Policy Statement
The Company is committed to complying with the Know Your Customer (KYC) and Customer Due Diligence (CDD) requirements as mandated by the Reserve Bank of India (RBI) and the Prevention of Money Laundering Act (PMLA), 2002. This policy outlines the processes for verifying the identity and address of customers, understanding the nature of their activities, and assessing the risk they may pose to the Company.
Objective
- Prevent the use of the Company's services for money laundering or terrorist financing activities.
- Ensure proper identification and verification of all customers and beneficial owners.
- Implement a risk-based approach to customer due diligence.
- Establish robust systems for monitoring, record keeping, and periodic review of customer data.
Regulatory Framework
- Prevention of Money Laundering Act (PMLA), 2002 and Rules thereunder.
- RBI Master Directions on Know Your Customer (KYC) dated February 25, 2016, and subsequent amendments.
- Financial Intelligence Unit, India (FIU-IND) guidelines.
- FATF recommendations on Customer Due Diligence.
Turn this template into a living policy
Book a 20-minute demo to see how PolicyCentral.ai distributes, translates, and tracks acknowledgement of policies like this across your entire workforce.
Book a DemoScope and Applicability
This policy applies to all customers, counterparties, and beneficial owners engaging with the Company It covers both individuals and legal entities, including vendors, partners, and clients.
KYC Components
- Customer Identification Procedure (CIP): Collecting and verifying identity and address proof of customers using officially valid documents (OVDs) such as Aadhaar, PAN, Passport, etc.
- Customer Due Diligence (CDD): Assessing the customer's background, business activities, and risk category.
- Ongoing Due Diligence: Monitoring transactions to ensure consistency with the customer's profile and risk level.
- Enhanced Due Diligence (EDD): Applying additional scrutiny to high-risk customers and politically exposed persons (PEPs).
Risk Categorization
- Low Risk: Customers with well-defined profiles, such as salaried individuals, government employees, and reputable entities.
- Medium Risk: Customers with limited transparency in operations or variable income sources.
- High Risk: Politically exposed persons (PEPs), non-resident customers, and those from high-risk jurisdictions.
Customer Identification Procedure (CIP)
- Full name and date of birth/incorporation.
- Permanent and correspondence address.
- Contact details and email ID.
- Identity proof and address proof as per OVDs.
- Details of beneficial owners in case of non-individual entities.
Ongoing Monitoring
The Company shall implement systems to continuously monitor transactions for unusual or suspicious activity. Monitoring will include verification of consistency between transactions and the customer's known profile.
Periodic KYC reviews shall be carried out based on risk category:
- Low Risk, Every 10 years
- Medium Risk, Every 8 years
- High Risk, Every 2 years
Record Keeping
All KYC documents, transaction records, and due diligence reports shall be maintained for at least five (5) years after the cessation of the relationship with the customer, as per PMLA and FIU-IND requirements.
Employee Training & Awareness
All employees involved in customer onboarding and account management must undergo periodic KYC and AML training. Training sessions will focus on identifying suspicious activities, proper documentation, and adherence to regulatory guidelines.
Non-Compliance & Penalties
Failure to comply with this policy may result in disciplinary actions, including suspension, termination, or reporting to regulatory authorities. Non-compliance may also attract legal penalties under the PMLA and other applicable laws.
Policy Review
This policy shall be reviewed annually by the Compliance Department and approved by the Board of Directors. Any changes or regulatory updates shall be communicated promptly to all concerned employees.
Employee Acknowledgment
I acknowledge that I have read and understood the Know Your Customer (KYC) & Customer Due Diligence (CDD) Policy of the Company I agree to comply with all the provisions mentioned herein.
Employee Name: __________________________
Signature: ______________________________
Date: _________________________________
Browse all policy categories
Frequently asked questions
What is the purpose of the KYC & CDD Policy?
To ensure compliance with regulatory requirements and prevent misuse of the Company's services for money laundering or terrorist financing by verifying customer identity and assessing risk.
Which regulations govern this policy?
The policy aligns with the Prevention of Money Laundering Act (PMLA), RBI KYC Master Directions, FIU-IND guidelines, and FATF recommendations.
Who must comply with this policy?
All employees involved in onboarding, customer management, or transaction monitoring, as well as all customers, vendors, partners, and beneficial owners engaging with the Company.
What is KYC?
KYC refers to verifying the identity and address of customers using officially valid documents (OVDs).
What is Customer Due Diligence (CDD)?
CDD involves understanding a customer's background, business activities, and risk level to ensure legitimacy of engagement.
What documents are required for identification?
Typical requirements include name, date of birth/incorporation, address, contact details, and identity/address proof (e.g., Aadhaar, PAN, Passport).
What are beneficial owners and why are they identified?
Beneficial owners are individuals who ultimately control or benefit from an entity. Identifying them ensures transparency and regulatory compliance.
What is Enhanced Due Diligence (EDD)?
EDD involves additional scrutiny for high-risk customers such as PEPs or those from high-risk jurisdictions.
Can Video KYC be used?
Yes, RBI-compliant Video KYC processes may be used for identity verification where applicable.
How are customers categorized by risk?
Customers are classified as Low, Medium, or High risk based on profile transparency, activity, and regulatory indicators.
How often is KYC reviewed?
Low Risk, Every 10 years Medium Risk, Every 8 years High Risk, Every 2 years
What is ongoing monitoring?
Continuous review of transactions to detect unusual or suspicious activities and ensure alignment with customer profiles.
How long are KYC records retained?
For at least five years after the relationship ends, in line with PMLA and FIU-IND requirements.
What training is provided to employees?
Periodic AML/KYC training focused on detection of suspicious activity, documentation standards, and regulatory adherence.
What happens in case of non-compliance?
Employees may face disciplinary action, and the Company may face regulatory or legal penalties.
How often is the policy reviewed?
Annually by the Compliance Department and approved by the Board, or sooner if regulations change.
What does employee acknowledgment mean?
It confirms the employee has read, understood, and agrees to follow the policy.
Whom should employees contact for clarification?
The Compliance Department should be contacted for any interpretation or implementation guidance.