RBI Updates KYC/AML Guidance for UCBs on High-Risk Jurisdictions
Current · Source: Reserve Bank of India · RBI/2010-11/171 · issued 12 Aug 2010 · ~1 min read
Quick answerRBI directs AD I category UCBs to apply enhanced scrutiny on transactions involving Iran, North Korea, and Sao Tome and Principe due to FATF-identified AML/CFT deficiencies. Banks must assess risks before onboarding or dealing with entities from these jurisdictions.
The rule, in the simplest words
Banks must check extra carefully when dealing with money from Iran, North Korea, or Sao Tome and Principe because these countries have weak rules against money laundering (hiding dirty money) and terrorist funding.
For Iran, banks must use the strongest safety steps, like asking for more documents or limiting how much money can move, to protect the financial system.
For North Korea and Sao Tome and Principe, banks must decide for themselves how risky each customer or deal is and write down their decision.
The bank's compliance officer (the person who makes sure rules are followed) must send a note to the RBI regional office saying they got this rule.
How it plays out — a real example
A KYC & compliance officer in Indore receives a request from a small business owner who wants to send money to a supplier in Iran. The officer remembers the RBI rule and applies enhanced due diligence: she asks for extra proof of the supplier's identity and the purpose of the payment, and limits the transaction amount until she is sure it is safe.
What changed
RBI updated its earlier April 2010 circular by incorporating FATF's June 25, 2010 statement. The statement divides deficient jurisdictions into two groups: Iran (subject to countermeasures) and DPRK and Sao Tome and Principe (with unresolved deficiencies). UCBs must now factor these risks into business relationships and transactions.
What it means for you
UCBs must treat Iran with the highest caution, potentially applying countermeasures like enhanced due diligence or transaction restrictions. For DPRK and Sao Tome and Principe, banks need to evaluate risks individually. Compliance officers must acknowledge receipt to the regional RBI office, ensuring regulatory tracking.
What you must do
Review and update KYC/AML policies to include FATF's June 2010 classification of Iran, DPRK, and Sao Tome and Principe.
Apply enhanced due diligence or countermeasures for transactions involving Iran, as per FATF call.
Assess and document risks for business relationships with entities from DPRK and Sao Tome and Principe.
Ensure compliance officer acknowledges this circular to the respective RBI regional office.
Who it affects
AD I Category Urban Co-operative Banks, Compliance officers and principal officers of UCBs, Branches handling cross-border transactions with listed jurisdictions
❓ Common questions
What are the two groups of jurisdictions mentioned in the circular?
Group 1: Iran, where FATF calls for countermeasures. Group 2: DPRK and Sao Tome and Principe, which have strategic deficiencies but no committed action plan as of June 2010.
Do UCBs need to report compliance to RBI?
Yes, the compliance officer or principal officer must acknowledge receipt of this circular to the concerned RBI regional office.
📜 Read the original circular — full text as issued by RBI
RBI/2010-11/171
UBD.BPD. (PCB).Cir. No. 7 /14.01.062/2010-11
August 12, 2010
The Chief Executive Officers of
All AD I Category Urban Co-operative Banks
(As per List enclosed)
Dear Sir / Madam,
Know Your Customer (KYC) Norms / Anti-Money Laundering (AML) Standards / Combating of Financing of Terrorism (CFT)
Please refer to our circular UBD.BPD.(PCB) Cir.No.53/14.01.062/2009-10 dated April 1, 2010 on risks arising from the deficiencies in AML / CFT regime of Iran,Uzbekistan, Pakistan, Turkmenistan, Sao Tome and Principe.
2. The Financial Action Task Force (FATF) has issued a further Statement on June 25, 2010 on the subject ( copy enclosed ). It may be observed that the statement divides the strategic AML/CFT deficient jurisdictions into two groups as under:
Jurisdictions subject to FATF call on its members and other jurisdictions to apply countermeasures to protect the international financial system from the ongoing and substantial money laundering and terrorist financing (ML/FT) risks emanating from the jurisdiction: Iran
Jurisdictions with strategic AML/CFT deficiencies that have not committed to an action plan developed with the FATF to address key deficiencies as of June 2010. The FATF calls on its members to consider the risks arising from the deficiencies associated with each jurisdiction: Democratic People's Republic of Korea (DPRK), Sao Tome and Principe.
3. UCBs are accordingly advised to take into account risks arising from the deficiencies in AML / CFT regime of these countries, while entering into business relationships and transactions with persons (including legal persons and other financial institutions) from or in these countries/ jurisdictions.
4. The Compliance Officer / Principal Officer of the bank should acknowledge receipt of this circular to our Regional Office concerned .
Yours faithfully
(M. Nanda Kumar)
Deputy General Manager
Encl: As above.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2010-11/171 · issued 12 Aug 2010. The plain-English explanation above is BankPulse’s own independent summary.
Apply enhanced due diligence or countermeasures for transactions involving Iran, as per FATF call.
📜 Compliance
Review and update KYC/AML policies to include FATF's June 2010 classification of Iran, DPRK, and Sao Tome and Principe.
Assess and document risks for business relationships with entities from DPRK and Sao Tome and Principe.
Ensure compliance officer acknowledges this circular to the respective RBI regional office.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are a Compliance officer at a bank this circular applies to (AD I Category Urban Co-operative Banks, Compliance officers and principal officers of UCBs, Branches handling cross-border transactions with listed jurisdictions), your first concrete step on “RBI Updates KYC/AML Guidance for UCBs on High-Risk Jurisdictions” is: “Review and update KYC/AML policies to include FATF's June 2010 classification of Iran, DPRK, and Sao Tome and Principe.” (RBI issued this 12 Aug 2010).
Circular: RBI/2010-11/171 -- RBI Updates KYC/AML Guidance for UCBs on High-Risk Jurisdictions
Issued: 12 Aug 2010
Action required: Review and update KYC/AML policies to include FATF's June 2010 classification of Iran, DPRK, and Sao Tome and Principe.
Action required: Apply enhanced due diligence or countermeasures for transactions involving Iran, as per FATF call.
Action required: Assess and document risks for business relationships with entities from DPRK and Sao Tome and Principe.
Action required: Ensure compliance officer acknowledges this circular to the respective RBI regional office.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=5951&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.