KYC Policy & Customer Acceptance Policy (CAP): The Complete 2026 Guide for
Have you ever wondered why banks are so strict about KYC before they let you open even a basic savings account? If you are preparing for the JAIIB. CCP or IIBF KYC & AML paper.
Mastering the KYC policy and the Customer Acceptance Policy (CAP) is non-negotiable. These two topics sit at the heart of Module B. Show up in the exam year after year.
The good news? Once you understand the logic behind the rules. You stop memorising and start scoring.
This guide breaks down the entire framework in plain English. With tables. Examples.
A focused FAQ so you can win those marks with confidence.
🔑 Key Takeaways (read this first)
- KYC = Know Your Customer. It is a legal duty, not just paperwork.
- Every bank must have a Board-approved KYC policy built on four pillars: CAP. CIP, Risk Management and Monitoring of Transactions.
- The Customer Acceptance Policy (CAP) decides who the bank will. Will not accept as a customer.
- Customers are classified as Low. Medium or High risk; high-risk customers need Enhanced Due Diligence (EDD).
- The legal backbone is the PMLA. 2002 and the RBI Master Direction on KYC. Always confirm the latest figures on the official IIBF/RBI notification.
What Is a KYC Policy? (And Why It Matters)
A KYC policy is a written. Board-approved framework that tells a bank exactly how to identify customers. Assess their risk, and keep watching their transactions over time. The term KYC stands for Know Your Customer.
Think of it as the bank's rulebook for answering one simple question: "Do we really know who this person is. And is their money clean?" Without that answer. A bank becomes an easy pipe for money laundering and terrorist financing.
For exam purposes. Remember three things a KYC policy is designed to do:
- Prevent banks from being used for financial crime.
- Verify the true identity of every customer.
- Monitor activity so suspicious behaviour is caught early.
The Genesis of KYC: From Introducers to Full Verification
KYC did not always look the way it does today. Decades ago, banks relied on an old introduction-based system. If an existing customer "introduced" you, the bank opened your account. No introducer meant no cheque book — and sometimes no account at all.
As financial crime grew more sophisticated, this trust-based model broke down. Regulators worldwide pushed banks toward full identity verification using official documents. KYC evolved from a courtesy into a compliance mandate backed by law.
Why Is a KYC Policy a Legal Necessity?
This is a favourite exam angle, so be precise. A KYC policy is mandated by a layered structure of international standards. Indian law:
- FATF (Financial Action Task Force) — sets global anti-money-laundering standards.
- Basel Committee guidelines — frame KYC as a core banking-supervision principle.
- PMLA, 2002 — the Prevention of Money Laundering Act is the primary Indian statute.
- RBI Master Direction on KYC — the operational rulebook Indian banks must follow.
- Board-approved internal policy — each bank tailors the rules to its own business.
Banks must also review their KYC policy periodically. Typically when new risks or regulations emerge. For the exact review cycle and any prescribed timelines. Confirm on the latest official IIBF/RBI notification, as these can change.
Customer Due Diligence (CDD): The Engine of KYC
Customer Due Diligence (CDD) is the actual process of assessing a customer's risk profile. It is the engine that powers the whole KYC machine.
Strong CDD means the bank collects. Verifies enough information to be confident about who the customer is. What kind of activity to expect. The simple rule examiners want you to internalise:
Stronger CDD = Lower fraud and money-laundering risk.
CDD is also reusable. Once a bank has completed due diligence on a customer. The same CDD can support multiple products and services for that customer. Subject to updates when risk changes.
The 4 Pillars of a KYC Policy
This is the single most testable point in the entire chapter. The RBI Master Direction requires every KYC policy to be built on four key elements. Memorise them as the four pillars:
- Customer Acceptance Policy (CAP) — who the bank will accept.
- Customer Identification Procedures (CIP) — how the bank confirms identity.
- Risk Management — how the bank grades and controls customer risk.
- Monitoring of Transactions — how the bank watches activity for red flags.
| Pillar | Core Question It Answers | Example in Action |
|---|---|---|
| CAP | Should we accept this customer at all? | Rejecting anonymous or fictitious-name accounts. |
| CIP | Who exactly is this customer? | Verifying officially valid documents (OVDs). |
| Risk Management | How risky is this customer? | Tagging a PEP as high risk and applying EDD. |
| Monitoring | Is the activity consistent and clean? | Flagging a sudden, unexplained large transfer. |
Want to lock these four pillars into memory before the exam? Test yourself with our free mock tests and revisit our free guides for spaced revision.
Customer Acceptance Policy (CAP): The Gatekeeper
The Customer Acceptance Policy (CAP) is the bank's gatekeeper. It ensures the bank onboards only genuine, identifiable customers. Under the PMLA framework. The CAP lays down clear "do not accept" conditions.
As a rule, a bank's CAP must ensure that:
- ❌ No anonymous accounts are opened.
- ❌ No accounts in fictitious or fake names are allowed.
- ❌ No account is opened where identity cannot be verified.
- ✅ CDD is completed before or at the time of onboarding.
- ✅ KYC is done for all joint account holders. Not just the first holder.
Crucially, the CAP must balance compliance with financial inclusion. A genuine low-income customer should not be denied a basic account simply. They lack elaborate documentation. Strictness must never become exclusion.
Prohibited Customers: Who Banks Must Never Onboard
The CAP also screens against prohibited and sanctioned persons. Banks must not open accounts for individuals or entities flagged under lists such as:
- UAPA (Unlawful Activities Prevention Act) designated lists and FIU-IND alerts.
- RBI advisories and caution lists.
- References from agencies like CBI, ED and Interpol.
- Internationally sanctioned entities (for example, UN sanction lists).
Screening names against these lists is a mandatory part of customer acceptance. Not an optional extra.
Risk-Based Customer Categorisation
Not every customer carries the same risk, so banks classify them. This risk-based approach lets banks focus their energy where the danger is highest. The standard three buckets are:
| Risk Category | Typical Customers | Due Diligence Level |
|---|---|---|
| Low Risk | Salaried employees, government staff, small accounts | Simplified / standard CDD |
| Medium Risk | Businesspersons, traders, self-employed professionals | Standard CDD with closer review |
| High Risk | PEPs, certain foreign nationals, NPOs, complex structures | Enhanced Due Diligence (EDD) |
A PEP (Politically Exposed Person) is someone entrusted with a prominent public function. Because of their position. PEPs carry a higher corruption risk. So banks apply Enhanced Due Diligence — deeper checks. Senior approval and closer monitoring.
KYC Policy vs Process Manual: Know the Difference
Examiners love this distinction. A KYC policy and a process manual are not the same document:
- KYC Policy = the strategic framework. It states the principles, the four pillars and the bank's risk appetite.
- Process Manual = the operational steps. It explains exactly how staff onboard customers. Run checks and monitor accounts day to day.
In short: the policy says what and why; the manual says how.
Compliance & Responsibility
KYC is mandatory at every level of the bank. And accountability is built in. Typical responsibilities include:
- Appointing a designated KYC / Principal Officer.
- Setting strong internal controls.
- Conducting regular internal audits.
- Submitting periodic compliance reports to the regulator.
One golden line to remember: core KYC responsibility cannot be fully outsourced. A bank may use service providers for some steps. But the accountability stays with the bank.
How to Study This Chapter (A Smart Plan)
Theory is easy to read and easy to forget. Use this simple, high-yield study plan to actually retain it:
- Anchor the four pillars first. If you can recall CAP. CIP, Risk Management and Monitoring instantly, half the marks are yours.
- Map laws to roles. PMLA = the Act; RBI Master Direction = the rulebook; FATF/Basel = global standards.
- Use comparison tables. Policy vs manual. And the three risk categories, are perfect for one-glance revision.
- Drill with MCQs. Apply each concept by attempting mock tests until you stop second-guessing.
- Revise with summaries. Skim our free guides the night before the exam for a quick refresh.
Common Mistakes Students Make
Avoid these frequent traps that cost easy marks:
- Confusing CAP with CIP. CAP decides whether to accept; CIP confirms who the customer is.
- Thinking KYC can be skipped for joint holders. KYC applies to all joint account holders.
- Believing KYC can be fully outsourced. Operational help is allowed; accountability cannot be handed off.
- Treating all customers as the same risk. The whole point is a risk-based approach with EDD for high-risk cases.
- Forgetting financial inclusion. Strict KYC must not unfairly exclude genuine low-income customers.
- Quoting outdated figures. When unsure of a timeline or threshold. Confirm on the latest official IIBF/RBI notification.
Frequently Asked Questions (FAQ)
What is the difference between KYC and the Customer Acceptance Policy?
KYC is the overall framework a bank uses to identify. Verify and monitor customers. The Customer Acceptance Policy (CAP) is one pillar within KYC that specifically decides. Customers the bank will and will not accept.
What are the four pillars of a KYC policy?
The four pillars are the Customer Acceptance Policy (CAP). Customer Identification Procedures (CIP), Risk Management, and Monitoring of Transactions. Every Board-approved KYC policy must contain all four.
What is Enhanced Due Diligence (EDD)?
EDD is a deeper level of scrutiny applied to high-risk customers such as PEPs. Certain foreign nationals and NPOs. It involves additional verification, senior management approval and closer ongoing monitoring.
Can a bank outsource its KYC responsibilities?
A bank may use service providers for parts of the process. But the core responsibility and accountability for KYC cannot be fully outsourced. The regulator holds the bank itself answerable.
Which law is the legal basis of KYC in India?
The primary statute is the Prevention of Money Laundering Act (PMLA). 2002, operationalised through the RBI Master Direction on KYC. For current thresholds and timelines. Always confirm on the latest official IIBF/RBI notification.
Conclusion: Turn Rules Into Marks
The KYC policy and Customer Acceptance Policy are not about blind memorisation. They are about understanding how banks build safe. Transparent and fraud-free systems.
Once you grasp the four pillars. The risk categories and the policy-versus-manual distinction. This becomes one of the most scoring chapters in Module B.
Study smart. Drill with practice questions. And walk into your JAIIB. CCP or IIBF exam knowing you have mastered KYC and CAP. You have got this — now go convert this knowledge into marks.
Related Guides
📚 Free Learning Sessions resources — connect & crack your exam
- 📝 Free mock tests — chapter-wise, exam-pattern, with instant solutions
- 🎮 Matching games — gamified revision of key terms & concepts
- 📄 Study notes & PDFs — downloadable chapter material
- 🎥 Video classes on YouTube — subscribe to @learningsessions
💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.
📱 Study on the go — get our iOS & Android app at iibf.store/app.


Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading