RBI flags high-risk jurisdictions for NBFC KYC/AML compliance
No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2009-10/439 · issued 30 Apr 2010 · ~2 min read
Quick answerRBI has directed all NBFCs and RNBCs to factor in AML/CFT deficiencies of Iran, Angola, North Korea, Ecuador, Ethiopia, Pakistan, Turkmenistan, and Sao Tome and Principe when assessing customer risk, based on FATF's February 2010 statement.
What changed
RBI issued a circular on April 30, 2010, updating the list of jurisdictions with strategic AML/CFT deficiencies as per FATF's February 18, 2010 statement. It categorizes these jurisdictions into three groups: those requiring countermeasures (Iran), those with unaddressed deficiencies (Angola, DPRK, Ecuador, Ethiopia), and those previously identified with lingering issues (Pakistan, Turkmenistan, Sao Tome and Principe). NBFCs and RNBCs must now consider risks from these countries in their KYC/AML processes.
What it means for you
NBFCs and RNBCs must enhance due diligence for any transactions or relationships involving these jurisdictions, as they pose higher money laundering and terrorist financing risks. This could lead to stricter screening, additional documentation, or even rejection of business from these countries. Lenders should update their risk assessment frameworks and ensure compliance officers are aware of these specific geographies.
Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.
What banks were required to do at the time
Update your KYC/AML risk assessment policies to include the listed jurisdictions: Iran, Angola, DPRK, Ecuador, Ethiopia, Pakistan, Turkmenistan, and Sao Tome and Principe.
Train compliance and operations teams to flag transactions or customers linked to these countries for enhanced due diligence.
Submit an acknowledged receipt of this circular to your respective DNBS Regional Office via the Compliance Officer or Principal Officer.
Review existing customer portfolios for any exposure to these jurisdictions and apply appropriate risk mitigation measures.
Who it affects
All Non-Banking Financial Companies (NBFCs), Residuary Non-Banking Companies (RNBCs), Compliance Officers and Principal Officers of NBFCs/RNBCs, Regional Offices of the Department of Non-Banking Supervision (DNBS)
❓ Common questions
Regulatory timeline
Decoded by BankPulse2026-06-19 06:31 IST
repealed_by — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
Status change: withdrawn03 Aug 2026, 04:00 IST
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
Which jurisdictions require countermeasures according to this circular?
Iran is the only jurisdiction where FATF calls for countermeasures to protect the international financial system from ongoing and substantial money laundering and terrorist financing risks.
What should NBFCs do if they have existing customers from these high-risk jurisdictions?
NBFCs should conduct enhanced due diligence on such customers, reassess the risk profile, and consider applying additional monitoring or restrictions as per their AML/CFT policies.
Is there a deadline for submitting the receipt of this circular?
The circular does not specify a deadline, but it advises that an acknowledged receipt be submitted by the Compliance Officer/Principal Officer to the concerned DNBS Regional Office.
📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Repealed byRBI/2025-26/100 — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
RBI’s words: “Official withdrawal register entry #1712: DNBS.(PD).CC.No.172/03.10.42/2009-10 — "Know Your Customer (KYC) Norms / Anti-Money Laundering (AML) Standards / Combating of Financing of Terrorism (CFT)" da”
📜 Read the original circular — full text as issued by RBI
RBI/2009-10/439
DNBS(PD).CC. No. 172/03.10.42 /2009-10
April 30, 2010
All Non Banking Financial Companies /
Residuary Non Banking Companies
Dear Sir,
Know Your Customer (KYC) Norms/ Anti- Money Laundering (AML) Standards/
Combating of Financing of Terrorism (CFT)
Please refer to Company Circular No 166 dated December 2, 2009 on the captioned subject. Financial Action Task Force (FATF) has issued a Statement dated February 18, 2010 on the subject ( Copy enclosed ) which divides the strategic AML/CFT deficient jurisdictions into three groups as under:
(i) Jurisdictions subject to FATF call on its members and other jurisdictions to apply countermeasures to protect the international financial system from the ongoing and substantial money laundering and terrorist financing (ML/FT) risks emanating from the jurisdiction: Iran
(ii) Jurisdictions with strategic AML/CFT deficiencies that have not committed to an action plan developed with the FATF to address key deficiencies as of February 2010. The FAFT calls on its members to consider the risks arising from the deficiencies associated with each jurisdiction: Angola , Democratic People's Republic of Korea (DPRK), Ecuador and Ethiopia.
(iii) Jurisdictions previously publicly identified by the FAFT as having strategic AML/CFT deficiencies, which remain to be addressed as of February 2010: Pakistan , Turkmenistan, Sao Tome and Principe
2. All NBFCs/RNBCs are accordingly advised to take into account risks arising from the deficiencies in AML/CFT regime of these countries.
3. An acknowledged receipt of this circular may be submitted by the Compliance officer/ Principal Officer of the NBFCs to the concerned Regional Office of DNBS in whose jurisdiction the NBFC/RNBC is functioning.
Yours faithfully,
(Uma Subramaniam)
Chief General Manager-in-Charge
Encl: as above
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2009-10/439 · issued 30 Apr 2010. The plain-English explanation above is BankPulse’s own independent summary.
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=5641&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.