Last Updated on: 4th August 2026 | Last Reviewed on: 4th August 2026
Key takeaways at a glance
- Who is covered: Any person carrying on one or more of the notified trust and company service activities on behalf of another person in the course of business, This includes firms that act as company or LLP formation agents, provide or arrange directors, secretary or partner, provide registered offices or business addresses, act as trustee of an express trust on behalf of clients, or provide nominee shareholder services, as notified under section 2(1)(sa)(vi) of the PMLA.
- The trigger: The notified activity undertaken by the service provider is the trigger, not the type of business or profession nor any monetary threshold.
- Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the FIU-IND AML/CFT Guidelines for TCSPs, effective from 21 April 2026; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
- Regulator: the Financial Intelligence Unit – India (FIU-IND), which supervises TCSPs directly and receives their reports. The Enforcement Directorate (ED) enforces the PMLA.
- Core duties: registration with FIU-IND, an internal risk assessment, customer due diligence and KYC, beneficial owner identification, ongoing monitoring, suspicious transaction reporting, five-year record-keeping and sanctions screening.
This guide is general information on Indian law, not legal advice. For your services-specific position, speak to a qualified AML professional.
Trust and company service providers, known as TCSPs, are reporting entities under the Prevention of Money-Laundering Act, 2002. A firm is caught not by a turnover or cash figure, but by what it does: forming companies and limited liability partnerships, providing directors, secretaries or partners, providing a registered office or address, or acting as a trustee, in each case on behalf of a client. From the moment it carries out one of those activities, its AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the AML/CFT Guidelines for TCSPs, the UAPA, the WMD Act and the FIU-IND reporting framework. Here, the Financial Intelligence Unit of India is both the regulator and the body that receives the reports.
The core instruments at a glance
Instrument | What it does for a provider |
PMLA, 2002 | The parent legislation. Makes a provider a reporting entity and creates the core duties of CDD, record-keeping and reporting. |
PML (Maintenance of Records) Rules, 2005 | Set out what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. |
S.O. 2135(E), 9 May 2023 | The notification that designates the trust and company service activities, with no turnover or cash threshold. |
AML/CFT Guidelines for TCSPs (FIU-IND) | The provider’s working rulebook, issued by the regulator, effective from 21 April 2026. |
UAPA Section 51A and WMD Act Section 12A | Impose targeted financial sanctions for terrorism and proliferation financing, applied by every service provider. |
FATF Recommendations 22 and 23 | The international standards for DNFBPs that India’s TCSP regime is built to meet, supported by the FATF TCSP guidance of 2019. |
What counts as a trust or company service provider in India?
TCSP is any person who, in the course of business and on behalf of another person, carries out one or more of the activities notified by the central government under Notification S.O. 2135 (E) dated 9 May 2023. These activities include acting as a formation agent for companies or limited liability partnerships(LLPs); acting as, or arranging for another person to act as, a director, secretary of a company or a partner of a firm; providing a registered office, business or correspondence address for a company, LLP or trust; acting as, or arranging for another person to act as, a trustee of an express trust or performing an equivalent function; and acting as, or arranging for another person to act as, a nominee shareholder.
The classification depends on the activity performed, not the type of business or profession. Accordingly, any person or firm that provides one or more of these notified services during business is treated as a reporting entity under the PMLA. The notification also excludes certain limited activities, including the filing of the incorporation declaration under section 7(1)(b) of the Companies Act, 2013 by an advocate, chartered accountant, cost accountant or company secretary in practice. TCSPs are specifically brought within the framework because the services they provide can be used to establish or administer shell companies; appoint nominee directors and create opaque trust structures, all of which can be exploited to conceal beneficial ownership, disguise the movement of illicit funds, and facilitate money laundering.
Are trust and company service providers reporting entities under the PMLA?
Yes. Trust and company service providers (TCSPs) are reporting entities under the Prevention of Money-Laundering Act, 2002 when they carry out the specified activities notified by the central government under section 2(1) (sa)(vi)through notification by S.O. 2135(E) of 9 May 2023. As a result, they fall within the definition of the reporting entity under section 2(1) (wa) of the PMLA.
Once the service provider becomes a reporting entity, it must register with FIU-IND and comply with the obligations prescribed under the PMLA. IN doing so, TCSPs become part of the wider category of reporting entities that submit to FIU-IND alongside banks and other financial institutions. Because their services can be used to build the very structures criminals rely on, TCSPs sit close to the misuse of shell companies, and they form part of the DNFBPs subject to the PMLA group.
Supervisory authority for trust and company service providers in India
Trust and company service providers are supervised directly by the Financial Intelligence Unit of India. FIU-IND issues the AML/CFT Guidelines that TCSPs rely upon and designates eligible service providers as reporting entities. It receives, analyses and disseminates their reports. In this sector, the supervisory authority and the reporting hub are the same body.
The Financial Intelligence Unit – India therefore both sets the rules and takes the filings, while the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. Accordingly, a service provider engages with FIU-IND for registration, guidance and reporting and compliance.
Onboarding clients without a documented due-diligence process?
AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.
AML Regulatory Requirements for Trust and Company Service Providers in India
The law that governs a trust and company service provider is built on several interconnected layers: the core legislation, the overarching obligations, the sectoral regulator and its guidelines, the miscellaneous official reports, the international standards, and the allied laws.
Core Legislation
The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into three categories.
AML Legislation
Prevention of Money-Laundering Act, 2002 (PMLA)
India’s parent anti-money laundering statute and the source of a service provider’s reporting entity status. It defines the offence of money laundering and imposes the duties of customer due diligence under Section 11A and record-keeping under Section 12 that a formation agent or corporate trustee must apply to every client engagement. Because the services a provider offers can be used to construct the corporate and trust structures that disguise ownership, the Act reaches the firms that build them, not only the banks that hold the accounts.
The PML (Maintenance of Records) Rules, 2005 (PMLR)
The operational rulebook made under the PMLA, and the instrument that a service provider applies in practice. The PMLR prescribes the records and reports to be maintained and submitted, including reporting obligations under Rules 3 and 8, sets out the customer due diligence and beneficial ownership requirements under Rule 9, requires the appointment of a Principal Officer and Designated Director under Rule 7, and under Rule 7(3), obliges every reporting entity to establish an internal mechanism for detecting suspicious transactions. Since their introduction, the PMLR has been amended through 31 Gazette notifications and orders, set out below as a legal history timeline.
The 31 PMLR Amendment Notifications, in Date Order:
| Gazette notification and date | Key change or rule touched |
| G.S.R. 389(E), 24 May 2007 | It modified Rule 2 concept of a suspicious transaction to include dealings without economic rationale or bona fide purpose and those indicative of terrorism financing, altered Rule 3 around cash dealings in forged or counterfeit currency, substituted Rule 8 on the furnishing of information to the Director, and decreased Rule 9’s three certified copies requirement to one. |
| G.S.R. 816(E), 12 November 2009 | It brought the non-profit organisation and Regulator in the ambit of Act, revised the suspicious transaction meaning, and added reporting of NPO receipts over Rupees 10 lakh. Under Rule 6 it fixed record retention at ten years, and it amended Rule 9 to require beneficial owner identification, ongoing due diligence, a furnished bar on anonymous accounts and a Client Identification Programme. |
| G.S.R. 76(E), 12 February 2010 | Revised Rules 3, 4, 5 and 7 to refine record-keeping and the reporting cross-references, further inserted the first Explanation in Rule 9(1A), defining the beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction takes place. |
| G.S.R. 508(E), 16 June 2010 | Amended Rules 2, 9 and 10, the definitions, customer due diligence and record-keeping provisions, altering how a reporting entity identifies customers and what it must preserve, part of the continued 2010 tightening of the CDD and records regime. |
| G.S.R. 980(E), 16 December 2010 | Established the small-account regime. It defined the Designated Officer and the small account, brought the NREGA job card and the Aadhaar letter into the officially valid documents in Rule 2, and added Rule 9(2A) on the opening and monitoring of such an account. |
| G.S.R. 481(E), 24 June 2011 | Through revising Rule 1 it abbreviated the long name to the Prevention of Money-Laundering (Maintenance of Records) Rules, the PMLR label used ever since. |
| G.S.R. 576(E), 27 August 2013 | Modified Rules 2, 3, 7,8,9 and inserted Rule 10A, provided definitions of CDD and designated director, explained the record maintenance of all the transactions and it’s reporting duties and the procedure and for CCD, manner of furnishing. Information, internal audit. |
| G.S.R. 288(E), 15 April 2015 | Revised the Rule 2 definitions. As definitions determine the scope of the operative provisions, the amendment had a cascading effect across the framework and started a run of 2015 updates. |
| G.S.R. 544(E), 7 July 2015 | Inserted provisions into Rules 2 and 9, introducing Definitions relating to KYC and its national registry. It strengthened the framework for customer identification dn record maintenance as part of the wider 2015 haul. |
| G.S.R. 730(E), 22 September 2015 | Revised the reporting framework by empowering the director to prescribe reporting procedures and formats in consultation with the relevant regulator, while also clarified the validation of official documents after the name change. |
| G.S.R. 882(E), 18 November 2015 | Revised the definitions and reporting provisions refined the interpretation of the key terms and reporting framework and marked the end of the 2015 cluster of amendments. |
| G.S.R. 347(E), 12 April 2017 | Amended Rule 2 and inserted Rule 9A, bringing the Central KYC Records Registry into the Rules by requiring reporting entities to upload customer KYC records centrally and enabling their retrieval and reuse across reporting entities. |
| G.S.R. 538(E), 1 June 2017 | Revised Rules 2 and 9 to embed Aadhaar in customer due diligence, prescribing Aadhaar-based identification and authentication for KYC, an approach later reshaped by the Supreme Court’s Aadhaar decision. |
| G.S.R. 1038(E), 21 August 2017 | Amended the Rule 2 definitions, adjusting the defined terms that govern how the operative rules apply, one of several 2017 definition updates. |
| G.S.R. 1318(E), 23 October 2017 | A subsequent 2017 revision of the Rule 2 definitions, keeping the defined terms aligned as the framework advanced. |
| G.S.R. 456(E), 16 May 2018 | Inserted clauses under Rule 9 regarding customer due diligence, clarifying how customers are identified and verified, in the ongoing adjustment of the CDD framework. |
| G.S.R. 1078(E), 31 October 2018 | Revised Rule 9 on customer due diligence, refining the steps a reporting entity follows to identify and verify customers and beneficial owners. |
| G.S.R. 108(E), 13 February 2019 | Amended Rules 2 and 9 on definitions and customer due diligence, in the aftermath of the legislative changes to Aadhaar use and altered the ways identification could be carried out. |
| G.S.R. 381(E), 28 May 2019 | Inserted a proviso under Rule 9 relating to an individual’s identification requirement. |
| G.S.R. 582(E), 19 August 2019 | Amended Rules 2 and 9 and inserted annexure after Rule 11, covering definitions, customer due diligence and the supporting provisions on information and records, one of the broader 2019 revisions. |
| G.S.R. 669(E), 18 September 2019 | Inserted definitions under Rule 2 and under Rule 9 sharpened the customer due diligence process within the 2019 sequence of CDD amendments. |
| G.S.R. 840(E), 13 November 2019 | Modified Rule 9 with further refinements to the identification and verification requirements, ending the 2019 series of CDD changes. |
| G.S.R. 228(E), 31 March 2020 | Amended Rule 9 to extend the validity of small accounts, allowing the reporting entities to operate such accounts for the prescribed period while completing the CDD. |
| G.S.R. 251(E), 13 April 2020 | Revised Rule 8, to strengthen the principals of manner and content in which the prescribed reports are to be submitted to FIU-IND. |
| G.S.R. 254(E), 16 April 2020 | A further Rule 8 amendment days after the previous one, together tightening the reporting provisions and the route by which reports reach the FIU. |
| G.S.R. 798(E), 28 December 2020 | Amended Rule to revise the definition of regulator by specifying the competent authorities for DNFBPs, thereby strengthening the framework. |
| G.S.R. 575(E), 13 July 2022 | Inserted the International Financial Services Centre definition together with a supporting beneficial owner provision for entities based in Gift City and added an IFSC proviso to Rule 9A on the CKYCR, fitting the Rules to the regime. |
| S.O. 1074(E), 7 March 2023 | A major change directly relevant to a provider. It added definitions of politically exposed persons, non-profit organisations and group and a Rule 3A duty for group-wide AML policies and cut the company beneficial ownership threshold from 25 to 10 per cent, with a matching change to Rule 9(3)(e), pulling more corporate owners into view. |
| G.S.R. 652(E), 4 September 2023 | The second major 2023 amendment, of particular weight for trustees. It required the Principal Officer to be at management level, cut the partnership beneficial ownership threshold from 15 to 10 per cent, added an Explanation of control, obliged trustees to disclose their status, and added the results of any Rule 3 and Rule 9 analysis to the records a reporting entity keeps. |
| G.S.R. 745(E), 17 October 2023 | Revised Rules 2, 3, 3A, 8 and 9 together, spanning definitions, the reporting duties and customer due diligence, refining several operative provisions in a single notification and completing the 2023 changes. |
| G.S.R. 419(E), 19 July 2024 | Amended Rule 9(1C) on the KYC Identifier and imposed a seven-day deadline to update a CKYCR record after any change, added a duty to pull the updated record, and modified Rule 9A(2)(g) on filing, retrieving and using registry records, tightening how current central KYC data is maintained. |
The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005
Rules on accepting customer records authenticated outside India. For a service provider, they are routinely in play, because forming a company for an overseas client or acting as trustee for a foreign settlor means relying on identity and ownership documents executed, notarised and certified abroad rather than in India.
CFT Legislation
The Unlawful Activities (Prevention) Act, 1967 (UAPA)
India’s principal counter terrorism statute. Its Section 51A obliges a service provider to screen clients, settlors, beneficiaries and beneficial owners against the designated terrorism lists and to freeze, without delay, the funds and assets of any listed person or entity. This screening obligation binds every service provider from the first client engagement.
Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023 and 29 August 2023)
The simple procedure a service provider has to follow to give effect to Section 51A when a client or a party to a structure matches a designated list. FIU-IND folds the screening and freezing steps into the AML/CFT Guidelines that TCSPs work from, so the statutory order becomes a rigid workflow.
CPF Legislation
The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)
India’s counter-proliferation financing Act. Its Section 12A provides the legal basis for targeted financial sanctions aimed at the financing of weapons of mass destruction, and it reaches a service provider because a shell company or a nominee arrangement can be used to move value for a sanctioned procurement network as readily as any account.
Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)
The implementation procedure for Section 12A, which provides screening and freezing steps for proliferation financing designations list matches. For a service provider, it is applied through the sector-specific FIU-IND Guidelines, so terrorism and proliferation lists are both checked before a company is formed or a trusteeship is accepted.
The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016
The supporting rules that put the WMD Act into operation and support the Designated list handling, freezing and reporting actions a service provider must be able to carry out the moment a proliferation financing designation match arises in a client relationship.
Not registered with FIU-IND yet, or unsure whether you have to be?
AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.
Overarching Obligations
The shared national structure that a service provider navigates through once it is a reporting entity.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
The operating guidelines for the national KYC registry. It sets out how a reporting entity uploads, retrieves, and updates customer KYC records through the registry. For a TCSP service provider, often onboarding the same corporate client for several services, the guidelines facilitate the reuse of verified KYC information across engagements, reducing duplication while promoting consistency in customer identification and beneficial ownership verification.
FINnet 2.0 reporting formats (2024) and the FINGate 2.0 user manuals
The FIU-IND reporting platform, together with the 2024 reporting formats and the FINGate 2.0 user manuals, through which reporting entities enrol, register and submit prescribed reports under the PMLA. For TCSPs, registration on the portal is one of the first practical compliance steps after becoming a reporting entity.
Section 11A Aadhaar Authentication Procedure for Non-Banking Entities (9 May 2019)
The procedure by which an entity other than a banking company applies for permission to use Aadhaar authentication services for KYC. It matters to TCSP service providers because they are DNFBPS and not the banking sector reporting entities. Therefore, they must obtain the approval before verifying a client’s identity through Aadhaar.
Sectoral
The regulator and its service provider-specific instruments. This is the layer that gives the TCSP regime its distinct character, because the same body, FIU-IND, writes the rulebook, registers the firms and receives their reports.
Financial Intelligence Unit - India (FIU-IND)
AML/CFT Guidelines for Trust and Company Service Providers (effective 21 April 2026)
The principal operational guidance for TCSP service providers, and the most important instrument on this page. Issued by FIU-IND, the Guidelines explain how TCSPs are to comply with their obligations as reporting entities under PMLA. They require service providers to establish policies and procedures, risk assessment, customer due diligence, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction reporting, record-keeping, Internal audit and the appointment of a Designated Director and a Principal Officer, together with implementation of Sections 51A of UAPA and 12A of the WMD Act. The Guidelines took on 21 April 2026 and provide the practical detail behind the statutory obligations discussed throughout this article.
Registration of TCSPs with FIU-IND on the FINnet 2.0 portal as reporting entities
The FIU-IND process by which a trust or company service provider enrols on the FINnet 2.0 portal as a reporting entity, the practical first step once a firm starts offering the notified services, ahead of any reporting.
Notification designating TCSPs as DNFBPs, S.O. 2135(E) (9 May 2023)
The notification that brings specified trust and company service provider activities within the scope of section 2(1)(sa)(vi) of the PMLA by designating them as reporting entities. It covers five activities: acting as a formation agent, director, secretary or partner, registered office provider, acting as trustee, and acting or arranging to act as nominee shareholder. It also excludes incidental company formation work by an advocate or a chartered accountant, cost accountant or company secretary professional in practice.
Miscellaneous
Official reports and guidance that sit outside the binding rulebook but shape how a provider reads its risk and its duties.
FIU-IND Annual Report 2024-25
The national FIU’s annual account of the reports it received, analysed and disseminated. As FIU-IND is also the provider’s regulator, this report is a direct read on the supervisor’s priorities and on how DNFBP reporting is developing across sectors.
Directorate of Enforcement Annual Report 2025-26
The Enforcement Directorate’s annual report of investigations, provisional attachments and prosecutions under the PMLA. It shows how the criminal enforcement end of the framework is used, including cases turning on shell companies and nominee structures.
FIU-IND and its Core Functions and FAQs
An easy-to-understand explanation of what FIU-IND does and how reporting works. For a TCSP service provider whose regulator and reporting hub are the same body, it is a useful first primer when standing up the reporting function and enrolling on FINnet 2.0.
MHA National Counter Terrorism Policy and Strategy
The Ministry of Home Affairs statement of national counter terrorism policy and strategy. It frames the broader intent behind the CFT duties that Section 51A places on a provider, and answers why sanctions screening applies from the first client engagement.
International Standards
The global benchmark India is measured against, and the sources a provider can use to calibrate a risk-based approach to company and trust services.
FATF Recommendations
The international AML, CFT and CPF standards on which India’s framework is based. Recommendations 22 and 23 bring trust and company service providers into customer due diligence and suspicious transaction reporting requirements applicable to DNFBPs. The recommendations were last updated by FATF in June 2026, with significant revisions to recommendation 6 on targeted financial sanctions. These continue to shape the development and interpretation of India’s national framework.
FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)
The evaluation of India’s system, with a separate executive summary. It assessed the national legal framework and its implementation across reporting entities. It provides insights into how DNFBP supervision and reporting operate in practice, identifies company and trust services as higher-risk activities, and highlights the areas where the regulatory framework is expected to tighten further.
FATF Risk-Based Approach Guidance for Trust and Company Service Providers (2019)
Sector-specific FATF guidance on the money laundering risks in company formation, nominee and trustee services, and how to manage them under a risk-based approach. It is a simple, procedure-led template for a provider’s internal risk assessment, covering red flags related to opaque ownership and the controls a TCSP should have in place.
Allied Laws
The supporting body of law that defines the offences and the enforcement powers and underlying criminal conduct relevant to money laundering, together with the statutes that govern the legal vehicles that a TCSP service provider creates and administers. A service provider does not administer these Acts, but they shape the risk it must assess and the conduct it may need to report.
The allied laws that most often bear on a provider’s risk are the following:
The Indian Trusts Act, 1882: Governs the creation and administration of trusts, supporting the identification of settlors, trustees, beneficiaries and ownership arrangements.
The Limited Liability Partnership Act, 2008: Regulates the incorporation and management of LLPS, making it relevant for when TCSPs establish and administer LLPs.
The Companies Act, 2013: Central to company formation, directorships and registered offices, forming the legal basis for TCSP companies.
The Bharatiya Nyaya Sanhita, 2023, and The Bharatiya Nagarik Suraksha Sanhita, 2023: These Acts create offences that constitute predicate offences under the PMLA and provide enforcement procedures for their administration.
The Benami Transactions (Prohibition) Act, 1988: prohibits concealed ownership arrangements and is therefore directly relevant where a nominee holds property or shares.
The Foreign Exchange Management Act, 1999, The Prevention of Corruption Act, 1988, The Narcotic Drugs and Psychotropic Substances Act, 1985, The Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, The Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974 (COFEPOSA), The Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976 (SAFEMA), The Arms Act, 1959, The Chemical Weapons Convention Act, 2000 and The Central Vigilance Commission Act, 2003 do not directly regulate the TCSP sector for AML, CFT and CPF purpose. However, they remain relevant because they address criminal conduct and regulatory risk that may generate proceeds of crime and give rise to heightened AML, CFT and CPF risks.
Core AML/CFT/CPF Obligations for Trust and Company Service Providers in India
Across that framework, the regulations require a trust or company service provider to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each. Correspondent banking and wire-transfer duties are not included here because they do not apply to a provider.
- Register with FIU-IND. Enrol with the Financial Intelligence Unit India on the FINnet 2.0 / FINGate 2.0 portal once the firm begins offering the notified trust or company services, so the provider can file its reports.
- Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR. The same person cannot hold both roles, and both are to be informed to FIU-IND.
- Conduct the internal risk assessment. Assess money laundering, terror financing and proliferation financing risk across client types, services, structures and geographies, drawing on the FATF TCSP guidance, and keep it current.
- Document AML policy, controls and procedures. Adopt an approved policy that turns the risk assessment into the firm’s operating procedures, as required by the FIU-IND Guidelines.
- Customer identification and CDD. Identify and verify every client and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals; for a trust, the author, the trustees, beneficiaries with a 10 per cent or more interest and any person exercising ultimate control), with enhanced due diligence for politically exposed persons and high-risk clients, under Section 11A of the PMLA, Rule 9 of the PMLR and the FIU-IND Guidelines. Look through nominee arrangements to the natural person behind the structure.
- Ongoing monitoring and periodic update. Monitor the client relationship on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low-risk clients respectively. Review each client’s risk categorisation at least once every six months and decide whether enhanced due diligence is required.
- Sanctions screening. Screen clients, settlors, beneficiaries and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act and freeze and report any match. Verify the relevant UNSC and domestic designated lists daily. This duty applies to every provider, from the first engagement.
- Regulatory reporting. File suspicious transaction reports of any value, including attempted transactions, promptly once the Principal Officer is satisfied that a transaction is suspicious, under Rule 8(2) of the PMLR. Where a provider handles cash, it must also file cash transaction reports for cash over Rupees 10 lakh and reports on cash transactions involving counterfeit currency or forged documents, filed monthly by the 15th day of the succeeding month, under Rule 3. Reports are made through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction and keep identity records and business correspondence for five years after the business relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the Central KYC Records Registry under Rule 9A, reuse an existing record where applicable, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train staff in correspondence with their role to apply the controls and recognise the red flags of shell-company and nominee-based laundering.
- Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
What this article does not cover
This article explains the laws and regulatory instruments that apply to trust and company service providers for AML, CFT and CPF purposes. It is intended to provide an overview of the legal and regulatory framework; accordingly, it does not provide a control-by-control compliance manual and does not restate the company, LLP and trust law that governs the vehicles a provider creates, except where that law bears on money laundering risk. For implementation, a provider separately documents client acceptance, KYC and CDD procedures, beneficial owner identification and nominee verification, sanctions screening, transaction monitoring, suspicious transaction reporting, staff training, audit testing and management reporting. Those controls are the subject of the companion compliance guide.
To see how the provider framework fits within the national picture, see AML laws and regulations in India, and use the parent overview, AML laws and regulations for DNFBPs in India, to see how providers sit alongside the other designated businesses and professions.
From regulation to compliance: your next step
Knowing the law is only the first step. These obligations protect a firm only when they are embedded in a practical programme of risk assessment, policy and procedure, customer due diligence, ongoing monitoring, screening, reporting, training and independent audit. Because a provider’s core services can create structures that obscure true ownership, identifying and verifying beneficial owners remains most important control. The safest approach is therefore to apply the programme from the very first client engagement. Understanding the three stages of money laundering and how the sanctions screening process works provides a useful foundation for implementing these obligations effectively.
Not sure whether your services make you a TCSP?
AML India can confirm whether the activities you offer bring you within the notification, and what a proportionate programme looks like for a corporate services or trustee business.
Frequently Asked Questions
Carrying out any of the notified activities under notification S.O. 2135(E) of 9 May 2023 on behalf of a client: acting as a formation agent of companies or LLPs; acting as, or arranging for another to act as, a director, secretary or partner; providing a registered office, business or administrative address; or acting as, or arranging for another to act as, a trustee of an express trust or nominee shareholder.
No. There is no transaction or turnover threshold for service providers. A person or firm becomes a reporting entity under PMLA as soon as it carries on one or more of the notified activities on behalf of another person in the course of business.
The Financial Intelligence Unit of India. FIU-IND issues the AML/CFT Guidelines for TCSPs, registers providers as reporting entities and receives their reports, so the regulator and the reporting hub are the same body, while the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA.
The FIU-IND AML/CFT Guidelines for Trust and Company Service Providers have been effective from 21 April 2026. They classify TCSPs as reporting entities and set out the customer due diligence, beneficial-owner identification, monitoring, reporting, record-keeping and sanctions obligations a provider must operate.
Primarily suspicious transaction reports, of any value and including attempted transactions, filed promptly once the Principal Officer is satisfied a transaction is suspicious. A provider that also handles cash must file cash transaction reports for cash over Rupees 10 lakh and reports on counterfeit or forged instruments. All reports are filed through FINnet 2.0.
Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every trust and company service provider from the first engagement, with no threshold. A provider screens clients, settlors, beneficiaries and beneficial owners against the designated lists and freezes and reports any match.
No, the notification S.O. 2135(E) of 9 May 2023 expressly excludes an activity carried out by an advocate, chartered accountant, cost accountant or company secretary in practice to the extent of filing a declaration on company formation, because those professionals are designated separately under S.O. 2036(E) of 3 May 2023. A professional whose business is providing these corporate services more broadly should take advice on which designation applies.
Official sources and review
Last reviewed: July 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
- Prevention of Money-Laundering Act, 2002 (India Code)
- Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (India Code)
- Notification S.O. 2135(E), 9 May 2023, designating trust and company service activities (Gazette of India)
- AML/CFT Guidelines for Trust and Company Service Providers, effective 21 April 2026 (FIU-IND)
- Unlawful Activities (Prevention) Act, 1967 and Section 51A procedure.
- WMD Act, 2005 and its Section 12A implementation procedure (India Code)
- FATF Recommendations, including the June 2026 update to Recommendation 6
- FATF Risk-Based Approach Guidance for Trust and Company Service Providers, 2019
- FATF Mutual Evaluation Report on India, 2024
- Financial Intelligence Unit – India, including the Annual Report 2024-25
- Central KYC Records Registry (CKYCR) Operating Guidelines, 2025 (CERSAI)
Why work with AML India
AML India helps trust and company service providers meet their PMLA and FIU-IND obligations, from registration and risk assessment to CDD, beneficial owner identification and verification, screening, monitoring, reporting, training and independent audit.
Industries we serve: Trust and Company Service Providers, Real Estate Agents, Dealers in Precious Metals and Stones, Chartered Accountants, Company Secretaries and Cost and Management Accountants, Virtual Asset Service Providers, Casinos and the Gaming Sector, and Banks, Financial Institutions and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik