Regulatory Reporting for FATCA, CRS & India's RBI/FIU Framework 2026

BCP By Ashish Jain · IIBF STORE Editorial · 18 June 2026 · Updated 15 Sep 2026 · 13 min read · 41 views
Regulatory Reporting for FATCA, CRS & India's RBI/FIU Framework 2026

Regulatory reporting sits at the heart of modern bank compliance. And no certification tests this knowledge more rigorously than the IIBF Banking Compliance Professional (BCP) exam. From the moment a bank opens an account. It is drawn into an interlocking web of domestic. Cross-border reporting obligations.

The two pillars of global automatic exchange of financial information. FATCA (Foreign Account Tax Compliance Act) and CRS (Common Reporting Standard). Together with India's own frameworks under RBI/CIMS.

The Financial Intelligence Unit (FIU-IND). Define what banks must collect, verify, aggregate and transmit. This guide unpacks each layer systematically so BCP candidates build a clear.

Exam-ready map of the entire regulatory reporting ecosystem.

FATCA: Due Diligence and Reporting Obligations for Indian Banks

FATCA was enacted by the United States in 2010. Came into force in 2014. Its core purpose is to prevent US persons from hiding income in foreign financial institutions (FFIs). India signed an Intergovernmental Agreement (IGA) with the US in 2015. Making Indian banks Reporting Model 1 FFIs.

Under this arrangement. Indian banks report directly to the Indian tax authority (CBDT). Which in turn exchanges data with the US Internal Revenue Service (IRS). Rather than banks reporting to the IRS directly.

Account Classification under FATCA

Banks must first classify every account as either a US Reportable Account or an excluded account. The classification uses monetary thresholds and indicia searches. For pre-existing individual accounts. The threshold is USD 50,000 (USD 250,000 for insurance and annuity contracts).

Above the threshold. The bank searches electronic records for US indicia — a US birthplace. A US address.

A US telephone number. Standing instructions to transfer funds to a US account. Or a power of attorney granted to a person with a US address.

Where indicia exist. The account holder must provide a self-certification and. If US, a Form W-9, or if non-US, a Form W-8BEN.

Self-Certification Requirements

Self-certification is the backbone of both FATCA and CRS due diligence. The customer declares their tax residency status. Provides their Tax Identification Number (TIN). Confirms whether they are a Specified US Person. Banks are obligated to rely on self-certification unless it is facially incorrect.

Where the customer refuses to certify. The account must be treated as a US Reportable Account (for FATCA) or a Reportable Account (for CRS). Reported accordingly. Incomplete or withheld self-certifications must be flagged. And on-boarding should not proceed until the form is obtained.

Candidates should note the distinction between pre-existing accounts (which get a curing period). New accounts (for which self-certification is mandatory at on-boarding).

Annual FATCA Reporting to CBDT

Every Reporting Indian Financial Institution (RIFI) submits an annual FATCA return to CBDT by 31 May. The return covers the prior calendar year and captures: name, address, US TIN, account number, account balance/value as of 31 December, gross payments credited (interest, dividends, gross proceeds), and custodial gross income. The CBDT then transmits this data to the IRS. Non-compliance can attract withholding on US-source payments and reputational risk. Banks should also be aware that the definition of 'financial institution' includes custodial institutions, depository institutions, investment entities and specified insurance companies — all are within scope for IIBF BCP purposes. Explore more about compliance frameworks at iibf.store/blog.

FATCA due diligence workflow: account classification, indicia search, self-certification collection and annual CBDT reporting flow for Indian banks
FATCA due diligence workflow: account classification, indicia search, self-certification collection and annual CBDT reporting flow for Indian banks

CRS: Common Reporting Standard and India's Commitment to AEOI

The OECD's Common Reporting Standard was adopted in 2014. Is the multilateral counterpart to FATCA. India committed to Automatic Exchange of Information (AEOI) under CRS from 2017 onwards.

Unlike FATCA, which is bilateral (India–US), CRS covers over 100 jurisdictions. The Indian legal basis is the Income-tax Act. 1961 (Section 285BA and Rule 114H), supplemented by CBDT notifications and guidance notes.

Identifying Reportable Accounts under CRS

CRS reportable accounts are those held by residents of any participating jurisdiction other than India. Banks apply due diligence procedures that mirror FATCA. Are broader in scope. For individuals.

The relevant indicia include: a residential/mailing address in another jurisdiction. Telephone numbers only in another jurisdiction. Standing instructions to transfer funds outside India.

Or a currently effective power of attorney held by a person with an address in another jurisdiction. For new individual accounts opened after 1 July 2017. Self-certification is mandatory before the account is opened.

Entity Due Diligence and Controlling Persons

CRS entity due diligence adds an extra layer. For entities, banks must (a) determine whether the entity itself is a Reportable Account (i.e., resident in a participating jurisdiction), and (b) identify the Controlling Persons of Passive Non-Financial Entities (Passive NFEs) where the entity account balance exceeds USD 250,000. Controlling persons are natural persons who exercise control — typically UBOs with 25% or more ownership. Each controlling person's tax residency and TIN must be obtained via self-certification. This is a favourite exam question area: candidates should be clear that Passive NFEs require look-through, while Active NFEs do not (with limited exceptions). For test-practice on CRS entity due diligence, visit iibf.store/tests.

Annual CRS Return Submission

Like FATCA, the annual CRS return is due by 31 May for the preceding calendar year. The return is filed in the OECD Common Reporting Standard XML schema via the CBDT's Compliance Portal. Reported data includes: account holder name and address, jurisdiction(s) of tax residence, TIN, date of birth, account number, account balance, and income (interest, dividends, other income, gross proceeds). CBDT forwards the data to competent authorities of relevant jurisdictions through the OECD's Common Transmission System. India also receives CRS data from partner jurisdictions, which the Income Tax Department uses for enforcement. More on OECD CRS standards at www.oecd.org.

CRS Common Reporting Standard process: individual and entity due diligence, controlling person identification, CRS XML return submission and OECD AEOI data exchange
CRS Common Reporting Standard process: individual and entity due diligence, controlling person identification, CRS XML return submission and OECD AEOI data exchange

India's Domestic Regulatory Reporting Ecosystem: RBI/CIMS and FIU-IND

Beyond cross-border tax information exchange. Indian banks are embedded in a dense domestic regulatory reporting network. The Reserve Bank of India's Centralised Information Management System (CIMS).

The Financial Intelligence Unit. India (FIU-IND) represent the two most prominent pillars of this ecosystem. And both are directly examined in the BCP certification.

RBI CIMS: Centralised Information Management System

CIMS is the RBI's modern. Integrated data portal, replacing the older XBRL-based reporting system (ORFS). Banks submit over 200 regulatory returns to RBI through CIMS.

Covering capital adequacy. Liquidity (LCR. NSFR).

Asset quality (SMA. NPA classification). Credit (sectoral deployment.

Large exposures), foreign exchange (R-Returns, FCNR balances), and interest rate risk. CIMS uses a structured. Machine-readable format and enables RBI to run near-real-time surveillance on systemic risk.

Key returns BCP candidates must know include:

  • DSB returns — Daily, Weekly, Fortnightly and Monthly statutory returns (SLR, CRR, LCR)
  • XBRL supervisory returns — Capital adequacy (Basel III), NPA and provision coverage
  • Form A and Form B. Balance sheet and P&L data for off-site surveillance
  • R-Returns — Foreign exchange transactions for FEMA compliance monitoring
  • Large Exposure Framework (LEF) returns — Aggregate exposures to connected counterparties

Timely and accurate submission to CIMS is a compliance obligation; delays attract monetary penalties under Section 47A of the Banking Regulation Act, 1949. Banks are required to establish clear ownership of each return, maintain data governance protocols and reconcile returns with core banking systems before submission. Explore RBI guidelines at www.rbi.org.in.

FIU-IND Reporting Obligations

FIU-IND is India's national agency responsible for receiving. Processing. Analysing and disseminating financial intelligence related to money laundering and terror financing.

It was established in 2004 under the Prevention of Money Laundering Act, 2002 (PMLA). Banks are Reporting Entities under PMLA. Must submit the following reports to FIU-IND via its secure online portal:

  1. Cash Transaction Reports (CTR). All cash transactions above ₹10 lakh (or integrally connected transactions) within a month. Submitted by the 15th of the following month.
  2. Suspicious Transaction Reports (STR) — Within 7 days of determining suspicion; no threshold.
  3. Cross-Border Wire Transfer Reports (CBWTR). All international wire transfers of ₹5 lakh or more. Or equivalent, filed monthly.
  4. Non-Profit Organisation Transaction Reports (NTR) — Transactions by NPOs above ₹10 lakh.
  5. Counterfeit Currency Reports (CCR) — When counterfeit notes are detected.

The Principal Officer (PO) designated under PMLA is personally responsible for FIU-IND submissions. Failure to report or delayed reporting attracts penalties up to ₹1 lakh per violation and can result in attachment of property under PMLA. BCP candidates frequently face scenario questions about STR timelines and threshold triggers — practice on iibf.store/games/match to sharpen recall.

India regulatory reporting ecosystem: RBI/CIMS return types, FIU-IND CTR/STR/CBWTR obligations, data governance controls and compliance accountability framework
India regulatory reporting ecosystem: RBI/CIMS return types, FIU-IND CTR/STR/CBWTR obligations, data governance controls and compliance accountability framework

Data Quality, Governance and the Four-Eyes Principle in Regulatory Reporting

Regulatory reporting is only as good as the data underpinning it. Across all frameworks — FATCA. CRS.

CIMS and FIU-IND. Data quality is both a compliance imperative. A recurring BCP exam theme.

Poor data quality leads to incorrect returns. Regulatory queries, penalties and reputational damage. Banks need a structured data governance framework to ensure completeness.

Accuracy, timeliness and consistency of reported data.

Data Quality Dimensions

The key data quality dimensions BCP candidates should know are:

  • Completeness: All required fields populated; no missing TINs, addresses or account numbers.
  • Accuracy: Data matches source systems (core banking. Treasury, custody); no rounding errors or currency conversion mistakes.
  • Timeliness: Returns filed by prescribed due dates. STRs within 7 days; CTRs by the 15th.
  • Consistency: Same balances reported across different returns (e.g.. CIMS balance sheet vs CRS account balance).
  • Validity: TIN formats comply with each country's specific format (e.g.. US SSN/EIN, UK UTR, Indian PAN).

Governance Controls for Regulatory Reporting

Best-practice governance for regulatory reporting includes the following controls. All of which are examined in the BCP paper:

  • Data Lineage Mapping: Documenting how each reported data element flows from originating system through transformation to submission.
  • Maker-Checker (Four-Eyes): All returns prepared by one officer. Reviewed/approved by another before submission. No single point of control.
  • Reconciliation: Pre-submission reconciliation between the return and source system data. Variances above defined thresholds must be escalated before filing.
  • Change Management: Any system change that could affect report output must be assessed via a regulatory impact analysis before implementation.
  • Retention: PMLA mandates record retention for a minimum of 5 years from the date of transaction. FATCA/CRS self-certifications must be retained for 7 years after the account relationship ends.

Banks are also expected to conduct periodic data quality audits, and the internal audit function should independently test a sample of regulatory returns against underlying source data. The Compliance Officer must escalate material data quality deficiencies to the Board's Audit Committee without delay. Find study resources and current IIBF updates at iibf.store/resources/iibf-news.

Technology and Automation in Regulatory Reporting

Modern banks increasingly use RegTech solutions to automate FATCA/CRS due diligence workflows, CRS XML generation and CIMS return production. Automated indicia scanning, TIN validation engines and pre-submission validation tools reduce manual error. However, the compliance function must retain oversight: technology automates execution, not judgment. Banks must also be prepared for regulatory XML schema upgrades (OECD updates CRS schema periodically) and CIMS return format changes notified by RBI. The compliance team should track IIBF regulatory news and RBI circulars to ensure systems stay current. Monitor rate changes and RBI guidance through iibf.store/resources/rbi-rates.

What is the difference between FATCA and CRS reporting for Indian banks?

FATCA is a bilateral US law requiring Indian banks (as Reporting Indian Financial Institutions) to identify US persons. Report their accounts to CBDT. Which passes data to the US IRS. CRS is a multilateral OECD standard requiring Indian banks to identify residents of any of 100+ participating jurisdictions. Report their accounts to CBDT.

Which then exchanges data with those jurisdictions. FATCA applies a 30% withholding sanction as enforcement. While CRS relies on reciprocal data exchange.

Domestic PMLA/IT Act penalties. Both use self-certification and due diligence procedures. But CRS is wider in scope.

What are the key due dates for regulatory reporting returns in India?

Annual FATCA. CRS returns to CBDT are due by 31 May for the preceding calendar year. CTRs to FIU-IND are due by the 15th of the month following the transaction month.

STRs to FIU-IND must be filed within 7 days of the bank forming suspicion. CIMS returns to RBI have varying frequencies: daily (LCR. CRR position).

Fortnightly (SLR). Monthly (Form A/B, sectoral credit), and quarterly (Basel III capital returns). Candidates must memorise due dates as they frequently appear in BCP multiple-choice questions.

What is a self-certification under FATCA/CRS and what happens if a customer refuses?

A self-certification is a written declaration by an account holder (or controlling person of an entity) stating their tax residency. Tax Identification Number (TIN), and US person status. It is required at on-boarding for all new accounts under CRS (from 1 July 2017). When US indicia are detected under FATCA for pre-existing accounts.

If a customer refuses to provide a self-certification. FATCA treats the account as a US Reportable Account. The bank must report it.

Under CRS. The bank must still report the account to the jurisdiction indicated by available indicia. Or treat it as undocumented.

Banks cannot open new accounts for customers who refuse CRS self-certification.

How does data quality impact regulatory reporting compliance?

Data quality failures — missing TINs. Incorrect balances. Wrong currency conversions.

Late submissions — constitute regulatory violations even when the underlying transactions are legitimate. For FATCA/CRS. Incorrect data can cause CBDT to transmit wrong information to foreign tax authorities.

Triggering diplomatic or legal issues. For FIU-IND, an inaccurate CTR or delayed STR attracts penalties under PMLA. For CIMS.

Inaccurate capital adequacy returns can mislead RBI supervisors. Trigger enforcement action under the Banking Regulation Act. Banks must maintain robust data governance with maker-checker controls.

Reconciliation procedures. Periodic internal audit testing of report quality to ensure compliance.

Conclusion: Building Exam Readiness for Regulatory Reporting

Regulatory reporting is not a single obligation. A system of interlocking frameworks. Each with its own scope, methodology, due dates and penalty regime.

For the IIBF BCP exam. Candidates must master: (a) FATCA due diligence procedures. Annual reporting to CBDT.

(b) CRS entity and individual due diligence including controlling person look-through. (c) the self-certification lifecycle from on-boarding to periodic review. (d) FIU-IND reporting under PMLA — CTR.

STR. CBWTR thresholds and timelines. (e) RBI/CIMS return types and governance.

And (f) data quality principles and governance controls. Connecting all of these is the theme of accountability. A named Compliance Officer or Principal Officer is personally liable for each framework.

The best way to cement this knowledge is through active recall and exam simulation. Start your BCP preparation with chapter-wise mock tests at iibf.store/tests and track your progress. Candidates preparing for JAIIB or CAIIB can also build foundational compliance knowledge through the respective courses at iibf.store/course/jaiib and iibf.store/course/caiib. Consistent practice on real exam-pattern questions is the proven route to clearing the BCP certification with confidence.

Quick summary in plain words

In short: keep it simple.

Read each point slow.

Take notes as you go.

Use the free tests to check what you know.

Watch the video if a part feels hard.

Do a bit each day.

Ask us on WhatsApp if you get stuck.

You can pass this exam.

Stay calm and trust your prep.

Come back to this guide often.

Small steps add up fast.

Skim the box below first.

Quick summary in plain words

In short: keep it simple.

Read each point slow.

Take notes as you go.

Watch the video if a part feels hard.

Do a bit each day.

Ask us on WhatsApp if you get stuck.

You can pass this exam.

Stay calm and trust your prep.

Come back to this guide often.

Small steps add up fast.

Skim the box below first.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading