Blog

Jurisdictions & Regulation

The Reserve Bank of India and AML/CTF Regulations

What the RBI's KYC Directions require of regulated entities: identification methods, V-CIP controls, risk review every six months, periodic updation cycles and what the RBI penalises.

The Reserve Bank of India sets AML and CTF obligations for the entities it regulates through its Know Your Customer Directions, first issued on 25 February 2016 and amended many times since. The Directions turn the Prevention of Money-laundering Act into operating rules covering identification, risk categorisation, periodic updation, screening and reporting.

Key takeaways

  • The operative instrument is the Reserve Bank of India (Know Your Customer) Directions, 2016, last amended on 14 August 2025.
  • Customer risk categorisation must be reviewed at least once every six months, and failing to do so has been a sustained charge in RBI penalty orders.
  • Periodic KYC updation runs on a two, eight and ten year cycle for high, medium and low risk customers respectively.
  • Remote onboarding is permitted only through V-CIP, which requires liveness detection, geo-tagging, PAN verification and concurrent audit before the account operates.
  • Penalties come under section 47A(1)(c) of the Banking Regulation Act, 1949, separately from FIU-IND penalties under section 13 of the PMLA.

What does the RBI's KYC Direction actually require?

The instrument is the Reserve Bank of India (Know Your Customer) Directions, 2016, issued as Master Direction DBR.AML.BC.No.81/14.01.001/2015-16 on 25 February 2016 and updated most recently on 14 August 2025. It is a consolidated direction rather than a guidance note, so each paragraph is directly enforceable.

Four blocks of obligation run through it. The first is a customer acceptance policy setting out who the entity will and will not take on, and the second is customer identification and verification, including the evidence permitted at onboarding. The third is ongoing monitoring of transactions against the expected profile of the account. The fourth is risk management, covering governance, internal audit, staff training and the two named officer roles.

Reading it as a single compliance programme rather than four separate projects matters, because the RBI examines the connections. A risk rating that never feeds monitoring thresholds, or an updation cycle that never triggers rescreening, fails even where each component exists on paper.

Which customer identification methods are permitted?

India runs a narrower list of acceptable evidence than most jurisdictions, and that list is set centrally rather than by the bank. The Directions permit officially valid documents, Aadhaar-based electronic verification where the customer submits it voluntarily, offline Aadhaar verification, and the video process described in the next section.

One restriction catches firms out. Accounts opened using the one-time-password based electronic route in non-face-to-face mode must be flagged in the Central KYC Records Registry, and other regulated entities may not open accounts on the strength of the KYC information from those accounts. Portability of a KYC record is therefore conditional on the method that produced it.

The practical consequence is that identity evidence has to be tracked by provenance, not just by outcome. Knowing that a customer is verified is insufficient; the file must record how, because the how determines what the record can later be used for. See identity verification for how document, biometric and data-source checks combine.

What does the RBI require for video-based onboarding?

The Video based Customer Identification Process is defined in the Directions as a seamless, secure, live, informed-consent based audio-visual interaction used to complete customer due diligence. The controls attached to it are unusually prescriptive, and they are technical rather than procedural.

The application must be hosted on the regulated entity's own premises within secured network domains, with end-to-end encryption between the customer's device and the hosting point. Recordings must carry live GPS coordinates and a date and time stamp. The application needs face liveness and spoof detection alongside facial recognition, and the infrastructure must pass vulnerability assessment, penetration testing and a security audit by auditors empanelled with CERT-In.

Process controls sit on top. Only specially trained officials may conduct the session, the sequence and type of questions must vary to prove the interaction is live, PAN details must be captured and verified with the issuing authority, and every V-CIP account requires concurrent audit before it becomes operational.

How does the RBI expect customer risk categorisation to work?

Risk categorisation is a control with a fixed cadence, not a rating exercise performed once. The Directions require customers to be classified as low, medium or high risk based on the entity's own assessment, and require a system of periodic review of that categorisation with a periodicity of at least once in six months.

The parameters are specified rather than left open. They include the customer's identity, social and financial status, the nature of the business activity, information about the customer's business and its location, geographical risk covering both customers and transactions, the type of products and services offered, and the delivery channel used.

Risk categoryMinimum periodic updationSix-monthly categorisation review
High riskAt least once every two yearsRequired
Medium riskAt least once every eight yearsRequired
Low riskAt least once every ten yearsRequired

The two clocks are separate and are often confused. Updation refreshes the customer's KYC record. Review re-asks whether the risk rating is still right, and it happens far more frequently. Continuous transaction monitoring is what makes the six-month review evidence-based rather than a rubber stamp.

Who must a regulated entity appoint, and for what?

Two roles are mandatory and cannot be held by the same person. The Designated Director is nominated by the board and is accountable for overall compliance with the obligations imposed under chapter IV of the PMLA and the Rules made under it.

The Principal Officer is responsible for ensuring compliance, monitoring transactions, and sharing and reporting information as required by law. The name, designation, address and contact details of both must be communicated to FIU-IND and to the RBI, and kept current when either role changes hands.

Separating the roles is the point. The Designated Director carries board-level accountability that cannot be discharged by the person running the day-to-day filings, which is what prevents an entire programme from resting on one officer's judgement. FIU-IND's own mandate and reporting line to the Economic Intelligence Council explains why it wants a named board-level contact.

What screening does the RBI expect against sanctions and PEP lists?

The Directions require a suitable system to ensure that the identity of a customer does not match any person or entity whose name appears in the sanctions lists set out in the Directions themselves. That is a systems obligation, not a lookup performed at the discretion of the onboarding team.

Two design points follow from the wording. Screening has to run against the verified customer record rather than a free-text string typed at account opening, otherwise a later change to the record never re-triggers a check. And because designations change between review cycles, the list refresh interval, not the customer review interval, sets the real detection lag.

Politically exposed persons are handled alongside this in the customer acceptance and enhanced due diligence provisions rather than in the sanctions paragraph. Our explainer on politically exposed persons sets out the categories, and PEP and sanctions screening covers how continuous rescreening closes the gap between reviews.

Which entities does the RBI's KYC framework cover?

The Directions apply to regulated entities, a term that extends well beyond scheduled commercial banks. It covers co-operative banks, all-India financial institutions, non-banking financial companies, payment system operators and other entities licensed or registered by the RBI, each of which sits within the wider Indian AML regime built on the PMLA.

Scope questions arise most often with fintech firms operating through a licensed partner. The obligation sits with the regulated entity, and outsourcing an onboarding journey does not move it. Where a third party performs identification, the regulated entity remains answerable for the quality of the record and for its upload to the Central KYC Records Registry.

Entities regulated by SEBI or IRDAI follow their own sector instruments instead, though the statutory basis is identical. A group with a bank, a broking arm and an insurer therefore runs three rule sets over one customer base. The India country coverage page sets out how the supervisory split works.

What does the RBI actually penalise?

Enforcement is granular and it targets missing systems rather than individual customer files. On 14 August 2025 the RBI announced a penalty of Rs 2.50 lakh on a Vadodara co-operative bank by an order dated 8 August 2025, imposed under section 47A(1)(c) read with sections 46(4)(i) and 56 of the Banking Regulation Act, 1949.

The sustained charges are instructive. Among them was a failure to carry out periodic review of the risk categorisation of certain accounts with a periodicity of at least once in six months, alongside failures in internal audit and asset classification. The finding came from a statutory inspection referenced to the bank's financial position as at 31 March 2024, so the lag between the control failure and the order was over a year.

Two enforcement tracks run in parallel and firms should budget for both. The RBI acts under the Banking Regulation Act for supervisory breaches, while FIU-IND acts under section 13 of the PMLA for reporting and record-keeping failures. More jurisdiction analysis sits in our jurisdictions and regulation collection.

FAQ

Common questions.

What is the RBI's main AML/CTF instrument?
The Reserve Bank of India (Know Your Customer) Directions, 2016, issued on 25 February 2016 as Master Direction DBR.AML.BC.No.81/14.01.001/2015-16 and most recently amended on 14 August 2025. It gives effect to the Prevention of Money-laundering Act, 2002 and the 2005 Maintenance of Records Rules for entities the RBI regulates.
How often must an Indian bank review a customer's risk category?
At least once every six months. The RBI's KYC Directions require a system of periodic review of the risk categorisation of accounts with that periodicity, and failure to do it is a charge the RBI has sustained in penalty proceedings.
How often must KYC records be updated in India?
At least once every two years for high-risk customers, once every eight years for medium-risk customers and once every ten years for low-risk customers, measured from the date of the last KYC update. These are minimum intervals, not a substitute for event-driven review.
Can an Indian bank onboard a customer remotely?
Yes, through the Video based Customer Identification Process. The RBI requires the application to be hosted on the regulated entity's own premises with end-to-end encryption, geo-tagged and time-stamped recording, liveness and spoof detection, PAN verification with the issuing authority, and a concurrent audit of every V-CIP account before it becomes operational.
Who must a regulated entity appoint under the RBI's KYC framework?
A Designated Director nominated by the board, who is accountable for overall compliance with chapter IV of the PMLA and the Rules, and a separate Principal Officer responsible for monitoring transactions and reporting. The same person cannot hold both roles, and both must be notified to FIU-IND and the RBI.
What penalties can the RBI impose for KYC failures?
The RBI imposes monetary penalties under section 47A(1)(c) read with sections 46(4)(i) and 56 of the Banking Regulation Act, 1949. Amounts on co-operative banks commonly run from tens of thousands to a few lakh rupees. Administrative penalties under section 13 of the PMLA sit separately with FIU-IND.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.