KYC & CKYCR
Compliance

What the RBI Know Your Customer Directions, 2025 require, who they apply to, and what RBI has actually penalised banks and NBFCs for, from missed CKYCR uploads to V-CIP gaps, in plain language, linked to the source.

Entity-class KYC Directions · 28 Nov 2025 Banks · NBFCs · Co-ops · RRBs · AIFIs Last reviewed: Jun 2026
At a glance
InstrumentKYC Directions, 2025one per entity class
Issued / in force28 Nov 2025
Replaces2016 KYC Master Directionconsolidated "as is"
Risk reviewEvery 6 monthsrisk categorisation
Re-KYC cadence2 / 8 / 10 yrshigh / medium / low risk
FY25-26 actions here4banks & NBFCs (illustrative)
What the rule requires

KYC & CKYCR, in plain terms

Know who your customer is when you onboard them, keep that knowledge current for as long as the relationship lasts, and file it with the Central KYC Records Registry so the system as a whole can rely on it.

What it is

A lifecycle obligation, not an onboarding form

The KYC framework runs on a Board-approved policy built on four elements: a Customer Acceptance Policy, Risk Management, Customer Identification Procedures and Monitoring of Transactions. Identity is verified at onboarding (in person, via Aadhaar e-KYC, or by video through V-CIP), every customer is risk-categorised, the categorisation is re-reviewed on a six-month cycle, KYC is periodically refreshed on a risk-based cadence, and records are filed with the CKYCR. Most penalties land where one of these recurring loops quietly stops running.

Does this apply to you?

Applicability, by entity class

  • Commercial banks (including SBI and corresponding new banks) under their own 2025 KYC Directions. SFBs, Payments Banks and Local Area Banks are carved out into their own directions.
  • NBFCs across all layers, except NBFCs with no customer interface.
  • RRBs, urban and rural co-operative banks, and All India Financial Institutions, each under their own 2025 KYC Directions.
  • Foreign branches and majority-owned overseas subsidiaries, subject to host-country law.
The single 2016 KYC Master Direction was superseded on 28 Nov 2025 by these entity-class Directions, part of RBI consolidating its rulebook into 238 Master Directions. The consolidation was on an "as is" basis, so the underlying obligations carried over.
Core obligations
Policy

Board-approved KYC policy

A KYC policy approved by the Board (or a committee it delegates to), built on the four key elements: Customer Acceptance Policy, Risk Management, Customer Identification Procedures and Monitoring of Transactions.

Risk review

Re-categorise every six months

Risk categorisation of accounts must be reviewed at least once in every six months, the exact obligation an NBFC was penalised for missing in FY25-26.

Re-KYC

Periodic updation: 2 / 8 / 10 years

KYC must be refreshed at least once every two years for high-risk, eight years for medium-risk and ten years for low-risk customers, measured from opening or the last updation.

CKYCR

File records with the registry

Customers' KYC records must be uploaded to the Central KYC Records Registry within the prescribed timeline and kept current, missed uploads drew a penalty this year.

V-CIP

Video KYC that actually verifies

Video-based Customer Identification must run on tech with face liveness / spoof detection and accurate face matching, and the institution must confirm the customer's economic and financial profile, not just sight their documents.

Beneficial owners

Look through non-individual customers

Where the customer is a company, firm or trust, the institution must identify the beneficial owner(s) and take all reasonable steps to verify their identity.

Paragraph references are to the Commercial Banks Directions, 2025; each entity class's own 2025 KYC Directions carry the corresponding provisions.
What RBI has penalised

The pattern across FY25-26

4 of the FY25-26 actions in our tracker cite KYC failures, and none of them are comprehension gaps. A registry upload that didn't happen on time, beneficial owners never identified, a six-month review cycle that stopped running, video KYC missing its required face-matching component, the obligation was known; the operational loop behind it broke. The actions below are drawn from the FACE compilation of RBI press releases.

Each entry states only the reason cited in the RBI press release. Where a penalty covered more than one issue, the amount shown is the total and is not attributable to any single reason.

Bank · Public27 Mar 2026
Central Bank of India
₹63.6 Ltotal penalty
Cited reason (KYC-related)
Did not upload the KYC records of certain customers onto the Central KYC Records Registry within the prescribed timeline.
Multiple reasons
Bank · Public13 Feb 2026
Bank of Maharashtra
₹32.5 Ltotal penalty
Cited reason (KYC-related)
Did not identify Beneficial Owners in certain accounts.
Multiple reasons
Bank · Private05 Dec 2025
Jammu & Kashmir Bank Ltd
₹99.3 Ltotal penalty
Cited reason (KYC-related)
Did not have face-matching technology in the Video-based Customer Identification Process and did not confirm the customer's economic/financial profile during V-CIP.
Multiple reasons

Showing 3 of 4 KYC-related actions, see all of them in the enforcement tracker.

Where the failures actually happen

Understanding the rule is step one.
Operationalising it is where penalties occur.

Every cited failure above is a procedure that existed on paper and broke in a branch, a back office, or a system handover. Here's an honest split of what a policy distribution-and-attestation layer like PolicyCentral does and does not address.

PolicyCentral helps here

Distribute · attest · prove

The "did everyone get it, read it, and can you show an auditor" layer around your KYC framework.

  • Push the Board-approved KYC policy and its operating procedures, CKYCR upload SOPs, V-CIP scripts, re-KYC campaign playbooks, to every relevant staff member in every branch, with read receipts and digital acknowledgement.
  • When the rulebook changes, as it did wholesale on 28 Nov 2025, version the policy, re-push to affected staff, and chase the unread automatically.
  • Distribute KYC/AML refresher material as trackable training content, with completion visible per branch and per role.
  • Maintain a tamper-evident audit trail of who received, read and acknowledged each version, the evidence a supervisory review asks for first.
A different system handles this

What PolicyCentral is not

We're explicit about scope, these are jobs for your KYC/AML stack, not a policy platform.

  • The customer identification stack itself, Aadhaar e-KYC, V-CIP video infrastructure, face-matching and liveness technology.
  • CKYCR upload integrations and registry reconciliation.
  • Customer risk-scoring engines, transaction monitoring and AML screening systems.

Being clear about this is the point, sophisticated compliance teams trust a vendor that names its boundaries.

Go deeper
For compliance & risk teams

Get the KYC policy & dissemination checklist

A practical checklist covering what your Board-approved KYC policy should contain under the 2025 Directions, which procedures every branch must hold and acknowledge, and the audit-trail evidence to keep ready for a supervisory review.

Request the checklist
For CCOs, HR & InfoSec leaders

See KYC procedure attestation tracked across every branch

PolicyCentral shows you, live and branch-by-branch, exactly who has read and acknowledged each KYC procedure and every update, with a tamper-evident trail you can export for an RBI review. Walk through it on your own data.

Book a walkthrough
PolicyCentral.ai builds policy management software, not legal advice. These are plain-language summaries to help your teams understand what applies to them. Always verify against the original instrument on rbi.org.in and consult your compliance/legal team before acting.
PolicyGPT
AI-powered policy assistant

Hi! I'm PolicyGPT. Ask me anything about PolicyCentral.ai — features, security, compliance, pricing, or hosting.