KYC Norms in Banking: Complete JAIIB PPB Guide 2026

JAIIB By Ashish Jain · IIBF STORE Editorial · 14 June 2026 · Updated 30 Jul 2026 · 12 min read · 21 views
KYC Norms in Banking: Complete JAIIB PPB Guide 2026

KYC norms in banking are the single most reliably tested topic in the JAIIB Principles and Practices of Banking (PPB) paper, and for good reason - they sit at the entry point of every account, every transaction and every audit a banker will ever touch. Yet most candidates treat Know Your Customer rules as a list to be crammed the night before, then lose easy marks the moment the examiner wraps a definition inside a short scenario. This guide fixes that. It rebuilds the entire topic from first principles, in plain English, so you understand why each rule exists and can apply it under exam pressure rather than merely reciting it.

Whether you are sitting PPB for the first time or revising in the final week, treat this as your one-stop reference. We cover the four pillars of a KYC policy, risk categorisation, Customer Due Diligence, Officially Valid Documents, Video-KYC, periodic updation and the link to anti-money-laundering law - then turn all of it into a usable study plan.

Key Takeaways
  • A bank's KYC policy rests on four elements: Customer Acceptance Policy, Customer Identification Procedures, Risk Management and Monitoring of Transactions.
  • Customers are graded low, medium or high risk, and the depth of due diligence scales with that grade.
  • Officially Valid Documents (OVDs) establish identity and address; PAN or Form 60 is required for most accounts.
  • V-CIP allows fully remote, consent-based video KYC with liveness and geo-tagging checks.
  • KYC is a continuous process - periodic updation is risk-based, and the whole framework feeds directly into AML reporting.

For a guided video walkthrough that pairs with the notes below, here is the Learning Sessions class on this exact topic:

KYC norms in banking JAIIB PPB video class
Watch the full KYC norms in banking session before you revise the written notes.

What KYC Norms in Banking Actually Mean

At its core, Know Your Customer is a risk-management discipline, not a form-filling chore. The objective is simple to state and hard to do well: a bank must know who its customer genuinely is, understand the nature of their dealings and stay alert to anything that does not fit. Done properly, KYC norms in banking protect three parties at once - the bank from fraud and regulatory penalty, the customer from identity misuse, and the wider financial system from being used to launder illicit money.

The framework flows from the RBI Master Direction on KYC, which itself draws on the Prevention of Money Laundering Act and its rules. For PPB, you do not need to memorise circular numbers, but you do need the architecture cold, because almost every question is built on it.

The Four Elements of a KYC Policy

Every bank's board-approved KYC policy must contain four building blocks. Examiners love these because they invite clean one-mark questions - so learn them in order and be able to describe each in a sentence.

  • Customer Acceptance Policy (CAP) - the rules for on-boarding. No account is opened in an anonymous or fictitious name, and none is opened where identity cannot be verified.
  • Customer Identification Procedures (CIP) - establishing the customer's identity and verifying it using reliable, independent documents, data or information.
  • Risk Management - categorising customers by risk and applying due diligence in proportion to that risk.
  • Monitoring of Transactions - ensuring the actual transaction pattern matches the customer's declared profile, and flagging deviations.

A useful memory hook is that the four elements mirror the customer life cycle: you accept, then identify, then assess risk, then monitor for as long as the relationship lasts. If you can sketch that sequence on rough paper in the hall, the direct questions become almost automatic.

KYC norms in banking customer due diligence and risk categorisation overview for JAIIB PPB
The KYC framework at a glance - acceptance, identification, risk grading and ongoing monitoring.

Risk Categorisation and Customer Due Diligence

Once a customer is accepted and identified, the bank must grade the risk they pose. Customers are classified into low, medium and high risk based on factors such as identity, social and financial status, the nature of business or activity, and the country of origin or operation.

The depth of Customer Due Diligence (CDD) then scales with that grade. Low-risk customers attract simplified diligence, while high-risk customers - politically exposed persons, certain non-residents, trusts and complex legal entities - attract Enhanced Due Diligence (EDD). Applying the correct level to a given customer is precisely the kind of judgement PPB scenarios test.

Two sub-topics recur often. First, Politically Exposed Persons (PEPs): accounts for PEPs require senior-management approval, the source of funds must be established, and the relationship must be monitored more closely. Second, the beneficial owner - the natural person who ultimately owns or controls a legal entity. For companies the controlling-interest threshold is generally taken at 10%, while for partnerships and unincorporated bodies and trusts it is generally 15%. These thresholds are frequently tested verbatim, so commit them to memory and lock them in on our JAIIB matching games.

OVDs, Form 60 and Video-KYC

To identify a customer, banks rely on Officially Valid Documents (OVDs). The accepted list for individuals includes the passport, the driving licence, the Voter ID, the Aadhaar number (subject to the customer's consent), the NREGA job card and the PAN. Note one frequently examined nuance: PAN serves as proof of identity only, not of address.

Where the OVD submitted does not carry the customer's current address, a supplementary document such as a recent utility bill may be accepted for a limited period, after which an updated OVD is required. PAN, or Form 60 where the customer does not hold a PAN, is mandatory for most accounts.

The biggest practical change in recent years is the Video-based Customer Identification Process (V-CIP). V-CIP lets a bank complete identification entirely remotely through a live, consent-based video interaction that incorporates liveness checks and geo-tagging, so that genuine presence and location can be confirmed. For the exam, connect V-CIP to the broader themes of digital banking and financial inclusion - it is the bridge that lets KYC keep pace with branchless on-boarding. The detailed rules sit within the RBI Master Direction; you can confirm any time-sensitive specific on the official IIBF website and the regulator's master direction.

Periodic Updation and the AML Linkage

A point candidates routinely miss is that KYC is never finished. Banks must carry out periodic updation on a risk-based cycle - longest intervals for low-risk customers, shorter for medium-risk and shortest for high-risk customers, as per the latest released RBI Master Direction (always confirm the current intervals on the official notification before quoting them). If there has been no change in the customer's information, a self-declaration is sufficient; failure to update can lead to the account being restricted, which is why customers are reminded well in advance.

Crucially, KYC feeds directly into Anti-Money Laundering (AML) obligations under the Prevention of Money Laundering Act. Banks must file Cash Transaction Reports (CTRs), Suspicious Transaction Reports (STRs) and other prescribed reports with the Financial Intelligence Unit - India (FIU-IND). The examiner wants you to see KYC as the first line of defence in the AML chain rather than a stand-alone task. Get this linkage right and case-study questions that combine on-boarding, monitoring and reporting fall into place. A solid grounding here also supports the wider depositor-protection syllabus covered in our Deposit Insurance and RBI Ombudsman Scheme guide.

Quick Reference: Risk Categories and Due Diligence

Use the table below as a one-glance revision aid. It maps each risk grade to the typical customer profile and the level of due diligence the bank must apply.

Risk CategoryTypical Customer ProfileDue Diligence Applied
LowSalaried individuals, low-balance savings, well-documented identitySimplified due diligence; longest periodic-updation cycle
MediumSelf-employed, small businesses, higher transaction volumesStandard CDD; intermediate updation cycle
HighPEPs, certain non-residents, trusts, complex entitiesEnhanced Due Diligence; source of funds; closest monitoring

For the exact updation intervals attached to each row, refer to the prevailing RBI Master Direction rather than memorising a number that may change - the principle that the cycle shortens as risk rises is what the examiner is really after.

A 7-Day Study Plan for the KYC Section

Knowing the theory is half the battle; converting it into marks needs deliberate practice. Here is a compact plan you can slot into your final revision week for PPB.

  1. Day 1-2: Build a one-page master sheet - the four elements, the three risk categories, the beneficial-owner thresholds (10% and 15%) and the OVD list. Recite the four elements until the order is automatic.
  2. Day 3: Study V-CIP and periodic updation together, framing both as the digital and ongoing faces of the same discipline.
  3. Day 4: Map the AML linkage - CTR, STR and FIU-IND - and practise explaining why KYC is the first line of defence.
  4. Day 5: Attempt a timed mock and review every wrong answer. Reinforce with our JAIIB mock tests built to mirror the live PPB pattern.
  5. Day 6: Drill terminology with active recall and our match games, focusing on easily confused pairs.
  6. Day 7: Skim recent regulatory updates and re-read your master sheet aloud. Browse the full set of JAIIB study guides for any gaps.

This topic also rewards strong fundamentals in the rest of the paper, so make sure your broader PPB preparation is on track through the Principles and Practices of Banking course and the wider JAIIB course hub.

Common Mistakes Candidates Make

Most lost marks on KYC come from a handful of avoidable errors. Watch for these.

  • Memorising without applying. The examiner often hides the four elements or the risk grades inside a short case. Practise translating each concept into a worked example, not just a definition.
  • Confusing PAN with an address proof. PAN establishes identity only - a separate document is needed for current address.
  • Mixing up the beneficial-owner thresholds. Keep 10% (companies) and 15% (partnerships, unincorporated bodies, trusts) distinct and rehearsed.
  • Treating KYC as a one-time event. Forgetting periodic updation, or its risk-based cadence, is a classic slip.
  • Missing negatively-phrased stems. Questions asking which option is NOT correct trip up even strong candidates - read every stem twice.

Frequently Asked Questions

What are the four key elements of a KYC policy?

The four elements are the Customer Acceptance Policy, Customer Identification Procedures, Risk Management and Monitoring of Transactions. Together they cover on-boarding, verifying identity, grading risk and watching the relationship over time. Direct one-mark questions frequently ask you to list all four in order.

What is Enhanced Due Diligence and when is it applied?

Enhanced Due Diligence (EDD) is deeper scrutiny reserved for high-risk customers such as politically exposed persons, certain non-residents and trusts. It involves establishing the source of funds, obtaining senior-management approval for the relationship and applying closer ongoing monitoring. It is the opposite end of the spectrum from the simplified diligence used for low-risk customers.

How often must KYC be updated?

KYC updation is risk-based: the cycle is longest for low-risk customers, shorter for medium-risk and shortest for high-risk customers, as per the latest RBI Master Direction. If there is no change in the customer's information, a self-declaration is enough. Always confirm the exact intervals on the official notification before relying on a specific figure.

What is V-CIP in banking?

V-CIP stands for the Video-based Customer Identification Process, a consent-based method of completing KYC remotely through a live video interaction. It uses liveness detection and geo-tagging to confirm the customer is genuinely present and to capture their location. It is now widely used for fully digital account opening.

Who is a beneficial owner under KYC norms?

A beneficial owner is the natural person who ultimately owns or controls a legal entity or on whose behalf a transaction is conducted. For companies the controlling interest is generally taken at a 10% threshold, and for partnerships, unincorporated associations and trusts at 15%. Identifying this person prevents entities being used to mask the real party behind an account.

How do KYC norms connect to anti-money-laundering rules?

KYC is the first line of defence in the AML framework under the Prevention of Money Laundering Act. By knowing the customer and monitoring transactions, banks can detect activity that does not fit a customer's profile and file Cash Transaction Reports and Suspicious Transaction Reports with FIU-IND. Strong KYC therefore makes the entire AML reporting chain effective.

Final Word

Master the four elements, the risk categories, the OVD list, Video-KYC and periodic updation, and you will comfortably clear the KYC questions in PPB - they are among the most predictable marks in the whole paper. The trick is to treat KYC norms in banking as a living, risk-based process linked to AML, not a static checklist to be parroted. Lock in the framework, practise applying it to scenarios, and walk into the hall knowing this section is a dependable scorer.

Related Guides

📚 Free Learning Sessions resources — connect & crack your exam

💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.

📱 Study on the go — get our iOS & Android app at iibf.store/app.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

Principles and Practices of Banking · 5 questions · instant result
Q1. Why do banks increasingly promote cash management (fee-based) services rather than relying only on traditional lending? Which is the most logical reason?
Q2. A corporate wants to route a payment of exactly ₹1,90,000 through RTGS for instant settlement. As per RBI's RTGS rules, what is the technically correct position?
Q3. Regarding the challenges and issues in offering cash management services, consider: 1. Bankers need to comprehend the client's line of activity. 2. Decisions regarding sourcing of software (in-house, vendor, or outsourced). 3. Making the Internet a reliable business system (operational reliability). 4. Cash management services should be denied to small and medium companies. Which are correct?
Q4. A company with numerous supplier, salary and statutory payments to beneficiaries holding accounts in many bank branches across the country wants these credited electronically in bulk. Which combination of CMS services best fits?
Q5. Which statement about the importance of cash management services for banks is correct?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading