FATF AML/CFT Risks: Iran & DPRK – Payment System Alert
No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2010-11/374 · issued 18 Jan 2011 · ~1 min read
Quick answerRBI directs all payment system entities to factor in AML/CFT risks from Iran (subject to countermeasures) and DPRK (strategic deficiencies) when dealing with persons or institutions from these jurisdictions.
What changed
RBI forwarded FATF's October 2010 statement classifying Iran as requiring countermeasures due to substantial ML/FT risks, and DPRK as having strategic deficiencies without an action plan. Payment system entities must now consider these risks in business relationships and transactions.
What it means for you
Banks and payment operators must enhance due diligence for any transaction or relationship involving Iran or DPRK. This aligns with global FATF standards and previous RBI circulars, reinforcing the need to protect India's financial system from cross-border illicit flows.
Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.
What banks were required to do at the time
Update AML/CFT risk assessments to include heightened risks from Iran and DPRK.
Apply enhanced due diligence for transactions or relationships with persons/entities from these jurisdictions.
Ensure nodal/principal officers acknowledge receipt of this circular.
Refer to earlier RBI circular DBOD.AML.No.1930/14.01.036/2009-10 for additional guidance.
Who it affects
All authorised payment system operators in India, Banks handling cross-border transactions, Compliance and AML/CFT teams
❓ Common questions
Regulatory timeline
Decoded by BankPulse2026-06-19 02:56 IST
Status change: withdrawn03 Aug 2026, 04:00 IST
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
What are the two categories of jurisdictions mentioned in this circular?
Iran is subject to FATF countermeasures due to ongoing ML/FT risks. DPRK has strategic deficiencies and has not committed to an action plan as of October 2010.
Do I need to stop all transactions with Iran and DPRK?
No, but you must assess and mitigate the risks arising from their deficient AML/CFT regimes before entering into any business relationship or transaction.
Is this a new requirement?
No, it supplements earlier RBI guidance from August 2010 (circular DBOD.AML.No.1930/14.01.036/2009-10) and aligns with FATF updates.
📜 Read the original circular — full text as issued by RBI
RBI/2010-11/374
DPSS. CO. AD. No. 1569/02.27.005/2010-11
January 18, 2011
All the Authorised entities operating payment system in India
Dear Sir
Anti-Money Laundering (AML)/Combating of Financing of Terrorism (CFT) – Standards
We are forwarding herewith a copy of Statement issued on October 22, 2010 by the Financial Action Task Force (FATF) on the subject ( enclosed ). It may be observed that the statement divides the strategic AML/CFT deficient jurisdictions into two groups as under:
Jurisdictions subject to FATF call on its members and other jurisdictions to apply countermeasures to protect the international financial system from the ongoing and substantial money laundering and terrorist financing (ML/FT) risks emanating from the jurisdiction : Iran
Jurisdictions with strategic AML/CFT deficiencies that have not committed to an action plan developed with the FATF to address key deficiencies as of October 2010. The FATF calls on its members to consider the risks arising from the deficiencies associated with each jurisdiction: Democratic People's Republic of Korea (DPRK).
2. All the Authorised entities operating payment system in India are accordingly advised to take into account risks arising from the deficiencies in AML/CFT regime of these countries, while entering into business relationships and transactions with persons (including legal persons and other financial institutions) from or in these countries/ jurisdictions.
3. You are also advised to refer to the circular DBOD. AML.No.1930/14.01.036/2009-10 dated August 2, 2010 on risks arising from the deficiencies in AML/CFT regime of Iran, Democratic People's Republic of Korea (DPRK), and Sao Tome and Principe. The said circular is available on our website www.rbi.org.in .
4. Nodal Officer/Principal Officer should acknowledge receipt of this circular letter.
Yours faithfully,
(K. C. Anand)
Deputy General Manager
Encl: As above
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2010-11/374 · issued 18 Jan 2011. The plain-English explanation above is BankPulse’s own independent summary.
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6225&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.