1. Applicable Entities
The new directions and the SOP are applicable to a broad spectrum of the banking sector, while providing specific exemptions to prevent disruption of corporate operations.
- Fully Applicable To:
- All Commercial Banks (including Small Finance Banks, Payments Banks, Regional Rural Banks, and Local Area Banks).
- All Urban Cooperative Banks (Primary Co-operative Banks).
- Explicitly Exempted Accounts:
- Nodal accounts and Pool accounts.
- Escrow accounts.
- Special-purpose accounts (e.g., dividend distribution, share capital accounts).
2. Detailed Analysis of Amendments & Management Action Plan
The draft directions introduce two major amendments to the existing KYC Directions, 2025. Below is a detailed breakdown of the specific changes, the required management action plan, and practical real-world scenarios.
Amendment 1: Stricter Liability for “Operation of Bank Accounts and Money Mules”
Specific Change Required: Paragraph 1 of the amendment replaces existing guidelines to mandate meticulous transaction monitoring. The most critical regulatory shift is the introduction of deemed non-compliance: “If it is established that an account opened and operated is that of a Money Mule, but STR (Suspicious Transaction Report) was not filed by the concerned bank, it shall then be deemed that the bank has not complied with these Directions.”
Management Action Plan:
- Rule Engine Overhaul: The IT and Compliance teams must update the Anti-Money Laundering (AML) transaction monitoring systems to proactively identify typologies of phishing, smurfing, and identity theft.
- Zero-Leakage STR Policy: Establish a secondary audit layer for alerts generated by the system to ensure no valid money mule alert is closed without filing an STR with FIU-IND.
- Staff Sensitization: Conduct mandatory training for branch managers and account opening staff on the latest behavioral indicators of third-party account operators (mule recruiters).
Amendment 2: Implementation of Annex III (SOP on Suspected Money Mule Accounts)
Specific Change Required: Banks must now follow a uniform, time-bound Standard Operating Procedure (SOP) to place “Temporary Debit Holds” on suspected transactions of ₹1,000 and above, or on entire accounts. The SOP dictates strict turnaround times (TATs) to balance fraud prevention with customer convenience. The maximum duration of a hold, absent law enforcement instructions, is capped at 60 days.
A. Procedural Timeline for Debit Holds
| Stage | Action Required by Bank | Mandatory Timeline |
|---|---|---|
| 1. Detection & Hold | Place temporary debit hold on the transaction (or full account). | Immediately upon detection. |
| 2. Notification | Notify customer with reasons, removal process, and officer contact details. | Immediately (digital) or by EOD next day (physical). |
| 3. Customer Rebuttal | Allow customer to provide justification for the transaction. | 20 days from the date of the hold. |
| 4. Bank Decision | Examine explanation and either (a) remove hold, or (b) report to Police via NCRP-CFCFRMS. | Within 10 days of receiving explanation (or within 30 days of hold if no explanation). |
| 5. LEA Coordination | Act on instructions from Law Enforcement Agencies (LEA) or Competent Authority. | Immediately upon receipt within 30 days of reporting. |
| 6. Auto-Release | Remove hold if no LEA instruction is received requiring continuation. | On the 31st day from reporting to LEA (Max 60 days total). |
Management Action Plan for SOP Procedural Changes:
- Core Banking System (CBS) Upgrades: IT must configure the CBS to allow transaction-level debit holds (freezing specific amounts rather than the whole account, to minimize customer friction) and automate the 60-day auto-release trigger.
- AI/ML Integration: Deploy AI/ML-based tools to flag suspected transactions (≥₹1000) that are disproportionate to the customer’s declared KYC profile.
- Portal Linkage: Integrate internal systems with the Ministry of Home Affairs (MHA) NCRP-CFCFRMS portal for seamless, API-driven reporting to Jurisdictional Police Authorities.
B. Internal Policy, Record Keeping, and Grievance Redressal
Specific Change Required: Banks are required to draft an overarching Internal Policy for this SOP. Additionally, strict record-keeping and grievance mechanisms must be instituted.
Management Action Plan:
- Board-Approved Policy: Draft a comprehensive policy detailing tech solutions, scenarios for debit hold removals, communication templates, and parameters to minimize flagging genuine accounts. (Target Completion: Q4 2026).
- Centralized MIS & Data Retention: Develop an MIS to track the lifecycle of every temporary hold. Ensure related records are retained for a minimum of 5 years from the hold date, or 10 years post account closure.
- Grievance Redressal Mechanism:
- Appoint dedicated Nodal Officers at Regional, Zonal, and Head Office levels.
- Display Nodal Officer contact details prominently on the bank website and branch notice boards.
- Ensure all complaints related to temporary holds are resolved within a strict 30-day TAT.
3. Conclusion & Strategic Next Steps
The RBI’s draft directions signal a shift towards technology-driven, highly accountable fraud prevention. The shift from account-level freezing to transaction-level debit holds, combined with strict timelines, requires an immediate overhaul of IT infrastructure and compliance workflows. Management should initiate a cross-functional task force (IT, Compliance, Operations, and Legal) to ensure full system readiness well before the April 1, 2027 deadline.