Banks email statements as password-protected PDFs, and the password is not a secret — the covering email states the format. To get the rows into Excel or Tally you never have to strip it. Type it once at upload and the statement is read as it was sent.
Uploading the statement to a free online "PDF password remover"
Type the password at upload instead. The statement never goes to a site you know nothing about.
Guessing the password until the file stops accepting attempts
The covering email states the format. Read it before the third try.
Asking the client for an unlocked copy and waiting three days
Ask for the password format instead. That is one reply, not a new file.
Printing the statement and scanning it back in to lose the password
Scanning adds misreads on every page. The locked PDF is read directly.
Leaving an unlocked copy of a client statement on a shared drive
You never have to make one.
Typing the whole statement in by hand because the file will not open
It opens with the password, and every row comes out checked against the balance.
Three steps, and most people do not know they can skip the third one.
Open the email the statement arrived in. Every Indian bank states the password format in the covering note, usually right under the attachment. If you downloaded it from net banking, the download page says it there instead. Treat that as the authority rather than a formula found online: the same bank uses different rules for savings accounts, current accounts and credit cards, and those rules change.
Several formats are case-sensitive and several are lowercase, so copy the shape of it precisely. On a joint account it is the first holder's details, not yours. If two attempts fail, stop and re-read the email rather than guessing again.
An unlocked copy is not needed to get the data out. Drag the locked PDF in, type the password once, and the statement is read as sent. You get a clean Excel file, or entries ready to post into Tally, without ever creating an unprotected copy of a client's bank statement or handing it to a password-removal site.
The HDFC and ICICI formats below are confirmed against the help pages of those two banks. The rest are the formats commonly reported for each bank, so treat them as a starting point rather than the authority. Your covering email is the authority: rules differ between savings, current and credit card statements at the same bank, a joint account uses the details of the first holder, and banks change them.
| Bank | Password format the bank states |
|---|---|
| HDFC Bank | Your Customer ID. HDFC states it on the statement download page and in the covering email. |
| ICICI Bank | Eight characters: the first four letters of the account title, then date and month of birth as ddmm. Lowercase. Current accounts use the date of incorporation. |
| State Bank of India | Commonly reported as the account number, or the first four letters of your name with date and month of birth. Varies by statement type — the covering email says which. |
| Axis Bank | Commonly reported as the first four letters of your name, then date and month of birth as ddmm. Check the covering email. |
| Kotak Mahindra Bank | Commonly reported as your CRN, the Customer Relationship Number. Check the covering email. |
| Credit card statements | Almost always a different rule from the same bank's account statement. Read the card statement email on its own. |
| Any other bank | The covering email states it. If it does not, net banking or the branch will confirm the format. |
Whichever format yours uses, you do not have to remove it. Upload the locked statement and type the password once.
Because it was emailed. A statement carries your account number, your balance and every transaction on it, so the bank locks the PDF with something only the account holder knows rather than trusting the inbox it lands in. Statements pulled straight from net banking are often unlocked, because you were already signed in to get them.
Read the email the statement arrived in. Every Indian bank prints the format in the covering note, and net banking states it on the download page. That is the reliable answer, because the rule differs between savings, current and credit card statements at the same bank.
HDFC uses your Customer ID, and states this on the account statement download page and in the covering email. Credit card statements follow a different rule. If you do not know your Customer ID, it is on your welcome kit, your passbook and your net banking dashboard.
ICICI states an eight-character password: the first four letters of the account title followed by date and month of birth as ddmm. A current account uses the date of incorporation instead. It is case-sensitive and lowercase.
No. Upload the locked PDF and type the password at upload. The statement is read as sent, so you never create an unprotected copy of it and never have to put a bank statement through a password-removal website.
Think hard before you do. A bank statement is among the most sensitive documents you hold, and those sites take a full copy of it onto a server you know nothing about. If all you want is the data out of it, you do not need one at all.
Ask whoever the statement belongs to for the format, not for an unlocked file. If the account is yours, sign in to net banking and download a fresh copy, or call the bank. Nobody outside the bank can open a locked statement without the password, and that is exactly the point of it.
Yes. Type the password at upload, review the entries, and they post into Tally through Tally Connector as receipt, payment and contra vouchers. There is no unlocked file and no Tally XML file anywhere in between.
Yes. The password is handled first, then the pages are read even though they are images rather than text. Scans are the format most likely to be misread, so every row is still checked against the statement's running balance before you get the file.