HomeCirculars › RBI/DOR/2025-26/377

RBI KYC Directions for Asset Reconstruction Companies, 2025

Current · Source: Reserve Bank of India · RBI/DOR/2025-26/377 · issued 28 Nov 2025 · ~2 min read
Quick answerRBI issued comprehensive KYC directions for ARCs effective November 28, 2025, aligning them with PMLA and FATF standards. ARCs must adopt customer acceptance policies, risk management, CDD, record-keeping, and reporting to FIU-IND. Non-compliance invites regulatory action.
The rule, in the simplest words
How it plays out — a real example

A KYC & compliance officer in Indore is selling a bad loan to an ARC. The ARC's compliance officer asks for the borrower's Aadhaar and PAN card, runs a risk check, and files a report to FIU-IND (the government's money-laundering watchdog) because the loan is over ₹10 lakh. The officer feels relieved knowing the ARC is following the new RBI rules, so the deal won't get blocked later.

What changed

RBI consolidated and updated KYC norms specifically for ARCs under the Securitisation Act, RBI Act, PMLA, and FEMA. The directions cover customer identification, due diligence, risk categorization, record management, and reporting to FIU-IND. They replace earlier fragmented instructions and align ARC practices with broader AML/CFT framework.

What it means for you

ARCs must now implement robust KYC processes similar to banks, including Aadhaar-based authentication and enhanced due diligence for high-risk customers. This tightens oversight on asset reconstruction activities to prevent money laundering and terrorist financing. Banks dealing with ARCs should ensure their counterparties comply, as lapses could affect shared transactions.

What you must do

Who it affects

All Asset Reconstruction Companies (ARCs), Banks and financial institutions that transact with ARCs, Compliance and AML teams within ARCs and partner banks

❓ Common questions

Regulatory timeline

Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).

When do these KYC directions take effect?

The directions came into effect on November 28, 2025, the date they were placed on the RBI website.

What is the legal basis for these directions?

RBI issued them under the Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002, the RBI Act, 1934, the Payment and Settlement Systems Act, 2007, FEMA, 1999, and the PML Rules, 2005.

Do these directions apply to all ARCs?

Yes, they are applicable to all Asset Reconstruction Companies registered with RBI.

📜 Read the original circular — full text as issued by RBI
Notifications - Reserve Bank of India Skip to main content Selected Selected Change Language हिंदी Search the Website Search Home About Us ▼ About Us Organisation & Functions ▶ Organisation Structure Departments Offices Training Establishment ▶ College of Agricultural Banking Reserve Bank Staff College College of Supervisors RBI's Functions and Working Governors Deputy Governors Executive Directors Communication Policy of RBI Sources of Information ▶ Annual Publications Half-yearly Publications Quarterly Publications Monthly Publications Weekly Publications Occasional Publications SDDS NSDP Data Releases Publications available on Subscription General Information RBI History Museum ▶ The RBI Museum RBI Monetary Museum Notification ▼ Notifications Master Directions Master Circulars Amendment Directions Draft Notifications/Guidelines ▶ Draft Notifications/Guidelines Draft Directions (RE-wise) Index To RBI Circulars Standalone Circulars Circulars Withdrawn Press Releases Speeches & Media Interactions ▼ Speeches Media Interactions Memorial Lectures Podcasts Publications ▼ Biennial Annual Half-Yearly Quarterly Bi-monthly Monthly Weekly Occasional Reports Working Papers Legal Framework ▼ Act Rules Regulations Schemes Research ▼ External Research Schemes RBI Occasional Papers Working Papers RBI Bulletin History DRG Studies KLEMS State Statistics and Finances Statistics ▼ Data Releases Database on Indian Economy Public Debt Statistics Regulatory Reporting ▼ List of Returns Data Definition Validation rules/ Taxonomy List of RBI Reporting Portals FAQs of RBI Reporting Portals Home Notifications Notifications ( 565 kb ) Reserve Bank of India (Asset Reconstruction Companies – Know Your Customer) Directions, 2025 (Updated as on December 29, 2025) RBI/DOR/2025-26/377 DOR.AML.REC.No.296/14.01.010/2025-26 November 28, 2025 Previous Versions Reserve Bank of India (Asset Reconstruction Companies – Know Your Customer) Directions, 2025 (Updated as on December 29, 2025) Table of Contents Chapter I – Preliminary Chapter II – General Chapter III – Customer Acceptance Policy Chapter IV – Risk Management Chapter V – Customer Identification Procedure (CIP) Chapter VI – Customer Due Diligence (CDD) Procedure Chapter VII – Record Management Chapter VIII – Reporting Requirements to Financial Intelligence Unit – India Chapter IX – Requirements/obligations under International Agreements - Communications from International Agencies Chapter X – Other Instructions Chapter XI – Repeal and Other Provisions Annex - I Annex - II Introduction In order to prevent banks and other financial institutions from being used as a channel for Money Laundering (ML) / Terrorist Financing (TF) and to ensure the integrity and stability of the financial system, efforts are continuously being made both internationally and nationally, by way of prescribing various rules and regulations. Internationally, the Financial Action Task Force (FATF), which is an inter-governmental body established in 1989 by the Ministers of its member jurisdictions, sets standards and promotes effective implementation of legal, regulatory and operational measures for combating money laundering, terrorist financing and other related threats to the integrity of the international financial system. India, as a member of FATF, is committed to upholding measures to protect the integrity of the international financial system. In India, the Prevention of Money-Laundering Act, 2002, and the Prevention of Money- Laundering (Maintenance of Records) Rules, 2005, form the legal framework on Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT). The provisions of the PML Act, 2002 and the PML Rules, 2005, as amended from time to time by the Government of India, require Regulated Entities (REs) to follow certain customer identification procedures while undertaking a transaction either by establishing an account-based relationship or otherwise, and to monitor their transactions. Accordingly, in exercise of the powers conferred by sections 3, 9, 10, 12 and 12A of the Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002 (54 of 2002) , sections 45JA, 45K, and 45L of the Reserve Bank of India Act, 1934, section 10(2) read with section 18 of Payment and Settlement Systems Act 2007 (Act 51 of 2007), section 11(1) of the Foreign Exchange Management Act (FEMA), 1999, Rule 9(14) of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, and all other laws enabling the Reserve Bank in this regard, the RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby issues the Directions hereinafter specified. Chapter I – Preliminary A. Short Title and Commencement. 1. These Directions shall be called the Reserve Bank of India (Asset Reconstruction Companies – Know Your Customer) Directions, 2025. 2. These directions shall come into effect on the day they are placed on the official website of the RBI. B. Applicability 3. These Directions shall be applicable to all Asset Reconstruction Companies (hereinafter collectively referred to as 'ARCs' and individually as an 'ARC'). C. Definitions 4. In these Directions, unless the context otherwise requires, the following meanings are assigned to the terms herein: (1) Terms bearing meaning assigned in terms of the Prevention of Money-Laundering Act, 2002, and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005: (i) ‘Aadhaar number’ shall have the meaning assigned to it in clause (a) of section 2 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016); (ii) ‘Act’ and ‘Rules’ mean the Prevention of Money-Laundering Act, 2002 and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, respectively and amendments thereto. (iii) ‘Authentication’ , in the context of Aadhaar authentication, means the process as defined under sub-section (c) of section 2 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016. (iv) ‘Beneficial Owner (BO)’ (a) Where the customer is a company , the beneficial owner is the natural person(s), who, whether acting alone or together, or through one or more juridical persons, has / have a controlling ownership interest or who exercises control through other means. Explanation: For the purpose of this sub-clause- • ‘Controlling ownership interest’ means ownership of / entitlement to more than 10 percent of the shares or capital or profits of the company. • ‘Control’ shall include the right to appoint the majority of the directors or to control the management or policy decisions including by virtue of their shareholding or management rights or shareholders agreements or voting agreements. (b) Where the customer is a partnership firm , the beneficial owner is the natural person(s), who, whether acting alone or together, or through one or more juridical person(s), has / have ownership of / entitlement to more than 10 percent of capital or profits of the partnership or who exercises control through other means. Explanation: For the purpose of this sub-clause, ‘control’ shall include the right to control the management or policy decision. (c) Where the customer is an unincorporated association or body of individuals , the beneficial owner is the natural person(s), who, whether acting alone or together, or through one or more juridical person, has / have ownership of / entitlement to more than 15 percent of the property or capital or profits of the unincorporated association or body of individuals. Explanation: Term ‘body of individuals’ includes societies where no natural person is identified under (a), (b) or (c) above, the beneficial owner is the relevant natural person who holds the position of senior managing official. (d) Where the customer is a trust , the identification of beneficial owner(s) shall include identification of the author of the trust, the trustee, the beneficiaries with 10 percent or more interest in the trust and any other natural person exercising ultimate effective control over the trust through a chain of control or ownership. (v) ‘Certified Copy’ – Obtaining the certified copy by the ARC shall mean comparing the copy of the proof of possession of Aadhaar number (where offline verification cannot be carried out) or the officially valid document produced by the customer with the original, and recording the same on the copy by the authorised officer of the ARC as per the provisions contained in the Act. Provided that in case of Non-Resident Indians (NRIs) and Persons of Indian Origin (PIOs), as defined in Foreign Exchange Management (Deposit) Regulations, 2016 {FEMA 5(R)}, the ARC may alternatively obtain the original certified copy, certified by any one of the following: (a) authorised officials of overseas branches of Scheduled Commercial Banks registered in India, (b) branches of overseas banks with whom Indian banks have relationships, (c) Notary Public abroad, (d) Court Magistrate, (e) Judge, (f) Indian Embassy / Consulate General in the country where the non-resident customer resides. (vi) ‘Central KYC Records Registry (CKYCR)’ means an entity defined under Rule 2(1) of the Rules, to receive, store, safeguard and retrieve the KYC records in digital form of a customer. (vii) ‘Designated Director’ means a person whom the ARC designates to ensure overall compliance with the obligations imposed under chapter IV of the PML Act and the Rules and shall include the Managing Director or a whole-time Director, duly authorized by the Board of Directors. Explanation: For the purpose of this clause, the terms ‘Managing Director’ and ‘Whole-time Director’ shall have the meaning assigned to them in the Companies Act, 2013. (viii) ‘Digital KYC’ means the capturing live photo of the customer and officially valid document or the proof of possession of Aadhaar (where offline verification cannot be carried out), along with the latitude and longitude of the location where such live photo is being taken by an authorized officer of the ARC, as per the provisions contained in the Act. (ix) ‘Digital Signature’ shall have the same meaning as assigned to it in clause (p) of sub-section (1) of section (2) of the Information Technology Act, 2000 (21 of 2000). (x) ‘Equivalent e-document’ means an electronic equivalent of a document issued by the issuing authority of such document with its valid digital signature, including documents issued to the digital locker account of the customer as per rule 9 of the Information Technology (Preservation and Retention of Information by Intermediaries Providing Digital Locker Facilities) Rules, 2016. (xi) ‘Group’ – The term ‘group’ shall have the same meaning assigned to it in clause (e) of sub-section (9) of section 286 of the Income-tax Act,1961 (43 of 1961). (xii) ‘Know Your Client (KYC) Identifier’ means the unique number or code assigned to a customer by the Central KYC Records Registry. Explanation: A customer can obtain his KYC Identifier through the following ways: In the process of opening an account, once the customer’s KYC Identifier is generated by CKYCR and provided to the ARC, the latter shall share the same with the concerned customer. The customer can also access his KYC Identifier on CKYCR Portal ( www.ckycindia.in ). (xiii) ‘Non-profit organisations (NPO)’ means any entity or organisation, constituted for religious or charitable purposes referred to in clause (15) of section 2 of the Income-tax Act, 1961 (43 of 1961), that is registered as a trust or a society under the Societies Registration Act, 1860 or any similar State legislation or a company registered under section 8 of the Companies Act, 2013 (18 of 2013). (xiv) ‘Officially Valid Document (OVD)’ means the passport, the driving licence, proof of possession of Aadhaar number, the Voter's Identity Card issued by the Election Commission of India, job card issued by NREGA duly signed by an officer of the State Government, and letter issued by the National Population Register containing details of name and address. Provided that, (a) where the customer submits his proof of possession of Aadhaar number as an OVD, he may submit it in such form as are issued by the Unique Identification Authority of India (UIDAI). (b) when the customer furnishes an OVD that does not have an updated address, the ARC shall deem the following documents or the equivalent e-documents thereof to be OVDs for the limited purpose of proof of address:- • utility bill which is not more than two months old of any service provider (electricity, telephone, post-paid mobile phone, piped gas, water bill); • property or Municipal tax receipt; • pension or family pension payment orders (PPOs) issued to retired employees by Government Departments or Public Sector Undertakings, if they contain the address; • letter of allotment of accommodation from employer issued by State Government or Central Government Departments, statutory or regulatory bodies, public sector undertakings, scheduled commercial banks, financial institutions and listed companies and leave and licence agreements with such employers allotting official accommodation; Illustration: If a customer is staying in Chennai but their OVD contains an address of New Delhi, they can open an account in Chennai by submitting a deemed to be OVD for the purpose of proof of address. However, as mentioned below in clause (c), they are required to submit an OVD with current address within a period of three months. (c) the customer shall submit OVD with current address within a period of three months of submitting the documents specified at (b) above (d) if the OVD that a foreign national presents does not contain the details of address, the ARC shall accept documents that Government departments of foreign jurisdictions issue, and aletter that the Foreign Embassy or Mission in India issues, as proof of address. Explanation: For the purpose of this clause, the ARC shall deem a document to be an OVD even if there is a change in the name subsequent to its issuance provided it is supported by a marriage certificate issued by the State Government or Gazette notification, indicating such a change of name. (xv) ‘Offline verification’ shall have the same meaning as assigned to it in clause (pa) of section 2 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016). (xvi) ‘Person’ has the same meaning assigned in the Act and includes: (a) an individual, (b) a Hindu undivided family, (c) a company, (d) a firm, (e) an association of persons or a body of individuals, whether incorporated or not, (f) every artificial juridical person, not falling within any one of the above persons (a to e), and (g) any agency, office or branch owned or controlled by any of the above persons (a to f). (xvii) ‘Principal Officer’ means an ARC’s nominated officer at the management level, responsible for furnishing information as per rule 8 of the Rules. (xviii) ‘Suspicious transaction’ means a ‘transaction’ as defined below, including an attempted transaction, whether or not made in cash, which, to a person acting in good faith: (a) gives rise to a reasonable ground of suspicion that it may involve proceeds of an offence specified in the Schedule to the Act, regardless of the value involved; or (b) appears to be made in circumstances of unusual or unjustified complexity; or (c) appears to have no economic rationale or bona fide purpose; or (d) gives rise to a reasonable ground of suspicion that it may involve financing of the activities relating to terrorism. Explanation: Transaction involving financing of the activities relating to terrorism includes transaction involving funds that the ARC suspects are linked or related to, or to be used for terrorism, terrorist acts or by a terrorist, terrorist organisation or those who finance or are attempting to finance terrorism. (xix) ‘Transaction’ means a purchase, sale, loan, pledge, gift, transfer, delivery or the arrangement thereof and includes: (a) opening of an account; (b) deposit, withdrawal, exchange or transfer of funds in whatever currency, whether in cash or by cheque, payment order or other instruments or by electronic or other non-physical means; (c) entering into any fiduciary relationship; (d) any payment made or received, in whole or in part, for any contractual or other legal obligation; or (e) establishing or creating a legal person or legal arrangement. (2) Unless the context otherwise requires, terms in these Directions shall bear the meanings assigned to them below: (i) ‘Common Reporting Standards (CRS)’ means reporting standards set for implementation of multilateral agreement signed to automatically exchange information based on Article 6 of the Convention on Mutual Administrative Assistance in Tax Matters. (ii) ‘Customer’ means a person who is engaged in a financial transaction or activity with the ARC and includes a person on whose behalf the person who is engaged in the transaction or activity, is acting. (iii) ‘Customer Due Diligence (CDD)’ means identifying and verifying the customer and the beneficial owner using reliable and independent sources of identification. Explanation: The CDD, at the time of commencement of an account-based relationship or while carrying out occasional transaction of an amount equal to or exceeding ₹50,000 whether conducted as a single transaction or several transactions that appear to be connected, or any international money transfer operations, shall include: (a) Identification of the customer, verification of their identity using reliable and independent sources of identification, obtaining information on the purpose and intended nature of the business relationship, where applicable (b) Taking reasonable steps to understand the nature of the customer's business, and its ownership and control; (c) Determining whether a customer is acting on behalf of a beneficial owner, and identifying the beneficial owner and taking all steps to verify the identity of the beneficial owner, using reliable and independent sources of identification. (iv) ‘Customer identification’ means undertaking the process of CDD. (v) ‘FATCA’ means Foreign Account Tax Compliance Act of the United States of America (USA) which, inter alia, requires foreign financial institutions to report about financial accounts held by U.S. taxpayers or foreign entities in which U.S. taxpayers hold a substantial ownership interest. (vi) ‘IGA’ means Inter Governmental Agreement between the Governments of India and the USA to improve international tax compliance and to implement FATCA of the USA. (vii) ‘KYC Templates’ means templates prepared to facilitate collating and reporting KYC data to the CKYCR, for individuals and legal entities. (viii) ‘Non-face-to-face customers’ means customers who open accounts without visiting the branch / offices of the ARC or meeting the officials of the ARC. (ix) ‘On-going Due Diligence’ means regular monitoring of transactions in accounts to ensure that transactions are consistent with the ARC’s knowledge about the customers, customers’ business and risk profile, the source of funds / wealth. (x) ‘Payable-through accounts’: The term payable-through accounts refers to correspondent accounts that third parties use directly to transact business on their own behalf. (xi) ‘Periodic Updation’ means the steps taken to ensure that documents, data or information collected under the CDD process are kept up-to-date and relevant by undertaking reviews of existing records at the periodicity prescribed by the RBI. (xii) 'Regulated Entities (REs)' means: (a) all Scheduled Commercial Banks (SCBs) / Regional Rural Banks (RRBs) / Local Area Banks (LABs) / All Primary (Urban) Co-operative Banks (UCBs) / State and Central Co-operative Banks (StCBs / CCBs), and any other entity which has been licensed under section 22 of Banking Regulation Act, 1949, which as a group shall be referred as ‘banks’ (b) All India Financial Institutions (AIFIs) (c) All Non-Banking Finance Companies (NBFCs), Miscellaneous Non-Banking Companies (MNBCs) and Residuary Non-Banking Companies (RNBCs) (d) Asset Reconstruction Companies (ARCs) (e) All Payment System Providers (PSPs) / System Participants (SPs) and Prepaid Payment Instrument Issuers (PPI Issuers) (f) All authorised persons (APs), including those who are agents of Money Transfer Service Scheme (MTSS), regulated by the Regulator. (xiii) ‘Shell Bank’ means a bank that has no physical presence in the country in which it is incorporated and licensed, and which is unaffiliated with a regulated financial group that is subject to effective consolidated supervision. Physical presence means meaningful mind and management located within a country. The existence simply of a local agent or low-level staff does not constitute physical presence. (xiv) ‘Video based Customer Identification Process (V-CIP)’: an alternative method by which an authorised official of the ARC conducts customer identification with facial recognition and customer due diligence. This process involves a seamless, secure, live, informed- consent based audio-visual interaction with the customer to obtain identification information required for CDD purpose, and to ascertain the veracity of the information which the customer furnished, through independent verification and by maintaining an audit trail of the process. The ARC shall treat such processes complying with prescribed standards and procedures on par with face-to-face CIP for the purpose of this Direction. (3) Unless defined herein, all other expressions shall have the same meaning as has been assigned to them under the Banking Regulation Act, 1949, the Reserve Bank of India Act, 1935, the Prevention of Money Laundering Act, 2002, the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002 (54 of 2002) and regulations made thereunder, any statutory modification or re-enactment thereto or as used in commercial parlance, as the case may be. Chapter II – General A. Board of Directors / Policies related guidelines: 5. Know Your Customer (KYC) Policy: (1) The ARC shall have a KYC policy. The Board of Directors of the ARC, or any committee to which the Board has delegated power, shall duly approve the KYC policy. (2) The KYC policy shall include following four key elements: (i) Customer Acceptance Policy; (ii) Risk Management; (iii) Customer Identification Procedures (CIP); and (iv) Monitoring of Transactions (3) The KYC policy shall, inter alia, incorporate provisions for the following: (i) Periodic updation of KYC (ii) Any exceptional measures for KYC updation, such as requiring a recent photograph, physical presence, or a more frequent updation schedule than the minimum prescribed. (iii) Obtaining a copy of OVD or deemed OVD, for the purpose of proof of change of address during KYC updation. (iv) Providing facility of updation / periodic updation of KYC at any branch. (4) Furthermore, the ARC shall have the policies approved by the Board detailing a robust due diligence process for managing requests to change the registered Mobile Number for Accounts opened in non-face-to-face mode. 6. The specific responsibilities and actions stipulated for the Board or its relevant committees in paragraph 5 above are elaborated upon in greater detail in the Directions. 7. In terms of PML Rules, groups shall implement group-wide policies for the purpose of discharging obligations under the provisions of Chapter IV of the PML Act, 2002. (15 of 2003). Accordingly, every ARC which is part of a group, shall implement group-wide programmes against money laundering and terror financing, including group-wide policies for sharing information required for the purposes of client due diligence, money laundering, and terrorist finance risk management, and such programmes shall include adequate safeguards on the confidentiality and use of information exchanged, including safeguards to prevent tipping-off. 8. ARC’s policy framework shall seek to ensure compliance with PML Act / Rules, including regulatory instructions in this regard and shall provide a bulwark against threats arising from money laundering, terrorist financing, proliferation financing and other related risks. While ensuring compliance with the legal / regulatory requirements as above, the ARC may also consider adoption of best international practices taking into account the FATF standards and FATF guidance notes, for managing risks better. 9. Money Laundering and Terrorist Financing Risk Assessment by the ARC: (1) The ARC shall carry out ‘Money Laundering (ML) and Terrorist Financing (TF) Risk Assessment’ exercises periodically to identify, assess and take effective measures to mitigate its money laundering and terrorist financing risk for clients, countries or geographic areas, products, services, transactions or delivery channels, etc. (2) The assessment process shall consider all the relevant risk factors before determining the level of overall risk and the appropriate level and type of mitigation to be applied. While preparing the internal risk assessment, the ARC shall take cognizance of the overall sector-specific vulnerabilities, if any, that the regulator / supervisor may share with the ARC from time to time. (3) The ARC shall properly document its risk assessment and it shall be proportionate to the nature, size, geographical presence, complexity of activities / structure, etc. of the ARC. Further, the Board or a committee of the Board to which the power has been delegated shall determine the periodicity of the risk assessment exercise, in alignment with the outcome of the risk assessment exercise. However, the ARC shall review it at least annually. (4) The ARC shall present the outcome of the exercise to the Board or any committee of the Board to which the power has been delegated in this regard. The outcome shall also be made available to competent authorities and self-regulating bodies. 10. The ARC shall apply a Risk Based Approach (RBA) for mitigation and management of the risks (identified on its own or through national risk assessment) and shall have Board-approved policies, controls and procedures in this regard. The ARC shall implement a CDD programme, having regard to the ML / TF risks identified and the size of business. Further, the ARC shall monitor the implementation of the controls and enhance them if necessary. 11. Compliance of KYC policy: The ARC shall ensure compliance with KYC Policy through: (1) specifying as to who constitute ‘Senior Management’ for the purpose of KYC compliance. (2) allocation of responsibility for effective implementation of policies and procedures. (3) independent evaluation of the compliance functions of the ARC’s policies and procedures, including legal and regulatory requirements. (4) concurrent / internal audit system to verify compliance with KYC / AML policies and procedures. (5) submission of quarterly audit notes and compliance to the Audit Committee. 12. The ARC shall ensure that it does not outsource the decision-making functions of determining compliance with KYC norms. B. Other General Guidelines: 13. Designated Director: (1) A ‘Designated Director’ is a Board-nominated person whom the ARC designates to ensure overall compliance with the obligations imposed under Chapter IV of the PML Act and the Rules. (2) The ARC shall communicate the name, designation, address, and contact details of the Designated Director to the FIU-IND and RBI. (3) The ARC shall not nominate the Principal Officer as the 'Designated Director'. 14. Principal Officer: (1) The Principal Officer shall be responsible for ensuring compliance, monitoring transactions, and sharing and reporting information as required under the law / regulations. (2) The ARC shall communicate the name, designation, address, and contact details of the Principal Officer to the FIU-IND and RBI. Chapter III – Customer Acceptance Policy 15. The ARC shall frame a Customer Acceptance Policy. 16. Without prejudice to the generality of the aspect that Customer Acceptance Policy may contain, the ARC shall: (1) not open any account in an anonymous or fictitious / benami name. Also, ARC shall ensure not to acquire financial assets / accounts where KYC (i.e. customer identification and verification of customer’s identity) is pending at the level of transferor bank / financial institution. (2) open no account where it is unable to apply appropriate CDD measures, either due to non-cooperation of the customer or unreliability of the documents / information furnished by the customer. The ARC shall consider filing an STR, if necessary, when it is unable to comply with the relevant CDD measures in relation to the customer. (3) not undertake a transaction or commence an account-based relationship without following the CDD procedure. (4) specify the mandatory information to be sought for KYC purposes while opening an account or taking over the financial asset / account and during the periodic updation. (5) obtain additional information, where its internal KYC Policy has not specified such information requirement, with the explicit consent of the customer. (6) apply the CDD procedure at the Unique Customer Identification Code (UCIC) level. Thus, if an existing KYC-compliant customer of an ARC desires to open another account or avail of any other product or service from the same ARC, there shall be no need for a fresh CDD exercise as far as identification of the customer is concerned. (7) follow the CDD Procedure for all the joint account holders, while opening a joint account. (8) clearly spell out the circumstances in which a customer is permitted to act on behalf of another person / entity. (9) put in place a suitable system to ensure that the identity of the customer does not match with any person or entity, whose name appears in the sanctions lists indicated in Chapter IX of these Directions (10) verify the Permanent Account Number (PAN) (if obtained) from the verification facility of the issuing authority. (11) verify the customer’s digital signature on the equivalent e-document (if obtained) as per the provisions of the Information Technology Act, 2000 (21 of 2000). (12) verify the Goods and Services Tax (GST) number from the search / verification facility of the issuing authority, where the GST details are available. 17. The Customer Acceptance Policy shall not result in denial of a banking / financial facility to members of the general public, especially those who are financially or socially disadvantaged, including the Persons with Disabilities (PwDs). The ARC shall not reject an application for onboarding or periodic updation of KYC without application of mind. The officer concerned shall duly record the reason(s) for rejection. 18. Where the ARC forms a suspicion of money laundering or terrorist financing, and it reasonably believes that performing the CDD process will tip off the customer, it shall not pursue the CDD process and instead file an STR with FIU-IND. Chapter IV – Risk Management 19. For risk management, the ARC shall have a risk-based approach which includes the following. (1) The ARC shall categorise customers into low, medium, and high-risk categories, based on its assessment and risk perception. (2) The ARC may lay down broad principles for the risk-categorisation of customers. (3) The ARC shall undertake risk categorisation based on parameters such as the customer’s identity, social / financial status, nature of business activity, and information about the customer’s business and its location, geographical risk covering customers as well as transactions, type of products / services offered, delivery channel used for delivery of products / services, types of transactions undertaken such as cash, cheque / monetary instruments, wire transfers, forex transactions, etc. The ARC may also factor in the ability to confirm identity documents through online or other services offered by issuing authorities, while considering customer’s identity. (4) The ARC shall keep the risk categorisation of a customer and the specific reasons for such categorisation confidential and shall not reveal this information to the customer to avoid tipping off. Provided that the ARC collects various other non-intrusive information from different categories of customers relating to the perceived risk, and specifies the same in the KYC policy. Explanation: The ARC may also use the FATF Public Statement, the reports and guidance notes on KYC / AML issued by the Indian Banks Association (IBA), and other agencies, etc., in its risk assessment Chapter V – Customer Identification Procedure (CIP) 20. The ARC shall undertake identification of customers in the following cases: (1) Commencement of an account-based relationship with the customer (2) When there is a doubt about the authenticity or adequacy of the customer identification data it has obtained. (3) Carrying out transactions for a non-account-based customer, i.e., a walk-in customer, where the amount involved is equal to or exceeds ₹50,000 whether conducted as a single transaction or several transactions that appear to be connected. (4) When the ARC has reason to believe that a customer (account-based or walk-in) is intentionally structuring a transaction into a series of transactions below the threshold of ₹50,000. (5) The ARC shall ensure it does not seek introductions while opening accounts. 21. For the purpose of verifying the identity of customers at the time of commencement of an account-based relationship or while carrying out an occasional transaction of an amount equal to or exceeding ₹50,000 whether conducted as a single transaction or several transactions that appear to be connected, the ARC shall at its option, rely on customer due diligence done by a third party, subject to the following conditions: (1) The ARC obtains the records or information of the customer due diligence carried out by the third party immediately from the third party or from the Central KYC Records Registry. (2) The ARC shall take adequate steps to satisfy itself that the third party will make copies of identification data and other relevant documentation relating to the customer due diligence requirements available, upon request, without delay. (3) A regulator regulates, supervises, or monitors the third party, and the third party has measures in place for compliance with customer due diligence and record-keeping requirements in line with the requirements and obligations under the PML Act. (4) The ARC shall ensure that the third party is not based in a country or jurisdiction assessed as high-risk. (5) The ARC will have the ultimate responsibility for customer due diligence and undertaking enhanced due diligence measures, as applicable. Chapter VI – Customer Due Diligence (CDD) Procedure A. CDD Procedure in case of Individuals 22. For undertaking CDD, the ARC shall obtain the following from an individual while establishing an account-based relationship or while dealing with the individual who is a beneficial owner, authorised signatory or the power of attorney holder related to any legal entity: (1) the Aadhaar number where, (i) they are desirous of receiving any benefit or subsidy under any scheme notified under section 7 of the Aadhaar (Targeted Delivery of Financial and Other subsidies, Benefits and Services) Act, 2016 (18 of 2016); or (ii) they decide to submit their Aadhaar number voluntarily to an ARC or any RE notified under the first proviso to sub-section (1) of section 11A of the PML Act; or (2) the proof of possession of Aadhaar number where the ARC can carry out offline verification; or (3) the proof of possession of Aadhaar number where the ARC cannot carry out the offline verification or any OVD or the equivalent e-document thereof containing the details of their identity and address; or (4) the KYC Identifier with an explicit consent to download records from CKYCR; and (5) the PAN or the equivalent e-document thereof or Form No. 60 as defined in Income-tax Rules, 1962; and (6) the ARC may require such other documents including in respect of the nature of business and financial status of the customer, or the equivalent e-documents thereof. Provided that where the customer has submitted, (i) Aadhaar number under clause (1) above to an ARC notified under first proviso to sub-section (1) of section 11A of the PML Act, such ARC shall carry out authentication of the customer’s Aadhaar number using UIDAI’s e-KYC authentication facility. Further, in such a case, if the customer wants to provide a current address, different from the address as per the identity information available in the Central Identities Data Repository, they may give a self-declaration to that effect to the ARC. (ii) proof of possession of Aadhaar under clause (2) above where offline verification can be carried out, the ARC shall carry out offline verification. (iii) an equivalent e-document of any OVD, the ARC shall verify the digital signature as per the provisions of the Information Technology Act, 2000 (21 of 2000) and any rules issued thereunder and take a live photo as specified under paragraph 22 below. (iv) any OVD or proof of possession of Aadhaar number under clause (3) above where offline verification cannot be carried out, the ARC shall carry out verification through digital KYC as specified under paragraph 22 below. (v) KYC Identifier under clause (4) above, the ARC shall retrieve the KYC records online from the CKYCR in accordance with paragraph 59. Provided that for a period not beyond such date as the Government may notify for a class of REs, instead of carrying out digital KYC, the ARC pertaining to such class may obtain a certified copy of the proof of possession of Aadhaar number or the OVD and a recent photograph where the customer does not submit an equivalent e- document. Provided further that in case the ARC cannot perform an e-KYC authentication for an individual desirous of receiving any benefit or subsidy under any scheme notified under section 7 of the Aadhaar (Targeted Delivery of Financial and Other subsidies, Benefits and Services) Act, 2016 owing to injury, illness or infirmity on account of old age or otherwise, and similar causes, the ARC shall, apart from obtaining the Aadhaar number, perform identification preferably by carrying out offline verification or alternatively by obtaining the certified copy of any other OVD or the equivalent e-document thereof from the customer. An official of the ARC shall invariably carry out CDD in this manner, and such exception handling shall also be a part of the concurrent audit as mandated in paragraph 11. The ARC shall ensure to duly record the cases of exception handling in a centralised exception database. The database shall contain the details of grounds of granting exception, customer details, name of the designated official authorising the exception and additional details, if any. The ARC shall subject the database to periodic internal audit / inspection and the ARC shall make database available for supervisory review. Explanation 1: The ARC shall, where its customer submits a proof of possession of Aadhaar Number containing Aadhaar Number, ensure that such customer redacts or blacks out his Aadhaar number through appropriate means where the authentication of Aadhaar number is not required as per proviso (i) above. Explanation 2: An ARC official can perform biometric-based e-KYC authentication, including Aadhaar Face Authentication. Explanation 3: The ARC shall ensure that the use of Aadhaar, proof of possession of Aadhaar etc., is in accordance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies Benefits and Services) Act, 2016 and the regulations made thereunder. Explanation 4: Aadhaar number is not mandatory for purposes of KYC. However, in case the customer is desirous of receiving any benefit or subsidy under any scheme notified under section 7 of the Aadhaar (Targeted Delivery of Financial and Other subsidies, Benefits and Services) Act, 2016 (18 of 2016), the customer shall provide the Aadhaar number to the ARC. In other cases, customers may provide the Aadhaar number voluntarily. 23. Digital KYC Process: (1) The ARC shall develop an application for digital KYC process and make it available at customer touch points for undertaking KYC of its customers and shall undertake the KYC process only through this authenticated application. (2) The ARC shall control the access to the Application and shall ensure that unauthorised persons do not use it. Authorised officials shall access the Application only through a login-id and password or a Live OTP or Time OTP controlled mechanism that the ARC provides. (3) The customer, for the purpose of KYC, shall visit the location of the authorised official of the ARC or vice-versa. The original OVD shall be in possession of the customer. (4) The ARC shall ensure that the authorised officer takes a Live photograph of the customer and embeds the same photograph in the Customer Application Form (CAF). Further, the ARC’s system Application shall put a watermark in readable form, containing the CAF number, GPS coordinates, authorised official’s name, unique employee code (which the ARC assigns) and date (DD:MM:YYYY) and time stamp (HH:MM:SS), on the captured live photograph of the customer. (5) The ARC’s Application shall have the feature that it captures only a live photograph of the customer and does not capture any printed or video graphed photograph. The background behind the customer while capturing live photograph shall be of white colour and no other person shall come into the frame while capturing the live photograph of the customer. (6) Similarly, the authorised officer shall capture the live photograph of the original OVD or proof of possession of Aadhaar where offline verification cannot be carried out (placed horizontally), vertically from above and shall apply a water-marking in readable form as mentioned above. The authorised officer shall ensure there is no skew or tilt in the mobile device while capturing the live photograph of the original documents. (7) The authorised officer shall capture the live photograph of the customer and his original documents in proper light so that they are clearly readable and identifiable. (8) Thereafter, the authorised officer shall fill all the entries in the CAF as per the documents and information furnished by the customer. In those documents where Quick Response (QR) code is available, such details may be auto-populated by scanning the QR code instead of manual filing the details. For example, in case of physical Aadhaar / e-Aadhaar downloaded from UIDAI where QR code is available, the details like name, gender, date of birth and address may be auto-populated by scanning the QR available on Aadhaar / e-Aadhaar. (9) Once the above-mentioned process is completed, a One Time Password (OTP) message containing the text that ‘Please verify the details filled in form before sharing OTP’ shall be sent to customer’s own mobile number. Upon successful validation of the OTP, the ARC will treat it as the customer’s signature on CAF. However, if the customer does not have their own mobile number, the ARC may use the mobile number of their family / relatives / known persons for this purpose and clearly mention it in the CAF. In any case, the ARC shall not use the mobile number of authorised officer registered with the ARC for the customer signature. The ARC shall check that the mobile number used in customer signature is not the mobile number of the authorised officer. (10) The authorised officer shall provide a declaration about the capturing of the live photograph of the customer and original document. For this purpose, the ARC shall verify the authorised officer with One Time Password (OTP) which will be sent to his mobile number registered with the ARC. Upon successful OTP validation, the ARC shall treat it as the authorised officer’s signature on the declaration. The live photograph of the authorised officer shall also be captured in this authorised officer’s declaration. (11) Subsequent to all these activities, the Application shall give information about the completion of the process and submission of activation request to activation officer of the ARC, and also generate the transaction-id / reference-id number of the process. The authorised officer shall intimate the details regarding transaction-id / reference-id number to the customer for future reference. (12) The authorised officer of the ARC shall check and verify that: (i) information available in the picture of the document matches with the information entered by authorised officer in CAF. (ii) live photograph of the customer matches with the photo available in the document.; and (iii) the authorised officer has properly filled all of the necessary details in CAF, including mandatory field. (13) On Successful verification, the CAF shall be digitally signed by authorised officer of the ARC who will take a print of CAF, get signatures / thumb-impression of customer at appropriate place, then scan and upload the same in system. Original hard copy may be returned to the customer. 24. Accounts opened using Aadhaar OTP based e-KYC, in non-face-to-face mode, are subject to the following conditions: (1) The Customer shall give specific consent for the authentication through OTP. (2) As a risk-mitigating measure for such accounts, the ARC shall ensure that it sends transaction alerts, OTP, etc., only to the mobile number of the customer registered with Aadhaar. The ARC shall have a Board-approved policy delineating a robust process of due diligence for dealing with requests for change of mobile number in such accounts. (3) The ARC shall obtain declaration from the customer to the effect that no other account has been opened nor will be opened using OTP based KYC in non-face-to-face mode with any other RE. Further, while uploading KYC information to CKYCR, ARC shall clearly indicate that such accounts are opened using OTP based e-KYC and other REs shall not open accounts based on the KYC information of accounts opened with OTP based e-KYC procedure in non-face- to-face mode. (4) The ARC shall have strict monitoring procedures including systems to generate alerts in case of any non-compliance / violation, to ensure compliance with the above-mentioned conditions. 25. The ARC may undertake V-CIP to carry out: (1) CDD in case of new customer on-boarding for individual customers, proprietor in case of proprietorship firm, authorised signatories and Beneficial Owners (BOs) in case of Legal Entity (LE) customers. Provided that in case of CDD of a proprietorship firm, the ARC shall also obtain the equivalent e-document of the activity proofs with respect to the proprietorship firm, as mentioned in paragraph 28 and paragraph 29, apart from undertaking CDD of the proprietor. (2) Conversion of existing accounts opened in non-face-to-face mode using Aadhaar OTP based e-KYC authentication as per paragraph 24. (3) Updation / Periodic updation of KYC for eligible customers. 26. The ARC opting to undertake V-CIP, shall adhere to the following minimum standards: (1) V-CIP Infrastructure (i) The ARC shall have complied with the RBI guidelines on minimum baseline cyber security and resilience framework for ARCs, as updated from time to time as well as other general guidelines on IT risks. The ARC shall house the technology infrastructure in its own premises and the V-CIP connection and interaction shall necessarily originate from its own secured network domain. Any technology related outsourcing for the process shall comply with relevant RBI guidelines. Where the ARC uses a cloud deployment model, it shall ensure that ownership of data in such model rests with the ARC only and all the data including video recording is transferred to the ARC’s exclusively owned / leased server(s) including cloud server, if any, immediately after the V-CIP process is completed and the cloud service provider or third-party technology provider assisting the V-CIP shall retain no data. (ii) The ARC shall ensure end-to-end encryption of data between customer device and the hosting point of the V-CIP application, as per appropriate encryption standards. The ARC shall record the customer consent in an auditable and alteration-proof manner. (iii) The V-CIP infrastructure / application shall be capable of preventing connection from IP addresses outside India or from spoofed IP addresses. (iv) The video recordings shall contain the live GPS co-ordinates (geo-tagging) of the customer undertaking the V-CIP and date and time stamp. The quality of the live video in the V-CIP shall be adequate to allow identification of the customer beyond doubt. (v) The application shall have components with face liveness / spoof detection as well as face matching technology with high degree of accuracy, even though the ultimate responsibility of any customer identification rests with the ARC. Explanation: Making specific facial gestures, like blinking of eyes, smiling, frowning, etc. is not mandatory for liveness check. The ARC shall take due cognizance of special needs, if any, of the customer during liveness check. (vi) The ARC may use appropriate artificial intelligence (AI) technology to ensure that the V-CIP is robust. (vii) Based on experience of detected / attempted / ‘near-miss’ cases of forged identity, the ARC shall regularly update the technology infrastructure including application software as well as workflows. The ARC shall report any detected case of forged identity through V-CIP as a cyber event under extant regulatory guidelines. (viii) The ARC shall subject the V-CIP infrastructure to necessary tests such as Vulnerability Assessment, Penetration testing and a Security Audit to ensure its robustness and end-to-end encryption capabilities. The ARC shall mitigate any critical gap reported under this process before rolling out its implementation. The empaneled auditors of Indian Computer Emergency Response Team (CERT-In) shall conduct such tests. Such tests shall also be carried out periodically in conformance to internal / regulatory guidelines. (ix) The ARC shall subject the V-CIP application software and relevant APIs / webservices to appropriate testing of functional, performance, and maintenance strength before being used in live environment. The ARC shall roll out the application only after closure of any critical gap found during such tests. Such tests shall also be carried out periodically in conformity with internal / regulatory guidelines. (2) V-CIP Procedure (i) Each ARC shall formulate a clear workflow and standard operating procedure for V-CIP and ensure adherence to it. The V-CIP process shall be operated only by officials of the ARC specially trained for this purpose. The official shall be capable to carry out liveness check and detect any other fraudulent manipulation or suspicious conduct of the customer and act upon it. The liveness check shall not result in exclusion of person with special needs. (ii) Disruption of any sort including pausing of video, reconnecting calls, etc., may not result in creation of multiple video files. If pause or disruption is not leading to the creation of multiple files, then the ARC may not initiate a fresh session. However, in case of call drop / disconnection, fresh session shall be initiated. (iii) The ARC shall vary the sequence and / or type of questions, including those indicating the liveness of the interaction, during video interactions to establish that the interactions are real-time and not pre-recorded. (iv) The ARC shall reject the account opening process if it observes any prompting at the customer end. (v) The ARC shall factor in the fact that the V-CIP customer is an existing or new customer, or if the case relates to one rejected earlier or if the name appears in some negative list, at an appropriate stage of workflow. (vi) The authorised official of the ARC performing the V-CIP shall record audio and video as well as capture a photograph of the customer present for identification and obtain the identification information using any one of the following: (a) OTP based Aadhaar e-KYC authentication. (b) Offline Verification of Aadhaar for identification. (c) KYC records downloaded from CKYCR, in accordance with paragraph 59, using the KYC identifier provided by the customer. (d) Equivalent e-document of Officially Valid Documents (OVDs) including documents issued through DigiLocker. (vii) The ARC shall ensure to redact or blackout the Aadhaar number in terms of paragraph 22. (viii) In case of o2ffline verification of Aadhaar using XML file or Aadhaar Secure QR Code, the ARC shall ensure that the XML file or QR code generation date is not older than three working days from the date of carrying out V-CIP. (ix) Further, in line with the prescribed period of three working days for usage of Aadhaar XML file / Aadhaar QR code, the ARC shall ensure that it undertakes video process of the V-CIP within three working days of downloading / obtaining the identification information through CKYCR / Aadhaar authentication / equivalent e-document, if in the rare cases, the entire process cannot be completed at one go or seamlessly. However, the ARC shall ensure that no incremental risk is added due to this. (x) If the address of the customer is different from that indicated in the OVD, the ARC shall capture suitable records of the current address, as per the existing requirement. The ARC shall ensure that it also confirms the economic and financial profile / information submitted by the customer from the customer undertaking the V-CIP in a suitable manner. (xi) The ARC shall capture a clear image of PAN card displayed by the customer during the process, except in cases where e-PAN is provided by the customer. The ARC shall verify the PAN details from the database of the issuing authority ,including through DigiLocker. (xii) The use of printed copy of equivalent e-document, including an e-PAN is not valid for the V-CIP. (xiii) The authorised official of the ARC shall ensure that photograph of the customer in the Aadhaar / OVD and PAN / e-PAN matches with the customer undertaking the V-CIP and the identification details in Aadhaar / OVD and PAN / e-PAN shall match with the details provided by the customer. (xiv) The ARC shall make all accounts opened through V-CIP operational only after subjecting them to concurrent audit to ensure the integrity of process and its acceptability of its outcome. (xv) The ARC shall appropriately comply with all matters not specified under the paragraph but required under other statutes such as the Information Technology (IT) Act. (3) V-CIP Records and Data Management (i) The ARC shall store the entire data and recordings of V-CIP in a system / systems located in India. The ARC shall ensure that the video recording is stored in a safe and secure manner and bears the date and time stamp that affords easy historical data search. The extant instructions on record management, as stipulated in this direction, shall also apply to V-CIP. (ii) The ARC shall preserve the activity log along with the credentials of the official performing the V-CIP. 27. KYC verification once done by one branch / office of the ARC shall be valid for transfer of the account to any other branch / office of the same ARC, provided the ARC has already completed the full KYC verification for the concerned account and the same is not due for periodic updation. B. CDD Measures for Sole Proprietary firms 28. For opening an account in the name of a sole proprietary firm, the ARC shall carry out the CDD of the individual (proprietor). 29. In addition to the above, the ARC shall also obtain any two of the following documents or the equivalent e-documentsc thereof as proof of business / activity in the name of the proprietary firm: (1) Registration certificate including Udyam Registration Certificate (URC) issued by the Government. (2) Certificate / licence issued by the municipal authorities under Shop and Establishment Act (3) Sales and income tax returns (4) CST / VAT / GST certificate (5) Certificate / registration document issued by Sales Tax / Service Tax / Professional Tax authorities (6) IEC (Importer Exporter Code) issued to the proprietary concern by the office of DGFT or Licence / certificate of practice issued in the name of the proprietary concern by any professional body incorporated under a statute (7) Complete Income Tax Return (not just the acknowledgement) in the name of the sole proprietor where the firm's income is reflected, duly authenticated / acknowledged by the Income Tax authorities (8) Utility bills such as electricity, water, landline telephone bills, etc. 30. In cases where the ARC is satisfied that it is not possible to furnish two such documents, the ARC may, at its discretion, accept only one of those documents as proof of business / activity. Provided that the ARC undertakes contact point verification and collects such other information and clarifications as would be required to establish the existence of such firm, and shall confirm and satisfy itself that it has verified the business activity from the address of the proprietary concern. C. CDD Measures for Legal Entities 31. For opening an account of a company, the ARC shall obtain certified copies of each of the following documents or the equivalent e-documents thereof: (1) Certificate of incorporation (2) Memorandum and Articles of Association (3) PAN of the company (4) A resolution from the Board of Directors and power of attorney granted to its managers, officers or employees to transact on its behalf (5) Documents, as specified in paragraph 22, relating to beneficial owner, managers, officers or employees, as the case may be, holding an attorney to transact on the company’s behalf (6) The names of the relevant persons holding a senior management position; and (7) The registered office and the principal place of its business, if it is different. 32. For opening an account of a partnership firm, the ARC shall obtain the certified copies of each of the following documents or the equivalent e-documents thereof: (1) Registration certificate (2) Partnership deed (3) PAN of the partnership firm (4) Documents, as specified in paragraph 22, relating to beneficial owner, managers, officers or employees, as the case may be, holding an attorney to transact on its behalf (5) the names of all the partners and (6) address of the registered office, and the principal place of its business, if it is different. 33. For opening an account of a trust, the ARC shall obtain the certified copies of each of the following documents or the equivalent e-documents thereof: (1) Registration certificate (2) Trust deed (3) PAN or Form No.60 of the trust (4) Documents, as specified in paragraph 22, relating to beneficial owner, managers, officers or employees, as the case may be, holding an attorney to transact on its beha
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/DOR/2025-26/377 · issued 28 Nov 2025. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
⚙️ Operations
  • Ensure record-keeping systems can retain customer identification data and transaction records as per the prescribed timelines.
📜 Compliance
  • Review and update your ARC's KYC policy to align with these directions, covering customer acceptance, risk management, and CDD procedures.
  • Train staff on the new requirements, including Aadhaar authentication and reporting obligations to FIU-IND.
  • Coordinate with your legal and compliance teams to map existing processes against the detailed chapters in the direction.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All Asset Reconstruction Companies (ARCs), Banks and financial institutions that transact with ARCs, Compliance and AML teams within ARCs and partner banks), your first concrete step on “RBI KYC Directions for Asset Reconstruction Companies, 2025” is: “Review and update your ARC's KYC policy to align with these directions, covering customer acceptance, risk management, and CDD procedures.” (RBI issued this 28 Nov 2025).

  1. Circular: RBI/DOR/2025-26/377 -- RBI KYC Directions for Asset Reconstruction Companies, 2025
  2. Issued: 28 Nov 2025
  3. Action required: Review and update your ARC's KYC policy to align with these directions, covering customer acceptance, risk management, and CDD procedures.
  4. Action required: Train staff on the new requirements, including Aadhaar authentication and reporting obligations to FIU-IND.
  5. Action required: Ensure record-keeping systems can retain customer identification data and transaction records as per the prescribed timelines.
  6. Action required: Coordinate with your legal and compliance teams to map existing processes against the detailed chapters in the direction.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12927&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗