Last Updated on: 24h September 2026 | Last Reviewed on: 24th September 2026
Key Takeaways at a Glance
- For an individual, identity and address rest on one of six Officially Valid Documents, with four categories of deemed OVD available for address alone.
- KYC records must be uploaded to the Central KYC Records Registry within 10 days of commencement of an account-based relationship, and updated information furnished within seven days.
- Re-KYC runs on a risk clock: at least once every two years for high-risk customers, once every eight years for medium-risk and once every ten years for low-risk, measured from account opening or the last updation.
- Transaction records are retained for five years from the date of the transaction, and identity records for five years after the relationship ends or the account is closed, whichever is later.
Quick Answer: What the KYC Process Involves
The KYC process in India runs in four blocks: customer acceptance, customer identification and verification, risk categorisation, and monitoring of transactions. Those four are what a KYC policy must contain under the PMLA, 2002, the PML (Maintenance of Records) Rules, 2005 and your regulator’s KYC directions.
Before You Start: What the KYC Process Is Meant to Achieve
The law describes the process from the inside out: a Board-approved policy, an acceptance decision taken against it, verification through a permitted mode, a risk category that governs everything afterwards, and observation of the relationship for as long as it lasts. Account opening is the middle of the process, not the end.
The Four Building Blocks of Any Compliant KYC Process
The KYC policy must be approved by the Board, or a committee to which the Board has delegated the power and contain four key elements: a Customer Acceptance Policy, Risk Management, Customer Identification Procedures and Monitoring of Transactions. It must also cover periodic updation, exceptional updation measures, proof of address change by OVD or deemed OVD, and updation at any branch. Two further Board-approved policies sit alongside: one on due diligence for mobile number change requests on non-face-to-face accounts, and one on cross-border correspondent banking, approved by the Board or a committee headed by the Chairman, CEO or Managing Director.
What Decides Which Path a Customer Takes
Three variables decide the path.
- Customer type: individual, sole proprietorship (proprietor identified plus activity proofs for the firm), or legal person (entity documents plus beneficial owner).
- Assessed risk: low, medium or high, which drives monitoring intensity, re-KYC periodicity and enhanced due diligence.
- Verification mode: in-person, the Digital KYC Process, V-CIP, Aadhaar OTP-based eKYC, or retrieval from the CKYCR against a KYC Identifier. Each mode carries its own conditions, and one carries hard account limits.
The Legal Instruments That Set the Process for Your Sector
The statutory spine is common to everyone. The Prevention of Money Laundering Act, 2002 imposes the obligations to maintain records, verify identity and report transactions. The Prevention of Money Laundering (Maintenance of Records) Rules, 2005 prescribe the details: client due diligence, CKYCR mechanics, reportable categories and reporting deadlines. What sits on top differs by sector.
|
Sector |
Governing instrument |
Date |
|
Sector-specific KYC Directions govern each category of bank, with requirements tailored to the respective type of regulated entity.
|
28 November 2025, updated as on 29 December 2025 |
|
|
Financial Institutions / NBFCs |
It is either Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Directions, 2025 or as specified for their sector. |
28 November 2025, updated as on 29 December 2025 |
|
Guidelines on AML Standards and CFT / Obligations of Securities Market Intermediaries; Master Circular on KYC norms for the securities market |
6 June 2024; 12 October 2023 modified 6 June 2024 |
|
|
Insurance |
Master Guidelines on Anti-Money Laundering / Counter Financing of Terrorism (AML/CFT), 2022 |
Issued 1 August 2022, in force from 1 November 2022 |
|
Master Circular – Guidelines on Know Your Customer / Anti Money Laundering / Combating the Financing of Terrorism (KYC/AML/CFT) |
Originally 23 January 2023, last updated 25 September 2025 |
|
|
International Financial Services Centres Authority (Anti Money Laundering, Counter-Terrorist Financing and Know Your Customer) Guidelines, 2022 |
28 October 2022, updated as on 26 February 2026 |
|
|
DNFBPs |
No single consolidated KYC instrument. Obligations flow from the PMLA and the PML Rules, with sector guidance from the respective supervisory authorities |
28 December 2020; 3 May 2023 |
Worried About KYC Compliance Gaps?
Let our AML experts review your KYC framework and help you address gaps before they become regulatory issues.
Step 1: Apply the Customer Acceptance Policy
The process does not begin with collecting documents. It begins with a decision on whether the customer will be accepted at all, taken against a policy framed in advance.
Before establishing a business, relationship or carrying out a transaction, the reporting entity should apply its Customer Acceptance Policy to determine whether the customer can be accepted and what level of due diligence is required. The assessment should be based on the customer’s money laundering and terrorist financing risk and should consider relevant factors such as the nature of the customer, its business or activities, ownership and control, beneficial ownership, geographical exposure, and the products, services or transactions involved.
As part of this process, the reporting entity must identify and verify the customer using reliable and independent sources, understand the purpose and intended nature of the business relationship where applicable, and take reasonable steps to understand the customer’s business and ownership and control structure. Where the customer is acting on behalf of another person, the beneficial owner must also be identified and verified. The reporting entity should also verify the authority and identity of any person acting on behalf of the customer.
The Customer Acceptance Policy should prevent the establishment or continuation of relationships where the customer’s identity cannot be satisfactorily established or verified. Anonymous accounts, accounts in fictitious names, and relationships involving undisclosed persons whose identities cannot be verified must not be accepted. The policy should also ensure that high-risk customers or relationships are subject to appropriate enhanced measures, while simplified measures may only be applied where permitted and must not be used where there is a suspicion of money laundering or terrorist financing.
Customer acceptance is therefore a risk-based decision rather than a purely administrative onboarding step. The information obtained at acceptance should enable the reporting entity to establish an appropriate customer risk profile and determine the level of ongoing due diligence and monitoring required throughout the business relationship.
Step 2: Trigger the Customer Identification Procedure
The Occasions That Trigger Identification
The Customer Identification Procedure (CIP) is triggered at the points specified under Rule 9 of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005. A reporting entity must identify and verify the customer at the commencement of an account-based relationship, when carrying out an occasional transaction of ₹50,000 or more, whether undertaken as a single transaction or as connected transactions, and in relation to international money transfer operations.
Relying on Customer Due Diligence Done by a Third Party
Rule 9 of the PML rules permits the entity, at its option, to rely on CDD carried out by a third party for verifying identity at commencement of an account-based relationship, for an occasional transaction of Rs 50,000 or more, or for any international money transfer operation. Five conditions attach: the CDD records are obtained immediately, from the third party or the CKYCR; copies of identification data will be available on request without delay; the third party is regulated, supervised or monitored and has CDD and record-keeping measures in line with the PMLA; it is not based in a high-risk jurisdiction; and the entity retains ultimate responsibility for CDD and enhanced due diligence. Reliance transfers the work, not the responsibility.
Step 3: Collect Identity and Address Evidence
For an individual, this step produces the documentary record that identity and address rest on. The provisions are precise: a document that is nearly on the list is not on the list.
The Six Officially Valid Documents
An Officially Valid Document means one of six: the passport, the driving licence, proof of possession of Aadhaar number, the Voter’s Identity Card issued by the Election Commission of India, the NREGA job card duly signed by a State Government officer, and the National Population Register letter containing name and address. Proof of possession of Aadhaar number may be in such form as the UIDAI issues, and where it carries the number, the entity must ensure the customer redacts it wherever Aadhaar authentication is not required. A document remains a deemed OVD despite a change of name after issuance if supported by a State Government marriage certificate or a Gazette notification.
When an OVD Does Not Carry the Current Address
Where the OVD furnished does not carry an updated address, four categories of document, or their equivalent e-documents, are deemed OVDs for the limited purpose of proof of address: a utility bill not more than two months old of any service provider, being an electricity, telephone, post-paid mobile phone, piped gas or water bill; a property or Municipal tax receipt; a pension or family pension payment order issued to a retired employee by a Government Department or Public Sector Undertaking, if it contains the address; and a letter of allotment of accommodation from a Government Department, statutory or regulatory body, public sector undertaking, scheduled commercial bank, financial institution or listed company employer, with leave and licence agreements. The two-month test run on the bill is the commonest failure point. The OVD is still required, and the customer shall submit an OVD carrying the current address within three months.
Documents for Foreign Nationals and Non-Resident Customers
Where a foreign national’s OVD does not contain address details, the entity shall accept documents issued by Government departments of foreign jurisdictions and a letter from the Foreign Embassy or Mission in India as proof of address.
For Non-Resident Indians and Persons of Indian Origin as defined in the Foreign Exchange Management (Deposit) Regulations, 2016, the certified copy may be certified by any one of six authorities: an authorised official of an overseas branch of a Scheduled Commercial Bank registered in India, a branch of an overseas bank with which Indian banks have relationships, a Notary Public abroad, a Court Magistrate, a Judge, or the Indian Embassy or Consulate General in the country of residence.
A sole proprietary firm is not a separate legal person: the entity carries out CDD of the proprietor and obtains any two documents evidencing business or activity in the firm’s name, from a list running from the Udyam Registration Certificate and Shop and Establishment Act licence through GST, VAT and CST certificates, the Importer Exporter Code, a professional body’s certificate of practice, an authenticated Income Tax Return in the proprietor’s name and utility bills. Where satisfied that two cannot be furnished, it may accept one, provided it undertakes contact point verification, collects such other information as would establish the existence of the firm, and verifies the business activity from the address of the concern.
Get a KYC Compliance Consultation
Discuss your current KYC process with an AML professional and identify the key areas that need improvement.
Step 4: Verify Identity Using an Approved Mode
Collecting a document is not the same as verifying identity. The PML Rules provide for multiple methods of customer identification and verification, including Aadhaar-based authentication or offline verification, Digital KYC, use of equivalent e-documents of Officially Valid Documents, Video-based Customer Identification Process (V-CIP), and retrieval of KYC records from the CKYCR using the KYC Identifier. Where an OVD or proof of Aadhaar cannot be verified through offline means, the Rules provide for Digital KYC, which includes capturing a live photograph and the prescribed location information. The detailed operational requirements for Digital KYC and V-CIP, including liveness checks, trained personnel, recording and other safeguards, are prescribed through the applicable regulatory KYC directions. The Rules also provide a specific exception for individuals who cannot complete Aadhaar e-KYC authentication because of injury, illness, infirmity due to old age or similar causes while seeking benefits or subsidies under a scheme notified under section 7 of the Aadhaar Act; in such cases, alternative identification methods prescribed by the Rules may be used.
Pulling an Existing Record From CKYCR
Where the customer supplies a KYC Identifier with explicit consent, the entity retrieves the records online from the CKYCR and shall not require the customer to submit the same KYC records or information again, unless there is a change in information, the record is not KYC compliant, or the validity of downloaded documents has expired. Those three exceptions are the whole of the entity’s right to ask again. The entity that last uploaded or updated the record carries responsibility for verifying identity and address, which is dealt with under Step 10.
Step 5: For Non-Individual Customers, Identify the Beneficial Owner
A legal entity cannot itself be the subject of identity verification. What is verified is its legal existence, the authority of the people acting for it, and the identity of the natural persons who own or control it.
Two definitional points attach to the entity type document sets in Rule 9. Unregistered trusts and unregistered partnership firms are treated as unincorporated associations or bodies of individuals for these Directions. And a company for this purpose means a company as defined in the Companies Act, 2013, so a body corporate outside that definition falls to be documented under whichever of the other categories fits it, which is a classification decision the entity has to record.
The Beneficial Ownership Thresholds
The thresholds differ by entity type, and the difference is not cosmetic. In each of the first three limbs, the beneficial owner is the natural person or persons who, acting alone or together, or through one or more juridical persons, meet the stated test. For a company, that test is a controlling ownership interest, meaning ownership of or entitlement to more than 10 per cent of the shares or capital or profits, or control through other means, control including the right to appoint the majority of directors or to control management or policy decisions, whether by shareholding, management rights, shareholders’ agreements or voting agreements. For a partnership firm, ownership of or entitlement to more than 10 per cent of the capital or profits, or control through other means. For an unincorporated association or body of individuals, ownership of or entitlement to more than 15 per cent of the property or capital or profits. For a trust, identification shall include the author of the trust, the trustee, the beneficiaries with 10 per cent or more interest in the trust, and any other natural person exercising ultimate effective control through a chain of control or ownership.
Where no natural person is identified under the company, partnership or unincorporated association limbs, the beneficial owner is the natural person holding the position of senior managing official. That is a fallback, not a shortcut, and reaching for it before the ownership analysis has been done and documented is a common review finding.
The Listed-Entity Exemption
Where the customer or the owner of the controlling interest is an entity listed on a stock exchange in India, or an entity resident in a jurisdiction notified by the Central Government and listed on a stock exchange there, or a subsidiary of such listed entities, it is not necessary to identify and verify any shareholder or beneficial owner. The exemption extends to subsidiaries; for foreign listings it depends on the jurisdiction having been notified; and it exempts only shareholder and beneficial owner identification, not entity-level documents or identification of authorised signatories.
Step 6: Screen Against Sanctions and PEP Lists
Screening is not a step that happens once at onboarding. Two of the obligations in this section run every single day, whether or not any customer is being onboarded.
The Lists That Must Be Checked Every Day
In terms of section 51A of the Unlawful Activities (Prevention) Act, 1967 and amendments to it, the entity must ensure it holds no account in the name of individuals or entities appearing in the lists of those suspected of terrorist links approved and periodically circulated by the United Nations Security Council. Two are named: the ISIL (Da’esh) and Al-Qaida Sanctions List, maintained pursuant to Security Council resolutions 1267, 1989 and 2253, and the Taliban Sanctions List, maintained pursuant to resolution 1988 of 2011. The entity must also refer to the lists in the Schedules to the Prevention and Suppression of Terrorism (Implementation of Security Council Resolutions) Order, 2007, as amended. The frequency obligation is explicit: those lists and Schedules shall be verified on a daily basis, with additions, deletions and other changes taken into account. Separately, the entity shall verify every day the UNSCR 1718 Sanctions List of Designated Individuals and Entities and comply with the Implementation of Security Council Resolution on Democratic People’s Republic of Korea Order, 2017, as amended, and shall take into account other UNSCRs and the lists in the First Schedule and Fourth Schedule of the UAPA, 1967.
The Proliferation Financing Layer
Obligations under the Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 run in parallel with a different reporting line. The entity shall ensure meticulous compliance with the Procedure for Implementation of Section 12A of the WMD Act, 2005, laid down by Order dated 1 September 2023 by the Ministry of Finance. Where particulars match the designated list, it shall not carry out transactions, and it shall run a check on establishing a relationship and periodically thereafter. On a match, it shall immediately inform the transaction details, with full particulars of the funds, financial assets or economic resources involved, to the Central Nodal Officer; the Director, FIU-India, is the designated Central Nodal Officer. Where there are reasons to believe beyond doubt that funds or assets held by a customer would fall under section 12A, it shall prevent that person from conducting financial transactions, under intimation to the Central Nodal Officer by email, fax and post without delay, and shall without delay comply with any freezing order under section 12A.
For unfreezing, the entity shall forward a copy of the application received from the individual or entity, with full details of the asset frozen as given by the applicant, to the Central Nodal Officer by email, fax and post within two working days. That is one of the few short, hard deadlines in the framework, and it runs from an inbound customer request rather than an outbound alert, so it needs an owner and a clock.
PEP Screening and Senior Management Approval
The entity may establish a relationship with a Politically Exposed Person, with a family member or close relative of a PEP, or with an account of which a PEP is the ultimate beneficial owner, subject to five conditions, and those five conditions are themselves the enhanced due diligence required for PEPs.
- It shall have appropriate risk management systems to determine whether the customer or beneficial owner is a PEP.
- It shall take reasonable measures to verify the source of funds, including the source of wealth.
- It shall obtain senior management approval before establishing the relationship.
- It shall conduct enhanced monitoring on an ongoing basis. And where an existing customer, or the beneficial owner of an existing account, subsequently becomes a PEP,
- it shall obtain senior management approval to continue and apply the same measures.
The definition is jurisdictionally limited: PEPs are individuals who are or have been entrusted with prominent public functions by a foreign country, including Heads of State or Government, senior politicians, senior government, judicial or military officers, senior executives of state-owned corporations and important political party officials. Domestic public officials are not PEPs under this definition, though nothing prevents an entity from treating them as high risk under its own policy.
Escalation and Reporting on a Match
The entity shall report the details of accounts resembling any of the individuals or entities in the lists to FIU-IND, in addition to advising the Ministry of Home Affairs as required under the UAPA notification dated 2 February 2021, annexed to the Directions. “Resembling” is doing important work: the trigger is a resemblance rather than a confirmed match, and the escalation runs to two destinations. For freezing of assets under section 51A of the UAPA, 1967, the entity shall strictly follow the procedure in the UAPA Order dated 2 February 2021; the list of Nodal Officers is on the Ministry of Home Affairs website.
Build a Stronger AML Compliance Framework
Get practical guidance on KYC, CDD, risk assessment, monitoring, and other AML controls tailored to your business.
Step 7: Assign a Risk Category
Risk categorisation is the hinge. Everything after this step, and much before it, is calibrated by the category assigned here.
The Institutional Risk Assessment That Comes First
The entity shall carry out Money Laundering and Terrorist Financing Risk Assessment exercises periodically across clients, countries or geographic areas, products, services, transactions and delivery channels. The assessment shall be documented, proportionate to the entity’s nature, size, geographical presence and complexity, reviewed at least annually, presented to the Board, which sets its periodicity, and made available to competent authorities.
The Customer Risk Categorisation Parameters
Customers are categorised as low, medium or high risk on the entity’s assessment and risk perception. The parameters include identity, social and financial status, nature and location of business activity; geographical risk for customers and transactions; products and services; delivery channel; and transaction types such as cash, cheque, wire transfers and foreign exchange. The entity may also factor in whether documents can be confirmed online with the issuing authority.
How the Risk Category Changes Everything After This Point
Three consequences follow. Monitoring intensity is aligned with the category, with high-risk accounts attracting more intensified monitoring. Re-KYC periodicity is set by it: at least once every two years for high-risk, eight years for medium-risk, ten years for low-risk. And the category itself must be reviewed at least once every six months. That six-month review is among the most frequently missed obligations, because it is not a re-KYC event and does not involve the customer.
Why You Cannot Tell the Customer Their Risk Category
The entity shall keep the risk categorisation, and the specific reasons for it, confidential, and shall not reveal this to the customer, to avoid tipping off. A rejection letter, a document request or an explanation of a held transaction can each disclose the category by implication, so front-line scripts should be reviewed against this provision.
Step 8: Apply Enhanced or Simplified Due Diligence Where Required
Enhanced due diligence is not a general instruction to be careful. It is a defined set of measures triggered by defined circumstances.
The PML Rules require reporting entities to apply enhanced or simplified due diligence measures on a risk-sensitive basis, in accordance with the guidelines issued by the relevant regulator. Enhanced measures are required where the customer, relationship, transaction, product, service, delivery channel or geographic exposure presents a higher money laundering or terrorist financing risk. Simplified measures may be permitted for lower-risk situations but cannot be applied where there is suspicion of money laundering or terrorist financing or where specific higher-risk circumstances apply. The reporting entity must incorporate these measures into its Customer Due Diligence Programme and maintain appropriate policies, controls and procedures for managing identified risks.
Step 9: Approve, Open and Assign Identifiers
Steps 1 to 8 produce a file. Step 9 turns that file into a customer record, and three things happen here.
After completing the required customer due diligence and resolving any applicable risk concerns, the reporting entity can approve and establish the customer relationship in accordance with its internal policies, controls and procedures. Before opening the account, the entity must ensure that the customer’s identity has been established and verified and, where applicable, that the beneficial owner and any person acting on behalf of the customer have been identified and verified. The Rules prohibit maintaining anonymous, fictitious or unverifiable accounts.
Once the relationship is established, the required KYC records and identifiers must be properly recorded and maintained. Where applicable, the reporting entity must furnish the electronic KYC records to the Central KYC Records Registry (CKYCR) within the prescribed period and retrieve updated information when notified. This ensures that the customer has a properly documented identity record that can support ongoing due diligence and monitoring throughout the relationship.
Step 10: Upload to CKYCR and Communicate the KYC Identifier
The Central KYC Records Registry is the step vendor process diagrams most often leave out, and it carries the shortest statutory clocks. The Government of India authorised CERSAI, the Central Registry of Securitisation Asset Reconstruction and Security Interest of India, to act as the CKYCR vide Gazette Notification No. S.O. 3183(E) dated November 26, 2015.
The Ten-Day Upload Deadline
Rule 9(1A) of the PML Rules, 2005 sets the primary clock. The entity shall capture the customer’s KYC records and upload them onto CKYCR within 10 days of commencement of an account-based relationship. Ten days from commencement, not from file completion or internal approval.
The Seven-Day Update Rule
The second clock is shorter. Whenever the entity obtains additional or updated information from a customer, it shall, within seven days or such period as the Central Government may notify, furnish the updated information to CKYCR, which shall update the existing customer’s records. On the cross-reference: in the PML Rules, 2005, the seven-day words appear in rule 9(1D), while rule 9(1C) is a different rule requiring the entity to seek or retrieve the KYC Identifier and not ask the customer to resubmit the same records except in defined cases.
Telling the Customer Their KYC Identifier
Rule (1B) states that once the KYC Identifier is generated by CKYCR, the entity shall ensure it is communicated to the individual or legal entity. It is a customer communication step, because the identifier is what allows the customer to avoid resubmitting documents at the next regulated entity.
Who Is Responsible for the Record You Download
Under the Rules, the reporting entity remains responsible for the KYC records it relies upon, even when the records are retrieved from the Central KYC Records Registry (CKYCR). The reporting entity must use the KYC Identifier to retrieve the client’s KYC records and should not require the client to resubmit the same information unless the existing record has changed, is incomplete, does not meet current KYC requirements, or the validity of the documents has expired.
The Rules also require the reporting entity to maintain records of the client’s identity obtained in accordance with Rule 9. Therefore, downloading or retrieving a KYC record from CKYCR does not transfer responsibility for the customer’s due diligence to the Registry. The reporting entity remains responsible for using the retrieved information appropriately and for complying with its ongoing due diligence obligations.
Streamline Your KYC & Customer Due Diligence
Strengthen customer onboarding, identity verification, risk profiling, and ongoing due diligence with professional AML support.
Step 11: Monitor the Relationship on an Ongoing Basis
Onboarding ends; the process does not. The entity shall undertake ongoing due diligence to ensure customer transactions are consistent with its knowledge about the customer, the customer’s business and risk profile, and the source of funds or wealth.
The Four Transaction Types That Must Be Monitored
As part of ongoing due diligence, regulated entities must closely monitor four categories of transactions. These include large and complex transactions, particularly those with unusual patterns, inconsistent with the customer’s normal activity, or lacking an apparent economic rationale or legitimate purpose; transactions that exceed the prescribed thresholds for particular categories of accounts; high account turnover that is inconsistent with the balance maintained in the account; and deposits of third-party cheques, drafts or similar instruments followed by large cash withdrawals. The extent of monitoring should be proportionate to the customer’s risk profile, with high-risk accounts subject to more intensive monitoring.
Monitoring Intensity Follows the Risk Category
The rules require monitoring to be aligned with the customer’s risk category. Low-risk customers may be subject to standard monitoring, while medium-risk customers require closer scrutiny based on their profile and transaction behaviour. High-risk customers must be subjected to more intensified monitoring, with greater attention to unusual activity, changes in transaction patterns, source of funds and other risk indicators. The RBI KYC Directions also require regulated entities to periodically review customer risk categorisation and assess whether enhanced due diligence measures are necessary, with such review carried out at least once every six months.
The Six-Month Risk Review
It carries a clock easy to miss because it is not the re-KYC clock. The entity shall put in place a system of periodic review of risk categorisation of accounts, at least once every six months, and shall establish the need for enhanced due diligence measures. Six months for the risk category; two, eight or ten years for the KYC record. An entity that reviews risk only at re-KYC is not compliant.
Alert Generation
The Legislation states the requirement to identify and report suspicious transactions effectively; the entity shall implement robust software that generates alerts when transactions are inconsistent with a customer’s risk categorisation and updated profile. Two inputs are named, linking Steps 7 and 12 back into Step 11. A system fed a stale risk category, or an unrefreshed profile is alerting against the wrong baseline, which is a system deficiency.
When Monitoring Produces Suspicion
Where monitoring produces suspicion, rule 8(2) of the PML Rules applies: the Principal Officer, on being satisfied that the transaction is suspicious, shall furnish the information promptly in writing by fax or electronic mail to the Director, FIU-IND. There is no day count in rule 8(2); the standard is promptness from the point of satisfaction.
Step 12: Periodic Updation
Periodic updation, commonly called re-KYC, is a step rather than a separate exercise, because it re-runs Steps 3 to 8 on an existing relationship and feeds the result back into Steps 10 and 11.
The Two, Eight and Ten-Year Clocks
Reporting entities are required to undertake a risk-based approach to periodic updation, ensuring CDD data is kept up to date and relevant, particularly where risk is high. The minimum periodicity is at least once every two years for high-risk customers, eight years for medium-risk and ten years for low-risk, from the date of opening of the account or the last KYC updation. The policy must be documented in the internal KYC policy and approved by the Board or a delegated committee.
The Self Declaration Route for Individuals
Self-declaration is permitted in limited circumstances. An individual may provide a self-declaration of the current address, even if it differs from the one recorded in Aadhaar. During periodic KYC updation, a self-declaration may also be used where there is no change in the customer’s KYC information, subject to the applicable conditions. Self-declaration does not generally replace the identity and KYC documents required for initial customer identification.
Customers Other Than Individuals
For entities such as companies, partnerships, trusts and other legal persons, the regulated entity must obtain and verify the prescribed constitutional, registration and ownership/control documents, and identify the beneficial owner and persons authorised to act on behalf of the entity. A self-declaration may be obtained for particular information where the applicable regulatory framework expressly permits it, but it does not replace the entity’s mandatory KYC/CDD requirements
Additional Measures That Apply to Every Updation
At the time of KYC updation or periodic updation, the regulated entity must ensure that the KYC documents and information held for the customer meet the current CDD standards, even where there has been no change in the customer’s information. If the documents already held are outdated or no longer meet the applicable CDD requirements, the entity must obtain the necessary updated documents. The entity must also verify the customer’s PAN, where available, against the database of the issuing authority at the time of periodic KYC updation. In addition, updated KYC information must be appropriately reflected in the CKYCR, in accordance with the applicable requirements.
The Customer's Own Thirty Day Duty
Rule 9(B) creates a duty that runs to the customer but places the advisory obligation on the entity. The entity shall advise customers that, to comply with the PML Rules, where there is any update in the documents submitted at the time of establishment of the relationship and thereafter as necessary, the customer shall submit the updated documents within 30 days of the update. Thirty days for the customer to bring the update in, seven days for the entity to push it to CKYCR. Consecutive, not concurrent.
Step 13: Retain Records
Retention is the last step of the process and the first thing examined in any inspection, because it is the only step whose failure cannot be cured after the fact.
The Retention Periods and Where They Come From
The periods are set by statute. Section 12(3) of the PMLA, 2002 requires records of transactions under section 12(1)(a) to be maintained for five years from the date of the transaction, and section 12(4) requires records of identity of clients to be maintained for five years after the business relationship has ended or the account has been closed, whichever is later.
What Must Be Kept
The reporting entities are required to make identification records and transaction data available to competent authorities on request. The Explanation is the part most retention schedules miss: identification records include the results of any analysis undertaken, such as inquiries to establish the background and purpose of complex, unusual large transactions. The obligation therefore reaches the reasoning, not only the paperwork, so alert dispositions, escalation notes and beneficial ownership working papers belong on the retention schedule alongside the OVD copies.
Non-Profit Organisation Customers and the DARPAN Portal
Section 9 of the PML rules adds a duty for one customer type. Where customers are non-profit organisations, the entity shall register the details on the DARPAN portal of NITI Aayog and shall maintain those registration records for five years after the business relationship has ended or the account has been closed, whichever is later. The definition follows the PML Rules, being any entity constituted for religious or charitable purposes referred to in clause 15 of section 2 of the Income-tax Act, 1961, registered as a trust, a society under the Societies Registration Act, 1860 or a company under section 8 of the Companies Act, 2013. The duty pairs with a reporting duty: Rule 3(1) (BA) requires a record of all transactions involving receipts by non-profit organisations of value more than rupees ten lakh, monthly reportable under Rule 8(1).
Is Your KYC Process Fully Compliant?
Get your KYC procedures reviewed by AML professionals and identify gaps that could expose your business to compliance risks.
Reporting Obligations Running Alongside the Process
The reporting stream is not a fourteenth step. It runs in parallel from the moment the first transaction occurs. The entity shall furnish to the Director, FIU-IND, the information referred to in Rule 3 of the PML Rules, 2005 in accordance with Rule 7 thereof.
The Seven Categories Under Rule 3(1)
Rule 3(1) of the PML Rules, 2005 sets out seven categories of transactions for which every reporting entity must maintain a record.
Clause | Transaction category | Threshold |
(A) | All cash transactions | More than Rs 10 lakh, or equivalent in foreign currency |
(B) | All series of cash transactions integrally connected to each other, individually valued below Rs 10 lakh, taking place within a month | Monthly aggregate exceeding Rs 10 lakh, or equivalent foreign currency |
(BA) | All transactions involving receipts by non-profit organisations | More than Rs 10 lakh, or equivalent in foreign currency |
(C) | All cash transactions where forged or counterfeit currency notes have been used as genuine, or where forgery of a valuable security or document has taken place facilitating the transaction | No monetary threshold |
(D) | All suspicious transactions, whether or not made in cash, across deposits and credits, non-monetary accounts, money transfers and remittances, loans and advances, and collection services | No monetary threshold |
(E) | All cross-border wire transfers where either the origin or destination of funds is in India | More than Rs 5 lakh, or equivalent in foreign currency |
(F) | All purchase and sale by any person of immovable property registered by the reporting entity | Valued at Rs 50 lakh or more |
The Deadlines and Why Delay Compounds
Rule 8 sets three different clocks. Under Rule 8(1), the Principal Officer shall furnish information on the transactions referred to in clauses (A), (B), (BA), (C) and (E) of Rule 3(1) every month to the Director by the 15th day of the succeeding month. Under Rule 8(2), on being satisfied that a transaction referred to in clause (D) is suspicious, the Principal Officer shall furnish the information promptly in writing by fax or by electronic mail; there is no day count in Rule 8(2), and any figure presented as the statutory STR deadline should be traced to its source before it is relied on. Under Rule 8(3), information on the clause (F) immovable property transactions is furnished every quarter, by the 15th day of the month succeeding the quarter. Rule 8(4) is not a deadline but the sanction multiplier: delay of each day in not reporting a transaction, or delay of each day in rectifying a misreported transaction beyond the time limit specified in the rule, shall constitute a separate violation.
The Reporting Infrastructure
The detailed formats, filing procedures and technical requirements are implemented through the FIU-IND’s reporting framework, with reports submitted electronically through the FINnet 2.0 platform. The reporting framework therefore operates through a combination of statutory obligations under the PMLA and PML Rules and the operational requirements specified by FIU-IND. On the enforcement side, Section 12A of the PMLA gives the Director powers to call for information and records from reporting entities, while Section 13 provides for appropriate directions and monetary penalties where a reporting entity fails to comply with its obligations. Together, these provisions create the reporting and supervisory framework through which reporting entities submit, maintain and substantiate their AML/CFT reporting obligations.
Who Owns Each Step
The process fails most often not because a step is unknown but because no named function owns it. The Directions name three roles and one function.
The KYC framework assigns responsibility across the regulated entity rather than leaving the process to a single KYC team. The Designated Director carries overall responsibility for ensuring compliance with the obligations under Chapter IV of the PMLA and the Rules, while the Principal Officer is responsible for ensuring compliance, monitoring transactions, and sharing and reporting information as required by law. The Principal Officer and Designated Director are separate roles, and the Principal Officer cannot also be designated as the Designated Director. The regulated entity must also establish clear responsibility for implementing its KYC policies, identify the relevant senior management, and provide for independent evaluation of its compliance functions.
Conclusion
KYC in India is a structured process governed primarily by the Prevention of Money laundering Act, 2002 (PMLA)and the Prevention of Money laundering (Maintenance of Records) Rules, 2005 (PML Rules), together with sector-specific KYC directions issued by regulators such as the RBI. These rules require reporting entities to identify and verify customers and beneficial owners, assess customer risk, conduct ongoing due diligence, maintain prescribed records and report relevant transactions to the FIU-IND. The framework also provides for the use of the Central KYC Records Registry (CKYCR) for maintaining and retrieving KYC records.
The process therefore extends beyond the initial collection of identity documents and continues throughout the customer relationship through risk-based monitoring, periodic updation and enhanced due diligence where required. Within a reporting entity, the Designated Director is responsible for ensuring overall compliance with the PMLA framework, while the Principal Officer oversees the implementation of AML/CFT/CPF measures and reporting obligations. By following the PMLA, PML Rules, applicable regulatory KYC directions and CKYCR requirements, regulated entities can meet their statutory obligations while strengthening the detection and prevention of money laundering, terrorist financing and other financial crime risks.
Need Help Strengthening Your KYC Process?
Get expert support to build, review, and improve your KYC and customer due diligence process in line with Indian AML requirements.
Frequently Asked Questions
The regulated entity, as a reporting entity, has overall responsibility for ensuring that KYC requirements are properly implemented and complied with. The Designated Director has overall responsibility for ensuring compliance with the obligations under the PMLA and the applicable rules, while the Principal Officer is responsible for implementing the AML/CFT framework, including monitoring transactions, ensuring that customer due diligence and KYC measures are carried out, and reporting suspicious transactions and other prescribed information to the FIU-IND. Operational responsibility is generally shared with the KYC/Compliance function and front-line staff, who collect and verify customer information, identify beneficial owners, conduct customer risk assessment and perform ongoing due diligence.
If the customer does not provide the information or documents required to establish and verify their identity, the reporting entity should not establish the relationship. For an existing customer, failure to provide required KYC information may result in restriction or closure of the account, as prescribed under the Rules and applicable regulatory guidelines.
Within 10 days of commencement of the account-based relationship, under Rule 9(1A) of the PML Rules, 2005. Where the entity later obtains additional or updated information, it must be furnished to CKYCR within seven days, or such period as may be notified by the Central Government.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik