What a commercial bank must do: at a glance
- Register and govern: enrol with FIU-IND on the FINnet 2.0 portal and appoint a Board-nominated Designated Director and a management-level Principal Officer.
- Assess risk: run an internal risk assessment (also called the enterprise-wide risk assessment) and put it before the Board.
- Document and identify: adopt board-approved AML policies, then do customer due diligence and KYC and identify the beneficial owner (a controlling interest of more than 10 percent).
- Monitor and screen: keep KYC current through periodic updation (2, 8 and 10 years by risk), monitor transactions, and screen against sanctions lists.
- Report, keep, train, test: file CTRs, STRs and CBWTRs with FIU-IND on time, keep records for five years, train staff, and test the programme through internal audit, compliance assurance or independent review.
This article is general information about AML compliance in India, not legal advice. For your bank’s specific position, speak to a qualified AML professional.
A commercial bank in India becomes AML compliant by building and running a connected programme, in order: enrol with FIU-IND and appoint a Designated Director and a Principal Officer, complete an internal risk assessment, write and adopt board-approved policies, then run KYC and customer due diligence, ongoing monitoring, sanctions screening and reporting, supported by record-keeping, training and independent testing.
Last reviewed: June 2026.
AML Compliance Requirements for Commercial Banks in India
Commercial banks carry one of the heaviest AML compliance workloads in India because a significant share of laundered money can pass through the banking system at some point. Meeting the law is not a one-time project. It is a programme that a bank builds, runs, and proves year after year to the Reserve Bank of India and the Financial Intelligence Unit – India.
This guide sets out the AML compliance requirements for commercial banks in India as a practical, step-by-step programme: registering with FIU-IND, appointing officers, assessing risk, writing policies, doing KYC and customer due diligence, screening, monitoring, reporting, training, record-keeping and independent testing. It is the how-to. For the law behind each duty, read the companion guide, AML Laws and Regulations for Commercial Banks in India.
This article sits under AML Compliance Requirements for the Banking Sector in India, and within the wider AML Compliance Requirements in India. For banks, the RBI is the AML/CFT supervisor; the FIU-IND receives and analyses prescribed reports and enforces reporting compliance; and the Enforcement Directorate investigates and enforces against money-laundering offences under the PMLA.
Who this guide is for, and who it is not for
Use this guide if you are | Do not use this guide if you are |
A public sector commercial bank | A small finance bank |
A private sector commercial bank | A payments bank |
A foreign bank operating in India | A local area bank |
A scheduled or non-scheduled commercial bank | A regional rural bank, or an urban or rural cooperative bank |
Sector challenges for commercial banks
Commercial banks face one of the widest ranges of money-laundering risks among reporting entities, and the compliance load reflects that. The main challenges are the sheer volume and speed of transactions; complex corporate and trust ownership that hides beneficial owners; correspondent banking and cross-border flows that import another institution’s risk; exposure to politically exposed persons; and the constant arrival of new digital channels and products that create fresh typologies.
On top of this, the rulebook itself moved with the RBI’s consolidated Master Directions of 28 November 2025, so many banks are updating policies, training and systems built on the withdrawn 2016 Master Direction. Staying current and keeping the programme connected rather than running in silos is the real test.
The scale of the obligation: statistics
In FY 2024-25, FIU-IND received more than 2 million reports per month and issued 8 compliance orders with penalties exceeding Rs 30 crore (FIU-IND Annual Report 2024-25). The Financial Action Task Force, which evaluated India in 2024, found a good general understanding of financial sector risks but expects preventive measures to continue improving (FATF Mutual Evaluation Report on India, 2024). India’s 2022 National Risk Assessment, as summarised by the FATF, points to fraud, corruption and drug trafficking as the largest sources of laundered funds, all of which move through banks. A strong, evidence-based programme is the only reliable defence.
“In a bank, the beneficial owner is where the risk hides. If you cannot see who is really behind the account, you cannot price the risk or defend the file. Identify them before you open the account, not after a regulator asks.”
Dipali Vora, CAMS, ACS
The AML compliance lifecycle for a commercial bank
AML compliance is easier to manage when you see it as a connected lifecycle rather than a pile of separate rules. Each step feeds the next, and a weakness in one shows up as a failure in another. The order that works in practice runs from registration and governance, through risk assessment and policy, to the day-to-day controls of KYC, monitoring, screening and reporting, with record-keeping, training and independent testing around all of it.
Throughout, remember the golden thread of the risk-based approach: a bank does more where the risk is higher and less where it is lower, and it can explain, with evidence, why it made each choice.
Register with FIU-IND and set up reporting.
Before a bank can file anything, it must be enrolled with the Financial Intelligence Unit-India. Enrolment is done on the FINnet platform, accessed via the FINGate 2.0 portal, which is also the channel for submitting all reports. Getting this set up right, with the correct users and access, is a basic condition for meeting the reporting duty.
As part of this, the bank confirms how it will generate and file the prescribed reports: cash transaction reports, suspicious transaction reports, cross-border wire transfer reports and others. The reporting obligation flows from Rule 3 and Rule 8 of the PMLR, and Chapter VIII of the RBI (Commercial Banks – Know Your Customer) Directions, 2025, sets out the reporting requirements for banks.
Setting up your bank's AML function from scratch?
FINnet enrolment, officer appointments and the reporting workflow all have to line up before day one. AML India helps you stand up a complete, inspection-ready compliance department.
Appoint a Designated Director and a Principal Officer
Every bank must appoint two named officers under Rule 7 of the PMLR. The Designated Director is a Board-nominated person who is responsible for overall compliance. The Principal Officer is a management-level officer responsible for monitoring transactions, determining whether activity is suspicious, and filing reports with FIU-IND.
The RBI (Commercial Banks – KYC) Directions, 2025 set out these roles in sections 14 and 15 and make one point very clear: the same person cannot be both the Designated Director and the Principal Officer. The bank must inform FIU-IND and the RBI of the names and details of both officers and update them whenever they change. For the function to work, the Principal Officer needs genuine seniority, authority and access to the Board; an officer with the title but no budget or independence is a common reason programmes fail at inspection.
Conduct the internal risk assessment (IRA)
The internal risk assessment, also known as the enterprise-wide risk assessment, is the foundation of the whole programme. It is the bank’s own study of where its money-laundering, terror-financing and proliferation-financing risks lie. The RBI issued dedicated Internal Risk Assessment Guidance for ML/TF Risks on 10 October 2024, which calls the enterprise-level risk assessment the bedrock of the risk-based approach.
In practice, the bank assesses risk across four families of factors: its customers, its products and services, the geographies in which it operates, and the channels through which it onboards and transacts. It assigns weights, classifies the risk, sets controls to respond to that risk, and calculates a residual risk. The guidance also expects proliferation-financing risk to be built in. The outcome should go before the Board or a Board committee, and the assessment should be reviewed at least annually, the minimum the RBI sets, and whenever a material risk change occurs. Every subsequent control, from CDD to monitoring, should be sized to the findings of this assessment.
A bank’s own risk assessment does not sit in a vacuum. India conducts a National Risk Assessment (the last completed in 2022 and not public) and sectoral risk assessments that set out where the country sees the greatest risk of money laundering and terror financing. The FATF noted in 2024 that these conclusions have been shared with many reporting entities, although a significant number remain to be engaged. Use the national and sectoral risk assessments to inform and justify the risk ratings in your own internal risk assessment and policy. Because the National Risk Assessment is not public, reference its existence and the FATF summary rather than quoting figures you cannot verify against a source you hold.
Use these in the internal risk assessment and in deciding the level of due diligence for a customer.
Risk category | Examples for commercial banks |
Customer | Politically exposed persons and their associates, cash-intensive businesses, non-residents, customers with complex or opaque ownership, and those reluctant to disclose the beneficial owner. |
Product/service/transaction | Correspondent banking, trade finance, cross-border wire transfers, private banking, and high-value or prepaid products. |
Geography | Customers, funds or counterparties linked to higher-risk jurisdictions or to areas with elevated predicate-crime activity. |
Delivery channel | Non-face-to-face and digital onboarding, third-party introducers, and accounts operated through power of attorney. |
Is your risk assessment doing real work, or sitting on a shelf?
If the IRA does not actually drive your controls, the whole programme is pointed in the wrong direction. AML India builds a board-ready internal risk assessment that sets your priorities and stands up to scrutiny.
AML policies, controls and procedures implementation
With the risk assessment done, the bank turns it into a written AML policy that the Board approves and owns. Chapter II of the KYC Directions, 2025, places this duty on the Board. The policy is the operating manual that the bank and any inspector works from.
A workable policy covers the customer acceptance policy; the customer identification and due diligence steps; the rules for higher- and lower-risk customers; ongoing monitoring; the escalation route to the Principal Officer; reporting; record-keeping; and training. For a banking group, it also covers group-wide policies and how overseas branches and subsidiaries apply them, adopting the more stringent of the Indian and host-country standards where they differ. The test of a good policy is simple: does it describe how the bank actually works?
Customer identification and customer due diligence (CDD)
Customer due diligence is the front line of the programme. It is how the bank satisfies itself that it knows who each customer is, and keeps that knowledge current. The duty comes from Section 11A of the PMLA, Rule 9 of the PMLR, and Chapters V and VI of the KYC Directions, 2025.
At onboarding, the bank follows the Customer Identification Procedure (Chapter V): it collects and verifies identity using reliable, independent documents or their electronic equivalents, including through video-based customer identification where allowed.
Chapter VI then sets out customer due diligence, with different routes for individuals, sole proprietors and legal entities. The depth of CDD varies with risk: lower-risk customers receive simplified due diligence, while higher-risk customers receive enhanced due diligence, and the rationale should be documented. For non-profit organisation customers, the bank verifies the nature and purpose of the organisation, registers the NPO’s details on the NITI Aayog DARPAN Portal where it is not already registered, maintains that registration record for the prescribed period, and monitors donation and foreign-contribution activity on a risk-sensitive basis.
Behind every company, partnership or trust, there is a real person who owns or controls it, and the bank must identify that person. Beneficial-ownership identification is part of CDD, not a separate requirement, and it is where much of the laundering risk hides. It is required under Rule 9 of the PMLR and Chapter VI-D of the KYC Directions, 2025.
For a company or a partnership, the beneficial owner is the natural person who has a controlling interest of more than 10 per cent of the shares, capital or profits, or who controls the customer through other means. For an unincorporated association or body of individuals, the threshold is more than 15 per cent. For a trust, the bank identifies the author, the trustees, the beneficiaries with a 10 per cent or more interest, and anyone else exercising ultimate control. Where ownership is layered through several entities, the bank traces the chain to the natural person at the top, and the identified beneficial owner is screened against sanctions lists like any other customer.
Higher-risk customers, including politically exposed persons and their families and close associates, receive senior-management approval for onboarding, including establishing the source of funds and wealth, and closer ongoing monitoring. This, too, is part of CDD, and its trigger is the customer’s risk rating from the internal risk assessment.
Onboarding at scale without slowing down or missing risk?
CDD has to be fast for good customers and thorough for risky ones. AML India helps you design the process and choose the identity, screening and risk-rating tools that make both possible.
Correspondent banking and wire transfers
Correspondent banking, in which one bank provides services to another, often across borders, imports the other institution’s risk and is a known money-laundering channel. It calls for enhanced due diligence on the respondent bank before the relationship begins and on an ongoing basis thereafter.
Banks must also ensure that cross-border wire transfers carry complete originator and beneficiary information, the rule often called the travel rule, and must not enter into or continue relationships with shell banks. These provisions sit within the RBI (Commercial Banks – Know Your Customer) Directions, 2025.
Ongoing monitoring and periodic updation
Knowing a customer at onboarding is not enough because risk changes over the life of a relationship. Ongoing monitoring means monitoring transactions and account behaviour for activity that does not align with what the bank knows about the customer, and escalating any unusual activity to the Principal Officer for a decision on whether to file a suspicious transaction report.
Periodic updation is the scheduled refresh of customer KYC. Under Chapter VI-E of the KYC Directions, 2025, a bank carries this out at least once every 2 years for high-risk customers, once every 8 years for medium-risk customers and once every 10 years for low-risk customers, and sooner when a trigger occurs.
Good monitoring is tuned to the bank’s real risks rather than left on default settings, and the alerts it raises are actually worked on and closed. The bank also reviews each customer’s risk categorisation periodically, at least once every six months. Banks should check whether any temporary RBI concession on periodic updation is still available at the time of implementation, as such concessions are time-bound and may expire or change.
Buried in alerts, or behind on periodic updation?
Manual monitoring misses patterns and lets KYC go stale. AML India helps you select and configure monitoring and updation tools that fit your size and clear the backlog.
The monitoring framework should also address money mule accounts, especially accounts used to receive, layer or rapidly move fraud proceeds, cyber-enabled fraud proceeds, or unexplained third-party credits that do not fit the customer’s profile. Treat sudden pass-through and fan-in activity as a trigger to escalate to the Principal Officer for review and STR consideration.
Sanctions screening and targeted financial sanctions
Banks must make sure they are not dealing with designated terrorists, their financiers, or those involved in financing weapons of mass destruction. This is done through sanctions screening against officially designated lists and is mandatory under Section 51A of the UAPA, 1967, for terrorism, and under Section 12A of the WMD Act, 2005, for proliferation financing.
The bank screens customers and beneficial owners against the United Nations Security Council lists and the domestic lists of individuals and entities designated by the Ministry of Home Affairs (MHA) under the UAPA, both at onboarding and on an ongoing basis as the lists change. Where there is a true match, the bank must freeze the funds and report without delay, in accordance with the implementation procedures issued for Sections 51A and 12A. There is no minimum amount: screening applies to every customer and relevant payment, and every hit decision is recorded for the audit trail. In practice, follow a clear hit workflow: detect a possible match; pause or freeze as required; escalate; confirm whether it is a true match; report and freeze on a true match; and document false positives.
Regulatory reporting to FIU-IND
Reporting is how a bank’s intelligence reaches the authorities, and it is one of the most closely watched duties. The Principal Officer files the reports with FIU-IND under Rule 8 of the PMLR, through FINnet 2.0. Chapter VIII of the KYC Directions, 2025, sets the reporting requirements for banks.
The main report types, set by Rule 3 of the PMLR, are the cash transaction report (CTR) for cash over Rs 10 lakh and connected cash transactions over Rs 10 lakh in a month; the suspicious transaction report (STR) for any transaction of any value that raises suspicion, including attempted transactions; the cross-border wire transfer report (CBWTR) for cross-border wire transfers of more than Rs 5 lakh, or its equivalent in foreign currency, where either the origin or destination of the funds is in India; and reports on cash transactions involving counterfeit currency, forged valuable security or forged documents, and reports on receipts by non-profit organisations above the prescribed threshold.
Timing matters. Cash transaction reports, non-profit transaction reports, counterfeit or forged-document reports and cross-border wire transfer reports are filed monthly, by the 15th day of the succeeding month. Suspicious transaction reports must be filed promptly once the Principal Officer is satisfied that the transaction is suspicious, not held to a monthly cycle. Reports on immovable property transactions under Rule 3(F), where applicable, are filed quarterly. Reports must be generated in the prescribed FINnet 2.0 format, so the bank’s systems should produce reports that match the current format. Reporting is confidential: a bank must not tip off a customer that a suspicious transaction report has been or may be filed.
Confident every report is complete and on time?
Late or missed reports are an easy, penalised failure. AML India helps you build the reporting function, from FINnet 2.0 filing to the STR decision process, so nothing slips.
Record management, CKYCR and FINnet 2.0
A bank must be able to prove it did the work, which makes records a control in their own right. Under Section 12 of the PMLA and Chapter VII of the KYC Directions, 2025, the bank keeps transaction records for 5 years from the date of the transaction, and customer identity, account files, and business correspondence for 5 years after the business relationship ends or the account is closed, whichever is later. The records must be retrievable quickly when the RBI, FIU-IND, or law enforcement requests them.
Two pieces of national infrastructure connect to this. The Central KYC Records Registry (CKYCR), governed by guidelines updated in 2025, is a central repository of customer KYC; the bank uploads each customer’s KYC, receives a KYC identifier, and can reuse an existing record. The bank files the electronic copy of a customer’s KYC record with the CKYCR within the prescribed timeline, currently 10 days after the account-based relationship commences, and furnishes any updated KYC information to the CKYCR within seven days of obtaining it, or within any period notified. FINnet 2.0, through FINGate 2.0, is the FIU-IND platform for filing reports. Both need to be set up correctly and kept current.
Training and awareness
Controls only work if the people at the counter and in the back office understand them. The KYC Directions, 2025, expect banks to train staff, and a good programme is role-based: front-line and onboarding staff learn to spot red flags and complete CDD, while compliance and monitoring staff go deeper into typologies, screening and reporting. Training is refreshed regularly, kept up to date with new risks and rule changes, and evidenced with records of who was trained and when.
Would your branch staff recognise a layered, third-party deposit?
Red flags only help if people remember them. AML India delivers role-based training that turns the PMLA, the RBI Directions and real typologies into scenarios your teams will actually use.
Independent testing and audit
Finally, the bank checks its own programme through independent testing, such as an internal or external AML audit. The point is to have someone other than the people running the controls confirm that they actually work, and to track every finding through to closure. A useful discipline is to test the AML programme the way an outsider would: pull a sample of files, follow an alert from generation to STR decision, and time how long it takes to retrieve records.
Training and awareness
Controls only work if the people at the counter and in the back office understand them. The KYC Directions, 2025 expect banks to train their staff, and the strongest programmes are role-based: front-line and onboarding staff learn to spot red flags and complete CDD, while compliance and monitoring staff go deeper into typologies, screening and reporting. Training is refreshed regularly, kept current with new risks and rule changes, and evidenced with records of who was trained and when. In small-team banks, the same person may need several of these modules at once.
Would your branch staff recognise a layered, third-party deposit?
Red flags only help if people remember them. AML India delivers role-based training that turns the PMLA, the RBI Directions and real typologies into scenarios your teams will actually use.
Independent testing and audit
Finally, the bank tests its own programme through an independent review, such as an internal or concurrent audit. The aim is to have someone other than the people operating the controls confirm that they actually work, and to drive every finding through to closure. A useful discipline is to test the way an outsider would: pull a sample of files, follow an alert from generation to the STR decision, and time how long it takes to retrieve a record. Where a category relies on a sponsor or parent for its systems, the audit should extend to those shared arrangements as well.
Commercial-bank implementation: priorities and ownership
The lifecycle is the same as for any bank, but a commercial bank carries it at a different scale. These are the areas where the work concentrates, and who owns each control.
Area | Why it matters for commercial banks |
Corporate accounts | Layered ownership and complex control |
Trade finance | Trade-based money laundering and document risk |
Correspondent banking | Respondent-bank risk and the shell-bank bar |
Cross-border wire transfers | Complete originator and beneficiary information |
PEPs and high-risk customers | Senior approval and enhanced due diligence |
Digital onboarding | Impersonation and mule-account risk |
Non-resident accounts | Cross-border and FEMA-linked risk |
High transaction volume | Alert quality and case management |
Requirement | Owner | Oversight |
FIU-IND registration | Principal Officer | Senior management |
AML policy | Compliance | Board |
IRA/EWRA | Compliance with business input | Board or committee |
CDD and KYC | Operations and front line | Compliance |
Sanctions screening | Operations and compliance | Principal Officer |
Ongoing monitoring | Compliance or FCC team | Principal Officer |
STR decisions | Principal Officer | Confidential escalation |
Training | Compliance and HR | Senior management |
Independent audit | Internal audit or independent reviewer | Audit Committee |
Evidence to keep ready for inspection
A supervisor tests the programme by requesting proof, so a bank keeps an evidence pack up to date and retrievable. Map each requirement to its internal owner and the evidence that proves it:
Requirement | Internal owner | Evidence |
FIU-IND enrolment | Principal Officer / Compliance | FINnet 2.0 registration and user records |
Internal risk assessment | Compliance / Risk / Board | Board-approved IRA report |
CDD and KYC | Operations / Compliance | Customer file, risk rating and beneficial-owner record |
Reporting | Principal Officer | STR, CTR and CBWTR filing records |
Sanctions screening | Compliance | Screening logs and sanctions-hit decisions |
Training | Compliance / HR | Attendance and assessment records |
Independent testing and audit | Internal audit / compliance assurance / independent reviewer | Testing report, audit report and closure tracker |
From compliance back to the law: every requirement above rests on a specific provision. For the legal basis, read the companion guide, AML Laws and Regulations for Commercial Banks in India. Start broader with AML Compliance Requirements for the Banking Sector in India or the top-level AML Compliance Requirements in India.
Red flags to watch for commercial banks
Observable signs that should trigger a closer look or a suspicious transaction report.
- Cash deposits or withdrawals structured just under the Rs 10 lakh reporting threshold.
- Many third-party credits flow into a single account with no clear connection to the holder.
- A sudden change in account behaviour, such as a dormant account becoming very active.
- Transactions that do not match the customer’s known profile or stated business.
- Reluctance to provide identity or beneficial-ownership details, or use of nominees and shell entities.
- Rapid movement of funds in and out with no economic rationale, including mule-account behaviour.
- A customer or beneficial owner with a possible match to a sanctions or designated list.
Want to know if your programme would pass an inspection today?
An AML Health Check reviews your risk assessment, policies, KYC, screening, reporting and records against the 2025 Directions and the PMLA, and gives you a prioritised fix list.
The Indian equivalent of the Bank Secrecy Act
Readers often arrive searching for the Bank Secrecy Act, the United States law that requires banks to keep records and file reports to help detect money laundering. India has no statute of that name. Its equivalent is the Prevention of Money-Laundering Act, 2002 (PMLA) read with the PML (Maintenance of Records) Rules, 2005, which impose the same kinds of duties on Indian commercial banks: verify customer identity, maintain records, and report prescribed transactions to the Financial Intelligence Unit, India. So when a compliance team benchmarks against the Bank Secrecy Act (BSA), the Indian obligations that map to it are the PMLA, the Rules, and the Reserve Bank of India Master Direction on Know Your Customer.
What the PMLA requires of a commercial bank
The bank AML compliance requirements flow from Section 12 of the PMLA and the Rules made under it. A commercial bank must run customer due diligence and identify beneficial owners, maintain records of transactions and identity, and file the prescribed reports: cash transaction reports by the fifteenth day of the succeeding month, suspicious transaction reports within seven working days of forming the suspicion, and reports on counterfeit currency and cross border wire transfers. It appoints a Principal Officer and a Designated Director, screens against the UAPA and Weapons of Mass Destruction sanctions lists, and files KYC records with the Central KYC Records Registry. These are the AML requirements for commercial banks in India in practice.
Best practices for AML compliance for commercial banks
- Let the internal risk assessment drive the policy, and the policy drive the controls, so the programme is connected end-to-end.
- Identify the beneficial owner before opening the account, not after.
- Tune monitoring and screening to your real risks, and work alerts through to a decision.
- Keep a reporting calendar and file suspicious transaction reports promptly.
- Clear periodic-updation backlogs by risk priority, starting with high-risk customers.
- Train staff by role, refresh regularly, and keep records.
- Test the programme independently and close every finding.
- Keep records retrievable, and rehearse producing a file before a supervisor asks for one.
“The banks that pass inspection are not the ones with the thickest policy manual. They are the ones whose risk assessment, screening and reporting actually connect, and who can prove it with evidence.”
Pathik Shah, FCA, CAMS, FAFD
Want an expert to pressure-test your programme?
An AML India expert reviews where your programme is strong and where it would fail an inspection, and gives you a prioritised plan.
Primary sources relied upon
This guide is grounded in the following primary official sources, linked to their official source where available. The reporting statistics are drawn from the FIU-IND Annual Report 2024-25.
- Prevention of Money-laundering Act, 2002 (India Code)
- Prevention of Money-laundering (Maintenance of Records) Rules, 2005 (India Code)
- RBI (Commercial Banks – Know Your Customer) Directions, 2025
- Unlawful Activities (Prevention) Act, 1967 and Section 51A procedure (MHA)
- FATF Recommendations, including the June 2026 update to Recommendation 6 on targeted financial sanctions
- Financial Intelligence Unit – India, including the Annual Report 2024-25
- WMD Act, 2005 and its Section 12A implementation procedure (India Code)
- RBI Internal Risk Assessment Guidance for ML/TF Risks (10 October 2024)
- Central KYC Records Registry (CKYCR) Operating Guidelines, 2025 (CERSAI)
- FATF Mutual Evaluation Report on India, 2024
- Directorate of Enforcement Annual Report 2025-26
Frequently Asked Questions
A bank becomes compliant by building and running a connected programme. The usual order is to enrol with FIU-IND and appoint a Designated Director and a Principal Officer, complete an internal risk assessment, write board-approved policies from it, then operate CDD and KYC, beneficial-ownership checks, ongoing monitoring, periodic updation, sanctions screening and reporting, supported by record-keeping, training and independent testing. Each step is tied to the PMLA, the PMLR, the RBI KYC Directions 2025, and the bank must be able to evidence all of them.
A bank appoints two officers under Rule 7 of the PMLR: a Board-nominated Designated Director with overall responsibility, and a management-level Principal Officer who monitors transactions, assesses suspicious activity, and files reports. The KYC Directions 2025 make clear in sections 14 and 15 that the same person cannot hold both roles. The bank must inform both FIU-IND and the RBI and keep the details up to date.
The bank identifies and verifies every customer and their beneficial owner, and keeps that information current. This runs from the Customer Identification Procedure in Chapter V of the KYC Directions 2025 to the customer due diligence in Chapter VI, and rests on Section 11A of the PMLA and Rule 9 of the PMLR. The depth of due diligence follows the risk, with simplified due diligence for low-risk customers and enhanced due diligence for higher-risk customers, such as politically exposed persons.
The beneficial owner is the natural person who ultimately owns or controls a customer, even when the account is in the name of a company, partnership or trust. For a company or partnership, the threshold is a controlling interest of more than 10 per cent of shares, capital or profits; for an unincorporated association or body of individuals, it is more than 15 per cent; and for a trust, it covers the author, trustees, beneficiaries with a 10 per cent or more interest and anyone exercising ultimate control. Control can also exist through other means, such as the right to appoint most of the directors.
KYC is refreshed on a risk-based cycle called periodic updation. Under Chapter VI-E of the KYC Directions 2025, this is at least once every 2 years for high-risk customers, once every 8 years for medium-risk customers and once every 10 years for low-risk customers. The bank also updates sooner when a trigger occurs, such as a change in ownership or in transaction patterns.
Under Rule 3 of the PMLR, a bank reports cash transactions over Rs 10 lakh, connected cash transactions exceeding Rs 10 lakh in a month, suspicious transactions of any value, cross-border wire transfers of more than Rs 5 lakh (or equivalent in foreign currency, where the origin or destination is in India), and certain counterfeit and non-profit transactions. Cash, non-profit, counterfeit and cross-border wire transfer reports are filed monthly, by the 15th of the succeeding month under Rule 8. In contrast, suspicious transaction reports are filed promptly once the Principal Officer is satisfied. Reports are sent to FIU-IND via FINnet 2.0.
A cash transaction report (CTR) is filed because a cash transaction crosses a fixed threshold, currently more than Rs 10 lakh, regardless of whether anything looks wrong. A suspicious transaction report (STR) is filed when a transaction raises suspicion of money laundering or terrorist financing, regardless of its size, including attempted transactions. CTRs follow a monthly cycle, while STRs must be filed promptly once the Principal Officer is satisfied.
Five years, under Section 12 of the PMLA and Chapter VII of the KYC Directions 2025, but on two clocks. For transactions, the five-year period runs from the date of the transaction; for identity records, account files and business correspondence, it runs for five years after the business relationship ends or the account is closed, whichever is later. The records must be kept so the bank can retrieve and produce them quickly on request.
Yes. The RBI issued category-specific KYC Directions on 28 November 2025, including the RBI (Commercial Banks – Know Your Customer) Directions, 2025, and earlier KYC directions stand repealed or superseded to the extent provided in that Direction. Banks should review any policy, procedure or training built on the old 2016 direction and update it to the current text, because that is the standard a supervisor will apply.
The Reserve Bank of India can impose monetary penalties and require the bank to remediate its controls, and FIU-IND can issue compliance orders with penalties of its own; it issued 8 such orders carrying penalties of more than Rs 30 crore in FY 2024-25. Where an account is linked to money laundering, the Enforcement Directorate can attach property and prosecute. The cost of weak compliance is therefore financial, legal and reputational.
No. India has no law called the Bank Secrecy Act. The comparable framework is the Prevention of Money-Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005, supported by the RBI Master Direction on Know Your Customer. Together these impose the record keeping and reporting duties on Indian banks that the Bank Secrecy Act imposes in the United States.
An Indian commercial bank must perform customer due diligence and beneficial owner identification, keep transaction and identity records, and report cash transactions, suspicious transactions, counterfeit currency and cross border wire transfers to FIU-IND. It must appoint a Principal Officer and Designated Director, screen customers against sanctions lists, and file KYC records with the Central KYC Records Registry, all under the PMLA and the Rules.
Why work with AML India
AML India helps banks and other regulated entities build, run, and prove their PMLA and RBI programmes, from internal risk assessment and policies through to CDD, screening, monitoring, reporting, training, software selection, and independent review.
Industries we serve: banks and financial institutions, insurance companies, securities intermediaries, payments and fintech businesses, real estate agents, dealers in precious metals and stones, virtual asset service providers, and IFSC and GIFT City entities.
“We are thrilled to have AML India as our compliance partner. Their consultants have immense knowledge in executing the right KYC and CDD processes for our business, and made it easy to onboard new customers without the fear of money-laundering risks.” General Manager, Financial Company |
Want an expert to pressure-test your programme?
An AML India expert reviews where your programme is strong and where it would fail an inspection, and gives you a prioritised plan.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik