Key takeaways at a glance

  • What it covers: India’s AML, CFT and CPF legal framework for all reporting entities, from financial institutions to DNFBPs and virtual digital asset service providers.
  • Governing laws: the PMLA 2002 and the PML (Maintenance of Records) Rules, 2005; Section 51A of the UAPA and Section 12A of the WMD Act for sanctions.
  • Authorities: the RBI, SEBI, IRDAI, IFSCA and notified authorities supervise their sectors; the Financial Intelligence Unit – India (FIU-IND) receives reports; the Enforcement Directorate (ED) enforces the PMLA.
  • Core duties: risk assessment, customer due diligence and beneficial-owner identification, monitoring and sanctions screening, prescribed reporting, five-year record-keeping, and appointed officers.
  • Find your rules: this is the national overview; follow the sector links to the detailed rulebook and supervisor that bind your business.

This guide is general information on Indian law, not legal advice. For your specific position, speak to a qualified AML professional.

India’s AML, CFT and CPF framework rests on the Prevention of Money Laundering Act, 2002 and the PML Rules, 2005, with sanctions duties under Section 51A of the UAPA and Section 12A of the WMD Act. Reporting entities, from banks and other financial institutions to DNFBPs and virtual digital asset service providers, must run an AML programme under the directions of their sector regulator (the RBI, SEBI, IRDAI, IFSCA or a notified authority), file reports with FIU-IND, and answer to the Enforcement Directorate for the offence of money laundering.

AML Laws and Regulations in India 2026

Use this page to understand India’s national AML, CFT, and CPF legal framework for all reporting entities. If you need the detailed rulebook for a particular sector or bank type, follow the sector links below rather than this overview.

India runs one of the world’s largest anti-money-laundering systems, built on a single parent statute and a web of rules, regulators and international standards. This guide explains the AML, CFT, and CPF laws and regulations in India: what money laundering is under the law, the architecture of the Prevention of Money Laundering Act, who counts as a reporting entity, which authorities supervise and enforce, and how the pieces fit together.

AML stands for anti-money laundering, CFT for countering the financing of terrorism, and CPF for counter-proliferation financing. This guide is the law. For the programme that turns these rules into day-to-day controls, read the companion guide, AML Compliance Requirements in India. This is the national, navigational overview: it stays broad and then routes you to the regulations for your sector, because the detailed rulebook and the supervisor differ between banks and other financial institutions, securities and insurance intermediaries, DNFBPs, and virtual digital asset service providers.

What is money laundering, and what do CFT and CPF mean?

Money laundering is the process of making the proceeds of crime look legitimate. The Prevention of Money Laundering Act, 2002 makes it an offence to deal with the proceeds of crime, including their concealment, possession, acquisition, use, and projecting or claiming them as untainted. Classically, laundering moves through three stages: placement, where illicit cash first enters the financial system; layering, where the funds are moved through transactions and accounts to disguise their origin; and integration, where the funds return to the economy as apparently legitimate wealth.

Counter-financing terrorism (CFT) is the duty to stop funds from reaching terrorism, and counter-proliferation financing (CPF) is the duty to stop funds from reaching the financing of weapons of mass destruction. India’s framework addresses all three.

Who is a reporting entity under the PMLA?

The PMLA places AML duties on reporting entities. A reporting entity is a business that the law requires to verify customers and to report certain transactions. The main groups are financial institutions, including banks and non-banking financial companies; securities market intermediaries, insurance entities and other intermediaries covered as reporting entities; persons carrying on a designated business or profession, including casinos or gaming businesses where notified, real estate agents, dealers in precious metals and stones, and other notified professional activities; and virtual digital asset service providers carrying out notified VDA activities.

Supervisory authorities for AML in India

Unlike a single-sector page, the national framework has several supervisors, each responsible for the entities it regulates. The reporting and enforcement bodies sit across all of them.

Authority

Main role

Reserve Bank of India (RBI)

Banks, NBFCs and RBI-regulated financial institutions.

SEBI

Securities market intermediaries.

IRDAI

Insurers and insurance intermediaries.

IFSCA

Entities in the International Financial Services Centre.

Notified authorities

Specified categories of DNFBPs, depending on the notification and sector (for example the Directorate General of Audit under CBIC for real estate agents).

FIU-IND

Receives, analyses and disseminates the reports that reporting entities file.

Enforcement Directorate (ED)

Investigates and prosecutes the offence of money laundering under the PMLA.

AML Regulatory Requirements in India

Read this framework as the national source map: the laws, rules, regulators and official instruments that sit across the whole AML, CFT and CPF regime, before you narrow to a sector.

The law does not sit in one place. It is a layered framework, and it helps to see it grouped under the source folders: the core legislation, the overarching obligations, the sectoral directions of the supervisors, the miscellaneous official reports, the international standards, and the allied laws. Each category below lists the instruments that apply, with a short note on what each one does.

The framework reads from the core outward. The PMLA is the parent Act; the PML Rules turn it into operating duties; each sector regulator translates both into directions for the entities it supervises; the UAPA and the WMD Act add the counter-terrorism and proliferation-financing sanctions; and the allied laws shape the predicate-offence risk. The risk-based approach is the thread that runs through it all.

Core Legislation

The primary statutes and rules that create the AML, CFT and CPF obligations are grouped into three sub-folders.

AML Legislation

Prevention of Money-Laundering Act, 2002 (PMLA)

The parent anti-money-laundering law. It creates the offence and the core duties on reporting entities, including customer due diligence under Section 11A and record-keeping under Section 12.

The PML (Maintenance of Records) Rules, 2005 (PMLR)

The rules made under the PMLA. They set what to report and when (Rule 3 and Rule 8), how to identify customers and beneficial owners (Rule 9), and the duty to appoint officers (Rule 7). The PMLR has been amended through 31 Gazette notifications and orders, listed below.

The 31 PMLR amendment notifications, in date order:

Gazette notification and date

Key change or rule touched

G.S.R. 389(E), 24 May 2007

Amendment to the PML Rules

G.S.R. 816(E), 12 November 2009

Amendment to the PML Rules

G.S.R. 76(E), 12 February 2010

Amendment to the PML Rules

G.S.R. 508(E), 16 June 2010

Rules 2, 9 and 10 (CDD and records)

G.S.R. 980(E), 16 December 2010

Amendment to the PML Rules

G.S.R. 481(E), 24 June 2011

Amendment to the PML Rules

G.S.R. 576(E), 27 August 2013

Rules 2 and 3 and after rule 10 (records and reporting)

G.S.R. 288(E), 15 April 2015

Rule 2 (definitions)

G.S.R. 544(E), 7 July 2015

Rules 2, 9 and 10 (CDD and records)

G.S.R. 730(E), 22 September 2015

Rules 2 and 7 (Principal Officer and procedure)

G.S.R. 882(E), 18 November 2015

Definitions and reporting

G.S.R. 347(E), 12 April 2017

Rules 2 and 9A (CKYCR)

G.S.R. 538(E), 1 June 2017

Rules 2 and 9 (Aadhaar and CDD)

G.S.R. 1038(E), 21 August 2017

Rule 2 (definitions)

G.S.R. 1318(E), 23 October 2017

Rule 2 (definitions)

G.S.R. 456(E), 16 May 2018

Definitions and CDD

G.S.R. 1078(E), 31 October 2018

Rule 9 (CDD)

G.S.R. 108(E), 13 February 2019

Rules 2 and 9 (definitions and CDD)

G.S.R. 381(E), 28 May 2019

Rule 9 (CDD)

G.S.R. 582(E), 19 August 2019

Rules 2 and 9 and after rule 11

G.S.R. 669(E), 18 September 2019

Rules 2 and 9 (CDD)

G.S.R. 840(E), 13 November 2019

Rule 9 (CDD)

G.S.R. 228(E), 31 March 2020

Definitions and reporting

G.S.R. 251(E), 13 April 2020

Rule 8 (reporting)

G.S.R. 254(E), 16 April 2020

Rule 8 (reporting)

G.S.R. 798(E), 28 December 2020

Rule 2: designation of DNFBPs, including real estate agents, as reporting entities

G.S.R. 575(E), 13 July 2022

IFSC definition and IFSC beneficial-owner provision; rule 9A IFSC proviso

S.O. 1074(E), 7 March 2023

Inserted the PEP, NPO and group definitions and rule 3A; cut the beneficial-ownership threshold to 10 percent for companies and in rule 9(3)(e)

G.S.R. 652(E), 4 September 2023

Principal Officer at management level; partnership beneficial-owner threshold cut to 10 percent; control Explanation; trust-trustee disclosure

G.S.R. 745(E), 17 October 2023

Rules 2, 3, 8 and 9 (definitions and reporting)

G.S.R. 419(E), 19 July 2024

Rewrote rule 9(1C) (the KYC Identifier); CKYCR update within seven days; rule 9A(2)(g) filing, retrieval and utilisation

The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005

Rules for accepting customer records authenticated outside India, relevant to non-resident and cross-border onboarding.

The Unlawful Activities (Prevention) Act, 1967 (UAPA)

The counter-terrorism law. Section 51A requires reporting entities to screen against designated lists and freeze the funds of listed persons, applied through the implementation procedure of 2 February 2021 and its corrigendum of 15 March 2023.

CPF Legislation

The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)

The proliferation-financing law. Section 12A extends targeted financial sanctions to the financing of weapons of mass destruction, applied through the implementation procedure of 1 September 2023 and the WMD Implementation Rules, 2016.

Overarching

National infrastructure that spans the framework to which every reporting entity connects.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

The Central KYC Records Registry stores customer KYC records centrally, enabling reporting entities to upload and reuse them consistently.

FINnet 2.0 / FINGate 2.0 reporting format and user manuals

The FIU-IND platform and current formats through which reporting entities enrol and file their reports.

Sectoral

The sector regulators and their directions. Each regulator issues its own KYC and AML directions for the entities it supervises; read the regulations guide for your sector for the directions that bind you.

RBI KYC Directions, 2025 (banks and NBFCs)

The RBI’s category-specific KYC and AML rulebook for the banks and finance companies it regulates.

SEBI directions (securities market intermediaries)

SEBI’s AML and KYC requirements for the intermediaries it regulates.

IRDAI directions (insurance)

IRDAI’s AML and KYC requirements for insurers and insurance intermediaries.

IFSCA directions (IFSC entities)

IFSCA’s AML and KYC requirements for entities in the International Financial Services Centre.

Notified-authority guidance (DNFBPs)

Sector guidance for designated non-financial businesses and professions, for example, the DGA AML/CFT/CPF Guidelines for Real Estate Agents, 2023.

Miscellaneous

Official reports and policy documents that inform how the system works and where the risks lie. They are not rules to comply with, but they shape the understanding of risk.

FIU-IND Annual Report 2024-25

Reports the volume of reports filed and FIU-IND’s supervisory and enforcement activity. In FY 2024-25, FIU-IND received more than 2 million reports per month and issued 8 compliance orders carrying penalties exceeding Rs 30 crore. The source for current reporting statistics.

Directorate of Enforcement Annual Report 2025-26

Records PMLA investigations, attachments and prosecutions by the Enforcement Directorate.

FIU-IND and its Core Functions and FAQs

An official explainer of what FIU-IND does and how reporting works.

National Risk Assessment and the MHA National Counter-Terrorism Policy and Strategy

India’s assessment of its money-laundering and terror-financing risks, and the national counter-terrorism policy that provides context for the CFT obligations.

International Standards

The global standards India’s framework implements and is measured against.

FATF Recommendations

The international AML, CFT and CPF standards that India’s laws implement.

FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)

The Financial Action Task Force assessment of India’s AML/CFT system. The 2024 evaluation found a good general understanding of risk in the financial sector, with preventive measures steadily progressing, and India’s 2022 National Risk Assessment identifies fraud, corruption and drug trafficking as the largest money-laundering risks.

Basel Committee, Sound Management of Risks Related to Money Laundering and Financing of Terrorism (2014, revised July 2020)

International supervisory guidance for banks on managing money-laundering and terror-financing risk.

FATF Risk-Based Approach Guidance

Guidance on applying the risk-based approach, which underpins the regulators’ expectations.

Allied Laws

These laws do not replace the PMLA, the PMLR or the regulators’ directions as the core AML framework. They shape predicate-offence risk, customer risk and suspicious-transaction indicators.

The Banking Regulation Act, 1949

The foundation of banking law and the source of the RBI’s power to issue the KYC Directions.

The Companies Act, 2013

Governs companies and their ownership disclosures, which matters for beneficial-owner checks on corporate customers.

The Foreign Exchange Management Act, 1999 (FEMA)

Governs foreign exchange, cross-border dealings and non-resident accounts.

The Benami Transactions (Prohibition) Act, 1988

Targets assets and accounts held in another person’s name to hide the real owner.

The Prevention of Corruption Act, 1988

Relevant where the proceeds of bribery and corruption move through the financial system.

The Narcotic Drugs and Psychotropic Substances Act, 1985 (NDPS)

Drug trafficking is a major predicate offence and source of laundered funds.

The Bharatiya Nyaya Sanhita, 2023

The criminal code that replaces the Indian Penal Code, 1860, and defines the predicate offences behind laundered funds.

The Bharatiya Nagarik Suraksha Sanhita, 2023

The Criminal Procedure Code replaces the Code of Criminal Procedure, 1973.

The Fugitive Economic Offenders Act, 2018; the Black Money Act, 2015; the FCRA, 2010; COFEPOSA, 1974; the Smugglers Forfeiture Act, 1976; the Arms Act, 1959; the Chemical Weapons Convention Act, 2000; and the Central Vigilance Commission Act, 2003

Further allied laws that shape predicate-offence risk and the wider enforcement framework.

Core AML/CFT/CPF obligations on reporting entities

Across that framework, the law requires a reporting entity to do the following. This guide states each duty at the level set by the law; the companion compliance guide explains how to carry each one out.

Assess your risk. Conduct a risk assessment of money-laundering, terror-financing and proliferation-financing risk across customers, products, geographies and channels, and put the outcome before the Board or senior management.

Know your customer. Identify and verify every customer under Section 11A of the PMLA and Rule 9 of the PMLR, with due diligence commensurate with the risk. For non-profit organisation customers, register the entity’s details on the NITI Aayog DARPAN Portal where required, and keep that record for 5 years after the relationship ends or the account is closed.

Find the real owner. Identify the beneficial owner behind a customer. For a company or partnership, the threshold is a controlling interest of more than 10 per cent; for an unincorporated association or body of individuals, it is more than 15 per cent; and for a trust, it covers the author, trustees, beneficiaries with a 10 per cent or more interest, and anyone exercising ultimate control.

Monitor and screen. Watch transactions on an ongoing basis and screen customers against the UAPA Section 51A and WMD Act Section 12A designated lists, freezing and reporting any match without delay. Verify the relevant UNSC and domestic designated lists daily and act on any additions, deletions, or other changes.

Report to FIU-IND. File the prescribed reports under Rule 3 and Rule 8 of the PMLR, where applicable: monthly reports, such as cash transaction reports and cross-border wire transfer reports, by the 15th of the succeeding month; suspicious transaction reports promptly once the Principal Officer is satisfied that the transaction is suspicious; and immovable property reports under Rule 3(F), where applicable, quarterly.

Keep records. Keep transaction records for five years from the date of the transaction, and identity records, account files and business correspondence for five years after the relationship ends or the account is closed, whichever is later, under Section 12 of the PMLA.

Appoint officers and govern. Appoint a Board-nominated Designated Director and a management-level Principal Officer under Rule 7 of the PMLR (the same person cannot hold both), train staff, and test the programme through independent testing and audit.

How the laws fit together

Taken together, these instruments are the AML, CFT and CPF laws and regulations in India. They form a ladder, each rung resting on the one below: the PMLA creates the offence and the obligation, the PML Rules explain CDD, record-keeping and reporting, each sector regulator turns those duties into detailed rules for its entities, FIU-IND receives and analyses the reports, the UAPA and the WMD Act impose sanctions duties, and the FATF Recommendations set the global benchmark. The table below maps each authority and instrument to its role.

Authority or instrument

Role

PMLA, 2002

The parent anti-money-laundering law. Creates the offence and the core reporting-entity duties.

PML (Maintenance of Records) Rules, 2005

Set out customer due diligence, beneficial ownership, record-keeping and reporting.

Sector regulators (RBI, SEBI, IRDAI, IFSCA, notified authorities)

Turn the PMLA duties into detailed directions for the entities each supervises.

FIU-IND

Receives, analyses and disseminates the reports reporting entities file.

Enforcement Directorate

Investigates and prosecutes the offence of money laundering under the PMLA.

UAPA Section 51A and WMD Act Section 12A

Impose counter-terrorism and proliferation-financing targeted financial sanctions.

FATF

Sets the international AML, CFT and CPF standards India is measured against.

Which sector are you in? Find your regulations guide.

The framework above applies nationally, but the detailed rulebook and the supervisor differ by sector. Use the links below for the laws and regulations guide for your sector.

Sector

Who it covers

Guide

Banks and financial institutions

Banks, NBFCs and other RBI-regulated institutions.

Read the guide

Securities market intermediaries

Stock brokers, mutual funds and other SEBI-regulated intermediaries.

Read the guide

Insurance

Insurers and insurance intermediaries under IRDAI.

Read the guide

DNFBPs

Real estate agents, dealers in precious metals and stones, and professionals.

Read the guide

IFSC entities

Entities in the International Financial Services Centre under IFSCA.

Read the guide

Virtual digital asset service providers

Businesses carrying out notified VDA activities.

Read the guide

From regulation to compliance: your next step

Knowing the law is step one. For the step-by-step programme these rules require, read the companion guide, AML Compliance Requirements in India. For the detailed rules that bind you, follow the link to your sector above.

Not sure which rules apply to your business?

Tell us what your business does and AML India will confirm your reporting-entity status, your supervisor and the directions that bind you, then map the programme you need.

Frequently Asked Questions

Money laundering is the process of making the proceeds of crime look legitimate. Under the Prevention of Money Laundering Act, 2002, it is an offence to deal with the proceeds of crime, including concealing, possessing, acquiring or using them, or projecting them as untainted. It typically moves through placement, layering and integration. The PMLA is the law that defines and punishes it.

The main law is the Prevention of Money Laundering Act, 2002, known as the PMLA. It creates the offence of money laundering and places core duties on reporting entities, supported by the PML (Maintenance of Records) Rules, 2005. Counter-terrorism and counter-proliferation sanctions come from the UAPA and the WMD Act. Together, these form the backbone of India’s AML, CFT and CPF framework.

There is no single AML regulator. The RBI supervises banks and NBFCs; SEBI supervises securities market intermediaries, IRDAI supervises insurance; and IFSCA supervises entities in the International Financial Services Centre, with notified authorities overseeing certain DNFBPs. The Financial Intelligence Unit – India receives and analyses reports, and the Enforcement Directorate enforces the PMLA. Which one applies depends on your sector.

A reporting entity is a business that the law requires to verify customers and report certain transactions. It includes financial institutions such as banks and NBFCs, securities and insurance intermediaries, persons carrying on a designated business or profession, such as real estate agents and dealers in precious metals, and virtual digital asset service providers carrying out notified activities. If your business is a reporting entity, the AML framework applies to you, and your sector guide carries the details.

The Financial Intelligence Unit – India is the national agency that receives, analyses and disseminates reports filed by reporting entities, such as cash transaction reports and suspicious transaction reports. It can also act against a reporting entity for reporting failures. Reports are filed through its FINnet 2.0 platform. It is the central hub of India’s AML reporting system.

The Enforcement Directorate, known as the ED, investigates and prosecutes the offence of money laundering under the PMLA. It can attach and confiscate the proceeds of crime and pursue prosecution in the designated courts. It is the criminal-enforcement arm of the framework, distinct from the regulators who supervise compliance and the FIU-IND, which receives intelligence.

AML (anti-money laundering) is about preventing the proceeds of crime from being laundered. CFT, countering the financing of terrorism, is about stopping funds from reaching terrorism. CPF, counter-proliferation financing, is about stopping funds from reaching the financing of weapons of mass destruction. India’s framework addresses all three, with sanctions duties under the UAPA and the WMD Act.

Targeted financial sanctions require screening of customers and transactions against designated lists and freezing matched funds without delay. The counter-terrorism duty flows from Section 51A of the UAPA and the counter-proliferation duty from Section 12A of the WMD Act. Reporting entities screen against the United Nations Security Council lists and the relevant domestic lists, then act on any match through a freeze-and-report workflow.

The Financial Action Task Force, or FATF, sets the international AML, CFT and CPF standards through its Recommendations. India is a member and implements those standards in its laws and regulatory directions. The FATF evaluated India in 2024 and found a good general understanding of risks while expecting preventive measures to keep improving. Its assessment shapes how India’s framework develops.

It depends on what your business does. Banks and NBFCs answer to the RBI, securities intermediaries to SEBI, insurers to IRDAI, and IFSC entities to IFSCA, while certain DNFBPs sit under notified authorities. All of them report to FIU-IND and are exposed to enforcement by the ED. Follow the link to your sector to see the rules and the supervisor that apply to you.

Primary sources relied upon

Prevention of Money-Laundering Act, 2002; the PML (Maintenance of Records) Rules, 2005; the applicable sector-regulator KYC Directions, 2025 (RBI, SEBI, IRDAI, IFSCA and notified-authority guidance); Section 51A of the UAPA and Section 12A of the WMD Act with their implementation procedures; the FATF Recommendations and the FATF Mutual Evaluation Report on India, 2024; and the FIU-IND Annual Report 2024-25. Link each to its official source before publishing.

Official sources and review

Why work with AML India

AML India helps reporting entities of every kind meet their PMLA obligations, from risk assessment and policy through to CDD, screening, monitoring, reporting, training, software selection and independent review. Industries we serve: banks and financial institutions, insurance companies, securities intermediaries, payments and fintech businesses, real estate agents, dealers in precious metals and stones, virtual asset service providers, and IFSC and GIFT City entities.
“We are thrilled to have AML India as our compliance partner. Their consultants have immense knowledge in executing the right KYC and CDD processes for our business, and made it easy to onboard new customers without the fear of money-laundering risks.” General Manager, Financial Company

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik