Last Updated on: 10th August 2026 | Last Reviewed on: 10th August 2026
Key takeaways at a glance
- Who is covered: payment aggregators authorised or seeking authorisation to operate a payment system, whether online payment aggregators or physical point of sale aggregators, as reporting entities under the PMLA.
- Why they are caught: a payment aggregator that operates a payment system is a payment system operator, which is expressly named within the financial institution definition in section 2(1)(l) of the PMLA, so it is a reporting entity under section 2(1)(wa).
- Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the RBI Master Direction on Regulation of Payment Aggregators and the RBI KYC Directions, 2025; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
- Supervisor: the Reserve Bank of India (RBI), under the Payment and Settlement Systems Act, 2007. Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
- Core duties: an internal risk assessment, merchant and customer due diligence and KYC, beneficial owner identification, periodic updates, transaction monitoring, prescribed transaction reporting, five year record-keeping and sanctions screening.
This guide is general information on Indian law, not legal advice. For your company’s specific position, speak to a qualified AML professional.
Payment aggregators, the entities that let merchants accept online card, wallet and bank payments through a single integration. They are classified as reporting entities under the Prevention of Money-Laundering Act, 2002.
A payment aggregator receives payment instructions from merchants’ customers, pools the funds in an escrow account and settles them to merchants, placing it at the centre of digital payment flows.
The AML, CFT and CPF duties flow from the PMLA, 2002, the PML (Maintenance of Records) Rules, 2005, the RBI Master Direction on Regulation of Payment Aggregators, the RBI KYC Directions, 2025, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework. The Reserve Bank of India authorises and supervises payment aggregators under the Payment and Settlement Systems Act, 2007, and requisite reports are furnished to FIU-IND.
The core instruments at a glance
Instrument | What it does for a payment aggregator |
PMLA, 2002 | The parent Act. Brings a payment aggregator within the financial institution definition and creates the duties of CDD, record-keeping and reporting. |
PML (Maintenance of Records) Rules, 2005 | Set out what to report and when, how to identify customers, merchants and beneficial owners, and the duty to appoint officers. |
RBI Payment Aggregator Master Direction, 2025 | The aggregator’s working rulebook on authorisation, merchant onboarding KYC, escrow and conduct, issued by the RBI on 15 September 2025. |
RBI KYC Directions, 2025 | Undertake the customer due diligence, risk categorisation, monitoring and reporting requirements the aggregator applies to its customers and merchants. |
UAPA Section 51A and WMD Act Section 12A | Impose targeted financial sanctions for terrorism and proliferation financing. |
FATF Recommendations 9 to 23 | The international preventive measures and standards for financial institutions that India’s framework is built to meet. |
Who is a Payment Aggregator in India?
A payment aggregator is an entity that facilitates online or point of sale payments by onboarding merchants, receiving payment instructions from the merchant’s customers, pooling the collected funds and settling them to the merchants, without the merchants having to build their own payment integration.
The Reserve Bank of India authorises payment aggregators under the Payment and Settlement Systems Act, 2007 and regulates their conduct through its Master Direction on Regulation of Payment Aggregators. Because an aggregator handles customer funds in transit and determines which merchants can accept payments, it occupies a gatekeeping position in the digital payments chain.
The money laundering risk of a payment aggregator is primarily a merchant onboarding and transaction flow onboarding risk. It arises from the merchants it onboards, where a fictitious or complicit merchant may be used to launder proceeds through apparently legitimate sales, a practice known as transaction laundering; from the payment transactions it processes, including those involving stolen or compromised payment credentials and mule accounts; and from the speed and volume of digital payment transactions and settlements, which can obscure the audit trail.
The AML framework therefore places particular emphasis on robust merchant due diligence, identifying and verifying the beneficial owners of merchant businesses, and monitoring transaction patterns for indicators of suspicious activity.
Are Payment Aggregators Reporting Entities under the PMLA?
Yes. The Prevention of Money-Laundering Act, 2002 creates the offence of money laundering and places core duties on reporting entities.
A payment aggregator that operates a payment system is a payment system operator, and a payment system operator is expressly named within the financial institution definition in section 2(1)(l) of the PMLA, so a payment aggregator is a reporting entity under section 2(1)(wa). No notification under section 2(1)(sa) is needed; it is inside the regime by virtue of what it does.
A payment aggregator authorised by the Reserve Bank of India under the Payment and Settlements Systems Act, 2007 is a payment system operator. A payment system operator is expressly included within the definition of financial institution in section 2(1)(l) of the PMLA, 2002. Accordingly, a payment aggregator is a reporting entity under section 2(1)(wa) of the PMLA. No notification under section 2(1)(sa) is required because payment aggregators fall within the PMLA by virtue of being payment system operators.
As a result, this places a payment aggregator in the same broad category of reporting entities that file with FIU-IND as banks and other financial institutions, and within the wider AML laws and regulations for financial institutions in India. The obligations are calibrated to the aggregator’s business, but the reporting entity status is not optional.
Supervisory Authority for Payment Aggregators in India
The supervisor for payment aggregators is the Reserve Bank of India, which authorises them to operate a payment system under the Payment and Settlement Systems Act, 2007 and regulates their conduct through the Master Direction on Regulation of Payment Aggregators dated 15 September 2025.
Alongside the Master Direction, payment aggregators are required to comply with the RBI KYC Directions, 2025, consolidated on 28 November 2025, and apply the RBI Internal Risk Assessment Guidance of 2024 as the basis of their risk based approach.
The framework and procedure for obtaining and maintaining authorisation are set out in the RBI Master Directions on Authorisation to Operate a Payment System.
The Financial Intelligence Unit – India receives, analyses and disseminates the reports filed by the payment aggregators, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA.
Onboarding clients without a documented due-diligence process?
AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.
AML Regulatory Requirements for Payment Aggregators in India
The law that governs a payment aggregator is spread across several instruments rather than gathered in one code. It is easiest to read as a layered framework, grouped the way the official source set groups it: the core legislation, the overarching infrastructure, the sectoral supervisor and its directions, the miscellaneous official reports, the international standards, and the allied laws. Each category below lists the instruments that bind a payment aggregator, with a short note on what each one does in practice.
The framework reads from the core with the PMLA is acting as the parent Act; the PML Rules convert it into working duties; the RBI Payment Aggregator Master Direction and the RBI KYC Directions translate both into instructions an aggregator can operate; the UAPA and the WMD Act layer on counter terrorism and proliferation financing sanctions; and the allied laws, including the Payment and Settlement Systems Act under which the aggregator is authorised, shape the risk it must manage. The risk based approach is the common thread.
Core Legislation
The primary statutes and rules that create a payment aggregator’s AML, CFT and CPF duties, grouped into three categories, each covering money laundering, terrorism financing and proliferation financing.
AML Legislation
Prevention of Money Laundering Act, 2002 (PMLA)
India’s primary AML statute and the source of a payment aggregator’s reporting entity status. It defines the offence of money laundering, supports the attachment and confiscation of the proceeds of crime, and sets AML obligations and duties such as customer due diligence, record-keeping and reporting for every reporting entity, including payment aggregators.
Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (PMLR)
The operational engine of the Act. The PMLR tell a payment aggregator how to verify a customer, how to find the beneficial owner behind a merchant business, which transactions to report and by when, how long to preserve records, and that it must appoint a Designated Director and a Principal Officer. The daily AML obligations performed by aggregators trace back to these Rules.
PML (Manner of Receiving Records Authenticated Outside India) Rules, 2005
It sets out how records are executed or authenticated outside India may be received and relied on, which is relevant when a payment aggregator onboards a merchant or a merchant’s beneficial owner whose documents originate abroad.
The PML (Maintenance of Records) Rules, 2005 have been amended many times. The table below is a legal history timeline: each Gazette notification with a short note on what it changed. For a payment aggregator, the important through line is the steady tightening of customer due diligence, beneficial ownership and reporting, and the two 2023 amendments that cut the beneficial ownership thresholds, which bear directly on identifying who owns and controls the merchants it onboards.
The 31 PMLR Amendment Notifications, in Date Order:
G.S.R. 389(E), 24 May 2007 | Amended the PML Rules, 2005 by expanding the definition of suspicious transaction to include transactions with no economic rationale or links to terrorist financing, extending reportable cash transactions to cover forged currency and documents, prescribing clear reporting timelines to the Director, and reducing the requirement for certified copies in certain filings from three to one. |
G.S.R. 816(E), 12 November 2009 | Introduced the definitions of non profit organisation and Regulator, broadened the scope of suspicious transactions to include those involving unusual complexity, absence of economic rationale, or links to terrorist financing, required reporting of NGO cash receipts exceeding ten lakh rupees, replaced references to RBI, SEBI and IRDA with the term Regulator, and extended the record retention period to ten years from the date of the transaction. |
G.S.R. 76(E), 12 February 2010 | Strengthened Rules 3, 4, 5 and 7 of the PML Rules, 2005 by reinforcing record keeping and reporting requirements and inserted the first Explanation to Rule 9(1A), clarifying that the beneficial owner is the natural person who ultimately owns or controls a client or on whose behalf a transaction is conducted. |
G.S.R. 508(E), 16 June 2010 | Revised Rules 2, 9 and 10 of the PML Rules, 2005 relating to definitions, customer due diligence and record keeping requirements, strengthening the framework for customer identification and preservation of records by reporting entities as part of the 2010 reforms to the CDD and records regime. |
G.S.R. 980(E), 16 December 2010 | Introduced the small account framework by defining Designated Officer and small account, expanding the list of officially valid documents under Rule 2 to include the NREGA job card and Aadhaar letter, and inserting Rule 9(2A) to prescribe the conditions and procedures for opening and monitoring such accounts. |
G.S.R. 481(E), 24 June 2011 | Amended Rule 1 of the PML Rules, 2005 to introduce the short title Prevention of Money Laundering Maintenance of Records Rules, replacing the earlier longer title and establishing the abbreviated PMLR reference used thereafter. |
G.S.R. 576(E), 27 August 2013 | Introduced the definition of Designated Director under Rule 2 and amended Rules 3, 7, 8, 9 and 10 of the PML Rules, 2005 to strengthen reporting obligations, governance requirements, customer due diligence measures and record keeping provisions. |
G.S.R. 288(E), 15 April 2015 | Specified the documents recognised as officially valid documents for the purposes of customer identification under the PML Rules, 2005. |
G.S.R. 544(E), 7 July 2015 | Introduced the definition of Central KYC Records Registry and amended Rules 9 and 10 by inserting additional provisions to strengthen the KYC framework and enable centralised KYC record management. |
G.S.R. 730(E), 22 September 2015 | Made amendments to the definitions under Rule 2 and introduced related changes across the PML Rules, 2005 to align the framework with evolving KYC requirements. |
G.S.R. 882(E), 18 November 2015 | Extended the prescribed timeline under the relevant provisions of the PML Rules, 2005 from 90 days to 180 days. |
G.S.R. 347(E), 12 April 2017 | Introduced the definition of Regulator and inserted Rule 9B to further strengthen the customer due diligence framework under the PML Rules, 2005. |
G.S.R. 538(E), 1 June 2017 | Amended Rules 2 and 9 of the PML Rules, 2005 by inserting additional provisions to strengthen the operational AML framework. |
G.S.R. 1038(E), 21 August 2017 | Amended the definitions under Rule 2 of the PML Rules, 2005 by inserting additional provisions to update and clarify key terms used in the framework. |
G.S.R. 1318(E), 23 October 2017 | Further amended Rule 2 by adding a proviso relating to the acceptance and treatment of officially valid documents. |
G.S.R. 456(E), 16 May 2018 | Amended Rule 9 by introducing additional provisions and requiring reporting entities to establish and implement a customer due diligence programme. |
G.S.R. 1078(E), 31 October 2018 | Revised Rule 9(1A) by extending the prescribed period from three days to ten days. |
G.S.R. 108(E), 13 February 2019 | Introduced significant changes to Rule 9, strengthening the customer due diligence framework and establishing the basis for further amendments introduced in 2019. |
G.S.R. 381(E), 28 May 2019 | Introduced a dedicated customer due diligence framework for prisoners opening or maintaining bank accounts. The amendment allowed the certification of signatures or thumb impressions by the officer in charge of the jail and permitted continued operation of such accounts subject to annual submission of a proof of address certificate issued by the same authority. |
G.S.R. 582(E), 19 August 2019 | Updated the PML Rules, 2005 by introducing digital KYC, equivalent electronic documents and offline Aadhaar verification. The amendments revised Rule 9 to recognise different modes of customer identification and prescribed a comprehensive digital KYC process involving live photographs, geotagging, OTP based authentication and verification requirements. |
G.S.R. 669(E), 18 September 2019 | Introduced the definition of depository receipt and streamlined customer due diligence requirements for specified foreign investments. The amendments allowed reliance on beneficial ownership standards of notified foreign jurisdictions for certain investments and provided exemptions for listed companies and their subsidiaries from identifying and verifying individual shareholders or beneficial owners in specified circumstances. |
G.S.R. 840(E), 13 November 2019 | Enabled customers using Aadhaar based identity verification to provide a current address different from the address recorded in the Central Identities Data Repository. The amendment allowed reporting entities to accept a self declaration of the current address for customer due diligence purposes, simplifying the address verification process. |
G.S.R. 228(E), 31 March 2020 | Provided temporary relief for small accounts that were due for closure under customer due diligence requirements. The amendment allowed such accounts to continue operating from 1 April 2020 to 30 June 2020, with the possibility of further extensions by the Central Government in view of the COVID 19 pandemic. |
G.S.R. 251(E), 13 April 2020 | Increased the timeline for reporting entities to furnish prescribed transaction reports under Rule 8. The temporary relaxation permitted eligible reports to be submitted up to 30 June 2020 in view of operational challenges arising from the COVID 19 pandemic. |
G.S.R. 254(E), 16 April 2020 | Specified the categories of transaction reports covered by the temporary extension under Rule 8. The amendment applied to reports under Rule 3(1)(A), (B), (BA), (C) and (E) for March, April and May 2020, along with Rule 3(1)(F) reports for the January to March 2020 quarter, allowing their submission until 30 June 2020. |
G.S.R. 798(E), 28 December 2020 | Notified real estate agents with an annual turnover of Rupees 20 lakh or more as persons carrying on a designated business or profession under the PMLA, thereby bringing them within the reporting entity framework and subjecting them to applicable AML obligations. |
G.S.R. 575(E), 13 July 2022 | Introduced specific AML and KYC provisions for reporting entities operating in an International Financial Services Centre. The amendment recognised the head of the reporting entity in India as the designated officer for IFSC entities, expanded the list of officially valid documents available to foreign nationals, inserted the definition of International Financial Services Centre in the Rules, and provided exemptions from certain Central KYC Records Registry requirements for foreign national clients of IFSC reporting entities. |
S.O. 1074(E), 7 March 2023 | Strengthened the AML framework by reducing the beneficial ownership threshold to 10 percent, introducing group wide AML policies, and adding the definitions of group, politically exposed person and non profit organisation. The notification also expanded customer due diligence requirements for legal persons and trusts and introduced registration related obligations for eligible non profit organisations. |
G.S.R. 652(E), 4 September 2023 | Reinforced the AML framework by reducing the beneficial ownership threshold to 10 percent, introducing group wide AML policies, and adding the definitions of group, politically exposed person and non profit organisation. The notification also expanded customer due diligence requirements for legal persons and trusts and introduced registration related obligations for eligible non profit organisations. |
G.S.R. 745(E), 17 October 2023 | Enhanced customer due diligence requirements by requiring identity verification using reliable and independent sources, expanding group wide AML programmes, requiring suspicious transaction reports to be filed promptly after suspicion is formed, and reinforcing confidentiality obligations relating to AML records and reporting. |
G.S.R. 419(E), 19 July 2024 | Strengthened the Central KYC Records Registry framework by requiring reporting entities to use the KYC Identifier to retrieve customer records, limiting requests for duplicate KYC documents to specified circumstances, introducing a seven day timeline for updating KYC records, and requiring reporting entities to retrieve, update and rely on revised KYC information maintained in the Central KYC Records Registry. |
CFT Legislation
Unlawful Activities (Prevention) Act, 1967 (UAPA)
The counter terrorism financing pillar. Section 51A requires a payment aggregator to screen its customers, beneficial owners, and merchants against the designated lists and without delay, freeze funds or other financial assets belonging to persons or entities named under United Nations Security Council resolutions and sanctions regimes.
Procedure for implementing Section 51A of the UAPA
The operating procedure for implementing Section 51A. It explains how designated lists are communicated, how potential matches are identified, verified and reported, and the actions and the timelines a payment aggregator must follow when the details of a customer, merchant or beneficial owner match the details in the designated list.
CPF Legislation
Weapons of Mass Destruction Act, 2005 (WMD Act)
The pillar act to counter proliferation financing. Section 12A prohibits any person, including a payment aggregator, from making funds, financial services or related services available, either directly or indirectly, to persons or entities designated in connection with the proliferation of weapons of mass destruction and their delivery systems.
Procedure for implementing Section 12A of the WMD Act
The implementation procedure for Section 12A. It explains how proliferation related designations are communicated, how potential matches are to be handled, the freezing, reporting and compliance steps a payment aggregator must take on identifying a match.
Weapons of Mass Destruction (Implementation) Rules, 2016
The detailed rules supporting Section 12A. They prescribe the procedural framework for implementing proliferation financing controls, including the obligations relating to designated persons and entities and the corresponding compliance measures.
Not registered with FIU-IND yet, or unsure whether you have to be?
AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.
Overarching Obligations
The cross-cutting obligations that support the AML, CFT, and CPF frameworks across all regulated sectors.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
Govern the central registry that stores customer KYC records for reuse across the financial system. A payment aggregator uploads KYC records to the CKYCR, retrieves existing records during onboarding where available, and updates them within the prescribed timelines when customer information changes, reducing duplication in the KYC process.
FINnet 2.0 reporting formats and the FINGate 2.0 user manuals
Prescribes the electronic reporting formats and the reporting gateway through which a payment aggregator submits suspicious transaction reports and other prescribed reports to FIU-IND, using FINnet 2.0 and FINGate 2.0 platform
Section 11A Aadhaar authentication procedure for reporting entities
Sets out the conditions under which an authorised reporting entity may use Aadhaar authentication for customer due diligence under Section 11A of the PMLA. Where permitted, it provides a lawful digital means of verifying a customer’s identity during onboarding, subject to the prescribed statutory conditions.
Sectoral: The Reserve Bank of India
The Reserve Bank of India is the supervisor for payments. This is the sector specific layer, and the RBI’s regulatory instruments provide the framework governing their authorisation, operations and AML and CFT compliance. The RBI Master Direction on Regulation of the Payment Aggregators is the primary instrument, read alongside the RBI KYC Directions.
Reserve Bank of India, the supervisor
RBI Master Direction on Regulation of Payment Aggregators (15 September 2025)
The principal regulatory instrument for payment aggregators. Issued by the Reserve Bank on 15 September 2025, this Master Direction is the primary rulebook governing the payment aggregator business. It regulates authorisation, merchant onboarding, escrow and settlement arrangements, governance and capital requirements, and the AML and CFT framework, including customer and merchant due diligence, transaction monitoring and reporting obligations. It is the first point of reference for the rules governing how a payment aggregator onboards merchants and processes customer funds.
RBI KYC Directions, 2025 and the KYC compliance notification (28 November 2025)
The consolidated, category specific KYC framework issued on 28 November 2025. Payment aggregators apply these Directions to identify and verify customers, merchant entities and their beneficial owners, assess customer risk, conduct ongoing due diligence, perform periodic KYC updates, maintain records and comply with reporting obligations alongside the Payment Aggregator Master Direction.
RBI Internal Risk Assessment Guidance for ML/TF Risks (2024)
The Reserve Bank’s 2024 guidance requires payment aggregators to maintain a documented assessment of their money laundering and terrorist financing risks across customers, merchant relationships, products, services, delivery channels and geographic exposure, with the assessment reviewed by the board or an appropriate governing body. It provides the practical framework for implementing a risk based approach.
Miscellaneous official reports and guidance
Official reports, circulars and guidance that do not themselves create binding legal obligations but assist payment aggregators in understanding regulatory expectations, emerging risks and supervisory priorities.
FIU-IND Annual Report 2024 to2025
The Financial Intelligence Unit’s annual report summarising reporting volumes, financial intelligence, typologies and enforcement trends. It helps a payment aggregator understand emerging money laundering and terrorist financing risks and calibrate its transaction monitoring and suspicious transaction reporting.
Directorate of Enforcement Annual Report 2025 to 2026
The Enforcement Directorate’s annual report summarising investigations, provisional attachments, prosecutions and other enforcement activity under the Prevention of Money-laundering Act, 2002. It provides a payment aggregator with insight into current enforcement priorities and money laundering trends.
FIU-IND and its Core Functions and FAQs
FIU-IND’s explanation of its statutory role, functions and reporting framework, together with answers to frequently asked questions. It provides a practical reference for payment aggregators on registration, reporting obligations and interaction with FIU-IND.
MHA National Counter Terrorism Policy and Strategy
The Ministry of Home Affairs’ statement of India’s national counter terrorism policy and strategy. Although not a binding regulatory instrument, it provides useful context for understanding the terrorist financing risks and sanctions framework implemented through section 51A of the Unlawful Activities (Prevention) Act, 1967.
International Standards
The global standards India’s framework is built to meet, and against which a payment aggregator’s controls are ultimately judged.
FATF Recommendations
The Financial Action Task Force’s forty Recommendations are the international standard for AML and CFT. Recommendations 9 to 23 set the preventive measures expected of financial institutions and are reflected in a payment aggregator’s customer due diligence, record keeping, and monitoring obligations, while Recommendation 6 sets the framework for the targeted financial sanctions. FATF updated Recommendation 6 on targeted financial sanctions in June 2026.
FATF Mutual Evaluation Report on India, 2024
The peer assessment of India’s AML, CFT and CPF regime, including the Executive Summary. The report assessed India’s technical compliance with the FATF Recommendations and the effectiveness of its AML, CFT, CPF framework, identifying strengths and areas for improvement that continue to influence the supervision of financial institutions, including payment aggregators.
Basel Committee guidance on ML/TF risk (2014, revised 2020)
The Basel Committee’s guidance on the sound management of money laundering and terrorist financing risks, providing internationally recognised supervisory principles for embedding AML/CFT risk management within a regulated financial institution. Although written for banks, it offers useful guidance for a payment aggregator’s own risk management framework.
FATF Risk Based Approach Guidance for the Banking Sector (2014)
FATF’s guidance on applying the risk based approach in the banking sector. Although developed for deposit taking institutions, its principles for assessing customer, product, delivery channel and geographic risk provide useful guidance for payment aggregators in designing their own risk based AML/CFT framework.
Allied Laws
The wider body of Indian law that intersects with a payment aggregator’s AML duties, from the statute under which it is authorised to the predicate offence and enforcement Acts that give money laundering its underlying criminal status.
Payment and Settlement Systems Act, 2007
The Act under which a payment aggregator is authorised to operate a payment system, and the source of the statutory meaning of a payment system and a payment system operator, which includes payment system operator that the PMLA relies on, making it the foundational allied law for the sector.
Master Directions on Authorisation to Operate a Payment System (15 June 2026)
The RBI directions that set the process and conditions for authorisation under the PSS Act, the gateway a payment aggregator must pass through before it may operate, and a reference point for who is a regulated aggregator.
Reserve Bank of India Act, 1934
The parent central banking statute under which the RBI regulates the wider financial system, providing the supervisory backdrop against which a payment aggregator’s authorisation and conduct sit.
Companies Act, 2013
Governs the incorporation, ownership and control of the aggregator itself and of the merchant companies it onboards and supplies the beneficial ownership and significant-control concepts that merchant due diligence relies on.
Foreign Exchange Management Act, 1999 (FEMA)
Regulates cross border funds and foreign investment, which a payment aggregator must observe when a merchant, customer or settlement has an overseas dimension, including cross border payment activity.
Predicate offence and enforcement statutes
Money laundering is the laundering of the proceeds of some other crime, so the schedule of predicate offences and the allied enforcement statutes matter to a payment aggregator assessing why funds passing through a merchant might be tainted. These include the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money Act, 2015, the Foreign Contribution (Regulation) Act, 2010, COFEPOSA 1974, SAFEMA 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.
Core AML, CFT, CPF Obligations for Payment Aggregators in India
The AML, CFT, CPF framework outlines several obligations for a payment aggregator. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.
- Register with FIU-IND. Enrol on the FINnet 2.0 or FINGate 2.0 portal so the institution can file its reports.
- Appoint officers. Appoint a Designated Director and a management level Principal Officer under Rule 7 of the PMLR, the RBI KYC Directions and the Payment Aggregator Master Direction. The same person cannot hold both roles, and both are informed to FIU-IND and the RBI.
- Conduct the internal risk assessment. Run an ML and TF risk assessment across customers, products, channels and geographies, document it, and take its outcome to the board, as the RBI KYC Directions, the Payment Aggregator Master Direction and the IRA Guidance require.
- Document AML policy, controls and procedures. Adopt a board approved policy that turns the risk assessment into the institution’s operating procedures.
- Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR, the RBI KYC Directions 2025 and the Payment Aggregator Master Direction. Given the aggregator business, rigorous merchant onboarding due diligence, the identification of the beneficial owners behind merchant businesses, and watching for fictitious or high risk merchants, are central.
- Ongoing monitoring and periodic updates. Monitor transactions on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low risk customers and merchants. Review each customer’s risk categorisation at least once every six months.
- Sanctions screening. Screen customers and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
- Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value and counterfeit currency reports under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly once the Principal Officer is satisfied, through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train staff by role to apply the controls and recognise red flags in payments, such as transaction laundering through fictitious merchants, sudden spikes in a merchant’s volume, and card testing or mule account patterns.
- Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
- Run group wide controls. Where the institution has subsidiaries, apply AML and CFT programmes at group level, including for branches and majority owned subsidiaries, as the RBI Directions require.
What this article does not cover
This article explains the laws and regulatory instruments that apply to payment aggregators. It does not provide a control compliance manual, and it does not restate each institution’s own establishing statute or its developmental mandate, except where they bear on the AML duties. For implementation, a payment aggregator separately documents customer acceptance, KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction escalation, staff training, audit testing and board reporting. Those controls are the subject of the companion compliance guide.
To see how the payment aggregator framework fits within the sector, see AML laws and regulations for financial institutions in India, and to place it within the national picture, see AML laws and regulations in India.
From regulation to compliance: your next step
Knowing the law is step one. These obligations only protect an institution when they are built into a working programme of risk assessment, policy, customer due diligence, monitoring, screening, reporting, training and independent review. For a payment aggregator, rigorous merchant onboarding due diligence, the identification of the beneficial owners behind merchant businesses and transaction monitoring for signs of misuse are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.
Want to confirm the 2025 directions for your institution?
AML India can walk you through the RBI Payment Aggregator Master Direction and the KYC Directions and build a proportionate merchant due diligence and monitoring programme for your aggregator business.
Frequently Asked Questions
An entity that lets merchants accept online or point of sale payments through a single integration by onboarding the merchants, receiving payment instructions from their customers, pooling the funds and settling them to the merchants. It is authorised and regulated by the Reserve Bank of India under the Payment and Settlement Systems Act, 2007 and is a reporting entity under the PMLA.
Yes. A payment aggregator that operates a payment system is a payment system operator, which is expressly named within the financial institution definition in section 2(1)(l) of the PMLA, so it is a reporting entity under section 2(1)(wa). No separate designation notification is needed.
The RBI Master Direction on Regulation of Payment Aggregators dated 15 September 2025 is the sector specific rulebook, read with the RBI KYC Directions, 2025 consolidated on 28 November 2025 and the RBI Internal Risk Assessment Guidance of 2024. Authorisation to operate the payment system is granted under the Payment and Settlement Systems Act, 2007.
A payment aggregator must carry out full due diligence on every merchant it onboards, identifying the merchant, the beneficial owners behind the merchant business and the nature of the merchant’s activity, and it must monitor merchant transactions for signs of misuse such as transaction laundering. This merchant due diligence is central because a fictitious or complicit merchant is the main money laundering risk in the aggregator model.
Suspicious transaction reports of any value, cash transaction reports where cash above Rupees 10 lakh is involved, and counterfeit currency reports. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly once the Principal Officer is satisfied, through FINnet 2.0.
Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every payment aggregator. A payment aggregator screens its customers, its merchants and their beneficial owners against the United Nations and domestic designated lists and freezes and reports any match.
Official sources and review
Last reviewed: July 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
- Prevention of Money-Laundering Act, 2002 (India Code)
- Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (India Code)
- RBI (payment aggregators – Know Your Customer) Directions, 2025 (Reserve Bank of India)
- RBI Internal Risk Assessment Guidance for ML/TF Risks, 2024 (Reserve Bank of India)
- Unlawful Activities (Prevention) Act, 1967 and Section 51A procedure (MHA)
- WMD Act, 2005 and its Section 12A implementation procedure (India Code)
- FATF Recommendations, including the June 2026 update to Recommendation 6
- FATF Mutual Evaluation Report on India, 2024
- Basel Committee, Sound Management of Risks Related to ML and TF (2014, revised July 2020)
- Financial Intelligence Unit – India, including the Annual Report 2024-25
- Central KYC Records Registry (CKYCR) Operating Guidelines, 2025 (CERSAI)
- Enforcement Directorate Annual Report 2025 to 2026
This guide covers money-laundering law and compliance, a sensitive area where the rules change; confirm the current position for your institution with a qualified professional before acting.
Why work with AML India
AML India helps payment aggregators meet their PMLA and RBI obligations, from risk assessment and policy through to CDD, screening, monitoring, reporting, training and independent review.
Industries we serve: hire purchase and asset finance companies, payment aggregators, housing finance, mortgage guarantee and asset reconstruction companies, insurers, payment system operators and aggregators, banks, DNFBPs, securities intermediaries and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik