Re-KYC Process: A Complete Guide for Banks and NBFCs

Posted by

KYC does not end when a customer is onboarded.

For banks and NBFCs, customer information needs to remain current throughout the relationship. As customers move through their applicable KYC review cycles, regulated entities need a structured process to identify accounts due for Re-KYC, communicate with customers, collect the required information and maintain evidence of the actions taken.

This makes the Re-KYC process fundamentally different from initial customer onboarding.

Initial KYC is focused on establishing a customer’s identity and completing onboarding requirements. Re-KYC is a recurring operational process designed to keep the customer’s KYC information current while providing the regulated entity with appropriate controls, records and visibility.

A well-designed Re-KYC process therefore needs to cover both the customer journey and the compliance operation behind it.

What is Re-KYC?

Re-KYC, or periodic KYC updation, refers to the process through which a regulated entity reviews and updates a customer’s KYC information at the applicable intervals.

The process does not necessarily mean that every customer must go through the exact same verification journey again. The appropriate journey can depend on what has changed in the customer’s KYC information and the processes configured by the institution.

This distinction is important.

For one customer, Re-KYC may involve confirming that existing information remains unchanged. For another, an address update may require an additional confirmation process. A customer with broader changes may need to undergo a more comprehensive KYC verification journey.

The Re-KYC process therefore needs to support multiple paths rather than a single standard workflow.

Step 1: Identify customers due for Re-KYC

The process begins with identifying the customers whose KYC is due or approaching its due date.

The institution’s systems can identify relevant customer records and provide information such as the customer’s risk category, KYC due date, existing contact information and previous KYC details.

These cases then need to enter the Re-KYC workflow. This can happen individually through APIs or in bulk through batch ingestion.

At this stage, having a central case record is useful because it provides the foundation for tracking everything that happens later.

Step 2: Initiate customer communication

Once a customer is identified, the institution needs to initiate the configured communication journey.

Depending on the operating model, this can include SMS, WhatsApp, email or physical letters. The communication should clearly inform the customer that KYC updation is required and provide the appropriate next step.

The operational challenge is not simply sending the first message. The institution needs to know whether the communication was delivered and what should happen if the customer does not respond.

A Re-KYC workflow can therefore maintain communication events and delivery status against the customer’s case.

Step 3: Manage reminders and escalation

Not every customer will respond to the first communication.

The Re-KYC process therefore needs a defined cadence for reminders and escalation. Based on the configured workflow, a customer who has not acted can automatically move to the next communication stage.

The workflow may include additional digital reminders and, where configured, physical communication. Waiting periods can also be managed based on the customer’s remaining time before the applicable KYC due date.

This is where a lifecycle-based approach becomes important. Instead of treating each reminder as an isolated activity, the institution can manage the entire communication history as part of the same customer case.

Step 4: Customer completes the Re-KYC journey

When the customer responds, the next step is to authenticate the customer and present the KYC information already available with the institution.

The customer can then indicate whether their information has changed.

A simple decision structure can be:

No Change → Address Changed → Other KYC Information Changed

This allows the institution to avoid applying an unnecessarily complex journey to every customer.

For a no-change declaration, the customer can confirm that the existing information remains accurate and provide the required declaration or consent.

If the address has changed, the customer can submit the new address and proceed through the institution’s configured address confirmation process.

If other KYC information has changed, the case can move to an additional verification journey.

Step 5: Route the customer to the appropriate verification method

This is one of the most important stages of the Re-KYC process.

Different customers may require different verification mechanisms. Depending on the institution’s SOP and technology ecosystem, the case could be routed to V-CIP, a branch journey, CKYC, Aadhaar-based verification, CPV or another existing KYC process.

The objective is not necessarily to introduce another verification system. Instead, the Re-KYC layer should be able to connect with the institution’s existing infrastructure and determine where the customer needs to go next.

For example, an existing V-CIP provider can continue performing the verification while the orchestration layer manages the case before and after the verification. A successful callback can then update the Re-KYC case accordingly.

Step 6: Update internal systems

Completing the customer journey is not necessarily the final operational step.

Once Re-KYC has been successfully completed, the updated information and status may need to flow back into the institution’s core banking system, CRM, customer master or compliance/KYC systems.

This system synchronisation closes the loop between the customer-facing journey and the institution’s internal records.

Without this step, an institution could have a completed digital journey while its internal systems still show outdated information.

Step 7: Maintain a complete audit trail

For banks and NBFCs, the Re-KYC process also needs strong evidence management.

The institution should be able to reconstruct what happened to a case: when it was created, which communication was sent, whether it was delivered, whether a physical letter was dispatched, when the customer authenticated, what declaration was provided, which verification journey was used and when the updated information was synchronised.

A customer-level timeline provides this visibility by bringing these events together in chronological order.

This turns the audit trail from a collection of disconnected records into a usable compliance history.

What happens when Re-KYC becomes overdue?

A robust Re-KYC process should also account for customers who do not complete the process within the expected timeline.

When a case crosses its due date, it can move from Due to Overdue and enter a configured post-due workflow. Additional reminders, physical communication and escalation actions can then be managed through the same case rather than through a separate manual process.

This gives compliance teams visibility into overdue cases and the actions already taken against them.

What should banks and NBFCs look for in a Re-KYC platform?

A Re-KYC platform should not be evaluated only on its customer-facing KYC journey. The broader question is whether it can manage the operational lifecycle around that journey.

For banks and NBFCs, important capabilities include case ingestion, due-date management, configurable communication workflows, physical-letter orchestration, customer journeys, dynamic KYC routing, integration with existing providers, system synchronisation, audit trails and compliance dashboards.

Just as importantly, the platform should be configurable and provider-agnostic. Banks should be able to continue using their existing SMS, WhatsApp, email, letter-delivery and KYC providers rather than being forced into a closed ecosystem.

Re-KYC is a lifecycle, not a one-time task

The most effective way to look at Re-KYC is as a continuous compliance lifecycle.

It starts with identifying customers who are due, moves through communication and customer engagement, branches into the appropriate verification journey, updates internal systems and ends with complete evidence of what happened.

For banks and NBFCs managing Re-KYC at scale, the ability to orchestrate this lifecycle can be as important as the verification technology itself.

A well-structured Re-KYC process brings customer experience, operational execution and compliance governance into one connected workflow—giving teams visibility into every case from identification to completion.

Leave a Reply

Your email address will not be published. Required fields are marked *