HomeCirculars › RBI/2007-2008/247

UCBs: KYC Norms and AML Standards Update

Current · Source: Reserve Bank of India · RBI/2007-2008/247 · issued FY 2007-08 · ~2 min read
Quick answerRBI clarifies that KYC document lists are indicative, not exhaustive, to avoid denying banking services. Banks must review internal instructions, accept alternative address proofs for relatives, and update customer risk profiles every six months, with data refresh every 2-5 years based on risk.
The rule, in the simplest words
How it plays out — a real example

A KYC & compliance officer in Indore is helping a woman who wants to open a savings account but lives with her father. The officer accepts her father's electricity bill and a signed declaration from him that she is his daughter and lives with him, following the RBI rule to not deny service just because the bill is not in her name.

What changed

RBI reiterates that the indicative list of KYC documents in Annex-II of the 2004 circular is not exhaustive; banks treating it as such are denying services. It clarifies that permanent address can be verified via a relative's utility bill and declaration. Risk categorization review must occur at least every six months, and customer identification data must be updated every five years for low-risk and every two years for high/medium-risk customers.

What it means for you

Banks must relax rigid KYC practices to include alternative address proofs for dependents living with relatives, reducing customer friction. The six-monthly risk review and periodic data updation impose operational discipline, ensuring compliance with AML/CFT standards. Non-compliance could lead to regulatory scrutiny or penalties for denying banking access.

What you must do

Who it affects

Primary (Urban) Co-operative Banks (UCBs), Compliance and KYC teams at UCBs, Branch managers and customer-facing staff, Low-risk customers, especially dependents living with relatives

❓ Common questions

Can a wife open an account if utility bills are in her husband's name?

Yes, banks can accept the husband's utility bill and a declaration from him confirming the wife is a relative and staying with him. This avoids denying services to dependents.

How often must we update customer KYC data?

For low-risk customers, update at least once every five years. For high and medium-risk customers, update at least once every two years. Risk categorization itself must be reviewed every six months.

What if a bank treats the indicative document list as exhaustive?

RBI warns this denies banking services to the public. Banks must review internal instructions to ensure flexibility, especially for low-risk customers, to avoid regulatory action.

📜 Read the original circular — full text as issued by RBI
RBI/2007-2008/247 UBD. CO. BPD. (PCB). No.32 /09.39.000/2007-08 February 25 , 2008 The Chief Executive Officers, All Primary (Urban) Co-operative Banks Dear Sir, Know your Customer (KYC) Norms / Anti-Money Laundering (AML) Standards / Combating of Financing of Terrorism Primary (Urban) Co-operative Banks (UCBs) have been advised vide our circular UBD. PCB.Cir.30/09.161.00/2004-05 dated December 15, 2004 that the adoption of customer acceptance policy and its implementation should not result in denial of banking services to general public, especially to those, who are financially or socially disadvantaged. It was also clarified to the banks that a risk based approach has been followed in the KYC guidelines issued by Reserve Bank to avoid disproportionate cost to banks and a burdensome regime for the customers. UCBs were accordingly advised that customer identification means identifying the customer and verifying his/her identity by using reliable, independent source documents, data or information to their satisfaction. 2. It was further clarified to banks that 'being satisfied' means that the bank must be able to satisfy the competent authorities that due diligence was observed based on the risk profile of the customer in compliance with the extant guidelines in place. An indicative list of the nature and type of documents/ information that may be relied upon for customer identification was also given in the Annex-II to the aforesaid circular.  It has been brought to our notice that Annex-II, which was clearly termed as an indicative list, is being treated by some banks as an exhaustive list as a result of which a section of public is being denied access to banking services. Banks are, therefore, advised to take a review of their extant internal instructions in this regard. 3.  It is clarified that permanent correct address, as referred to in Annex-II of our said circular, means the address at which a person usually resides and can be taken as the address as mentioned in a utility bill or any other document accepted by the bank for verification of the address of the customer. It has been observed that some close relatives, e.g. wife, son, daughter and parents etc. who live with their husband, father/mother and son, as the case may be, are finding it difficult to open account in some banks as the utility bills required for address verification are not in their name. It is clarified, that in such cases, banks can obtain an identity document and a utility bill of the relative with whom the prospective customer is living along with a declaration from the relative that the said person (prospective customer) wanting to open an account is a relative and is staying with him/her. Banks can use any supplementary evidence such as a letter received through post for further verification of the address. While issuing operational instructions to the branches on the subject, banks should keep in mind the spirit of instructions issued by the Reserve Bank and avoid undue hardships to individuals who are, otherwise, classified as low risk customers. 4. The instructions contained in paragraph 5 of guidelines on 'Know Your Customer' norms and Anti-Money Laundering Measures of our circular dated December 15, 2004 , also  require banks to put in place a system of periodical review of risk categorization of accounts and the need for applying enhanced due diligence measures in case of higher risk perception on a customer.  Banks are further advised that such review of risk categorization of customers should be carried out at a periodicity of  not less than once in six months. Banks should also introduce a system of periodical updation of customer identification data (including photograph/s) after the account is opened.  The periodicity of such updation should not be less than once in five years in case of low risk category customers and not less than once in two years in case of high and medium risk categories. 5. Combating financing of terrorism a) In terms of PMLA Rules, suspicious transaction should include inter alia transactions which give rise to a reasonable ground of suspicion that these may involve financing of the activities relating to terrorism.  UCBs are, therefore, advised to develop suitable mechanism through appropriate policy framework for enhanced monitoring of accounts suspected of having terrorist links and swift identification of the transactions and making suitable reports to the Financial Intelligence Unit – India (FIU-IND) on priority.  b) As and when list of individuals and entities, approved by Security Council Committee established pursuant to various United Nations' Security Council Resolutions (UNSCRs), are received from Government of India, Reserve Bank circulates these to all banks and financial institutions. UCBs should ensure to update the consolidated list of individuals and entities as circulated by Reserve Bank. Further, the updated list of such individuals/entities can be accessed in the United Nations website at  http://www.un.org/sc/committees/1267/consolist.shtml . UCBs are advised that before opening any new account it should be ensured that the name/s of the proposed customer does not appear in the list. Further, UCBs should scan all existing accounts to ensure that no account is held by or linked to any of the entities or individuals included in the list.  Full details of accounts bearing resemblance with any of the individuals/entities in the list should immediately be intimated to RBI and FIU-IND. 6.  It may be appreciated that KYC norms/AML standards/CFT measures have been prescribed to ensure that criminals are not allowed to misuse the banking channels.  It would, therefore, be necessary that adequate screening mechanism is put in place by UCBs as an integral part of their recruitment/hiring process of personnel. 7. These guidelines are issued under Section 35A of the Banking Regulation Act, 1949 (AACS) and any contravention thereof may attract penalties under the relevant provisions of the Act. Yours faithfully, (A.K.Khound) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2007-2008/247 · issued FY 2007-08. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
💻 IT / Systems
  • Implement a system for risk categorization review of accounts at least once every six months.
📜 Compliance
  • Review internal KYC instructions to ensure the indicative document list is not treated as exhaustive.
  • Accept utility bills of relatives along with a declaration for address verification of dependents.
  • Set up periodic updation of customer identification data: every 5 years for low-risk, every 2 years for high/medium-risk customers.
  • Train staff on suspicious transaction reporting related to terrorism financing under PMLA rules.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (Primary (Urban) Co-operative Banks (UCBs), Compliance and KYC teams at UCBs, Branch managers and customer-facing staff, Low-risk customers, especially dependents living with relatives), your first concrete step on “UCBs: KYC Norms and AML Standards Update” is: “Review internal KYC instructions to ensure the indicative document list is not treated as exhaustive.” (RBI issued this FY 2007-08).

  1. Circular: RBI/2007-2008/247 -- UCBs: KYC Norms and AML Standards Update
  2. Issued: FY 2007-08
  3. Action required: Review internal KYC instructions to ensure the indicative document list is not treated as exhaustive.
  4. Action required: Accept utility bills of relatives along with a declaration for address verification of dependents.
  5. Action required: Implement a system for risk categorization review of accounts at least once every six months.
  6. Action required: Set up periodic updation of customer identification data: every 5 years for low-risk, every 2 years for high/medium-risk customers.
  7. Action required: Train staff on suspicious transaction reporting related to terrorism financing under PMLA rules.
  8. Owner: ____________ Target date: ____________
  9. Board/committee approval needed? Y / N
  10. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 05 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=4067&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗