HomeCirculars › RBI/2011-12/327

KYC/AML/CFT Risk Assessment for Co-operative Banks

Current · Source: Reserve Bank of India · RBI/2011-12/327 · issued 30 Dec 2011 · ~2 min read
Quick answerRBI directs StCBs/DCCBs to identify and assess ML/TF risk across customers, geographies, products, and channels, and adopt board-approved policies for risk-based mitigation. Enhanced due diligence is required for medium/high-risk accounts.
The rule, in the simplest words
How it plays out — a real example

A KYC & compliance officer in Indore reviews her bank's new risk assessment. She sees that customers from a high-risk country need extra paperwork, so she asks for proof of income and source of gold before approving a loan, following the board-approved policy to keep the bank safe from money laundering.

What changed

RBI now requires co-operative banks to conduct a formal risk assessment of money laundering and terror financing across customers, countries, products, services, and delivery channels. This goes beyond earlier guidance that only asked for customer risk profiling and enhanced due diligence on high-risk cases. Banks must also implement board-approved policies and controls to manage these risks using a risk-based approach.

What it means for you

Co-operative banks must now systematically evaluate and document ML/TF risks across all business dimensions, not just customer profiles. This will require investment in risk assessment frameworks, training, and monitoring systems. Non-compliance can attract regulatory action under the Banking Regulation Act and PMLA rules.

What you must do

Who it affects

State Co-operative Banks (StCBs), District Central Co-operative Banks (DCCBs), All co-operative banks regulated by RBI

❓ Common questions

What is the key new requirement in this circular?

Co-operative banks must now formally assess ML/TF risk across customers, countries, products, services, and delivery channels, and have board-approved policies to manage these risks.

Can we use the IBA guidance for our risk assessment?

Yes, RBI explicitly allows StCBs/DCCBs to use the IBA's Report on Parameters for Risk Based Transaction Monitoring as guidance for their own risk assessment.

What happens if we don't comply?

Non-compliance is a contravention under Section 35A of the Banking Regulation Act and PMLA Rules, which can lead to regulatory action.

📜 Read the original circular — full text as issued by RBI
RBI/2011-12/327 RPCD.CO.RCB. AML.BC. No.50/07.40.00/2011-12 December 30, 2011 The Chairmen / Chief Executive Officers All State and Central Co-operative Banks Dear Sir, Know Your Customer (KYC) norms/Anti-Money Laundering (AML) standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under Prevention of Money Laundering Act (PMLA), 2002- Assessment and Monitoring of Risk Please refer to our circular RPCD.AML.BC.No.80/07.40.00/2004-05 dated February 18, 2005 on Know Your Customer (KYC) Guidelines - Anti-Money Laundering (AML) standards and RPCD.CO.RCB.AML.BC.No.50/07.40.00/2010-11 dated February 2, 2011 on Know Your Customer (KYC) Norms / Anti-Money Laundering (AML) standards /Combating of Financing of Terrorism (CFT) / Obligation of banks under PMLA, 2002. 2. In terms of paragraph 2 of the Guidelines on ’Know Your Customer’ Norms and Anti-Money Laundering Measures enclosed to our circular dated February 18, 2005 and paragraph 2 of the circular dated February 2, 2011, State and Central Co-operative Banks (StCBs/DCCBs) are required to prepare a risk profile of each customer and apply enhanced due diligence measures on higher risk customers. Some illustrative examples of customers requiring higher due diligence have also been provided in the paragraph under reference.Further, paragraph 5 of the circular dated February 18, 2005 requires StCBs/DCCBs to put in place policies, systems and procedures for risk management keeping in view the risks involved in a transaction, account or banking/business relationship. 3. The Government of India had constituted a National Money Laundering / Financing of Terror Risk Assessment Committee to assess money laundering and terror financing risks, a national AML/CFT strategy and institutional framework for AML/CFT in India.  Assessment of risk of Money Laundering /Financing of Terrorism helps both the competent authorities and the regulated entities in taking necessary steps for combating ML/FT adopting a risk-based approach. This helps in judicious and efficient allocation of resources and makes the AML/CFT regime more robust. The Committee has made recommendations regarding adoption of a risk-based approach, assessment of risk and putting in place a system which would use that assessment to take steps to effectively counter ML/FT. The recommendations of the Committee have since been accepted by the Government of India and need to be implemented. 4. Accordingly, StCBs/DCCBs should take steps to identify and assess their ML/TF risk for customers, countries and geographical areas as also for products/ services/ transactions/delivery channels, in addition to what has been prescribed in our circulars dated February 18, 2005 and February 2, 2011 referred to in paragraph 2 above. StCBs/DCCBs should have policies, controls and procedures, duly approved by their boards, in place to effectively manage and mitigate their risk adopting a risk-based approach as discussed above. As a corollary, StCBs/DCCBs would be required to adopt enhanced measures for products, services and customers with a medium or high risk rating. 5. In this regard, Indian Banks' Association (IBA) has taken initiative in assessment of ML/FT risk in the banking sector. It has circulated to its member banks on May 18, 2011, a copy of their Report on Parameters for Risk Based Transaction Monitoring (RBTM) as a supplement to their guidance note on Know Your Customer (KYC) norms / Anti-Money Laundering (AML) standards issued in July 2009. The IBA guidance also provides an indicative list of high risk customers, products, services and geographies. StCBs/DCCBs may use the same as guidance in their own risk assessment. 6. These guidelines are issued under Section 35A of the Banking Regulation Act, 1949 (As Applicable to Co-operative Societies) read with Rule 7 of Prevention of Money-laundering (Maintenance of Records of the Nature and Value of Transactions, the Procedure and Manner of Maintaining and Time for Furnishing Information and Verification and Maintenance of Records of the Identity of the Clients of the Banking Companies, Financial Institutions and Intermediaries) Rules, 2005.Any contravention thereof or non-compliance shall attract penalties under the Act, ibid. Please acknowledge receipt of the circular to our Regional Office concerned. Yours faithfully, (C.D.Srinivasan) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2011-12/327 · issued 30 Dec 2011. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (State Co-operative Banks (StCBs), District Central Co-operative Banks (DCCBs), All co-operative banks regulated by RBI), your first concrete step on “KYC/AML/CFT Risk Assessment for Co-operative Banks” is: “Conduct a comprehensive ML/TF risk assessment covering customers, geographies, products, services, and delivery channels.” (RBI issued this 30 Dec 2011).

  1. Circular: RBI/2011-12/327 -- KYC/AML/CFT Risk Assessment for Co-operative Banks
  2. Issued: 30 Dec 2011
  3. Action required: Conduct a comprehensive ML/TF risk assessment covering customers, geographies, products, services, and delivery channels.
  4. Action required: Develop and get board approval for policies, controls, and procedures to manage and mitigate identified risks.
  5. Action required: Apply enhanced due diligence for all medium and high-risk customers, products, and services.
  6. Action required: Use IBA's guidance on Risk Based Transaction Monitoring as a reference for your own risk assessment.
  7. Action required: Ensure compliance with Section 35A of the Banking Regulation Act and PMLA Rules, 2005.
  8. Owner: ____________ Target date: ____________
  9. Board/committee approval needed? Y / N
  10. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6908&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗