NISM Professor

Client Identification Procedure

Also written CIP · Client Identification Procedure (CIP) · Client identification

The written procedure each registered intermediary must frame and run to establish the true identity of a client — at onboarding, during transactions, and whenever earlier identification data is doubted.

In plain language

The Client Identification Procedure is the intermediary's own rulebook for establishing who a client really is.

SEBI does not merely require identification; it requires each intermediary to formulate and implement a CIP incorporating the PML Rules and any additional requirements it considers appropriate to determine the true identity of its clients. Two firms in the same business may therefore run different procedures, and both can be compliant — but a firm running no written procedure at all cannot be.

It sits inside client due diligence as the identity limb, and it is one of the four written anti-money laundering procedures every registered intermediary must maintain: a policy for acceptance of clients, a procedure for identifying clients, risk management, and monitoring of transactions.

How it works

When CIP is carried out. At three points, not one:

  1. To establish the intermediary-client relationship
  2. While carrying out transactions for the client
  3. When the intermediary has doubts about the veracity or adequacy of previously obtained client identification data

What the procedure must contain. The SEBI guidelines require that the intermediary identify the client using reliable sources including documents and information; obtain adequate information to satisfactorily establish the identity of each new client and the purpose of the intended nature of the relationship; and hold information adequate enough to satisfy regulatory or enforcement authorities in future that due diligence was observed. Two operational rules follow from that:

  • Each original document shall be seen prior to acceptance of a copy.
  • Failure by a prospective client to provide satisfactory evidence of identity shall be noted and reported to the higher authority within the intermediary — not simply filed away as an abandoned application.

Politically exposed persons. The CIP must include a risk management system to determine whether a client, a potential client, or the beneficial owner of a client is a PEP — by seeking information from the client, referring to publicly available information, or accessing commercial electronic databases of PEPs. Senior management approval is required to establish a business relationship with a PEP, and again to continue one where a client is later found to be, or becomes, a PEP. The intermediary must also take reasonable measures to verify the source of funds and the source of wealth.

A worked example

Anvay Securities Ltd receives an account opening application from Mr R. Deshmukh, described as a management consultant, on 9 January.

Stage 1 — establishing the relationship. PAN is verified online at the Income Tax website. Proof of identity and proof of address are collected, and each original is seen before the copy is taken. IPV is done by an authorised person on 11 January and the name, designation, organisation, signature and date of the person doing it are recorded on the KYC form.

The PEP check. A commercial PEP database returns a match: the applicant is the son of a serving state minister. That is not a bar — but it makes the client a politically exposed person, and therefore a client of special category. Three consequences follow. Senior management approval is required before the relationship can be established. The source of funds and the source of wealth must be verified by reasonable measures. And the client goes into the high-risk category, attracting enhanced due diligence and more frequent KYC updates.

Stage 2 — during transactions. In March the client instructs a purchase of Rs 2.1 crore of listed equity. The declared net worth on file is Rs 40 lakh. CIP is triggered again, because the intermediary now has doubts about the adequacy of previously obtained identification data.

Stage 3 — the applicant who walks away. A second applicant the same week is asked for the original of his address proof, declines, and stops responding. The application cannot simply be closed: the failure to provide satisfactory evidence of identity shall be noted and reported to the higher authority within the intermediary, and an attempted transaction abandoned on being asked for documents is reportable in an STR even though it was never completed, and irrespective of amount.

Why NISM asks about it

Chapter 6 (SEBI Guidelines for AML, CFT and PF), section 6.2.3, is the CIP section, and the four written procedures come from section 6.2 immediately before it. Expect a question on the three occasions when CIP is carried out, the rule that each original must be seen before a copy is accepted, and — a reliable favourite — the requirement of senior management approval both to establish and to continue a relationship with a PEP.

Common exam traps

  • CIP happens three times, not once. Onboarding is only the first; transactions and doubts about earlier data trigger it again.
  • A PEP is not prohibited. The client can be accepted — with senior management approval, verification of source of funds and wealth, and enhanced due diligence. Answers that say "refuse the account" are wrong.
  • The PEP test extends to the beneficial owner, not just the person signing the form.
  • An abandoned application is still reportable. Registered intermediaries must report attempted transactions in STRs even if not completed by the client, irrespective of the amount.
  • Copies are not enough. Each original document must be seen before its copy is accepted — which is also why "original seen and verified" has a specified digital equivalent in the online KYC route.
  • Do not confuse CIP with KYC: KYC is the platform-wide documentation standard, CIP is the intermediary's own written procedure built on top of it.

Check yourself

  1. 1.To satisfy itself that its measures are adequate for effective implementation of the PMLA, every intermediary should carefully evaluate which factors?

    1. a)All of the above
    2. b)Nature of business
    3. c)Types of clients
    4. d)Nature of transactions
    Show the answer

    Answer: (a) All of the above

    Each intermediary shall consider carefully the specific nature of its business, organizational structure, type of client and transaction, etc. to satisfy itself that the measures taken by it are adequate and appropriate and follow the spirit of the suggested measures and the requirements as laid down in the PMLA and guidelines issued by the Government of India from time to time.

    Four factors are named — nature of business, organizational structure, type of client, and type of transaction — with etc. signalling that the list is not closed.

    And the standard is self-satisfaction, measured by spirit as well as letter: the overriding principle is that they shall be able to satisfy themselves that the measures taken by them are adequate, appropriate and abide by the spirit of such measures and the requirements as enshrined in the PMLA.

    Who is bound. The PMLA and PML Rules mandate every reporting entity which includes intermediaries registered under section 12 of the Securities and Exchange Board of India Act, 1992 (SEBI Act) and stock exchanges i.e. a stockbroker, share transfer agent, banker to an issue, trustee to a trust deed, registrar to an issue, asset management company, depository participant, merchant banker, portfolio manager, investment adviser and any other intermediary associated with the SEBI and stock exchanges, to adhere to client account opening procedures, maintain records and report such transactions.

    And SEBI's power comes from the Rules: they empower SEBI to specify the information required to be maintained by the intermediaries and the procedure, manner and the form in which such information is to be maintained.

    One consequence of the self-satisfaction standard. The guidelines cannot be applied mechanically — a large broker and a small portfolio manager will reach different but equally compliant answers, because each must judge its own nature of business, organizational structure, type of client and transaction.

    The current source is the Master Circular SEBI/HO/MIRSD/MIRSDSECFATF/P/CIR/2024/78 June 06' 2024.

  2. 2.Transactions or account-based relationships can be undertaken without following the CDD procedure. True or false?

    1. a)False
    2. b)True
    3. c)True, for clients below a minimum investment threshold
    4. d)True, for existing clients
    Show the answer

    Answer: (a) False

    No transaction or account-based relationship shall be undertaken without following the CDD procedure.

    An absolute rule, and the guidelines close every apparent gap around it.

    Option C is expressly rejected: irrespective of the amount of investment made by clients, no minimum threshold or exemption is available to registered intermediaries (brokers, depository participants, AMCs etc.) from obtaining the minimum information/documents from clients as stipulated in the PML Rules/ SEBI Circulars.

    And further: no exemption from carrying out CDD exists in respect of any category of clients. In other words, there shall be no minimum investment threshold/ category-wise exemption available for carrying out CDD measures by registered intermediaries. This shall be strictly implemented by all registered intermediaries and non-compliance shall attract appropriate sanctions.

    Option D fails too. CDD applies also to existing clients on the basis of materiality and risk, must be revisited when there are suspicions of ML/TF, and documents must be periodically update[d]... particularly for high-risk clients.

    What CDD is: screening and verification carried out on an existing/prospective client using reliable and independent sources of identification... to ensure that they are properly risk-assessed before being onboarded. CDD is at the heart of Anti-Money Laundering (AML) and Know Your Customer (KYC) initiatives.

    And if CDD cannot be done, the account is not opened: it must be ensured that an account is not opened where the intermediary is unable to apply appropriate CDD measures.

    There is one situation where CDD stops — but it does not permit a relationship without it. Where registered intermediary is suspicious that transactions relate to money laundering or terrorist financing, and reasonably believes that performing the CDD process will tip-off the client, the registered intermediary shall not pursue the CDD process, and shall instead file a STR with FIU-IND.

    Stop and report — not proceed regardless.

  3. 3.By when must a registered intermediary submit a Suspicious Transaction Report to FIU-IND?

    1. a)Within 7 days of arriving at a conclusion that the transaction or series of transactions is of a suspicious nature
    2. b)By the 15th of the succeeding month
    3. c)Within 30 days of the transaction
    4. d)Only when FIU-IND requests it
    Show the answer

    Answer: (a) Within 7 days of arriving at a conclusion that the transaction or series of transactions is of a suspicious nature

    The Suspicious Transaction Report (STR) shall be submitted within 7 days of arriving at a conclusion that any transaction, whether cash or non-cash, or a series of transactions integrally connected are of suspicious nature.

    The clock runs from the conclusion, not from the transaction — which is why the guidelines add that it shall be ensured that there is no undue delay in arriving at such a conclusion. Postponing the conclusion does not lawfully postpone the report.

    The Principal Officer shall on being satisfied that the transaction is suspicious, furnish the information promptly in writing by fax or by electronic mail to the Director — and shall record his reasons for treating any transaction or a series of transactions as suspicious.

    Option B gives the deadline for the other two reports: the Cash Transaction Report (CTR) (wherever applicable) for each month shall be submitted to FIU-IND by 15th of the succeeding month, and the Non Profit Organization Transaction Reports (NTRs) for each month shall be submitted to FIU-IND by 15th of the succeeding month.

    Option D reverses the duty. Reporting is proactive; the Principal Officer will be responsible for timely submission of CTR, STR and NTR to FIU-IND.

    Three related rules. Utmost confidentiality shall be maintained in filing of CTR, STR and NTR to FIU-IND. No NIL reporting needs to be made to FIU-IND in case there are no cash/ suspicious/non-profit organization transactions to be reported. And registered intermediaries shall not put any restrictions on operations in the accounts where an STR has been made.

    No threshold limits the duty: irrespective of the amount of transaction and/or the threshold limit envisaged for predicate offences specified in part B of Schedule of PMLA, 2002, an STR must be filed where there are reasonable grounds to believe that the transactions involve proceeds of crime.

    And attempts count: report all such attempted transactions in STRs, even if not completed by clients, irrespective of the amount of the transaction.

Where this is taught

Free preparation for NISM Series III-A

Related terms

← All terms
Something look wrong? Report it