KYCKART
KYCKART Guide · August 2026Guide

KYC & AML Glossary: EDD, CKYCRR, and POA Full Forms Explained

A KYC and AML glossary for Indian BFSI compliance teams: EDD, CKYCRR, POA, PMLA, PEP, STR, CTR, and 18 more terms, each defined with the RBI, CERSAI, and FIU-IND regulatory detail behind it.

calendar_monthAugust 2026
schedule17 min read
library_books51 Cited Sources
personBhanujeet Choudhary, Head of Compliance

EDD, CKYCRR, and POA are three terms compliance and onboarding teams in Indian BFSI run into constantly, and each has a precise regulatory meaning that’s easy to get slightly wrong. This glossary defines all three, plus 22 more terms spanning the KYC process, verification methods, documents, AML/CFT rules, and reporting obligations that regulated entities work with day to day. Every entry opens with a direct definition, then adds the regulatory detail behind it.

Jump to a Term

Core KYC concepts:KYC·CDD·EDD·RBA
Documents & identifiers:OVD·POA·PAN
AML/CFT & risk terms:AML·CFT·PMLA·UBO·PEP·Sanctions/Name Screening
Reporting & regulators:STR·CTR·FIU-IND·RE·KRA
01

Core KYC Concepts

These four terms establish the base vocabulary. Everything else in this glossary nests inside one of them.

KYC (Know Your Customer)

KYC is the regulatory framework requiring banks, NBFCs, and other regulated entities to know their customer, monitor customer activity, keep records, and report to FIU-IND, to prevent money laundering and terrorist financing[11][12]. In India it runs primarily on RBI’s KYC Master Direction, 2016 (Master Direction DBR.AML.BC.No.81/14.01.001/2015-16), issued 25 February 2016, under the framework of the Prevention of Money-Laundering Act, 2002 and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005[11]. The Master Direction defines Regulated Entities to include banks, All India Financial Institutions, NBFCs, Asset Reconstruction Companies, Payment System Providers, System Participants, Authorised Persons, and Money Transfer Service Scheme Agents[12].

CDD (Customer Due Diligence)

CDD means identifying and verifying a customer and its beneficial owner, the baseline check every regulated entity runs before or during a relationship[9]. RBI’s amended KYC Master Direction requires CDD at the Unique Customer Identification Code (UCIC) level, using “reliable” and “independent” sources of identification[9]. CDD applies both when opening an account-based relationship and for certain transactions carried out without one, such as domestic remittances and sale of pre-paid instruments[10]. A further amendment, reported dated 17 October 2023, tightened related requirements: CDD data obtained from third parties must now be furnished “immediately,” removing a prior 2-day allowance, trust-customer CDD requires additional Protector information, and STR-filing and wire-transfer reporting requirements were expanded[37].

EDD (Enhanced Due Diligence)

EDD is the heightened level of customer verification and risk assessment applied to high-risk customers, going beyond CDD into source-of-funds verification against documentary evidence, deeper beneficial-ownership tracing, sanctions and PEP screening, adverse-media checks, and continuous monitoring[1][2]. RBI’s KYC Master Direction makes EDD a mandatory regulatory obligation for high-risk customers, including PEP relationships and non-face-to-face onboarding scenarios[2].

DimensionCDDEDD
Applies toEvery customer, at onboarding or for certain transactions run without an account relationship[9][10]High-risk customers specifically, including PEP relationships and non-face-to-face onboarding[2]
What it verifiesCustomer and beneficial-owner identity, via reliable, independent sources[9]Source of funds against documentary evidence, deeper beneficial-ownership tracing, sanctions/PEP screening, adverse media, continuous monitoring[1]
Regulatory statusMandatory baseline under RBI’s KYC Master Direction[9]Mandatory regulatory obligation for high-risk customers[2]

RBA (Risk-Based Approach)

RBA is RBI’s requirement that regulated entities sort every customer into a low-, medium-, or high-risk category, based on an assessed profile covering identity, location, nature of business, and transaction history[20][21][22]. Named high-risk indicators include entities whose ultimate beneficial owner is a PEP, and cash-intensive businesses such as bullion dealers, jewellers, and real estate developers[20][22]. This risk categorization directly drives how often that customer’s KYC gets refreshed, covered under Re-KYC below[20].

02

Verification Methods

How KYC actually gets done, and kept current, once a customer’s risk tier is set.

e-KYC (Electronic KYC)

e-KYC is Aadhaar-based electronic authentication carried out only through OTP or biometric (fingerprint or iris) verification[13][14]. The Aadhaar number holder’s OTP or biometric data is matched against records in UIDAI’s Central Identities Data Repository (CIDR), with the holder’s consent, and UIDAI returns a digitally signed e-KYC response to the requesting entity[13].

V-CIP (Video KYC)

V-CIP, commonly called Video KYC, is an RBI-permitted method where a specially trained, authorised official of the regulated entity completes CDD through a live, secure, informed-consent-based audio-visual interaction with the customer[15]. It’s set out under RBI’s KYC Master Direction as amended; no specific circular or notification number for V-CIP’s original introduction was available in the sourcing for this piece. It requires geo-tagging the video with live GPS coordinates, face liveness and spoofing detection, face-matching, a captured photograph and audio-visual recording of the customer, and varying security questions to confirm the interaction is happening in real time rather than pre-recorded[15]. RBI treats V-CIP as equivalent to face-to-face verification, unlike other non-face-to-face methods such as Aadhaar OTP-based e-KYC[15]. See KYCKART’s breakdown of V-CIP vs. e-KYC for the full mechanics.

NFTF (Non-Face-to-Face onboarding)

NFTF covers onboarding methods where the customer and the regulated entity never meet in person, including Aadhaar OTP-based e-KYC, use of DigiLocker-sourced documents, and certified copies of Officially Valid Documents for NRIs/PIOs[15]. Except for V-CIP, RBI classifies customers onboarded through NFTF methods as high-risk[15].

CKYC and CKYCRR

CKYC and CKYCRR get used interchangeably, but the more precise distinction is that CKYC refers to a customer’s stored KYC record itself, while CKYCRR is the registry, operated by CERSAI, that houses, governs access to, and centrally manages those records[5]. CKYCRR (Central KYC Records Registry) is India’s centralized digital repository for verified customer KYC records across the financial sector, operated by CERSAI under authorization from the Prevention of Money Laundering Act, 2002[5][7]. CERSAI assigns each processed record a unique 14-digit KYC Identification Number that any registered financial institution can use to retrieve verified KYC details instead of re-collecting documents[5][7].

That covers what CKYCRR is. For the deeper mechanics, KIN generation timelines, the CKYCRR 2.0 upgrade direction, and the full risk-based re-verification schedule, see KYCKART’s dedicated CKYCRR full-form explainer, which this hub deliberately doesn’t duplicate.

KIN (KYC Identification Number)

KIN is the unique 14-digit code CERSAI assigns to a customer’s record once it’s processed into CKYCRR, functioning as a single identifier any registered financial institution can use to pull that customer’s verified KYC data instead of collecting it again[6][7].

Re-KYC / Periodic KYC Update

Re-KYC is the periodic refresh RBI requires for existing customers, at a frequency set by risk category: at least once every 2 years for high-risk customers, once every 8 years for medium-risk customers, and once every 10 years for low-risk customers[16][18][19]. Regulated entities may apply a tighter internal cadence, but can’t exceed these regulatory ceilings[16]. A June 2025 RBI proposal would let regulated entities authorize Business Correspondents to help customers submit self-declarations where there’s no change, or only an address change, to their KYC details, though ultimate responsibility for updation stays with the bank; the same proposal would give low-risk customers until June 2026, or one year from their periodic-KYC due date (whichever is later), to complete updates while keeping transaction privileges, and would require regulated entities to issue at least three advance due-notices, including one by letter, ahead of a customer’s due date[16][17]. No specific circular or notification number for this proposal was available in the sourcing for this piece.

Risk CategoryRe-KYC Frequency Ceiling
High-risk customersAt least once every 2 years[16][18][19]
Medium-risk customersAt least once every 8 years[16][18][19]
Low-risk customersAt least once every 10 years[16][18][19]
03

Documents & Identifiers

The physical and digital document layer underneath the process above.

OVD (Officially Valid Document)

An OVD is one of six documents RBI accepts as proof of identity for KYC: the Indian Passport, Driving Licence, Voter’s Identity Card, PAN Card, Aadhaar Card, and the NREGA Job Card issued by a State Government[3][4].

POA (Proof of Address)

POA can be satisfied either by an OVD that already carries the customer’s current address, or, if it doesn’t, by a separate “deemed OVD” address document: a utility bill (electricity, telephone, gas, or water) not more than two months old, a property or municipal tax receipt, a Pension Payment Order, or a letter of allotment of accommodation from an employer[3]. A PAN card is accepted as an OVD for proof of identity only, not proof of address, so a customer submitting PAN as their identity document still has to submit a separate address document[4].

PAN (Permanent Account Number)

PAN is a 10-digit alphanumeric identifier issued by India’s Income Tax Department, used to track tax payments, returns, TDS/TCS credits, and specified financial transactions[24]. Under Rule 114B of the Income-tax Rules, quoting PAN is mandatory for specified high-value transactions, including opening a new bank account, opening a demat account, cash deposits above ₹50,000, and sale or purchase of immovable property or a motor vehicle other than a two-wheeler; it’s the statutory responsibility of the entity receiving the transaction documents, such as a bank, to ensure PAN is quoted wherever required[23].

04

AML/CFT and Higher-Risk-Customer Terms

The anti-financial-crime layer KYC ultimately feeds into.

AML (Anti-Money Laundering)

AML is the broader set of laws, regulations, and institutional practices requiring regulated entities to prevent, detect, and report money laundering and related financial crime[25]. In India, it’s governed primarily by the Prevention of Money Laundering Act (PMLA), 2002 and its associated Rules, which define money-laundering offences, enable seizure of assets, mandate CDD, and require filing of Suspicious Transaction Reports and record-keeping[25]. Regulatory responsibility is distributed by sector: RBI covers banks and NBFCs, SEBI covers stockbrokers, mutual funds, and other capital-market participants, IRDAI supervises insurance companies, and the Enforcement Directorate handles money-laundering prosecutions and asset seizure, while FIU-IND is the central body that receives and analyzes Suspicious Transaction Reports from all of them[26][27].

CFT (Countering the Financing of Terrorism)

CFT is the parallel set of laws, screening processes, and reporting duties designed to stop funds, licit or illicit, from reaching terrorist individuals, groups, or acts[28]. It runs on much of the same customer-identity data KYC collects, which is why “AML/CFT” is typically used as one combined term[28]. India participates in international AML/CFT bodies including the Financial Action Task Force (FATF), the Asia/Pacific Group on Money Laundering (APG), and the Eurasian Group (EAG)[29].

A joint FATF-APG-EAG mutual evaluation found India’s AML/CFT framework “achieving good results,” placing it in “regular follow-up,” FATF’s highest rating category.[29]

PMLA (Prevention of Money Laundering Act, 2002)

PMLA is the underlying statute establishing India’s anti-money-laundering framework. It was enacted 17 January 2003 and came into force 1 July 2005, and it defines money laundering, provides for confiscation of proceeds of crime, and imposes customer due diligence, record-keeping, and reporting obligations on regulated and reporting entities[30][31].

UBO (Ultimate Beneficial Owner)

UBO refers to the natural person who actually owns or controls a customer, as distinct from whoever is named on the paperwork. Under Rule 9 of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, the beneficial owner of a company is a natural person who, alone or through others, owns or is entitled to more than 25% of the company’s shares, capital, or profits, or who otherwise controls it through the right to appoint a majority of directors or to control management or policy decisions[33]. Where a trust is the customer, the beneficial owner includes the author or settlor, the trustees, and beneficiaries holding more than 15% interest, plus anyone else exercising ultimate effective control through a chain of ownership. If no natural person meets the applicable threshold under any of these categories, the beneficial owner defaults to whoever holds the position of Senior Managing Official[33].

A Ministry of Finance notification dated 4 September 2023 (GSR 652(E)) lowered this threshold specifically for partnership firms, from more than 15% to more than 10% of the firm’s capital or profits, and added “exercises control through other means” as an additional basis for identifying a partnership’s beneficial owner, a change intended to close a loophole enabling shell-company and benami structuring[34][35][36]. That amendment was scoped to partnership firms; the company-level 25% and trust-level 15% thresholds above are the figures set out in Rule 9 itself.

PEP (Politically Exposed Person)

A PEP, per RBI circular RBI/2023-24/107 dated 4 January 2024 amending the KYC Master Direction, is an individual who is or has been entrusted with a prominent public function by a foreign country, including heads of state or government, senior politicians, senior government, judicial, or military officers, senior executives of state-owned corporations, and important political party officials, with the definition explicitly extending to their immediate family members and known close associates[38][39][40]. The same amendment relocated the PEP definition from a sub-clause of Section 3 to an explanatory note under Section 41 of the Master Direction, a restructuring RBI framed as providing “better clarity,” while emphasizing the “foreign country” qualifier to reduce ambiguity about domestic versus international political exposure[38].

Sanctions and Name Screening

RBI requires regulated entities to screen customers, beneficial owners, and, depending on context, counterparties against sanctions lists implemented under Section 51A of the Unlawful Activities (Prevention) Act, 1967, which gives domestic legal effect to United Nations Security Council sanctions lists, including the UNSCR 1267/1989 ISIL/Al-Qaida list and the UNSCR 1718 list[41][42]. Regulated entities must verify the UNSCR 1718 list daily for additions, deletions, or other modifications, and are encouraged to use technology to automate this screening[41]. In practice, sanctions and name screening means comparing a customer’s or transaction party’s name against watchlists, sanctions lists, PEP lists, and similar registers, as part of CDD, both before onboarding and on an ongoing basis[43][44].

05

Reporting & Regulators

Who regulated entities report to, and who regulates them.

STR (Suspicious Transaction Report)

An STR is the report a regulated entity’s Principal Officer must file with the Director, FIU-IND, once the entity becomes satisfied that a transaction is suspicious. Under Rule 8 of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, it must be filed within 7 working days of that determination[49][50].

CTR (Cash Transaction Report)

A CTR is a mandatory report of every cash transaction exceeding ₹10 lakh, or its equivalent in foreign currency, required under Rule 3 of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. It also covers a series of individually smaller cash transactions that are “integrally connected” and whose monthly aggregate exceeds ₹10 lakh. CTRs must be filed with FIU-IND by the 15th of the month following the reported transactions[48][49].

FIU-IND

FIU-IND, the Financial Intelligence Unit – India, is the central national agency responsible for receiving, processing, analyzing, and disseminating information about suspect financial transactions in India[45]. It was established by the Government of India via an official memorandum dated 18 November 2004, and reports directly to the Economic Intelligence Council, headed by the Finance Minister[45]. FIU-IND is the central reception point for Cash Transaction Reports, Suspicious Transaction Reports, Non-Profit Organisation Transaction Reports, Cross-Border Wire Transfer Reports, and Reports on Purchase or Sale of Immovable Property from reporting entities[46][47]; it analyzes this information to uncover patterns suggesting money laundering or related crimes and shares findings with national intelligence and law-enforcement agencies, national regulators, and foreign Financial Intelligence Units[47].

RE (Regulated Entity)

RE is the umbrella shorthand RBI’s KYC/AML framework uses for the institutions legally required to perform CDD and KYC and file AML-related reports: banks, All India Financial Institutions, NBFCs, Asset Reconstruction Companies, Payment System Providers, System Participants, Authorised Persons, and Money Transfer Service Scheme Agents[12].

KRA (KYC Registration Agency)

A KRA is a SEBI-regulated entity that centrally stores and digitizes investor KYC records for India’s securities market, so an investor who has already completed KYC with one SEBI-registered intermediary doesn’t have to redo it when opening an account with another broker, mutual fund house, or Registered Investment Adviser[51][53]. KRAs operate under the SEBI (KYC (Know Your Client) Registration Agency) Regulations, 2011, most recently amended 28 November 2024[52]. As of one source’s reporting in February 2026, six KRAs are registered with SEBI[51].

TermFiles WithTriggerDeadline / Cadence
STRFIU-IND[49][50]Entity becomes satisfied a transaction is suspicious[49][50]Within 7 working days of that determination[49][50]
CTRFIU-IND[48][49]Cash transaction exceeding ₹10 lakh, including connected smaller transactions aggregating past that in a month[48][49]By the 15th of the following month[48][49]
06

How These Terms Connect for a Compliance Team

Read together, RBA is the hinge most of this glossary swings on. It’s what decides whether a given customer gets EDD instead of standard CDD[2][20], how often that customer’s KYC has to be refreshed under the 2/8/10-year cadence[16][18][19][20], and, for anyone onboarded through an NFTF method other than V-CIP, whether they land in the high-risk bucket automatically in the first place[15][20]. The practical implication is that a channel-mix decision, such as favoring Aadhaar OTP e-KYC over V-CIP for a given onboarding flow, isn’t only an onboarding-conversion choice. Because e-KYC is one of the NFTF methods RBI treats as high-risk by default while V-CIP is treated as equivalent to face-to-face verification, that channel choice also determines whether the resulting customer relationship carries a shorter re-verification cycle and a mandatory EDD obligation from day one[2][15][16][18][19][20]. A team evaluating onboarding channels on speed or drop-off alone is only looking at half the cost of that decision.

Frequently Asked Questions

This article summarizes publicly available regulatory information for informational purposes. It isn’t legal, tax, or compliance advice; verify specific obligations against the primary RBI, SEBI, CERSAI, and FIU-IND notifications, and your own counsel, before acting on them.


person

Bhanujeet Choudhary

Head of Compliance, KYCKART

Published August 19, 2026

KYCKART Intelligence

Need Help Getting KYC/AML Terminology Right?

KYCKART’s compliance team tracks how EDD, CKYCRR, PEP, and every other term in this glossary actually plays out in onboarding and monitoring workflows. Talk to us about where your own KYC/AML process needs a closer look.

Talk to Our Teamarrow_forward