Re-KYC Periodicity and CDD Rules Bankers Must Know
Three terms get used interchangeably at branch counters and they should not be. KYC is the overall obligation, customer due diligence is the process of discharging it, and re-KYC is the periodic refresh of records already held. Get those straight and the re-KYC periodicity rules stop feeling arbitrary — they are simply the refresh interval attached to a customer's risk category, and the risk category is itself an output of due diligence.
KYC, CDD and Re-KYC explained · Watch on YouTube
What customer due diligence actually means
CDD is not a form. It is the set of steps a regulated entity takes to know who it is dealing with: identifying the customer, verifying identity from reliable independent documents, identifying the beneficial owner where the customer is not a natural person, and understanding the intended nature of the relationship. Only after these steps does risk categorisation happen, and only then does a refresh interval attach.
Two variants matter. Simplified due diligence applies to lower-risk situations and permits a lighter touch. Enhanced due diligence applies where risk is higher — politically exposed persons, complex ownership structures, unusually large or unexplained transactions — and requires additional information and closer ongoing monitoring. Enhanced measures are not a punishment; they are a proportionate response to a risk profile.

The intervals themselves
Under the Reserve Bank's Master Direction on Know Your Customer, periodic updation of KYC records is carried out at least once in every two years for high-risk customers, eight years for medium-risk customers and ten years for low-risk customers.
| Risk category | Refresh interval | Typical supervisory expectation |
|---|---|---|
| High risk | At least once every two years | Closer transaction monitoring and enhanced due diligence measures |
| Medium risk | At least once every eight years | Standard monitoring against the declared profile |
| Low risk | At least once every ten years | Simplified measures where permitted |
The word "periodic" is doing real work here. These are outer limits, not schedules to be met complacently. If a customer's transaction behaviour diverges materially from the profile on record, the relationship is reviewed then — not at the next due date. Ongoing monitoring is a continuous obligation that sits alongside the calendar-based refresh, and treating the interval as the whole duty is precisely the error supervisory findings tend to highlight.
There is also relief on timing. Under an RBI direction issued in June 2025, KYC updates falling due were permitted to be completed within one year of falling due, or up to 30 June 2026, whichever is later. Confirm the position applicable on your date from the Master Direction on rbi.org.in, since transitional relaxations are exactly the kind of provision that lapses quietly.

What a re-KYC actually involves
Less than customers fear, in most cases. If there is no change in KYC information, a self-declaration from the customer is generally sufficient, and it can be obtained through channels the bank already offers rather than requiring a branch visit. If only the address has changed, a declaration of the new address is obtained and then verified within the prescribed timeline. A full re-verification is required where identity information itself has changed or where the earlier documents were deficient.
This distinction matters at the counter. Asking every customer for a fresh document set at every refresh is over-collection, and it generates the complaints and account-freeze grievances that reach the ombudsman. Under-collecting is the opposite failure and carries regulatory consequence. The correct answer is proportionality, which is the same principle running through the whole framework.
Why this appears in every certification paper
KYC and AML sits at the intersection of the Prevention of Money Laundering Act, the RBI Master Direction and the bank's own board-approved policy. Questions rarely ask you to recite a rule; they describe a customer and ask what should happen next. That is why the re-KYC periodicity intervals are worth committing to memory but are not sufficient on their own — you also need the reasoning that produced the risk category in the first place.
For structured coverage, the compliance and KYC-AML certification material is listed on the iibf.store blog, and the flagship syllabus overlap is set out on the JAIIB and CAIIB course pages — Principles and Practices of Banking covers the same ground from the operational side. To check recall rather than recognition, run a mixed set on the practice tests.
One habit is worth building whatever your role. Before answering any question in this area, ask what the customer's risk category is. Almost every rule in the framework — the depth of due diligence, the monitoring intensity, the re-KYC periodicity itself — follows from that single classification. Candidates who start from the risk category get these questions right consistently; candidates who start from the document list do not.
A simple way to hold the rule in your head
Start with risk. High risk means two years. Medium risk means eight years. Low risk means ten years. That is the whole table.
Then ask what has changed. If nothing has changed, a self-declaration is enough. If only the address has changed, take a fresh declaration for it. If identity details have changed, run the full check again.
Then watch the account itself. A due date is not the only trigger. Odd transactions call for a review at once. Waiting for the next cycle is a mistake.
Bankers who follow this order rarely get the answer wrong. Risk first, then change, then the account. Keep that order in mind and the rest of the framework tends to follow on its own. It also matches the way the questions are framed in the exam.
Frequently asked questions
How often must re-KYC be done?
At least once every two years for high-risk customers, eight years for medium-risk and ten years for low-risk, per the RBI Master Direction on KYC. These are outer limits, and an out-of-cycle review is expected if behaviour diverges from the recorded profile.
Do I have to visit the branch for re-KYC?
Not usually. Where there is no change in KYC information, a self-declaration is generally sufficient and can be submitted through the channels the bank offers. A branch visit or fresh verification is needed only where identity information has changed or earlier records were deficient.
What is the difference between CDD and re-KYC?
CDD is the process of identifying and verifying a customer and understanding the relationship, performed at onboarding and whenever circumstances require. Re-KYC is the periodic refresh of records already collected, timed by risk category.
What triggers enhanced due diligence?
Higher-risk indicators such as politically exposed persons, opaque beneficial ownership, non-face-to-face onboarding in certain cases, or transactions inconsistent with the declared profile. It means more information and closer ongoing monitoring, not refusal of service by default.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading