What the RBI Know Your Customer Directions, 2025 require, who they apply to, and what RBI has actually penalised banks and NBFCs for, from missed CKYCR uploads to V-CIP gaps, in plain language, linked to the source.
Know who your customer is when you onboard them, keep that knowledge current for as long as the relationship lasts, and file it with the Central KYC Records Registry so the system as a whole can rely on it.
The KYC framework runs on a Board-approved policy built on four elements: a Customer Acceptance Policy, Risk Management, Customer Identification Procedures and Monitoring of Transactions. Identity is verified at onboarding (in person, via Aadhaar e-KYC, or by video through V-CIP), every customer is risk-categorised, the categorisation is re-reviewed on a six-month cycle, KYC is periodically refreshed on a risk-based cadence, and records are filed with the CKYCR. Most penalties land where one of these recurring loops quietly stops running.
A KYC policy approved by the Board (or a committee it delegates to), built on the four key elements: Customer Acceptance Policy, Risk Management, Customer Identification Procedures and Monitoring of Transactions.
Risk categorisation of accounts must be reviewed at least once in every six months, the exact obligation an NBFC was penalised for missing in FY25-26.
KYC must be refreshed at least once every two years for high-risk, eight years for medium-risk and ten years for low-risk customers, measured from opening or the last updation.
Customers' KYC records must be uploaded to the Central KYC Records Registry within the prescribed timeline and kept current, missed uploads drew a penalty this year.
Video-based Customer Identification must run on tech with face liveness / spoof detection and accurate face matching, and the institution must confirm the customer's economic and financial profile, not just sight their documents.
Where the customer is a company, firm or trust, the institution must identify the beneficial owner(s) and take all reasonable steps to verify their identity.
4 of the FY25-26 actions in our tracker cite KYC failures, and none of them are comprehension gaps. A registry upload that didn't happen on time, beneficial owners never identified, a six-month review cycle that stopped running, video KYC missing its required face-matching component, the obligation was known; the operational loop behind it broke. The actions below are drawn from the FACE compilation of RBI press releases.
Each entry states only the reason cited in the RBI press release. Where a penalty covered more than one issue, the amount shown is the total and is not attributable to any single reason.
Showing 3 of 4 KYC-related actions, see all of them in the enforcement tracker.
Every cited failure above is a procedure that existed on paper and broke in a branch, a back office, or a system handover. Here's an honest split of what a policy distribution-and-attestation layer like PolicyCentral does and does not address.
The "did everyone get it, read it, and can you show an auditor" layer around your KYC framework.
We're explicit about scope, these are jobs for your KYC/AML stack, not a policy platform.
Being clear about this is the point, sophisticated compliance teams trust a vendor that names its boundaries.
A practical checklist covering what your Board-approved KYC policy should contain under the 2025 Directions, which procedures every branch must hold and acknowledge, and the audit-trail evidence to keep ready for a supervisory review.
Request the checklistPolicyCentral shows you, live and branch-by-branch, exactly who has read and acknowledged each KYC procedure and every update, with a tamper-evident trail you can export for an RBI review. Walk through it on your own data.
Book a walkthrough