Last Updated: June 2026

KYC Norms Explained — V-CIP, CKYC, PMLA 2002 & AML Compliance

Know Your Customer (KYC) norms form the backbone of Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) frameworks in Indian banking. For the JAIIB PPB examination, KYC is a high-weightage topic that appears in multiple question formats — from the legal framework under PMLA 2002 to the practical aspects of V-CIP (Video-based Customer Identification Process) and periodic updates. This comprehensive guide covers the complete KYC ecosystem including customer due diligence, CKYC registry, suspicious transaction reporting, beneficial ownership identification, and the latest regulatory requirements that every banking professional must master.

What is KYC? Full Form & Definition

KYC stands for "Know Your Customer" (also referred to as "Know Your Client"). It is a set of guidelines and procedures mandated by the RBI under the Prevention of Money Laundering Act (PMLA), 2002 and RBI Master Direction on KYC (2016, updated periodically). KYC requires financial institutions to verify the identity and address of all customers at the time of account opening and periodically thereafter. The KYC framework has four key pillars: Customer Acceptance Policy (CAP), Customer Identification Procedures (CIP), Monitoring of Transactions, and Risk Management.

The fundamental objective of KYC norms is to prevent banks from being used — intentionally or unintentionally — for money laundering, terrorist financing, or other financial crimes. KYC enables banks to understand their customers better, assess risk profiles, and detect unusual or suspicious activities early. Non-compliance with KYC norms can attract severe penalties including monetary fines, restrictions on business operations, and even cancellation of banking licenses in extreme cases.

Legal Framework — PMLA 2002

The Prevention of Money Laundering Act (PMLA) was enacted in 2002 and came into effect on July 1, 2005. It is the primary legislation governing anti-money laundering compliance in India. Under PMLA, the RBI issues KYC directions that all Regulated Entities (REs) — including banks, NBFCs, payment banks, and cooperative banks — must follow. The Act was significantly amended in 2009, 2012, and 2019 to align with the Financial Action Task Force (FATF) recommendations.

Key provisions of PMLA relevant to KYC include: Section 12 mandates reporting entities to maintain records of transactions and verify customer identity; Section 12A requires reporting of cash transactions and suspicious transactions to the Financial Intelligence Unit (FIU-IND); Section 13 empowers the Director of FIU to call for records and impose penalties; and Section 4 prescribes punishment for money laundering with rigorous imprisonment of 3 to 7 years (extendable to 10 years in certain cases).

V-CIP (Video-based Customer Identification Process)

V-CIP was introduced by the RBI in January 2020 to enable remote, paperless, and consent-based KYC verification through video interaction. This was a landmark reform that allowed banks to onboard customers digitally without requiring physical presence. V-CIP involves a real-time video interaction between the bank's trained official and the customer, during which the official verifies the customer's identity documents (Aadhaar, PAN, etc.) through a live video call.

Key features of V-CIP include: (a) The process must be seamless, secure, and end-to-end encrypted; (b) The customer's live photograph is captured during the video call along with the Aadhaar XML or Digilocker verification; (c) Geo-tagging and IP address logging are mandatory; (d) The entire video interaction must be recorded and stored for audit purposes; (e) The bank official conducting V-CIP must be specifically trained and authorized; (f) V-CIP can be used for both individual and proprietary firm accounts but NOT for trusts, companies, or partnership firms.

Periodic KYC Update Requirements

The RBI mandates that banks must periodically update the KYC records of all existing customers based on their risk categorization. The frequency of periodic updates is determined by the customer's risk profile:

Risk CategoryUpdate FrequencyExamples
High RiskEvery 2 yearsPEPs, non-face-to-face customers, high-value accounts, customers from high-risk jurisdictions
Medium RiskEvery 8 yearsStandard salaried individuals, regular business accounts
Low RiskEvery 10 yearsPensioners, government employees, small accounts under PMJDY

Banks cannot restrict account operations solely on the grounds of KYC non-updation without giving adequate notice (at least 30 days). The RBI has also clarified that periodic KYC updates can be done through digital channels including net banking, mobile banking, and V-CIP, without requiring the customer to visit the branch physically.

CKYC (Central KYC) Registry

Central KYC (CKYC) is a centralized repository of KYC records maintained by the Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI). The CKYC system was introduced to eliminate the need for customers to undergo KYC verification repeatedly with different financial institutions. Once a customer's KYC is done by one financial institution and uploaded to the CKYC registry, other institutions can download and use the same KYC records, thereby reducing duplication and customer inconvenience.

Every financial institution must generate a 14-digit CKYC Identifier (KIN — KYC Identification Number) for each customer and upload the KYC data to the CERSAI registry within 10 days of completing KYC. The CKYC number is linked to the customer's identity proof and remains valid across all financial institutions — banks, insurance companies, mutual funds, and intermediaries registered with SEBI.

Transaction Reporting — CTR & STR

Under PMLA and RBI's KYC directions, banks must file certain reports with the Financial Intelligence Unit-India (FIU-IND):

Report TypeThreshold / TriggerFiling Timeline
CTR (Cash Transaction Report)Cash transactions ≥ ₹10 lakh (single or aggregate in a month)By 15th of the succeeding month
STR (Suspicious Transaction Report)Any transaction that appears suspicious regardless of amountWithin 7 days of suspicion being confirmed
CCT (Counterfeit Currency Report)All counterfeit notes detectedBy 15th of the succeeding month
NTR (Non-Profit Transaction Report)Transactions of non-profit organizations ≥ ₹10 lakhBy 15th of the succeeding month

Banks must maintain records of all transactions (including CTRs and STRs) for a minimum period of 5 years from the date of the transaction. The STR filing is particularly important — banks must not tip off the customer that an STR has been filed, and the 7-day filing timeline starts from the date when the transaction is confirmed as suspicious by the Principal Officer of the bank.

Beneficial Ownership

Under the RBI's KYC framework, banks must identify the beneficial owners of all non-individual accounts (companies, trusts, partnerships). A beneficial owner is the natural person who ultimately owns or controls a customer or on whose behalf a transaction is being conducted. The identification thresholds are:

  • Companies: Any natural person holding more than 25% of shares or voting rights, or exercising control through other means
  • Partnership Firms: Any natural person with more than 15% of capital or profits
  • Trusts: The author/settlor, trustee, and beneficiaries with more than 15% interest
  • Unincorporated Associations: Persons with more than 15% of the property or capital

Key Points for JAIIB Exam

  • • KYC is mandated under PMLA 2002 and RBI Master Direction on KYC
  • • CTR threshold: cash transactions of ₹10 lakh or more in a month
  • • STR must be filed within 7 days of confirming suspicion
  • • Periodic KYC update: High risk — 2 years, Medium — 8 years, Low — 10 years
  • • V-CIP enables video-based remote KYC without physical presence
  • • CKYC number is a 14-digit identifier maintained by CERSAI
  • • Records must be maintained for 5 years after transaction/account closure
  • • Beneficial owner threshold for companies: 25% shareholding or voting rights
  • • Banks must NOT tip off customers about STR filing

Sample MCQs for JAIIB PPB

Q1. As per RBI's KYC norms, periodic KYC update for high-risk customers must be done every:

  • (a) 1 year
  • (b) 2 years
  • (c) 5 years
  • (d) 10 years

Answer: (b) — High-risk customers require KYC update every 2 years. Medium-risk customers need updates every 8 years, and low-risk customers every 10 years.

Q2. A Suspicious Transaction Report (STR) must be filed with FIU-IND within:

  • (a) 3 days of the transaction
  • (b) 7 days of confirming the suspicion
  • (c) 15 days of the transaction
  • (d) 30 days of the transaction

Answer: (b) — STR must be filed within 7 days of the date when the transaction is confirmed as suspicious by the Principal Officer. The bank must not alert or tip off the customer about the STR filing.

Q3. The threshold for filing a Cash Transaction Report (CTR) with FIU-IND is:

  • (a) ₹5 lakh in a month
  • (b) ₹10 lakh in a month
  • (c) ₹50 lakh in a month
  • (d) ₹1 crore in a month

Answer: (b) — CTR must be filed for all cash transactions of ₹10 lakh and above (single or aggregate across all accounts in a month). The report must be filed with FIU-IND by the 15th of the succeeding month.