Part 02 — RBI Regulatory Framework
KYC/AML
KYC in SME lending is not a single PAN check. A lender must identify the borrowing entity, its authorised signatories, beneficial owners, guarantors, security providers and sometimes key proprietors/directors behind group entities. The governing document is the Master Direction - Know Your Customer (KYC) Direction, 2016, as amended from time to time. RBI amended it again on June 12, 2025 to ease periodic KYC updation for low-risk customers and permit Business Correspondent (BC) support for specified update flows (RBI KYC Amendment Directions, June 12, 2025).
Customer Due Diligence
Section titled “Customer Due Diligence”Customer Due Diligence (CDD) starts before an account-based relationship is created. For an individual proprietor or guarantor, Officially Valid Documents (OVDs), PAN/Form 60 where applicable, photograph, address, and risk category are captured. For a proprietorship, lenders normally establish both the proprietor’s identity and the business existence: Udyam Registration Certificate, GST registration, shop and establishment licence, trade licence, IEC, utility bill, bank statement, or other activity proof depending on policy.
For partnerships, LLPs and companies, the file expands:
| Constitution | Typical KYC file |
|---|---|
| Proprietorship | Proprietor OVD/PAN, business proof, Udyam/GST, bank account proof, place-of-business evidence. |
| Partnership firm | Partnership deed, registration certificate if registered, PAN, authorised signatory mandate, KYC of partners and beneficial owners. |
| LLP | Certificate of incorporation, LLP agreement, PAN, designated partner details, board/partner authority, beneficial ownership checks. |
| Private/public company | Certificate of incorporation, Memorandum and Articles, PAN, board resolution, authorised signatory list, directors’ KYC, beneficial owner identification. |
| Trust/society/HUF | Constitutive document, registration if applicable, PAN, trustee/karta/member authority and relevant individual KYC. |
The Master Direction requires a risk-based approach: customer acceptance policy, risk management, customer identification procedure and transaction monitoring. In SME credit this becomes practical when a loan to a scrap trader, jewellery wholesaler, cash-heavy restaurant, export-import unit or politically exposed owner is not treated like a salaried borrower top-up. Higher-risk files usually require senior approval, more documentary evidence, negative-list screening and closer post-disbursement monitoring.
Beneficial Ownership
Section titled “Beneficial Ownership”Beneficial Owner (BO) checks prevent the borrower from hiding behind a legal shell. Lenders identify the natural persons who ultimately own or control the entity, applying thresholds prescribed under the KYC Master Direction and Prevention of Money-Laundering Rules. In practice, this means the loan origination system should not stop at “company PAN verified”; it needs shareholding, control, authorised signatory, director/partner and guarantor structures. A 51:49 company with nominee shareholders, a partnership where the operational controller is not the highest capital contributor, or a trust-controlled trading entity requires judgement, not just document upload.
CKYC, V-CIP and Digital KYC
Section titled “CKYC, V-CIP and Digital KYC”Central KYC Records Registry (CKYCR) allows KYC records to be uploaded and retrieved through KYC Identifier (KYC ID). For lenders, CKYC is most useful when onboarding repeat individual promoters and guarantors, but it does not remove the need to verify entity documents, authorisation, beneficial ownership and current risk.
Video Customer Identification Process (V-CIP) is an RBI-recognised remote CDD method. It is useful for digital SME journeys where a proprietor or director cannot visit a branch. A compliant V-CIP flow requires live interaction, liveness/location controls as applicable, official document or equivalent e-document verification, clear audit trail, trained officials and secure storage. It is not just a video recording uploaded to the LOS.
The 2025 KYC amendment is operationally important. For low-risk individual customers whose periodic updation is due, RBI allowed transactions to continue while KYC is updated within one year of falling due or up to June 30, 2026, whichever is later; it also allowed banks to obtain self-declarations for no-change/address-only change through authorised BCs (RBI KYC Amendment Directions, June 12, 2025). This was a customer-service change, not a relaxation of AML monitoring.
Periodic Re-KYC
Section titled “Periodic Re-KYC”The standard periodic updation cycle in the KYC Master Direction is risk-linked: at least once every two years for high-risk customers, once every eight years for medium-risk customers and once every ten years for low-risk customers. Lenders often fail not at first KYC but at re-KYC: phone numbers change, proprietors shift premises, GST is cancelled, directors resign, ownership changes, or bank accounts become dormant. A serious SME lending system should generate re-KYC queues well before due date, block only as policy permits, record outreach attempts and distinguish “no change” declarations from actual document refresh.
AML/CFT Monitoring
Section titled “AML/CFT Monitoring”Anti-Money Laundering/Combating Financing of Terrorism (AML/CFT) for SME loans includes sanction screening, adverse media, politically exposed person checks, transaction monitoring, suspicious transaction reporting to FIU-IND, and ongoing customer risk review. Lending teams should treat AML as a live portfolio control. Red flags include circular transactions between related entities, sudden cash deposits before EMI date, GST turnover inconsistent with banking credits, exports with unrelated remitters, high-value related-party payments, multiple recent bank account openings, or use of loan proceeds outside declared business.
For software design, KYC creates entities and events: party, business_entity, beneficial_owner, authorized_signatory, kyc_document, risk_rating, sanctions_screening, v_cip_session, ckyc_id, periodic_kyc_due_date, kyc_refresh_event and aml_alert. Those objects feed KYC onboarding, underwriting data and compliance hooks.