🪢 Happy Raksha Bandhan!

KYC AML Chapter 2 (Module B): Customer Identification, Beneficial Ownership &

By Ashish Jain · IIBF STORE Editorial · 18 June 2026 · Updated 07 Aug 2026 · 11 min read · 42 views
KYC AML Chapter 2 (Module B): Customer Identification, Beneficial Ownership &

Ever wondered why your bank asks for a mountain of documents just to open a simple savings account? Or why one customer breezes through verification. Another faces extra questions and a second visit?

You are not alone. And the answer sits at the heart of KYC AML Chapter 2 of Module B. This single chapter quietly powers every account opening.

Every onboarding form, and every compliance check in Indian banking.

In this 2026 guide. We break down KYC AML Chapter 2 the way a senior compliance trainer would: clearly. Completely, and with exam-ready structure.

By the end you will understand who a customer is. Who really owns an account. How risk is scored, and how often KYC must be refreshed.

This is essential reading whether you work in account opening. Compliance. Or risk.

And especially if you are preparing for JAIIB. CCP, or the IIBF KYC AML certification.

Key Takeaways

  • KYC (Know Your Customer) exists to identify. Verify customers and stop financial crime.
  • A beneficial owner is the real person who ultimately owns or controls an entity. Identified using fixed percentage thresholds.
  • Customer Due Diligence (CDD) comes in three flavours: Simplified, Standard, and Enhanced.
  • Customers are placed in Low. Medium, or High risk categories, which decides how often KYC is updated.
  • Always verify the latest figures and timelines on the official IIBF notification. As RBI Master Directions are revised periodically.

Why KYC AML Chapter 2 Matters for Every Banker

Banks are the gatekeepers of the financial system. If a criminal can open an account easily. They can launder money. Fund illegal activity, and damage the trust that banking runs on. KYC AML Chapter 2 is the rulebook that prevents exactly that.

This chapter is not just theory for an exam. It maps directly to what you do at the branch counter and on the compliance desk. The same concepts appear again and again in mock tests and in real onboarding decisions. Master it once, and both your exam score and your daily work get easier.

What Is Customer Identification and Why Is It Important?

KYC stands for Know Your Customer. The core goal is simple: identify. Verify every customer so the bank knows exactly who it is dealing with. This is the first line of defence against fraud. Money laundering, and terror financing.

The Customer Identification Procedure (CIP) is not limited to individuals. It covers a wide range of entities. Each with its own document set:

  • Individuals walking in to open personal accounts
  • HUFs (Hindu Undivided Families)
  • Companies registered under company law
  • Partnership firms
  • Trusts and NGOs
  • Government bodies and their agents

The takeaway: no customer type is exempt. Each category simply has a tailored verification path.

Who Is a Beneficial Owner? (The Concept Examiners Love)

A beneficial owner is the natural person who ultimately owns or controls an entity. Or on whose behalf a transaction is conducted. Behind a company.

A trust. Or a partnership there is always a real human pulling the strings. And the bank must identify that person.

This stops criminals from hiding behind shell companies and complex structures. The rules use fixed ownership thresholds to decide who counts as a beneficial owner.

Beneficial Ownership Thresholds at a Glance

Entity Type Beneficial Owner Threshold
Company More than 25% of shares or controlling ownership interest
Partnership Firm More than 15% of capital or profits
Trust More than 15% beneficial interest
Association of Persons (AOP) More than 15% share in profit or property

Remember the simple memory hook: 25% for companies, 15% for everyone else. These percentages are favourite exam questions. So commit them to memory. Confirm them against the latest official IIBF notification before exam day.

How to Verify a Customer's Identity

Verification means matching the customer to genuine, independent proof. Banks rely on a mix of officially valid documents (OVDs). Supporting evidence. The most common include:

  • PAN Card, Aadhaar, and Passport for identity
  • GST Certificate and MSME proof for businesses
  • Income proof such as Income Tax Returns (ITR) and salary slips
  • Transaction pattern monitoring to confirm activity matches the declared profile

Verification is not a one-time photo match. Banks keep watching how an account behaves. Because a sudden mismatch between declared income. Actual transactions is a classic red flag.

When Should KYC Be Carried Out?

KYC is not only an account-opening ritual. It is triggered at several points across the customer relationship. KYC is mandatory in the following situations:

  • At the time of opening any account
  • During walk-in financial transactions above the prescribed limit
  • Whenever there is a suspicious or fraudulent case
  • On sale of insurance. Mutual funds. Or prepaid instruments above the prescribed value (commonly cited as above 500. But confirm the current limit on the latest official IIBF notification)
  • For cross-border transactions, regardless of the amount involved

The pattern is clear: any moment that introduces new risk into the relationship reopens the KYC requirement.

Documents Required for KYC by Entity Type

Different customers need different paperwork. Here is a practical breakdown a branch officer would use during onboarding:

  • Individuals: PAN, Aadhaar, recent photograph, and address proof
  • Companies: Certificate of Incorporation, Memorandum of Association (MOA), and GSTIN
  • Trusts: Trust deed, list of trustees, and PAN
  • Foreign Nationals: Passport. Valid visa, and an embassy or mission letter where required
  • Minors: Guardian's KYC plus the minor's Birth Certificate

For a deeper walkthrough of related onboarding topics, our free guides cover document checklists in detail.

Relaxed KYC Norms: Where Banking Makes Life Easier

Regulators understand that strict rules must not block genuine customers. So several relaxations exist to reduce friction without weakening safety:

  • A single OVD can be accepted for an entire family in defined cases
  • Existing KYC can be reused when the same customer opens another account
  • Self-declaration is accepted for a change of address
  • Third-party verification is permitted for NRIs where physical presence is impractical

These norms balance compliance with convenience. A theme examiners frequently test through scenario questions.

Customer Risk Scoring and Categorization

Not every customer carries the same level of risk. KYC AML Chapter 2 requires banks to score each customer. Place them in a risk bucket. Risk scoring is based on four key dimensions:

  1. Customer profile such as income, location, and industry
  2. Product being used by the customer
  3. Delivery channel through which services are accessed
  4. Transaction patterns observed over time

The output of this scoring is a risk category that drives every later decision. From the depth of due diligence to how often KYC is refreshed.

Product and Delivery Channel Risk

Products and channels themselves carry inherent risk. The table below shows how typical offerings are commonly classified.

Risk Level Typical Products
Low Risk Fixed Deposits, salary accounts, home loans
Medium Risk Credit cards, demand loans
High Risk Overdrafts, cash credit, crypto-linked dealings, prepaid wallets

Higher-risk products demand closer scrutiny. Because they offer more ways to move funds quickly and opaquely.

The Three Types of Customer Due Diligence (CDD)

Customer Due Diligence (CDD) is the process of checking. Monitoring customers in proportion to their risk. There are three levels. And matching the right level to the right customer is a core skill for the exam.

  1. Simplified CDD applies to low-risk customers. It needs minimal documents and often comes with a transaction limit.
  2. Standard CDD applies to medium-risk customers and represents the normal. Full verification process.
  3. Enhanced CDD (EDD) applies to high-risk customers such as Politically Exposed Persons (PEPs). NRIs, and high-cash clients. It involves deeper checks, senior approval, and closer ongoing monitoring.

Screening, Field Verification, and Watchlists

Before and during onboarding. Banks screen customers against official watchlists to catch sanctioned or flagged individuals. Screening typically references:

  • FATF (Financial Action Task Force) lists
  • United Nations (UN) sanctions lists
  • RBI alerts and circulars
  • FIU (Financial Intelligence Unit) watchlists

Where doubt remains. Banks carry out field verification through a home or office visit. Or via digital verification tools. To confirm the customer genuinely exists at the stated address.

Periodic KYC Updates: How Often Must KYC Be Refreshed?

KYC is a living obligation, not a one-time event. The update frequency depends directly on the customer's risk category. The widely taught timelines are summarised below.

Risk Level Periodic Update Frequency
High Risk Every 2 years
Medium Risk Every 8 years
Low Risk Every 10 years

Beyond the calendar. KYC must also be updated on a trigger event, including when:

  • A dormant account becomes active again
  • A customer becomes a PEP
  • A Suspicious Transaction Report (STR) is filed or suspicious activity is detected

Because these timelines can change. Always cross-check the exact update cycle on the latest official IIBF notification before relying on it in the exam.

PAN Submission and the Cost of Non-Compliance

PAN or Form 60 is mandatory for the relationship. If a customer refuses to provide it. The consequence is serious: the account can be suspended or closed.

Limited exceptions exist. For example on genuine medical or old-age grounds. But only when the bank applies proper monitoring. Compliance here is non-negotiable.

A Practical Study Plan for KYC AML Chapter 2

Knowing the content is half the battle. Here is a simple. High-yield way to actually retain KYC AML Chapter 2 for your exam:

  1. Memorise the numbers first. Beneficial ownership thresholds (25% and 15%) and the update frequencies (2. 8, 10 years) are the most commonly tested facts.
  2. Group concepts in threes. Three CDD types. Three risk levels are easy to recall as paired sets.
  3. Use scenario practice. Read a customer situation and decide the risk level and CDD type. This mirrors how IIBF frames questions.
  4. Attempt timed mock tests. Repetition under time pressure locks the rules into memory.
  5. Revise with a one-page sheet. Condense every table in this guide onto a single revision page.

Common Mistakes Students Make in This Chapter

Avoid these frequent slip-ups that cost easy marks:

  • Swapping the thresholds: applying 15% to companies or 25% to partnerships. Companies are 25%; the rest are 15%.
  • Confusing the update cycles: mixing up the 2. 8, and 10 year timelines for high, medium, and low risk.
  • Treating CDD as one process: forgetting that Simplified. Standard, and Enhanced are distinct levels tied to risk.
  • Ignoring trigger-based KYC: assuming KYC only happens at account opening.
  • Relying on outdated figures: not confirming current limits on the latest official IIBF notification. Since RBI revises them over time.

Frequently Asked Questions (FAQ)

What does KYC stand for and why is it important?

KYC stands for Know Your Customer. It is the process of identifying. Verifying customers so banks can prevent money laundering. Fraud, and terror financing. It protects both the customer and the integrity of the financial system.

Who is a beneficial owner in KYC AML Chapter 2?

A beneficial owner is the natural person who ultimately owns or controls an entity. For companies the threshold is more than 25% ownership. While for partnerships, trusts, and AOPs it is more than 15%.

What are the three types of Customer Due Diligence?

The three types are Simplified CDD for low-risk customers. Standard CDD for medium-risk customers. And Enhanced CDD for high-risk customers such as PEPs and high-cash clients.

How often does KYC need to be updated?

Commonly taught frequencies are every 2 years for high-risk customers. Every 8 years for medium-risk, and every 10 years for low-risk. KYC is also updated on trigger events. Confirm the exact cycle on the latest official IIBF notification.

What happens if a customer does not submit PAN?

PAN or Form 60 is mandatory. If a customer refuses, the account can be suspended or closed. Exceptions. Such as medical or old-age grounds, are allowed only with proper monitoring.

Conclusion: Turn KYC Knowledge into Exam Marks

You now have the full picture of KYC AML Chapter 2. From identifying customers and beneficial owners to scoring risk. Running due diligence, and refreshing KYC on schedule. These are not isolated facts; they form a single. Logical system that protects banking every single day.

Key takeaway: KYC is about more than documents. It is about protecting the trust. Integrity of the entire banking system. And that mindset is exactly what examiners want to see.

Bookmark this guide, build your one-page revision sheet, and put the rules to the test with timed mock tests. Master this chapter, and you will walk into your JAIIB, CCP, or IIBF KYC AML exam with genuine confidence.

Related Guides

📚 Free Learning Sessions resources — connect & crack your exam

💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.

📱 Study on the go — get our iOS & Android app at iibf.store/app.

For more on KYC AML Chapter 2. See the official IIBF circulars. Our chapter-wise free notes on iibf.store.

KYC AML Chapter 2 (Module B): Customer Identification, Beneficial Ownership &

KYC AML Chapter 2 (Module B): Customer Identification, Beneficial Ownership &

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading