Last Updated on: 21st August 2026 | Last Reviewed on: 21st August 2026
Key Takeaways Briefly
- Who is covered: entities authorised to operate a payment system, including card and ATM networks, prepaid payment instrument issuers, money-transfer operators and clearing and settlement systems, as reporting entities under the PMLA.
- Why they are caught: a payment system operator is expressly named within the financial-institution definition in section 2(1)(l) of the PMLA, so it is a reporting entity under section 2(1)(wa). No separate designation is needed.
- Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the RBI Master Directions on Authorisation to Operate a Payment System and the RBI KYC Directions, 2025; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
- Supervisor: the Reserve Bank of India (RBI), under the Payment and Settlement Systems Act, 2007. Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
- Core duties: an internal risk assessment, customer and participant due diligence and KYC, beneficial owner identification, periodic updation, transaction monitoring, prescribed transaction reporting, five year record-keeping and sanctions screening.
This guide is general information on Indian law, not legal advice. For your company’s specific position, speak to a qualified AML professional.
Payment system operators, the entities authorised to operate the systems through which money moves between people and businesses, are reporting entities under the Prevention of Money-Laundering Act, 2002. A payment system operator operates a payment system such as a card or ATM network, a prepaid payment instrument, a money transfer service or a clearing and settlement arrangement. Its AML, CFT and CPF obligations arise under the PMLA, the PML (Maintenance of Records) Rules, 2005, the RBI Master Directions on Authorisation to Operate a Payment System, the RBI KYC Directions, 2025, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework. The Reserve Bank of India authorises and supervises payment system operators under the Payment and Settlement Systems Act, 2007, and reports are submitted to FIU-IND. This guide covers payment system operators as a class; payment aggregators, a specific type, have their own guide.
The core instruments at a glance
Instrument | What it does for a payment system operator |
PMLA, 2002 | The core Act for AML. Names the payment system operator within the financial institution definition and creates the duties of CDD, record-keeping and reporting. |
PML (Maintenance of Records) Rules, 2005 | Set out what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. |
RBI Master Directions on Authorisation to Operate a Payment System | The gateway instrument that sets who may operate a payment system and on what conditions, issued by the RBI and updated to 15 June 2026. |
RBI KYC Directions, 2025 | Carry the customer due diligence, risk categorisation, monitoring, record-keeping and reporting requirements the operator applies. |
UAPA Section 51A and WMD Act Section 12A | Impose targeted financial sanctions for terrorism and proliferation financing. |
FATF Recommendations 9 to 23 | The international preventive measure standards for financial institutions that India’s framework is built to meet. |
Who is a Payment System Operator in India?
A payment system operator is an entity authorised by the Reserve Bank of India under the Payment and Settlement Systems Act, 2007 to operate a payment system. It is an arrangement that enables payments between a payer and a beneficiary.
The category is broad and includes card networks, ATM networks, prepaid payment instrument issuers such as wallet providers, money transfer and remittance operators, clearing houses and settlement systems, and the operators of retail payment systems. This guide covers payment system operators as a class.
The money laundering risk of a payment system operator is a transaction and participant risk. It sits in the customers and participants it serves, in prepaid and stored value instruments that can be loaded and used to layer illicit funds, in money transfer and remittance channels that can carry proceeds across borders, and in the volume and speed of transactions and settlement that can obscure the origin of funds.
The AML framework therefore leans on identifying customers and participants, understanding the nature and source of funds moving through the system, monitoring for structuring, mule activity, sanctions evasion, fraud and other forms of misuse.
Are Payment System Operators Reporting Entities under the PMLA?
Yes. The Prevention of Money-Laundering Act, 2002 creates the offence of money laundering and places core duties on reporting entities. A payment system operator is expressly named within the financial institution definition in section 2(1)(l) of the PMLA, so it is a reporting entity under section 2(1)(wa). No notification under section 2(1)(sa) is needed; a payment system operator is inside the regime by name.
This places a payment system operator in the same broad category of reporting entities that file with FIU-IND, such as banks and other financial institutions, and fall within the wider AML laws and regulations for financial institutions in India. The obligations are calibrated to the kind of system operated, but the reporting entity status is not optional.
Supervisory Authority for Payment System Operators in India
The supervisor for payment system operators is the Reserve Bank of India, which authorises them under the Payment and Settlement Systems Act, 2007 and prescribes the terms of that authorisation through its Master Directions on Authorisation to Operate a Payment System, updated to 15 June 2026.
For AML purposes, the payment system operators apply the RBI KYC Directions, 2025, consolidated on 28 November 2025, and the RBI Internal Risk Assessment Guidance of 2024 as a part of their risk based approach. Authorisation is the gateway to operating a payment system. An entity may not operate a payment system without RBI authorization incorporates the RBI’s AML, CFT, and CPF expectations into the regulatory expectations.
The Financial Intelligence Unit – India receives, analyses, and disseminates reports filed by the payment system operator, while the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA.
Onboarding clients without a documented due-diligence process?
AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.
AML Regulatory Requirements for Payment System Operators in India
The law governing payment system operators is spread across several instruments rather than consolidated in a single code. It is best understood as a layered framework, grouped in the way as the official source material.
This includes core legislation, the overarching obligations, the sectoral supervisor and its directions, the miscellaneous official reports, the international standards, and the allied laws. Each category below lists the instruments that bind a payment system operator, with a short note on what each one does in practice.
The framework is best read from the core. The PMLA is the parent statute, while the PML Rules translate it into operational obligations. The RBI’s Master Directions and KYC Directions give effect to those obligations for the payment system operators.
The UAPA and the WMD Act add on counter terrorism and proliferation financing obligations while the allied laws, including the Payment and Settlement Systems Act under which the payment system operators are authorised, shape the regulatory environment and the risks they must manage. The risk based approach is the common thread that stitches the entire framework together.
Core Legislation
The primary statutes and rules that establish the AML, CFT and CPF obligations for payment system operators, grouped into three categories that cover money laundering, terrorism financing and proliferation financing.
AML Legislation
Prevention of Money-Laundering Act, 2002 (PMLA)
India’s principal AML statute and the foundation of the AML framework for payment system operators. It defines the offence of money laundering, empowers attachment and confiscation of the proceeds of crime, and casts the standing duties of customer due diligence, record-keeping and reporting onto every reporting entity, a payment system operator among them.
Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (PMLR)
The PMLRs give practical effect to the PMLA by prescribing how payment system operators must comply with their statutory obligations. They set out the requirements for customer due diligence and beneficial ownership identification, specify the reports to be filed with FIU-IND and the applicable timelines, prescribe record retention periods, and require the appointment of a Designated Director and a Principal Officer. Most AML compliance obligations of a payment system operator are governed by these Rules.
The PML Rules, 2005 have been amended on numerous occasions to strengthen India’s AML, CFT and CPF framework. The table below provides a chronological legislative history, listing each Gazette notification together with a summary of its key changes.
For payment system operators, the most significant developments have been the progressive strengthening of customer due diligence, beneficial ownership and reporting requirements, particularly the 2023 amendments that reduced the beneficial ownership threshold to 10 per cent and expanded customer due diligence obligations for legal persons and arrangements. These changes have a direct impact on identifying and verifying the natural persons who ultimately own or control corporate participants.
The 31 PMLR Amendment Notifications, in Date Order:
Gazette notification and date | Key change or rule touched |
G.S.R. 389(E), 24 May 2007 | The first round of edits to the 2005 Rules. It extended the Rule 2 meaning of a suspicious transaction to cover dealings with no economic rationale or bona fide purpose and those suggesting terrorism financing, remade Rule 3 for cash tied to forged or counterfeit currency, replaced Rule 8 on furnishing information to the Director, and reduced the Rule 9 requirement from three certified copies to one. |
G.S.R. 816(E), 12 November 2009 | A wide ranging rewrite. It added the non profit organisation and Regulator definitions, redefined the suspicious transaction, and required non profit receipts above Rupees 10 lakh to be reported. It set a ten year record retention rule under Rule 6 and remade Rule 9 to require beneficial owner identification, ongoing due diligence, a ban on anonymous accounts and a Client Identification Programme. |
G.S.R. 76(E), 12 February 2010 | Fine tuned Rules 3, 4, 5 and 7 to bolster record-keeping and the reporting cross references and, most notably, added the first Explanation to Rule 9(1A), which reads the beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction is undertaken. |
G.S.R. 508(E), 16 June 2010 | Reworked Rules 2, 9 and 10 covering definitions, customer due diligence and record-keeping, reshaping how a reporting entity identifies its customers and holds records, within the 2010 tightening of the CDD and records regime. |
G.S.R. 980(E), 16 December 2010 | Built the small account regime, defining the Designated Officer and the small account, adding the NREGA job card and the Aadhaar letter to the officially valid documents in Rule 2, and inserting Rule 9(2A) on how such accounts are opened and watched. |
G.S.R. 481(E), 24 June 2011 | Gave the Rules their short title, editing Rule 1 to shorten the long 2005 name into the Prevention of Money-Laundering (Maintenance of Records) Rules, the PMLR label used from then on. |
G.S.R. 576(E), 27 August 2013 | Reworked Rules 2 and 3 and inserted provisions after Rule 10, touching definitions, the cash and suspicious transaction reporting duties and the records framework so that they matched the reporting obligations. |
G.S.R. 288(E), 15 April 2015 | Reset the Rule 2 definitions; because definitions decide who and what the operative rules reach, the change ran through the framework and began a run of 2015 updates. |
G.S.R. 544(E), 7 July 2015 | Reset Rules 2, 9 and 10 on definitions, customer due diligence and record-keeping, reworking how a reporting entity identifies customers and the records it holds, within a substantial 2015 rewrite of the CDD and records provisions. |
G.S.R. 730(E), 22 September 2015 | Reset Rules 2 and 7, the definitions and the requirement for a Principal Officer and an internal reporting mechanism, bolstering the governance side and the ownership of the reporting function. |
G.S.R. 882(E), 18 November 2015 | Reset the definitions and reporting provisions, reworking how key terms are read and how transactions reach the FIU, and ending the 2015 run of amendments. |
G.S.R. 347(E), 12 April 2017 | Reworked Rule 2 and inserted Rule 9A, bringing the Central KYC Records Registry into the Rules, creating the duty to file customer KYC records centrally and the basis to reuse them, the structural groundwork of today’s CKYCR. |
G.S.R. 538(E), 1 June 2017 | Reworked Rules 2 and 9 to build Aadhaar into customer due diligence, prescribing Aadhaar based identification and authentication for KYC, an approach the Supreme Court’s Aadhaar judgment later reshaped. |
G.S.R. 1038(E), 21 August 2017 | Reworked the Rule 2 definitions, reworking the defined terms that decide how the operative rules apply, one of several definition edits during 2017. |
G.S.R. 1318(E), 23 October 2017 | A further 2017 edit to the Rule 2 definitions, keeping the defined terms current as the framework kept evolving. |
G.S.R. 456(E), 16 May 2018 | Reworked the definitions and customer due diligence provisions, clarifying coverage and how customers are identified and verified, within the continuing refinement of the CDD framework. |
G.S.R. 1078(E), 31 October 2018 | Reworked Rule 9 on customer due diligence, reworking the steps a reporting entity follows to identify and verify customers and beneficial owners, one of a series of Rule 9 edits over 2018 and 2019. |
G.S.R. 108(E), 13 February 2019 | Reworked Rules 2 and 9 on definitions and customer due diligence, after the legislative changes to Aadhaar use, reworking the permitted means of identification. |
G.S.R. 381(E), 28 May 2019 | Reworked Rule 9, reworking the identification and verification process and the routes for confirming a customer’s identity, part of the post Aadhaar reshaping of CDD. |
G.S.R. 582(E), 19 August 2019 | Reworked Rules 2 and 9 and inserted provisions after Rule 11, covering definitions, customer due diligence and the supporting provisions on information and records, among the broader 2019 updates. |
G.S.R. 669(E), 18 September 2019 | Reworked Rules 2 and 9 again, reworking the definitions and the customer due diligence process within the 2019 run of CDD amendments. |
G.S.R. 840(E), 13 November 2019 | Reworked Rule 9 with further edits to the identification and verification requirements, ending the 2019 run of CDD changes. |
G.S.R. 228(E), 31 March 2020 | Reworked the definitions and reporting provisions, reworking defined terms and the manner of reporting transactions, the first of three closely spaced 2020 amendments. |
G.S.R. 251(E), 13 April 2020 | Reworked Rule 8, which governs how transaction reports are furnished to the FIU, reworking the manner and content of what a reporting entity submits. |
G.S.R. 254(E), 16 April 2020 | A follow up Rule 8 edit days after the previous one, the two together tightening the reporting provisions and the route by which reports reach the FIU. |
G.S.R. 798(E), 28 December 2020 | A landmark extension of the regime past the purely financial sector. Read together with G.S.R. 799(E) and 800(E) of the same date, it designated real estate agents and dealers in precious metals and stones and appointed their regulator, drawing non financial businesses into the net. |
G.S.R. 575(E), 13 July 2022 | Brought in the International Financial Services Centre definition with a purpose built beneficial owner provision for IFSC entities and inserted an IFSC proviso into Rule 9A on the CKYCR, so the Rules matched the GIFT City regime. |
S.O. 1074(E), 7 March 2023 | A major amendment adding definitions of politically exposed persons, non profit organisations and group and a Rule 3A duty for group wide AML policies, and lowering the company beneficial ownership threshold from 25 to 10 per cent, with a matching edit to Rule 9(3)(e), squarely relevant to a payment system operator identifying who owns a corporate participant. |
G.S.R. 652(E), 4 September 2023 | The second major 2023 amendment. It placed the Principal Officer at management level, lowered the partnership beneficial ownership threshold from 15 to 10 per cent, added an Explanation of control, obliged trustees to disclose their status, and included the outcome of any Rule 3 and Rule 9 analysis in the records retained, all of which bear on a payment system operator dealing with firms and partnerships as participants. |
G.S.R. 745(E), 17 October 2023 | Reworked Rules 2, 3, 8 and 9 in a single notification, covering definitions, the reporting duties and customer due diligence, adjusting several operative provisions at once to close the 2023 changes. |
G.S.R. 419(E), 19 July 2024 | Rewrote Rule 9(1C) on the KYC Identifier and imposed a seven day deadline to update a CKYCR record after any change, added a duty to pull the updated record, and reworked Rule 9A(2)(g) on filing, retrieving and using registry records, sharpening how current central KYC data is held. |
PML (Manner of Receiving Records Authenticated Outside India) Rules, 2005
A narrow but useful companion set. It fixes how records executed or authenticated outside India are to be received and relied on, which matters when a payment system operator onboards a customer or participant whose documents originate abroad.
CFT Legislation
Unlawful Activities (Prevention) Act, 1967 (UAPA)
The counter terrorism financing pillar. Section 51A obliges a payment system operator to screen customers and participants against the designated lists and to freeze, without delay, funds or accounts belonging to persons or entities named under United Nations Security Council resolutions, so that the payment system cannot service terrorism.
Procedure for implementing Section 51A of the UAPA
The operating manual for those freezes. It sets out how the designated lists are circulated, how a match is to be handled and reported, and the timelines a payment system operator must meet when a name among its customers or participants coincides with a listing.
CPF Legislation
Weapons of Mass Destruction Act, 2005 (WMD Act)
The counter proliferation financing pillar. Section 12A prohibits any person, a payment system operator included, from making funds or financial services available to those connected with the financing of weapons of mass destruction and their delivery systems.
Procedure for Implementing Section 12A of the WMD Act
The companion procedure that makes Section 12A workable, describing how proliferation related designations reach a payment system operator and the freezing and reporting steps it must take on a match.
Weapons of Mass Destruction (Implementation) Rules, 2016
The detailed rules under the WMD Act that fill in the mechanics of implementation, giving a payment system operator certainty on how the proliferation financing controls are to be applied in practice.
Not registered with FIU-IND yet, or unsure whether you have to be?
AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.
Overarching Obligations
The cross cutting systems and procedures that sit above any single sector and carry a payment system operator’s KYC data and reports.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
Govern the central registry that stores customer KYC records for reuse across the financial system. A payment system operator files KYC data to the CKYCR, retrieves an existing record on onboarding, and updates it within the prescribed window when details change, cutting duplicate paperwork for customers and participants.
FINnet 2.0 Reporting Formats and the FINGate 2.0 User Manuals
Define the electronic formats and the gateway through which a payment system operator files its cash, suspicious and other prescribed reports to FIU-IND, replacing the older FINnet system with the current FINnet 2.0 and FINGate 2.0 environment.
Section 11A Aadhaar Authentication Procedure for Reporting Entities
Sets the conditions under which a payment system operator may use Aadhaar authentication for customer verification, following the statutory and Supreme Court limits, giving a lawful digital route to confirm identity at onboarding.
Sectoral: the Reserve Bank of India
The supervisor for payment system operators and the instruments it issues. This is the sector specific layer, and the RBI Master Directions on Authorisation to Operate a Payment System are the gateway an operator works through, read with the RBI KYC Directions for AML.
Reserve Bank of India, the supervisor
RBI Master Directions on Authorisation to Operate a Payment System (15 June 2026)
The star instrument for a payment system operator. Updated by the Reserve Bank to 15 June 2026, these Master Directions govern who may operate a payment system and on what terms: the authorisation process, the eligibility, net worth and governance conditions, and the ongoing obligations that come with running a system through which the public’s money moves. Authorisation is the gateway, and the conditions attached carry the AML expectations into the operator’s licence, so it is where a payment system operator should look first.
RBI KYC Directions, 2025 and the KYC compliance notification (28 November 2025)
The consolidated, category specific KYC framework the RBI issued on 28 November 2025, which a payment system operator applies to identify and risk rate its customers and participants, identify the beneficial owner behind a corporate participant, and set the periodic updating, monitoring, record-keeping, and reporting duties that sit alongside the authorisation conditions.
RBI Internal Risk Assessment Guidance for ML/TF Risks (2024)
The Reserve Bank’s 2024 guidance requiring a payment system operator to run a documented assessment of its money laundering and terrorism financing risks across customers, participants, products, channels and geographies, and to place the outcome before its board, making the risk based approach concrete for a payments business.
Miscellaneous Official Reports and Guidance
Official reports and guidance that are not binding rules but shape how a payment system operator reads its risk and the wider enforcement picture.
FIU-IND Annual Report 2024 to 2025
The Financial Intelligence Unit’s yearly account of reporting volumes, typologies and enforcement trends, useful for a payment system operator calibrating what unusual customer or transaction activity looks like across the sector.
Directorate of Enforcement Annual Report 2025 to 2026
The ED’s yearly summary of PMLA investigations, attachments and prosecutions, a reminder of how the criminal side of the regime operates and where enforcement attention has fallen.
FIU-IND and its Core Functions and FAQs
FIU-IND’s explanation of its own role and a set of frequently asked questions, a plain language reference a payment system operator can use to understand registration and reporting expectations.
MHA National Counter Terrorism Policy and Strategy
The Ministry of Home Affairs statement of national counterterrorism policy, background that frames the UAPA sanctions obligations a payment system operator must apply.
International Standards
The global standards India’s framework is built to meet, and against which a payment system operator’s controls are ultimately judged.
FATF Recommendations
The Financial Action Task Force’s forty Recommendations are the international baseline for AML and CFT. Recommendations 9 to 23 set the preventive measures for financial institutions that a payment system operator’s duties reflect, and FATF updated Recommendation 6 on targeted financial sanctions in June 2026.
FATF Mutual Evaluation Report on India, 2024
The peer assessment of India’s AML and CFT regime, including the Executive Summary, which found India largely compliant and set the direction of travel that continues to shape supervision of financial institutions, payment system operators included.
Basel Committee Guidance on ML and TF risk (2014, revised 2020)
The Basel Committee’s sound management guidance on money laundering and terrorism financing risk, a supervisory benchmark for how a regulated financial institution should embed AML risk management, informative for a payment system operator’s own framework.
FATF Risk Based Approach Guidance for the Banking Sector (2014)
FATF’s guidance on applying the risk based approach in a lending and deposit context, directly transferable to a payment system operator weighing customer, participant and channel risk across the systems it runs.
Allied Laws
The wider body of Indian law that intersects with a payment system operator’s AML duty, from the statute under which it is authorised to the predicate offence and enforcement Acts that give money laundering its underlying crimes.
Payment and Settlement Systems Act, 2007
The Act under which a payment system operator is authorised to run a payment system, and the source of the statutory meaning of a payment system and a payment system operator that the PMLA relies on, making it the foundational allied law for the sector.
Reserve Bank of India Act, 1934
The parent central banking statute under which the RBI oversees the wider financial and payments system, providing the supervisory backdrop against which a payment system operator’s authorisation and conduct sit.
Companies Act, 2013
Governs the incorporation, ownership and control of the operator itself and of the corporate participants it deals with and supplies the beneficial ownership and significant control concepts that customer and participant due diligence relies on.
Foreign Exchange Management Act, 1999 (FEMA)
Regulates cross border funds and foreign investment, which a payment system operator must observe when a customer, participant or settlement has an overseas dimension, including cross border remittance activity.
Predicate offence and enforcement statutes
Money laundering is the laundering of the proceeds of some other crime, so the schedule of predicate offences and the allied enforcement statutes matter to a payment system operator assessing why funds moving through its system might be tainted. These include the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money Act, 2015, the Foreign Contribution (Regulation) Act, 2010, COFEPOSA 1974, SAFEMA 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.
Core AML/CFT/CPF Obligations for Payment System Operators in India
Across that framework, the regulations require a payment system operator to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.
- Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the institution can file its reports.
- Appoint officers. Appoint a Designated Director and a management level Principal Officer under Rule 7 of the PMLR and the RBI KYC Directions. The same person cannot hold both roles, and both are informed to FIU-IND and the RBI.
- Conduct the internal risk assessment. Run an ML and TF risk assessment across customers, products, channels and geographies, document it, and take its outcome to the board, as the RBI KYC Directions and the IRA Guidance require.
- Document AML policy, controls and procedures. Adopt a board approved policy that turns the risk assessment into the institution’s operating procedures.
- Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the RBI KYC Directions 2025. Given the payment system business, identifying customers and participants, the beneficial owners behind corporate participants, and the nature and source of the funds moving through the system, are central.
- Ongoing monitoring and periodic updates. Monitor transactions on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low risk customers and participants. Review each customer’s risk categorisation at least once every six months.
- Sanctions screening. Screen customers and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
- Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value and counterfeit currency reports under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly once the Principal Officer is satisfied, through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train staff by role to apply the controls and recognise red flags in payments, such as structuring across prepaid instruments, mule account activity, rapid pass through of funds, and unusual cross border remittance patterns.
- Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
- Run group wide controls. Where the institution has subsidiaries, apply AML and CFT programmes at group level, including for branches and majority owned subsidiaries, as the RBI Directions require.
What This Article Does Not Cover
This article explains the laws and regulatory instruments that apply to payment system operators. It does not provide a control compliance manual, and it does not restate each institution’s own establishing statute or its developmental mandate, except where they bear on the AML duties. For implementation, a payment system operator separately documents customer acceptance, KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction escalation, staff training, audit testing and board reporting. Those controls are the subject of the companion compliance guide.
To see how the payment system operator framework fits within the sector, see AML laws and regulations for financial institutions in India, and to place it within the national picture, see AML laws and regulations in India.
From Regulation to Compliance: Your Next Step
Knowing the law is step one. These obligations only protect an institution when they are built into a working programme of risk assessment, policy, customer due diligence, monitoring, screening, reporting, training and independent review. For a payment system operator, identifying customers and participants and their beneficial owners, understanding the funds moving through the system and transaction monitoring for signs of misuse are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.
Want to confirm the 2025 directions for your institution?
AML India can walk you through the RBI authorisation and KYC Directions and build a proportionate customer due diligence and monitoring programme for the payment system you operate.
Frequently Asked Questions
An entity authorised by the Reserve Bank of India under the Payment and Settlement Systems Act, 2007 to operate a payment system, such as a card or ATM network, a prepaid payment instrument, a money transfer service or a clearing and settlement arrangement. It is a reporting entity under the PMLA.
Yes. A payment system operator that operates a payment system is a payment system operator, which is expressly named within the financial institution definition in section 2(1)(l) of the PMLA, so it is a reporting entity under section 2(1)(wa). No separate designation notification is needed.
The RBI Master Direction on Regulation of Payment Aggregators dated 15 September 2025 is the sector specific rulebook, read with the RBI KYC Directions, 2025 consolidated on 28 November 2025 and the RBI Internal Risk Assessment Guidance of 2024. Authorisation to operate the payment system is granted under the Payment and Settlement Systems Act, 2007.
A payment system operator must identify and verify its customers and participants, find the beneficial owners behind any corporate participant, and understand the nature and source of the funds moving through its system, with enhanced due diligence for higher risk relationships. It must then monitor transactions on an ongoing basis for structuring, mule activity and other misuse. What the customer base looks like depends on the type of system operated, but the due diligence and monitoring duties apply throughout.
Suspicious transaction reports of any value, cash transaction reports where cash above Rupees 10 lakh is involved, and counterfeit currency reports. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly once the Principal Officer is satisfied, through FINnet 2.0.
Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every payment system operator. A payment system operator screens its customers, its participants and their beneficial owners against the United Nations and domestic designated lists and freezes and reports any match.
Official sources and review
Official sources and review
Last reviewed: July 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
- Prevention of Money-Laundering Act, 2002 (India Code)
- Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (India Code)
- RBI (payment system operators – Know Your Customer) Directions, 2025 (Reserve Bank of India)
- RBI Internal Risk Assessment Guidance for ML/TF Risks, 2024 (Reserve Bank of India)
- Unlawful Activities (Prevention) Act, 1967 and Section 51A procedure (MHA)
- WMD Act, 2005 and its Section 12A implementation procedure (India Code)
- FATF Recommendations, including the June 2026 update to Recommendation 6
- FATF Mutual Evaluation Report on India, 2024
- Basel Committee, Sound Management of Risks Related to ML and TF (2014, revised July 2020)
- Financial Intelligence Unit – India, including the Annual Report 2024-25
- Central KYC Records Registry (CKYCR) Operating Guidelines, 2025 (CERSAI)
- Enforcement Directorate Annual Report 2025 to 2026
This guide covers money-laundering law and compliance, a sensitive area where the rules change; confirm the current position for your institution with a qualified professional before acting.
Why work with AML India
AML India helps payment system operators meet their PMLA and RBI obligations, from risk assessment and policy through to CDD, screening, monitoring, reporting, training and independent review.
Industries we serve: payment system operators, payment aggregators, prepaid payment instrument issuers, NBFCs, housing finance, mortgage guarantee and asset reconstruction companies, insurers, banks, DNFBPs, securities intermediaries and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik