The Reserve Bank of India sets AML and CTF obligations for the entities it regulates through its Know Your Customer Directions, first issued on 25 February 2016 and amended many times since. The Directions turn the Prevention of Money-laundering Act into operating rules covering identification, risk categorisation, periodic updation, screening and reporting.
Key takeaways
- The operative instrument is the Reserve Bank of India (Know Your Customer) Directions, 2016, last amended on 14 August 2025.
- Customer risk categorisation must be reviewed at least once every six months, and failing to do so has been a sustained charge in RBI penalty orders.
- Periodic KYC updation runs on a two, eight and ten year cycle for high, medium and low risk customers respectively.
- Remote onboarding is permitted only through V-CIP, which requires liveness detection, geo-tagging, PAN verification and concurrent audit before the account operates.
- Penalties come under section 47A(1)(c) of the Banking Regulation Act, 1949, separately from FIU-IND penalties under section 13 of the PMLA.
What does the RBI's KYC Direction actually require?
The instrument is the Reserve Bank of India (Know Your Customer) Directions, 2016, issued as Master Direction DBR.AML.BC.No.81/14.01.001/2015-16 on 25 February 2016 and updated most recently on 14 August 2025. It is a consolidated direction rather than a guidance note, so each paragraph is directly enforceable.
Four blocks of obligation run through it. The first is a customer acceptance policy setting out who the entity will and will not take on, and the second is customer identification and verification, including the evidence permitted at onboarding. The third is ongoing monitoring of transactions against the expected profile of the account. The fourth is risk management, covering governance, internal audit, staff training and the two named officer roles.
Reading it as a single compliance programme rather than four separate projects matters, because the RBI examines the connections. A risk rating that never feeds monitoring thresholds, or an updation cycle that never triggers rescreening, fails even where each component exists on paper.
Which customer identification methods are permitted?
India runs a narrower list of acceptable evidence than most jurisdictions, and that list is set centrally rather than by the bank. The Directions permit officially valid documents, Aadhaar-based electronic verification where the customer submits it voluntarily, offline Aadhaar verification, and the video process described in the next section.
One restriction catches firms out. Accounts opened using the one-time-password based electronic route in non-face-to-face mode must be flagged in the Central KYC Records Registry, and other regulated entities may not open accounts on the strength of the KYC information from those accounts. Portability of a KYC record is therefore conditional on the method that produced it.
The practical consequence is that identity evidence has to be tracked by provenance, not just by outcome. Knowing that a customer is verified is insufficient; the file must record how, because the how determines what the record can later be used for. See identity verification for how document, biometric and data-source checks combine.
What does the RBI require for video-based onboarding?
The Video based Customer Identification Process is defined in the Directions as a seamless, secure, live, informed-consent based audio-visual interaction used to complete customer due diligence. The controls attached to it are unusually prescriptive, and they are technical rather than procedural.
The application must be hosted on the regulated entity's own premises within secured network domains, with end-to-end encryption between the customer's device and the hosting point. Recordings must carry live GPS coordinates and a date and time stamp. The application needs face liveness and spoof detection alongside facial recognition, and the infrastructure must pass vulnerability assessment, penetration testing and a security audit by auditors empanelled with CERT-In.
Process controls sit on top. Only specially trained officials may conduct the session, the sequence and type of questions must vary to prove the interaction is live, PAN details must be captured and verified with the issuing authority, and every V-CIP account requires concurrent audit before it becomes operational.
How does the RBI expect customer risk categorisation to work?
Risk categorisation is a control with a fixed cadence, not a rating exercise performed once. The Directions require customers to be classified as low, medium or high risk based on the entity's own assessment, and require a system of periodic review of that categorisation with a periodicity of at least once in six months.
The parameters are specified rather than left open. They include the customer's identity, social and financial status, the nature of the business activity, information about the customer's business and its location, geographical risk covering both customers and transactions, the type of products and services offered, and the delivery channel used.
| Risk category | Minimum periodic updation | Six-monthly categorisation review |
|---|---|---|
| High risk | At least once every two years | Required |
| Medium risk | At least once every eight years | Required |
| Low risk | At least once every ten years | Required |
The two clocks are separate and are often confused. Updation refreshes the customer's KYC record. Review re-asks whether the risk rating is still right, and it happens far more frequently. Continuous transaction monitoring is what makes the six-month review evidence-based rather than a rubber stamp.
Who must a regulated entity appoint, and for what?
Two roles are mandatory and cannot be held by the same person. The Designated Director is nominated by the board and is accountable for overall compliance with the obligations imposed under chapter IV of the PMLA and the Rules made under it.
The Principal Officer is responsible for ensuring compliance, monitoring transactions, and sharing and reporting information as required by law. The name, designation, address and contact details of both must be communicated to FIU-IND and to the RBI, and kept current when either role changes hands.
Separating the roles is the point. The Designated Director carries board-level accountability that cannot be discharged by the person running the day-to-day filings, which is what prevents an entire programme from resting on one officer's judgement. FIU-IND's own mandate and reporting line to the Economic Intelligence Council explains why it wants a named board-level contact.
What screening does the RBI expect against sanctions and PEP lists?
The Directions require a suitable system to ensure that the identity of a customer does not match any person or entity whose name appears in the sanctions lists set out in the Directions themselves. That is a systems obligation, not a lookup performed at the discretion of the onboarding team.
Two design points follow from the wording. Screening has to run against the verified customer record rather than a free-text string typed at account opening, otherwise a later change to the record never re-triggers a check. And because designations change between review cycles, the list refresh interval, not the customer review interval, sets the real detection lag.
Politically exposed persons are handled alongside this in the customer acceptance and enhanced due diligence provisions rather than in the sanctions paragraph. Our explainer on politically exposed persons sets out the categories, and PEP and sanctions screening covers how continuous rescreening closes the gap between reviews.
Which entities does the RBI's KYC framework cover?
The Directions apply to regulated entities, a term that extends well beyond scheduled commercial banks. It covers co-operative banks, all-India financial institutions, non-banking financial companies, payment system operators and other entities licensed or registered by the RBI, each of which sits within the wider Indian AML regime built on the PMLA.
Scope questions arise most often with fintech firms operating through a licensed partner. The obligation sits with the regulated entity, and outsourcing an onboarding journey does not move it. Where a third party performs identification, the regulated entity remains answerable for the quality of the record and for its upload to the Central KYC Records Registry.
Entities regulated by SEBI or IRDAI follow their own sector instruments instead, though the statutory basis is identical. A group with a bank, a broking arm and an insurer therefore runs three rule sets over one customer base. The India country coverage page sets out how the supervisory split works.
What does the RBI actually penalise?
Enforcement is granular and it targets missing systems rather than individual customer files. On 14 August 2025 the RBI announced a penalty of Rs 2.50 lakh on a Vadodara co-operative bank by an order dated 8 August 2025, imposed under section 47A(1)(c) read with sections 46(4)(i) and 56 of the Banking Regulation Act, 1949.
The sustained charges are instructive. Among them was a failure to carry out periodic review of the risk categorisation of certain accounts with a periodicity of at least once in six months, alongside failures in internal audit and asset classification. The finding came from a statutory inspection referenced to the bank's financial position as at 31 March 2024, so the lag between the control failure and the order was over a year.
Two enforcement tracks run in parallel and firms should budget for both. The RBI acts under the Banking Regulation Act for supervisory breaches, while FIU-IND acts under section 13 of the PMLA for reporting and record-keeping failures. More jurisdiction analysis sits in our jurisdictions and regulation collection.



