KYC Compliance Framework for Banks: RBI Norms for BCP Exam

BCP By Ashish Jain · IIBF STORE Editorial · 07 August 2026 · Updated 23 Sep 2026 · 9 min read · 52 views
KYC Compliance Framework for Banks: RBI Norms for BCP Exam

The KYC compliance framework for banks sits at the centre of every branch's daily operations and every BCP exam paper. It tells staff who a customer really is, how much scrutiny to apply, and when to escalate a doubtful account. Get the framework wrong and a bank risks regulatory strictures, reputational damage, and misuse of accounts for money laundering. Get it right and onboarding stays smooth while risk stays contained.

This article walks through the building blocks of the framework as banks apply it today — customer due diligence, risk categorisation, ongoing monitoring, and the governance layer that RBI expects around it. It is written for candidates preparing the Banking Compliance Professional (BCP) paper and for compliance staff who need a quick, accurate refresher.

🔍 The Building Blocks of the KYC Compliance Framework

Every bank's KYC compliance framework for banks rests on four pillars laid down in RBI's Master Direction on Know Your Customer: a Customer Acceptance Policy, Customer Identification Procedure, ongoing transaction monitoring, and risk management. The Customer Acceptance Policy sets out who the bank will onboard and under what conditions — it explicitly bars anonymous or fictitious accounts and requires enhanced checks before onboarding customers linked to higher-risk jurisdictions or activities.

Customer identification relies on Officially Valid Documents, PAN or Form 60, and — since the framework matured — the Central KYC Registry (CKYCR), which issues a 14-digit KYC Identification Number so a customer's verified data can be reused across banks instead of re-collected each time. Branches also apply Video-based Customer Identification Process (V-CIP) for remote onboarding, subject to the safeguards RBI has prescribed for liveness checks and officer verification.

Staff preparing for the exam should study the underlying regulatory restrictions on lending alongside KYC, because due diligence failures often surface first in loan accounts. The chapter on Loans And Advances Regulatory Restrictions connects directly to how weak identification checks can let a borrower breach exposure or end-use conditions unnoticed.

💡 Exam Tip: Questions often test the difference between the Customer Acceptance Policy (who to onboard) and the Customer Identification Procedure (how to verify them) — keep the two distinct in your notes.
KYC compliance framework pillars: acceptance policy, identification, monitoring, risk management
KYC compliance framework pillars: acceptance policy, identification, monitoring, risk management

🧭 Customer Due Diligence and Risk Categorisation

Customer Due Diligence (CDD) is not a one-time formality; it is calibrated to risk. Banks classify every customer as low, medium, or high risk at onboarding, based on factors like occupation, source of funds, geography, and the nature of the expected transactions. A politically exposed person (PEP), a cash-intensive business, or an account with cross-border remittances typically lands in the high-risk bucket and draws Enhanced Due Diligence — additional documentation, senior-management sign-off, and closer transaction review.

Risk categorisation is not static. RBI's framework requires periodic KYC updation on a risk-based cycle, so a high-risk profile is revisited far more often than a low-risk one. Simplified due diligence applies to specific low-risk categories, such as small accounts with capped balances and turnover, where the compliance burden is deliberately lighter to support financial inclusion without diluting the underlying safeguards.

This risk-based approach also determines how a bank prices and monitors credit exposure. The chapter on Large Exposures And Exposure Norms shows how concentration limits build on the same customer and group identification data that KYC establishes.

⚠️ Common Mistake: Candidates confuse "risk categorisation" with "credit rating" — KYC risk categorisation measures money-laundering and compliance risk, not creditworthiness.
Risk-based customer due diligence: low, medium and high risk categorisation
Risk-based customer due diligence: low, medium and high risk categorisation

🛡️ Ongoing Monitoring, PEPs and Suspicious Transactions

KYC does not end at onboarding. Banks run ongoing monitoring to spot transactions that are inconsistent with a customer's declared profile — an account suddenly receiving large, unexplained cash deposits, or fund transfers that do not match the stated occupation. Where monitoring throws up an unresolved red flag, the bank files a Suspicious Transaction Report (STR) with the Financial Intelligence Unit-India (FIU-IND) under the Prevention of Money Laundering Act, 2002 and the PML Rules.

Politically Exposed Persons need continuous attention even after onboarding, because a customer's political exposure can change mid-relationship. Banks are expected to have processes that periodically re-screen customers against updated PEP and sanctions lists, not just check once at account opening.

Trade and export-linked accounts add another layer of scrutiny, since fund flows there are easier to disguise. Staff studying this area should also revisit Irac Norms And Wilful Defaulters, since accounts that later turn into wilful-default cases often show early KYC and monitoring gaps that a sharper review could have caught.

The general principles behind spotting irregular customer conduct carry over into recovery practice too — see ethics in loan recovery practices for how fair-conduct norms apply once an account turns delinquent.

⚖️ Governance, Board Oversight and RBI Supervision

None of this works without governance. The board and senior management own the KYC/AML policy, approve risk categorisation criteria, and receive periodic reports on STR filings, exception handling, and V-CIP performance. A designated Principal Officer coordinates with FIU-IND and ensures staff training keeps pace with regulatory circulars.

RBI supervises this through on-site inspections and off-site returns, and gaps in KYC implementation are a recurring theme in supervisory findings across the industry. A weak KYC framework rarely stays contained — it tends to surface later as a branch authorisation or outlet-level control gap, which is why the chapter on branch authorisation policy for banks is worth revising alongside KYC.

Escalation matters just as much as detection. When a customer disputes a KYC-related account freeze or documentation demand, the grievance eventually routes through the bank's internal escalation chain and, if unresolved, to the internal ombudsman in banks before it can reach RBI's Ombudsman scheme. Under the RBI Integrated Ombudsman Scheme 2026, which replaced the 2021 scheme from 1 July 2026, a customer now has 90 days to file a complaint, and compensation ceilings have moved up to ₹30 lakh (and ₹3 lakh for specific categories) — a KYC-linked grievance that drags on can easily invite this scrutiny.

All of this sits inside the bank's wider compliance culture. A branch that treats KYC as paperwork rather than risk control tends to show the same attitude elsewhere, which is why examiners and exam-setters alike link it back to compliance culture in banks as a root cause.

📌 Remember: The Principal Officer is the single point of accountability for STR filing — the exam frequently tests this designation.
Bank KYC governance chain: board oversight, Principal Officer, RBI supervision
Bank KYC governance chain: board oversight, Principal Officer, RBI supervision

📊 Risk Categories at a Glance

The table below summarises how the three standard KYC risk categories differ in practice — useful for quick revision before the BCP paper.

Risk CategoryTypical TriggerReview CycleEnhanced Due Diligence?
Low RiskSalaried individual, stable address, domestic-only transactionsLongest cycle (least frequent updation)
Medium RiskSelf-employed / small business, moderate cash useIntermediate cycle
High RiskPEP, cross-border remittances, cash-intensive business, NGO/trust structuresShortest cycle (most frequent updation)

Notice that the review cycle tightens as risk rises — this risk-based periodicity, rather than a flat calendar rule for every customer, is what RBI's framework is built around, and it is a favourite exam distinction between low, medium, and high-risk accounts.

🧠 Practice MCQs: KYC Compliance Framework for Banks

Q1. Under the KYC Master Direction, which document establishes the bank's policy on who it will onboard as a customer? (a) Customer Identification Procedure (b) Customer Acceptance Policy (c) Risk Management Policy (d) Suspicious Transaction Report

Answer: (b) — The Customer Acceptance Policy defines who the bank accepts as a customer and under what conditions, distinct from identification procedure.

Q2. A customer whose fund flows are cross-border and who holds a politically sensitive public office would normally be classified as: (a) Low risk (b) Medium risk (c) High risk (d) No risk category applies

Answer: (c) — Political exposure combined with cross-border transactions is a classic high-risk trigger requiring Enhanced Due Diligence.

Q3. The Central KYC Registry (CKYCR) issues customers a unique identifier of how many digits? (a) 10-digit (b) 12-digit (c) 14-digit (d) 16-digit

Answer: (c) — CKYCR assigns a 14-digit KYC Identification Number (KIN) so verified KYC data can be reused across reporting entities.

Q4. Suspicious Transaction Reports arising from KYC monitoring are filed with: (a) RBI directly (b) FIU-IND (c) SEBI (d) The local police station

Answer: (b) — STRs go to the Financial Intelligence Unit-India under the PMLA, 2002 and PML Rules framework.

Q5. Which risk category under the KYC framework is subject to the most frequent periodic updation? (a) Low risk (b) Medium risk (c) High risk (d) All categories are updated at the same frequency

Answer: (c) — High-risk customers are reviewed and re-verified on the shortest cycle because their potential for misuse is greatest.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

What is the core purpose of the KYC compliance framework for banks?

It lets a bank verify a customer's identity, judge the money-laundering risk they carry, and monitor their transactions on a cycle matched to that risk — reducing the chance accounts are misused for illicit funds.

Is video-based KYC (V-CIP) legally equivalent to in-branch verification?

Yes, when carried out under RBI's prescribed safeguards — live officer verification, geotagging, and document checks — V-CIP is treated as a valid customer identification method under the Master Direction.

Who is responsible for filing Suspicious Transaction Reports in a bank?

The Principal Officer, designated under the bank's KYC/AML policy, is accountable for reviewing monitoring alerts and filing STRs with FIU-IND.

Do all customers get KYC updated on the same schedule?

No. Updation frequency is risk-based — high-risk customers are reviewed far more often than medium or low-risk customers, in line with RBI's periodicity norms.

The KYC compliance framework for banks is one of the highest-yield topics in the BCP syllabus precisely because it links identification, risk, monitoring, and governance into one chain — break any link and the whole control fails. Revise the CDD-to-STR flow until it is second nature, then test yourself against exam-style questions. Ready to go deeper? Explore the full CAIIB course or head to the Banking Compliance Professional article hub for more topic-wise reads, and check RBI's Master Direction on KYC for the primary source text. For live rate and policy updates relevant to your exam, bookmark IIBF exam news as well.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading