HomeCirculars › RBI/2013-14/261

RBI Cracks Down on Overreach in KYC Data Collection by RRBs and Co-op Banks

Current · Source: Reserve Bank of India · RBI/2013-14/261 · issued 16 Sep 2013 · ~2 min read
Quick answerRBI has warned RRBs and cooperative banks against demanding excessive personal details (e.g., dependents, spouse name, assets) for KYC. Only mandatory risk-relevant info must be collected at account opening; optional data needs explicit customer consent and must be kept confidential.
The rule, in the simplest words
How it plays out — a real example

Meena, a KYC & compliance officer in Indore, was updating a customer's KYC form. She remembered the new RBI rule and stopped herself from asking the customer how many children he had or what his wife's name was. Instead, she only collected the mandatory risk-related details and explained that any extra information would need his written permission later.

What changed

RBI observed that banks were seeking intrusive personal information—like number of dependents, names of children, lifestyle details, foreign visits, assets, and spouse details—beyond what is required for KYC/AML compliance. The circular reiterates that only mandatory, risk-relevant information should be collected at account opening; any optional data must be obtained separately with explicit customer consent and kept confidential.

What it means for you

Banks must immediately stop demanding excessive personal details from customers during account opening or periodic updates. This reduces customer friction and privacy complaints, but also tightens compliance: banks need to clearly distinguish mandatory vs. optional fields and obtain explicit consent for the latter. Non-adherence could invite regulatory action.

What you must do

Who it affects

Regional Rural Banks (RRBs), State Cooperative Banks (StCBs), Central Cooperative Banks (CCBs), Customers opening accounts or undergoing periodic KYC updation

❓ Common questions

What specific information is now considered 'overboard' for KYC?

RBI flagged details like number of dependents, names of children, lifestyle, foreign visits in last three years, family members abroad, assets/liabilities, spouse name/DOB, wedding date, and investments as intrusive and not mandatory for KYC.

Can we still collect optional information from customers?

Yes, but only after the account is opened and with the customer's explicit consent. The customer must be told which fields are mandatory and which are optional.

What are the consequences if we continue collecting excessive data?

RBI has directed strict adherence. Non-compliance may lead to regulatory action, including penalties or supervisory restrictions, and could damage customer trust.

📜 Read the original circular — full text as issued by RBI
RBI/2013-14/261 RPCD.RRB.RCB.AML.BC.No. 31/07.51.018/2013-14 September 16, 2013 The Chairmen / CEOs of all Regional Rural Banks / State and Central Co-operative Banks Dear Sir, Know Your Customer (KYC) Norms / Anti-Money Laundering (AML) Standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under PMLA, 2002 – Information sought by banks from customers Please refer to our circulars RPCD.No.RRB.BC.81/03.05.33(E)/2004-05 and RPCD.AML.BC.No.80/07.40.00/2004-05 both dated February 18, 2005 on Know Your Customer (KYC) Guidelines - Anti-Money Laundering Standards. The objective of these guidelines is to prevent banks from being used, intentionally or unintentionally, by criminal elements for money laundering or terrorist financing activities. The KYC procedures also enable banks to know/understand their customers and their financial dealings better which in turn help them manage their risks prudently. However, it has come to the notice of Reserve Bank that banks are seeking personal information/details like number of dependents, the names of sons and daughters, lifestyle, number of foreign visits undertaken during the last three years, details of family members/relatives settled abroad, assets and liabilities, name and date of birth of spouse, wedding date, investments, etc,. from customers which are not mandatory and relevant to perceive risk of a prospective customer while complying with KYC/AML requirement during the process of opening an account or during periodic updation. This has led to customer complaints that banks are going overboard in seeking information for KYC compliance and thereby invading into their privacy. 2. In this connection, attention of Regional Rural Banks and State and Central Co-operative Banks is drawn to paragraph 2 of our circulars dated February 18, 2005 referred to above that information sought from the customer is relevant to the perceived risk, is not intrusive, and is in conformity with the guidelines issued in this regard. Any other information from the customer should be sought separately with his/her consent and after opening the account. 3. It is, therefore, reiterated that ‘mandatory’ information required for KYC purpose which the customer is obliged to give while opening an account only should be obtained at the time of opening the account/during periodic updation. 4. Other ‘optional’ customer details/additional information, if required may be obtained separately after the account is opened only with the explicit consent of the customer. The customer has a right know what is the information required for KYC that she/he is obliged to give, and what is the additional information sought by the bank that is optional. 5. Further, it is reiterated that banks should keep in mind that the information (both ‘mandatory’ – before opening the account as well as ‘optional’- after opening the account with the explicit consent of the customer) collected from the customer is to be treated as confidential and details thereof are not to be divulged for cross selling or any other like purposes. 6. Regional Rural Banks and State and Central Co-operative Banks are advised to ensure strict adherence to the same. Yours faithfully, (A. Udgata) Principal Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2013-14/261 · issued 16 Sep 2013. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
🏦 Branch Manager
  • Clearly label mandatory vs. optional fields in account opening forms and customer communication.
  • Obtain explicit written consent before collecting any optional information, and only after account opening.
📜 Compliance
  • Review and prune KYC forms to remove non-mandatory fields like dependents, spouse name, wedding date, assets, and foreign visit history.
  • Ensure all customer data (mandatory and optional) is treated as confidential and not used for cross-selling without separate consent.
  • Train frontline staff on the revised KYC data collection norms to avoid overreach.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (Regional Rural Banks (RRBs), State Cooperative Banks (StCBs), Central Cooperative Banks (CCBs), Customers opening accounts or undergoing periodic KYC updation), your first concrete step on “RBI Cracks Down on Overreach in KYC Data Collection by RRBs and Co-op Banks” is: “Review and prune KYC forms to remove non-mandatory fields like dependents, spouse name, wedding date, assets, and foreign visit history.” (RBI issued this 16 Sep 2013).

  1. Circular: RBI/2013-14/261 -- RBI Cracks Down on Overreach in KYC Data Collection by RRBs and Co-op Banks
  2. Issued: 16 Sep 2013
  3. Action required: Review and prune KYC forms to remove non-mandatory fields like dependents, spouse name, wedding date, assets, and foreign visit history.
  4. Action required: Clearly label mandatory vs. optional fields in account opening forms and customer communication.
  5. Action required: Obtain explicit written consent before collecting any optional information, and only after account opening.
  6. Action required: Ensure all customer data (mandatory and optional) is treated as confidential and not used for cross-selling without separate consent.
  7. Action required: Train frontline staff on the revised KYC data collection norms to avoid overreach.
  8. Owner: ____________ Target date: ____________
  9. Board/committee approval needed? Y / N
  10. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8419&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗