Last Updated on: 12th August 2026 | Last Reviewed on: 12th August 2026
Key Takeaways
- KYC is the identity layer of a wider anti-money laundering programme. It answers one question: is this customer who they say they are?
- The obligation comes from the Prevention of Money-Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005. Your sector regulator then sets the mechanics.
- It applies to every ‘reporting entity’: banks, financial institutions, intermediaries, and designated non-financial businesses and professions.
- There are six Officially Valid Documents. A utility bill or tax receipt is only a stop-gap for proof of address, and only for three months.
- KYC is not a one-time event. It must be refreshed at least once every 2 years for high-risk, 8 years for medium-risk and 10 years for low-risk customers.
Quick Answer: What KYC Means in India
KYC, or Know Your Customer, is the process a regulated business in India uses to establish and verify who its customer is, before and throughout the business relationship. It is mandatory under the Prevention of Money-Laundering Act, 2002 and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, and it is enforced sector by sector by the RBI, SEBI, IRDAI, PFRDA, IFSCA and FIU-IND.
KYC Meaning and Full Form: Know Your Customer Explained
The KYC full form is Know Your Customer. The KYC definition in regulation is the set of checks a regulated business must carry out to satisfy itself of a customer’s identity. In everyday use, doing your KYC means submitting an identity document and an address document. In regulation, it means more: identify the customer, verify that identity from reliable and independent sources, understand why they want the relationship, and keep watching it for as long as it lasts. “Know your client” is the same thing; securities and pensions prefer “client”; banking prefers “customer”.
What "Know Your Customer" Actually Requires a Business to Do
Four obligations sit inside the phrase.
- Identification: collect the customer’s identity details.
- Verification: check them against a reliable and independent source, the standard the PML Rules set for client due diligence.
- Purpose: understand the nature of the relationship sought.
- Ongoing monitoring: keep the information current and keep watching the transactions. Miss any one, and you have collected documents without doing KYC. Most supervisory findings in India are failures of the third and fourth limbs, not the first.
KYC vs Customer Due Diligence vs AML: How the Three Fit Together
These three terms are used loosely in vendor marketing, and the confusion causes real compliance gaps. They are nested, not synonymous.
Layer | What it covers | Where it comes from |
KYC | The identity layer. Who is this customer, and can I prove it from an independent source? | PML Rules, 2005 read with your regulator’s KYC directions |
Customer Due Diligence (CDD) | The risk layer. Having identified the customer, what is their risk rating, who is the beneficial owner, and how much scrutiny does this relationship need? | PMLA sections 11A and 12AA; Rule 9 of the PML Rules |
AML / CFT programme | The whole control environment. Policy, governance, risk assessment, screening, monitoring, reporting, record-keeping, training and audit. | PMLA Chapter IV, the PML Rules, and sectoral master directions and guidelines |
So KYC sits inside CDD, and CDD sits inside the AML programme. A business can have perfect KYC files and still fail an AML inspection.
Why KYC Exists: The Problem It Is Designed to Solve
Money laundering depends on anonymity. If value moves through the financial system without a verified name attached to it, tracing and confiscation become almost impossible. KYC removes that anonymity at the point of entry, which is why every international standard treats customer due diligence as foundational. The global standard-setter is the Financial Action Task Force, established in 1989 by the ministers of its member jurisdictions; India’s framework was assessed against those standards in the FATF mutual evaluation of India published in September 2024.
Is KYC Mandatory in India? The Law Behind It
Yes. KYC in India is a statutory obligation, not a banking convention or a matter of internal policy. Without it, an institution cannot lawfully open or continue the relationship.
The Prevention of Money-Laundering Act, 2002 and the PML Rules, 2005
The Act creates the obligation; the Rules set the mechanics. Chapter IV of the PMLA carries the operative duties: section 11A on verification of identity by a reporting entity, section 12 on maintaining records of prescribed transactions and of client identity, section 12A on the Director of FIU-IND’s power to call for information, and section 12AA on enhanced due diligence before certain transactions. Under the Act, the PML (Maintenance of Records) Rules, 2005 do the detailed work: Rule 3 lists the transactions to be recorded and reported, Rule 7 sets the procedure for furnishing information and requires the Principal Officer’s details to be communicated to the Director, and Rule 9 governs client due diligence and the upload of KYC records to the Central KYC Records Registry.
Who Counts as a "Reporting Entity" Under PMLA
Section 2(1)(wa) of the PMLA defines a reporting entity as a banking company, financial institution, intermediary, or a person carrying on a designated business or profession. That last category is the one businesses underestimate: it brings in real estate agents, dealers in precious metals and stones, trust and company service providers, practising chartered accountants, company secretaries and cost accountants performing specified activities, and virtual digital asset service providers. There is no size exemption, and the obligations bite personally through your Designated Director and Principal Officer.
Which Regulator's KYC Rules Apply to You
This is the most common source of error in Indian KYC content. The PMLA is common to everyone; the operating instrument is not.
Entity type | Regulator | Current governing instrument |
RBI | Reserve Bank of India (Commercial Banks – Know Your Customer) Directions, 2025: RBI/DOR/2025-26/169, DOR.AML.REC.No.88/14.01.002/2025-26, dated 28 November 2025, updated as on 29 December 2025 | |
NBFCs | RBI | Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Directions, 2025: RBI/DOR/2025-26/361, DOR.AML.REC.No.280/14.01.003/2025-26, dated 28 November 2025, updated as on 29 December 2025 |
Securities market intermediaries | SEBI | Master Circular SEBI/HO/MIRSD/MIRSDSECFATF/P/CIR/2024/78 dated 6 June 2024 (AML/CFT obligations), read with the Master Circular on KYC Norms for the Securities Market, SEBI/HO/MIRSD/SECFATF/P/CIR/2023/169 dated 12 October 2023 |
Insurers | IRDAI | Master Guidelines on AML/CFT, 2022: Ref. IRDAI/IID/GDL/MISC/160/8/2022 dated 1 August 2022, in force from 1 November 2022, as amended |
Pension sector (PoPs, NPS Trust) | PFRDA | Master Circular PFRDA/Master Circular/2024/04/PoP-02, updated as on 25 September 2025 |
IFSC entities (GIFT City) | IFSCA | IFSCA AML, CTF and KYC Guidelines, 2022, updated as on 26 February 2026 |
Virtual digital asset service providers | Director, FIU-IND | Designated by Ministry of Finance notification S.O. 4877(E) dated 9 November 2023; AML/CFT Guidelines for reporting entities providing services related to virtual digital assets, updated 8 January 2026 |
What Changed on 28 November 2025 and Why Older Articles Are Now Wrong
On 28 November 2025, the Reserve Bank reorganised the instructions administered by its Department of Regulation. Instructions in approximately 3,500 directions, circulars and guidelines were consolidated into 238 function-wise Master Directions across 11 types of regulated entities. Counting seven new Master Directions on Digital Banking Channels Authorisation issued the same day, 244 documents were released, alongside a list of 9,445 circulars being repealed or withdrawn. The RBI stated that these Master Directions will serve as the sole library of regulations administered by the Department of Regulation. (RBI Press Release 2025-2026/1588, 28 November 2025.)
The consequence for KYC is specific: the single, all-entity Master Direction – Know Your Customer Direction, 2016 no longer applies. It was withdrawn and replaced by entity-specific 2025 KYC Directions. Any article, internal policy, training deck or audit checklist that still cites the 2016 Master Direction is citing a withdrawn instrument. If you maintain a compliance manual, this is the paragraph to act on.
Types of KYC in India
There is no single KYC verification method. Indian regulation permits five broad routes, and which one you may use depends on the customer, the product and the risk. Paragraph references below are to the RBI (Commercial Banks – Know Your Customer) Directions, 2025; other sectors follow comparable structures.
In-Person Verification (Physical KYC)
The traditional route. The customer presents an original Officially Valid Document, an authorised officer compares the copy against the original and records that comparison on the copy, and a photograph is taken. That is what the Directions mean by a “certified copy”. It remains the default for higher-risk relationships and for most legal-entity onboarding.
Aadhaar-Based e-KYC: OTP and Biometric
Authentication under section 11A of the PMLA allows identity to be established electronically. Accounts opened using Aadhaar OTP-based e-KYC in non-face-to-face mode carry conditions: specific customer consent to OTP authentication, and transaction alerts and OTPs sent only to the Aadhaar-registered mobile number, with requests to change that number handled under a Board-approved due diligence process. Because the route carries hard product and value limits, treat it as a constrained channel rather than a general-purpose one.
Digital KYC Process
“Digital KYC” has a precise regulatory meaning in India and is not a synonym for online onboarding. Under paragraph 24, the bank must build an authenticated application, make it available at customer touchpoints, control access through a login-and-password or live-OTP mechanism, and undertake KYC only through that application. Critically, the customer must visit the authorised official or the official must visit the customer, with the original OVD in the customer’s possession at that moment.
Video KYC: The Video-Based Customer Identification Process (V-CIP)
V-CIP is a live, consent-based audio-visual interaction that can substitute for physical presence. Paragraph 26 allows it for due diligence on new individual customers, on the proprietor of a proprietorship firm, and on authorised signatories and beneficial owners of legal entity customers; for converting existing accounts opened through Aadhaar OTP-based e-KYC; and for periodic updation for eligible customers. Paragraph 27 sets the minimum infrastructure, cyber-security, recording and audit-trail standards required before offering it.
Central KYC Records Registry (CKYC) and the KYC Identifier
CKYC is the shared national repository that lets one institution’s verified KYC record be reused by another. The Government of India, by notification dated 26 November 2015, authorised the Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) to act as the Central KYC Records Registry, having amended the PML Rules for that purpose by notification dated 7 July 2015.
The mechanics sit in Rule 9. Under Rule 9(1A), every reporting entity must file the electronic copy of a client’s KYC records with the Registry within ten days of commencing an account-based relationship. The Registry de-duplicates the record and issues a 14-digit KYC Identifier, which must be communicated to the client in writing. Where an identifier already exists, the entity must retrieve the records online rather than re-collect documents. Customers can retrieve their own identifier at ckycindia.in.
Which Type Applies to Which Customer
Customer situation | Usual route | Watch-out |
Resident individual, walk-in, standard product | In-person verification or Digital KYC | Certified-copy comparison must be recorded on the copy |
Resident individual, remote onboarding | V-CIP, or Aadhaar OTP e-KYC | OTP route carries limits; alerts must go only to the Aadhaar-registered mobile |
Existing customer already on CKYCR | Retrieve records via the KYC Identifier | You still owe ongoing due diligence and periodic updation |
Company, partnership, trust, association | In-person or V-CIP of signatories and beneficial owners | Entity documents plus CDD on every natural person behind the entity |
Foreign student opening an NRO account | Passport with visa and immigration endorsement, plus admission letter | Local address declaration within 30 days; capped operations until verified; Pakistani nationality needs prior RBI approval |
Onboarding clients without a documented due-diligence process?
AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.
KYC Documents Required in India
The documents required for KYC fall into two groups. The first group is one of the six Officially Valid Documents. It proves your identity and your address. The second group is PAN or Form 60. PAN sits alongside the OVD and does not replace it. Legal entities must also produce constitution and authorisation documents.
The Six Officially Valid Documents
Paragraph 5(1)(xiv) of the Commercial Banks KYC Directions, 2025 defines an Officially Valid Document exhaustively. There are six:
- Passport
- Driving licence
- Proof of possession of Aadhaar number, which may be submitted in the form issued by the Unique Identification Authority of India
- Voter’s Identity Card issued by the Election Commission of India
- The job card issued by NREGA, duly signed by an officer of the State Government
- The letter issued by the National Population Register containing details of name and address
Nothing else is an OVD. A PAN card, an employee ID, a bank passbook or a ration card is not on this list, however often they are accepted informally.
When a Utility Bill or Tax Receipt Can Be Used as Proof of Address
If a customer’s OVD does not carry their current address, a limited set of documents is deemed to be an OVD for the sole purpose of proof of address: a utility bill not more than two months old from a service provider of electricity, telephone, post-paid mobile, piped gas or water; a property or municipal tax receipt; a pension or family pension payment order issued to a retired employee by a government department or public sector undertaking, if it contains the address; and a letter of allotment of accommodation, or a leave and licence agreement, from a qualifying government department, statutory or regulatory body, public sector undertaking, scheduled commercial bank, financial institution or listed company.
This is a bridge, not a destination. The customer must submit an OVD carrying the current address within three months. Institutions that never close that loop are carrying an open finding.
PAN and the Documents That Sit Alongside an OVD
PAN, or its equivalent e-document, sits alongside the OVD rather than replacing it, and must be quoted where required. For existing customers the Directions require the bank to obtain PAN or Form No. 60 by such date as the Central Government may notify, failing which operations in the account must be temporarily ceased. PAN details on file must also be verified against the issuing authority’s database at periodic updation.
KYC Documents for Companies, Partnerships and Trusts
Legal entities need two things: documents proving the entity exists and is authorised to act, and full customer due diligence on the natural persons behind it. A company file typically requires the certificate of incorporation, the memorandum and articles of association, a board resolution or power of attorney authorising the persons who will operate the account, and OVDs plus PAN for those persons and for the beneficial owners. A partnership requires the registration certificate and partnership deed; a trust, the registration certificate and trust deed; an unincorporated association or body of individuals, the resolution of its managing body and a power of attorney. Sole proprietorships additionally require activity proofs for the firm.
Documents for Foreign Nationals and Non-Resident Customers
For non-resident Indians and persons of Indian origin the Directions relax how a copy may be certified, recognising certification abroad through prescribed channels. Foreign students may open a Non-Resident Ordinary account on a passport bearing proof of identity and address in the home country with visa and immigration endorsement, a photograph, and an admission letter from the Indian institution. A local address declaration must follow within 30 days, and until it is verified the account operates with a cap of USD 1,000 or equivalent on inward foreign remittances and Rs 50,000 on aggregate withdrawals in that period. Students of Pakistani nationality require prior RBI approval.
The KYC Process, Step by Step
The KYC process runs in four stages: acceptance, identification, risk profiling and monitoring. The first three happen at onboarding. The fourth never stops. Each stage feeds the next, so a weak risk rating weakens everything after it.
The Four Stages: Acceptance, Identification, Risk Profiling, Monitoring
Acceptance comes first: the Customer Acceptance Policy decides whether the customer may be onboarded at all, and it must not be applied so as to deny banking services to ordinary members of the public. Identification follows, through one of the permitted routes. Risk profiling then assigns the customer to a low, medium or high-risk category. Monitoring runs for the life of the relationship, aligned in intensity to that category.
One nuance worth flagging: an institution may rely on customer due diligence carried out by a regulated third party for onboarding, or for occasional transactions of Rs 50,000 or more and international money transfers, but only on strict conditions, including immediate access to the records, a supervised third party not based in a high-risk jurisdiction, and ultimate responsibility for CDD staying with the relying institution.
How Risk Categorisation Drives Everything Downstream
Risk categorisation is not an administrative label. It determines how much documentation you collect, whether enhanced due diligence applies, how closely transactions are monitored, and how often KYC must be refreshed. The Directions require categorisation into low, medium and high risk on parameters including the customer’s identity, social and financial status, nature and location of business activity, geographic risk, products and services used, delivery channel and transaction types. The rating and its reasons must be kept confidential and must not be disclosed to the customer, to avoid tipping off.
KYC Rules Every Regulated Entity Must Follow
KYC compliance is more than a document file. The rules below cover governance, beneficial ownership, screening, records and reporting. Each one is a separate obligation, and a supervisor can cite you for any of them on its own.
A Board-Approved KYC Policy and the Four Elements RBI Requires
Every regulated entity must have a KYC policy approved by the Board or a committee to which the Board has delegated the power. It must contain four key elements: a Customer Acceptance Policy, risk management, Customer Identification Procedures, and monitoring of transactions. It must also address periodic updation, any exceptional measures the entity applies, when a copy of an OVD will be required for a change of address, and whether updation will be offered at any branch.
Designated Director and Principal Officer
Two named individuals carry personal accountability. The Designated Director, defined in Rule 2(ba) of the PML Rules, is a Board-nominated person responsible for overall compliance with Chapter IV of the PMLA and the Rules; for a company this is the Managing Director or a duly authorised whole-time Director. The Principal Officer is responsible for ensuring compliance, monitoring transactions, and sharing and reporting information. Both sets of details must be communicated to FIU-IND and to the RBI. And a rule missed surprisingly often: the Principal Officer must not be nominated as the Designated Director.
Beneficial Ownership Identification
Identifying the natural person behind a legal entity is where most KYC programmes are weakest. The thresholds are: for a company, ownership of or entitlement to more than 10 per cent of shares, capital or profits, or control through other means; for a partnership firm, more than 10 per cent of capital or profits, or control; for an unincorporated association or body of individuals, including societies, more than 15 per cent of property, capital or profits. For a trust, identification must extend to the author of the trust, the trustee, beneficiaries with 10 per cent or more interest, and any natural person exercising ultimate effective control through a chain of control or ownership. Where no natural person is identified, the beneficial owner is the relevant natural person holding the position of senior managing official.
Enhanced Due Diligence and Politically Exposed Persons
Enhanced due diligence applies where risk is higher, including non-face-to-face onboarding. The Directions define politically exposed persons as individuals entrusted with prominent public functions by a foreign country, including heads of state or government, senior politicians, senior government, judicial or military officers, senior executives of state-owned corporations and important political party officials. A relationship with a PEP, as customer or beneficial owner, requires systems to detect PEP status, reasonable measures to establish source of funds and wealth, senior management approval to open the account, and enhanced ongoing monitoring. Where an existing customer or beneficial owner subsequently becomes a PEP, senior management approval is needed to continue. The same requirements extend to family members and close associates.
Sanctions and Watchlist Screening
Screening is a daily obligation, not a periodic one. Under section 51A of the Unlawful Activities (Prevention) Act, 1967, an entity must ensure it holds no account for individuals or entities on the UNSC lists, the ISIL (Da’esh) and Al-Qaida Sanctions List maintained under resolutions 1267, 1989 and 2253, and the Taliban Sanctions List maintained under resolution 1988 (2011), and must also refer to the schedules to the Prevention and Suppression of Terrorism (Implementation of Security Council Resolutions) Order, 2007. Those lists must be verified on a daily basis and every addition, deletion or change acted on. The UNSCR 1718 Sanctions List relating to the Democratic People’s Republic of Korea must likewise be checked every day. Matches must be reported to FIU-IND and advised to the Ministry of Home Affairs, and the freezing procedure in the UAPA Order dated 2 February 2021 followed.
Record Keeping and Retention
Transaction records must be kept for at least five years from the date of the transaction. Records identifying customers and their addresses, obtained at onboarding and during the relationship, must be preserved for at least five years after the relationship ends. Records must permit reconstruction of an individual transaction (its nature, amount and currency, date and parties) and be retrievable swiftly for competent authorities. Identification records include updated identification data, account files, business correspondence and the results of any analysis undertaken.
Reporting to FIU-IND
Reporting entities furnish prescribed information to the Director, FIU-IND, under Rule 3 read with Rule 7. In broad terms this covers cash transactions above Rs 10 lakh; series of connected cash transactions individually below Rs 10 lakh where the monthly aggregate exceeds Rs 10 lakh; receipts by non-profit organisations above Rs 10 lakh; counterfeit currency and forged-security transactions; all suspicious transactions, whether or not in cash; cross-border wire transfers above Rs 5 lakh where either origin or destination is in India; and purchases and sales of immovable property valued at Rs 50 lakh or more registered by the entity. Alert generation must be driven by software that flags transactions inconsistent with a customer’s risk categorisation and updated profile.
How Often Must KYC Be Updated?
Periodic Updation Periodicity for High, Medium and Low-Risk Customers
The approach is risk-based, with mandatory outer limits. Under paragraph 42 of the Commercial Banks KYC Directions, 2025, periodic updation must be carried out at least once every two years for high-risk customers, once every eight years for medium-risk customers and once every ten years for low-risk customers, counted from the date of account opening or the last KYC updation. The policy giving effect to this must be documented and Board-approved.
There is also a transitional relief worth knowing. For an individual customer categorised as low risk, the bank must allow all transactions and ensure KYC updation within one year of it falling due, or up to 30 June 2026, whichever is later, with the account subject to regular monitoring. This applies equally where periodic updation had already fallen due.
Customers must be given advance notice: at least three advance intimations before the due date, including at least one by letter, and at least three reminders afterwards, including at least one by letter, all recorded in the system for audit trail.
What Happens When Nothing Has Changed
Where there is no change in KYC information, a self-declaration from the customer is enough. It may be given through the email address or mobile number registered with the bank, ATMs, digital channels such as internet banking or the bank’s mobile application, or by letter, and may be collected through an authorised Business Correspondent. Legal entity customers may also self-declare, but must confirm that beneficial ownership information on record is accurate and update it if not.
What Happens When Only the Address Has Changed
Where only the address has changed, the customer gives a self-declaration of the new address through the same channels, and the institution must then verify the declared address through positive confirmation within two months: by address verification letter, contact point verification, deliverables or similar. Separately, customers are required to submit updates to previously submitted documents within 30 days of the update.
Re-KYC When a Minor Turns 18 or Documents Have Expired
Where the validity of the customer due diligence documents on file has expired at the time of periodic updation, the institution must undertake a KYC process equivalent to onboarding a new customer. The same equivalence applies to a legal entity customer whose KYC information has changed. For accounts opened when the customer was a minor, fresh photographs must be obtained on the customer becoming a major and current CDD standards must be met.
What Happens If You Do Not Complete KYC?
Consequences for Customers
An account is KYC compliant when the record on file is complete, meets the current standard and is not due for refresh. Accounts can be restricted, and eventually operations can cease, where KYC is not completed or PAN or Form 60 is not furnished by the notified date. One widely believed myth deserves correcting: an institution must not place any restriction on operations in an account merely because a suspicious transaction report has been filed. Filing an STR is an intelligence step, not a customer sanction, and the fact of filing is confidential.
Consequences for Regulated Entities
Under section 13(2) of the PMLA, if the Director of FIU-IND finds on inquiry that a reporting entity, its Designated Director on the Board or any of its employees has failed to comply with the obligations under Chapter IV, the Director may issue a warning in writing, direct compliance with specific instructions, direct periodic reports on the measures being taken, or by order impose a monetary penalty of not less than Rs 10,000 and up to Rs 1,00,000 for each failure. The Director may also direct a special audit of records.
The multiplier matters more than the headline figure. When furnishing information to the Director, a delay of each day in reporting a transaction, or each day’s delay in rectifying a misrepresented transaction beyond the prescribed time limit, constitutes a separate violation. A single late report held open for weeks is not one failure.
The Money-Mule Rule Compliance Teams Miss
The Directions require diligence and meticulous monitoring to identify accounts operated as money mules: accounts used to launder the proceeds of phishing, identity theft and similar fraud through recruited third parties. The sting is in the deeming provision: if it is established that an account is that of a money mule but no suspicious transaction report was filed, the bank is deemed not to have complied with the Directions.
Not registered with FIU-IND yet, or unsure whether you have to be?
AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.
KYC Compliance Checklist for Regulated Entities
Use this as a self-assessment. Any “no” is a remediation item.
- Board-approved KYC policy in place, covering all four required elements and periodic updation
- Designated Director and Principal Officer appointed, with the two roles held by different people, and both notified to FIU-IND and the sector regulator
- The correct current instrument identified for your entity type: for banks and NBFCs, the 2025 KYC Directions, not the withdrawn 2016 Master Direction
- Customer Acceptance Policy applied without denying service to ordinary customers, and applied with due consideration rather than mechanically
- Documented ML/TF risk assessment, with customers categorised as low, medium or high risk and the rating kept confidential
- Only the six Officially Valid Documents accepted as OVDs; deemed OVDs tracked and closed out within three months
- Beneficial owners identified at the correct thresholds (10 per cent, 10 per cent, 15 per cent and 10 per cent for trust beneficiaries), with senior managing official as fallback
- PEP screening covering the customer, the beneficial owner, family members and close associates, with senior management approval on file
- UNSC and UAPA schedule lists, and the UNSCR 1718 list, screened daily with change logs retained
- KYC records uploaded to CKYCR within ten days of commencing the relationship, and KYC Identifiers communicated to clients in writing
- Periodic updation tracked at 2, 8 and 10 years, with three advance intimations and three reminders evidenced
- Transaction monitoring software generating alerts against risk category and updated profile
- CTR, STR, NPO, counterfeit, cross-border wire transfer and immovable property reports filed within prescribed timelines, with no operational restriction imposed merely because an STR was filed
- Records retained five years from transaction date and five years after the relationship ends, retrievable on request
- Employee hiring due diligence and periodic AML/CFT training completed and documented
Conclusion
KYC, or Know Your Customer, is the verified-identity foundation of every anti-money laundering programme in India. The obligation comes from the Prevention of Money-Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005; the operating detail comes from your sector regulator: for banks and NBFCs, the entity-specific Reserve Bank of India Know Your Customer Directions, 2025 issued on 28 November 2025 and updated as on 29 December 2025, and for other sectors the instruments named in the regulator table above.
If you are a customer, check which of the six OVDs you hold and whether your KYC is due for refresh. If you are a compliance officer, confirm that your policy, training material and audit checklist cite the current instrument rather than the withdrawn 2016 Master Direction.
Frequently Asked Questions
KYC stands for Know Your Customer. In the securities and pension sectors it is often written as Know Your Client. The two terms carry the same regulatory meaning.
Yes. It is a statutory obligation on every reporting entity under Chapter IV of the Prevention of Money-Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005, and it is not optional or waivable by the institution or the customer.
The Prevention of Money-Laundering Act, 2002, read with the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. Sector regulators (RBI, SEBI, IRDAI, PFRDA, IFSCA and FIU-IND) then prescribe how the obligation is to be discharged.
Passport, driving licence, proof of possession of Aadhaar number, Voter’s Identity Card issued by the Election Commission of India, the NREGA job card signed by a State Government officer, and the National Population Register letter containing name and address.
Yes, through defined routes: Aadhaar OTP-based e-KYC in non-face-to-face mode, subject to consent and mobile-number conditions; the Video-based Customer Identification Process; and retrieval of existing records from the Central KYC Records Registry. Note that the regulatory term “Digital KYC” describes a supervised process in which the customer and an authorised official are in the same location.
There is no single expiry date. KYC must be refreshed on a risk-based basis, and in any event at least once every two years for high-risk customers, eight years for medium-risk and ten years for low-risk, measured from account opening or the last updation.
KYC is the verification process an institution carries out. CKYC refers to the Central KYC Records Registry operated by CERSAI, where those verified records are stored centrally so that another regulated entity can retrieve them instead of collecting documents again.
It is the 14-digit unique number the Central KYC Records Registry issues against your KYC record. Your reporting entity must communicate it to you in writing, and you can also access it on the CKYCR portal at ckycindia.in.
No. Proof of possession of Aadhaar number is one of the six Officially Valid Documents, not the only one. Aadhaar-based authentication routes are permitted under section 11A of the PMLA where applicable, but a customer may present another OVD instead.
Under section 13(2) of the PMLA the Director of FIU-IND may issue a written warning, direct compliance, direct periodic reporting, or impose a monetary penalty of not less than Rs 10,000 and up to Rs 1,00,000 for each failure. Each day’s delay in reporting or in rectifying a misreported transaction is a separate violation.
Yes. Legal entities must provide constitutional and authorisation documents, and the institution must additionally carry out customer due diligence on authorised signatories and on beneficial owners identified at the prescribed thresholds.
Yes, substantially. On 28 November 2025 the RBI replaced the single all-entity Master Direction – Know Your Customer Direction, 2016 with entity-specific 2025 KYC Directions, as part of consolidating approximately 3,500 instructions into 238 function-wise Master Directions across 11 categories of regulated entities, with 9,445 circulars repealed or withdrawn.
Ask the institution that holds your account, or search the CKYCR portal at ckycindia.in with your KYC Identifier. Your bank must also tell you when your periodic updation falls due. Your status is compliant when the record on file meets the current standard and is not due for refresh.
Three routes are open to you. You can use Aadhaar OTP-based e-KYC, subject to the consent and mobile-number conditions. You can complete a live video call under the Video KYC process. Or your institution can pull your existing record from the Central KYC Records Registry instead of collecting documents again.
If nothing has changed, a self-declaration is enough. You can send it by registered email or mobile number, internet banking, the bank’s mobile application, an ATM or a letter. If only your address has changed, declare the new address. The bank must then confirm that address within two months.
The KYC number is the 14-digit KYC Identifier issued by the Central KYC Records Registry. Your reporting entity must send it to you in writing after it files your record with the Registry. You can also retrieve it yourself at ckycindia.in.
It means the institution holds a complete KYC record for you that meets the current standard. It does not mean the record never expires. High-risk customers still need a refresh every two years, medium-risk customers every eight years and low-risk customers every ten years.
KYC verification is the step where the reporting entity confirms that the identity and address details you have given are genuine, using an officially valid document plus an independent check such as Aadhaar authentication, a database match or a live video call. Collecting the document is not verification. Establishing that the document is authentic and belongs to you is.
KYC stands for Know Your Customer. Indian regulation uses the same abbreviation for Know Your Client, the term SEBI prefers for securities market intermediaries. Both point to the same obligation under the PML (Maintenance of Records) Rules, 2005.
In banking, KYC is the set of checks the RBI requires a bank to complete before it opens an account, and to repeat through the life of the relationship. Under the RBI (Commercial Banks – Know Your Customer) Directions, 2025 the bank must verify identity and address against an officially valid document, identify the beneficial owner where the customer is not an individual, assign a risk category, screen the customer against the sanctions lists and refresh the record on the periodicity set for that risk category. A bank cannot open an account without it.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik