The RBI's fraud risk management framework has tightened significantly over 2023–2025. Between the Master Direction on Fraud Risk Management (2024), the CERT-In Directions on Cybersecurity (2022), and NPCI's updated UPI fraud reporting guidelines, financial institutions face a complex compliance landscape — and the penalties for gaps are escalating.

This checklist covers the 20 most critical compliance requirements for a UPI fraud detection system. Items marked MANDATORY are explicitly required by current RBI or CERT-In directions. Items marked RECOMMENDED are best-practice requirements that RBI examiners are increasingly flagging in supervisory reviews.

Disclaimer: This checklist is for informational purposes and reflects publicly available RBI, CERT-In, and NPCI guidelines as of May 2025. Consult your compliance counsel for institution-specific regulatory obligations.

1. Real-Time Transaction Monitoring

01

Real-time scoring for all UPI transactions MANDATORY

RBI's 2024 Master Direction requires "real-time monitoring of digital payment transactions." This means every transaction must be scored before or at execution — not in a batch review. Sub-100ms detection latency is the accepted technical threshold.

02

Automated blocking capability for high-risk transactions MANDATORY

The system must be capable of blocking — not just flagging — transactions that exceed defined risk thresholds. Flagging-only systems do not satisfy the "intervention" obligation in the Master Direction.

03

Velocity monitoring across multiple time windows MANDATORY

Transaction velocity must be monitored at minimum across 1-hour and 24-hour windows. Best practice adds 72-hour and 30-day windows for catching investment scam patterns and mule cycling behaviour.

04

New beneficiary and new device flags RECOMMENDED

RBI examiners increasingly expect to see transaction context signals — first transaction to a new VPA, transaction from a new device — incorporated into risk scoring, particularly following the 2024 direction on payment security controls.

2. Mule Account Detection

05

Pass-through ratio monitoring MANDATORY

The 2024 direction explicitly mentions mule account detection. Pass-through accounts (inflow ≈ outflow within 5%) must be automatically identified and flagged. The RBI expects proactive identification, not only reactive response to customer complaints.

06

Device sharing detection MANDATORY

Multiple VPAs operating from a single device ID is a strong mule signal. Systems must track device-to-VPA associations and flag accounts where a device is shared by 2+ VPAs.

07

MHA high-risk district overlay RECOMMENDED

Accounts originating from MHA Cyber Crime Portal high-risk districts (Jamtara, Mewat, Deoghar, Nuh, Bharatpur, etc.) should receive elevated risk scoring. RBI examiners are specifically asking about geographic risk factors.

08

Network graph analysis for layered mule detection RECOMMENDED

With average mule hop depth at 3.4 in FY26, institutions that only flag direct recipients miss the majority of mule chains. Graph-based analysis of VPA→VPA flows is required to detect second- and third-hop mules.

3. Incident Reporting & FMR Filing

09

CERT-In incident reporting within 6 hours MANDATORY

CERT-In Directions 2022 require cybersecurity incidents — including large-scale UPI fraud — to be reported within 6 hours of detection. Systems must support automated incident report generation with the required fields: incident type, scope, affected systems, initial response actions.

10

Financial Monitoring Report (FMR) export capability MANDATORY

Fraud cases above the RBI-specified threshold require FMR submission. Systems must be capable of generating structured FMR-format exports with all required fields: transaction IDs, parties, amounts, rule triggers, and ML scores.

11

RBI reporting countdown dashboard RECOMMENDED

Compliance teams should have a live view of pending FMR submissions and their deadlines. Missing FMR deadlines is treated as a control failure by RBI examiners — a dashboard prevents this through proactive alerting.

4. Audit Trail & Data Retention

12

Immutable decision logs for all scored transactions MANDATORY

Every fraud scoring decision — including the rule or model that triggered it and the score assigned — must be logged and retained in a tamper-evident format. RBI examinations regularly request transaction-level decision logs for spot-check review.

13

Rule change history with user attribution MANDATORY

All changes to fraud detection rules — threshold updates, new rules, disabling existing rules — must be logged with timestamp and the identity of the user who made the change. This is a standard examination request.

14

Minimum 5-year data retention MANDATORY

The Master Direction on Fraud Risk Management requires financial institutions to retain records relating to fraud cases for a minimum of 5 years. This includes transaction data, decision logs, and correspondence.

5. Model Explainability & Governance

15

SHAP or equivalent ML decision explanations MANDATORY

RBI's guidance on responsible AI in financial services requires ML-based decisions to be explainable. Every fraud block or flag must be accompanied by a human-readable explanation of the key factors — "the model said so" is not acceptable in an examination or customer dispute.

16

Model version control and performance tracking RECOMMENDED

Active model version history — with precision, recall, and false positive rate tracked per version — is expected in mature fraud governance frameworks and is increasingly queried during RBI IT examinations.

17

Analyst review workflow for flagged transactions MANDATORY

There must be a defined workflow for human review of flagged transactions — including who can review, approve, or override a flag, and how that decision is logged. Fully automated systems without human oversight escalation do not satisfy the governance requirements.

6. Access Control & Role Separation

18

Role-based access control with principle of least privilege MANDATORY

CERT-In Directions require role-based access to cybersecurity systems. Analysts, compliance officers, and administrators must have distinct permission levels. Analysts should not be able to modify rules; administrators should not be able to suppress audit logs.

19

API key and credential management MANDATORY

Third-party intelligence integrations (bureau APIs, SEON, etc.) must use properly managed API credentials — not hardcoded in application code. Key rotation policies must be documented.

20

SAR/STR filing workflow MANDATORY

Suspicious Activity Reports (SAR) and Suspicious Transaction Reports (STR) must be filed with FIU-India for transactions meeting defined thresholds. Systems must support SAR generation from fraud alerts and maintain filing status records for each report.

How vcurd Maps to This Checklist

vcurd satisfies all 20 checklist items out of the box. Key compliance capabilities:

  • Real-time scoring at <50ms with automated block/flag/2FA actions
  • Mule Score engine with pass-through ratio, device sharing, and MHA district signals
  • One-click FMR export and CERT-In incident report generation
  • RBI reporting countdown dashboard with deadline alerts
  • Immutable transaction and rule-change audit trail
  • SHAP explainability on every ML decision
  • Three-tier RBAC: viewer / analyst / admin
  • SAR/STR filing module with FIU-India format export

For a full walkthrough of vcurd's compliance capabilities, visit the RBI & CERT-In Compliance page.