Bankers’ Books Evidence Bill, 2026: Police Can Access Your Bank Records without a Court Order — and That Is Just the Beginning of the Problem
Moneylife Digital Team 05 August 2026
Updated on 7 August 2026 at 2.40pm
 
Editor’s Note: What This Revision Changes and Why
 
For the original article, we relied on the evaluation by bank union leader Devidas Tuljapurkar, who is also the chairman of the Banking Education Training Research Academy (BETRA), particularly regarding the police-instead-of-a-judge provision. Following the PIB fact-check issued , we verified Mr Tuljapurkar’s evaluation against the actual statutory text — the Bankers' Books Evidence Act, 1891 (as it stands today, after its 1984, 2000, and 2002 amendments) and the sections of the Bankers' Books Evidence Bill, 2026. Three corrections and one new finding came out of that exercise.
 
1.  The ‘police instead of a judge’ provision is not new. The original article calls Section 11 — which lets an officer not below the rank of Superintendent of Police stand in for a court's order during a police investigation — "the single most serious provision in the Bill" and frames it as the Bill transferring power from judges to police. It doesn't. Section 8 of the 1891 Act already says this, in nearly identical words, and has done so since a 1984 amendment. The 2026 Bill re-enacts a four-decade-old provision almost verbatim. The issue is that 41 years of complaints about this clause produced a wholesale rewrite of the law and still didn't touch it.
 
2.  "Written for leather-bound ledgers" oversells the case for the Bill. The Bill says that the 1891 Act never anticipated digital records. In fact, "bankers' books" was redefined in 2000 and 2002 to explicitly include microfilm, magnetic tape, "any other form of mechanical or electronic data retrieval mechanism," and off-site back-up and disaster-recovery locations, and a certification regime for computerised printouts (Section 2A) has existed since 2000. The 2026 Bill's real innovation is narrower: it adds the words ‘digital’, ‘virtual’ and ‘cloud’ to an already electronic definition, and it makes admissibility of the digital record itself (not just certified copies of it) explicit. It is an update to an already-digital law.
 
3.  A new finding the original article missed — and it strengthens, not weakens, the certification critique. The 1891 Act's existing certification scheme (Section 2A, inserted in 2000) already splits the job in two: a branch manager or principal accountant certifies only that a printout is a true copy of an entry, while a separate certificate — describing system safeguards, tamper-detection, data transfer and backup integrity — must come from ‘the person in-charge of the computer system’, a technical role. Reporting on the 2026 Bill's Section 3(2) indicates its certificate is instead signed by ‘the branch head or the office head or any other authorised officer of the bank’ — combining both the transactional and technical attestations into one signature from what is typically a generalist, non-technical role. If so, the new Bill doesn't just fail to fix the branch-manager problem (as the original article describes). It appears to remove a modular safeguard that the 1891 Act, in its digital-era amendments, already had. We could not verify this against the Bill's full Second Schedule text, which was not available to us, but true, it is arguably the most damaging finding in this entire exercise.
 
4. The Bill actually adds one safeguard that the original article doesn't credit it for. Section 8(2) of the new Bill defines ‘special cause’ — the threshold a court must find before it can compel a bank officer to testify — for the first time, listing three specific grounds. The 1891 Act's Section 5 uses the phrase ‘special cause’ but never defines it, leaving it entirely to judicial discretion. Whatever else is wrong with the Bill, this is a narrowing of an open-ended power, not an expansion of one, and a fair reading should say so.
 
------------------
 
In a Parliament that has seen too many important laws pass without adequate scrutiny, the Bankers' Books Evidence Bill, 2026 (the Bill) has now joined the list. Introduced in Lok Sabha on 3 August 2026, the Bill was passed by voice vote on Wednesday — without a single word of debate — as Opposition members continued sloganeering and the Speaker, unable to restore order, simply put the legislation to a vote, amid the din.
 
The manner of its passage should itself be a red flag. A Bill that replaces a 135-year-old law governing the production of banking records in courts, that transfers the power to demand citizens' financial histories from judges to police officers, that requires branch managers to certify facts about cloud servers and cybersecurity systems they have no access to and that leaves bank customers with virtually no protection against wrongful or politically motivated disclosure of their most intimate financial data — this is precisely the kind of legislation that needed the most rigorous parliamentary examination. Instead, it got none.
 
Union finance minister Nirmala Sitharaman introduced the Bill with a straightforward justification: the Bankers' Books Evidence Act, 1891 (the Act), was written when bank records meant leather-bound ledgers. Today, they live in cloud servers, disaster-recovery sites and core banking systems spanning multiple states and third-party platforms. The argument for modernisation is, on its face, unimpeachable. But a detailed reading of the Bill's text and a critical evaluation by Devidas Tuljapurkar, chairman of the Banking Education Training Research Academy (BETRA) and a senior bank union leader, reveal something more troubling beneath the surface.
 
The Bill, as drafted and now passed in the Lok Sabha, expands State access to citizens' financial records, burdens frontline bank employees with certifications they cannot honestly make, strips away judicial supervision at a critical stage and leaves bank customers with virtually no protection against wrongful, excessive, or politically motivated disclosure of their financial histories. The disruptions denied Lok Sabha the debate this Bill deserved. The task of scrutiny now falls to the Rajya Sabha and if the upper house simply waves it through, the consequences will be felt by every bank customer in India.
 
What the Bill Actually Does
 
The Bill repeals and replaces the 1891 Act. Its principal changes are these: 
 
It expands the definition of ‘bankers' books’ to cover records maintained physically, electronically, digitally, virtually or in cloud and disaster-recovery locations which is a necessary and sensible update. It expressly recognises digital banking records as admissible, valid and legally enforceable evidence. It prescribes separate certification formats for physical and electronic records. It allows certification by a branch head, office head, or any other officer that the bank nominates. It empowers the Union government to extend the law's reach to any entity or class of entities operating in the financial sector by notification. And — most controversially — it allows investigative orders that would ordinarily require a court order to instead be issued by an officer not below the rank of superintendent of police (SP).
 
The statement of objects and reasons presents all of this as a technology-neutralisation exercise. But the implications extend far beyond recordkeeping procedure.
 
Your Financial Life Is Your Most Intimate Data
 
Before examining the Bill's specific defects, it is worth pausing on what a bank statement actually contains.
 
A statement of account is not merely a record of debits and credits. It is a map of a person's life. It reveals medical expenses and which hospitals or pharmacies were used. It shows political donations and union subscriptions. It discloses religious contributions, travel patterns, family relationships, subscription services, consumption habits and financial vulnerabilities. It can identify a journalist's sources, a whistle-blower's contacts, a trade unionist's associations, or an activist's support networks.
 
The 1891 Act was narrow and specific. It addressed the production of copies of bank records in court proceedings in which the bank was typically a party. The 2026 Bill substantially widens the legal landscape and does so without building in the privacy, proportionality and judicial oversight safeguards that the expansion demands.
 
The Surveillance Concern: Police Access without a Judge
 
The single most serious provision in the Bill is Section 11.
 
Under the existing framework, compelling production of bank records during an investigation requires a court order. Section 11 of the new Bill provides that for investigations and inquiries, the order of court referred to elsewhere in the Bill "shall be construed as referring to an order made by an officer not below the rank of a SP or such other officer as may be specified in this behalf by the appropriate government."
 
In plain terms: the Bill transfers the power to demand a citizen's banking records from an independent judicial authority to the investigating police establishment itself — or to any officer the government designates.
 
Mr Tuljapurkar's evaluation puts the risk with admirable precision. “The provision creates the possibility that bank records may be obtained without prior judicial scrutiny, through broad fishing inquiries, against political opponents, trade unions, civil society organisations, or journalists, without the bank or the customer being heard, and without any adequate remedy against excessive or irrelevant demands. An SP rank is not a substitute for judicial independence. The person issuing the order is the same institution conducting the investigation.”
 
This is not a theoretical concern. India has seen financial information weaponised against political opponents, investigative journalists, non-government organisations (NGOs) and labour organisations. Building a statutory framework that removes judicial scrutiny from the process of accessing citizens' financial histories is a significant step in the wrong direction, regardless of how the provision is packaged.
 
The fix, Mr Tuljapurkar argues, is straightforward: production or inspection of customer-level banking records during an investigation should require an order of a judicial magistrate or special court. A narrow emergency exception is defensible where there is an imminent risk of fund destruction or transfer, but it should require documented reasons and judicial confirmation within 48 to 72 hours, he added.
 
The Branch Manager Certification Problem
 
The Second Schedule of the Bill sets out the certificate that must accompany every digital banking record admitted as evidence. That certificate requires the signatory to affirm, among other things, that the computer system was operating properly throughout, that data entry was performed only by authorised persons, that no unauthorised alteration was detected, that adequate safeguards were taken to transfer data securely, that the network and devices were secure and that the system was equipped to meet the challenge of cyber risks or threats.
 
The certificate must be signed by the branch head, the office head, or another officer authorised by the bank.
 
Here is the structural absurdity. In a modern bank, a branch manager does not control, monitor, or have personal access to the bank's data centre. They do not manage the cloud service-provider. They have no visibility into the network security architecture, core banking software, audit trails, patch management, database administration, or cybersecurity incident logs. They do not know whether there is a system outage in Pune that affected a customer's transaction records in Delhi. They have no personal knowledge of whether the disaster-recovery site replicated the relevant entry correctly. 
 
The Bill's proviso that it is "sufficient for a matter to be stated to the best of the knowledge and belief of the person stating it" does not solve this problem. It simply means the branch manager is making a sworn statement about things they structurally cannot know, qualified only by the word ‘belief’. This is a recipe for either systematic false certification, in which managers sign whatever the bank's system generates, or personal legal exposure, in which a manager who signed in good faith is later blamed when a cybersecurity incident affects a particular record.
 
The solution, according to Mr Tuljapurkar, is modular certification. He said, “A transaction or account certificate can reasonably be signed by the branch or records officer. A system-integrity certificate should be issued centrally by the bank's designated technology or cybersecurity officer. A cryptographic hash or authenticity certificate should be generated through an approved automated system. Where a third-party cloud or infrastructure provider is involved, they should issue the relevant certificate for their component. And the law must expressly state that an employee who certifies in good faith on the basis of official system-generated information incurs no personal liability unless fraud, wilful falsification, or gross misconduct is proved.”
 
The Impossible Cybersecurity Declaration
 
Section 7(1)(i) of the Bill requires a declaration that "the network, devices and the data contained therein were secure and equipped to meet the challenge of cyber risks or threats." The Second Schedule certificate repeats this in clause (j).
 
No information system on earth can make this declaration truthfully. As we know and witness regularly, absolute security does not exist. A well-governed bank, with a top-class and mature security operations centre, experienced information technology (IT) teams, Reserve Bank of India (RBI)-compliant controls and a clean audit history, may still experience a phishing attack, a zero-day vulnerability, insider misuse, a brief outage, or a third-party service failure. The question the law should be asking is not whether the system is absolutely secure, but whether the specific record in question is affected by any identified incident.
 
The correct legal standard — as Mr Tuljapurkar's evaluation recommends — is whether the bank had implemented the security, access-control, audit-trail, and data-integrity safeguards prescribed by the applicable regulator and whether no identified incident is known to have materially affected the authenticity or accuracy of the particular record. 
 
“Demanding an absolute declaration of security does not strengthen evidentiary reliability. It simply produces certificates that no honest technology professional can sign without qualification,” he said.
 
No Audit Trail, No Chain of Custody
 
When a digital banking record is produced as evidence in a fraud case, a loan-account dispute, or a regulatory investigation, the critical questions are often not about what the record says, but about how it came to say it.
 
Was the entry made at the time it claims to have been made? Was it ever altered, reversed, or restored from backup? Who authorised it? Which system generated it? Was there a system migration between the original entry and the extraction? What does the audit trail show?
 
The Bill speaks in general terms about integrity and safe transfer, but it does not expressly mandate the production of timestamps, hash values, user access logs, maker-checker details, amendment history, extraction logs, chain-of-custody documentation, or details of any system migration. These are precisely the records that matter most in disputes involving cyber fraud, unauthorised transactions, backdated entries, wilful-default classification, or allegations of account manipulation.
 
For disputed electronic records, the certified copy needs to be accompanied by a unique record identifier, date and time of extraction, source application or database, cryptographic hash, audit trail of creation, modification and reversal, name or digital identity of the extracting official, details of system migration or restoration, and a chain-of-custody record. The Bill as drafted contains none of these requirements.
 
The Single Computer Fiction
 
Section 7(2) provides that where the function of creating, storing, or processing banking information is performed by one or more computer systems, networks, devices, computer resources, or intermediaries, whether in standalone mode, on a network, through a cloud resource, or through an intermediary, all such systems shall be treated ‘as constituting a single computer system or communication device’.
 
This simplification is procedurally convenient but analytically dangerous. A banking transaction today may pass through the bank's own core banking system, a payment gateway, a unified payments interface (UPI) application-provider, an automated teller machine (ATM) switch, a third-party cloud-provider, a business correspondent's device and a fin-tech intermediary before it is finally recorded. Each of these components has different security standards, audit systems, points of failure and responsible parties.
 
According to Mr Tuljapurkar, treating the entire chain as one system for evidentiary purposes may conceal the exact point at which an error, manipulation, or security failure occurred. “In a cyber fraud dispute, knowing whether the failure was in the bank's own system, the payment gateway, or the UPI provider could be decisive. The Bill should allow aggregation for procedural convenience where there is no dispute, but it should not dispense with the obligation to identify every material system or intermediary through which the disputed information passed when authenticity is genuinely in issue.”
 
Who Extends the Law and to Whom?
 
Section 4 of the Bill empowers the Union government to extend the Bill's provisions to ‘any entity or class of entities operating in the financial sector’ by notification, with such conditions, exceptions, or modifications as it chooses to specify. It may equally rescind, vary, or modify any such notification.
 
This is an extraordinarily broad power. The evidentiary privilege created by this Bill, the presumption that a certified copy of a banking record is reliable prima facie evidence, is designed for scheduled commercial banks (SCBs) operating under the detailed supervision of RBI, along with mandatory audit requirements, prescribed record-retention periods and capital adequacy and governance standards.
 
“The same presumption of reliability cannot automatically apply to a loosely regulated digital lending platform, a payment aggregator, a fintech intermediary, or a credit information company (CIC) merely because the government issues a notification. Parliament should list the eligible categories of entities in the Act itself. Any further extension should require prior consultation with the relevant statutory regulator, publication of a draft notification, invitation of public objections, and demonstration that the entity meets prescribed audit, cybersecurity, and record-retention standards. Affirmative parliamentary approval, rather than mere laying before Parliament, should be required for any significant extension,” Mr Tuljapurkar said.
 
The Customer Who Has No Voice
 
The Bill facilitates access to bank records but contains no substantive provision protecting the customer whose records are being produced.
 
There is no requirement to notify the customer before placing an order for inspection or production. There is no judicial assessment of the necessity and proportionality of the demand. There is no requirement that disclosure be limited to the relevant account, period, or subject matter. There is no provision for masking unrelated transactions. There is no prohibition on the secondary use of the records once produced. There is no requirement to secure the destruction of records after proceedings are complete. And there is no remedy where the wrong account is disclosed, excessive information is supplied, or data is used for an unrelated purpose.
 
Section 9 allows a court to permit a party to inspect and take copies of banking entries. “The order may be made without summoning the bank, and ordinarily requires only three clear days' notice to the bank before compliance — a period that is wholly inadequate when records are archived, stored in legacy or disaster-recovery systems, require redaction, or involve large numbers of transactions across multiple branches,” Mr Tuljapurkar said.
 
“Critically, the three-day notice protects the bank institutionally, not the customer. The customer has no formal standing in the process at all,” he added.
 
For borrowers and small depositors, the implications are particularly serious. In recovery proceedings, a certified bank statement should not, by itself, prove valid execution of loan documents, proper communication of interest-rate changes, compliance with restructuring instructions, lawful non-performing asset (NPA) classification, correctness of penal charges, service of recall notices, absence of unauthorised entries, or liability of guarantors. 
 
“Where a borrower specifically disputes an entry, the bank should be required to produce the underlying record, audit trail, sanction terms, computation methodology, or transaction authorisation. Small borrowers, pensioners, farmers, and digitally inexperienced customers cannot be expected to challenge a complex electronic certificate without legal assistance,” Mr Tuljapurkar said.
 
What Should Happen Next
 
Mr Tuljapurkar's evaluation makes a recommendation that this article endorses unreservedly: the Bill should have been referred to the parliamentary standing committee on Finance for stakeholder consultation before it was even taken up for passage. The Bill has now been passed by the Lok Sabha without any debate or discussion.
 
The proposed amendments by Mr Tuljapurkar seek to strengthen legal safeguards, improve transparency and balance investigative powers with customer rights. One of his key recommendations is to require judicial authorisation before investigators can access customer records. It also calls for clear safeguards based on the principles of privacy, necessity and proportionality, along with a requirement to notify affected customers, except in narrowly defined circumstances where such notice could hamper an investigation.
 
The proposals also seek to prohibit fishing expeditions and bulk disclosure of customer information. They recommend a modular certification framework that separates branch-level certification from technical system certification. In addition, employees acting in good faith while complying with legal requirements should be protected from liability.
 
To improve accountability, the amendments propose mandatory audit trails, metadata and chain-of-custody records in cases where evidence is disputed. They also recommend replacing absolute cybersecurity compliance declarations with a ‘reasonable safeguards’ standard and clarifying how the law will operate alongside the Bharatiya Sakshya Adhiniyam.
 
The recommendations further call for extending the compliance period for responding to requests from the current three days to at least 10 working days. They also propose that any future extension of the law to additional categories of entities should require Parliamentary approval.
 
The proposed changes include remedies for wrongful, excessive, or unauthorised disclosure of customer information. They also recommend establishing central evidence-certification units within banks to ensure consistency and reliability in records produced during investigations.
 
Finally, the amendments seek to clarify the evidentiary value of bank records by explicitly stating in law that a bank entry should constitute only prima facie evidence and should not, by itself, conclusively establish the existence of a debt, customer authorisation or the legality of a transaction.
 
None of these amendments would prevent the legitimate modernisation that the Bill's statement of objects and reasons promises. They would, however, ensure that modernisation does not become a cover for surveillance, that evidentiary efficiency does not come at the cost of customers' rights, and that frontline bank employees are not exposed to personal legal jeopardy for certifying facts they lack the institutional capacity to verify.
 
The 1891 Act served Indian courts for 135 years. It deserves a worthy successor. Unfortunately, the currently drafted Bankers' Books Evidence Bill, 2026, is not that successor.
 
Comments
Subba Rao
2 days ago
A law that existed for close to 125 years has been amended or re-drawn to suit current day needs. And that is a problem ? There are a hundred subjects on which Moneylife and it's editors/founders have championed consumer/customer interests, but this does not seem to be one such subject. We do not need to see ghosts in every corner. And why blame the ruling party (am not a supporter of any political party) when the opposition abdicates it's responsibilities. Change is the order of nature. So, there is no need to worry and fear monger every change that occurs. Critique the change by all means and help improve it.
adityag
1 week ago
This is wild! It will lead to exodus of HNIs. I'm surprised this isn't widely discussed in mainstream media. Cockroaches still grab headlines, not real issues.
ramlivs
1 week ago
The author/authors have not read section 8 of the old act which have exact same provisions. Check https://x.com/i/status/2085420647359074554 where the link to the old provision and the old act is provided.
yerramr
1 week ago
This Bill robs the customers ' rights. It should be stopped.
Jitendra B Parmar
1 week ago
Why Government is not banning huge amount of cash movement by Angadiys which is encouraging Hawala transaction , corruption and Black money transactions? If the Government is really sincre about total transparacy of financial transactions , they would have stopped Angadiya services , since with the digital transaction money can be remitted across the country within few hours and without physical movement of cash. Financial transparacy equally applies to all including the Government supported trust getting funds from PSUs and the public .
Jambunathan
1 week ago
The writer has brilliantly assessed the imminent dangers the proposed law will create for the customer. The fears expressed by him are real. Probably, the law needs to be challenged in the SC by the Bank Depositors Association. God save the Bank Deositors!
suketu
1 week ago
the public wl pull down this law by next yr.PUblic wl be all powerful,not leaders.The intent is sileening people for one world govt and dictatorship but it wl fail badly.
arorasid2711
1 week ago
I read more than half of this article and found it to be of no use. Branch manager or any other person means who so ever is competing by whatever name. But union leaders have it in blood to oppose for the sake of it.
Girish Mittal
1 week ago
This is a draconian bill and if it becomes an Act, must be challenged at an appropriate forum
PSBs Write Off ₹3.57 Lakh Crore Bad Loans in 5 Years; 15,930 Wilful Defaulters Owe ₹2.85 Lakh Crore: Govt
Moneylife Digital Team 03 August 2026
Public sector banks (PSBs) have written off bad loans worth more than ₹3.57 lakh crore during the past five financial years, while recovering about ₹1.65 lakh crore from written-off accounts over the same period, the Union government...
Bank of Baroda Says Cyber Incident Stemmed from Business Email Compromise; Probe Underway amid Claims of 1TB Data Leak
Moneylife Digital Team 28 July 2026
Public sector lender Bank of Baroda (BoB) has disclosed that it is investigating a cybersecurity incident after receiving a communication from an anonymous source claiming access to certain data. The Bank said preliminary findings...
HDFC Bank Board Penalises CEO, CFO over MSRDC Deposit Deal; Says It Was 'Business Overreach', Not Fraud
Moneylife Digital Team 27 July 2026
Following an internal review into its arrangements with Maharashtra State Road Development Corporation (MSRDC) for mobilising deposits in 2017 and 2021, the board of HDFC Bank Ltd has imposed a monetary penalty of ₹1 lakh each on its...
Moneylife Foundation Study Urges RBI To Cap Borrowing Costs and Limit Multiple Digital Loans
Moneylife Digital Team 24 July 2026
Can a borrower legally end up paying borrowing costs equivalent to 365% a year while simultaneously servicing half a dozen or more digital loans? According to a new study by Moneylife Foundation, the answer is yes—and it stems from...
Free Helpline
Legal Credit
Feedback