifying the user right away.
The Experian survey highlighted three clear consumer expectations for automated tools:
- •Proactive risk warnings: 89% of respondents value early alerts when at risk of missing a loan payment or overdrafting an account.
- •Automated financial tracking: 89% value automated expense tracking and offer monitoring.
- •Security concerns: 72% worry that AI agents could make choices using outdated or incorrect data. In addition, 71% fear personal data misuse, and 70% fear impersonation by attackers.
Consumer trust remains tied to established banking brands. While 89% of consumers trust Large Language Models to compare loan options and 60% feel comfortable with an AI agent applying for credit for them, 85% say they feel much more comfortable when the tool comes from a bank they already trust. In addition, only 9% of consumers favor full autonomy for automated financial tasks. Instead, 32% demand semi-autonomy where systems act only after explicit user approval. Another 23% accept conditional autonomy with set rules, and 36% permit recommendations only.
Regulatory Mandates for Real-Time Fraud Interception
Indian regulators now require real-time risk screening across digital payment rails. Under the RBI Master Direction on Digital Payment Security Controls[4], regulated lenders and payment providers must deploy real-time fraud monitoring. This rule applies to Scheduled Commercial Banks, Small Finance Banks, Payments Banks, Credit Card issuing NBFCs, and PPI Issuers. Systems must identify behavioral anomalies, velocity spikes, and location mismatches. When suspicious activity appears, the institution must trigger step-up checks, user alerts, or payment holds before settlement.
To strengthen cross-industry defense, the Department of Telecommunications launched the Digital Intelligence Platform and Sanchar Saathi initiative on 22 May 2025. According to a Press Information Bureau release[5], the platform delivers the Financial Fraud Risk Indicator. This service assigns real-time risk scores of Medium, High, or Very High to mobile numbers linked to cybercrime reports from the National Cybercrime Reporting Portal and the Mobile Number Revocation List.
Official documentation on the Sanchar Saathi portal[6] states that over 1,000 banks, NBFCs, and payment operators now query these APIs in real time. By screening transaction endpoints before payment authorization, connected institutions helped prevent over ₹5,000 crore in cyber fraud losses as of August 2026. Consolidated RBI cybersecurity guidelines require regulated entities to feed telecom risk signals into pre-authorization checks. These signals include SIM-swap alerts and disconnected number lists. These controls help stop coordinated attacks, including bank fraud networks and mule account fraud.
The Latency Gap: Batch Processing vs. Real-Time API Screening
Traditional fraud systems rely on scheduled batch jobs run hourly or at the end of the day. This setup creates a delay of minutes or hours. In contrast, modern fraud rings use automated scripts to move stolen money through multiple accounts in seconds. When transaction monitoring runs on delayed batch files, funds leave the bank long before an alert reaches an analyst.
“Fraud today moves at the speed of an API call.”
Sanjay Malhotra, Governor, Reserve Bank of India, FIBAC 2026 Address
Real-time fraud systems close this gap by scoring transactions during the authorization round-trip. RBI rules state the required operational outcome rather than an exact millisecond limit. Even so, industry engineering standards typically target 200 to 500 milliseconds for pre-settlement screening. Real-time APIs evaluate device data, user behavior, transaction speed, and telecom risk before the payment completes.
| Control Dimension | Batch and Periodic Monitoring | Real-Time API Screening |
|---|---|---|
| Processing Speed | Scheduled hourly or end-of-day runs | Sub-second synchronous checks (200–500 ms) |
| Interception Point | Post-settlement alert generation | Pre-settlement authorization gate |
| Risk Data Sources | Internal ledgers and static lists | Multi-source telemetry, device data, and telecom signals |
| Friction Management | Static limits and manual holds | Risk-based step-up challenges on anomalies only |
| Mule Account Defense | Identifies layered transfers after exit | Blocks multi-hop transfers at payment initiation |
By shifting from static rule engines to machine-learning anomaly detection, institutions also cut down on false alarms. Instead of blocking accounts or applying broad limits, real-time systems trigger step-up challenges only when an API call looks anomalous. These challenges include biometric checks or video verification. Using advanced tools like graph analytics for mule detection allows risk engines to spot suspicious links before funds leave the account.
What This Means for BFSI Fraud Architecture
Governor Malhotra’s speech and the Experian survey data show that Indian lenders must redesign their fraud defenses. The old separation between customer onboarding checks and payment monitoring no longer works. Attackers now steal valid user credentials and use automated scripts to drain accounts in seconds.
Read together, these findings point to three practical steps for fraud and risk teams:
Combine signals into one fast check
Evaluating KYC data, device signals, telecom risk scores, and credit bureau data in separate steps creates too much delay. Real-time API systems allow risk engines to check these data points at the same time before approving a transaction.
Keep fraud controls clear and balanced
The survey shows that 85% of consumers trust bank-provided AI tools, while 71% fear data misuse. Banks that add extra authentication steps only to risky transfers can keep accounts safe without slowing down ordinary payments.
Keep humans accountable for automated decisions
Governor Malhotra's warning on human judgment means that banks cannot treat machine learning as an unmonitored system. Risk teams should keep clear audit logs for every automated decision, follow board-approved AI governance rules, and ensure human officers set risk thresholds.
Frequently Asked Questions
Disclaimer: This article is for informational purposes only and does not constitute legal, regulatory, tax, or compliance advice. For specific implementation requirements under RBI directions, consult qualified legal or compliance counsel.
KYCKART Intelligence
Is your fraud control fast enough for payment authorization?
KYCKART brings identity, device, and telecom risk signals into one real-time check, so suspicious transactions can be stopped before settlement.
See fraud intelligencearrow_forward