NBFC AML Obligations: A Practical Checklist under RBI’s Master Directions

On 28 November 2025 the Reserve Bank repealed the KYC Master Direction of 2016 and issued ten entity-specific instruments. NBFCs now read one written for them. Here is what it requires, how it meshes with the RBI’s Internal Risk Assessment guidance, and what the first enforcement cycle is saying.

The instrument is the Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Directions, 2025, RBI/DOR/2025-26/361, dated 28 November 2025.1 One amendment, on 29 December 2025, added an Explanation to paragraph 63: the regulated entity that last uploaded or updated a customer’s KYC records on the CKYCR verifies identity and address, so an NBFC relying on those records need not re-verify them if they are current and PMLA-compliant, while remaining responsible for every other aspect of CDD.2 No later revision is notified.1 A house policy still citing the 2016 Master Direction cites a repealed instrument.

A note on scope. This article is about NBFCs and cites the NBFC Directions alone. Nine other entity-specific KYC instruments issued the same day differ in content and paragraph numbering, so nothing below should be read across to another regulated entity.

Why NBFCs needed a Direction of their own

Partly legal. One 2016 instrument had to reach banks, NBFCs, payment system operators and authorised persons at once. The NBFC Directions rest on sections 45JA, 45K and 45L of the RBI Act, 1934, with powers under the PSS Act, 2007, FEMA, 1999, the NHB Act, 1987 and the PML Rules, 2005.1 No Banking Regulation Act power appears in that list.

Partly behavioural, though one shorthand needs correcting. NBFCs cannot accept demand deposits, a genuine statutory dividing line, but they are not absent from payments. An NBFC authorised under the PSS Act can issue prepaid instruments and run wallet and card products, and the Directions assume as much: paragraph 21(4) requires customer identification on payment of credit card dues and on the sale or reloading of prepaid and travel cards, and paragraph 69 imposes wire transfer information requirements.1 Payment capability sits alongside a book originated overwhelmingly through third parties, against collateral often portable and liquid, so layering and integration risk through repayment, prepayment and collateral release runs high. NBFC credit stood at ₹57.8 trillion in June 2026, up 14.4 per cent year on year.3

Scope is broad, carve-outs narrow. Paragraph 3 applies the Directions to all categories of NBFC and all layers, unless specified otherwise, excluding only NBFCs with no customer interface. Paragraph 4 extends them to branches and majority-owned subsidiaries abroad so far as they do not contradict host-country law, requiring the more stringent standard wherever the two vary.1

The practical checklist

Twelve obligations out of many, not a summary. This list still leaves out the Designated Director and Principal Officer under paragraphs 14 and 15, and the CKYCR, UCIC and money mule provisions under paragraphs 63 to 67. Each item carries its paragraph anchor.

  1. Board-approved KYC policy. Paragraph 6 requires a policy approved by the Board, or a committee to which the Board has delegated power, on four elements: customer acceptance, risk management, customer identification procedures and monitoring of transactions. It must also cover periodic updation, exceptional measures, proof of change of address, updation at any branch, and change of registered mobile number on non-face-to-face accounts.
  2. Enterprise ML/TF risk assessment. Paragraph 10 requires a documented assessment across clients, countries, products, services, transactions and delivery channels, proportionate to the nature, size, geographical presence and complexity of the NBFC. The Board, or its delegated committee, sets periodicity, but review must be at least annual, and the outcome goes to the Board and must be made available to competent authorities and self-regulating bodies. Paragraph 11 requires a risk-based approach with Board-approved controls.
  3. Assurance, and what cannot be outsourced. Paragraph 12 requires the NBFC to specify who constitutes senior management for KYC purposes, allocate responsibility for effective implementation of policies and procedures, provide independent evaluation of the compliance function including legal and regulatory requirements, run a concurrent or internal audit system to verify compliance, and submit quarterly audit notes and compliance to the Audit Committee. Paragraph 13 prohibits outsourcing the decision-making functions of determining compliance with KYC norms.
  4. Customer acceptance discipline. Paragraph 17 prohibits anonymous and benami accounts, and bars opening any account where the NBFC cannot apply appropriate CDD because of non-cooperation or unreliable documents. It applies CDD at UCIC level, requires a system ensuring no customer matches the Chapter IX sanctions lists, and requires PAN, where obtained, and GST, where available, verified from the issuing authority. Paragraph 18 provides that the Customer Acceptance Policy shall not deny a financial facility to the financially or socially disadvantaged, including Persons with Disabilities, and forbids rejection without application of mind. Paragraph 19 requires an STR in place of CDD where CDD would tip off the customer.
  5. When identification is required. Paragraph 21 lists the occasions: commencement of an account-based relationship; international money transfer operations for a person who is not an account holder; doubt about the authenticity or adequacy of identification data already obtained; selling third-party products as agents or its own products, payment of dues of credit cards, and the sale or reloading of prepaid or travel cards; transactions for a walk-in customer where the amount is equal to or exceeds ₹50,000, whether as a single transaction or several that appear connected; and reason to believe a customer is structuring transactions below that threshold. It also bars the NBFC from seeking introductions while opening accounts. Note the drafting. Sub-paragraph (4) closes with the words “and any other product for more than ₹50,000”, while sub-paragraph (5) reads “equal to or exceeds ₹50,000”. Whether the threshold in (4) governs the whole limb or only its residual clause is not free from doubt, and a policy applying one operator across the paragraph will be wrong somewhere. Take a documented position rather than an implicit one.
  6. Risk categorisation and the six-month clock. Paragraph 20 requires low, medium and high categorisation on documented parameters, kept confidential from the customer. Paragraph 41(1) requires periodic review of that categorisation at least once every six months, and establishment of any need for enhanced due diligence.
  7. Onboarding routes, limits and reliance. Paragraph 25 caps Aadhaar OTP-based e-KYC accounts opened non-face-to-face: deposit balances not exceeding ₹1 lakh, credits not exceeding ₹2 lakh a financial year, borrowal accounts confined to term loans of not more than ₹60,000 a year, and no operation beyond one year without full CDD, failing which deposit accounts close and no further debits are allowed. Paragraph 28 is a fallback, not a product option: it applies where a person cannot produce the paragraph 23 documents, capping balances at ₹50,000 and annual credits at ₹1 lakh for twelve months. Paragraph 22 permits reliance on third-party due diligence on conditions but leaves ultimate responsibility with the NBFC.
  8. Beneficial ownership. Paragraph 5(1)(iv) sets the thresholds: more than 10 per cent of shares, capital or profits for a company, more than 10 per cent of capital or profits for a partnership firm, more than 15 per cent of property, capital or profits for an unincorporated association or body of individuals, and for a trust, beneficiaries with 10 per cent or more interest together with the author, the trustee and any natural person exercising ultimate effective control. Note where the fallback sits: the senior managing official rule is expressed to apply where no natural person is identified under the company, partnership or unincorporated association limbs, and the trust limb follows it separately. Paragraph 38 requires reasonable steps under Rule 9(3) of the PML Rules to verify the beneficial owner, exempts entities listed on a stock exchange in India or in notified jurisdictions and their subsidiaries, and requires the NBFC to establish the identity of intermediaries and of the persons on whose behalf they act in trust, nominee and fiduciary accounts.
  9. Enhanced due diligence and PEPs. Paragraph 44 governs non-face-to-face onboarding: where the NBFC has introduced V-CIP it must offer that as the first option, no alternate mobile number is linked after CDD, the current address is confirmed positively, PAN is verified from the issuing authority, the first transaction must be a credit from an existing KYC-compliant bank account, and the customer stays high risk until verified face to face or by V-CIP. Paragraph 45 permits a relationship with a PEP, as customer or beneficial owner, provided the NBFC has risk management systems to identify one, takes reasonable measures to establish source of funds or wealth, obtains senior management approval, and applies enhanced ongoing monitoring; the same applies to family members and close associates, and to an existing customer who later becomes a PEP. Read its explanation: PEPs are defined as individuals entrusted with prominent public functions by a foreign country, so on the face of the text domestic PEPs fall outside the definition. Paragraph 59 requires EDD for persons from countries that do not or insufficiently apply the FATF Recommendations.
  10. Periodic updation, PAN and ceasing operations. Paragraph 42(1) sets the cycle at two years for high-risk, eight for medium and ten for low-risk customers; 42(2) allowed low-risk individuals to keep transacting while update was completed within one year of falling due or up to 30 June 2026, whichever is later. Paragraph 42(7) requires at least three advance intimations, including at least one by letter, and at least three reminders afterwards on the same basis, implemented no later than 1 January 2026. Paragraph 43 requires existing customers to furnish PAN, or the declaration prescribed in lieu of it, by such date as the Central Government may notify, failing which operations are temporarily ceased after notice and a hearing, with only credits allowed on loan accounts.
  11. Records, reporting and alerting. Paragraph 47 requires transaction records for at least five years from the transaction and identification records for at least five years after the relationship ends. Paragraph 48 requires NPO customers registered on the DARPAN Portal. Paragraph 51 makes each day of delay in reporting a separate violation and bars restricting an account merely because an STR was filed. Paragraph 53 requires robust software generating alerts where transactions are inconsistent with risk categorisation and updated profile.
  12. Sanctions and proliferation financing. Paragraph 54 implements section 51A of the UAPA, 1967. The NBFC must ensure it holds no account for any individual or entity on the ISIL (Da’esh) and Al-Qaida Sanctions List or the Taliban Sanctions List, and must verify those lists together with the Schedules to the Prevention and Suppression of Terrorism (Implementation of Security Council Resolutions) Order, 2007 on a daily basis, taking account of every addition, deletion or other change. Accounts resembling a listed person are reported to FIU-IND and advised to the Ministry of Home Affairs, with freezing to follow the UAPA Order of 2 February 2021 at Annex I. Paragraph 55 applies the section 12A procedure under the WMD Act, 2005 as laid down by the Ministry of Finance Order of 1 September 2023 at Annex II: no transaction where particulars match the designated list, a check at the time of establishing a relationship and periodically thereafter, immediate intimation of any match to the Central Nodal Officer with copies to the State Nodal Officer and the RBI, the Director, FIU-India being that Central Nodal Officer, and any unfreezing application forwarded to him within two working days. Paragraph 56 requires the UNSCR 1718 list to be verified every day. Paragraphs 57 and 58 extend this to other UNSCRs, to the First and Fourth Schedules to the UAPA, and to countermeasures called for by an intergovernmental organisation of which India is a member.

The Internal Risk Assessment: the method behind paragraph 10

Paragraph 10 says an NBFC must assess its ML/TF risk. It does not say how. That gap is filled by the RBI’s Internal Risk Assessment Guidance for Money Laundering / Terrorist Financing Risks of 10 October 2024.4 It is guidance, not a Direction, so what an inspector cites is still paragraph 10; and it addresses the Reserve Bank’s regulated entities, not every reporting entity under the PML Act.4

The architecture is dual level, and the levels are not head office and business unit. Business Level IRA addresses risk from the entity’s specific business model, its nature and complexity. Individual Level IRA addresses risk from entering a business relationship with a customer, or an occasional transaction for a walk-in customer. The assessment then determines the level of CDD applied to particular types of customer, product, service and delivery channel.4 That is the point boards miss: the IRA is not filed alongside the CDD programme, it sets it.

The method is a weighted risk scoring model in a fixed sequence. Identify inherent risk factors and sub-risk factors, weighting each by contribution to overall ML/TF/PF risk. Calculate a weighted inherent score and map it to High, Medium or Low. Identify the control factors mitigating each risk factor, weight them, calculate a control score and map it to Strong, Satisfactory or Weak. Derive residual risk per factor, aggregate to an enterprise-wide residual risk as the weighted average, and determine a remediation plan.4 An assessment producing a rating without an evidenced control-effectiveness step has not produced a residual risk conclusion; it has produced an inherent risk conclusion wearing the wrong label.

Four disciplines are worth putting to a governing body. The exercise must not sit siloed inside the AML team; product, audit and compliance belong in it. It must be data-oriented and objective, and draw on all relevant internal and external sources. And it must assure the integrity of the processes on which ML/TF risk management depends: CDD, transaction monitoring, sanctions screening, alert generation and management, and CTR and STR reporting.4 Alert generation appears there for the same reason it appears in paragraph 53. An IRA that has changed no control, threshold or monitoring rule has not been used.

This is where scale bites. Paragraph 3 gives an Upper Layer NBFC the same baseline text as a base-layer one, and the RBI’s Upper Layer list for 2026-27, released on 6 August 2026, names seventeen entities whose balance sheets rival mid-sized scheduled commercial banks.5 Identical drafting is not identical supervisory tolerance. Where the text is silent on scale, the burden of proving proportionality falls on the institution’s own documentation.

Technology is an obligation, not an efficiency

Read as a technology specification, the Directions are prescriptive. Paragraph 27(1) requires V-CIP infrastructure on the NBFC’s own premises, the connection originating from its own secured network domain; under a cloud model, data ownership must rest with the NBFC and the provider must retain nothing. It mandates end-to-end encryption, blocking of IP addresses outside India or spoofed, geo-tagged recordings, liveness and face-matching to a high degree of accuracy, and testing by CERT-In empanelled auditors; paragraph 27(2)(xiv) makes V-CIP accounts operational only after concurrent audit and paragraph 27(3)(i) requires data stored in India. Paragraph 27(1)(vi) permits artificial intelligence in V-CIP, paragraph 40 invites AI and machine learning in ongoing monitoring, and paragraph 60 encourages innovation in name screening.1

Paragraph 68 is the easiest to miss: it requires ML/TF risk assessment before the launch or use of new products, practices, services and technologies.1 A new co-lending arrangement, embedded-finance partnership or digital sourcing channel is, on a natural reading, a new delivery mechanism within its meaning, though the Directions do not define the term. Written after go-live, the obligation has been missed however good the assessment turns out to be.

What a tick-box regime costs

Between 3 and 19 August 2026 the Reserve Bank issued monetary penalty orders against at least eight NBFCs, with KYC non-compliance among the grounds in each reported order, in some cases alongside Fair Practices Code or Governance directions. Penalties ran from ₹2.70 lakh to ₹8.10 lakh, under section 58G(1)(b) read with section 58B(5)(aa) of the RBI Act, 1934.6 Two findings recur: failure to put in place a system of periodic review of risk categorisation of accounts, with such periodicity being at least once in six months; and failure to put in place robust software for effective identification and reporting of suspicious transactions.6

Those are paragraph 41(1) and paragraph 53. Not exotic, not matters of interpretation, and both trivially easy to mark “complied” while the underlying capability does not exist. A policy can state that the review happens every six months; it will not survive an inspection that asks to see the output.

The penalties are immaterial to any balance sheet of consequence, which is why they are the least interesting number in the story. The costs sit in remediation, since building monitoring that genuinely detects and re-running risk categorisation across a live retail book costs far more than the fine; in disclosure, since a listed NBFC must report the order to the exchanges; and in counterparty consequence, since a public finding that suspicious transaction detection was inadequate is a finding about everything downstream of it.

The orders record inspections referenced to financial position as on 31 March 2025, placing the findings under the predecessor framework.6 Inspections referenced to 31 March 2026 will be the first tested against the 2025 Directions. An NBFC that has not re-baselined its policy and register enters that cycle citing a repealed instrument, against a supervisor who has just shown which two paragraphs it intends to test.

The judgement the Directions will not make for you

The 2025 Directions did not make NBFC AML compliance harder. They made it specific: for the first time the sector has an instrument that speaks about loan accounts, agent-sourced onboarding and non-face-to-face origination without passing through a branch-banking assumption. The hard part was never the text. Paragraph 10(3) asks an NBFC to decide, and document, how much control its own risk profile deserves, and paragraph 3 declines to answer by layer.1 Get that right and the checklist above describes what you already do. Get it wrong and it becomes what it became for a run of NBFCs this August: a column of ticks above a capability that was not there.

References

  1. Reserve Bank of India, Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Directions, 2025, RBI/DOR/2025-26/361, DOR.AML.REC.No.280/14.01.003/2025-26, 28 November 2025 (updated as on 29 December 2025). Available at: https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12943 (accessed 23 August 2026). All paragraph references in this article were read from this text.
  2. Reserve Bank of India, Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Amendment Directions, 2025, Notification No. RBI/2025-26/160, DOR.AML.REC.364/14.01.003/2025-26, 29 December 2025.
  3. Reserve Bank of India data on credit deployment by NBFCs for June 2026, as reported in Business Standard, 7 August 2026. Figures are as at June 2026, year on year. This figure rests on press reporting of the RBI release rather than on the release itself.
  4. Reserve Bank of India, Internal Risk Assessment Guidance for Money Laundering / Terrorist Financing Risks, 10 October 2024, addressed to the Reserve Bank’s regulated entities including banks, NBFCs, authorised persons and payment system operators. The RBI’s own file was not directly retrievable at the time of writing. The principles, the dual-level structure and the weighted scoring sequence set out above follow published accounts that reproduce the guidance and are consistent across sources, but the wording should be checked against the RBI document before being relied on in a Board-approved policy or methodology.
  5. Reserve Bank of India, “RBI releases list of NBFCs in the Upper Layer (NBFC-UL) under Scale Based Regulation for NBFCs”, Press Release 2026-2027/823, 6 August 2026.
  6. Reserve Bank of India monetary penalty orders dated 3, 14 and 19 August 2026 imposed on non-banking financial companies for non-compliance with the Reserve Bank of India (Know Your Customer (KYC)) Directions, announced by press release. Entities are not named here by choice. The orders are published on the RBI website; the figures and quoted findings in this article are taken from compilations reproducing those press releases, the RBI’s own release files not being retrievable directly.