Skip to content
BankPulseBETARegulatory intelligence for Indian banking
Directions · Reserve Bank of India

Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Directions, 2025

UR

The four dates on this rule

At a glanceThe rules rest on the Prevention of Money-Laundering Act, 2002 and its 2005 Rules. These Directions apply to every non-banking financial company. An account opened by Aadhaar one-time password cannot run past one year without full checks.

Official RBI page

Numbers to remember

ten per centFor a company, holding more than ten per cent is one test of beneficial ownership. RBI Para 5(1)
fifteen per centIn an unincorporated body the same test is more than fifteen per cent. RBI Para 5(1)
₹50,000A one-off transaction of ₹50,000 or more brings the full identification duty. RBI Para 5(2)
one lakh rupeesIn an Aadhaar one-time password account the total balance cannot cross one lakh rupees. RBI Para 25(3)
two lakh rupeesCredits into those accounts in a financial year cannot cross two lakh rupees. RBI Para 25(4)
one yearAn account opened by Aadhaar one-time password cannot run past one year without full checks. RBI Para 25(6)
six monthsCustomer risk categories must be reviewed at least once in every six months. RBI Para 41(1)
two yearsPapers of a high-risk customer must be refreshed at least once in two years. RBI Para 42(1)
eight yearsFor a medium-risk customer the gap may be eight years. RBI Para 42(1)
ten yearsFor a low-risk customer the gap may be ten years. RBI Para 42(1)
30 daysA change in a customer's papers must reach the bank's records within 30 days. RBI Para 42(6)
five yearsTransaction records must be kept for at least five years from the date of the transaction. RBI Para 47(1)
ten daysA new customer's KYC record goes to the central registry within ten days. RBI Para 63(1)
seven daysUpdated customer information must reach the central registry within seven days. RBI Para 63(10)

What it says

Opening paragraphs

1. The law behind it

The rules rest on the Prevention of Money-Laundering Act, 2002 and its 2005 Rules.

Chapter I. Preliminary

Must know

1. Ten per cent, a company

For a company, holding more than ten per cent is one test of beneficial ownership.

2. Fifteen per cent, a body

In an unincorporated body the same test is more than fifteen per cent.

3. Fifty thousand triggers checks

A one-off transaction of ₹50,000 or more brings the full identification duty.

Do it

4. Designated Director named

The Board must name a Designated Director who answers for compliance under the Act.

Background

5. KYC rules for NBFCs

This document sets the customer identification rules for non-banking financial companies.

6. Who is covered

These Directions apply to every non-banking financial company.

7. Control counts as well

A person who controls the entity by other means is a beneficial owner too.

8. Then the senior official

Where no natural person can be found, the senior managing official is named.

9. Split payments still count

Several linked payments are read together, so splitting a sum does not avoid it.

10. What a remote customer is

A remote customer is one who opens an account without meeting the NBFC at all.

11. What a shell bank is

A shell bank has no physical presence where it is licensed and no real group behind it.

12. Video equals a meeting

A video call that follows the rules counts the same as meeting in person.

Chapter II. General

Must know

1. Never tip off a customer

Group information sharing must be built so that nobody is tipped off.

2. The decision stays inside

Whether KYC has been met is a decision the NBFC cannot outsource to anyone.

3. Director reported to FIU-IND

The name and contact details of that Director must go to FIU-IND and RBI.

Do it

4. Four parts to the policy

The policy must cover acceptance, risk management, identification and monitoring.

Background

5. Quarterly note to the committee

An audit note and compliance go to the Audit Committee every quarter.

6. Principal Officer duties

The Principal Officer watches transactions and reports what the law requires.

Chapter III. Customer Acceptance Policy

1. No anonymous accounts

No account may be opened in an anonymous, fictitious or benami name.

2. No account without checks

Where customer due diligence cannot be done, the account is not opened at all.

Chapter V. Customer Identification Procedure (CIP)

1. Walk-in customers too

A walk-in customer paying ₹50,000 or more must be identified in the same way.

Chapter VI. Customer Due Diligence (CDD) Procedure

Must know

1. OTP account balance limit

In an Aadhaar one-time password account the total balance cannot cross one lakh rupees.

2. Two lakh a year

Credits into those accounts in a financial year cannot cross two lakh rupees.

3. OTP account, one year

An account opened by Aadhaar one-time password cannot run past one year without full checks.

4. Questions must change

The officer must change the questions so the video cannot be a recording.

5. Printed e-PAN not valid

A printed copy of an electronic document, such as an e-PAN, cannot be used.

6. Risk reviewed twice a year

Customer risk categories must be reviewed at least once in every six months.

7. High risk, two years

Papers of a high-risk customer must be refreshed at least once in two years.

BankPulse example. Suppose a high-risk customer's papers were refreshed today. They must be refreshed again within two years. For a medium-risk customer the same papers would last eight years. For low risk they would last 10 years.

8. Medium risk, eight years

For a medium-risk customer the gap may be eight years.

9. Low risk, ten years

For a low-risk customer the gap may be ten years.

10. Thirty days to update

A change in a customer's papers must reach the bank's records within 30 days.

11. No second mobile number

A second mobile number cannot be linked to such an account for one-time passwords.

Do it

12. Live location in video

The video must carry the customer's live location, with the date and time.

13. Three warnings before

At least three advance intimations must go out before KYC falls due, one by letter.

14. Three reminders after

At least three reminders must follow, again including one by letter.

15. Notice before stopping account

Before it temporarily stops an account for a missing PAN, the NBFC must give notice.

16. First credit from own bank

The first money into such an account must come from the customer's checked account.

17. Find the source of funds

For a politically exposed person the source of funds and wealth must be established.

18. Senior approval for PEPs

If a customer becomes a politically exposed person, senior management must approve keeping the account.

Background

19. Only term loans there

In such an account only a term loan may be sanctioned, within a set ceiling.

20. Audit before account opens

An account opened by video call starts working only after an audit clears it.

21. Only credits on loans

When a loan account is stopped, only credits into it are allowed.

22. Watched until met in person

Such an account stays under closer watch until the customer is seen or verified by video.

23. Politically exposed persons

A relationship with a politically exposed person is allowed only on set terms.

24. Senior approval for a PEP

Opening an account for such a person needs senior management approval.

25. Their families are covered

The same duties apply to the family members and close associates of such a person.

Chapter VII. Record Management

1. Records kept five years

Transaction records must be kept for at least five years from the date of the transaction.

2. Identity papers after closure

Customer identity records must be kept for five years after the relationship ends.

3. Charities on DARPAN

A non-profit customer must be registered on the DARPAN portal of NITI Aayog.

Chapter VIII. Reporting Requirements to Financial Intelligence Unit – India

1. Alerts for odd transactions

Software must raise an alert when a transaction does not match the customer's profile.

2. Report does not freeze

Filing a suspicious transaction report is not by itself a reason to stop an account.

Chapter IX. Requirements / obligations under International Agreements - Communications from International Agencies

1. Sanctions list checked daily

The UNSCR 1718 sanctions list must be checked every single day.

2. Duty under the UAPA

The NBFC carries duties under section 51A of the Unlawful Activities Prevention Act.

3. Duty under the WMD Act

Separate duties arise under the Weapons of Mass Destruction Act of 2005.

Chapter X. Other Instructions

Must know

1. Ten days to the registry

A new customer's KYC record goes to the central registry within ten days.

2. Seven days for an update

Updated customer information must reach the central registry within seven days.

3. Money mule accounts

The NBFC must find accounts used as money mules and report them to FIU-IND.

4. Three days for details

Details of a wire transfer must be supplied within three working days of a request.

5. Transfer stopped if unclear

The NBFC must not send the transfer if it cannot meet these rules.

Do it

6. Foreign tax reporting too

The rules on foreign account tax reporting must be followed alongside these.

7. Training differs by role

Training must differ for counter staff, compliance staff and staff opening new accounts.

Background

8. Records sent to CKYCR

Records of company accounts opened on or after 1 April 2021 go to CKYCR.

Chapter XI. Repeal and Other Provisions

1. Approvals carried over

Approvals given under the cancelled rules are now treated as given under these rules.

2. Other laws still apply

These Directions add to other laws. They do not replace any of them.

What RBI has fined people for under this rulebook

RBI has imposed 15 monetary penalties on this kind of lender. In each one its own stated reason names the subject of this rulebook. The 12 most recent are listed here. Each one links to the press release it was read from.

This tells you the rulebook RBI named. It does not tell you which of the points on this page was broken, because RBI does not say. Read the order itself before drawing any conclusion about your own bank.

These come from RBI press releases. The penalty tracker holds them all. It also lists the penalties we could not place on any rulebook, and the reason for each one.

How this rule has changed

The points above are the rule as it stands today, after every change listed here.

  1. Issued on November 28, 2025. This is the date RBI put the rule out.

  2. Changed on Dec 29, 2025. Takes effect Immediate effect (date of the amendment)..

    • directions start date. These amendment directions take effect at once from the issue date.
    • other cdd duties stay. The NBFC must still meet all other customer due diligence duties in these directions.

The same subject for other kinds of institution

The same subject for other kinds of institution.

Other RBI rules for NBFCs

Every rule page on BankPulse  ·  Questions bankers ask, answered