🪢 Happy Raksha Bandhan!

The Compliance Function in Banks: RBI Framework & FATCA Guide 2026

BCP By Ashish Jain · IIBF STORE Editorial · 29 June 2026 · Updated 09 Aug 2026 · 8 min read · 144 views हिन्दी में पढ़ें
The Compliance Function in Banks: RBI Framework & FATCA Guide 2026

compliance function

The compliance function is the backbone of a well-governed bank. It is the independent line of defence that keeps a bank on the right side of the law, RBI directions, and global standards. For anyone preparing for the IIBF Certificate in Banking Compliance Professional (BCP), understanding how this function is structured, who runs it, and how it interacts with frameworks such as PMLA, FATCA and CRS is non-negotiable. This guide breaks the subject down the way the 2026 exam expects you to know it.

A bank handles public money, so regulators demand that compliance is not an afterthought bolted on to the business but an embedded, board-monitored discipline. The Reserve Bank of India formalised this thinking in its circular on "Compliance Function and Role of Chief Compliance Officer (CCO)" dated 11 September 2020, which remains the master reference for the Indian banking compliance function today.

Below we walk through the RBI framework, the three-lines-of-defence model, the statutory obligations under anti-money-laundering law, and the cross-border reporting regimes of FATCA and CRS that every Indian bank now operates under.

What the Compliance Function Actually Does

The compliance function in a bank is an independent unit that identifies, assesses, advises on, monitors and reports on the bank's compliance risk — the risk of legal or regulatory sanctions, material financial loss, or reputational damage arising from a failure to comply with laws, regulations, codes of conduct and standards of good practice.

Its core responsibilities include:

  • Advisory: guiding the board and senior management on applicable laws, RBI directions, and the compliance implications of new products.
  • Monitoring and testing: conducting compliance reviews, tracking regulatory changes, and ensuring corrective action on supervisory observations.
  • Regulatory liaison: acting as the single point of contact for RBI inspections, Risk Assessment Reports (RAR), and the timely submission of returns.
  • Education: building a compliance culture through staff training so that line managers own first-level compliance.

Crucially, the function must be independent of the business it monitors. It cannot have any business targets, and its staff should not be placed in roles that create conflicts of interest. Independence, adequate stature, authority and direct access to the board are the four pillars RBI insists upon. Candidates strengthening their fundamentals can pair this with the broader syllabus on the CAIIB course, where bank management and risk topics overlap heavily with compliance.

The RBI Compliance Framework and the Chief Compliance Officer

The 2020 RBI framework made the appointment of a Chief Compliance Officer (CCO) mandatory for all scheduled commercial banks. The CCO sits at the apex of the compliance function and reports functionally to the board's Audit Committee or a dedicated committee, with the MD & CEO providing administrative oversight.

Key features of the framework you must memorise for the exam:

  • Seniority: the CCO should be a senior executive, ideally a rank below the Executive Director, and not below two levels from the CEO.
  • Tenure: a minimum fixed tenure of three years; premature transfer needs board approval and prior intimation to RBI.
  • Selection: appointment through a well-defined, board-approved process; RBI must be informed of the appointment and any change.
  • Independence: the CCO must have no reporting relationship with business verticals and no responsibility for any business target.
  • Authority: the right to access any information, attend relevant management committees, and escalate directly to the board.

The framework is built on the globally accepted three lines of defence model. The first line is the business unit that owns and manages its own risks. The second line is the compliance function (alongside risk management), which sets standards and monitors. The third line is internal audit, which independently assures the board that the first two lines are working. You can cross-check current RBI master directions and circulars on the official Reserve Bank of India website, and keep an eye on policy moves through our IIBF news tracker.

Three lines of defence model showing business, compliance and audit
The three lines of defence: business ownership, independent compliance, and internal audit assurance.

Statutory Anchors: PMLA, KYC and AML Compliance

A large part of the day-to-day compliance function revolves around anti-money-laundering (AML) and Know Your Customer (KYC) obligations. The governing law is the Prevention of Money-Laundering Act, 2002 (PMLA), operationalised through the PML (Maintenance of Records) Rules and RBI's Master Direction on KYC.

Under this regime, banks must:

  • Carry out Customer Due Diligence (CDD) at onboarding and Enhanced Due Diligence (EDD) for high-risk customers, PEPs and complex structures.
  • Undertake risk categorisation of customers as low, medium or high risk and review it periodically.
  • Maintain records for five years and file reports with the Financial Intelligence Unit-India (FIU-IND) — Cash Transaction Reports (CTR), Suspicious Transaction Reports (STR), Counterfeit Currency Reports (CCR) and Non-Profit Organisation Transaction Reports (NTR).
  • Appoint a Principal Officer and a Designated Director responsible for AML reporting.

The exam loves precise thresholds and timelines, so it pays to drill them. A CTR covers cash transactions above ₹10 lakh (or integrally connected transactions in a month), while an STR must be filed within seven working days of establishing suspicion. Practising these numbers under timed conditions on our mock test series is one of the fastest ways to lock them in, and a quick round on the terms match game helps the abbreviations stick.

Cross-Border Reporting: FATCA and CRS

Modern compliance is global. Two regimes dominate cross-border tax transparency and form a guaranteed part of the BCP syllabus: FATCA and CRS.

FATCA — the Foreign Account Tax Compliance Act — is a US law that requires foreign financial institutions to identify accounts held by US persons and report them. India signed an Inter-Governmental Agreement (IGA Model 1) with the United States in 2015, so Indian banks report this information to the Central Board of Direct Taxes (CBDT), which then exchanges it with the US IRS.

CRS — the Common Reporting Standard — developed by the OECD, is the multilateral equivalent. India is a signatory to the Multilateral Competent Authority Agreement, enabling automatic exchange of financial account information with over 100 jurisdictions. Both regimes are implemented domestically through Rules 114F to 114H of the Income-tax Rules.

For the compliance team this means:

  • Self-certification: obtaining a tax-residency self-certification from every account holder at onboarding.
  • Due-diligence: applying separate procedures for pre-existing versus new, and individual versus entity accounts.
  • Reporting: filing Form 61B annually with the Income-tax Department for reportable accounts.
FATCA and CRS cross-border reporting flow between banks, CBDT and foreign authorities
How FATCA and CRS route account information from banks through CBDT to foreign tax authorities.

A failure in FATCA/CRS due diligence is a direct compliance breach with penalties under the Income-tax Act, which is why the compliance function treats self-certification gaps as a high-priority monitoring item.

Building a Compliance Culture

Frameworks and forms only work when the wider organisation believes in them. RBI repeatedly stresses that compliance is the responsibility of every employee, with the dedicated function acting as the second line, not the sole owner. A strong culture means clear escalation paths, a no-blame approach to self-reporting genuine errors, board-level tone-setting, and consequence management for wilful breaches. Compliance must also keep pace with digital banking, fintech partnerships and outsourcing — areas where RBI has issued specific directions in recent years. To anchor the fundamentals before tackling advanced compliance, many candidates first revise the JAIIB course and read related explainers on the IIBF blog.

Frequently Asked Questions

Is the Chief Compliance Officer mandatory for all banks?

Yes. Under RBI's September 2020 circular, every scheduled commercial bank must appoint a Chief Compliance Officer with a minimum three-year tenure. The CCO heads the compliance function, reports to the board's audit committee, holds no business targets, and must be informed to RBI on appointment or any change.

What is the difference between FATCA and CRS?

FATCA is a US law targeting US-person accounts, exchanged bilaterally under an India-US IGA. CRS is the OECD's multilateral standard for automatic exchange among 100-plus jurisdictions. Both are implemented in India through Income-tax Rules 114F-114H, and banks report reportable accounts annually to CBDT using Form 61B.

What are the three lines of defence in compliance?

The first line is the business unit that owns and manages its risks daily. The second line is the compliance and risk-management functions that set standards and independently monitor. The third line is internal audit, which assures the board that the first two lines operate effectively. The model underpins RBI's compliance framework.

Which reports does a bank file with FIU-IND under PMLA?

Under the Prevention of Money-Laundering Act, 2002, banks file Cash Transaction Reports for cash above ₹10 lakh, Suspicious Transaction Reports within seven working days of forming suspicion, Counterfeit Currency Reports, and Non-Profit Organisation Transaction Reports. A Principal Officer is responsible for filing these with the Financial Intelligence Unit-India.

Final Takeaways

The compliance function is no longer a box-ticking exercise — it is an independent, board-supervised guardian of a bank's licence to operate, anchored by RBI's CCO framework, PMLA-driven AML obligations, and the FATCA/CRS reporting regimes. Master the structure, the timelines and the thresholds, and you will handle the BCP paper with confidence. Ready to test yourself? Take a full-length IIBF mock test now and turn this theory into exam marks.

Free download · no sign-up

Free Revision PDFs — One-Liners & True/False

Printable last-minute revision sheets for The Compliance Function in Banks: RBI Framework & FATCA Guide 2026: 20 quick-fire one-liners and 20 true/false questions, each with answers & explanations. Free to download and share.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading