The International Financial Services Centres Authority (IFSCA) has updated its Anti-Money Laundering, Counter-Terrorist Financing and Know Your Customer (AML/CFT/KYC) Guidelines, consolidating regulatory changes made over recent years and incorporating amendments issued as recently as 3 August 2026.
The updated document retains the basic architecture of the IFSCA’s 2022 framework but provides a more detailed compliance structure covering risk assessment, customer due diligence, beneficial ownership, enhanced due diligence, correspondent banking, wire transfers, suspicious-transaction reporting, record keeping, regulatory reporting and digital customer identification.
The consolidated guidelines apply, subject to specified exemptions, to regulated entities licensed, recognised, registered or authorised by IFSCA. They also extend to financial groups to the extent specified in the framework. The document runs across 12 chapters and two annexures, including detailed procedures for video-based customer identification and digital KYC for Indian nationals.
At the centre of the framework is a familiar but increasingly important regulatory principle: AML/CFT controls are expected to be risk-based, proportionate and continuously reviewed, rather than applied as a uniform checklist to every customer and transaction.
Risk-based compliance remains the foundation
The guidelines require regulated entities to identify and assess their exposure to money-laundering and terrorist-financing risks based on factors including the nature of their business, customers, countries and geographic areas, products, services, transactions and delivery channels.
The risk-based approach must be objective, proportionate and based on reasonable grounds. It must also be reviewed and updated at appropriate intervals.
Importantly, the framework goes beyond assessing individual customers. Where applicable, regulated entities must conduct an enterprise-wide, financial-group-wide or group-wide assessment that takes into account risks across business units, product lines and delivery channels.
The resulting risk assessment must be documented and made available to IFSCA upon request. Customer and business risks are ultimately expected to be classified as low, medium or high, with enhanced measures applied to higher-risk relationships and simplified measures available for lower-risk relationships. The framework requires the risk assessment itself to be reviewed at least once every two years or sooner where a material trigger event occurs.
That requirement gives the risk assessment a role beyond documentation. It becomes the mechanism through which an entity determines where its AML/CFT resources should be deployed.
Technology and new products must be assessed before launch
The guidelines also make clear that AML/CFT risk cannot be separated from changes in business models and technology.
When a regulated entity introduces a new product, business practice, delivery mechanism or new technology — including technology applied to an existing product — it is required to identify and assess the potential ML/TF risks before launch or implementation.
The entity must then put appropriate measures in place to manage and mitigate those risks.
The business-risk framework therefore links product development, technology adoption and financial-crime controls rather than treating them as separate compliance functions.
Customer risk assessment must precede and inform due diligence
Customer risk assessment forms the next layer of the framework.
IFSCA requires regulated entities to undertake a risk-based assessment of every customer and assign a risk rating proportionate to the customer’s ML/TF risk. The assessment considers the customer’s identity and beneficial ownership, purpose and intended nature of the relationship, business activities, ownership and control structure, geography, products and services involved and, where relevant, the beneficiary of an insurance policy.
The framework identifies a broad range of circumstances that may indicate higher risk. These include unusually complex ownership structures, nominee shareholders, personal asset-holding vehicles, unusual geographic circumstances, exposure to jurisdictions with weaknesses in AML/CFT systems, sanctions or terrorism-financing concerns, private banking, anonymity-enhancing products, non-face-to-face relationships without adequate safeguards and payments from unknown or unassociated third parties.
At the same time, the guidelines caution that a single risk factor should not automatically determine the final risk classification. The overall risk picture must be considered.
For regulated entities, this creates an important operational requirement: risk scoring cannot be treated as a static onboarding exercise. If information obtained during CDD changes the customer’s risk rating, the resulting due-diligence measures must change accordingly.
Beneficial ownership remains a central line of defence
The framework places substantial emphasis on identifying the natural persons who ultimately own or control customers.
For companies, the beneficial owner is the natural person who has a controlling ownership interest or exercises control through other means. The guidelines define controlling ownership interest as ownership of or entitlement to more than 10% of shares, capital or profits.
Comparable ownership and control tests apply to partnerships, unincorporated associations and trusts, with specific requirements for identifying relevant natural persons and, where necessary, the senior managing official.
For trusts, identification extends to the author, trustee, beneficiaries with 10% or more interest and other natural persons exercising ultimate effective control through ownership or a chain of control.
The practical implication is that customer onboarding cannot stop at identifying the legal entity appearing on an account. Regulated entities are expected to establish who ultimately owns or controls the entity and to understand its ownership and control structure.
CDD is designed to continue after onboarding
The updated framework makes clear that customer due diligence is not a one-time verification exercise.
For every customer, regulated entities must identify and verify the customer, identify and take reasonable measures to verify the beneficial owner, understand the purpose and intended nature of the relationship and conduct ongoing due diligence.
That ongoing process includes scrutiny of transactions to determine whether activity remains consistent with the entity’s knowledge of the customer, the customer’s business and risk profile, including source of funds where necessary.
For legal persons and arrangements, regulated entities must also identify and screen related or connected parties and remain aware of changes involving those parties.
The guidelines also establish circumstances in which additional CDD is required for an existing customer — including doubts about the adequacy or veracity of existing information, suspicion of ML/TF or a change in risk rating or circumstances.
The framework permits limited flexibility — but with strict controls
The guidelines allow a regulated entity, under specified circumstances, to establish a business relationship before completing all verification requirements.
That flexibility is conditional. Deferral must be essential to avoid interrupting normal business, the ML/TF risk must be low and manageable, and appropriate safeguards must be in place.
Verification should normally be completed as soon as reasonably practicable and, in any event, within 30 business days of establishing the relationship.
If verification remains incomplete after 30 days, the entity must suspend the relationship and refrain from further transactions, except where funds can be returned to their source. If verification remains incomplete after 120 days, the business relationship must be terminated.
The framework also requires the non-compliance to be documented and reported to the governing body where the 30-day requirement cannot be met.
Enhanced due diligence for higher-risk customers
The risk-based model is particularly visible in the treatment of high-risk customers.
Once a customer is classified as high risk, enhanced customer due diligence must be conducted in addition to normal CDD. Low-risk customers may instead qualify for simplified measures, although simplified CDD cannot be used where there is suspicion of ML/TF.
Ongoing monitoring remains necessary even when simplified measures are applied.
The framework therefore creates three broad levels of treatment: enhanced CDD for higher-risk relationships, normal CDD for other customers and simplified CDD for appropriately classified low-risk customers.
Suspicious transactions: no monetary threshold
One of the framework’s clearest messages is that suspicious-transaction reporting is not dependent on transaction size.
The guidelines state that there is no minimum monetary threshold for reporting a suspicious transaction. Where reasonable grounds for suspicion exist, the transaction should be reported to the Financial Intelligence Unit-India (FIU-IND), regardless of currency or amount.
The framework also covers attempted transactions. Employees who know, suspect or have reasonable grounds to suspect that a person is engaged in or attempting ML/TF are required to promptly notify the Principal Officer with the relevant details.
The guidelines provide a four-step approach to suspicious-transaction identification: detect suspicious indicators, ask appropriate questions, review the customer’s records and evaluate the information collected.
Importantly, the presence of a red flag by itself does not automatically establish criminality or suspicion. The document says indicators should prompt closer monitoring and further assessment.
August 2026 brings changes to regulatory reporting
The most directly identifiable changes associated with the 3 August 2026 circular concern reporting requirements to FIU-IND.
The consolidated guidelines now explicitly require the information prescribed under the relevant rules to be furnished to FIU-IND in accordance with Rule 7 and Rule 8 of the Prevention of Money-laundering (Maintenance of Records) Rules.
The August amendment also revised the guidance around FIU-IND reporting tools. Regulated entities are directed to use the reporting resources available through FIU-India’s FINnet 2.0 resources and file reports online through the FINgate 2.0 portal. The document’s amendment notes specifically identify these changes as having been introduced through the 3 August 2026 circular.
The reporting framework also now expressly incorporates Cross Border Wire Transfer Reports (CBWTRs) alongside STRs and Non-Profit Organisation Transaction Reports (NTRs) in the monthly reporting requirements. The consolidated text states that CBWTRs and NTRs for each month are to be submitted to FIU-IND by the 15th of the succeeding month, with the Principal Officer responsible for timely submission and confidentiality. The amendment footnotes identify these additions as changes made through the 3 August 2026 circular.
For compliance teams, the significance is operational as much as regulatory: reporting workflows need to accommodate multiple report types, defined reporting timelines and appropriate governance over the submission process.
Digital KYC is becoming more sophisticated
The guidelines’ treatment of Video-based Customer Identification Process (V-CIP) reflects the increasingly digital nature of customer onboarding.
V-CIP is treated as an alternative to face-to-face identification, provided the prescribed process and controls are followed. It involves live audio-visual interaction, facial recognition, independent verification and maintenance of an audit trail.
The framework also places significant responsibility on technology. V-CIP infrastructure is expected to incorporate face-liveness and spoof detection, face matching and appropriate AI technology designed to address deepfakes and fraud. The technology and associated workflows are expected to be upgraded based on experience with detected or attempted forged identities.
The framework further requires appropriate security testing, including vulnerability assessment, penetration testing and security audits, before deployment and periodically thereafter.
A significant V-CIP change: broader geographic flexibility for NRI onboarding
The consolidated guidelines also contain an August 2026 amendment concerning the jurisdictions permitted for certain NRI customers using V-CIP.
Earlier wording had specified a defined list of countries and jurisdictions. The updated text removes the specific European Union reference from that list through the 3 August 2026 circular.
The remaining framework continues to require that the relevant jurisdiction not be identified by FATF as a high-risk jurisdiction subject to a call for action or as a jurisdiction under increased monitoring, and that it not be identified by the Central Government as high risk for money laundering, terrorist financing or proliferation financing.
The document therefore retains a risk-based geographic safeguard while changing the way the permitted-jurisdiction list is expressed.
Correspondent banking remains subject to enhanced scrutiny
The guidelines impose extensive requirements on correspondent banking relationships.
Before establishing such relationships, regulated entities are expected to gather sufficient information about respondent banks, understand their business and jurisdictions of operation, assess their reputation and regulatory supervision, and evaluate the effectiveness of their AML/CFT controls.
Senior Management approval is required before providing correspondent banking or similar services to a respondent bank.
Correspondent relationships with shell financial institutions are prohibited, and regulated entities must be cautious when dealing with respondent banks in jurisdictions with strategic AML/CFT deficiencies or insufficient progress in implementing FATF recommendations.
Wire transfers face a parallel risk-control framework
The guidelines extend AML/CFT controls into the movement of funds through wire transfers.
Regulated entities must monitor payment messages and transactions involving high-risk jurisdictions and suspend or reject transactions involving sanctioned parties or jurisdictions.
Where name-screening checks identify a terrorist or terrorist entity as the originator or beneficiary, the entity must block, reject or freeze the relevant assets immediately.
The framework also establishes responsibilities for beneficiary and intermediary institutions, including identifying missing originator or beneficiary information and establishing risk-based procedures for deciding when a transfer should be executed, rejected or suspended.
Governance sits firmly with senior management
The compliance framework is not positioned as the responsibility of the AML team alone.
Every regulated entity must formulate an AML/CFT policy approved by its governing body or a properly delegated committee. It must also maintain a KYC policy as part of its AML/CFT policy.
Senior Management members are responsible for compliance with the guidelines and are expected to exercise due skill, care and diligence.
The framework separately requires a Principal Officer with appropriate seniority, authority, resources and access to customer records. The Principal Officer’s responsibilities include ongoing monitoring, AML/CFT compliance, suspicious-transaction reporting, employee guidance and training, and reporting key AML/CFT risk-management and control issues to Senior Management.
Internal audit must also be adequately resourced and independent, with the AML/CFT framework subject to periodic review on an entity-wide basis.
KYC records are increasingly centralised
The guidelines also place regulated entities under defined obligations relating to the Central KYC Records Registry.
For relevant Indian-resident customers, KYC records are to be uploaded to CKYCR within the prescribed timeframe, and entities are expected to retrieve existing KYC information rather than repeatedly require customers to submit the same information where the conditions for reuse are met.
The framework also specifies circumstances in which additional information can still be requested — including changes in customer information, incomplete or non-compliant KYC records, expired documents, or situations where enhanced due diligence or appropriate risk profiling requires additional verification.
This approach points toward a compliance model in which KYC information becomes a reusable regulatory record rather than a collection of documents repeatedly recreated by individual institutions.
The wider message for financial institutions
Taken as a whole, the 73-page consolidated framework illustrates how AML/CFT compliance within India’s international financial services ecosystem is moving toward an increasingly integrated model.
Customer identification is only the starting point. The framework connects business-risk assessment, customer-risk assessment, beneficial ownership, CDD, enhanced due diligence, transaction monitoring, suspicious-transaction reporting, sanctions controls, wire-transfer oversight, record keeping, governance and audit.
Technology is similarly embedded throughout the framework. Regulated entities are expected to assess financial-crime risks before adopting new technologies, deploy monitoring systems capable of identifying activity inconsistent with customer risk profiles and use digital mechanisms such as V-CIP and CKYCR within defined controls.
The August 2026 amendments add another layer by sharpening reporting requirements and updating digital onboarding parameters.
What compliance teams will need to keep in focus
For regulated entities operating within the IFSCA ecosystem, the consolidated guidelines translate into several practical areas of attention.
First, risk assessments need to remain live. The framework requires periodic review and reassessment when material trigger events occur rather than allowing an initial risk assessment to become a static document.
Second, customer profiles need to evolve with the evidence. Changes discovered through ongoing monitoring or CDD can affect customer risk classification and therefore the level of due diligence required.
Third, beneficial ownership and connected-party information require continuing attention. Identifying an entity’s legal structure at onboarding is not sufficient where ownership or control changes.
Fourth, suspicious-transaction reporting requires strong operational processes. The absence of a monetary threshold, the inclusion of attempted transactions and the requirement for prompt escalation place importance on monitoring, investigation and reporting workflows.
Fifth, reporting infrastructure needs to be aligned with FIU-IND requirements. The August 2026 amendments specifically bring Rule 8 into the reporting provision and incorporate CBWTRs into the reporting framework.
Finally, digital onboarding cannot be treated as a lighter form of KYC. V-CIP brings its own requirements around liveness, anti-spoofing, deepfake detection, encryption, audit trails, testing and trained personnel.
A framework built around continuous financial-crime oversight
The updated IFSCA Guidelines do not replace the underlying 2022 framework so much as consolidate and refine it through successive amendments. Their structure reflects a regulatory model in which AML/CFT is expected to operate continuously across the customer lifecycle.
The regulatory journey begins with understanding the risks associated with the business itself, moves into customer and beneficial-owner risk assessment, continues through onboarding and ongoing due diligence, and extends into transaction monitoring and suspicious-transaction reporting.
The 3 August 2026 amendments add particular emphasis to the reporting side of that lifecycle while also adjusting the geographic parameters associated with digital onboarding of certain NRI customers.
For financial institutions and other regulated entities operating in India’s international financial services centre, the practical challenge is therefore not simply meeting a KYC requirement at the point of account opening. It is maintaining a connected system in which risk intelligence, customer information, transaction activity, reporting and governance remain aligned throughout the life of the relationship.
That is ultimately the architecture reflected in the consolidated 2026 guidelines: a risk-based AML/CFT framework in which compliance is expected to evolve as customers, transactions, technology and financial-crime risks evolve.
By FCCT Editorial Team

