AML prevention strategies, regular identity audits, and customer identification/onboarding controls.
ANTI-MONEY LAUNDERING & KYC POLICY MANUAL
| Policy Category | Compliance │ AML / KYC │ Policy Manual |
| Policy Owner | Chief Operation Officer |
| Policy Approving Authority | Board of Directors |
| Review Date | 01-04-2026 |
| Review Frequency | Annual (or as triggered by RBI / regulatory change) |
| Next Review Due | 01-04-2027 |
| Supersedes | DJT AML-KYC Policy v1.0 (all prior versions) |
| Version | 2.0 |
| Classification | Confidential – Internal Use Only |
Document Revision History
| Version | Release Date | Details |
| 1.0 | 01-04-2025 | First Version |
| 2.0 | 01-04-2026 | Second Version – Updated to align with RBI (Non-Banking Financial Companies – Know Your Customer) Directions, 2025 dated November 28, 2025 (Updated as on December 29, 2025) |
Table of Contents
| S.No | Particulars |
| 1 | Introduction |
| 2 | Policy Objectives |
| 3 | Scope of the Policy |
| 4 | Definitions |
| 5 | Money Laundering |
| 6 | Stages of Money Laundering |
| 7 | Obligations under the PML Act 2002 |
| 8 | DJT MFI Role in Preventing Money Laundering |
| 9 | Definition of Customer |
| 10 | Key Elements of the Policy |
| 11 | Customer Acceptance Policy (CAP) |
| 12 | Customer Identification Procedures (CIP) |
| 13 | Monitoring of Transactions |
| 14 | Client Due Diligence Measures |
| 15 | Risk Management |
| 16 | Customer Education |
| 17 | KYC for Existing Accounts |
| 18 | Suspicious Transaction Report |
| 19 | Principal Officer |
| 20 | Designated Director |
| 21 | IT System |
| 22 | Review of Policy |
| 23 | Additions Required to DJT MFI KYC & AML Policy |
| 24 | Annexure-I: Customer Identification Procedure |
| 25 | Annexure-II: Suspicious Transaction Internal Report Form |
1. Introduction
In order to prevent banks and other financial institutions from being used as a channel for Money Laundering (ML) / Terrorist Financing (TF) and to ensure the integrity and stability of the financial system, efforts are continuously being made both internationally and nationally, by way of prescribing various rules and regulations. Internationally, the Financial Action Task Force (FATF) which is an inter-governmental body established in 1989 by the Ministers of its member jurisdictions, sets standards and promotes effective implementation of legal, regulatory and operational measures for combating money laundering, terrorist financing and other related threats to the integrity of the international financial system. India, as a member of FATF, is committed to upholding measures to protect the integrity of the international financial system.
In India, the Prevention of Money-Laundering Act, 2002, and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, form the legal framework on Anti Money Laundering (AML) and Countering the Financing of Terrorism (CFT). The provisions of the PML Act, 2002 and the PML Rules, 2005, as amended from time to time by the Government of India, require Regulated Entities (REs) to follow certain customer identification procedures while undertaking a transaction either by establishing an account-based relationship or otherwise, and to monitor their transactions.
This policy document is prepared in line with the Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Directions, 2025 issued vide RBI/DOR/2025-26/361 dated November 28, 2025 (updated as on December 29, 2025), which supersede all prior RBI KYC directions for NBFCs. These Directions take into account the recommendations of the Financial Action Task Force (FATF) on AML Standards and on Combating Financing of Terrorism, as well as aspects covered in the Basel Committee document on customer due diligence.
2. Policy Objectives
It is the Policy of DJT MFI that statutory and regulatory obligations to prevent money laundering are to be met in full. Positive management action will be exercised to minimize the risk of DJT MFI services being abused for the purposes of laundering funds associated with drug trafficking, terrorism and other serious crime. The objectives of the Policy are as follows:
- To prevent criminal elements from using DJT MFI system for money laundering activities;
- To enable DJT MFI to know/understand the customers and their financial dealings better, which in turn would help DJT MFI to manage risks prudently;
- To put in place appropriate controls for detection and reporting of suspicious activities in accordance with applicable laws/laid down procedures;
- To comply with applicable laws and regulatory guidelines; and
- To take necessary steps to ensure that the concerned staff are adequately trained in KYC/AML procedures.
3. Scope of the Policy
This policy is applicable to all branches/offices of DJT MFI and is to be read in conjunction with related operational guidelines issued from time to time. In accordance with the RBI KYC Directions, 2025, this policy also applies to those branches and majority-owned subsidiaries of DJT MFI which are located abroad, to the extent they are not contradictory to the local laws of the host country. In case of any variance in KYC/AML standards prescribed by RBI and the host country regulators, the more stringent of the two regulations shall apply.
4. Definitions
4.1 Terms under the Prevention of Money Laundering Act, 2002 and Rules, 2005
The following terms bear the meaning assigned in the Prevention of Money Laundering Act, 2002, and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005:
- 'Aadhaar number' shall have the meaning assigned to it in clause (a) of section 2 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016);
- 'Act' and 'Rules' mean the Prevention of Money-Laundering Act, 2002 and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, respectively and amendments thereto;
- 'Authentication' in the context of Aadhaar authentication, means the process as defined under sub-section (c) of section 2 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016;
- 'Beneficial Owner (BO)' – (a) Where the customer is a company: the natural person(s), whether acting alone or together or through juridical persons, having controlling ownership interest (more than 10% of shares/capital/profits) or who exercises control through other means; (b) Where the customer is a partnership firm: the natural person(s) having ownership/entitlement to more than 10% of capital or profits, or who exercises control; (c) Where the customer is an unincorporated association or body of individuals: the natural person(s) having ownership/entitlement to more than 15% of property, capital or profits; (d) Where the customer is a trust: the author, trustee, beneficiaries with 10% or more interest, and any natural person exercising ultimate effective control;
- 'Central KYC Records Registry (CKYCR)' means an entity defined under Rule 2(1) of the Rules, to receive, store, safeguard and retrieve the KYC records in digital form of a customer;
- 'Certified Copy' means comparing the copy of OVD or proof of possession of Aadhaar number produced by the customer with the original, and recording the comparison on the copy by an authorised officer of the NBFC as per the provisions of the Act;
- 'Customer Due Diligence (CDD)' means identifying and verifying the customer and the beneficial owner using reliable and independent sources of identification;
- 'Designated Director' means a person whom the NBFC designates to ensure overall compliance with the obligations imposed under Chapter IV of the PML Act and the Rules and shall include the Managing Director or a whole-time Director, whom the Board of Directors has duly authorised;
- 'Digital KYC' means that an authorised officer of the NBFC captures a live photo of the customer and officially valid document or the proof of possession of Aadhaar (where offline verification cannot be carried out), along with the latitude and longitude of the location where such live photo is being taken, as per the provisions contained in the Act;
- 'Digital Signature' shall have the same meaning as assigned to it in clause (p) of sub-section (1) of section 2 of the Information Technology Act, 2000 (21 of 2000);
- 'Equivalent e-document' means an electronic equivalent of a document that the issuing authority issues with its valid digital signature, including documents issued to the digital locker account of the customer;
- 'Know Your Client (KYC) Identifier' means the unique number or code that the Central KYC Records Registry assigns to a customer. A customer can obtain his KYC Identifier on the CKYCR Portal (www.ckycindia.in);
- 'Non-profit organisations (NPO)' means any entity or organisation constituted for religious or charitable purposes registered as a trust or a society under the Societies Registration Act, 1860 or any similar State legislation, or a company registered under section 8 of the Companies Act, 2013;
- 'Officially Valid Document (OVD)' means the passport, the driving licence, proof of possession of Aadhaar number, the Voter's Identity Card issued by the Election Commission of India, the job card issued under NREGA and duly signed by a State Government officer, and the letter issued by the National Population Register containing details of name and address;
- 'Offline verification' shall have the same meaning as assigned to it in clause (pa) of section 2 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016);
- 'On-going Due Diligence' means regular monitoring of transactions in accounts to ensure that transactions are consistent with the NBFC's knowledge about the customers, customers' business and risk profile, the source of funds/wealth;
- 'Periodic Updation' means the steps taken to ensure that documents, data or information collected under the CDD process are kept up-to-date and relevant by undertaking reviews of existing records at the periodicity prescribed by the RBI;
- 'Person' has the same meaning assigned in the Act and includes: (a) an individual; (b) a Hindu undivided family; (c) a company; (d) an association of persons or a body of individuals, whether incorporated or not; (e) every artificial juridical person; and (f) any agency, office or branch owned or controlled by any of the above;
- 'Principal Officer' means a NBFC's nominated officer at the management level, responsible for furnishing information as per rule 8 of the Rules;
- 'Shell Bank' means a bank that has no physical presence in the country in which it is incorporated and licensed, and which is unaffiliated with a regulated financial group that is subject to effective consolidated supervision;
- 'Suspicious transaction' means a transaction, including an attempted transaction, whether or not made in cash, which, to a person acting in good faith: (a) gives rise to a reasonable ground of suspicion that it may involve proceeds of an offence specified in the Schedule to the Act, regardless of the value involved; or (b) appears to be made in circumstances of unusual or unjustified complexity; or (c) appears to have no economic rationale or bona fide purpose; or (d) gives rise to a reasonable ground of suspicion that it may involve financing of the activities relating to terrorism;
- 'Video based Customer Identification Process (V-CIP)' means an alternative method by which an authorised official of the NBFC conducts customer identification with facial recognition and customer due diligence through a seamless, secure, live, informed-consent based audio-visual interaction with the customer.
5. Money Laundering
Money laundering is a process to make illegitimate money appear legitimate. It involves cleansing of 'dirty money' engaging in a series of financial transactions. It is called 'dirty money' because it originates from criminal activities like drug trafficking, embezzlement, tax evasion, corruption, illegal gambling, smuggling, arson, racketeering, illegal prostitution, fraud or any other illegal activity, with the objective of hiding their true source and making them legally usable.
Section 3 of the Prevention of Money Laundering Act, 2002 defines the offence of money laundering as under:
"Whosoever directly or indirectly attempts to indulge or knowingly assists or knowingly is a party or is actually involved in any process or activity connected with the proceeds of crime and projecting it as untainted property shall be guilty of offence of money laundering."
Money Laundering is not just the attempt to disguise money derived from illegal activities. Rather, money laundering is involvement in any transaction or series of transactions that seeks to conceal or disguise the nature or source of proceeds derived from illegal activities, including drug trafficking, terrorism, organized crime, fraud and many other crimes. A financial institution may be used at any point in the money laundering process.
6. Stages of Money Laundering
The laundering process is often described as taking place in three stages:
Placement (Injection or Pre-washing): Placement, being the first stage, is the means by which funds derived from a criminal activity are introduced into the financial system, either directly or through other retail businesses. This can be in the form of large sums of cash or a series of smaller sums.
Layering (Stacking or Washing): The aim of the second stage is to disguise the transaction through a succession of complex financial transactions with the purpose of erasing all links with its unlawful origin. The funds may be converted into shares, bonds or any other easily negotiable asset or may be transferred to other accounts in other jurisdictions.
Integration (Recycling): Complex integration schemes then place the laundered funds back into the economy through real estate, business assets, securities and equities, in such a way that they re-enter the financial system appearing as normal business funds that have been legitimately earned.
The largest amount of criminal money that needs to be laundered comes from the sale of illegal drugs, primarily heroin, cocaine and cannabis.
7. Obligations under the PML Act 2002
Section 12 of the PML Act 2002 places certain obligations on every banking company, financial institution and intermediary, which include:
- Maintaining a record of prescribed transactions;
- Furnishing information of prescribed transactions to the specified authority;
- Verifying and maintaining records of the identity of its clients; and
- Preserving records in respect of (i), (ii) and (iii) above for a period of five years from the date of transaction (for transactions) and five years after the business relationship has ended (for customer identification records), in accordance with the RBI KYC Directions, 2025.
8. DJT MFI's Role in Preventing Money Laundering
The prevention of money laundering from the point of view of DJT MFI has three objectives:
- Ethical – taking part in the fight against crime;
- Professional – ensuring that DJT MFI is not involved in recycling the proceeds of crime that would call into question its reputation, integrity and, if fraud is involved, its solvency; and
- Legal – complying with RBI Regulations that impose a series of specific obligations on financial institutions and their employees.
All members of DJT MFI's management and staff are expected to be aware of their personal legal obligations and the legal obligations of DJT MFI, be alert for anything suspicious, and report suspicions in line with internal procedures.
It is thus required that DJT MFI's Standard Operating Procedures address the demands of KYC and AML norms as laid down in the RBI KYC Directions, 2025.
9. Definition of Customer
A Customer for the purpose of this policy is defined as:
- A person or an entity that maintains an account and/or has a business relationship with DJT MFI;
- One on whose behalf the account is maintained (i.e. the 'beneficial owner');
- Beneficiaries of transactions conducted by professional intermediaries, such as Stock Brokers, Chartered Accountants, Solicitors etc. as permitted under the law; and
- Any person or entity connected with a financial transaction.
A 'Walk-in Customer' means a person who does not have an account-based relationship with DJT MFI but undertakes transactions with DJT MFI.
All members of DJT MFI's staff are expected to be aware of such definition of 'Customer' and 'Beneficial Owner' to ensure adherence to the policy during acquisition of new clientele and review of existing clientele.
10. Key Elements of the Policy
- Customer Acceptance Policy
- Customer Identification Procedures
- Monitoring of Transactions
- Risk Management
11. Customer Acceptance Policy (CAP)
DJT MFI shall frame a Customer Acceptance Policy. The Customer Acceptance Policy ensures that explicit guidelines are in place on the following aspects of customer relationship in DJT MFI. The NBFC shall:
- Not open any account in an anonymous or fictitious / benami name;
- Open no account where it is unable to apply appropriate CDD measures, either due to non-cooperation of the customer or unreliability of the documents/information furnished by the customer. The NBFC shall consider filing an STR, if necessary, when it is unable to comply with the relevant CDD measures;
- Not undertake a transaction or an account-based relationship without following the CDD procedure;
- Specify the mandatory information to be sought for KYC purposes while opening an account and during the periodic updation;
- Obtain additional information, where its internal KYC Policy has not specified such information requirement, with the explicit consent of the customer;
- Apply the CDD procedure at the Unique Customer Identification Customer (UCIC) level. If an existing KYC-compliant customer desires to open another account or avail of any other product or service from the same NBFC, there shall be no need for a fresh CDD exercise as far as identification of the customer is concerned;
- Follow the CDD procedure for all the joint account holders, while opening a joint account;
- Clearly spell out the circumstances in which a customer is permitted to act on behalf of another person/entity;
- Put in place a suitable system to ensure that the identity of the customer does not match with any person or entity whose name appears in the sanctions lists indicated in Chapter IX of the RBI KYC Directions, 2025;
- Verify the Permanent Account Number (PAN) (if obtained) from the verification facility of the issuing authority;
- Verify the customer's digital signature on the equivalent e-document (if obtained) as per the provisions of the Information Technology Act, 2000;
- Verify the Goods and Services Tax (GST) number from the search/verification facility of the issuing authority, where the GST details are available; and
- Allot a Unique Customer Identification Code (UCIC) while entering into new relationships with individual customers as also the existing individual customers.
The Customer Acceptance Policy shall not result in denial of a financial facility to members of the general public, especially those who are financially or socially disadvantaged, including Persons with Disabilities (PwDs). The NBFC shall not reject an application for onboarding or periodic updation of KYC without application of mind. The officer concerned shall duly record the reason(s) for rejection.
Where the NBFC forms a suspicion of money laundering or terrorist financing, and it reasonably believes that performing the CDD process will tip off the customer, it shall not pursue the CDD process and instead file an STR with FIU-IND.
DJT MFI shall ensure that it does not outsource the decision-making functions of determining compliance with KYC norms.
11.1 Risk Management under CAP
For risk management, DJT MFI shall have a risk-based approach which includes the following:
- DJT MFI shall categorise customers into low, medium, and high-risk categories, based on its assessment and risk perception;
- DJT MFI may lay down broad principles for the risk-categorisation of customers;
- DJT MFI shall undertake risk categorisation based on parameters such as the customer's identity, social/financial status, nature of business activity, information about the customer's business and its location, geographical risk covering customers as well as transactions, type of products/services offered, delivery channel used for delivery of products/services, types of transactions undertaken such as cash, cheque/monetary instruments, wire transfers, forex transactions, etc. DJT MFI may also factor in the ability to confirm identity documents through online or other services offered by issuing authorities;
- DJT MFI shall keep the risk categorisation of a customer and the specific reasons for such categorisation confidential and shall not reveal this information to the customer to avoid tipping off; and
- DJT MFI shall carry out periodic review of risk categorisation of accounts, with such periodicity being at least once in every six months, and shall establish the need for applying enhanced due diligence measures.
Note: DJT MFI may also use the FATF Public Statement, the reports and guidance notes on KYC/AML issued by the Indian Banks Association (IBA), and other agencies in its risk assessment.
| High Risk – Customers Requiring High Level of Monitoring |
| Non-Resident Accounts |
| High Net Worth Individuals |
| Trust, Charities, etc. |
| Companies having close family shareholding |
| Firms with sleeping partners |
| Politically Exposed Persons (PEP) |
12. Customer Identification Procedures (CIP)
This policy spells out the Customer Identification Procedure to be carried out at different stages. Customer identification means identifying the customer and verifying his/her identity by using reliable, independent source documents, data or information. Branches need to obtain sufficient information necessary to establish, to their satisfaction, the identity of each new customer, whether regular or occasional, and the purpose of the intended nature of business relationship.
For customers that are natural persons, branches have to obtain sufficient identification data to verify the identity of the customer, his/her address/location and also his/her recent photograph.
For customers that are legal persons or entities, the branches have to: (i) verify the legal status of the legal person/entity through proper and relevant documents; (ii) verify that any person purporting to act on behalf of the legal person/entity is so authorised and verify the identity of that person; and (iii) understand the ownership and control structure of the customer and determine who are the 'beneficial owners' or natural persons who ultimately control the legal person.
Customers will be classified into three risk categories namely High, Medium and Low, based on the risk perception. The risk categorization will be reviewed periodically.
12.1 When Customer Identification is Mandatory
DJT MFI shall undertake identification of customers in the following cases:
- Commencement of an account-based relationship with the customer;
- Carrying out any international money transfer operations for a person who is not an account holder of DJT MFI;
- When there is a doubt about the authenticity or adequacy of the customer identification data obtained;
- Selling third-party products as agents, selling its own products, payment of dues of credit cards/sale and reloading of prepaid/travel cards and any other product for more than ₹50,000;
- Carrying out transactions for a non-account-based customer (walk-in customer) where the amount involved is equal to or exceeds ₹50,000, whether conducted as a single transaction or several transactions that appear to be connected;
- When DJT MFI has reason to believe that a customer is intentionally structuring a transaction into a series of transactions below the threshold of ₹50,000; and
- DJT MFI shall ensure it does not seek introductions while opening accounts.
For the purpose of verifying identity at the time of commencement of an account-based relationship or while carrying out an occasional transaction of an amount equal to or exceeding ₹50,000 or any international money transfer operations, DJT MFI may, at its option, rely on customer due diligence done by a third party, subject to: (i) obtaining CDD records from the third party immediately or from CKYCR; (ii) the third party being a regulated entity; (iii) the third party not being based in a high-risk jurisdiction; and (iv) DJT MFI retaining ultimate responsibility for CDD and enhanced due diligence measures.
12.2 CDD Documents for Individuals
For undertaking CDD for an individual while establishing an account-based relationship, DJT MFI shall obtain:
- The Aadhaar number where (i) the individual is desirous of receiving any benefit under a scheme notified under section 7 of the Aadhaar Act, 2016, or (ii) submits the Aadhaar number voluntarily; or
- The proof of possession of Aadhaar number where DJT MFI can carry out offline verification; or
- The proof of possession of Aadhaar number where offline verification cannot be carried out, or any Officially Valid Document (OVD) or equivalent e-document containing details of identity and address; or
- The KYC Identifier with explicit consent to download records from CKYCR; and
- The PAN or equivalent e-document thereof or Form No. 60 as defined in Income-tax Rules, 1962 – mandatory in addition to the above.
- DJT MFI may require such other documents including in respect of the nature of business and financial status of the customer, or the equivalent e-documents thereof.
The verification method shall depend on the document submitted:
- Aadhaar number (voluntarily submitted to a notified NBFC): e-KYC authentication through UIDAI shall be carried out.
- Proof of possession of Aadhaar (offline verifiable): Offline verification shall be carried out.
- Equivalent e-document of OVD: Digital signature shall be verified as per the IT Act, 2000, and a live photo shall be taken.
- OVD or Aadhaar proof (offline verification not possible): Digital KYC process shall be carried out.
- KYC Identifier: KYC records shall be retrieved online from CKYCR.
Explanation 1: The NBFC shall, where its customer submits a proof of possession of Aadhaar Number containing Aadhaar Number, ensure that such customer redacts or blacks out his Aadhaar number through appropriate means where the authentication of Aadhaar number is not required.
Explanation 2: An NBFC official can perform biometric-based e-KYC authentication, including Aadhaar Face Authentication.
Explanation 3: The NBFC shall ensure that the use of Aadhaar, proof of possession of Aadhaar etc., is in accordance with the Aadhaar Act, 2016 and the regulations made thereunder.
Explanation 4: Aadhaar number is not mandatory for purposes of KYC. However, if the customer is desirous of receiving any benefit/subsidy under any scheme notified under section 7 of the Aadhaar Act, 2016, the customer shall provide the Aadhaar number to DJT MFI. In other cases, customers may provide the Aadhaar number voluntarily.
12.3 Digital KYC Process
DJT MFI shall put in place the following Digital KYC process for customer onboarding:
- DJT MFI shall develop an application for the digital KYC process available at all customer touch points. The KYC process shall be undertaken only through this authenticated application;
- Access to the application shall be controlled through login-id and password or a Live OTP/Time OTP mechanism. Unauthorised persons shall not be permitted to use it;
- The customer shall visit the location of the authorised official of DJT MFI or vice-versa. The original OVD shall be in possession of the customer;
- The authorised officer shall take a live photograph of the customer and embed it in the Customer Application Form (CAF). The application shall apply a watermark in readable form containing: CAF number, GPS coordinates, authorised official's name, unique employee code, date (DD:MM:YYYY) and time stamp (HH:MM:SS);
- The application shall capture only a live photograph (not printed or video-graphed). The background shall be white and no other person shall appear in the frame;
- The authorised officer shall capture the live photograph of the original OVD or proof of possession of Aadhaar where offline verification cannot be carried out, placed horizontally from above, and shall apply a watermark in readable form as mentioned above. No skew or tilt shall be permitted;
- The authorised officer shall capture the live photograph of the customer and documents in proper light so that they are clearly readable and identifiable;
- The authorised officer shall fill all entries in the CAF as per the documents. Where QR code is available (e.g., physical Aadhaar/e-Aadhaar), details may be auto-populated by scanning the QR code;
- An OTP message shall be sent to the customer's own mobile number. Upon successful OTP validation, it shall be treated as the customer's signature on CAF. DJT MFI shall not use the authorised officer's mobile number for this purpose;
- The authorised officer shall provide a declaration about the capturing of the live photograph. DJT MFI shall verify the authorised officer with an OTP sent to his registered mobile number. Upon successful OTP validation, it shall be treated as the authorised officer's signature;
- Subsequent to all these activities, the application shall generate a transaction-id/reference-id number. The authorised officer shall intimate the customer for future reference;
- The authorised officer shall check and verify that: (i) information in the document picture matches the CAF; (ii) live photograph of the customer matches the photo in the document; and (iii) all necessary CAF details including mandatory fields have been properly filled; and
- On successful verification, the CAF shall be digitally signed by the authorised officer. A print of CAF shall be taken, customer's signatures/thumb-impression obtained, and then scanned and uploaded.
Accounts Opened Using Aadhaar OTP-Based e-KYC in Non-Face-to-Face Mode
Accounts opened using Aadhaar OTP based e-KYC, in non-face-to-face mode, are subject to the following conditions:
- The Customer shall give specific consent for the authentication through OTP;
- As a risk-mitigating measure, DJT MFI shall ensure that transaction alerts, OTP, etc., are sent only to the mobile number of the customer registered with Aadhaar. DJT MFI shall have a Board-approved policy delineating a robust process of due diligence for dealing with requests for change of mobile number in such accounts;
- The aggregate balance of all deposit accounts of the customer shall not exceed ₹1,00,000 (Rupees One Lakh). If the balance exceeds the threshold, DJT MFI shall cease the account's operation until full CDD is completed;
- The aggregate of all credits in a financial year, in all deposit accounts taken together, shall not exceed ₹2,00,000 (Rupees Two Lakh);
- As regards borrowal accounts, DJT MFI shall sanction only term loans. The aggregate amount of term loans sanctioned shall not exceed ₹60,000 in a year;
- DJT MFI shall not allow accounts opened using OTP based e-KYC to operate for more than one year unless full CDD per Section 12.2 or V-CIP is carried out;
- If the full CDD procedure is not completed within a year: (a) in respect of deposit accounts, DJT MFI shall close the same immediately; and (b) in respect of borrowal accounts, DJT MFI shall allow no further debits;
- DJT MFI shall obtain declaration from the customer that no other account has been opened nor will be opened using OTP based KYC in non-face-to-face mode with any other RE. CKYCR upload shall clearly indicate such accounts;
- DJT MFI shall have strict monitoring procedures including systems to generate alerts in case of any non-compliance/violation.
12.4 Video-based Customer Identification Process (V-CIP)
DJT MFI may undertake V-CIP to carry out:
- CDD for new individual customers, proprietor in case of proprietorship firm, authorised signatories and Beneficial Owners (BOs) in case of Legal Entity (LE) customers;
- Conversion of existing accounts opened in non-face-to-face mode using Aadhaar OTP based e-KYC authentication; and
- Updation/Periodic updation of KYC for eligible customers.
DJT MFI opting to undertake V-CIP shall adhere to the following minimum standards:
V-CIP Infrastructure
- DJT MFI shall house V-CIP technology infrastructure on its own premises. The V-CIP connection shall originate from DJT MFI's own secured network domain with end-to-end encryption as per appropriate encryption standards. The infrastructure shall prevent connections from IP addresses outside India or spoofed IP addresses;
- DJT MFI shall record the customer consent in an auditable and alteration-proof manner;
- Video recordings shall contain live GPS co-ordinates (geo-tagging), date and time stamp. The quality of live video shall be adequate to allow identification beyond doubt;
- The application shall have face liveness/spoof detection and face matching technology with a high degree of accuracy. DJT MFI may use Artificial Intelligence (AI) technology to ensure robustness. Making specific facial gestures is not mandatory for liveness check; special needs of customers shall be duly considered;
- DJT MFI shall regularly update the technology infrastructure including application software and workflows based on experience of detected/attempted/near-miss cases of forged identity. Any detected case of forged identity through V-CIP shall be reported as a cyber event under extant regulatory guidelines;
- DJT MFI shall subject the V-CIP infrastructure to Vulnerability Assessment, Penetration Testing and Security Audit conducted by CERT-In empanelled auditors. Critical gaps shall be mitigated before rollout. Such tests shall also be carried out periodically; and
- The V-CIP application software and relevant APIs/webservices shall be subject to appropriate testing of functional, performance and maintenance strength before being used in live environment.
V-CIP Procedure
- V-CIP shall be operated only by specially trained DJT MFI officials. DJT MFI shall formulate a clear workflow and Standard Operating Procedure (SOP) for V-CIP and ensure adherence;
- In case of call drop/disconnection, a fresh session shall be initiated. DJT MFI may not initiate a fresh session where disruption does not lead to creation of multiple files;
- DJT MFI shall vary the sequence and/or type of questions during video interactions to establish that the interactions are real-time and not pre-recorded;
- DJT MFI shall reject the account opening process if it observes any prompting at the customer end;
- DJT MFI shall factor in whether the V-CIP customer is an existing or new customer, or if the case relates to one rejected earlier or if the name appears in some negative list;
- During V-CIP, the authorised official shall record audio and video, capture a photograph of the customer, and obtain identification information using one of: (a) OTP-based Aadhaar e-KYC authentication; (b) Offline Verification of Aadhaar; (c) KYC records from CKYCR; or (d) Equivalent e-document of OVDs including DigiLocker documents;
- DJT MFI shall ensure to redact or blackout the Aadhaar number where required;
- In case of offline Aadhaar verification using XML file or Aadhaar Secure QR Code, DJT MFI shall ensure the XML file or QR code generation date is not older than three working days from the date of V-CIP;
- If the address of the customer is different from that indicated in the OVD, DJT MFI shall capture suitable records of the current address. DJT MFI shall also confirm the economic and financial profile/information submitted by the customer;
- DJT MFI shall capture a clear image of the PAN card displayed by the customer during the process. A printed copy of e-PAN is not valid for V-CIP. PAN details shall be verified from the database of the issuing authority including through DigiLocker;
- The authorised official shall ensure that the photograph of the customer in the Aadhaar/OVD and PAN/e-PAN matches with the customer undertaking the V-CIP; and
- All accounts opened through V-CIP shall be made operational only after concurrent audit to ensure the integrity of the process.
V-CIP Records and Data Management
- DJT MFI shall store all V-CIP data and recordings in a system located in India, in a safe and secure manner with date and time stamp that affords easy historical data search; and
- DJT MFI shall preserve the activity log along with the credentials of the official performing the V-CIP.
12.5 Simplified Procedure for Opening Accounts
In case a person is not able to produce the standard CDD documents, DJT MFI may at its discretion open accounts subject to the following conditions:
- DJT MFI shall obtain a self-attested photograph from the customer;
- The designated officer of DJT MFI shall certify under signature that the person has affixed signature or thumb impression in the officer's presence;
- The account shall remain operational initially for twelve months, within which full CDD per Section 12.2 or V-CIP shall be carried out;
- Balances in all accounts taken together shall not exceed ₹50,000 at any point of time;
- Total credit in all accounts taken together shall not exceed ₹1,00,000 in a year;
- DJT MFI shall make the customer aware that no further transactions will be permitted until full KYC procedure is completed if the limits in (iv) and (v) above are breached;
- DJT MFI shall notify the customer when the balance reaches ₹40,000 or total credit in a year reaches ₹80,000 that appropriate KYC documents must be submitted; otherwise account operations will be stopped; and
- The account shall be monitored and when there is suspicion of ML/TF activities or other high-risk scenarios, the identity of the customer shall be established as per full CDD or V-CIP.
An indicative list of documents/information that may be relied upon for customer identification is given in Annexure-I.
13. Monitoring of Transactions
Ongoing monitoring is an essential element of effective KYC procedures. DJT MFI can effectively control and reduce risk only if they have an understanding of the normal and reasonable activity of the customer so that they can identify transactions that fall outside the regular pattern of activity. However, the extent of monitoring will depend on the risk sensitivity of the account.
DJT MFI shall necessarily monitor the following types of transactions:
- Large and complex transactions including RTGS transactions, and those with unusual patterns, inconsistent with the normal and expected activity of the customer, which have no apparent economic rationale or legitimate purpose;
- Transactions which exceed the thresholds prescribed for specific categories of accounts;
- High account turnover inconsistent with the size of the balance maintained;
- Deposit of third-party cheques, drafts, etc. in the existing and newly opened accounts followed by cash withdrawals for large amounts;
- All cash transactions of ₹10 lakh and above shall be reported to the Principal Officer immediately;
- Payment of maturity proceeds of Fixed Deposits of ₹20,000 and above should not be paid in cash, but paid to the credit of account or by means of crossed BPO/DD;
- Legal compliance certificate should be ensured for transactions involving ₹10 lakh and above and should be verified by the concurrent auditors; and
- Closely monitor the transactions in accounts of marketing firms, especially accounts of Multi-level Marketing (MLM) companies.
DJT MFI shall align the extent of monitoring with the risk category of the customer. High-risk accounts shall be subject to more intensified monitoring. For ongoing due diligence, DJT MFI may consider adopting appropriate innovations including artificial intelligence and machine learning (AI and ML) technologies to support effective monitoring.
DJT MFI will not accept any cross-border fund transfers (through SWIFT transfer, cheques in foreign currency or any other means of sending funds from an account held with a financial institution outside India), to its account(s) held with banks in India, from its clients towards repayment of any loan taken from DJT MFI.
DJT MFI shall implement robust software that generates alerts when transactions are inconsistent with a customer's risk categorisation and updated profile. To identify and report suspicious transactions effectively, such software shall be installed, and STRs shall be filed without delay with FIU-IND.
14. Client Due Diligence Measures
DJT MFI will undertake on-going Client Due Diligence with every client and closely examine transactions to ensure that all transactions are consistent with DJT MFI's knowledge of the client, their business and risk profile, and wherever necessary, the source of funds. Risk profile of customer will be determined by the Credit Committee/Risk Committee on an annual basis.
To update existing KYC, DJT MFI shall exercise full KYC at the following minimum frequency (from the date of opening of the account/last KYC updation):
- At least once in every two years for high-risk customers;
- At least once in every eight years for medium-risk customers; and
- At least once in every ten years for low-risk customers.
Notwithstanding the above, in respect of an individual customer who is categorised as low-risk, DJT MFI shall allow all transactions and ensure the updation of KYC within one year of its falling due for KYC or up to June 30, 2026, whichever is later. DJT MFI shall subject accounts of such customers to regular monitoring.
14.1 KYC Updation – Individuals
- No change in KYC information: DJT MFI shall obtain a self-declaration from the customer through the customer's email-id registered with DJT MFI, customer's mobile number registered with DJT MFI, digital channels (including mobile application), letter, etc.;
- Change in address only: DJT MFI shall obtain a self-declaration of the new address through the customer's registered email-id, mobile number, ATMs, digital channels, letter, etc. DJT MFI shall verify the declared address through positive confirmation within two months by means such as address verification letter, contact point verification, deliverables, etc.;
- Customers who were minor at time of account opening on becoming major: DJT MFI shall obtain fresh photographs upon their becoming a major and ensure that CDD documents as per current CDD standards are available; and
- Aadhaar OTP-based e-KYC in non-face-to-face mode may be used for KYC updation. The conditions stipulated for OTP-based accounts (balance limits, etc.) are not applicable in case of updation/periodic updation.
14.2 KYC Updation – Legal Entity (LE) Customers
- No change in KYC information: DJT MFI shall obtain a self-declaration from the LE customer through its registered email id, ATMs, digital channels, letter from an authorised official, board resolution, etc. DJT MFI shall ensure that Beneficial Ownership (BO) information is accurate and updated; and
- Change in KYC information: DJT MFI shall undertake the KYC process equivalent to that applicable for onboarding a new LE customer.
14.3 Additional Measures for KYC Updation
- DJT MFI shall ensure that customers' KYC documents are as per the current CDD standards. If the validity of CDD documents has expired at the time of periodic updation, DJT MFI shall undertake the KYC process equivalent to that applicable for onboarding a new customer;
- DJT MFI shall verify the Customer's PAN details, if available, from the database of the issuing authority at the time of periodic updation;
- DJT MFI shall provide an acknowledgment to the customer mentioning the date of receipt of documents/self-declaration, and shall promptly update the information in its records and provide an intimation to the customer mentioning the date of KYC updation;
- DJT MFI may make available the facility of KYC updation at any branch, in terms of its internal KYC policy;
- DJT MFI shall advise customers that any update to documents submitted at the time of account opening must be submitted to DJT MFI within 30 days of the update; and
- Due Notices for Periodic Updation: DJT MFI shall intimate its customers in advance to update their KYC. Prior to the due date, DJT MFI shall give at least three advance intimations (including at least one by letter) at appropriate intervals. Subsequent to the due date, DJT MFI shall give at least three reminders (including at least one by letter) to customers who have not yet complied. Issue of advance intimation/reminder shall be duly recorded in DJT MFI's system against each customer for audit trail. DJT MFI shall implement this not later than January 01, 2026.
15. Risk Management
Our internal audit has an important role in evaluating and ensuring adherence to the KYC policies and procedures, including legal and regulatory requirements. DJT MFI shall ensure that the audit machinery is staffed adequately with individuals who are well versed in such policies and procedures. Concurrent Internal Auditors shall specifically check and verify the application of KYC procedures at the branches. The compliance in this regard may be put up before the Audit Committee of the Board on quarterly intervals.
15.1 ML and TF Risk Assessment
In accordance with the RBI KYC Directions, 2025, DJT MFI shall carry out ML and TF Risk Assessment exercises periodically to identify, assess and take effective measures to mitigate its money laundering and terrorist financing risks across clients, countries or geographic areas, products, services, transactions or delivery channels.
- The assessment process shall consider all relevant risk factors before determining the level of overall risk and the appropriate level and type of mitigation to be applied. DJT MFI shall take cognizance of overall sector-specific vulnerabilities shared by RBI from time to time;
- DJT MFI shall properly document its risk assessment, proportionate to the nature, size, geographical presence and complexity of activities/structure of DJT MFI. The Board or a committee of the Board shall determine the periodicity of the risk assessment exercise – however, DJT MFI shall review it at least annually; and
- DJT MFI shall present the outcome of the exercise to the Board or any committee to which the Board has delegated power. The outcome shall also be made available to competent authorities and self-regulating bodies.
15.2 Risk Based Approach (RBA)
DJT MFI shall apply a Risk Based Approach (RBA) for mitigation and management of risks identified on its own or through national risk assessment, and shall have Board-approved policies, controls and procedures in this regard. DJT MFI shall implement a Customer Due Diligence (CDD) programme, having regard to the ML/TF risks identified and the size of business, and shall monitor the implementation of controls and enhance them if necessary.
DJT MFI's policy framework shall seek to ensure compliance with PML Act/Rules, including regulatory instructions in this regard and shall provide a bulwark against threats arising from money laundering, terrorist financing, proliferation financing and other related risks. DJT MFI may also consider adoption of best international practices taking into account the FATF standards and FATF guidance notes, for managing risks better.
15.3 Enhanced Due Diligence (EDD)
EDD for Non-Face-to-Face Customer Onboarding
Non-face-to-face onboarding facilitates DJT MFI to establish a relationship with the customer without meeting the customer physically or through V-CIP. DJT MFI shall undertake the following EDD measures for non-face-to-face customer onboarding (other than OTP-based e-KYC accounts):
- If DJT MFI has introduced V-CIP, it shall provide the same as the first option to the customer for remote onboarding;
- Alternate mobile numbers shall not be linked post-CDD with such accounts for transaction OTP, transaction updates, etc. DJT MFI shall permit transactions only from the mobile number used for account opening. DJT MFI shall have a Board-approved policy for requests for change of registered mobile number;
- Apart from obtaining current address proof, DJT MFI shall verify the current address through positive confirmation before allowing operations in the account;
- DJT MFI shall obtain PAN from the customer and the PAN shall be verified from the verification facility of the issuing authority;
- The first transaction in such accounts shall be a credit from an existing KYC-complied bank account of the customer; and
- DJT MFI shall categorise such customers as high-risk and subject accounts opened in non-face-to-face mode to enhanced monitoring until identity is verified face-to-face or through V-CIP.
Accounts of Politically Exposed Persons (PEPs)
DJT MFI may establish a relationship with PEPs (whether as customer or beneficial owner) provided that, apart from performing normal customer due diligence:
- DJT MFI has in place appropriate risk management systems to determine whether the customer or the beneficial owner is a PEP;
- DJT MFI shall take reasonable measures for establishing the source of funds/wealth;
- DJT MFI shall obtain approval to open an account for a PEP from senior management;
- DJT MFI shall subject all such accounts to enhanced monitoring on an on-going basis;
- In the event of an existing customer or the beneficial owner of an existing account subsequently becoming a PEP, DJT MFI shall obtain senior management approval to continue the business relationship; and
- These instructions shall also apply to family members or close associates of PEPs.
Note: 'Politically Exposed Persons' (PEPs) are individuals who are or have been entrusted with prominent public functions by a foreign country, including Heads of States/Governments, senior politicians, senior government or judicial or military officers, senior executives of state-owned corporations and important political party officials.
Client Accounts Opened by Professional Intermediaries
- DJT MFI shall identify clients when a professional intermediary opens a client account on behalf of a single client;
- DJT MFI shall have the option to hold 'pooled' accounts managed by professional intermediaries on behalf of entities like mutual funds, pension funds or other types of funds;
- DJT MFI shall not open accounts of professional intermediaries who are bound by any client confidentiality which prohibits disclosure of client details;
- DJT MFI shall identify all beneficial owners where intermediaries do not co-mingle funds, and where funds are co-mingled at DJT MFI level, DJT MFI shall look for the beneficial owners;
- DJT MFI shall, at its discretion, rely on CDD done by an intermediary, provided the intermediary is regulated and supervised and has adequate KYC compliance systems; and
- The ultimate responsibility for knowing the customer lies with DJT MFI.
15.4 Risk Management and Monitoring Procedures
(i) Internal Control Systems
Duties and responsibilities shall be explicitly allocated for ensuring that policies and procedures are managed effectively and that there is full commitment and compliance to an effective KYC programme. Regional offices shall periodically monitor strict adherence to the laid down policies and procedures by branch-level officials.
(ii) Terrorism Finance
No account shall be opened in the names of terrorist organizations. DJT MFI shall maintain a system to consult UNSC Sanctions Lists (1267/1989/2253 – ISIL/Al-Qaida; 1988 – Taliban), UNSCR 1718 Sanctions List (DPRK), UAPA lists and WMD Act lists on a daily basis. Where any match is found, DJT MFI shall immediately report to FIU-IND and the Ministry of Home Affairs as per the prescribed procedure under the UAPA Order dated February 2, 2021, and the WMD Act Order dated September 1, 2023. DJT MFI shall also freeze assets as directed by the competent authorities.
(iii) Internal Audit
(a) An independent evaluation of the controls for identifying high value transactions shall be carried out on a regular basis by the internal audit function.
(b) Internal auditors must specifically scrutinize and comment on the effectiveness of the measures taken in adoption of KYC norms and steps towards prevention of money laundering. Such compliance reports shall be placed before the Audit Committee of the Board (ACB) at quarterly intervals.
(iv) Identification and Reporting of Suspicious Transactions
DJT MFI shall report transactions of suspicious nature to the appropriate law enforcement authorities designated under the relevant laws. There shall be quarterly reporting of such aspects and action taken thereon to the ACB or the Board of Directors. A delay of each day in not reporting a transaction or delay of each day in rectifying a mis-represented transaction beyond the time limit specified shall constitute as a separate violation. DJT MFI shall not put any restriction on operations in the accounts merely on the basis of the STR filed.
(v) Adherence to Foreign Contribution Regulation Act (FCRA), 2010
DJT MFI shall adhere to the provisions of the Foreign Contribution (Regulation) Act, 2010, and Rules made thereunder. DJT MFI shall also ensure meticulous compliance with any instructions/communications issued by RBI from time to time based on advice received from the Ministry of Home Affairs, Government of India.
(vi) Record Keeping
As per the RBI KYC Directions, 2025, DJT MFI shall:
- Maintain all necessary records of transactions between DJT MFI and the customer, both domestic and international, for at least five years from the date of transaction;
- Preserve the records pertaining to the identification of the customers and their addresses, obtained while opening the account and during the course of business relationship, for at least five years after the business relationship has ended;
- Maintain all necessary information in respect of transactions to permit the reconstruction of an individual transaction, including the nature, amount, currency, date and parties to the transaction;
- Evolve a system for proper maintenance and preservation of account information in a manner that allows DJT MFI to retrieve data easily and quickly;
- Make available identification records and transaction data to the competent authorities upon request; and
- In case of customers who are Non-Profit Organisations (NPOs), DJT MFI shall register details of such customers on the DARPAN Portal of NITI Aayog and maintain such registration records for five years after the business relationship has ended or the account has been closed, whichever is later.
(vii) Wire Transfer Obligations
DJT MFI shall comply with the following requirements for wire transfers:
- All cross-border wire transfers shall be accompanied by accurate, complete and meaningful originator and beneficiary information (name, account number, address/national identity number/date and place of birth, beneficiary name and account number);
- Domestic wire transfers where the originator is an account holder shall be accompanied by originator and beneficiary information. Domestic wire transfers of ₹50,000 and above where the originator is not an account holder shall also be so accompanied;
- DJT MFI (as ordering NBFC) shall not execute the wire transfer if it cannot comply with the information requirements;
- DJT MFI (as intermediary NBFC) shall ensure that all originator and beneficiary information accompanying a wire transfer is retained;
- DJT MFI (as beneficiary NBFC) shall take reasonable measures to identify wire transfers lacking required originator or beneficiary information; and
- DJT MFI is prohibited from conducting transactions with designated persons and entities and shall ensure it does not process cross-border transactions of designated persons and entities.
(viii) Training of Staff and Management
It is crucial that all operating and management staff fully understand the need for strict adherence to KYC norms. DJT MFI shall have an ongoing training programme so that staff are adequately trained for their roles and responsibilities. The focus of training shall be different for frontline staff, compliance staff and staff dealing with new customers. DJT MFI shall also put in place an adequate screening mechanism, including a Know Your Employee/Staff policy, as an integral part of its personnel recruitment/hiring process.
15.5 Compliance of KYC Policy
DJT MFI shall ensure compliance with KYC Policy through:
- Specifying as to who constitutes 'Senior Management' for the purpose of KYC compliance;
- Allocation of responsibility for effective implementation of policies and procedures;
- Independent evaluation of the compliance functions of DJT MFI's policies and procedures, including legal and regulatory requirements;
- Concurrent/internal audit system to verify compliance with KYC/AML policies and procedures;
- Submission of quarterly audit notes and compliance reports to the Audit Committee; and
- Ensuring that DJT MFI does not outsource the decision-making functions of determining compliance with KYC norms.
16. Customer Education
DJT MFI recognizes the need to spread awareness on KYC, Anti Money Laundering measures and the rationale behind them amongst the customers and shall keep taking suitable steps for the purpose.
17. KYC for Existing Accounts
The KYC guidelines that will apply to all new customers will also be applicable for the existing customers. All existing customers are subject to periodic review requirements on the basis of materiality and risk. Along with periodic reviews, transactions in existing accounts would also be continuously monitored for any unusual pattern in the operation of the accounts.
On the basis of materiality and risk, the existing accounts of companies, firms, trusts, charities, religious organizations and other institutions are subjected to minimum KYC standards which would establish the identity of the natural/legal person and those of the 'beneficial owners'. Any material change in customer profile including but not limited to changes in PEP status of directors/'beneficial owners', negative reporting in media, regulatory action, list of beneficial owners, source of wealth, and business activity should be captured in KYC reviews.
PEP clients are subject to compulsory special periodic reviews capturing the following information in addition to normal KYC requirements:
- Change in customer background/profile in terms of PEP;
- Change in source of wealth and source of funds; and
- Any other material change or unusual pattern in operations of these accounts.
In case of existing customers, DJT MFI shall obtain the PAN or equivalent e-document thereof or Form No. 60, failing which DJT MFI shall temporarily cease operations in the account until the customer submits the same. Before temporarily ceasing operations, DJT MFI shall give the customer an accessible notice and a reasonable opportunity to be heard.
DJT MFI will also ensure that fixed deposit accounts are subject to revised KYC procedures at the time of renewal of the deposits on the basis of materiality and risk. KYC verification once done by one branch/office of DJT MFI shall be valid for transfer of the account to any other branch/office of DJT MFI, provided full KYC verification has been completed and the same is not due for periodic updation.
18. Suspicious Transaction Report
The Prevention of Money Laundering Act, 2002 and the Rules thereunder require DJT MFI to furnish details of suspicious transactions whether or not made in cash. Suspicious transaction means a transaction whether or not made in cash which, to a person acting in good faith:
- Gives rise to a reasonable ground of suspicion that it may involve the proceeds of crime; or
- Appears to be made in circumstances of unusual or unjustified complexity; or
- Appears to have no economic rationale or bonafide purpose; or
- Gives rise to a reasonable ground of suspicion that it may involve financing of the activities relating to terrorism.
It is the duty of every member of management and staff to report any suspicious transactions or suspicions immediately to the Principal Officer on the Suspicious Transaction Report Form set out in Annexure-II.
The Principal Officer will report information relating to cash and suspicious transactions, if detected, to the Director, Financial Intelligence Unit-India (FIU-IND) as advised in terms of the PMLA rules:
Director, FIU-IND, Financial Intelligence Unit-India,
6th Floor, Hotel Samrat, Kautilya Marg, Chanakyapuri, New Delhi – 110021
Email: helpdesk@fiuindia.gov.in │ ctrcell@fiuindia.gov.in
18.1 Broad Categories of Suspicious Transactions
Identity of Client
- False identification documents;
- Identification documents which could not be verified within reasonable time; and
- Accounts opened with names very close to other established business entities.
Background of Client
- Suspicious background or links with known criminals.
Multiple Accounts
- Large number of accounts having a common account holder, introducer or authorized signatory with no rationale; and
- Unexplained transfers between multiple accounts with no rationale.
Activity in Accounts
- Unusual activity compared with past transactions; and
- Activity inconsistent with what would be expected from declared business.
Nature of Transactions
- Unusual or unjustified complexity;
- No economic rationale or bonafide purpose;
- Frequent purchases of drafts or other negotiable instruments with cash; and
- Nature of transactions inconsistent with what would be expected from declared business.
Value of Transactions
- Value just under the reporting threshold amount in an apparent attempt to avoid reporting; and
- Value inconsistent with the client's apparent financial standing.
18.2 Secrecy Obligations and Sharing of Information
DJT MFI shall maintain secrecy regarding customer information that arises out of the contractual relationship between DJT MFI and the customer. Information collected from customers for the purpose of opening of account shall be treated as confidential and shall not be divulged for cross-selling or any other purpose without the express permission of the customer.
Exceptions to this rule are:
- Where disclosure is under compulsion of law;
- Where there is a duty to the public to disclose;
- Where the interest of DJT MFI requires disclosure; and
- Where the disclosure is made with the express or implied consent of the customer.
The fact of maintenance of records and furnishing of information to the FIU-IND Director shall be treated as confidential by all directors, officers and employees of DJT MFI. However, this confidentiality requirement shall not inhibit sharing of information under group-wide programmes or any analysis of unusual transactions.
19. Principal Officer [Money Laundering Reporting Officer]
DJT MFI has designated a senior officer as Principal Officer who is responsible for implementation of and compliance with this policy. His illustrative duties are as follows:
- Monitoring the implementation of the KYC/AML policy;
- Reporting of transactions and sharing of the information as required under the law;
- Maintaining liaison with law enforcement agencies; and
- Ensuring submission of periodical reports to the top Management/Board.
The Principal Officer is responsible for ensuring compliance, monitoring transactions, and sharing and reporting information as required under the law/regulations. The name, designation, address and contact details of the Principal Officer shall be communicated to the FIU-IND and RBI.
The name and address of the Principal Officer can be obtained from the Company Secretary of the company.
20. Designated Director
In compliance with the RBI KYC Directions, 2025, and the Prevention of Money Laundering (PML) Act, DJT MFI shall designate a 'Designated Director' – a Board-nominated person – to ensure overall compliance with the obligations imposed under Chapter IV of the PML Act and Rules.
- The Designated Director is a Board-nominated person designated to ensure overall compliance with obligations under Chapter IV of the PML Act and Rules;
- DJT MFI shall communicate the name, designation, address and contact details of the Designated Director to the FIU-IND and RBI; and
- DJT MFI shall not nominate the Principal Officer as the 'Designated Director'.
21. IT System
To facilitate the acceptance and adherence of KYC & AML policy recommendations, it is DJT MFI's policy to put in place an IT System to capture detailed information on the customer and transaction. Necessary controls and checks are to be incorporated into the system to ensure that clients not conforming to KYC norms are rejected by the system.
The IT system shall be equipped to:
- Capture information on all beneficial owners in a transaction and serve as a checking mechanism for client screening;
- Enable periodic KYC review of customers by the relevant relationship managers and capture any changes in PEP status, negative reporting in media, regulatory action, list of beneficial owners, source of wealth, and business activity;
- Implement robust software that generates alerts when transactions are inconsistent with a customer's risk categorisation and updated profile; and
- Support implementation of CTR/STR reporting to FIU-IND including the Report Generation Utility and Report Validation Utility developed by FIU-IND.
The NBFC shall also use the CKYCR for uploading and downloading KYC records. DJT MFI shall upload KYC records pertaining to new individual accounts opened on or after April 1, 2017, and KYC records of Legal Entity accounts opened on or after April 1, 2021, to CKYCR within 10 days of commencement of the account-based relationship. Updated KYC information shall be furnished to CKYCR within seven days of receipt.
22. Review of the Policy
The policy will be reviewed at yearly intervals or as and when considered necessary by the Board, or as triggered by any change in RBI/regulatory directions.
23. Additions Required to DJT MFI KYC & AML Policy
23.1 General Areas of Improvement
- Establish 'Standard Operating Procedures' specific to the needs of project finance business;
- Improve IT System to capture the information on clients and transactions in greater detail;
- Develop comprehensive risk assessment form to serve as a preliminary basis for risk assessment of a customer/beneficial owners, as discussed in the CAP section;
- Develop a Risk Categorization Framework for all beneficial owners in a corporate entity, as discussed in the CAP section; and
- Equip IT systems to enable periodic KYC review of customers by the relevant relationship managers, and capture any changes in PEP status, negative reporting in media, regulatory action, list of beneficial owners, source of wealth, and business activity.
23.2 Beneficial Owner
DJT MFI shall identify 'Beneficial Owners', particularly for corporate entities through study of their ownership pattern, to ensure adherence to KYC & AML policy, as follows:
A. Where the client is a company: the beneficial owner is the natural person(s), whether acting alone or together or through one or more juridical persons, having controlling ownership interest (more than 10% of shares/capital/profits of the company) or who exercises control through other means (including right to appoint the majority of directors or to control management or policy decisions including by virtue of shareholding or management rights or shareholders agreements or voting agreements).
B. Where the client is a partnership firm: the beneficial owner is the natural person(s) having ownership/entitlement to more than 10% of capital or profits, or who exercises control through other means.
C. Where the client is an unincorporated association or body of individuals: the beneficial owner is the natural person(s) having ownership/entitlement to more than 15% of property, capital or profits.
D. Where the client is a trust: the identification shall include the author of the trust, the trustee, the beneficiaries with 10% or more interest, and any other natural person exercising ultimate effective control.
E. Where the client or owner of controlling interest is a company listed on a stock exchange in India, or an entity in a jurisdiction notified by the Central Government listed on a recognised stock exchange, or a subsidiary of such listed entities: it is not necessary to identify and verify the identity of any shareholder or beneficial owner.
Where no natural person is identified as beneficial owner under (A), (B), or (C) above, the beneficial owner shall be the relevant natural person who holds the position of senior managing official.
DJT MFI shall ensure that all clients declare the names and customer identification details of the beneficial owners. The declaration can be accepted on the client's letterhead.
23.3 Politically Exposed Person
- Request PEP status of beneficial owners in existing KYC form;
- Capture of PEP-related information in the IT system; and
- Compulsory high-risk categorization for clients with PEPs as directors/beneficial owners, and compulsory re-KYC for such clients, as mentioned in the 'KYC for Existing Accounts' section.
23.4 Screening System
- DJT MFI's screening system shall check against the UNSC Sanctions Lists (ISIL/Al-Qaida, Taliban, DPRK), UAPA lists and WMD Act designated lists, on a daily basis, for meticulous compliance;
- The NBFC is encouraged to leverage the latest technological innovations and tools for effective implementation of name screening to meet the sanctions requirements; and
- DJT MFI shall take into account FATF Statements circulated by the RBI from time to time for identifying countries that do not or insufficiently apply FATF Recommendations, and shall apply enhanced due diligence measures accordingly.
23.5 IT System Upgrades
- Upgrade the current IT System to meet the requirements of the policy, and serve as a check for implementing CAP and CIP; and
- Mandate a maker-checker system through appropriate changes in IT System for all transaction posting, as discussed in the 'Monitoring of Transactions' section.
Annexure-I: Customer Identification Procedure
The following table provides the document requirements for customer identification in line with the RBI (Non-Banking Financial Companies – Know Your Customer) Directions, 2025.
| Features | Documents |
| Accounts of Individuals Legal Name and any other names used | Minimum Documents Required: Any ONE of the following documents constitutes a valid Officially Valid Document (OVD) for identity and address proof: 1. Passport 2. PAN Card 3. Voter's Identity Card issued by the Election Commission of India 4. Valid Driving Licence (Learning licence not acceptable) 5. Aadhaar Card or letter issued by UIDAI containing name, address and Aadhaar number (Acknowledgement receipts not acceptable) 6. Job card issued under NREGA duly signed by a State Government officer (with photograph) 7. Letter issued by the National Population Register containing details of name and address 8. Identity Card subject to DJT MFI's satisfaction 9. Letter from a recognised public authority verifying identity and residence 10. Bank account or Post Office Savings Bank account statement as ID proof if photograph is attested PLUS PAN Card or equivalent e-document thereof, or Form No. 60 (as defined in Income-tax Rules, 1962) – mandatory in addition to the OVD. Note: Aadhaar number is not mandatory. However, if the customer is desirous of receiving any benefit/subsidy under any scheme notified under Section 7 of the Aadhaar Act, 2016, the Aadhaar number must be provided. In all other cases, Aadhaar may be provided voluntarily. Where an Aadhaar card is submitted, the customer must redact/blackout the Aadhaar number on the copy where authentication is not required. |
| Current Address not same as Permanent Address (Deemed OVD – Proof of Current Address) | Minimum Documents Required: Where the customer furnishes an OVD that does not contain an updated/current address, the customer shall provide: STEP 1: Submit any ONE of the following documents as deemed OVD for current address proof: 1. Utility Bill (not more than 2 months old) – Electricity, Telephone, Post-paid Mobile, Piped Gas, or Water Bill 2. Property or Municipal Tax Receipt 3. Pension or Family Pension Payment Orders (PPOs) issued to retired employees by Government Departments or Public Sector Undertakings, if they contain the address 4. Letter of Allotment of Accommodation from employer issued by State/Central Government Departments, statutory or regulatory bodies, PSUs, scheduled commercial banks, financial institutions and listed companies; or leave and licence agreements with such employers allotting official accommodation 5. Passport (if it contains the current address) 6. Current and old bank account statement reflecting current address 7. Ration Card (if it contains the current address) STEP 2: Mandatory Follow-up: The customer must submit an OVD with the current address within THREE MONTHS of submitting the deemed OVD. The NBFC shall verify the declared address through positive confirmation within two months by means such as address verification letter, contact point verification, deliverables, etc. For Foreign Nationals: If the OVD of a foreign national does not contain address details, DJT MFI shall accept documents issued by Government departments of foreign jurisdictions or a letter from the Foreign Embassy/Mission in India as proof of address. Important Note: Any one document from STEP 1 providing customer's current address to the satisfaction of DJT MFI will suffice as interim proof, subject to submission of OVD with current address within three months. |
| Accounts of Companies: • Name of the company • Principal place of business • Mailing address • Telephone / Fax Number | 1. Certificate of Incorporation 2. Memorandum and Articles of Association 3. PAN of the Company 4. Resolution of Board of Directors to open an account and identification of authorised signatories 5. Power of attorney granted to managers, officers or employees to transact business 6. Documents (as applicable to individuals) relating to beneficial owners, managers, officers or employees holding attorney to transact on the company's behalf 7. Names of the relevant persons holding senior management positions 8. Registered office address and principal place of business (if different) |
| Accounts of Partnership Firms: • Legal Name • Address • Name of all partners and their addresses • Telephone numbers of firm and partners | 1. Registration Certificate (if registered) 2. Partnership Deed 3. PAN of the Partnership Firm 4. Documents (as applicable to individuals) relating to beneficial owners, managers, officers or employees holding attorney to transact on its behalf 5. Names of all partners and their addresses 6. Address of the registered office and principal place of business (if different) 7. If change in partnership shareholding is found during PD, latest partnership deed to be collected |
| Accounts of Trusts & Foundations: • Names of trustees, settlors, beneficiaries and signatories • Names and addresses of founder, manager/directors and beneficiaries • Telephone / fax numbers | 1. Registration Certificate (if registered) 2. Trust Deed 3. PAN or Form No. 60 of the Trust 4. Documents (as applicable to individuals) relating to beneficial owners, managers, officers or employees holding attorney to transact on its behalf 5. Names of beneficiaries, trustees, settlor, protector (if any) and authors of the trust 6. Address of the registered office of the trust 7. List of trustees and documents for those discharging the role as trustee and authorised to transact on behalf of the trust |
| Accounts of Un-incorporated Association or Body of Individuals | 1. Resolution of the managing body of such association or body of individuals 2. PAN or Form No. 60 of the unincorporated association or body of individuals 3. Power of attorney granted to transact on its behalf 4. An officially valid document in respect of the person holding the attorney 5. Such information as may be required by DJT MFI to collectively establish the legal existence of such association or body of individuals |
| Accounts of Proprietary Concerns (Updated in line with RBI KYC Directions, 2025) | DJT MFI shall obtain any TWO of the following documents or equivalent e-documents as proof of business/activity in the name of the proprietary firm: i. Registration certificate including Udyam Registration Certificate (URC) issued by the Government ii. Certificate/licence issued by municipal authorities under Shop and Establishment Act iii. Sales and income tax returns iv. CST / VAT / GST certificate v. Certificate/registration document issued by Sales Tax / Service Tax / Professional Tax authorities vi. IEC (Importer Exporter Code) issued by DGFT, or Licence/certificate of practice issued by any professional body incorporated under statute vii. Complete Income Tax Return (not just acknowledgement) in the name of sole proprietor where the firm's income is reflected, duly authenticated/acknowledged by Income Tax Authorities viii. Utility bills such as electricity, water, landline telephone bills, etc. Note: Where DJT MFI is satisfied that it is not possible to furnish two documents, it may, at its discretion, accept only ONE document as proof of business/activity. In such cases, DJT MFI shall undertake Contact Point Verification (CPV) and confirm business activity from the address of the proprietary concern. |
Operational Procedure for e-KYC Exercise
The e-KYC service of the UIDAI is to be leveraged by NBFCs through a secured network. Any NBFC willing to use the UIDAI e-KYC service is required to sign an agreement with the UIDAI. The process flow to be followed is as follows:
- Sign KYC User Agency (KUA) agreement with UIDAI to enable the NBFC to specifically access the e-KYC service;
- NBFCs to deploy hardware and software for deployment of e-KYC service across various delivery channels. These should be STQC Institute, Department of Electronics & Information Technology, Government of India certified biometric scanners at NBFC branches as per UIDAI standards;
- Develop a software application to enable use of e-KYC across various DJT MFI branches, as per UIDAI defined Application Programming Interface (API) protocols;
- Define a procedure for obtaining customer authorization to UIDAI for sharing e-KYC data with DJT MFI. This authorization can be in physical (by way of a written explicit consent) / electronic form as defined by UIDAI from time to time; and
- Sample process flow: Customer visits branch with 12-digit Aadhaar number and explicit consent; DJT MFI representative enters number into e-KYC application; customer inputs biometrics via UIDAI compliant reader; software encrypts and sends data to UIDAI CIDR; upon successful authentication, UIDAI responds with digitally signed demographic information and photograph which DJT MFI's system auto-populates; customer can then open account subject to satisfying other account opening requirements.
Annexure-II: Suspicious Transaction Internal Report Form
Reporter Details
| Date | _____________________________________________ |
| Name | _____________________________________________ |
| Telephone | _____________________________________________ |
| Branch / Department | _____________________________________________ |
| Position | _____________________________________________ |
Customer Details
| Customer Name | _____________________________________________ |
| Account No. | _____________________________________________ |
| Address | _____________________________________________ |
| Contact Name | _____________________________________________ |
| Contact Telephone | _____________________________________________ |
| Date Relationship Started | _____________________________________________ |
| Customer Reference | _____________________________________________ |
| Type of Business | _____________________________________________ |
Information / Suspicion
| Date of Suspected Offence | _____________________________________________ |
| Amount Concerned | _____________________________________________ |
| Type of Suspected Offence | _____________________________________________ |
| Reason for Suspicion | _____________________________________________ |
Additional Comments by Branch Manager
| Comments | _____________________________________________ |
| Name and Signature of Branch Manager: _________________________________ | Date: _________________________________ |
Note: It is an offence to advise the customer/client or anyone else of your suspicion or report.
For Principal Officer (PO) Use
| Date Received: __________________ | Time Received: __________________ | Ref: __________________ |
| PO's Comments | _____________________________________________ |
— End of Document —
DJT Microfinance Private Limited | AML & KYC Policy Manual | Version 2.0 | Confidential