Last Updated  on: 06th October 2026       |        Last Reviewed on: 06th October 2026

Key Takeaways

  • Bank KYC in India now sits in an entity-specific instrument. There are separate 2025 KYC Directions for Commercial Banks, Small Finance Banks, Payments Banks, Local Area Banks, Regional Rural Banks, Urban Co-operative Banks and Rural Co-operative Banks.
  • A bank’s KYC policy must contain four elements: a Customer Acceptance Policy, Risk Management, a Customer Identification Procedure and Monitoring of Transactions. Each is a separate chapter of the 2025 Directions.
  • Customer identification is triggered in seven situations. The seven include suspected structuring below the Rs 50,000 threshold and an express prohibition on seeking introductions.
  • Periodic updation runs at least once every two years for high-risk customers, eight years for medium-risk and ten years for low-risk, measured from account opening or the last updation.
  • The Principal Officer cannot be nominated as the Designated Director. Paragraph 14(3) says so in one sentence, and it is the governance rule most often collapsed in practice.
  • Reporting to FIU-IND is governed by Rule 3 and Rule 8 of the PML Rules. Rule 3(1) contains seven categories of reportable transactions, and Rule 8(4) makes each day of delay a separate violation.
  • Records of transactions are kept for at least five years from the date of the transaction; identification records are kept for at least five years after the relationship ends.
  • Penalty exposure under section 13(2) of the PML Act runs from a written warning to a monetary penalty of not less than ten thousand rupees and up to one lakh rupees for each failure.

Quick Answer:

KYC is the set of statutory customer due diligence obligations a bank must discharge before opening an account, during operation, and for record retention after the relationship ends. It is not a form; it is a control framework imposed by the Prevention of Money Laundering Act, 2002, detailed by the PML (Maintenance of Records) Rules, 2005, and operationalised by the RBI Know Your Customer Directions, 2025.

What KYC Means for a Bank Specifically

Ask a retail customer what KYC means, and you will hear a description of paperwork. Ask a supervisor, and you will hear a description of a control. The gap between those two answers is where most bank KYC failures live.

KYC is a control framework, not a document collection exercise

The clearest statement of this in Indian law is in the 2025 Directions:

Banks shall undertake ongoing due diligence of customers to ensure that their transactions are consistent with their knowledge about the customers, customers’ business and risk profile, and the source of funds and wealth.

The obligation is not to hold documents. The obligation is to hold knowledge and test transactions against it continuously. A bank with perfect documents but no monitoring has not done KYC. The framework requires the policy and procedure to provide a bulwark against threats arising from money laundering, terrorist financing, proliferation financing and other related risks.

The bank must know the customer and the risk the customer represents

The directions require categorisation of every customer as low, medium or high risk, on parameters including identity, financial status, business nature, geography, product type, delivery channel and transaction type.

Banks shall keep the risk categorisation of a customer and the specific reasons for such categorisation confidential and shall not reveal this information to the customer to avoid tipping off.

The risk rating is a regulatory artefact the customer is not entitled to see. This affects grievance responses and customer communications; explanations for account flagging can themselves constitute tipping-off.

KYC in banking is now entity-specific, and that is new

Until 28 November 2025, a single Master Direction covered banks, NBFCs, All India Financial Institutions, payment system providers and others. The Reserve Bank replaced it with entity-specific Directions, one for each of eleven regulated entity categories.

If your institution is a Small Finance Bank and your policy cites the Commercial Banks Directions, you cite an instrument that does not apply to you. Substantive obligations are aligned, but paragraph numbers, applicability clauses and repeal provisions are not interchangeable.

Need Professional KYC & AML Compliance Support?

Build a stronger compliance framework with expert support for KYC, CDD, customer risk assessment, and AML controls. Get in touch to discuss your institution’s specific requirements.

The RBI Instrument That Governs Bank KYC Today

The entity-specific KYC Directions, with circular numbers

Regulated entity 

Specific Directions 

Commercial Banks 

Commercial Bank- Know Your Customer 2025 

Small Finance Banks 

Small Finance Bank- Know Your Customer 2025 

Payments Banks 

Payment Bank- Know Your Customer 2025 

Local Area Banks 

Local Area Bank- Know Your Customer 

Regional Rural Banks 

Regional Rural Bank- Know Your Customer 2025 

Urban Cooperative Banks 

Urban Cooperative Bank- Know Your Customer 

Rural Cooperative Banks 

Rural Cooperative Bank- Know Your Customer 2025 

The enabling powers, and why they matter

The Directions are issued under four separate statutory powers:

  • section 35A of the Banking Regulation Act, 1949;
  • section 10(2) read with section 18 of the Payment and Settlement Systems Act, 2007;
  • section 11(1) of the Foreign Exchange Management Act, 1999; and
  • Rule 9(14) of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005.

Rule 9(14) is the one to understand, because it explains the architecture. It empowers the regulator to issue guidelines incorporating the requirements of Rules 9(1) to 9(13), and to prescribe enhanced or simplified measures to verify the client’s identity, taking into consideration the type of client, business relationship and nature of transactions. Read together with the PML Act, this produces a three-layer structure:

  • The statutory floor. The PML Act sets the obligations of a reporting entity.
  • The structural detail. The PML Rules prescribe records, thresholds, timelines and the client due diligence framework.
  • The sectoral policy. The guidelines issued by the sector-specific supervisor in accordance with the PMLA and PML Rules.

Nothing in the sector-specific guidance can lower the statutory floor. Where the guidance is silent, the Rules still bind.

The Four Elements of a Bank's KYC Policy

The Directions are structured around four policy elements. A bank’s Board-approved KYC policy is expected to contain all four, and a supervisor reading that policy will look for all four.

Element one: Customer Acceptance Policy

The directions explicitly require banks to frame a Customer Acceptance Policy and list twelve things the policy must do, without prejudice to whatever else it contains. The bank shall:

  1. Not open any account in an anonymous or fictitious / benami name;
  2. Not open an account where it is unable to apply appropriate CDD measures, either due to non-cooperation of the customer or unreliability of the documents or information furnished, and shall consider filing an STR where it cannot comply with the relevant CDD measures;
  3. Not undertake a transaction or commence an account-based relationship without following the CDD procedure;
  4. Specify the mandatory information required for KYC purposes at account opening and during periodic updation;
  5. Obtain additional information, where the internal KYC Policy has not specified such a requirement, with the explicit consent of the customer;
  6. Apply the CDD procedure at the Unique Customer Identification Code (UCIC) level, so that an existing KYC-compliant customer opening another account or taking another product from the same bank does not need a fresh CDD exercise as far as identification is concerned;
  7. follow the CDD procedure for all joint account holders when opening a joint account;
  8. clearly spell out the circumstances in which a customer is permitted to act on behalf of another person or entity;
  9. put in place a suitable system to ensure the customer’s identity does not match any person or entity named in the sanctions lists in the direction;
  10. verify the PAN, if obtained, from the verification facility of the issuing authority;
  11. verify the customer’s digital signature on an equivalent e-document, if obtained, under the Information Technology Act, 2000; and
  12. verify the GST number from the search or verification facility of the issuing authority, where GST details are available.

The financial inclusion counterweight

Paragraph 18 pulls in the opposite direction from every other acceptance rule, deliberately:

“The Customer Acceptance Policy shall not result in denial of a banking / financial facility to members of the general public, especially those who are financially or socially disadvantaged, including the Persons with Disabilities (PwDs). The bank shall not reject an application for onboarding or periodic updation of KYC without application of mind. The officer concerned shall duly record the reason(s) for rejection.”

The tipping-off exception

Paragraph 19 provides the carve-out that reconciles CDD with intelligence:

“Where the bank forms a suspicion of money laundering or terrorist financing, and it reasonably believes that performing the CDD process will tip off the customer, it shall not pursue the CDD process, and instead file an STR with FIU-IND.”

Element two: Risk Management

Paragraph 20 sets the risk-categorisation obligation already discussed. Paragraph 10 sits above it and requires a Money Laundering and Terrorist Financing Risk Assessment at institution level.

Paragraph 10(1) requires the bank to carry out ML and TF risk assessment exercises periodically to identify, assess and mitigate risk across clients, countries or geographic areas, products, services, transactions and delivery channels, considering all relevant risk factors. The assessment must reflect sector-specific vulnerabilities the regulator may identify.

Paragraph 10(2) requires the assessment to be documented and proportionate to the nature, size, geographical presence and complexity of the bank. The Board or a delegated committee determines the periodicity, aligned with the outcome of the exercise, but the floor is fixed: “However, the bank shall review it at least annually.”

Paragraph 10(3) requires the outcome to be presented to the Board or the delegated committee and made available to competent authorities and self regulating bodies.

Paragraph 11 completes the loop by requiring a Risk-Based Approach with Board approved policies, controls and procedures, a CDD programme calibrated to identified ML/TF/PF risk and the size of business, and ongoing monitoring and enhancement of those controls.

For the substance of that institutional assessment, the Reserve Bank has published separate guidance: the Internal Risk Assessment Guidance for Money Laundering / Terrorist Financing Risks dated 10.10.2024. Section 3.3 of that guidance, headed “Incorporation of Proliferation Financing Risk in IRA”, extends the exercise beyond ML and TF:

Accordingly, REs while ensuring compliance with section 12A of the WMD Act, 2005 and associated Government Orders, may carry out an appropriate PF risk assessment for their institution and suitably incorporate the same in the internal ML/TF/PF risk assessment (IRA) and also ensure suitable mitigation measures.

Element three: Customer Identification Procedure

Paragraph 21 lists the seven situations in which the bank shall undertake identification of customers:

  1. commencement of an account-based relationship with the customer;
  2. carrying out any international money transfer operations for a person who is not an account holder of the bank;
  3. when there is a doubt about the authenticity or adequacy of the customer identification data it has obtained;
  4. selling third-party products as agents, selling its own products, payment of dues of credit cards, sale and reloading of prepaid or travel cards and any other product for more than Rs 50,000;
  5. carrying out transactions for a non-account-based customer, i.e., a walk-in customer, where the amount involved is equal to or exceeds Rs 50,000, whether as a single transaction or several transactions that appear to be connected;
  6. when the bank has reason to believe that a customer, account-based or walk-in, is intentionally structuring a transaction into a series of transactions below the threshold of Rs 50,000; and
  7. the bank shall ensure it does not seek introductions while opening accounts.

Relying on a third party's CDD

Paragraph 22 permits the bank, at its option, to rely on CDD done by a third party when verifying identity at the commencement of an account based relationship, for occasional transactions of Rs 50,000 or more (single or connected), or for international money transfer operations. Five conditions attach:

  1. the bank obtains the records or information of the CDD carried out by the third party immediately, from the third party or from the CKYCR;
  2. the bank takes adequate steps to satisfy itself that the third party will make copies of identification data and other relevant documentation available on request, without delay;
  3. the third party is regulated, supervised or monitored by a regulator, and has measures in place for compliance with CDD and record-keeping requirements in line with the PML Act;
  4. the third party is not based in a country or jurisdiction assessed as high-risk; and
  5. the bank retains ultimate responsibility for customer due diligence and for enhanced due diligence measures, as applicable.

Element four: Monitoring of Transactions

Paragraph 39 sets the ongoing due diligence standard. Paragraph 40 then names four transaction types the bank “shall necessarily monitor”, without prejudice to the generality of factors calling for close monitoring:

  • large and complex transactions including RTGS transactions, and those with unusual patterns, inconsistent with the normal and expected activity of the customer, which have no apparent economic rationale or legitimate purpose;
  • transactions which exceed the thresholds prescribed for specific categories of accounts;
  • high account turnover inconsistent with the size of the balance maintained; and
  • deposit of third-party cheques, drafts, etc. in existing and newly opened accounts followed by cash withdrawals for large amounts.

Paragraph 40 closes with a permissive sentence that is new and worth noting: “For ongoing due diligence, the bank may consider adopting appropriate innovations including artificial intelligence and machine learning (AI and ML) technologies to support effective monitoring.” That is an enabling provision, not a mandate, and it does not displace any other obligation in the chapter.

Paragraph 41 requires the extent of monitoring to align with the customer’s risk category. Paragraph 41(1) then sets a hard review cycle:

The bank shall put in place a system of periodic review of risk categorisation of accounts, with such periodicity being at least once every six months and shall establish the need for applying enhanced due diligence measures.

Six months. Not annually. This is one of the most frequently missed timelines in bank KYC because it is often confused with the periodic updation cycle in paragraph 42, which is a different obligation with different intervals. Reviewing the risk category every six months and re-verifying the KYC record every two, eight or ten years are two separate controls.

Are You Managing Customer Due Diligence Correctly?

Effective CDD goes beyond collecting identity documents. Make sure your process covers customer verification, beneficial ownership, business purpose, and risk assessment as required.

The KYC Process in a Bank, Step by Step

Step 1: Screen before you accept

Paragraph 17(9) requires a system to ensure the customer’s identity does not match any person or entity in the sanctions lists in Chapter IX. This is an acceptance stage control, which means the screening result must be available before the account is opened, not reconciled afterwards.

Step 2: Collect the identification set

Paragraph 23 governs what the bank obtains from an individual, whether the individual is the customer, a beneficial owner, an authorised signatory or a power of attorney holder related to a legal entity. There are six clauses, and the connectors between them matter:

  • the Aadhaar number, where the individual is desirous of receiving a benefit or subsidy under a scheme notified under section 7 of the Aadhaar Act, 2016, or decides to submit their Aadhaar number voluntarily to a bank or an RE notified under the first proviso to section 11A(1) of the PML Act;
  • proof of possession of Aadhaar number where the bank can carry out offline verification;
  • proof of possession of Aadhaar number where the bank cannot carry out offline verification, or any OVD or equivalent e-document containing details of identity and address;
  • the KYC Identifier with explicit consent to download records from CKYCR;
  • PAN or the equivalent e-document or Form No. 60 as defined in the Income-tax Rules, 1962;
  • such other documents as the bank may require, including in respect of the nature of business and financial status of the customer.

Clauses (1) to (4) are alternatives. Clauses (5) and (6) are cumulative. PAN or Form 60 is not one of the identity routes; it sits alongside whichever route is chosen.

Exception handling

Where e-KYC authentication cannot be performed for a section 7 beneficiary owing to injury, illness, infirmity or old age, the bank obtains the Aadhaar number and performs identification by offline verification or certified copy of OVD or equivalent e-document.

The controls that attach to the exception are the substantive part:

  • a bank official must invariably carry out CDD done in this manner;
  • such exception handling forms part of the concurrent audit mandated in paragraphs 12 and 13;
  • the bank must duly record cases of exception handling in a centralised exception database, containing the grounds for granting the exception, customer details, the name of the designated official authorising it and any additional details; and
  • the database is subject to periodic internal audit or inspection and must be available for supervisory review.

A bank that grants exceptions at branch level without a centralised database is non-compliant regardless of how well founded each exception was.

Step 3: Verify by the permitted method

Verification must follow one of the prescribed modes. Paragraph 24 sets the Digital KYC Process in ten clauses: an application at the bank’s own customer touch points, an authorised official carrying out the capture, a live photograph with location coordinates, originals seen and imaged in a single session, and the whole record digitally signed. Paragraphs 26 and 27 govern V-CIP, requiring liveness checks, an encrypted end-to-end connection, a time-stamped recording with an audit trail, a trained official, a randomised question sequence and geolocation confirming the customer is in India. Paragraph 44(1) requires V-CIP to be offered as the first option for remote onboarding.

Step 4: Establish beneficial ownership and legal entity documentation

Paragraph 32 permits accepting one document where two are genuinely unavailable, provided the bank undertakes contact point verification, collects clarifications establishing the firm’s existence, and verifies business activity from the address. The relief is conditional on field work.

Step 5: Assign a risk category

Paragraph 20 requires categorisation into low, medium and high risk based on broad principles (20(2)), specified parameters (20(3)), kept confidential (20(4)). This single field drives everything downstream: due diligence depth, monitoring intensity and periodic updation interval.

Step 6: Apply enhanced or simplified due diligence

Paragraph 44 sets out six EDD measures for non-face-to-face onboarding other than V-CIP onboarding under paragraph 25. Non-face-to-face modes here include digital channels such as CKYCR, DigiLocker and equivalent e-documents, and non digital modes such as a copy of an OVD certified by the additional certifying authorities allowed for NRIs and PIOs. The six measures:

  1. where the bank has introduced V-CIP, it must be offered as the first option for remote onboarding;
  2. alternate mobile numbers shall not be linked post CDD for transaction OTP or updates; transactions are permitted only from the mobile number used for account opening, and the bank must have a Board-approved policy setting out a robust due diligence process for requests to change the registered mobile number;
  3. apart from obtaining current address proof, the bank must verify the current address through positive confirmation before allowing operations in the account;
  4. the bank must obtain PAN and verify it from the issuing authority’s verification facility;
  5. the first transaction in such an account must be a credit from an existing KYC complied bank account of the customer; and
  6. such customers must be categorised as high-risk and the accounts subjected to enhanced monitoring until identity is verified face-to-face or through V-CIP.

Step 7: Upload to CKYCR and issue the identifiers

Paragraph 65 governs the Central KYC Records Registry. CERSAI was authorised to act as and perform the functions of the CKYCR by amendment notification dated 26 November 2015.

The core operational rule is in paragraph 65(2): in terms of Rule 9(1A) of the PML Rules, the bank shall capture the customer’s KYC records and upload them onto CKYCR within 10 days of commencement of an account based relationship.

CKYCR began operation on 15 July 2016. Scheduled Commercial Banks must upload new individual account KYC data from 1 January 2017. Other reporting entities began on 1 April 2017 for individual accounts. Legal entity accounts opened on or after 1 April 2021 must use the CERSAI LE Template.

Paragraph 65(7) requires the KYC Identifier to be communicated to the customer. Paragraph 65(8) requires pre-dating records to be uploaded at periodic updation or when updated information is received; updated information must reach CKYCR within seven days. CKYCR informs all relevant reporting entities, which must retrieve and update their own records. Paragraph 65(9) requires migration to current CDD standards during periodic updation.

Paragraph 65(10) is the customer benefit: for establishing a relationship, updation, periodic updation or identity verification, the bank must seek the KYC Identifier from the customer or retrieve it from CKYCR, obtain records online, and not require duplicate submission except where the customer’s information has changed, the record is incomplete, or not to current CDD standard.

Unique Customer Identification Code

Paragraph 70 requires the bank to allot a UCIC when entering into new relationships with individual customers and to existing individual customers. Paragraph 71 permits the bank, at its option, not to issue a UCIC to walk-in or occasional customers, provided there is an adequate mechanism to identify walk-in customers who transact frequently and to ensure they are allotted a UCIC.

The UCIC is what makes paragraph 17(6) work. Because CDD is applied at UCIC level, a customer who is already KYC-compliant does not need fresh identification to take a second product from the same bank.

Branch portability, with its qualifier

Paragraph 29 is short and is routinely quoted without its condition:

“KYC verification once done by one branch of the bank shall be valid for transfer of the account to any other branch of the same bank, provided the bank has already completed the full KYC verification for the concerned account and the same is not due for periodic updation.”

Portability is not unconditional. An account whose periodic updation has fallen due does not carry its verification across on transfer. Any bank process that treats intra-bank transfer as automatically KYC-neutral is reading the first half of the paragraph only.

Step 8: Monitor, review and re-verify

Steps 1 to 7 are onboarding. Step 8 is the rest of the relationship, and it is where the Directions place most of their weight: ongoing due diligence under paragraph 39, the four mandatory monitoring categories under paragraph 40, six month risk-category review under paragraph 41(1), alert software under paragraph 55, and periodic updation under paragraph 42.

Get Expert Support for RBI KYC Compliance

Managing RBI KYC requirements can be challenging as your customer base and compliance obligations grow. Get practical guidance to strengthen KYC, CDD, risk assessment, and ongoing monitoring.

Periodic Updation of KYC (Re-KYC)

The intervals

Paragraph 42(1) sets the rule most bank customers eventually encounter:

The bank shall carry out periodic updation at least once in every two years for high-risk customers, once in every eight years for medium-risk customers and once in every 10 years for low-risk customers from the date of opening of the account.

Paragraph 42(2) then created a transitional relief for low-risk individual customers:

Notwithstanding the provisions given above, in respect of an individual customer who is categorised as low-risk, the bank shall allow all transactions and ensure the updation of KYC within one year of it falling due for KYC or up to June 30, 2026, whichever is later.

What updation actually requires

Paragraph 42(3) deals with individuals across seven clauses.

Where there is no change in KYC information, the bank obtains a self declaration from the customer through the registered email ID, the registered mobile number, ATMs, digital channels such as online or internet banking or the bank’s mobile application, or by letter.

Where there is a change only in address, the bank obtains a self declaration of the new address through the same channels and then must verify the declared address through positive confirmation within two months, by means such as an address verification letter, contact point verification or deliverables.

Clause (iii) permits the bank, at its option, to obtain a copy of an OVD or deemed OVD, or the equivalent e-document, as proof of the declared address at updation but only if the bank clearly specifies that requirement in its Board approved internal KYC policy. A branch cannot invent the requirement locally.

Clause (v) covers accounts opened when the customer was a minor: on attaining majority, the bank obtains fresh photographs and ensures CDD documents meeting current CDD standards are available, carrying out fresh KYC where required.

The additional measures that catch banks out

Paragraph 42(5) contains five requirements that sit on top of everything above:

  1. The bank must hold the customer’s KYC document as per current CDD standards, and this applies even where there is no change in customer information, but the documents held are not to current standard. Where the validity of the documents held has expired at the time of periodic updation, the bank must undertake a KYC process equivalent to onboarding a new customer.
  2. The bank must verify the customer’s PAN details, if available, from the issuing authority’s database at the time of periodic updation.
  3. The bank must give the customer an acknowledgement recording the date of receipt of the documents or self declaration, must promptly update its records, and must then send the customer an intimation stating the date on which KYC details were updated.
  4. The bank may, for customer convenience, make updation available at any branch, in terms of its Board-approved internal KYC policy.
  5. The bank must adopt a risk-based approach to periodic updation, and must specify in its Board-approved internal policy any additional or exceptional measures it adopts that are not otherwise mandated – such as requiring a recent photograph, requiring the customer’s physical presence, requiring updation only at the branch where the account is maintained, or applying a more frequent periodicity than the minimum specified.

Customer-side duty and the notice regime

Paragraph 42(6) places a duty on the customer, communicated by the bank: where a document submitted at the time of establishing the relationship is updated, the customer must submit the update to the bank within 30 days of the update, so the bank’s records can be updated.

Six communications and an audit trail per customer per cycle is a systems obligation, not a call-centre one.

PAN, Form 60 and temporary ceasing of operations

Paragraph 43 handles the existing customer without PAN. The bank must obtain PAN, the equivalent e-document, or Form No. 60 by such date as the Central Government may notify, failing which the bank “shall temporarily cease operations in the account” until the customer submits it.

Paragraph 43 requires an accessible notice and reasonable opportunity to be heard before temporary ceasing. The policy must provide relaxations for customers unable to provide PAN or Form 60 owing to injury, illness or infirmity. Where a customer declines in writing, the bank must close the account after establishing identity and settling all obligations.

The Explanation defines the sanction: temporary ceasing of operations means temporary suspension of all transactions or activities in the account until the customer complies. For asset accounts such as loan accounts, only credits are allowed.

Governance: Who Is Accountable Inside the Bank

The Board

The Board owns the framework. Paragraphs 10(2) and 10(3) fix the periodicity and the use of the money laundering and terrorist financing risk assessment; paragraph 11 requires Board approved policies implementing a risk-based approach; paragraph 44(2) governs a change in the registered mobile number; paragraph 73 requires Board approval, or approval by a committee headed by the Chairman, Chief Executive Officer or Managing Director, for correspondent banking relationships; and paragraphs 42(1), 42(3)(iii) and 42(5) require the internal KYC policy, including the periodic updation approach, to be Board-approved.

Senior Management and the compliance architecture

Paragraph 12 sets out five mechanisms through which the bank must ensure compliance with its KYC policy:

  1. specifying who constitutes ‘Senior Management’ for KYC compliance;
  2. allocation of responsibility for effective implementation of policies and procedures;
  3. independent evaluation of the compliance functions of the bank’s policies and procedures, including legal and regulatory requirements;
  4. a concurrent or internal audit system to verify compliance with KYC and AML policies and procedures; and
  5. submission of quarterly audit notes and compliance reports to the Audit Committee.

Paragraph 13 draws the boundary on outsourcing: “The bank shall ensure that it does not outsource the decision making functions of determining compliance with KYC norms.” Processing may be outsourced. Judgement may not.

The Designated Director

Paragraph 14(1) defines the role: A ‘Designated Director’ is a Board nominated person whom the bank designates to ensure overall compliance with the obligations imposed under Chapter IV of the PML Act and the Rules. Paragraph 14(2) requires the name, designation, address and contact details to be communicated to FIU-IND and the RBI.

Paragraph 14(3) is one sentence, and it decides an organisational design question that many banks get wrong:

“The bank shall not nominate the Principal Officer as the ‘Designated Director’.”

The two roles must be held by different people. The reason is structural: the Designated Director is a Board level accountability holder for the institution’s compliance, while the Principal Officer is the operational reporting channel to FIU-IND. Collapsing them removes the internal check between the person who files and the person accountable for the framework within which filing happens.

Rule 2(ba) of the PML Rules defines “Designated Director” as a person designated to ensure overall compliance with Chapter IV obligations. For a company as defined in the Companies Act, 2013: Managing Director or duly authorised whole time Director; for a partnership: managing partner; for a proprietorship: proprietor; for a trust: managing trustee; for an unincorporated association: the controlling person; and such other person as the Government may notify.

For a bank, that narrows the field to the Managing Director or a duly authorised whole-time Director. A senior executive who is not on the Board cannot be the Designated Director.

The Principal Officer

Paragraph 15(1) makes the Principal Officer responsible for ensuring compliance, monitoring transactions, and sharing and reporting information as required under the laws and regulations. Paragraph 15(2) requires name, designation, address and contact details to be communicated to FIU-IND and the RBI.

Rule 7 requires communication of the Principal Officer’s name, designation and address to the Director. Rule 7(2) makes the Principal Officer responsible for furnishing Rule 3(1) information categories (A), (B), (BA), (C) and (D). Rule 7(3) requires an internal mechanism for detecting and reporting transactions. Rule 7(4) requires the entity, directors, officers and employees to observe the specified procedure.

Paragraph 53 requires the bank to note FIU-IND’s reporting formats, the comprehensive reporting guide, and the Report Generation and Validation Utilities. Banks without suitable technological tools must use the editable utilities FIU-IND provides on its website. The Principal Officer must arrange to extract transaction details from non computerised branches and feed data into electronic files using those utilities.

Group-level obligations

Paragraph 8 requires banks in a group to implement group wide programmes against money laundering and terror financing, including group-wide policies for information sharing on client due diligence and ML/TF/PF risk management, with adequate safeguards on confidentiality and use to prevent tipping-off. Rule 3A of the PML Rules imposes the same obligation on reporting entities in groups.

Paragraph 9 sets the policy standard already quoted, and adds a permissive note: the bank may consider adopting best international practices taking into account FATF standards and FATF guidance notes, for managing risks better.

Simplify Your KYC Compliance Requirements

Managing KYC requirements can be challenging for banks and financial institutions. Get expert guidance to build practical KYC procedures that support your compliance obligations.

Record Keeping

Paragraph 50 sets six record-keeping obligations, with reference to the PML Act and Rules. The bank shall:

  1. maintain all necessary records of transactions between the bank and the customer, both domestic and international, for at least five years from the date of transaction;
  2. preserve the records about identification of customers and their addresses, obtained while opening the account and during the course of the business relationship, for at least five years after the business relationship has ended;
  3. swiftly make available the identification records and transaction data to competent authorities on request;
  4. introduce a system of maintaining proper records of transactions prescribed under Rule 3 of the PML Rules, 2005;
  5. maintain all necessary information in respect of transactions prescribed under Rule 3 to permit the reconstruction of an individual transaction, including the nature of the transaction, the amount and the currency in which it was denominated, the date on which it was conducted, and the parties to it; and
  6. evolve a system for proper maintenance and preservation of account information in a manner that allows the bank to retrieve data easily and quickly whenever required or when competent authorities request it.

Clauses (1) and (2) run on different clocks, and this is the most common record retention error in banking. Transaction records run five years from the transaction. Identification records run five years from the end of the relationship.

Clause (5) is the reconstruction standard, and it is what turns a retention rule into an investigative capability. Holding the record is not enough if the four data points cannot be assembled into an account of what happened.

Paragraph 51 adds the reporting of information to DARPAN and the related maintenance requirements.

A note on sourcing, because it recurs in published content: the five year periods stated above are cited here to paragraph 50(1) and 50(2) of the 2025 Directions. Rule 10 of the PML Rules governs the procedure and manner of maintaining and furnishing information but does not itself prescribe those retention periods, and this article does not attribute them to it.

Reporting Obligations to FIU-IND

The seven reporting categories and their thresholds

Rule 3(1) of the PML Rules requires every reporting entity to maintain a record of all transactions, including the record of seven enumerated categories.

Clause 

Category 

Threshold 

(A) 

All cash transactions 

More than ten lakh rupees or equivalent in foreign currency 

(B) 

Series of integrally connected cash transactions individually below the threshold, within a month 

Monthly aggregate exceeding ten lakh rupees or equivalent 

(BA) 

Receipts by non-profit organisations 

More than rupees ten lakh or equivalent 

(C) 

Cash transactions where forged or counterfeit currency notes or bank notes have been used as genuine, or where forgery of a valuable security or a document has taken place facilitating the transactions 

No threshold 

(D) 

All suspicious transactions, whether or not made in cash 

No threshold 

(E) 

Cross-border wire transfers where either the origin or destination of funds is in India 

More than five lakh rupees or equivalent in foreign currency 

(F) 

Purchase and sale by any person of immovable property registered by the reporting entity 

Valued at fifty lakh rupees or more 

Category (BA) is the one most often absent from bank reporting matrices. Receipts by non-profit organisations above ten lakh rupees are reportable on their own footing, independently of whether the receipt was in cash and independently of any suspicion.

The reporting calendar

Rule 8 sets the timelines, and the Principal Officer is the named obligor throughout.

Rule 8(1) – categories (A), (B), (BA), (C) and (E): “every month to the Director by the 15th day of the succeeding month.”

Rule 8(2) – category (D), suspicious transactions: the Principal Officer, “on being satisfied that the transaction is suspicious, [shall] furnish the information promptly in writing by fax or by electronic mail to the Director.”

Rule 8(3) – category (F), immovable property: “every quarter to the Director by the 15th day of the month succeeding the quarter.”

Rule 8(4) – the compounding provision: “For the purpose of this rule, delay of each day in not reporting a transaction or delay of each day in rectifying a mis-reported transaction beyond the time limit as specified in this rule shall constitute a separate violation.”

Rule 8(2) of the PML Rules contains no day-count deadline. The standard is “promptly”, upon satisfaction that a transaction is suspicious. Banks should cite any specific day-count to their own policy or a regulatory instrument, not to Rule 8(2). Writing a day-count into policy is good practice; attributing it to Rule 8(2) is a citation error that will not survive supervisory review.

Confidentiality and the no-restriction rule

Paragraph 54 of the Directions carries two propositions worth reading together.

The first restates Rule 8(4): each day’s delay in reporting, or in rectifying a misrepresented transaction, beyond the time limit specified in the Rule constitutes a separate violation and then adds a rule that operates in the customer’s favour: “The bank shall not put any restriction on operations in the accounts merely based on the STR filed.”

Filing an STR is an intelligence act, not a basis for freezing or restricting an account. A restriction requires its own legal foundation: a sanctions match, a court or authority order, a contractual right, or the paragraph 43 temporary ceasing procedure. Restricting solely on STR strength breaches paragraph 54 and risks tipping off.

The confidentiality rule: the bank, its directors, officers and employees must keep the fact of Rule 3 record maintenance and furnishing information to the Director confidential. The carve out is narrow confidentiality “shall not inhibit sharing of information under paragraph 8 of any analysis of transactions and activities which appear unusual.” Rule 8(6) of the PML Rules permits sharing under Rule 3A.

So group-wide sharing of unusual activity analysis is permitted. Broader disclosure is not.

Worried About Gaps in Your KYC Process?

Small gaps in customer due diligence can create bigger compliance challenges. Let our experts review your KYC framework and help you address potential weaknesses.

Sanctions, Terrorism Financing and Proliferation Financing

UAPA and the UNSC lists

The Terrorist Financing Act, along with the rules and the directions, require the bank to ensure, in terms of section 51A of the Unlawful Activities (Prevention) Act, 1967, that it does not hold any account in the name of individuals or entities in the UNSC sanctions lists: the ISIL (Da’esh) and Al-Qaida Sanctions List (Security Council resolutions 1267/1989/2253) and the Taliban Sanctions List (established under separate Council resolutions).

Paragraph 56(2) extends the obligation to the lists in the Schedules to the Prevention and Suppression of Terrorism (Implementation of Security Council Resolutions) Order, 2007, as amended, and sets the frequency: the bank shall verify the UNSC Sanctions Lists and the 2007 Order Schedules daily, and any modification by way of addition, deletion or other change must be taken into account for meticulous compliance.

Paragraph 56(3) requires details of accounts resembling any listed individual or entity to be reported to FIU-IND, in addition to advising the Ministry of Home Affairs per the UAPA notification dated 2 February 2021 (Annex I to the Directions). Paragraph 56(4) requires strict adherence to the freezing procedure in that Order.

Proliferation financing and the WMD Act

Paragraph 57(1) requires meticulous compliance with the “Procedure for Implementation of Section 12A of the Weapons of Mass Destruction (WMD) and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005”, laid down under section 12A by Order dated 1 September 2023 of the Ministry of Finance, which is Annex II to the Directions.

Paragraph 57(2) prohibits transactions with individuals or entities matching the designated list. Paragraph 57(3) requires verification at relationship establishment and periodically to confirm that no funds or resources are held. Paragraph 57(4) requires immediate communication of transaction details with full particulars to the Central Nodal Officer, with copies to the State Nodal Officer and RBI. The Director, FIU-India is the Central Nodal Officer.

DPRK, residual lists and high-risk jurisdictions

Paragraphs 58 to 60 carry the obligations relating to the Democratic People’s Republic of Korea and the residual UNSC lists and related communications from international agencies.

Paragraph 61 requires the bank to consider FATF public statements on jurisdictions with strategic AML/CFT/CPF deficiencies and apply proportionate enhanced due diligence. Paragraph 62 requires response to communications from international agencies. Rule 9(14)(ib) of the PML Rules requires the regulator’s guidelines to include countermeasures when called upon by international or intergovernmental organisations accepted by the Central Government.

High-Risk Areas Banks Get Wrong

Money mules

Paragraph 68 requires strict adherence to the instructions on opening accounts and monitoring transactions, to minimise the operation of money mules used to launder the proceeds of fraud schemes such as phishing and identity theft. The bank must undertake due diligence measures and meticulous monitoring to identify accounts operated as money mules and take appropriate action, including reporting suspicious transactions to FIU-IND.

The sting is in the final sentence:

“Further, if it is established that an account opened and operated is that of a Money Mule, but STR was not filed by the concerned bank, it shall then be deemed that the bank has not complied with these directions.”

That is a deeming provision. Once mule status is established and no STR was filed, non compliance is not argued it follows. There is no defence of reasonable systems available on the face of the paragraph.

Correspondent banking

Paragraph 73 requires a Board-approved policy and imposes ten conditions before a correspondent relationship is entered into. The bank must gather sufficient information about the respondent bank to understand its business, assess its reputation and the quality of its supervision from publicly available information, and establish whether it has been subject to a money laundering or terrorist financing investigation or regulatory action. Relationships with shell banks are prohibited.

Wire transfers

Paragraph 74 governs wire transfers. The operative threshold for domestic transfers is Rs 50,000: transfers of that amount or more by a non-account holder require identification, with the originator information accompanying the transfer, and records preserved. Name screening against the sanctions lists applies to wire transfer parties, and the paragraph sets the record preservation requirement for the information collected.

Secrecy and its exceptions

The directions govern the customer confidentiality obligation and its limits, including disclosure where compelled by law, where there is a duty to the public to disclose, where the bank’s own interests require disclosure, and where disclosure is made with the customer’s express or implied consent. Addresses obligations under the Foreign Contribution (Regulation) Act.

The interaction to hold in mind is that the secrecy obligation and the reporting obligation do not conflict. Reporting to FIU-IND is disclosure compelled by law. What is not permitted is disclosing the fact of that reporting, which is where Rule 8(6) bites.

Penalties for KYC Failure

Under the PML Act

Section 13(2) of the Prevention of Money Laundering Act, 2002 gives the Director of the FIU-IND four options, having regard to the nature of the default or contravention:

  1. issue a warning in writing;
  2. direct the reporting entity, its designated director on the Board, or any of its employees, to comply with specific instructions;
  3. direct the reporting entity, its designated director on the Board, or any of its employees, to send reports at such interval as may be prescribed on the measures it is taking; or
  4. impose a monetary penalty on the reporting entity, its designated director on the Board, or any of its employees, “which shall not be less than ten thousand rupees but may extend to one lakh rupees for each failure.”

Under the Banking Regulation Act and the Directions themselves

The Directions are issued under section 35A of the Banking Regulation Act, 1949, among other powers. Non-compliance with a direction issued under section 35A engages the Reserve Bank’s enforcement powers under that Act independently of the PML Act route.

The entity-specific directions confirm the Directions “shall be in addition to, and not in derogation of the provisions of any other laws, rules, regulations, or directions, for the time being in force.” Further, it reserves interpretation to the Reserve Bank.

The RBI may issue clarifications to give effect to the Directions or remove difficulties in their application or interpretation.

That last clause is worth quoting in a compliance policy. Where a paragraph is genuinely ambiguous, the answer is a clarification sought from the Reserve Bank, not a reasoned internal legal opinion relied on as authority.

Conclusion

Bank KYC can be understood as three layers. The PML Act, 2002 creates reporting entity obligations. The PML Rules, 2005 give those obligations their records, thresholds and timelines. The Reserve Bank of India specific bank category Directions, 2025 operationalise that framework through a Customer Acceptance Policy, risk categorisation, identification procedure and monitoring programme.

If updating a bank KYC policy, four things reliably surface in the 2025 Directions: Paragraph 14(3) separates the Principal Officer from the Designated Director. Paragraph 41(1) requires half yearly review of risk categorisation. Paragraph 42(5)(v) requires every additional friction at re-KYC to be in Board-approved policy. Paragraph 57 requires proliferation financing screening capability that most Indian programmes lack.

Get the instrument right first. The gaps show up on their own after that.

Need Help Strengthening Your KYC Process?

Make sure your bank or financial institution has a practical KYC process that meets applicable regulatory expectations. Get expert support to review gaps and improve your customer due diligence framework.

Frequently Asked Questions

KYC (Know Your Customer) in banking means the statutory customer due diligence framework under the Prevention of Money Laundering Act, 2002, the PML (Maintenance of Records) Rules, 2005, and the RBI (Specified Banks – Know Your Customer) Directions, 2025. It provides for identifying and verifying the customer, categorising risk, monitoring transactions, keeping records and reporting transactions to FIU-IND.

The applicable RBI KYC instrument now depends on the category of bank. The earlier RBI (KYC) Directions, 2016were replaced as part of the RBI’s 2025 restructuring, with separate KYC Directions for specific categories of regulated entities, like the RBI (Commercial Banks – Know Your Customer) Directions, 2025.

No. The RBI’s Master Direction – Know Your Customer (KYC) Direction, 2016 was replaced on 28 November 2025 by the RBI (Know Your Customer) Directions, 2025. The applicable KYC framework now depends on the category of banking company.

Under paragraph 42(1), at least once every two years for high-risk customers, once every eight years for medium-risk customers and once every ten years for low-risk customers, measured from the date of account opening or the last KYC updation. These are minimum intervals. A bank may set a shorter cycle in its Board-approved internal KYC policy.

The Directions do not authorise account freezes for non-completion of periodic updation. Paragraph 42(7) requires at least three advance intimations and three reminders, including by letter. Paragraph 43 permits temporary ceasing where PAN or Form 60 is missing, but only after notice and reasonable opportunity to be heard.

Where the bank is unable to apply appropriate CDD, paragraph 17(2) requires that no account be opened, with an option to file an STR. However, paragraph 18 mandates that the Customer Acceptance Policy not deny banking facilities to the general public or financially disadvantaged persons, and rejection must involve application of mind with recorded reasons.

KYC compliance is a shared but clearly allocated responsibility. The Board approves the KYC policy and risk-assessment framework, while Senior Management is responsible for implementation. The Designated Director bears overall responsibility for ensuring compliance with the applicable AML/KYC requirements, and the Principal Officer manages day-to-day AML compliance, including transaction monitoring and reporting to FIU-IND. Core decision-making functions relating to KYC and AML compliance cannot be outsourced.

The Designated Director is a Board-nominated person ensuring overall compliance with Chapter IV PML Act obligations; for a company, this must be the Managing Director or duly authorised whole-time Director. The Principal Officer holds operational responsibility for compliance, monitoring and reporting. The direction mandates the two roles be held by different people.

Rule 3(1) lists seven reporting categories: cash above ten lakh rupees; integrally connected cash aggregating above ten lakh monthly; non-profit receipts above ten lakh; forged currency or securities; all suspicious transactions; cross-border wire transfers above five lakh; and immovable property sales at fifty lakh or more.

Rule 8(2) requires the Principal Officer, satisfied that a transaction is suspicious, to furnish information “promptly in writing” to the Director. Rule 8(2) does not specify a day-count; banks should trace any internal deadline to their own policy or regulatory instrument, not to Rule 8(2). Rule 8(4) makes each day of delay a separate violation.

Records of transactions between the bank and customer (domestic and international) for at least five years from the transaction date. Identification records: kept for at least ten years from account closure.

Under section 13(2) of the PML Act, the Director may issue written warnings, direct compliance, direct report filing, or impose penalties of ten thousand to one lakh rupees per failure, attaching to the reporting entity, designated director, or employees. Rule 8(4) makes each day of delay a separate violation. Section 35A of the Banking Regulation Act, 1949 engages the Reserve Bank’s enforcement powers.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik