AML policy, controls and procedures: at a glance
- What: the approved document that turns the law and the risk assessment into the rules a reporting entity actually follows, with the controls and procedures that deliver them.
- Why: it is the operating manual auditors and supervisors test the programme against; a generic or stale policy undermines everything built on it.
- How: derive it from the internal risk assessment and cover customer acceptance, due diligence, monitoring, reporting, records and training.
- When: approved by the Board or the management that takes significant decisions, and reviewed regularly and on any material change.
This guide is general information on Indian law, not legal advice. For your own policy, speak to a qualified AML professional.
An AML policy, controls, and procedures document is the written framework, approved at the level required by the applicable sector framework, that translates the PMLA, the PML Rules, and the reporting entity’s own risk assessment into practical rules, controls, and step-by-step procedures for its people to follow. For banks, the RBI KYC Directions require a KYC policy built around four key elements: a Customer Acceptance Policy, Risk Management, Customer Identification Procedures and Monitoring of Transactions. It must be approved at the level required by the framework, built on the risk assessment, and kept current. It is the first document a supervisor reads.
AML Policy, Controls and Procedures in India
The AML policy is the document against which a reporting entity is tested. It is the operating manual that turns the law and the entity’s risk assessment into rules its people actually follow, and it is the first thing an inspector reads. This guide explains the AML policy in India in depth: the legal duty to have one, the four key elements it must contain, what it must cover, how to build it from the risk assessment, the governance around it, and how the requirement differs by sector.
It is a cross-sector deep-dive. It sits within the wider AML compliance requirements in India and builds directly on the internal risk assessment (IRA/EWRA) in India, which is where every good policy starts. A policy copied from a template, or written once and left on the shelf, is the most common reason programmes fail at inspection. A real policy is built from the entity’s own risk, approved at the top, and kept alive.
Key takeaways
- An AML policy in India translates the PMLA, the PML Rules, the sector directions and the entity’s own risk assessment into practical rules its people can follow.
- For banks, the KYC policy must cover the four key elements: a Customer Acceptance Policy, Risk Management, Customer Identification Procedures and Monitoring of Transactions.
- Across sectors, approval sits where the framework requires it: the Board, the governing body, the partners, the proprietor, or senior management, as applicable.
- A defensible policy covers customer due diligence, enhanced due diligence, beneficial ownership, ongoing monitoring, STR and CTR reporting, record keeping, targeted financial sanctions, training, audit and review.
- The policy should be version-controlled, reviewed on a set of triggers, and supported by evidence that it is approved, implemented, and followed.
The scale of the obligation: statistics
The policy is where supervisory attention lands first, because it is the reference against which the rest of the programme is judged. In FY 2024-25, FIU-IND continued to receive a high volume of prescribed reports and to act on non-compliance through compliance orders and monetary penalties (FIU-IND Annual Report 2024-25). The Financial Action Task Force evaluated India in 2024 and found a good general understanding of financial sector risks, while expecting preventive measures to continue improving (FATF Mutual Evaluation Report on India, 2024). That evaluation also found that India’s main money-laundering risks arise primarily from fraud, including cyber-enabled fraud, corruption and drug trafficking.
“A template can help with structure, but it cannot replace the entity’s own risk assessment. A defensible policy must explain the business, the risks and the controls in the entity’s own context.”
Jyoti Maheshwari, AML and compliance specialist
Who does this requirement apply to
Applies to | All reporting entities under the PMLA: banks, NBFCs and other financial institutions, securities and insurance intermediaries, DNFBPs and the notified professions, and VDA service providers. |
Does not apply to | Persons who are not reporting entities under the PMLA. |
What are the AML policy, controls and procedures?
An AML policy is the written framework that sets out how a reporting entity meets its anti-money-laundering, counter-terrorist financing and counter-proliferation-financing duties. The phrase policy, controls and procedures captures three layers: the policy states what the entity will do and why; the controls are the mechanisms that deliver it, such as screening and monitoring; and the procedures are the step-by-step instructions staff follow at the counter and the desk.
It is not a compliance ornament. The policy is where the risk-based approach becomes operational: it records the decisions an entity has made about who it will accept, how hard it will look, and what it will do when something is wrong. Because it is the reference, an entity can show a supervisor, a weak or generic policy undermines everything built on it. At the same time, a strong one makes the whole programme coherent and defensible. The three layers, with the evidence that proves them, sit together like this.
Layer | What it is | Evidence |
Policy | What the entity will do and why, at the approval level required by the applicable framework. | Approved policy document plus the minutes of the approving body (Board, governing body, partners, proprietor or senior management). |
Controls | The mechanisms that deliver the policy, such as screening, monitoring and CDD. | System configuration and control-testing results. |
Procedures | The step-by-step instructions staff follow at the counter and the desk. | SOPs, work instructions and training records. |
The legal requirement in India
The duty to have a written, approved AML policy runs through the framework, with the binding rule in the sector directions and the foundation in the PML Rules. For banks, the RBI (Commercial Banks – Know Your Customer) Directions, 2025, dated 28 November 2025, require banks to have a KYC policy that the Board, or a committee to which the Board has delegated authority, duly approves. The directions also require a risk-based approach with Board-approved policies, controls, and procedures, and ensure compliance through senior management, independent evaluation, and a concurrent or internal audit that reports to the Audit Committee.
The foundation is set out in the PML Rules. They require every reporting entity to appoint a Principal Officer and a Designated Director, to communicate the Principal Officer to the Director, FIU-IND, and to evolve an internal mechanism for detecting and furnishing the prescribed transactions under Rule 7, with the Designated Director responsible for overall compliance under Chapter IV of the PMLA and the Rules. Comparable obligations are generally set out in the applicable regulator, supervisor or FIU framework for other sectors, although the approval route, format and level of prescription differ.
Mapping each policy area to its legal source
A defensible policy maps every area back to the rule it satisfies so that an inspector can trace each control to its source. The table below links the main policy areas to the provisions behind them and the evidence that supports them.
Policy area | Source to map against | Evidence |
Risk assessment | PML Rules, Rule 9(13) | Internal risk assessment (IRA/EWRA) report |
Customer due diligence programme | PML Rules, Rule 9(14) | Approved policies, controls and procedures |
Reporting mechanism | PML Rules, Rules 7 and 8 | STR and CTR logs and FIU-IND acknowledgements |
Group-wide programme | PML Rules, Rule 3A | Group policy and information-sharing controls |
Record keeping | PML Rules, Rules 3, 4, 5 and 10 | Retention schedule and retrieval evidence |
KYC policy for banks | RBI KYC Directions, 2025 | Board-approved KYC policy and minutes |
Targeted financial sanctions | UAPA, the WMD Act and sector directions | Screening, freeze and reporting records |
Essential elements of an AML policy, controls and procedures manual
An AML policy manual is built from eight essential elements, each tracing back to a specific obligation. The map below shows them at a glance.
Risk Identification
- Internal inputs, external factors, and ML/TF/PF trends and typologies considered for risk identification
- Identified ML/TF/PF Risk vs Management’s risk appetite
- Likelihood of occurrence, timing, and impact
Risk identification is the first stage of the risk-based approach and the foundation on which the rest of the policy rests. The entity should look across its customers, products, services, delivery channels, and geographies, drawing on internal data and external sources, including FATF typologies, FIU-IND advisories, and India’s national and sectoral risk assessments. Each risk is weighed against the entity’s approved risk appetite and scored for its likelihood and potential impact, so the policy can direct effort to where it matters most. The PML Rules require that this assessment be carried out and kept up to date under sub-rule (13) of Rule 9.
Risk Mitigation
- Risk rating methodologies, classification and prioritisation of the risk
- ML/TF/PF control measures
Once the risks are identified, the policy sets out how they are rated and brought under control. A documented rating methodology classifies each customer, product, channel and geography, usually as low, medium or high, and prioritises them so resources follow the exposure. The control measures are then sized to the rating: standard customer due diligence and routine monitoring for lower risk, and enhanced due diligence, closer monitoring and senior sign-off for higher risk. Each control should trace back to a specific identified risk, so a supervisor can see why it is there.
Customer Onboarding
- KYC, Screening and Risk Profiling
- Documentation to be obtained and verified
- Ongoing monitoring policy: Review and update of CDD information
- Customer Acceptance and Exit Policy
Onboarding is where the policy meets the customer, and it carries the four key elements the RBI Directions require: customer acceptance, risk management, customer identification and ongoing monitoring. Before a relationship begins, the entity verifies identity, identifies the beneficial owner, screens against sanctions and PEP lists, and assigns a risk profile that sets how much diligence applies. The policy states which documents to obtain and verify, the cadence for refreshing CDD information as the relationship progresses, and the grounds and process for declining or exiting a customer who falls outside the acceptance criteria.
Suspicious Transactions
- What are the red flags
- Policy for updating red flags
- Internal mechanism for identification, reporting and investigation of suspicious transactions
- Results of internal analysis, decision and rationale behind the decision
The policy must give staff a clear path to recognise, escalate and act on suspicion. It sets out the red flags relevant to the entity’s business, keeps them current as new typologies emerge, and describes the internal mechanism that carries an alert from the front line to the Principal Officer for investigation, as required under Rule 7 of the PML Rules. Every decision, whether to file a report or close the alert, should be documented with the analysis and reasoning behind it, so the entity can later show a supervisor how it reached its conclusion.
Reporting
- Log of internal investigation done
- Policy around tipping off
- Regulatory reporting with FIU-IND
Reporting turns a confirmed suspicion into a filing. The policy specifies who files the prescribed reports with FIU-IND, including Suspicious Transaction Reports and Cash Transaction Reports, and the channel through which they are submitted. It sets the timelines: Cash Transaction Reports by the 15th day of the succeeding month, and Suspicious Transaction Reports promptly and, as reflected in FIU-IND’s reporting guidance, no later than seven working days after the Principal Officer is satisfied that a transaction is suspicious. It keeps a log of each internal investigation that leads to a report, or to a documented decision not to report, and it states the prohibition on tipping off, so a customer is never made aware that a report has been made or is being considered.
Record Keeping
- What records are to be maintained about AML/CFT
- The format for data maintenance, time period, access rights, etc.
- Archival & disposal policy
The policy fixes what records are kept, in what form, for how long, and who may see them. It should cover records of customer identity and due diligence, and records of transactions, both of which must be capable of being produced to the authorities and used to reconstruct an individual transaction when asked. It sets the retention period required under the PMLA and the PML Rules, the access controls that protect the records, and a defined archival and disposal process once the retention period ends. The exact manner, form and access controls should follow the applicable regulator’s directions.
Governance
- Compliance Officer’s roles & responsibilities
- Employees’ training and development
- Senior management’s roles & responsibilities
- Independent Audit function
Governance fixes accountability for the policy. It records the appointment of the Principal Officer and the Designated Director under the PML framework, the communication of Principal Officer details to FIU-IND, and the approval of the policy at the level required by the applicable framework. It assigns senior management responsibility for implementation, provides for role-based training so staff can apply the policy in practice, and establishes an independent evaluation of the compliance function and a concurrent or internal audit that submits quarterly audit notes to the Audit Committee. Setting these roles along the three lines of defence, with the business owning its risk, compliance setting and monitoring the rules, and internal audit testing the whole, keeps ownership and assurance separate and documented. A simple RACI, naming who is responsible, accountable, consulted and informed for each control, turns that into something an inspector can follow.
Targeted Financial Sanctions
- TFS and other International Sanctions
- Sanctions screening and Alert Management
- Reporting requirement
The policy must build in India’s targeted financial sanctions obligations. The entity screens its customers and transactions against the UNSC consolidated list and the lists designated under the Unlawful Activities (Prevention) Act, as applicable under the Indian targeted financial sanctions framework and the entity’s sector directions, and, on a confirmed match, freezes the funds without delay and reports the match to the designated authority. The policy sets out how screening alerts are generated, managed, and cleared; how often the lists are refreshed; and how records are kept of each alert and its disposition, so screening is demonstrable and not merely switched on.
Need a board-ready policy mapped to every rule?
A real policy maps each clause to the PMLA rule or regulator direction it satisfies. AML India writes and reviews policies built from your own risk and ready for inspection.
What an anti money laundering policy must contain
An anti money laundering policy is the written backbone of a reporting entity’s compliance, required in substance by Section 12 of the PMLA and the PML (Maintenance of Records) Rules, 2005. A complete AML and CFT policy sets out the entity’s risk appetite, the customer due diligence and enhanced due diligence it will perform, its approach to beneficial ownership, ongoing monitoring, sanctions screening, record keeping and reporting to FIU-IND. It names the Principal Officer and the Designated Director and defines their authority. In short, the anti money laundering policy in India is where the law’s obligations become the entity’s own written rules.
From policy to AML CFT procedures
A policy states intent; the AML CFT procedures make it operational. Good aml policies, controls and procedures break each obligation into a step a staff member can follow: how to verify identity, when to escalate to the Principal Officer, how to file a suspicious transaction report on the FINGate 2.0 portal, and how long to retain records, which is five years under Rule 10. The controls layer sits between the two, the checks and maker checker approvals that make sure the procedures are actually followed. Together the aml cft policies and procedures form the anti money laundering compliance program that an inspection will test.
Keeping a simple anti money laundering policy proportionate
A simple anti money laundering policy is not a thin one, it is a proportionate one. A smaller reporting entity can meet the law with a concise AML and CFT policy that still covers every required element, sized to its risk profile rather than copied from a large bank. The test is whether the policy and its procedures address the entity’s actual customers, products and geographies, and whether staff can apply them. Reviewing and updating the aml procedures when the business or the law changes keeps the programme current and defensible.
How to draft an AML policy, step by step
A usable policy is built in a logical order, with each step feeding the next. The structure of the drafting process also makes a clean table of contents for the document itself.
- Start from the business and its risk assessment, and define the policy’s scope, applicability and key terms.
- Translate the risk findings into the CDD, EDD and monitoring rules, the escalation route to the Principal Officer, and the reporting to FIU-IND.
- Set the governance and accountability, the training, the review cadence and triggers, and the record-keeping and retention.
How to build the policy from your risk assessment
A policy is only defensible if it is built on the entity’s own risk. The PML Rules require a reporting entity to carry out and keep up to date a risk assessment under sub-rule (13) of Rule 9. The policy should operationalise the controls that the assessment calls for. For the assessment that should drive it, see the internal risk assessment (IRA/EWRA) in India.
Is there a gap between your policy and your practice?
The fastest inspection finding is a policy that no longer matches how you operate. An AML health check measures policy against practice and gives you a prioritised plan to close the gap.
Group-wide policies and overseas branches
Where a reporting entity is part of a group, the PML Rules, reflected in paragraph 8 of the RBI KYC Directions for banks, require group-wide programmes against money laundering and terror financing, including group-wide policies for sharing the information needed for customer due diligence and risk management. Those programmes must include adequate safeguards for the confidentiality and use of the information exchanged, including safeguards to prevent tipping off. For a banking group with branches or subsidiaries, the policy must be consistent across the group while remaining proportionate to each entity’s operations. A smaller or cooperative entity sizes its policy to its own operations rather than copying a large institution’s.
Keeping the policy current: review and change control
A policy drifts out of date the moment the business or the law changes, so it must be reviewed regularly and in response to triggers. Each version should be approved, dated and kept under change control, with a change log. An amendment to the PMLA should trigger a review, the PML Rules or the sector regulator’s directions; a change in the entity’s risk exposure, such as a new product, service, customer segment or geography; a new typology or a public statement from the FATF or FIU-IND; a change in the monitoring or screening systems or their configuration; or adverse findings from an inspection or an independent testing and audit. The fastest finding at an inspection is a policy last reviewed years ago, or one that no longer matches how the entity actually operates.
AML/CFT Policy and Procedure Documentation Methodology
A policy that survives inspection is documented from the entity’s own facts, not lifted from a template. AML India uses a fixed set of five inputs for each policy and procedure, so the final manual reflects how the business actually runs.
Nature and Size of Business
The starting point is the entity itself: its products and services, customer base, delivery channels, geographies and transaction volumes. A single-branch cooperative and a multi-state NBFC require policies of very different depths, so the documentation is tailored to the operation rather than to a generic standard.
Compliance Officer's Inputs
The Principal Officer and the compliance function bring what no template can: recurring alerts, onboarding frictions, typologies observed in practice, and gaps an inspection might find. Their inputs ground the policy in the entity’s lived experience.
Results of EWRA
The enterprise-wide risk assessment sets the risk picture that the policy must address. Each rated risk drives a corresponding control, so the policy can explain why a measure exists and why it is sized as it is.
Existing Controls, if any
Where the entity already runs systems, procedures or screening tools, the documentation formalises and tightens them rather than starting from scratch. Mapping what exists shows what to keep, what to fix and what to build.
Applicable AML/CFT/CPF laws
Finally, the policy is written against the binding instruments: the PMLA, the PML Rules and the sector regulator’s directions, together with the targeted financial sanctions framework under the UAPA and the WMD Act. Each clause is mapped to the provision it satisfies.
Risk factors that shape the policy
How much the policy has to carry depends on a few factors that should be read from the risk assessment.
- The complexity of products and the customer base determines how detailed the acceptance and due diligence rules must be.
- Group structure and overseas operations, which trigger the group-wide policy and information-sharing safeguards.
- Maturity of the existing control environment, which determines how much the policy must build versus formalise.
What a strong AML policy looks like
A strong policy is one that a supervisor cannot fault. It helps to know the warning signs of a weak policy, to check yours against a completeness checklist, and to apply the few practices that keep it usable.
Red flags of a weak policy
Supervisors test the policy early, so it is worth knowing the warning signs of a weak one. Each should trigger a rebuild.
- A template not built from the entity’s own risk assessment.
- No clear customer acceptance criteria, or no escalation route to the Principal Officer.
- A policy never approved, or last reviewed years ago, with no change log.
- A policy that does not align with how the entity actually onboards and transacts.
The AML policy checklist
Use this to keep the policy complete and inspection-ready.
- Board or committee approval recorded, and the policy built from the risk assessment.
- The four key elements covered are acceptance, risk management, identification, and monitoring.
- Customer due diligence, risk categorisation, and beneficial ownership rules are set out.
- Monitoring, escalation to the Principal Officer, reporting and timelines covered.
- Record-keeping, sanctions screening, training and group-wide controls included.
- A review cadence and a change log to keep the policy up to date.
Best practices for a usable, audit-ready policy
- Build the policy around the real workflow, then document it, so it matches practice.
- Keep procedures usable at the counter, not just at head office.
- Tie the policy to training, so it becomes staff behaviour rather than a shelf document.
“Map every clause to the rule it satisfies. When an inspector asks why a control exists, the answer should be a paragraph number in the directions, not an opinion. That single discipline turns a policy from a wish list into evidence.”
Pathik Shah, FCA, CAMS, CISA, CS, DISA, FAFD
How the policy differs by sector
Every reporting entity should maintain documented AML/CFT policies, controls and procedures appropriate to its sector, risk profile and governing framework. The approval route differs: banks typically require Board or Board-committee approval, while other sectors may require approval from the governing body, partners, the proprietor or senior management.
Sector | Framework and approval route | Approver |
Commercial banks | RBI Commercial Banks KYC Directions, 2025; KYC policy with the four key elements, assured by senior management and audit. | Board or Board committee |
NBFCs | RBI category-specific KYC Directions for NBFCs; policy, controls and procedures proportionate to risk and business size. | Board or committee, as applicable |
Insurance | IRDAI Master Guidelines; intermediaries bound by contract; annual compliance certificate within 45 days of year end. | Insurer’s Board |
Securities | SEBI AML and CFT framework; KYC ecosystem built around the KYC Registration Agencies. | Board or AMC and trustees |
Pension | PFRDA guidelines; a bank as point of presence may fold the NPS into its existing RBI board-approved policy. | Board or management |
DNFBPs | DGA AML/CFT/CPF guidance; an AML programme with policies approved by senior management, partners or proprietor. | Senior management |
Professions (CA, CS, CMA) | Joint ICAI, ICSI and ICMAI guidelines; a firm approves through its governing body or partners; a sole practitioner is his own Principal Officer. | Governing body or partners |
VDA service providers | FIU-IND AML/CFT guidelines for VDA providers; tailored to wallet, transfer, custody, exchange and analytics risks. | Senior management |
IFSC entities | IFSCA AML, CFT and KYC framework; adapted to the licensed activity. | Governing body or committee |
How the policy connects to the rest of the programme
The policy is the hinge of the programme. It is built on the internal risk assessment and sets the rules for customer due diligence and KYC, ongoing monitoring, regulatory reporting, and training and awareness. To see the whole programme the policy organises, return to AML compliance requirements in India.
Documents to keep as evidence of your AML policy
A policy is judged by what proves it, not just by what it says. Keep the records below so the entity can show at any inspection that the policy is approved, implemented, reviewed, and followed.
Evidence | Why it matters |
Approved AML and KYC policy | Proves the framework is in place |
Board or senior-management minutes | Shows formal approval at the right level |
Version history and change log | Shows the policy is kept current |
Internal risk assessment | Shows the policy is risk-based |
SOPs and work instructions | Show operational implementation |
Training records | Show staff awareness |
Screening and monitoring logs | Show the controls are operating |
Internal investigation and FIU-IND reporting logs | Show reporting discipline |
Audit and testing reports | Show independent assurance |
Remediation tracker | Shows findings are fixed |
Not sure which rules apply to your business?
Tell us what your business does and AML India will confirm your reporting-entity status, your supervisor and the directions that bind you, then map the programme you need.
Frequently Asked Questions
An AML policy is the written, approved document that translates the PMLA, the PML Rules, and a reporting entity’s risk assessment into the rules, controls, and procedures it follows. It must be approved at the level required by the applicable framework and built from the entity’s documented risk assessment. It is the document against which a supervisor tests the programme.
Yes. For banks, the RBI Commercial Banks KYC Directions, 2025 require the KYC policy to be approved by the Board or a Board committee. The duty rests on the PMLA and the PML Rules: Rule 7 requires an internal mechanism for detecting and furnishing prescribed transactions to FIU-IND. At the same time, the Client Due Diligence Programme under Rule 9 must include policies, controls and procedures approved by senior management. Other sectors carry the same duty under their own regulator, with the policy approved by the Board or the management that takes significant decisions. An inspector will expect to see an approved, current policy.
Under the RBI KYC Directions, the four key elements are the Customer Acceptance Policy, which sets who the entity will accept and on what terms; Risk Management, which is how it categorises customers by risk and sizes controls; Customer Identification Procedures, which is how it identifies and verifies customers and beneficial owners; and Monitoring of Transactions, which is how it watches activity and reports the suspicious. Together, they form the spine of the policy, and any reporting entity can use the same structure.
A complete policy covers customer acceptance, customer due diligence and KYC, the risk categorisation of customers, beneficial ownership, ongoing monitoring and periodic updation, the escalation route to the Principal Officer, reporting to FIU-IND and the timelines, record-keeping, sanctions screening, training and, for a group, the group-wide programme. It should also name the roles and responsibilities. The aim is for every legal duty to have a documented home and an owner.
For banks, the Board or a Board committee with delegated power approves the KYC policy. Senior management is responsible for implementation, with an independent evaluation and a concurrent or internal audit that reports to the Audit Committee. Across sectors, the approver is either the Board or management, depending on the entity. The Principal Officer owns the day-to-day operation of the policy, and the Designated Director carries overall responsibility.
Yes, and this is where most policies fail. The risk-based approach requires controls to be sized to risk, so the policy must flow from the internal risk assessment. A policy that is not traceable to a risk assessment is the classic template that an inspector spots immediately. Assess risk first, then write the policy from it, and make the link explicit.
Yes. The PML Rules require a group to implement group-wide programmes against money laundering and terror financing, including group-wide policies for sharing information needed for customer due diligence and risk management, with safeguards against tipping off. For a banking group with branches or subsidiaries, the policy must be consistent across the group while remaining proportionate to each entity. A standalone or smaller entity sizes its policy to its own operations.
The policy should be reviewed regularly and whenever something significant changes, such as a new product, a new channel, a regulatory change or a major typology. Each version should be approved, dated and kept under change control, with a change log. The most common inspection finding is a policy that was last reviewed years ago or that no longer aligns with practice.
A policy states what the entity will do and why, at the level approved under the applicable framework. A procedure is the step-by-step instruction that staff follow to deliver it, such as how to complete customer due diligence or act on a sanctions match. The controls sit between them, as the mechanisms that make the policy work. A good programme has all three aligned, so the policy is not just a statement but something the front line can actually follow.
The need for documented AML/CFT policies, controls and procedures is common across sectors, but the governing instrument, approval route and level of prescription differ. Banks follow the RBI KYC Directions with Board approval and four key elements; insurers follow IRDAI with Board approval and an annual compliance certificate; securities intermediaries follow SEBI’s AML framework; pension entities follow PFRDA; DNFBPs follow the DGA guidance with senior-management approval; VDA providers follow the FIU-IND VDA framework; IFSC entities follow the IFSCA framework; and the professions follow the ICAI, ICSI and ICMAI guidelines. The mechanism is shared; the framework is sector-specific.
Keep the records that prove the policy is real, not just written: the Board or committee approval and the minutes, the version history and change log, the risk assessment the policy was built from, training records, internal and concurrent audit reports, control-testing results, breach or incident logs, and the FIU-IND reporting records. Together, these show the policy is approved, implemented, reviewed and followed.
A template can be a starting point, but it must be tailored before it is fit for use. The policy has to reflect the entity’s own risk assessment, its products and customers, its geographies and delivery channels, and its specific reporting obligations. Use a template to save time on structure, then make it the entity’s own.
An anti money laundering policy should cover risk assessment and risk appetite, customer due diligence and enhanced due diligence, beneficial ownership identification, ongoing monitoring, sanctions screening, record keeping for five years, and reporting to FIU-IND. It should name the Principal Officer and Designated Director and set out training. These elements follow from Section 12 of the PMLA and the PML (Maintenance of Records) Rules, 2005.
The AML policy states what the entity will do and why, its risk appetite and its commitments. The AML procedures state how staff actually do it, step by step, and the controls check that they do. Together the aml policies, controls and procedures make up the anti money laundering compliance program required under the PMLA.
Yes. A simple anti money laundering policy is acceptable as long as it is proportionate to the entity’s risk and still covers every required element: due diligence, monitoring, reporting, record keeping and governance. It should be tailored to the entity’s real customers and products rather than copied wholesale, and reviewed when the business or the law changes.
Official sources and review
This guide is grounded in the following primary official sources, linked to their official source where available.
- Prevention of Money-laundering Act, 2002 (India Code)
- Prevention of Money-laundering (Maintenance of Records) Rules, 2005 (India Code)
- RBI category-specific Know Your Customer Directions, 2025
- FATF Recommendations, including the June 2026 update to Recommendation 6, which supports humanitarian activities and requires compliance with the humanitarian exemptions in UN Security Council Resolutions 2664, 2761 and 2615
- Financial Intelligence Unit – India, including the Annual Report 2024-25
Why work with AML India
AML India writes and reviews AML policies that hold up at inspection, built from the entity’s own risk and mapped to the directions that bind it. The team is practitioner-led and risk-based, and every position is checked against the source instrument and signed off by a named expert.
Case study A reporting entity failed an inspection on a policy that was an unedited template, with no link to any risk assessment and no change log. AML India rebuilt it from the entity’s own risk, mapped each clause to the rule it satisfied, added a customer acceptance policy and an escalation route, and put it under version control. The re-inspection accepted the policy with no major findings. “It finally reads like our business, and every line has a reason behind it.” Compliance head, regulated reporting entity |
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik