Last Updated on: 24th August 2026 | Last Reviewed on: 24th August 2026
Key Takeaways
- KYC is the identity layer of a wider anti-money laundering programme. It answers one question: is this customer who they say they are?
- The obligation comes from the Prevention of Money-Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005. Your sector regulator then sets the mechanics.
- It applies to every ‘reporting entity’ like banks, financial institutions, intermediaries, and designated non-financial businesses and professions.
- There are six Officially Valid Documents. A of two months old or tax receipt is only a stop-gap for proof of address.
- KYC is not a single event. It must be refreshed periodically, that is, at least once every 2 years for high-risk, 8 years for medium-risk and 10 years for low-risk customers.
Quick Answer: What KYC Means in India
KYC, or Know Your Customer, is the process a regulated business in India uses to establish and verify the identity of its customer before and throughout the business relationship. It is mandatory under the Prevention of Money-Laundering Act, 2002, and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. It is enforced sector by sector by the RBI, SEBI, IRDAI, PFRDA, IFSCA and FIU-IND.
KYC Meaning: Know Your Customer Explained in Simple Terms
Know Your Customer (KYC) refers to the process by which a regulated business identifies and verifies a customer and obtains the information needed to understand the customer and the relationship. In everyday use, doing your KYC means submitting an identity document and an address document. In regulation, it means more: identify the customer, verify that identity from reliable and independent sources, understand why they want the relationship, and keep watching it for as long as it lasts. “Know your client” is the same thing; securities and pensions prefer using “client”, banking prefers using “customer”.
What "Know Your Customer" Actually Requires a Business to Do
Four obligations sit inside the phrase. Identification: collect the customer’s identity details. Verification: check them against a reliable and independent source, the standard the PML Rules set for client due diligence. Purpose: understand the nature of the relationship sought. Ongoing monitoring: keep the information current and keep watching the transactions.
KYC vs Customer Due Diligence vs AML: How the Three Fit Together
These three terms are used loosely in vendor marketing, and the confusion causes real compliance gaps. KYC sits inside CDD, and CDD sits inside the AML programme.
Layer | What it covers | Where it comes from |
KYC | The identity layer. Who is this customer, and can I prove it from an independent source? | PML Rules, 2005 read with your regulator’s KYC directions |
Customer Due Diligence (CDD) | The risk layer. Having identified the customer, what is their risk rating, who is the beneficial owner, and how much scrutiny does this relationship need? | PMLA sections 11A and 12AA; Rule 9 of the PML Rules |
AML / CFT programme | The whole control environment. Policy, governance, risk assessment, screening, monitoring, reporting, record-keeping, training and audit. | PMLA Chapter IV, the PML Rules, and sectoral master directions and guidelines |
So, KYC sits inside CDD, and CDD sits inside the AML programme. A business can have perfect KYC files and still fail an AML inspection.
Why KYC Exists: The Problem It Is Designed to Solve
Money laundering is facilitated when criminals can conceal their identity, ownership or control of assets and transactions. KYC reduces that risk by requiring regulated businesses to identify and verify customers and understand the relationships they maintain. If value moves through the financial system without a verified name attached to it, tracing and confiscation become almost impossible. KYC removes that anonymity at the point of entry.
The Financial Action Task Force (FATF) was established in 1989 by its member jurisdictions to set international standards for combating money laundering, terrorist financing and, today, proliferation financing. Customer due diligence is a core component of those standards, principally reflected in FATF Recommendations.
India’s AML/CFT framework is assessed against these international standards. In 2024, a joint FATF/APG/EAG mutual evaluation assessed India’s technical compliance with the FATF Recommendations and the effectiveness of its AML/CFT system. The report was adopted in June 2024 and published in September 2024.
Is KYC Mandatory in India? The Law Behind It
Yes. KYC is a statutory and regulatory obligation in India. A reporting entity must complete the applicable customer identification and due-diligence requirements before establishing a relationship and must continue to comply with ongoing KYC requirements throughout the relationship, subject to the specific rules and exceptions applicable to that entity and customer.
The Prevention of Money-Laundering Act, 2002 and the PML Rules, 2005
The Act creates the obligation; the Rules set the mechanics. The PMLA establishes core obligations for reporting entities, while the PML Rules and sector-specific regulatory directions provide detailed requirements for customer identification, due diligence, record-keeping and reporting. Chapter IV of the PMLA carries the operative duties: section 11A on verification of identity by a reporting entity, section 12 on maintaining records of prescribed transactions and of client identity, section 12A on the Director of FIU-IND’s power to call for information, and section 12AA on enhanced due diligence before certain transactions. Under the Act, the PML (Maintenance of Records) Rules, 2005 do the detailed work: Rule 3 lists the transactions to be recorded and reported, Rule 7 sets the procedure for furnishing information and requires the Principal Officer’s details to be communicated to the Director, and Rule 9 governs client due diligence and the upload of KYC records to the Central KYC Records Registry.
Who Counts as a "Reporting Entity" Under PMLA
Section 2(1)(wa) of the PMLA defines a reporting entity as a banking company, financial institution, intermediary, or a person carrying on a designated business or profession. That last category is the one businesses underestimate: it brings in real estate agents, dealers in precious metals and stones, trust and company service providers, practising chartered accountants, company secretaries and cost accountants performing specified activities, and virtual digital asset service providers. The reporting entity must designate a Designated Director and a Principal Officer for the purposes prescribed under the PMLA and Rules.
Which Regulator's KYC Rules Apply to You
This is the most common source of error in Indian KYC content. The PMLA is common to everyone; the operating instrument is not.
Entity type | Regulator | Current governing instrument |
Commercial banks | RBI | Reserve Bank of India (Commercial Banks – Know Your Customer) Directions, 2025 dated 28 November 2025, updated as on 29 December 2025 |
NBFCs | RBI | Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Directions, 2025 dated 28 November 2025, updated as on 29 December 2025 |
Securities Market Intermediaries | SEBI | Master Circular dated 6 June 2024 (AML/CFT obligations), read with the Master Circular on KYC Norms for the Securities Market dated 12 October 2023, as amended and updated |
Insurers | IRDAI | Master Guidelines on AML/CFT, 2022 dated 1 August 2022, in force from 1 November 2022, as amended |
Pension sector (PoPs, NPS Trust) | PFRDA | Master Circular updated as on 25 September 2025, as amended |
IFSC Entities (GIFT City) | IFSCA | IFSCA AML, CTF and KYC Guidelines, 2022, updated as on 26 February 2026 |
Virtual Digital Asset Service Providers | Director, FIU-IND | Designated by Ministry of Finance notification S.O. 4877(E) dated 9 November 2023; AML/CFT Guidelines for reporting entities providing services related to virtual digital assets, updated 8 January 2026 |
What Changed on 28 November 2025 and Why Older KYC References Need Updating
On 28 November 2025, the Reserve Bank reorganised the instructions administered by its Department of Regulation. Instructions in approximately 3,500 directions, circulars and guidelines were consolidated into 238 function-wise Master Directions across 11 types of regulated entities. Counting seven new Master Directions on Digital Banking Channels Authorisation issued the same day, 244 documents were released, alongside a list of 9,445 circulars being repealed or withdrawn. The RBI stated that these Master Directions will serve as the sole library of regulations administered by the Department of Regulation. (RBI Press Release 2025-2026/1588, 28 November 2025.)
The consequence for KYC is specific: the single, all entity Master Direction Know Your Customer Direction, 2016 no longer applies. It was withdrawn and replaced by entity specific 2025 KYC Directions. Any article, internal policy, training deck or audit checklist that still cites the 2016 Master Direction is citing a withdrawn instrument. If you maintain a compliance manual, this is the paragraph to act on.
Strengthen Your KYC & Customer Due Diligence
Improve customer onboarding, beneficial ownership checks, risk categorisation and ongoing KYC monitoring with expert support.
KYC Methods and Verification Routes in India
Indian regulation permits five broad routes, and which one you may use depends on the customer, the product and the risk. Paragraph references below are to the RBI (Commercial Banks Know Your Customer) Directions, 2025; other sectors follow comparable structures.
In Person Verification (Physical KYC)
The traditional route. The customer presents an original Officially Valid Document, an authorised officer compares the copy against the original and records that comparison on the copy, and a photograph is taken. That is what the Directions mean by a “certified copy”. Where face to face verification is used, the authorised official verifies the customer’s identity document against the original and records the prescribed certification. The applicable Directions also permit other prescribed verification routes.
Aadhaar Based e KYC: OTP and Biometric
Authentication under section 11A of the PMLA allows identity to be established electronically. Accounts opened using Aadhaar OTP based e KYC in non face to face mode carry conditions: specific customer consent to OTP authentication, and transaction alerts and OTPs sent only to the Aadhaar registered mobile number, with requests to change that number handled under a Board approved due diligence process. Because the route carries hard product and value limits, treat it as a constrained channel rather than a general purpose one.
Digital KYC Process
“Digital KYC” has a precise regulatory meaning in India and is not a synonym for online onboarding. Under paragraph 24, the bank must build an authenticated application, make it available at customer touchpoints, control access through a login and password or live OTP mechanism, and undertake KYC only through that application. Critically, the customer must visit the authorised official or the official must visit the customer, with the original OVD in the customer’s possession at that moment.
Video Based Customer Identification Process (V-CIP)
V-CIP is a live, consent based audio visual customer identification process that the applicable RBI Directions recognise as a permitted customer identification method, subject to prescribed technological, security, recording, audit trail and other requirements. It allows it for due diligence on new individual customers, on the proprietor of a proprietorship firm, and on authorised signatories and beneficial owners of legal entity customers; for converting existing accounts opened through Aadhaar OTP based e-KYC; and for periodic updation for eligible customers.
Central KYC Records Registry (CKYC) and the KYC Identifier
The Central KYC Records Registry (CKYCR) is a central repository for KYC records. It allows reporting entities to retrieve KYC information using the customer’s KYC Identifier, subject to the conditions prescribed under the PML Rules and applicable regulatory directions. The Government authorised CERSAI to act as the Central KYC Records Registry following amendments to the PML Rules for this purpose.
Rule 9 contains the framework governing submission and retrieval of KYC records. Where a customer already has a KYC Identifier, the reporting entity should retrieve the available KYC records in accordance with the applicable requirements rather than unnecessarily collecting information that is already available.
However, CKYCR does not eliminate the reporting entity’s own CDD obligations. The institution must still establish that the retrieved information is adequate for the relationship and must obtain additional information or documents where required, including where information is incomplete, outdated or inconsistent or where the customer’s risk requires enhanced due diligence.
Which Type Applies to Which Customer
Customer situation | Usual route | Watch-out |
Resident individual, walk in, standard product | In person verification or Digital KYC | Certified copy comparison must be recorded on the copy |
Resident individual, remote onboarding | V-CIP, or Aadhaar OTP e-KYC | OTP route carries limits; alerts must go only to the Aadhaar-registered mobile |
Existing customer already on CKYCR | Retrieve records via the KYC Identifier | You still owe ongoing due diligence and periodic updation |
Company, partnership, trust, association | In person or V-CIP of signatories and beneficial owners | Entity documents plus CDD on every natural person behind the entity |
Foreign student opening an NRO account | Passport with visa and immigration endorsement, plus admission letter | Local address declaration within 30 days; capped operations until verified; Pakistani nationality needs prior RBI approval |
KYC Documents Required in India
The Six Officially Valid Documents
Paragraph 5(1)(xiv) of the Commercial Banks KYC Directions, 2025 defines an Officially Valid Document exhaustively. There are six:
- Passport
- Driving licence
- Proof of possession of Aadhaar number, which may be submitted in the form issued by the Unique Identification Authority of India
- Voter’s Identity Card issued by the Election Commission of India
- The job card issued by NREGA, duly signed by an officer of the State Government
- The letter issued by the National Population Register containing details of name and address
A PAN card, employee identity card, bank passbook or ration card is not an OVD under this definition. Such documents may, however, be relevant for other regulatory or customer identification purposes where specifically permitted.
When a Utility Bill or Tax Receipt Can Be Used as Proof of Address
If a customer’s OVD does not carry their current address, a limited set of documents is deemed to be an OVD for the sole purpose of proof of address: a utility bill not more than two months old from a service provider of electricity, telephone, post paid mobile, piped gas or water; a property or municipal tax receipt; a pension or family pension payment order issued to a retired employee by a government department or public sector undertaking, if it contains the address; and a letter of allotment of accommodation, or a leave and licence agreement, from a qualifying government department, statutory or regulatory body, public sector undertaking, scheduled commercial bank, financial institution or listed company. This is a bridge, not a destination. The customer must submit an OVD carrying the current address within three months. Institutions that never close that loop are carrying an open finding.
PAN and the Documents That Sit Alongside an OVD
PAN, or its equivalent e-document, sits alongside the OVD rather than replacing it, and must be quoted where required. For existing customers the Directions require the bank to obtain PAN or Form No. 60 by such date as the Central Government may notify, failing which operations in the account must be temporarily ceased. PAN details on file must also be verified against the issuing authority’s database at periodic updation.
KYC Documents for Companies, Partnerships and Trusts
Legal entities need two things: documents proving the entity exists and is authorised to act, and full customer due diligence on the natural persons behind it. A company file typically requires the certificate of incorporation, the memorandum and articles of association, a board resolution or power of attorney authorising the persons who will operate the account, and OVDs plus PAN for those persons and for the beneficial owners. A partnership requires the registration certificate and partnership deed; a trust, the registration certificate and trust deed; an unincorporated association or body of individuals, the resolution of its managing body and a power of attorney. Sole proprietorships additionally require activity proofs for the firm.
Documents for Foreign Nationals and Non Resident Customers
For non resident Indians and persons of Indian origin the Directions relax how a copy may be certified, recognising certification abroad through prescribed channels. Foreign students may open a Non Resident Ordinary account on a passport bearing proof of identity and address in the home country with visa and immigration endorsement, a photograph, and an admission letter from the Indian institution. A local address declaration must follow within 30 days, and until it is verified the account operates with a cap of USD 1,000 or equivalent on inward foreign remittances and Rs 50,000 on aggregate withdrawals in that period. Students of Pakistani nationality require prior RBI approval.
The KYC Process, Step by Step
The Four Stages: Acceptance, Identification, Risk Profiling, Monitoring
Acceptance comes first: the Customer Acceptance Policy decides whether the customer may be onboarded at all, and it must not be applied to deny banking services to ordinary members of the public. Identification follows, through one of the permitted routes. Risk profiling then assigns the customer to a low, medium or high risk category. Monitoring runs for the life of the relationship, aligned in intensity to that category.
One nuance worth flagging: an institution may rely on customer due diligence carried out by a regulated third party for onboarding, or for occasional transactions of Rs 50,000 or more and international money transfers but only on strict conditions, including immediate access to the records, a supervised third party not based in a high risk jurisdiction, and ultimate responsibility for CDD staying with the relying institution.
How Risk Categorisation Drives Everything Downstream
Risk categorisation is not an administrative label. It determines how much documentation you collect, whether enhanced due diligence applies, how closely transactions are monitored, and how often KYC must be refreshed. The Directions require categorisation into low, medium and high risk on parameters including the customer’s identity, social and financial status, nature and location of business activity, geographic risk, products and services used, delivery channel and transaction types. The rating and its reasons must be kept confidential and must not be disclosed to the customer, to avoid tipping off.
Need End-to-End AML Compliance Support?
From KYC and CDD to AML policies, monitoring and regulatory compliance, get tailored support for your organisation.
KYC Rules Every Regulated Entity Must Follow
A Board Approved KYC Policy and the Four Elements RBI Requires
Every regulated entity must have a KYC policy approved by the Board or a committee to which the Board has delegated the power. It must contain four key elements: a Customer Acceptance Policy, risk management, Customer Identification Procedures, and monitoring of transactions. It must also address periodic updation, any exceptional measures the entity applies, when a copy of an OVD will be required for a change of address, and whether updation will be offered at any branch.
Designated Director and Principal Officer
Two named individuals carry personal accountability. The Designated Director, defined in Rule 2(ba) of the PML Rules, is a Board nominated person responsible for overall compliance with Chapter IV of the PMLA and the Rules; for a company this is the Managing Director or a duly authorised whole time Director. The Principal Officer is responsible for ensuring compliance, monitoring transactions, and sharing and reporting information. Both sets of details must be communicated to FIU-IND and to the RBI. And a rule missed surprisingly often: the Principal Officer must not be nominated as the Designated Director.
Beneficial Ownership Identification
Identifying the natural person behind a legal entity is where most KYC programmes are weakest. The thresholds are: for a company, ownership of or entitlement to more than 10 per cent of shares, capital or profits, or control through other means; for a partnership firm, more than 10 per cent of capital or profits, or control; for an unincorporated association or body of individuals, including societies, more than 15 per cent of property, capital or profits. For a trust, identification must extend to the author of the trust, the trustee, beneficiaries with 10 per cent or more interest, and any natural person exercising ultimate effective control through a chain of control or ownership. Where no natural person is identified, the beneficial owner is the relevant natural person holding the position of senior managing official.
Enhanced Due Diligence and Politically Exposed Persons
Enhanced due diligence applies where risk is higher, including non face to face onboarding. The Directions define politically exposed persons as individuals entrusted with prominent public functions by a foreign country, including heads of state or government, senior politicians, senior government, judicial or military officers, senior executives of state owned corporations and important political party officials. A relationship with a PEP, as customer or beneficial owner, requires systems to detect PEP status, reasonable measures to establish source of funds and wealth, senior management approval to open the account, and enhanced ongoing monitoring. Where an existing customer or beneficial owner subsequently becomes a PEP, senior management approval is needed to continue. The same requirements extend to family members and close associates.
Sanctions and Watchlist Screening
Screening is a daily obligation, not a periodic one. Under section 51A of the Unlawful Activities (Prevention) Act, 1967, an entity must ensure it holds no account for individuals or entities on the UNSC lists the ISIL (Da’esh) and Al-Qaida Sanctions List maintained under resolutions 1267, 1989 and 2253, and the Taliban Sanctions List maintained under resolution 1988 (2011) and must also refer to the schedules to the Prevention and Suppression of Terrorism (Implementation of Security Council Resolutions) Order, 2007. Those lists must be verified on a daily basis and every addition, deletion or change acted on. The UNSCR 1718 Sanctions List relating to the Democratic People’s Republic of Korea must likewise be checked every day. Matches must be reported to FIU-IND and advised to the Ministry of Home Affairs, and the freezing procedure in the UAPA Order dated 2 February 2021 followed.
Record Keeping and Retention
Transaction records must be kept for at least five years from the date of the transaction. Records identifying customers and their addresses, obtained at onboarding and during the relationship, must be preserved for at least five years after the relationship ends. Records must permit reconstruction of an individual transaction, its nature, amount and currency, date and parties, and be retrievable swiftly for competent authorities. Identification records include updated identification data, account files, business correspondence and the results of any analysis undertaken.
Reporting to FIU-IND
Reporting entities furnish prescribed information to the Director FIU-IND, under Rule 3 read with Rule 8. In broad terms this covers cash transactions above Rs 10 lakh; series of connected cash transactions individually below Rs 10 lakh where the monthly aggregate exceeds Rs 10 lakh; receipts by non profit organisations above Rs 10 lakh; counterfeit currency and forged security transactions; all suspicious transactions, whether or not in cash; cross border wire transfers above Rs 5 lakh where either origin or destination is in India; and purchases and sales of immovable property valued at Rs 50 lakh or more registered by the entity. Alert generation must be driven by software that flags transactions inconsistent with a customer’s risk categorisation and updated profile.
How Often Must KYC Be Updated?
Periodic Updation Periodicity for High, Medium and Low Risk Customers
The approach is risk based, with mandatory outer limits. Under paragraph 42 of the Commercial Banks KYC Directions, 2025, periodic updation must be carried out at least once every two years for high risk customers, once every eight years for medium risk customers and once every ten years for low risk customers, counted from the date of account opening or the last KYC updation. The policy giving effect to this must be documented and Board approved.
There is also a transitional relief worth knowing. For an individual customer categorised as low risk, the bank must allow all transactions and ensure KYC updation within one year of it falling due, or up to 30 June 2026, whichever is later, with the account subject to regular monitoring. This applies equally where periodic updation had already fallen due.
Customers must be given advance notice: at least three advance intimations before the due date, including at least one by letter, and at least three reminders afterwards, including at least one by letter, all recorded in the system for audit trail.
What Happens When Nothing Has Changed
Where there is no change in KYC information, a self declaration from the customer is enough. It may be given through the email address or mobile number registered with the bank, ATMs, digital channels such as internet banking or the bank’s mobile application, or by letter, and may be collected through an authorised Business Correspondent. Legal entity customers may also self declare but must confirm that beneficial ownership information on record is accurate and update it if not.
What Happens When Only the Address Has Changed
Where only the address has changed, the customer gives a self declaration of the new address through the same channels, and the institution must then verify the declared address through positive confirmation within two months by address verification letter, contact point verification, deliverables or similar. Separately, customers are required to submit updates to previously submitted documents within 30 days of the update.
Re-KYC When a Minor Turns 18 or Documents Have Expired
Where the validity of the customer due diligence documents on file has expired at the time of periodic updation, the institution must undertake a KYC process equivalent to onboarding a new customer. The same equivalence applies to a legal entity customer whose KYC information has changed. For accounts opened when the customer was a minor, fresh photographs must be obtained on the customer becoming a major and current CDD standards must be met.
Talk to an AML Consultant About Your KYC Requirements
Tell us about your business and compliance requirements. Our experts can help you identify the right KYC and AML controls.
What Happens If You Do Not Complete KYC?
Consequences for Customers
Accounts can be restricted, and eventually operations can cease, where KYC is not completed or PAN or Form 60 is not furnished by the notified date. One widely believed myth deserves correcting: an institution must not place any restriction on operations in an account merely because a suspicious transaction report has been filed. Filing an STR is an intelligence step, not a customer sanction, and the fact of filing is confidential.
Consequences for Regulated Entities
Under section 13(2) of the PMLA, if the Director of FIU-IND finds on inquiry that a reporting entity, its Designated Director on the Board or any of its employees has failed to comply with the obligations under Chapter IV, the Director may issue a warning in writing, direct compliance with specific instructions, direct periodic reports on the measures being taken, or by order impose a monetary penalty of not less than Rs 10,000 and up to Rs 1,00,000 for each failure. The Director may also direct a special audit of records.
The multiplier matters more than the headline figure. When furnishing information to the Director, a delay of each day in reporting a transaction, or each day’s delay in rectifying a misrepresented transaction beyond the prescribed time limit, constitutes a separate violation. A single late report held open for weeks is not one failure.
The Money Mule Rule Compliance Teams Miss
The Directions require diligence and meticulous monitoring to identify accounts operated as money mules accounts used to launder the proceeds of phishing, identity theft and similar fraud through recruited third parties. The sting is in the deeming provision: if it is established that an account is that of a money mule, but no suspicious transaction report was filed, the bank is deemed not to have complied with the Directions.
KYC Compliance Checklist for Regulated Entities
Use this as a self-assessment. Any “no” is a remediation item.
- Board-approved KYC policy in place, covering all four required elements and periodic updation
- Designated Director and Principal Officer appointed, with the two roles held by different people, and both notified to FIU-IND and the sector regulator
- The correct current instrument identified for your entity type for banks and NBFCs, the 2025 KYC Directions, not the withdrawn 2016 Master Direction
- Customer Acceptance Policy applied without denying service to ordinary customers, and applied with due consideration rather than mechanically
- Documented ML/TF risk assessment, with customers categorised as low, medium or high risk and the rating kept confidential
- Only the six Officially Valid Documents accepted as OVDs; deemed OVDs tracked and closed out within three months
- Beneficial owners identified at the correct thresholds, that is, 10 per cent (company), 10 per cent (partnership), 15 per cent (unincorporated association/body of individuals) and 15 per cent for trust beneficiaries, with senior managing official as fallback
- PEP screening covering the customer, the beneficial owner, family members and close associates, with senior management approval on file
- UNSC and UAPA schedule lists, and the UNSCR 1718 list, screened daily with change logs retained
- KYC records uploaded to CKYCR within ten days of commencing the relationship, and KYC Identifiers communicated to clients in writing
- Periodic updation tracked at 2, 8 and 10 years, with three advance intimations and three reminders evidenced
- Transaction monitoring software generating alerts against risk category and updated profile
- CTR, STR, NPO, counterfeit, cross-border wire transfer and immovable property reports filed within prescribed timelines, with no operational restriction imposed merely because an STR was filed
- Records retained five years from transaction date and five years after the relationship ends, retrievable on request
- Employee hiring due diligence and periodic AML/CFT training completed and documented
Conclusion
KYC, or Know Your Customer, is the verified-identity foundation of every anti-money laundering programme in India. The obligation comes from the Prevention of Money-Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005; the operating detail comes from your sector regulator for banks and NBFCs, the entity-specific Reserve Bank of India Know Your Customer Directions, 2025 issued on 28 November 2025 and updated as on 29 December 2025, and for other sectors the instruments named in the regulator table above.
If you are a customer, check which of the six OVDs you hold and whether your KYC is due for refresh. If you are a compliance officer, confirm that your policy, training material and audit checklist cite the current instrument rather than the withdrawn 2016 Master Direction.
Need Help With Your KYC Compliance?
Make your KYC process more effective with expert guidance on customer identification, verification, risk assessment and ongoing monitoring.
Frequently Asked Questions
KYC stands for Know Your Customer. In the securities and pension sectors, it is often written as Know Your Client. The two terms carry the same regulatory meaning.
Yes. It is a statutory obligation on every reporting entity under Chapter IV of the Prevention of Money-Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005, and it is not optional or waivable by the institution or the customer.
The Prevention of Money-Laundering Act, 2002, read with the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. Sector regulators RBI, SEBI, IRDAI, PFRDA, IFSCA and FIU-IND then prescribe how the obligation is to be discharged.
Passport, driving licence, proof of possession of Aadhaar number, Voter’s Identity Card issued by the Election Commission of India, the NREGA job card signed by a State Government officer, and the National Population Register letter containing name and address.
Yes, through defined routes: Aadhaar OTP-based e-KYC in non-face-to-face mode, subject to consent and mobile-number conditions; the Video-based Customer Identification Process; and retrieval of existing records from the Central KYC Records Registry. Note that the regulatory term “Digital KYC” describes a supervised process in which the customer and an authorised official are in the same location.
There is no single expiry date. KYC must be refreshed on a risk-based basis, and in any event at least once every two years for high-risk customers, eight years for medium-risk and ten years for low-risk, measured from account opening or the last updation.
KYC is the verification process an institution carries out. CKYC refers to the Central KYC Records Registry operated by CERSAI, where those verified records are stored centrally so that another regulated entity can retrieve them instead of collecting documents again.
It is the 14-digit unique number the Central KYC Records Registry issues against your KYC record. Your reporting entity must communicate it to you in writing, and you can also access it on the CKYCR portal at ckycindia.in.
No. Proof of possession of Aadhaar number is one of the six Officially Valid Documents, not the only one. Aadhaar-based authentication routes are permitted under section 11A of the PMLA where applicable, but a customer may present another OVD instead.
Under section 13(2) of the PMLA the Director of FIU-IND may issue a written warning, direct compliance, direct periodic reporting, or impose a monetary penalty of not less than Rs 10,000 and up to Rs 1,00,000 for each failure. Each day’s delay in reporting or in rectifying a misreported transaction is a separate violation.
Yes. Legal entities must provide constitutional and authorisation documents, and the institution must additionally carry out customer due diligence on authorised signatories and on beneficial owners identified at the prescribed thresholds.
Yes, substantially. On 28 November 2025 the RBI replaced the single all-entity Master Direction – Know Your Customer Direction, 2016 with entity-specific 2025 KYC Directions, as part of consolidating approximately 3,500 instructions into 238 function-wise Master Directions across 11 categories of regulated entities, with 9,445 circulars repealed or withdrawn.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik