Home
Fraud Detection

Mule Accounts and the Law: How is AML Liability Tightening on Banks

Date Published

A money mule scam starts when fraudsters recruit account holders to move illicit cash. Historically, banks treated these accounts as an operational nuisance: flag, freeze, report.

That approach is dead.

Strict AML mandates, tighter KYC requirements, and legal shifts putting the burden of proof squarely on banks have changed the game. Mule accounts are no longer just an operational fraud problem; they are a direct legal and compliance liability.

Here is why this shift happened, and what it means for your risk and compliance teams.

Why Mule Accounts Are an AML Problem

Handling a money mule in Anti-money laundering (AML) processes is not optional. AML regulation exists to stop illicit funds from entering and moving through the formal financial system, and a mule account is precisely that entry point. It represents the placement stage: the moment fraud proceeds first land inside a regulated account, before layering through further transfers disguises their origin.

Institutions that route mule-account cases exclusively through fraud operations, rather than also treating them as a Prevention of Money Laundering Act (PMLA) reporting matter, are applying a narrower lens than the law itself does. A mule account discovered during onboarding is a KYC failure. A mule account discovered after funds have moved through it is, more precisely, an AML failure, and the reporting and record-keeping obligations differ accordingly.

The KYC Obligations Banks and NBFCs Actually Carry

RBI's Master Direction on Know Your Customer sets the baseline, and it has grown more specific rather than simpler. Since November 2025, banks and NBFCs operate under separate, more detailed Master Directions, both of which retain Video-based Customer Identification Process (VKYC or V-CIP) as the standard alternative to in-branch verification, while tightening the audit trail requirements around it.

Two obligations dictate your actual mule-account exposure today:

Central KYC (CKYC) uploads: Banks and NBFCs must submit customer KYC records to CKYC. This central registry closes the gap where an applicant rejected by one institution simply walks into another

Equal obligations for wallets and aggregators: Payment aggregators and prepaid instrument (PPI) issuers now operate under the same KYC Master Direction framework as banks. Because mule networks usually move money through digital wallets before touching core bank accounts, your compliance boundary starts at the wallet layer.

The Enforcement Stack Closing In

The regulatory response to mule accounts has moved from guidance to infrastructure in a short span of time.

Regulatory and enforcement frameworks continue to evolve rapidly to address fraudulent activity across financial networks. Key initiatives such as MuleHunter.AI, DPIP, the I4C Suspect Registry, and the Supreme Court SOP collectively enhance data sharing, cross-institutional signals, and standardized procedures to better identify suspicious account activity and mitigate fraud risks.

But none of these tools change the underlying AML and KYC obligations institutions already carry. 

What Technology Adds That Regulation Alone Cannot

National registries spot known bad actors across institutions. But proactive mule detection requires tech built directly into your own infrastructure. Automated money mule detection depends on four core capabilities:

  1. Onboarding checks: VKYC and document validation create timestamped proof of what you verified before opening an account.
  2. Transaction monitoring: Behavioural models spot suspicious velocity and cash flow patterns after an account opens.
  3. Graph analysis: Link analysis spots shared devices, IP addresses, and beneficiaries to expose full network operations instead of isolated accounts.
  4. Unified record engine: A single system ties all three inputs into one auditable trail.

Liability Is Moving Onto Banks

The biggest legal shift isn't about fraud detection technology. It's about who pays when detection fails. RBI's Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, issued June 24, 2026 and taking effect for transactions from January 1, 2027, introduce the concept of a ‘fraudulent electronic banking transaction’ and place the burden of proving customer liability on the bank, not the customer.

The framework defines bank negligence explicitly, covering failure to implement mandated security systems, non-issuance of transaction alerts, absence of round-the-clock reporting channels, and failure to act diligently on complaints. Customers get zero liability where the fraud stems from bank negligence or a third-party breach reported within five calendar days. A separate compensation mechanism, also effective from January 1, 2027, covers losses up to ₹50,000: eligible customers receive 85% of net loss or ₹25,000, whichever is lower, once in their lifetime, with the cost initially shared between RBI and the banks involved before that share phases out over the following year.

The RBI Governor confirmed that nearly 65% of digital fraud involves amounts under ₹50,000. This rule hits that exact bracket. It covers the vast majority of mule-account complaints banks handle today, and puts the burden of proof squarely on institutions. The scale of the shift is clearer when set against the 2017 framework it replaces:

What Compliance and Risk Teams Should Do Now

Sync Fraud-Ops and AML: Route every confirmed mule through both teams immediately. PMLA obligations apply no matter who catches the account first.

Audit CKYC uploads now: Fix upload gaps before your next audit cycle. Missing records don't just invite regulatory penalties; they blind you to flags raised by other banks.

Document security controls: Collect hard evidence for your alert systems, response timelines, and complaint channels. The new rules require you to prove your bank wasn't negligent. Don't assume your setup holds up; prove it.

Treat detection as legal defence: View detection technology as compliance risk mitigation, not just fraud loss control. From January 2027, weak detection means weak legal defensibility.

Unify your risk signals: Combine onboarding data, transaction logs, and suspect registries into a single system of record. Disconnected logs won't satisfy a regulator asking what you knew and when.

Where This Is Headed

The direction of travel is consistent: DPIP and the I4C-RBIH data-sharing MoU move fraud intelligence from siloed, bank-by-bank systems toward shared, real-time data, while the new liability framework and KYC Master Direction amendments both tighten what counts as adequate diligence. With the compensation mechanism's RBI-funded share explicitly designed to taper off after its first year, banks should expect the full cost of detection failure to land on their own books well before the framework matures.

Conclusion

Mule accounts sit at the intersection of fraud operations, AML reporting, and KYC compliance, and treating them as only the first of those three is no longer a defensible position, legally or operationally. With liability shifting onto banks from January 2027, the institutions that already run consolidated, auditable detection, rather than three separate logs across three separate teams, will be the ones that can prove diligence when it counts. Platforms that combine onboarding intelligence with fraud analytics, such as IDfy's OnboardIQ and OneRisk, are increasingly where that consolidated record actually gets built.

FAQs

How are mule accounts an AML issue rather than only a fraud issue? A mule account is the placement stage of money laundering, the point where illicit funds first enter the regulated financial system, which brings it under Prevention of Money Laundering Act reporting and record-keeping obligations, separate from ordinary fraud-loss handling.

What is CKYC and why does it matter for mule account detection? CKYC, the Central KYC Registry, is where banks and NBFCs must upload customer KYC records under RBI's Master Direction. It lets an institution check whether an applicant has already raised concerns elsewhere, closing the gap where a rejected applicant simply opens an account at a different bank.

Who bears the loss when a mule-linked fraudulent transaction occurs? Under RBI's Third Amendment Directions, effective from January 1, 2027, the burden of proving customer liability lies with the bank. Customers get zero liability where negligence lies with the bank or a third party, provided the fraud is reported within five calendar days.

What is MuleHunter.AI? A machine-learning tool built by the Reserve Bank Innovation Hub that flags mule accounts from transaction data using nineteen behavioural patterns, now live at roughly half of India's banks.

Does the new RBI compensation framework cover all fraud losses? No. It applies only to losses up to ₹50,000 involving bona fide victims who report within five calendar days, and pays 85% of net loss or ₹25,000, whichever is lower, once per customer's lifetime. Larger losses fall outside this specific mechanism.


money mules
Fraud Detection,  Fraud Detection / Privy,  Fraud Detection / KYC

Who are money mules? A money mule is someone who transfers money on behalf of or in the direction of another person. They look for people to