RBI simplifies KYC norms with expanded V-CIP and periodic updation
No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2021-22/35 · issued 10 May 2021 · ~2 min read
Quick answerRBI has amended the KYC Master Direction to expand Video-based Customer Identification Process (V-CIP) for onboarding individuals, proprietors, and legal entity customers, and to simplify periodic KYC updation. V-CIP is now at par with face-to-face identification, with strict tech and security standards.
What changed
The definition of V-CIP has been updated to include facial recognition, live consent-based audio-visual interaction, and independent verification with audit trail. V-CIP can now be used for CDD of new individual customers, proprietors, authorised signatories, and beneficial owners of legal entities, as well as for converting OTP-based e-KYC accounts and periodic KYC updation. Accounts opened using OTP-based e-KYC are now restricted to one year unless full identification via Section 16 or V-CIP is completed.
What it means for you
Banks and regulated entities can now onboard customers remotely using V-CIP with the same legal standing as in-person verification, reducing branch footfall and operational costs. The one-year limit on OTP-based e-KYC accounts pushes lenders to upgrade these accounts via V-CIP or face-to-face, ensuring stronger due diligence. Strict tech requirements like geo-tagging, liveness detection, and India-only IP connections raise the bar for IT infrastructure and cybersecurity compliance.
Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.
What banks were required to do at the time
Update internal KYC policies and systems to support V-CIP for all eligible customer types, including legal entities and proprietors.
Implement face liveness detection and spoof prevention technology, with regular reviews of near-miss fraud cases.
Set up processes to convert existing OTP-based e-KYC accounts within one year, using V-CIP or Section 16 identification.
Train staff on the new V-CIP standards and audit trail maintenance for compliance.
Who it affects
All regulated entities (banks, NBFCs, payment banks, etc.), IT and cybersecurity teams of regulated entities, Compliance and KYC operations teams, Customers using OTP-based e-KYC accounts
❓ Common questions
Regulatory timeline
Decoded by BankPulse2026-06-18 08:09 IST
repealed_by — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
Status change: withdrawn03 Aug 2026, 04:00 IST
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
Can V-CIP be used for all customer types?
Yes, V-CIP is allowed for onboarding individual customers, proprietors of proprietorship firms, authorised signatories, and beneficial owners of legal entities. For proprietorship firms, you must also obtain e-documents for activity proofs.
What happens to accounts opened with OTP-based e-KYC?
Such accounts are restricted to one year unless you complete full identification via Section 16 (face-to-face) or Section 18 (V-CIP). If using Aadhaar under V-CIP, a fresh Aadhaar OTP authentication is required.
What are the key tech requirements for V-CIP?
The V-CIP application must prevent connections from outside India, use end-to-end encryption, record live GPS co-ordinates and date-time stamp, and include face liveness/spoof detection and face matching technology. The infrastructure must be housed in the RE's own premises and comply with RBI's cybersecurity framework.
📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Repealed byRBI/2025-26/100 — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
RBI’s words: “Official withdrawal register entry #308: DOR.AML.REC.No.15/14.01.001/2021-22 — "Amendment to the Master Direction (MD) on KYC" dated May 10, 2021”
📜 Read the original circular — full text as issued by RBI
RBI/2021-22/35
DOR.AML.REC.No.15/14.01.001/2021-22
May 10, 2021
The Chairpersons/ CEOs of all the Regulated Entities
Madam/Sir,
Amendment to the Master Direction (MD) on KYC
Please refer to the Master Direction (MD) on KYC dated February 25, 2016 , as amended from time to time, in terms of which Regulated Entities (REs) have to undertake Customer Due Diligence (CDD) while dealing with the customers as per the process laid out therein.
2. In this regard, on a review, it has been decided to amend the MD on KYC to further leverage the Video based Customer Identification Process (V-CIP) and to simplify and rationalise the process of periodic updation of KYC. The amended provisions read as under:
I. V-CIP:
Clause (xx) of Section 3: Amended Definition of V-CIP:
Video based Customer Identification Process (V-CIP) is an alternate method of customer identification with facial recognition and customer due diligence by an authorised official of the RE by undertaking seamless, secure, live, informed-consent based audio-visual interaction with the customer to obtain identification information required for CDD purpose, and to ascertain the veracity of the information furnished by the customer through independent verification and maintaining audit trail of the process. Such processes complying with prescribed standards and procedures shall be treated on par with face-to-face CIP for the purpose of this Master Direction.
Clause (v) of Section 17:
v. Accounts, both deposit and borrowal, opened using OTP based e-KYC shall not be allowed for more than one year unless identification as per Section 16 or as per Section 18 (V-CIP) is carried out, If Aadhaar details are used under Section 18, the process shall be followed in its entirety including fresh Aadhaar OTP authentication.
Amended Section 18 on V-CIP:
REs may undertake V-CIP to carry out:
CDD in case of new customer on-boarding for individual customers, proprietor in case of proprietorship firm, authorised signatories and Beneficial Owners (BOs) in case of Legal Entity (LE) customers.
Provided that in case of CDD of a proprietorship firm, REs shall also obtain the equivalent e-document of the activity proofs with respect to the proprietorship firm, as mentioned in Section 28, apart from undertaking CDD of the proprietor.
Conversion of existing accounts opened in non-face to face mode using Aadhaar OTP based e-KYC authentication as per Section 17.
Updation/Periodic updation of KYC for eligible customers. REs opting to undertake V-CIP, shall adhere to the following minimum standards:
(a) V-CIP Infrastructure
(i) The RE should have complied with the RBI guidelines on minimum baseline cyber security and resilience framework for banks, as updated from time to time as well as other general guidelines on IT risks. The technology infrastructure should be housed in own premises of the RE and the V-CIP connection and interaction shall necessarily originate from its own secured network domain. Any technology related outsourcing for the process should be compliant with relevant RBI guidelines.
(ii) The RE shall ensure end-to-end encryption of data between customer device and the hosting point of the V-CIP application, as per appropriate encryption standards. The customer consent should be recorded in an auditable and alteration proof manner.
(iii) The V-CIP infrastructure / application should be capable of preventing connection from IP addresses outside India or from spoofed IP addresses.
(iv) The video recordings should contain the live GPS co-ordinates (geo-tagging) of the customer undertaking the V-CIP and date-time stamp. The quality of the live video in the V-CIP shall be adequate to allow identification of the customer beyond doubt.
(v) The application shall have components with face liveness / spoof detection as well as face matching technology with high degree of accuracy, even though the ultimate responsibility of any customer identification rests with the RE. Appropriate artificial intelligence (AI) technology can be used to ensure that the V-CIP is robust.
(vi) Based on experience of detected / attempted / ‘near-miss’ cases of forged identity, the technology infrastructure including application software as well as work flows shall be regularly upgraded. Any detected case of forged identity through V-CIP shall be reported as a cyber security event under extant regulatory guidelines.
(vii) The V-CIP infrastructure shall undergo necessary tests such as Vulnerability Assessment, Penetration testing and a Security Audit to ensure its robustness and end-to-end encryption capabilities. Any critical gap reported under this process shall be mitigated before rolling out its implementation. Such tests should be conducted by suitably accredited agencies as prescribed by RBI. Such tests should also be carried out periodically in conformance to internal / regulatory guidelines.
(viii) The V-CIP application software and relevant APIs / webservices shall also undergo appropriate testing of functional, performance, maintenance strength before being used in live environment. Only after closure of any critical gap found during such tests, the application should be rolled out. Such tests shall also be carried out periodically in conformity with internal/ regulatory guidelines.
(b) V-CIP Procedure
(i) Each RE shall formulate a clear work flow and standard operating procedure for V-CIP and ensure adherence to it. The V-CIP process shall be operated only by officials of the RE specially trained for this purpose. The official should be capable to carry out liveliness check and detect any other fraudulent manipulation or suspicious conduct of the customer and act upon it.
(ii) If there is a disruption in the V-CIP procedure, the same should be aborted and a fresh session initiated.
(iii) The sequence and/or type of questions, including those indicating the liveness of the interaction, during video interactions shall be varied in order to establish that the interactions are real-time and not pre-recorded.
(iv) Any prompting, observed at end of customer shall lead to rejection of the account opening process.
(v) The fact of the V-CIP customer being an existing or new customer, or if it relates to a case rejected earlier or if the name appearing in some negative list should be factored in at appropriate stage of work flow.
(vi) The authorised official of the RE performing the V-CIP shall record audio-video as well as capture photograph of the customer present for identification and obtain the identification information using any one of the following:
OTP based Aadhaar e-KYC authentication
Offline Verification of Aadhaar for identification
KYC records downloaded from CKYCR, in accordance with Section 56, using the KYC identifier provided by the customer
Equivalent e-document of Officially Valid Documents (OVDs) including documents issued through DigiLocker
RE shall ensure to redact or blackout the Aadhaar number in terms of Section 16.
In case of offline verification of Aadhaar using XML file or Aadhaar Secure QR Code, it shall be ensured that the XML file or QR code generation date is not older than 3 days from the date of carrying out V-CIP.
Further, in line with the prescribed period of three days for usage of Aadhaar XML file / Aadhaar QR code, REs shall ensure that the video process of the V-CIP is undertaken within three days of downloading / obtaining the identification information through CKYCR / Aadhaar authentication / equivalent e-document, if in the rare cases, the entire process cannot be completed at one go or seamlessly. However, REs shall ensure that no incremental risk is added due to this.
(vii) If the address of the customer is different from that indicated in the OVD, suitable records of the current address shall be captured, as per the existing requirement. It shall be ensured that the economic and financial profile/information submitted by the customer is also confirmed from the customer undertaking the V-CIP in a suitable manner.
(viii) RE shall capture a clear image of PAN card to be displayed by the customer during the process, except in cases where e-PAN is provided by the customer. The PAN details shall be verified from the database of the issuing authority including through DigiLocker.
(ix) Use of printed copy of equivalent e-document including e-PAN is not valid for the V-CIP.
(x) The authorised official of the RE shall ensure that photograph of the customer in the Aadhaar/OVD and PAN/e-PAN matches with the customer undertaking the V-CIP and the identification details in Aadhaar/OVD and PAN/e-PAN shall match with the details provided by the customer.
(xi) Assisted V-CIP shall be permissible when banks take help of Banking Correspondents (BCs) facilitating the process only at the customer end. Banks shall maintain the details of the BC assisting the customer, where services of BCs are utilized. The ultimate responsibility for customer due diligence will be with the bank.
(xii) All accounts opened through V-CIP shall be made operational only after being subject to concurrent audit, to ensure the integrity of process and its acceptability of the outcome.
(xiii) All matters not specified under the paragraph but required under other statutes such as the Information Technology (IT) Act shall be appropriately complied with by the RE.
(c) V-CIP Records and Data Management
(i) The entire data and recordings of V-CIP shall be stored in a system / systems located in India. REs shall ensure that the video recording is stored in a safe and secure manner and bears the date and time stamp that affords easy historical data search. The extant instructions on record management, as stipulated in this MD, shall also be applicable for V-CIP.
(ii) The activity log along with the credentials of the official performing the V-CIP shall be preserved.
II. Periodic updation of KYC:
Amended Section 38:
REs shall adopt a risk-based approach for periodic updation of KYC. However, periodic updation shall be carried out at least once in every two years for high risk customers, once in every eight years for medium risk customers and once in every ten years for low risk customers from the date of opening of the account / last KYC updation. Policy in this regard shall be documented as part of REs’ internal KYC policy duly approved by the Board of Directors of REs or any committee of the Board to which power has been delegated.
i. Individual Customers:
No change in KYC information: In case of no change in the KYC information, a self-declaration from the customer in this regard shall be obtained through customer’s email-id registered with the RE, customer’s mobile number registered with the RE, ATMs, digital channels (such as online banking / internet banking, mobile application of RE), letter etc.
Change in address: In case of a change only in the address details of the customer, a self-declaration of the new address shall be obtained from the customer through customer’s email-id registered with the RE, customer’s mobile number registered with the RE, ATMs, digital channels (such as online banking / internet banking, mobile application of RE), letter etc., and the declared address shall be verified through positive confirmation within two months, by means such as address verification letter, contact point verification, deliverables etc.
Further, REs, at their option, may obtain a copy of OVD or deemed OVD or the equivalent e-documents thereof, as defined in Section 3(a)(xiii), for the purpose of proof of address, declared by the customer at the time of periodic updation. Such requirement, however, shall be clearly specified by the REs in their internal KYC policy duly approved by the Board of Directors of REs or any committee of the Board to which power has been delegated.
Accounts of customers who were minor at the time of opening account on their becoming major: In case of customers for whom account was opened when they were minor, fresh photographs shall be obtained on their becoming a major and at that time it shall be ensured that CDD documents as per the current CDD standards are available with the REs. Wherever required, REs may carry out fresh KYC of such customers i.e. customers for whom account was opened when they were minor, on their becoming a major. ii. Customers other than individuals:
No change in KYC information: In case of no change in the KYC information of the LE customer, a self-declaration in this regard shall be obtained from the LE customer through its email id registered with the RE, ATMs, digital channels (such as online banking / internet banking, mobile application of RE), letter from an official authorized by the LE in this regard, board resolution etc. Further, REs shall ensure during this process that Beneficial Ownership (BO) information available with them is accurate and shall update the same, if required, to keep it as up-to-date as possible.
Change in KYC information: In case of change in KYC information, RE shall undertake the KYC process equivalent to that applicable for on-boarding a new LE customer.
iii. Additional measures: In addition to the above, REs shall ensure that -
The KYC documents of the customer as per the current CDD standards are available with them. This is applicable even if there is no change in customer information but the documents available with the RE are not as per the current CDD standards. Further, in case the validity of the CDD documents available with the RE has expired at the time of periodic updation of KYC, RE shall undertake the KYC process equivalent to that applicable for on-boarding a new customer.
Customer’s PAN details, if available with the RE, is verified from the database of the issuing authority at the time of periodic updation of KYC.
An acknowledgment is provided to the customer mentioning the date of receipt of the relevant document(s), including self-declaration from the customer, for carrying out periodic updation. Further, it shall be ensured that the information / documents obtained from the customers at the time of periodic updation of KYC are promptly updated in the records / database of the REs and an intimation, mentioning the date of updation of KYC details, is provided to the customer.
In order to ensure customer convenience, REs may consider making available the facility of periodic updation of KYC at any branch, in terms of their internal KYC policy duly approved by the Board of Directors of REs or any committee of the Board to which power has been delegated.
REs shall adopt a risk-based approach with respect to periodic updation of KYC. Any additional and exceptional measures, which otherwise are not mandated under the above instructions, adopted by the REs such as requirement of obtaining recent photograph, requirement of physical presence of the customer, requirement of periodic updation of KYC only in the branch of the RE where account is maintained, a more frequent periodicity of KYC updation than the minimum specified periodicity etc., shall be clearly specified in the internal KYC policy duly approved by the Board of Directors of REs or any committee of the Board to which power has been delegated.
REs shall ensure that their internal KYC policy and processes on updation / periodic updation of KYC are transparent and adverse actions against the customers should be avoided, unless warranted by specific regulatory requirements.
3. Accordingly, the relevant Sections of the MD on KYC are hereby amended to reflect the aforementioned changes. The amended provisions shall come into force with immediate effect.
Yours faithfully,
(Prakash Baliarsingh)
Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2021-22/35 · issued 10 May 2021. The plain-English explanation above is BankPulse’s own independent summary.
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12089&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.