KYCKART
KYCKART Intel · July 2026Newsletter

KYC Is Not a Moment: The Regulatory Case for a Living Customer Record

RBI’s KYC Directions require ongoing due diligence, not a one-time check. The four regulatory obligations behind a living customer record, and where DPDP draws the line.

calendar_monthIssue date:
schedule~5 min read
library_books6 Cited Sources

Indian KYC regulation treats customer understanding as a standing obligation, not a task completed at onboarding. RBI’s KYC Directions[1] require regulated entities to run ongoing due diligence throughout the relationship, watch for transactions that don’t fit the customer’s known profile, and review risk categorisation on a fixed schedule, the same framework RBI rebuilt into ten entity-specific Directions in November 2025, its most significant KYC restructuring in nearly a decade. Most operating models don’t run that way. The KYC file gets built once at onboarding and then sits, largely untouched, until a scheduled review comes due, sometimes years later.

01

The Obligation, in Four Parts

Four regulatory duties that don't end when the account opens

Know the Customer at Entry
RBI’s KYC Directions require regulated entities to identify and verify a customer using reliable, independent sources[2], understand the purpose of the relationship, and establish who the beneficial owner is if the customer isn’t acting for themselves. It’s also the part that ends the day the account opens.
Know the Customer During the Relationship
The same Directions require ongoing due diligence: monitoring transactions to make sure they’re consistent with what the institution knows about the customer[3], their business, their risk profile, and their source of funds or wealth. Large or complex transactions, and any pattern with no clear economic rationale, draw particular scrutiny. The Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 place the same obligation directly on reporting entities as a matter of statute. RBI’s Directions and the PML Rules describe the same standard from two different angles. FATF Recommendation 10 sets the equivalent expectation internationally: ongoing scrutiny for the life of the relationship, applied more often as risk rises.
Reassess Changing Risk
Risk categorisation isn’t assigned once and left alone. RBI requires a system of periodic review, at least once every six months, and that review determines whether enhanced due diligence is now warranted. SEBI’s own KYC Master Circular for the securities market carries an equivalent ongoing-review obligation for registered intermediaries, without stating RBI’s specific six-month interval.
Maintain the Record
Two obligations run here in opposite directions, and they get conflated more often than they should. RBI’s re-KYC cadence is risk-based: at least every two years for high-risk customers, every eight years for medium-risk, every ten for low-risk, measured from account opening or the last update. Separately, if a customer’s own documents change, the Directions require the customer to give the regulated entity that update within 30 days. And separately again, once a regulated entity has that updated information in hand, the PML (Maintenance of Records) Amendment Rules, 2024 give it seven days to pass it on to the Central KYC Records Registry. Three clocks govern three obligations across two parties. The regulated entity carries two of them; the customer carries the third.

Together, these three clocks set a minimum standard. A two-year or eight-year re-KYC cycle satisfies the update requirement, but it says nothing about what happened to the customer in year one. Periodic KYC updation creates a cadence. It doesn’t remove the need to respond to risk or material change the moment it appears.

A file that's correct on the day of review can still be wrong for every month on either side of it.
02

Why This Is Live Right Now

RBI's November 2025 restructuring of the KYC Master Directions

Until November 2025, this standard lived in one consolidated KYC Master Direction. That month, RBI retired the consolidated Direction and replaced it with ten entity-specific Directions: one for commercial banks, another for NBFCs, and so on, each with its own name and notification. Nine months in, per secondary legal-update coverage, the restructuring appears to carry forward the same ongoing-due-diligence and periodic-review standards described above into the new entity-specific texts.

tips_and_updates

For compliance and risk teams, this standard now sits inside current, freshly rebuilt regulatory architecture that regulators are still actively maintaining.

03

The Cost of Treating It as a Snapshot

Where KYCKART's own research makes the operational case

KYCKART’s own whitepaper frames this same pattern in operational and economic terms: a customer record that’s accurate on day one doesn’t stay accurate, and every stage of the relationship pays for that in its own way. This newsletter makes the regulatory case; the whitepaper makes the operational and economic one.

description
Continuous KYC: Why One-Time Checks Fail BFSI Firms[4]

The operational and economic evidence behind data decay across onboarding, portfolio monitoring, and collections.

04

What a Living Customer Record Looks Like

Refreshed by events, checked against sources, bounded by DPDP

The direction of travel is a customer record refreshed as much by what happens to the customer as by the calendar: a change of address, a shift in transaction behaviour, a new beneficial owner. That record should be checked against sources the institution can stand behind, and it should carry a history of what changed, why it changed, and what the institution did in response, so the file can be audited after the fact rather than reconstructed from memory.

Four composite scenarios, not drawn from any single case, show where this plays out once a loan has actually been disbursed and a servicing relationship is underway.

home_work

Address Change After Relocation

A salaried employee takes a personal loan, then changes jobs and cities eight months later. Updating that address is the customer's obligation, due within 30 days. If it doesn't happen, the file stays wrong for the rest of the tenure, and recovery or default outreach later goes to an address the borrower left months earlier.

swap_horiz

Funds Diverted After Disbursement

A working-capital loan is disbursed to a small business for inventory financing. Within weeks, a large share of the funds moves out to unrelated third parties with no clear connection to that stated purpose. Ongoing transaction monitoring is meant to catch exactly this shift.

trending_down

Risk Profile Shifts Mid-Tenure

A retail borrower categorised as low-risk at onboarding, based on salaried income and a clean credit history, loses that job or takes on a large, unexplained deposit a few months into the loan. It only surfaces if a risk review, scheduled or triggered, happens before the next reassessment comes due.

groups

Beneficial Ownership Changes

An NBFC extends a working-capital facility to an SME. Midway through the loan tenure, a founding partner exits and a new investor takes a majority stake. The beneficial owner identified at onboarding was accurate on day one; nothing updates that automatically when ownership changes.

That vision runs into a boundary set by the Digital Personal Data Protection (DPDP) Act, 2023[5], which requires personal data be processed only for a lawful purpose, and only with valid consent or under one of its specific “legitimate use” grounds. Consent itself has to be free, specific, informed, and limited to what the stated purpose actually needs.

gpp_maybe

Ignore that boundary and continuous monitoring turns into surveillance, out of step with DPDP even where the underlying KYC obligation is fully met.

The law itself builds in a narrower example of how this is supposed to work: Section 7(f) lets a regulated entity check a defaulting customer’s financial information without fresh consent, specifically for recovery purposes. That’s a legitimate-use ground scoped to that one recovery situation only.

The DPDP Rules, 2025[6], notified in November 2025, put a phased clock on this: governance provisions are already in force, and the substantive fiduciary obligations (notice and consent, data-principal rights, security safeguards) come into effect in May 2027. For institutions building the living-record capability, the purpose-limitation discipline runs on that same May 2027 clock.

Frequently Asked Questions

This newsletter reflects KYCKART’s interpretation of publicly available regulatory text and is offered for informational purposes only. It is not legal advice. Verify regulatory citations independently against the current Directions applicable to your entity type (bank, NBFC, insurer, or fintech), particularly given RBI’s November 2025 restructuring of the KYC Master Directions.

KYCKART Intelligence

Read the Whitepaper Behind This Case

Continuous KYC: Why One-Time Checks Fail BFSI Firms explores how data decay creates exposure across onboarding, portfolio monitoring, and recovery, and what a lifecycle-based verification model can change. For risk and compliance leaders: where in your portfolio does customer reality change faster than your KYC controls catch up?

Read the Whitepaperarrow_forward