Last Updated on: 6 August 2026 | Last Reviewed on: 6 August 2026
Key takeaways at a glance
- Who is covered: all insurers writing life, general or health insurance, as reporting entities under the PMLA and subject to IRDAI directions and supervision.
- Why they are caught: an insurer carries on insurance business and is a financial institution within section 2(1)(l) of the PMLA, so it is a reporting entity under section 2(1)(wa). No separate designation is needed.
- Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the IRDAI Master Guidelines on AML/CFT, 2022 and the 2023 amendment; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
- Supervisor: the Insurance Regulatory and Development Authority of India (IRDAI). Reports go to the Financial Intelligence Unit India (FIU IND); the Enforcement Directorate (ED) enforces the PMLA.
- Core duties: an internal risk assessment, customer due diligence and KYC, beneficial owner identification, ongoing monitoring, prescribed transaction reporting, five year record keeping and sanctions screening.
This guide is general information on Indian law, not legal advice. For your company’s specific position, speak to a qualified AML professional.
Insurance companies are reporting entities under the Prevention of Money Laundering Act, 2002. An insurer, whether it writes life, general or health insurance, carries on insurance business and is a financial institution for the purposes of the Act. Its AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the IRDAI Master Guidelines on Anti Money Laundering and Counter Financing of Terrorism, 2022, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU IND reporting framework. The Insurance Regulatory and Development Authority of India supervises insurers, and reports are filed with FIU IND.
The core instruments at a glance
Instrument | What it does for an insurer |
PMLA, 2002 | The parent Act. Makes an insurer a reporting entity as a financial institution and creates the core duties of CDD, record keeping and reporting. |
PML (Maintenance of Records) Rules, 2005 | Set out what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. |
IRDAI Master Guidelines on AML/CFT, 2022 | The insurer’s working rulebook, issued by the IRDAI, effective from 1 August 2022 and amended in October 2023. |
UAPA Section 51A and WMD Act Section 12A | Impose targeted financial sanctions for terrorism and proliferation financing. |
FATF Recommendations 9 to 23 | The international preventive measure standards for financial institutions, which single out life insurance. |
CKYCR and FINnet 2.0 | The central KYC registry and the FIU IND reporting platform an insurer plugs into. |
What Counts as an Insurance Company in India?
An insurance company is an insurer registered with the IRDAI to carry on the business of insurance, across the life, general and health insurance classes. It collects premiums and pays claims, and in the case of life insurance, it also offers savings and investment linked products that build a cash value.
The money laundering risk of an insurer is concentrated in life and investment linked insurance rather than in pure protection or general insurance. It sits in the payment of large or single premiums, potentially in cash or by a third party; in the early surrender of a policy to obtain clean funds; in the assignment of a policy to another person; and in the beneficial ownership behind a corporate policyholder. The FATF singles out life insurance for this reason, and the IRDAI Master Guidelines therefore lean on customer due diligence at proposal and payout, on scrutiny of premium sources and third party payers, and on monitoring of surrenders and assignments.
Are Insurance companies Reporting Entities under the PMLA?
Yes. The Prevention of Money Laundering Act, 2002 creates the offence of money laundering and places core duties on reporting entities. An insurer carries on insurance business and is recognised as a financial institution within section 2(1)(l) of the PMLA, read with section 45-I of the Reserve Bank of India Act, 1934, so it is a reporting entity under section 2(1)(wa).
This places an insurer in the same broad category of reporting entities that file with FIU IND as banks and other financial institutions, and within the wider AML laws and regulations for financial institutions in India. The obligations are calibrated to the class and scale of business, but the status is not optional.
Supervisory Authority for Insurance Companies in India
The supervisor for insurance companies is the Insurance Regulatory and Development Authority of India, which registers and supervises insurers and issues the AML rulebook they work from. The IRDAI Master Guidelines on Anti Money Laundering and Counter Financing of Terrorism, 2022, effective from 1 August 2022 and amended by a circular of 10 October 2023, consolidate the earlier life and general insurance guidelines and set out customer due diligence, beneficial owner identification, monitoring, reporting and record keeping for all classes of insurer.
The Financial Intelligence Unit India receives, analyses and disseminates the reports an insurer files, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. In short, the IRDAI sets and supervises the rules, FIU IND receives intelligence, and the ED enforces criminal law.
Onboarding clients without a documented due-diligence process?
AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.
AML Regulatory Requirements for Insurance Companies in India
The law that governs an insurer does not sit in one place. It is a layered framework, and it helps to see it grouped as the official source set groups it: the core legislation, the overarching obligations, the sectoral supervisor and its directions, the miscellaneous official reports, the international standards, and the allied laws. Each category below lists the instruments that apply.
The framework reads from the core outward. The PMLA is the parent Act; the PML Rules turn it into operational duties; the RBI Directions translate both into instructions an insurer can follow; the UAPA and the WMD Act add counter terrorism and proliferation financing sanctions; and the allied laws, including each institution’s own establishing statute, shape the risk. The risk based approach carries this all together.
Core Legislation
The primary statutes and rules that create the AML, CFT and CPF obligations are grouped into three categories.
AML Legislation
Prevention of Money Laundering Act, 2002 (PMLA)
India’s prime act on anti money laundering statute and the source of an insurer’s reporting entity status. It defines the offence of money laundering and imposes duties like customer due diligence under Section 11A and record keeping under Section 12 that an insurer must fulfil across its regulated activities.
An insurer deals in the settlement of acquired debts and the sale of securities, as a result, its exposure sits at a higher level. Thus, undertaking identification of the source of settlement funds and the identification of beneficial ownership of asset buyers, which is where the Act bites.
The PML (Maintenance of Records) Rules, 2005 (PMLR)
The rules made under the PMLA apply to insurers. Rule 3 and Rule 8 outline what to report and when, Rule 7 specifies how to identify customers and beneficial owners; and Rule 7 sets out the duty to appoint a Principal Officer and Designated Director. The PMLR has been amended through 31 Gazette notifications and orders.
The 31 PMLR Amendment Notifications, in Date Order:
Gazette notification and date | Key change or rule touched |
G.S.R. 389(E), 24 May 2007 | The first and the only amendment for 2007. It introduced revisions to Rule 2 pertaining to suspicious transaction dealings, Rule 8 on furnishing information to the Director and Rule 9 which substituted the requirement from three to one certified copy. |
G.S.R. 816(E), 12 November 2009 | This amendment of 2009 identified and included Non Profit organisation, Regulator, Suspicious Transaction. In addition to this, Rule 3, Rule 5, Rule 6, Rule 7, Rule 8 and Rule 7 were revised by way of this amendment notification. |
G.S.R. 76(E), 12 February 2010 | This amendment notification reworked on Rules 3, Rule 4, Rule 5 and Rule 7. In addition to this, it inserted an explanation in Rule 9(1A). |
G.S.R. 508(E), 16 June 2010 | Inserted an Explanation in Rule 2, substituted sub rule 1A, 1B and 1C in Rule 9, and added an explanation in Rule 10. |
G.S.R. 980(E), 16 December 2010 | This established the regime pertaining to small account and widened the scope of documents accepted for valid documents to include NREGA job card and Aadhaar letter under Rule 2. It also brought in Rule 9(2A) pertaining to opening and monitoring of such an account. |
G.S.R. 481(E), 24 June 2011 | Set the short title, restating Rule 1 to shorten the long 2005 name to the Prevention of Money Laundering (Maintenance of Records) Rules, the PMLR shorthand used since. |
G.S.R. 576(E), 27 August 2013 | Incorporated the definition for Designated Director under Rule 2 and added additional sub-clauses in Rule 3, Rule 7, Rule 8, Rule 9 and Rule 10 among other rules. |
G.S.R. 288(E), 15 April 2015 | It recognised officially valid documents and listed them in this notification. |
G.S.R. 544(E), 7 July 2015 | It introduced definitions such as Central KYC Records Registry among other sub rule additions in Rule 9 and Rule 10. |
G.S.R. 730(E), 22 September 2015 | This amendment introduced minor changes to sub rules under Rule 2 and made certain insertions. |
G.S.R. 882(E), 18 November 2015 | This substituted the 90 days with 180 days and revised the timeline. |
G.S.R. 347(E), 12 April 2017 | Added the definition of Regulator and inserted Rule 9B to reinforce the PML Rules, 2005. |
G.S.R. 538(E), 1 June 2017 | It inserted sub rules under Rule 2 and Rule 9. |
G.S.R. 1038(E), 21 August 2017 | Minor insertions in Rule 2 by a way of this notification. |
G.S.R. 1318(E), 23 October 2017 | A later 2017 restatement of the Rule 2, added an additional proviso pertaining to valid documents. |
G.S.R. 456(E), 16 May 2018 | Restated Rule 9 by inserting additional sub-clauses and necessitated every reporting entity to create and implement a client due diligence programme. |
G.S.R. 1078(E), 31 October 2018 | This was the final amendment for the year 2019. It changed the three day timeline set under Rule 9(1A) to ten days. |
G.S.R. 108(E), 13 February 2019 | This notification made a slew of changes in sub rules for Rule 9 and opened way for further changes for the year 2019. |
G.S.R. 381(E), 28 May 2019 | This amendment introduced a special customer due diligence provision for prisoners opening or operating bank accounts. Where the customer is a prisoner in a jail, the signature or thumb impression must be affixed in the presence of the officer in charge of the jail, who must certify it. The account may remain operational upon the annual submission of a proof of address certificate issued by the officer in charge of the jail. The amendment facilitates access to financial services for prisoners while maintaining appropriate identity verification safeguards. |
G.S.R. 582(E), 19 August 2019 | This amendment modernised the PML Rules by introducing the concepts of digital KYC, equivalent e-documents and offline Aadhaar verification. It revised Rule 9 to provide multiple modes of customer identification, including Aadhaar, officially valid documents and digital verification, while recognising electronically issued documents. The notification also prescribed a detailed Digital KYC process, including live photographs, geotagging, OTP authentication and verification standards. These changes enabled technology-driven customer due diligence while maintaining AML safeguards. |
G.S.R. 669(E), 18 September 2019 | Introduced the definition of a depository receipt into the PML Rules and eased customer due diligence requirements for certain foreign investments. It allowed reporting entities to rely on the beneficial ownership norms of notified foreign jurisdictions for clients dealing in specified depository receipts or equity shares. It also exempted listed companies in India and notified foreign jurisdictions, and their subsidiaries, from identifying and verifying individual shareholders or beneficial owners during customer due diligence. |
G.S.R. 840(E), 13 November 2019 | This amendment allowed customers who use Aadhaar for identity verification to declare a current address that differs from the address recorded in the Central Identities Data Repository. Reporting entities may accept a self declaration of the current address for customer due diligence. The change simplified address verification while retaining Aadhaar based identification. |
G.S.R. 228(E), 31 March 2020 | This amendment temporarily extended the validity of small accounts that were otherwise due for closure under the customer due diligence requirements. Small accounts remained operational from 1 April 2020 to 30 June 2020, with provision for further extensions by the Central Government. The change ensured continued access to banking services during the COVID-19 period. |
G.S.R. 251(E), 13 April 2020 | This amendment extended the deadline for reporting entities to furnish prescribed transaction reports under Rule 8 of the PML Rules. Instead of the usual reporting timelines, the information covered under sub rules that could be submitted up to 30 June 2020. The temporary relaxation was introduced to address operational disruptions during the COVID-19 period. |
G.S.R. 254(E), 16 April 2020 | This amendment clarified the temporary reporting relief introduced during the COVID-19 period by specifying the transaction reports covered by the extended deadline. It applied to reports for transactions under Rule 3(1)(A), (B), (BA), (C) and (E) for March, April and May 2020, and Rule 3(1)(F) reports for the January to March 2020 quarter. The specified reports could be furnished up to 30 June 2020. |
G.S.R. 798(E), 28 December 2020 | This notification designated real estate agents with an annual turnover of Rupees 20 lakh or above as persons carrying on a designated business or profession under the PMLA. As a result, they became reporting entities. |
G.S.R. 575(E), 13 July 2022 | Introduced special AML and KYC provisions for reporting entities operating in an International Financial Services Centre. It recognised the head of the reporting entity in India as the designated officer for IFSC entities, expanded the list of officially valid documents for foreign nationals, including foreign bank statements and government issued identity documents, and defined International Financial Services Centre in the Rules. It also exempted IFSC reporting entities from receiving, storing, safeguarding and retrieving Central KYC Records Registry records for foreign national clients. |
S.O. 1074(E), 7 March 2023 | Reduced the beneficial ownership threshold to 10 percent, introducing group wide AML policies, and adding definitions for group, politically exposed persons and non profit organisations. It also expanded identification requirements for legal entities and trusts and required eligible non profit organisations. |
G.S.R. 652(E), 4 September 2023 | Strengthened governance and beneficial ownership requirements by requiring the Principal Officer to be at the management level, reducing the beneficial ownership threshold for certain entities to 10 percent, and clarifying that control includes the right to influence management or policy decisions. It also introduced trustee disclosure requirements and required reporting entities to retain the results of AML risk analysis along with customer records. |
G.S.R. 745(E), 17 October 2023 | Reinforced customer due diligence by requiring identity verification using reliable and independent sources. They also expanded group wide AML programmes, required suspicious transaction reports to be filed promptly after suspicion is formed, and reinforced strict confidentiality obligations for AML records and reporting. |
G.S.R. 419(E), 19 July 2024 | Enhanced the Central KYC Records Registry framework by requiring reporting entities to use the KYC Identifier to retrieve customer records and limiting requests for duplicate KYC documents to specified circumstances. It also introduced a seven day timeline for updating KYC records and required reporting entities to retrieve, update and utilise revised KYC information from the Central KYC Records Registry. |
The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005
Rules for accepting customer records authenticated outside India, relevant where an insurer lends to a non resident Indian buyer or a foreign owned developer and must rely on identity and ownership documents executed and certified abroad.
CFT Legislation
The Unlawful Activities (Prevention) Act, 1967 (UAPA)
India’s counter terrorism statute. Section 51A requires an insurer to screen customers and beneficial owners against the designated lists and to freeze, without delay, the funds and assets of listed persons and entities, whatever the size of the exposure.
Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigenda dated 15 March 2023 and 29 August 2023)
The official procedure an insurer follows to apply Section 51A. The RBI Directions fold the screening and freezing steps into the institution’s controls, turning the statutory order into a workable process.
The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)
India’s counter proliferation financing statute. Section 12A provides the legal basis for targeted financial sanctions relating to the financing of weapons of mass destruction, and reaches an insurer, particularly where an acquired asset or a settlement has a cross border dimension.
Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)
The official procedure for applying Section 12A mirrors the Section 51A screening and freezing steps, applied by an insurer alongside its terrorism list screening.
The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016
Rules implementing the WMD Act and supporting the proliferation financing controls an insurer must operate.
Not registered with FIU-IND yet, or unsure whether you have to be?
AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.
Overarching
The shared national infrastructure that an insurer plugs into as a reporting entity.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
The Central KYC Records Registry stores customer KYC records centrally. An insurer uploads to it and can reuse a customer’s existing record, keeping KYC consistent and reducing duplication. Getting beneficial ownership and identity data right for an institutional customer at onboarding is what makes the registry useful.
FINnet 2.0 reporting formats (2024) and the FINGate 2.0 user manuals
The FIU IND reporting platform and its current formats, through which an insurer enrols and files, with the FINGate 2.0 manuals covering enrolment, request response and reports.
Procedure for Aadhaar authentication under Section 11A of the PMLA (9 May 2019)
The procedure for reporting entities other than banking companies to apply to use Aadhaar authentication services, relevant where an insurer verifies an individual’s identity through Aadhaar.
Sectoral
The supervisor and its directions. The Reserve Bank of India regulates insurers and issues the KYC Directions the institution works from, read with its consolidated master directions and internal risk assessment guidance.
Insurance Regulatory and Development Authority of India (IRDAI)
IRDAI Master Guidelines on AML/CFT, 2022 (1 August 2022)
The insurer’s working rulebook, and the most important instrument on this page. Issued by the IRDAI and effective from 1 August 2022, the Master Guidelines apply to all classes of life, general and health insurer and consolidate the earlier life and general insurance guidelines. They set out customer identification and due diligence, beneficial owner identification, the risk based approach, the appointment of a Principal Officer, monitoring, reporting, record keeping and the implementation of Sections 51A and 12A. Where this article states a duty at the level of the law, the Master Guidelines are where an insurer finds the detail.
Circular amending the Master Guidelines on AML/CFT (10 October 2023)
The IRDAI circular of 10 October 2023 amending the 2022 Master Guidelines, which an insurer reads together with the Guidelines to keep its programme current.
The PMLA and PMLR framework applied by insurers as financial institutions
Because an insurer is a financial institution under the PMLA, the customer due diligence, beneficial owner identification, monitoring, reporting, record keeping and sanctions duties flow from the PMLA and PMLR themselves, with the IRDAI Master Guidelines translating them for the insurance business.
Miscellaneous
Official reports and guidance that sit outside the binding rulebook but shape how an insurer reads its risk and its duties.
FIU IND Annual Report 2024 to 2025
The national FIU’s annual account of the reports it received, analysed and disseminated, a useful read on reporting volumes and priorities across reporting entity types.
Directorate of Enforcement Annual Report 2025 to 2026
The Enforcement Directorate’s annual account of investigations, provisional attachments and prosecutions under the PMLA, showing how the criminal enforcement end of the framework is used.
FIU IND and its Core Functions and FAQs
A plain language explanation of what FIU IND does and how reporting works, a useful primer for an institution’s reporting function.
MHA National Counter Terrorism Policy and Strategy
The Ministry of Home Affairs statement of national counter terrorism policy, which frames the CFT duties that Section 51A places on an insurer.
International Standards
The global benchmarks India is measured against, and the sources an insurer can use to calibrate a risk based approach.
FATF Recommendations
The international AML, CFT and CPF standards. Recommendations 9 to 23 set the preventive measures for financial institutions, and Recommendation 6 on targeted financial sanctions was updated by FATF in June 2026. India’s framework for insurers is built to meet them.
FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)
The peer assessment of India’s AML and CFT system, which examined how the financial sector’s preventive measures and supervision work in practice.
Basel Committee, Sound Management of Risks Related to Money Laundering and Financing of Terrorism (2014, revised July 2020)
The Basel Committee guidance on managing ML and TF risk, a benchmark for the risk based approach and group wide controls that an insurer can read across to its own risk management.
FATF Risk Based Approach Guidance for the Banking Sector (2014)
FATF sector guidance on applying the risk based approach in banking and financial institutions, useful to an insurer in shaping its customer due diligence and monitoring.
Allied Laws
The wider body of law that defines each institution’s own mandate and the predicate offences and enforcement machinery around money laundering. An insurer operates under the Insurance Act, 1938 and the IRDA Act, 1999, while the predicate and enforcement Acts shape the risk it must assess and the conduct it may need to report.
The Insurance Act, 1938 and the Insurance Regulatory and Development Authority Act, 1999 regulate insurance operations, registration, and supervision. The Companies Act, 2013 governs corporate compliance, while the Bharatiya Nyaya Sanhita, 2023 and Bharatiya Nagarik Suraksha Sanhita, 2023 provide the criminal offence and enforcement framework.
The Foreign Exchange Management Act, 1999 regulates foreign exchange activities. The Benami Transactions (Prohibition) Act, 1988, Prevention of Corruption Act, 1988, Narcotic Drugs and Psychotropic Substances Act, 1985, Fugitive Economic Offenders Act, 2018, and Black Money Act, 2015 address illicit assets, corruption, economic offences, and related proceeds.
The Foreign Contribution (Regulation) Act, 2010 regulates foreign contributions, while the COFEPOSA Act, 1974 and SAFEMA Act, 1976 deal with smuggling and property forfeiture. The Arms Act, 1959, Chemical Weapons Convention Act, 2000, and Central Vigilance Commission Act, 2003 address arms control, chemical weapons compliance, and anti-corruption oversight.
Core AML, CFT, CPF Obligations for Insurance Companies in India
Across that framework, the regulations require an insurer to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.
- Register with FIU IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the institution can file its reports.
- Appoint officers. Appoint a Designated Director and a management level Principal Officer under Rule 7 of the PMLR and the RBI Directions. The same person cannot hold both roles, and both are informed to FIU IND and the RBI.
- Conduct the internal risk assessment. Run an ML and TF risk assessment across customers, products, channels and geographies, document it, and take its outcome to the board, as the RBI Directions and the IRA Guidance require.
- Document AML policy, controls and procedures. Adopt a board approved policy that turns the risk assessment into the institution’s operating procedures.
- Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the RBI insurer KYC Directions 2025. Given the life and investment linked business, the identification of policyholders and any beneficial owner, the source of premiums and third party payers, and the monitoring of surrenders and assignments, are central.
- Ongoing monitoring and periodic updates. Monitor transactions on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low risk customers. Customer’s risk categorisation should be reviewed periodically as per the entity’s risk based approach.
- Sanctions screening. Screen customers and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
- Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit currency reports and, where an insurer finances a cross border transaction, cross border wire transfer reports of Rupees 5 lakh or more where applicable, under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly, through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train staff by role to apply the controls and recognise red flags in life insurance, such as large or cash premiums, early surrenders and policy assignments.
- Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
- Run group wide controls. Where the institution has subsidiaries, apply AML and CFT programmes at group level, including for branches and majority owned subsidiaries, as the RBI Directions require.
What this article does not cover
This article explains the laws and regulatory instruments that apply to insurers. It does not provide a control by control compliance manual, and it does not restate each institution’s own establishing statute or its developmental mandate, except where they bear on the AML duties. For implementation, an insurer separately documents customer acceptance, KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction escalation, staff training, audit testing and board reporting. Those controls are the subject of the companion compliance guide.
To see how the insurer framework fits within the sector, see AML laws and regulations for financial institutions in India, and to place it within the national picture, see AML laws and regulations in India.
From regulation to compliance: your next step
Knowing the law is the first step. These obligations only protect an institution when they are built into a working programme of risk assessment, policy, customer due diligence, monitoring, screening, reporting, training and independent review. For an insurer, the identification of borrowers and asset buyers and their beneficial owners and the scrutiny of the source of settlement funds are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.
Want to confirm the 2025 directions for your institution?
AML India can walk you through the RBI insurer KYC Directions and build a proportionate programme for a life, general or health insurer.
Frequently Asked Questions
An insurer registered with the IRDAI to carry on the business of insurance, across the life, general and health insurance classes. It collects premiums and pays claims, and in life insurance it also offers savings and investment linked products. An insurer carries on insurance business and is a financial institution. Thus, it is a reporting entity under the PMLA.
Yes. An insurer is a reporting entity under section 2(1)(wa) of the PMLA because it is a financial institution within section 2(1)(l), taking meaning from section 45-I of the RBI Act, 1934.
The IRDAI Master Guidelines on Anti Money Laundering and Counter Financing of Terrorism, 2022, effective from 1 August 2022 and amended by a circular of 10 October 2023. They apply to all classes of life, general and health insurers and set out the customer due diligence, beneficial owner identification, monitoring, reporting and record keeping obligations for insurers.
An insurer deals mainly with corporate borrowers, selling banks and the buyers of acquired assets rather than retail customers over a counter, so its customer due diligence centres on those parties and their beneficial owners, and on the source of settlement funds. Where an insurer deals with individual borrowers or buyers, ordinary KYC applies. The full AML framework applies in either case.
Cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit currency reports and, where an insurer finances across border transaction, cross border wire transfer reports of Rupees 5 lakh or more where applicable. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly, through FINnet 2.0.
Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every insurer, whatever the size of the exposure. An insurer screens customers and beneficial owners against the United Nations and domestic designated lists and freezes and reports any match.
Official sources and review
Last reviewed: July 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
- Prevention of Money Laundering Act, 2002 (India Code)
- Prevention of Money Laundering (Maintenance of Records) Rules, 2005 (India Code)
- RBI (Insurance Companies Know Your Customer) Directions, 2025 (Reserve Bank of India)
- RBI Internal Risk Assessment Guidance for ML/TF Risks, 2024 (Reserve Bank of India)
- Unlawful Activities (Prevention) Act, 1967 and Section 51A procedure (MHA)
- WMD Act, 2005 and its Section 12A implementation procedure (India Code)
- FATF Recommendations, including the June 2026 update to Recommendation 6
- FATF Mutual Evaluation Report on India, 2024
- Basel Committee, Sound Management of Risks Related to ML and TF (2014, revised July 2020)
- Financial Intelligence Unit India, including the Annual Report 2024 25
- Central KYC Records Registry (CKYCR) Operating Guidelines, 2025 (CERSAI)
- Enforcement Directorate Annual Report 2025 to 2026
This guide covers money laundering law and compliance, a sensitive area where the rules change; confirm the current position for your institution with a qualified professional before acting.
Why work with AML India
AML India helps insurers meet their PMLA and RBI obligations, from risk assessment and policy through to CDD, screening, monitoring, reporting, training and independent review.
Industries we serve: insurers, NBFCs, hire purchase, mortgage guarantee and asset reconstruction companies, insurers, payment system operators and aggregators, banks, DNFBPs, securities intermediaries and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik