Bankers’ Books Evidence Bill, 2026: Police Can Access Your Bank Records without a Court Order — And That Is Just the Beginning of the Problem

In a Parliament that has seen too many important laws pass without adequate scrutiny, the Bankers’ Books Evidence Bill, 2026 (the Bill) has now joined the list. Introduced in Lok Sabha on 3 August 2026, the Bill was passed by voice vote on Wednesday — without a single word of debate — as opposition members continued sloganeering and the Speaker, unable to restore order, simply put the legislation to a vote amid the din.

The manner of its passage should itself be a red flag. A Bill that replaces a 135-year-old law governing the production of banking records in courts, that transfers the power to demand citizens’ financial histories from judges to police officers, that requires branch managers to certify facts about cloud servers and cybersecurity systems they have no access to, and that leaves bank customers with virtually no protection against wrongful or politically motivated disclosure of their most intimate financial data — this is precisely the kind of legislation that needed the most rigorous parliamentary examination. Instead, it got none.

Union finance minister Nirmala Sitharaman introduced the Bill with a straightforward justification: the Bankers’ Books Evidence Act, 1891 (the Act), was written when bank records meant leather-bound ledgers. Today, they live in cloud servers, disaster-recovery sites, and core banking systems spanning multiple states and third-party platforms. The argument for modernisation is, on its face, unimpeachable. But a detailed reading of the Bill’s text and a critical evaluation by Devidas Tuljapurkar, chairman of the Banking Education Training Research Academy (BETRA) and a senior bank union leader, reveal something more troubling beneath the surface.

The Bill, as drafted and now passed in the Lok Sabha, expands State access to citizens’ financial records, burdens frontline bank employees with certifications they cannot honestly make, strips away judicial supervision at a critical stage, and leaves bank customers with virtually no protection against wrongful, excessive, or politically motivated disclosure of their financial histories. The disruptions denied Lok Sabha the debate this Bill deserved. The task of scrutiny now falls to the Rajya Sabha and if the upper house simply waves it through, the consequences will be felt by every bank customer in India.

What the Bill Actually Does

The Bill repeals and replaces the 1891 Act. Its principal changes are these: 

It expands the definition of ‘bankers’ books’ to cover records maintained physically, electronically, digitally, virtually or in cloud and disaster-recovery locations, which is a necessary and sensible update. It expressly recognises digital banking records as admissible, valid and legally enforceable evidence. It prescribes separate certification formats for physical and electronic records. It allows certification by a branch head, office head, or any other officer that the bank nominates. It empowers the Union government to extend the law’s reach to any entity or class of entities operating in the financial sector by notification. And — most controversially — it allows investigative orders that would ordinarily require a court order to instead be issued by an officer not below the rank of superintendent of police (SP).

The statement of objects and reasons presents all of this as a technology-neutralisation exercise. But the implications extend far beyond recordkeeping procedure.

Your Financial Life Is Your Most Intimate Data

Before examining the Bill’s specific defects, it is worth pausing on what a bank statement actually contains.

A statement of account is not merely a record of debits and credits. It is a map of a person’s life. It reveals medical expenses and which hospitals or pharmacies were used. It shows political donations and union subscriptions. It discloses religious contributions, travel patterns, family relationships, subscription services, consumption habits and financial vulnerabilities. It can identify a journalist’s sources, a whistleblower’s contacts, a trade unionist’s associations, or an activist’s support networks.

The 1891 Act was narrow and specific. It addressed the production of copies of bank records in court proceedings in which the bank was typically a party. The 2026 Bill substantially widens the legal landscape and does so without building in the privacy, proportionality, and judicial oversight safeguards that the expansion demands.

The Surveillance Concern: Police Access without a Judge

The single most serious provision in the Bill is Section 11.

Under the existing framework, compelling production of bank records during an investigation requires a court order. Section 11 of the new Bill provides that for investigations and inquiries, the order of court referred to elsewhere in the Bill “shall be construed as referring to an order made by an officer not below the rank of a SP or such other officer as may be specified in this behalf by the appropriate government.”

In plain terms: the Bill transfers the power to demand a citizen’s banking records from an independent judicial authority to the investigating police establishment itself — or to any officer the government designates.

Mr Tuljapurkar’s evaluation puts the risk with admirable precision. “The provision creates the possibility that bank records may be obtained without prior judicial scrutiny, through broad fishing inquiries, against political opponents, trade unions, civil society organisations, or journalists, without the bank or the customer being heard, and without any adequate remedy against excessive or irrelevant demands. An SP rank is not a substitute for judicial independence. The person issuing the order is the same institution conducting the investigation.”

This is not a theoretical concern. India has seen financial information weaponised against political opponents, investigative journalists, non-government organisations (NGOs) and labour organisations. Building a statutory framework that removes judicial scrutiny from the process of accessing citizens’ financial histories is a significant step in the wrong direction, regardless of how the provision is packaged.

The fix, Mr Tuljapurkar argues, is straightforward: production or inspection of customer-level banking records during an investigation should require an order of a judicial magistrate or special court. A narrow emergency exception is defensible where there is an imminent risk of fund destruction or transfer, but it should require documented reasons and judicial confirmation within 48 to 72 hours, he added.

The Branch Manager Certification Problem

The Second Schedule of the Bill sets out the certificate that must accompany every digital banking record admitted as evidence. That certificate requires the signatory to affirm, among other things, that the computer system was operating properly throughout, that data entry was performed only by authorised persons, that no unauthorised alteration was detected, that adequate safeguards were taken to transfer data securely, that the network and devices were secure and that the system was equipped to meet the challenge of cyber risks or threats.

The certificate must be signed by the branch head, the office head, or another officer authorised by the bank.

Here is the structural absurdity. In a modern bank, a branch manager does not control, monitor, or have personal access to the bank’s data centre. They do not manage the cloud service provider. They have no visibility into the network security architecture, core banking software, audit trails, patch management, database administration, or cybersecurity incident logs. They do not know whether there is a system outage in Pune that affected a customer’s transaction records in Delhi. They have no personal knowledge of whether the disaster-recovery site replicated the relevant entry correctly. 

The Bill’s proviso that it is “sufficient for a matter to be stated to the best of the knowledge and belief of the person stating it” does not solve this problem. It simply means the branch manager is making a sworn statement about things they structurally cannot know, qualified only by the word ‘belief’. This is a recipe for either systematic false certification, in which managers sign whatever the bank’s system generates, or personal legal exposure, in which a manager who signed in good faith is later blamed when a cybersecurity incident affects a particular record.

The solution, according to Mr Tuljapurkar, is modular certification. He said, “A transaction or account certificate can reasonably be signed by the branch or records officer. A system-integrity certificate should be issued centrally by the bank’s designated technology or cybersecurity officer. A cryptographic hash or authenticity certificate should be generated through an approved automated system. Where a third-party cloud or infrastructure provider is involved, they should issue the relevant certificate for their component. And the law must expressly state that an employee who certifies in good faith on the basis of official system-generated information incurs no personal liability unless fraud, wilful falsification, or gross misconduct is proved.”

The Impossible Cybersecurity Declaration

Section 7(1)(i) of the Bill requires a declaration that “the network, devices and the data contained therein were secure and equipped to meet the challenge of cyber risks or threats.” The Second Schedule certificate repeats this in clause (j).

No information system on earth can make this declaration truthfully. As we know and witness regularly, absolute security does not exist. A well-governed bank, with a top-class and mature security operations centre, experienced information technology (IT) teams, Reserve Bank of India (RBI)-compliant controls and a clean audit history, may still experience a phishing attack, a zero-day vulnerability, insider misuse, a brief outage, or a third-party service failure. The question the law should be asking is not whether the system is absolutely secure, but whether the specific record in question is affected by any identified incident.

The correct legal standard — as Mr Tuljapurkar’s evaluation recommends — is whether the bank had implemented the security, access-control, audit-trail, and data-integrity safeguards prescribed by the applicable regulator and whether no identified incident is known to have materially affected the authenticity or accuracy of the particular record. 

“Demanding an absolute declaration of security does not strengthen evidentiary reliability. It simply produces certificates that no honest technology professional can sign without qualification,” he said.

No Audit Trail, No Chain of Custody

When a digital banking record is produced as evidence in a fraud case, a loan-account dispute, or a regulatory investigation, the critical questions are often not about what the record says, but about how it came to say it.

Was the entry made at the time it claims to have been made? Was it ever altered, reversed, or restored from backup? Who authorised it? Which system generated it? Was there a system migration between the original entry and the extraction? What does the audit trail show?

The Bill speaks in general terms about integrity and safe transfer, but it does not expressly mandate the production of timestamps, hash values, user access logs, maker-checker details, amendment history, extraction logs, chain-of-custody documentation, or details of any system migration. These are precisely the records that matter most in disputes involving cyber fraud, unauthorised transactions, backdated entries, wilful-default classification, or allegations of account manipulation.

For disputed electronic records, the certified copy needs to be accompanied by a unique record identifier, date and time of extraction, source application or database, cryptographic hash, audit trail of creation, modification and reversal, name or digital identity of the extracting official, details of system migration or restoration, and a chain-of-custody record. The Bill as drafted contains none of these requirements.

The Single Computer Fiction

Section 7(2) provides that where the function of creating, storing, or processing banking information is performed by one or more computer systems, networks, devices, computer resources, or intermediaries, whether in standalone mode, on a network, through a cloud resource, or through an intermediary, all such systems shall be treated ‘as constituting a single computer system or communication device’.

This simplification is procedurally convenient but analytically dangerous. A banking transaction today may pass through the bank’s own core banking system, a payment gateway, a unified payments interface (UPI) application provider, an automated teller machine (ATM) switch, a third-party cloud provider, a business correspondent’s device and a fintech intermediary before it is finally recorded. Each of these components has different security standards, audit systems, points of failure and responsible parties.

According to Mr Tuljapurkar, treating the entire chain as one system for evidentiary purposes may conceal the exact point at which an error, manipulation, or security failure occurred. “In a cyber fraud dispute, knowing whether the failure was in the bank’s own system, the payment gateway, or the UPI provider could be decisive. The Bill should allow aggregation for procedural convenience where there is no dispute, but it should not dispense with the obligation to identify every material system or intermediary through which the disputed information passed when authenticity is genuinely in issue.”

Who Extends the Law, and to Whom?

Section 4 of the Bill empowers the Union government to extend the Bill’s provisions to ‘any entity or class of entities operating in the financial sector’ by notification, with such conditions, exceptions, or modifications as it chooses to specify. It may equally rescind, vary, or modify any such notification.

This is an extraordinarily broad power. The evidentiary privilege created by this Bill, the presumption that a certified copy of a banking record is reliable prima facie evidence, is designed for scheduled commercial banks (SCBs) operating under the detailed supervision of the RBI, along with mandatory audit requirements, prescribed record-retention periods, and capital adequacy and governance standards.

“The same presumption of reliability cannot automatically apply to a loosely regulated digital lending platform, a payment aggregator, a fintech intermediary, or a credit information company (CIC) merely because the government issues a notification. Parliament should list the eligible categories of entities in the Act itself. Any further extension should require prior consultation with the relevant statutory regulator, publication of a draft notification, invitation of public objections, and demonstration that the entity meets prescribed audit, cybersecurity, and record-retention standards. Affirmative parliamentary approval, rather than mere laying before Parliament, should be required for any significant extension,” Mr Tuljapurkar said.

The Customer Who Has No Voice

The Bill facilitates access to bank records but contains no substantive provision protecting the customer whose records are being produced.

There is no requirement to notify the customer before placing an order for inspection or production. There is no judicial assessment of the necessity and proportionality of the demand. There is no requirement that disclosure be limited to the relevant account, period, or subject matter. There is no provision for masking unrelated transactions. There is no prohibition on the secondary use of the records once produced. There is no requirement to secure the destruction of records after proceedings are complete. And there is no remedy where the wrong account is disclosed, excessive information is supplied, or data is used for an unrelated purpose.

Section 9 allows a court to permit a party to inspect and take copies of banking entries. “The order may be made without summoning the bank, and ordinarily requires only three clear days’ notice to the bank before compliance — a period that is wholly inadequate when records are archived, stored in legacy or disaster-recovery systems, require redaction, or involve large numbers of transactions across multiple branches,” Mr Tuljapurkar said.

“Critically, the three-day notice protects the bank institutionally, not the customer. The customer has no formal standing in the process at all,” he added.

For borrowers and small depositors, the implications are particularly serious. In recovery proceedings, a certified bank statement should not, by itself, prove valid execution of loan documents, proper communication of interest-rate changes, compliance with restructuring instructions, lawful non-performing asset (NPA) classification, correctness of penal charges, service of recall notices, absence of unauthorised entries, or liability of guarantors. 

“Where a borrower specifically disputes an entry, the bank should be required to produce the underlying record, audit trail, sanction terms, computation methodology, or transaction authorisation. Small borrowers, pensioners, farmers, and digitally inexperienced customers cannot be expected to challenge a complex electronic certificate without legal assistance,” Mr Tuljapurkar said.

What Should Happen Next

Mr Tuljapurkar’s evaluation makes a recommendation that this article endorses unreservedly: the Bill should have been referred to the Parliamentary Standing Committee on Finance for stakeholder consultation before it was even taken up for passage. The Bill has now been passed by the Lok Sabha without any debate or discussion.

The proposed amendments by Mr Tuljapurkar seek to strengthen legal safeguards, improve transparency and balance investigative powers with customer rights. One of his key recommendations is to require judicial authorisation before investigators can access customer records. It also calls for clear safeguards based on the principles of privacy, necessity and proportionality, along with a requirement to notify affected customers, except in narrowly defined circumstances where such notice could hamper an investigation.

The proposals also seek to prohibit fishing expeditions and bulk disclosure of customer information. They recommend a modular certification framework that separates branch-level certification from technical system certification. In addition, employees acting in good faith while complying with legal requirements should be protected from liability.

To improve accountability, the amendments propose mandatory audit trails, metadata and chain-of-custody records in cases where evidence is disputed. They also recommend replacing absolute cybersecurity compliance declarations with a ‘reasonable safeguards’ standard and clarifying how the law will operate alongside the Bharatiya Sakshya Adhiniyam.

The recommendations further call for extending the compliance period for responding to requests from the current three days to at least 10 working days. They also propose that any future extension of the law to additional categories of entities should require Parliamentary approval.

The proposed changes include remedies for wrongful, excessive, or unauthorised disclosure of customer information. They also recommend establishing central evidence-certification units within banks to ensure consistency and reliability in records produced during investigations.

Finally, the amendments seek to clarify the evidentiary value of bank records by explicitly stating in law that a bank entry should constitute only prima facie evidence and should not, by itself, conclusively establish the existence of a debt, customer authorisation or the legality of a transaction.

None of these amendments would prevent the legitimate modernisation that the Bill’s statement of objects and reasons promises. They would, however, ensure that modernisation does not become a cover for surveillance, that evidentiary efficiency does not come at the cost of customers’ rights, and that frontline bank employees are not exposed to personal legal jeopardy for certifying facts they lack the institutional capacity to verify.

The 1891 Act served Indian courts for 135 years. It deserves a worthy successor. Unfortunately, the currently drafted Bankers’ Books Evidence Bill, 2026, is not that successor.

https://www.moneylife.in/article/bankers-books-evidence-bill-2026-police-can-access-your-bank-records-without-a-court-order-and-that-is-just-the-beginning-of-the-problem/81266.html

If the Bank loses your documents

Manoj Madhusudhanan took a ₹1.86 crore home loan from ICICI Bank.

As collateral, he handed over his original property documents. Every homebuyer does this. You have no choice.

ICICI Bank sent those documents to their storage facility in Hyderabad via courier. Somewhere on that journey — Bangalore to Hyderabad — the documents vanished.

Gone. Originals. Irreplaceable.

When Manoj found out, ICICI Bank had one answer: it was the courier company’s fault. Not ours.

He went to the Banking Ombudsman. They told ICICI to publish a public notice about the loss and pay him ₹25,000 for the trouble.

Twenty-five thousand rupees. For losing the original documents to a ₹1.86 crore property.

Manoj sent a legal notice. ICICI denied any mistake.

He went to the NCDRC.

The apex consumer court looked at the facts. The bank had taken custody of the documents. The bank had chosen the courier. The bank could not hand that liability to a third party and walk away.

ICICI Bank — India’s second-largest private bank, ₹9 lakh crore in assets — was held liable. Ordered to obtain reconstructed certified copies, issue an indemnity bond, and pay ₹25 lakh in compensation.

One loan. One lost file. One bank that blamed the courier.

Save this — if your bank loses your original property documents, they cannot blame their courier agent. The documents were in their custody. The liability is theirs. File at your district consumer forum. The law is on your side.

(Source: Manoj Madhusudhanan vs. ICICI Bank Ltd. | NCDRC | LiveLaw, September 2023)

Are you 60+ or helping parents or senior citizens use digital payments?

The Reserve Bank of India has proposed new safeguards to reduce fraud—such as:

  • A possible delay in certain transactions
  • Extra checks for senior citizens
  • A “kill switch” to block payments instantly

While these aim to improve safety, they may also affect how quickly and easily payments can be made.

We want your views—this short survey takes just 3 minutes: https://www.surveymonkey.com/r/mlf-survey

Your feedback will help Moneylife Foundation prepare a public response to the RBI.

Please fill this survey and share it too. It is important feedback to make a proper representation to the RBI. It impacts all of us. 🙏

Supreme Court rules that Banks fully liable for fraudulent withdrawals

In a landmark verdict, the Supreme Court has ruled that banks are fully liable if money is fraudulently
withdrawn from a customer’s account. The decision, delivered on 3rd January 2025 in the case of State Bank of India vs. Pallabh Bhowmik and Others, reinforces the accountability of financial institutions in safeguarding customer funds.


Banking expert Vidyadhar Anaskar emphasized that the ruling provides significant relief to account holders, affirming that banks cannot evade responsibility in cases of fraud. The verdict is expected to have a profound impact on banking operations and consumer protectionin the financial sector.
The court based its decision on Section 5 of the Banking Regulation Act, Section 10 of the Reserve Bank of India Act, and the Consumer Protection Act of 2019. The ruling mandates that banks must fully compensate customers for fraudulent withdrawals and ensure strict security measures to prevent such incidents.

During the hearing, the account holder argued that the bank had failed to fulfill its obligations by not implementing adequate fraud prevention measures. It was also alleged that the bank violated the Consumer Protection Act by neglecting its duty to protect customer funds. In response, the bank contended that it bore no negligence and that the customer’s failure to act promptly had contributed to the fraud.

However, the Supreme Court firmly held that the safety of customer deposits is not just a courtesy but a fundamental responsibility of banks. The judgment stressed that financial institutions must establish robust security systems to prevent fraud and cannot shift the burden onto customers under any circumstances.
This decision sets a critical precedent for the banking industry, reinforcing consumer rights and highlighting the necessity for stringent cybersecurity measures. Anaskar noted that this ruling will enhance public trust in banks and encourage financial institutions to adopt more effective fraud prevention mechanisms.
With this verdict, banks are expected to implement immediate and comprehensive security upgrades to protect customer accounts, ensuring better compliance with consumer protection laws and regulatory requirements.

Recent Changes in Nomination Rules

There have been recent changes to nomination rules for bank accounts, mutual funds, and demat accounts. 

Bank accounts 

  • The Banking Laws Amendment Act, 2024 allows up to four nominees to be named for a bank account.
  • The nomination can be made for deposits, safe custody, and safety lockers.
  • The nomination must specify the percentage of the deposit allocated to each nominee.
  • If the order of nomination is not specified, the nominees will be considered in the order of their names.

Mutual funds and demat accounts

  • The Securities and Exchange Board of India (SEBI) allows up to 10 nominees to be named for a mutual fund or demat account. 
  • The nomination must be made directly by the investor. 
  • The nominees can hold the assets jointly or open separate accounts. 
  • The investor must provide detailed information about their nominees, including their PAN number, driving license number, or Aadhaar number. 

These changes aim to improve services for depositors, nominees, and investors. They also help to reduce unclaimed assets and improve the management of investments. 

Section 138 cheque bouncing cases

Section 138 cheque bouncing cases:

    Made simple to understand:  

    A complete Resource:  

I am excited to share the Resource I am developing about cheque bouncing cases. https://www.litigationplatform.com/Judgment/Index/60104591-fc87-4cd8-af8a- 26c08c5a9465

It is an organized compilation of HC and SC Rulings on all aspects of cheque bouncing Cases.

It will help in understanding the intricacies of criminal trial and might help in getting swift outcomes.

Regards, Sandeep Jalan Advocate

Banking on legislation

The ‘bail-in’ clause, in a draft bill, would change the relationship between the customer and the bank

The recapitalisation of public sector banks (PSBs) through bailouts, be they as budgetary allocation or some sort of bond issue, has evoked much discussion. The Insolvency and Bankruptcy Code is cited as adequate punishment for defaulting borrower companies. However, under the code, the resolution process has brought little succour to banks as the recovery rate from defaulting companies has so far been merely 15-20% of the original amount lent. Meanwhile, there is no attempt so far by the Reserve Bank of India (RBI) to issue guidance to PSBs to blacklist these entities from getting further loans or prevent their managements from retaining a majority equity stake during the resolution process as penalty for the huge haircuts being taken by banks.

The result is that banks have been continually reporting losses in each successive quarter. Six PSBs have already been placed under prompt corrective action by the RBI. Even the State Bank of India was still stuck with non-performing assets worth ₹1,88,068 crore as on June 2017.

Deposits are at risk

According to the Financial Stability Board (FSB) Peer Review Report August 2016, 63% of the financial investments ordinary Indians make are within the banking system; PSBs account for 63% of the market share while private banks control 18%. Given the shaky financial condition of most public banks, deposits in these banks are very much at risk. In the best case scenario, there could be a government bailout. Other possibilities are the transfer of their assets and liabilities to a bridge service provider, a merger with an existing bank, or even liquidation. But none of these options guarantees safety of customer money.

What adds to the disquiet is the Financial Resolution and Deposit Insurance (FRDI) Bill, 2017 that was referred to a joint parliamentary committee this August after cabinet approval. This covers bankruptcy of businesses such as banks and insurance. Financial resolution includes solutions for banks facing ‘material’ or ‘imminent’ risk to viability depending on their capital and asset worth.

This Bill also introduces the provision for a “bail-in”, whose purpose is to provide capital to absorb the losses of a bank and ensure its survival. Here, survival does not mean safety of depositors’ money, but restoration of capital of the bank. The bail-in empowers the proposed Resolution Corporation to cancel a liability owed by the bank or change the form of an existing liability to another security.

All of us are aware that money in a savings or fixed deposit account is a liability owed by the bank to its customer. The bank promises to repay the money when demanded by the customer. Since the customer has not taken any security from the bank when handing over his money, legally, the customer is an unsecured creditor of the bank. With a ‘bail-in’, the bank simply refuses repayment of a customer’s money or instead issues securities such as preference shares (with no guarantee of fixed dividends) to a customer. This is in lieu of his deposits which are then used for recapitalisation of the bank.

The only money owed to depositors that cannot be bailed-in is the amount covered by deposit insurance. The Deposit Insurance and Credit Guarantee Corporation Act, 1961 which insured deposits worth one lakh for each depositor has been repealed by the cabinet. The FRDI Bill further empowers the Resolution Corporation to decide the amount insured for each depositor. Thus, it is possible that the insured amounts will not only vary for customers in different banks, but may also be different for different customers of the same bank.

No longer safe

The ‘bail-in’ clause changes the nature of relationship between the customer and the bank. It would mean that money is no longer safe in a bank. An account would lose its sovereign guarantee and instead become an investment. Putting away money in a bank would be akin to buying shares of a company or units of a mutual fund. The customer would need to monitor the level of toxicity of his bank with respect to its losses and accordingly keep switching bank accounts.

The banking saga has all the ingredients of a full-fledged Shakespearean tragedy. Out of the three protagonists, the government as the majority shareholder and the corporate borrower are wearing their victimhood as a badge of honour. Whereas, the real victim, the customer, is the unsung hero coerced into parting with his money.

The reality is that without customer deposits, a bank cannot carry on its business. It has to be understood that banking business is not the same as any other business. A bank customer cannot be treated on a par with an unsecured creditor of a regular business. The customer is not privy to the lending decisions in a bank unlike any vendor or investor dealing with a company. Hence the rules for bankruptcy of a regular business cannot be applied to bank failures. For the sake of justice and fairness to its citizens, the government must take a stand and defy the FSB’s diktat on the ‘bail-in’ clause.

by Meera Nangia who is Associate Professor in Commerce, University of Delhi

 

https://www.thehindu.com/opinion/op-ed/banking-on-legislation/article20005363.ece