HomeCirculars › RBI/2009-10/398

RBI Alert: FATF-Listed High-Risk Jurisdictions for AML/CFT

No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2009-10/398 · issued 22 Dec 2009 · ~1 min read
Quick answerRBI directs all payment system operators to factor in AML/CFT risks from FATF-identified jurisdictions: Iran (countermeasures), Angola, DPRK, Ecuador, Ethiopia (no action plan), and Pakistan, Turkmenistan, Sao Tome & Principe (unaddressed deficiencies).

What changed

RBI issued a circular on April 13, 2010, updating the FATF statement of February 18, 2010, which categorizes jurisdictions with strategic AML/CFT deficiencies into three groups. This replaces the earlier December 22, 2009, reference and requires operators to consider risks from these countries.

What it means for you

Banks and payment operators must enhance due diligence for transactions involving these jurisdictions, potentially applying countermeasures for Iran. Non-compliance could expose institutions to regulatory action and reputational risk. This aligns with global FATF standards to curb money laundering and terrorist financing.

Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.

What banks were required to do at the time

Who it affects

All payment system operators authorized under PSS Act, 2007, Banks and financial institutions involved in cross-border payments, Compliance and AML/CFT teams in Indian financial entities

❓ Common questions

Regulatory timeline

Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).

What are the three FATF groups mentioned in this circular?

Group 1: Iran (subject to countermeasures). Group 2: Angola, DPRK, Ecuador, Ethiopia (no action plan). Group 3: Pakistan, Turkmenistan, Sao Tome and Principe (unaddressed deficiencies).

Does this circular apply to all payment systems or only specific ones?

It applies to all payment system operators authorized under the Payment and Settlement Systems Act, 2007, covering all digital payment systems including UPI.

What action should banks take for transactions with Iran?

Banks should apply countermeasures as called by FATF to protect the financial system from ML/FT risks, which may include enhanced scrutiny, restrictions, or transaction monitoring.

📜 Read the original circular — full text as issued by RBI
RBI/2009-10/398 DPSS CO No. 2232 / 02.27.005/2009-2010 13th April 2010 To All the Payment Systems Operators authorized under the Payment and Settlement Systems Act, 2007 Know Your Customer (KYC) Norms/Anti-Money Laundering (AML) Standards/Combating of Financing of Terrorism (CFT) Please refer to our letter DPSS.CO.AD.1320/02.27.005/2009-10 dated December 22, 2009. 2. Financial Action Task Force (FATF) has issued a further Statement on February 18, 2010 on the subject ( copy enclosed ). It may be observed that the instant FATF statement divides the strategic AML/CFT deficient jurisdictions into three groups as under: Jurisdictions subject to FATF call on its members and other jurisdictions to apply countermeasures to protect the international financial system from the ongoing and substantial money laundering and terrorist financing (ML/FT) risks emanating from the jurisdiction: Iran Jurisdictions with strategic AML/CFT deficiencies that have not committed to an action plan developed with the FATF to address key deficiencies as of February 2010. The FATF calls on its members to consider the risks arising from the deficiencies associated with each jurisdiction: Angola , Democratic People's Republic of Korea (DPRK), Ecuador and Ethiopia. Jurisdictions previously publicly identified  by the FATF as having strategic AML/ CFT  deficiencies, which remain to be addressed as of February 2010: Pakistan, Turkmenistan and Sao Tome and Principe. 3. All payment system operators are accordingly advised to take into account risks arising from the deficiencies in AML/CFT regime of these countries. Payment System Operators should bring the contents of this circular to the notice of their constituents. 4 . Please acknowledge receipt of this circular letter. Yours faithfully, (G. Padmanabhan) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2009-10/398 · issued 22 Dec 2009. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Topics: Digital Payments / UPI
Key dataSee the live numbers behind this topic: RBI Penalty Tracker, Credit & Deposit Growth — updated from official RBI data.
Key termsPlain-English definitions of terms in this circular — see the full Indian banking glossary. UPI · KYC / AML · Deposit insurance (DICGC) · NEFT / RTGS

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=5592&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗