📜 Read the original circular — full text as issued by RBI
Notifications - Reserve Bank of India Skip to main content Selected Selected Change Language हिंदी Search the Website Search Home About Us ▼ About Us Organisation & Functions ▶ Organisation Structure Departments Offices Training Establishment ▶ College of Agricultural Banking Reserve Bank Staff College College of Supervisors RBI's Functions and Working Governors Deputy Governors Executive Directors Communication Policy of RBI Sources of Information ▶ Annual Publications Half-yearly Publications Quarterly Publications Monthly Publications Weekly Publications Occasional Publications SDDS NSDP Data Releases Publications available on Subscription General Information RBI History Museum ▶ The RBI Museum RBI Monetary Museum Notification ▼ Notifications Master Directions Master Circulars Amendment Directions Draft Notifications/Guidelines ▶ Draft Notifications/Guidelines Draft Directions (RE-wise) Index To RBI Circulars Standalone Circulars Circulars Withdrawn Press Releases Speeches & Media Interactions ▼ Speeches Media Interactions Memorial Lectures Podcasts Publications ▼ Biennial Annual Half-Yearly Quarterly Bi-monthly Monthly Weekly Occasional Reports Working Papers Legal Framework ▼ Act Rules Regulations Schemes Research ▼ External Research Schemes RBI Occasional Papers Working Papers RBI Bulletin History DRG Studies KLEMS State Statistics and Finances Statistics ▼ Data Releases Database on Indian Economy Public Debt Statistics Regulatory Reporting ▼ List of Returns Data Definition Validation rules/ Taxonomy List of RBI Reporting Portals FAQs of RBI Reporting Portals Home Notifications Notifications ( 724 kb ) Reserve Bank of India (Urban Co-operative Banks – Know Your Customer) Directions, 2025 (Updated as on December 29, 2025) RBI/DOR/2025-26/291 DOR.AML.REC.No.210/14.01.006/2025-26 November 28, 2025 Previous Versions Reserve Bank of India (Urban Co-operative Banks – Know Your Customer) Directions, 2025 (Updated as on December 29, 2025) Table of Contents Chapter I – Preliminary A. Short Title and Commencement B. Applicability C. Definitions Chapter II – General A. Board of Directors / Policies related guidelines: B. Other General Guidelines: Chapter III – Customer Acceptance Policy Chapter IV – Risk Management Chapter V – Customer Identification Procedure (CIP) Chapter VI – Customer Due Diligence (CDD) Procedure A. CDD Procedure in case of Individuals B. CDD Measures for Sole Proprietary firms C. CDD Measures for Legal Entities D. Identification of Beneficial Owner E. On-going Due Diligence F. Enhanced and Simplified Due Diligence Procedure F.1 Enhanced Due Diligence F.2 Simplified Due Diligence Chapter VII – Record Management Chapter VIII – Reporting Requirements to Financial Intelligence Unit – India Chapter IX – Requirements / obligations under International Agreements - Communications from International Agencies Chapter X – Other Instructions Chapter XI – Repeal and Other Provisions A. Repeal and Saving B. Application of other laws not barred C. Interpretations Annex – I Annex – II Introduction In order to prevent banks and other financial institutions from being used as a channel for Money Laundering (ML)/ Terrorist Financing (TF) and to ensure the integrity and stability of the financial system, efforts are continuously being made both internationally and nationally, by way of prescribing various rules and regulations. Internationally, the Financial Action Task Force (FATF), which is an inter-governmental body established in 1989 by the Ministers of its member jurisdictions, sets standards and promotes effective implementation of legal, regulatory and operational measures for combating money laundering, terrorist financing and other related threats to the integrity of the international financial system. India, as a member of FATF, is committed to upholding measures to protect the integrity of the international financial system. In India, the Prevention of Money-Laundering Act, 2002, and the Prevention of Money- Laundering (Maintenance of Records) Rules, 2005, form the legal framework on Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT). The provisions of the PML Act, 2002 and the PML Rules, 2005, as amended from time to time by the Government of India, require Regulated Entities (REs) to follow certain customer identification procedures while undertaking a transaction either by establishing an account-based relationship or otherwise, and to monitor their transactions. Accordingly, in exercise of the powers conferred by sections 35A of the Banking Regulation Act, 1949, the Banking Regulation Act (AACS), 1949, read with section 56 of the Act ibid., section 10(2) read with section 18 of Payment and Settlement Systems Act 2007 (Act 51 of 2007), section 11(1) of the Foreign Exchange Management Act, 1999, Rule 9(14) of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, and all other laws enabling the Reserve Bank in this regard, the RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby issues the Directions hereinafter specified. Chapter I – Preliminary A. Short Title and Commencement 1. These Directions shall be called the Reserve Bank of India (Urban Co-operative Banks – Know Your Customer) Directions, 2025. 2. These Directions shall come into effect from the date of issue. B. Applicability 3. These Directions shall be applicable to Urban Co-operative Banks (hereinafter collectively referred to as 'banks' and individually as a 'bank'). In this context, Urban Co-operative Banks shall mean Primary Co-operative Banks as defined under section 5(ccv) read with Section 56 of Banking Regulation Act, 1949. C. Definitions 4. For the purpose of these Directions unless the context states otherwise, the terms herein shall bear the meanings assigned to them below: (1) Terms bearing meaning assigned in terms of the Prevention of Money-Laundering Act, 2002, and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005: (i) ‘Aadhaar Number’ shall have the meaning assigned to it in clause (a) of section 2 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016); (ii) ‘Act’ and ‘Rules’ mean the Prevention of Money-Laundering Act, 2002 and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, respectively and amendments thereto. (iii) ‘Authentication’ , in the context of Aadhaar authentication, means the process as defined under sub-section (c) of section 2 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016. (iv) Beneficial Owner (BO) (a) Where the customer is a company , the beneficial owner is the natural person(s), who, whether acting alone or together, or through one or more juridical persons, has / have a controlling ownership interest or who exercises control through other means. Explanation: For the purpose of this sub-clause- ‘Controlling ownership interest’ means ownership of / entitlement to more than 10 percent of the shares or capital or profits of the company. ‘Control’ shall include the right to appoint the majority of the directors or to control the management or policy decisions including by virtue of their shareholding or management rights or shareholders agreements or voting agreements. (b) Where the customer is a partnership firm , the beneficial owner is the natural person(s), who, whether acting alone or together, or through one or more juridical person(s), has / have ownership of / entitlement to more than 10 percent of capital or profits of the partnership or who exercises control through other means. Explanation: For the purpose of this sub-clause, ‘control’ shall include the right to control the management or policy decision. (c) Where the customer is an unincorporated association or body of individuals , the beneficial owner is the natural person(s), who, whether acting alone or together, or through one or more juridical person, has / have ownership of / entitlement to more than 15 percent of the property or capital or profits of the unincorporated association or body of individuals. Explanation: Term ‘body of individuals’ includes societies. Where no natural person is identified under (a), (b) or (c) above, the beneficial owner is the relevant natural person who holds the position of senior managing official. (d) Where the customer is a trust , the identification of beneficial owner(s) shall include identification of the author of the trust, the trustee, the beneficiaries with 10 percent or more interest in the trust and any other natural person exercising ultimate effective control over the trust through a chain of control or ownership. (v) ‘Certified Copy’ – Obtaining the certified copy by the bank shall mean comparing the copy of the proof of possession of Aadhaar number where offline verification cannot be carried out or the officially valid document produced by the customer with the original, and an authorised officer of the bank shall record the comparison on the copy as per the provisions contained in the Act. Provided that in case of Non-Resident Indians (NRIs) and Persons of Indian Origin (PIOs), as defined in Foreign Exchange Management (Deposit) Regulations, 2016 {FEMA 5(R)}, the bank may alternatively obtain the original certified copy, certified by any one of the following: (a) authorised officials of overseas branches of Scheduled Commercial Banks registered in India, (b) branches of overseas banks with whom Indian banks have relationships, (c) Notary Public abroad, (d) Court Magistrate, (e) Judge, (f) Indian Embassy / Consulate General in the country where the non-resident customer resides. (vi) ‘Central KYC Records Registry’ (CKYCR) means an entity defined under Rule 2(1) of the Rules, to receive, store, safeguard and retrieve the KYC records in digital form of a customer. (vii) ‘Designated Director’ means a person whom the bank designates to ensure overall compliance with the obligations imposed under chapter IV of the PML Act and the Rules and shall include a person who holds the position of senior management or equivalent. (viii) ‘Digital KYC’ means that an authorised officer of the bank captures a live photo of the customer and officially valid document or the proof of possession of Aadhaar (where offline verification cannot be carried out), along with the latitude and longitude of the location where such live photo is being taken, as per the provisions contained in the Act. (ix) ‘Digital Signature’ shall have the same meaning as assigned to it in clause (p) of sub-section (1) of section (2) of the Information Technology Act, 2000 (21 of 2000). (x) ‘Equivalent e-document’ means an electronic equivalent of a document that the issuing authority of such document issues with its valid digital signature, including documents issued to the digital locker account of the customer as per rule 9 of the Information Technology (Preservation and Retention of Information by Intermediaries Providing Digital Locker Facilities) Rules, 2016. (xi) ‘Group’ – The term ‘group’ shall have the same meaning assigned to it in clause (e) of sub-section (9) of section 286 of the Income-tax Act,1961 (43 of 1961). (xii) ‘Know Your Client (KYC) Identifier’ means the unique number or code that the Central KYC Records Registry assigns to a customer. Explanation: A customer can obtain his KYC Identifier through the following ways: In the process of opening an account, once the customer’s KYC Identifier is generated by CKYCR and provided to the bank, the latter shall share the same with the concerned customer. The customer can also access his KYC Identifier on CKYCR Portal ( www.ckycindia.in ). (xiii) ‘Non-profit organisations’ (NPO) means any entity or organisation, constituted for religious or charitable purposes referred to in clause (15) of section 2 of the Income-tax Act, 1961 (43 of 1961), that is registered as a trust or a society under the Societies Registration Act, 1860 or any similar State legislation or a company registered under section 8 of the Companies Act, 2013 (18 of 2013). (xiv) ‘Officially Valid Document’ (OVD) means the passport, the driving licence, proof of possession of Aadhaar number, the Voter's Identity Card that the Election Commission of India issues, the job card that NREGA issues and an officer of the State Government duly signs, and the letter that the National Population Register issues containing details of name and address. Provided that, (a) where the customer submits his proof of possession of Aadhaar number as an OVD, he may submit it in such form that the Unique Identification Authority of India (UIDAI) issues. (b) when the customer furnishes an OVD that does not have an updated address, the bank shall deem the following documents or the equivalent e-documents thereof to be OVDs for the limited purpose of proof of address:- utility bill which is not more than two months old of any service provider (electricity, telephone, post-paid mobile phone, piped gas, water bill); property or Municipal tax receipt; pension or family pension payment orders (PPOs) issued to retired employees by Government Departments or Public Sector Undertakings, if they contain the address; letter of allotment of accommodation from employer that is issued by State Government or Central Government Departments, statutory or regulatory bodies, public sector undertakings, scheduled commercial banks, financial institutions and listed companies and leave and licence agreements with such employers allotting official accommodation; Illustration: If a customer is staying in Chennai but their OVD contains an address of New Delhi, they can open an account in Chennai by submitting a deemed to be OVD for the purpose of proof of address. However, as mentioned below in clause (c), they are required to submit an OVD with current address within a period of three months. (c) the customer shall submit OVD with current address within a period of three months of submitting the documents specified at (b) above. (d) if the OVD that a foreign national presents does not contain the details of address, the bank shall accept documents that Government departments of foreign jurisdictions issue, and a letter that the Foreign Embassy or Mission in India issues, as proof of address. Explanation: For the purpose of this clause, the bank shall deem a document to be an OVD even if there is a change in the name subsequent to its issuance provided that it is supported by a marriage certificate that the State Government issues or a Gazette notification, indicating such a change of name. (xv) ‘Offline Verification’ shall have the same meaning as assigned to it in clause (pa) of section 2 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016). (xvi) ‘Person’ has the same meaning assigned in the Act and includes: (a) an individual, (b) a Hindu undivided family, (c) a company, (d) a firm, (e) an association of persons or a body of individuals, whether incorporated or not, (f) every artificial juridical person, not falling within any one of the above persons (a to e), and (g) any agency, office or branch owned or controlled by any of the above persons (a to f). (xvii) ‘Principal Officer’ means a bank’s nominated officer at the management level, responsible for furnishing information as per rule 8 of the Rules. (xviii) ‘Suspicious Transaction’ means a ‘transaction’ as defined below, including an attempted transaction, whether or not made in cash, which, to a person acting in good faith: (a) gives rise to a reasonable ground of suspicion that it may involve proceeds of an offence specified in the Schedule to the Act, regardless of the value involved; or (b) appears to be made in circumstances of unusual or unjustified complexity; or (c) appears to have no economic rationale or bona fide purpose; or (d) gives rise to a reasonable ground of suspicion that it may involve financing of the activities relating to terrorism. Explanation: Transaction involving financing of the activities relating to terrorism includes transaction involving funds that the bank suspects are linked or related to, or to be used for terrorism, terrorist acts or by a terrorist, terrorist organisation or those who finance or are attempting to finance terrorism. (xix) ‘Small Account' means a savings account which is opened in terms of sub- rule (5) of rule 9 of the PML Rules, 2005. Details of the operation of a small account and controls to be exercised for such account are specified in paragraph 27. (xx) ‘Transaction’ means a purchase, sale, loan, pledge, gift, transfer, delivery or the arrangement thereof and includes: (a) opening of an account; (b) deposit, withdrawal, exchange or transfer of funds in whatever currency, whether in cash or by cheque, payment order or other instruments or by electronic or other non-physical means; (c) the use of a safety deposit box or any other form of safe deposit; (d) entering into any fiduciary relationship; (e) any payment made or received, in whole or in part, for any contractual or other legal obligation; or (f) establishing or creating a legal person or legal arrangement. (2) Unless the context otherwise requires, terms in these Directions shall bear the meanings assigned to them below: (i) ‘Common Reporting Standards’ (CRS) means reporting standards set for implementation of multilateral agreement signed to automatically exchange information based on Article 6 of the Convention on Mutual Administrative Assistance in Tax Matters. (ii) Correspondent Banking: Correspondent banking is the provision of banking services by one bank (the ‘correspondent bank’) to another bank (the ‘respondent bank’). A correspondent bank may provide the respondent banks with a wide range of services, including cash management (e.g., interest-bearing accounts in a variety of currencies), international wire transfers, cheque clearing, payable- through accounts and foreign exchange services. (iii) ‘Customer’ means a person who is engaged in a financial transaction or activity with the bank and includes a person on whose behalf the person who is engaged in the transaction or activity, is acting. (iv) ‘Walk-in Customer’ means a person who does not have an account-based relationship with the bank, but undertakes transactions with the bank. (v) ‘Customer Due Diligence (CDD)’ means identifying and verifying the customer and the beneficial owner using reliable and independent sources of identification. Explanation: The CDD, at the time of commencement of an account-based relationship or while carrying out occasional transaction of an amount equal to or exceeding ₹50,000 whether conducted as a single transaction or several transactions that appear to be connected, or any international money transfer operations, shall include: (a) Identification of the customer, verification of their identity using reliable and independent sources of identification, obtaining information on the purpose and intended nature of the business relationship, where applicable (b) Taking reasonable steps to understand the nature of the customer's business, and its ownership and control; (c) Determining whether a customer is acting on behalf of a beneficial owner and identifying the beneficial owner and taking all steps to verify the identity of the beneficial owner, using reliable and independent sources of identification. (vi) ‘Customer Identification’ means undertaking the process of CDD. (vii) ‘FATCA’ means Foreign Account Tax Compliance Act of the United States of America (USA) which, inter alia, requires foreign financial institutions to report about financial accounts held by U.S. taxpayers or foreign entities in which U.S. taxpayers hold a substantial ownership interest. (viii) ‘IGA’ means Inter Governmental Agreement between the Governments of India and the USA to improve international tax compliance and to implement FATCA of the USA. (ix) ‘KYC Templates’ means templates prepared to facilitate collating and reporting KYC data to the CKYCR, for individuals and legal entities. (x) ‘Non-face-to-face customers’ means customers who open accounts without visiting the branch / offices of the bank or meeting the officials of the bank. (xi) ‘On-going Due Diligence’ means regular monitoring of transactions in accounts to ensure that transactions are consistent with the bank’s knowledge about the customers, customers’ business and risk profile, the source of funds / wealth. (xii) Payable-through accounts: The term payable-through accounts refers to correspondent accounts that third parties use directly to transact business on their own behalf. (xiii) ‘Periodic Updation’ means the steps taken to ensure that documents, data or information collected under the CDD process are kept up-to-date and relevant by undertaking reviews of existing records at the periodicity prescribed by the RBI. (xiv) 'Regulated Entities' (REs) means: (a) all Scheduled Commercial Banks (SCBs) / Regional Rural Banks (RRBs) / Local Area Banks (LABs) / All Primary (Urban) Co-operative Banks (UCBs) / State and Central Co-operative Banks (StCBs / CCBs), and any other entity which has been licensed under section 22 of Banking Regulation Act, 1949, which as a group shall be referred as ‘banks’ (b) All India Financial Institutions (AIFIs) (c) All Non-Banking Finance Companies (NBFCs), Miscellaneous Non-Banking Companies (MNBCs) and Residuary Non-Banking Companies (RNBCs) (d) Asset Reconstruction Companies (ARCs) (e) All Payment System Providers (PSPs) / System Participants (SPs) and Prepaid Payment Instrument Issuers (PPI Issuers) (f) All authorised persons (APs), including those who are agents of Money Transfer Service Scheme (MTSS), regulated by the Regulator. (xv) ‘Shell Bank’ means a bank that has no physical presence in the country in which it is incorporated and licensed, and which is unaffiliated with a regulated financial group that is subject to effective consolidated supervision. Physical presence means meaningful mind and management located within a country. The existence simply of a local agent or low-level staff does not constitute physical presence. (xvi) ‘Video based Customer Identification Process (V-CIP)’: an alternative method by which an authorised official of the bank conducts customer identification with facial recognition and customer due diligence. This process involves a seamless, secure, live, informed- consent based audio-visual interaction with the customer to obtain identification information required for CDD purpose, and to ascertain the veracity of the information which the customer furnished, through independent verification and by maintaining an audit trail of the process. The bank shall treat such processes complying with prescribed standards and procedures on par with face-to-face CIP for the purpose of this Direction. (xvii) ‘Wire transfer’ related definitions: (a) Batch transfer: A batch transfer is a transfer comprised of a number of individual wire transfers that are being sent to the same financial institutions but may / may not be ultimately intended for different persons. (b) Beneficiary: Beneficiary refers to a natural or legal person or legal arrangement whom / which the originator identifies as the receiver of the requested wire transfer. (c) Beneficiary RE: It refers to a financial institution that RBI regulates, which receives the wire transfer from the ordering financial institution directly or through an intermediary RE and makes the funds available to the beneficiary. (d) Cover Payment: Cover Payment refers to a wire transfer that combines a payment message which the ordering financial institution sends directly to the beneficiary financial institution with the routing of the funding instruction (the cover) from the ordering financial institution to the beneficiary financial institution through one or more intermediary financial institutions. (e) Cross-border Wire Transfer: Cross-border wire transfer refers to any wire transfer where the ordering financial institution and beneficiary financial institution are located in different countries. This term also refers to any chain of wire transfer in which at least one of the financial institutions involved is located in a different country. (f) Domestic Wire Transfer: Domestic wire transfer refers to any wire transfer where the ordering financial institution and beneficiary financial institution are located in India. This term, therefore, refers to any chain of wire transfers that takes place entirely within the borders of India, even though the system used to transfer the payment message may be located in another country. (g) Financial Institution: In the context of wire-transfer instructions, the term ‘Financial Institution’ shall have the same meaning as has been ascribed to it in the FATF Recommendations, as revised from time to time. (h) Intermediary RE: Intermediary RE refers to an RBI regulated financial institution / entity that handles an intermediary element of the wire transfer, in a serial or cover payment chain and that receives and transmits a wire transfer on behalf of the ordering financial institution and the beneficiary financial institution, or another intermediary financial institution. (i) Ordering RE: Ordering RE refers to the RBI-regulated financial institution which initiates the wire transfer and transfers the funds upon receiving the request for a wire transfer on behalf of the originator. (j) Originator: Originator refers to the account holder who allows the wire transfer from that account, or where there is no account, the natural or legal person that places the order with the ordering financial institution to perform the wire transfer. (k) Serial Payment: Serial Payment refers to a direct sequential chain of payment where the wire transfer and accompanying payment message travel together from the ordering financial institution to the beneficiary financial institution directly or through one or more intermediary financial institutions (e.g., correspondent banks). (l) Straight-through Processing: Straight-through processing refers to payment transactions that are conducted electronically without the need for manual intervention. (m) Unique Transaction Reference Number: Unique transaction reference number refers to a combination of letters, numbers or symbols, a payment service provider determines, in accordance with the protocols of the payment and settlement system or messaging system used for the wire transfer. (n) Wire Transfer: Wire transfer refers to any transaction carried out on behalf of an originator through a financial institution by electronic means with a view to making an amount of funds available to a beneficiary at a beneficiary financial institution, irrespective of whether the originator and the beneficiary are the same person. (3) Unless defined herein, all other expressions shall have the same meaning as has been assigned to them under the Banking Regulation Act, 1949, the Reserve Bank of India Act, 1935, the Prevention of Money Laundering Act, 2002, the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and regulations made thereunder, any statutory modification or re-enactment thereto or as used in commercial parlance, as the case may be. Chapter II – General A. Board of Directors / Policies related guidelines: 5. Know Your Customer (KYC) Policy: (1) The bank shall have a KYC policy. The Board of Directors of the bank, or any committee to which the power has been delegated shall duly approve the KYC policy. (2) The KYC policy shall include following four key elements: (i) Customer Acceptance Policy; (ii) Risk Management; (iii) Customer Identification Procedures (CIP); and (iv) Monitoring of Transactions (3) The KYC policy shall, inter alia, incorporate provisions for the following: (i) Periodic updation of KYC (ii) Any exceptional measures for KYC updation, such as requiring a recent photograph, physical presence, or a more frequent updation schedule than the minimum prescribed. (iii) Obtaining a copy of OVD or deemed OVD, for the purpose of proof of change of address during KYC updation. (iv) Providing facility of updation / periodic updation of KYC at any branch. (v) Furthermore, the bank shall have the following: (a) Policies approved by the Board detailing a robust due diligence process for managing requests to change the registered Mobile Number for Accounts opened in non-face-to-face mode. (b) Policy approved by the Board or a committee headed by the Chairman / CEO / MD, to establish parameters for approving cross-border correspondent banking relationships. New correspondent banking relationships require post facto approval from the Board or the empowered committee. 6. The specific responsibilities and actions stipulated for the Board or its relevant committees in paragraph 5 above are elaborated upon in greater detail within the Directions. 7. In terms of PML Rules, groups shall implement group-wide policies for the purpose of discharging obligations under the provisions of Chapter IV of the PML Act, 2002. (15 of 2003). Accordingly, every bank which is part of a group, shall implement group-wide programmes against money laundering and terror financing, including group-wide policies for sharing information required for the purposes of client due diligence, money laundering, and terrorist finance risk management, and such programmes shall include adequate safeguards on the confidentiality and use of information exchanged, including safeguards to prevent tipping-off. 8. Bank’s policy framework shall seek to ensure compliance with PML Act / Rules, including regulatory instructions in this regard and shall provide a bulwark against threats arising from money laundering, terrorist financing, proliferation financing and other related risks. While ensuring compliance with the legal / regulatory requirements as above, the bank may also consider adoption of best international practices taking into account the FATF standards and FATF guidance notes, for managing risks better. 9. Money Laundering and Terrorist Financing Risk Assessment by the bank: (1) The bank shall carry out ‘Money Laundering (ML) and Terrorist Financing (TF) Risk Assessment’ exercises periodically to identify, assess and take effective measures to mitigate its money laundering and terrorist financing risk for clients, countries or geographic areas, products, services, transactions or delivery channels, etc. The assessment process shall consider all the relevant risk factors before determining the level of overall risk and the appropriate level and type of mitigation to be applied. While preparing the internal risk assessment, the bank shall take cognizance of the overall sector-specific vulnerabilities, if any, that the regulator / supervisor may share with the bank from time to time. (2) The bank shall properly document its risk assessment and it shall be proportionate to the nature, size, geographical presence, complexity of activities / structure, etc. of the bank. Further, the Board or a committee of the Board to which it has delegated power shall determine the periodicity of the risk assessment exercise, in alignment with the outcome of the risk assessment exercise. However, the bank shall review it at least annually. (3) The bank shall present the outcome of the exercise to the Board or any committee of the Board to which the Board has delegated power in this regard. The outcome shall also be made available to competent authorities and self-regulating bodies. 10. The bank shall apply a Risk Based Approach (RBA) for mitigation and management of the risks (identified on its own or through national risk assessment) and shall have Board-approved policies, controls and procedures in this regard. The bank shall implement a CDD programme, having regard to the ML / TF risks identified and the size of business. Further, the bank shall monitor the implementation of the controls and enhance them if necessary. 11. Compliance of KYC policy: The bank shall ensure compliance with KYC Policy through: (1) specifying as to who constitute ‘Senior Management’ for the purpose of KYC compliance. (2) allocation of responsibility for effective implementation of policies and procedures. (3) independent evaluation of the compliance functions of the bank’s policies and procedures, including legal and regulatory requirements. (4) concurrent / internal audit system to verify compliance with KYC / AML policies and procedures. (5) submission of quarterly audit notes and compliance to the Audit Committee. 12. The bank shall ensure that it does not outsource the decision-making functions of determining compliance with KYC norms. B. Other General Guidelines: 13. Designated Director: (1) A ‘Designated Director’ is a Board-nominated person whom the bank designates to ensure overall compliance with the obligations imposed under Chapter IV of the PML Act and the Rules. (2) The bank shall communicate the name, designation, address, and contact details of the Designated Director to the FIU-IND and RBI. (3) The bank shall not nominate the Principal Officer as the 'Designated Director'. 14. Principal Officer: (1) The Principal Officer shall be responsible for ensuring compliance, monitoring transactions, and sharing and reporting information as required under the law / regulations. (2) The bank shall communicate the name, designation, address, and contact details of the Principal Officer to the FIU-IND and RBI. Chapter III – Customer Acceptance Policy 15. The bank shall frame a Customer Acceptance Policy. 16. Without prejudice to the generality of the aspect that Customer Acceptance Policy may contain, the bank shall: (1) not open any account in an anonymous or fictitious / benami name. (2) open no account where it is unable to apply appropriate CDD measures, either due to non-cooperation of the customer or unreliability of the documents / information furnished by the customer. The bank shall consider filing an STR, if necessary, when it is unable to comply with the relevant CDD measures in relation to the customer. (3) not undertake a transaction or commence an account-based relationship without following the CDD procedure. (4) specify the mandatory information to be sought for KYC purposes while opening an account and during the periodic updation. (5) obtain additional information, where its internal KYC Policy has not specified such information requirement, with the explicit consent of the customer. (6) apply the CDD procedure at the UCIC level. Thus, if an existing KYC-compliant customer of a bank desires to open another account or avail of any other product or service from the same bank, there shall be no need for a fresh CDD exercise as far as identification of the customer is concerned. (7) follow the CDD Procedure for all the joint account holders, while opening a joint account. (8) clearly spell out the circumstances in which a customer is permitted to act on behalf of another person / entity. (9) put in place a suitable system to ensure that the identity of the customer does not match with any person or entity, whose name appears in the sanctions lists indicated in Chapter IX of these Directions. (10) verify the Permanent Account Number (PAN) (if obtained) from the verification facility of the issuing authority. (11) verify the customer’s digital signature on the equivalent e-document (if obtained) as per the provisions of the Information Technology Act, 2000 (21 of 2000). (12) verify the Goods and Services Tax (GST) number from the search / verification facility of the issuing authority, where the GST details are available. 17. The Customer Acceptance Policy shall not result in denial of a banking / financial facility to members of the general public, especially those who are financially or socially disadvantaged, including the Persons with Disabilities (PwDs). The bank shall not reject an application for onboarding or periodic updation of KYC without application of mind. The officer concerned shall duly record the reason(s) for rejection. 18. Where the bank forms a suspicion of money laundering or terrorist financing, and it reasonably believes that performing the CDD process will tip off the customer, it shall not pursue the CDD process and instead file an STR with FIU-IND. Chapter IV – Risk Management 19. For risk management, the bank shall have a risk-based approach which includes the following. (1) The bank shall categorise customers into low, medium, and high-risk categories, based on its assessment and risk perception. (2) The bank may lay down broad principles for the risk-categorisation of customers. (3) The bank shall undertake risk categorisation based on parameters such as the customer’s identity, social / financial status, nature of business activity, and information about the customer’s business and its location, geographical risk covering customers as well as transactions, type of products / services offered, delivery channel used for delivery of products / services, types of transactions undertaken such as cash, cheque / monetary instruments, wire transfers, forex transactions, etc. The bank may also factor in the ability to confirm identity documents through online or other services offered by issuing authorities, while considering customer’s identity. (4) The bank shall keep the risk categorisation of a customer and the specific reasons for such categorisation confidential and shall not reveal this information to the customer to avoid tipping off. Provided that the bank collects various other non-intrusive information from different categories of customers relating to the perceived risk, and specifies the same in the KYC policy. Explanation: The bank may also use the FATF Public Statement, the reports and guidance notes on KYC / AML issued by the Indian Banks Association (IBA), and other agencies, etc., in its risk assessment. Chapter V – Customer Identification Procedure (CIP) 20. The bank shall undertake identification of customers in the following cases: (1) Commencement of an account-based relationship with the customer. (2) Carrying out any international money transfer operations for a person who is not an account holder of the bank. (3) When there is a doubt about the authenticity or adequacy of the customer identification data it has obtained. (4) Selling third-party products as agents, selling its own products, payment of dues of credit cards / sale and reloading of prepaid / travel cards and any other product for more than ₹50,000. (5) Carrying out transactions for a non-account-based customer, i.e., a walk-in customer, where the amount involved is equal to or exceeds ₹50,000, whether conducted as a single transaction or several transactions that appear to be connected. (6) When the bank has reason to believe that a customer (account-based or walk-in) is intentionally structuring a transaction into a series of transactions below the threshold of ₹50,000. (7) The bank shall ensure it does not seek introductions while opening accounts. 21. For the purpose of verifying the identity of customers at the time of commencement of an account-based relationship or while carrying out an occasional transaction of an amount equal to or exceeding ₹50,000, whether conducted as a single transaction or several transactions that appear to be connected, or any international money transfer operations, the bank, shall at its option, rely on customer due diligence done by a third party, subject to the following conditions: (1) The bank obtains the records or information of the customer due diligence carried out by the third party immediately from the third party or from the Central KYC Records Registry. (2) The bank shall take adequate steps to satisfy itself that the third party will make copies of identification data and other relevant documentation relating to the customer due diligence requirements available, upon request, without delay. (3) A regulator regulates, supervises, or monitors the third party, and the third party has measures in place for compliance with customer due diligence and record-keeping requirements in line with the requirements and obligations under the PML Act. (4) The bank shall ensure that the third party is not based in a country or jurisdiction assessed as high-risk. (5) The bank will have the ultimate responsibility for customer due diligence and undertaking enhanced due diligence measures, as applicable. Chapter VI – Customer Due Diligence (CDD) Procedure A. CDD Procedure in case of Individuals 22. For undertaking CDD, the bank shall obtain the following from an individual while establishing an account-based relationship or while dealing with the individual who is a beneficial owner, authorised signatory or the power of attorney holder related to any legal entity: (1) the Aadhaar number where, (i) they are desirous of receiving any benefit or subsidy under any scheme notified under section 7 of the Aadhaar (Targeted Delivery of Financial and Other subsidies, Benefits and Services) Act, 2016 (18 of 2016); or (ii) they decide to submit their Aadhaar number voluntarily to a bank or any RE notified under the first proviso to sub-section (1) of section 11A of the PML Act; or (2) the proof of possession of Aadhaar number where the bank can carry out offline verification; or (3) the proof of possession of Aadhaar number where the bank cannot carry out the offline verification or any OVD or the equivalent e-document thereof containing the details of their identity and address; or (4) the KYC Identifier with an explicit consent to download records from CKYCR; and (5) the PAN or the equivalent e-document thereof or Form No. 60 as defined in Income-tax Rules, 1962; and (6) the bank may require such other documents including in respect of the nature of business and financial status of the customer, or the equivalent e-documents thereof. Provided that where the customer has submitted, (i) Aadhaar number under clause (1) above to a bank, or REs notified under first proviso to sub-section (1) of section 11A of the PML Act, such bank shall carry out authentication of the customer’s Aadhaar number using UIDAI’s e-KYC authentication facility. Further, in such a case, if the customer wants to provide a current address, different from the address as per the identity information available in the Central Identities Data Repository, they may give a self-declaration to that effect to the bank. (ii) proof of possession of Aadhaar under clause (2) above where offline verification can be carried out, the bank shall carry out offline verification. (iii) an equivalent e-document of any OVD, the bank shall verify the digital signature as per the provisions of the Information Technology Act, 2000 (21 of 2000) and any rules issued thereunder and take a live photo as specified under paragraph 23 below. (iv) any OVD or proof of possession of Aadhaar number under clause (3) above where offline verification cannot be carried out, the bank shall carry out verification through digital KYC as specified under paragraph 23 below. (v) KYC Identifier under clause (4) above, the bank shall retrieve the KYC records online from the CKYCR in accordance with paragraph 64. Provided that for a period not beyond such date as the Government may notify for a class of REs, instead of carrying out digital KYC, the bank pertaining to such class may obtain a certified copy of the proof of possession of Aadhaar number or the OVD and a recent photograph where the customer does not submit an equivalent e- document. Provided further that in case the bank cannot perform an e-KYC authentication for an individual desirous of receiving any benefit or subsidy under any scheme notified under section 7 of the Aadhaar (Targeted Delivery of Financial and Other subsidies, Benefits and Services) Act, 2016 owing to injury, illness or infirmity on account of old age or otherwise, and similar causes, the bank shall, apart from obtaining the Aadhaar number, perform identification preferably by carrying out offline verification or alternatively by obtaining the certified copy of any other OVD or the equivalent e-document thereof from the customer. An official of the bank shall invariably carry out CDD done in this manner, and such exception handling shall also be a part of the concurrent audit as mandated in paragraph 11. The bank shall ensure to duly record the cases of exception handling in a centralised exception database. The database shall contain the details of grounds of granting exception, customer details, name of the designated official authorising the exception and additional details, if any. The bank shall subject the database to periodic internal audit / inspection and the bank shall make database available for supervisory review. Explanation 1: The bank shall, where its customer submits a proof of possession of Aadhaar Number containing Aadhaar Number, ensure that such customer redacts or blacks out his Aadhaar number through appropriate means where the authentication of Aadhaar number is not required as per proviso (i) above. Explanation 2: A bank official, business correspondent, or business facilitator can perform biometric-based e-KYC authentication, including Aadhaar Face Authentication. Explanation 3: The bank shall ensure that the use of Aadhaar, proof of possession of Aadhaar etc., is in accordance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Act, 2016 and the regulations made thereunder. Explanation 4: Aadhaar number is not mandatory for purposes of KYC. However, in case the customer is desirous of receiving any benefit or subsidy under any scheme notified under section 7 of the Aadhaar (Targeted Delivery of Financial and Other subsidies, Benefits and Services) Act, 2016 (18 of 2016), the customer shall provide the Aadhaar number to the bank. In other cases, customers may provide the Aadhaar number voluntarily. 23. Digital KYC Process: (1) The bank shall develop an application for digital KYC process and make it available at customer touch points for undertaking KYC of its customers and shall undertake the KYC process only through this authenticated application. (2) The bank shall control the access to the Application and shall ensure that unauthorised persons do not use it. Authorised officials shall access the Application only through a login-id and password or a Live OTP or Time OTP controlled mechanism that the bank provides. (3) The customer, for the purpose of KYC, shall visit the location of the authorised official of the bank or vice-versa. The original OVD shall be in possession of the customer. (4) The bank shall ensure that the authorised officer takes a Live photograph of the customer and embeds the same photograph in the Customer Application Form (CAF). Further, the bank’s system Application shall put a watermark in readable form, containing the CAF number, GPS coordinates, authorised official’s name, unique employee code (which the bank assigns) and date (DD:MM:YYYY) and time stamp (HH:MM:SS), on the captured live photograph of the customer. (5) The bank’s Application shall have the feature that it captures only a live photograph of the customer and does not capture any printed or video graphed photograph. The background behind the customer while capturing live photograph shall be of white colour and no other person shall come into the frame while capturing the live photograph of the customer. (6) Similarly, the authorised officer shall capture the live photograph of the original OVD or proof of possession of Aadhaar where offline verification cannot be carried out (placed horizontally), vertically from above and shall apply a water-marking in readable form as mentioned above. The authorised officer shall ensure there is no skew or tilt in the mobile device while capturing the live photograph of the original documents. (7) The authorised officer shall capture the live photograph of the customer and his original documents in proper light so that they are clearly readable and identifiable. (8) Thereafter, the authorised officer shall fill all the entries in the CAF as per the documents and information furnished by the customer. In those documents where Quick Response (QR) code is available, such details may be auto-populated by scanning the QR code instead of manual filing the details. For example, in case of physical Aadhaar / e-Aadhaar downloaded from UIDAI where QR code is available, the details like name, gender, date of birth and address may be auto-populated by scanning the QR available on Aadhaar / e-Aadhaar. (9) Once the above-mentioned process is completed, a One Time Password (OTP) message containing the text that ‘Please verify the details filled in form before sharing OTP’ shall be sent to customer’s own mobile number. Upon successful validation of the OTP, the bank will treat it as the customer’s signature on CAF. However, if the customer does not have their own mobile number, the bank may use the mobile number of their family / relatives / known persons for this purpose and clearly mention it in the CAF. In any case, the bank shall not use the mobile number of authorised officer registered with the bank for the customer signature. The bank shall check that the mobile number used in customer signature is not the mobile number of the authorised officer. (10) The authorised officer shall provide a declaration about the capturing of the live photograph of the customer and original document. For this purpose, the bank shall verify the authorised officer with One Time Password (OTP) which will be sent to his mobile number registered with the bank. Upon successful OTP validation, the bank shall treat it as the authorised officer’s signature on the declaration. The live photograph of the authorised officer shall also be captured in this authorised officer’s declaration. (11) Subsequent to all these activities, the Application shall give information about the completion of the process and submission of activation request to activation officer of the bank, and also generate the transaction-id / reference-id number of the process. The authorised officer shall intimate the details regarding transaction-id / reference-id number to the customer for future reference. (12) The authorised officer of the bank shall check and verify that: (i) information available in the picture of the document matches with the information entered by authorised officer in CAF; (ii) live photograph of the customer matches with the photo available in the document; and (iii) the authorised officer has properly filled all of the necessary details in CAF, including mandatory field. (13) On Successful verification, the CAF shall be digitally signed by authorised officer of the bank who will take a print of CAF, get signatures / thumb-impression of customer at appropriate place, then scan and upload the same in system. Original hard copy may be returned to the customer. (14) The bank may use the services of Business Correspondent (BC) for this process. 24. Accounts opened using Aadhaar OTP based e-KYC, in non-face-to-face mode, are subject to the following conditions: (1) The Customer shall give specific consent for the authentication through OTP. (2) As a risk-mitigating measure for such accounts, the bank shall ensure that it sends transaction alerts, OTP, etc., only to the mobile number of the customer registered with Aadhaar. The bank shall have a Board-approved policy delineating a robust process of due diligence for dealing with requests for change of mobile number in such accounts. (3) The aggregate balance of all the deposit accounts of the customer shall not exceed Rupees One Lakh. In case the balance exceeds the threshold, the bank shall cease the account’s operation, until it completes the CDD as mentioned at (6) below. (4) The aggregate of all credits in a financial year, in all the deposit accounts taken together, shall not exceed Rupees Two Lakh. (5) As regards borrowal accounts, the bank shall sanction only term loans. The aggregate amount of term loans sanctioned shall not exceed ₹50,000 in a year. (6) The bank shall not allow accounts, both deposit and borrowal, opened using OTP based e-KYC to operate for more than one year unless it carries out identification as per paragraph 22 or as per paragraphs 25 and 26 (V-CIP). If the bank uses Aadhaar details under paragraph 25 and 26, it shall follow the process in its entirety, including fresh Aadhaar OTP authentication. (7) If the bank does not complete the CDD procedure as mentioned above within a year; (a) in respect of deposit accounts, the bank shall close the same immediately, and (b) in respect of borrowal accounts, the bank shall allow no further debits. (8) The bank shall obtain declaration from the customer to the effect that no other account has been opened nor will be opened using OTP based KYC in non-face-to-face mode with any other RE. Further, while uploading KYC information to CKYCR, bank shall clearly indicate that such accounts are opened using OTP based e-KYC and other REs shall not open accounts based on the KYC information of accounts opened with OTP based e-KYC procedure in non-face- to-face mode. (9) The bank shall have strict monitoring procedures including systems to generate alerts in case of any non-compliance / violation, to ensure compliance with the above-mentioned conditions. 25. The bank may undertake V-CIP to carry out: (1) CDD in case of new customer onboarding for individual customers, proprietor in case of proprietorship firm, authorised signatories and Beneficial Owners (BOs) in case of Legal Entity (LE) customers. Provided that in case of CDD of a proprietorship firm, the bank shall also obtain the equivalent e-document of the activity proofs with respect to the proprietorship firm, as mentioned in paragraph 30 and paragraph 31, apart from undertaking CDD of the proprietor. (2) Conversion of existing accounts opened in non-face-to-face mode using Aadhaar OTP based e-KYC authentication as per paragraph 24. (3) Updation / Periodic updation of KYC for eligible customers. 26. The bank opting to undertake V-CIP, shall adhere to the following minimum standards: (1) V-CIP Infrastructure (i) The bank shall have complied with the RBI guidelines on minimum baseline cyber security and resilience framework for banks, as updated from time to time as well as other general guidelines on IT risks. The bank shall house the technology infrastructure in its own premises and the V-CIP connection and interaction shall necessarily originate from its own secured network domain. Any technology related outsourcing for the process shall comply with relevant RBI guidelines. Where the bank uses a cloud deployment model, it shall ensure that ownership of data in such model rests with the bank only and all the data including video recording is transferred to the bank’s exclusively owned / leased server(s) including cloud server, if any, immediately after the V-CIP process is completed and the cloud service provider or third-party technology provider assisting the V-CIP shall retain no data. (ii) The bank shall ensure end-to-end encryption of data between customer device and the hosting point of the V-CIP application, as per appropriate encryption standards. The bank shall record the customer consent in an auditable and alteration-proof manner. (iii) The V-CIP infrastructure / application shall be capable of preventing connection from IP addresses outside India or from spoofed IP addresses. (iv) The video recordings shall contain the live GPS co-ordinates (geo-tagging) of the customer undertaking the V-CIP and date and time stamp. The quality of the live video in the V-CIP shall be adequate to allow identification of the customer beyond doubt. (v) The application shall have components with face liveness / spoof detection as well as face matching technology with high degree of accuracy, even though the ultimate responsibility of any customer identification rests with the bank. Explanation: Making specific facial gestures, like blinking of eyes, smiling, frowning, etc. is not mandatory for liveness check. The bank shall take due cognizance of special needs, if any, of the customer during liveness check. (vi) The bank may use appropriate artificial intelligence (AI) technology to ensure that the V-CIP is robust. (vii) Based on experience of detected / attempted / ‘near-miss’ cases of forged identity, the bank shall regularly update the technology infrastructure including application software as well as workflows. The bank shall report any detected case of forged identity through V-CIP as a cyber event under extant regulatory guidelines. (viii) The bank shall subject the V-CIP infrastructure to necessary tests such as Vulnerability Assessment, Penetration testing and a Security Audit to ensure its robustness and end-to-end encryption capabilities. The bank shall mitigate any critical gap reported under this process before rolling out its implementation. The empanelled auditors of Indian Computer Emergency Response Team (CERT-In) shall conduct such tests. Such tests shall also be carried out periodically in conformance to internal / regulatory guidelines. (ix) The bank shall subject the V-CIP application software and relevant APIs / webservices to appropriate testing of functional, performance, and maintenance strength before being used in live environment. The bank shall roll out the application only after closure of any critical gap found during such tests. Such tests shall also be carried out periodically in conformity with internal / regulatory guidelines. (2) V-CIP Procedure (i) Each bank shall formulate a clear workflow and standard operating procedure for V-CIP and ensure adherence to it. The V-CIP process shall be operated only by officials of the bank specially trained for this purpose. The official shall be capable to carry out liveness check and detect any other fraudulent manipulation or suspicious conduct of the customer and act upon it. The liveness check shall not result in exclusion of person with special needs. (ii) Disruption of any sort including pausing of video, reconnecting calls, etc., may not result in creation of multiple video files. If pause or disruption is not leading to the creation of multiple files, then the bank may not initiate a fresh session. However, in case of call drop / disconnection, fresh session shall be initiated. (iii) The bank shall vary the sequence and / or type of questions, including those indicating the liveness of the interaction, during video interactions to establish that the interactions are real-time and not pre-recorded. (iv) The bank shall reject the account opening process if it observes any prompting at the customer end. (v) The bank shall factor in the fact that the V-CIP customer is an existing or new customer, or if the case relates to one rejected earlier or if the name appears in some negative list, at an appropriate stage of workflow. (vi) The authorised official of the bank performing the V-CIP shall record audio and video as well as capture a photograph of the customer present for identification and obtain the identification information using any one of the following: (a) OTP based Aadhaar e-KYC authentication. (b) Offline Verification of Aadhaar for identification. (c) KYC records downloaded from CKYCR, in accordance with paragraph 64, using the KYC identifier provided by the customer. (d) Equivalent e-document of Officially Valid Documents (OVDs) including documents issued through DigiLocker. (vii) The bank shall ensure to redact or blackout the Aadhaar number in terms of paragraph 22. (viii) In case of offline verification of Aadhaar u
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/DOR/2025-26/291 · issued 28 Nov 2025. The plain-English explanation above is BankPulse’s own independent summary.