Last Updated on: 21st August 2026 | Last Reviewed on: 21st August 2026
Key Takeaways at a Glance
Who is covered: casinos and operators of games of chance for cash or kind, licensed in the states that permit them, as persons carrying on a designated business or profession under section 2(1)(sa)(i) of the PMLA.
How they are covered: casinos are directly covered under PMLA without any turnover or transaction threshold requirement. On the other hand, For Gaming Sector playing game of chance is the trigger.
Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; state casino AML guidelines, notably the Goa Anti-Money-Laundering and Financing of Terrorism Guidelines, 2013; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
Supervisors: the state gaming regulators that license casinos (Goa, Sikkim and Daman). Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA. Online money gaming is separately governed by the Promotion and Regulation of Online Gaming Act, 2025.
Core duties: customer identification and KYC at prescribed thresholds, beneficial-owner identification, ongoing monitoring, cash and suspicious transaction reporting, five-year record-keeping and sanctions screening.
This guide is general information on Indian law, not legal advice. For your business’s specific position, speak to a qualified AML professional.
Casinos are reporting entities under the Prevention of Money-Laundering Act, 2002. Unlike most designated businesses, they are named in the Act itself: a person carrying on activities for playing games of chance for cash or kind, including the activities associated with a casino, is a person carrying on a designated business or profession. A licensed casino therefore does not wait for a separate notification. Its AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, any applicable state casino guidelines such as the Goa guidelines of 2013, the UAPA, the WMD Act and the FIU-IND reporting framework. The gaming sector also includes online gaming, which India now regulates separately, and this guide explains where the two regimes meet and part.
The core instruments at a glance
| Instrument | What it does for a payments bank |
| PMLA, 2002 | The parent Act. mandates casinos as a designated business and creates the core duties of CDD, record-keeping and reporting. |
| Section 2(1)(sa)(i) | The clause that makes a person running games of chance for cash or kind, including a casino, a reporting entity by statute. |
| PML (Maintenance of Records) Rules, 2005 | Set out what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. |
| Goa AML and Financing of Terrorism Guidelines, 2013 | State-level casino AML guidelines explaining KYC and reporting for casinos, the one AML-specific sector guideline in this space. |
| UAPA Section 51A and WMD Act Section 12A | Impose targeted financial sanctions for terrorism and proliferation financing on every casino. |
| Promotion and Regulation of Online Gaming Act, 2025 | The separate central law that regulates online gaming and prohibits online money gaming. |
What counts as a casino and gaming business in India?
The PMLA reaches a person carrying on activities for playing games of chance for cash or kind, and expressly includes the activities associated with a casino. In practice, this covers the licensed casinos that operate in the states which permit them, principally Goa, Sikkim and Daman, whether on land or on the offshore vessels that Goa licenses. Gaming for stakes is the activity that matters; a casino is a cash-intensive business where customers convert cash to chips and back again, which is exactly the environment in which the origin of money can be obscured.
The gaming sector is wider than casinos. Games of skill, lotteries and, most significantly, online gaming sit under their own laws, and the position of online money gaming changed with the Promotion and Regulation of Online Gaming Act, 2025, which prohibits online money games and online money gaming services and establishes an authority to oversee online gaming. Betting and gambling are, in the main, a state subject, so the licensing and conduct of gaming vary from state to state even where the PMLA duties are common. This guide covers the AML framework; it does not decide whether a given activity is lawful in a given state.
Are casinos reporting entities under the PMLA?
Yes. Casinos are expressly covered as reporting entities under the Prevention of Money-Laundering Act, 2002. Section 2(1)(sa)(i) of the Act includes a person carrying on a designated business or profession involving games of chance for cash or kind, including casino activities. Therefore, casinos fall within the PMLA framework by virtue of the statutory definition itself; no separate notification is required to designate them as reporting entities.
Once within the Act, a casino must run a full AML programme and report to FIU-IND. This places a casino in the same broad category of reporting entities that file with FIU-IND as banks and other designated businesses and connects it to the wider set of DNFBPs subject to the PMLA.
Supervisory authority for casinos and the gaming sector in India
Casinos are primarily licensed and regulated under the gaming laws of the state or union territory in which they operate. There is no single central sectoral regulator for casinos. IN the principal casino jurisdictions, including Goa, Sikkim and Daman, the relevant state or union territory authority administers the applicable licensing and gaming requirements. However, casinos that fall within the PMLA definition of a reporting entity must comply with the PMLA and PML rules.
Whatever the licensing state, the reports go to one place. A casino files with the Financial Intelligence Unit – India, which receives, analyses and disseminates them, while the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. For online gaming, oversight sits with the Ministry of Electronics and Information Technology, and the authority established under the Promotion and Regulation of Online Gaming Act, 2025, a separate line from the casino framework.
AML Regulatory Requirements for Casinos and the Gaming Sector in India
The law that governs a casino does not sit in one place. It is a layered framework, and it helps to see it grouped the core legislation, the overarching obligations, the sectoral regulators and their guidelines, the miscellaneous official reports, the international standards, and the allied laws.
Core Legislation
The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into three sub-sets.
AML Legislation
Prevention of Money Laundering Act, 2002 (PMLA)
India’s parent anti-money laundering statute, and the instrument that names casinos as a designated business in section 2(1)(sa)(i). It defines the offence of money laundering and imposes the duties of customer due diligence under Section 11A and record-keeping under Section 12 that a casino must run on the gaming floor. The Act reaches casinos because they are intensely cash-based, letting a customer turn cash into chips, play a little, and cash out with a clean casino cheque, a classic laundering route the FATF has long flagged.
The PML (Maintenance of Records) Rules, 2005 (PMLR)
The operational rulebook made under the PMLA, and the layer a casino applies day to day. It fixes what to report and when (Rule 3 and Rule 8), how to identify customers and beneficial owners (Rule 9), the duty to appoint a Principal Officer and Designated Director (Rule 7), and, in Rule 7(3), the obligation to run a mechanism to detect suspicious transactions.
The PMLR has been amended through 31 Gazette notifications and orders, set out below as a legal-history timeline.
The 31 PMLR amendment notifications, in date order:
| Gazette notification and date | Key change or rule touched |
| G.S.R. 389(E), 24 May 2007 | The first change to the 2005 Rules. It widened the Rule 2 definition of suspicious transaction to reach dealings lacking economic rationale or bona fide purpose and those pointing to terrorism financing, recast Rule 3 to capture cash dealings in forged or counterfeit currency, substituted Rule 8 on how information is furnished to the Director, and cut the Rule 9 requirement from three certified copies to one. |
| G.S.R. 816(E), 12 November 2009 | It introduced the non-profit organisation and Regulator definitions, redrew the meaning of a suspicious transaction, and required reporting of NPO receipts over Rupees 10 lakh. It set ten-year record retention under Rule 6 and remade Rule 9 to require beneficial owner identification, ongoing due diligence, a bar on anonymous accounts and a Client Identification Programme. |
| G.S.R. 76(E), 12 February 2010 | Touched Rules 3, 4, 5, 7 and 9 to refine record-keeping and the reporting references and, most importantly, added the first Explanation in Rule 9(1A), which treats the beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction is done. |
| G.S.R. 508(E), 16 June 2010 | Revised Rules 2, 9 and 10, the provisions on definitions, customer due diligence and record-keeping, adjusting how a reporting entity identifies customers and what it must keep, within the steady 2010 tightening of the CDD and records regime. |
| G.S.R. 980(E), 16 December 2010 | Introduced the small account regime, defining the Designated Officer and the small account, adding the NREGA job card and the Aadhaar letter to the officially valid documents in Rule 2, and inserting Rule 9(2A) on how such an account is opened and monitored. |
| G.S.R. 481(E), 24 June 2011 | Created the short title, amending Rule 1 to shorten the long 2005 name to the Prevention of Money-Laundering (Maintenance of Records) Rules, the PMLR shorthand used ever since. |
| G.S.R. 576(E), 27 August 2013 | Amended Rules 2 and 3 and added provisions after Rule 10, adjusting definitions, the cash and suspicious transaction reporting duties and the record framework so they matched the reporting obligations more closely. |
| G.S.R. 288(E), 15 April 2015 | Amended the Rule 2 definitions; because definitions decide who and what the operative rules reach, the change ran through the framework and began a series of 2015 updates. |
| G.S.R. 544(E), 7 July 2015 | Amended Rules 2, 9, 10 and inserted Rule 9A on definitions, customer due diligence and record-keeping, adjusting how a reporting entity identifies customers and what it keeps, within a substantial 2015 overhaul of the CDD and records provisions. |
| G.S.R. 730(E), 22 September 2015 | Inserted an explanation under Rule 2 stating that marriage certificate can be accepted as a supporting document for a subsequent name change in an officially valid document. |
| G.S.R. 882(E), 18 November 2015 | Revised the timeline under Rule 9A for the establishment of the central KYC records registry from 90 days to 180 days from the commencement of the amendment rules. |
| G.S.R. 347(E), 12 April 2017 | Amended Rule 2 and inserted Rule 9B, drawing the Central KYC Records Registry into the Rules, creating the duty to file customer KYC records centrally and the basis to reuse them, the structural addition behind today’s CKYCR. |
| G.S.R. 538(E), 1 June 2017 | Revised Rules 2 and 9 to bring Aadhaar into customer due diligence, prescribing Aadhaar-based identification and authentication for KYC, an approach the Supreme Court’s Aadhaar ruling later reshaped. |
| G.S.R. 1038(E), 21 August 2017 | Amended the Rule 2 definitions, adjusting the defined terms that govern how the operative rules apply, among several definition changes in 2017. |
| G.S.R. 1318(E), 23 October 2017 | A further 2017 amendment to the Rule 2 definitions, keeping the defined terms current as the framework moved on. |
| G.S.R. 456(E), 16 May 2018 | Inserted a clause under Rule 9 obligating reporting entities to align their customer due diligence programme with their sector-specific guidelines and what must those guidelines cover |
| G.S.R. 1078(E), 31 October 2018 | Revised the timeline under Rule 9 for filing a customer’s electronic CDD records on the registry from 3 days to 10 days. |
| G.S.R. 108(E), 13 February 2019 | Amended Rules 2 and 9 on definitions and customer due diligence, after the legislative changes to Aadhaar use, and adjusted the ways identification could be conducted. |
| G.S.R. 381(E), 28 May 2019 | Amended Rule 9, adjusting the identification and verification process and the routes to confirm a customer’s identity, part of the post-Aadhaar reshaping of CDD. |
| G.S.R. 582(E), 19 August 2019 | Amended Rules 2 and 9 and added provisions after Rule 11, covering definitions, customer due diligence and the supporting provisions on information and records, one of the broader 2019 updates. |
| G.S.R. 669(E), 18 September 2019 | Amended Rules 2 and 9 again, adjusting the definitions and the customer due diligence process within the 2019 series of CDD amendments. |
| G.S.R. 840(E), 13 November 2019 | Changed Rule 9 with additional refinements to the identification and verification requirements, drawing the 2019 series of CDD changes to a close. |
| G.S.R. 228(E), 31 March 2020 | Amended the timeline of small accounts for the year 2020 and any subsequent period as notified by the government. |
| G.S.R. 251(E), 13 April 2020 | Amended Rule 8, governing the submission of transaction reports to FIU-IND by revising the prescribed reporting timeline. |
| G.S.R. 254(E), 16 April 2020 | A follow-up Rule 8 amendment days after the previous one for the extension of the timeline for that specific quarter. |
| G.S.R. 798(E), 28 December 2020 | A landmark in widening the regime, designating real estate agents and dealers in precious metals and stones and, read with G.S.R. 799(E) and 800(E) of the same day, naming their regulator, the point from which the perimeter reached out to a range of non-financial businesses. |
| G.S.R. 575(E), 13 July 2022 | Brought in the International Financial Services Centre definition together with a special beneficial owner provision for IFSC entities and inserted an IFSC proviso into Rule 9A on the CKYCR, aligning the Rules with the GIFT City regime. |
| S.O. 1074(E), 7 March 2023 | A major change that added definitions of politically exposed persons, non-profit organisations and group and a Rule 3A duty for group-wide AML policies and cut the company beneficial ownership threshold from 25 to 10 per cent, with a matching change to Rule 9(3)(e). |
| G.S.R. 652(E), 4 September 2023 | The second major 2023 amendment, which put the Principal Officer at management level, cut the partnership beneficial ownership threshold from 15 to 10 per cent, added an Explanation of control, made trustees disclose their status, and brought the results of any Rule 3 and Rule 9 analysis into the records a reporting entity keeps. |
| G.S.R. 745(E), 17 October 2023 | Amended Rules 2, 3, 8 and 9 in one notification, spanning definitions, the reporting duties and customer due diligence, refining several operative provisions at once to close the 2023 changes. |
| G.S.R. 419(E), 19 July 2024 | Revised Rule 9(1C) on the KYC Identifier and imposed a seven-day window to refresh a CKYCR record after any change, added a duty to pull the refreshed record, and revised Rule 9A(2)(g) on filing, retrieving and using registry records, keeping central KYC data current. |
The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005
A short set of rules on accepting customer records authenticated outside India. For a casino, they apply when a high-value foreign patron, common on offshore casino vessels, is onboarded and the identity documents relied on were executed and certified abroad rather than in India.
CFT Legislation
The Unlawful Activities (Prevention) Act, 1967 (UAPA)
India’s principal counter terrorism statute. Its Section 51A requires a casino to screen patrons and beneficial owners against the designated terrorism lists and to freeze, without delay, the funds and chips of any listed person or entity. This screening obligation binds every casino, whatever the size of the play.
Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023 and 29 August 2023)
The step-by-step procedure a casino follows to give effect to Section 51A when a patron matches a designated list. A casino builds the screening and freezing steps into its floor and cage procedures, so the statutory order becomes a concrete workflow at the point of buy-in and cash-out.
CPF Legislation
The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)
India’s counter-proliferation financing statute. Its Section 12A supplies the legal basis for targeted financial sanctions aimed at the financing of weapons of mass destruction, and it reaches a casino because a cash-intensive floor can be used to place and move value for a sanctioned network.
Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)
The implementation procedure for Section 12A, which mirrors the Section 51A screening and freezing steps but for proliferation financing designations, is applied by a casino alongside its terrorism list screening at the cage.
The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016
The subordinate rules that put the WMD Act into operation and support the designated list handling, freezing and reporting actions a casino must be able to carry out the moment a proliferation financing designation match arises.
Overarching
The shared national instrument that a casino plugs into as a reporting entity.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
The national registry where a casino uploads a patron’s verified KYC record and can retrieve and reuse a record another reporting entity has already filed. Getting beneficial ownership and identity data right when a high-value patron is registered is what makes the registry useful and keeps KYC consistent.
FINnet 2.0 Reporting Formats (2024) and the FINGate 2.0 User Manuals
The FIU-IND reporting platform, its 2024 reporting formats and the FINGate 2.0 user manuals through which a casino enrols and files. Enrolling on the portal as a reporting entity is the practical first step for a licensed casino operating game of chance for money.
Procedure for Aadhaar authentication under Section 11A of the PMLA (9 May 2019)
The procedure by which an entity other than a banking company applies for permission to use Aadhaar authentication services for KYC. It matters to casinos because they are precisely the non-banking reporting entities that must obtain approval before verifying a patron’s identity through Aadhaar.
Sectoral
The sectoral layer is unusual here, because casinos have no single central AML regulator. Supervision runs through the states that license casinos and their guidelines, while online gaming sits under a separate central regime. The map below groups the two lines.
State gaming regulators (Goa, Sikkim and Daman)
Goa Anti-Money Laundering and Financing of Terrorism Guidelines, 2013
The one AML-specific sector guideline in this space, and the most important instrument on this page for a Goa casino. Made by the Government of Goa under the PML Rules, the Guidelines set out the objective of preventing casinos from being used for money laundering or terrorist financing, explain the KYC and customer identification a casino must run, and give worked examples of casino laundering methods, from generating certifiable winnings to buying winnings from legitimate patrons. Casinos in other licensing states apply the PMLA and PMLR framework with any guidance issued by their own state.
State casino licensing and the PMLA framework
Casinos operate under the gaming law and licence conditions of the state that permits them, principally Goa, Sikkim and Daman, and they run the PMLA and PMLR obligations on top of those licence conditions. In the absence of a single central AML rulebook for casinos, the state guidelines and the PMLR are read together.
Online gaming regime (MeitY and the Online Gaming Authority)
The Promotion and Regulation of Online Gaming Act, 2025
A separate central law for online gaming. It promotes and regulates online gaming while prohibiting online money games, online money gaming services, their advertisement and the transfer of funds for them, and it establishes an authority to oversee online gaming, with offences, penalties and the power to block a non-compliant service. It changes the map for online real money gaming and is distinct from the casino framework, so this guide treats it as a governing statute for the sector rather than a casino AML guideline.
Online Gaming Rules, 2026, and the Information Technology Rules, 2021
The subordinate rules under the 2025 Act, together with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which governed online gaming intermediaries before and alongside the new Act. They complete the online gaming regime that sits besides, not within, the casino AML duties.
Miscellaneous
Official reports and guidance that sit outside the binding rulebook but shape how a casino reads its risk and its duties.
FIU-IND Annual Report 2024-25
The national FIU’s annual account of the reports it received, analysed and disseminated, a useful read for a casino on how DNFBP reporting is developing and where FIU-IND is focusing its attention.
Directorate of Enforcement Annual Report 2025-26
The Enforcement Directorate’s annual account of investigations, provisional attachments and prosecutions under the PMLA, which shows how the criminal enforcement end of the framework is used, including matters involving gaming and betting proceeds.
FIU-IND and its Core Functions and FAQs
A plain-language explanation of what FIU-IND does and how reporting works, a practical first primer for a casino starting up its reporting function and enrolling on FINnet 2.0 for the first time.
MHA National Counter Terrorism Policy and Strategy
The Ministry of Home Affairs’ statement of national counter-terrorism policy and strategy, which frames the wider intent behind the CFT duties that Section 51A places on a casino.
International Standards
The global benchmarks India is measured against, and the sources a casino can use to calibrate a risk-based approach to the gaming floor.
FATF Recommendations
The international AML, CFT and CPF standards. Recommendation 22 specifically covers casinos as a designated non-financial business and requires customer due diligence on them above a designated threshold, and Recommendation 6 sets the standard for targeted financial sanctions relating to terrorism and terrorist financing and was updated by FATF in June 2026. India’s direct statutory designation of casinos meets the Recommendation 22 standard.
FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)
The 2024 FATF peer review of India’s system, with a separate executive summary. It examined how DNFBP supervision and reporting work in practice, including casinos among the cash-intensive sectors, and it signals where the regime is expected to tighten next.
Allied Laws
The supporting body of law that defines both the gaming licence framework and the predicate offences and enforcement machinery around money laundering. A casino operates under the gaming statutes, while the predicate and enforcement Acts shape the risk it must assess and the conduct it may need to report.
The gaming statutes that most bear on the sector are the following:
The Public Gambling Act, 1867: The central framework for public gaming and gambling in states that have adopted it. It principally addresses the operation and management of gaming houses and related gambling offences.
The several State gaming and gambling Acts: States regulate gambling and gaming through their own legislation, and the position differs significantly by state. It includes the Goa, Daman and Diu Public Gambling Act, 1976, the Sikkim casino and online gaming Acts, and the gaming Acts of Tamil Nadu, Nagaland, Meghalaya, Andhra Pradesh, Telangana, Kerala, West Bengal, Maharashtra, Rajasthan and Haryana, these laws determine whether particular forms of gambling or gaming are permitted, restricted or prohibited and establish the applicable licensing, regulatory and enforcement framework.
The Promotion and Regulation of Online Gaming Act, 2025, with its Rules, 2026: Establishes the central framework for online gaming. It prohibits online money games and specified activities connected with them, including their offering, advertising and related fund transfers, while creating an authority and enforcement mechanisms for the online gaming sector.
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: Apply to intermediaries and online platforms and impose due diligence and content-related obligations relevant to the hosting, promotion or dissemination of online gaming services and information.
The Companies Act, 2013, the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Foreign Exchange Management Act, 1999, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974, the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.
These laws collectively establish predicate offences, financial and corporate controls, asset forfeiture mechanisms, foreign exchange restrictions, corruption and tax offences, and investigation or enforcement powers that can generate or expose money laundering, terrorist financing or proceeds of crime.
Core AML/CFT/CPF Obligations for Casinos in India
As a reporting entity, a casino must do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each. Correspondent banking and wire-transfer duties are not included here because they do not apply to a casino.
- Register with FIU-IND. Enrol with the Financial Intelligence Unit of India on the FINnet 2.0 / FINGate 2.0 portal, so the casino can file its reports.
- Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR. The same person cannot hold both roles, and both are to be reported to FIU-IND.
- Conduct the internal risk assessment. Assess money laundering, terror financing and proliferation financing risk across patrons, games, delivery channels and geographies, giving weight to the cash-intensive nature of the floor, and keep it current.
- Document AML policy, controls and procedures. Adopt an approved policy that turns the risk assessment into the casino’s floor and cage operating procedures, drawing on any state casino guidelines such as the Goa guidelines.
- Customer identification and CDD. Identify and verify the patron and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals), with enhanced due diligence for politically exposed persons and high-risk patrons, under Section 11A of the PMLA, Rule 9 of the PMLR and the applicable state guidelines, at the buy-in, cash-out and other prescribed points.
- Ongoing monitoring and periodic updates. Monitor patron activity on an ongoing basis, watching for chip buying without play, minimal play cash-outs and structuring, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low-risk patrons respectively. Review each patron’s risk categorisation at least once every six months and decide whether enhanced due diligence is required.
- Sanctions screening. Screen patrons and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act and freeze and report any match. Verify the relevant UNSC and domestic designated lists on a daily basis. This duty applies to every casino.
- Regulatory reporting. File cash transaction reports for cash of more than Rupees 10 lakh and for connected cash transactions crossing that figure in a month, reports on cash transactions involving counterfeit currency, forged valuable security or forged documents, and suspicious transaction reports of any value, including attempted transactions, under Rule 3 and Rule 8 of the PMLR. Cash and counterfeit reports are filed monthly, by the 15th day of the succeeding month; a suspicious transaction report is filed promptly once the Principal Officer is satisfied that the transaction is suspicious, through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction and keep identity records and business correspondence for five years after the business relationship ends, under Section 12 of the PMLA. Upload patron KYC records to the Central KYC Records Registry under Rule 9A, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train floor, cage and surveillance staff by role to apply the controls and recognise the red flags of casino laundering.
- Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
Casinos and online gaming: two regimes
The gaming sector raises two distinct legal frameworks that should not be conflated. Licensed casinos, where permitted under applicable state law, are reporting entities under the PMLA and comply with the applicable AML obligations, including CDD, record-keeping, transaction monitoring and suspicious transaction reporting. Their gaming operations are also subject to the licensing and regulatory requirements of the relevant state.
Online gaming is governed by a separate framework. The Promotion and Regulation of Online Gaming Act 2025 prohibits online money games and related services, advertising and fund transfers connected with such games, and establishes a regulatory authority with enforcement powers, including the power to impose penalties and direct the blocking of prohibited services.
For businesses, the starting point is therefore to determine which legal regime applies to the activity. A licensed casino must comply with its PMLA reporting entity obligations in addition to applicable state gaming requirements. AN online money gaming operation, by contrast, must first be assessed under the prohibition and enforcement framework of the 2025 Act; it should not be treated simply as a licensed PMLA casino reporting entity. Other activities, including games of skill, lotteries and other forms of gaming, can be governed by different state laws depending on their nature and location.
What this article does not cover
This article explains the AML, CFT and CPF laws that apply to casinos as designated businesses. It does not provide a control-by-control compliance manual and does not resolve the licensing or legality of any gaming activity under state or central gaming law. For implementation, a casino separately documents patron acceptance, KYC and CDD procedures at buy-in and cash-out, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction reporting, staff training, audit testing and management reporting. Those controls are the subject of the companion compliance guide.
To see how the casino framework fits within the national picture, see AML laws and regulations in India, and use the parent overview, AML laws and regulations for DNFBPs in India, to see how casinos sit alongside the other designated businesses.
From regulation to compliance: your next step
Understanding the law is only the first step. A casino’s AML, CFT and CPF obligations must be translated into a practical compliance programme covering registration, risk assessment, policies and procedures, patron due diligence, transaction monitoring, sanctions screening reporting, staff training and independent review. Because casinos are cash-intensive, effective controls at buy-in and cash-out are particularly important. Understanding the three stages of money laundering and how the sanctions screening process works is a useful starting point.
Frequently Asked Questions
Yes. Casinos are named in the PMLA itself as a person carrying on activities for playing games of chance for cash or kind, including casino activities, is a person carrying on a designated business or profession under section 2(1)(sa)(i).
Casinos operate in the states that permit them, principally Goa, Sikkim and Daman, including on the offshore vessels that Goa licenses. There is no single central AML regulator for casinos; the licensing state supervises, Reports go to FIU-IND, and the Enforcement Directorate enforces the PMLA.
Cash transaction reports for cash of m Rupees 10 lakh or more, including the linked cash transactions crossing the figure, reports on counterfeit or forged instruments, and suspicious transaction reports of any value, including attempted transactions. Cash and counterfeit reports are filed monthly, by the 15th of the succeeding month; suspicious transaction reports are filed promptly, through FINnet 2.0.
Online gaming sits under a separate regime. The Promotion and Regulation of Online Gaming Act, 2025 promotes and regulates online gaming while prohibiting online money games and services, their advertisement and the transfer of funds for them, and it establishes an authority to oversee the space. This is distinct from the casino reporting entity framework, so an online real-money operation faces the prohibition and enforcement rules of the 2025 Act rather than a licensed reporting entity model.
The PMLA reporting entity duties apply to a licensed casino as a whole, and customer identification is carried out at the buy-in, cash-out and other prescribed points, with the FATF standard setting casino customer due diligence above a designated threshold. Cash transaction reporting is triggered at more than Rupees 10 lakh, while sanctions screening applies to every patron regardless of amount.
Yes. Sanctions obligations under Section 51A of the UAPA and Section 12A of the WMD Act apply to casinos. They are required by the statutes to screen patrons and beneficial owners against applicable UN and domestic designation lists and, where a match is confirmed, freeze the relevant assets and report it to the appropriate authority. These obligations apply regardless of the value of the play or transaction.
Yes. The Financial Action Task Force names casinos as a designated non-financial business in Recommendation 22 and applies customer due diligence to them above a designated threshold. India’s direct statutory designation of casinos under section 2(1)(sa)(i) meets that standard.
Official Sources and Review
Last reviewed: July 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
This guide covers money-laundering law and compliance, a sensitive area where the rules change; confirm the current position for your business with a qualified professional before acting.
Why work with AML India
AML India helps casinos and gaming operators meet their PMLA obligations, from registration and risk assessment to patron due diligence, sanctions screening, floor and cage monitoring, reporting, staff training and independent audit.
Industries we serve: Casinos and the Gaming Sector, Virtual Asset Service Providers, Trust and Company Service Providers, Real Estate Agents, Dealers in Precious Metals and Stones, Chartered Accountants, Company Secretaries and Cost and Management Accountants, and Banks, Financial Institutions and IFSC and GIFT City entities.
Running or licensing a casino?
AML India can help you register with FIU-IND and build a floor-to-cage AML programme aligned to your state’s casino guidelines.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik