FATF Updates: Enhanced AML/CFT Checks for Iran, DPRK, Sao Tome
Current · Source: Reserve Bank of India · RBI/2010-11/319 · issued 22 Dec 2010 · ~2 min read
Quick answerRBI mandates enhanced KYC/AML scrutiny for transactions involving Iran, North Korea, and Sao Tome and Principe due to FATF-identified deficiencies. Banks must apply countermeasures for Iran and assess risks for the other two jurisdictions.
The rule, in the simplest words
Banks must do extra checks on transactions with Iran, North Korea, and Sao Tome and Principe due to money laundering and terrorist financing risks
Iran is considered high-risk and needs special monitoring and possible transaction limits
North Korea and Sao Tome and Principe need risk assessments to prevent money laundering and terrorist financing
Banks must update their internal risk frameworks to include these countries
Banks must inform their staff and customers about the new rules
How it plays out — a real example
A compliance officer in Mumbai must update the bank's risk framework to include Iran, North Korea, and Sao Tome and Principe, and brief the staff on the new rules to prevent money laundering and terrorist financing. For instance, when a customer from Iran wants to open an account, the compliance officer will apply extra checks and monitoring to ensure the transaction is legitimate. The officer will also document the decision and report to senior management if necessary.
What changed
RBI updated its earlier November 2009 circular to reflect the FATF's June 2010 statement, which categorizes jurisdictions with strategic AML/CFT deficiencies into two groups. Iran is now subject to a FATF call for countermeasures, while Democratic People's Republic of Korea and Sao Tome and Principe are flagged for having deficiencies without committed action plans.
What it means for you
Banks must treat Iran as a high-risk jurisdiction requiring enhanced due diligence and possible transaction restrictions. For DPRK and Sao Tome and Principe, lenders need to assess and mitigate risks from potential money laundering or terrorist financing when dealing with entities from these countries.
What you must do
Update internal AML/CFT risk frameworks to include the three flagged jurisdictions with appropriate risk ratings.
Apply countermeasures for Iran, such as enhanced monitoring, transaction limits, or reporting to senior management.
Conduct risk assessments for transactions involving DPRK and Sao Tome and Principe and document decisions.
Inform your Principal Officer to acknowledge receipt and ensure compliance across branches.
Brief relevant staff and constituents on the updated FATF guidance and RBI circular.
Who it affects
All Authorised Persons (banks, forex dealers, money changers), Compliance and AML/CFT teams, Principal Officers of authorised entities, Customers dealing with entities from Iran, DPRK, or Sao Tome and Principe
❓ Common questions
What specific countermeasures are required for Iran?
The circular does not prescribe specific countermeasures; it directs banks to apply measures to protect the financial system from substantial ML/TF risks. This typically includes enhanced due diligence, transaction monitoring, and possibly restricting business relationships.
Does this circular apply to all types of transactions?
Yes, it applies to all business relationships and transactions with persons (including legal persons and financial institutions) from or in the listed jurisdictions.
What happens if we don't comply?
Non-compliance may attract penal provisions under FEMA, 1999, PMLA, 2002, and related rules, as stated in the circular.
📜 Read the original circular — full text as issued by RBI
RBI/2010-11/319
A.P. (DIR Series) Circular No. 25
A.P. (FL/RL Series) Circular No. 06
December 22, 2010
To
All Authorized Persons
Madam/ Sir
Know Your Customer (KYC) norms/Anti-Money Laundering (AML) standards/Combating the Financing of Terrorism (CFT)/Obligation of Authorised Persons under Prevention of Money Laundering Act, (PMLA), 2002, as amended by Prevention of Money Laundering (Amendment) Act, 2009- Money changing activities
Attention of all the Authorised Persons (APs) is invited to Paragraph 4.10 (b) of F-Part-I, Annex to A.P. (DIR Series) Circular No.17 {A.P. (FL/RL Series) Circular No.4} dated November 27, 2009 in terms of which APs were advised to take into account risks arising from the deficiencies in AML/CFT regime of certain jurisdictions, as identified in FATF Statement (www.fatf-gafi.org), issued from time to time, while dealing with individuals or businesses from these jurisdictions.
2. The Financial Action Task Force (FATF) has issued a further Statement on June 25, 2010 on the subject ( copy enclosed ). It may be observed that the statement divides the strategic AML/CFT deficient jurisdictions into two groups as under:
a. Jurisdictions subject to FATF call on its members and other jurisdictions to apply countermeasures to protect the international financial system from the ongoing and substantial money laundering and terrorist financing (ML/TF) risks emanating from the jurisdiction : Iran
b. Jurisdictions with strategic AML/CFT deficiencies that have not committed to an action plan developed with the FATF to address key deficiencies as of June 2010. The FATF calls on its members to consider the risks arising from the deficiencies associated with each jurisdiction: Democratic People's Republic of Korea (DPRK), Sao Tome and Principe.
3. Authorised Persons are accordingly advised to take into account risks arising from the deficiencies in AML/CFT regime of these countries, while entering into business relationships and transactions with persons (including legal persons and other financial institutions) from or in these countries/ jurisdictions.
4. Authorised Persons may bring the contents of this circular to the notice of their constituents concerned.
5. Please advise your Principal Officer to acknowledge receipt of this circular letter.
6. The directions contained in this Circular have been issued under Sections 10(4) and Section 11(1) of the Foreign Exchange Management Act, 1999 (42 of 1999) and also under the Prevention of Money Laundering Act, (PMLA), 2002, as amended by Prevention of Money Laundering (Amendment) Act, 2009 and Prevention of Money-Laundering (Maintenance of Records of the Nature and Value of Transactions, the Procedure and Manner of Maintaining and Time for Furnishing Information and Verification and Maintenance of Records of the Identity of the Clients of the Banking Companies, Financial Institutions and Intermediaries) Rules, 2005 as amended from time to time. Non-compliance with the guidelines would attract penal provisions of the Acts concerned or Rules made there under. Yours faithfully,
(Salim Gangadharan)
Chief General Manager-in-Charge
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2010-11/319 · issued 22 Dec 2010. The plain-English explanation above is BankPulse’s own independent summary.
Apply countermeasures for Iran, such as enhanced monitoring, transaction limits, or reporting to senior management.
Inform your Principal Officer to acknowledge receipt and ensure compliance across branches.
📜 Compliance
Update internal AML/CFT risk frameworks to include the three flagged jurisdictions with appropriate risk ratings.
Conduct risk assessments for transactions involving DPRK and Sao Tome and Principe and document decisions.
Brief relevant staff and constituents on the updated FATF guidance and RBI circular.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are a Compliance officer at a bank this circular applies to (All Authorised Persons (banks, forex dealers, money changers), Compliance and AML/CFT teams, Principal Officers of authorised entities, Customers dealing with entities from Iran, DPRK, or Sao Tome and Principe), your first concrete step on “FATF Updates: Enhanced AML/CFT Checks for Iran, DPRK, Sao Tome” is: “Update internal AML/CFT risk frameworks to include the three flagged jurisdictions with appropriate risk ratings.” (RBI issued this 22 Dec 2010).
Circular: RBI/2010-11/319 -- FATF Updates: Enhanced AML/CFT Checks for Iran, DPRK, Sao Tome
Issued: 22 Dec 2010
Action required: Update internal AML/CFT risk frameworks to include the three flagged jurisdictions with appropriate risk ratings.
Action required: Apply countermeasures for Iran, such as enhanced monitoring, transaction limits, or reporting to senior management.
Action required: Conduct risk assessments for transactions involving DPRK and Sao Tome and Principe and document decisions.
Action required: Inform your Principal Officer to acknowledge receipt and ensure compliance across branches.
Action required: Brief relevant staff and constituents on the updated FATF guidance and RBI circular.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6156&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.