For years, dormant accounts were an operational nuisance. Under DPDP and RBI's updated frameworks, they are a liability. Here is how to manage them systematically.
For years, "dormant accounts" were an operational nuisance — a list of customers who stopped transacting, costing you maintenance fees. As of January 2026, they are officially a security threat.
With the RBI's new Account Hygiene Norms now in effect, the definition of a "healthy ledger" has changed. The regulator is no longer just asking "How many inactive accounts do you have?" They are asking: "Why are they still open, and who controls them?"
The RBI's updated 2026 guidelines have tightened the screw on account classification. The days of passive "bulk closures" are over.
Why the regulatory heat? Because dormant accounts are the preferred vehicle for Money Mules. Fraud rings don't open new accounts; they buy old ones. A savings account that has been "sleeping" for 18 months is the perfect Trojan Horse — it has a vintage, a history, and flies under the radar of standard fraud models — until sudden high-velocity transfers begin.
Consider the ops challenge: You have 5 million accounts and 15% are inactive. If you close them all, you lose 750,000 potential future customers. If you keep them open without checks, you invite regulatory penalties and fraud.
You cannot solve this with a call center. Dialing 750,000 customers to ask "Are you still there?" is cost-prohibitive and low-yield. Leading banks are deploying Automated Re-KYC Journeys.
Instead of a generic "Use it or lose it" email, the system triggers a personalized engagement hook via WhatsApp or app notification: "Hi [Name], your card benefits are paused. Make one transaction of ₹1 to keep your lounge access active." This filters out the "Forgetful Savers" from the truly "Departed."
For accounts approaching the "Inoperative" danger zone, the workflow shifts to security. The system prompts a "Liveness Check" via the banking app (FaceID or OTP). If the customer verifies, the timer resets. If they fail or don't respond, the account is auto-segmented into a "High-Risk/Freeze" bucket before a mule ring can attack.
The new 2026 norms require an audit trail of intent. Regulators will look for the "Decision Log": Why was Account X kept open despite a zero balance? Who authorized the reactivation of Account Y after 3 years? If your answer relies on manual email approvals, you are non-compliant. You need an orchestration layer that logs the re-KYC trigger, the customer's digital consent, and the system's automated validation in a single, immutable timeline.
A crucial distinction in the Jan 26 rules: Zero Balance is a balance status — you cannot close an account solely for this without notice. Inoperative is a transaction status (24 months of silence). A zero-balance account receiving a government DBT (Direct Benefit Transfer) is active. Closing it triggers immediate grievance redressal penalties. Your system must distinguish an "Empty Wallet" from a "Ghost User."
The "Sleepy" account is no longer harmless. It is a dormant liability waiting to be weaponized. Convert your "Inactive" list into two clean piles: Recovered Customers and Safely Closed Files. Contact us at sales@simple.works.