HomeCirculars › RBI/2011-12/595

RBI Mandates KYC Risk Categorization & Profile Updation by March 2013

Current · Source: Reserve Bank of India · RBI/2011-12/595 · issued 08 Jun 2012 · ~1 min read
Quick answerRBI directs all scheduled commercial banks (excluding RRBs) and local area banks to complete risk categorization and profile updation of all existing customers by end-March 2013, citing lax compliance and operational risk vulnerabilities.
The rule, in the simplest words
How it plays out — a real example

A KYC & compliance officer in Indore, Mr. Kumar, is tasked with reviewing and updating the risk profiles of all existing customers. He ensures that each customer's risk categorization is accurate and up-to-date, and that the bank's system for periodic review is functioning properly. This helps the bank to reduce operational risk exposure and comply with regulatory guidelines.

What changed

RBI observed laxities in banks' implementation of KYC/AML/CFT guidelines, particularly in risk categorization, customer profile updation, and alert monitoring. It now mandates a time-bound completion of these processes for all existing customers, with a deadline of March 31, 2013.

What it means for you

Banks must urgently review and update customer risk profiles to meet regulatory standards, reducing operational risk exposure. Non-compliance could leave banks vulnerable to money laundering and terrorism financing risks, potentially attracting supervisory action.

What you must do

Who it affects

All scheduled commercial banks (excluding RRBs), Local area banks, KYC/AML compliance teams, Branch operations and customer onboarding staff

❓ Common questions

What is the deadline for completing risk categorization and profile updation?

The deadline is end-March 2013, as per the Monetary Policy Statement 2012-13 and RBI circular dated June 8, 2012.

Why is RBI emphasizing this now?

RBI observed laxities in banks' implementation of KYC/AML guidelines, which increases operational risk and vulnerability to money laundering and terrorism financing.

Which banks are covered by this circular?

All scheduled commercial banks (excluding Regional Rural Banks) and local area banks are required to comply.

📜 Read the original circular — full text as issued by RBI
RBI/2011-12/595 DBOD. AML.BC. No.110/14.01.001/2011-12 June 08, 2012 The Chairmen / CEOs of all Scheduled Commercial Banks (Excluding RRBs)/ Local Area Banks Dear Sir, Know Your Customer (KYC)/Anti-Money Laundering (AML)/Combating of Financing of Terrorism (CFT) - Risk Categorization and Updation of Customer Profiles Please refer to our circular DBOD.AML.BC.No.63 /14.01.001/2007-08 dated February 18, 2008 on KYC/AML/CFT. 2. In order to have an effective implementation of KYC/AML/CFT measures, banks were advised to put in place a system of periodic review of risk categorization of customers and updation of customer identification data. 3. In this context, a reference is invited to paragraphs 98 and 99 (extracts enclosed ) of the Monetary Policy Statement 2012-13 announced on April 17, 2012 on Implementation of KYC/AML Guidelines. Banks are aware that risk categorization of customers as also compilation and periodic updation of customer profiles and monitoring and closure of alerts in accounts by banks are extremely important for effective implementation of KYC/AML/CFT measures. It is, however, observed that there are laxities in effective implementation of the Reserve Bank’s guidelines in this area, leaving banks vulnerable to operational risk. Banks should, therefore, ensure compliance with the regulatory guidelines on KYC/AML/CFT both in letter and spirit. 4. Accordingly, banks are advised to complete the process of risk categorization and compiling/updating profiles of all of their existing customers in a time-bound manner, and in any case not later than end-March 2013. Yours faithfully, (Sudha Damodar) Chief General Manager Monetary Policy Statement 2012-13 Implementation of KYC/AML Guidelines 98. Risk categorisation of customers as also compilation, periodic updation of customer profiles and monitoring and closure of alerts in accounts by banks are very important for effective implementation of KYC, anti-money laundering (AML) and combating of financing of terrorism (CFT) measures apart from helping their business development. It is, however, observed that there are laxities in effective implementation of the Reserve Bank’s guidelines on KYC/AML measures. Any weakness in the KYC/AML process would leave banks vulnerable to operational risk. Banks should, therefore, ensure compliance with the regulatory guidelines on KYC/AML in both letter and spirit. Accordingly, it is proposed: to mandate banks to complete the process of risk categorisation and compiling/updating profiles of all of their existing customers in a time-bound manner, and in any case not later than end-March 2013. 99. Detailed guidelines in this regard will be issued separately.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2011-12/595 · issued 08 Jun 2012. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
💻 IT / Systems
  • Establish a system for periodic review of risk categorization and customer identification data.
📜 Compliance
  • Complete risk categorization and profile updation for all existing customers by March 31, 2013.
  • Ensure robust monitoring and closure of alerts in accounts to strengthen KYC/AML/CFT compliance.
  • Conduct internal audits to verify compliance with RBI guidelines in letter and spirit.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All scheduled commercial banks (excluding RRBs), Local area banks, KYC/AML compliance teams, Branch operations and customer onboarding staff), your first concrete step on “RBI Mandates KYC Risk Categorization & Profile Updation by March 2013” is: “Complete risk categorization and profile updation for all existing customers by March 31, 2013.” (RBI issued this 08 Jun 2012).

  1. Circular: RBI/2011-12/595 -- RBI Mandates KYC Risk Categorization & Profile Updation by March 2013
  2. Issued: 08 Jun 2012
  3. Action required: Complete risk categorization and profile updation for all existing customers by March 31, 2013.
  4. Action required: Establish a system for periodic review of risk categorization and customer identification data.
  5. Action required: Ensure robust monitoring and closure of alerts in accounts to strengthen KYC/AML/CFT compliance.
  6. Action required: Conduct internal audits to verify compliance with RBI guidelines in letter and spirit.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=7264&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗