Cyber Crime • AEPS • Aadhaar • Biometric Fraud • Micro-ATM Evidence
AEPS / Aadhaar Biometric Fraud: Money Withdrawn Without My Consent — How Can I Prove I Never Made the Withdrawal?
“Fingerprint se paise nikal gaye” is not properly investigated by asking only whether Aadhaar authentication returned “success”. A disputed AePS withdrawal has an Aadhaar-authentication trail, a banking transaction trail, a Business Correspondent and terminal trail, and a physical cash-delivery trail. Those layers can be compared to determine whether the customer was actually present, consented to the authentication and received the cash.
Current legal and technical review: 20 August 2026
Direct Answer
If an AePS cash withdrawal appears in your bank account and you say you never made it, collect evidence from four independent systems:
- UIDAI: authentication modality, date/time, AUA name, AUA Transaction ID, UIDAI Response Code and success/failure;
- Issuer / acquiring banks and NPCI: RRN, transaction type, acquiring bank and switch data;
- BC / CSP / micro-ATM: operator, terminal ID, device ID, recorded outlet location, terminal logs and receipt;
- physical evidence: CCTV, cash-disbursement records and evidence showing where you actually were.
A successful Aadhaar biometric response proves an important authentication event. It does not automatically prove that you were physically present at the Business Correspondent outlet, voluntarily consented to a ₹10,000 cash withdrawal or actually received ₹10,000 in cash.
AUTHENTICATION SUCCESS
≠
AUTOMATIC PROOF OF PRESENCE
BANK DEBIT
≠
AUTOMATIC PROOF OF CASH DELIVERY
Immediately dispute the withdrawal with the bank, report live financial fraud through 1930/NCRP where appropriate, preserve all records and lock Aadhaar biometrics to prevent further biometric authentication while the dispute is investigated.
Quick Navigation
- How AePS cash withdrawal works
- Aadhaar number vs actual biometric authentication
- UIDAI Authentication History
- AUA Transaction ID and Response Code
- Consent records
- BC/CSP terminal and location evidence
- Device ID, STAN and RRN
- How to prove cash was never received
- CCTV and location alibi
- Biometric Lock
- RBI's 2026 AePS operator controls
- NPCI AePS fraud-liability process
- Fraud vs failed cash withdrawal
- How to frame the bank complaint
- UIDAI/AUA complaint strategy
- Police and cybercrime evidence
- Master evidence matrix
- Frequently asked questions
How Does an AePS Cash Withdrawal Work?
AePS is a bank-led interoperable payment system that allows eligible banking transactions at AePS touchpoints such as Business Correspondent or Customer Service Point locations.
A conventional cash-withdrawal flow can involve:
AADHAAR / VID → BANK → TRANSACTION TYPE → AMOUNT → BIOMETRIC OR OTHER PERMITTED AUTHENTICATION → BANK DEBIT → BC CASH DELIVERY.
The last step matters.
Even if the electronic transaction is recorded as successful, a cash-withdrawal dispute must separately ask whether cash was actually handed to the customer.
Aadhaar Number Knowledge Is Not Biometric Authentication
Fraud victims sometimes conclude:
“Somebody knew my Aadhaar number, so they withdrew my money.”
That is incomplete.
Aadhaar number is one input into the AePS transaction. A compliant biometric transaction also involves an authentication event using biometric data through the Aadhaar authentication ecosystem.
Knowledge of an Aadhaar number alone should not be treated as proof that the holder's biometric was genuinely and consensually authenticated.
2026 nuance
Current RBI AePS directions define the system broadly enough to include biometric or OTP authentication.
Therefore never write:
“EVERY AEPS WITHDRAWAL IS A FINGERPRINT TRANSACTION.”
First obtain the authentication modality.
UIDAI Authentication History: The First Aadhaar-Side Evidence
UIDAI Authentication History provides important information concerning recent Aadhaar authentication events.
| UIDAI Field | Why It Matters |
|---|---|
| Authentication Modality | Was it biometric, OTP or another mode? |
| Date & Time | Can it be matched to the bank withdrawal? |
| AUA Name | Which Authentication User Agency generated the request? |
| AUA Transaction ID | Identifier for further enquiry with the AUA. |
| UIDAI Response Code | Identifier useful for tracing the authentication response. |
| Success / Failure | Was authentication accepted? |
| Error Code | If failed, what was the reason? |
Match the time precisely
Bank statement:
₹10,000 AEPS CASH WITHDRAWAL — 14:36.
UIDAI history:
BIOMETRIC AUTHENTICATION — 14:35:48.
That temporal proximity becomes a strong lead for correlation.
What if no matching biometric entry appears?
Do not immediately conclude that the bank record is fabricated.
Check:
- exact transaction time;
- authentication modality;
- date/time-zone issues;
- whether another permitted authentication method was used;
- whether the transaction is older than the consumer-history display period.
AUA Transaction ID and UIDAI Response Code: Your Authentication Join Keys
For every authentication event, the AUA generates its transaction identifier, while UIDAI generates a response code.
Preserve:
AUTHENTICATION TIME
AUA NAME
AUA TXN ID
UIDAI RESPONSE CODE.
Then require the relevant AUA/bank to correlate that authentication with the financial AePS transaction.
The goal is:
AADHAAR AUTHENTICATION ↔ AEPS RRN ↔ BC TERMINAL ↔ CASH WITHDRAWAL.
Where Is the Evidence of Customer Consent?
The Aadhaar framework requires requesting entities to obtain consent for authentication in accordance with applicable law.
Authentication logs maintained by the requesting entity include the record of disclosed purpose and consent.
Therefore a disputed transaction should not be analysed only as:
“BIOMETRIC MATCHED.”
Ask:
- What purpose was displayed or disclosed?
- How was consent captured?
- What exact transaction was the resident supposedly consenting to?
- Which system record preserves that consent?
The BC/CSP Terminal Can Identify Where the Transaction Originated
NPCI requires AePS online transactions to carry BC/CSP-related information including a unique terminal identifier and outlet-location information.
A bank fraud investigation should identify:
Example
Customer lives and was working in Patna.
Disputed AePS transaction originated from a BC terminal recorded in another district or State.
That does not alone prove fraud, but it becomes powerful when combined with:
- customer's independent location evidence;
- CCTV at the BC;
- terminal logs;
- other complaints against the same BC.
Device ID + STAN + RRN: Do Not Accept a Vague “Biometric Successful” Reply
Micro-ATM standards use transaction/device identifiers for traceability and dispute resolution.
RRN
+
STAN
+
TERMINAL ID
+
DEVICE ID
=
THE TECHNICAL ORIGIN TRAIL
A serious written complaint should request preservation of all four.
If the bank says that a device successfully authenticated the customer's fingerprint, the next question is:
WHICH DEVICE?
UIDAI's Registered Device architecture is specifically designed to improve device traceability and prevent replay of stored biometric data.
The Hard Question: Who Actually Received the Cash?
AePS cash withdrawal is unlike an ordinary account-to-account transfer.
The electronic debit must eventually correspond to physical cash delivery.
Demand the cash-delivery evidence
Depending on the transaction and dispute process, relevant records can include:
- micro-ATM terminal logs;
- transaction receipt;
- AePS/FI switch logs;
- BC confirmation;
- BC cash register/float records;
- end-of-day reconciliation;
- acquirer settlement records;
- CCTV;
- records of transactions immediately before and after the disputed transaction.
The four-way reconciliation
BANK: ₹10,000 debited.
AEPS: transaction successful.
BC: claims ₹10,000 delivered.
CUSTOMER: denies presence and receipt.
The dispute is not resolved until the fourth proposition is tested against independent evidence.
CCTV + Customer Location Can Be the Strongest Non-Biometric Evidence
Suppose the transaction record identifies:
BC OUTLET:
GAYA
11:14 AM.
But at exactly that time the customer appears on:
OFFICE CCTV:
PATNA
11:00–12:00.
That contradiction materially strengthens the dispute.
Preserve CCTV immediately
Do not wait for the bank's final complaint rejection because many DVR systems overwrite older footage.
Preserve:
- full relevant time window;
- original/source export where possible;
- camera/channel identity;
- DVR/NVR details;
- system time offset;
- hash/certificate where used in proceedings.
Current electronic-record evidence should be handled under the Bharatiya Sakshya Adhiniyam, including Sections 61-63.
Lock Aadhaar Biometrics After Suspected AEPS Fraud
UIDAI allows the Aadhaar holder to lock fingerprint, iris and face biometric authentication.
When biometrics are locked, biometric Aadhaar authentication cannot be performed until the permitted unlocking process is used.
Why lock immediately?
It can prevent:
A SECOND BIOMETRIC AUTHENTICATION WHILE THE FIRST FRAUD IS BEING INVESTIGATED.
What biometric lock does not do
It does not:
- reverse the earlier bank debit;
- identify the offender;
- prove how the earlier authentication occurred;
- automatically refund the customer.
Was it already locked?
If reliable contemporaneous evidence shows that biometric lock was active before the alleged fingerprint authentication, preserve that evidence immediately and specifically plead the contradiction.
RBI's 2026 AePS Operator Controls Make the Acquiring Bank's Records More Important
RBI's final AePS Touchpoint Operator Directions have applied since 1 January 2026.
The acquiring bank must conduct due diligence before onboarding an operator and must monitor the operator's transactions on an ongoing basis.
RBI specifically requires the fraud-risk framework to consider factors such as:
- location;
- operator type;
- volume;
- velocity.
Practical litigation questions
Ask the acquiring bank:
- When was this operator onboarded?
- When was KYC last updated?
- Was the operator inactive for more than three months before reactivation?
- What transaction limits/risk parameters applied?
- Was there unusual volume or velocity?
- Were previous fraud complaints linked to this operator or terminal?
- When was the terminal blocked?
NPCI's Published AePS Fraud-Liability Process
NPCI has a specific published fraud-liability framework for qualifying AePS financial transactions involving BCs/CSPs.
For qualifying off-us fraud reports
The published framework contemplates:
- fraud reporting by the issuer bank;
- successful/settled transaction as the relevant fraud category;
- issuer-bank investigation material;
- acquiring-bank investigation into the BC/CSP;
- supporting transaction logs;
- specific response time frames;
- liability consequences where the acquirer fails to respond properly;
- action where repeated fraud is associated with the same BC/CSP.
Published timelines
The published guideline provides:
CUSTOMER REPORTS TO ISSUER ↓ ISSUER REPORTS QUALIFYING FRAUD WITHIN 5 WORKING DAYS.
ACQUIRER RECEIVES FRAUD INTIMATION ↓ ACQUIRER INVESTIGATION REPORT WITHIN 10 WORKING DAYS.
The guideline also contains a 90-calendar-day transaction-date criterion for the inter-member fraud-reporting process.
Fraud vs “Cash Not Received” Failed Transaction
| Situation | Correct Focus |
|---|---|
| Customer was present; transaction failed; account debited; no cash | Failed-transaction reversal / credit adjustment / dispute. |
| Customer was absent; successful AePS debit appears | Unauthorised/fraud investigation. |
| Customer asked for ₹2,000 but ₹10,000 processed | BC conduct, consent, transaction logs, cash delivered. |
| Repeated debits from same BC | Terminal/operator pattern investigation. |
| Authentication history shows OTP rather than biometric | Do not pursue the case solely as “fingerprint cloning”. |
NPCI's operating framework separately prescribes reversal/credit-adjustment treatment for genuine transaction failures at the acquirer/BC side.
That process is different from a successful fraudulent transaction.
How Should the Bank Complaint Be Framed?
Do not write only:
“Fingerprint se paisa nikal gaya, please refund.”
A stronger factual complaint states:
Attach immediately
- bank statement;
- SMS alert;
- UIDAI Authentication History screenshot/download;
- AUA Transaction ID;
- UIDAI Response Code;
- proof of your location where available;
- 1930/NCRP acknowledgement;
- police complaint if filed.
Do not speculate unnecessarily
Instead of:
“My fingerprint was definitely cloned.”
prefer:
“I did not provide biometric authentication or consent and was not present; please identify how the recorded authentication was generated.”
UIDAI / AUA Remedy: Investigate the Authentication Separately From the Bank Debit
If UIDAI history contains an authentication you do not recognise, UIDAI's own FAQ directs the Aadhaar holder to contact the relevant Authentication User Agency for details.
Request correlation
Provide:
- date/time;
- modality;
- AUA name;
- AUA Transaction ID;
- UIDAI Response Code;
- bank AePS transaction details.
Ask for the legally available authentication logs, including the record of the purpose disclosed and consent.
UIDAI grievance
UIDAI maintains multiple grievance channels and its Aadhaar contact centre is available through 1947.
The UIDAI grievance does not replace the bank complaint or police complaint.
They address different evidence systems.
Police / Cybercrime Investigation: What Should Be Collected?
Account statement, exact debit, RRN and issuer records.
AUA ID, Response Code, modality, time and applicable backend logs.
Acquiring bank and AePS transaction records.
ATO / BC / CSP KYC, onboarding and risk-monitoring records.
Terminal ID, device identifier, STAN and outlet location.
Receipt, terminal log, cash register, reconciliation and BC float.
BC and nearby CCTV.
Independent evidence showing where the customer actually was.
Other customers, adjacent transactions and prior complaints against same BC/terminal.
Current criminal law
Depending upon the facts, post-1 July 2024 offences may require examination under the Bharatiya Nyaya Sanhita, including cheating under Section 318 and personation under Section 319 where its ingredients exist.
Information Technology Act provisions such as identity theft under Section 66C or cheating by personation through a computer resource under Section 66D may also require examination depending upon the actual mechanism.
Do not mechanically apply every cyber provision to every AePS debit.
Master AEPS Biometric Fraud Evidence Matrix
| Evidence Question | Record |
|---|---|
| Disputed amount | ___ |
| Bank debit date/time | ___ |
| Transaction marked AePS Cash Withdrawal? | ___ |
| RRN | ___ |
| STAN | ___ |
| Issuer bank | ___ |
| Acquiring bank | ___ |
| Authentication modality | Fingerprint / Iris / Face / OTP / Other |
| UIDAI auth date/time | ___ |
| AUA name | ___ |
| AUA Transaction ID | ___ |
| UIDAI Response Code | ___ |
| Authentication result | ___ |
| Consent record obtained? | ___ |
| BC/CSP/ATO name | ___ |
| BC outlet address | ___ |
| City / State / PIN | ___ |
| Terminal ID | ___ |
| Device ID | ___ |
| Terminal receipt | ___ |
| Micro-ATM terminal logs | ___ |
| Switch logs | ___ |
| Preceding/succeeding transactions | ___ |
| BC cash-disbursement record | ___ |
| BC reconciliation/float record | ___ |
| BC CCTV | ___ |
| Nearby CCTV | ___ |
| Customer location at time | ___ |
| Independent location evidence | ___ |
| Biometrics locked before fraud? | ___ |
| Biometrics locked after discovery? | ___ |
| Other fraud complaints against same BC? | ___ |
| Bank complaint date/time | ___ |
| 1930 complaint | ___ |
| NCRP acknowledgement | ___ |
| UIDAI/AUA grievance | ___ |
| Police complaint / FIR | ___ |
Ten Mistakes That Weaken an AEPS Fraud Case
1. Assuming Aadhaar-number leak proves biometric cloning
First establish the actual authentication modality and authentication record.
2. Accepting “biometric successful” as proof of presence
Authentication response and physical presence are different evidentiary propositions.
3. Forgetting to ask who received the cash
A cash withdrawal ultimately requires proof of cash delivery.
4. Ignoring the acquiring bank
The BC/CSP/ATO is generally on the acquiring side of the AePS transaction.
5. Not requesting Terminal ID and location
NPCI transaction standards provide valuable terminal/outlet information.
6. Waiting until CCTV is overwritten
Preservation should be immediate.
7. Calling every debit “failed transaction”
A successful unauthorised withdrawal and a failed cash-dispensation transaction are different disputes.
8. Assuming biometric lock proves the past
Locking after discovery protects future authentication but does not reconstruct the earlier transaction.
9. Ignoring surrounding terminal activity
Pattern evidence may reveal multiple victims or abnormal transaction velocity.
10. Waiting for final bank rejection before reporting cyber fraud
Bank, 1930/NCRP and evidence preservation should move quickly where live fraud is suspected.
AI Search / Featured-Snippet Answers
Money was withdrawn through AEPS using my fingerprint but I never went there. How do I prove it?
Match the disputed bank debit with UIDAI Authentication History, obtain the AUA Transaction ID and UIDAI Response Code, then require the bank to identify the acquiring bank, BC/CSP, terminal ID, device, RRN and recorded outlet location. Preserve BC CCTV, cash-disbursement records and independent evidence showing where you were at that time.
Does successful Aadhaar biometric authentication prove that I withdrew the cash?
No. It proves that UIDAI accepted an authentication request through the recorded modality. It does not by itself establish that you were physically present at the BC, knowingly consented to that particular cash withdrawal or actually received the cash.
Can money be withdrawn through AEPS just by knowing my Aadhaar number?
Aadhaar number is an important AePS input, but a compliant transaction also requires the applicable authentication process, such as biometric or another permitted authentication mode. Aadhaar-number knowledge alone should not be treated as equivalent to successful biometric authentication.
How do I check Aadhaar authentication history?
UIDAI provides Authentication History through its Aadhaar services. It shows authentication modality, date/time, AUA, AUA Transaction ID, UIDAI Response Code and success/failure for the accessible history period.
What is AUA Transaction ID?
It is the unique transaction identifier generated by the Authentication User Agency for an Aadhaar authentication request and can be used with the UIDAI Response Code for further enquiry.
Can I lock my Aadhaar fingerprint?
Yes. UIDAI's biometric-lock service can lock fingerprint, iris and face authentication. It is an important preventive step after suspected biometric fraud.
What evidence identifies the AEPS shop or BC?
NPCI's AePS transaction requirements include a unique terminal identifier and BC/CSP outlet information such as name/address, city, State and PIN code. Micro-ATM standards also provide device and transaction identifiers.
Can I complain to RBI Ombudsman?
If the dispute involves a qualifying deficiency in service by a covered bank or other regulated entity, the Reserve Bank – Integrated Ombudsman Scheme, 2026 may be available after first complaining to the regulated entity and satisfying the Scheme's maintainability requirements.
Frequently Asked Questions
What is AePS?Aadhaar Enabled Payment System is a bank-led interoperable payment system through which banking transactions such as cash withdrawal can be performed at authorised touchpoints using Aadhaar-enabled authentication.
Is every AePS transaction fingerprint-based?No. Current RBI directions recognise AePS authentication using biometrics or OTP. Check the actual modality in the authentication record.
Can I see the exact Aadhaar authentication time?UIDAI Authentication History provides date and time along with the authentication modality and other transaction identifiers.
How far back can I see online?UIDAI presently describes the consumer authentication-history service as providing records for the last six months, up to 50 at one instance. Older backend logs may still exist under the requesting entity's retention obligations.
What if the disputed transaction is eight months old?Do not conclude that evidence no longer exists merely because it has left the six-month consumer view. Request the relevant AUA/requesting-entity records, bank records and AePS transaction logs.
What if Authentication History shows “Success”?Investigate which modality, AUA and transaction generated the success and correlate it with the BC terminal and financial transaction. “Success” does not independently prove physical presence or cash delivery.
Can a BC store my fingerprint?UIDAI's security framework prohibits permanent storage of biometric and OTP data captured for Aadhaar authentication, and Registered Devices are designed to prevent replay of stored biometrics.
What is an L1 biometric device?UIDAI describes L1 Registered Devices as stronger-security devices using secure hardware, on-device encryption and enhanced liveness/anti-spoofing protections.
What is Fake Finger Detection?UIDAI states that Fake Finger Detection has been strengthened in L1 fingerprint devices to reduce spoofing and reject artificial/fake fingerprint captures at the device level.
Does this mean fingerprint fraud is impossible?No such conclusion should be drawn. Investigate the actual authentication, operator, device, consent and cash-disbursement trail instead of assuming either that spoofing certainly happened or that system authentication makes fraud impossible.
Can I identify the BC location?Yes. NPCI requires specified BC/CSP outlet identity and location details to be carried in AePS online transactions, which can be sought through the bank investigation.
What is RRN?The Retrieval Reference Number is an important transaction reference used for tracing and dispute resolution.
Why ask for STAN and Device ID?Micro-ATM standards use transaction/device identifiers for traceability and dispute resolution.
Should the BC have given a receipt?NPCI's procedural guidelines contemplate a transaction receipt with finality status for AePS transactions through the BC/merchant.
What if the bank says the BC confirms cash was paid?Ask for the underlying terminal logs, receipt, CCTV, cash-disbursement/reconciliation records and other supporting evidence rather than treating a bare BC statement as the only evidence.
Should I lock my biometrics?Yes, if you suspect misuse, biometric locking is an important preventive measure while the transaction is investigated.
Will biometric lock refund the money?No. It is a future-security control, not a refund mechanism.
What if my biometrics were already locked?Preserve reliable proof of the lock status and timing. A claimed successful biometric authentication during a proven lock period requires careful technical investigation.
Should I report to 1930?For suspected live financial cyber fraud, prompt reporting through the bank and 1930/NCRP can help trigger financial-fraud coordination while other Aadhaar and police remedies proceed.
Is there an NPCI AePS fraud process?NPCI has published a specific fraud-liability framework for qualifying AePS transactions involving issuer/acquirer banks and BC/CSP investigation.
Can I approach RBI Ombudsman?Potentially, if there is a maintainable deficiency-in-service complaint against a covered regulated entity after first approaching that entity.
Can the bank simply reject because biometric matched?A biometric success is important evidence, but the complaint can still require investigation of consent, operator, terminal, location, cash delivery and the customer's claim of non-presence. RBI's unauthorised-transaction framework places the burden of proving customer liability on the bank where that framework applies.
What is the strongest evidence that I never made the withdrawal?A combined contradiction: the AePS record identifies a specific BC terminal/location while independent contemporaneous evidence shows you were somewhere else, reinforced by CCTV, terminal logs and absence of credible evidence that cash was delivered to you.
Official Legal and Technical Sources
- Unique Identification Authority of India — Aadhaar Authentication History
- UIDAI — Aadhaar Biometric Lock / Unlock
- UIDAI — Aadhaar Registered Biometric Devices
- UIDAI — Aadhaar Authentication and Offline Verification Regulations
- National Payments Corporation of India — Aadhaar Enabled Payment System
- NPCI — AePS Procedural and Operating/Settlement Guidelines
- NPCI — BC Agent/CSP Details in AePS Online Transactions
- NPCI — AePS Fraud Liability Guidelines
- Reserve Bank of India — AePS Touchpoint Operator Due Diligence Directions, effective 1 January 2026
- Reserve Bank of India — Customer Protection for Unauthorised Electronic Banking Transactions
- Reserve Bank – Integrated Ombudsman Scheme, 2026
- India Code — Bharatiya Nyaya Sanhita, 2023
- India Code — Bharatiya Nagarik Suraksha Sanhita, 2023
- India Code — Bharatiya Sakshya Adhiniyam, 2023
- India Code — Information Technology Act, 2000
Related Detailed Research
For payment fraud involving a physically replaced merchant QR, see the separate Merchant QR Replacement analysis.
For a scam in which the victim was told to scan a QR or approve a request to receive a refund but instead authorised a debit, see the separate UPI Receive-Money / Refund Trick analysis.
For cases that later generate larger financial-crime proceedings, also review the dedicated cyber-fraud-to-ED/PMLA analysis.
Professional Consultation for AEPS, Aadhaar Biometric and Cyber-Financial Fraud Matters
Advocate Ankit Kumar Singh
Supreme Court of India | Patna High Court | Allahabad High Court at Prayagraj | Jharkhand High Court at Ranchi | Calcutta High Court | Delhi High Court and Delhi Courts/Tribunals | Matters concerning Bhopal, Madhya Pradesh | Multiple District Courts
Depending upon the facts, jurisdiction and accepted professional engagement, professional work may include:
- AePS biometric-withdrawal disputes;
- bank fraud representations;
- UIDAI/AUA authentication analysis;
- RRN, terminal and BC/CSP evidence reconstruction;
- 1930/NCRP complaint follow-up;
- police/cyber-police complaints;
- micro-ATM and CCTV evidence preservation;
- RBI Ombudsman strategy;
- consumer and civil recovery analysis;
- BNS / IT Act offence analysis;
- parallel financial-crime proceedings where legally applicable.
Phone: 8294431232
Email: ankitsingh.legum@gmail.com
Website: advocateankitkumarsingh.in
Subject to accepted professional engagement, territorial jurisdiction, applicable procedure and local-counsel coordination where required.
Add AdvocateAnkitKumarSingh.in as a Google Preferred Source
For detailed research concerning cyber fraud, AePS, Aadhaar-linked financial disputes, UPI fraud, digital evidence and PMLA, readers may add advocateankitkumarsingh.in as a Preferred Source on Google.
Legal and Technical Disclaimer: This article provides general legal and technical research and does not determine whether any particular AePS withdrawal was fraudulent. A successful Aadhaar authentication response does not, without more, establish the precise circumstances in which biometric or OTP authentication occurred, nor does it by itself prove customer presence, informed consent or physical delivery of cash. Conversely, a customer's denial does not by itself prove a biometric-system compromise. Each case should be reconstructed using UIDAI authentication records, bank/NPCI transaction data, acquiring-bank and BC/CSP records, terminal/device identifiers, receipt and cash-disbursement records, CCTV and other independent evidence. RBI/NPCI liability and dispute rules should be applied to the correct transaction category and current version. No refund, freezing, conviction or regulatory outcome is guaranteed.
