CKYCR KYC Upload Responsibility Clarified for AIFIs
Current · Source: Reserve Bank of India · RBI/2025-26/157 · issued 29 Dec 2025 · ~2 min read
Quick answerRBI clarifies that the AIFI which last uploaded/updated KYC records to CKYCR is responsible for verifying customer identity/address. Other AIFIs downloading current records need not re-verify, but remain liable for all other CDD aspects.
The rule, in the simplest words
The AIFI (a type of financial company) that last added or updated a customer's KYC (identity and address proof) records in CKYCR (a central database) is the one who must check if the customer's identity and address are real.
If another AIFI downloads those current records from CKYCR, it does NOT have to re-check the customer's identity and address again.
But the AIFI that downloads the records is still responsible for all other parts of CDD (checking the customer's background and risk), like making sure the records are up-to-date and following all other rules.
How it plays out — a real example
A KYC & compliance officer in Indore downloads a customer's KYC records from CKYCR that were last updated by another AIFI. She trusts those records for identity and address, saving time. But she still checks the records are current and follows all other customer due diligence steps, because she remains responsible for everything except identity/address verification.
What changed
RBI amended its November 2025 KYC Directions for All India Financial Institutions to insert an Explanation in paragraph 62. This Explanation specifies that the entity which last uploaded or updated customer KYC records to CKYCR bears the responsibility for verifying identity/address. AIFIs downloading and relying on such current records are exempt from re-verifying identity/address, but must still fulfill all other CDD requirements.
What it means for you
This amendment reduces duplication of KYC verification for AIFIs that use CKYCR, saving time and costs. However, the downloading AIFI remains fully accountable for the entire CDD process except identity/address verification, so due diligence on record currency and compliance is critical. It aligns with the government's September 2025 office memorandum on ultimate responsibility of regulated entities.
What you must do
Identify which AIFI last uploaded/updated each customer's KYC records in CKYCR before relying on them.
Ensure downloaded KYC records are current and compliant with PML Act/Rules before accepting them.
Maintain robust internal controls to verify record currency and completeness, as CDD responsibility remains with you.
Update your KYC policy and procedures to reflect this clarification and train staff accordingly.
Who it affects
All India Financial Institutions (AIFIs) covered under RBI's KYC Directions, Compliance and KYC operations teams at AIFIs, Customers whose KYC records are shared via CKYCR
❓ Common questions
Does this mean we never need to verify customer identity if we download from CKYCR?
No. You are exempt from re-verifying identity/address only if the records were last uploaded/updated by another AIFI and are current and compliant. You still must perform all other CDD steps and remain responsible for the overall CDD procedure.
What if the CKYCR record is outdated or non-compliant?
You cannot rely on such records. You must either obtain fresh KYC from the customer or ensure the uploading AIFI updates the record. Your responsibility for CDD means you must verify record currency and compliance before use.
Who is the 'last uploading or updating' AIFI?
It is the AIFI that most recently uploaded or updated the customer's KYC records in CKYCR. That entity bears the primary responsibility for verifying identity/address. You should check CKYCR metadata to identify this entity.
📜 Read the original circular — full text as issued by RBI
RBI/2025-26/157
DOR.AML.REC.361/14.01.011/2025-26
December 29, 2025
Reserve Bank of India (All India Financial Institutions – Know Your Customer) Amendment Directions, 2025
Reserve Bank had issued Reserve Bank of India (All India Financial Institutions – Know Your Customer) Directions, 2025 dated November 28, 2025 (hereinafter referred to as the Directions) in compliance of the provisions of the PML Act, 2002 and the Rules made thereunder. There is a need to amend the Directions to clarify the responsibility of entities uploading customer records to and downloading the same from CKYCR, based on the office memorandum (OM) titled “CKYCR and the ultimate responsibility of REs – reg.” issued by the Department of Revenue, Govt of India, dated September 18, 2025.
2. Accordingly, in exercise of the powers conferred by sections 35A of the Banking Regulation Act, 1949, the Banking Regulation Act (AACS), 1949, read with section 56 of the Act ibid, sections 45JA, 45K, and 45L of the Reserve Bank of India Act, 1934, section 10(2) read with section 18 of Payment and Settlement Systems Act 2007 (Act 51 of 2007), section 11(1) of the Foreign Exchange Management Act, 1999, Rule 9(14) of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, and all other enabling laws in this regard, the Reserve Bank being satisfied that it is necessary and expedient in the public interest so to do, hereby issues the Amendment Directions hereinafter specified.
3. Short Title and Commencement
(1) These Directions shall be called the Reserve Bank of India (All India Financial Institutions – Know Your Customer) Amendment Directions, 2025.
(2) These Directions shall come into force with immediate effect.
4. These Amendment Directions modify the Reserve Bank of India (All India Financial Institutions – Know Your Customer) Directions, 2025 as under:
(1) In paragraph 62, the following “Explanation” is being inserted after sub-paragraph (9):
“ Explanation: The RE that has last uploaded or updated the customer’s KYC records in the CKYCR shall be responsible for verifying the identity and / or address of the customer, as applicable. Accordingly, any AIFI downloading and relying on such records from the CKCYR shall not be required to re-verify the authenticity of the customer’s identity and / or address, provided the KYC records downloaded from CKYCR are current and compliant with the PML Act, 2002 / PML Rules, 2005. The AIFI downloading and relying on KYC records downloaded from the CKCYR shall remain responsible for all aspects of CDD procedure and provisions of these Directions, except verification of identity and / or address of the customer.”
(Veena Srivastava)
Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2025-26/157 · issued 29 Dec 2025. The plain-English explanation above is BankPulse’s own independent summary.
Example: if you are a Compliance officer at a bank this circular applies to (All India Financial Institutions (AIFIs) covered under RBI's KYC Directions, Compliance and KYC operations teams at AIFIs, Customers whose KYC records are shared via CKYCR), your first concrete step on “CKYCR KYC Upload Responsibility Clarified for AIFIs” is: “Identify which AIFI last uploaded/updated each customer's KYC records in CKYCR before relying on them.” (RBI issued this 29 Dec 2025).
Circular: RBI/2025-26/157 -- CKYCR KYC Upload Responsibility Clarified for AIFIs
Issued: 29 Dec 2025
Action required: Identify which AIFI last uploaded/updated each customer's KYC records in CKYCR before relying on them.
Action required: Ensure downloaded KYC records are current and compliant with PML Act/Rules before accepting them.
Action required: Maintain robust internal controls to verify record currency and completeness, as CDD responsibility remains with you.
Action required: Update your KYC policy and procedures to reflect this clarification and train staff accordingly.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=13233&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.