HomeCirculars › RBI/2011-12/305

RBI mandates bank-wide ML/TF risk assessment

Current · Source: Reserve Bank of India · RBI/2011-12/305 · issued 19 Dec 2011 · ~2 min read
Quick answerRBI now requires banks to formally assess and document money laundering and terror financing risks across customers, geographies, products, and delivery channels, with board-approved policies to manage these risks.
The rule, in the simplest words
How it plays out — a real example

A KYC & compliance officer in Indore is updating the bank's risk checklist. She now has to write down that giving gold loans in a busy market area is medium risk because many small shops could be used to hide cash. She then tells her team to ask for extra ID proof from any customer who takes a gold loan over ₹2 lakh, and to watch those accounts more often.

What changed

RBI has expanded existing KYC/AML requirements by mandating a structured, documented risk assessment for money laundering and terror financing across all customer segments, geographies, products, services, and delivery channels. Banks must now have board-approved policies, controls, and procedures to manage and mitigate these risks using a risk-based approach, with enhanced due diligence for medium or high-risk categories.

What it means for you

Banks can no longer rely solely on customer-level risk profiling; they must now assess and document ML/TF risk at the portfolio level, including country and product risks. This will require significant upgrades to risk management frameworks, transaction monitoring systems, and board-level oversight. Non-compliance invites penalties under the Banking Regulation Act, 1949.

What you must do

Who it affects

All Scheduled Commercial Banks (excluding RRBs), All India Financial Institutions, Local Area Banks, Board of Directors and senior management of these entities, Compliance and AML/KYC teams

❓ Common questions

What is the key change from the earlier Master Circular?

Earlier, banks only needed to prepare risk profiles of individual customers. Now, they must also assess and document ML/TF risk at the entity level, including country, product, and delivery channel risks, with board-approved policies.

What happens if we don't comply with this circular?

Non-compliance is a contravention of the Banking Regulation Act, 1949 and PMLA rules, and will attract penalties under the B R Act, 1949.

Can we use the IBA guidance as our risk assessment framework?

Yes, RBI explicitly states that banks may use the IBA's Report on Parameters for Risk Based Transaction Monitoring as guidance, but the final risk assessment and policies must be approved by your board.

📜 Read the original circular — full text as issued by RBI
RBI/2011-12/305 DBOD. AML.BC. No.65 /14.01.001/2011-12 December 19, 2011 The Chairmen / Chief Executive Officers All Scheduled Commercial Banks (excluding RRBs)/ All India Financial institutions/ Local Area Banks Dear Sir, Know Your Customer (KYC) norms/Anti-Money Laundering (AML) standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under Prevention of Money Laundering Act (PMLA), 2002- Assessment and Monitoring of Risk Please refer to our Master Circular DBOD.AML.BC.No.2/ 14.01.001 / 2011 -12 dated July 01, 2011 on Know Your Customer (KYC) norms /Anti-Money Laundering (AML) standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under PMLA, 2002. 2. In terms of paragraph 2.3 (b) and (c) of the aforesaid Master Circular, banks are required to prepare a risk profile of each customer and apply enhanced due diligence measures on higher risk customers. Some illustrative examples of customers requiring higher due diligence have also been provided in the paragraph under reference. Further, paragraph 2.12 (a) of the Master Circular requires banks to put in place policies, systems and procedures for risk management keeping in view the risks involved in a transaction, account or banking/business relationship. 3. The Government of India had constituted a National Money Laundering/Financing of Terror Risk Assessment Committee to assess money laundering and terror financing risks, a national AML/CFT strategy and institutional framework for AML/CFT in India.  Assessment of risk of Money Laundering /Financing of Terrorism helps both the competent authorities and the regulated entities in taking necessary steps for combating ML/FT adopting a risk-based approach. This helps in judicious and efficient allocation of resources and makes the AML/CFT regime more robust. The Committee has made recommendations regarding adoption of a risk-based approach, assessment of risk and putting in place a system which would use that assessment to take steps to effectively counter ML/FT. The recommendations of the Committee have since been accepted by the Government of India and need to be implemented. 4.  Accordingly, banks/FIs should take steps to identify and assess their ML/TF risk for customers, countries and geographical areas as also for products/ services/ transactions/delivery channels, in addition to what has been prescribed in our Master Circular dated July 1, 2011, referred to in paragraph 2 above. Banks/FIs should have policies, controls and procedures, duly approved by their boards, in place to effectively manage and mitigate their risk adopting a risk-based approach as discussed above. As a corollary, banks would be required to adopt enhanced measures for products, services and customers with a medium or high risk rating. 5.  In this regard, Indian Banks' Association (IBA) has taken initiative in assessment of ML/FT risk in the banking sector. It has circulated to its member banks on May 18, 2011, a copy of their Report on Parameters for Risk Based Transaction Monitoring (RBTM) as a supplement to their guidance note on Know Your Customer (KYC) norms / Anti-Money Laundering (AML) standards issued in July 2009. The IBA guidance also provides an indicative list of high risk customers, products, services and geographies. Banks may use the same as guidance in their own risk assessment. 6. These guidelines are issued under Section 35A of the Banking Regulation Act, 1949 read with Rule 7 of Prevention of Money-laundering (Maintenance of Records of the Nature and Value of Transactions, the Procedure and Manner of Maintaining and Time for Furnishing Information and Verification and Maintenance of Records of the Identity of the Clients of the Banking Companies, Financial Institutions and Intermediaries) Rules, 2005. Any contravention thereof or non-compliance shall attract penalties under B R Act, 1949. Please acknowledge receipt. Yours faithfully, (Deepak Singhal) Chief General Manager in-Charge
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2011-12/305 · issued 19 Dec 2011. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All Scheduled Commercial Banks (excluding RRBs), All India Financial Institutions, Local Area Banks, Board of Directors and senior management of these entities, Compliance and AML/KYC teams), your first concrete step on “RBI mandates bank-wide ML/TF risk assessment” is: “Conduct a comprehensive ML/TF risk assessment covering customers, geographies, products, services, and delivery channels.” (RBI issued this 19 Dec 2011).

  1. Circular: RBI/2011-12/305 -- RBI mandates bank-wide ML/TF risk assessment
  2. Issued: 19 Dec 2011
  3. Action required: Conduct a comprehensive ML/TF risk assessment covering customers, geographies, products, services, and delivery channels.
  4. Action required: Develop and get board approval for policies, controls, and procedures to manage and mitigate identified risks.
  5. Action required: Implement enhanced due diligence measures for all medium and high-risk categories identified in the assessment.
  6. Action required: Use IBA's guidance on risk-based transaction monitoring as a reference for your own risk assessment framework.
  7. Action required: Ensure compliance with Section 35A of the Banking Regulation Act, 1949 and PMLA rules, with documented evidence of risk assessment.
  8. Owner: ____________ Target date: ____________
  9. Board/committee approval needed? Y / N
  10. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6877&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗