KYC Is Not a Moment:
The Regulatory Case for a Living Customer Record
RBI’s KYC Directions require ongoing due diligence, not a one-time check. The four regulatory obligations behind a living customer record, and where DPDP draws the line.
Indian KYC regulation treats customer understanding as a standing obligation, not a task completed at onboarding. RBI’s KYC Directions[1] require regulated entities to run ongoing due diligence throughout the relationship, watch for transactions that don’t fit the customer’s known profile, and review risk categorisation on a fixed schedule, the same framework RBI rebuilt into ten entity-specific Directions in November 2025, its most significant KYC restructuring in nearly a decade. Most operating models don’t run that way. The KYC file gets built once at onboarding and then sits, largely untouched, until a scheduled review comes due, sometimes years later.
The Obligation, in Four Parts
Four regulatory duties that don't end when the account opens
Together, these three clocks set a minimum standard. A two-year or eight-year re-KYC cycle satisfies the update requirement, but it says nothing about what happened to the customer in year one. Periodic KYC updation creates a cadence. It doesn’t remove the need to respond to risk or material change the moment it appears.
“A file that's correct on the day of review can still be wrong for every month on either side of it.”
Why This Is Live Right Now
RBI's November 2025 restructuring of the KYC Master Directions
Until November 2025, this standard lived in one consolidated KYC Master Direction. That month, RBI retired the consolidated Direction and replaced it with ten entity-specific Directions: one for commercial banks, another for NBFCs, and so on, each with its own name and notification. Nine months in, per secondary legal-update coverage, the restructuring appears to carry forward the same ongoing-due-diligence and periodic-review standards described above into the new entity-specific texts.
For compliance and risk teams, this standard now sits inside current, freshly rebuilt regulatory architecture that regulators are still actively maintaining.
The Cost of Treating It as a Snapshot
Where KYCKART's own research makes the operational case
KYCKART’s own whitepaper frames this same pattern in operational and economic terms: a customer record that’s accurate on day one doesn’t stay accurate, and every stage of the relationship pays for that in its own way. This newsletter makes the regulatory case; the whitepaper makes the operational and economic one.
The operational and economic evidence behind data decay across onboarding, portfolio monitoring, and collections.
What a Living Customer Record Looks Like
Refreshed by events, checked against sources, bounded by DPDP
The direction of travel is a customer record refreshed as much by what happens to the customer as by the calendar: a change of address, a shift in transaction behaviour, a new beneficial owner. That record should be checked against sources the institution can stand behind, and it should carry a history of what changed, why it changed, and what the institution did in response, so the file can be audited after the fact rather than reconstructed from memory.
Four composite scenarios, not drawn from any single case, show where this plays out once a loan has actually been disbursed and a servicing relationship is underway.
Address Change After Relocation
A salaried employee takes a personal loan, then changes jobs and cities eight months later. Updating that address is the customer's obligation, due within 30 days. If it doesn't happen, the file stays wrong for the rest of the tenure, and recovery or default outreach later goes to an address the borrower left months earlier.
Funds Diverted After Disbursement
A working-capital loan is disbursed to a small business for inventory financing. Within weeks, a large share of the funds moves out to unrelated third parties with no clear connection to that stated purpose. Ongoing transaction monitoring is meant to catch exactly this shift.
Risk Profile Shifts Mid-Tenure
A retail borrower categorised as low-risk at onboarding, based on salaried income and a clean credit history, loses that job or takes on a large, unexplained deposit a few months into the loan. It only surfaces if a risk review, scheduled or triggered, happens before the next reassessment comes due.
Beneficial Ownership Changes
An NBFC extends a working-capital facility to an SME. Midway through the loan tenure, a founding partner exits and a new investor takes a majority stake. The beneficial owner identified at onboarding was accurate on day one; nothing updates that automatically when ownership changes.
That vision runs into a boundary set by the Digital Personal Data Protection (DPDP) Act, 2023[5], which requires personal data be processed only for a lawful purpose, and only with valid consent or under one of its specific “legitimate use” grounds. Consent itself has to be free, specific, informed, and limited to what the stated purpose actually needs.
Ignore that boundary and continuous monitoring turns into surveillance, out of step with DPDP even where the underlying KYC obligation is fully met.
The law itself builds in a narrower example of how this is supposed to work: Section 7(f) lets a regulated entity check a defaulting customer’s financial information without fresh consent, specifically for recovery purposes. That’s a legitimate-use ground scoped to that one recovery situation only.
The DPDP Rules, 2025[6], notified in November 2025, put a phased clock on this: governance provisions are already in force, and the substantive fiduciary obligations (notice and consent, data-principal rights, security safeguards) come into effect in May 2027. For institutions building the living-record capability, the purpose-limitation discipline runs on that same May 2027 clock.
Frequently Asked Questions
This newsletter reflects KYCKART’s interpretation of publicly available regulatory text and is offered for informational purposes only. It is not legal advice. Verify regulatory citations independently against the current Directions applicable to your entity type (bank, NBFC, insurer, or fintech), particularly given RBI’s November 2025 restructuring of the KYC Master Directions.
KYCKART Intelligence
Read the Whitepaper Behind This Case
Continuous KYC: Why One-Time Checks Fail BFSI Firms explores how data decay creates exposure across onboarding, portfolio monitoring, and recovery, and what a lifecycle-based verification model can change. For risk and compliance leaders: where in your portfolio does customer reality change faster than your KYC controls catch up?
Read the Whitepaperarrow_forward