Last Updated on: 3rd August 2026 | Last Reviewed on: 3rd August 2026
Key takeaways at a glance
- Who is covered: the five all India financial institutions, Export and Import bank of India (EXIM Bank), National Bank for Agriculture and Rural Development (NABARD), Small Industries Development Bank of India (SIDBI), National Housing Bank (NHB) and National Bank for Financing Infrastructure and Development (NaBFID), are categorized as reporting entities under the PMLA and subject to RBI regulations and supervision.
- Why are they covered: Because they are notified as financial institutions within section 2(1)(l) of the PMLA, and therefore qualify as the reporting entity under section 2(1)(wa). No separate designation is needed.
- Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the RBI (All India Financial Institutions Know Your Customer) Directions, 2025; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
- Supervisor: The Reserve Bank of India (RBI). Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
- Core duties: an internal risk assessment, customer due diligence and KYC, beneficial owner identification, periodic update, ongoing monitoring, prescribed transaction reporting, five year record-keeping and sanctions screening.
This guide is general information on Indian law, not legal advice. For your institution’s specific position, speak to a qualified AML professional.
All India financial institutions, also known as AIFIs, are reporting entities under the Prevention of Money-Laundering Act, 2002. These are the apex development finance institutions established by their own statutes: the Export Import Bank of India (EXIM Bank), the National Bank for Agriculture and Rural Development (NABARD), the Small Industries Development Bank of India (SIDBI), the National Housing Bank (NHB) and the National Bank for Financing Infrastructure and Development (NaBFID). Their AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the RBI All India Financial Institutions KYC Directions, 2025, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework.
The core instruments briefly
| Instrument | What it does for an AIFI |
| PMLA, 2002 | The parent Act. Qualifies AIFIs as reporting entities under financial institutions and creates the core duties of CDD, record-keeping and reporting. |
| PML (Maintenance of Records) Rules, 2005 | Provides for the working of the PMLA. Set out what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. |
| RBI AIFI KYC Directions, 2025 | The AIFI’s working rulebook, issued by the RBI on 28 November 2025 and updated as on 29 December 2025. |
| RBI Internal Risk Assessment Guidance (2024) | Requires the institution to run an ML and TF risk assessment whose outcome goes to the board. |
| UAPA Section 51A and WMD Act Section 12A | Impose targeted financial sanctions for terrorism and proliferation financing. |
| FATF Recommendations | The international preventive measure standards for financial institutions that India’s framework is built to meet. |
What counts as an All India Financial Institution in India?
All India Financial Institution is a specified apex level development finance institution regulated and supervised by the Reserve Bank of India (RBI). India currently has five AIFIs;
- the Export Import Bank of India, which finances and promotes India’s foreign trade;
- the National Bank for Agriculture and Rural Development, which finances agriculture and rural development;
- the Small Industries Development Bank of India, which finances the micro, small and medium enterprise sector;
- the National Housing Bank, which finances and supervises housing finance;
- the National Bank for Financing Infrastructure and Development, which finances infrastructure.
- Each is established by its own Act of Parliament and operates primarily as a wholesale developmental financial institution rather than a retail bank.
Because AIFIs mainly deal with institutions, intermediaries and corporates, their money laundering risks are concentrated in identifying corporate and institutional customers, beneficial owners, control structure, and verifying the source of large funds. Accordingly, they are subject to the full AML, CFT and CPF framework, through a risk based approach appropriate to their wholesale development finance activities.
Are all India financial institutions reporting entities under the PMLA?
Yes. AIFIs are designated as reporting entities under the Prevention of Money-Laundering Act, 2002; section 2(1)(wa) because it is categorised as a financial institution within section 2(1)(l), which takes its meaning from section 45-I of the Reserve Bank of India Act, 1934.
This places an AIFI in the same broad category of reporting entities that file with FIU-IND as banks and other financial institutions, and within the wider AML laws and regulations for financial institutions in India. The obligations are calibrated to the institution’s size and risk, but the status is not optional.
Supervisory authority for all India financial institutions in India
The supervisor for all India financial institutions is the Reserve Bank of India. The RBI issues the KYC and AML directions that govern AIFIs and supervises their compliance through inspection and regulatory oversight. On 28 November 2025, the RBI issued sector specific KYC Directions for AIFIs (All India Financial Institutions Know Your Customer) Directions, 2025, updated as of 29 December 2025, which acts as the principal rulebook for AIFIs. The RBI Internal Risk Assessment Guidance of 2024 sits alongside them as the RBI expectations for a documented, risk based approach.
The Financial Intelligence Unit – India receives, analyses, and disseminates the reports in an AIFI file, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. In short, the RBI sets and supervises the rules, FIU-IND receives the intelligence, and the ED enforces the criminal law.
Onboarding clients without a documented due-diligence process?
AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.
AML Regulatory Requirements for All India Financial Institutions in India
The AML, CFT and CPF framework for All India financial institutions is a layered one, consisting of legislation, rules, regulatory directions and guidance rather than a single law. It is best understood through its core legislation, overarching obligations, sectoral supervisor and its directions, miscellaneous official reports, t international standards, and allied laws.
The framework begins with the PMLA, supported by the PML Rules, which are implemented through the RBI issued guidelines specifically for AIFIs. The UAPA and the WMD Act add targeted financial sanctions obligations, while allied laws, including each AIFI’s establishing statute, shape its money laundering risk. The risk based approach underpins the entire framework.
Core Legislation
The primary statutes and rules that create the AML, CFT and CPF obligations are grouped into three categories.
AML Legislation
Prevention of Money-Laundering Act, 2002 (PMLA)
India’s parent AML statute and the source of an AIFI’s reporting entity status. It defines the offence of money laundering and imposes the duties of identifying and verifying customers under Section 11A and maintaining records under Section 12 that a development finance institution must run across its lending and treasury business. For AIFIs, the focus is on the integrity of institutional customers, beneficial ownership, and the source and intended use of large value funds.
The PML (Maintenance of Records) Rules, 2005 (PMLR)
The rules made under the PMLA, and the layer an AIFI applies day to day. They set reporting requirements and timeframes (Rule 3 and Rule 8), identification of customers and verification of beneficial owners (Rule 9), and the requirement of appointing a Principal Officer and Designated Director (Rule 7).
The PMLR has been amended through 31 Gazette notifications and orders, set out below in chronological order.
| Gazette notification and date | Key change or rule touched |
| G.S.R. 389(E), 24 May 2007 | The first amendment to the 2005 rules. It expanded the Rule 2 meaning of a suspicious transaction to include dealings without economic rationale or bona fide purpose and those pointing to terrorism financing, revised Rule 3 around cash dealings in forged or counterfeit currency, substituted Rule 8 on furnishing information to the Director, and simplified Rule 9 requirement from three certified copies to one for customer identification. |
| G.S.R. 816(E), 12 November 2009 | It added the non profit organisation and Regulator definitions, revised the suspicious transaction definition, and required NPO receipts over Rupees 10 lakh to be reported. It set the record retention period to 10 years under Rule 6 and revised Rule 9 to require beneficial owner identification, ongoing due diligence, a bar on anonymous accounts and a Client Identification Programme. |
| G.S.R. 76(E), 12 February 2010 | Amended Rules 3, 4, 5, 7 and 9. sharpened the record keeping and the reporting references and, added the first Explanation in Rule 9(1A) defining the beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction is conducted. |
| G.S.R. 508(E), 16 June 2010 | Revised Rules 2, 9 and 10, the provisions on definitions, customer due diligence and record keeping, changing how a reporting entity identifies customers and what it must retain, within the 2010 tightening of the CDD and records regime. |
| G.S.R. 980(E), 16 December 2010 | Established the small account regime, defining the Designated Officer and the small account, adding the NREGA job card and the Aadhaar letter to the officially valid documents under Rule 2, and inserted Rule 9(2A) on how such an account is opened and monitored. |
| G.S.R. 481(E), 24 June 2011 | Amended Rule 1 to shorten the rules long 2005 name to the Prevention of Money Laundering (Maintenance of Records) Rules, the PMLR shorthand in use since. |
| G.S.R. 576(E), 27 August 2013 | Revised Rules 2 and 3 and inserted provisions after Rule 10, touching definitions, the cash and suspicious transaction reporting duties and the record framework so they matched the reporting obligations. |
| G.S.R. 288(E), 15 April 2015 | Amended the Rule 2 definitions; since definitions set who and what the operative rules cover. |
| G.S.R. 544(E), 7 July 2015 | Revised Rules 2, 9, 10 and Inserted Rule 9A on definitions, customer due diligence and record registry, refining how a reporting entity identifies customers and what it retains. |
| G.S.R. 730(E), 22 September 2015 | Added an explanation under Rule 2, specifying that a marriage certificate is an acceptable supporting document for a subsequent name change in an officially valid document. |
| G.S.R. 882(E), 18 November 2015 | Extended the timeline under Rule 9A for the central government to establish the central KYC records registry from 90 days to 180 days from the commencement of the PML Rules. |
| G.S.R. 347(E), 12 April 2017 | Revised Rule 2 and inserted Rule 9B, bringing the Central KYC Records Registry into the Rules, creating the duty to file customer KYC records centrally and the basis to reuse them, the structural addition behind today’s CKYCR. |
| G.S.R. 538(E), 1 June 2017 | Amended Rules 2 and 9 to integrate Aadhaar into customer due diligence, prescribing Aadhaar based identification and authentication for KYC, an approach the Supreme Court’s Aadhaar ruling later reshaped. |
| G.S.R. 1038(E), 21 August 2017 | Revised certain definitions under Rule 2 that govern how the operative rules apply, among several definition changes in 2017. |
| G.S.R. 1318(E), 23 October 2017 | A subsequent 2017 amendment revised the Rule 2 definitions relating to the acceptance of officially valid documents for foreign nationals. |
| G.S.R. 456(E), 16 May 2018 | Inserted a clause in Rule 9 requiring reporting entities to formulate their customer due diligence programme in accordance with applicable sector specific guidelines and what the guidelines should provide for reporting entities. |
| G.S.R. 1078(E), 31 October 2018 | Revised Rule 9 by extending the timeline for filing electronic records of a customer’s CDD from 3 days to 10 days. |
| G.S.R. 108(E), 13 February 2019 | Amended Rules 2 and 9 on definitions and customer due diligence, following legislative changes to the use of Aadhaar, updating the permitted methods of customer identification. |
| G.S.R. 381(E), 28 May 2019 | Revised Rule 9, sharpening the identification and verification process and the routes to confirm a customer’s identity, part of the post Aadhaar reshaping of CDD. |
| G.S.R. 582(E), 19 August 2019 | Amended Rules 2 and 9 and inserted provisions after Rule 11, covering definitions, customer due diligence and the supporting provisions on information and records maintenance one of the broader 2019 updates. |
| G.S.R. 669(E), 18 September 2019 | Further amended Rules 2 and 9 to update the definitions and strengthen the customer due diligence framework for depository receipts. |
| G.S.R. 840(E), 13 November 2019 | Amended Rule 9 by making further revisions to the customer identification and verification requirements, concluding the 2019 series of CDD amendments. |
| G.S.R. 228(E), 31 March 2020 | Extended the operational timeline for small accounts to cover the year 2020 and any subsequent period as notified by the central government. |
| G.S.R. 251(E), 13 April 2020 | Revised Rule 8, which governs the furnishing of transaction reports to FIU IND, by changing the timeline for report submission |
| G.S.R. 254(E), 16 April 2020 | A subsequent amendment to Rule 8, made days after the previous one, revised the transaction reporting timeline for a single quarter. |
| G.S.R. 798(E), 28 December 2020 | A landmark that carried the regime beyond the financial sector. Read with G.S.R. 799(E) and 800(E) of the same day, it designated real estate agents and dealers in precious metals and stones and named their regulator, extending the perimeter to non financial businesses. |
| G.S.R. 575(E), 13 July 2022 | Inserted the International Financial Services Centre definition with a tailored beneficial owner provision for IFSC entities and added an IFSC proviso to Rule 9A on the CKYCR, aligning the Rules with the GIFT City regime, of note to an AIFI operating in an IFSC. |
| S.O. 1074(E), 7 March 2023 | A major amendment that inserted definitions of politically exposed persons, group and non profit organisations provided a duty for group wide AML policies under Rule 3A and cut the company beneficial ownership threshold from 25 to 10 per cent, with a matching change to Rule 9(3)(e), directly relevant to an institution assessing corporate borrowers. |
| G.S.R. 652(E), 4 September 2023 | The second major 2023 amendment. It mandated the Principal Officer to be at the management level, lowered the partnership beneficial ownership threshold from 15 to 10 per cent, inserted an Explanation of control, made trustees disclose their status, and brought the results of any Rule 3 and Rule 9 analysis into the records a reporting entity keeps. |
| G.S.R. 745(E), 17 October 2023 | Amended Rules 2, 3, 8 and 9 in one notification, making coordinated changes to definitions, reporting obligations and customer due diligence requirements, completing the 2023 amendments. |
| G.S.R. 419(E), 19 July 2024 | Revised Rule 9(1C) on the KYC Identifier and set a seven day deadline to update a CKYCR record after any change, added a duty to fetch the updated record, and reworked Rule 9A(2)(g) on filing, retrieving and using registry records, sharpening how current central KYC data is kept. |
The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005
Rules for accepting customer records authenticated outside India, relevant to an AIFI such as EXIM Bank that deals with overseas counterparties and must rely on identity and ownership documents executed and certified abroad.
CFT Legislation
The Unlawful Activities (Prevention) Act, 1967 (UAPA)
India’s counter terrorism statute. Section 51A of the Act requires an AIFI to screen customers and beneficial owners against the designated lists and to freeze, without delay, the funds and assets of listed persons and entities, whatever the size of the exposure.
Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023 and 29 August 2023)
The procedure an AIFI must follow to implement Section 51A obligations. The RBI Directions fold the screening and freezing steps into the institution’s controls, turning the statutory order into a workable process.
CPF Legislation
The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)
India’s counter proliferation financing statute. Section 12A of the Act provides the legal basis for targeted financial sanctions relating to the financing of weapons of mass destruction, and reaches an AIFI, particularly one financing trade or infrastructure with a cross border dimension.
Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)
The procedure applicable to all the reporting entities, including AIFIs, for implementing Section 12A sanctions screening and freezing steps, without delay on finding a match in the designated list.
The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016
The implementing rules under the WMD Act that give effect to targeted financial sanctions relating to proliferation financing. They support the controls that AIFIs must adopt and operate under.
Not registered with FIU-IND yet, or unsure whether you have to be?
AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.
Overarching
The shared national instruments that an AIFI plugs into as a reporting entity.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
The operating guidelines for the Central KYC Records Registry, setting out the roles and responsibilities of the registry and reporting entities. The CKYCR centrally stores customer KYC records, allowing AIFIs to upload customer information and retrieve existing records where available. This helps maintain consistent KYC information, reduces duplication and supports efficient customer onboarding by providing beneficial ownership and identification data.
FINnet 2.0 reporting formats (2024) and the FINGate 2.0 user manuals
The FIU-IND manuals for its reporting platform, covering enrolment, request response function and report submission. They explain how an AIFI enrols and submits the prescribed reports under the PMLA and PML rules.
Section 11A Aadhaar Authentication Procedure for Reporting Entities (9 May 2019)
The procedure that enables reporting entities, other than banking companies, to apply for permission to use Aadhaar authentication services. As AIFIs are categorised as financial institutions under PMLA, this framework is relevant where an AIFI verifies an individual’s identity using Aadhaar.
Sectoral
The supervisory authority for AIFIs is the Reserve Bank of India (RBI). The RBI issues guidelines, notifications and press release that help AIFIs interpret and implement their regulatory obligations on a daily basis.
Reserve Bank of India
The RBI (All India Financial Institutions Know Your Customer) Directions, 2025
AIFI’s primary working rulebook. Issued by the RBI on 28 November 2025 and updated as of 29 December 2025, the Directions apply to EXIM Bank, NABARD, SIDBI, NHB and NaBFID, their branches and majority owned subsidiaries. It sets out customer identification and due diligence, beneficial owner identification, the ML and TF risk assessment, the appointment of a Designated Director and Principal Officer, prescribed report submission, record management and the implementation of Sections 51A of the UAPA and 12A of the WMD Act. Where law creates a duty, these Directions explain how an AIFI must comply with it.
RBI Consolidated Master Directions and the KYC compliance notification (28 November 2025)
On 28 November 2025, the RBI consolidated its KYC framework by issuing a notification and 11 sector specific KYC Directions, including (All India Financial Institutions Know Your Customer) Directions 2025. These directions replaced the earlier KYC directions for AIFIs to the extent specified.
RBI Internal Risk Assessment (IRA) Guidance for ML and TF Risks (2024)
The RBI guidance that describes the internal risk assessment as the foundation of the risk based approach. It requires every reporting entity to document its assessment of ML and TF risks, keep it up to date and submit the results to the board for approval and oversight.
Miscellaneous
Official reports and guidance that sit outside the binding rulebook but shape risks and duties of AIFIs.
FIU IND Annual Report 2024 to 2025
The unit’s annual account of the reports it received, analysed and disseminated during the year. It proves a useful read for reporting entities including AIFIs as it provides insights on reporting volumes and supervisory authority priorities across reporting entity categories.
Directorate of Enforcement Annual Report 2025 to 2026
The Enforcement Directorate’s annual report of investigations, provisional attachments and prosecutions under the PMLA, useful for reporting entities to understand how the enforcement framework is applied in practice and the typologies of money laundering.
FIU-IND and its Core Functions and FAQs
A question and answer explanation of functions, duties and compliance principles for FIU-IND and how reporting actually works, a useful read for an institution’s reporting function.
MHA National Counter Terrorism Policy and Strategy
The Ministry of Home Affairs statement of national counter terrorism policy, which frames the CFT duties that Section 51A of the WMD Act places on an AIFI.
International Standards
The global benchmarks India is measured against, and the sources an AIFI can use to calibrate a risk based approach.
FATF Recommendations
The international AML, CFT and CPF standards, on which India’s framework is based. For AIFIs, the most relevant are Recommendations 9 to 23, which set preventive measures for financial institutions, and Recommendation 6 on targeted financial sanctions. The recommendations were last updated by FATF in June 2026.
FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)
The assessment report of India’s AML and CFT system by the FATF. They examined the practical implementation of the financial sector’s preventive measures and supervision and highlighted the drawbacks to be worked upon.
Basel Committee, Sound Management of Risks Related to Money Laundering and Financing of Terrorism (2014, revised July 2020)
The Basel Committee guidance on managing ML and TF risk, a benchmark for the risk based approach and group wide controls that an AIFI can read across to its own risk management.
FATF Risk Based Approach Guidance for the Banking Sector (2014)
FATF sector guidance on applying the risk based approach in banking and financial institutions, useful to an AIFI in shaping its customer due diligence and monitoring.
Allied Laws
The wider body of law that defines each institution’s own mandate, the offences and enforcement machinery around money laundering. AIFIs operate under their establishing statute, while the predicate and enforcement Acts shape the risk it must assess and the conduct it may need to report.
The allied laws that most often affect an AIFI’s AML, CFT and CPF risk are the following:
The Reserve Bank of India Act, 1934, which provides the statutory framework for RBI supervision of AIFIs, together with each institution’s establishing statute, the Export Import Bank of India Act, 1981, the National Bank for Agriculture and Rural Development Act, 1981, the Small Industries Development Bank of India Act, 1989, the National Housing Bank Act, 1987 and the National Bank for Financing Infrastructure and Development Act, 2021.
AIFIs must also consider other laws that give rise to the predicate offence and influence money laundering risk, including the Companies Act, 2013, the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Foreign Exchange Management Act, 1999, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974 (COFEPOSA), the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976(SAFEMA), the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.
Core AML/CFT/CPF Obligations for All India Financial Institutions in India
Across that framework, the regulations require AIFIs to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.
- Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the institution can file its reports.
- Appoint officers. Appoint a Designated Director and a management level Principal Officer under Rule 7 of the PMLR and the RBI Directions. The same person cannot hold both roles, and both are to be informed to FIU-IND and the RBI.
- Conduct the internal risk assessment. Run an ML and TF risk assessment across customers, products, channels and geographies, document it, and take its outcome to the board, as the RBI Directions and the IRA Guidance require.
- Document AML policy, controls and procedures. Adopt a senior management approved policy that turns the risk assessment into the institution’s operating procedures.
- Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the RBI AIFI KYC Directions 2025. Given the wholesale customer base, the identification of institutional and corporate customers and their beneficial owners is central.
- Ongoing monitoring and periodic updates. Monitor transactions on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low risk customers respectively. Review each customer’s risk categorisation at least once every six months.
- Sanctions screening. Screen customers and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
- Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit currency reports and, for an institution with cross border activity such as EXIM Bank, cross border wire transfer reports of Rupees 5 lakh or more, under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly, through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train staff by role to apply the controls and recognise red flags in wholesale and development finance.
- Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
- Run group wide controls. Where the institution has subsidiaries, apply AML and CFT programmes at group level, including for branches and majority owned subsidiaries, as the RBI Directions require.
What this article does not cover
This article explains the legal and regulatory AML, CFT and CPF framework that applies to all India financial institutions. It is not a procedural compliance manual and does not provide implementation guidelines, except where they bear on the AML duties. Practical topics such as KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction reporting, staff training, audit testing and board reporting are covered in the companion compliance guide.
To see how the AIFI framework fits within the sector, see AML laws and regulations for financial institutions in India, and to place it within the national picture, see AML laws and regulations in India.
From regulation to compliance: your next step
Understanding the legal framework alone is not enough. Effective compliance comes from embedding those obligations into day to day operations through a risk based working programme. For AIFIs, this means applying robust customer due diligence, transaction monitoring, sanctions screening, report filing, staff training and independent audit. As development finance institutions, AIFIs should place particular emphasis on identifying institutional customers and their beneficial owners and understanding the source and end use of large funds. A good next step is to understand the stages of money laundering and how the sanctions screening process works.
Want to confirm the 2025 directions for your institution?
AML India can walk you through the RBI AIFI KYC Directions and build a proportionate programme for a development finance institution.
Frequently Asked Questions
The five apex development finance institutions that the RBI regulates as AIFIs are the Export Import Bank of India, the National Bank for Agriculture and Rural Development, the Small Industries Development Bank of India, the National Housing Bank, and the National Bank for Financing Infrastructure and Development. Each is established by its own Act of Parliament and operates as a wholesale, developmental lender.
Yes. AIFIs are reporting entities under section 2(1)(wa) of the PMLA because it is a financial institution within section 2(1)(l), which takes its meaning from section 45-I of the RBI Act, 1934.
The Reserve Bank of India (All India Financial Institutions Know Your Customer) Directions, 2025, issued on 28 November 2025 and updated as of 29 December 2025. They apply to EXIM Bank, NABARD, SIDBI, NHB and NaBFID and their branches and majority owned subsidiaries and are read along with the RBI Internal Risk Assessment Guidance of 2024.
Yes, although AIFIs deal with institutional and corporate customers, they must carry out standard KYC and CDD whenever they deal with individuals or other retail customers. The same AML requirements apply, with the due diligence tailored to the customer and the level of risk.
Cash transaction reports for cash movement of Rupees 10 lakh or more, suspicious transaction reports of any value, counterfeit currency reports and, for an institution with cross border activity such as EXIM Bank, cross border wire transfer reports of Rupees 5 lakh or more. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly, through FINnet 2.0.
Yes. The sanctions screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every AIFI, irrespective of the exposure size. An AIFI must screen customers and beneficial owners against the United Nations and domestic designated lists and, upon identification of a match, immediately freeze assets and file the prescribed report.
Official sources and review
Last reviewed: July 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
- Prevention of Money-Laundering Act, 2002 (India Code)
- Prevention of Money-Laundering (Maintenance of Records) Rules, 2005
- RBI (All India Financial Institutions – Know Your Customer) Directions, 2025 (Reserve Bank of India)
- RBI Internal Risk Assessment Guidance for ML/TF Risks, 2024 (Reserve Bank of India)
- Unlawful Activities (Prevention) Act, 1967 and Section 51A procedure
- WMD Act, 2005 and its Section 12A implementation procedure (India Code)
- FATF Recommendations, including the June 2026 update to Recommendation 6
- FATF Mutual Evaluation Report on India, 2024
- Basel Committee, Sound Management of Risks Related to ML and TF (2014, revised July 2020)
- Financial Intelligence Unit – India, including the Annual Report 2024-25
- Central KYC Records Registry (CKYCR) Operating Guidelines, 2025 (CERSAI)
- Enforcement Directorate Annual Report 2025 to 2026
Why work with AML India
AML India helps all India financial institutions meet their PMLA and RBI obligations, from risk assessment and internal policy and procedure to CDD, sanctions screening, ongoing monitoring, prescribed report filing, staff training and independent audit.
Industries we serve: All India Financial Institutions, NBFCs, Housing Finance, Mortgage Guarantee and Asset Reconstruction Companies, Insurers, Payment System Operators and Aggregators, Banks, DNFBPs, Securities Intermediaries and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik