UCBs: KYC/AML Record Retention & PEP Rules Updated
Current · Source: Reserve Bank of India · RBI/2009-10/224 · issued 16 Nov 2009 · ~2 min read
Quick answerRBI mandates urban co-op banks to keep transaction records for 10 years from transaction date and customer ID records for 10 years after account closure, per PMLA 2009 amendments. Senior management approval is now required for existing customers who become PEPs.
The rule, in the simplest words
Keep records of every transaction for at least 10 years from the day the transaction happened.
Keep the customer's ID papers (like passport, PAN card, utility bill) for at least 10 years after the account is closed.
If a customer becomes a PEP (a person with a big government job), the bank's senior bosses must say 'okay' to keep doing business with them.
The bank must watch out for customers who become PEPs and then do extra checks on them.
How it plays out — a real example
Ravi, a KYC & compliance officer in Indore, notices that a long-time customer, Mr. Sharma, has just been elected as a local councilor. Ravi immediately flags this as a PEP case and sends it to his senior manager for approval, as per the new rule. He also updates Mr. Sharma's file with the enhanced customer due diligence (CDD) checks, keeping all records safe for the next 10 years.
What changed
The Prevention of Money Laundering (Amendment) Act, 2009, effective June 1, 2009, changed record retention periods. Transaction records must now be kept for 10 years from the transaction date, and customer identification records for 10 years after the business relationship ends. Additionally, if an existing customer becomes a Politically Exposed Person (PEP), banks must obtain senior management approval to continue the relationship and apply enhanced CDD measures.
What it means for you
Urban co-operative banks must update their record-keeping systems to comply with the new 10-year retention periods, which are longer than previous requirements. Banks also need to implement processes to identify when existing customers become PEPs and escalate such cases for senior management approval. This increases compliance burden but strengthens anti-money laundering efforts.
What you must do
Update record retention policies to keep transaction records for at least 10 years from transaction date and customer ID records for 10 years after account closure.
Implement monitoring to detect when existing customers or beneficial owners become PEPs and require senior management approval to continue the relationship.
Ensure Principal Officer and staff have timely access to customer identification data, transaction records, and other CDD information.
Review and align internal procedures with the amended PMLA 2009 requirements, including enhanced monitoring for PEP accounts.
Who it affects
Primary (Urban) Co-operative Banks, Compliance officers and Principal Officers at UCBs, Senior management at UCBs handling PEP relationships
❓ Common questions
Regulatory timeline
Stated effective dateeffective June 1, 2009
Decoded by BankPulse2026-06-19 08:15 IST
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
What is the new record retention period for transaction records under PMLA 2009?
Transaction records must be maintained for at least 10 years from the date of the transaction between the bank and the client.
How should banks handle an existing customer who becomes a Politically Exposed Person (PEP)?
Banks must obtain senior management approval to continue the business relationship and subject the account to enhanced CDD measures and ongoing monitoring.
What access should the Principal Officer have to comply with these rules?
The Principal Officer and appropriate staff must have timely access to customer identification data, CDD information, transaction records, and other relevant information to discharge their responsibilities.
📜 Read the original circular — full text as issued by RBI
RBI/2009-10/224
UBD. CO. BPD. PCB.Cir. No. 23/ 12.05.001 / 2009-10
November 16, 2009
The Chief Executive Officers of
All Primary (Urban) Co-operative Banks
Madam/Dear Sir
Know Your Customer (KYC) norms / Anti-Money Laundering (AML) standards / Combating Financing of Terrorism (CFT) / Obligation of banks under Prevention of Money Laundering Act, 2002 – Urban Co-operative Banks
Please refer to our circulars UBD.PCB. Cir.30/09.16.100/2004-05 dated December 15, 2004 on Know Your Customer (KYC) Guidelines – Anti Money Laundering Standards and UBD. BPD.Cir No. 38/09.16.100/2005-06 dated March 21, 2006 on Prevention of Money Laundering Act, 2002 – Obligation of banks in terms of Rules notified thereunder.
Preservation period of records
2. The Prevention of Money Laundering (Amendment) Act, 2009 (No. 21 of 2009) has come into force with effect from June 01, 2009 as notified by the Government. In terms of Sub-Section 2 (a) of Section 12 of The Prevention of Money Laundering (Amendment) Act, 2009, the records referred to in clause (a) of Sub-Section (1) of Section 12 shall be maintained for a period of ten years from the date of transaction between the clients and the banking company and in terms of Sub-Section 2 (b) of Section 12 of the Act ibid , the records referred to in clause (c) of Sub-Section (1) of Section 12 shall be maintained for a period of ten years from the date of cessation of transaction between the clients and the banking company.
3. Accordingly, in modification of paragraph 5 of the circular No. 38 dated March 21, 2006, banks are advised to maintain for at least ten years from the date of transaction between the bank and the client, all necessary records of transactions referred to at Rule 3 of the Prevention of Money Laundering (Maintenance of Records of the Nature and Value of Transactions, the Procedure and Manner of Maintaining and Time for Furnishing Information and Verification and Maintenance of Records of the Identity of the Clients of the Banking Companies, Financial Institutions and Intermediaries) Rules, 2005 (PMLA Rules), both domestic or international, which will permit reconstruction of individual transactions (including the amounts and types of currency involved, if any) so as to provide, if necessary, evidence for prosecution of persons involved in criminal activity.
4. However, records pertaining to the identification of the customer and his address (eg. copies of documents like passports, identity cards, driving licenses, PAN card, utility bills etc.) obtained while opening the account and during the course of business relationship, as indicated in paragraph 5 of the above said circular dated March 21, 2006, would continue to be preserved for at least ten years after the business relationship is ended as required under Rule 10 of the Rules ibid .
Accounts of the Politically Exposed Persons (PEPs)
5. Detailed guidelines on CDD measures to be made applicable to Politically Exposed Person and their family members or close relatives are contained in Annex I of UBD.PCB. Cir.30/09.16.100/2004-05 dated December 15, 2004. It is further advised that in the event of an existing customer or the beneficial owner of an existing account, subsequently becoming a PEP, banks should obtain senior management approval to continue the business relationship and subject the account to the CDD measures as applicable to the customers of PEP category including enhanced monitoring on an ongoing basis.
Principal Officer
6. Banks have been advised in paragraph 9 of ‘Guidelines on ‘Know Your Customer’ norms and Anti Money Laundering Measures’ contained in UBD.PCB. Cir.30/06.161.000/2004-05 dated December 15, 2004 that banks should appoint a senior management officer to be designated as Principal Officer and the role and responsibilities of the Principal Officer have been detailed therein. With a view to enable the Principal Officer to discharge his responsibilities, it is advised that the Principal Officer and other appropriate staff should have timely access to customer identification data and other CDD information, transaction records and other relevant information. Further, banks should ensure that the Principal Officer is able to act independently and report directly to the senior management or to the Board of Directors.
Yours faithfully,
(A. K. Khound)
Chief General Manager-in-Charge
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2009-10/224 · issued 16 Nov 2009. The plain-English explanation above is BankPulse’s own independent summary.
Example: if you are a Compliance officer at a bank this circular applies to (Primary (Urban) Co-operative Banks, Compliance officers and Principal Officers at UCBs, Senior management at UCBs handling PEP relationships), your first concrete step on “UCBs: KYC/AML Record Retention & PEP Rules Updated” is: “Update record retention policies to keep transaction records for at least 10 years from transaction date and customer ID records for 10 years after account closure.” (RBI issued this 16 Nov 2009).
Circular: RBI/2009-10/224 -- UCBs: KYC/AML Record Retention & PEP Rules Updated
Issued: 16 Nov 2009
Action required: Update record retention policies to keep transaction records for at least 10 years from transaction date and customer ID records for 10 years after account closure.
Action required: Implement monitoring to detect when existing customers or beneficial owners become PEPs and require senior management approval to continue the relationship.
Action required: Ensure Principal Officer and staff have timely access to customer identification data, transaction records, and other CDD information.
Action required: Review and align internal procedures with the amended PMLA 2009 requirements, including enhanced monitoring for PEP accounts.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=5372&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.