RBI Mandates KYC Risk Categorization & Profile Updation by March 2013
Current · Source: Reserve Bank of India · RBI/2011-12/595 · issued 08 Jun 2012 · ~1 min read
Quick answerRBI directs all scheduled commercial banks (excluding RRBs) and local area banks to complete risk categorization and profile updation of all existing customers by end-March 2013, citing lax compliance and operational risk vulnerabilities.
The rule, in the simplest words
Banks must review and update customer risk profiles to meet regulatory standards.
Banks must complete risk categorization and profile updation for all existing customers by March 31, 2013.
Banks must establish a system for periodic review of risk categorization and customer identification data.
How it plays out — a real example
A KYC & compliance officer in Indore, Mr. Kumar, is tasked with reviewing and updating the risk profiles of all existing customers. He ensures that each customer's risk categorization is accurate and up-to-date, and that the bank's system for periodic review is functioning properly. This helps the bank to reduce operational risk exposure and comply with regulatory guidelines.
What changed
RBI observed laxities in banks' implementation of KYC/AML/CFT guidelines, particularly in risk categorization, customer profile updation, and alert monitoring. It now mandates a time-bound completion of these processes for all existing customers, with a deadline of March 31, 2013.
What it means for you
Banks must urgently review and update customer risk profiles to meet regulatory standards, reducing operational risk exposure. Non-compliance could leave banks vulnerable to money laundering and terrorism financing risks, potentially attracting supervisory action.
What you must do
Complete risk categorization and profile updation for all existing customers by March 31, 2013.
Establish a system for periodic review of risk categorization and customer identification data.
Ensure robust monitoring and closure of alerts in accounts to strengthen KYC/AML/CFT compliance.
Conduct internal audits to verify compliance with RBI guidelines in letter and spirit.
Who it affects
All scheduled commercial banks (excluding RRBs), Local area banks, KYC/AML compliance teams, Branch operations and customer onboarding staff
❓ Common questions
What is the deadline for completing risk categorization and profile updation?
The deadline is end-March 2013, as per the Monetary Policy Statement 2012-13 and RBI circular dated June 8, 2012.
Why is RBI emphasizing this now?
RBI observed laxities in banks' implementation of KYC/AML guidelines, which increases operational risk and vulnerability to money laundering and terrorism financing.
Which banks are covered by this circular?
All scheduled commercial banks (excluding Regional Rural Banks) and local area banks are required to comply.
📜 Read the original circular — full text as issued by RBI
RBI/2011-12/595
DBOD. AML.BC. No.110/14.01.001/2011-12
June 08, 2012
The Chairmen / CEOs of all Scheduled Commercial
Banks (Excluding RRBs)/ Local Area Banks
Dear Sir,
Know Your Customer (KYC)/Anti-Money Laundering (AML)/Combating of
Financing of Terrorism (CFT) - Risk Categorization and Updation of Customer Profiles
Please refer to our circular DBOD.AML.BC.No.63 /14.01.001/2007-08 dated February 18, 2008 on KYC/AML/CFT.
2. In order to have an effective implementation of KYC/AML/CFT measures, banks were advised to put in place a system of periodic review of risk categorization of customers and updation of customer identification data.
3. In this context, a reference is invited to paragraphs 98 and 99 (extracts enclosed ) of the Monetary Policy Statement 2012-13 announced on April 17, 2012 on Implementation of KYC/AML Guidelines. Banks are aware that risk categorization of customers as also compilation and periodic updation of customer profiles and monitoring and closure of alerts in accounts by banks are extremely important for effective implementation of KYC/AML/CFT measures. It is, however, observed that there are laxities in effective implementation of the Reserve Bank’s guidelines in this area, leaving banks vulnerable to operational risk. Banks should, therefore, ensure compliance with the regulatory guidelines on KYC/AML/CFT both in letter and spirit.
4. Accordingly, banks are advised to complete the process of risk categorization and compiling/updating profiles of all of their existing customers in a time-bound manner, and in any case not later than end-March 2013.
Yours faithfully,
(Sudha Damodar)
Chief General Manager
Monetary Policy Statement 2012-13
Implementation of KYC/AML Guidelines
98. Risk categorisation of customers as also compilation, periodic updation of customer profiles and monitoring and closure of alerts in accounts by banks are very important for effective implementation of KYC, anti-money laundering (AML) and combating of financing of terrorism (CFT) measures apart from helping their business development. It is, however, observed that there are laxities in effective implementation of the Reserve Bank’s guidelines on KYC/AML measures. Any weakness in the KYC/AML process would leave banks vulnerable to operational risk. Banks should, therefore, ensure compliance with the regulatory guidelines on KYC/AML in both letter and spirit. Accordingly, it is proposed:
to mandate banks to complete the process of risk categorisation and compiling/updating profiles of all of their existing customers in a time-bound manner, and in any case not later than end-March 2013.
99. Detailed guidelines in this regard will be issued separately.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2011-12/595 · issued 08 Jun 2012. The plain-English explanation above is BankPulse’s own independent summary.
Establish a system for periodic review of risk categorization and customer identification data.
📜 Compliance
Complete risk categorization and profile updation for all existing customers by March 31, 2013.
Ensure robust monitoring and closure of alerts in accounts to strengthen KYC/AML/CFT compliance.
Conduct internal audits to verify compliance with RBI guidelines in letter and spirit.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are a Compliance officer at a bank this circular applies to (All scheduled commercial banks (excluding RRBs), Local area banks, KYC/AML compliance teams, Branch operations and customer onboarding staff), your first concrete step on “RBI Mandates KYC Risk Categorization & Profile Updation by March 2013” is: “Complete risk categorization and profile updation for all existing customers by March 31, 2013.” (RBI issued this 08 Jun 2012).
Circular: RBI/2011-12/595 -- RBI Mandates KYC Risk Categorization & Profile Updation by March 2013
Issued: 08 Jun 2012
Action required: Complete risk categorization and profile updation for all existing customers by March 31, 2013.
Action required: Establish a system for periodic review of risk categorization and customer identification data.
Action required: Ensure robust monitoring and closure of alerts in accounts to strengthen KYC/AML/CFT compliance.
Action required: Conduct internal audits to verify compliance with RBI guidelines in letter and spirit.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=7264&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.