🏹 Happy Dussehra — victory of good over evil!

KYC AML for small finance banks: IIBF SFB Guide

SFB By Ashish Jain · IIBF STORE Editorial · 18 August 2026 · Updated 01 Oct 2026 · 10 min read · 42 views
KYC AML for small finance banks: IIBF SFB Guide

For an IIBF SFB candidate, KYC AML for small finance banks is not a side topic — they sit at the centre of the exam's Module B and C weightage because SFBs serve exactly the customer base regulators worry about most: first-time bank users, cash-heavy micro-entrepreneurs, and rural borrowers with thin or absent paper trails. A universal bank can lean on salaried, well-documented customers to keep its risk profile light. An SFB cannot. That single structural fact is why the RBI's Master Direction on KYC and the Prevention of Money Laundering Act, 2002 (PMLA) apply with extra rigour inside SFB branches, and why examiners test this chapter heavily every cycle.

🏦 Why KYC and AML Carry Extra Weight at Small Finance Banks

Small finance banks were licensed specifically to serve small business units, marginal farmers, micro and small industries, and unorganised sector entities — the very segments least likely to walk in with a salary slip, a company ID, or a clean digital footprint. That mandate creates an inherent tension: the RBI wants SFBs to widen access, but wider access means more first-time, low-document, cash-intensive relationships, which is exactly the profile AML frameworks are built to scrutinise. An SFB officer opening a Basic Savings Bank Deposit Account for a street vendor is applying the same PMLA-driven due diligence logic as a metro branch onboarding a corporate client, just calibrated to a very different risk and document reality. This is where the banker-customer special relationship chapter becomes directly relevant — the duty of care, confidentiality, and reasonable diligence a bank owes its customer is the legal backdrop against which every KYC refusal, account freeze, or STR filing has to be justified. Get the classification wrong at onboarding and the bank either turns away a genuine financial-inclusion customer or lets a layering transaction slip through undetected. Both outcomes draw supervisory attention, and both are squarely in scope for the SFB paper.

📋 The Three Pillars: CDD, Risk Categorisation, and Ongoing Due Diligence

Customer Due Diligence (CDD) at any SFB rests on three linked pillars. First, identification and verification — collecting Officially Valid Documents (OVDs), Aadhaar-based e-KYC where consented, or Video-based Customer Identification Process (V-CIP) for a genuinely paperless onboarding that matters enormously for reaching unbanked and semi-urban customers. Second, risk categorisation into low, medium, and high buckets, which drives how often the bank must refresh KYC — this is the single most frequently tested numeric detail in this chapter. Third, ongoing due diligence: monitoring transactions against the customer's declared profile so that a ₹500-a-week tailor's account that suddenly moves lakhs in cash triggers a review rather than sailing through unnoticed. The full mechanics of document checklists, verification steps, and account-opening formalities are covered in depth in the dedicated KYC and AML chapter, and candidates should treat that chapter as the primary reference rather than relying on general banking-law recall, since SFB-specific nuances around simplified KYC for small accounts are examined separately from standard universal-bank KYC questions.

Key Concepts — Small Finance Bank
Key Concepts — Small Finance Bank

🚨 Suspicious Transaction Reporting and PMLA Obligations

Once an account is open, the AML obligation shifts from onboarding to monitoring. Under PMLA, 2002 and the rules framed under it, every reporting entity — SFBs included — must file Cash Transaction Reports (CTRs), Suspicious Transaction Reports (STRs), Counterfeit Currency Reports (CCRs), and Non-Profit Organisation Transaction Reports (NTRs) with the Financial Intelligence Unit-India (FIU-IND). STRs are the exam's favourite because the trigger is judgment-based, not threshold-based: a transaction need not cross any rupee limit to be suspicious if it is inconsistent with the customer's known profile, structured to avoid reporting thresholds, or involves a party on a sanctions or negative list. SFB branches, given their high volume of small-ticket cash transactions, generate a disproportionate share of alerts that need to be triaged correctly rather than either over-reported into noise or under-reported into a compliance gap. This links directly to the loan side of the business too — proper documentation norms at the credit-appraisal stage feed the same customer risk profile that AML monitoring later relies on, so a weak KYC file upstream almost always shows up as a monitoring blind spot downstream. Institutions building deposit books with cross-border exposure face a parallel discipline — the due-diligence rigour around FCNR(B) deposits and forward cover in treasury operations mirrors the same principle that higher-risk, higher-value flows demand tighter scrutiny.

🔐 Simplified KYC, V-CIP, and the Financial Inclusion Trade-off

Because SFBs exist to bank the underbanked, the RBI carved out simplified KYC provisions specifically to prevent compliance friction from defeating the inclusion mandate. Small accounts — opened with self-certification and limited turnover and balance caps — allow a customer without any OVD to still open a basic account, provided the bank applies enhanced monitoring in exchange for reduced upfront documentation. Video-based Customer Identification (V-CIP) extends this further, letting a customer complete full KYC over a live, agent-assisted video call using Aadhaar e-KYC or digital OVDs, which is especially valuable for SFB customers in remote geographies without a nearby branch. The trade-off examiners like to test is precisely this: relaxed onboarding always comes paired with tighter downstream monitoring, never with relaxed monitoring too. A candidate who assumes "small account" means "low scrutiny forever" is making the most common mistake in this chapter. The account remains under a periodic review clock, and if the self-certified turnover cap is breached, the relaxed status lapses and full KYC becomes mandatory before further credits are permitted. This entire framework sits close to how the bank structures its front-end processes described in the operations of banks chapter, since KYC checkpoints are embedded into routine account-opening and transaction workflows rather than run as a separate compliance silo.

💡 Exam Tip: When a question gives a re-KYC periodicity number, map it to the risk category first — low risk is the longest cycle, high risk the shortest — before picking an answer.
Process & Framework — Small Finance Bank
Process & Framework — Small Finance Bank

🧾 Risk Categorisation at a Glance

The table below is the fastest way to lock in the numbers examiners test most: how often each risk category must be re-verified, the typical SFB customer profile that falls into it, and whether enhanced due diligence (EDD) applies. Treat this as a quick-recall grid rather than a substitute for the full chapter, since real exam questions often embed these numbers inside a scenario rather than asking for them directly.

Risk CategoryRe-KYC PeriodicityTypical SFB Customer ProfileEnhanced Due Diligence
Low RiskOnce every 10 yearsSalaried, government scheme beneficiary, regular small depositor❌
Medium RiskOnce every 8 yearsSelf-employed micro-entrepreneur, small trader with variable cash flow❌
High RiskOnce every 2 yearsNon-face-to-face onboarding, cash-intensive business, PEP-linked account✅
⚠️ Common Mistake: Candidates often assume high-risk re-KYC means "annual" — the tested figure is once every two years, not one.

Beyond periodicity, risk categorisation also determines how a branch prioritises its transaction-monitoring alerts. A medium-risk small trader whose account behaviour drifts sharply from its declared pattern should trigger review well before the scheduled re-KYC date arrives — periodic KYC refresh and continuous monitoring run on separate, overlapping clocks, and the exam frequently tests whether candidates understand that the two are not substitutes for each other. For candidates comparing how this evolves as an SFB scales up, the norms discussed in the small finance bank to universal bank transition guide are worth reading alongside this chapter, since AML supervisory expectations tighten further once an SFB crosses into universal-bank territory. It is also worth revisiting how conversion pathways interact with compliance load — the MFI to SFB conversion norms piece covers how microfinance institutions inherit and then must upgrade their KYC infrastructure the moment they convert. And because capital strength underwrites the bank's ability to absorb compliance and provisioning costs from AML failures, the capital adequacy norms for small finance banks article rounds out the regulatory picture for anyone studying this subject end to end. You can browse every related explainer on the small finance bank tag hub for the full sequence.

📌 Remember: Simplified KYC lowers the entry barrier for the customer; it never lowers the bank's monitoring obligation.
In Practice — Small Finance Bank
In Practice — Small Finance Bank

🧠 Practice MCQs: KYC and AML for Small Finance Banks

Q1. Under the RBI KYC Master Direction, how often must a high-risk customer's KYC be updated at a small finance bank? (a) Once every 10 years (b) Once every 5 years (c) Once every 2 years (d) Once every year

Answer: (c) — High-risk customers, including non-face-to-face and cash-intensive profiles, require re-KYC once every two years.

Q2. A "small account" under simplified KYC provisions is primarily designed to serve which objective? (a) Reduce the bank's compliance cost (b) Enable financial inclusion for customers without OVDs (c) Replace CDD entirely (d) Exempt the account from AML monitoring

Answer: (b) — Small accounts let customers without Officially Valid Documents open a basic account under self-certification, subject to turnover and balance caps, in service of financial inclusion.

Q3. Which agency in India receives Suspicious Transaction Reports (STRs) filed by small finance banks? (a) RBI (b) SEBI (c) FIU-IND (d) NPCI

Answer: (c) — STRs, CTRs and related reports under PMLA obligations are filed with the Financial Intelligence Unit-India (FIU-IND).

Q4. What triggers a Suspicious Transaction Report, as tested under PMLA-based AML norms? (a) Only transactions above a fixed rupee threshold (b) Any transaction inconsistent with the customer's known profile, regardless of amount (c) Only cash transactions above ₹10 lakh (d) Only transactions involving foreign remittance

Answer: (b) — STR filing is judgment-based, triggered by inconsistency with the customer's declared profile or structuring behaviour, not a fixed threshold.

Q5. Video-based Customer Identification Process (V-CIP) is significant for small finance banks mainly because it: (a) Eliminates the need for any due diligence (b) Enables full KYC completion remotely for customers in areas without nearby branches (c) Applies only to corporate accounts (d) Replaces the need for risk categorisation

Answer: (b) — V-CIP allows agent-assisted, live-video KYC completion, extending SFB reach into remote and underbanked geographies without compromising due diligence.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Do small finance banks follow different KYC rules from universal banks?

No — the core RBI KYC Master Direction and PMLA obligations apply uniformly, but SFBs encounter a higher proportion of low-document, first-time, and cash-intensive customers, so simplified KYC, V-CIP, and risk-based monitoring are used more heavily in practice.

What happens if a small account customer's balance or turnover exceeds the prescribed cap?

The relaxed simplified-KYC status lapses, and the customer must complete full KYC with Officially Valid Documents before further credits are permitted into the account.

Is Aadhaar e-KYC mandatory for opening an account at a small finance bank?

No — Aadhaar-based e-KYC is offered as one consented option among several valid identification routes, alongside physical OVDs and V-CIP; a customer cannot be forced to use Aadhaar as the only path.

Who is responsible for filing STRs at a small finance bank?

The bank's designated Principal Officer, supported by the branch-level AML/compliance function, is responsible for reviewing alerts and filing Suspicious Transaction Reports with FIU-IND within the prescribed timelines.

KYC and AML norms for small finance banks reward candidates who treat onboarding and monitoring as one continuous discipline rather than two separate topics — risk categorisation at account opening sets the re-KYC clock, and that same profile governs how aggressively transactions get watched afterward. Revisit the risk-category table above until the periodicity numbers are automatic, then work through scenario-based questions that combine documentation gaps with STR triggers, since that combination is exactly how the IIBF SFB paper likes to test this chapter. Practise topic-wise SFB mock tests free to convert this reading into exam-ready recall.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading