KYC & Customer Due Diligence (CDD) Policy

Fraud Risk & KYC/AML
Experience PolicyCentral.ai platform features right here

Policy Statement

The Company is committed to complying with the Know Your Customer (KYC) and Customer Due Diligence (CDD) requirements as mandated by the Reserve Bank of India (RBI) and the Prevention of Money Laundering Act (PMLA), 2002. This policy outlines the processes for verifying the identity and address of customers, understanding the nature of their activities, and assessing the risk they may pose to the Company.

Objective

  • Prevent the use of the Company's services for money laundering or terrorist financing activities.
  • Ensure proper identification and verification of all customers and beneficial owners.
  • Implement a risk-based approach to customer due diligence.
  • Establish robust systems for monitoring, record keeping, and periodic review of customer data.

Regulatory Framework

  • Prevention of Money Laundering Act (PMLA), 2002 and Rules thereunder.
  • RBI Master Directions on Know Your Customer (KYC) dated February 25, 2016, and subsequent amendments.
  • Financial Intelligence Unit, India (FIU-IND) guidelines.
  • FATF recommendations on Customer Due Diligence.

Scope and Applicability

This policy applies to all customers, counterparties, and beneficial owners engaging with the Company It covers both individuals and legal entities, including vendors, partners, and clients.

KYC Components

  • Customer Identification Procedure (CIP): Collecting and verifying identity and address proof of customers using officially valid documents (OVDs) such as Aadhaar, PAN, Passport, etc.
  • Customer Due Diligence (CDD): Assessing the customer's background, business activities, and risk category.
  • Ongoing Due Diligence: Monitoring transactions to ensure consistency with the customer's profile and risk level.
  • Enhanced Due Diligence (EDD): Applying additional scrutiny to high-risk customers and politically exposed persons (PEPs).

Risk Categorization

  • Low Risk: Customers with well-defined profiles, such as salaried individuals, government employees, and reputable entities.
  • Medium Risk: Customers with limited transparency in operations or variable income sources.
  • High Risk: Politically exposed persons (PEPs), non-resident customers, and those from high-risk jurisdictions.

Customer Identification Procedure (CIP)

  • Full name and date of birth/incorporation.
  • Permanent and correspondence address.
  • Contact details and email ID.
  • Identity proof and address proof as per OVDs.
  • Details of beneficial owners in case of non-individual entities.

Ongoing Monitoring

The Company shall implement systems to continuously monitor transactions for unusual or suspicious activity. Monitoring will include verification of consistency between transactions and the customer's known profile.

Periodic KYC reviews shall be carried out based on risk category:

  • Low Risk, Every 10 years
  • Medium Risk, Every 8 years
  • High Risk, Every 2 years

Record Keeping

All KYC documents, transaction records, and due diligence reports shall be maintained for at least five (5) years after the cessation of the relationship with the customer, as per PMLA and FIU-IND requirements.

Employee Training & Awareness

All employees involved in customer onboarding and account management must undergo periodic KYC and AML training. Training sessions will focus on identifying suspicious activities, proper documentation, and adherence to regulatory guidelines.

Non-Compliance & Penalties

Failure to comply with this policy may result in disciplinary actions, including suspension, termination, or reporting to regulatory authorities. Non-compliance may also attract legal penalties under the PMLA and other applicable laws.

Policy Review

This policy shall be reviewed annually by the Compliance Department and approved by the Board of Directors. Any changes or regulatory updates shall be communicated promptly to all concerned employees.

Employee Acknowledgment

I acknowledge that I have read and understood the Know Your Customer (KYC) & Customer Due Diligence (CDD) Policy of the Company I agree to comply with all the provisions mentioned herein.

Employee Name: __________________________

Signature: ______________________________

Date: _________________________________

Browse all policy categories

Frequently asked questions

What is the purpose of the KYC & CDD Policy?

To ensure compliance with regulatory requirements and prevent misuse of the Company's services for money laundering or terrorist financing by verifying customer identity and assessing risk.

Which regulations govern this policy?

The policy aligns with the Prevention of Money Laundering Act (PMLA), RBI KYC Master Directions, FIU-IND guidelines, and FATF recommendations.

Who must comply with this policy?

All employees involved in onboarding, customer management, or transaction monitoring, as well as all customers, vendors, partners, and beneficial owners engaging with the Company.

What is KYC?

KYC refers to verifying the identity and address of customers using officially valid documents (OVDs).

What is Customer Due Diligence (CDD)?

CDD involves understanding a customer's background, business activities, and risk level to ensure legitimacy of engagement.

What documents are required for identification?

Typical requirements include name, date of birth/incorporation, address, contact details, and identity/address proof (e.g., Aadhaar, PAN, Passport).

What are beneficial owners and why are they identified?

Beneficial owners are individuals who ultimately control or benefit from an entity. Identifying them ensures transparency and regulatory compliance.

What is Enhanced Due Diligence (EDD)?

EDD involves additional scrutiny for high-risk customers such as PEPs or those from high-risk jurisdictions.

Can Video KYC be used?

Yes, RBI-compliant Video KYC processes may be used for identity verification where applicable.

How are customers categorized by risk?

Customers are classified as Low, Medium, or High risk based on profile transparency, activity, and regulatory indicators.

How often is KYC reviewed?

Low Risk, Every 10 years Medium Risk, Every 8 years High Risk, Every 2 years

What is ongoing monitoring?

Continuous review of transactions to detect unusual or suspicious activities and ensure alignment with customer profiles.

How long are KYC records retained?

For at least five years after the relationship ends, in line with PMLA and FIU-IND requirements.

What training is provided to employees?

Periodic AML/KYC training focused on detection of suspicious activity, documentation standards, and regulatory adherence.

What happens in case of non-compliance?

Employees may face disciplinary action, and the Company may face regulatory or legal penalties.

How often is the policy reviewed?

Annually by the Compliance Department and approved by the Board, or sooner if regulations change.

What does employee acknowledgment mean?

It confirms the employee has read, understood, and agrees to follow the policy.

Whom should employees contact for clarification?

The Compliance Department should be contacted for any interpretation or implementation guidance.

Stop emailing policy PDFs nobody reads

PolicyCentral.ai turns templates like this into living policies, versioned, translated, acknowledged, and answerable by AI.

PolicyGPT
AI-powered policy assistant

Hi! I'm PolicyGPT. Ask me anything about PolicyCentral.ai — features, security, compliance, pricing, or hosting.