Last Updated on: 20th July 2026 | Last Reviewed on: 20th July 2026
Key takeaways briefly
- Who is covered: an individual who holds a certificate of practice under section 6 of the Cost and Works Accountants Act, 1959, whether practising individually or through a firm, when carrying out a notified financial transaction for a client (a “relevant person” under the notification by Ministry of Finance).
- The trigger: carrying out any of five specified financial transactions for a client, managing client money, securities or other assets; managing bank, savings or securities accounts; buying or selling immovable property; organising contributions for the creation of companies; and the creation, operation or management of companies, LLPs or trusts and the buying and selling of business entities, under S.O. 2036(E) of 3 May 2023.
- Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the AML/CFT Guidelines for ICAI, ICSI and ICMAI professionals, 19 June 2023; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
- Supervisor: The Institute of Cost Accountants of India (ICMAI). Reports go to the Financial Intelligence Unit India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
- Core duties: registration with FIU-IND, an internal risk assessment, customer due diligence and KYC, beneficial owner identification, ongoing monitoring, suspicious transaction reporting, five-year record keeping and sanctions screening.
A cost and management accountant in practice becomes a reporting entity under the Prevention of Money Laundering Act, 2002 when carrying out certain specified financial transactions on behalf of a client. The trigger is the activity, not the cost audit, cost records or management accounting work at the heart of the profession. Once a member holding a certificate of practice performs one of the notified transactions for a client, the AML, CFT and CPF obligations flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the AML and CFT Guidelines issued jointly for the ICAI, ICSI and ICMAI professionals, the UAPA, the WMD Act and the FIU-IND reporting framework. The Institute of Cost Accountants of India supervises its members, and reports are filed with FIU-IND.
The core instruments at a glance
| Instrument | What it does for a CMA in practice |
| PMLA, 2002 | The core statute. It Makes a relevant person a reporting entity and creates the core obligations of CDD, record keeping and reporting. |
| PML (Maintenance of Records) Rules, 2005 | Set out what to report and when, how to identify clients and beneficial owners, and the duty to appoint officers. |
| Notification S.O. 2036(E), 3 May 2023 | The notification that lists the specified financial transactions and defines the relevant person by the certificate of practice. |
| AML/CFT Guidelines for ICAI, ICSI, ICMAI (19 June 2023) | The relevant person’s working framework, issued jointly for the three professions. |
| UAPA Section 51A and WMD Act Section 12A | Impose targeted financial sanctions for terrorism and proliferation financing on a relevant person. |
| FATF Recommendations 22 and 23 | The international standards for DNFBPs that India’s professional regime is built to meet, supported by the FATF accounting profession guidance of 2019. |
When is a cost and management accountant covered by the PMLA?
A cost and management accountant is covered by PMLA only when, in the course of practice and on behalf of a client, the member carries out one of five specified financial transactions: managing client money, securities or other assets; managing bank, savings or securities accounts; buying or selling any immovable property; organising contributions for the creation, operation or management of companies; and the creation, operation or management of companies, limited liability partnerships or trusts; the buying and selling of business entities.
The distinction is significant in practice. Cost audit, the maintenance of cost records, cost certification, management accounting advisory, performance and cost analysis and ordinary compliance work do not trigger PMLA compliance obligations. It is the handling or arranging of a client’s money, assets, accounts or corporate vehicles that brings a member within the scope of law, because those are the points at which a professional can, knowingly or unknowingly, help place or move illicit funds.
Are cost and management accountants reporting entities under the PMLA?
Yes, when they act on behalf of a client and undertake notified financial transactions, they become a relevant person under the notification S.O. 2036(E) of 3 May 2023 and are consequently treated as a reporting entity because the notification has been issued under sub-clause (vi) of section 2(1)(sa) of the Prevention of Money Laundering Act, 2002. The notification specifies both the financial transactions and the professionals who are covered under this provision.
Once covered, the relevant person must register with FIU-IND and run an AML programme proportionate to their service. This places a practising cost accountant in the same broad group of reporting entities that file with FIU-IND as banks and other professionals and connects the member to the wider set of DNFBPs subject to the PMLA.
Supervisory authority for cost and management accountants in India
The supervisory body for cost and management accountants is their own statutory body, the Institute of Cost Accountants of India (ICMAI). The institute grants a certificate of practice to eligible members, prescribes professional and ethical standards, and exercises disciplinary and regulatory oversight over their members.
A relevant person files all the prescribed reports with the Financial Intelligence Unit India, which receives, analyses and disseminates them, while the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA.
Onboarding clients without a documented due-diligence process?
AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.
AML Regulatory Requirements for Cost and Management Accountants in India
The legal framework governing a cost and management accountant acting as a relevant person is not contained in a single statute. It operates as a layered compliance framework comprising the core legislation, the overarching obligations, the sectoral supervisor and its guidelines, the miscellaneous official reports, the international standards, and the allied laws. Each of them performs a distinct function, but together they create a comprehensive compliance framework. The underlying principle across all these layers is the risk-based approach which underpins the AML, CFT and CPF compliance programme.
Core Legislation
The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into three catalogues.
AML Legislation
Prevention of Money-Laundering Act, 2002 (PMLA)
India’s parent anti-money laundering statute and the source of a relevant person’s reporting entity status. It defines the offence of money laundering and imposes the obligations of identifying the client (section 11A) and reporting the transaction to the financial intelligence unit of India (section 12) that a cost and management accountant must apply whenever a notified financial transaction is carried out on behalf of a client. The Act reaches the profession because a certificate holder who manages a client’s money, assets or accounts, or forms and administers corporate vehicles, stands where illicit value can be placed or moved under a professional legitimacy.
The PML (Maintenance of Records) Rules, 2005 (PMLR)
The operational rulebook made under the PMLA, and the layer of practice that applies for compliance after the notified transaction is undertaken. It fixes what to report and when (Rule 3 and Rule 8), how to identify clients and beneficial owners (Rule 9), the duty to appoint a Principal Officer and Designated Director (Rule 7), and, in Rule 7(3), the obligation to run a mechanism to detect suspicious transactions. The PMLR has been amended through 31 Gazette notifications and orders, set out below as a legal history timeline.
The 31 PMLR amendment notifications, in date order:
| Gazette notification and date | Key change or rule touched |
| G.S.R. 389(E), 24 May 2007 | The amendment to the 2005 Rules. It widened the Rule 2 definition of a suspicious transaction to encompass dealings with no economic rationale or bona fide purpose and those hinting at terrorism financing, amended Rule 3 to supervise cash dealings in forged or counterfeit currency, substituted Rule 8 on furnishing information to the Director, and revised the Rule 9 requirement from three certified copies down to one. |
| G.S.R. 816(E), 12 November 2009 | It added the definitions of non-profit organisation and Regulator, redefined the suspicious transaction, and mandated the reporting of NPO receipts beyond Rupees 10 lakh. It amended record retention at ten years under Rule 6 and rebuilt Rule 9 to require beneficial owner identification, ongoing due diligence, an embargo on anonymous accounts and a Client Identification Programme. |
| G.S.R. 76(E), 12 February 2010 | Revised Rules 3, 4, 5 and 7 to strengthen record keeping and the reporting requirements and, most consequentially, added the first Explanation in Rule 9(1A), which notifies the beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction is executed. |
| G.S.R. 508(E), 16 June 2010 | Amended Rules 2, 9 and 10, the provisions on definitions, customer due diligence and record keeping, changing how a reporting entity identifies clients and what it must retain, part of the sustained 2010 tightening of the CDD and records regime. |
| G.S.R. 980(E), 16 December 2010 | Introduced the small account regime. It defined the Designated Officer and the small account, placed the NREGA job card and the Aadhaar letter into the officially valid documents in Rule 2, and added Rule 9(2A) covering how such an account is opened and monitored. |
| G.S.R. 481(E), 24 June 2011 | Through Rule 1 it changed the name of the 2005 rules to the Prevention of Money Laundering (Maintenance of Records) Rules. |
| G.S.R. 576(E), 27 August 2013 | Revised Rules 2 and 3 and inserted provisions after Rule 10, dealing with definitions, the cash and suspicious transaction reporting duties and the record framework so that they fit with the reporting obligations. |
| G.S.R. 288(E), 15 April 2015 | Amended the Rule 2 definitions. Because definitions determine who and what the operative rules reach, the change permeated the framework and set off a run of 2015 updates. |
| G.S.R. 544(E), 7 July 2015 | Revised Rules 2, 9 and 10 on definitions, customer due diligence and record keeping, clarifying how a reporting entity identifies clients and what it retains, within a substantial 2015 overhaul of the CDD and records provisions. |
| G.S.R. 730(E), 22 September 2015 | Amended Rules 2 and 7, the requirement for a Principal Officer and an internal reporting mechanism, reinforcing the governance side and regulatory authority functions. |
| G.S.R. 882(E), 18 November 2015 | Revised the definitions and reporting provisions, altering how key terms are construed and how transactions reach the FIU-IND. |
| G.S.R. 347(E), 12 April 2017 | Amended Rule 2 and inserted Rule 9A, folding the Central KYC Records Registry into the Rules, creating the duty to file client KYC records centrally and the basis to reuse them, the structural addition supporting today’s CKYCR. |
| G.S.R. 538(E), 1 June 2017 | Revised Rules 2 and 9 to consider Aadhaar as identity proof in in identification and verification of client and beneficial owner, an approach later recast by the Supreme Court’s Aadhaar ruling. |
| G.S.R. 1038(E), 21 August 2017 | Amended Rule 2 definitions, revising the defined terms that govern how the operative rules apply, among several definition updates in 2017. |
| G.S.R. 1318(E), 23 October 2017 | A later 2017 recasting of the Rule 2 definitions, keeping the defined terms aligned as the framework moved forward. |
| G.S.R. 456(E), 16 May 2018 | Amended the definitions and inserted clarification on identification and verification of clients for customer due diligence provisions, strengthening the continuing adjustment of the CDD framework. |
| G.S.R. 1078(E), 31 October 2018 | Substituted changes under Rule 9 on customer due diligence, the steps a reporting entity follows to verify clients and identify beneficial owners, |
| G.S.R. 108(E), 13 February 2019 | Revised Rules 2 and 9 on definitions and customer due diligence, after the legislative changes to Aadhaar identity card, and revised the ways identification could be conducted. |
| G.S.R. 381(E), 28 May 2019 | Amended Rule 9, tightening the identification and verification process and the routes to confirm a client’s identity, part of the post-Aadhaar identification CDD. |
| G.S.R. 582(E), 19 August 2019 | Substituted Rules 2 and 9 and added an annexure after Rule 11, concerning definitions, customer due diligence and the supporting provisions on information and record. |
| G.S.R. 669(E), 18 September 2019 | Inserted definitions under Rule 2 and further inserted a proviso under Rule 9 to tighten the customer due diligence process within the 2019 run of CDD amendments. |
| G.S.R. 840(E), 13 November 2019 | Inserted one more clause to Rule 9 and accommodated the verification of different addresses by providing a self-declaration for the purposes of CDD. |
| G.S.R. 228(E), 31 March 2020 | Further revised Rule 9 in context with the operational validity of the small accounts. |
| G.S.R. 251(E), 13 April 2020 | Amended Rule 8, which governs the furnishing of transaction reports to the FIU, tightening the manner and content of what a reporting entity submits. |
| G.S.R. 254(E), 16 April 2020 | A follow-up Rule 8 amendment days after the previous one, together amplyfying the reporting provisions and the route by which reports reach the FIU. |
| G.S.R. 798(E), 28 December 2020 | Read with G.S.R. 799(E) and 800(E) of the same day, it designated DNFBPs and named their regulator, beginning the reach into non-financial businesses that the 2023 notifications later carried to the professions. |
| G.S.R. 575(E), 13 July 2022 | Inserted the International Financial Services Centre definition alongside a beneficial owner provision for entities based in the gift city and added an IFSC proviso to Rule 9A on the CKYCR, fitting the Rules to the IFSCA regime. |
| S.O. 1074(E), 7 March 2023 | A major change of direct relevance to a practice. It added definitions of politically exposed persons, non-profit organisations and group and a Rule 3A duty for group-wide AML policies and substituted the company beneficial ownership threshold from 25 to 10 per cent, with a matching change to Rule 9(3)(e), so a member must probe ownership further. |
| G.S.R. 652(E), 4 September 2023 | The second major 2023 amendment. It mandated the Principal Officer to be at management level, substituted the partnership beneficial ownership threshold from 15 to 10 per cent, added an Explanation of control, obliged trustees to disclose their status, and required the results of any Rule 3 and Rule 9 analysis to be kept among the records. |
| G.S.R. 745(E), 17 October 2023 | Revised Rules 2, 3,3A, 8 and 9 together, definitions, the reporting duties and customer due diligence, refining several operative provisions in one notification. |
| G.S.R. 419(E), 19 July 2024 | Reinforced Rule 9(1C) on the KYC Identifier and set a seven day deadline to update a CKYCR record after any change, added a duty to fetch the updated record, and revised Rule 9A(2)(g) on filing, retrieving and using registry records, bolstering how current central KYC data is maintained. |
The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005
A set of rules on accepting client records authenticated outside India. For a cost and management accountant, they apply when a notified engagement involves a non-resident client or a foreign entity, and the identity and ownership documents relied on were executed and certified abroad rather than in India.
CFT Legislation
The Unlawful Activities (Prevention) Act, 1967 (UAPA)
India’s counter terrorism statute. Its Section 51A requires a relevant person to screen clients and beneficial owners against the designated terrorism lists and to freeze, without delay, the funds and assets of any listed person or entity. The duty is attached to each notified transaction a relevant person undertakes.
Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023)
The step-by-step procedure a relevant person follows to give effect to Section 51A when a client matches a designated list. The joint professional Guidelines further integrate the screening and freezing steps into the compliance procedures, translating the statutory obligations into a workable process for relevant persons.
CPF Legislation
The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)
India’s counter-proliferation financing statute. Section 12A supplies the legal basis for targeted financial sanctions aimed at the financing of weapons of mass destruction, and it reaches a relevant person because professional services in managing money or forming entities can be used to route value for a sanctioned network.
Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)
The implementation procedure for Section 12A that reflects the Section 51A screening and freezing steps but for proliferation financing designations. For a relevant person, it is applied through the same joint Guidelines, so terrorism and proliferation lists are both checked in the occurrence of notified transactions.
The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016
The supporting rules that put the WMD Act into operation and support the list handling, freezing and reporting actions a relevant person must be able to carry out when a proliferation financing designation match arises in an engagement.
Not registered with FIU-IND yet, or unsure whether you have to be?
AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.
Overarching Obligations
The shared national regulatory framework that a relevant person plugs into once a notified engagement makes the member a reporting entity.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
The Central KYC Records Registry is a national registry where a relevant person uploads a client’s verified KYC record and can retrieve and reuse a record another reporting entity has already filed. The guideline prescribes the operating principles to the reporting entities and also the modes of access for getting beneficial ownership and identity data right at the start of a notified engagement.
FINnet 2.0 reporting formats (2024) and the FINGate 2.0 reports manual (June 2023)
The FIU-IND reporting platform, its reporting formats and the FINGate 2.0 user manuals through which a relevant person enrols and files the prescribed reports. Enrolling on the portal as a reporting entity is the practical first step once a member begins to carry out the notified transactions for clients.
Section 11A Aadhar authentication procedure for non-banking entities
The procedure by which an entity other than a banking company applies for permission to use Aadhaar authentication services for KYC. It applies to a relevant person, who is a non-banking reporting entity and must obtain approval before verifying a client’s identity through Aadhaar.
Sectoral Guidelines
The professional supervisor and its instruments. This is the layer that gives the cost accountant regime its own character, because the member’s own institute, the ICMAI, supervises compliance while FIU-IND receives the reports and ED investigates the crimes.
AML/CFT Guidelines for professionals with certificates of practice from ICAI, ICSI and ICMAI (19 June 2023)
The relevant person’s working rulebook, and the most important instrument for being compliant. Issued jointly for the professionals of the three institutes ICAI, ICSI and ICMAI, the Guidelines explain who is a relevant person, provides the duty to establish policies and procedures, customer due diligence and officially valid documents, beneficial owner identification, transaction monitoring and suspicious transaction reporting, record keeping, the appointment of a Designated Director and a Principal Officer, and the implementation of Sections 51A and 12A. Where this article states a duty at the level of the law, the Guidelines are where a member finds the detail.
PMLA Frequently Asked Questions for the professions
The question-and-answer guidance published for the professions on the PMLA, which explains in practical terms when a member is a relevant person, which engagements are covered and how the obligations apply. It is a useful companion to the joint Guidelines for day-to-day judgement, and a cost and management accountant should read it with the guidance issued.
SAFA guidelines on customer due diligence for accountants
Guidance from the South Asian Federation of Accountants on customer due diligence for the accounting profession, which supports the domestic Guidelines with a regional professional view of how CDD should be carried out, applicable to a cost and management accountant in the notified engagements.
Notification designating the professions, S.O. 2036(E) (3 May 2023)
The instrument that brings the specified financial transactions within section 2(1)(sa)(vi) of the PMLA and defines the relevant person by reference to a certificate of practice under the Cost and Works Accountants Act, 1959, section 6.
Miscellaneous official Reports and Guidance
Official reports and guidance that sit outside the binding rulebook but shape how a relevant person reads risk and duty.
FIU-IND Annual Report 2024-25
The FIU-IND’s annual report furnished from receiving, analysing and disseminating activities throughout the year. It is a valuable resource as it offers insights into the evolving reporting framework, the typologies and the risks for reporting entities including the relevant persons.
Directorate of Enforcement Annual Report 2025-26
The Enforcement Directorate’s annual account of investigations, provisional attachments and prosecutions under the PMLA, showing how the criminal enforcement framework operates in practice, including instances where professional services featured in a money laundering scheme.
FIU-IND and its Core Functions and FAQs
An ordinary explanation of the role of FIU-IND and the reporting obligations. It serves as a practical primer for a relevant person setting up its reporting function and enrolling on FINnet 2.0 for the first time.
MHA National Counter-Terrorism Policy and Strategy
The Ministry of Home Affairs statement of national counter terrorism policy and strategy, which frames the wider intent behind the CFT duties that Section 51A places on a relevant person.
International Standards
The global benchmarks India is measured against, and the sources a certificate holder can use to calibrate a risk-based approach to the notified engagements.
FATF Recommendations
The global AML, CFT and CPF benchmark. Recommendations 22 and 23 extend customer due diligence and suspicious transaction reporting obligations to DNFBPs, including the relevant persons when they carry out the specified transactions. Recommendation 6 establishes the framework for targeted financial sanctions relating to terrorism and terrorist financing. The recommendations were last updated by FATF in June 2026. India’s combating framework is built to align with these standards. .
FATF Mutual Evaluation Report on India, 2024 and Executive Summary
The 2024 FATF peer review of India’s system, with a separate executive summary. It examined how reporting entity supervision and compliance function practically, highlights the ambiguity in the regime, and signals where the regime is expected to tighten next.
FATF Risk-Based Approach Guidance for the Accounting Profession,2019
Sector-specific FATF guidance on the money laundering and terrorist financing risks the accounting profession faces in the services it provides, and how a risk-based approach applies. It is a practically applicable template for a cost and management accountant’s internal risk assessment of the notified engagements.
Allied Laws
The supporting body of law that defines the predicate offences and the enforcement machinery around money laundering, together with the statute that governs the profession itself. A member does not administer the criminal and enforcement Acts, but they shape the risk to assess and the conduct that may need reporting.
The allied laws most frequently relevant to Cost and Works Accountants’ money laundering and compliance extend beyond the core legislation and govern the professional, corporate, criminal, financial and enforcement framework within which professionals practice.
The Cost and Accountants Act, 1959 and the Chartered Accountants, the Cost and Works Accountants and the Company Secretaries (Amendment) Act, 2022: which govern the profession, professional conduct and disciplinary framework for cost and works accountants.
The Companies Act, 2013: particularly significant as it regulates the formation and management of corporate entities where a CMA is commonly engaged and acts as a relevant person.
The Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023: provide criminal law and criminal procedural law for economic and financial offences
The Foreign Exchange Management Act, 1999, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974(COFEPOSA), the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976(SAFEMA), the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003: This statues regulated activities that gives rise to money laundering risks and establish mechanisms professionals can use to be complaint with PMLA obligations.
Core AML/CFT/CPF Obligations for Cost and Management Accountants in India
Where a cost and management accountant carries out the notified transactions on behalf of a client, the regulations require the member to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.
- Register with FIU-IND. Enrol with the Financial Intelligence Unit India on the FINnet 2.0 / FINGate 2.0 portal once the member begins carrying out the notified financial transactions for clients, so the relevant person can file its reports.
- Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR. The same person cannot hold both roles, and both are to be informed to FIU-IND.
- Conduct the internal risk assessment. Assess money laundering, terror financing and proliferation financing risk across client types, the notified services and geographies, drawing on the FATF accounting profession guidance, and keep it up to date.
- Document AML policy, controls and procedures. Adopt an approved policy that turns the risk assessment into the professional’s operating procedures, as required by the joint Guidelines.
- Client identification and CDD. Identify and verify every client and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals), with enhanced due diligence for politically exposed persons and high-risk clients, under Section 11A of the PMLA, Rule 9 of the PMLR and the joint Guidelines, using the officially valid documents the Guidelines list.
- Ongoing monitoring and periodic updation. Monitor the engagement on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low risk clients. Review each client’s risk categorisation at least once every six months and decide whether enhanced due diligence is required.
- Sanctions screening. Screen clients and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act and freeze and report any match. Verify the relevant UNSC and domestic designated lists on a daily basis. This duty attaches to each notified engagement.
- Regulatory reporting. File suspicious transaction reports of any value, including attempted transactions, promptly once the Principal Officer is satisfied that a transaction is suspicious, under Rule 8(2) of the PMLR. Where a member handles cash in the notified work, cash transaction reports for cash over Rupees 10 lakh and reports on counterfeit or forged instruments are filed monthly by the 15th day of the succeeding month, under Rule 3. Reports are made through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction and keep identity records and business correspondence for five years after the business relationship ends, under Section 12 of the PMLA. Upload client KYC records to the Central KYC Records Registry under Rule 9A, reuse an existing record where applicable, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train partners and staff by role to apply the controls and recognise the red flags that arise in the notified engagements.
- Independent testing and audit. Test the programme through internal review or independent assurance and close every finding.
What this article does not cover
This article explains the laws and regulatory instruments that apply to a cost and management accountant acting as a relevant person. It does not provide a compliance manual, and it does not restate the cost accounting standards and the professional and ethical rules that the ICMAI sets for practice generally, except where they bear on the AML duties. For implementation, a practice separately documents client acceptance, KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction reporting, staff training, audit testing and management reporting. Those controls are the subject of the companion compliance guide.
To see how the professional framework fits within the national picture, see AML laws and regulations in India, and use the parent overview, AML laws and regulations for DNFBPs in India, to see how the professions sit alongside the other designated businesses.
From regulation to compliance: your next step
For being compliant, knowing the law is only the first step. These obligations only protect a practice when they are translated into an effective compliance programme that includes risk assessment, policy and procedure, client due diligence, monitoring, screening, reporting, training and audit. Since the trigger is the specific engagement, the safest approach is to identify at acceptance stage whether the mandates involve notified transactions and apply the programme to those from the start. Understanding the three stages of money laundering and how the sanctions screening process works is a useful starting point.
Not sure which of your mandates are notified transactions
AML India can help a practice identify which engagements bring it within the PMLA and build a proportionate programme for those.
Frequently Asked Questions
When, in practice and on behalf of a client, the member carries out one of the specified financial transactions: managing client money, securities or other assets; managing bank, savings or securities accounts; buying or selling any immovable property; organising contributions for the creation, operation or management of companies; or the creation, operation or management of companies, LLPs or trusts and the buying and selling of business entities. They become a reporting entity under PMLA.
No. Cost audit, the maintenance of cost records, cost certification, management accounting advisory and ordinary compliance work do not, by themselves, make a certified individual a reporting entity. They become a reporting entity only when the individual undertakes a notified transaction, including handling or arranging a client’s money, assets, accounts or corporate vehicles.
The Institute of Cost Accountants of India, the member’s own statutory body, under the AML and CFT Guidelines issued jointly for the ICAI, ICSI and ICMAI professionals. Reports are filed with the Financial Intelligence Unit India, and the Enforcement Directorate investigates and prosecutes the offence of money laundering.
No. A cost and management accountant is covered under PMLA as a reporting entity by carrying out a notified transaction on behalf of a client, whatever its value. The nature of the activity is the trigger, not a threshold.
A suspicious transaction report, of any value and including attempted transactions. A member who handles cash in the notified work must also file cash transaction reports for cash over Rupees 10 lakh and reports on counterfeit or forged instruments. All reports go through FINnet 2.0.
Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply whenever the member acts as a relevant person, from the start of a notified engagement. The member screens clients and beneficial owners against the designated lists and freezes and reports any match, whatever the value of the work.
A CMA balances AML reporting and client confidentiality by following the AML core rules. When undertaking a notified transaction on behalf of a client, the PMLA obligations override the general duty of confidentiality. Hence, A suspicious transaction report must not be disclosed to the client, which the law treats as prohibited tipping-off. The joint Guidelines address how a member manages this, so professional confidentiality and the reporting duty can both be met.
Official sources and review
Last reviewed: July 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
- Prevention of Money-Laundering Act, 2002 (India Code)
- Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (India Code)
- Notification S.O. 2036(E), 3 May 2023, notifying the specified financial transactions (Gazette of India)
- AML/CFT Guidelines for professionals with certificates of practice from ICAI, ICSI and ICMAI, 19 June 2023 (ICMAI)
- Cost and Works Accountants Act, 1959 (India Code)
- Unlawful Activities (Prevention) Act, 1967 and Section 51A procedure
- WMD Act, 2005 and its Section 12A implementation procedure (India Code)
- FATF Recommendations, including the June 2026 update to Recommendation 6
- FATF Risk-Based Approach Guidance for the Accounting Profession, 2019
- FATF Mutual Evaluation Report on India, 2024
- Financial Intelligence Unit – India, including the Annual Report 2024-25
Why work with AML India
AML India helps cost and management accountants in practice meet their PMLA obligations for the notified transactions, from registration and risk assessment to CDD, screening, monitoring, reporting, training and independent review.
Industries we serve: Cost and Management Accountants, Chartered Accountants and Company Secretaries, Trust and Company Service Providers, Real Estate Agents, Dealers in Precious Metals and Stones, Virtual Asset Service Providers, Casinos and the Gaming Sector, and Banks, Financial Institutions and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.