Current · Source: Reserve Bank of India · RBI/2011-12/305 · issued 19 Dec 2011 · ~2 min read
Quick answerRBI now requires banks to formally assess and document money laundering and terror financing risks across customers, geographies, products, and delivery channels, with board-approved policies to manage these risks.
The rule, in the simplest words
Banks must now write down a full check of how bad guys could use the bank to hide money or fund bad acts, looking at all customers, places, products, and ways to deliver services.
The bank's board must say 'yes' to a plan that explains how the bank will lower these risks, and the bank must follow that plan.
For any customer or product that is medium or high risk, the bank must do extra checks (like asking for more proof or watching more closely).
Banks can't just look at each customer alone; they must also check the whole group of customers and the risks from different countries and products.
How it plays out — a real example
A KYC & compliance officer in Indore is updating the bank's risk checklist. She now has to write down that giving gold loans in a busy market area is medium risk because many small shops could be used to hide cash. She then tells her team to ask for extra ID proof from any customer who takes a gold loan over ₹2 lakh, and to watch those accounts more often.
What changed
RBI has expanded existing KYC/AML requirements by mandating a structured, documented risk assessment for money laundering and terror financing across all customer segments, geographies, products, services, and delivery channels. Banks must now have board-approved policies, controls, and procedures to manage and mitigate these risks using a risk-based approach, with enhanced due diligence for medium or high-risk categories.
What it means for you
Banks can no longer rely solely on customer-level risk profiling; they must now assess and document ML/TF risk at the portfolio level, including country and product risks. This will require significant upgrades to risk management frameworks, transaction monitoring systems, and board-level oversight. Non-compliance invites penalties under the Banking Regulation Act, 1949.
What you must do
Conduct a comprehensive ML/TF risk assessment covering customers, geographies, products, services, and delivery channels.
Develop and get board approval for policies, controls, and procedures to manage and mitigate identified risks.
Implement enhanced due diligence measures for all medium and high-risk categories identified in the assessment.
Use IBA's guidance on risk-based transaction monitoring as a reference for your own risk assessment framework.
Ensure compliance with Section 35A of the Banking Regulation Act, 1949 and PMLA rules, with documented evidence of risk assessment.
Who it affects
All Scheduled Commercial Banks (excluding RRBs), All India Financial Institutions, Local Area Banks, Board of Directors and senior management of these entities, Compliance and AML/KYC teams
❓ Common questions
What is the key change from the earlier Master Circular?
Earlier, banks only needed to prepare risk profiles of individual customers. Now, they must also assess and document ML/TF risk at the entity level, including country, product, and delivery channel risks, with board-approved policies.
What happens if we don't comply with this circular?
Non-compliance is a contravention of the Banking Regulation Act, 1949 and PMLA rules, and will attract penalties under the B R Act, 1949.
Can we use the IBA guidance as our risk assessment framework?
Yes, RBI explicitly states that banks may use the IBA's Report on Parameters for Risk Based Transaction Monitoring as guidance, but the final risk assessment and policies must be approved by your board.
📜 Read the original circular — full text as issued by RBI
RBI/2011-12/305
DBOD. AML.BC. No.65 /14.01.001/2011-12
December 19, 2011
The Chairmen / Chief Executive Officers
All Scheduled Commercial Banks (excluding RRBs)/
All India Financial institutions/ Local Area Banks
Dear Sir,
Know Your Customer (KYC) norms/Anti-Money Laundering (AML) standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under Prevention of Money Laundering Act (PMLA), 2002- Assessment and Monitoring of Risk
Please refer to our Master Circular DBOD.AML.BC.No.2/ 14.01.001 / 2011 -12 dated July 01, 2011 on Know Your Customer (KYC) norms /Anti-Money Laundering (AML) standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under PMLA, 2002.
2. In terms of paragraph 2.3 (b) and (c) of the aforesaid Master Circular, banks are required to prepare a risk profile of each customer and apply enhanced due diligence measures on higher risk customers. Some illustrative examples of customers requiring higher due diligence have also been provided in the paragraph under reference. Further, paragraph 2.12 (a) of the Master Circular requires banks to put in place policies, systems and procedures for risk management keeping in view the risks involved in a transaction, account or banking/business relationship.
3. The Government of India had constituted a National Money Laundering/Financing of Terror Risk Assessment Committee to assess money laundering and terror financing risks, a national AML/CFT strategy and institutional framework for AML/CFT in India. Assessment of risk of Money Laundering /Financing of Terrorism helps both the competent authorities and the regulated entities in taking necessary steps for combating ML/FT adopting a risk-based approach. This helps in judicious and efficient allocation of resources and makes the AML/CFT regime more robust. The Committee has made recommendations regarding adoption of a risk-based approach, assessment of risk and putting in place a system which would use that assessment to take steps to effectively counter ML/FT. The recommendations of the Committee have since been accepted by the Government of India and need to be implemented.
4. Accordingly, banks/FIs should take steps to identify and assess their ML/TF risk for customers, countries and geographical areas as also for products/ services/ transactions/delivery channels, in addition to what has been prescribed in our Master Circular dated July 1, 2011, referred to in paragraph 2 above. Banks/FIs should have policies, controls and procedures, duly approved by their boards, in place to effectively manage and mitigate their risk adopting a risk-based approach as discussed above. As a corollary, banks would be required to adopt enhanced measures for products, services and customers with a medium or high risk rating.
5. In this regard, Indian Banks' Association (IBA) has taken initiative in assessment of ML/FT risk in the banking sector. It has circulated to its member banks on May 18, 2011, a copy of their Report on Parameters for Risk Based Transaction Monitoring (RBTM) as a supplement to their guidance note on Know Your Customer (KYC) norms / Anti-Money Laundering (AML) standards issued in July 2009. The IBA guidance also provides an indicative list of high risk customers, products, services and geographies. Banks may use the same as guidance in their own risk assessment.
6. These guidelines are issued under Section 35A of the Banking Regulation Act, 1949 read with Rule 7 of Prevention of Money-laundering (Maintenance of Records of the Nature and Value of Transactions, the Procedure and Manner of Maintaining and Time for Furnishing Information and Verification and Maintenance of Records of the Identity of the Clients of the Banking Companies, Financial Institutions and Intermediaries) Rules, 2005. Any contravention thereof or non-compliance shall attract penalties under B R Act, 1949.
Please acknowledge receipt.
Yours faithfully,
(Deepak Singhal)
Chief General Manager in-Charge
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2011-12/305 · issued 19 Dec 2011. The plain-English explanation above is BankPulse’s own independent summary.
Example: if you are a Compliance officer at a bank this circular applies to (All Scheduled Commercial Banks (excluding RRBs), All India Financial Institutions, Local Area Banks, Board of Directors and senior management of these entities, Compliance and AML/KYC teams), your first concrete step on “RBI mandates bank-wide ML/TF risk assessment” is: “Conduct a comprehensive ML/TF risk assessment covering customers, geographies, products, services, and delivery channels.” (RBI issued this 19 Dec 2011).
Action required: Conduct a comprehensive ML/TF risk assessment covering customers, geographies, products, services, and delivery channels.
Action required: Develop and get board approval for policies, controls, and procedures to manage and mitigate identified risks.
Action required: Implement enhanced due diligence measures for all medium and high-risk categories identified in the assessment.
Action required: Use IBA's guidance on risk-based transaction monitoring as a reference for your own risk assessment framework.
Action required: Ensure compliance with Section 35A of the Banking Regulation Act, 1949 and PMLA rules, with documented evidence of risk assessment.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6877&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.