RBI Extends Record Retention to 10 Years Under PMLA 2009
Current · Source: Reserve Bank of India · RBI/2009-10/152 · issued 11 Sep 2009 · ~2 min read
Quick answerRBI mandates banks to preserve transaction records for 10 years from transaction date and customer identification records for 10 years after account closure, aligning with PMLA 2009 amendments. PEP accounts require senior management approval for continued relationship.
The rule, in the simplest words
Banks must keep records of every transaction for 10 years from the date the transaction happened.
Banks must keep customer ID papers (like passport or PAN card) for 10 years after the account is closed.
If a customer becomes a PEP (a person with a big government job), the bank needs a senior boss's okay to keep doing business with them.
The person in charge of following these rules (Principal Officer) must be able to see all customer data and report directly to top bosses.
How it plays out — a real example
A KYC & compliance officer in Indore is reviewing an old customer's file. The customer, a local shopkeeper, was recently elected as a municipal councilor, making him a PEP. The officer knows she must get approval from her branch's senior manager before continuing his gold-loan relationship, and she also checks that his transaction records from five years ago are still safely stored, as the new rule says they must be kept for 10 years from each transaction date.
What changed
The Prevention of Money Laundering (Amendment) Act, 2009, effective June 1, 2009, mandates a 10-year preservation period for transaction records from the transaction date and for customer identification records from cessation of business relationship. RBI modified its July 1, 2009 master circular to reflect this, replacing earlier shorter retention periods. Additionally, banks must now obtain senior management approval to continue relationships with customers who become PEPs and apply enhanced CDD measures.
What it means for you
Banks must overhaul record-keeping systems to retain transaction data for a full decade from each transaction, not just from account closure. This increases storage and compliance costs but strengthens anti-money laundering defenses. For PEPs, the new approval requirement adds a layer of scrutiny, potentially slowing onboarding or relationship continuation. Principal Officers now need direct access to customer data and independence to report to senior management or the board.
What you must do
Update record retention policies to keep transaction records for at least 10 years from transaction date and customer ID records for 10 years after account closure.
Implement systems to flag existing customers who become PEPs and require senior management approval to continue the relationship.
Ensure Principal Officers have timely access to all customer identification and transaction data and can report independently to senior management or the board.
Train compliance teams on the new 10-year retention timelines and PEP monitoring requirements.
Who it affects
All scheduled commercial banks (excluding RRBs), Financial institutions, Local area banks, Compliance and AML teams, Principal Officers, Senior management and board members
❓ Common questions
Regulatory timeline
Stated effective dateeffective June 1, 2009
Decoded by BankPulse2026-06-19 08:47 IST
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
What is the new record retention period for transaction records?
Transaction records must be preserved for at least 10 years from the date of each transaction, as per the PMLA 2009 amendment.
How should banks handle a customer who becomes a Politically Exposed Person (PEP)?
Banks must obtain senior management approval to continue the business relationship and apply enhanced customer due diligence measures, including ongoing monitoring.
What access should the Principal Officer have?
The Principal Officer and appropriate staff must have timely access to customer identification data, CDD information, transaction records, and other relevant information to discharge their responsibilities.
📜 Read the original circular — full text as issued by RBI
RBI/2009-10/152
DBOD. AML.BC. No.43 /14.01.001/2009-10
September 11, 2009
The Chairmen and Chief Executive Officers
All Scheduled Commercial Banks excluding RRBs/
Financial institutions/ Local Area Banks
Dear Sir,
Know Your Customer (KYC) norms / Anti-Money Laundering (AML) standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under PMLA, 2002.
Please refer to the Master Circular DBOD.AML.BC. No.2/14.01.001/ 2009-10 dated July 01, 2009 on Know Your Customer (KYC) norms / Anti-Money Laundering (AML) standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under Prevention of Money Laundering Act 2002.
Preservation Period of Records
2. The Prevention of Money Laundering (Amendment) Act, 2009 (No. 21 of 2009) has come into force with effect from June 01, 2009 as notified by the Government. In terms of Sub-Section 2(a) of Section 12 of The Prevention of Money Laundering (Amendment) Act, 2009 (PMLA, 2009), the records referred to in clause (a) of Sub-Section (1) of Section 12 shall be maintained for a period of ten years from the date of transaction between the clients and the banking company and in terms of Sub-Section 2(b) of Section 12 of the Act ibid , the records referred to in clause (c) of Sub-Section (1) of Section 12 shall be maintained for a period of ten years from the date of cessation of transaction between the clients and the banking company.
3. Accordingly, in modification of paragraph 2.16(iii) (a) of the above said master circular dated July 1, 2009, banks are advised to maintain for at least ten years from the date of transaction between the bank and the client, all necessary records of transactions referred to at Rule 3 of the Prevention of Money-Laundering (Maintenance of Records of the Nature and Value of Transactions, the Procedure and Manner of Maintaining and Time for Furnishing Information and Verification and Maintenance of Records of the Identity of the Clients of the Banking Companies, Financial Institutions and Intermediaries) Rules, 2005 (PMLA Rules), both domestic or international, which will permit reconstruction of individual transactions (including the amounts and types of currency involved, if any) so as to provide, if necessary, evidence for prosecution of persons involved in criminal activity.
4. However, records pertaining to the identification of the customer and his address (e.g. copies of documents like passports, identity cards, driving licenses, PAN card, utility bills etc.) obtained while opening the account and during the course of business relationship, as indicated in paragraph 2.16(iii)(b) of the above said master circular dated July 1, 2009, would continue to be preserved for at least ten years after the business relationship is ended as required under Rule 10 of the Rules ibid.
Accounts of Politically Exposed Persons (PEPs)
5. Detailed guidelines on CDD measures to be made applicable to Politically Exposed Person (PEP) and their family members or close relatives are contained in paragraph 2.5(iv) of the master circular. It is further advised that in the event of an existing customer or the beneficial owner of an existing account,subsequently becoming a PEP, banks should obtain senior management approval to continue the business relationship and subject the account to the CDD measures as applicable to the customers of PEP category including enhanced monitoring on an ongoing basis.
Principal Officer
6. Banks have been advised in Para 2.15 of the master circular referred to above that banks should appoint a senior management officer to be designated as Principal Officer and the role and responsibilities of the Principal Officer have been detailed therein. With a view to enable the Principal Officer to discharge his responsibilities, it is advised that that the Principal Officer and other appropriate staff should have timely access to customer identification data and other CDD information, transaction records and other relevant information. Further, banks should ensure that the Principal Officer is able to act independently and report directly to the senior management or to the Board of Directors.
Yours faithfully,
(Vinay Baijal)
Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2009-10/152 · issued 11 Sep 2009. The plain-English explanation above is BankPulse’s own independent summary.
Implement systems to flag existing customers who become PEPs and require senior management approval to continue the relationship.
📜 Compliance
Update record retention policies to keep transaction records for at least 10 years from transaction date and customer ID records for 10 years after account closure.
Ensure Principal Officers have timely access to all customer identification and transaction data and can report independently to senior management or the board.
Train compliance teams on the new 10-year retention timelines and PEP monitoring requirements.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are a Compliance officer at a bank this circular applies to (All scheduled commercial banks (excluding RRBs), Financial institutions, Local area banks, Compliance and AML teams, Principal Officers, Senior management and board members), your first concrete step on “RBI Extends Record Retention to 10 Years Under PMLA 2009” is: “Update record retention policies to keep transaction records for at least 10 years from transaction date and customer ID records for 10 years after account closure.” (RBI issued this 11 Sep 2009).
Circular: RBI/2009-10/152 -- RBI Extends Record Retention to 10 Years Under PMLA 2009
Issued: 11 Sep 2009
Action required: Update record retention policies to keep transaction records for at least 10 years from transaction date and customer ID records for 10 years after account closure.
Action required: Implement systems to flag existing customers who become PEPs and require senior management approval to continue the relationship.
Action required: Ensure Principal Officers have timely access to all customer identification and transaction data and can report independently to senior management or the board.
Action required: Train compliance teams on the new 10-year retention timelines and PEP monitoring requirements.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=5262&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.