HomeCirculars › RBI/2010-11/392

RBI Updates AML/CFT Guidance for NBFCs on Iran and North Korea

Current · Source: Reserve Bank of India · RBI/2010-11/392 · issued 28 Jan 2011 · ~2 min read
Quick answerRBI directs all NBFCs and RNBCs to take into account AML/CFT risks from Iran and North Korea when dealing with entities from these jurisdictions, following FATF's October 22, 2010 statement.
The rule, in the simplest words
How it plays out — a real example

Rahul is dealing with a customer from Iran who wants to take a gold loan. Rahul must take into account the risks from Iran's AML/CFT regime and apply countermeasures before approving the loan. He also needs to assess the risks associated with North Korea, even though the customer is from Iran.

What changed

RBI updated its earlier AML/CFT circular (September 22, 2010) to reflect FATF's October 22, 2010 statement. Iran is now subject to countermeasures due to ongoing ML/FT risks, while North Korea (DPRK) is flagged for strategic deficiencies without a committed action plan. The earlier list of eight jurisdictions (Iran, Angola, DPRK, Ecuador, Ethiopia, Pakistan, Turkmenistan, Sao Tome and Principe) was narrowed to two.

What it means for you

NBFCs must apply enhanced due diligence and consider countermeasures for transactions involving Iran, and assess risks for North Korea. This increases compliance burden and may restrict business relationships with entities from these countries. Lenders need to update their AML policies and train staff accordingly.

What you must do

Who it affects

All Non-Banking Financial Companies (NBFCs), Residuary Non-Banking Companies (RNBCs), Principal Officers of NBFCs/RNBCs

❓ Common questions

Which countries are specifically mentioned in this circular?

Iran is subject to countermeasures, and Democratic People's Republic of Korea (DPRK) has strategic AML/CFT deficiencies without a committed action plan.

What should NBFCs do differently for Iran compared to North Korea?

For Iran, NBFCs must apply countermeasures to protect the financial system. For North Korea, they need to consider the risks from deficiencies but no mandatory countermeasures are called for.

Does this circular replace the earlier September 2010 circular?

It updates the earlier circular by narrowing the list of deficient jurisdictions to two based on FATF's October 22, 2010 statement. The earlier guidance on other countries is superseded.

📜 Read the original circular — full text as issued by RBI
RBI/2010-11/392 DNBS(PD).CC. No 209/03.10.42 /2010-11 January 28, 2011 All Non Banking Financial Companies/ Residuary Non Banking Companies Dear Sir, Anti- Money Laundering (AML) / Combating of Financing of Terrorism (CFT) Standards Please refer to Company Circular No 201 dated September 22, 2010 on Anti- Money Laundering (AML) Standards / Combating of Financing of Terrorism (CFT) giving details about risk arising from the deficiencies in AML / CFT regime of Iran, Angola, Democratic People's Republic of Korea (DPRK), Ecuador, Ethiopia, Pakistan, Turkmenistan and Sao Tome and Principe. 2. Financial Action Task Force (FATF) has issued a further statement dated October 22, 2010 on the subject ( copy enclosed ), which divides the strategic AML/CFT deficient jurisdictions into two groups as under: (i) Jurisdictions subject to FATF call on its members and other jurisdictions to apply countermeasures to protect the international financial system from the ongoing and substantial money laundering and terrorist financing (ML/FT) risks emanating from the jurisdiction : Iran (ii) Jurisdictions with strategic AML/CFT deficiencies that have not committed to an action plan developed with the FATF to address key deficiencies as of October 2010. The FATF calls on its members to consider the risks arising from the deficiencies associated with each jurisdiction: Democratic People's Republic of Korea (DPRK). 3. All NBFCs (including RNBCs) are accordingly advised to take into account risks arising from the deficiencies in AML/CFT regime of these countries, while entering into business relationships and transactions with persons (including legal entities and other financial institutions) from or in these countries/ jurisdictions. 4. Please advise Principal Officer of your Company to acknowledge receipt of this circular letter. Yours faithfully, (Uma Subramaniam) Chief General Manager-in-Charge Encl:as above
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2010-11/392 · issued 28 Jan 2011. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
🏦 Branch Manager
  • Apply countermeasures for Iran-related transactions and consider risks for North Korea.
📜 Compliance
  • Take into account risks arising from deficiencies in AML/CFT regime of Iran and DPRK when entering into business relationships and transactions with persons from these jurisdictions.
  • Ensure Principal Officer acknowledges receipt of this circular and disseminates it to relevant teams.
  • Review existing business relationships with entities from these jurisdictions for potential ML/FT risks.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All Non-Banking Financial Companies (NBFCs), Residuary Non-Banking Companies (RNBCs), Principal Officers of NBFCs/RNBCs), your first concrete step on “RBI Updates AML/CFT Guidance for NBFCs on Iran and North Korea” is: “Take into account risks arising from deficiencies in AML/CFT regime of Iran and DPRK when entering into business relationships and transactions with persons from these jurisdictions.” (RBI issued this 28 Jan 2011).

  1. Circular: RBI/2010-11/392 -- RBI Updates AML/CFT Guidance for NBFCs on Iran and North Korea
  2. Issued: 28 Jan 2011
  3. Action required: Take into account risks arising from deficiencies in AML/CFT regime of Iran and DPRK when entering into business relationships and transactions with persons from these jurisdictions.
  4. Action required: Apply countermeasures for Iran-related transactions and consider risks for North Korea.
  5. Action required: Ensure Principal Officer acknowledges receipt of this circular and disseminates it to relevant teams.
  6. Action required: Review existing business relationships with entities from these jurisdictions for potential ML/FT risks.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6243&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗