Last Updated on: 30th July 2026 | Last Reviewed on: 30th July 2026
Key takeaways at a glance
- Who is covered: asset reconstruction companies registered with the RBI under the SARFAESI Act, 2002 that acquire and resolve non-performing financial assets of banks and financial institutions, as reporting entities under the PMLA.
- Why are they covered: ARCs are covered under PMLA because they are categorised as financial institutions within section 2(1)(l) of the PMLA and therefore qualify as reporting entity under section 2(1)(wa).
- Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the RBI (Asset Reconstruction Companies – Know Your Customer) Directions, 2025; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
- Supervisor: The Reserve Bank of India (RBI). Reports go to the Financial Intelligence Unit of India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
- Core duties: an internal risk assessment, customer due diligence and KYC, beneficial owner identification, regular updating, monitoring, prescribed transaction reporting, five-year record maintenance and sanctions screening.
This guide is general information on Indian law, not legal advice. For your company’s specific position, speak to a qualified AML professional.
Asset reconstruction companies, known as ARCs, are reporting entities under the Prevention of Money-Laundering Act, 2002. An ARC is a company registered with the Reserve Bank of India under the Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002 (SARFAESI) to acquire and resolve the non-performing assets or bad loans of banks and financial institutions.
Its AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the RBI Asset Reconstruction Companies KYC Directions, 2025, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework. The Reserve Bank of India supervises ARCs, and reports are filed with FIU-IND.
The core instruments at a glance
| Instrument | What it does for an ARC |
| PMLA, 2002 | The parent Act. Makes an ARC a reporting entity as a financial institution and creates the core duties of CDD, record-keeping and reporting. |
| PML (Maintenance of Records) Rules, 2005 | Set out reporting obligations and timelines, measures on customers identification and beneficial owners verification, and the duties of reporting entities. |
| RBI ARC KYC Directions, 2025 | The ARC’s working rulebook, issued by the RBI on 28 November 2025 and updated as on 29 December 2025. |
| SARFAESI Act, 2002 | The Act under which an ARC is registered with the RBI and acquires and resolves financial assets. |
| UAPA Section 51A and WMD Act Section 12A | Impose targeted financial sanctions for terrorism and proliferation financing. |
| FATF Recommendations | The international preventive measure standards for financial institutions that India’s framework is aligned with. |
What counts as an asset reconstruction company in India?
An asset reconstruction company is a company registered with the Reserve Bank of India under section 3 of the SARFAESI Act, 2002, to carry on the business of asset reconstruction or securitisation. ARCs acquire the non-performing assets and bad loans of banks and financial institutions, often at a discount, and seek to resolve them through recovery, restructuring, settlement with the borrower, or the sale of the underlying security. They are financial institutions, not banks, and do not accept public deposits.
The money laundering risk of an ARC is distinctive. The key risks arise from verifying the source of settlement funds, identifying beneficial owners of borrowers and asset buyers, and detecting connected-party transactions or attempts by borrowers or related parties to require assets. Accordingly, ARCs are subject to the full AML, CFT and CPF framework under the PMLA and RBI KYC Directions
Are asset reconstruction companies reporting entities under the PMLA?
Yes. ARCs are reporting entities under the Prevention of Money-Laundering Act, 2002 because they are financial institutions within section 2(1)(l) and therefore fall within the definition of a reporting entity under section 2(1)(wa). which takes its meaning from section 45-I of the Reserve Bank of India Act, 1934. No notification under section 2(1)(sa) is needed, as an ARC is inside the regime by virtue of its registration and business.
This places an ARC in the same broad category of reporting entities that file with FIU-IND as banks and other financial institutions, and within the wider AML laws and regulations for financial institutions in India. The obligations are calibrated to the company’s size and risk, but the status is not optional.
Supervisory authority for asset reconstruction companies in India
The Reserve Bank of India is the primary supervisor for asset reconstruction companies. It registers ARCs under the SARFAESI Act 2002, issues the RBI (Asset Reconstruction Companies – Know Your Customer) Directions, 2025, and supervises compliance through inspections and enforcement. The RBI Internal Risk Assessment Guidance of 2024 compliment these directions by supporting the risk-based approach.
The Financial Intelligence Unit – India receives, analyses and disseminates the reports submitted by ARCs, while the Enforcement Directorate investigates and prosecutes the offences of money laundering under the PMLA. In short, the RBI regulates and supervises the ARCs, FIU-IND receives the intelligence, and the ED enforces the criminal law.
Onboarding clients without a documented due-diligence process?
AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.
AML Regulatory Requirements for Asset Reconstruction Companies in India
The law that governs an asset reconstruction company does not sit in one place. It is a layered framework, and it helps to see it grouped as the core legislation, the overarching obligations, the sectoral supervisor and its directions, the miscellaneous official reports, the international standards, and the allied laws.
The framework reads from the core outward. The PMLA is the parent Act; the PML Rules turn it into operational duties; the RBI Directions translate both into instructions an ARC can follow; the UAPA and the WMD Act add counter terrorism and proliferation financing sanctions; and the allied laws, including each institution’s own establishing statute, shape the risk. The risk-based approach is the thread that runs through it all.
Core Legislation
The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into three catalogues.
AML Legislation
Prevention of Money-Laundering Act, 2002 (PMLA)
India’s primary money laundering law and the source of an ARC’s reporting entity obligations. It defines the offence of money laundering and requires all reporting entities to conduct customer due diligence under Section 11A and record maintenance under Section 12. For ARCs, these obligations are particularly important in asset acquisition and resolution activities, where verifying the identity and beneficial ownership of borrowers and asset buyers, and scrutinising the source of settlement funds, are key AML/CFT controls.
The PML (Maintenance of Records) Rules, 2005 (PMLR)
The rules made under the PMLA, and the layer an ARC functions under on a day-to-day basis. They prescribe the reports to be filed and the timeline for the reporting (Rule 3 and Rule 8), principles of identifying customers and beneficial owners (Rule 9), and describe the duty to appoint a Principal Officer and Designated Director (Rule 7). The PMLR has been amended through 31 Gazette notifications and orders, set out below in chronological order.
| Gazette notification and date | Key change or rule touched |
| G.S.R. 389(E), 24 May 2007 | It broadened the definition of a suspicious transaction under Rule 2 to include transactions lacking an economic rationale or lawful purpose and those indicating possible terrorist financing, revised Rule 3 to cover transactions involving forged or counterfeit currency, replaced Rule 8 on furnishing information to the Director, and simplified Rule 9 by reducing the customer identification document requirement from three certified copies to one. |
| G.S.R. 816(E), 12 November 2009 | An extensive revision. It brought in the non-profit organisation and Regulator definitions, restated the suspicious transaction, and required reporting of NPO receipts over Rupees 10 lakh. Under Rule 6 it set ten-year record retention, and it revised Rule 9 to require beneficial owner identification, ongoing due diligence, a ban on anonymous accounts and a Client Identification Programme. |
| G.S.R. 76(E), 12 February 2010 | Revised Rules 3, 4, 5, 7 and 9 to strengthen the record-keeping and reporting requirements. inserted the first Explanation in Rule 9(1A), fixing beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction is done. |
| G.S.R. 508(E), 16 June 2010 | Revised Rules 2, 9 and 10, explaining transaction monitoring, identification of beneficial owner and the role of reporting entity when suspicion arises on a transaction or customer. |
| G.S.R. 980(E), 16 December 2010 | Brought in the small-account regime, defining the Designated Officer and the small account, adding the NREGA job card and the Aadhaar letter to the officially valid documents in Rule 2, and inserting Rule 9(2A) on how such an account is opened and monitored. |
| G.S.R. 481(E), 24 June 2011 | Gave the Rules their short title, amending Rule 1 to condense the long 2005 name into the Prevention of Money-Laundering (Maintenance of Records) Rules, the PMLR shorthand used since. |
| G.S.R. 576(E), 27 August 2013 | Revised Rules 2 and 3 and inserted provisions after Rule 10, strengthened definitions, the cash and suspicious transaction reporting duties and established record-keeping framework. |
| G.S.R. 288(E), 15 April 2015 | Amended Rule 2 to update key definitions, refining the scope of the PML rules and clarifying the persons and activities covered. |
| G.S.R. 544(E), 7 July 2015 | Revised Rules 2, 9 and 10 and inserted Rule 9A on definitions, customer due diligence and record-keeping, sharpening how a reporting entity identifies customers and what it stores. |
| G.S.R. 730(E), 22 September 2015 | Inserted explanation under Rule 2, clarifying marriage certificate as a supporting document for subsequent name change of officially valid document. |
| G.S.R. 882(E), 18 November 2015 | Substituted the timeline under Rule 9A for government to set up a central KYC records registry from 90 days to 180 days from the enforcement date of the PML rules. |
| G.S.R. 347(E), 12 April 2017 | Revised Rule 2 and inserted Rule 9B, introduced the Central KYC Records Registry into the Rules, requiring reporting entities to upload customer KYC records to the central registry and enabling the retrieval and reuse of the existing KYC records. |
| G.S.R. 538(E), 1 June 2017 | Revised Rules 2 and 9 to use Aadhaar into customer due diligence, prescribing Aadhaar-based identification and authentication for KYC, an approach the Supreme Court’s Aadhaar ruling later reshaped. |
| G.S.R. 1038(E), 21 August 2017 | Revised the Rule 2 definitions, updating the defined terms that govern how the operative rules apply, among several definition changes in 2017. |
| G.S.R. 1318(E), 23 October 2017 | An amendment specifically for the foreign nationals officially valid documents acceptance. |
| G.S.R. 456(E), 16 May 2018 | Inserted clause in Rule 9 regarding the inclusion requirements of sector specific guidelines and the formulation of CCD programme by all the reporting entities. |
| G.S.R. 1078(E), 31 October 2018 | Revised Rule 9 on the timeline for filing of electronic records of customer’s CDD from 3 days to 10 days. |
| G.S.R. 108(E), 13 February 2019 | Amended Rules 2 and 9 on definitions and customer due diligence, after the legislative changes to Aadhaar use, updating the ways identification could be conducted. |
| G.S.R. 381(E), 28 May 2019 | Revised Rule 9, to strengthen customer identification and verification requirements, clarified the permitted methods of verifying a customer’s identity, and align CDD with the post-Aadhaar framework. |
| G.S.R. 582(E), 19 August 2019 | Amended Rules 2 and 9 and inserted annexure after Rule 11, updated definitions, strengthening KYC process and introduced supporting provisions on information and record maintenance. |
| G.S.R. 669(E), 18 September 2019 | Again, revised Rules 2 and 9 sharpening the customer due diligence process dealing with depository receipt along with the definition. |
| G.S.R. 840(E), 13 November 2019 | Revised Rule 9 with further changes to the identification and verification requirements, closing the 2019 run of CDD changes. |
| G.S.R. 228(E), 31 March 2020 | Revised the operational timeline of the small accounts for the year 2020 and further as notified by the central government. |
| G.S.R. 251(E), 13 April 2020 | Revised Rule 8, which governs how transaction reports are furnished to the FIU, changed the timeline for the submission of the report. |
| G.S.R. 254(E), 16 April 2020 | A follow-up Rule 8 revision days after the previous one, changed the timeline for the transaction reporting under Rule 8 for one quarter. |
| G.S.R. 798(E), 28 December 2020 | A landmark widening of the regime. It provided triggers for DPMS and real estate agents to be covered under PMLA and their regulator. |
| G.S.R. 575(E), 13 July 2022 | Inserted the International Financial Services Centre definition with a tailored beneficial owner provision for IFSC entities and added an IFSC proviso to Rule 9A on the CKYCR, aligning the Rules with the GIFT City regime. |
| S.O. 1074(E), 7 March 2023 | The first major amendment of 2023 inserted definitions of politically exposed persons, group and non-profit organisations; introduced, a duty for group under Rule 3A; and reduced the beneficial ownership threshold for trust from 25 to 10 per cent, with a corresponding change to Rule 9(3)(e). These changes are of direct relevance to ARCs assessing corporate borrowers and asset buyers. |
| G.S.R. 652(E), 4 September 2023 | The second major 2023 amendment. Amended Rules 2, 9 and 10, by requiring the Principal Officer to be at the management level, reduced the partnership beneficial ownership threshold from 15 to 10 per cent, inserted an Explanation of control and mandated trustees to disclose their status before commencement of account-based relationship. |
| G.S.R. 745(E), 17 October 2023 | Revised Rules 2, 3, 8 and 9 key definitions, reporting obligations, maintenance of record and customer due diligence requirements, refining the operational framework. |
| G.S.R. 419(E), 19 July 2024 | Revised Rule 9(1C) requiring reporting entities to update a customer’s CKYCR record within seven days of any change and retrieve the updated record. Amended Rule 9A(2)(g) to strengthen the requirements for filing, retrieving and using CKYCR records, ensuring central KYC information remains accurate and up to date. |
The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005
Rules for accepting customer records authenticated outside India, relevant to an ARC that deals with a foreign investor or an overseas buyer of an acquired asset and must rely on identity and ownership documents executed and certified by a foreign certifying authority.
CFT Legislation
The Unlawful Activities (Prevention) Act, 1967 (UAPA)
India’s primary statute on countering terrorism. Section 51A of the Act requires all reporting entities, including ARCs to screen customers and beneficial owners against the designated lists and to freeze, without delay, the funds and assets of listed persons and entities, whatever the size and value of the exposure.
Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigenda dated 15 March 2023 and 29 August 2023)
The official procedure for implementing Section 51A. It sets out the process for screening customers against designated sanctions lists, freezing the funds or assets of designated persons and entities without delay, and reporting matches to the intelligence authority. Further, supported by the RBI Directions.
CPF Legislation
The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)
India’s primary statute on proliferation financing. Section 12A of the Act requires all the reporting entities, including ARCs, particularly where an acquired asset or a settlement has a cross-border dimension, to implement targeted financial sanctions by identifying and freezing the funds or assets of designated persons and entities without delay, and reporting matches to the competent authority.
Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)
The official procedure for applying Section 12A mirrors the Section 51A of the UAPA screening and freezing steps, applied by an ARC alongside the designated terrorism list screening.
The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016
Rules implementing the WMD Act and supporting the proliferation financing controls an ARC must operate through.
Not registered with FIU-IND yet, or unsure whether you have to be?
AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.
Overarching Obligations
The shared national framework that an ARC plugs into as a reporting entity.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
The guidelines govern the Central KYC Records Registry, which stores customer KYC records centrally. It enables ARCs to upload and reuse a customer’s KYC records, promoting consistent customer identification and reducing duplication. The guidelines also provide detailed requirements for capturing customer and beneficial ownership accurately, making KYC onboarding and updates more efficient.
FINnet 2.0 reporting formats (2024) and the FINGate 2.0 user manuals
The FIU-IND reporting framework and its filing platform, ARCs use FINnet 2.0 to submit prescribed regulatory reports, while the FINGate 2.0 user manuals provide instructions on enrolment, user management, report submission, and request-response processes.
Section Aadhaar Authentication Procedure for Reporting Entities (9 May 2019)
The procedure for reporting entities other than banking companies to apply to use Aadhaar authentication services, relevant where an ARC verifies an individual’s identity through Aadhaar.
Sectoral Guidelines
The supervisor and its directions. The Reserve Bank of India regulates ARCs and issues the KYC Directions the institution works from, read with its consolidated master directions and internal risk-assessment guidance.
Reserve Bank of India
The RBI (Non-Banking Financial Companies - Know Your Customer) Directions, 2025
The principal AML CFT, and CPF rulebook for ARCs. Issued by the RBI on 28 November 2025 and updated as of 29 December 2025, the Directions apply to all RBI-registered asset reconstruction companies and their branches and majority-owned subsidiaries. They set out detailed requirements for customer due diligence, beneficial owner identification, risk assessment, governance, appointment of Designated Director and Principal Officer, regulatory reporting, record keeping and compliance with Sections 51A and 12A of UAPA and WMD Act respectively. Where the PMLA and rules establish the legal obligations, these directions explain how ARCs must implement them.
RBI Consolidated Master Directions and the KYC compliance notification (28 November 2025)
On 28 November 2025, the RBI issued its consolidated master directions and a notification on compliance with KYC norms, under which the specific KYC Directions for ARCs were made, and earlier consolidated KYC directions for all the sub- sectors regulated by the RBI stand repealed and superseded to the extent provided.
RBI Internal Risk Assessment (IRA) Guidance for ML/TF Risks (2024)
The RBI guidance that calls the internal risk assessment the bedrock of the risk-based approach and requires its documented outcome to go to the board, applied by every ARC in preparing and updating its risk assessment.
Miscellaneous official Reports and Guidance
Official instruments that sit outside the binding rulebook but shape how an ARC reads its risk and its duties.
FIU-IND Annual Report 2024-25
The national FIU’s annual report provides an overview of the reports it received, analysed and disseminated during the year. It offers a useful insight into reporting volumes, typologies and regulatory priorities across different categories of reporting entities.
Directorate of Enforcement Annual Report 2025-26
The Enforcement Directorate’s annual report of investigations, provisional attachments and prosecutions under the PMLA, showing how the criminal enforcement end of the framework is used.
FIU-IND and its Core Functions and FAQs
A plain explanation of what FIU-IND does and how reporting works, a useful primer for an institution’s reporting function.
MHA National Counter Terrorism Policy and Strategy
The Ministry of Home Affairs statement of national counter terrorism policy, which frames the CFT duties that Section 51A places on an ARC.
International Standards
The global benchmarks India is measured against, and the sources an ARC can use to calibrate a risk-based approach.
FATF Recommendations
The international AML, CFT and CPF standards, against which India’s framework for ARCs is aligned. Recommendations 9 to 23 set out preventive measures applicable to financial institutions. In its June 2026 update, the FATF amended recommendations 6 and 16, including changes relating to humanitarian and basic human needs exemptions under targeted financial sanctions, and launched public consultation on improving transparency in cross-border payments.
FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)
The peer assessment of India’s AML and CFT system, which examined how the financial sector’s preventive measures and supervision work in practice and identified the shortcomings in the framework that India needs to address.
Basel Committee, Sound Management of Risks Related to Money Laundering and Financing of Terrorism (2014, revised July 2020)
The Basel Committee guidance on managing ML and TF risk, a benchmark for the risk-based approach and group-wide controls that an ARC can read across to its own risk management.
FATF Risk-Based Approach Guidance for the Banking Sector (2014)
FATF sector guidance on applying the risk-based approach in banking and financial institutions, useful to an ARC in shaping its customer due diligence and monitoring standards.
Allied Laws
The wider body of law that defines each institution’s own mandate and the predicate offences and enforcement machinery around money laundering. A hire purchase company operates under the RBI Act, 1934, while the predicate and enforcement Acts shape the risk it must assess and the conduct it may need to report.
The Prevention of Money Laundering Act, the Rules made under it, and directions issued for the AML, CFT and CPF obligations for asset reconstruction companies do not operate in isolation. The mentioned allied statutes support this framework by governing the registration and supervision of ARCs, defining their powers to acquire and enforce financial assets, establishing predicate offences that may generate proceeds of crime, enabling the tracing and confiscation of illicit assets and strengthening measures against ML, TF and PF.
The statutes that most directly influence an ARC’s risk include the Reserve Bank of India Act, 1934, the Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002 (SARFAESI), the Companies Act, 2013, the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Foreign Exchange Management Act, 1999, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974 (COFEPOSA), the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976 (SAFEMA), the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.
Core AML/CFT/CPF Obligations for Asset Reconstruction Companies in India
The regulatory framework requires an ARC to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.
- Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the institution can file its reports.
- Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR and the RBI Directions. The same person cannot hold both roles, and both are to be informed to FIU-IND and the RBI.
- Conduct the internal risk assessment. Run an ML and TF risk assessment across customers, products, channels and geographies, document it, and take its outcome to the board, as the RBI Directions and the IRA Guidance require.
- Document AML policy, controls and procedures. Adopt a board-approved policy that turns the risk assessment into the institution’s operating procedures.
- Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high-risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the RBI ARC KYC Directions 2025. Given the resolution business, the identification of borrowers settling acquired debts, the buyers of acquired assets and their beneficial owners is central.
- Ongoing monitoring and periodic Monitor transactions on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low-risk customers respectively. Review each customer’s risk categorisation at least once every six months.
- Sanctions screening. Screen customers and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
- Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit-currency reports and, for an ARC with a cross-border settlement or asset sale, cross-border wire transfer reports of Rupees 5 lakh or more where applicable, under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly, through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train staff by role to apply the controls and recognise red flags in stressed-asset acquisition and resolution.
- Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
- Run group-wide controls. Where the institution has subsidiaries, apply AML and CFT programmes at group level, including for branches and majority-owned subsidiaries, as the RBI Directions require.
What this article does not cover
This article explains the AML, CFT and CPF legal and regulatory framework that applies to asset reconstruction companies under the PMLA, RBI directions and supporting legislation. It does not provide detailed implementation guidance or a control-by-control compliance manual. Working programme topics such as KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction reporting, staff training, audit testing and board oversight are covered in the companion compliance guide.
For the broader regulatory context, see AML laws and regulations for financial institutions in India, and AML laws and regulations in India.
From regulation to compliance: your next step
Knowing the law is step one; ARCs must translate these obligations by building a working programme of risk assessment, policy and procedure, customer due diligence, ongoing monitoring, sanctions screening, prescribed report submission, training and independent review. For an asset reconstruction company, the identification of borrowers and asset buyers and their beneficial owners and the scrutiny of the source of settlement funds are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.
Want to confirm the 2025 directions for your institution?
AML India can walk you through the RBI hire purchase company KYC Directions and build a proportionate programme for an asset-finance business
Frequently Asked Questions
A company registered with the Reserve Bank of India under section 3 of the SARFAESI Act 2002, to carry on the business of asset reconstruction or securitisation. An ARC acquires the non-performing and bad loans of banks and financial institutions and resolves them through recovery, restructuring, settlement with the borrower, or the sale of the underlying security. It is a financial institution and does not take deposits from the public.
Yes. ARCs are reporting entities under section 2(1)(wa) of the PMLA because it is a financial institution within section 2(1)(l), which takes its meaning from section 45-I of the RBI Act, 1934.
A hire purchase company deals mainly with corporate borrowers, selling banks and the buyers of acquired assets rather than retail customers over a counter, so its customer due diligence centres on those parties and their beneficial owners, and on the source of settlement funds. Where a hire purchase company deals with individual borrowers or buyers, ordinary KYC applies. The full AML framework applies in either case.
Yes, although ARCs primarily deal with corporate borrowers, selling banks and buyers of acquired assets rather than retail customers, they must carry out standard KYC whenever they deal with individual borrowers or buyers. Their customer due diligence is therefore focused mainly on legal entities, beneficial ownership and the source of settlement funds, while the full AML framework applies in all cases.
ARCs must file Cash Transaction Reports (CTR) for cash above Rupees 10 lakh, Suspicious Transaction Reports (STR) of any value, Counterfeit Currency Reports (CCR) where applicable, and Cross-Border Wire Transfer Reports (CBWTR) for qualifying cross-border wire transfers of Rupees 5 lakh or more. Reports are filed through FINnet 2.0; CTRs, CCRs, and CBWTRs are due by the 15th of the succeeding month, while STRs must be filed promptly after suspicion arises.
Yes. Every ARC must comply with sanctions obligations under Section 51A of the UAPA, and Section 12A of the WMD, regardless of the size or value of the exposure. ARCs must screen customers and beneficial owners against the United Nations and domestic designated lists, without delay. If a match is identified, the ARC must immediately freeze their funds and submit the required report to competent authority.
Official sources and review
Last reviewed: July 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
- Prevention of Money-Laundering Act, 2002 (India Code)
- Prevention of Money-Laundering (Maintenance of Records) Rules, 2005
- RBI (Asset Reconstruction Companies – Know Your Customer) Directions, 2025 (Reserve Bank of India)
- RBI Internal Risk Assessment Guidance for ML/TF Risks, 2024 (Reserve Bank of India)
- Unlawful Activities (Prevention) Act, 1967 and Section 51A procedure
- WMD Act, 2005 and its Section 12A implementation procedure (India Code)
- FATF Recommendations, including the June 2026 update to Recommendation 6
- FATF Mutual Evaluation Report on India, 2024
- Basel Committee, Sound Management of Risks Related to ML and TF (2014, revised July 2020)
- Financial Intelligence Unit – India, including the Annual Report 2024-25
- Central KYC Records Registry (CKYCR) Operating Guidelines, 2025 (CERSAI)
Why work with AML India
AML India provides end-to-end guidance to help asset reconstruction companies meet their PMLA and RBI compliance obligations, from enterprise-wide risk assessment and policy development to CDD, sanctions screening, ongoing monitoring, report submission, staff training and independent audit.
Industries we serve: Asset Reconstruction Companies, NBFCs, Housing Finance, Mortgage Guarantee and Asset Reconstruction Companies, Insurers, Payment System Operators and Aggregators, Banks, DNFBPs, Securities Intermediaries and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik