HomeCirculars › RBI/2011-12/428

UCBs Must Now Assess and Mitigate ML/FT Risk Systematically

Current · Source: Reserve Bank of India · RBI/2011-12/428 · issued 05 Mar 2012 · ~2 min read
Quick answerRBI mandates urban co-operative banks to identify and assess money laundering and terror financing risks for customers, geographies, products, and delivery channels. Banks must adopt board-approved policies and enhanced due diligence for medium or high-risk categories, following a national risk assessment framework.
The rule, in the simplest words
How it plays out — a real example

Ravi, a KYC & compliance officer in Indore, now has to fill out a new risk form for every customer. For a farmer who takes a small loan for seeds, Ravi marks the risk as low. But for a new customer who wants a big loan and lives in a faraway city, Ravi marks it as medium and asks for extra papers, like proof of where the money comes from, to follow the new rule.

What changed

Previously, UCBs only needed to prepare customer risk profiles and apply enhanced due diligence on higher-risk customers. Now, they must systematically identify and assess ML/FT risks across customers, countries, geographies, products, services, transactions, and delivery channels. Banks are required to have board-approved policies and procedures to manage and mitigate these risks using a risk-based approach, with enhanced measures for medium or high-risk ratings.

What it means for you

UCBs must move from basic customer risk profiling to a comprehensive, enterprise-wide risk assessment covering all aspects of their operations. This will require significant investment in systems, training, and governance to identify and mitigate ML/FT risks effectively. Non-compliance can attract penalties under the Banking Regulation Act, so boards must prioritize this.

What you must do

Who it affects

All Primary (Urban) Co-operative Banks, Board of Directors of UCBs, Compliance and risk management teams of UCBs, Internal audit functions of UCBs

❓ Common questions

What is the key new requirement for UCBs under this circular?

UCBs must now identify and assess ML/FT risks not just for customers, but also for countries, geographies, products, services, transactions, and delivery channels. They need board-approved policies and enhanced due diligence for medium or high-risk items.

Can UCBs use external guidance for their risk assessment?

Yes, the circular explicitly mentions that the IBA guidance note on KYC/AML standards (July 2009) provides an indicative list of high-risk customers, products, services, and geographies. UCBs may use this as guidance for their own risk assessment.

What are the consequences of non-compliance with these guidelines?

These guidelines are issued under Section 35A of the Banking Regulation Act, 1949 (AACS) read with PMLA Rules, 2005. Any contravention or non-compliance will attract penalties under the B R Act, 1949 (AACS).

📜 Read the original circular — full text as issued by RBI
RBI/2011-12/428 UBD. CO. BPD. No 24 /12.05.001 / 2011-12 March  5, 2012 The Chief Executive Officers of All Primary (Urban) Co-operative Banks Dear Sir, Know Your Customer (KYC) norms/Anti-Money Laundering (AML) standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under Prevention of Money Laundering Act (PMLA), 2002- Assessment and Monitoring of Risk Please refer to our circular UBD. PCB. Cir. 30/09.161.00/2004-05 dated December 15, 2004 and subsequent instructions/circulars on Know Your Customer (KYC) norms and Anti-Money Laundering (AML) standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under PMLA, 2002. 2. In terms of extant instructions, banks are required to prepare a risk profile of each customer and apply enhanced due diligence measures on higher risk customers. Some illustrative examples of customers requiring higher due diligence have also been provided in the above referred circulars. Further, banks are also required to put in place policies, systems and procedures for risk management keeping in view the risks involved in a transaction, account or banking/business relationship. 3. The Government of India had constituted a National Money Laundering/Financing of Terror Risk Assessment Committee to assess money laundering and terror financing risks, a national AML/CFT strategy and institutional framework for AML/CFT in India. Assessment of risk of Money Laundering /Financing of Terrorism (ML / FT) helps both the competent authorities and the regulated entities in taking necessary steps for combating ML/FT adopting a risk-based approach. This helps in judicious and efficient allocation of resources and makes the AML/CFT regime more robust. The Committee has made recommendations regarding adoption of a risk-based approach, assessment of risk and putting in place a system which would use that assessment to take steps to effectively counter ML/FT. The recommendations of the Committee have since been accepted by the Government of India and need to be implemented. 4. Accordingly, UCBs should take steps to identify and assess their ML/FT risk for customers, countries and geographical areas as also for products/ services/ transactions/delivery channels, in addition to what has been prescribed in the circulars referred to in paragraph 1 above. UCBs should have policies, controls and procedures, duly approved by their boards in place, to effectively manage and mitigate their risk adopting a risk-based approach as discussed above. As a corollary, banks would be required to adopt enhanced measures for products, services and customers with a medium or high risk rating. 5. In this regard, Indian Banks' Association (IBA) has taken initiative in assessment of ML/FT risk in the banking sector and prepared a guidance note on Know Your Customer (KYC) norms / Anti-Money Laundering (AML) standards in July 2009. The guidance note is available on the IBA website. The IBA guidance also provides an indicative list of high risk customers, products, services and geographies. UCBs may use the same as guidance in their own risk assessment. 6. These guidelines are issued under Section 35A of the Banking Regulation Act, 1949 (AACS) read with Rule 7 of Prevention of Money-laundering (Maintenance of Records of the Nature and Value of Transactions, the Procedure and Manner of Maintaining and Time for Furnishing Information and Verification and Maintenance of Records of the Identity of the Clients of the Banking Companies, Financial Institutions and Intermediaries) Rules, 2005. Any contravention thereof or non-compliance shall attract penalties under B R Act, 1949 (AACS). 7. Please acknowledge receipt to the Regional Office concerned. Yours faithfully, (A.Udgata) Chief General Manager in-Charge
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2011-12/428 · issued 05 Mar 2012. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All Primary (Urban) Co-operative Banks, Board of Directors of UCBs, Compliance and risk management teams of UCBs, Internal audit functions of UCBs), your first concrete step on “UCBs Must Now Assess and Mitigate ML/FT Risk Systematically” is: “Conduct a thorough ML/FT risk assessment covering customers, geographies, products, services, transactions, and delivery channels.” (RBI issued this 05 Mar 2012).

  1. Circular: RBI/2011-12/428 -- UCBs Must Now Assess and Mitigate ML/FT Risk Systematically
  2. Issued: 05 Mar 2012
  3. Action required: Conduct a thorough ML/FT risk assessment covering customers, geographies, products, services, transactions, and delivery channels.
  4. Action required: Develop and get board approval for policies, controls, and procedures to manage and mitigate identified risks using a risk-based approach.
  5. Action required: Implement enhanced due diligence measures for all customers, products, or services rated medium or high risk.
  6. Action required: Refer to the IBA guidance note (July 2009) for indicative lists of high-risk categories and use it as a benchmark for your own risk assessment.
  7. Action required: Ensure compliance with Section 35A of the Banking Regulation Act and PMLA Rules, 2005, and acknowledge receipt of this circular to your Regional Office.
  8. Owner: ____________ Target date: ____________
  9. Board/committee approval needed? Y / N
  10. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=7041&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗