Bankers’ Books Evidence Bill, 2026: Police Can Access Your Bank Records without a Court Order — And That Is Just the Beginning of the Problem

In a Parliament that has seen too many important laws pass without adequate scrutiny, the Bankers’ Books Evidence Bill, 2026 (the Bill) has now joined the list. Introduced in Lok Sabha on 3 August 2026, the Bill was passed by voice vote on Wednesday — without a single word of debate — as opposition members continued sloganeering and the Speaker, unable to restore order, simply put the legislation to a vote amid the din.

The manner of its passage should itself be a red flag. A Bill that replaces a 135-year-old law governing the production of banking records in courts, that transfers the power to demand citizens’ financial histories from judges to police officers, that requires branch managers to certify facts about cloud servers and cybersecurity systems they have no access to, and that leaves bank customers with virtually no protection against wrongful or politically motivated disclosure of their most intimate financial data — this is precisely the kind of legislation that needed the most rigorous parliamentary examination. Instead, it got none.

Union finance minister Nirmala Sitharaman introduced the Bill with a straightforward justification: the Bankers’ Books Evidence Act, 1891 (the Act), was written when bank records meant leather-bound ledgers. Today, they live in cloud servers, disaster-recovery sites, and core banking systems spanning multiple states and third-party platforms. The argument for modernisation is, on its face, unimpeachable. But a detailed reading of the Bill’s text and a critical evaluation by Devidas Tuljapurkar, chairman of the Banking Education Training Research Academy (BETRA) and a senior bank union leader, reveal something more troubling beneath the surface.

The Bill, as drafted and now passed in the Lok Sabha, expands State access to citizens’ financial records, burdens frontline bank employees with certifications they cannot honestly make, strips away judicial supervision at a critical stage, and leaves bank customers with virtually no protection against wrongful, excessive, or politically motivated disclosure of their financial histories. The disruptions denied Lok Sabha the debate this Bill deserved. The task of scrutiny now falls to the Rajya Sabha and if the upper house simply waves it through, the consequences will be felt by every bank customer in India.

What the Bill Actually Does

The Bill repeals and replaces the 1891 Act. Its principal changes are these: 

It expands the definition of ‘bankers’ books’ to cover records maintained physically, electronically, digitally, virtually or in cloud and disaster-recovery locations, which is a necessary and sensible update. It expressly recognises digital banking records as admissible, valid and legally enforceable evidence. It prescribes separate certification formats for physical and electronic records. It allows certification by a branch head, office head, or any other officer that the bank nominates. It empowers the Union government to extend the law’s reach to any entity or class of entities operating in the financial sector by notification. And — most controversially — it allows investigative orders that would ordinarily require a court order to instead be issued by an officer not below the rank of superintendent of police (SP).

The statement of objects and reasons presents all of this as a technology-neutralisation exercise. But the implications extend far beyond recordkeeping procedure.

Your Financial Life Is Your Most Intimate Data

Before examining the Bill’s specific defects, it is worth pausing on what a bank statement actually contains.

A statement of account is not merely a record of debits and credits. It is a map of a person’s life. It reveals medical expenses and which hospitals or pharmacies were used. It shows political donations and union subscriptions. It discloses religious contributions, travel patterns, family relationships, subscription services, consumption habits and financial vulnerabilities. It can identify a journalist’s sources, a whistleblower’s contacts, a trade unionist’s associations, or an activist’s support networks.

The 1891 Act was narrow and specific. It addressed the production of copies of bank records in court proceedings in which the bank was typically a party. The 2026 Bill substantially widens the legal landscape and does so without building in the privacy, proportionality, and judicial oversight safeguards that the expansion demands.

The Surveillance Concern: Police Access without a Judge

The single most serious provision in the Bill is Section 11.

Under the existing framework, compelling production of bank records during an investigation requires a court order. Section 11 of the new Bill provides that for investigations and inquiries, the order of court referred to elsewhere in the Bill “shall be construed as referring to an order made by an officer not below the rank of a SP or such other officer as may be specified in this behalf by the appropriate government.”

In plain terms: the Bill transfers the power to demand a citizen’s banking records from an independent judicial authority to the investigating police establishment itself — or to any officer the government designates.

Mr Tuljapurkar’s evaluation puts the risk with admirable precision. “The provision creates the possibility that bank records may be obtained without prior judicial scrutiny, through broad fishing inquiries, against political opponents, trade unions, civil society organisations, or journalists, without the bank or the customer being heard, and without any adequate remedy against excessive or irrelevant demands. An SP rank is not a substitute for judicial independence. The person issuing the order is the same institution conducting the investigation.”

This is not a theoretical concern. India has seen financial information weaponised against political opponents, investigative journalists, non-government organisations (NGOs) and labour organisations. Building a statutory framework that removes judicial scrutiny from the process of accessing citizens’ financial histories is a significant step in the wrong direction, regardless of how the provision is packaged.

The fix, Mr Tuljapurkar argues, is straightforward: production or inspection of customer-level banking records during an investigation should require an order of a judicial magistrate or special court. A narrow emergency exception is defensible where there is an imminent risk of fund destruction or transfer, but it should require documented reasons and judicial confirmation within 48 to 72 hours, he added.

The Branch Manager Certification Problem

The Second Schedule of the Bill sets out the certificate that must accompany every digital banking record admitted as evidence. That certificate requires the signatory to affirm, among other things, that the computer system was operating properly throughout, that data entry was performed only by authorised persons, that no unauthorised alteration was detected, that adequate safeguards were taken to transfer data securely, that the network and devices were secure and that the system was equipped to meet the challenge of cyber risks or threats.

The certificate must be signed by the branch head, the office head, or another officer authorised by the bank.

Here is the structural absurdity. In a modern bank, a branch manager does not control, monitor, or have personal access to the bank’s data centre. They do not manage the cloud service provider. They have no visibility into the network security architecture, core banking software, audit trails, patch management, database administration, or cybersecurity incident logs. They do not know whether there is a system outage in Pune that affected a customer’s transaction records in Delhi. They have no personal knowledge of whether the disaster-recovery site replicated the relevant entry correctly. 

The Bill’s proviso that it is “sufficient for a matter to be stated to the best of the knowledge and belief of the person stating it” does not solve this problem. It simply means the branch manager is making a sworn statement about things they structurally cannot know, qualified only by the word ‘belief’. This is a recipe for either systematic false certification, in which managers sign whatever the bank’s system generates, or personal legal exposure, in which a manager who signed in good faith is later blamed when a cybersecurity incident affects a particular record.

The solution, according to Mr Tuljapurkar, is modular certification. He said, “A transaction or account certificate can reasonably be signed by the branch or records officer. A system-integrity certificate should be issued centrally by the bank’s designated technology or cybersecurity officer. A cryptographic hash or authenticity certificate should be generated through an approved automated system. Where a third-party cloud or infrastructure provider is involved, they should issue the relevant certificate for their component. And the law must expressly state that an employee who certifies in good faith on the basis of official system-generated information incurs no personal liability unless fraud, wilful falsification, or gross misconduct is proved.”

The Impossible Cybersecurity Declaration

Section 7(1)(i) of the Bill requires a declaration that “the network, devices and the data contained therein were secure and equipped to meet the challenge of cyber risks or threats.” The Second Schedule certificate repeats this in clause (j).

No information system on earth can make this declaration truthfully. As we know and witness regularly, absolute security does not exist. A well-governed bank, with a top-class and mature security operations centre, experienced information technology (IT) teams, Reserve Bank of India (RBI)-compliant controls and a clean audit history, may still experience a phishing attack, a zero-day vulnerability, insider misuse, a brief outage, or a third-party service failure. The question the law should be asking is not whether the system is absolutely secure, but whether the specific record in question is affected by any identified incident.

The correct legal standard — as Mr Tuljapurkar’s evaluation recommends — is whether the bank had implemented the security, access-control, audit-trail, and data-integrity safeguards prescribed by the applicable regulator and whether no identified incident is known to have materially affected the authenticity or accuracy of the particular record. 

“Demanding an absolute declaration of security does not strengthen evidentiary reliability. It simply produces certificates that no honest technology professional can sign without qualification,” he said.

No Audit Trail, No Chain of Custody

When a digital banking record is produced as evidence in a fraud case, a loan-account dispute, or a regulatory investigation, the critical questions are often not about what the record says, but about how it came to say it.

Was the entry made at the time it claims to have been made? Was it ever altered, reversed, or restored from backup? Who authorised it? Which system generated it? Was there a system migration between the original entry and the extraction? What does the audit trail show?

The Bill speaks in general terms about integrity and safe transfer, but it does not expressly mandate the production of timestamps, hash values, user access logs, maker-checker details, amendment history, extraction logs, chain-of-custody documentation, or details of any system migration. These are precisely the records that matter most in disputes involving cyber fraud, unauthorised transactions, backdated entries, wilful-default classification, or allegations of account manipulation.

For disputed electronic records, the certified copy needs to be accompanied by a unique record identifier, date and time of extraction, source application or database, cryptographic hash, audit trail of creation, modification and reversal, name or digital identity of the extracting official, details of system migration or restoration, and a chain-of-custody record. The Bill as drafted contains none of these requirements.

The Single Computer Fiction

Section 7(2) provides that where the function of creating, storing, or processing banking information is performed by one or more computer systems, networks, devices, computer resources, or intermediaries, whether in standalone mode, on a network, through a cloud resource, or through an intermediary, all such systems shall be treated ‘as constituting a single computer system or communication device’.

This simplification is procedurally convenient but analytically dangerous. A banking transaction today may pass through the bank’s own core banking system, a payment gateway, a unified payments interface (UPI) application provider, an automated teller machine (ATM) switch, a third-party cloud provider, a business correspondent’s device and a fintech intermediary before it is finally recorded. Each of these components has different security standards, audit systems, points of failure and responsible parties.

According to Mr Tuljapurkar, treating the entire chain as one system for evidentiary purposes may conceal the exact point at which an error, manipulation, or security failure occurred. “In a cyber fraud dispute, knowing whether the failure was in the bank’s own system, the payment gateway, or the UPI provider could be decisive. The Bill should allow aggregation for procedural convenience where there is no dispute, but it should not dispense with the obligation to identify every material system or intermediary through which the disputed information passed when authenticity is genuinely in issue.”

Who Extends the Law, and to Whom?

Section 4 of the Bill empowers the Union government to extend the Bill’s provisions to ‘any entity or class of entities operating in the financial sector’ by notification, with such conditions, exceptions, or modifications as it chooses to specify. It may equally rescind, vary, or modify any such notification.

This is an extraordinarily broad power. The evidentiary privilege created by this Bill, the presumption that a certified copy of a banking record is reliable prima facie evidence, is designed for scheduled commercial banks (SCBs) operating under the detailed supervision of the RBI, along with mandatory audit requirements, prescribed record-retention periods, and capital adequacy and governance standards.

“The same presumption of reliability cannot automatically apply to a loosely regulated digital lending platform, a payment aggregator, a fintech intermediary, or a credit information company (CIC) merely because the government issues a notification. Parliament should list the eligible categories of entities in the Act itself. Any further extension should require prior consultation with the relevant statutory regulator, publication of a draft notification, invitation of public objections, and demonstration that the entity meets prescribed audit, cybersecurity, and record-retention standards. Affirmative parliamentary approval, rather than mere laying before Parliament, should be required for any significant extension,” Mr Tuljapurkar said.

The Customer Who Has No Voice

The Bill facilitates access to bank records but contains no substantive provision protecting the customer whose records are being produced.

There is no requirement to notify the customer before placing an order for inspection or production. There is no judicial assessment of the necessity and proportionality of the demand. There is no requirement that disclosure be limited to the relevant account, period, or subject matter. There is no provision for masking unrelated transactions. There is no prohibition on the secondary use of the records once produced. There is no requirement to secure the destruction of records after proceedings are complete. And there is no remedy where the wrong account is disclosed, excessive information is supplied, or data is used for an unrelated purpose.

Section 9 allows a court to permit a party to inspect and take copies of banking entries. “The order may be made without summoning the bank, and ordinarily requires only three clear days’ notice to the bank before compliance — a period that is wholly inadequate when records are archived, stored in legacy or disaster-recovery systems, require redaction, or involve large numbers of transactions across multiple branches,” Mr Tuljapurkar said.

“Critically, the three-day notice protects the bank institutionally, not the customer. The customer has no formal standing in the process at all,” he added.

For borrowers and small depositors, the implications are particularly serious. In recovery proceedings, a certified bank statement should not, by itself, prove valid execution of loan documents, proper communication of interest-rate changes, compliance with restructuring instructions, lawful non-performing asset (NPA) classification, correctness of penal charges, service of recall notices, absence of unauthorised entries, or liability of guarantors. 

“Where a borrower specifically disputes an entry, the bank should be required to produce the underlying record, audit trail, sanction terms, computation methodology, or transaction authorisation. Small borrowers, pensioners, farmers, and digitally inexperienced customers cannot be expected to challenge a complex electronic certificate without legal assistance,” Mr Tuljapurkar said.

What Should Happen Next

Mr Tuljapurkar’s evaluation makes a recommendation that this article endorses unreservedly: the Bill should have been referred to the Parliamentary Standing Committee on Finance for stakeholder consultation before it was even taken up for passage. The Bill has now been passed by the Lok Sabha without any debate or discussion.

The proposed amendments by Mr Tuljapurkar seek to strengthen legal safeguards, improve transparency and balance investigative powers with customer rights. One of his key recommendations is to require judicial authorisation before investigators can access customer records. It also calls for clear safeguards based on the principles of privacy, necessity and proportionality, along with a requirement to notify affected customers, except in narrowly defined circumstances where such notice could hamper an investigation.

The proposals also seek to prohibit fishing expeditions and bulk disclosure of customer information. They recommend a modular certification framework that separates branch-level certification from technical system certification. In addition, employees acting in good faith while complying with legal requirements should be protected from liability.

To improve accountability, the amendments propose mandatory audit trails, metadata and chain-of-custody records in cases where evidence is disputed. They also recommend replacing absolute cybersecurity compliance declarations with a ‘reasonable safeguards’ standard and clarifying how the law will operate alongside the Bharatiya Sakshya Adhiniyam.

The recommendations further call for extending the compliance period for responding to requests from the current three days to at least 10 working days. They also propose that any future extension of the law to additional categories of entities should require Parliamentary approval.

The proposed changes include remedies for wrongful, excessive, or unauthorised disclosure of customer information. They also recommend establishing central evidence-certification units within banks to ensure consistency and reliability in records produced during investigations.

Finally, the amendments seek to clarify the evidentiary value of bank records by explicitly stating in law that a bank entry should constitute only prima facie evidence and should not, by itself, conclusively establish the existence of a debt, customer authorisation or the legality of a transaction.

None of these amendments would prevent the legitimate modernisation that the Bill’s statement of objects and reasons promises. They would, however, ensure that modernisation does not become a cover for surveillance, that evidentiary efficiency does not come at the cost of customers’ rights, and that frontline bank employees are not exposed to personal legal jeopardy for certifying facts they lack the institutional capacity to verify.

The 1891 Act served Indian courts for 135 years. It deserves a worthy successor. Unfortunately, the currently drafted Bankers’ Books Evidence Bill, 2026, is not that successor.

https://www.moneylife.in/article/bankers-books-evidence-bill-2026-police-can-access-your-bank-records-without-a-court-order-and-that-is-just-the-beginning-of-the-problem/81266.html

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.