Last Updated on: 31st August 2026 | Last Reviewed on: 31st August 2026
Key Takeaways at a Glance
- Who is covered: credit rating agencies registered with SEBI under the SEBI (Credit Rating Agencies) Regulations, 1999, as reporting entities under the PMLA.
- Why they are caught: a credit rating agency is an intermediary registered under section 12 of the SEBI Act and so falls within section 2(1)(n) of the PMLA, making it a reporting entity under section 2(1)(wa). No section 2(1)(sa) designation is needed.
- Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the SEBI AML/CFT Guidelines, 2024 and the SEBI KYC Master Circular; the SEBI (Credit Rating Agencies) Regulations, 1999; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
- Supervisor: the Securities and Exchange Board of India (SEBI). Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
- Core duties: an internal risk assessment, client due diligence and KYC, beneficial owner identification, monitoring, prescribed transaction reporting, five year record-keeping and sanctions screening.
This guide is general information on Indian law, not legal advice. For your firm’s specific position, speak to a qualified AML professional.
Credit rating agencies registered with the Securities and Exchange Board of India (SEBI) are subject to the applicable AML, CFT and CPF requirements under India’s legal and regulatory framework.
Their obligations may arise under the Prevention of Money-Laundering Act, 2002, the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, applicable SEBI AML/CFT and KYC requirements, Section 51A of the Unlawful Activities (Prevention) Act, 1967, Section 12A of the Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005, and the applicable FIU-IND reporting framework.
SEBI is the sectoral regulator for credit rating agencies, while FIU-IND administers the reporting framework applicable to reporting entities. This guide forms part of the wider series of AML/CFT/CPF guides covering securities market intermediaries in India.
The core instruments at a glance
|
Instrument |
What It Does for a Credit Rating Agency |
|
PMLA, 2002 |
The parent Act. Brings the credit rating agency in as an intermediary and creates the duties of client due diligence, record-keeping and reporting. |
|
PML (Maintenance of Records) Rules, 2005 |
Set out what to report and when, how to identify clients and beneficial owners, and the duty to appoint officers. |
|
SEBI AML/CFT Guidelines (6 June 2024) |
The working AML rulebook for every securities market intermediary, including credit rating agencies, and the primary AML source in the absence of a rating specific circular. |
|
SEBI KYC Master Circular (12 October 2023) |
Sets how a credit rating agency identifies and verifies its clients and maintains their records. |
|
UAPA Section 51A and WMD Act Section 12A |
Impose targeted financial sanctions for terrorism and proliferation financing. |
|
FATF Recommendations |
The international preventive measure standards India’s framework is built to meet. |
What Counts as a Credit Rating Agency in India?
A credit rating agency is a body corporate registered with SEBI under Section 12 of the SEBI Act, 1992 and the SEBI (Credit Rating Agencies) Regulations, 1999, and engaged in the business of rating securities and assessing the creditworthiness of issuers and their financial obligations. SEBI maintains a register of entities registered as credit rating agencies under this framework.
Credit rating agencies generally provide ratings in relation to securities and issuers rather than holding or transferring client funds or securities. Their AML risk profile therefore differs from that of intermediaries whose activities involve custody or movement of client assets. Relevant risks may arise from the identity and ownership of issuers and other customers, the transparency of their ownership and control structures, the source and nature of fees received, and the potential use of rating services to lend credibility to entities or arrangements presenting elevated ML or TF risks.
The AML framework therefore requires a risk based approach to understanding customers and their business activities, identifying and verifying beneficial ownership where applicable, assessing the purpose and nature of the relationship, monitoring relevant activity and applying enhanced due diligence where higher risks are identified.
Are Credit Rating Agencies Reporting Entities under the PMLA?
Yes. The Prevention of Money-Laundering Act, 2002 establishes the statutory framework for preventing money laundering and imposes specified obligations on reporting entities.
Section 2(1)(wa) of the PMLA defines a reporting entity to include an intermediary. Section 2(1)(n) defines an intermediary to include an intermediary associated with the securities market and registered under Section 12 of the SEBI Act, 1992. FIU IND material expressly identifies credit rating agencies among the intermediaries registered under Section 12 of the SEBI Act.
Accordingly, a credit rating agency registered with SEBI falls within the reporting entity framework through the intermediary limb of Section 2(1)(wa), read with Section 2(1)(n). No separate designation under Section 2(1)(sa) is required where the CRA is already covered through this intermediary category.
This places a credit rating agency within the wider framework of reporting entities that file with FIU-IND and the broader AML laws and regulations for intermediaries in India. However, reporting entity status does not mean that all reporting entities have identical AML obligations. The specific controls and reporting requirements applicable to a CRA must be read with the PMLA, the PML Rules and the applicable SEBI AML/CFT and KYC framework.
Supervisory Authority for Credit Rating Agencies in India
The Securities and Exchange Board of India is the sectoral regulator for credit rating agencies and regulates their activities under the SEBI (Credit Rating Agencies) Regulations, 1999. SEBI also issues AML/CFT requirements applicable to securities market intermediaries. Its Master Circular on AML Standards and CFT Obligations of Securities Market Intermediaries, issued on 6 June 2024, sets out the applicable AML/CFT framework under the PMLA and the Rules made under it.
These requirements operate alongside the SEBI regulatory framework applicable specifically to credit rating agencies, including the SEBI (Credit Rating Agencies) Regulations, 1999 and the dedicated Master Circular for Credit Rating Agencies.
The Financial Intelligence Unit – India receives, processes, analyses and disseminates financial intelligence and receives reports submitted by reporting entities under the PMLA framework. FIU-IND’s reporting framework covers intermediaries subject to the PMLA.
The Enforcement Directorate is the principal agency responsible for investigating money laundering offences under the PMLA and exercising the enforcement powers provided under the Act.
AML Regulatory Requirements for Credit Rating Agencies in India
The law that governs a credit rating agency does not sit in one place. It is a layered framework, and it helps to see it grouped as the official source set groups it: the core legislation, the overarching obligations, the sectoral regulator and its instruments, the miscellaneous official reports, the international standards, and the allied laws.
The framework reads from the core outward. The PMLA is the parent Act; the PML Rules turn it into operational duties; the SEBI Master Circular for Credit Rating Agencies and the SEBI AML/CFT Guidelines translate both into instructions a credit rating agency can follow; the UAPA and the WMD Act add counter terrorism and proliferation financing sanctions; and the allied laws, including the securities statutes, shape the risk. The risk based approach is the thread that runs through it all.
Core Legislation
The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into three sub sets.
AML Legislation
Prevention of Money-Laundering Act, 2002 (PMLA)
The parent anti money laundering law. It creates the offence of money laundering and the core duties on reporting entities, including client due diligence under Section 11A and record-keeping under Section 12. A credit rating agency is a reporting entity by virtue of the intermediary definition in section 2(1)(n), so the Act applies to a rating firm in the same shape as to a bank, scaled to the business.
The PML (Maintenance of Records) Rules, 2005 (PMLR)
The rules made under the PMLA. They set what to report and when (Rule 3 and Rule 8), how to identify clients and beneficial owners (Rule 9), and the duty to appoint officers (Rule 7). For a credit rating agency, the relevant Regulator named in Rule 2(1)(fa) is SEBI. The PMLR has been amended through 31 Gazette notifications and orders, set out below.
The 31 PMLR amendment notifications, in date order:
|
Gazette notification and date |
Key change or rule touched |
|
G.S.R. 389(E), 24 May 2007 |
Broadened the definition of a suspicious transaction under the PML Rules, 2005 to include transactions that lacked an apparent economic rationale or were associated with terrorist financing. The amendment also expanded reportable cash transactions to cover forged currency and documents, prescribed reporting timelines for submissions to the Director, and reduced the number of certified copies required for certain filings from three to one. |
|
G.S.R. 816(E), 12 November 2009 |
Introduced the definitions of non profit organisation and Regulator and further expanded the scope of suspicious transactions to include transactions involving unusual complexity, no apparent economic rationale, or links to terrorist financing. The amendment also introduced reporting requirements for cash receipts exceeding ten lakh rupees by NGOs, replaced references to specific regulators such as RBI, SEBI and IRDA with the broader term Regulator, and increased the record retention period to ten years from the date of the transaction. |
|
G.S.R. 76(E), 12 February 2010 |
Strengthened the record keeping and reporting framework under Rules 3, 4, 5 and 7 of the PML Rules, 2005. It also inserted an Explanation to Rule 9(1A), clarifying that the beneficial owner is the natural person who ultimately owns or controls the client or on whose behalf a transaction is conducted. |
|
G.S.R. 508(E), 16 June 2010 |
Amended Rules 2, 9 and 10 of the PML Rules, 2005 to strengthen requirements relating to definitions, customer due diligence and record keeping. The amendments enhanced customer identification procedures and reinforced obligations on reporting entities to maintain and preserve relevant records. |
|
G.S.R. 980(E), 16 December 2010 |
Introduced the framework for small accounts by defining Designated Officer and small account. The amendment expanded the list of officially valid documents to include the NREGA job card and Aadhaar letter and introduced Rule 9(2A), which prescribed conditions for opening, operating and monitoring small accounts. |
|
G.S.R. 481(E), 24 June 2011 |
Revised Rule 1 to change the short title of the legislation to the Prevention of Money Laundering Maintenance of Records Rules, 2005. This provided the abbreviated title subsequently used for references to the Rules. |
|
G.S.R. 576(E), 27 August 2013 |
Added the definition of Designated Director under Rule 2 and amended Rules 3, 7, 8, 9 and 10. The amendments strengthened the framework for reporting, compliance governance, customer due diligence and maintenance of records by reporting entities. |
|
G.S.R. 288(E), 15 April 2015 |
Identified the documents recognised as officially valid documents for customer identification purposes under the PML Rules, 2005. |
|
G.S.R. 544(E), 7 July 2015 |
Introduced the definition of Central KYC Records Registry and amended Rules 9 and 10 of the PML Rules, 2005 to strengthen the KYC framework. The amendments also facilitated the centralised collection, storage and management of KYC records maintained by reporting entities. |
|
G.S.R. 730(E), 22 September 2015 |
Updated various definitions under Rule 2 and made corresponding changes to the PML Rules, 2005 to reflect evolving KYC requirements. The amendments provided greater clarity on key regulatory terms and strengthened requirements relating to customer identification and due diligence. |
|
G.S.R. 882(E), 18 November 2015 |
Extended the prescribed period under the relevant provisions of the PML Rules, 2005 from 90 days to 180 days. This gave reporting entities additional time to meet the applicable procedural and reporting requirements. |
|
G.S.R. 347(E), 12 April 2017 |
Added provisions relating to the definition of Regulator and introduced Rule 9B to strengthen the customer due diligence framework under the PML Rules, 2005. The amendment also enhanced requirements concerning customer identification and verification. |
|
G.S.R. 538(E), 1 June 2017 |
Modified Rules 2 and 9 of the PML Rules, 2005 by adding provisions aimed at strengthening the operational AML framework. The changes further developed requirements relating to customer identification, due diligence and compliance processes applicable to reporting entities. |
|
G.S.R. 1038(E), 21 August 2017 |
Refined the definitions under Rule 2 of the PML Rules, 2005 by adding provisions to provide greater clarity on key terms used in the regulatory framework. The amendments supported more consistent interpretation and implementation of AML and KYC requirements. |
|
G.S.R. 1318(E), 23 October 2017 |
Clarified Rule 2 by adding a proviso concerning the acceptance and treatment of officially valid documents. The amendment provided greater clarity on the use of such documents for customer identification and verification under the PML Rules, 2005. |
|
G.S.R. 456(E), 16 May 2018 |
Reinforced Rule 9 by requiring reporting entities to establish and implement a formal customer due diligence programme. The amendment strengthened the need for appropriate procedures to identify and verify customers as part of the AML framework. |
|
G.S.R. 1078(E), 31 October 2018 |
Extended the period prescribed under Rule 9(1A) from three days to ten days. This provided reporting entities with additional time to complete the required customer due diligence procedures. |
|
G.S.R. 108(E), 13 February 2019 |
Strengthened Rule 9 through amendments aimed at enhancing the customer due diligence framework. The changes introduced additional requirements for customer identification and verification and further developed the regulatory framework for subsequent AML reforms. |
|
G.S.R. 381(E), 28 May 2019 |
Provided a specific customer due diligence framework for prisoners opening or maintaining bank accounts. The amendment allowed the officer in charge of the jail to certify the customers signature or thumb impression and permitted such accounts to remain operational subject to annual submission of a proof of address certificate issued by the same authority. |
|
G.S.R. 582(E), 19 August 2019 |
Introduced digital KYC, equivalent electronic documents and offline Aadhaar verification into the PML Rules, 2005. The amendment revised Rule 9 to recognise multiple modes of customer identification and introduced a detailed digital KYC process involving live photographs, geotagging, OTP based authentication and prescribed verification procedures. |
|
G.S.R. 669(E), 18 September 2019 |
Added the definition of depository receipt and simplified customer due diligence requirements for specified foreign investments. The amendment allowed reporting entities to rely on beneficial ownership requirements prescribed by notified foreign jurisdictions for certain investments. It also provided specified exemptions for listed companies and their subsidiaries from identifying and verifying individual shareholders or beneficial owners. |
|
G.S.R. 840(E), 13 November 2019 |
Enabled customers undergoing Aadhaar based identity verification to provide a current address different from the address recorded in the Central Identities Data Repository. The amendment allowed reporting entities to accept a self declaration of the customers current address for customer due diligence purposes. |
|
G.S.R. 228(E), 31 March 2020 |
Provided temporary relief for small accounts that were due to be closed because of pending customer due diligence requirements. The amendment allowed such accounts to remain operational from 1 April 2020 to 30 June 2020, with authority for the Central Government to extend the period further in view of the COVID 19 pandemic. |
|
G.S.R. 251(E), 13 April 2020 |
Extended the deadline for reporting entities to submit prescribed transaction reports under Rule 8. The temporary measure allowed eligible reports to be submitted by 30 June 2020 in response to the operational challenges faced by reporting entities during the COVID 19 pandemic. |
|
G.S.R. 254(E), 16 April 2020 |
Specified the transaction reports covered by the temporary extension under Rule 8. The amendment covered reports under Rule 3(1)(A), (B), (BA), (C) and (E) for March, April and May 2020 and reports under Rule 3(1)(F) for the January to March 2020 quarter, allowing submission up to 30 June 2020. |
|
G.S.R. 798(E), 28 December 2020 |
Brought real estate agents with an annual turnover of Rupees 20 lakh or more within the category of persons carrying on a designated business or profession under the PMLA. This brought qualifying real estate agents within the reporting entity framework and subjected them to applicable AML and customer due diligence requirements. |
|
G.S.R. 575(E), 13 July 2022 |
Introduced specific AML and KYC requirements for reporting entities operating in an International Financial Services Centre. The amendment designated the head of the reporting entity in India as the designated officer for IFSC entities, expanded the list of officially valid documents available to foreign nationals, introduced the definition of International Financial Services Centre into the Rules and provided exemptions from specified Central KYC Records Registry requirements for foreign national customers of IFSC reporting entities. |
|
S.O. 1074(E), 7 March 2023 |
Reduced the beneficial ownership threshold to 10 percent and introduced requirements relating to group wide AML policies. The amendment also added definitions for group, politically exposed person and non profit organisation, strengthened customer due diligence requirements for legal persons and trusts and introduced registration requirements for eligible non profit organisations. |
|
G.S.R. 652(E), 4 September 2023 |
Further reinforced the AML framework by strengthening requirements relating to beneficial ownership, group wide AML policies and customer due diligence. The amendment also refined provisions concerning groups, politically exposed persons and non profit organisations, enhanced due diligence requirements for legal persons and trusts and introduced additional registration obligations for eligible non profit organisations. |
|
G.S.R. 745(E), 17 October 2023 |
Enhanced customer due diligence requirements by requiring customer identity to be verified using reliable and independent sources. The amendment also strengthened group wide AML programmes, required suspicious transaction reports to be submitted promptly after suspicion was established and reinforced confidentiality requirements concerning AML records and reporting. |
|
G.S.R. 419(E), 19 July 2024 |
Strengthened the Central KYC Records Registry framework by requiring reporting entities to use the KYC Identifier when retrieving customer records. The amendment also limited requests for duplicate KYC documents to specified circumstances, introduced a seven day period for updating KYC records and required reporting entities to retrieve, update and rely on revised customer information maintained by the Central KYC Records Registry. |
The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005
Rules for accepting client records authenticated outside India, relevant where a debenture trustee onboards a non resident client or a foreign portfolio investor and must rely on documents executed abroad.
CFT Legislation
The Unlawful Activities (Prevention) Act, 1967 (UAPA)
The counter terrorism law. Section 51A requires a debenture trustee to screen clients against the designated lists and to freeze, without delay, the funds and securities of listed persons and entities. The duty binds every debenture trustee, whatever its size.
Procedure For Implementation of Section 51A Of the UAPA (Order Dated 2 February 2021; Corrigendum Dated 15 March 2023 And 29 August 2023)
The official procedure a debenture trustee follows to apply Section 51A, including how to act on a designated list match. The SEBI guidelines fold these steps into the debenture trustee to an issue’s screening and freezing controls.
CPF Legislation
The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)
The proliferation financing law. Section 12A provides the legal basis for targeted financial sanctions relating to the financing of weapons of mass destruction and applies to debenture trustees alongside banks and financial institutions.
Procedure for Implementation of Section 12A of the WMD Act (dated 1 September 2023)
The official procedure for applying Section 12A mirrors the screening and freezing steps that Section 51A sets for terrorism financing.
The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016
Rules implementing the WMD Act and supporting the proliferation financing controls a debenture trustee must operate.
Overarching Obligations
The cross cutting systems and procedures that sit above any single regulator and carry a debenture trustee’s KYC data and reports.
CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025
Govern the central registry that stores client KYC records for reuse across the financial system. A debenture trustee files client KYC data to the CKYCR, retrieves an existing record on onboarding, and updates it within the prescribed window when details change, cutting duplicate paperwork for investors.
SEBI KYC Registration Agency Regulations, 2011
Govern the KYC Registration Agencies that store and share client KYC records across SEBI-registered intermediaries. An underwriter uploads a new client’s KYC documents to a KRA, checks an incoming client’s KYC status before onboarding, and flags or updates the record when the client’s details change, so the same KYC is not repeated for every intermediary the client deals with.
FINnet 2.0 Reporting Formats (2024) and the FINGate 2.0 User Manuals
Define the electronic formats and the gateway through which a debenture trustee files its cash, suspicious and other prescribed reports to FIU-IND, in the current FINnet 2.0 and FINGate 2.0 environment.
eKYC and Section 11A Aadhaar Authentication for the Securities Market
SEBI’s circular on the eKYC authentication facility under Section 11A of the PMLA lets debenture trustees use Aadhaar based verification for resident clients within the statutory and Supreme Court limits, giving a lawful digital onboarding route.
Sectoral
The market regulator and the instruments it issues. This is the sector specific layer, and the SEBI Master Circular for Debenture Trustees and the SEBI AML/CFT Guidelines are the instruments a debenture trustee works from most closely.
Securities and Exchange Board of India (SEBI)
SEBI Master Circular for Debenture Trustees
The star instrument for a debenture trustee. This Master Circular consolidates the conduct requirements for debenture trustees, from registration and due diligence on an issue to security creation, covenant monitoring, disclosures and default handling, and it is the document into which the KYC and AML obligations are read for the trusteeship business. It is where a debenture trustee should look first for a rule that applies to how issuers and protects debenture holders.
SEBI Guidelines on AML Standards and CFT Obligations of Securities Market Intermediaries (6 June 2024)
The working AML rulebook for every SEBI registered intermediary, updated on 6 June 2024. It carries the client due diligence, risk categorisation, beneficial ownership, ongoing monitoring, record-keeping, reporting and sanctions requirements into the securities market, and it replaces the earlier 2010 and 2014 AML master circulars. For a debenture trustee, it is the source of the detailed AML duties that sit alongside the conduct rulebook.
SEBI Master Circular on KYC Norms for the Securities Market (12 October 2023)
The consolidated KYC framework for the securities market, read with the 12 October 2023 modification circular and the clarification on the use of technology for KYC, which sets how a debenture trustee identifies and verifies its clients and maintains their records through the KYC Registration Agencies.
eKYC, KYC clarification circulars and SEBI FAQs
SEBI’s circular on the eKYC authentication facility under Section 11A (5 November 2019), the clarification on the use of technology for KYC (24 April 2020) and the frequently asked questions on KYC norms give a debenture trustee practical guidance on digital onboarding and record-keeping.
Miscellaneous Official Reports and Guidance
Official reports and guidance that are not binding rules but shape how a debenture trustee reads its risk and the wider enforcement picture.
FIU-IND Annual Report 2024 to 2025
The Financial Intelligence Unit’s yearly account of reporting volumes, typologies and enforcement trends, useful for a debenture trustee calibrating what unusual client or trading activity looks like across the market.
Directorate of Enforcement Annual Report 2025 to 2026
The ED’s yearly summary of PMLA investigations, attachments and prosecutions, a reminder of how the criminal side of the regime operates.
FIU-IND and its Core Functions and FAQs
FIU-IND’s explanation of its own role and a set of frequently asked questions, a plain language reference on registration and reporting expectations.
MHA National Counter Terrorism Policy and Strategy
The Ministry of Home Affairs statement of national counter terrorism policy, background that frames the UAPA sanctions obligations a debenture trustee must apply.
International Standards
The global standards India’s framework is built to meet, and against which a debenture trustee’s controls are ultimately judged.
FATF Recommendations
The Financial Action Task Force’s forty Recommendations are the international baseline for AML and CFT. FATF updated Recommendation 6 on targeted financial sanctions in June 2026.
FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)
The peer assessment of India’s AML and CFT regime, which found India largely compliant and set the direction of travel that continues to shape the supervision of debenture trustees and other securities intermediaries.
Allied Laws
The wider body of law that defines the securities statutes and the predicate offences and enforcement machinery around money laundering. A debenture trustee operates under the securities statutes, while the predicate and enforcement Acts shape the risk it must assess and the conduct it may need to report.
The allied laws that most often bear on a debenture trustee’s risk. The Bharatiya Nagarik Suraksha Sanhita 2023 is India’s new code of criminal procedure, replacing the earlier CrPC. The Bharatiya Nyaya Sanhita 2023 is India’s new penal code, replacing the earlier IPC.
The Black Money Undisclosed Foreign Income and Assets and Imposition of Tax Act 2015 taxes and penalises undisclosed foreign income and assets held by Indian residents. The Central Vigilance Commission Act 2003 establishes the CVC as India’s apex anti corruption watchdog for government bodies.
The Chemical Weapons Convention Act 2000 implements India’s obligations under the international Chemical Weapons Convention, banning their production and use. The Conservation of Foreign Exchange and Prevention of Smuggling Activities Act 1974, also known as COFEPOSA, allows preventive detention to curb smuggling and foreign exchange violations.
The Foreign Contribution Regulation Act 2010 regulates the receipt and use of foreign funding by individuals and organisations in India. The Foreign Exchange Management Act 1999 governs foreign exchange transactions and cross border trade and payments in India.
The Fugitive Economic Offenders Act 2018 enables confiscation of assets of economic offenders who flee India to evade prosecution. The Narcotic Drugs and Psychotropic Substances Act 1985 prohibits and penalises the production, possession, and trafficking of narcotic drugs.
The Prevention of Corruption Act 1988 criminalizes bribery and corrupt practices by public servants. The Securities and Exchange Board of India Act 1992 establishes SEBI as the regulator of India’s securities markets.
The SEBI Debenture Trustees Regulations 1993 set registration, eligibility, and conduct norms for entities acting as debenture trustees. The SEBI Intermediaries Regulations 2008 lay down common registration and conduct obligations for various SEBI regulated market intermediaries.
The SEBI Issue and Listing of Municipal Debt Securities Regulations 2015 govern how municipalities can issue and list debt securities on stock exchanges. The Smugglers and Foreign Exchange Manipulators Forfeiture of Property Act 1976, also known as SAFEMA, allows forfeiture of illegally acquired property of smugglers and foreign exchange offenders.
The Arms Act 1959 regulates the acquisition, possession, manufacture, sale, and transport of firearms and ammunition in India. The Benami Transactions Prohibition Act 1988 prohibits property transactions where the ownership is held in the name of a person other than the one who actually paid for it and allows confiscation of such benami property.
Core AML/CFT/CPF Obligations for Debenture Trustees in India
Across that framework, the regulations require a debenture trustee to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.
- Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the debenture trustee can file its reports.
- Appoint officers. Appoint a Designated Director and a management level Principal Officer under Rule 7 of the PMLR and the SEBI Guidelines. The same person cannot hold both roles, and both are informed to FIU-IND and, where applicable, SEBI.
- Conduct the internal risk assessment. Run an ML and TF risk assessment across clients, products, channels and geographies, document it, and take its outcome to the board, as the SEBI AML/CFT Guidelines require.
- Document AML policy, controls and procedures. Adopt a board approved policy that turns the risk assessment into the debenture trustee’s operating procedures.
- Client identification and CDD. Identify and verify every client and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high risk clients, under Section 11A of the PMLA, Rule 9 of the PMLR and the SEBI KYC Master Circular. Given the trusteeship business, due diligence on the issuer and the debenture holders, identifying the beneficial owners behind corporate issuers and holders, and understanding the assets charged as security, are central.
- Ongoing monitoring and periodic updation. Monitor the issuer’s covenants and the debenture holdings on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low risk clients. Review each client’s risk categorisation at least once every six months.
- Sanctions screening. Screen clients and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
- Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, non profit organisation receipt reports and counterfeit currency reports under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly once the Principal Officer is satisfied, through FINnet 2.0.
- Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload client KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
- Training and awareness. Train staff by role to apply the controls and recognise red flags in trusteeship work, such as shell or connected issuers raising debt, a small group of connected or nominee debenture holders in a private placement, opaque security structures, and unusual flows of enforcement or redemption proceeds.
- Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
- Run group wide controls. Where the debenture trustee is part of a group, apply AML and CFT programmes at group level, including for branches and majority owned subsidiaries, as the SEBI Guidelines require.
What This Article Does Not Cover
This article explains the laws and regulatory instruments that apply to debenture trustees. It does not provide a control by control compliance manual, and it does not restate the SEBI (Debenture Trustees) Regulations or the trust deed and disclosure rules except where they bear on the AML duties. For implementation, a debenture trustee separately documents issuer and holder due diligence, KYC and CDD procedures, beneficial owner identification, record-keeping, sanctions screening, monitoring, suspicious transaction escalation, staff training, audit testing and board reporting. Those controls are the subject of the companion compliance guide.
To see how the debenture trustee framework fits within the sector, see AML laws and regulations for intermediaries in India, and to place it within the national picture, see AML laws and regulations in India.
From Regulation to Compliance: Your Next Step
Knowing the law is step one. These obligations only protect a debenture trustee when they are built into a working programme of risk assessment, policy, due diligence, monitoring, screening, reporting, training and independent review. For a debenture trustee, due diligence on the issuer and the debenture holders, identifying the beneficial owners behind them and watching for connected party or opaque debt structures are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.
Want to confirm what the SEBI framework means for your firm?
AML India can walk you through the SEBI AML/CFT Guidelines and build a proportionate client due diligence and monitoring programme for your rating business.
Frequently Asked Questions
A person registered with SEBI under section 12 of the SEBI Act, 1992 and the SEBI (Debenture Trustees) Regulations, 1993, who acts as trustee to a trust deed securing an issue of debentures or debt securities, holding the security for the debenture holders, monitoring the issuer and enforcing on default. In the PMLA it is a trustee to a trust deed, an intermediary and a reporting entity.
Yes. A trustee to a trust deed is expressly named as an intermediary in section 2(1)(n) of the PMLA, so a debenture trustee is a reporting entity under section 2(1)(wa). No separate designation notification is needed; it is inside the regime by virtue of its SEBI registration.
The SEBI Master Circular for Debenture Trustees, updated on 13 August 2025, is the consolidated conduct rulebook, read with the SEBI AML/CFT Guidelines for Securities Market Intermediaries of 6 June 2024 and the SEBI Master Circular on KYC Norms for the Securities Market of 12 October 2023. Together they carry the AML and KYC duties into the trusteeship business.
A debenture trustee stands between an issuer and its debenture holders, so its AML risks sit in shell or connected issuers raising debt to move funds, in privately placed issues subscribed by a small group of connected or nominee holders, in opaque security structures, and in the flow of enforcement or redemption proceeds on a default. Due diligence on the issuer and the holders and identifying the beneficial owners behind them are the core controls.
Suspicious transaction reports of any value, cash transaction reports where cash above Rupees 10 lakh is involved, non profit organisation receipt reports and counterfeit currency reports. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly once the Principal Officer is satisfied, through FINnet 2.0.
Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every debenture trustee. A debenture trustee screens issuers, debenture holders and their beneficial owners against the United Nations and domestic designated lists and reports and acts on any match without delay.
Official sources and review
Last reviewed: August 2026. This guide is grounded in the following primary official sources, linked to their official source where available.
This guide covers money laundering law and compliance, a sensitive area where the rules change; confirm the current position for your firm with a qualified professional before acting.
Why work with AML India
AML India helps debenture trustees meet their PMLA and SEBI obligations, from risk assessment and policy through to issuer and holder due diligence, screening, monitoring, reporting, training and independent review.
Industries we serve: debenture trustees, merchant bankers, underwriters, registrars, custodians, stock brokers, mutual funds and other securities intermediaries, alongside banks, NBFCs, insurers, DNFBPs and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik