Every time you walk into a bank to open an account, you are asked for your Aadhaar, PAN card, and a recent photograph. This seemingly routine exercise is part of a carefully constructed legal framework designed to keep the financial system clean. Know Your Customer (KYC) norms, as mandated by the Prevention of Money Laundering Act, 2002 (PMLA) and enforced through guidelines issued by the Reserve Bank of India (RBI), form the first and most critical line of defence against money laundering in India. For cooperative banks especially, understanding these norms is not just a compliance obligation – it is a responsibility toward the integrity of the financial system.
Table of Contents
- What is KYC and why does it matter?
- The legal framework: PMLA and RBI’s role
- Core components of KYC compliance
- Customer acceptance policy
- Customer identification procedure
- Risk-based approach and customer categorisation
- Customer due diligence and enhanced due diligence
- The Unique Customer Identification Code (UCIC) and Central KYC Records Registry
- Ongoing transaction monitoring and suspicious transaction reporting
- Record-keeping obligations
- KYC challenges for cooperative banks
- The evolving KYC landscape: 2024-2025 updates
What is KYC and why does it matter?
KYC is the process by which banks and other financial institutions verify the identity and address of their customers before providing any financial service. The objective is straightforward: ensure that no financial institution unknowingly facilitates money laundering, terrorist financing, or other financial crimes by dealing with anonymous or fictitious customers.
Under India’s regulatory framework, KYC serves as the gateway to a broader set of Anti-Money Laundering (AML) checks. It allows institutions to establish the identity of a customer, understand the nature of their financial activities, and detect any transactions that deviate from expected behaviour. The PMLA, 2002, lays the legal foundation, while the RBI’s Master Direction on KYC – originally issued on February 25, 2016 – provides the operational blueprint for regulated entities (REs) such as banks, NBFCs, and cooperative banks.
Penalties for non-compliance are serious. Under the PMLA, individuals convicted of money laundering face imprisonment ranging from three to seven years, with harsher sentences where specific offences under the Narcotic Drugs and Psychotropic Substances Act are involved. Institutions that fail to maintain KYC compliance face significant regulatory penalties – RBL Bank, for instance, was fined ₹61.40 lakh in November 2024 for failing to adhere to prescribed KYC procedures.
The legal framework: PMLA and RBI’s role
The PMLA, 2002 is the primary legislation governing anti-money laundering obligations in India. Chapter IV of the Act, read with the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, places specific duties on “reporting entities” – a category that includes banks, financial institutions, and intermediaries – to conduct customer due diligence, maintain records, and report suspicious transactions.
The RBI operates as the regulator for the banking and credit sector and gives effect to the PMLA’s requirements through its Master Direction on KYC. These guidelines are issued under Section 35A of the Banking Regulation Act, 1949, and Rule 9(14) of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 – and non-compliance attracts penalties under the Banking Regulation Act. Importantly, these guidelines apply not just to commercial banks but also to cooperative banks, NBFCs, and local area banks.
In a significant development, the RBI issued 10 new sector-specific KYC Master Directions on November 28, 2025, replacing the 2016 Master Direction. These new directions cover 10 categories of institutions separately, including commercial banks, NBFCs, payment banks, and cooperative banks – bringing greater specificity and clarity to KYC compliance obligations for each type of institution.
Core components of KYC compliance
Customer acceptance policy
Every regulated entity must have a board-approved Customer Acceptance Policy (CAP). This policy sets out the conditions under which an institution will – and will not – enter into a banking relationship. Under this policy, no account can be opened in an anonymous, fictitious, or benami name, and no account can be opened where the bank is unable to apply appropriate Customer Due Diligence (CDD) measures due to non-cooperation from the customer or unreliable documents.
Customer identification procedure
This is the core of KYC. Customers must provide identity documents – Aadhaar, PAN card, passport, or voter ID – along with proof of address such as utility bills or bank statements, and a recent photograph. For legal entities, the bank must verify the entity’s legal status, confirm that signatories are authorised, and identify ultimate beneficial owners.
India also offers an electronic KYC (eKYC) route. Powered by the Unique Identification Authority of India (UIDAI), eKYC allows institutions to verify customer details digitally using an Aadhaar number and biometric or OTP-based consent – making the process faster, paperless, and more accessible for customers in rural areas.
Risk-based approach and customer categorisation
Not every customer poses the same risk. The RBI’s guidelines adopt a risk-based approach, categorising customers as low, medium, or high risk based on factors such as their profile, geographical location, type of business, and transaction patterns. Under the updated framework, high-risk customers require KYC updates at least once every two years, medium-risk customers once every eight years, and low-risk customers once every ten years.
A particularly sensitive category is Politically Exposed Persons (PEPs) – individuals who hold or have held prominent public positions. Banks must apply enhanced due diligence for PEPs, establish the source of their funds and wealth, obtain senior management approval before onboarding them, and subject their accounts to continuous heightened monitoring.
Customer due diligence and enhanced due diligence
Customer Due Diligence (CDD) is the structured process of verifying customer information. It covers identity verification, cross-referencing PAN or Form 60 for tax purposes, identifying beneficial owners in case of companies or trusts, and verifying authorised signatories. Under Rule 9(1) of the PML Rules, every reporting entity must conduct due diligence at the commencement of any account-based relationship involving ₹50,000 or more, covering verification of identity, source of funds, the purpose of the transaction, and beneficial ownership.
Enhanced Due Diligence (EDD) applies to high-risk scenarios – large transactions, dealings with PEPs, and connections with high-risk countries. EDD involves a closer review of a customer’s financial history, source of funds, and asset ownership, and is triggered whenever there is a substantial deviation from expected transaction patterns.
The Unique Customer Identification Code (UCIC) and Central KYC Records Registry
A major development in recent years is the introduction of the Unique Customer Identification Code (UCIC). Under an amendment effective November 6, 2024, regulated entities are required to apply Customer Due Diligence at the UCIC level – meaning that if an existing, KYC-compliant customer wants to open another account or avail a new service from the same institution, no fresh CDD procedure is needed. This reduces duplication and simplifies the banking experience.
Complementing the UCIC is the Central KYC Records Registry (CKYCR), a government-authorised entity that stores KYC records in digital form. Regulated entities are required to upload and update KYC data to the CKYCR, and any additional or updated customer information must be furnished to the CKYCR within seven days of receipt. This centralised registry reduces redundancy across financial institutions and supports a unified national approach to KYC compliance.
Ongoing transaction monitoring and suspicious transaction reporting
KYC compliance does not end at account opening. The guidelines mandate continuous monitoring of transactions to ensure they are consistent with the customer’s declared profile, stated purpose, and expected activity patterns. Any substantial deviations must be investigated further.
When a bank identifies a suspicious transaction, it has a clear obligation to report it. Reports must be submitted to the Financial Intelligence Unit – India (FIU-IND) covering cash transactions, suspicious transactions, receipts by non-profit organisations exceeding ₹10 lakh, and cross-border wire transfers exceeding ₹5 lakh. Critically, institutions are prohibited from “tipping off” any customer or entity about the fact that a Suspicious Transaction Report (STR) has been filed – this prohibition applies before, during, and after submission of the STR.
Record-keeping obligations
The PMLA and RBI guidelines impose strict record-keeping obligations on regulated entities. All identification documents secured through CDD measures must be retained for a minimum of five years. This requirement ensures that auditors and law enforcement authorities can reconstruct individual transactions and verify the due diligence conducted. Banks must maintain records not just for account holders but also for walk-in customers who conduct one-time transactions – a requirement that was strengthened through amendments to the KYC Master Direction.
KYC challenges for cooperative banks
While the KYC framework applies uniformly, implementation is more challenging for cooperative banks, particularly smaller ones serving rural and semi-urban populations. Many such banks operate with limited technology infrastructure, making it harder to implement sophisticated monitoring systems or maintain CKYCR-linked digital records. The customer base often includes individuals who lack standard identification documents, requiring the use of simplified KYC procedures with reduced documentation.
The 2024 amendments specifically clarify the requirements around high-risk account monitoring and mandate enhanced vigilance – obligations that require capable software systems and trained personnel. Cooperative banks that adopt a risk-based approach, invest in appropriate technology, and conduct regular staff training on identifying suspicious transactions will be better positioned to meet regulatory expectations without compromising customer service.
The evolving KYC landscape: 2024-2025 updates
The RBI’s November 2024 amendments to the KYC Master Direction aligned the guidelines with the July 2024 gazette notification amending the PML (Maintenance of Records) Rules, 2005, bringing the framework in line with both domestic legal changes and evolving international standards set by the Financial Action Task Force (FATF). The 2025 sector-specific Master Directions go further, providing institution-type specific rules that acknowledge the operational differences between commercial banks, payment banks, and cooperative banks – and introduce protections for differently-abled individuals in digital KYC processes.
Together, these developments reflect a financial system that is continuously tightening its defences against money laundering. For students of business law and for banking professionals, understanding the interplay between the PMLA, 2002 and the RBI’s KYC framework is essential – not just as an academic exercise, but as a foundation for building a financially sound and legally compliant institution.
What do you think? With the rapid shift to digital banking and eKYC, do you think existing KYC regulations are robust enough to prevent newer forms of financial crime like cryptocurrency-based money laundering? And should smaller cooperative banks be given a different compliance timeline compared to large commercial banks when new KYC norms are introduced?
References
- https://fiuindia.gov.in/files/AML_Legislation/notification.html
- https://withpersona.com/blog/kyc-india
- https://elplaw.in/wp-content/uploads/2024/12/Analysis-of-RBI-Norms-on-KYC-Data-Privacy-and-Confidentiality-Obligations-in-Banking.pdf
- https://www.iibf.org.in/documents/kyc-aml-cft-pmla.pdf
- https://www.signzy.com/blogs/RBI-KYC-Master-Directions-2025-key-changes
- https://www.hpscb.bank.in/upload/policies/kyc_policy.pdf
- https://www.sanctionscanner.com/blog/kyc-requirements-in-india-1133
- https://www.goodreturns.in/classroom/rbi-updates-kyc-guidelines-key-changes-and-benefits-for-financial-transactions-details-here-1387417.html
- https://www.rbi.org.in/commonman/Upload/English/Notification/PDFs/98UKY010710_F.pdf
- https://www.lexology.com/library/detail.aspx?g=051102c5-9058-43c8-99c0-9c1def734dc4
- https://www.outlookmoney.com/banking/rbi-amends-kyc-rules-to-align-with-anti-money-laundering-regulations-heres-whats-new
- https://authbridge.com/blog/rbi-amends-kyc-norms-align-with-aml/
- https://thedigitalfifth.com/rbi-overhauls-kyc-norms-for-robust-customer-due-diligence/
- https://fiuindia.gov.in/pdfs/AML_legislation/AMLCFTguidelines10032023.pdf
- https://zcybersecurity.com/key-amendments-changes-by-rbi-to-kyc-guidelines-india/
- https://www.businesstoday.in/personal-finance/banking/story/know-your-customer-rbi-issues-updated-norms-to-align-with-money-laundering-rules-452869-2024-11-07
Leave a Reply