us

216.73.217.135

Back
News

RBI Allows Multinational Banks to Retain Limited Data Abroad for AML Screening

R Richard M. OCTOBER 14, 2021 1 minute read

KYC data can be retained in offshore bank branches for the purpose of sanctions and AML screening. 

The Reserve Bank of India has authorized foreign banks to retain certain fields of information which include name and address of customers, Know Your Customer (KYC) details, name of beneficiary, transaction details like date and amount, and reference numbers, putting an end to a long-standing debate. 

According to an industry source, the regulator informed the Indian Banks’ Association (IBA) about this a week ago.

Prior to this, banks had been advised by the regulator that in the event payment data was sent to overseas servers, it had to be deleted within 24 hours, with copies of them being stored onshore. A few months back, major foreign banks appealed to the RBI, asking for permission to store certain transaction data overseas for the detection of money-laundering activities and sanctions screening. “They had asked for a whole lot of data, but RBI has finally allowed only 6 to 7 fields,” remarked a banker.

Numerous multinational firms raised concerns to the regulator prior to this step, stating that having a worldwide set of data for tracing money laundering activities was critical.

Typically, foreign banks in India generate suspicious activity reports through Anti-Money Laundering (AML) software that are housed in offshore locations. AML verification is necessary under global AML laws, non-compliance to which can lead to grey listing by the FATF. Additionally, sanctions screening refers to the verification of customer names against sanction lists to ensure the prevention of fraudulent activity.

On the other hand, the RBI has denied foreign banks the ability to retain information such as phone numbers and ‘purpose of remittance’ on servers in other countries. 

Suggested Read: RBI Gives Stark Warning Against Emerging KYC Fraud

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.