Last Updated on: 12th August 2026 | Last Reviewed on: 12th August 2026
Key takeaways at a Glance
- Who is covered: custodians registered with SEBI under the SEBI (Custodian) Regulations, 1996, including those acting as custodians for foreign portfolio investors and funds, as reporting entities under the PMLA.
- Why they are covered: custodians are covered because they are intermediaries registered with SEBI under section 12 of the SEBI Act. As a result, they fall within the definition of “Intermediary” under section 2(1)(n) of the PMLA and therefore treated as reporting entity under section 2(1)(wa).
- Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the SEBI Master Circular for Custodians, the SEBI AML/CFT Guidelines, 2024 and the SEBI KYC Master Circular; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
- Supervisor: The Securities and Exchange Board of India (SEBI). Reports go to the Financial Intelligence Unit of India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
- Core duties: internal risk assessment, client due diligence and KYC, beneficial owner identification, monitoring of custody and settlement, prescribed transaction reporting, record maintenance for a period of 5 years, and sanctions screening.
This guide is general information on Indian law, not legal advice. For your service’s specific position, speak to a qualified AML professional.
An individual or business registered with the Securities and Exchange Board of India to hold securities and other assets on behalf of clients, to settle their trades and collect the benefits and rights arising from those assets, is classified as a Custodian.
Custodians are reporting entities under the Prevention of Money-Laundering Act, 2002. Their AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the SEBI Master Circular for Custodians, the SEBI AML/CFT Guidelines for securities market intermediaries, the SEBI KYC Master Circular, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework. SEBI supervises custodians, and reports are filed with FIU-IND. This guide forms a wider part of guides covering ML, TF and PF countering obligations for securities market intermediaries.
The core instruments at a glance
Instrument | What it does for a custodian |
PMLA, 2002 | The core legislation. It covers custodians as SEBI registered intermediaries and establishes core duties relating to client due diligence, record-keeping and reporting. |
PML (Maintenance of Records) Rules, 2005 | Provides a procedural framework that supports the PMLA by setting out what a reporting entity must do and how to comply. |
SEBI Master Circular for Custodians | The consolidated conduct rulebook for custodians, into which the KYC and AML obligations are provided. |
SEBI AML/CFT Guidelines (6 June 2024) | The working AML rulebook for every securities market intermediary, including custodians. |
UAPA Section 51A and WMD Act Section 12A | Impose targeted financial sanctions for terrorism and proliferation financing. |
FATF Recommendations | The international preventive measure standards for financial institutions that India’s framework is built to meet. |
What Counts as a Custodian in India?
A custodian is an individual or firm registered with SEBI under section 12 of the SEBI Act, 1992 and the SEBI (Custodian) Regulations, 1996. They carry on the business of holding securities, funds and other assets on behalf of their clients, settle transactions in those assets, collect dividends, interest and other benefits arising from them. Typically, they serve institutional clients, including foreign portfolio investors (FPIs), mutual funds, alternative investment funds (AIFs) and insurers. A custodian serving FPIs may also act as a designated depository participant for their registration and onboarding.
The money laundering risk for custodians is primarily linked to the institutional clients they serve and the assets and transactions they administer. These risks include complex investment structures that obscure beneficial ownership, uncertainty about the source and legitimacy of assets placed in custody, movement of securities and funds between accounts or to third parties, and cross-border transactions involving offshore clients. The AML framework therefore focuses on robust client and beneficial owner identification, understanding the source of holding assets, and on monitoring settlement activity for signs of suspicious activity.
Are Custodians Reporting Entities Under the PMLA?
Yes. Custodians are reporting entities under the Prevention of Money-Laundering Act, 2002. Section 2(1)(n) of the PMLA defines “Intermediary” to include any intermediary associated with the securities market and registered under section 12 of the SEBI Act, 1992; and them being SEBI-registered intermediaries, they fall within this definition. Section 2(1)(wa) then defines a “reporting entity” to include an intermediary. Therefore, custodians are reporting entities under the PMLA by virtue of their registration status.
This brings custodians in the same broad category of reporting entities that file with FIU-IND, like banks and other intermediaries, and within the wider AML laws and regulations for intermediaries in India. The obligations can be calibrated to the custody business, but the reporting entity status is not optional.
Supervisory authority for custodians in India
The Securities and Exchange Board of India is the sectoral regulator and supervisory authority for custodians. SEBI registers and regulates them under the SEBI (Custodian) Regulations, 1996, issues the AML rules custodians rely upon and inspects their compliance. The consolidated conduct instrument is the SEBI Master Circular for Custodians, and the central AML instrument is the SEBI Guidelines on AML Standards and CFT Obligations of Securities Market Intermediaries, read with the SEBI Master Circular on KYC Norms for the Securities Market. Together, these instruments apply requirements relating to client due diligence, beneficial ownership, ongoing monitoring, record-keeping and reporting duties into the language of the custody business.
The Financial Intelligence Unit – India receives, analyses and disseminates the reports submitted by custodians. The Enforcement Directorate investigates and enforces the offence of money laundering under the PMLA. In practical terms, SEBI sets and inspects the rules, FIU-IND receives the intelligence, and the ED enforces the criminal law.
Onboarding clients without a documented due-diligence process?
AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.
AML Regulatory Requirements for Custodians in India
The legal instruments governing custodians are a layered framework, grouped as the core legislation, the overarching obligations, the sectoral regulator and its instruments, the miscellaneous official reports, the international standards, and the allied laws.
Core Legislation
The primary statutes and rules that create the AML, CFT and CPF obligations are grouped into three sub-sets.
AML Legislation
Prevention of Money-Laundering Act, 2002 (PMLA)
The parent anti-money laundering statute. It creates the offence of money laundering and establishes the core obligations for reporting entities. It covers custodians as an intermediary under section 2(1)(n) and provides duties for them, including identification of the client and their ultimate beneficial owner under Section 11A and record maintenance under Section 12. The obligations of the Act are implemented according to the nature and risk profile of the custody services provided.
The PML (Maintenance of Records) Rules, 2005 (PMLR)
The rules made to support the provisions of PMLA. They set out reporting requirements under Rules 3 and 8, mandated appointment of officers under Rule 7, and identification and verification of clients and beneficial owners under Rule 9.
The Rules have been amended from time to time to fit better with the evolving risks and market. The PMLR has been amended through 31 Gazette notifications and orders, set out below in chronological order.
The 31 PMLR Amendment Notifications, in Date Order:
Gazette notification and date | Key change or rule touched |
G.S.R. 389(E), 24 May 2007 | It expanded the Rule 2 meaning of a suspicious transaction to include dealings without economic rationale or bona fide purpose and those pointing to terrorism financing, revised Rule 3 around cash dealings in forged or counterfeit currency, substituted Rule 8 on furnishing information to the Director and lightened the requirement of certified copies from 3 to 1 under Rule 9. |
G.S.R. 816(E), 12 November 2009 | A comprehensive amendment that added the non-profit organisation and Regulator definitions, broadened the suspicious transaction criteria, and required NPO receipts over Rupees 10 lakh to be reported. It set ten-year record retention under Rule 6 and revised Rule 9 to require identification of beneficial owner, ongoing due diligence, a bar on anonymous accounts and a Client Identification Programme. |
G.S.R. 76(E), 12 February 2010 | Amended Rules 3, 4, 5, 7 and 9 to sharpen record-keeping and the reporting references and, above all, added the first Explanation in Rule 9(1A) defining the beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction is conducted. |
G.S.R. 508(E), 16 June 2010 | Revised Rules 2, 9 and 10, covering definitions, customer due diligence and record-keeping. The amendments strengthened the CDD and records framework by updating how reporting entities identify customers and the information and records they must retain. |
G.S.R. 980(E), 16 December 2010 | Established the small-account regime, defining the Designated Officer and the small account, adding the NREGA job card and the Aadhaar letter to the officially valid documents in Rule 2, and inserted Rule 9(2A) on how such an account is opened and monitored. |
G.S.R. 481(E), 24 June 2011 | Amended Rule 1 to shorten the long 2005 name to the Prevention of Money-Laundering (Maintenance of Records) Rules, the PMLR shorthand in use since. |
G.S.R. 576(E), 27 August 2013 | Revised Rules 2 and 3 and inserted provisions after Rule 10, touching definitions, the cash and suspicious transaction reporting duties and the record framework so they matched the reporting obligations. |
G.S.R. 288(E), 15 April 2015 | Amended definitions under Rule 2 since definitions set who and what the operative rules reach. |
G.S.R. 544(E), 7 July 2015 | Revised Rules 2, 9, 10 and inserted Rule 9A on definitions, customer due diligence and record-keeping, revising how a reporting entity identifies customers and what it retains. |
G.S.R. 730(E), 22 September 2015 | Inserted an explanation under Rule 2 clarifying that a marriage certificate may be used as a supporting document for a subsequent change of name in an officially valid document. |
G.S.R. 882(E), 18 November 2015 | Amended Rule 9A for the Central Government to establish the Central KYC Records Registry, extending it from 90 days to 180 days from the date of commencement. |
G.S.R. 347(E), 12 April 2017 | Amended Rule 2 and inserted Rule 9B, bringing the Central KYC Records Registry into the Rules, creating the duty to file customer KYC records centrally and the basis to reuse them, the structural addition behind today’s CKYCR. |
G.S.R. 538(E), 1 June 2017 | Revised Rules 2 and 9 to weave Aadhaar into customer due diligence, prescribing Aadhaar-based identification and authentication for KYC, an approach the Supreme Court’s Aadhaar ruling later reshaped. |
G.S.R. 1038(E), 21 August 2017 | Updated definitions in Rule 2, as they determine how the operative provisions of the Rules apply as part of the broader set of definition changes introduced in 2017. |
G.S.R. 1318(E), 23 October 2017 | An amendment providing for the officially valid documents specifically for foreign nationals. |
G.S.R. 456(E), 16 May 2018 | Inserted a provision in Rule 9 requiring sector-specific regulators to issue applicable guidelines and requiring all reporting entities to establish and implement a customer due diligence (CDD) programme. |
G.S.R. 1078(E), 31 October 2018 | Amended Rule 9 on customer due diligence, by changing the timeline for filing of the customers electronic records from 3 days to 10 days. |
G.S.R. 108(E), 13 February 2019 | Reworked Rules 2 and 9 following legislative changes to Aadhaar use, updating key definitions and the methods available for customer identification and due diligence. |
G.S.R. 381(E), 28 May 2019 | Revised Rule 9, sharpening the identification and verification process and the routes to confirm a customer’s identity, part of the post-Aadhaar reshaping of CDD. |
G.S.R. 582(E), 19 August 2019 | Amended Rules 2 and 9 and inserted annexure after Rule 11, covering definitions, customer due diligence and the supporting provisions on information and records, one of the broader 2019 updates. |
G.S.R. 669(E), 18 September 2019 | Strengthened the regime under Rules 2 and 9 for depository receipt and their CDD. |
G.S.R. 840(E), 13 November 2019 | Further incorporated changes in the identification and verification requirements under Rule 9 closing the 2019 run of CDD changes. |
G.S.R. 228(E), 31 March 2020 | Revised the operational timeline for small accounts during 2020 and allowed for further extensions or changes as notified by the Central Government. |
G.S.R. 251(E), 13 April 2020 | Amended Rule 8, which governs the manner and timeline for furnishing transaction reports to FIU-IND, and changed the applicable reporting deadline. |
G.S.R. 254(E), 16 April 2020 | A follow-up amendment to Rule 8, issued days after the previous revision, temporarily revised the timeline for submitting transaction reports for one quarter. |
G.S.R. 798(E), 28 December 2020 | A landmark expansion of the regime. It introduced the conditions under which dealers in precious metals and stones (DPMS) and real estate agents become subject to the PMLA and identified their respective regulatory authorities. |
G.S.R. 575(E), 13 July 2022 | Inserted the International Financial Services Centre definition with a tailored beneficial owner provision for IFSC entities and added an IFSC proviso to Rule 9A on the CKYCR, aligning the Rules with the GIFT City regime, of note to an AIFI operating in an IFSC. |
S.O. 1074(E), 7 March 2023 | A major amendment that inserted definitions of politically exposed persons, group and non-profit organisations. Inserted Rule 3A duty for group-wide AML policies and revised the company beneficial ownership threshold from 25 to 10 per cent, with a matching change to Rule 9(3)(e), directly relevant to an institution assessing corporate borrowers. |
G.S.R. 652(E), 4 September 2023 | This amendment placed the Principal Officer at management level, lowered the partnership beneficial ownership threshold from 15 to 10 per cent, inserted an Explanation of control, made trustees disclose their status, and brought the results of any Rule 3 and Rule 9 analysis into the records a reporting entity maintains. |
G.S.R. 745(E), 17 October 2023 | Revised Rules 2, 3, 8 and 9 covering definitions, the reporting duties and customer due diligence, adjusting several operative provisions together to close the 2023 changes. |
G.S.R. 419(E), 19 July 2024 | Amended Rule 9(1C) to strengthen the use and maintenance of KYC Identifiers. The changes introduced a seven-day deadline for updating CKYCR records following a change in customer information, required reporting entities to retrieve updated records, and revised Rule 9A(2)(g) on filing, retrieving and use of registry records. Together these amendments strengthened the requirement to keep central KYC data current and accessible. |
The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005
Rules issued under the main act for accepting client records authenticated outside India, relevant where a custodian onboards a non-resident client or a foreign portfolio investor and must rely on documents certified and executed by a foreign certifying authority.
CFT Legislation
The Unlawful Activities (Prevention) Act, 1967 (UAPA)
The counter terrorism statute. Section 51A of the Act requires a custodian to screen clients against the designated lists and to freeze, without delay, the funds and securities of listed persons and entities. The duty binds every custodian, whatever its size, nature and risks involved.
Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023 and 29 August 2023)
The procedure a custodian follows to apply Section 51A, including how to act on a designated list match. The SEBI guidelines fold these steps into the custodian’s legal regime for screening and freezing controls.
CPF Legislation
The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)
The proliferation financing statute. Section 12A of the Act provides the legal basis for targeted financial sanctions relating to the financing of weapons of mass destruction and applies to custodians alongside banks and financial institutions.
Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)
The procedure for applying Section 12A of the Act. It provides steps for custodians to complete the screening and freezing to be followed without any delay once a designated list is matched.
The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016
Rules implementing the WMD Act and supporting the proliferation financing controls custodians must maintain, including screening, identification and action against designated persons and entities.
Not registered with FIU-IND yet, or unsure whether you have to be?
AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.
Overarching Obligations
The cross-cutting systems and procedures that sit above any single regulator and carry a custodian’s external obligations.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
The guidelines govern the central registry that stores client KYC records for reuse across the financial system. It provides functions and duties to be followed by reporting entities, including custodians, to file client KYC data to the CKYCR, retrieve an existing record on onboarding, and update it within the prescribed window when details change, cutting duplicate paperwork for investors.
FINnet 2.0 Reporting Formats (2024) and the FINGate 2.0 User Manuals
These instruments define the electronic formats and the gateway through which a custodian files its cash, suspicious and other prescribed reports to FIU-IND, in the current FINnet 2.0 and FINGate 2.0 environment.
eKYC and Section 11A Aadhaar authentication for the securities market
SEBI’s circular on the eKYC authentication facility under Section 11A of the PMLA provides for custodians to use Aadhaar-based verification for resident clients within the statutory and Supreme Court limits, giving a lawful digital onboarding route.
Sectoral
The market regulator and the instruments it issues. This is the sector-specific layer that applies the broader AML, CFT and CPF framework to custodians and translates it into requirements tailored to the custody services.
Securities and Exchange Board of India (SEBI)
SEBI Master Circular for Custodians
This Master Circular consolidates the conduct requirements for custodians, from registration and net worth to segregation of assets, settlement and reporting. It clearly states that custodians must independently comply with all applicable requirements issued by SEBI from time to time. The master circular therefore functions alongside SEBI’s separate AML CFT and CPF framework.
SEBI Guidelines on AML Standards and CFT Obligations of Securities Market Intermediaries (6 June 2024)
The working AML rulebook for every SEBI-registered intermediary, updated on 6 June 2024. It carries the client due diligence, risk categorisation, beneficial ownership, ongoing monitoring, record-keeping, reporting and sanctions requirements into the securities market. For a custodian, it is the source of the detailed AML duties that sit alongside the master conduct circular.
SEBI Master Circular on KYC Norms for the Securities Market (12 October 2023)
The consolidated KYC framework for the securities market, read with the 12 October 2023 modification circular and the clarification on the use of technology for KYC, which sets how a custodian identifies and verifies its clients and maintains their records through the KYC Registration Agencies.
eKYC, KYC clarification circulars and SEBI FAQs
SEBI’s circular on the eKYC authentication facility under Section 11A, the clarification on the use of technology for KYC and the frequently asked questions on KYC norms give a custodian practical guidance on digital onboarding and record-keeping.
Miscellaneous
Official reports and guidance that are not binding rules but shape how a custodian reads its risk and the wider enforcement picture.
FIU-IND Annual Report 2024-25
The Financial Intelligence Unit’s yearly account of reporting volumes, typologies and enforcement trends, useful for a custodian calibrating what unusual client or trading activity looks like across the market.
Directorate of Enforcement Annual Report 2025-26
The ED’s yearly summary of PMLA investigations, attachments and prosecutions. It shows how the enforcement side of the AML framework operates and helps custodians understand the risks and compliance failures that may affect the securities sector.
FIU-IND and its Core Functions and FAQs
FIU-IND’s explanation of its role and a practical reference for reporting entities on registration, reporting compliance and related compliance expectations.
MHA National Counter Terrorism Policy and Strategy
The Ministry of Home Affairs statement of national counter terrorism policy, background that frames the UAPA sanctions obligations a custodian must apply.
International Standards
The global standards India’s framework is built to meet, and against which a custodian’s controls are ultimately judged.
FATF Recommendations
The Financial Action Task Force’s forty Recommendations provide the international baseline on which India’s AML, CFT and CPF framework is built. Recommendations 9 to 23 set the preventive measures applicable to financial institutions and intermediaries. The recommendations were last updated in June 2026, wherein various recommendations were amended, of which the major one was Recommendation 6 on targeted financial sanctions.
FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)
The peer assessment of India’s AML and CFT regime. It found India largely compliant and set the direction to be travelled for further improvement. Its findings continue to shape India’s risk-based approach, including the supervision of custodians and other securities intermediaries.
IOSCO Objectives and Principles of Securities Regulation
The International Organisation of Securities Commissions standards for securities regulators, the global benchmark, and SEBI’s own conduct and AML expectations for custodians are built to meet.
Basel Committee, Sound Management of Risks Related to Money Laundering and Financing of Terrorism (2020)
The Basel Committee’s sound management guidance, a supervisory benchmark for embedding AML risk management that informs a custodian’s own framework, even though it is bank-facing in origin.
Allied Laws
The wider body of law that defines the securities statutes, offences and enforcement machinery around money laundering. A custodian operates under the securities statutes, while the predicate and enforcement Acts shape the risk it must assess and the conduct it may need to report.
The allied laws that most often bear on a custodian’s risk and together support their compliance principals under the AML, CFT and CPF framework are the following:
The Securities and Exchange Board of India Act, 1992, the Securities Contracts (Regulation) Act, 1956, the Depositories Act, 1996: These laws govern SEBI’s regulatory powers, securities-market activities, securities contracts and the depository system. They provide how custodians are to hold, administer and settle client securities and operate as a reporting entity.
The Companies Act, 2013, the Foreign Exchange Management Act, 1999, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015: These laws are relevant to the identification of corporate clients and beneficial owners, the assessment of foreign investment and cross-border fund flows, and the legitimacy and disclosure of foreign assets. They are particularly important for custodians serving foreign investors and other offshore clients.
The Bharatiya Nyaya Sanhita, 2023, the Bharatiya Nagarik Suraksha Sanhita, 2023, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Fugitive Economic Offenders Act, 2018, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974, the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976: These laws address fraud, cheating, forgery, corruption, concealed ownership, economic offences, foreign exchange violations, smuggling and the forfeiture of illicit property. They may identify predicate offences or other financial crime risks affecting the source, ownership or legitimacy of assets held in custody.
The Narcotic Drugs and Psychotropic Substances Act, 1985, the Foreign Contribution (Regulation) Act, 2010, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000: These laws regulate activities involving unlawful arms, chemical weapons and restricted foreign contributions, relevant for proliferation financing and The Central Vigilance Commission Act, 2003 provides an anti-corruption framework relevant to identifying corruption- related financial crime and its proceeds.
Core AML/CFT/CPF Obligations for Custodians in India
Across the framework, the regulations require a custodian to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.
- Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the custodian can file its prescribed reports.
- Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR and the SEBI Guidelines. The same person cannot hold both roles, and both are to be informed to FIU-IND and, where applicable, SEBI.
- Conduct the internal risk assessment. Run an ML and TF risk assessment across clients, products, channels and geographies, document it, and take its outcome to the board, as the SEBI AML/CFT Guidelines require.
- Document AML policy, controls and procedures. Adopt a board-approved policy that turns the risk assessment into the custodian’s operating procedures.
- Client identification and CDD. Identify and verify every client and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high-risk clients, under Section 11A of the PMLA, Rule 9 of the PMLR and the SEBI KYC Master Circular. Given the custody business, rigorous due diligence on institutional clients such as foreign portfolio investors and funds, identifying the beneficial owners behind layered structures, and understanding the source of the assets brought into custody, are central.
- Ongoing monitoring and periodic updates. Monitor custody and settlement activity on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low-risk clients respectively. Review each client’s risk categorisation at least once every six months.
- Sanctions screening. Screen clients and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
- Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, non-profit organisation receipt reports and counterfeit currency reports under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly once the Principal Officer is satisfied, through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload client KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train staff by role to apply the controls and recognise red flags in custody, such as opaque or multi-layered client ownership, assets brought into custody from unclear sources, unexplained transfers of securities or cash to third parties, and complex cross-border settlement patterns.
- Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
- Run group-wide controls. Where the custodian is part of a group, apply AML and CFT programmes at group level, including for branches and majority-owned subsidiaries, as the SEBI Guidelines require.
What this article does not cover
This article explains the laws and regulatory instruments that apply to custodians for AML, CFT and CPF compliance. It does not provide a control-by-control compliance manual, and it does not restate the SEBI (Custodian) Regulations or the segregation and settlement rules except where they bear on the AML duties. For practical insight, custodians should separately rely on the companion compliance guide that provides for client and beneficial owner due diligence, KYC and CDD procedures, asset source checks, sanctions screening, settlement monitoring, suspicious transaction reporting, staff training, audit testing and board reporting.
To see how the custodian framework fits within the sector, see AML laws and regulations for intermediaries in India, and to place it within the national picture, see AML laws and regulations in India.
From regulation to compliance: your next step
Knowing the law is only the first step. The obligations protect a custodian only when they are translated into a working programme covering risk assessment, policies and procedures, client due diligence, transaction monitoring, sanctions screening, reporting, training and independent review.
For custodians, rigorous client and beneficial owner identification, understanding the source of custodied assets and monitoring settlement for signs of misuse are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.
Want to confirm what the SEBI framework means for your firm?
AML India can walk you through the SEBI Master Circular for Custodians and the AML/CFT Guidelines and build a proportionate client due diligence and source-of-assets programme for your custody business.
Frequently Asked Questions
A person or business registered with SEBI under section 12 of the SEBI Act, 1992 and the SEBI (Custodian) Regulations, 1996, who holds the securities, funds and other assets on behalf of clients, settles their transactions and collects the benefits accruing on those assets.
Yes. Custodians are intermediaries associated with the securities market and registered under section 12 of the SEBI Act, so they fall within section 2(1)(n) and are reporting entities under section 2(1)(wa).
The SEBI Master Circular for Custodians is the consolidated conduct rulebook, read together with the SEBI AML/CFT Guidelines for Securities Market Intermediaries dated 6 June 2024 and the SEBI Master Circular on KYC Norms for the Securities Market dated 12 October 2023. Together they carry the AML and KYC duties into the custody business.
A custodian holds assets for institutional clients, often foreign portfolio investors and funds structured through several layers, so its AML risks sit in seeing the ultimate beneficial owner behind those structures, in the source and legitimacy of the assets brought into custody, and in transfers of securities and cash to third parties or across borders. Rigorous client and beneficial owner identification and source-of-assets checks are the core controls.
Suspicious transaction reports of any value, cash transaction reports where cash above Rupees 10 lakh is involved, non-profit organisation receipt reports and counterfeit currency reports. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly once the Principal Officer is satisfied, through FINnet 2.0.
Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every custodian. A custodian screens its clients and their beneficial owners against the United Nations and domestic designated lists and acts according to the procedure for any match without delay.
Official sources and review
Last reviewed: July 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
- Prevention of Money-Laundering Act, 2002 (India Code)
- Prevention of Money-Laundering (Maintenance of Records) Rules, 2005
- SEBI Master Circular for Custodians (SEBI)
- SEBI Guidelines on AML Standards and CFT Obligations of Securities Market Intermediaries, 6 June 2024 (SEBI)
- SEBI Master Circular on KYC Norms for the Securities Market, 12 October 2023 (SEBI)
- Unlawful Activities (Prevention) Act, 1967 and Section 51A procedure
- WMD Act, 2005 and its Section 12A implementation procedure (India Code)
- FATF Recommendations, including the June 2026 update to Recommendation 6
- FATF Mutual Evaluation Report on India, 2024
- Basel Committee, Sound Management of Risks Related to ML and TF (2014, revised July 2020)
- Financial Intelligence Unit – India, including the Annual Report 2024-25
- Central KYC Records Registry (CKYCR) Operating Guidelines, 2025 (CERSAI)
This guide covers money-laundering law and compliance, a sensitive area where the rules change; confirm the current position for your firm with a qualified professional before acting.
Why work with AML India
AML India helps custodians meet their PMLA and SEBI obligations, from risk assessment and policy development to client due diligence, screening, settlement monitoring, reporting, training and independent review.
Industries we serve: Custodians, Depositories, Foreign Portfolio Investors, Mutual Funds, Stock Brokers, Registrars and other Securities Intermediaries, alongside Banks, NBFCs, Insurers, DNFBPs and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik