KYC and Customer Due Diligence in Retail Banking: RBWM Guide
Every retail banking relationship, from a first savings account to a large fixed deposit, begins with the same regulatory checkpoint: KYC and customer due diligence in retail banking. For JAIIB candidates, this is one of the most frequently tested areas of the Retail Banking and Wealth Management paper, because it sits at the intersection of compliance, operations and customer experience. Branches cannot open an account, issue a locker, or process a large-value transaction without first establishing who the customer is, what the relationship is for, and how much risk that relationship carries. This article breaks down the framework banks actually follow — Customer Identification Procedure (CIP), Simplified Due Diligence (SDD), Enhanced Due Diligence (EDD), risk categorisation, periodic KYC updation, and the shift to Video-based Customer Identification Process (V-CIP) and e-KYC — in the depth the exam demands, while linking each concept back to the core retail banking concepts chapter you are expected to know cold.
🪪 What Is KYC and Why It Matters in Retail Banking
Know Your Customer (KYC) is the statutory and regulatory obligation on banks to verify the identity and address of every customer before establishing a relationship, and to keep that information current throughout the life of the account. Its legal foundation lies in the Prevention of Money Laundering Act (PMLA), 2002, and its operating detail is spelt out in the RBI's Master Direction on KYC, which every scheduled commercial bank, NBFC and payments bank in India must follow. The objective is twofold: prevent the banking system from being used, knowingly or unknowingly, for money laundering or terror financing, and give the bank enough information to judge whether a transaction is consistent with what it knows about the customer. This second point is often missed by candidates who treat KYC as a one-time, box-ticking exercise at account opening. In reality, KYC is a continuous obligation — it starts at onboarding but continues through the customer's life cycle via monitoring and periodic updation. This is precisely why the topic is folded into the introduction of retail banking chapter — KYC is not a side process bolted onto retail banking, it is a foundational control that every retail product, from savings accounts to wealth management mandates, is built on top of.
💡 Exam Tip: If a question asks "what is KYC," the safest answer frames it as an ongoing risk-management process, not a single form filled at account opening. Examiners frequently test this distinction between KYC as a continuum versus CDD as a discrete verification step.
📋 Customer Due Diligence: CDD, Simplified and Enhanced Due Diligence
Customer Due Diligence (CDD) is the operational core of KYC — the actual process of identifying the customer using Officially Valid Documents (OVDs) such as Aadhaar, passport, voter ID, driving licence or the NREGA job card, verifying the current address, and understanding the purpose and expected nature of the banking relationship. But not every customer carries the same risk, so RBI allows banks to calibrate the depth of due diligence to the risk the customer presents.
For low-risk customers — typically salaried individuals with a transparent, stable source of income and a well-defined, low-value transaction pattern — banks may apply Simplified Due Diligence (SDD), accepting a smaller documentation set and relying more on self-certification. At the other end, Enhanced Due Diligence (EDD) applies to high-risk customers: politically exposed persons (PEPs), non-resident customers, trusts, cash-intensive businesses, or customers whose ownership structure is not straightforward. EDD requires additional information — source of funds, source of wealth, and often senior management approval before the relationship is opened. The table below summarises how these tiers differ in practice.
| Risk Category | KYC Updation Cycle | Documentation Depth | Physical Verification |
|---|---|---|---|
| Low Risk (SDD) | Once every 10 years | Basic OVD + address proof | ❌ Not mandatory (e-KYC accepted) |
| Medium Risk | Once every 8 years | OVD + address + income proof | ✅ Recommended |
| High Risk (EDD) | Once every 2 years | OVD + address + source of funds | ✅ Mandatory |
| PEPs / Complex Ownership | Once every 2 years | Enhanced background check + approval | ✅ Mandatory |
Notice that CDD sits inside KYC, not alongside it — CDD is the "how," KYC is the ongoing "why" and "when." This layered structure also explains why other retail products carry their own diligence overlays: a bank assessing a home loan applicant, for instance, layers income and property verification on top of the same base KYC record rather than repeating it from scratch, which is a distinction worth revisiting alongside our companion piece on home loan appraisal and LTV norms.

🔍 Risk Categorization and Periodic KYC Updation
Risk categorisation is the mechanism that ties CDD intensity to actual exposure, and it is a standing responsibility of the branch, not a one-time system flag. Banks classify every customer into low, medium or high risk based on factors such as customer type (individual, proprietorship, trust, NGO), location (domestic versus cross-border), nature and volume of transactions, mode of payments used, and the customer's occupation or business profile. A daily-wage account holder using only ATM withdrawals sits at one end; a trust with foreign beneficiaries and large cash deposits sits at the other.
⚠️ Common Mistake: Candidates often assume KYC updation only means collecting a fresh address proof. In practice it means banks must re-verify the risk category itself — a customer who opened a low-risk salary account can migrate to medium or high risk if their transaction behaviour changes, well before the scheduled updation date arrives.
Periodic KYC updation exists precisely because customer risk is not static. The periodicities in the table above (10/8/2 years) are the default cycle, but RBI permits banks to trigger an off-cycle updation whenever a transaction pattern, adverse media report, or a change in occupation or address suggests the existing risk rating no longer holds. Failure by the customer to respond to updation requests typically results in operational restrictions such as debit freezes until documents are refreshed — a control point that examiners like to pair with questions on branch-level compliance responsibility, a theme that runs through the retail banking role within the bank operations chapter. The Central KYC Records Registry (CKYCR), maintained by CERSAI, further reduces duplication by letting one bank's verified KYC record be reused by another regulated entity through a unique KYC identifier, so a customer does not have to redo full CDD every time they open an account elsewhere.
💻 Video KYC, e-KYC and Digital Onboarding in Retail Banking
The single biggest operational shift in retail KYC over the last few years has been digitisation. RBI's Video-based Customer Identification Process (V-CIP) allows banks to complete full CDD — identity check, liveness confirmation, and document capture — over a live, recorded video interaction, without the customer ever visiting a branch. This has materially cut onboarding time for savings accounts, fixed deposits and even entry-level investment products, and it is now the default channel banks push customers toward for digital account opening.
Aadhaar-based e-KYC (through OTP authentication or offline XML/QR sharing) remains the fastest route for individual onboarding, and RBI's "small account" scheme still allows simplified opening for customers who cannot immediately produce a full OVD set, subject to caps on aggregate credits, balance, and withdrawals. Digital onboarding does not stop at deposit accounts either — customers opening demat accounts to invest in the secondary market must complete a parallel KYC with the depository, a process explained in our related article on stock exchanges and depositories in India, which shows how NSDL and CDSL handle investor-side verification alongside the bank's own record.
📌 Remember: V-CIP is treated as equivalent to a face-to-face, in-branch verification under RBI norms — it is not a "reduced" form of KYC, and the same risk-categorisation and updation rules apply afterward exactly as they would for a branch-verified customer.
Digitisation has also changed how banks cross-sell once the base KYC record exists: a customer verified once through V-CIP can subsequently be offered a recurring deposit, a small savings product, or a wealth advisory conversation without repeating identity checks, provided the risk category has not changed. This underpins the shift toward branch staff focusing on advisory and relationship work — the same operational realignment covered in our guide to branch profitability in retail banking, where digitised KYC frees up front-desk time for higher-value conversations. It also intersects with tax documentation: customers opening products for tax-saving purposes still need PAN linkage as part of KYC, a point explored further in our piece on tax planning for retail banking customers. RBI's KYC framework itself is documented in detail on the Reserve Bank of India's official Master Direction on KYC, which remains the primary source examiners draw questions from.

🧠 Practice MCQs: KYC and Customer Due Diligence
Q1. Under RBI's risk categorisation norms, how frequently must a high-risk retail customer's KYC be updated? (a) Once every 5 years (b) Once every 2 years (c) Once every 8 years (d) Once every 10 years
Answer: (b) — High-risk customers, including PEPs, require KYC updation once every 2 years under RBI's periodicity norms.
Q2. Which of the following is NOT accepted as an Officially Valid Document (OVD) for retail KYC? (a) Aadhaar (b) Passport (c) Voter ID card (d) College identity card
Answer: (d) — A college identity card is not a recognised OVD; Aadhaar, passport, voter ID, driving licence and the NREGA job card are among the accepted documents.
Q3. The Central KYC Records Registry (CKYCR) is maintained by which body? (a) NPCI (b) CERSAI (c) IBA (d) SEBI
Answer: (b) — CKYCR is maintained by CERSAI and allows KYC records verified by one regulated entity to be reused by another via a unique KYC identifier.
Q4. Video-based Customer Identification Process (V-CIP) is treated under RBI norms as: (a) A lower standard than branch KYC (b) Equivalent to face-to-face verification (c) Valid only for existing customers (d) A backup channel with no legal standing
Answer: (b) — V-CIP is recognised as equivalent to in-person, face-to-face customer verification when conducted per RBI's prescribed process.
Q5. Under RBI's "small account" scheme, what is the maximum balance permissible in the account at any point in time? (a) ₹25,000 (b) ₹50,000 (c) ₹1,00,000 (d) ₹2,00,000
Answer: (b) — A small account is capped at a balance of ₹50,000 at any time, alongside limits on aggregate annual credits and monthly withdrawals.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
What is the difference between KYC and CDD?
KYC is the overarching, ongoing regulatory framework requiring banks to know and monitor their customers throughout the relationship, while Customer Due Diligence (CDD) is the specific process of verifying identity and address and understanding the purpose of the relationship at a point in time.
Is Aadhaar mandatory for KYC in retail banking?
No. Aadhaar-based e-KYC is one convenient route, but customers can complete KYC using any accepted Officially Valid Document such as a passport, voter ID or driving licence if they prefer not to submit Aadhaar.
How often should banks update KYC records for existing customers?
The updation cycle depends on risk category: once every 10 years for low-risk customers, once every 8 years for medium-risk, and once every 2 years for high-risk customers and PEPs, as prescribed under RBI's KYC Master Direction.
What happens if a customer does not respond to a periodic KYC update request?
Banks typically restrict operations in the account, such as freezing debit transactions, until the customer submits updated KYC documents, in line with the bank's internal KYC policy and RBI guidelines.
KYC and customer due diligence in retail banking is not a compliance footnote — it is the operating layer every deposit account, loan product and wealth advisory conversation is built on, and JAIIB examiners test it from multiple angles: legal basis, risk tiers, updation cycles and the shift to digital onboarding. Revisit the Retail Banking and Wealth Management tag hub for the full set of linked concepts, and when you are ready to test your recall under exam conditions, enrol in our JAIIB course for chapter-wise practice sets built around exactly this kind of scenario-based questioning.

Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading