Last Updated  on: 28nd July 2026       |        Last Reviewed on: 28nd July 2026

This guide is general information on Indian law, not legal advice. For your institution’s specific position, speak to a qualified AML professional.

Financial institutions in India are reporting entities under the Prevention of Money-Laundering Act, 2002. They are caught not by a special designation but because they are financial institutions: non-banking financial companies, all India financial institutions, housing finance and mortgage guarantee companies, asset reconstruction companies, insurers, payment system operators and aggregators, chit fund companies and the postal savings system all sit within the definition.

Their AML, CFT and CPF obligations flow mainly from the PMLA, the PML (Maintenance of Records) Rules, 2005, the applicable supervisor’s directions, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting requirements. The Reserve Bank of India supervises most of them, with the IRDAI, the Department of Posts and the state chit registrars covering the rest, while every report is filed with FIU-IND.

Key takeaways at a glance

  • Who is covered: financial institutions across India, including NBFCs, all India financial institutions, housing finance, mortgage guarantee and asset reconstruction companies, insurers, payment system operators and aggregators, authorised persons, chit fund companies and India Post, as reporting entities under the PMLA.

  • Why they are caught: as a financial institution within section 2(1)(l) of the PMLA, read with the reporting-entity definition in section 2(1)(wa). No section 2(1)(sa) designation is needed, unlike the DNFBPs.

  • Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the applicable supervisor’s directions, chiefly the RBI category-specific KYC Directions, 2025, the IRDAI Master Guidelines on AML/CFT, 2022, and the Department of Posts norms; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).

  • Supervisors: the Reserve Bank of India for most institutions, the IRDAI for insurers, the Department of Posts for India Post, and the state Registrars of Chits for chit funds. Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.

  • Core duties: an internal risk assessment, customer due diligence and KYC, beneficial-owner identification, periodic updation, monitoring, prescribed-transaction reporting, five-year record-keeping and sanctions screening.

AML Laws and Regulations for Financial Institutions in India

Use this page to understand the common AML, CFT and CPF framework that applies across India’s financial institutions. If you need the detailed rulebook for one type, use the guide for NBFCs, all India financial institutions, housing finance, mortgage guarantee or asset reconstruction companies, insurers, payment system operators or aggregators, chit funds or India Post instead. It explains the law, not how to apply it day to day; for implementation steps, a companion compliance guide covers the controls.

A financial institution is any of the entities that hold, lend, invest, insure or move money outside the banking-licence perimeter but within the financial system. That reach is exactly what money launderers try to exploit, which is why the law places a defined set of anti-money-laundering duties on every financial institution, scaled to its size and risk. This is a sector-level overview: it covers what is common to all financial institutions and then routes you to the rules for your specific type, and it sits within the wider AML laws and regulations framework in India.

What the financial-institutions sector covers and why it is regulated for AML

The financial institutions sector spans a wide range of entities that are not banks but perform bank-like or financial functions. It includes non-banking financial companies and the all India financial institutions such as NABARD, SIDBI, EXIM Bank, the National Housing Bank and NaBFID; housing finance and mortgage guarantee companies; asset reconstruction companies; insurers; payment system operators and payment aggregators; authorised persons dealing in foreign exchange; chit fund companies; and the postal savings and remittance services of India Post. They differ in what they do and who regulates them, yet each is a reporting entity under the anti-money-laundering law.

Financial institutions are regulated for AML because they are the channels through which value enters, moves within and leaves the financial system alongside banks. Lending, investment, insurance, remittance, payment processing and savings products can all be used to layer and integrate illicit funds. The law therefore asks each institution to know its customers, watch how money moves and report suspicious or prescribed transactions, so that the stages of money laundering can be detected wherever they touch the system.

Are financial institutions reporting entities under the PMLA?

Yes. The Prevention of Money-Laundering Act, 2002, known as the PMLA, is India’s parent anti-money-laundering law. It recognises the offence of money laundering and imposes core duties on reporting entities to mitigate it. Under section 2(1)(wa), a reporting entity includes a banking company, a financial institution and an intermediary. A financial institution is defined in section 2(1)(l) by reference to section 45-I of the Reserve Bank of India Act, 1934, so an NBFC, an insurer, a payment system operator or a chit fund company is a reporting entity by virtue of what it is, without any further notification.

This is the key difference from the designated non-financial businesses and professions, which are brought in one activity at a time by notification under section 2(1)(sa). A financial institution is inside the regime from the moment it carries on its financial business, which is why AML compliance is a standing feature of a financial institution’s licence or registration, and why the register of reporting entities that file with FIU-IND is dominated by financial institutions and banks.

Supervisory authority for financial institutions in India

Financial institutions do not share a single supervisor. Which authority sets and inspects the AML rules depends on the type of institution. The Reserve Bank of India supervises the great majority, including NBFCs, all India financial institutions, housing finance, mortgage guarantee and asset reconstruction companies, payment system operators and payment aggregators, and authorised persons, and issues the category-specific KYC Directions, 2025 that each type works from. The Insurance Regulatory and Development Authority of India supervises insurers under its Master Guidelines on AML and CFT. The Department of Posts oversees the postal savings and remittance services of India Post, and the state Registrars of Chits oversee chit fund companies under the Chit Funds Act, 1982.

Whatever the supervisor, the destination of the reports is common. Every financial institution files its cash, suspicious and other prescribed reports with the Financial Intelligence Unit – India, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. In short, the sector supervisor sets and inspects the rules for its institutions, FIU-IND receives the intelligence, and the ED enforces the criminal law.

Onboarding clients without a documented due-diligence process?

AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.

AML Regulatory Requirements for Financial Institutions in India

Read this framework as the financial-institutions sector’s common legal basis; the structure is shared across institution types, while the applicable supervisor’s directions differ by category. The law that governs a financial institution does not sit in one place. It is a layered framework, and it helps to see it grouped as the official source set groups it: the core legislation, the overarching infrastructure, the sectoral supervisors and their directions, the miscellaneous official reports, the international standards, and the allied laws.

The framework reads from the core outward. The PMLA is the parent Act; the PML Rules turn it into operational duties; the supervisor’s directions translate both into instructions an institution can follow; the UAzPA and the WMD Act add counter-terrorism and proliferation-financing sanctions; and the allied laws, including the sector statutes, shape the risk. The risk-based approach runs through the entire framework.

Core Legislation

The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into three sub-sets.

AML Legislation

Prevention of Money-Laundering Act, 2002 (PMLA)

The parent anti-money-laundering law. It creates the offence of money laundering and the core duties on reporting entities, including customer due diligence under Section 11A and record-keeping under Section 12. A financial institution is a reporting entity by virtue of the definition in section 2(1)(l), so the Act applies to an NBFC, an insurer or a payment operator in the same shape as to a bank, scaled to the business.

The PML (Maintenance of Records) Rules, 2005 (PMLR)

The rules made under the PMLA. They set what to report and when (Rule 3 and Rule 8), how to identify customers and beneficial owners (Rule 9), and the duty to appoint officers (Rule 7). For each financial institution, the relevant regulator is the one named in Rule 2(1)(fa) for its category. The PMLR has been amended through 31 Gazette notifications and orders, set out below as a legal-history timeline.

The 31 PMLR amendment notifications, in date order:
Gazette notification and date Key change or rule touched
G.S.R. 389(E), 24 May 2007 The primary amendment to the 2005 Rules. It expanded the Rule 2 test for a suspicious transaction to reach dealings without economic rationale or bona fide purpose and those signaling terrorism financing, restructured Rule 3 around cash dealings in forged or counterfeit currency, replaced Rule 8 pertaining to furnishing information to the Director, and decreased Rule 9’s certified-copy requirement from three to one.
G.S.R. 816(E), 12 November 2009 This amendment introduced the non-profit organisation and Regulator definitions, restated the suspicious transaction, and mandated the reporting of NPO receipts above Rupees 10 lakh. Under Rule 6 it set ten-year record retention requirement, and it reconstructed Rule 9 to require beneficial-owner identification, ongoing due diligence, a ban on anonymous accounts and a Client Identification Programme.
G.S.R. 76(E), 12 February 2010 Refined Rules 3, 4, 5 and 7 to strengthen record-keeping and the reporting of cross-references and, above all, added the first Explanation in Rule 9(1A), explaining and defining the beneficial owner to be a natural person who has ultimate ownership or controls of a client or on whose behalf a transaction is carried out.
G.S.R. 508(E), 16 June 2010 Introduced changes to Rules 2, 9 and 10, the provisions defining, customer due diligence and record-keeping, revising how a reporting entity identifies its customers and what records and details it must retain, according to the sustained 2010 tightening of the CDD and records regime.
G.S.R. 980(E), 16 December 2010 Set up the small-account regime, defining the Designated Officer and the small account, incorporated the NREGA job card and the Aadhaar letter and recognized them as officially valid documents in Rule 2, and adding Rule 9(2A) on how such an account is opened and monitored.
G.S.R. 481(E), 24 June 2011 Introduced the short title and amended Rule 1 to condense the long 2005 name into the Prevention of Money-Laundering (Maintenance of Records) Rules, the PMLR has been in use since.
G.S.R. 576(E), 27 August 2013 It refined Rules 2 and 3 and inserted provisions after Rule 10, addressing several aspects such as definitions, the cash and suspicious-transaction reporting duties and the record framework so that they match the reporting obligations.
G.S.R. 288(E), 15 April 2015 This amendment revised the Rule 2 definitions; since definitions determine who and what the operative rules reach towards, the change carried across the framework and showcased a run of 2015 updates.
G.S.R. 544(E), 7 July 2015 Refined Rules 2, 9 and 10 on definitions, other requirements such as customer due diligence and record-keeping, revising how a reporting entity identifies its customers and what records and details it retains, within the 2015 overhaul of the CDD and records provisions.
G.S.R. 730(E), 22 September 2015 Refined Rules 2 and 7, the definitions and the requirement for a Principal Officer and setting up an internal reporting mechanism, strengthening the governance side and who runs the reporting function.
G.S.R. 882(E), 18 November 2015 Refined the definitions and reporting provisions, revising how key terms are read and how transactions reach the FIU, and closing the 2015 run of amendments.
G.S.R. 347(E), 12 April 2017 Refined Rule 2 and inserted Rule 9A, incorporating the Central KYC Records Registry into the Rules, introducing the duty to file customer KYC records centrally and the basis to reuse them, the structural addition behind today’s CKYCR.
G.S.R. 538(E), 1 June 2017 Refined Rules 2 and 9 to incorporate Aadhaar into customer due diligence, prescribing Aadhaar-based identification and authentication for KYC, an approach that was later reshaped by the Aadhar ruling by the Supreme Court.
G.S.R. 1038(E), 21 August 2017 Refined the definitions under Rule 2, updated the defined terms that determine how the operative rules apply, among several definition changes in 2017.
G.S.R. 1318(E), 23 October 2017 A later 2017 refinement of the Rule 2 definitions, keeping the defined terms current as the framework moved on.
G.S.R. 456(E), 16 May 2018 Refined the definitions and customer due diligence provisions, clarifying coverage and how customers are identified and verified, within the continuing adjustment of the CDD framework.
G.S.R. 1078(E), 31 October 2018 Refined Rule 9 on customer due diligence, revising the steps a reporting entity follows to identify and verify customers and beneficial owners, one of a run of Rule 9 changes over 2018 and 2019.
G.S.R. 108(E), 13 February 2019 The legislative changes to Aadhar used led to the revision of Rules 2 and 9 on definitions and customer due diligence, revising the ways identification could be conducted.
G.S.R. 381(E), 28 May 2019 Refined Rule 9, revising the process for identification and verification of customer and additionally process and the routes to authenticate a customer’s identity, as a part of the post-Aadhaar reshaping of CDD.
G.S.R. 582(E), 19 August 2019 Revised Rules 2 and 9 and introduced provisions after Rule 11, that covering definitions, customer due diligence and the supporting provisions on information and records, one of the broader 2019 updates.
G.S.R. 669(E), 18 September 2019 Refined Rules 2 and 9 once again, the revisions were concentrated around the definitions and the customer due diligence process in the 2019 run of CDD amendments.
G.S.R. 840(E), 13 November 2019 Refined Rule 9 which consisted of changes to the identification and verification requirements.
G.S.R. 228(E), 31 March 2020 The first of the three closely spaced amendments that refined the definitions and reporting provisions, revising defined terms and the manner of reporting transactions.
G.S.R. 251(E), 13 April 2020 This amendment introduced changes to Rule 8, which outlines how transaction reports are furnished to the FIU.
G.S.R. 254(E), 16 April 2020 A subsequent refinement to Rule 8, that  firming up the reporting provisions and the route by which reports reach the FIU.
G.S.R. 798(E), 28 December 2020 A landmark in expanding the regime beyond the financial sector. It should be read in connection with G.S.R. 799(E) and 800(E) , it designated real estate agents and dealers in precious metals and stones and identified the names of their regulator, extending the perimeter to the non-financial businesses.
G.S.R. 575(E), 13 July 2022 Inserted the International Financial Services Centre definition with a tailored beneficial-owner provision for entities in IFSC, and added an IFSC provison under Rule 9A pertaining to the CKYCR, aligning the Rules with the GIFT City regime.
S.O. 1074(E), 7 March 2023 Anamendment that inserted definitions of politically exposed persons, non-profit organisations and group and a Rule 3A duty for group-wide AML policies, and reduced the company beneficial-ownership threshold from 25 to 10 per cent, with a matching change to Rule 9(3)(e), of direct relevance to a financial institution assessing their corporate customers.
G.S.R. 652(E), 4 September 2023 This amendment set the management level requirement for the Principal Officer, reduced the partnership beneficial-ownership threshold from 15 to 10 per cent, added an Explanation of control, status disclosure by obliged trustees, and requirement of the results of any Rule 3 and Rule 9 analysis to be included in the records.
G.S.R. 745(E), 17 October 2023 Refined Rules 2, 3, 8 and 9 in this single notification, including  definitions, the reporting duties and customer due diligence, adjusting several operative provisions together to close the 2023 changes.
G.S.R. 419(E), 19 July 2024 This amendment rewrote Rule 9(1C) pertaining to the KYC Identifier and established a seven-day deadline to update a CKYCR record after any change, introduced  the duty to retrieve the updated record, and refined Rule 9A(2)(g) on filing, retrieving and using registry records, sharpening how current central KYC data is kept.
The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005

Rules for accepting customer records authenticated outside India, relevant where a financial institution onboards a non-resident customer or a foreign corporate counterparty and must rely on documents executed abroad.

CFT Legislation

The Unlawful Activities (Prevention) Act, 1967 (UAPA)

The counter-terrorism law. Section 51A requires a financial institution to screen customers against the designated lists and to freeze, without delay, the funds and assets of listed persons and entities. The duty binds every institution, whatever its size.

Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023)

The official procedure a financial institution follows to apply Section 51A, including how to act on a designated-list match. The supervisor’s directions fold these steps into the institution’s screening and freezing controls.

CPF Legislation

The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)

The proliferation-financing law. Section 12A provides the legal basis for targeted financial sanctions relating to the financing of weapons of mass destruction, and applies to financial institutions alongside banks.

Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)

The official procedure for applying Section 12A mirrors the screening and freezing steps that Section 51A sets for terrorism financing.

The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016

Rules implementing the WMD Act and supporting the proliferation-financing controls a financial institution must operate.

Not registered with FIU-IND yet, or unsure whether you have to be?

AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.

Overarching Obligations

The shared national infrastructure that every financial institution plugs into, whatever its category or supervisor.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

The Central KYC Records Registry stores customer KYC records centrally. An institution uploads to it and can reuse a customer’s existing record, keeping KYC consistent and reducing duplication. Getting beneficial ownership and identity data right at onboarding is what makes the registry useful to the next reporting entity.

FINnet 2.0 reporting formats (2024) and the FINGate 2.0 user manuals

The FIU-IND reporting platform and its current formats, through which a financial institution enrols and files its reports, with the FINGate 2.0 manuals covering enrolment, request-response and reports.

Procedure for Aadhaar authentication under Section 11A of the PMLA (9 May 2019)

The procedure for reporting entities other than banking companies to apply to use Aadhaar authentication services, relevant to the many non-banking financial institutions that verify identity through Aadhaar.

Sectoral Guidelines

The supervisors and their directions. This is the layer that differs most across the sector, because financial institutions answer to several regulators depending on the category. The map below groups each supervisor with the institutions it oversees.

Reserve Bank of India

The RBI category-specific KYC Directions, 2025

The RBI’s detailed KYC and AML rulebook, issued on 28 November 2025 as a consolidated, category-specific set and updated as of 29 December 2025. Each institution works from the Direction for its category, the All India Financial Institutions KYC Directions for AIFIs such as NABARD, SIDBI, EXIM Bank, the NHB and NaBFID, the Asset Reconstruction Companies KYC Directions for ARCs, the NBFC KYC Directions for NBFCs and, by application, for authorised persons and similar entities, and the Housing Finance Companies and Mortgage Guarantee Companies Directions for those categories. Payment system operators and aggregators apply the relevant KYC Directions read with the payment-sector master directions. Earlier KYC directions stand repealed or superseded to the extent provided in the 2025 set.

RBI Internal Risk Assessment (IRA) Guidance for ML/TF Risks (2024)

The RBI guidance that calls the internal risk assessment the bedrock of the risk-based approach and requires its outcome to go to the board, applied by every RBI-regulated financial institution.

Insurance Regulatory and Development Authority of India (IRDAI)

IRDAI Master Guidelines on AML/CFT, 2022 (1 August 2022) and the 2023 amendment

The insurance sector’s AML and CFT rulebook, issued by the IRDAI and effective from 1 August 2022, amended on 10 October 2023, which sets out customer due diligence, beneficial-owner identification, monitoring, reporting and record-keeping for insurers.

Department of Posts

Post Office Savings Bank KYC/AML/CFT norms and the Money Transfer Service Scheme Master Direction

The Department of Posts norms for the Post Office Savings Bank, revised on 25 May 2023, and the money transfer service scheme, which apply AML and CFT duties to the postal savings and remittance services of India Post.

State Registrars of Chits

Chit fund companies under the Chit Funds Act, 1982

Chit fund companies are registered and supervised by the state Registrars of Chits under the Chit Funds Act, 1982, and apply the PMLA and PMLR framework as financial institutions, in the absence of a single central AML direction for the sector.

Miscellaneous official Reports and Guidance

Official reports and guidance that sit outside the binding rulebook but shape how a financial institution reads its risk and its duties.

FIU-IND Annual Report 2024-25

The annual account of reporting, analysis and dissemination by the national FIU, useful for understanding reporting volumes and priorities across reporting-entity types.

Directorate of Enforcement Annual Report 2025-26

The ED’s annual account of investigations, attachments and prosecutions under the PMLA, showing how the criminal-enforcement end of the framework is used.

FIU-IND and its Core Functions and FAQs

A plain-language explanation of what FIU-IND does and how reporting works, a useful primer for an institution setting up its reporting function.

MHA National Counter-Terrorism Policy and Strategy

The Ministry of Home Affairs statement of national counter-terrorism policy, which frames the CFT duties that Section 51A places on financial institutions.

International Standards

The global benchmarks India is measured against, and the sources an institution can use to calibrate a risk-based approach.

FATF Recommendations

The international AML, CFT and CPF standards. Recommendations 9 to 23 set the preventive measures for financial institutions, from customer due diligence and record-keeping to reporting and internal controls, and Recommendation 6 on targeted financial sanctions was updated by FATF in June 2026. India’s financial-institution framework is built to meet them.

FATF Mutual Evaluation Report on India, 2024 and Executive Summary

The peer assessment of India’s AML and CFT system, which examined how the financial sector’s preventive measures and supervision work in practice and where they are expected to strengthen.

FATF Risk-Based Approach Guidance for the Real Estate Sector (2022)

The Basel Committee guidance on managing ML and TF risk, widely used by the banking and financial sector as a benchmark for the risk-based approach and group-wide controls.

Allied Laws

The wider body of law that defines the sector statutes and the predicate offences and enforcement machinery around money laundering. An institution operates under its own sector statute, while the predicate and enforcement Acts shape the risk it must assess and the conduct it may need to report.

The allied laws that most often bear on a financial institution’s risk are the Reserve Bank of India Act, 1934 (which defines a financial institution and governs the RBI-regulated categories), the Insurance Act, 1938 and the Insurance Regulatory and Development Authority Act, 1999 (for insurers), the National Housing Bank Act, 1987 (for housing finance), the Factoring Regulation Act, 2011, the Payment and Settlement Systems Act, 2007 (for payment operators and aggregators), the Chit Funds Act, 1982 (for chit funds), the Companies Act, 2013, the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Foreign Exchange Management Act, 1999, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974, the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.

How the laws fit together

Together, these instruments form the AML laws and regulations applicable to Financial Institutions in India. Each serves a distinct purpose while complementing the others to create a comprehensive compliance regime. The PMLA establishes the legal offences and core obligations; the PML Rules set out the requirements for customer due diligence, record-keeping, and reporting; the sectoral regulator’s directions provide detailed operational requirements; FIU-IND receives and analyses the reports; the UAPA and WMD Act impose targeted financial sanctions obligations; and the FATF Recommendations provide international benchmarks.

Authority or instrument Role
PMLA, 2002 The parent anti-money-laundering law. Creates the offence and the core reporting-entity duties.
PML (Maintenance of Records) Rules, 2005 Set out customer due diligence, beneficial ownership, record-keeping and reporting.
Reserve Bank of India Supervises most financial institutions and issues the category-specific KYC Directions, 2025.
IRDAI Supervises insurers under the Master Guidelines on AML/CFT, 2022.
Department of Posts / State Registrars of Chits Supervise India Post and chit fund companies respectively.
FIU-IND Receives, analyses and disseminates the reports institutions file.
Enforcement Directorate Investigates and prosecutes the offence of money laundering under the PMLA.
UAPA Section 51A / WMD Act Section 12A Impose counter-terrorism and proliferation-financing targeted financial sanctions.
FATF Recommendations 9 to 23 Set the international preventive-measure standards for financial institutions.

Core obligations across all financial institutions at a glance

Across that framework, the law requires every financial institution to do the following. This guide states each duty at the level set by the law; the companion compliance guidance explains how to carry each one out.

  • Register with FIU-IND. Enroll on the FINnet 2.0 / FINGate 2.0 portal so the institution can file its reports.
  • Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR. The same person cannot hold both roles, and both are informed to FIU-IND and, where applicable, the supervisor.
  • Assess your risk. Conduct an internal risk assessment of money-laundering, terror-financing and proliferation-financing risk across customers, products, channels and geographies, with its outcome going to the board, as the RBI IRA Guidance requires for RBI-regulated institutions.
  • Know your customer. Identify and verify every customer and the beneficial owner (more than 10 per cent for a company or partnership, more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high-risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the applicable supervisor’s directions.
  • Keep KYC current. Carry out periodic updation at least once every 2, 8 and 10 years for high, medium and low-risk customers, and review each customer’s risk categorisation at least once every six months.
  • Monitor and report. Watch accounts on an ongoing basis, and file cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, cross-border wire transfer reports of Rupees 5 lakh or more where applicable, and counterfeit-currency reports, under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th of the succeeding month; suspicious transaction reports are filed promptly.
  • Keep records. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA, and upload KYC records to the CKYCR.
  • Screen against sanctions lists. Screen customers and beneficial owners against the UAPA and WMD Act designated lists daily and freeze any matched funds without delay.
  • Run group-wide controls. Where the institution is part of a group, apply AML and CFT programmes at group level, including for branches and majority-owned subsidiaries.

CFT and CPF: targeted financial sanctions

Anti-money laundering is only part of the duty. A financial institution must also counter the financing of terrorism and the financing of weapons of mass destruction, both of which work through targeted financial sanctions: screening customers and transactions against designated lists and freezing any matched funds without delay. The sanctions screening process is the same in principle across institution types, scaled to the business.

The CFT duty flows from Section 51A of the UAPA, as implemented by the 2 February 2021 procedure and its corrigenda. The CPF duty flows from Section 12A of the WMD Act, applied through the procedure dated 1 September 2023. In practice an institution screens against the United Nations Security Council lists and the relevant domestic lists, acts on any match, and reports as required, verifying the lists daily.

What happens if a financial institution breaches AML law?

A breach of the AML framework is not a single risk but several, because more than one body can act, each under its own power. The reporting duties also run continuously, so a missed or incorrect filing can be treated as an ongoing default rather than a one-off.
Body What it can do on a breach
The sector supervisor (RBI, IRDAI and others) Monetary penalties and supervisory directions on the institution under the supervisor’s governing law, such as the RBI Act, 1934 or the Insurance Act, 1938.
FIU-IND Compliance orders, monetary penalties and warnings on the reporting entity and its officers under Section 13 of the PMLA.
Enforcement Directorate Investigation, provisional attachment of the proceeds of crime, and prosecution for the offence of money laundering under the PMLA.
Beyond the formal penalties, a breach carries consequences that often prove more costly: reputational damage, the loss or repricing of banking and correspondent relationships when controls are questioned, and adverse findings in the next inspection or independent review. Because the framework runs on the live programme, the cheapest position is always to stay compliant rather than to remediate after an order.

From regulation to compliance: your next step

Knowing the law is only step one. These obligations become effective only when they are implemented through practical measures of risk assessment, policy and procedure, customer due diligence, monitoring, screening, reporting, staff training and independent audit. Because even a single high-value property deal can carry significant laundering risk, agencies are placed to establish their compliance before reaching the prescribed turnover threshold rather than after it. A good starting point is to understand the three stages of money laundering and how the sanctions screening process works. 

Not sure which directions bind your institution?

Financial institutions carry different licences, registrations and supervisors. Talk to an AML consultant if you would like help confirming the framework that applies to your institution

Frequently Asked Questions

Yes. Every financial institution is a reporting entity under the PMLA, because the reporting-entity definition in section 2(1)(wa) includes a financial institution, defined in section 2(1)(l) by reference to section 45-I of the RBI Act, 1934. Unlike the designated non-financial businesses, a financial institution is caught by what it is, not by a separate notification.

It depends on the type. The Reserve Bank of India supervises most, including NBFCs, all India financial institutions, housing finance, mortgage guarantee and asset reconstruction companies, payment system operators and aggregators, and authorised persons, and issues the category-specific KYC Directions, 2025. The IRDAI supervises insurers, the Department of Posts oversees India Post, and the state Registrars of Chits oversee chit funds. Reports go to FIU-IND.

The RBI issued category-specific KYC Directions on 28 November 2025, updated as on 29 December 2025. An institution works from the Direction for its category: the All India Financial Institutions KYC Directions, the Asset Reconstruction Companies KYC Directions, the NBFC KYC Directions, or the Housing Finance and Mortgage Guarantee Companies Directions, read with the payment-sector master directions where relevant. Any policy relying only on the earlier 2016 KYC framework should be updated.

The core PMLA duties are the same, but the supervisor and the sector rulebook differ. An NBFC works from the RBI NBFC KYC Directions, 2025, while an insurer works from the IRDAI Master Guidelines on AML and CFT, 2022. Both identify customers and beneficial owners, monitor transactions, screen against sanctions lists and report to FIU-IND, but the detailed directions come from different regulators.

The prescribed reports under Rule 3 of the PMLR: cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, cross-border wire transfer reports of Rupees 5 lakh or more where applicable, and counterfeit-currency reports. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly, through FINnet 2.0.

Yes. A chit fund company is a financial institution and a reporting entity under the PMLA. It is registered and supervised by the state Registrar of Chits under the Chit Funds Act, 1982, and it applies the PMLA and PMLR framework, files with FIU-IND and screens against the sanctions lists, even though there is no single central AML direction dedicated to the sector.

Official sources and review

Why work with AML India

AML India helps financial institutions of every type meet their PMLA and supervisor obligations, from risk assessment and policy through to CDD, screening, monitoring, reporting, training, software selection and independent review.

Industries we serve: NBFCs, all India financial institutions, housing finance, mortgage guarantee and asset reconstruction companies, insurers, payment system operators and aggregators, authorised persons, chit fund companies and India Post, alongside banks, DNFBPs, securities intermediaries and IFSC and GIFT City entities.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik