Periodic KYC Updation in Banks: Rules, Risk and Timeline

JAIIB By Ashish Jain · IIBF STORE Editorial · 27 August 2026 · Updated 10 Oct 2026 · 11 min read · 93 views हिन्दी में पढ़ें
Periodic KYC Updation in Banks: Rules, Risk and Timeline

Periodic KYC updation is the mandatory re-verification of an existing customer's identity, address and risk profile at the intervals fixed by the RBI Master Direction on Know Your Customer — at least once every two years for high risk customers, once every eight years for medium risk and once every ten years for low risk. It is deliberately not a fresh account-opening exercise: where nothing in the customer's records has changed, a simple self-declaration through a registered channel closes the loop. For JAIIB Principles and Practices of Banking, this one provision generates more questions than almost any other part of the KYC chapter.

🔍 What Periodic KYC Updation Really Requires

The legal backbone is the Prevention of Money Laundering Act, 2002 read with the PML (Maintenance of Records) Rules, 2005. The operating instructions come from the Master Direction – Know Your Customer (KYC) Direction, 2016, as amended, which you can always pull in its current form from the RBI Master Directions page. Examiners like this layering because candidates routinely credit the wrong instrument for the wrong rule.

Customer Due Diligence at onboarding and periodic updation later are two halves of the same obligation. Onboarding CDD establishes identity and address using an Officially Valid Document (OVD). Periodic updation confirms that the record the bank is still relying on is current — that the customer is alive, traceable, correctly risk-rated, and that the beneficial ownership behind a non-individual account has not quietly shifted.

Three points decide most exam questions. First, the obligation sits on the bank, not the customer; the customer's failure to respond does not discharge the bank. Second, updation is due from the date of opening or the date of the last KYC updation, whichever is later — not from a calendar year-end. Third, "no change" is a valid outcome, recorded as such, and does not require fresh documents.

💡 Exam Tip: Periodic updation is measured from the last KYC updation, not from the last transaction. A dormant account and an active account with the same last-updation date fall due on exactly the same day.

📊 Risk Categories, Timelines and the Due Date Clock

Every customer must be placed in a risk category — low, medium or high — at onboarding, and that rating must be reviewed periodically. The rating drives both the depth of due diligence and the frequency of re-KYC. High risk customers attract Enhanced Due Diligence (EDD): closer transaction monitoring, source-of-funds enquiry and senior-level sign-off. Low risk customers may be handled with simplified measures, but never with no measures at all.

Risk categoryPeriodic updation due at least once inEDD applicable?Typical profile
High risk2 years✅PEPs, non-face-to-face relationships, complex ownership, cash-intensive trades
Medium risk8 years❌Traders, firms and companies with ordinary turnover patterns
Low risk10 yearsSimplified CDD permittedSalaried individuals, pensioners, small-balance accounts with stable activity

Note what the table does not say. The periodicity is a maximum outer limit, not a target date — a bank may update earlier, and must do so whenever it has reason to believe the existing records are inadequate or the risk rating has shifted. A low risk salaried customer who begins receiving large inward remittances should be re-rated immediately, and the two-year clock then applies from that point.

Risk classification itself is confidential. It cannot be disclosed to the customer, and a customer cannot demand to be rated low risk. This confidentiality rule appears frequently as a true/false item, and the same discipline of dating and re-dating records carries over to credit files — see how documentation vintage is treated under principles of lending and types of credit facilities.

Key Concepts — Principles and Practices of Banking
Key Concepts — Principles and Practices of Banking

🧾 Re-KYC Channels: Self-Declaration, V-CIP, Branch and BC

The single biggest change in practice over the last few years is that a branch visit is now the exception, not the rule. Where there is no change in KYC information, the customer may submit a self-declaration to that effect through any registered channel — registered email, registered mobile number, ATM, internet banking, mobile banking, a letter, or a digital channel offered by the bank. No fresh OVD is required.

Where only the address has changed, the customer may declare the new address through the same channels; the bank then verifies the declared address within a reasonable period through positive confirmation. Only where identity particulars themselves have changed, or the existing OVD has expired, does a fresh OVD become necessary.

V-CIP — the Video-based Customer Identification Process — is permitted for periodic updation as well as onboarding, provided the session is live, unscripted, geo-tagged, recorded and conducted by a trained official of the bank. Banks may also route re-KYC through Business Correspondents, which matters enormously for rural and DBT-linked accounts where physical branch access is the real constraint.

  • No change: self-declaration through a registered channel; no documents.
  • Address changed: declaration of new address plus verification by the bank.
  • Identity particulars changed or OVD expired: fresh OVD required.
  • Non-individual accounts: refresh beneficial ownership, authorised signatories and constitution documents.

The six OVDs remain the anchor: passport, driving licence, proof of possession of Aadhaar, Voter's identity card, NREGA job card duly signed by a State Government officer, and the letter issued by the National Population Register. PAN is required separately under tax law but is not an OVD — a distinction that catches a large share of candidates. The same document discipline appears in specialised accounts covered under foreign currency accounts for residents.

❄️ Non-Compliance: Partial Freezing, Notices and Revival

A bank cannot simply stop an account the day updation falls due. The Master Direction requires a graded, notice-driven process, and the sequence is examinable in exactly that order.

  1. Advance intimation before the due date, followed by reminders after it, with at least one communication sent by letter so that the customer is not defeated by a stale mobile number.
  2. Partial freezing after due notice — credits continue to be allowed, debits are disallowed. The account is not closed and the balance is not forfeited.
  3. Full freezing if non-compliance persists, so that the account becomes inoperative for both debits and credits.
  4. Closure only as a last resort, after the prescribed notice, and with the balance paid to the customer.

Two nuances are worth memorising. First, partial freezing means debits stop, credits do not — candidates frequently reverse this. Second, the freeze is instantly reversible: the moment the customer completes periodic updation, the account must be restored to full operation without any fresh account-opening formality.

RBI has also cautioned banks repeatedly against mechanical freezing that inconveniences customers, particularly beneficiaries of government benefit transfers, and against treating re-KYC as a pretext for cross-selling. Handling this well is a customer-service issue as much as a compliance one, and the operational discipline overlaps with the settlement and collection workflows in cash management services.

⚠️ Common Mistake: Assuming a frozen account must be reopened as a new account. It must not — completion of periodic updation revives the same account, with the same number and the same balance.
Process & Framework — Principles and Practices of Banking
Process & Framework — Principles and Practices of Banking

🗂️ CKYCR, the KYC Identifier and Where Re-KYC Meets Credit

The Central KYC Records Registry (CKYCR), operated by CERSAI, is the shared repository that makes repeat KYC across regulated entities unnecessary. When a bank uploads a customer's KYC records, the registry generates a unique KYC Identifier — a 14-digit number — which the customer can quote to any other regulated entity. That entity retrieves the records electronically instead of collecting documents again.

Two conditions matter. The customer need not submit the same documents again unless something has changed, and the entity must still satisfy itself about the customer's identity. CKYCR reduces friction; it does not outsource responsibility. A bank that relies on a stale record and skips its own risk assessment has still failed its CDD obligation.

For lending, re-KYC has a direct operational consequence. Security creation, charge registration and renewal of documents all assume a verified, current borrower identity. Where identity records lapse, enforceability arguments become messier, which is why credit administration teams track KYC due dates alongside document renewal dates. Pair this area with types of charge on securities and with types of collateral, since the same file carries both sets of records.

Retail credit products show the same overlap: sanction limits and margin rules assume a fully KYC-compliant borrower, as the current position on gold loan LTV illustrates. Recent circular-driven changes across the paper are consolidated in JAIIB PPB latest updates, and the analytical habit of reading dated records carries into AFM through cash flow statement for bankers. For the full topic list, browse the Principles and Practices of Banking tag hub, and keep current RBI rates handy for the numerical sections of the paper.

In Practice — Principles and Practices of Banking
In Practice — Principles and Practices of Banking

🧠 Practice MCQs: Periodic KYC Updation

Q1. Under the RBI Master Direction on KYC, periodic updation for a medium risk customer must be carried out at least once in every — (a) 2 years (b) 5 years (c) 8 years (d) 10 years

Answer: (c) — High risk is 2 years, medium risk 8 years and low risk 10 years, reckoned from the last KYC updation.

Q2. A customer confirms there is no change in any KYC information. What is the correct treatment for periodic updation? (a) A fresh OVD must always be obtained (b) A self-declaration through a registered channel is sufficient (c) The account must be frozen until the customer visits the branch (d) V-CIP is compulsory in every such case

Answer: (b) — Where there is no change, a self-declaration via a registered email, mobile number, ATM, internet or mobile banking or a letter completes the updation.

Q3. Which of the following is NOT an Officially Valid Document under the PML (Maintenance of Records) Rules? (a) PAN card (b) Passport (c) NREGA job card duly signed by a State Government officer (d) Voter's identity card

Answer: (a) — PAN is required separately under tax law but is not listed as an OVD; the OVD list covers passport, driving licence, proof of possession of Aadhaar, Voter's ID, NREGA job card and the NPR letter.

Q4. A customer does not comply with periodic updation despite due notice. What is the bank's first prescribed step? (a) Immediate closure of the account (b) Reporting the customer to FIU-IND (c) Partial freezing, where credits are allowed but debits are disallowed (d) Levy of a non-compliance penalty on the balance

Answer: (c) — Partial freezing comes first: credits continue, debits stop. Full freezing and closure follow only if non-compliance persists after further notice.

Q5. Which statement about the Central KYC Records Registry is correct? (a) It removes the need for the bank to carry out customer due diligence (b) It is maintained directly by the Reserve Bank of India (c) The KYC Identifier it generates is a 10-digit number (d) A KYC Identifier can be quoted to fetch existing records instead of submitting documents afresh

Answer: (d) — CKYCR is operated by CERSAI and issues a 14-digit KYC Identifier; the regulated entity still carries out its own due diligence.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Does periodic KYC updation require a branch visit?

Usually not. If there is no change in KYC information, a self-declaration through a registered email, registered mobile number, ATM, internet banking, mobile banking or a letter is enough. A branch visit, V-CIP or a Business Correspondent is needed only when identity particulars have changed or the existing OVD has expired.

From which date is the updation period counted?

From the date of account opening or the date of the last KYC updation, whichever is later. It is not counted from the last transaction date, so an active account and a dormant account with the same last-updation date fall due together.

What is the difference between partial freezing and full freezing?

Under partial freezing the bank allows credits but disallows debits. Full freezing stops both debits and credits and is imposed only if non-compliance continues after further notice. Both are reversed as soon as updation is completed, without opening a new account.

Can a customer ask the bank to change their risk category?

No. Risk categorisation is an internal, confidential assessment by the bank based on identity, social and financial status, business activity and transaction patterns. It is not disclosed to the customer and cannot be negotiated.

🎯 Key Takeaways and Next Step

Remember the three numbers — 2, 8 and 10 years — the direction of partial freezing (debits stop, credits continue), and that PAN is not an OVD. Those three points alone cover most of what this topic contributes to the paper. Work through the full question bank in the JAIIB course and time yourself on a full-length mock before exam week.

Prefer revising from a printed book?

Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.

All books →
Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

Principles and Practices of Banking · 5 questions · instant result
Q1. Assertion (A): Security and risk management is treated as a critical challenge in providing cash management services. Reason (R): Electronic transmission and retrieval of sensitive corporate treasury data require security and trust.
Q2. A corporate wants demand drafts and payable-at-par cheques issued by its bank's branches across the country to be honoured on presentation for payment. Which CMS product directly meets this need?
Q3. A CMS client must push a high-value, time-critical payment of ₹5,00,000 that has to be settled in real time on a one-to-one (gross) basis. Which payment system is appropriate, and what is its regulatory minimum?
Q4. Consider the following statements about CMS services: 1. Cash collection service reduces operational risk and cost. 2. Auto-sweeping facility pools funds at desired locations. 3. NEFT payment electronic channels are used to facilitate bulk disbursements. 4. The cheque/DD drawing arrangement is mainly a tool for the bank to raise long-term capital. Which statements are correct?
Q5. All of the following are RBI initiatives that strengthened the country's payments mechanism, as mentioned in the chapter, EXCEPT:
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading