Introduction
Applying the same KYC controls to a first-time savings account holder in a small town and a high-net-worth individual with complex international transactions is both operationally wasteful and regulatory misaligned. Risk-based KYC the application of due diligence controls proportionate to the actual money laundering and fraud risk a customer presents is the foundation of both FATF’s global standards and RBI’s domestic KYC framework. Building a tiered compliance model that implements risk-based KYC at scale requires systematic risk assessment, defined due diligence workflows for each tier, and technology that automates tier assignment and ongoing review.
The Regulatory Foundation: FATF and RBI
FATF Recommendation 10 requires financial institutions to apply customer due diligence (CDD) measures to verify customer identities on a risk-sensitive basis.
If an account starts with a standard-risk classification but later shows high-value, unusual transaction patterns, the system should, therefore, automatically escalate it to EDD review rather than continue standard monitoring.
RBI’s Master Directions on KYC (2016, updated 2023) incorporate this explicitly: Section 13 on Customer Due Diligence distinguishes between Simplified Due Diligence (SDD) for lower-risk customers, Standard CDD for the general population, and Enhanced Due Diligence (EDD) for higher-risk customers. Risk assessment determines which CDD level each customer requires, rather than relying on arbitrary classifications.
The Three-Tier Risk-Based KYC Framework
Tier 1: Simplified Due Diligence (SDD)
Regulators permit financial institutions to apply SDD to customers who present a demonstrably low risk of money laundering and terrorist financing. RBI permits SDD for: small-value accounts with capped balances and transaction limits; customers onboarded through formally administered government schemes; and certain categories of regulated customers (bank staff accounts, financial institutional accounts in some contexts).
Under SDD, identity verification requirements are reduced; typically, a single OVD with basic name confirmation and ongoing monitoring is lighter. The critical compliance point: the institution must document its risk assessment that justifies SDD classification. Financial institutions cannot apply SDD by default simply to avoid verification efforts.
Tier 2: Standard Customer Due Diligence
Standard CDD applies to the majority of customers who do not present specific elevated risk indicators. It requires: verification of identity through an OVD (Aadhaar, PAN, passport, etc.); confirmation of current address; understanding of the purpose and nature of the business relationship; and monitoring of transactions for patterns inconsistent with the stated purpose.
For digital platforms, standard CDD is the baseline that automated KYC APIs support: document verification, database cross-reference, and face match for individuals; entity verification and director checks for businesses.
Tier 3: Enhanced Due Diligence (EDD)
EDD applies to customers presenting elevated ML/TF risk. Mandatory EDD triggers under RBI’s framework: Politically Exposed Persons (PEPs) and their family members and close associates; customers from countries identified by FATF as high-risk; non-face-to-face customers engaged in high-value transactions; customers with unusual transaction patterns inconsistent with stated purpose; and cases where adverse media or intelligence information raises concerns.
EDD requirements include: additional identity documentation beyond standard OVDs; source of funds/wealth documentation; understanding of ownership and control structure (critical for legal entities); enhanced ongoing monitoring; and senior management approval for account opening. Financial institutions must document EDD in the customer’s CDD record.
Building Risk Assessment into the Onboarding Flow
Customer Risk Factors
Risk-based KYC requires a structured risk assessment at onboarding that evaluates: customer type (individual, business, legal entity), nationality and jurisdiction, PEP status and family connections, expected transaction profile and product usage, delivery channel (face-to-face, digital, third-party), and income/source of funds profile.
Product and Transaction Risk Factors
The product a customer accesses also affects the risk tier. For example, high-value savings and investment products carry greater risk than basic payment accounts. Similarly, international transfer capabilities increase jurisdictional risk. Moreover, lending products secured by complex collateral require lenders to conduct enhanced borrower verification.
Geographic Risk Factors
FATF’s regularly updated list of High-Risk and Other Monitored Jurisdictions, combined with India-specific geographic risk intelligence (Naxal-affected districts, certain border regions), contributes to the geographic risk dimension of customer assessment.
Risk Scoring Automation
Manual risk assessment at the individual customer level does not scale. Production implementations use automated risk scoring: each risk factor receives a weighted score; the aggregate score determines the initial risk tier; the tier assignment triggers the appropriate CDD workflow.
Moreover, compliance teams must be able to explain automated scoring. In addition, regulators must be able to understand why the system assigned a customer to a specific tier.
Ongoing Risk Review: Dynamic Risk Classification
Risk classification at onboarding is a starting point, not a permanent assignment. Transaction monitoring, life event triggers (large deposits, unusual counterparties, address changes to high-risk locations), and periodic review must update risk classifications dynamically. If an account starts with a standard-risk classification but later shows high-value, unusual transaction patterns, the system should automatically escalate it to EDD review instead of keeping it under standard monitoring.
Where BeFiSc Fits
BeFiSc’s verification APIs support all three tiers of the risk-based KYC framework: simplified document checks for SDD-eligible accounts, full KYC and KYB verification for standard CDD, and enhanced multi-source verification, document forensics, and fraud intelligence for EDD scenarios. The API-driven architecture allows tier-based verification workflow configuration without manual routing.
Key Takeaways
PEP identification and EDD execution are the most scrutinised elements during regulatory KYC inspections.
Risk-based KYC is mandated by both FATF Recommendation 10 and RBI’s Master Directions — it is a regulatory requirement, not an option.
The three tiers — SDD, Standard CDD, EDD — must be defined with documented risk criteria, not applied arbitrarily.
Automated risk scoring at onboarding is essential for scale — manual assessment does not work for high-volume digital platforms.
Dynamic risk classification through ongoing monitoring is as important as initial tier assignment.
Frequently Asked Questions
Can a customer’s KYC risk rating change after onboarding?
Yes. A customer’s risk rating should change when new information or activity indicates a different level of risk. For example, unusual transaction patterns, significant changes in transaction volume, adverse media, ownership changes, or new PEP exposure can trigger a risk reassessment. Therefore, risk classification should remain dynamic rather than being treated as a one-time onboarding decision.
How does technology help implement risk-based KYC?
Technology automates customer risk scoring, identity verification, PEP screening, transaction monitoring, and periodic reviews. As a result, financial institutions can assign customers to the appropriate KYC tier faster while maintaining consistent compliance controls. Moreover, automated systems can trigger EDD when a customer’s risk profile changes or suspicious activity is detected.
How often should customer risk classifications be reviewed?
High-risk (EDD) customers: annually at minimum. Medium-risk: every three years. Low-risk: every five years. Additionally, any trigger event- an unusual transaction, adverse media, or change in relationship profile should initiate an unscheduled review regardless of the periodic review schedule.
Who qualifies as a Politically Exposed Person (PEP) under RBI’s KYC framework?
A PEP is an individual who is, or has been, entrusted with a prominent public function heads of state, senior politicians, senior government officials, senior judicial officials, senior military officials, and senior executives of state-owned enterprises. Family members and close associates of PEPs are subject to EDD even if they are not PEPs themselves.
What is the difference between risk-based KYC and standard KYC?
Standard KYC applies uniform verification requirements to all customers. Risk-based KYC varies the intensity and scope of verification based on each customer’s assessed risk profile. Risk-based KYC is more efficient (fewer resources spent on low-risk customers) and more effective (more scrutiny on higher-risk situations) than uniform application.
Conclusion
Risk-based KYC enables financial institutions to apply the right level of due diligence to the right customer. Instead of treating every customer identically, institutions can use documented risk factors to determine whether Simplified Due Diligence, Standard CDD, or Enhanced Due Diligence is appropriate.
More importantly, effective risk-based KYC does not end at onboarding. Continuous monitoring, automated risk scoring, and trigger-based reviews help institutions identify changes in customer risk and escalate cases when necessary. By combining RBI-aligned compliance processes with scalable verification technology, banks, NBFCs, and fintechs can strengthen fraud prevention while making KYC operations faster and more efficient.
Build smarter compliance with BeFisc.
[…] without adding customer friction, catching fraud while preserving the frictionless experience. [Behavioural biometrics], [device intelligence], digital footprint analysis, and [AI-driven risk assessment] enable fraud […]
[…] direction of the ecosystem favours them. Transport registries are digitising deeper, face-binding is becoming routine, and insurers increasingly price platform risk on verification rigour. A driving licence […]
[…] you are (inherent factors). Biometric characteristics of the user include fingerprint, facial recognition, iris, voice, and [behavioural biometrics]. […]