Home / NBFC & Fintech / NBFC KYC / AML Compliance
RBI’s 2025 amendments tightened periodic KYC updation, sanctions screening, and customer outreach requirements — and a missed STR or CTR filing is a PMLA violation, not just an RBI compliance gap. CS Chetna Shoor builds and runs the KYC/AML program so gaps don’t surface at inspection.
RBI’s Master Direction on KYC, first issued in 2016 and substantially amended through 2025 — with a dedicated NBFC-specific Master Direction now in force since November 2025 — works alongside the Prevention of Money Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005 to set NBFCs’ customer due diligence, risk categorization, and suspicious-activity reporting obligations. None of this is a one-time onboarding checklist: it’s a continuous program covering periodic KYC updation on a risk-based cadence, monthly Cash Transaction Reports, Suspicious Transaction Reports filed within days of identifying suspicion, and a board-approved policy with named, personally accountable officers.
This page is for NBFCs that need a working KYC/AML program, not a policy document sitting unused in a drawer — the difference RBI inspection actually checks for. Chetna sets up the risk categorization framework, the periodic updation trigger system, and the FIU-IND reporting discipline your NBFC needs to run continuously, not just at onboarding.
Periodic KYC updation cadence for high, medium, and low-risk customers respectively
Cash Transaction Report threshold — integrally connected transactions are aggregated against this limit
Window to file a Suspicious Transaction Report once suspicion is identified
Suspicious transactions are reported regardless of amount, based on suspicion alone
Named, personally accountable roles every NBFC's KYC/AML policy must specify
Legal basis, layered on top of RBI's NBFC-specific registration framework
RBI rejects over 40% of NBFC applications on the first attempt. Here’s what actually causes it.
RBI's risk-based cadence — every 2 years for high-risk, 8 for medium-risk, 10 for low-risk customers — combined with the 2025 amendment's three-intimation, three-reminder outreach requirement, means NBFCs need a system that proactively flags customers approaching their update window. Customers whose KYC has lapsed without being refreshed are consistently the single most common finding in RBI inspections.
A customer update recorded internally but never pushed to the Central KYC Registry, or a CKYCR update the NBFC's own system never pulls in, creates a divergence that a well-run compliance program treats as an incident to investigate, not a data-quality footnote to ignore.
An NBFC that files a Suspicious Transaction Report must never disclose that filing to the customer, even indirectly. Getting internal communication protocols wrong around a flagged transaction can create a separate compliance violation on top of whatever triggered the STR in the first place.
These two services are related but distinct, and a complete program needs both.
The broader customer due diligence, risk categorization, and suspicious-activity reporting framework — covers who your customers are and what you report to FIU-IND.
The specific, more mechanical obligation to upload and retrieve customer KYC records via the Central KYC Registry operated by CERSAI. See our dedicated CKYC Compliance service.
A complete KYC/AML program needs both the judgment-based due diligence and reporting framework, and the registry mechanics that keep records synced across the financial system.
We review your current policy, confirm your Principal Officer and Designated Director appointments, and check your risk categorization framework.
A full review against RBI's current KYC Master Direction and its 2025 amendments, identifying specific gaps.
Policy updates, risk categorization refinement, and a periodic updation trigger system built to flag customers proactively.
Monthly Cash Transaction Reports, and Suspicious Transaction Reports filed within 7 working days of any identified suspicion.
Coordinated with our CKYC Compliance service to keep internal records and the central registry aligned.
Sanctions and PEP list refresh, alongside an annual review of the KYC/AML policy itself.
Gaps here carry consequences on two separate fronts — RBI’s supervisory action and FIU-IND’s own enforcement.
RBI inspection findings and potential monetary penalties for KYC deficiencies.
FIU-IND action for missed or late STR/CTR filings, independent of RBI's own enforcement track.
Personal accountability exposure for the named Principal Officer and Designated Director.
Visibility during any future acquisition — a weak KYC/AML program is exactly the kind of gap buyer-side diligence surfaces. See NBFC Due Diligence (Buyer Side).
CS Chetna Shoor’s team replies within 4 hours on WhatsApp.
RBI’s risk-based framework requires periodic KYC updation every 2 years for high-risk customers, every 8 years for medium-risk customers, and every 10 years for low-risk customers. A 2025 amendment gave low-risk customers whose update had fallen due an extended deadline of one year from the due date or June 30, 2026, whichever is later, to allow NBFCs time to migrate customers to digital re-KYC.
A Cash Transaction Report (CTR) is filed with FIU-IND for any cash transaction exceeding ₹10 lakh, including a series of smaller, integrally connected cash transactions that together cross that threshold. CTRs are filed monthly, by the 15th of the succeeding month, and the obligation is amount-triggered — no suspicion of wrongdoing is required.
A Suspicious Transaction Report (STR) is filed with FIU-IND whenever a transaction raises reasonable suspicion of money laundering or financial crime, regardless of the transaction amount — unlike a CTR, which is triggered purely by crossing the ₹10 lakh threshold. STRs must be filed within 7 working days of identifying the suspicion, and the NBFC is legally barred from disclosing the filing to the customer involved.
Every NBFC’s board-approved KYC/AML policy must name a Principal Officer, responsible for day-to-day AML compliance and FIU-IND reporting, and a Designated Director, who carries board-level accountability for the program. RBI inspections specifically check that these roles are actually functioning, not just named on paper.
KYC/AML compliance is the broader framework covering customer due diligence, risk categorization, and suspicious-activity reporting to FIU-IND. CKYC compliance is the narrower, more mechanical obligation to upload and keep customer records current in the Central KYC Registry operated by CERSAI. A complete program needs both — see our dedicated CKYC Compliance service for the registry-specific obligations.
Qualified Company Secretary · ICSI Member · Founder, Expertvuw Management Pvt Ltd
Chetna has guided NBFC promoters through RBI’s COR process end to end, with particular focus on structuring the Net Owned Fund and business plan so the application survives first-round RBI scrutiny rather than coming back with a query.