IFSCA aml_compliance F. No. IFSCA-DAC/7/2024-AMLCFT · 31 Oct 2025
Official title
Modifications under the International Financial Services Centres Authority (Anti Money Laundering, Counter-Terrorist Financing and Know Your Customer) Guidelines, 2022
Summary
Check the official recordThe International Financial Services Centres Authority has updated its 2022 Guidelines regarding the Video-based Customer Identification Process (V-CIP). The modifications expand the scope of personnel authorized to conduct V-CIP to include officials from financial group entities in India supervised by a financial regulator or a KYC Registration Agency. The circular establishes comprehensive standards for V-CIP infrastructure, including cybersecurity, data storage, and encryption requirements. It also introduces specific procedures for onboarding low-risk Non-Resident Indian (NRI) customers, including IP address restrictions and mandatory verification of bank accounts in specified jurisdictions. Regulated Entities must ensure compliance with these updated standards, including conducting concurrent audits for all accounts opened via V-CIP, effective immediately.
What you must do
Key dates
Who is affected
Thresholds
If you do not comply
[IMAGE]
CIRCULAR
F. No. IFSCA-DAC/7/2024-AMLCFT
31st October, 2025
To All Regulated Entities in the International Financial Services Centres
Subject: Modifications under the International Financial Services Centres Authority (Anti Money Laundering, Counter-Terrorist Financing and Know Your Customer) Guidelines, 2022.
Sir/Madam,
A. Reference is drawn to the International Financial Services Centres Authority (Anti Money Laundering, Counter-Terrorist Financing and Know Your Customer) Guidelines, 2022 (hereinafter referred as ‘Guidelines’) issued vide notification IFSCA/2022-23/GN/GL001 dated October 28, 2022.
B. Pursuant to publication of consultation paper on this subject matter and comments/ suggestions received from the market participants and, on the examination, thereof, the International Financial Services Centres Authority hereby carries out the following modifications:
(i) In clause 1.3.43. under the definition of Video based Customer Identification Process or V-CIP, after the words ‘by an authorised official of the Regulated Entity,’ and before the words ‘by undertaking seamless, secure, live’ the following words shall be added “or financial group entity in India supervised by a financial regulator or a KYC Registration Agency”
(ii) Further the Part -A of Annexure II of the Guidelines shall be substituted as follows: -
“PART-A V-CIP PROCESS FOR ONBOARDING INDIAN NATIONALS
1.1. Regulated Entities may undertake V-CIP to carry out:
(a) CDD in case of on-boarding of new customers such as an individual, proprietor (in case of a proprietorship firm), authorised signatories and Beneficial Owners (BOs) in case of customers which are non-natural persons and other connected parties appointed to act on behalf of the customer.
(b) Updation/Periodic updation of KYC for eligible customers.
1.2. Regulated Entities opting to undertake V-CIP shall adhere to the following minimum standards:
1.2.1.V-CIP Infrastructure
(i) A Regulated Entity shall comply with the minimum baseline cyber security and resilience framework namely, “Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs” dated March 10, 2025 (as amended from time to time), issued by the Authority and all other applicable laws on mitigating or managing Information Technology risks.
(ii) The technology infrastructure for V-CIP shall be housed within the premises of the Regulated Entity or its Financial Group supervised by a financial regulator or a KYC Registration Agency (KRA); and the connections and interactions for undertaking V-CIP shall originate from its own secured network domain.
(iii) Any technology related outsourcing for the process shall be compliant with the standards, as may be specified by the Authority.
(iv) Where cloud deployment model is used, the Regulated Entity shall ensure that the ownership of data in such model rests only with the Regulated Entity or its Financial Group.
(v) Further, the Regulated Entity shall also ensure that all such data including video recordings are transferred to the server(s)/cloud server owned or taken on lease by the Regulated Entity or its Financial Group, immediately after the V-CIP process is completed and no data shall be retained by the cloud service provider or third-party technology provider assisting the V-CIP of the Regulated Entity.
Explanations:
Explanation I : In case the technology infrastructure is housed outside India with the Financial Group, the Regulated Entity shall immediately inform the Authority;
Explanation II : In case the data, including video recordings, are transferred to the server(s) or cloud server owned or taken on lease by the Regulated Entity’s Financial Group, the Regulated Entity shall have access to such data.
(vi) A Regulated Entity shall ensure end-to-end encryption of data between customer device and the hosting point of the V-CIP application/digital platform, as per appropriate encryption standards. The customer consent should be recorded in an auditable and alteration proof manner.
(vii) The V-CIP infrastructure/application should be capable of preventing the connections from spoofed IP addresses, using VPNs or proxy servers. Explanation. – For removal of doubt, it is hereby clarified that for resident Indian customers, the IP address shall emanate from India and for Non-Resident Indian it shall emanate either from India or from any one of the following countries where he or she is resident:
a) United States of America; b) Japan; c) South Korea; d) United Kingdom excluding British Overseas Territories; e) France; f) Germany; g) Canada; h) UAE; i) Singapore; j) Australia. k) European Union excluding Croatia
(viii) The video recordings should contain the live GPS co-ordinates (geo-tagging) of the customer undertaking the V-CIP and date-time stamp through use of tamper-proof technology. The quality of the live video in the V-CIP shall be adequate to allow identification of the customer beyond doubt.
(ix) The application shall have components with face liveness / spoof detection as well as face matching technology with high degree of accuracy, even though the ultimate responsibility of any customer identification rests with the Regulated Entity. Appropriate artificial intelligence (AI) technology with randomness and anti-deep fake and anti-fraud checks must be used to ensure that the V-CIP is robust.
(x) Based on experience of detected / attempted / ‘near-miss’ cases of forged identity, the technology infrastructure including application software as well as workflows shall be regularly upgraded. Any detected case of forged identity through V-CIP shall be reported as a cyber event under extant regulatory guidelines.
(xi) The V-CIP infrastructure shall undergo necessary tests such as Vulnerability Assessment, Penetration Testing and a Security Audit to ensure its robustness and end-to-end encryption capabilities. Any critical gap reported under this process shall be mitigated before rolling out its implementation. Such tests should be conducted by the empaneled auditors of Indian Computer Emergency Response Team (CERT-In) or any such other suitably accredited agencies as may be specified. Such tests should also be carried out periodically in conformance to internal / regulatory guidelines.
(xii) The V-CIP application software and relevant APIs / web services shall also undergo appropriate testing of functional, performance and maintenance strength before being used in live environment. Only after closure of any critical gap found during such tests, the application should be rolled out. Such tests shall also be carried out periodically in conformity with internal/ regulatory guidelines.
1.2.2.V-CIP Procedure
(i) Each Regulated Entity shall formulate a clear policy, workflow and standard operating procedure for V-CIP and ensure adherence to it.
(ii) The V-CIP process shall be operated only by officials of the Regulated Entity, or financial group entity in India supervised by a financial regulator or a KRA Registration Agency under an agreement with specific terms and conditions ensuring customer secrecy and data protection. The Regulated Entity will be ultimately responsible for customer due diligence.
(iii) The official should be specially trained for this purpose and capable of carrying out liveliness check and detect deep-fakes, any other fraudulent manipulation or suspicious conduct of the customer and act upon it. The liveness check shall not result in exclusion of person with special needs.
(iv) Disruption of any sort including pausing of video, reconnecting calls, etc., should not result in creation of multiple video files. If pause or disruption is not leading to the creation of multiple files, then there is no need to initiate a fresh session by the Regulated Entity. However, in case of call drop / disconnection, fresh session shall be initiated.
(v) The sequence and/or type of questions, including those indicating the liveness of the interaction during video interactions shall be varied and randomised in order to establish that the interactions are real-time and not pre-recorded or by AI deep fake.