Last Updated  on: 25th August 2026       |        Last Reviewed on: 25th August 2026

Key Takeaways at a Glance

  • Who is covered: persons carrying on designated business or profession under section 2(1)(sa) of the PMLA, including real estate agents, dealers in precious metals and stones, trust and company service providers, chartered accountants, company secretaries, cost and management accountants, virtual digital asset service providers, casinos and the gaming sector, and multi-state cooperative societies.
  • Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the section 2(1)(sa) designation notifications; the supervisor’s AML/CFT/CPF guidelines; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
  • Supervisors: vary by sub-sector, the CBIC through its Directorate General of Audit, FIU-IND, the professional institutes (ICAI, ICSI, ICMAI), the Central Registrar and state gaming regulators. Reports go to FIU-IND; the Enforcement Directorate enforces the PMLA.
  • Core duties: an internal risk assessment, customer due diligence and KYC, beneficial owner identification, ongoing monitoring, prescribed transaction reporting, five-year record-keeping and sanctions screening.
  • How are the DNFBPs covered: an activity or threshold trigger, real estate agents at an annual turnover of Rupees 20 lakh or more, and dealers in precious metals and stones at a single or linked cash transaction of Rupees 10 lakh or above.

This guide is general information on Indian law, not legal advice. For your business’s specific position, speak to a qualified AML professional.

Designated non-financial businesses and professions, known as DNFBPs, are reporting entities under the Prevention of Money-Laundering Act, 2002. Their AML, CFT and CPF obligations flow mainly from the PMLA, the PML (Maintenance of Records) Rules, 2005, the notification that brings each activity within section 2(1)(sa), the AML/CFT/CPF guidelines issued by the relevant supervisor, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework. Unlike banks, DNFBPs answer to several different supervisors depending on the sub-sector, while every report is filed with FIU-IND.

Introduction

This guide explains the common AML, CFT and CPF framework that applies across India’s DNFBPs. While the core legal obligations are broadly consistent, the criteria for becoming a reporting entity, the applicable notification and the supervisory authority differ by sector. For detailed requirements specific to a particular business, refer to the dedicated guides for real estate agents, dealers in precious metals and stones, trust and company service providers, the accounting and secretarial professions, virtual digital asset service providers, casinos, or multi-state cooperative societies.

DNFBPs are businesses or professions that, although not financial institutions, provide services involving money, assets or ownership structures that can be misused for money laundering, terrorist financing or proliferation financing. Examples include property transactions, company formation, high-value stones and metals sales, virtual digital asset services and gaming activities. Because of these risks, India extends AML obligations beyond banks to these sectors in line with international standards.

This guide provides a legal overview of the DNFBP framework rather than day-to-day compliance procedures. It explains the principal laws, rules, notifications, regulators and international standards that govern DNFBPs and how they fit together within India’s wider AML, CFT and CPF regime. For practical implementation requirements, refer to the companion guidance on AML compliance requirements.

What DNFBPs Cover and why they are Regulated for AML

The term DNFBP comes from the Financial Action Task Force (FATF), whose Recommendations 22 and 23 ask countries to apply customer due diligence and reporting duties to a defined set of non-financial businesses and professions. India gives effect to that standard through section 2(1)(sa) of the PMLA, which defines the person carrying on a designated business or profession. As the government notifies each activity, that business or profession becomes a reporting entity and must run an AML programme suited to its risk.

The businesses and professions covered as DNFBPs in India are the casinos and gaming operators, real estate agents, dealers in precious metals and stones, virtual digital asset service providers, trust and company service providers, the accounting and secretarial professions when they carry out specified financial transactions for clients, and multi-state cooperative societies. They differ enormously in size, customers and permitted activity, from a single professional in practice to a national exchange, yet each is a gatekeeper the law asks to know its customer, watch how value moves and report what looks wrong.

DNFBPs are regulated because they sit at the points where illicit funds enter the legitimate economy. Placement often runs through a cash-intensive dealer; layering through property, corporate vehicles or virtual assets; and integration through professional advice that lends a transaction respectability. Understanding the three stages of money laundering explains why the perimeter was widened beyond banks in the first place.

DNFBPs as reporting entities under the PMLA

The Prevention of Money-Laundering Act, 2002, known as the PMLA, is the principal legislation governing money laundering in India. It creates the offence of money laundering and imposes core duties on reporting entities. DNFBPs become reporting entities under section 2(1)(wa) when their activities fall within the designated business or profession definition in section 2(1)(sa).

The definition operates through specific sub-clauses. Sub-clause (i) covers activities relating to games of chance, including casinos. Real estate agents and dealers in precious metals, precious stones and other high-value goods were subsequently brought within the definition through notification. The residual sub-clause (vi) has been used to bring additional activities within the framework, including virtual digital asset service providers, specified professional activities of accountants and company secretaries, trust and company service providers and multi-state cooperative societies.

This matters because a DNFBP is not caught the moment it opens for business. It is caught when the government notifies its activity, and often only above an activity or threshold test. The list of DNFBPs subject to the PMLA has grown steadily since 2018, and the section that follows sets out the exact instrument and trigger for each one.

Who supervises DNFBPs in India?

The DNFBP supervisory framework in India is sector specific rather than centralised. Unlike banks, which are primarily supervised by the RBI, DNFBPs are overseen by different authorities depending on the activity involved. This determines which sector-specific requirements apply, who conducts supervision, and which authority can take regulatory or enforcement actions.

The Central Board of Indirect Taxes and Customs (CBIC), acting through its Directorate General of Audit, supervises notified real estate agents and dealers in precious metals and stones. FIU-IND is the designated regulator for trust and company service providers and, since November 2023, for virtual digital asset service providers. The three professional institutes, the Institute of Chartered Accountants of India (ICAI), the Institute of Company Secretaries of India (ICSI) and the Institute of Cost Accountants of India (ICMAI), exercise regulatory and supervisory functions over their respective members in practice. The Central Registrar of Cooperative Societies oversees multi-state cooperative societies, while the relevant state authorities supervise casinos where permitted.

Across the framework, the Financial Intelligence Unit – India is the central recipient of prescribed AML reports, including suspicious transaction reports and other required reports under the PMLA framework. The Enforcement Directorate is responsible for investigating and prosecuting the offence of money laundering under the PMLA. Thus, the framework can be understood as sector-specific supervision, centralised financial intelligence reporting to FIU-IND, and criminal enforcement by the ED.

AML Regulatory Requirements for DNFBPs in India

Read this framework as the common legal basis for DNFBPs. The structure is shared across every DNFBP type, while the designation instrument and the supervisor’s guidelines differ by sub-sector. The law that governs a DNFBP does not sit in one place. It is a layered framework, and it helps to see it grouped as the core legislation, the overarching obligations, the sectoral supervisors and their guidelines, the miscellaneous official reports, the international standards, and the allied laws.

Core Legislation

The primary statutes and rules that create the AML, CFT and CPF obligations are grouped into three sectors.

AML Legislation

Prevention of Money-Laundering Act, 2002 (PMLA)

The parent anti-money laundering law. It creates the offence of money laundering and provides the core duties on reporting entities, including customer due diligence under Section 11A and record-keeping under Section 12. Every notified DNFBP is a reporting entity under the PMLA, so the Act applies to a jeweller, an estate agent or a company secretary in the same way it applies to a bank, adjusted for the scale and nature of the business.

The PML (Maintenance of Records) Rules, 2005 (PMLR)

The rules made under the PMLA, they prescribe the operational AML obligations for reporting entities. They set out the requirements for reporting (Rule 3 and Rule 8), customer due diligence and beneficial ownership identification (Rule 9), and the appointment of principal officer and designated directors (Rule 7). Rule 2(1)(fa) identifies the AML supervisory authority for each DNFBP sector.

The PMLR have been amended numerous times, with several amendments expanding the AML regime by bringing additional DNFBP sectors within its scope.

The 31 PMLR Amendment Notifications, in Date Order:

Gazette notification and date 

Key change or rule touched 

G.S.R. 389(E), 24 May 2007 

The first amendment to the 2005 Rules. It widened the suspicious transaction definition in Rule 2 to cover transactions with no economic rationale or bona fide purpose and those suggesting terrorism financing and revised Rule 3 to capture cash transactions involving forged or counterfeit currency. It also substituted Rule 8 on furnishing information to the Director and eased Rule 9 from three certified copies to one.

G.S.R. 816(E), 12 November 2009 

It inserted the definitions of non-profit organisation and Regulator, redefined suspicious transaction, and added a reporting clause for NPO receipts over Rupees 10 lakh. It set record retention at ten years (Rule 6) and revised Rule 9 to require identification of the beneficial owner, ongoing due diligence, a bar on anonymous accounts, and a Client Identification Programme.

G.S.R. 76(E), 12 February 2010 

Amended Rules 3, 4, 5, 7 and 9 to refine record-keeping and the reporting references. Most notably, it inserted the first Explanation defining the beneficial owner in Rule 9(1A), the natural person who ultimately owns or controls a client or on whose behalf a transaction is conducted.

G.S.R. 508(E), 16 June 2010 

Amended Rules 2, 9 and 10, the core provisions on definitions, customer due diligence and record-keeping. The changes adjusted how customers are identified and what records a reporting entity must maintain, part of the steady tightening of the CDD and records framework through 2010.

G.S.R. 980(E), 16 December 2010 

Introduced the small account regime. It defined the Designated Officer and the small account, widened the officially valid documents in Rule 2 to include the NREGA job card and the Aadhaar letter, and inserted Rule 9(2A) on how a small account is opened and monitored.

G.S.R. 481(E), 24 June 2011 

Created the short title for the Rules. It amended Rule 1 to rename the lengthy 2005 title to the Prevention of Money Laundering (Maintenance of Records) Rules, the short form, PMLR, used ever since.

G.S.R. 576(E), 27 August 2013 

Amended Rules 2 and 3 and inserted provisions after Rule 10, touching definitions, the cash and suspicious transaction reporting duties and the record framework, part of aligning the Rules more closely with the reporting obligations.

G.S.R. 288(E), 15 April 2015 

Amended Rule 2 definitions to determine the scope of the operative provisions.

G.S.R. 544(E), 7 July 2015 

Amended Rules 2, 9, 10, and added Rule 9A covering definitions, customer due diligence and record-keeping. It refined how reporting entities identify customers and what they must retain, part of a substantial 2015 overhaul of the CDD and records provisions.

G.S.R. 730(E), 22 September 2015 

Added an explanation under Rule 2 clarifying that a marriage certificate can be used as a supporting document for a subsequent name change in an officially valid document.

G.S.R. 882(E), 18 November 2015 

Substituted the timeline under Rule 9A from 90 days to 180 days for the central government to establish central KYC records registry.

G.S.R. 347(E), 12 April 2017 

Amended Rule 2 and inserted Rule 9B, which brought the Central KYC Records Registry into the Rules. This created the duty to file customer KYC records centrally and the basis for reusing them, the structural addition that underpins the CKYCR.

G.S.R. 538(E), 1 June 2017 

Revised Rules 2 and 9 to build Aadhaar into the customer due diligence process, setting out how Aadhaar-based identification and authentication fitted into KYC, later reshaped by the Supreme Court’s Aadhaar ruling.

G.S.R. 1038(E), 21 August 2017 

Amended Rule 2, the definitions clause, adjusting defined terms that govern how the operative rules apply. It was one of several definition updates in 2017.

G.S.R. 1318(E), 23 October 2017 

A further amendment to the Rule 2 definitions later in 2017, keeping the defined terms current as the framework evolved.

G.S.R. 456(E), 16 May 2018 

Added a clause under Rule 9 obligating reporting entities to align their CDD programme with the applicable sector specific guidelines.

G.S.R. 1078(E), 31 October 2018 

Extended the timeline for filing a customer’s electronic CDD records from 3 days to 10 days under Rule 9.

G.S.R. 108(E), 13 February 2019 

Amended Rules 2 and 9, covering definitions and customer due diligence. It followed the legislative changes to Aadhaar use and adjusted how identification may be carried out.

G.S.R. 381(E), 28 May 2019 

Amended the identification and verification process and updated the options for verifying a customer’s identity under Rule 9.

G.S.R. 582(E), 19 August 2019 

Amended Rules 2 and 9 and inserted provisions after Rule 11, touching definitions, customer due diligence and the supporting provisions on information and records, one of the wider ranging 2019 updates.

G.S.R. 669(E), 18 September 2019 

Amended Rules 2 and 9, again refining definitions and the customer due diligence process, within the cluster of 2019 CDD amendments.

G.S.R. 840(E), 13 November 2019 

Amended Rule 9, making further refinements to the identification and verification requirements and closing out the run of 2019 amendments to CDD.

G.S.R. 228(E), 31 March 2020 

Increased the validity period for small accounts in the year 2020 and for any other period as central government notifies. 

G.S.R. 251(E), 13 April 2020 

Amended Rule 8, which governs the furnishing of transaction reports to the FIU, refining timeline for reporting entities report.

G.S.R. 254(E), 16 April 2020 

A further amendment to Rule 8 amending the transaction reporting deadline for the specific quarter.

G.S.R. 798(E), 28 December 2020 

It designated real estate agents and dealers in precious metals and stones as persons carrying on designated business or profession and named the CBIC as their regulator, widening the perimeter of the regime well beyond banks and financial institutions.

G.S.R. 575(E), 13 July 2022 

Added the International Financial Services Centre (IFSC) definition and a tailored beneficial owner provision for entities located in an IFSC and added an IFSC proviso to Rule 9A on the CKYCR, adapting the Rules to the GIFT City IFSC framework.

S.O. 1074(E), 7 March 2023 

It inserted definitions of politically exposed persons, non-profit organisations and group, and added Rule 3A requiring group-wide AML policies. Most significantly, it cut the beneficial ownership threshold for companies from 25 per cent to 10 per cent and made the matching cut in Rule 9(3)(e), pulling more owners and entities into the due diligence net.

G.S.R. 652(E), 4 September 2023 

The second major 2023 amendment. It required the Principal Officer to be at management level, cut the beneficial ownership threshold for partnerships from 15 per cent to 10 per cent, and inserted the Explanation clarifying what counts as control. It also required trustees to disclose their status and added the results of any analysis under Rules 3 and 9 to the records a reporting entity must keep. The unincorporated association threshold stayed at more than 15 per cent.

G.S.R. 745(E), 17 October 2023 

Amended Rules 2, 3, 8 and 9, covering definitions, the reporting duties and customer due diligence, refining several operative provisions together and rounding off the run of 2023 amendments.

G.S.R. 419(E), 19 July 2024 

Amended Rule 9(1C) on the KYC Identifier and required records on the CKYCR to be updated within seven days of any change. It added the duty to retrieve updated records and amended Rule 9A(2)(g) on the filing, retrieval and use of registry records, sharpening how reporting entities keep central KYC data current. 

The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005

Rules for accepting customer records authenticated outside India, relevant where a DNFBP onboards a non-resident client or a foreign corporate structure, common for trust and company service providers and larger real estate transactions.

CFT Legislation

The Unlawful Activities (Prevention) Act, 1967 (UAPA)

The counter terrorism law. Section 51A requires every reporting entity, including a DNFBP, to screen customers against the designated lists and to freeze, without delay, the funds and assets of listed persons and entities.

Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023 and 29 August 2023)

The official procedure a DNFBP follows to apply Section 51A, including how to act on a designated list match. Several supervisors have issued sub-sector standard operating procedures that mirror this order, for example, the screening SOPs for real estate agents and for dealers in precious metals and stones dated December 2023.

CPF Legislation

The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)

The proliferation financing law. Section 12A provides the legal basis for targeted financial sanctions relating to the financing of weapons of mass destruction and applies to DNFBPs alongside financial institutions.

Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)

The official procedure for applying Section 12A mirrors the screening and freezing steps for proliferation financing that Section 51A sets for terrorism financing.

The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016

Rules implementing the WMD Act and supporting the proliferation financing controls a DNFBP must comply with.

Overarching Obligations

The national instruments that every DNFBP relies upon, whatever its sub-sector or supervisor.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

The guidelines govern the central repository for customer KYC records. Reporting entities, including eligible DNFBPs, upload and retrieve KYC records through CKYCR, enabling the reuse of verified customer information, reducing duplication, and promoting consistent customer due diligence. Accurate identity and beneficial ownership information is essential to ensure reliability and effectiveness.

FINnet 2.0 reporting formats (2024) and the FINGate 2.0 user manuals

The FINnet 2.0 and FINGate 2.0 platforms are FIU-IND’s electronic reporting systems through which reporting entities, including DNFBPs, register and submit prescribed AML reports. The FINGate 2.0 manuals guide enrolment, user management, portal guidance on enrolment, user management, portal operations and report filing, while the reporting entity register includes the notified DNFBP categories.

Section 11A Aadhaar Authentication Procedure for Non-Banking Entities (9 May 2019)

The procedure for processing applications by entities other than banking companies to use Aadhaar authentication services. It matters to DNFBPs because they are precisely the non-banking reporting entities that must apply for permission before using Aadhaar-based identity verification.

Sectoral Guidelines

The supervisors, the designation notifications and the sub-sector guidelines. This is the layer that differs most from the banking framework, because DNFBPs share no single regulator. The map below groups each supervisor with the DNFBPs it oversees.

Central Board of Indirect Taxes and Customs (through the Directorate General of Audit)

The CBIC is the AML supervisory authority for real estate agents and for dealers in precious metals and stones, named as such in Rule 2(1)(fa) of the PMLR. Real estate agents become reporting entities when they have an annual turnover of Rupees 20 lakh or more, while dealers in precious metals and stones are covered when they engage in a cash transaction with a customer of Rupees 10 lakh or more in a single or in segregated linked transactions. Both sectors must comply with the CBIC’s follow AML, CFT and CPF guidelines issued on 29 November 2023, with dealers also subject to additional suspicious transaction reporting guidance under Rule 7(3) dated 3 July 2023.

Financial Intelligence Unit - India (FIU-IND)

FIU-IND serves both as India’s central AML reporting and financial intelligence hub and as the designated regulator for trust and company service providers and virtual digital asset service providers. TCSP activities were brought within the PMLA framework by S.O. 2135(E) of 9 May 2023, covering activities such as acting as a formation agent, providing a director, secretary or partner, providing a registered office or address, and acting as a trustee. Their TCSP AML/CFT guidelines took effect from 21 April 2026.

Virtual digital asset service providers were brought within the framework by S.O. 1072(E) of 7 March 2023, covering the exchange, transfer, safekeeping and issuance of virtual digital assets. The Director of FIU-IND was designated as their regulator on 9 November 2023; their guidelines were updated on 8 January 2026. Thus, FIU-IND combines reporting, regulatory and supervisory functions for these two DNFBP categories.

Because company structures and virtual assets are classic layering tools, this is also where the misuse of shell companies is most closely watched.

The professional institutes (ICAI, ICSI and ICMAI)

The ICAI, ICSI and ICMAI supervise their respective members in practice. Under S.O. 2036(E) of 3 May 2023, specified financial transactions carried out by a relevant person on behalf of a client were brought within the PMLA framework. A relevant person is an individual holding a certificate of practice under the Chartered Accountants Act, the Company Secretaries Act or the Cost and Works Accountants Act. The covered activities include managing client money, securities or other assets, managing bank, savings or securities accounts, and the creation, operation or management of companies, limited liability partnerships or trusts. The three institutes issued joint AML, CFT and CPF guidelines for their members on 19 June 2023, and the ICAI has published its own PMLA FAQs; avoiding the common AML mistakes chartered accountants make starts with reading them.

Other supervisors: the Central Registrar and state gaming regulators

Multi-state cooperative societies were among the earliest DNFBPs, notified by G.S.R. 424(E) of 4 May 2018 under section (2)(sa)(vi), and are supervised within the cooperative framework of the Central Registrar; their AML, CFT and CPF guidelines came into effect on 11 October 2024.

Casinos fall within section(2)(sa)(i) as activities for playing games of chance and are overseen by state gaming regulators where they are licensed, with Goa’s anti-money laundering and financing terrorism guidelines of 2013 an early example of sub-national supervision in this space.

Miscellaneous

Official reports and guidance that sit outside the binding rulebook but shape how a DNFBP reads its risk and its duties.

FIU-IND Annual Report 2024-25

It provides an overview of the FIU-IND’s supervisory, reporting and intelligence activities. It highlights reporting trends across different reporting entities, including DNFBPs, summarises typologies and enforcement initiatives, and identifies emerging ML, TF and PF risks. The report is a useful resource for understanding FIU-IND’s supervisory priorities and regulatory expectations for reporting entities.

Directorate of Enforcement Annual Report 2025-26

The ED’s annual report provides an overview of investigations, provisional attachments, prosecutions and asset confiscation under the regulatory framework. It highlights significant cases and operational priorities, helping DNFBPs understand how compliance obligations are to be enforced in practice and the consequences of non-compliance.

FIU-IND and its Core Functions and FAQs

A question-and-answer explanation of how FIU-IND functions and how the prescribed reports are to be submitted, a useful primer for a DNFBP setting up its reporting function for the first time.

MHA National Counter Terrorism Policy and Strategy

The Ministry of Home Affairs statement of national counter terrorism policy outlines India’s approach to preventing and combatting terrorism. It provides the broader policy context for the counter terrorist financing obligations imposed on reporting entities under Section 51A of the UAPA.

DPMS suspicious transaction guidance under Rule 7(3) (3 July 2023)

Guidance for dealers in precious metals and stones on detecting suspicious transactions, a concrete example of sub-sector red flag guidance that other DNFBPs can read across for their own monitoring.

International Standards

The global benchmarks India is measured against, and the sources DNFBPs can use to calibrate a risk-based approach.

FATF Recommendations

The international AML, CFT and CPF standards on which India’s DNFBPs regulatory framework is based. Recommendations 22 and 23 extend customer due diligence and suspicious transaction reporting obligations to non-financial businesses and professions, while Recommendation 6 sets the framework for targeted financial sanctions. The recommendations were last updated in June 2026, and India’s DNFBP framework continues to align with these international standards.

FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)

The peer assessment report of India’s AML, CFT and CPF framework against the FATF recommendations. It evaluates how well DNFBPs are supervised, implement AML obligations and report suspicious transactions, identifies areas requiring improvement, and serves as a key benchmark for strengthening India’s DNFBP regulatory regime.

FATF Risk-Based Approach Guidance for the Real Estate Sector (2022)

Sector guidance for estate agents on identifying and managing money laundering risk in property transactions, a ready-made template for a real estate agent’s internal risk assessment.

FATF Risk-Based Approach Guidance for Trust and Company Service Providers (2019)

Sector guidance for TCSPs on the money laundering risks in company formation, nominee and trustee services, and how to manage them under a risk-based approach.

FATF Risk-Based Approach Guidance for the Accounting Profession (2019)

Sector guidance for accountants on the money laundering and terrorist financing risks in the specified financial transactions they carry out on behalf of clients, and how a risk-based approach applies to the profession.

Allied Laws

The supporting statutes that define the offences and the enforcement machinery around money laundering. A DNFBP does not administer these Acts, but they shape the risk it must assess and the conduct it may need to report. Some are sub-sector specific such as the Real Estate (Regulation and Development) Act, 2016 for estate agents, and the Indian Trusts Act, 1882 and the Limited Liability Partnership Act, 2008 for trust and company service providers.

The PMLA, UAPA and the WMD Act are the principal AML, CFT and CPF law, but DNFBPs must also consider a range of allied laws that govern the activities, transactions and offences connected with money laundering. These laws regulate areas such as company formation, real estate, foreign exchange, trusts corruption, tax evasion, narcotics, sanctions and other financial economic crimes. These includes, the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023 the Companies Act, 2013, the Limited Liability Partnership Act, 2008, the Indian Trusts Act, 1882, the Real Estate (Regulation and Development) Act, 2016, the Foreign Exchange Management Act, 1999, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974 (COFEPOSA), the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976(SAFEMA), the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.

How the laws fit together

The AML framework for DNFBPs in India is built in layers. Each layer interrelating amongst each other. The PMLA establishes the legal obligations; the PML rules set out the requirements for CDD, record-keeping, report filing and the notifications issued under section 2(1)(sa), together with sector-specific guidance, identify who is covered and how compliance must be implemented. FIU-IND receives and analyses prescribed reports, while the UAPA and the WMD Act impose targeted financial sanctions obligations. The FATF Recommendations provide the international standards that underpin the entire framework. The table below maps each law, authority and guidance to its role.

Authority or instrument Role
PMLA, 2002 The parent anti-money laundering law. Creates the offence and the core reporting entity duties.
PML (Maintenance of Records) Rules, 2005 Set out customer due diligence, beneficial ownership, record-keeping and reporting requirements.
Section 2(1)(sa) designation notifications Bring each business or profession within the reporting entity net, often on an activity or threshold trigger.
Sub-sector supervisors and guidelines CBIC, FIU-IND, the professional institutes, the Central Registrar and state gaming regulators issue and inspect the rules for their sub-sector.
FIU-IND Receives, analyses and disseminates the reports DNFBPs file.
Enforcement Directorate  Investigates and prosecutes the offence of money laundering under the PMLA.
UAPA Section 51AImposes counter terrorism targeted financial sanctions.
WMD Act Section 12A Extends targeted financial sanctions to proliferation financing.
FATF Recommendations 22 and 23  Set the international standards for DNFBPs that India is measured against.

How each DNFBP is covered: the activity and threshold triggers

Because DNFBPs are notified on an activity-by-activity basis, the legal instrument, qualification trigger and supervisory authority vary by sector. The table below shows whether a business is covered, when it becomes a reporting entity, and who supervises it. While the core compliance obligations are common, the basis for designation differs across sectors.

DNFBP type Designation instrument Trigger or threshold Supervisor
Casinos and gaming Section 2(1)(sa)(i) Activities for playing games of chance for cash or kind, including casino activity State gaming regulators
Multi-state cooperative societies  G.S.R. 424(E), 4 May 2018 The mere registration under the multi-state cooperative society act. Central Registrar
Real estate agents  G.S.R. 798(E), 28 December 2020  Annual turnover of Rupees 20 lakh or more. CBIC (DG Audit)
Dealers in precious metals and stones G.S.R. 799(E), 28 December 2020 Cash transaction of Rupees 10 lakh or more, through a single or several linked transactions CBIC (DG Audit)
Virtual digital asset service providers S.O. 1072(E), 7 March 2023 Exchange, transfer, safekeeping or issuance services for virtual digital assets FIU-IND (from 9 Nov 2023)
Chartered accountants, company secretaries, cost and management accountants S.O. 2036(E), 3 May 2023 Specified financial transactions carried out on behalf of a client during practice ICAI, ICSI, ICMAI
Trust and company service providers S.O. 2135(E), 9 May 2023 Formation agent, director or secretary, registered office provider or trustee services FIU-IND

Core obligations across all DNFBPs at a glance

Across that framework, the law requires every notified DNFBP to do the following. This guide states each duty at the level set by the law; the sub-sector guides and the compliance companion explain how to carry each one out.

  • Assess your risk. Conduct an internal risk assessment of money laundering, terrorist financing, and proliferation financing across your customers, products or services, delivery channels, and geographies, and keep it current.
  • Know your customer. Identify and verify every customer and the beneficial owner under Section 11A of the PMLA, Rule 9 of the PMLR and your supervisor’s guidelines, before or during the transaction as the rules require.
  • Find the real owner. Identify the beneficial owner, the natural person who ultimately owns or controls the customer. For a company or partnership, the threshold is a controlling interest of more than 10 per cent; for an unincorporated association or body of individuals it is more than 15 per cent; and for a trust it covers the author, the trustees, beneficiaries with a 10 per cent or more interest and anyone exercising ultimate control.
  • Monitor on an ongoing basis. Watch the business relationship for unusual or suspicious activity and review the customer’s risk categorisation so you can decide whether enhanced due diligence is required.
  • Report to FIU-IND. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, cross-border wire transfer reports where applicable, and reports on cash transactions involving counterfeit currency, forged valuable security or forged documents, under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; a suspicious transaction report is filed promptly once the Principal Officer is satisfied that the transaction is suspicious.
  • Keep records. Keep transaction records for five years from the date of the transaction, and keep identity records, account files and business correspondence for five years after the business relationship ends, under Section 12 of the PMLA.
  • Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR. The same person cannot hold both roles, and the entity must inform FIU-IND.
  • Screen against sanctions lists. Screen customers and transactions against the UAPA and WMD Act designated lists and freeze any matched funds without delay.

CFT and CPF: targeted financial sanctions

Anti-money laundering is only part of the duty. A DNFBP must also counter the financing of terrorism (CFT) and the financing of weapons of mass destruction, known as counter-proliferation financing (CPF). Both work through targeted financial sanctions: screening customers and transactions against designated lists and freezing any matched funds without delay. The sanctions screening process is the same in principle for all reporting entities.

The CFT duty flows from Section 51A of the UAPA, as implemented by the 2 February 2021 procedure and its corrigendum. The CPF duty arises under Section 12A of the WMD Act and is applied through the procedure dated 1 September 2023. In practice, DNFBPs screen their clients against the United Nations Security Council lists and the relevant domestic lists, act on any match, and file the prescribed report as required.

What happens if a DNFBP breaches AML law?

A breach of the AML framework is not a single risk but several, because more than one body can act, each under its own power. The reporting duties also run continuously, so a missed or incorrect filing can be treated as an ongoing default rather than a one-off.

Body What it can do on a breach
FIU-IND and the sub-sector supervisorCompliance orders, monetary penalties and warnings on the reporting entity and its officers under Section 13 of the PMLA, and supervisory action within the sub-sector’s own framework.
Enforcement DirectorateInvestigation, provisional attachment of the proceeds of crime, and prosecution for the offence of money laundering under the PMLA.
Professional or licensing bodyFor the professions and licensed operators, disciplinary action against the member’s certificate of practice or the operator’s licence.

From regulation to compliance: your next step

Knowing the law is only the first step. Compliance is effective only when these obligations are embedded into a practical AML programme that includes risk assessment, policy and procedure, customer due diligence, ongoing monitoring, sanctions screening, prescribed reports filing, staff training and independent audit. To see how the DNFBP framework fits within the national picture, see AML laws and regulations in India, and use navigating the AML regulatory framework in India to place your business within it.

Want to talk through what your designation means in practice?

AML India can confirm whether your business is a notified DNFBP, which supervisor and guidelines apply, and what a proportionate programme looks like for your size and risk.

Frequently Asked Questions

A DNFBP is a designated non-financial business or profession, defined in the PMLA as a person carrying on designated business or profession under section 2(1)(sa). It is a business or profession that is not itself a financial institution but is notified by the government as a reporting entity, so it must run an AML programme, carry out customer due diligence and report prescribed transactions to FIU-IND.

The notified DNFBPs are casinos and the gaming sector, real estate agents, dealers in precious metals and stones, virtual digital asset service providers, trust and company service providers, chartered accountants, company secretaries and cost and management accountants, and multi-state cooperative societies. The list has grown through successive notifications since 2018.

There is no single supervisor. The CBIC, through its Directorate General of Audit, supervises real estate agents and dealers in precious metals and stones; FIU-IND supervises trust and company service providers and virtual digital asset service providers; the ICAI, ICSI and ICMAI are supervised by their own statutory body; the Central Registrar oversees multi-state cooperative societies; and state gaming regulators oversee casinos. Every DNFBP files its reports with FIU-IND, and the Enforcement Directorate enforces the PMLA.

A real estate agent is a designated business once its annual turnover reaches Rupees 20 lakh or more, under G.S.R. 798(E) of 28 December 2020. A dealer in precious metals and stones is covered when it engages in a cash transaction with a customer of Rupees 10 lakh or more, in a single transaction or in several linked transactions, under G.S.R. 799(E) of the same date.

Yes, when acting in practice and carrying out specified financial transactions on behalf of a client, such as managing client money, securities or accounts, or forming or managing companies, LLPs or trusts. This was notified by S.O. 2036(E) of 3 May 2023.

Yes. Virtual digital asset service providers are treated as DNFBPs, as the central government, exercising its power under section 2(1)(sa)(vi) of the PMLA 2002, issued a notification by S.O. 1072(E) of 7 March 2023, notifying specified VDA activities as designated businesses or professions.

DNFBPs must file the reports prescribed under Rule 3 of the PMLR, including cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit-currency reports and, where applicable, cross-border wire transfer reports. Reports are filed electronically through the FINnet 2.0 platform, cash and related reports monthly by the 15th of the succeeding month, and suspicious transaction reports promptly once the Principal Officer is satisfied that a transaction is suspicious.

Official sources and review

Why work with AML India

AML India helps DNFBPs in meeting their PMLA and sector-specific obligations through risk assessment, policy development, CDD, screening, ongoing monitoring, report filing, staff training, software selection and independent audit.

Industries we serve: Real Estate Agents, Dealers in Precious Metals and Stones, Trust and Company Service Providers, Chartered Accountants, Company Secretaries and Cost and Management Accountants, Virtual Asset Service Providers, Casinos and the Gaming Sector, Multi-State Cooperative Societies, and Banks, Financial Institutions and IFSC and GIFT City entities.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik