Periodic KYC Updation Rules: Re-KYC Timelines by Risk Category (2026)
The periodic KYC updation rules laid down by the Reserve Bank of India tell every bank exactly how often a customer's KYC record must be refreshed, and the interval depends entirely on the customer's assigned risk category. This is not the same exercise as the KYC done at account opening — periodic updation, commonly called re-KYC, is a recurring obligation that continues for as long as the account stays open. For JAIIB and CAIIB candidates, and for bankers handling day-to-day compliance, knowing the exact re-KYC timelines by risk category — and what happens when a customer ignores the bank's updation notice — is a frequently tested, operationally important area.
🔄 What Is Periodic KYC Updation (Re-KYC)?
Periodic KYC updation is the recurring review a bank must carry out on every existing customer's identification records, independent of the one-time KYC completed when the account was opened. The objective is straightforward: addresses change, occupations change, income levels change, and officially valid documents can lapse. Without a periodic refresh, a bank's customer database would slowly drift out of date, weakening the very due-diligence framework KYC is meant to support.
Re-KYC applies across customer types — individual savings and current account holders, sole proprietorships, and other non-individual constituents — not just to new-to-bank relationships. It is distinct from event-driven due diligence, where a bank refreshes a record because of a specific trigger such as an unusual transaction pattern or a change in beneficial ownership. Periodic updation, by contrast, is calendar-driven: it falls due on a schedule set by the customer's risk category, whether or not anything unusual has happened in the account. The statutory backbone for this obligation sits in India's AML/CFT legal architecture; for the underlying framework, see the chapter on legislation at the national level. Understanding this distinction — periodic vs event-driven review — is a common examiner trap, since both feed into ongoing due diligence but are triggered differently.
💡 Exam Tip: If a question describes a bank acting because of a suspicious transaction, that is event-driven due diligence — not periodic KYC updation. Periodic updation is the calendar-based obligation tied to risk category.
⏳ Re-KYC Timelines by Risk Category
Under the extant RBI instructions on periodic updation, the frequency of re-KYC is tiered by the risk category the bank has assigned to the customer at onboarding and revised thereafter. The broad pattern followed by banks is that high-risk customers are reviewed the most often, medium-risk customers at a longer interval, and low-risk customers least frequently of all, since they present the smallest window of concern for misuse of the account. The precise cadence for each tier is commonly stated as roughly once every two years for high risk, roughly once every eight years for medium risk, and roughly once every ten years for low risk — with individual banks free to tighten (never loosen) these outer limits in their board-approved KYC policy.
The risk category itself is not decided at random — it flows from the customer risk assessment done under the bank's KYC policy, based on factors like customer profile, geography, and the nature and volume of expected transactions. For the mechanics of how that classification is arrived at, see the companion article on customer risk categorisation in KYC. Certain limited-document accounts opened under relaxed norms (sometimes called small accounts) carry their own shorter, separately defined validity window under the PMLA Rules, independent of the risk-tier schedule described here — always check the specific product's terms rather than assuming the general timeline applies.
| Risk Category | Typical Re-KYC Periodicity | Branch Visit Usually Mandatory? | Digital / Self-Certification Allowed? |
|---|---|---|---|
| Low | ~Every 10 years | ❌ No, if no change reported | ✅ Yes |
| Medium | ~Every 8 years | ❌ No, if no change reported | ✅ Yes |
| High | ~Every 2 years | ✅ Usually yes | ✅ Yes, with tighter conditions |
⚠️ Watch Out: The periodic updation clock does not override event-driven checks. Even a low-risk account due for re-KYC only once a decade can be pulled up early for enhanced review if the transaction pattern or profile changes materially in between.

📱 How Banks Carry Out Re-KYC: Digital and Branch Modes
RBI's framework does not force every customer into a branch queue for periodic updation. Where the customer confirms there is no change in the KYC information already on record, banks may accept a self-declaration through channels such as registered mobile number, registered email id, ATM, net-banking, mobile banking app, or through a business correspondent — without insisting on a fresh set of documents. Where there is a change, or where the bank's policy calls for a fuller review, updation can still be completed without a physical visit through Video-based Customer Identification Process (V-CIP), subject to the safeguards that apply to that channel.
High-risk customers are generally not offered the lightest-touch self-certification route, precisely because periodic updation for this segment is meant to re-validate the entire risk profile, not merely confirm that nothing has changed. Banks handling cross-border or correspondent relationships layer in additional scrutiny during updation, since exposure to higher country risk compounds the consequences of stale records — see the chapters on correspondent banking and country risk for that context. Because digital and video-based updation depend on secure channels, the same weaknesses that expose banks to phishing and credential theft — covered in computer insecurity in banking — are directly relevant to how safely a bank can run a remote re-KYC process. A poorly secured OTP or e-mail channel used for self-certification is itself an AML/CFT control gap, not just an IT problem.
🚫 Non-Compliance: Reminders and Partial Freezing
When a customer does not respond to a bank's periodic updation notice, the response is graduated rather than immediate. Banks typically issue reminders — through letters, SMS, and email — asking the customer to submit updated information or documents by a given date. Only if the customer continues to remain non-compliant after adequate notice do RBI's instructions permit the bank to move to restrictive action, most commonly a partial freezing of the account: certain debit operations are curtailed while credits generally continue to be allowed, rather than the account being shut down outright.
This graduated approach is deliberate — it balances the bank's AML/CFT obligation to keep records current against the customer's right to fair notice and an opportunity to comply before facing restrictions. Once the customer completes the pending updation — often achievable through the same digital or branch channels described above — the freeze is expected to be lifted without further delay. Escalation of unresolved non-compliance beyond partial freezing follows the supervisory structure set out for banks in India; see organisation structure in India for how AML/CFT oversight is layered between the bank, the regulator, and FIU-India.
📌 Remember: Partial freezing is a graduated compliance measure, not a penalty for suspected money laundering. A customer who was never under any adverse-media or transaction-monitoring flag can still be partially frozen purely for missing a routine re-KYC deadline.

🧠 Practice MCQs: Periodic KYC Updation
Q1. What is the generally prescribed periodicity for re-KYC of high-risk customers under RBI's KYC norms? (a) Every 2 years (b) Every 5 years (c) Every 8 years (d) Every 10 years
Answer: (a) - High-risk customers need closer monitoring, so re-KYC is due roughly every two years, well ahead of the medium- and low-risk schedules.
Q2. Under the periodic KYC updation rules, low-risk customers are typically required to complete re-KYC: (a) Every 2 years (b) Every 8 years (c) Every 10 years (d) Every 15 years
Answer: (c) - Low-risk accounts carry the longest interval, commonly cited as roughly once every ten years, reflecting their lower exposure to misuse.
Q3. Which of the following is TRUE about digital or self-certification modes for periodic KYC updation? (a) Not permitted for any customer (b) Permitted only where the customer confirms no change in KYC information (c) Permitted only for high-risk customers (d) Requires a fresh officially valid document every single time
Answer: (b) - Self-certification through registered channels is accepted specifically when there is no change to update, sparing the customer a document resubmission.
Q4. If a customer does not respond to a bank's periodic KYC updation notices even after reminders, the bank may: (a) Close the account immediately without notice (b) Apply partial freezing of the account (c) Initiate criminal prosecution directly (d) Take no action at all
Answer: (b) - After due reminders go unanswered, RBI's instructions permit graduated restriction through partial freezing, not immediate closure or prosecution.
Q5. How does periodic KYC updation differ from customer risk categorisation? (a) They are identical processes (b) Risk categorisation decides the re-KYC timeline; updation is the calendar-based act of refreshing the record (c) Risk categorisation happens only once and never affects re-KYC afterward (d) Re-KYC entirely replaces the need for risk categorisation
Answer: (b) - Risk categorisation feeds the schedule; periodic updation is the recurring compliance action carried out on that schedule.
Want chapter-wise mock tests with 100+ MCQs? Start practising free

❓ Frequently Asked Questions
What is the standard periodicity of re-KYC for low-risk customers?
Low-risk customers are typically due for periodic KYC updation on the longest interval among the three risk tiers, commonly cited as roughly once every ten years, unless an intervening event calls for an earlier review.
Do I need to visit my branch physically for periodic KYC updation?
Not always. If there is no change in your KYC information, most banks accept self-certification through registered mobile number, email, net-banking, or a business correspondent. High-risk customers, or cases involving a change in details, are more likely to need a branch visit or Video-based Customer Identification Process.
What happens if I miss my bank's re-KYC deadline?
The bank will typically send reminders through letters, SMS, or email. If you remain unresponsive after due notice, the bank may apply partial freezing on debit transactions in the account until the updation is completed.
Is periodic KYC updation the same as customer risk categorisation?
No. Risk categorisation is the ongoing process of classifying a customer as low, medium, or high risk. Periodic KYC updation is the separate, calendar-based obligation to refresh records, and the risk category assigned to a customer is what determines how often that updation falls due.
Periodic KYC updation is one of the more procedural but heavily tested corners of the KYC-AML syllabus, and it rewards candidates who can map risk category directly to timeline, mode, and consequence. Reinforce this with the full three stages of money laundering picture and the escalation logic in enhanced due diligence for high-risk customers, then browse the full KYC, AML and CFT topic hub for related chapters. Ready to test what you have learned? Attempt free chapter-wise questions at iibf.store/tests or work through the complete syllabus with the CAIIB course on iibf.store.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.