Introduction
Applying the same KYC controls to a first-time savings account holder in a small town and a high-net-worth individual with complex international transactions is both operationally wasteful and regulatory misaligned. Risk-based KYC the application of due diligence controls proportionate to the actual money laundering and fraud risk a customer presents is the foundation of both FATF’s global standards and RBI’s domestic KYC framework. Building a tiered compliance model that implements risk-based KYC at scale requires systematic risk assessment, defined due diligence workflows for each tier, and technology that automates tier assignment and ongoing review.
The Regulatory Foundation: FATF and RBI
FATF Recommendation 10 requires financial institutions to apply customer due diligence (CDD) measures and verify customer identities on a risk-sensitive basis. Therefore, financial institutions must tailor the intensity of verification to each customer’s risk profile, rather than applying the same level of verification to everyone.
\RBI’s Master Directions on KYC (2016, updated 2023) incorporate this explicitly: Section 13 on Customer Due Diligence distinguishes between Simplified Due Diligence (SDD) for lower-risk customers, Standard CDD for the general population, and Enhanced Due Diligence (EDD) for higher-risk customers. Therefore, risk assessment determines which CDD level applies to each customer, rather than arbitrary classification.
The Three-Tier Risk-Based KYC Framework
Tier 1: Simplified Due Diligence (SDD)
Furthermore, financial institutions may apply SDD when they can demonstrate that a customer’s risk of money laundering and terrorist financing is low. In particular, the RBI permits SDD for small-value accounts with capped balances and transaction limits, customers onboarded through formally administered government schemes, and certain categories of regulated customers, such as bank staff accounts and financial institutional accounts in some contexts.
Under SDD, identity verification requirements are reduced; typically, a single OVD with basic name confirmation and ongoing monitoring is lighter. The critical compliance point: the institution must document its risk assessment that justifies SDD classification. Financial institutions cannot use SDD as a default to avoid verification efforts.
Tier 2: Standard Customer Due Diligence
Standard CDD applies to the majority of customers who do not present specific elevated risk indicators. It requires: verification of identity through an OVD (Aadhaar, PAN, passport, etc.); confirmation of current address; understanding of the purpose and nature of the business relationship; and monitoring of transactions for patterns inconsistent with the stated purpose.
For digital platforms, standard CDD is the baseline that automated KYC APIs support: document verification, database cross-reference, and face match for individuals; entity verification and director checks for businesses.
Tier 3: Enhanced Due Diligence (EDD)
EDD applies to customers presenting elevated ML/TF risk. Mandatory EDD triggers under RBI’s framework: Politically Exposed Persons (PEPs) and their family members and close associates; customers from countries identified by FATF as high-risk; non-face-to-face customers engaged in high-value transactions; customers with unusual transaction patterns inconsistent with stated purpose; and cases where adverse media or intelligence information raises concerns.
EDD requirements include: additional identity documentation beyond standard OVDs; source of funds/wealth documentation; understanding of ownership and control structure (critical for legal entities); enhanced ongoing monitoring; and senior management approval for account opening. Financial institutions must document EDD in the customer’s CDD record.
Building Risk Assessment into the Onboarding Flow
Customer Risk Factors
Risk-based KYC requires a structured risk assessment at onboarding that evaluates: customer type (individual, business, legal entity), nationality and jurisdiction, PEP status and family connections, expected transaction profile and product usage, delivery channel (face-to-face, digital, third-party), and income/source of funds profile.
Product and Transaction Risk Factors
Additionally, the product also affects the risk tier. For example, high-value savings and investment products carry higher risk than basic payment accounts. Similarly, international transfer capabilities add jurisdictional risk, while lending products secured by complex collateral require enhanced borrower verification.
Geographic Risk Factors
FATF’s regularly updated list of High-Risk and Other Monitored Jurisdictions, combined with India-specific geographic risk intelligence (Naxal-affected districts, certain border regions), contributes to the geographic risk dimension of customer assessment.
Risk Scoring Automation
Manual risk assessment at individual customer level does not scale. Production implementations use automated risk scoring: each risk factor receives a weighted score; the aggregate score determines the initial risk tier; the tier assignment triggers the appropriate CDD workflow.
Moreover, compliance teams must be able to explain automated scoring. Similarly, regulators must be able to understand why the system assigned a customer to a specific tier.
Ongoing Risk Review: Dynamic Risk Classification
Risk classification at onboarding is a starting point, not a permanent assignment. Transaction monitoring, life event triggers (large deposits, unusual counterparties, address changes to high-risk locations), and periodic review must update risk classifications dynamically. For example, if a standard-risk account later shows high-value, unusual transaction patterns, the system should automatically escalate it to EDD review. As a result, the account should not continue under standard monitoring.
Key Takeaways
PEP identification and EDD execution are the most scrutinized elements during regulatory KYC inspections.
Risk-based KYC is mandated by both FATF Recommendation 10 and RBI’s Master Directions it is a regulatory requirement, not an option.
The three tiers SDD, Standard CDD, EDD must be defined with documented risk criteria, not applied arbitrarily.
Automated risk scoring at onboarding is essential for scale manual assessment does not work for high-volume digital platforms.
Dynamic risk classification through ongoing monitoring is as important as initial tier assignment.
Where BeFiSc Fits
BeFiSc’s verification APIs support all three tiers of the risk-based KYC framework: simplified document checks for SDD-eligible accounts, full KYC and KYB verification for standard CDD, and enhanced multi-source verification, document forensics, and fraud intelligence for EDD scenarios. The API-driven architecture allows tier-based verification workflow configuration without manual routing.
Frequently Asked Questions
How often should customer risk classification be reviewed?
High-risk customers should be reviewed at least annually, medium-risk customers every three years, and low-risk customers every five years. However, institutions should also conduct an immediate review when trigger events, such as unusual transactions, adverse media, or changes in the customer’s risk profile, occur.
How does risk-based KYC differ from standard KYC?
Risk-Based KYC adjusts the intensity of customer due diligence according to the customer’s assessed risk. Low-risk customers may qualify for simplified due diligence, while higher-risk customers require Enhanced Due Diligence, including additional verification, source-of-funds checks, and enhanced monitoring.
How often should customer risk classifications be reviewed?
High-risk (EDD) customers: annually at minimum. Medium-risk: every three years. Low-risk: every five years. Additionally, any trigger event- an unusual transaction, adverse media, change in relationship profile should initiate an unscheduled review regardless of the periodic review schedule.
Who qualifies as a Politically Exposed Person (PEP) under RBI’s KYC framework?
A PEP is an individual who is, or has been, entrusted with a prominent public function, such as heads of state, senior politicians, senior government officials, senior judicial officials, senior military officials, and senior executives of state-owned enterprises. Family members and close associates of PEPs are subject to EDD even if they are not PEPs themselves.
What is the difference between risk-based KYC and standard KYC?
Standard KYC applies uniform verification requirements to all customers. Risk-based KYC varies the intensity and scope of verification based on each customer’s assessed risk profile. Risk-based KYC is more efficient (fewer resources spent on low-risk customers) and more effective (more scrutiny on higher-risk situations) than uniform application.
Conclusion
Risk-based KYC is no longer a one-size-fits-all compliance exercise. A strong framework aligns the depth of customer due diligence with the actual ML/TF and fraud risk each customer presents. By clearly defining SDD, Standard CDD, and EDD tiers, institutions can strengthen regulatory compliance while reducing unnecessary friction for low-risk customers.
The most effective approach combines structured risk assessment, explainable automated scoring, continuous transaction monitoring, and dynamic risk classification. As customer behaviour and risk profiles change, KYC controls must evolve with them. For financial institutions scaling digital onboarding, technology-enabled risk-based KYC provides the foundation for faster onboarding, stronger fraud prevention, and more consistent compliance with RBI and FATF expectations.
Automate Risk-Based KYC with BeFiSc. Verify smarter. Comply faster.
[…] and current-address requirements, exactly as a risk-based KYC design like the tiered model in our [risk-based KYC guide] would […]
[…] authentication only when risk warrants (an unusual action, a new device, a high-value transaction). Risk-based authentication authenticates most of the time seamlessly and demands more only when signals indicate risk, […]