Chapter 6 — Part 4: Comprehensive Study Notes: IFSCA Guidelines for KYC Norms

Comprehensive Study Notes: IFSCA Guidelines for KYC Norms (Chapter 6 — Part 4)

This study guide represents Part 4 (the final part) of the comprehensive series for Chapter 6: IFSCA Guidelines for KYC Norms. It covers the critical compliance mechanisms of Ongoing Customer Due Diligence (CDD) [23, 6.7], Ongoing Sanctions Screening [24, 6.8], the Failure of CDD Processes [24, 6.9], Periodic Updation Norms [24, 6.10], and a detailed structural comparison highlighting the Differences between IFSCA AML/CFT Guidelines and other Domestic Indian Regulators [24, 6.11].

1. Ongoing Customer Due Diligence (CDD)

Establishing a business relationship is only the starting point of compliance. Under the IFSCA framework, Regulated Entities (REs) must perform continuous monitoring to ensure that transactions remain consistent with the client's established risk profile.

Step YES — Red Flag Identified NO — Normal Activity
Trigger Transaction is complex, unusually large, or completely lacking economic rationale No unusual complexity, size, or unexplained economic rationale
Action 🔴 MANDATORY INQUIRY 🟢 STANDARD PERIODIC MONITORING
1. Review Interrogate the background and purpose of the transaction Continue standard monitoring
2. Source Verification Request information on Source of Wealth (SOW) or Source of Funds (SOF) Follow normal KYC/update procedures
3. Documentation Document all findings in writing for submission/availability to authorities as required Maintain routine monitoring records
Outcome Determine whether the activity requires further AML/CFT action or reporting Continue the established monitoring cycle

1.1 Core Operational Mandates

  • Continuous Monitoring: An RE is legally required to actively monitor its business relations with every customer on an ongoing basis.
  • Account Scrutiny: Throughout the course of the relationship, the RE must observe the conduct of the customer’s account and scrutinize transactions. This ensures that all activities are consistent with the RE's knowledge of the customer, their specific business, and their overall risk profile.
  • Source of Funds/Wealth: Where appropriate and necessary based on transaction patterns, the RE may seek and verify the customer's source of wealth and source of funds.

1.2 Scrutiny of High-Risk & Anomalous Transactions

Regulated Entities must pay particular attention to transactions that exhibit unusual characteristics.

  1. Red Flag Patterns: Any transaction that is complex, unusually large, or displays unusual patterns of transactions that have no apparent or visible economic or legitimate purpose must trigger intensive examination.
  2. Mandatory Inquiries: The RE must make active, documented enquiries into the background and purpose of such anomalous transactions.
  3. Written Documentation: The findings of these enquiries must be formally documented in writing by the RE so that this information is readily available to the relevant competent authorities should the need arise.

1.3 Dynamic Risk Rating Reviews

  • Commensurate Classification: The RE must periodically review each customer to ensure that their assigned risk rating remains strictly commensurate with the actual money laundering and terrorist financing (ML/TF) risks they pose.
  • Material Trigger Reviews: If there are indications or events suggesting that the risks associated with an existing business relationship have increased, the RE must request additional up-to-date information and conduct an immediate review of the customer’s risk profile to determine if additional enhanced measures are necessary.
  • Relevance of Data: The RE must ensure that all CDD data, documents, and information obtained (including data on natural persons acting on behalf of customers, related parties, and beneficial owners) are kept relevant and up-to-date through regular reviews, with highest priority given to customers with a high-risk rating.

2. Ongoing Sanctions Screening

Sanctions compliance is a non-negotiable component of international financial operations. Under the IFSCA guidelines, this process is integrated directly into the ongoing due diligence workflow.

  • Targeted Database Screening: Regulated Entities must regularly review their customer base, ongoing business, and transaction counterparties against the United Nations Security Council (UNSC) sanctions lists and any other relevant sanctions lists.
  • Execution Timing: This screening must be conducted actively as part of the ongoing due diligence process to prevent the facilitation of transactions for sanctioned individuals, groups, or jurisdictions.

3. Regulatory Consequences of CDD Failure

The IFSCA guidelines outline strict, mandatory steps that an RE must take if it is unable to successfully conduct or complete the required Customer Due Diligence.

3.1 Mandatory Operational Bans

If an RE is unable to complete the requisite CDD for a prospective or existing customer, it is prohibited from facilitating their business. The RE shall:

  1. Not open an account or otherwise provide any financial service.
  2. Not carry out any transaction with or for the customer.
  3. Not establish any business relationship.
  4. Terminate or suspend any existing business relationship with the customer immediately.
  5. Return any monies or assets received from the customer.
  6. Consider filing a Suspicious Transaction Report (STR) with FIU-IND if the failure to complete CDD raises suspicion of ML/TF.

3.2 Inclusive Protection: Persons with Disabilities (PwDs)

  • Application of Mind: No application for onboarding or periodic updation of KYC shall be rejected in the case of Persons with Disabilities (PwDs) without proper application of mind.
  • Mandatory Record keeping: The specific reasons for any such rejection must be formally and duly recorded in writing by the concerned officer of the RE.

3.3 Exemptions to the Failure Protocol (Anti-Tipping-Off Safeguard)

  • Tipping-Off Exception: A Regulated Entity is not bound to refuse transactions, terminate the relationship, or return assets if doing so would result in "tipping off" the customer about an active AML/CFT investigation.
  • Regulatory Directions: The RE may also bypass these restriction mandates if explicitly directed to act otherwise by FIU-IND.

4. Periodic Updation Framework

The periodic updation of Customer Due Diligence is a key requirement of the IFSCA guidelines, adopting a strict risk-based approach to determine the frequency of updates.

4.1 Comparative Periodicity Matrix

The frequency of updating KYC records depends on both the customer’s risk category and whether the customer is a resident Indian with an existing relationship within the RE's broader financial group.

Customer Risk Category Standard Periodicity (IFSCA Default) Periodicity for Resident Indians with Financial Group in India
High Risk Annually (Once every year) Once in every two years
Medium Risk Once in three years Once in every eight years
Low Risk Once in every five years Once in every ten years

The "Stricter Periodicity" Rule: Where the risk categorization made by the Financial Group entity in India differs from the risk categorization made by the IFSC Regulated Entity, the stricter of the two periodicities must be applied to the customer.

4.2 Updation Procedures for Individual Customers

The operational requirements for updating an individual's KYC vary based on whether their underlying details have changed:

  • Scenario A: No Change in CDD Information
    • The RE can obtain a simple self-declaration from the customer confirming that there is no change in their CDD details.
    • This self-declaration can be obtained securely through the customer's registered mobile number or various digital channels (such as internet banking, registered e-mail, or the RE's official mobile application).
  • Scenario B: Change in Address
    • The customer can submit a self-declaration of the new address through registered digital channels (e-mail, registered mobile number, or mobile app).
    • Positive Confirmation Mandate: The RE must verify this declared address through positive confirmation within two months of submission. Verification methods include address verification letters, contact point verification, or official deliverables.
    • OVD Proof: If specified in the RE's Governing Body-approved internal KYC policy, the RE must obtain a physical or digital copy of an Officially Valid Document (OVD) or equivalent e-document to support the declared address change.

4.3 Updation Procedures for Non-Natural Persons (Corporates & Trusts)

  • No Change in CDD Information: The RE must obtain a formal self-declaration through registered digital channels, or a physical letter duly signed by an authorized official accompanied by the requisite board/managing resolutions.
  • Beneficial Ownership Check: The RE must take active measures to ensure that the Beneficial Ownership (BO) details in its possession are entirely accurate and up-to-date.
  • Change in CDD Information: If there is any change in the core CDD information, the RE must undertake a fresh CDD process identical to the process required for onboarding a new non-natural customer.

4.4 Mandatory Quality & Operational Standards

  1. Compliance with Current CDD Standards: During periodic updation, the RE must ensure that all KYC documents meet current regulatory CDD standards. If the existing documents are outdated or their validity has expired, the RE must conduct a fresh CDD process as if onboarding a new customer.
  2. PAN Verification: For Indian nationals, the customer's PAN details must be actively verified against the database of the official issuing authority (Income Tax Department) during the updation process.
  3. Mandatory Acknowledgment: The RE must provide a formal, dated acknowledgment of receipt to the customer upon receiving their updation documents or self-declaration. Once updated, the RE must promptly record this in its system and send a final confirmation to the customer.
  4. Governing Body Approval: All exceptional or additional measures adopted by the RE (such as requiring a recent photograph, mandatory physical presence, or more frequent update cycles) must be clearly documented within the RE's internal KYC policy and formally approved by its Governing Body.
  5. The 30-Day Client Reporting Window: If there is any change to a customer's submitted documents after initial onboarding, the customer is legally required to submit the updated documents to the RE within 30 days of the change.

5. Comparing IFSCA Guidelines vs. Domestic Indian Regulators

As a unified regulator, the IFSCA's AML/CFT framework is uniquely designed to balance robust risk management with the ease of doing business for international operations.

Parameter IFSCA Guidelines (GIFT IFSC) Domestic Indian Regulators (RBI, SEBI, IRDAI, PFRDA)
Regulatory Jurisdiction Acts as a single, unified point of regulation managing diverse financial activities (banking, insurance, capital markets) in the IFSC [74/75, 419]. Focus on specific sectors (e.g., RBI for banking, SEBI for securities, IRDAI for insurance).
Target Audience & Clients Primarily designed for international clients and complex cross-border transactions. Primary focus is on domestic clients within the mainland Indian financial environment.
Global Alignment Highly aligned with the international recommendations of the Financial Action Task Force (FATF). Aligned primarily with the domestic Indian financial, legal, and economic environment.
Compliance Focus Heavy emphasis on global KYC, cross-border due diligence, and international sanctions screening. Focus on domestic verification standards, local laws, rules, and mainland tax regulations.
Ease of Doing Business Designed to provide a world-class financial environment with streamlined, flexible KYC procedures to attract global capital. KYC and CDD processes are tightly carved out to specifically suit mainland Indian business and retail banking requirements.

 

6. Practice Exam Questions (Topic-Specific)

MCQs — KYC Periodic Updation & Ongoing CDD

Q1. Under the IFSCA Guidelines, what is the standard KYC periodic updation frequency for High-Risk customers?

A) Once in two years
B) Once in three years
C) Annually (once every year)
D) Once in five years

Answer: C

Q2. For a resident Indian customer with an existing relationship with a Financial Group in India, what is the periodic updation timeframe for a Medium-Risk customer under the IFSCA Guidelines?

A) Once in three years
B) Once in five years
C) Once in every eight years
D) Once in every ten years

Answer: C

Q3. If a Regulated Entity’s risk categorization of a customer is Medium-Risk, but its parent Financial Group in India classifies the same customer as High-Risk, what periodic updation frequency must be applied?

A) Once in eight years (Financial Group Medium-Risk)
B) Once in every two years (Financial Group High-Risk)
C) Once in three years (IFSCA Medium-Risk)
D) Annually (IFSCA High-Risk)

Answer: B

Q4. Within how many days must a customer submit updated identification documents to an IFSC Regulated Entity after a change has occurred?

A) Within 7 business days
B) Within 15 calendar days
C) Within 30 days
D) Within 60 days

Answer: C

Q5. Under the IFSCA Ongoing CDD guidelines, what action must an RE take if a transaction is identified as complex, unusually large, and has no apparent economic purpose?

A) Report the transaction to the board of directors within 30 days without inquiry.
B) Conduct enquiries into the background and purpose of the transaction, and document the findings in writing.
C) Immediately freeze the customer's assets and close the account.
D) File an automatic CTR with the Reserve Bank of India.

Answer: B

7. Key Terminology for Quick Recall

  • Ongoing CDD: The continuous process of monitoring business relationships and scrutinizing transactions to ensure alignment with the customer's risk profile.
  • UNSC Sanctions List: International databases of sanctioned individuals and entities that REs must screen against during ongoing CDD.
  • Tipping-Off: The risk of alerting a client that they are under suspicious transaction investigation or that their CDD has failed.
  • Resident Indian Proviso: A specific regulatory amendment relaxing the periodicity of CDD updates for Indian residents with existing domestic group relationships.
  • Unified Regulator: The unique legal status of the IFSCA, consolidating the regulatory powers of RBI, SEBI, IRDAI, and PFRDA into a single entity within the IFSC 

Practice with a Free Mock Test

Ready to test your NISM IFSCA 01: Anti Money Laundering and Counter Terrorist Financing Certification in the IFSC preparation? Start with Test 1 — no payment required.

Notify me when you update the Notes

Free account · No payment needed for Test 1

Create a free PassNISM account

Continue with Google to start a free NISM mock test (Test 1) for this subject, save scores, and compare attempts.

Continue with Google