KYC, AML and CFT Framework: Complete IIBF 2026 Guide
KYC, AML and CFT Framework: The Complete IIBF 2026 Exam Guide
The KYC, AML and CFT framework is the single most exam-critical pillar of the IIBF certification, and yet it is where most candidates lose easy marks because they treat it as a list to memorise rather than a logical chain of accountability. In this guide we connect the statutory backbone of the Prevention of Money Laundering Act, 2002 (PMLA), the RBI Master Direction on Know Your Customer, the risk-based Customer Due Diligence (CDD) process and reporting to FIU-India into one coherent picture, so that on test day you can reason through a question instead of guessing.
Key takeaways
- PMLA 2002 is the legal spine; the RBI KYC Master Direction operationalises it for regulated entities.
- Every relationship rests on four pillars: Customer Acceptance Policy, Customer Identification, Risk Management and ongoing monitoring.
- CDD is the standard; EDD applies to higher-risk customers such as PEPs and complex ownership structures.
- Risk grading (low / medium / high) decides how often KYC is updated and how deeply you scrutinise.
- FIU-India receives the CTR and STR through the FINnet gateway; tipping off a customer about an STR is prohibited.
- India aligns the whole system with the FATF Forty Recommendations, the global AML/CFT benchmark.
Before we go section by section, anchor your prep with the dedicated KYC, AML and CFT exam hub and the full KYC, AML and CFT subject notes. Treat this guide as the conceptual map; the course pages give you the chapter-wise depth.
Why the KYC, AML and CFT Framework Carries So Much Weight
The KYC, AML and CFT framework sits at the heart of every Indian bank's compliance function, and that is exactly why it is a high-weight area in the IIBF certification syllabus for 2026. Examiners favour it because it tests judgement, not recall: a single scenario can touch acceptance policy, due diligence depth, beneficial ownership and a reporting deadline all at once.
Think of the framework as three connected layers. The law (PMLA 2002 and its Rules) creates obligations. The regulator (RBI, through the Master Direction) translates those obligations into operating procedure. The bank then executes them at onboarding, during the relationship and at the point of reporting. Almost every exam question is really asking, "which layer governs this situation?"
Exam tip: When a question feels overwhelming, identify the trigger first — onboarding, a change in behaviour, or a transaction crossing a threshold. The trigger tells you which obligation applies.
The Legal Spine: PMLA 2002 and the RBI KYC Master Direction
The legal spine of anti-money-laundering work in India is the Prevention of Money Laundering Act, 2002 (PMLA), supported by the PMLA (Maintenance of Records) Rules, 2005. Under Section 12 of PMLA, every reporting entity must verify client identity, maintain records of transactions and furnish prescribed information to the Financial Intelligence Unit. These three duties — verify, record, report — are the seed from which the entire framework grows.
The RBI operationalises these duties through the Master Direction on Know Your Customer, which all regulated entities must apply uniformly across branches and digital channels. The Master Direction lays down four building blocks you should be able to recite in your sleep:
- Customer Acceptance Policy (CAP) — no account in anonymous or fictitious names, and clear criteria for accepting a customer.
- Customer Identification Procedures (CIP) — verify identity and address using Officially Valid Documents (OVDs).
- Risk Management — classify customers by risk and align controls accordingly.
- Ongoing monitoring of transactions so behaviour is checked against the declared profile.
Key terms that frequently appear in MCQs include OVDs, Aadhaar e-KYC and the Central KYC Records Registry (CKYCR), which lets banks pull an existing KYC record instead of re-collecting documents. Two accountable roles also feature heavily: every reporting entity must appoint a Principal Officer, who owns reporting to FIU-India, and a Designated Director, who carries board-level accountability for compliance.
On record retention, remember the headline rule: records must be kept for at least five years after the business relationship ends or the transaction is completed. Specific timelines and document lists are periodically refined, so for any exact requirement always confirm against the latest released RBI Master Direction and IIBF notification.
Customer Due Diligence: CDD, SDD and EDD
Customer Due Diligence (CDD) is the process of identifying and verifying a customer at onboarding and understanding the nature of the intended relationship. For most retail customers, standard CDD using an OVD and a recent photograph is sufficient, and the identity is verified before the account becomes fully operational.
The framework also recognises Simplified Due Diligence (SDD) for low-risk small accounts, where relaxed documentation applies subject to balance and turnover limits laid down by the RBI. This is a common trap in MCQs: SDD does not mean "no due diligence" — it means proportionate due diligence for genuinely low-risk, low-value relationships.
Where the risk is higher, banks must apply Enhanced Due Diligence (EDD). This means gathering additional information on the source of funds, understanding the purpose of the account and the expected pattern of transactions, and applying closer ongoing scrutiny. EDD is mandatory for politically exposed persons (PEPs), non-face-to-face customers, complex ownership structures and customers from jurisdictions flagged by the FATF.
Continuous monitoring is the thread that ties CDD and EDD together: it ensures the transaction profile stays consistent with the declared activity, and any material deviation triggers a review. To pressure-test these distinctions, work through topic-wise mock papers on the KYC and AML practice tests, which mirror the certification pattern and explain each answer.
CDD vs EDD at a Glance
| Feature | Standard CDD | Enhanced Due Diligence (EDD) |
|---|---|---|
| Applies to | Most retail / low-to-medium risk customers | PEPs, non-face-to-face, complex entities, high-risk jurisdictions |
| Identity check | OVD plus recent photograph | OVD plus source-of-funds and source-of-wealth checks |
| Approval level | Branch / normal onboarding | Senior management approval (especially for PEPs) |
| Monitoring | Routine ongoing monitoring | Intensified, more frequent scrutiny |
Risk Categorisation, PEPs and Beneficial Ownership
The framework is built on a risk-based approach. Banks must categorise every customer as low, medium or high risk based on identity, social and financial status, the nature of the business and the country of origin. This grading is not cosmetic — it directly determines both the depth of due diligence and the frequency of periodic KYC updation.
For the IIBF exam, the periodic updation intervals are a reliable scoring opportunity. As per the prevailing RBI Master Direction, the broad cadence is:
- Low risk — KYC updation every ten years.
- Medium risk — KYC updation every eight years.
- High risk — KYC updation every two years.
Politically Exposed Persons (PEPs) are individuals entrusted with prominent public functions in a foreign country — heads of state, senior politicians, and senior judicial or military officers. PEP relationships demand senior management approval, enhanced ongoing monitoring and source-of-wealth checks, because the risk of corruption proceeds entering the system is elevated.
Equally important is identifying the beneficial owner — the natural person who ultimately owns or controls a customer that is a legal entity. The PMLA Rules set control thresholds for companies, partnerships and trusts so that no real owner can hide behind a corporate veil. In a scenario question, if the customer is a company or trust, your instinct should immediately be to ask, "who is the natural person behind it?"
FIU-India Reporting: CTR, STR and the FATF Standards
The Financial Intelligence Unit India (FIU-IND) is the central national agency that receives, analyses and disseminates information on suspicious financial transactions. Reporting entities file prescribed reports electronically through the FINnet gateway. Two reports dominate the IIBF syllabus — the Cash Transaction Report and the Suspicious Transaction Report — alongside Counterfeit Currency Reports, Non-Profit Organisation (NPO) reports and cross-border wire transfer reports.
- A Cash Transaction Report (CTR) covers all cash transactions above ten lakh rupees, or a series of integrally connected cash transactions exceeding that threshold within a month, and must be filed by the fifteenth of the following month.
- A Suspicious Transaction Report (STR) is filed whenever a transaction gives reasonable grounds to suspect the involvement of proceeds of crime — regardless of amount — and must be submitted within seven working days of forming that suspicion.
One rule is non-negotiable and a favourite of examiners: tipping off the customer about an STR is strictly prohibited. The customer must never be alerted that a report has been or will be filed. Because reporting thresholds and formats can be revised, confirm any precise figure or deadline against the latest FIU-India and RBI instructions before relying on it.
Finally, India aligns these duties with the FATF Forty Recommendations, the global standard on combating money laundering and the financing of terrorism. FATF mutual evaluations assess how effectively a country implements the standard, which is why PMLA and the RBI Master Direction are periodically updated to stay compliant. You can compare reporting mechanics in depth in our FIU-India reporting: STR, CTR and CDD guide and broaden the legal angle with the AML compliance under PMLA guide.
A Practical 4-Week Study Plan for This Topic
Concepts stick when you study them in the order the framework actually flows. Use this sequence to convert reading into recall:
- Week 1 — Law first. Master PMLA 2002, Section 12, the 2005 Rules and the four pillars of the RBI Master Direction. Write the "verify, record, report" chain from memory.
- Week 2 — Due diligence. Drill CDD, SDD and EDD, then map each to its trigger. Memorise the low/medium/high updation intervals.
- Week 3 — People and reporting. Cover PEPs, beneficial ownership, the Principal Officer and Designated Director, then lock in CTR and STR rules including the tipping-off prohibition.
- Week 4 — Application and revision. Solve full-length mocks daily, revise FATF alignment, and reinforce weak terms with quick recall drills using the KYC and AML matching games.
For the wider syllabus map and a downloadable reference, keep the KYC, AML and CFT Certificate Syllabus 2026 with free PDF open as you plan. Browse every related explainer in one place on the KYC and AML guides hub.
Common Mistakes Candidates Make
- Confusing SDD with no due diligence. Simplified does not mean skipped; it is proportionate, limit-bound due diligence for low-risk accounts.
- Mixing up CTR and STR triggers. CTR is amount-based (above ten lakh in cash); STR is suspicion-based, with no amount threshold.
- Forgetting the tipping-off rule. Disclosing an STR to the customer is an offence, not a courtesy.
- Ignoring beneficial ownership. For legal entities, always trace control to a natural person.
- Memorising figures that may have changed. Treat all thresholds, fees and intervals as confirm-on-the-official-source items rather than fixed truths.
Frequently Asked Questions
What is the difference between CDD and EDD?
CDD is the standard identification and verification applied to all customers at onboarding using an OVD and recent photograph. EDD is the deeper scrutiny applied to higher-risk customers such as PEPs and complex entities. It additionally covers source of funds, purpose of the account and closer ongoing monitoring.
What threshold triggers a Cash Transaction Report (CTR)?
A CTR is required for cash transactions above ten lakh rupees, or a series of integrally connected cash transactions exceeding that limit within a calendar month. It must be filed with FIU-India by the fifteenth of the following month. Always confirm the current threshold against the latest FIU-India instructions.
Who is a politically exposed person (PEP) under the KYC framework?
A PEP is an individual entrusted with prominent public functions in a foreign country, such as a head of state, senior politician or senior judicial officer. Such relationships require senior management approval, enhanced ongoing monitoring and source-of-wealth checks. The aim is to mitigate the elevated risk of corruption-related proceeds.
Why are FATF standards relevant to Indian banks?
The FATF Forty Recommendations are the global benchmark for anti-money-laundering and counter-terrorist-financing controls. India implements them through PMLA 2002 and the RBI Master Direction. FATF mutual evaluations then assess how effectively the country complies, which keeps the domestic framework evolving.
How long must banks retain KYC and transaction records?
As a headline rule, records must be retained for at least five years after the business relationship ends or the transaction is completed. The exact scope of records and any extensions are set out in the PMLA Rules and the RBI Master Direction. Confirm the precise requirement on the official IIBF and RBI sources before test day.
What is the role of the Principal Officer and Designated Director?
The Principal Officer is responsible for monitoring transactions and ensuring timely reporting to FIU-India. The Designated Director carries board-level accountability for the reporting entity's overall compliance with PMLA. Both are personally accountable roles that examiners like to test in scenario questions.
Conclusion: Turn the Framework Into Marks
Mastering the KYC, AML and CFT framework is not about memorising disconnected rules — it is about seeing the chain: PMLA 2002 creates the duty, the RBI Master Direction operationalises it, risk-based CDD and EDD execute it, and FIU-India reporting closes the loop, all anchored to the FATF standard. Study it in that order, drill the deadlines, and the marks follow. For authoritative regulatory wording, always cross-check with the Indian Institute of Banking and Finance (IIBF). Stay consistent, practise full-length mocks, and walk into your 2026 certification with quiet confidence.
Related Guides
📚 Free Learning Sessions resources — connect & crack your exam
- 📝 Free mock tests — chapter-wise, exam-pattern, with instant solutions
- 🎮 Matching games — gamified revision of key terms & concepts
- 📄 Study notes & PDFs — downloadable chapter material
- 🎥 Video classes on YouTube — subscribe to @learningsessions
💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.
📱 Study on the go — get our iOS & Android app at iibf.store/app.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading