NBFC Account Opening and Operational Compliance: RBI Rules (2026)

NBFC By Ashish Jain · IIBF STORE Editorial · 28 July 2026 · Updated 11 Sep 2026 · 11 min read · 50 views
NBFC Account Opening and Operational Compliance: RBI Rules (2026)

Ask any compliance officer at a deposit-taking or systemically important NBFC what keeps them up at night, and account opening will be near the top of the list. NBFC account opening and operational compliance sits at the intersection of KYC/AML law, RBI's customer service directions, and day-to-day branch or app-based onboarding — and RBI examiners test exactly this intersection during supervisory reviews. This guide walks through the current 2026 rules that govern how an NBFC must onboard a customer, what records it must keep, and how its customer interface has to work — so you can answer exam questions and understand real branch practice with equal confidence.

📋 The Regulatory Framework Behind Account Opening

NBFC account opening does not run on a single rulebook. It draws from the RBI's Master Direction on Know Your Customer (KYC), the Prevention of Money Laundering Act (PMLA) and the Maintenance of Records Rules framed under it, and RBI's Master Direction – Non-Banking Financial Company – Scale Based Regulation, which layers governance obligations on top of the KYC requirements depending on an NBFC's regulatory tier.

Every deposit-taking NBFC (NBFC-D) and every systemically important non-deposit-taking NBFC (NBFC-ND-SI) must have a board-approved KYC policy before it opens a single account. That policy has to spell out the customer acceptance policy, risk categorisation methodology, customer identification procedure, and ongoing monitoring — the four pillars RBI expects every regulated entity to document explicitly, not leave to branch discretion.

Operational compliance also means the NBFC cannot open an account for a walk-in prospect anonymously or under a fictitious name — a standing prohibition under both the KYC directions and the PMLA framework. For a deeper walkthrough of these foundational norms, the chapter on KYC, AML and CFT norms is essential exam reading, and it pairs well with the chapter covering regulatory requirements and compliance for NBFCs generally.

💡 Exam Tip: If a question asks "who approves the KYC policy," the answer is always the Board of Directors — never a branch manager or even the compliance officer alone.
RBI regulatory framework for NBFC account opening and KYC compliance
RBI regulatory framework for NBFC account opening and KYC compliance

🪪 KYC and Customer Due Diligence at Onboarding

Customer Due Diligence (CDD) is the operational engine of NBFC account opening and operational compliance. For an individual, the NBFC must obtain an Officially Valid Document (OVD) for identity and address, a recent photograph, and PAN or Form 60 where PAN is not available. For non-individual entities — companies, partnerships, trusts — CDD extends to identifying the beneficial owner, meaning the natural person who ultimately owns or controls the entity above the prescribed threshold.

Digital onboarding has become the default channel for many NBFCs, and RBI permits both Aadhaar-based e-KYC (OTP or biometric) and the Video-based Customer Identification Process (V-CIP). V-CIP requires a live, consent-based video interaction where the customer displays the original OVD on camera, and the NBFC's official captures a geo-tagged, time-stamped photograph along with facial-match and liveness checks — a paper application photocopied and couriered in does not satisfy this standard.

Risk categorisation follows immediately after identification: every customer is placed into low, medium, or high risk, and that categorisation drives how often the NBFC must refresh KYC information later. High-risk customers, including Politically Exposed Persons (PEPs), attract Enhanced Due Diligence — additional scrutiny of the source of funds and closer transaction monitoring — while low-risk retail customers get simplified, less frequent updation. The chapter on operational aspects of opening accounts covers this workflow step by step and is worth revising alongside the broader customer relationship chapter, which explains the legal character of the NBFC-customer relationship that begins the moment CDD is completed.

🗂️ Record-Keeping, CKYCR, and Documentation Duties

Opening the account correctly is only half the job — NBFCs must then preserve what they collected. Under the Maintenance of Records Rules framed under the PMLA, identification records and account files must be retained for a minimum of five years after the account is closed or the business relationship ends, and transaction records for five years from the date of the transaction. This is a favourite exam figure, so remember it precisely: five years, measured from closure or from the transaction, not from account opening.

NBFCs are also required to upload individual customer KYC records to the Central KYC Records Registry (CKYCR) within the prescribed timeline. CKYCR exists so that once a customer completes KYC with one regulated entity, other financial institutions can retrieve that record instead of repeating the process from scratch — a reform aimed squarely at reducing onboarding friction across the financial system.

Table 1 below summarises how risk categorisation links to periodic KYC updation frequency — a relationship examiners and exam-setters both like to test.

Risk CategoryTypical Re-KYC TriggerEnhanced Due Diligence Applicable
High Risk (incl. PEPs)Shortest periodicity, most frequent review✅ Yes
Medium RiskModerate periodicity as per board policy❌ No
Low RiskLongest periodicity; simplified updation❌ No
⚠️ Common Mistake: Candidates often assume record retention starts from account opening — it actually runs from account closure (for identity records) or from the transaction date (for transaction records).
NBFC customer risk categorisation and record retention timeline
NBFC customer risk categorisation and record retention timeline

🤝 Customer Interface, Service Standards, and Grievance Redressal

Operational compliance is not just about paperwork before the account opens — it governs how the NBFC behaves afterward. Every NBFC-D and NBFC-ND-SI must adopt a Fair Practices Code covering loan appraisal, disclosure of terms, and grievance handling; the mechanics of that code are covered in detail in our companion piece on the Fair Practices Code for NBFCs, which every candidate revising this topic should read alongside this one.

NBFCs must also display the Most Important Terms and Conditions (MITC), interest rate ranges and the methodology for arriving at them, and grievance escalation contacts prominently, whether at the branch or on the app/website. A board-approved Grievance Redressal Policy is mandatory, and complaints must be resolved within defined timelines with an internal escalation matrix. Since 2021, eligible NBFCs are also brought within the RBI Integrated Ombudsman Scheme, giving customers a cost-free, statutory recourse if internal grievance redressal fails.

An NBFC's compliance tier — and therefore how strictly some of these customer-interface obligations bite — is shaped by its classification under scale-based regulation, which in turn interacts with capital adequacy expectations such as Net Owned Fund thresholds and, for financially stressed entities, the PCA Framework trigger points that can restrict fresh lending and onboarding activity. Where an NBFC uses agents or business correspondents to source accounts, the legal principles of agency — covered from a banking angle in our contract of agency for bankers guide — determine how liability for onboarding errors is allocated between the NBFC and its agent.

NBFC customer interface and grievance redressal process flow
NBFC customer interface and grievance redressal process flow

⚠️ Where NBFCs Slip: Common Operational Pitfalls

Supervisory inspections repeatedly flag the same handful of gaps. First, treating V-CIP as optional paperwork rather than a controlled process — skipping liveness checks or reusing an old photograph instead of a live capture invalidates the onboarding. Second, static risk categorisation: assigning a customer to "low risk" at onboarding and never revisiting it even as transaction behaviour changes defeats the purpose of ongoing due diligence.

Third, incomplete beneficial-ownership capture for corporate and trust accounts — a persistent audit finding, since NBFCs sometimes stop at verifying the entity's own KYC without tracing the natural person who controls it. Fourth, CKYCR upload delays, which break the very interoperability the registry was built to enable. Fifth, grievance logs that exist on paper but are not reviewed by the board or a designated committee, which defeats the purpose of having a policy at all.

Each of these gaps traces back to the same root cause: treating account opening as a one-time transaction rather than the start of a continuously monitored relationship. That distinction — between a point-in-time KYC check and an ongoing compliance obligation — is precisely what separates an exam-ready understanding of recent RBI initiatives in this space from a superficial one, and it is also what RBI's supervisory teams probe for during on-site inspections.

📌 Remember: Account opening compliance is judged not at the moment of onboarding but by how consistently the NBFC maintains, updates, and audits that customer record afterward.

📚 RBI's Authoritative Position

For the current, consolidated text of these obligations, always cross-check against the RBI's official Master Direction on Know Your Customer, which is periodically updated and remains the single source of truth examiners and auditors rely on. Treat any secondary summary — including this one — as a study aid, not a replacement for the primary text when a specific threshold or timeline is in question.

Broader background on how NBFCs fit within India's financial architecture, and how their onboarding obligations compare with those of banks and other intermediaries, is covered in the Indian Financial System overview chapter and the chapter on NBFC types and roles, since onboarding obligations can vary slightly by NBFC category.

🧠 Practice MCQs: NBFC Account Opening and Operational Compliance

Q1. Under the Maintenance of Records Rules framed under the PMLA, for how long must an NBFC generally retain customer identification records after an account is closed? (a) 3 years (b) 5 years (c) 7 years (d) 10 years

Answer: (b) — Identification records must be retained for a minimum of five years after the account is closed or the business relationship ends.

Q2. Individual customer KYC records collected by an NBFC must be uploaded to which registry as mandated by RBI? (a) CIBIL (b) CKYCR (c) CERSAI (d) NPCI

Answer: (b) — The Central KYC Records Registry (CKYCR) allows KYC data to be shared across regulated entities, reducing repeat onboarding.

Q3. Which of the following is mandatory for a valid Video-based Customer Identification Process (V-CIP) at an NBFC? (a) A physical branch visit within 30 days of the video call (b) A live, consent-based video interaction with real-time OVD display and liveness check (c) Aadhaar OTP e-KYC alone, without any video component (d) Skipping the liveness check for customers already KYC-compliant elsewhere

Answer: (b) — V-CIP requires a live video interaction where the customer displays the original OVD on camera, with facial-match and liveness verification.

Q4. When must an NBFC apply Enhanced Due Diligence (EDD) to a customer? (a) For every NRE account irrespective of assessed risk (b) For customers assessed as high risk, including Politically Exposed Persons (c) Only for accounts with balances above a fixed rupee threshold (d) EDD is entirely optional and left to branch discretion

Answer: (b) — EDD applies to customers categorised as high risk, including PEPs, and involves closer scrutiny of source of funds and transactions.

Q5. Which body within an NBFC must approve the overarching policy covering KYC, customer acceptance, risk categorisation, and grievance redressal? (a) The compliance officer alone (b) The Board of Directors (c) The branch manager (d) No formal approval is required

Answer: (b) — RBI requires the Board of Directors to approve the comprehensive KYC and customer-interface policy before it is operationalised.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

What is the difference between CDD and EDD in NBFC account opening?

Customer Due Diligence (CDD) is the baseline identity and address verification applied to every customer at onboarding. Enhanced Due Diligence (EDD) adds extra scrutiny — such as verifying the source of funds and more frequent monitoring — and applies only to customers assessed as high risk, including Politically Exposed Persons.

Can an NBFC open an account using only Aadhaar-based e-KYC?

Yes, subject to conditions. Aadhaar-based e-KYC (OTP or biometric) or the Video-based Customer Identification Process is permitted for onboarding, but the NBFC must still apply its risk categorisation and CDD framework, and may require further verification later for accounts assessed as high risk.

How often must an NBFC update KYC records for existing customers?

The periodicity depends on the customer's risk category, as fixed in the NBFC's board-approved KYC policy: high-risk customers are reviewed most frequently, medium-risk customers at a moderate interval, and low-risk customers on a simplified, longer cycle, consistent with RBI's risk-based approach to periodic updation.

What happens if an NBFC fails to maintain proper account-opening records?

Deficient record-keeping can trigger adverse findings in RBI's supervisory inspections and statutory KYC audits, and can expose the NBFC to regulatory action, including directions and monetary penalties, since proper documentation is central to both the KYC Master Direction and PMLA compliance obligations.

✅ Conclusion: Make Onboarding Your Compliance Strength

NBFC account opening and operational compliance is not a checkbox exercise — it is a continuous discipline spanning board-approved policy, disciplined CDD and risk categorisation at onboarding, five-year record retention, CKYCR reporting, and a customer interface that stands up to grievance-redressal scrutiny. For the exam, memorise the specific triggers — five-year retention, board approval, EDD for high-risk customers — and for practice, remember that every one of these rules exists to keep the customer relationship auditable long after the account is opened. Explore more subject coverage on our NBFC blog tag hub, and when you are ready to test yourself, take a full JAIIB-aligned mock test to see how these rules show up in scored questions.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading