Banking Compliance Function 2026: FATCA, CRS & Risk Guide

BCP By Ashish Jain · IIBF STORE Editorial · 15 June 2026 · Updated 29 Jul 2026 · 14 min read · 24 views
Banking Compliance Function 2026: FATCA, CRS & Risk Guide

The banking compliance function is the independent second line of defence that keeps a bank aligned with every law, RBI guideline and internal code that governs its business. For anyone preparing for the IIBF Banking Compliance Professional (BCP) certification in 2026, this is not a peripheral chapter — it is the very heart of the syllabus, and examiners reward candidates who can explain not just what compliance does, but why its independence matters.

This guide walks you through the role of the compliance department and the Chief Compliance Officer, how compliance risk is identified and controlled, how FATCA and CRS reporting actually works inside an Indian bank, and how a genuine compliance culture protects both the institution and its customers. Use it as a study companion, revise the bullet checklists before your exam, and confirm every time-sensitive detail against the official IIBF notification.

Banking compliance function and FATCA CRS risk management study guide for BCP
The banking compliance function sits at the centre of governance, FATCA/CRS reporting and risk control.

Key takeaways

  • The banking compliance function is an independent, enterprise-wide unit in the second line of defence, distinct from internal audit.
  • The Chief Compliance Officer (CCO) heads it with a Board-approved appointment, a fixed minimum tenure under RBI norms and direct access to the Board.
  • Compliance risk is managed as a separate risk category using tools such as the Risk Control Self Assessment (RCSA) and a breach register.
  • FATCA (a US law applied through an IGA) and CRS (the OECD global standard) drive cross-border tax-transparency reporting via Form 61B.
  • Regulatory returns, Risk-Based Supervision under SPARC, the DPDP Act and a strong compliance culture complete the BCP picture.

What the banking compliance function actually does

The banking compliance function is best understood through the three-lines-of-defence model. The first line is the business itself, which owns and manages its own risks day to day. The second line — where compliance sits — independently identifies, assesses, advises on, monitors and reports on the bank's compliance risk. The third line, internal audit, then independently tests whether all those controls actually work.

RBI guidance treats compliance as an enterprise-wide function rather than a back-office formality. To do its job, the function must be adequately staffed, sufficiently senior and free from conflicts of interest, so that it can challenge the business without fear or favour. The moment a compliance team reports to the very people whose work it is meant to scrutinise, its independence collapses — which is exactly why the reporting lines are protected.

In practice, the function maintains the bank's compliance policy, builds and updates the regulatory universe of applicable laws and circulars, advises senior management, runs monitoring and testing programmes, and escalates breaches. It is the institutional memory for "what the rules require" and the early-warning system for "where we might be falling short".

The Chief Compliance Officer and reporting lines

The Chief Compliance Officer (CCO) heads the compliance function and is the single most examinable figure in the BCP syllabus. Under RBI norms, the CCO is appointed for a fixed minimum tenure, and the Board or its committee approves the appointment, removal and remuneration — a deliberate design choice that stops line management from quietly sidelining an inconvenient compliance officer.

Two features protect the CCO's independence above all others:

  • A direct reporting line to the Managing Director or CEO, so compliance findings travel straight to the top.
  • Unfettered access to the Board, so that uncomfortable findings cannot be filtered or suppressed before they reach the directors.

The CCO's core responsibilities typically include maintaining the compliance policy and the regulatory universe, advising senior management on compliance laws and standards, putting in place monitoring, testing and escalation mechanisms for breaches, and reporting periodically to the Board on the bank's overall compliance health. For governance questions like these, working through the structured papers on the BCP mock tests is one of the fastest ways to lock the concepts in.

Exam tip: If a question contrasts compliance with internal audit, remember the line: compliance is the second line that advises and monitors in real time, while internal audit is the third line that independently tests after the fact. They are partners, not duplicates.

Compliance risk and how it is managed

For the banking compliance function, compliance risk has a precise definition worth memorising: it is the risk of legal or regulatory sanctions, material financial loss, or reputational damage that a bank may suffer when it fails to comply with applicable laws, regulations, codes of conduct and standards of good practice. Because a single lapse can trigger penalties, business restrictions and a loss of customer trust, compliance risk is managed as a distinct category — sitting alongside credit, market and operational risk rather than being folded into them.

The function maps the entire regulatory universe and assigns clear ownership for each obligation. The core tool is the Risk Control Self Assessment (RCSA), in which business units systematically identify their compliance obligations, rate the inherent risk, document the controls in place, and assess the residual risk that remains. Where controls are weak, the RCSA produces action plans with named owners and firm deadlines.

A practical, exam-ready compliance risk programme usually includes:

  • A board-approved compliance policy reviewed at least annually.
  • An annual compliance risk assessment feeding a risk-based monitoring plan.
  • Compliance testing of high-risk processes such as KYC, AML and customer charges.
  • A breach register with root-cause analysis and timely escalation to the Board.

Inherent risk vs residual risk — a quick comparison

Candidates often blur these two terms. The table below fixes the distinction in one glance.

Aspect Inherent risk Residual risk
Meaning Risk before any controls are applied Risk that remains after controls
Driven by Nature and volume of the activity Strength and design of controls
RCSA action Identify and rate the exposure Accept, mitigate further, or escalate
Owner Business unit (first line) Business unit, monitored by compliance

To see how these governance ideas connect to wider risk and regulation topics, the Banking Compliance Professional subject hub ties the modules together, and the complete BCP guide to the compliance function in banks expands each pillar in depth.

FATCA and CRS reporting obligations

Cross-border tax transparency is one of the heaviest workloads handled by the banking compliance function, and FATCA and CRS are favourite exam territory. The Foreign Account Tax Compliance Act (FATCA) is a US law, implemented in India through an Inter-Governmental Agreement (IGA), that requires financial institutions to identify accounts held by US persons and report them to the tax authorities. The Common Reporting Standard (CRS), developed by the OECD, extends the same idea globally, allowing India to automatically exchange financial-account information with many partner jurisdictions.

FATCA and CRS account due diligence and Form 61B reporting flow in Indian banks
FATCA/CRS due diligence builds directly on the bank's existing KYC foundation.

In India, the legal machinery sits in Rules 114F to 114H of the Income Tax Rules. Reporting financial institutions must apply due diligence to classify account holders, obtain a self-certification of tax residency, and file the prescribed information through Form 61B with the Income Tax Department, which then routes it to the relevant foreign authority. Because the precise reporting thresholds and timelines are updated from time to time, always confirm the current requirement against the latest official notification.

The practical steps a bank follows are:

  1. Collecting a self-certification of tax residency at account opening.
  2. Screening for US indicia and other foreign tax-residency markers.
  3. Identifying reportable accounts and the controlling persons of entities.
  4. Filing Form 61B annually and retaining the supporting records.

Crucially, FATCA and CRS due diligence is not a standalone process — it builds directly on the bank's existing KYC framework, reusing the same identity and residency data already collected. For a deeper treatment, see the dedicated guide on the compliance function, FATCA, CRS and RBI expectations, and the broader walkthrough of regulatory reporting under India's RBI and FIU framework.

Regulatory reporting, RBI supervision and data protection

Beyond FATCA and CRS, the banking compliance function oversees the steady stream of regulatory returns that banks file with the RBI, largely through centralised platforms such as XBRL and CIMS. Accurate and timely returns are themselves a compliance obligation, so the function governs the entire filing process — not just the content of each return, but the controls that ensure it is correct.

On the supervisory side, the RBI has moved firmly towards Risk-Based Supervision (RBS) under the SPARC framework. Instead of applying a uniform checklist to every institution, each bank receives a risk score, and supervisory attention is calibrated to its risk profile. The message for candidates is simple: a strong compliance function and timely regulatory reporting directly improve a bank's supervisory outcomes.

Data protection has also become inseparable from compliance. Under the Digital Personal Data Protection (DPDP) Act, banks act as data fiduciaries and must obtain consent, limit data use to stated purposes, secure personal data and report breaches — all while observing RBI directions on IT and cyber governance. The compliance team now watches privacy obligations alongside traditional banking rules.

Effective handling of regulatory reporting and supervision rests on:

  • A return-filing calendar with maker-checker controls and sign-offs.
  • Prompt, complete responses to RBI inspection observations and risk-assessment reports.
  • Consent and purpose-limitation controls aligned to the DPDP Act.
  • Coordinated breach notification to the regulator and to affected customers.

A practical study plan for the BCP certification

Knowing the syllabus is one thing; passing the exam efficiently is another. Here is a focused, four-week study rhythm that mirrors how the banking compliance function is actually examined:

  1. Week 1 — Governance core. Master the three lines of defence, the CCO's appointment and reporting lines, and the difference between compliance and internal audit. These appear in almost every paper.
  2. Week 2 — Risk machinery. Drill the compliance-risk definition, the RCSA cycle, inherent vs residual risk, and the breach register. Practise framing them in your own words.
  3. Week 3 — FATCA, CRS and reporting. Learn Rules 114F–114H, Form 61B, US indicia and self-certification, then layer on XBRL/CIMS returns and SPARC supervision.
  4. Week 4 — Culture, DPDP and revision. Cover compliance culture and the DPDP Act, then spend most of your time on full-length mocks and active recall.

Throughout, alternate reading with testing. Reinforce vocabulary using the BCP matching games, sit timed papers on the mock-test platform, and browse every explainer in one place through the full library of BCP guides. For the certification roadmap and the exam-window context, the BCP certification start-here guide sets out the path — just verify the exact exam date on the official IIBF notification.

Common mistakes candidates make

Examiners see the same avoidable errors year after year. Steer clear of these and you will already be ahead of most of the room:

  • Confusing compliance with audit. They are separate lines of defence with different jobs; never describe them as the same function.
  • Forgetting why the CCO's tenure is fixed. The protected tenure and Board access exist to guarantee independence — that "why" is often the marked point.
  • Mixing up FATCA and CRS. FATCA is US-specific via an IGA; CRS is the OECD's multilateral standard. Both flow through Form 61B in India.
  • Treating data protection as "out of scope". The DPDP Act is squarely a compliance obligation for banks as data fiduciaries.
  • Memorising figures that change. Thresholds, dates and tenures get updated — learn the framework, and confirm specifics against the latest IIBF and RBI notifications.

Building a strong compliance culture

Rules and registers only work when people choose to follow them, which is why compliance culture is the final pillar of the certification — and a recurring theme in the banking compliance function syllabus. Culture starts with a clear tone from the top: the Board and senior management visibly support the compliance function, allocate resources and refuse to override controls for short-term gains.

It is reinforced through training, transparent escalation channels, and a fair consequence framework that rewards integrity and addresses misconduct consistently. A healthy culture also depends on protected whistle-blowing, so staff can raise concerns without fear of retaliation, and on aligning incentives so that sales targets never quietly encourage mis-selling or KYC shortcuts. When compliance is treated as everyone's responsibility rather than a back-office formality, the bank reduces regulatory risk and strengthens customer trust at the same time. You can deepen this mindset with the guide to the compliance function and CCO role on the blog.

Frequently Asked Questions

What is the role of the Chief Compliance Officer in a bank?

The Chief Compliance Officer heads the independent compliance function and owns the compliance policy and the regulatory universe. The CCO advises senior management, monitors and tests for breaches, and reports compliance risk directly to the Board. RBI norms give the CCO a fixed minimum tenure and unfettered Board access precisely to protect that independence.

How is compliance risk different from operational risk?

Compliance risk is the risk of legal or regulatory sanctions, financial loss or reputational damage from failing to follow laws, regulations and codes. Operational risk is broader, covering losses from failed processes, people, systems or external events. Compliance risk is managed through dedicated tools such as the RCSA, compliance testing and a breach register.

What is the difference between FATCA and CRS?

FATCA is a US law applied in India through an Inter-Governmental Agreement, focused on identifying and reporting accounts held by US persons. CRS is the OECD's global standard that lets India automatically exchange financial-account information with many partner countries. In India, both rely on self-certification of tax residency and reporting through Form 61B.

What does Risk-Based Supervision mean for banks?

Under the SPARC framework, the RBI assesses each bank, assigns a risk score, and directs supervisory attention according to that risk profile rather than using a uniform checklist. Banks with a higher risk score receive more intensive supervision. A strong compliance function and timely regulatory reporting therefore improve supervisory outcomes directly.

How do FATCA and CRS connect to a bank's KYC process?

FATCA and CRS due diligence builds directly on the existing KYC framework, reusing the identity and tax-residency data collected at account opening. The bank adds a self-certification of tax residency and screens for US indicia and other foreign-residency markers. This avoids duplicating data collection while satisfying the cross-border reporting rules.

Is the DPDP Act part of the banking compliance syllabus?

Yes. Under the Digital Personal Data Protection Act, banks act as data fiduciaries and must obtain consent, limit data use to stated purposes, secure personal data and report breaches. The compliance team now monitors these privacy obligations alongside traditional banking rules, so expect DPDP themes in the BCP certification.

Conclusion

The banking compliance function ties together independent governance under the Chief Compliance Officer, disciplined compliance-risk management through the RCSA, rigorous FATCA and CRS reporting, accurate regulatory returns under SPARC supervision, DPDP-aligned data protection, and a genuine compliance culture. Master these themes and you master exactly what the IIBF Banking Compliance Professional certification sets out to reward in 2026. Study with intent, test relentlessly, and you will walk into the exam hall ready. For primary-source confirmation of any figure or date, always check the official IIBF website.

Related Guides

📚 Free Learning Sessions resources — connect & crack your exam

💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.

📱 Study on the go — get our iOS & Android app at iibf.store/app.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading