Current · Source: Reserve Bank of India · RBI/2013-14/150 · issued 23 Jul 2013 · ~2 min read
Quick answerRBI has relaxed KYC updation frequency: full KYC every 10 years for low-risk, 8 for medium-risk, and 2 for high-risk customers. Positive confirmation required every 2-3 years for medium/low risk. Fresh photos on minor becoming major.
The rule, in the simplest words
For low-risk customers, do a full KYC (checking all ID and address proof) every 10 years.
For medium-risk customers, do a full KYC every 8 years.
For high-risk customers, do a full KYC every 2 years.
For medium-risk customers, get a positive confirmation (like an email or phone call to check if details changed) every 2 years; for low-risk, every 3 years.
When a minor customer turns 18 (becomes major), take a new photo for their account.
How it plays out — a real example
A KYC & compliance officer in Indore is updating customer files. For Mrs. Sharma, a low-risk customer who has had an account for 9 years, the officer schedules a full KYC check next year, but sends her a friendly email every 3 years to confirm her address is still the same. For a high-risk business customer, the officer insists on a full KYC review every 2 years without fail.
What changed
Earlier, full KYC updation was required every 5 years for low-risk and every 2 years for high/medium-risk customers. Now, full KYC is required every 10 years for low-risk, every 8 years for medium-risk, and every 2 years for high-risk customers. Additionally, positive confirmation (via email, letter, phone, etc.) is needed every 2 years for medium-risk and every 3 years for low-risk customers.
What it means for you
Banks can reduce the compliance burden for low and medium-risk customers by extending full KYC cycles, but must maintain ongoing due diligence and transaction monitoring. The new rules require banks to update KYC policies and ensure strict adherence, especially for high-risk customers who still face 2-year full KYC cycles. Fresh photographs must be obtained when minor customers become major.
What you must do
Revise your bank's KYC policy to reflect the new periodicity: full KYC every 10 years for low-risk, 8 for medium-risk, and 2 for high-risk customers.
Implement a system for positive confirmation every 2 years for medium-risk and every 3 years for low-risk customers using email, letter, phone, or visits.
Ensure ongoing due diligence and transaction monitoring for all customers, especially high-risk ones.
Update procedures to obtain fresh photographs from minor customers upon reaching majority.
Who it affects
All Scheduled Commercial Banks (excluding RRBs), Local Area Banks, All India Financial Institutions
❓ Common questions
What is the new full KYC updation period for low-risk customers?
Full KYC exercise must be done at least every ten years for low-risk individuals and entities, as per the July 2013 circular.
Do we still need to do positive confirmation for low-risk customers?
Yes, positive confirmation (via email, letter, phone, etc.) is required at least every three years for low-risk customers, in addition to the full KYC every ten years.
What about minor customers turning major?
Fresh photographs must be obtained from minor customers when they become major, as per the updated instructions.
📜 Read the original circular — full text as issued by RBI
RBI/2013-14/150
DBOD.AML.BC. No. 34/14.01.001/2013-14
July 23, 2013
The Chairmen / CEOs of all Scheduled Commercial Banks
(Excluding RRBs)/Local Area Banks / All India Financial Institutions
Dear Sir,
Know Your Customer (KYC) Norms /Anti-Money Laundering (AML) Standards/ Combating of Financing of Terrorism (CFT)/Obligation of banks under Prevention of Money Laundering Act (PMLA), 2002 - Simplifying norms for Periodical Updation of KYC
Please refer to paragraph 2.4 (k) of our Master circular DBOD.AML.BC. No. 24/14.01.001/2013-14 dated July 1, 2013 on Know Your Customer (KYC) Norms / Anti-Money Laundering (AML) Standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under PMLA, 2002 which states that “Banks should introduce a system of periodical updation of customer identification data (including photograph/s) after the account is opened. The periodicity of such updation should not be less than once in five years in the case of low risk category customers and not less than once in two years in case of high and medium risk categories”.
2. The issue has been reviewed in the light of practical difficulties/constraints expressed by bankers/customers in obtaining/submitting fresh KYC documents at frequent intervals as the relative documents submitted earlier specially by low-risk customers have remained unchanged in most of the accounts. Accordingly, based on the suggestions received, it has been decided to amend the instructions as under:
a) Banks would need to continue to carry out on-going due diligence with respect to the business relationship with every client and closely examine the transactions in order to ensure that they are consistent with their knowledge of the client, his business and risk profile and, wherever necessary, the source of funds.
b) Full KYC exercise will be required to be done at least every two years for high risk individuals and entities.
c) Full KYC exercise will be required to be done at least every ten years for low risk and at least every eight years for medium risk individuals and entities.
d) Positive confirmation (obtaining KYC related updates through e-mail/letter/telephonic conversation/forms/interviews/visits, etc.), will be required to be completed at least every two years for medium risk and at least every three years for low risk individuals and entities.
e) Fresh photographs will be required to be obtained from minor customer on becoming major.
3. Banks may revise their KYC policy in the light of the above instructions and ensure strict adherence to the same.
Yours faithfully,
(Prakash Chandra Sahoo)
Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2013-14/150 · issued 23 Jul 2013. The plain-English explanation above is BankPulse’s own independent summary.
Implement a system for positive confirmation every 2 years for medium-risk and every 3 years for low-risk customers using email, letter, phone, or visits.
📜 Compliance
Revise your bank's KYC policy to reflect the new periodicity: full KYC every 10 years for low-risk, 8 for medium-risk, and 2 for high-risk customers.
Ensure ongoing due diligence and transaction monitoring for all customers, especially high-risk ones.
Update procedures to obtain fresh photographs from minor customers upon reaching majority.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are a Compliance officer at a bank this circular applies to (All Scheduled Commercial Banks (excluding RRBs), Local Area Banks, All India Financial Institutions), your first concrete step on “KYC Updation Periodicity Simplified for Banks” is: “Revise your bank's KYC policy to reflect the new periodicity: full KYC every 10 years for low-risk, 8 for medium-risk, and 2 for high-risk customers.” (RBI issued this 23 Jul 2013).
Circular: RBI/2013-14/150 -- KYC Updation Periodicity Simplified for Banks
Issued: 23 Jul 2013
Action required: Revise your bank's KYC policy to reflect the new periodicity: full KYC every 10 years for low-risk, 8 for medium-risk, and 2 for high-risk customers.
Action required: Implement a system for positive confirmation every 2 years for medium-risk and every 3 years for low-risk customers using email, letter, phone, or visits.
Action required: Ensure ongoing due diligence and transaction monitoring for all customers, especially high-risk ones.
Action required: Update procedures to obtain fresh photographs from minor customers upon reaching majority.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8259&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.