Blog

What is GRC_India

What is Governance, Risk, Compliance (GRC)? Setup + Best Practices

🗒️  Key Highlights
  • GRC stands for Governance, Risk, and Compliance. It refers to how a business defines decision rules, manages risks, and ensures it follows relevant laws and internal standards.
  • KYC and onboarding are compliance-heavy workflows. GRC ensures those flows follow the rules, store the correct data, and flag risks early, primarily when handled through APIs or digital tools.
  • You don’t need a single paid software to start GRC. You can use spreadsheets and task tools. But as you scale, the software helps automate tracking, reporting, access logs, and audit trails.

Every fast-moving finance business runs on one simple mechanism: decisions, actions, and consequences.

  • Who approved that payout?
  • Why was that vendor cleared?
  • Was that onboarding flow compliant? 

These questions don’t come up when things go right. 

…But they define everything when things don’t.

That’s where GRC steps in. 

Not as a cost center, not as a corporate ritual, but as a system that ensures critical decisions don’t rely on memory, mood, or muscle memory.

If you want to know how to structure it, run it, and make it part of your operations without slowing down what matters, this guide has everything you need to know and take-home trackers. 

Let’s start with nuts and bolts first.

Governance, Risk, Compliance (GRC), Explained

If you’re building in fintech, crypto, or anything that touches money, you can’t afford loose ends.

Not just in code or design but in how your company works behind the scenes. Who’s making decisions? What happens when things break? Whether you’re following the rules that apply to you.

That’s GRC. Governance, Risk, Compliance. It’s more like the spine that keeps everything straight as you grow.

  • Governance → Defines who has the authority to make decisions, approve changes, sign contracts, manage funds, and access sensitive systems. Prevents overlap, confusion, and unauthorized actions.
  • Risk It detects threats like fraud, regulatory action, system downtime, and third-party failure and sets up controls to reduce or respond to them.
  • Compliance → Tracks which laws, regulations, and standards apply (like RBI, SEBI, FATF, GDPR) and ensures internal processes, documentation, and product features meet those requirements. Includes audit readiness.

GRC is built so your team doesn’t get stuck fixing preventable problems. It’s what lets you move fast without crossing lines you didn’t even know existed.

Without GRC, you fix things when they break. With GRC, you avoid most breaks to begin with. Especially as you grow, it keeps operations stable while everything else scales. It is not a visible feature, but it keeps the engine clean.

How to Implement GRC in an Organization?

You do not need to over-architect the system, but it has to be deliberate. GRC is not something that happens in the background. It is something you set up intentionally. 

Here’s a comprehensive 6-step process to get running.

Step 1: Assign Clear Ownership

GRC does not work unless each component has a responsible owner. 

  • Governance is typically handled by senior leadership, such as the COO or board members since it involves decision-making rules, oversight mechanisms, and accountability. 
  • Risk should be owned by operations or a product-risk team, depending on the business model. 
  • Compliance usually falls under legal or finance, especially in regulated sectors. 

These roles should be fixed, documented, and visible to the entire leadership team.

Step 2: Build a Live Compliance Inventory

The first tactical step is building a compliance inventory. This is a single document that lists every regulatory, legal, and operational requirement your company must follow. It should include authorities like RBI, SEBI, FIU-IND, income tax, and any self-imposed obligations like contractual requirements from partners or investors. 

For each item, document the frequency, responsible owner, due date, and status. This should be reviewed every month and updated as rules evolve.

Look at this tracker, for example:

GRC Trackers - Signzy Technologies

You can get this tracker template – HERE. Please read the disclaimer carefully before using it.

Step 3: Maintain a Risk Register

This register is a working document that makes your leadership aware of what could go wrong, how prepared you are, and where you need to act next.

In this, create a structured register of risks across the business. Include legal, operational, financial, cybersecurity, vendor, and reputational risks. Each risk entry should include a short description, its likelihood and impact rating, an owner, and the mitigation plan. Refer the example below for better idea.

GRC Trackers - Signzy Technologies2

Grab tracker – HERE (check second sheet). Once again, please read the disclaimer carefully before using it.

If a risk materializes, the register should also track the incident history and recovery steps.

Step 4: Apply Access and Change Controls

Every tool or system that handles data, money, or sensitive workflows must have permission layers. 

No one should get admin access without documented approval, and no access should go unmonitored. 

You should be able to review logs showing who accessed what and when. For workflows that involve financial decisions, refunds, reconciliations, or reporting, enforce a maker-checker system. One person performs, and another person verifies. 

This prevents internal fraud, misuse, and unintentional errors from going unnoticed.

Step 5: Define Protocols for Incidents

You need a basic response plan for the most common categories like: data breaches, financial errors, system outages, regulatory notices, or internal fraud. These plans should define who is responsible, what steps are taken immediately, who is informed, and whether reporting to regulators or partners is required.

This can be stored in a simple internal document. Everyone involved in operations, tech, or compliance should be trained on it once per quarter. The aim is to avoid delays and miscommunication during high-pressure events.

Step 6: Conduct Internal Reviews Quarterly

Set a fixed schedule to review GRC functioning across departments. 

Each quarter, review the compliance tracker, governance logs, risk register, and access controls. 

  • Check what was missed, what got delayed, and what changed. 
  • Document the gaps. Assign fix owners. 
  • Set a 30-day resolution period for anything that affects compliance or customer trust.

These reviews don’t need to be formal audits. But they need to be routine, structured and followed through. GRC stays strong only when it’s maintained, such as in infrastructure.

Best Practices to Implement GRC

A structured GRC system is good. But what keeps it working week after week is operational hygiene. Beyond the core setup, there are specific habits and decisions that make the difference between a GRC program that exists on paper and one that actually holds up under pressure.

Read these four best practices we’ve compiled. 

  1. Regulations should live close to your product, not just in legal docs: Maintain a product-to-regulation mapping. For every customer-facing flow (like onboarding, lending, payments), clearly link the governing rule, circular, or internal policy. Update this during every major release cycle. This avoids accidental non-compliance with product updates.
  2. Regulatory updates should be treated as version changes, not alerts. Set a fixed monthly slot to review new circulars, enforcement trends, and legal shifts. Assign a team member to summarize what changed, what’s relevant, and what needs action. Tag affected workflows and assign follow-ups.
  3. Compliance tasks need to show up where work happens, not in static files: Use task management tools like ClickUp, Notion, or Trello to assign and track compliance activities. Each task must have an owner, deadline, and proof-of-work link. Reminders and missed-task visibility should be built in by default.
  4. Vendor risks should be logged and monitored like internal ones: For every third-party tool, partner, or contractor with access to sensitive data or systems, maintain a basic vendor risk profile. Note compliance clauses, data handling risks, and SLA violations. Review high-risk vendors quarterly. Keep contracts easily retrievable.

The tighter your internal processes get, the more your external systems need to keep pace. When workflows like onboarding, Video KYC, and risk checks become routine, they should not rely on manual checks or scattered tools. That’s where APIs step in for consistency and control.

Whether it’s checking if your information is compromised in data breaches or verifying identities during onboarding, these compliance checks are foundational steps in how trust is built, and risk is managed.

Signzy’s suite of APIs is designed to support that shift. Quietly, in the background, where structure matters most.

[2025 Guide] AML Regulations India: Laws, Regulators, and More

🗒️ Key Highlights
  • The core AML law is the Prevention of Money Laundering Act, 2002, supported by rules and circulars issued by various regulators.
  • In India, the Enforcement Directorate (ED) and Financial Intelligence Unit (FIU) handle investigations related to money laundering, while sector regulators like RBI, SEBI, and IRDAI oversee compliance.
  • Under PMLA, any business or professional that handles, moves, or facilitates money, including banks, brokers, insurers, and certain consultants, is categorized as a reporting entity.

Every business that deals with money eventually builds some form of control. Sometimes it’s just basic KYC. Sometimes, it’s a detailed risk engine tied to dozens of checks. 

Either way, the idea is the same: you want to know who’s transacting, why they’re doing it, and whether the money being moved should raise concern. 

That’s the essence of AML in India.

If there’s financial value being handled, 

AML compliance becomes part of the operations.

But here’s where it gets overlooked. Many businesses don’t struggle because the rules are unclear. They struggle because the guidance they follow is either too high-level to act on or too fragmented to implement properly.

Today, we’re going to make sense of it all: what laws apply, who the regulators are, what practical steps matter, and where technology can reduce friction without compromising risk coverage. So, without further ado, let’s dive in.

AML in India, Quick Overview

Anti-Money Laundering (AML) regulations in India don’t sit under a single document. It’s a tight mesh of laws, rules, circulars, and regulatory instructions. At the center of it sits the Prevention of Money Laundering Act, 2002. This is what gives the legal backing. But that’s just one piece.

In practice, compliance plays out across multiple fronts. There are the PMLA Rules from 2005. Then there are sector-specific directions as well. Six key regulatory bodies oversee this all:

  1. Reserve Bank of India: Regulates banks, non-banking financial companies (NBFCs), and payment system operators
  2. Securities and Exchange Board of India: Regulates stockbrokers, mutual funds, portfolio managers, and investment advisers
  3. Insurance Regulatory and Development Authority of India: Regulates life insurance, general insurance, and health insurance providers
  4. Financial Intelligence Unit – India: Receives reports from all reporting entities across sectors and analyzes suspicious transaction patterns
  5. Enforcement Directorate: investigates and prosecutes individuals and entities involved in money laundering under PMLA
  6. Ministry of Finance: notifies and brings under compliance real estate agents, dealers in precious metals and stones, professionals like chartered accountants, company secretaries, cost accountants, and virtual digital asset service providers

Each of these bodies promotes its own version of AML guidelines depending on who it regulates. So, a payment app doesn’t face the same expectations as a stockbroker or insurance firm.

Now that we have a working knowledge of AML regulations and who needs to follow them, let’s go through some of the most important regulations. 

AML Laws in India

To comply with the AML regulations India has enforced, it’s not enough to follow just one law. Businesses have to track the full set, from what the PMLA defines to how reporting should be done to what the latest circular means for their category.

We are going to cover 6 areas below which covers the nice range of information for “reporting entities” regarding the laws they need to comply with at minimum.

1. Prevention of Money Laundering Act, 2002 (PMLA)

This is the spine. Everything else leans on this. The PMLA defines what counts as money laundering, what qualifies as proceeds of crime, and what the penalties are. It gives powers to authorities like the Enforcement Directorate to investigate and prosecute offenses.

The Act also lays out responsibilities for businesses. These include record keeping, reporting of suspicious transactions, and verifying clients through KYC processes.

Over the years, the law has been amended to widen its scope. Today, even tax evasion linked to foreign assets or cross-border transactions can fall under its net.

2. PMLA (Maintenance of Records) Rules, 2005

This is where the operational side comes in. The Rules break down the “how”: how to maintain records, how long to keep them, and what exactly needs to be reported to the FIU.

They also define terms like “beneficial owner”, “politically exposed person”, and explain how enhanced due diligence should be done in higher-risk cases. These rules are updated regularly. For instance, recent changes brought virtual asset providers and specific professionals into the fold.

3. RBI Guidelines on AML and KYC

For entities under RBI (i.e., banks, NBFCs, payment companies) the AML checklist is stricter. RBI has issued detailed Master Directions that cover everything from risk grading of customers to periodic review of accounts.

These guidelines are not suggestions. They’re binding. Any gap in adherence can trigger audits, monetary penalties, or even suspension of operations.

4. SEBI Guidelines for Capital Market Intermediaries

Stockbrokers, mutual fund houses, portfolio managers: all these players answer to SEBI. SEBI’s AML framework is structured around client onboarding, transaction monitoring, and risk-based due diligence.

There are clear formats for suspicious transaction reports. There’s also a strong push towards automation of alerts and red-flag detection.

5. IRDAI Guidelines for Insurance Entities

Insurers have a different customer flow and product structure. IRDAI has crafted its AML instructions to reflect that. From verifying the source of premium payments to tracking policy transfers, insurers need to watch for patterns that might be used to clean up money.

In case of a flagged transaction, they are expected to alert the FIU just like any other financial intermediary.

6. Sector-Specific Circulars and Notifications

Apart from the main regulators, the Ministry of Finance has also issued notifications for niche sectors. These include guidelines for:

Each comes with its own list of expectations. The language is clear. If you handle money, you need to know your customer. And you need to report what doesn’t look right.

Steps to Comply with AML Setups

Not every business follows the same compliance path. A stockbroker’s AML setup will look different from a payment gateway’s. A jeweller will follow a different set of instructions than an NBFC. 

The AML regulations laid out in India are shaped by the type of entity, the kind of transactions handled, and the level of risk exposure.

That said, there are certain steps that cut across categories. The broad strokes every regulated business is expected to follow. Here’s a high-level view. 

Use this as a base, and adapt it to fit the exact guidelines that apply to your sector.

Step 1: Risk-Based Customer Due Diligence

The first layer is knowing your customer, not just identity, but intent and behavior too. Businesses are expected to classify customers based on risk levels. A salaried account holder with basic transactions will fall into low risk. A foreign entity wiring funds regularly might be marked as high risk.

Depending on the level, due diligence requirements change. The higher the risk, the deeper the scrutiny.

Step 2: Establish an Internal AML Policy

Prepare an AML policy that should clearly define internal responsibilities, reporting chains, how suspicious activity is flagged, and what kind of monitoring is expected.

The policy should also include procedures for staff training, escalation paths, and periodic reviews. Most regulators now expect this policy to be formally approved by the board.

Step 3: Set Up a Monitoring and Reporting System

Every regulated entity must have a system in place to detect unusual transactions. This could be manual tracking in smaller setups, or an automated rule-based system for higher-volume players.

Once detected, suspicious transactions need to be reported to the FIU using prescribed formats like STRs (Suspicious Transaction Reports) or CTRs (Cash Transaction Reports).

Step 4: Maintain Proper Records

Regulations require businesses to store key customer and transaction records for at least five years after the relationship ends or the transaction is complete, whichever is later.

These records must be clear, retrievable, and structured in a way that allows quick access if requested by the regulator.

Step 5: Ongoing Training and Audits

AML setups are not a one-time effort. Staff handling onboarding, finance, and customer service should receive periodic training on AML red flags and compliance workflows.

Many sectors also require internal audits of AML systems. These checks help plug process gaps and show regulators that the business takes India’s AML obligations seriously.

Scaling AML Compliance Operations With Technology

Manual checks don’t scale. And in AML, delays are dangerous. 

With regulatory pressure increasing and fraud techniques getting sharper, relying only on paperwork or spreadsheets isn’t enough. 

That’s where API-first tools help. With the right integrations, businesses can automate their AML processes without breaking existing systems. Here are three solutions often used to tighten AML workflows:

  • PAN Verification API: Instantly verifies customer PAN details with official government databases, helping eliminate false entries and reduce onboarding fraud.
  • Face Match + Liveness Check APIs: Verifies if the person behind the screen is real and matches the submitted ID, reducing the risk of impersonation or mule accounts.
  • Bank Account Verification API: Confirms if a bank account exists, is active, and belongs to the intended user. Useful for payout businesses, fintechs, and NBFCs.

Whether you’re onboarding customers, verifying identities, or monitoring fraud, Signzy APIs are designed to make compliance smoother and faster.

Want to see how this fits your setup? Book a free demo.

Bringing KYC to Every Corner of India with RBI: Video KYC, Security, and More

🗒️ Key Highlights
  • RBI selected Signzy for its regulatory sandbox to pilot unassisted Video KYC, marking a shift toward fully automated verification.
  • Signzy’s vKYC currently supports over half a million video calls every month, with infrastructure tested for concurrency, uptime, and failover scenarios.
  • More than 30 banks, NBFCs, and financial institutions across India trust this system to onboard users every day (not as a pilot, but as part of core business operations).

On April 1, 2025, the Reserve Bank of India will complete 90 years. That’s 90 years of shaping how India banks, saves, invests, and grows. A milestone like this isn’t just about looking back. It’s about taking a moment to see how far the system has come and how many lives it has touched along the way.

Since the early 2010s, we’ve had the chance to be a small part of that journey. From experimenting with digital onboarding to building KYC tools that reach people in the most remote corners, every step has been about making finance simpler and more inclusive.

Let’s take a look at what’s been built together with RBI and the vision that continues to guide what we build next.

A Shared Vision for Inclusive Finance

In a country as diverse and complex as India, where access often depends on geography or circumstance, the ability to engage with formal finance can change lives. RBI has played a central role in enabling this by streamlining processes and setting clear regulatory paths. 

This way, it is now easier for institutions to reach everyone, from the underserved to the urban user.

From the early push to bring banking to rural India to supporting digital payments and UPI, RBI’s intent has been clear: make finance available to everyone, not just the privileged few.

Look closely, and the pattern shows up everywhere. 

  • In villages where branch infrastructure is still limited. 
  • In urban slums, paperwork is often rejected. 
  • In small towns where people want to save, invest, or insure but don’t know how to begin.

Tools need to be built with those realities in mind. Not just high-tech, but high-reach. Not everyone will have perfect documents, a 4G connection, or a quiet room for verification. But everyone deserves a shot.

At Signzy, we’ve tried to build in the same spirit. From the beginning, our focus has been to make onboarding tools that don’t assume high-speed internet, tech-savviness, or urban infrastructure. If something only works in Tier 1 cities, it doesn’t really work for India.

Our Video KYC journey reflects that belief. And our work with RBI as a partner has pushed us to stretch that belief even further. 

Together, we’re changing what that entry point looks and feels like.

Solving the KYC Bottleneck

For years, KYC has been the silent friction point in financial services. Everything else could be digital (e.g., account opening, app journeys, customer support), but identity verification dragged behind. 

Manual checks took days, required in-person visits, and made the cost of onboarding disproportionately high. Even when financial institutions moved to online flows, the process still broke down too often. Document uploads failed, images were unclear, users didn’t know what went wrong. Completion rates stayed low, especially in rural or low-bandwidth settings.

This is where the bottleneck really showed. Not in policy or in product, but in that one moment where a user had to prove who they were, and the system couldn’t keep up. 

RBI recognized this early. It permitted new methods like video KYC and actively pushed the ecosystem to explore them. Through innovation contests, sandbox environments, and regulatory clarity, it set the tone: identity verification had to become faster, safer, and more inclusive. 

That shift in direction gave space for players like Signzy to build systems that could meet those expectations. Before diving into how Signzy took it a step further, let’s understand how the solution works in general.

How Does Video KYC Work

Good onboarding feels invisible. That’s exactly what video KYC was designed to do. 
Whether someone starts the process from a bank app, website, or shared link, the experience is the same: simple, direct, and fully guided.

Here’s how it works, step by step:

  1. Session starts via a link or embedded widget: Customers begin their journey through a secure web link or in-app flow. No installations and no friction. The front-end handles pre-call checks, network, camera, mic, VPN restrictions, and device compatibility.
  2. Document and PAN verification in real-time: The customer is prompted to show their PAN or other valid ID to the camera. OCR extracts data live, and PAN is verified instantly through APIs. Any mismatch is flagged immediately for correction.
  3. Live face match and passive liveness detection: Advanced AI compares the customer’s face to the document photo, confirming the identity and detecting spoofs (e.g., masks, pre-recorded videos) without interrupting the flow.
  4. Agent joins for final checks and Q&A: A trained KYC agent conducts dynamic questioning guided by configurable rule engines. Responses are assessed alongside captured data, ensuring both compliance and fraud prevention.
  5. Outcome is logged, time-stamped, and audited: The entire session (including video, screenshots, document scans, face match results, and network diagnostics) is logged. All data is stored securely and is accessible through a real-time admin portal and MIS dashboard.

No uploads. No silent failures. Just one clean, human interaction.

The entire process wraps up in minutes, and the user walks away verified. 

What Makes Signzy’s vKYC Solution Powerful

Once the bottleneck was reimagined, it had to be rebuilt with infrastructure that could actually deliver.

Here’s what makes Signzy’s vKYC platform resilient, scalable, and truly inclusive:

  • Works on 75 kbps connections: Designed to operate even on low-speed mobile data, making it accessible to users in remote or low-infra bandwidth regions.
  • Supports 9 Indian languages: The interface, prompts, and agent workflows are multilingual by design, so customers aren’t forced to navigate in a language they’re not comfortable with.
  • Advanced spoof and liveness detection: Detects pre-recorded videos, static images, or screen replays in real-time, protecting against fraud without requiring heavy backend checks.
  • 300+ concurrent calls supported: Built to handle large-scale deployment across multiple regions and teams without performance dips or scheduling conflicts.
  • Built-in chat, rejoin, and queueing systems: If a call drops or load spikes, the session isn’t lost. Customers can rejoin, chat with support, or reschedule without restarting the process.
  • 96% conversion rate across implementations: Higher completion rates, fewer retries, and increased application acceptance, resulting in lower onboarding costs and faster go-to-market for partners.
  • Real-time dashboards and automated MIS reports: Get full visibility into call volumes, agent activity, and session outcomes with a 360° dashboard. Daily MIS reports are generated automatically, offering transparency without manual effort.

This feature set was built with India’s unique environments in mind and the belief that inclusion can’t wait for perfect conditions.

Now, the question of security arises. Let’s address that as well.

Security Standards

When it comes to KYC, speed means nothing without security. Every session on Signzy’s platform is encrypted end-to-end and stored with full regulatory compliance. 

The system is ISO 27001:2013 and SOC 2 Type 2 certified, with built-in controls for data privacy, audit trails, and secure access across every layer, from agent interfaces to backend dashboards.

Even India’s top regulators have acknowledged this push. 

Recognition and Regulatory Collaboration

Regulatory bodies and industry forums played a key role in shaping the direction of what Signzy has built.

  • RBI Payments Innovation Award (2016 & 2018): Early recognition that identity verification could be reimagined using digital-first infrastructure without compromising on compliance.
  • Limited Use Authorization for Unified KYC (2022): Approval to enable broader adoption of seamless, cross-platform KYC journeys under a regulated framework.
  • RBI Sandbox for Unassisted Video KYC (2024): Selected for testing fully automated KYC flows, moving beyond assisted models, and pushing the envelope on trust and scale.
  • IFSCA Global FinTech Hackathon Winner: Chosen among top global solutions for regulatory-grade innovation in onboarding and identity.
  • IAMAI RegTech & Fintech Awards (2018–2021): Repeatedly recognized as the most innovative provider in KYC, compliance automation, and financial data handling.
  • India Fintech Forum – IFTA Awards: Acknowledged for best-in-class RegTech design and operational excellence across consecutive years.

vKYC Use Cases

vKYC’s real strength is how it fits across different parts of the financial ecosystem. Wherever identity verification is a barrier, video KYC makes the process faster, safer, and easier to scale.

Use Case How vKYC Helps
Bank Account Opening Fast, compliant onboarding without physical visits
Loan Disbursals Real-time verification before funds are released
Insurance Onboarding Policyholder validation with live checks
Mutual Fund KYC Quick activation for first-time investors
Pension & Retirement Plans Enables remote onboarding for older or rural users
Credit Card Issuance End-to-end digital application and KYC validation
CKYC Record Creation Seamless upload and verification into the central KYC

We offer this through a robust Video KYC API as well as a comprehensive KYC suite that includes DigiLocker, Aadhaar verification, and more. Built to plug into existing systems or run as a full-stack solution, it’s trusted by 30+ institutions across India, including the likes of Union Bank, Citi Bank, Tata Mutual Fund, Aditya Birla Capital and more.

And we’re just getting started.

Closing note

A heartfelt thank you to the Reserve Bank of India and every partner who placed their trust in this journey. We’ve come a long way together, but the work is far from done. Onboarding should feel simple, safe, and seamless—no matter who you are, where you’re from, or what device you’re on.

RBI_tribute to the RBI

A Tribute to the RBI: 90 Years of Steady Hands and Bold Steps

The Reserve Bank of India is turning 90 on April 1, 2025. It’s more than an anniversary. It’s a moment to pause and look at how far India’s financial system has come, and how quietly the RBI has shaped that progress.

From managing currency in the early years to supporting digital payments today, the RBI has stayed focused on building stability, access, and trust in finance. Its role has changed over the decades, but the intent has remained steady.

At Signzy, we’ve been fortunate to contribute to this journey since the 2010s. Our work has aligned with the RBI’s vision in areas like KYC, compliance, and digital transformation.

This blog is our way of saying thank you. A reflection on how RBI’s approach to regulation has grown over time, especially in the world we know best (digital banking, fintech, and identity).

Let’s start by seeing where it all started. 

Reserve Bank of India’s Origins

On April 1, 1935, when the Reserve Bank of India opened its doors, few would have imagined the journey it would undertake. The RBI was India’s answer to chaotic currency systems (India witnessed over 570 bank failures in the 1940s alone), frequent bank failures, and a lack of centralized monetary control. 

It began as a private entity, regulating currency and acting as banker to the government, but post-independence, it was nationalized in 1949. From that point on, the RBI started shaping India’s economic destiny.

In many ways, RBI is like the infrastructure we don’t see but which never fails. It has walked with India, through wars, reforms, scams, crises, liberalization, pandemics, and digitization. And every time, it has emerged with credibility intact.

RBI’s Timeline of Transformation

The RBI’s journey is filled with moments that quietly changed the way India banks, transacts and trusts the system. Here are 20 key turning points.

  1. 1935 – RBI begins operations on April 1 as a private shareholders’ bank, focusing on currency issuance and acting as a banker to the government.
  2. 1949 – RBI was nationalized and gained legal authority to supervise and regulate commercial banks under the Banking Regulation Act.
  3. 1955 – RBI helps set up the State Bank of India to expand banking services and act as a development arm in rural India.
  4. 1961 – Launches Deposit Insurance in the wake of bank failures, protecting small depositors. A first in Asia.
  5. 1969 – Executes nationalization of 14 major commercial banks; priority sector lending norms and branch expansion in rural India follow.
  6. 1980 – Six more banks are nationalized; RBI deepens focus on inclusive banking and cooperative sector regulation.
  7. 1991 – In the wake of a balance of payments crisis, RBI starts deregulating interest rates, launches monetary policy reforms, and liberalizes banking.
  8. 1993 – Licenses new private sector banks (e.g., ICICI Bank, HDFC Bank), bringing competition and innovation into mainstream banking.
  9. 1997 – Gets power to regulate NBFCs under revised RBI Act, important for managing India’s fast-growing shadow banking space.
  10. 2002 – Introduces Real-Time Gross Settlement (RTGS) system, ushering in real-time payments for high-value transactions.
  11. 2008 – Responds swiftly to global financial crisis by ensuring liquidity, while maintaining capital buffers and strict NPA recognition norms.
  12. 2010 – Launches Base Rate system, replacing benchmark prime lending rate for more transparent pricing of loans.
  13. 2016 – Monetary Policy Committee (MPC) established, RBI now sets interest rates through a structured, inflation-targeting framework.
  14. 2017 – Formal rollout of UPI gains momentum; RBI supports rapid fintech growth while refining oversight on digital payments.
  15. 2018 – Tightens norms for NBFCs and cooperative banks after IL&FS crisis; begins cleanup via PCA and stricter provisioning.
  16. 2020 – Allows Video KYC during COVID, accelerating remote onboarding; also launches regulatory sandbox for fintech innovation.
  17. 2021 – Rolls out scale-based regulation for NBFCs, classifying them by systemic importance to reduce regulatory arbitrage.
  18. 2022 – Releases guidelines for Digital Lending, curbing predatory practices and enforcing direct disbursals and transparency.
  19. 2022–23 – Initiates CBDC (Digital Rupee) pilots (wholesale and retail) to explore programmable, sovereign-backed digital currency.
  20. 2024 – UPI becomes globally accepted in multiple countries; RBI actively collaborates on cross-border payment frameworks (Project Nexus, etc.).

Achievements Over the Decades

Deposit Insurance Priority Sector Lending Bank Nationalization

Protected small depositors during bank failures. First of its kind in Asia

Ensured credit flow to agriculture, small businesses, and weaker sections

Brought banks under public control to push financial inclusion at scale

UPI & Digital Payments

Spearheaded UPI, enabling 14B+ monthly transactions and global adoption

Video KYC Enablement

Simplified remote onboarding, helping expand access in rural/low-infra areas

CBDC Rollout

Initiated central bank digital currency pilots for retail and wholesale transactions

NBFC Scale-Based Regulation

Structured NBFC oversight based on size and risk to prevent regulatory arbitrage

Monetary Policy Committee (MPC)


Created a formal, data-driven framework for inflation-targeting via MPC

Robust Crisis Management

Navigated IL&FS, COVID, and global crises without major financial system failures

Collaboration with Signzy

It’s not every day that a startup gets to co-create with the central bank of a nation. At Signzy, we consider it a privilege.

We were recognized by RBI through the Payments Systems Innovation Awards in 2016 and 2018. More recently, in 2024, we were awarded a place in the Regulatory Sandbox for Unassisted Video KYC, one of the most forward-looking initiatives in digital onboarding.

In our journey, we’ve contributed to making KYC more accessible. Working with banks and regulators, including under RBI’s guidance, we’ve enabled verification, helped rural banks onboard users with minimal infrastructure, and reduced drop-offs in onboarding with AI-powered ID verification.

Our systems now power parts of the digital onboarding stack for several institutions governed by RBI. 

Signing Off

RBI’s story mirrors India’s story. Full of resilience, reinvention, and quiet conviction.

And for those of us building at the intersection of finance and technology, the RBI is more than just a regulator. 

It’s a reason. 

A reason why India could go from long queues in bank branches to instant bank transfers on mobile phones.

We’re proud to have played a small role in this journey, making digital identity more inclusive, KYC more seamless, and compliance less intimidating.

Here’s to 90 years of the Reserve Bank of India. Thank you for being the invisible force that keeps India’s financial heart beating.

And here’s to the next decade. Where trust will still matter, but so will speed, access, and adaptability. 

We’re building for that future, with you. ♥️

RBI

Complying RBI’s New MNRL Guidelines: 11 Key Questions Answered

🗒️  Key Highlights
  • When financial institutions verify a number against MNRL, they can detect if it has been compromised and prevent fraud before it happens.
  • Without this check, banks might unknowingly send OTP codes and account reset links to fraudsters instead of legitimate customers.
  • If your business processes transactions, credit approvals, or KYC using mobile numbers, MNRL compliance is a must.

A mobile number is supposed to be personal. But what happens when it isn’t?

A number gets deactivated. The telecom provider reassigns it. Now, someone else has access to messages, calls, and possibly sensitive financial details that weren’t meant for them. 

Meanwhile, banks and fintechs continue sending OTPs, approving transactions, and verifying users, without realizing the number is no longer in the right hands.

This is why RBI released the new MNRL guidelines on January 17, 2025.

If your operations rely on mobile numbers for customer verification, onboarding, or transactions, you need to comply with these guidelines by March 31, 2025.

If you’re still unsure about what this means, we’ve answered the 11 most common questions below.

Let’s dive in.

The Mobile Number Revocation List (MNRL) is a database of permanently deactivated numbers that financial institutions must check before linking to customer accounts. It’s published on TRAI’s platform every month, with data sourced from telecom operators under DoT’s guidelines.

Think of it as a reference list of numbers that should not be used for financial transactions because they were permanently deactivated. 

Banks, NBFCs, and fintechs must cross-check their customer numbers against MNRL to avoid fraudsters sneaking into their systems.

Ignoring this list means taking a huge risk (e.g., unauthorized transactions, money mules, and regulatory penalties). Financial businesses that rely on mobile authentication can’t afford to skip this check.

2.

Why has RBI made MNRL compliance mandatory?

Fraudsters have too many tricks when it comes to mobile numbers. Some use SIM swap fraud to intercept OTPs, others register fake numbers with banks, and some exploit old, reassigned numbers to access financial accounts.

Until now, financial institutions had no standardized way to check if a number was permanently deactivated. MNRL provides a centralized list to help them clean up outdated records.

If a bank sends an OTP to a number that has changed hands, the risk of unauthorized access increases. Money moves fast, and reversing fraudulent transactions is nearly impossible.

So, the RBI stepped in. MNRL is now a hard requirement. Financial institutions must verify numbers against MNRL to prevent fraudulent activity and remove flagged numbers from their database.

3.

Which businesses must follow MNRL regulations?

Anyone handling financial transactions linked to mobile numbers. That includes:

  1. Banks (Commercial, Small Finance, Payment Banks, Cooperative Banks)
  2. NBFCs (Including lending startups, housing finance, and microfinance companies)
  3. Payment Aggregators & Wallets
  4. Credit Information Companies
  5. Loan and BNPL providers

If mobile numbers are part of customer onboarding, transaction verification, or fraud prevention, MNRL compliance is non-negotiable. 

Even fintech startups running KYC checks must integrate this.

And no, it doesn’t matter if a company is big or small, if it holds a financial license, it must comply.

4.

How can banks and fintechs access the MNRL database?

There are two ways to check numbers against MNRL:

  1. Manual lookup: Financial institutions can log into the Digital Intelligence Platform (DIP) and check numbers one by one. Not ideal for businesses with large customer bases. It’s slow and requires constant updates.
  2. Automated API integration: The smarter option. Signzy offers an MNRL API that instantly verifies numbers in real time. This lets businesses automate the process and flag risky numbers before they cause trouble.

For high-volume businesses, manual checking isn’t practical. Fraud prevention needs speed, and an API integration removes the human delay.

5.

What is the deadline for MNRL compliance?

RBI has set March 31, 2025, as the deadline for financial institutions to implement MNRL compliance. By this date, banks, NBFCs, fintechs, and Payment aggregators should integrate MNRL checks to ensure they are not processing transactions or sending OTPs to deactivated numbers, reducing the chances of account misuse.

6.

What’s the fastest way to meet MNRL compliance before the deadline?

The March 31, 2025 deadline is fast approaching, and businesses must act immediately. The quickest way to get everything in place is to automate the process with an API instead of relying on manual checks.

Here’s how to speed things up:

  1. Integrate an MNRL API: Use Signzy’s MNRL API to eliminate manual verifications and automatically screen numbers in real time. This ensures flagged or deactivated numbers don’t slip through during customer onboarding or transactions.
  2. Run a bulk database check: Cross-check all existing customer numbers against MNRL to remove flagged entries.
  3. Update internal workflows: Ensure new customer onboarding and transaction approvals include automatic MNRL checks.
  4. Remove disconnected numbers: Fraud and risk teams need to know how to handle flagged numbers and prevent misuse.

Rushing compliance at the last minute creates operational bottlenecks and increases risks. Automating verification now ensures seamless compliance without disrupting business.

7.

How does MNRL actually prevent fraud?

Most fraudsters don’t use their real names or IDs. They rely on burner numbers and stolen identities to trick financial institutions.

MNRL helps prevent misuse by ensuring financial institutions do not process transactions using:

  • Deactivated numbers that may have been reassigned
  • Long-inactive numbers that could be exploited for fraudulent activities

For financial institutions, this means fewer fake KYC approvals, fewer hacked accounts, and fewer fraudulent transactions.

A flagged number should be immediately blocked from being used for banking, credit applications, or payments. Without this check, businesses are basically inviting fraudsters to exploit their system.

8.

What happens if a bank or NBFC doesn’t comply with MNRL regulations?

RBI has set strict penalties, and financial institutions that ignore MNRL risk:

  • Telecom restrictions: Banks or fintechs that keep using risky mobile numbers may have their telecom resources (SMS/call services) suspended for up to 2 years, per  TRAI’s commercial communication rules. That means no customer outreach, no OTPs, no transaction alerts.
  • Regulatory action: Institutions that fail to clean up their databases may face audits, penalties, or even restrictions on business operations.
  • Fraud liability: If a fraud happens due to an unverified number, the institution could be held responsible. This includes legal consequences, financial losses, and brand damage.

Most fintechs and banks run on trust. Customers won’t think twice before switching if they feel their data or transactions aren’t secure. As a result, MNRL compliance becomes necessary.

9.

Can financial institutions still call customers using regular phone numbers?

No. RBI has enforced strict numbering rules to eliminate fraud calls and scams. Banks and NBFCs can no longer make transactional or promotional calls from random 10-digit mobile numbers.

Here’s how calls must be handled:

  • Service & Transactional Calls: Must come from the ‘1600xx’ series (this will be activated soon).
  • Promotional Calls: Must use ‘140xx’ series.
  • No regular 10-digit mobile or fixed-line numbers should be used for any official communication.

This prevents fraudsters from spoofing customer care numbers and tricking people into revealing sensitive details.

10.

Does MNRL only apply to banks, or do fintech startups need to comply too?

Every financial institution that relies on mobile numbers for authentication or transactions must comply, including fintechs, lending startups, and payment service providers.

A common misconception is that only large banks are affected. That’s not the case. Even startups offering BNPL (Buy Now Pay Later), microloans, or prepaid wallets need to check customer numbers against MNRL.

This regulation is especially relevant for fintechs, since many of them onboard customers using digital KYC, where fraudsters often exploit loopholes. Many also depend on SMS and call-based authentication, which can be hijacked if numbers aren’t verified. Therefore, yes, MNRL compliance is a must even if you are fintech.

11.

Can businesses manually verify numbers instead of using an API?

Technically, yes. Practically, it’s a nightmare.

Manual verification involves logging into the DIP platform and checking numbers one by one. This might work for small businesses with a few dozen customers, but for banks, NBFCs, and fintechs handling thousands or millions of transactions, manual checks don’t scale.

Here’s why API integration is the only logical choice:

  • Verification checks: API solutions validate numbers before transactions or onboarding.
  • Automated monitoring: The system can continuously screen customer databases for newly flagged numbers.
  • Faster fraud prevention: Fraudsters move fast. An automated system catches them before they cause damage.

For high-volume businesses, manual checks are slow, error-prone, and impossible to maintain at scale. An API automates this seamlessly, running checks in real time without disrupting operations. 

Signzy’s MNRL API enables financial institutions to automate verification, ensuring customer numbers are screened against the latest MNRL dataset. This helps businesses prevent fraud, maintain clean databases, and stay compliant without manual intervention.

To know more about Signzy’s Mobile Number Revocation List API, book a demo here.

KYC documents required for UAE customer verification

UAE KYC Document List: Requirements by Customer Type [2025]

🗒️  Key Highlights
  • In a 2023 evaluation, the UAE achieved notable FATF ratings: Compliant for 15 and Largely Compliant for 24 of the 40 Recommendations.
  • The requirements to verify individuals and corporate customers in the UAE are totally different, demanding comprehensive knowledge.
  • Violations of KYC and AML regulations face strict enforcement measures, with penalties ranging from financial fines to imprisonment.

Collecting KYC documents in the UAE isn’t exactly anyone’s idea of a good time. Yet here you are, tasked with making sure your business gets it right. 

And with financial penalties that can make your CFO break out in a cold sweat, the stakes couldn’t be higher. So, if you came here looking for a straight-shooting guide to KYC document collection in the UAE, perfect – you got exactly that. 

Let’s start right away.

UAE KYC Document Requirements for Individual Customers 

Running a UAE business means you’ll be collecting KYC documents from individual customers pretty regularly. And while it might seem straightforward, there’s more to it than just grabbing a copy of someone’s Emirates ID.

Document Required Purpose
Emirates ID (Latest version) Serves as primary identity verification and confirms UAE residency status
Valid Passport Verifies nationality, provides secondary identification, and required for non-residents
UAE Visa Page Confirms legal residency status and duration of stay
Proof of Address (< 3 months old) Establishes current residential location and validates contact details
FATCA/CRS Self-Certification Determines tax residency status and ensures international compliance
Source of Funds Declaration Creates transparency about income sources and helps assess risk levels
Recent Photograph Enables visual verification and maintains updated records
Specimen Signature Provides a baseline for future transaction verification

UAE KYC Document Requirements for Businesses and Corporate Customers

Corporate KYC is like peeling an onion – there are multiple layers to verify, and yes, sometimes it might make you want to cry. 

Document Required Purpose
Trade License Confirms legal registration and permitted business activities
Certificate of Incorporation Verifies company formation and registration details
Memorandum & Articles of Association Outlines company structure and operational framework
Board Resolution Authorizes specific individuals to act on the company’s behalf
Shareholder Registry Maps ownership structure and identifies major stakeholders
UBO Declaration Identifies ultimate beneficial owners with >25% ownership
Director Details & IDs Verifies the identity of all board members and decision-makers
POA Holder Documents Validates authority of designated representatives
Business Bank Statements (3 months) Demonstrates financial activity and transaction patterns
Entity FATCA/CRS Forms Confirms tax residency status and reporting obligations

Now, these were requirements for any normal corporation and businesses. But if your customer base includes non-financial businesses and professions, you need to collect some additional documents. 

Designated Non-Financial Businesses and Professions (DNFBPs) UAE KYC Document Requirements

If you are dealing with – Real estate agents, law firms, accounting practices, precious metal dealers and such businesses in UAE – you’d need to collect some additional documents than normal businesses and individuals. 

Everyone’s KYC requirements are unique because their risks are different. Not complete, but here’s the list you can refer to along with collecting some sector-specific documents.  

Document Required Purpose
Professional License Validates authority to operate in a regulated sector
Registration Certificate with Supervisory Authority Confirms compliance with sector-specific regulations
Beneficial Ownership Declaration Maps control structure beyond 25% ownership
Partner/Owner Identity Documents Verifies key stakeholders’ backgrounds
Business Activity Profile Establishes the nature and scope of operations
Compliance Officer Appointment Shows commitment to regulatory requirements
Risk Assessment Documentation Demonstrates understanding of sector-specific risks
AML Policy & Procedures Proves the existence of internal controls
Staff Training Records Confirms ongoing compliance awareness
Transaction Monitoring Framework Shows capability to identify suspicious activities

While verifying DNFBPs in UAE, you’re often dealing with professionals who know the rules but might be resistant to extensive documentation. Be ready to make it clear that proper KYC protects their practice as much as it protects you.

UAE KYC Document Requirements for Trusts and Non-Profit Organizations

Trusts and NPOs require extra scrutiny – not because they’re inherently risky, but because their structures can be complicated and their activities often cross borders.

Trust and NPO verification in UAE is like a detailed family portrait – you need to capture every relationship, every flow of funds, and every decision-maker in the picture.

Document Required Purpose
Trust Deed/NPO Constitution Establishes legal framework and operational scope
Founder/Settlor Documentation Identifies the source of assets and founding purpose
Trustee Appointment Documents Verifies authority of asset managers
Beneficiary Information Maps out who ultimately benefits from the structure
Council Member Details Confirms the identity of governing body members
Source of Donations (NPOs) Tracks the origin of funds and ensures legitimacy
Annual Financial Reports Shows pattern of activities and fund distribution
Regulatory Approvals Validates compliance with UAE charity regulations
Guardian Details (if applicable) Identifies oversight personnel
Project Implementation Reports (NPOs) Documents how funds are being used

The layered nature of these organizations can make it tricky. 

A trust might have beneficiaries who are themselves other trusts. An NPO might receive donations through complex channels. Your job is to untangle these threads without getting caught in them.

You can create a visual mapping tool for these structures. Sometimes seeing the relationships drawn out makes verification easier and helps spot potential risks you might miss in text-only documentation.

Verifying the collected UAE documents

Having a stack of KYC documents doesn’t mean you’re actually meeting compliance requirements. The real challenge kicks in when you need to verify each document’s authenticity, cross-reference details across multiple sources, and maintain ongoing monitoring. All while keeping your customer onboarding smooth and swift.

In a region where regulatory scrutiny is intensifying and penalties for non-compliance can be severe, the margin for error is basically zero. 

Even worse, high-quality forgeries are just a few clicks away nowadays – traditional eyeball-and-approve methods just don’t cut it anymore. 

That’s where Signzy steps in, offering targeted solutions for UAE businesses. Our KYC Verification API handles everything from Emirates ID validation to corporate document verification, while our Identity Verification Suite ensures comprehensive individual authentication. 

For corporate clients, our UBO and Criminal Screening APIs add that extra layer of security your compliance team needs. Because at the end of the day, verification shouldn’t be your bottleneck – it should be your strength.

How to conduct proof of income verification UAE

How to Conduct Proof of Income Verification in UAE | Step-by-Step Process

🗒️ Key Highlights
  • UAE lacks a government system for tracking income, leaving banks, landlords, and employers to rely on self-reported data or documents, which can lead to discrepancies in verification.
  • Using bank statements for income verification is common, but these can be easily manipulated, complicating the verification process for institutions.
  • Without income tax, there are no government records to verify earnings, leaving employer-issued documents vulnerable to manipulation.

Numbers don’t lie. 

But they certainly know how to hide.

You might glance at a pay stub or a bank statement and think you’ve got everything you need. Sometimes, those small details – the ones you might overlook – can be the ones that matter most.

Verifying income is not always as clear-cut as it seems, especially in UAE where endless types of income categories coexist. Doing this right is about more than just crossing off a checklist. 

It’s about making sure everything adds up, not just for the sake of compliance but because you want to get it right from the start. 

You don’t want to be left scrambling later on because a tiny thing wasn’t caught early right? 

Got 6 minutes? Let’s walk through the steps to ensure your income verification in the UAE is spot on. We’ll make it easy.

What is Proof of Income – Quick Definition

Proof of income refers to official documentation that validates a person’s earnings and financial stability. In the UAE context, this encompasses various financial records such as salary certificates, authenticated bank statements, and formal employment documentation. 

Common income verification documents in the UAE include salary certificates (issued by employers), bank statements showing salary transfers, and Emirates ID-linked income certificates. For business owners, valid trade licenses and audited financial statements serve as proof of income. 

How to Verify Proof of Income of Different Categories in UAE

Small but mighty – that’s what makes proof of income verification for non-traditional earners in the UAE so interesting. Their income patterns might not follow the usual paths, but verification strategies make all the difference. Let’s see exactly how to handle these unique cases:

💡 Related Blog: UBO Check Guide UAE

Regular Employed Professionals

The fastest and most reliable way to verify proof of income of an employed professional in the UAE starts with obtaining a valid salary certificate. This document must be less than 30 days old and needs to come directly from the employer’s HR department. 

What makes a salary certificate trustworthy? 

  • Check the company’s official letterhead, stamps, and authorized signatures. 
  • Contact HR directly – yes, every single time. 
  • Match everything against bank statements showing consistent salary transfers. 

When these align, that’s solid proof worth trusting. This three-way verification catches most discrepancies early in the process.

It should be simple since salary usually makes up most of the income of employed professionals. But it doesn’t mean they can have only one source of income. While verifying proof of income, consider all income streams they have, along with salary. Dividend earnings, rental earnings, and consulting fees are some examples. 

Business Owners & Investors

In the UAE, you are obliged to verify business before dealing with it. Verifying for proof of income carries even more weight in this category. 

Business owners’ proof comes from multiple sources. Start by checking valid trade licences, recent bank statements, and audited financials. 

Start establishing patterns of sustainable income now. Look for regular transfers between business and personal accounts. Check how profit distributions match declared income – the numbers should align across all documents.

Freelancers & Independent Contractors

Freelance income verification requires a different approach than traditional employment. Most freelancers in the UAE work with multiple clients or through digital platforms, creating a distinct income pattern.

Examine:

  • Client agreements alongside bank statements. 
  • Contract if they can provide
  • Deposits that match contract values
  • Analyze payment frequency. 

Most importantly, monthly bank statements should reflect a consistent flow of business transactions, even if amounts vary. Pay attention to their freelance platform income as well, if any. Payoneer, Upwork, or direct client transfers are some examples. Then, cross-reference these with freelance contracts and client invoices to see how they match the declared income. 

Variable Income Professionals

Professionals with performance-linked income need comprehensive verification. These professionals earn through multiple components – fixed pay, commissions, incentives, and bonuses. 

To verify, examine each income stream separately before building a complete picture. Track regular base salary deposits alongside performance payouts through bank statements. Here, the goal should be finding predictable patterns in their total monthly earnings despite varying commission amounts.

Spot Red Flags

While automated tools help catch many issues, knowing what to watch for manually remains crucial. Be extra cautious if you spot any of these red flags:  

🚩 Salary certificates missing official company stamps or authorized signatures – often indicate unauthorized alterations

🚩 Bank statements showing irregular salary credit patterns without proper explanation

🚩 Employment details that don’t match between salary certificate and bank records

🚩 Unexplained large deposits appearing alongside regular salary credits

🚩 Company information that can’t be verified through official UAE business registries

🚩 Multiple versions of the same income document with contradicting information

🚩 Salary amounts that vary significantly month-to-month with no documented reason

🚩 Document dates showing signs of manipulation or alteration

🚩 HR contact information that doesn’t match official company records

🚩 Income levels far above typical industry standards for the stated position

🚩 Salary certificates missing mandatory UAE allowance breakdowns

🚩 Bank statements containing suspicious patterns of round-number transactions

🚩 Income documents lacking essential details like trade license numbers or employee IDs

🚩 Salary certificates older than the standard 30-day validity period

🚩 Commission earnings that don’t align with documented bank deposit patterns

Use Technology To Verify Proof of Income in UAE

Digital verification tools have changed the game, making instant checks possible through banking APIs and digital solutions. 

Bank APIs can validate accounts and transaction histories in real time, while OCR technology extracts data from salary certificates automatically – reducing errors and verification time. Business verification APIs help confirm company details and employee status instantly, making HR verification more reliable.

It’s important to note that the verification systems you use will make a world of difference. The right system makes the difference between catching red flags early and dealing with verification failures later.

That’s where integrated verification platforms like Signzy make a measurable impact. By combining essential verification APIs – from bank account validation and OCR technology to KYC and business verification – into a single platform, organizations can streamline their entire income-proof verification process. 

With this unified approach, you can conduct faster verifications and reduce manual errors through a single integration point (while staying compliant).

KYB documents required for UAE business verification

UAE KYB Documents Requirements [Take-Home List Inside]

🗒️  Key Highlights
  • Non-compliance with KYB requirements in UAE can result in fines ranging from AED 50,000 to AED 1 million.
  • Commercial licenses in UAE’s free zones are only valid within the issuing free zone’s jurisdiction, making verification of operational scope essential in KYB checks.
  • UAE Central Bank mandates all financial institutions to conduct business verification as part of their due diligence under Federal Decree-Law No. 20 of 2018.

Think about buying gold – a $50,000 bar is presented to you. 

It’s got the right shine, weight feels perfect, and the price is compelling. But there’s no certificate of authenticity. No hallmark. No trace of its origin. Would you still buy it? 

Just like that gold bar, every business needs “proof” it’s the real deal. 

In compliance, this process is called KYB – Know Your Business. Simple as that.

A company might look perfect on paper – impressive revenue, solid partnerships, attractive terms. But without proper verification, you could be dealing with smoke and mirrors.

But it’s not tough to filter real businesses so why take risk? 

Here’s every document you need to conduct KYB verification in the UAE. 

But first, go through this quick-help section to understand requirements better. 

What do you need to verify in UAE under KYB?

Whether you’re a small business expanding your supplier network or a large corporation seeking new partners, proper verification protects not just your bottom line, but your reputation too. That’s why UAE regulations lay out five clear categories of documentation for KYB verification: 

  • Core business documents 
  • Financial records
  • Address verification
  • Ownership structure
  • UBO documentation

Each of these verification requirements are like layers of an onion – each one peels back to reveal more about your potential business partner. Let’s discuss each in detail.

List of KYB Verification Documents Required in UAE

1. Core Business Verification Documents in UAE

UAE business verification requires four mandatory documents: 

  • Trade license
  • Certificate of incorporation
  • Articles of Association
  • Commercial registration

No amount of charming business presentations or impressive figures can replace these essentials when verifying UAE business partners. These requirements stem directly from UAE Federal Law No. 2 of 2015 concerning Commercial Companies and its subsequent amendments.

The trade license, issued by the Department of Economic Development (DED) or relevant free zone authority, stands as the primary proof of operating permission. The certificate of incorporation backs this up by confirming legal establishment details, while the commercial registration fills in crucial operational specifics.

2. Financial documents

Alongside core documents, you need to collect supporting financial information as well. Here’s a list you can refer to for financial document collection:

  • Bank account opening documents
  • Recent bank statements (typically 3-6 months)
  • Banking references where applicable
  • Audited financial statements (if applicable)
  • Annual returns filed with authorities
  • Financial projections for new businesses

3. Address Verification Documents

Physical presence verification forms the third pillar of UAE business validation. You need to make sure your business partner has actual walls and doors, not just a fancy website. The primary documents needed to verify address for KYB protocols are:

  1. Tenancy Contract (Ejari in Dubai/Tawtheeq in Abu Dhabi)
  2. Recent Utility Bills (DEWA/ADDC/AADC)
  3. Location proof as registered with the licensing authority

Additional documentation might be required based on business location (mainland vs free zone), type of premises (commercial/industrial), and number of operational locations.

4. Ownership Structure Documentation

Business structures in the UAE range from straightforward to mind-bendingly complex. But whether simple or complex, clarity is non-negotiable because you need to face UAE’s compliance at the end of the day. A clear chain of ownership must be established through:

  • Shareholder registry with percentage holdings
  • Partnership agreements for non-corporate entities
  • Corporate organizational charts
  • Parent company details for subsidiaries
  • Group structure documentation for larger organizations

At this point, you may confuse ownership documentation requirements with those of UBO (ultimate beneficial ownership) requirements. 

Here’s where it gets interesting. While ownership structure shows the formal arrangement of a business, UBO documentation reveals who actually pulls the strings. A company might be owned by another company, which is owned by yet another company – but at the end of this chain stands a real person making real decisions.

5. UBO (Ultimate Beneficial Owner) Documentation

Businesses that hide their true owners (not always the ones on paper) usually have reasons for doing so. And those reasons are rarely good ones.

That’s why UAE’s Article 9 of AML-CFT decision doesn’t just ask “who owns this company?” but rather “who actually controls and benefits from this business?” .

When verifying UBOs, insist on:

For Individual UBOs
  • Valid passport copies
  • Emirates ID (for UAE residents)
  • Proof of residential address
  • Declaration of beneficial ownership percentage
For Corporate UBOs
  • Corporate documents showing ownership chain
  • Documentation tracing ownership to natural persons
  • Evidence of voting rights and control mechanisms

UBO thresholds in the UAE are set at 25% ownership or voting rights, though financial institutions might require documentation for lower thresholds based on risk assessment.

Full List of KYB Verification Documents Required in UAE

Here’s your take-home verification documents list you need to collect in UAE for KYB.

 

Category Required Documents
Core Business Documents – Trade License

– Certificate of Incorporation

– Articles of Association

– Commercial Registration

Address Verification – Tenancy Contract (Ejari/Tawtheeq)

– Recent Utility Bills

– Location Proof with Licensing Authority

Ownership Structure – Shareholder Registry

– Partnership Agreements

– Corporate Organizational Charts

– Parent Company Documentation

– Group Structure Documents

UBO Documentation (Individual) – Valid Passport Copies

– Emirates ID (for UAE residents)

– Proof of Residential Address

– Beneficial Ownership Declaration

UBO Documentation (Corporate) – Corporate Ownership Chain Documents

– Natural Person Tracing Documentation

– Voting Rights Evidence

Financial Documentation – Bank Account Opening Documents

– Recent Bank Statements

– Banking References

– Audited Financial Statements

– Annual Returns

– Financial Projections

Document Verification Process

As we all know – document verification isn’t the most exciting part of building business relationships. It can be time-consuming and resource-intensive, often pulling teams away from core business activities. 

Most businesses would rather focus on growth opportunities and partnerships. 

The real challenge comes in balancing thoroughness with efficiency. Every document needs checking for authenticity, matching details across files, and ensuring nothing’s expired. 

Doing this manually? That’s like counting grains of sand – possible, but hardly practical.

This is precisely where digital solutions can save the day. Modern verification platforms like Signzy handle the heavy lifting – automating document checks, UBO verification, and compliance monitoring, all while staying perfectly aligned with UAE regulations. Explore Signzy’s comprehensive KYB Verification Suite now.

How to carry out Enhanced due diligence in UAE

How to Conduct Enhanced Due Diligence in UAE: Procedures for All Customer Categories

🗒️  Key Highlights
  • 42% of UAE organizations faced increased fraud attempts last year, highlighting why traditional due diligence no longer suffices in current risk landscape.
  • Declining conversion rates due to fraud have pushed UAE businesses to seek balanced EDD solutions that protect while enabling growth.
  • For the first time in EMEA, digital channels surpassed physical ones in fraud losses – making robust EDD processes crucial for even online business relationships.

Think about it – you’re about to partner with a UAE business that operates across multiple free zones, has investment ties across the world, and manages regional trade worth millions. 

Your standard background check won’t reveal the full picture. 

It’s precisely why the UAE has developed one of the world’s most sophisticated Enhanced Due Diligence frameworks. 

While global businesses rush to apply their standard expansion playbooks in the UAE market, they’re overlooking a critical reality: the UAE has quietly built the world’s most unique business ecosystem, where traditional due diligence playbooks can actually work against you.

Clear your next 7 minutes. That’s all you need to know how to conduct Enhanced Due Diligence for any type of business entity as per UAE official regulations.

Understanding Enhanced Due Diligence in UAE

The UAE’s financial system balances opportunity with responsibility. Enhanced Due Diligence (EDD) stands as the practical solution to this balance. While basic Customer Due Diligence (CDD) might catch obvious risks, the EDD process UAE framework addresses those subtle, complex scenarios that demand deeper scrutiny.

In short – Enhanced Due Diligence (EDD) in the UAE is a critical second line of defense, going beyond standard verification processes. 

The Central Bank of UAE has designed specific requirements – documentation, verifications, and monitoring systems that fit the regional context. This creates an EDD process that’s both practical and meaningful.

When is Enhanced Due Diligence Mandatory?

Money flows differently in every market. The UAE regulators understand this reality and have set clear, practical triggers for when standard checks simply aren’t enough:

Financial Thresholds:

  • Foreign currency transactions: AED 100,000 or above
  • Outward transfers: AED 75,000 or above
  • Inward transfers: AED 75,000 or above

High-Risk Categories:

  • Politically Exposed Persons (PEPs) and their associates
  • Entities from high-risk jurisdictions like from FATF grey list countries
  • Complex corporate structures
  • Non-resident customers
  • Dual-use goods traders
  • Companies with adverse media mentions

Core Components of the EDD Process in UAE

The EDD process builds on this principle with three essential elements:

 

Component What to Verify Key Considerations
Enhanced Identity Verification
  • Identity authenticity
  • Business existence 
  • Operational presence
  • Independent verification needed 
  • Multiple source validation
  • Official document authentication
Source of Funds/Wealth
  • Transaction origins 
  • Wealth background 
  • Revenue streams
  • Historical documentation 
  • Pattern consistency 
  • Supporting evidence alignment
Business Relationship
  • Transaction purpose
  • Business model 
  • Relationship scope
  • Regular monitoring needed
  • Pattern matching
  • Purpose validation

Entity-Specific Requirements

The EDD process acts differently for different entities. Think of it as having a unique security protocol for each type of visitor to your building – what works for one might not work for another.

💡 Related Blog: UAE UBO Check Guide

Natural Persons

When dealing with individuals, especially in high-risk situations, standard identity checks simply don’t suffice. UAE regulations require a deep understanding of the person’s connections, activities, and risk factors. 

This means verifying their UAE residence status through official channels, confirming their physical presence through utility bills or lease agreements, and establishing clear transaction patterns through documented history.

Legal Entities

Corporate structures in the UAE often reflect the region’s complex business relationships. A proper EDD process here means understanding:

  1. Ultimate Beneficial Ownership (UBO): The focus stays sharp on identifying who truly controls the company (and everyone who holds 25% or more stake). This includes tracking ownership chains through multiple jurisdictions and identifying any politically exposed persons in the structure.
  2. Group Structure Mapping: Corporate relationships rarely exist in isolation. The EDD process must map out:
  • Parent-subsidiary connections
  • Sister company relationships
  • Joint venture partnerships
  • Regional operational presence
  1. 3. Cross-Border Elements: With UAE’s position as a global business hub, most legal entities maintain international ties. This requires:
  • Understanding foreign ownership implications
  • Verifying overseas operational legitimacy
  • Assessing cross-border transaction patterns
  • Evaluating international regulatory compliance

Non-Compliance Costs

The UAE’s regulatory framework takes a serious stance on EDD compliance, and the implications run deep into business operations. Recent regulatory actions have shown that financial penalties, while significant, represent just the beginning of troubles for non-compliant businesses.

When businesses fail to implement proper EDD processes, they face immediate regulatory consequences – 

  • Fines ranging from AED 100,000 to AED 1,000,000
  • Potential imprisonment for serious violations. 
  • Banking relationships deteriorate
  • Restricted services
  • International partners grow hesitant to engage.

More concerning is the long-term market impact. Once a business faces compliance issues, rebuilding trust becomes a significant challenge. Banking services restrict access, government contracts become inaccessible, and even basic business expansion faces heightened scrutiny.

Step-by-Step Guide to Conducting EDD

When conducting Enhanced Due Diligence in the UAE, each step requires careful attention and thorough documentation. The UAE’s regulatory framework demands a comprehensive approach that goes beyond basic verification.

Customer Risk Assessment

Each customer requires evaluation against multiple risk factors according to UAE regulations. Consider their business nature, geographical presence, ownership complexity, and transaction types. Pay special attention to triggers like high-value transactions above AED 75,000, involvement in high-risk sectors, or connections to sanctioned jurisdictions.

Additional Information Collection

For high-risk customers, standard documentation isn’t sufficient. UAE regulations require extended verification through:

Business operation evidence through recent utility bills, lease agreements, or contracts. Bank statements spanning sufficient periods to establish transaction patterns. 

For business entities, obtain audited financial statements and board resolutions. Document clear evidence of source of funds and wealth – crucial for transactions exceeding AED 100,000 in foreign exchange or AED 75,000 in transfers.

Source of Funds and Wealth Verification

Start by understanding both the immediate source of transaction funds and the broader wealth picture. Obtain concrete evidence through bank statements, business accounts, and asset documentation. For business entities, analyze financial statements and verify major revenue streams.

Payment Channel Verification

UAE regulations specifically require first payments from high-risk customers to come from their own bank accounts – no third-party payments allowed. This creates clear transaction trails and helps prevent money laundering attempts. 

Verify bank account ownership and ensure it matches the customer’s documented profile.

Senior Management Approval

High-risk relationships require explicit senior management approval in UAE. Present a complete risk assessment package including identified risks, proposed mitigation measures, and ongoing monitoring plans. 

Enhanced Monitoring Setup

Establish specific monitoring parameters based on the customer’s risk profile. Set up:

  • Transaction monitoring thresholds
  • Regular review schedules
  • Clear red flag indicators
  • Documentation update requirements

Handling Red Flags Effectively

This is where many UAE businesses face practical challenges. When red flags emerge during EDD, quick and appropriate action becomes crucial:

  • For Transaction Pattern Changes: Request clear explanations and supporting evidence for any deviation from expected patterns. If a business customer suddenly shows significant increase in transaction volumes, seek updated financial statements and business contracts justifying this growth.
  • For Ownership Structure Updates: When beneficial ownership changes occur, initiate fresh UBO verification immediately. UAE regulations demand particular attention to new PEP connections or complex holding structures that emerge post-relationship establishment.
  • For Adverse Information: Don’t just note negative news – analyze its relevance and impact. Request customer clarification with supporting evidence. If explanations seem insufficient, consider filing a Suspicious Activity Report (SAR) through the goAML portal.

Documentation gaps require immediate attention. 

When customers delay providing updated information, implement a structured follow-up process while considering whether the delay itself constitutes a red flag.

Using Technology for Enhanced Due Diligence Compliance

Manual Enhanced Due Diligence processes can add 3-5 days to customer onboarding and still miss critical risks. This impacts both compliance and business growth. High-value customers grow frustrated with delays, while compliance teams struggle with increasing documentation and monitoring demands.

Quality EDD solutions transform this reality. Modern systems can reduce verification time to hours while strengthening compliance through:

  • Real-time sanctions and PEP screening with Arabic name matching
  • Automated document validation and authentication
  • Direct integration with UAE regulatory reporting systems
  • Customizable risk assessment frameworks
  • Comprehensive audit trails and monitoring alerts

The investment pays off through faster customer onboarding, reduced manual errors, and stronger compliance. 

For businesses seeking reliable EDD solutions in UAE, Signzy offers comprehensive verification tools tailored to regulatory requirements. Our integrated API suite includes essential services like Business Verification, UBO Check, and PEP Screening – all crucial for robust EDD processes. Convert time-consuming compliance processes into efficient, automated workflows – Book Your No-Obligation Demo.

FAQs

  • How long does a typical EDD process take in UAE? 

Standard EDD processes typically take 3-5 business days. However, complex cases involving multiple jurisdictions or unclear ownership structures may require additional time for thorough verification.

  • What’s the minimum transaction value that triggers EDD? 

Foreign currency exchanges over AED 100,000 and money transfers above AED 75,000 require EDD. However, high-risk indicators may trigger EDD regardless of transaction value.

  • Can we rely on EDD conducted by other financial institutions?

While you can consider third-party verifications, UAE regulations require institutions to conduct their own EDD and maintain responsibility for customer due diligence.

  • What documents are mandatory for EDD in UAE?

Core requirements include verified identification, proof of address, source of funds evidence, and ownership documentation. High-risk cases need additional supporting evidence.

How to Pick a Freezone While Starting a Business in UAE?

🗒️  Key Highlights
  • While UAE has 45+ freezones across seven emirates, only specific ones like DIFC and ADGM operate under their own comprehensive legal and regulatory frameworks.
  • Office space requirements directly impact visa quotas – physical offices allow one visa per 9-10 square meters across Dubai freezones.
  • Some freezones demand physical office space from day one, while others like IFZA allow flexible arrangements – impacting initial setup costs significantly.

Imagine moving to a new city. You need a neighborhood that clicks—one that suits your pace, has the right connections, and feels like home. 

Choose wrong, and you’re stuck in a place that doesn’t fit your lifestyle. Choose right, and everything clicks—you’re right where you belong.

Picking a free zone in the UAE is like choosing that perfect neighborhood. 

Especially for businesses in highly regulated sectors like financial services, digital assets, or high-tech ventures, you need a zone that’s “in sync” with your goals. 

Some free zones offer immediate access to like-minded businesses, giving you a front-row seat to industry connections. Others come with built-in regulatory support, helping you stay in the clear as you grow. And a few are designed for pure flexibility, letting you scale up without missing a beat.

Curious where your business would “click” best? It’s a fast read – let’s go.

What Exactly is a Freezone (and Why It Matters) 

Setting up a business in the UAE requires understanding a fundamental choice between mainland and freezone operations. 

Think of freezones as specialized business communities, each with its own character, costs, and focus industries. 

UAE freezones offer clear advantages: 

  • 100% foreign ownership
  • Zero corporate tax on most activities (for qualified income only)
  • Complete repatriation of capital and profits. 

Yes, there are 45+ UAE freezones across seven emirates, but choosing the right one becomes simple when you focus on what truly matters for your business.

💡 Related Blog: UAE UBO Check Guide

Picking Best UAE Freezone For Your Business

While freezones differ in dozens of ways, the 80/20 rule applies perfectly here – 80% of your success depends on just three critical factors. These are:

  • Your Business Activity – what you can and cannot do
  • Your Budget – beyond the advertised prices
  • Location Practicality – when it matters and when it doesn’t

Master these, and the rest becomes secondary. Let’s focus on what actually moves the needle for your business.

1. Your Business Activity 

Gone are the days when all free zones allowed everything. Your entire business model might need adjustment based on what’s permitted. 

While multiple freezones permit various financial and professional activities, only specific ones provide the robust frameworks and ecosystems needed for complex operations.

Some freezones operate under their own comprehensive regulations, offering frameworks based on English common law and housing complete business ecosystems. This becomes crucial when your operations involve regulated activities, digital assets, or innovative financial solutions. 

Business Activity Key Requirements Recommended Freezones Critical Considerations
Digital Assets & Trading Regulatory clarity, secure infrastructure ADGM, DIFC Licensing requirements, compliance framework
Investment Services Legal framework, market access DIFC, ADGM Capital requirements, regulatory oversight
Advisory Services Professional licensing, client access DIFC, DMCC, DAFZA Qualification requirements, scope limitations
Technology & Innovation Testing environment, modern infrastructure DIFC, ADGM, DIC Sandbox access, data regulations
Trading & Commodities Market connectivity, trading platforms DMCC, DAFZA Trading restrictions, reporting requirements

Beyond the basic license permissions, it’s crucial to understand how each freezone supports complex operations. 

While some offer regulatory sandboxes for testing new solutions, others provide established frameworks for traditional activities. The key is matching your operational needs with the freezone’s regulatory and infrastructural capabilities.

Here’s what to verify before choosing:

  • Specific activities permitted under your license type
  • Regulatory requirements and compliance frameworks
  • Access to necessary market infrastructure
  • Integration possibilities with local systems
  • Growth and expansion pathways

The cost implications can be significant but necessary – specialized freezones typically have higher setup and licensing fees. However, they provide the regulatory clarity and market access essential for sophisticated operations in the UAE.

2. Your Budget

When businesses compare UAE freezones, they often focus solely on license fees – which range from AED 10,000 to 50,000. But focusing only on these headline numbers misses the bigger picture. The real costs include registration fees (different for each freezone), legal documentation, and attestation (around AED 5,000).

Your essential first-year costs include:

  • Initial license and registration (Including regulatory fees)
  • Legal documentation and attestation
  • Pre-approval fees
  • Establishment card costs
  • Trade name registration
  • Initial visa processing
  • Basic facility setup

While many freezones advertise attractive first-year packages, the real test comes in year two when renewal costs often increase substantially. 

A realistic approach is to map out costs over three years. Here’s a practical framework: 

  • Year 1: Initial setup + operating costs 
  • Year 2: License renewal + expected growth costs 
  • Year 3: License renewal + expected growth costs + Factor in potential expansion needs

Facilities and Visas

Your choice of facility directly impacts how many people you can bring on board and how effectively your team can operate. 

  • A flexi-desk typically allows 2-3 visas in Dubai, while northern emirates tend to be more generous, making them cost-effective for staff-heavy operations. 
  • For physical offices, the standard ratio across Dubai freezones is one visa per 9-10 square meters.

A flexi-desk might cost AED 15,000-25,000 annually, while a small office of 200 square feet can exceed AED 50,000 per year. 

Larger spaces come with custom pricing structures. Your business type and growth plans should drive this decision – not just current budget constraints.

Other regular operational costs include:

  • Annual regulatory compliance costs
  • Bank minimum balance requirements (AED 10,000-50,000)
  • License and permit renewals
  • Facility maintenance and service charges
  • Visa quota management
  • Professional fees (audit, legal)
  • Technology and infrastructure costs

This longer view often reveals that the cheapest initial option isn’t always the most cost-effective.

3. Freezone Location 

Location only matters when it directly affects your money or operations. But when it matters, it matters significantly.

The real question isn’t “which is the best location?” but rather “what location features actually impact your business?”

Premium locations command premium prices – but does your business model justify the investment? 

For regulated activities and sophisticated operations, being in established financial districts provides proximity to regulators, access to specialized infrastructure, and integration into professional networks that could prove invaluable.

Other Tips on Picking Best Location

When picking a location, don’t forget to take advantage of (if any) connections you have in the free zones you’ve shortlisted. Current freezone tenants offer insights no brochure will mention. 

They know about the real response times from authorities, the hidden operational challenges, and the true benefits of different locations. Look for businesses similar to yours – their experiences often predict your own journey.

If you are still confused, start by looking at where your target clients are already doing business. If most of your potential clients are in one freezone, there’s often a good reason for it. The ecosystem benefits – from networking to business development – can outweigh pure cost considerations.

Other Factors

While the core factors determine your primary freezone choice, several secondary elements can significantly impact your long-term operations. These aren’t deal-breakers, but they can make the difference between smooth operations and constant friction.

Factor Why It Matters
Banking Relations Certain freezones (like DIFC, DMCC) have stronger banking relationships, making account opening smoother and international transactions more efficient. Critical for businesses handling frequent cross-border transactions.
Regulatory Support Quality and speed of regulatory assistance vary significantly. Premium freezones offer dedicated relationship managers, fast-track processing, and clear escalation pathways – crucial during operational challenges.
Technology Infrastructure Beyond basic internet, advanced freezones provide integrated regulatory reporting platforms, payment systems, and digital documentation processes. Impacts operational efficiency and compliance costs.
Business Ecosystem The presence of key service providers, quality talent pool, and industry peers can significantly reduce operational friction. Strong ecosystems often translate to better business opportunities and knowledge sharing.
Exit Options Different freezones have varying processes for restructuring, ownership changes, or license cancellation. Clean exit possibilities become crucial during strategic changes or market shifts.
Community Benefits Regular industry events, networking opportunities, and knowledge sharing initiatives can provide unexpected business development opportunities and market insights.
Market Access Some freezones provide better access to specific markets or industries through established networks and partnerships. Can significantly impact business development efforts.

 

After Picking Freezone in UAE – Next Steps

So you’ve picked your freezone – congratulations on clearing that first hurdle! But here’s where things get interesting, especially for financial institutions.

Setting up financial operations in the UAE means adapting to well-structured regulations that protect market quality. Each freezone has its own distinct framework designed to maintain the region’s high standards. 

While these robust regulations ensure market integrity, managing multiple compliance requirements across customer onboarding, transactions, and document verifications can be complex for growing institutions. Traditional manual processes, though thorough, often struggle to keep pace with UAE’s dynamic financial sector.

Signzy helps financial institutions streamline these challenges with automated KYC, business verification, and identity check solutions designed specifically for UAE freezone requirements. 

Frequently Asked Questions

  1. Does choosing a premium freezone like DIFC actually matter for financial operations? 

A: Yes. Premium freezones offer specialized regulatory frameworks, stronger banking relationships, and established financial ecosystems – crucial advantages that often justify higher costs.

  1. How long does the freezone setup process typically take? 

A: Standard setup takes 2-3 weeks. Regulated financial activities may require additional 2-4 weeks for specific approvals and licensing.

  1. Can financial institutions operate across multiple UAE freezones?

Yes, but each presence requires separate licensing and compliance frameworks. Most institutions start with one primary location for operational efficiency.

  1. Are there restrictions on changing freezones later? 

Yes. Moving between freezones requires new licensing and may affect existing permits. Strategic initial choice saves significant future costs.

1 2 3 4 26