Home  /  NBFC & Fintech  /  NBFC KYC / AML Compliance

CERSAI Registration Services
Tier 4 Service · Critical Priority

KYC Isn't a One-Time Onboarding Step — It's a Continuous Obligation RBI Actively Audits

RBI’s 2025 amendments tightened periodic KYC updation, sanctions screening, and customer outreach requirements — and a missed STR or CTR filing is a PMLA violation, not just an RBI compliance gap. CS Chetna Shoor builds and runs the KYC/AML program so gaps don’t surface at inspection.

Overview

Why KYC/AML Is a Running Program, Not a Policy Document

RBI’s Master Direction on KYC, first issued in 2016 and substantially amended through 2025 — with a dedicated NBFC-specific Master Direction now in force since November 2025 — works alongside the Prevention of Money Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005 to set NBFCs’ customer due diligence, risk categorization, and suspicious-activity reporting obligations. None of this is a one-time onboarding checklist: it’s a continuous program covering periodic KYC updation on a risk-based cadence, monthly Cash Transaction Reports, Suspicious Transaction Reports filed within days of identifying suspicion, and a board-approved policy with named, personally accountable officers.

This page is for NBFCs that need a working KYC/AML program, not a policy document sitting unused in a drawer — the difference RBI inspection actually checks for. Chetna sets up the risk categorization framework, the periodic updation trigger system, and the FIU-IND reporting discipline your NBFC needs to run continuously, not just at onboarding.

Talk to an NBFC Compliance Specialist →
Service Covers

What This Service Covers

1

Board-approved KYC/AML policy drafting, with named Principal Officer and Designated Director accountability.

2

Customer Due Diligence (CDD) framework — risk categorization and beneficial ownership identification for legal entity customers.

3

Periodic KYC updation program, run on RBI's risk-based cadence rather than a fixed calendar.

4

AML transaction monitoring and FIU-IND reporting — Cash Transaction Reports and Suspicious Transaction Reports, filed within the prescribed windows.

5

CKYC Registry integration, so your KYC records stay in sync with the central registry — see our dedicated CKYC Compliance service for the registry-specific obligations.

6

Sanctions and Politically Exposed Person (PEP) screening, kept current against RBI's latest lists.

Eligibility & key criteria

2 / 8 / 10 years

Periodic KYC updation cadence for high, medium, and low-risk customers respectively

₹10 lakh

Cash Transaction Report threshold — integrally connected transactions are aggregated against this limit

7 working days

Window to file a Suspicious Transaction Report once suspicion is identified

No STR threshold

Suspicious transactions are reported regardless of amount, based on suspicion alone

Principal Officer + Designated Director

Named, personally accountable roles every NBFC's KYC/AML policy must specify

PMLA, 2002 + RBI KYC Master Direction

Legal basis, layered on top of RBI's NBFC-specific registration framework

Why It's Complex

Three Reasons NBFC KYC/AML Programs Fail Inspection

RBI rejects over 40% of NBFC applications on the first attempt. Here’s what actually causes it.

Periodic updation needs a trigger engine, not a memory

RBI's risk-based cadence — every 2 years for high-risk, 8 for medium-risk, 10 for low-risk customers — combined with the 2025 amendment's three-intimation, three-reminder outreach requirement, means NBFCs need a system that proactively flags customers approaching their update window. Customers whose KYC has lapsed without being refreshed are consistently the single most common finding in RBI inspections.

CKYCR and internal records drift apart

A customer update recorded internally but never pushed to the Central KYC Registry, or a CKYCR update the NBFC's own system never pulls in, creates a divergence that a well-run compliance program treats as an incident to investigate, not a data-quality footnote to ignore.

Tipping off is its own PMLA offense

An NBFC that files a Suspicious Transaction Report must never disclose that filing to the customer, even indirectly. Getting internal communication protocols wrong around a flagged transaction can create a separate compliance violation on top of whatever triggered the STR in the first place.

KYC/AML VS. CKYC

KYC/AML Compliance vs. CKYC Compliance — Where Each Fits

These two services are related but distinct, and a complete program needs both.

KYC/AML compliance

The broader customer due diligence, risk categorization, and suspicious-activity reporting framework — covers who your customers are and what you report to FIU-IND.

CKYC Registry compliance

The specific, more mechanical obligation to upload and retrieve customer KYC records via the Central KYC Registry operated by CERSAI. See our dedicated CKYC Compliance service.

Together

A complete KYC/AML program needs both the judgment-based due diligence and reporting framework, and the registry mechanics that keep records synced across the financial system.

Documents Required

What you'll need to hand us

Company Documents

Process Documents

Our Process

From Program Health Check to Ongoing Monitoring

1

KYC/AML program health check

We review your current policy, confirm your Principal Officer and Designated Director appointments, and check your risk categorization framework.

2

Gap analysis

A full review against RBI's current KYC Master Direction and its 2025 amendments, identifying specific gaps.

3

Policy & trigger system setup

Policy updates, risk categorization refinement, and a periodic updation trigger system built to flag customers proactively.

4

CTR & STR filing

Monthly Cash Transaction Reports, and Suspicious Transaction Reports filed within 7 working days of any identified suspicion.

5

CKYCR sync monitoring

Coordinated with our CKYC Compliance service to keep internal records and the central registry aligned.

6

Sanctions & policy review

Sanctions and PEP list refresh, alongside an annual review of the KYC/AML policy itself.

Get your NBFC's KYC/AML program reviewed before your next inspection →
IF COMPLIANCE LAPSES

What Happens If KYC/AML Compliance Falls Behind

Gaps here carry consequences on two separate fronts — RBI’s supervisory action and FIU-IND’s own enforcement.

RBI inspection findings and potential monetary penalties for KYC deficiencies.

FIU-IND action for missed or late STR/CTR filings, independent of RBI's own enforcement track.

Personal accountability exposure for the named Principal Officer and Designated Director.

Visibility during any future acquisition — a weak KYC/AML program is exactly the kind of gap buyer-side diligence surfaces. See NBFC Due Diligence (Buyer Side).

Eligibility & key criteria

CS Chetna Shoor’s team replies within 4 hours on WhatsApp.






    FAQs

    Frequently Asked Questions

    How often does an NBFC need to update customer KYC?

    RBI’s risk-based framework requires periodic KYC updation every 2 years for high-risk customers, every 8 years for medium-risk customers, and every 10 years for low-risk customers. A 2025 amendment gave low-risk customers whose update had fallen due an extended deadline of one year from the due date or June 30, 2026, whichever is later, to allow NBFCs time to migrate customers to digital re-KYC.

    A Cash Transaction Report (CTR) is filed with FIU-IND for any cash transaction exceeding ₹10 lakh, including a series of smaller, integrally connected cash transactions that together cross that threshold. CTRs are filed monthly, by the 15th of the succeeding month, and the obligation is amount-triggered — no suspicion of wrongdoing is required.

    A Suspicious Transaction Report (STR) is filed with FIU-IND whenever a transaction raises reasonable suspicion of money laundering or financial crime, regardless of the transaction amount — unlike a CTR, which is triggered purely by crossing the ₹10 lakh threshold. STRs must be filed within 7 working days of identifying the suspicion, and the NBFC is legally barred from disclosing the filing to the customer involved.

    Every NBFC’s board-approved KYC/AML policy must name a Principal Officer, responsible for day-to-day AML compliance and FIU-IND reporting, and a Designated Director, who carries board-level accountability for the program. RBI inspections specifically check that these roles are actually functioning, not just named on paper.

    KYC/AML compliance is the broader framework covering customer due diligence, risk categorization, and suspicious-activity reporting to FIU-IND. CKYC compliance is the narrower, more mechanical obligation to upload and keep customer records current in the Central KYC Registry operated by CERSAI. A complete program needs both — see our dedicated CKYC Compliance service for the registry-specific obligations.

    Who Handles This

    CS Chetna Shoor — you'll be working directly with her

    CS Chetna Shoor

    CS Chetna Shoor

    Qualified Company Secretary · ICSI Member · Founder, Expertvuw Management Pvt Ltd

    Chetna has guided NBFC promoters through RBI’s COR process end to end, with particular focus on structuring the Net Owned Fund and business plan so the application survives first-round RBI scrutiny rather than coming back with a query.

    — Chetna