KYCKART
KYCKART Guide · August 2026Guide

What Does KYC Mean? Definition and Why It Matters for BFSI

KYC means Know Your Customer: the RBI-defined process a bank or regulated entity uses to confirm who a customer is, understand their financial profile, and verify the relationship isn’t being used to launder money or finance terrorism, backed by a specific law and real financial and legal consequences when institutions get it wrong.

calendar_monthAugust 2026
schedule10 min read
library_books14 Cited Sources
personBhanujeet Choudhary, Head of Compliance

KYC stands for Know Your Customer: the process a bank or other regulated entity uses to confirm who a customer is, understand their financial profile, and verify that the relationship isn’t being used to launder money or finance terrorism. In India, that definition comes directly from the Reserve Bank of India and is backed by a specific law, with real financial and legal consequences attached when institutions get it wrong.

This piece covers where the definition comes from, how it fits into India’s anti-money-laundering framework, and what’s at stake when KYC breaks down.

01

The RBI Definition

RBI’s own consumer-facing FAQ defines KYC as “a process by which a Regulated Entity (RE), including a bank, obtains information on identity and address of the customer, nature of business and financial status of a customer and, verifies the same.”[1] The same FAQ states the purpose plainly: this process “helps to ensure that an RE is aware of the customer it is dealing with, and the services provided by the RE are not misused for Money Laundering/ Terrorist Financing/ Proliferation Financing (ML/TF/PF) purposes.”[1]

KYC applies well beyond account opening. Per the same FAQ, it’s also mandatory for walk-in customer transactions of ₹50,000 or more, for international money transfers, whenever the bank doubts the authenticity or adequacy of documents it already holds, and for sale of products exceeding ₹50,000.[1]

03

How India's KYC Rules Got Here

India’s KYC framework didn’t start with the 2016 Master Direction. RBI issued its first Know Your Customer guidelines in February 2005, building on earlier guidelines from January 2004, in the context of Financial Action Task Force (FATF) recommendations on anti-money laundering and countering the financing of terrorism.[5] Those guidelines were later consolidated into the 2016 Master Direction.[5]

Per one industry tracker’s account of RBI’s most recent KYC restructuring (no specific circular or notification number was available in the sourcing reviewed for this piece), the framework was reorganized again on 28 November 2025: the 2016 Direction was repealed and replaced with ten separate sector-specific KYC Master Directions covering institution types from commercial banks and NBFCs to co-operative banks, regional rural banks, and asset reconstruction companies.[6] That exercise was reportedly part of a larger RBI consolidation that folded roughly 3,500 prior directions, circulars, and guidelines into 238 Master Directions while withdrawing 9,445 circulars.[6]

04

How KYC Fits Inside CDD and EDD

KYC identity verification is one part of a broader, ongoing process called Customer Due Diligence (CDD): assessing and understanding a customer’s risk profile, which also covers understanding the purpose of the relationship, monitoring transactions, and keeping customer information current.[7] Per FATF Recommendation 10, due diligence is required when establishing a business relationship or verifying a new customer’s identity, applied on a risk-sensitive basis.[8]

Within the customer lifecycle, that due diligence is generally staged:

StageWhat It Does
Customer Identification Program (CIP)Confirms identity at onboarding[7]
Customer Due Diligence (CDD)Risk-assesses the customer, screening against watchlists and reviewing transaction and credit history, before an account-opening decision is made[7]
Enhanced Due Diligence (EDD)Applied to customers judged higher-risk during CDD[7]
Ongoing monitoringOnce the account is open, tracks changes in transaction behavior, sanctions exposure, adverse media, and ownership structure[7]
05

Why It Matters: The Scale of the Problem

The UN Office on Drugs and Crime estimates that money laundered worldwide each year equals 2-5% of global GDP, roughly US$800 billion to US$2 trillion, a figure UNODC itself flags as an estimate rather than a precise count, given how clandestine money laundering is by nature.[9]

06

Where India Stands: FATF's 2024 Assessment

FATF published India’s most recent Mutual Evaluation Report on 19 September 2024, assessing the country’s AML/CFT regime.[10][11] The outcome placed India in “regular follow-up,” FATF’s highest rating category, alongside only a small number of other G20 countries, reportedly including the UK, France, and Italy.[10] India was found compliant or largely compliant on 37 of FATF’s 40 Recommendations, with partial compliance on the remaining three: Recommendation 8 (non-profit organisations), Recommendation 12 (politically exposed persons), and Recommendation 28 (designated non-financial businesses and professions).[11]

Monetary penalties, when imposed, are generally not proportionate or dissuasive, in particular for larger firms.[11]

FATF's 2024 assessment of India's AML/CFT enforcement

The same assessment found supervisors leaned more on educational measures than financial sanctions, with average penalties reported in the $4,350-$87,000 range depending on institution type.[11]

07

The Cost of Getting It Wrong in India

RBI’s own enforcement record shows what that gap looks like domestically. In FY 2024-25, RBI imposed ₹54.78 crore in monetary penalties across 353 regulated entities (banks, NBFCs, cooperative banks, and other REs) for violations spanning cybersecurity framework lapses, exposure and IRAC norms, KYC directions, fraud classification and reporting, CRILC reporting, and credit information submission.[13]The sources behind that total don’t isolate how much of it is attributable to KYC violations specifically, only that KYC lapses were among the named categories.

Per one industry tracker’s breakdown of that total, cooperative banks accounted for 264 penalties worth ₹15.63 crore, eight public sector banks were penalised ₹11.11 crore, 15 private banks ₹14.8 crore, 37 NBFCs and asset reconstruction companies a combined ₹7.29 crore, and 13 housing finance companies ₹83 lakh, with six foreign banks also penalised.[13]

One recent case shows how a specific KYC lapse plays out. On 18 November 2025, RBI imposed a ₹91 lakh penalty on HDFC Bank, citing among its findings that the bank had outsourced the responsibility of determining customer compliance with KYC norms to external agents, a violation of RBI’s KYC-compliance expectations.[14] The penalty was issued under Section 47A(1)(c) read with Section 46(4)(i) of the Banking Regulation Act, 1949, following a Statutory Inspection for Supervisory Evaluation covering the bank’s position as of 31 March 2024.[14]

For NBFCs, the consequences can go further than a fine. RBI can cancel an NBFC’s Certificate of Registration for failing to implement KYC/AML norms, and operating as an NBFC without a valid Certificate is a criminal offence under Section 45-IA of the RBI Act, 1934, carrying penalties that can include imprisonment of up to five years alongside heavy fines.[15] In 2024, RBI cancelled the Certificates of Registration of NBFCs including Polytex India Ltd and FinServ India Ltd, citing reasons that included outsourcing core functions such as credit assessment and KYC without adequate oversight, plus data-privacy violations.[15]

08

What This Means for BFSI Compliance Teams

Read together, these facts show where the risk for individual institutions actually concentrates. FATF’s 2024 assessment found India’s AML/CFT framework compliant or largely compliant on 37 of 40 Recommendations.[11] RBI’s own enforcement record shows the framework is actively used: ₹54.78 crore in penalties across 353 entities in a single year[13], plus the HDFC Bank and NBFC cases described above.[14][15] The practical implication is that most institutions’ real exposure now sits in implementation, in how consistently an existing, board-approved KYC policy gets applied in practice. FATF’s assessment separately found that monetary penalties, when imposed, are generally not proportionate or dissuasive, particularly for larger firms.[11] That finding is about penalty size, separate from how consistently the underlying rules get applied day to day.

The HDFC Bank and NBFC cases point to a narrower pattern than a general policy gap. Both involve outsourcing without adequate oversight. RBI’s own Direction requires a Board-approved KYC policy.[2] The HDFC penalty was issued because the bank had outsourced responsibility for determining customer compliance with KYC norms to external agents.[14] The 2024 NBFC license cancellations also cited outsourcing core functions such as credit assessment and KYC without adequate oversight.[15] For a compliance team, the highest-value review is how consistently an existing KYC policy is actually being applied at every point where part of the process has been delegated to someone else.

Related Reading

This piece covers the core definition and the regulatory stakes. A few adjacent topics get their own dedicated treatment:

Frequently Asked Questions

This piece summarizes publicly available regulatory information for informational purposes. It is not legal, tax, or compliance advice; institutions should consult qualified counsel or their own compliance function for guidance specific to their situation.


person

Bhanujeet Choudhary

Head of Compliance, KYCKART

Published August 19, 2026

KYCKART Intelligence

Building or Auditing Your KYC Framework?

KYCKART works with BFSI compliance teams on CDD, EDD, and ongoing KYC monitoring implementation. Talk to our team about where your current process stands.

Talk to KYCKARTarrow_forward