Data Fiduciary Under DPDP Act: What It Means for Fintechs Handling User Data

Introduction

Applying the same KYC controls to a first-time savings account holder in a small town and a high-net-worth individual with complex international transactions is both operationally wasteful and regulatory misaligned. Risk-based KYC the application of due diligence controls proportionate to the actual money laundering and fraud risk a customer presents is the foundation of both FATF’s global standards and RBI’s domestic KYC framework. Building a tiered compliance model that implements risk-based KYC at scale requires systematic risk assessment, defined due diligence workflows for each tier, and technology that automates tier assignment and ongoing review.

The Regulatory Foundation: FATF and RBI

FATF Recommendation 10 requires that financial institutions ‘apply customer due diligence (CDD) measures to verify the identity of their customers’ and that this be done ‘on a risk-sensitive basis.’ This means the intensity of verification, not just whether verification happens, must reflect the customer’s risk profile.

RBI’s Master Directions on KYC (2016, updated 2023) incorporate this explicitly: Section 13 on Customer Due Diligence distinguishes between Simplified Due Diligence (SDD) for lower-risk customers, Standard CDD for the general population, and Enhanced Due Diligence (EDD) for higher-risk customers. The choice of which CDD level applies to which customer is driven by risk assessment, not arbitrary classification.

The Three-Tier Risk-Based KYC Framework

Tier 1: Simplified Due Diligence (SDD)

SDD is permitted for customers where the risk of money laundering and terrorist financing is demonstrably low. RBI permits SDD for: small-value accounts with capped balances and transaction limits; customers onboarded through formally administered government schemes; and certain categories of regulated customers (bank staff accounts, financial institutional accounts in some contexts).

Under SDD, identity verification requirements are reduced; typically, a single OVD with basic name confirmation and ongoing monitoring is lighter. The critical compliance point: the institution must document its risk assessment that justifies SDD classification. SDD cannot be applied as a default to avoid verification effort.

Tier 2: Standard Customer Due Diligence

Standard CDD applies to the majority of customers who do not present specific elevated risk indicators. It requires: verification of identity through an OVD (Aadhaar, PAN, passport, etc.); confirmation of current address; understanding of the purpose and nature of the business relationship; and monitoring of transactions for patterns inconsistent with the stated purpose.

For digital platforms, standard CDD is the baseline that automated KYC APIs support: document verification, database cross-reference, and face match for individuals; entity verification and director checks for businesses.

Tier 3: Enhanced Due Diligence (EDD)

EDD applies to customers presenting elevated ML/TF risk. Mandatory EDD triggers under RBI’s framework: Politically Exposed Persons (PEPs) and their family members and close associates; customers from countries identified by FATF as high-risk; non-face-to-face customers engaged in high-value transactions; customers with unusual transaction patterns inconsistent with stated purpose; and cases where adverse media or intelligence information raises concerns.

EDD requirements include: additional identity documentation beyond standard OVDs; source of funds/wealth documentation; understanding of ownership and control structure (critical for legal entities); enhanced ongoing monitoring; and senior management approval for account opening. EDD must be documented in the customer’s CDD record.

Building Risk Assessment into the Onboarding Flow

Customer Risk Factors

Risk-based KYC requires a structured risk assessment at onboarding that evaluates: customer type (individual, business, legal entity), nationality and jurisdiction, PEP status and family connections, expected transaction profile and product usage, delivery channel (face-to-face, digital, third-party), and income/source of funds profile.

Product and Transaction Risk Factors

The product being accessed also affects the risk tier: high-value savings and investment products carry higher risk than basic payment accounts; international transfer capability adds jurisdictional risk; lending products secured by complex collateral require enhanced borrower verification.

Geographic Risk Factors

FATF’s regularly updated list of High-Risk and Other Monitored Jurisdictions, combined with India-specific geographic risk intelligence (Naxal-affected districts, certain border regions), contributes to the geographic risk dimension of customer assessment.

Risk Scoring Automation

Manual risk assessment at the individual customer level does not scale. Production implementations use automated risk scoring: each risk factor receives a weighted score; the aggregate score determines the initial risk tier; the tier assignment triggers the appropriate CDD workflow. Automated scoring must be explainable to compliance teams, and regulators must be able to understand why a customer was assigned to a specific tier.

Ongoing Risk Review: Dynamic Risk Classification

Risk classification at onboarding is a starting point, not a permanent assignment. Transaction monitoring, life event triggers (large deposits, unusual counterparties, address changes to high-risk locations), and periodic review must update risk classifications dynamically. An account that opens as standard-risk and then exhibits high-value, unusual-pattern transactions should be automatically escalated to EDD review, not continue under standard monitoring.

Where BeFiSc Fits

BeFiSc’s verification APIs support all three tiers of the risk-based KYC framework: simplified document checks for SDD-eligible accounts, full KYC and KYB verification for standard CDD, and enhanced multi-source verification, document forensics, and fraud intelligence for EDD scenarios. The API-driven architecture allows tier-based verification workflow configuration without manual routing.

Key Takeaways

PEP identification and EDD execution are the most scrutinized elements during regulatory KYC inspections.

Risk-based KYC is mandated by both FATF Recommendation 10 and RBI’s Master Directions — it is a regulatory requirement, not an option.

The three tiers, SDD, Standard CDD, and EDD, must be defined with documented risk criteria, not applied arbitrarily.

Automated risk scoring at onboarding is essential for scale manual assessment does not work for high-volume digital platforms.

Dynamic risk classification through ongoing monitoring is as important as initial tier assignment.

Frequently Asked Questions

How often should customer risk classifications be reviewed?

High-risk (EDD) customers: annually at minimum. Medium-risk: every three years. Low-risk: every five years. Additionally, any trigger event — unusual transaction, adverse media, change in relationship profile — should initiate an unscheduled review regardless of the periodic review schedule.

Who qualifies as a Politically Exposed Person (PEP) under RBI’s KYC framework?

A PEP is an individual who is, or has been, entrusted with a prominent public function — heads of state, senior politicians, senior government officials, senior judicial officials, senior military officials, and senior executives of state-owned enterprises. Family members and close associates of PEPs are subject to EDD even if they are not PEPs themselves..

What is the difference between risk-based KYC and standard KYC?

Risk-based KYC varies the intensity and scope of verification based on each customer’s assessed risk profile. Risk-based KYC is more efficient (fewer resources spent on low-risk customers) and more effective (more scrutiny on higher-risk situations) than uniform application.

Conclusion

A well-designed risk-based KYC framework enables financial institutions to balance regulatory compliance with operational efficiency by applying the right level of due diligence to the right customers. By implementing structured risk assessment, automated risk scoring, and tiered workflows for SDD, Standard CDD, and EDD, banks, NBFCs, and fintechs can strengthen AML compliance while improving the customer onboarding experience. Combined with continuous monitoring and periodic risk reviews, risk-based KYC helps detect emerging risks, reduce fraud exposure, and meet FATF and RBI compliance requirements. Investing in a scalable, technology-driven risk-based KYC strategy is essential for building secure, compliant, and future-ready onboarding processes.

Previous Article

 Corporate Fraud in India: Patterns, Risk Signals, and Prevention Frameworks

Next Article

 AML Compliance Software: What to Look for and How to Evaluate Vendors

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *