Last Updated  on: 21st August 2026       |        Last Reviewed on: 21st August 2026

Key Takeaways Briefly

  • Who is covered: authorised dealer, money changers, and offshore banking unit authorised by the RBI to deal in foreign exchange or foreign securities under section 10 of FEMA.
  • Why are they covered: an authorised person is specifically defined under section 2(1)(da) of the PMLA and is expressly included within the definition of a “financial institution” under section 2(1)(l). Consequently, they fall within the definition of reporting entity under section 2(1)(wa).
  • Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the RBI NBFC KYC Directions, 2025 read with the Master Directions on Money Changing Activities and the Money Transfer Service Scheme; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
  • Supervisor: the Reserve Bank of India (RBI), which authorises and supervises authorised persons under FEMA. Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
  • Core duties: an internal risk assessment, customer due diligence and KYC, beneficial owner identification, ongoing monitoring, cash and suspicious transaction reporting, five-year record-keeping and sanctions screening.

This guide is general information on Indian law, not legal advice. For your business’s specific position, speak to a qualified AML professional.

Authorised persons are reporting entities under the Prevention of Money-Laundering Act, 2002. An authorised person is a money changer, an authorised dealer, an offshore banking unit, or any other person authorised by the Reserve Bank of India under section 10 of the Foreign Exchange Management Act, 1999, to deal in foreign exchange or securities, including the agents of the money transfer service scheme. Because these businesses convert currency and move value across borders, they carry a high money laundering and terrorist financing risk.

Their AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the RBI NBFC KYC Directions read with the money-changing and MTSS master directions, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework.

The core instruments at a glance

Instrument 

What it does for an authorised person 

PMLA, 2002 

The principal Act. Includes the authorised person within the financial institution definition and creates the core duties of CDD, record-keeping and reporting. 

PML (Maintenance of Records) Rules, 2005 

Set out what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. 

RBI KYC Directions, 2025 

For authorised persons regulated by department of regulation, their respective KYC directions and for the ones not regulated by department of regulation RBI (NBFC-KYC) Directions.  

FEMA, 1999 

The Act under which the RBI authorises a person to deal in foreign exchange or securities and supervises the business. 

UAPA Section 51A and WMD Act Section 12A 

Impose targeted financial sanctions for terrorism and proliferation financing. 

FATF Recommendations  

The international preventive measure standards, including the standard for money or value transfer services. 

What Counts as an Authorised Person in India?

Any person authorised by the Reserve Bank of India to act as an authorised dealer, a money changer, an offshore banking unit and deal with foreign exchange or securities under section 10 of FEMA is known as an authorised person. In practice, this covers the full-fledged money changers who buy and sell foreign currency, the authorised dealers who handle a wider range of foreign exchange business, and the agents of the money transfer service scheme who pay out inbound cross-border personal remittances. This guide addresses these businesses as reporting entities in their own right, rather than the banks that also hold authorised dealer status and are covered by the banking framework.

The dealings conducted by authorised persons involve cash-intensive currency exchange and cross-border remittance flows, both of which may be misused to convert the form or currency of illicit funds and move value rapidly across jurisdictions. These activities are particularly vulnerable to structuring transactions below applicable thresholds, the use of third parties and the layering of multiple small transactions to obscure the source and beneficial ownership of funds.

Are Authorised Persons Reporting Entities Under the PMLA?

Yes, authorised persons are expressly covered as reporting entities under section 2(1)(wa) by being categorised as financial institutions under section 2(1)(l) of the Prevention of Money-Laundering Act, 2002, which creates the offence of money laundering and places core duties on reporting entities. The Act defines authorised person under section 2(1)(da) with reference to FEMA.

This places authorised persons in the same broad category of reporting entities that file with FIU-IND alongside banks and other financial institutions and brings them within the wider AML laws and regulations for financial institutions in India. The obligations are calibrated to the size and nature of the business, but their status as reporting entities is not optional.

Supervisory Authority for authorised persons in India

The supervisor for authorised persons is the Reserve Bank of India, which authorises them under section 10 of FEMA and supervises their conduct through its master directions. The KYC and AML baseline is the RBI NBFC KYC Directions, 2025 for unregulated authorised persons by the Department of Regulation, and for the regulated ones, their specific directions apply, i.e., the Master Direction on Money Changing Activities and the Master Direction on the Money Transfer Service Scheme.

The Financial Intelligence Unit – India receives, analyses and disseminates the reports an authorised person files, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. In short, the RBI authorises and supervises the business, FIU-IND receives the intelligence, and the ED enforces the criminal law.

Onboarding clients without a documented due-diligence process?

AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.

AML Regulatory Requirements for Authorised Persons in India

Governing laws, rules and guidelines for authorised persons are layered into the core legislation, the overarching obligations, the sectoral supervisor and its directions, the miscellaneous official reports, the international standards, and the allied laws.

The core statute leading the AML, CFT and CPF obligations for authorised persons is the PMLA is the parent Act; the PML Rules turn it into operational duties; the RBI Directions translate both the Act and rules into instructions an authorised person can follow; the UAPA and the WMD Act add counter terrorism and proliferation financing sanctions; and the allied laws, including each institution’s own establishing statute, shape the risk. The risk-based approach is the thread that runs through it all.

Core Legislation

The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into three catalogues.

AML Legislation

Prevention of Money-Laundering Act, 2002 (PMLA)

India’s parent anti-money laundering statute and the source of an authorised person’s status as a reporting entity. It defines the offence of money laundering and imposes the core obligations on the reporting entities, including customer due diligence under Section 11A and record-keeping and reporting requirements under Section 12, which an authorised person must apply across its foreign exchange and remittance business. Because authorised persons convert currency and facilitate the movement of value across borders, their AML exposure is concentrated at the point of exchange or payout, particularly where transactions involve structuring, third-party use, unusual payment patterns or attempts to conceal the source or beneficial owner of funds.

The PML (Maintenance of Records) Rules, 2005 (PMLR)

The rules made under the PMLA provide the detailed operational framework that authorised persons apply in their day-to-day compliance. They prescribe the transactions and information that must be reported, and the manner and timelines for reporting under Rule 3 and Rule 8, set out the requirements for identifying and verifying customers and beneficial owners under Rule 9, and require the appointment of a Principal Officer and Designated Director under Rule 7.

The PMLR has been amended through 31 Gazette notifications and orders, which are set out below as a legal history timeline.

The 31 PMLR Amendment Notifications, in Date Order:

Gazette notification and date 

Key change or rule touched 

G.S.R. 389(E), 24 May 2007 

It sharpened the Rule 2 concept of a suspicious transaction to cover dealings without economic rationale or bona fide purpose and those pointing to terrorism financing, revised Rule 3 for cash dealings in forged or counterfeit currency, substituted Rule 8 on furnishing information to the Director, and reduced Rule 9 from three certified copies to one. 

G.S.R. 816(E), 12 November 2009 

It brought in the non-profit organisation and Regulator definitions under Rule 2, amended the suspicious transaction definition and mandated NPO receipts over Rupees 10 lakh to be reported. Under Rule 6 it set ten years as record retention period, and it revised Rule 9 around beneficial owner identification, ongoing due diligence, a bar on anonymous accounts and a Client Identification Programme. 

G.S.R. 76(E), 12 February 2010 

Amended Rules 3, 4, 5, 7 and 9 to strengthen record keeping and the reporting references and, most notably, added the first Explanation in Rule 9(1A), which fixes the beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction is carried out. 

G.S.R. 508(E), 16 June 2010 

Revised Rules 2, 9 and 10, the definitions, customer due diligence and record keeping, changing how a reporting entity identifies customers and what records it keeps, within the 2010 tightening of the CDD and records regime. 

G.S.R. 980(E), 16 December 2010 

It defined the Designated Officer and the small account, brought the NREGA job card and the Aadhaar letter into the officially valid documents in Rule 2, and added Rule 9(2A) on the opening and monitoring of a small account. 

G.S.R. 481(E), 24 June 2011 

Amended Rule 1 to shorten the long 2005 name to the Prevention of Money-Laundering (Maintenance of Records) Rules, the PMLR shorthand used since. 

G.S.R. 576(E), 27 August 2013 

Amended Rules 2 and 3 and inserted provisions after Rule 10, touching definitions, the cash and suspicious transaction reporting obligations and the record keeping framework. 

G.S.R. 288(E), 15 April 2015 

Revised Rule 2 definitions; because definitions set who and what the operative rules reach, the change carried through the framework and began a run of 2015 updates. 

G.S.R. 544(E), 7 July 2015 

Amended Rules 2, 9, 10 and inserted Rule 9A on definitions, customer due diligence and record keeping, changed how a reporting entity identifies customers and what records it keeps. 

G.S.R. 730(E), 22 September 2015 

Inserted an explanation under Rule 2, recognising a marriage certificate as a supporting document for a subsequent change of name in an officially valid document. 

G.S.R. 882(E), 18 November 2015 

Revised the timeline under Rule 9A for the Government to establish a Central KYC Records Registry, extending it from 90 days to 180 days from the date of commencement of 2015 amendments. 

G.S.R. 347(E), 12 April 2017 

Amended Rule 2 and added Rule 9B, bringing the Central KYC Records Registry into the Rules, mandated reporting entities to file customer KYC records centrally and the basis to reuse them, the structural addition behind today’s CKYCR. 

G.S.R. 538(E), 1 June 2017 

Revised Rules 2 and 9 to bring Aadhaar into customer due diligence, prescribing Aadhaar based identification and authentication for KYC, an approach the Supreme Court’s Aadhaar ruling later reshaped. 

G.S.R. 1038(E), 21 August 2017 

Amended the Rule 2 definitions, changing the defined terms that govern how the operative rules apply, among several definition updates in 2017. 

G.S.R. 1318(E), 23 October 2017 

Inserted proviso for acceptance of officially valid documents from abroad of a foreign national.  

G.S.R. 456(E), 16 May 2018 

Inserted a clause under Rule 9 setting out the requirements for incorporating sector specific guidelines and requiring all reporting entities to formulate a Customer Due Diligence (CDD) programme. 

G.S.R. 1078(E), 31 October 2018 

Revised Rule 9 by extending the timeline for filing electronic records of a customer’s CDD from 3 days to 10 days. 

G.S.R. 108(E), 13 February 2019 

Amended Rules 2 and 9 on definitions and customer due diligence, to accommodate the legislative changes of Aadhaar use. 

G.S.R. 381(E), 28 May 2019 

Revised Rule 9 strengthened the identification and verification process and the routes to confirm a customer’s identity, part of the post-Aadhaar reshaping of CDD. 

G.S.R. 582(E), 19 August 2019 

Amended Rules 2 and 9 and added annexure after Rule 11, definitions, customer due diligence and the supporting information and records provisions. 

G.S.R. 669(E), 18 September 2019 

Again, revised Rules 2 and 9, refining the definition and strengthening the customer due diligence framework in relation to depository receipts. 

G.S.R. 840(E), 13 November 2019 

Amended Rule 9 with further changes to the identification and verification requirements, closing the 2019 run of CDD changes. 

G.S.R. 228(E), 31 March 2020 

Revised the timeline for small accounts operationalisation for 2020 and further as notified by the government. 

G.S.R. 251(E), 13 April 2020 

Amended the reporting timeline under Rule 8 for furnishing transaction reports to the FIU. 

G.S.R. 254(E), 16 April 2020 

Further amended Rule 8 to incorporate a new timeline for report submission for the quarter.   

G.S.R. 798(E), 28 December 2020 

It introduced Dealers in Precious Metals and Stones and Real Estate Agents as a DNFBP for them to be covered under PMLA.  

G.S.R. 575(E), 13 July 2022 

Brought in the International Financial Services Centre definition with a tailored beneficial-owner provision for IFSC entities and added an IFSC proviso to Rule 9A on the CKYCR, aligning the Rules with the GIFT City regime. 

S.O. 1074(E), 7 March 2023 

A major amendment adding definitions of politically exposed persons, group and non-profit organisations. Rule 3A duty for group-wide AML policies and cutting the company beneficial ownership threshold from 25 to 10 per cent, with a matching change to Rule 9(3)(e), relevant to an authorised person serving corporate customers. 

G.S.R. 652(E), 4 September 2023 

The second major 2023 amendment. It set the Principal Officer at management level, cut the partnership beneficial ownership threshold from 15 to 10 per cent, added an Explanation of control, required trustees to disclose their status, and brought the results of any Rule 3 and Rule 9 analysis into the records kept. 

G.S.R. 745(E), 17 October 2023 

Amended Rules 2, 3, 8 and 9 covering definitions, the reporting duties and customer due diligence, changing several operative provisions together to close the 2023 changes. 

G.S.R. 419(E), 19 July 2024 

Revised Rule 9(1C) on the KYC Identifier and set a seven-day deadline to update a CKYCR record after any change, added a duty to fetch the updated record, and amended Rule 9A(2)(g) on filing, retrieving and using registry records, changing how current central KYC data is kept. 

The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005

Rules made under the parent anti-money laundering statute for accepting customer records authenticated outside India, relevant to an authorised person that pays out an inbound remittance or serves a non-resident customer. It mandates the institutions to rely on identity documents executed and certified abroad by the relevant authority.

CFT Legislation

The Unlawful Activities (Prevention) Act, 1967 (UAPA)

India’s counter terrorism statute. Section 51A of the Act requires an authorised person to screen customers and beneficial owners against the designated lists and to freeze, without delay, the funds of listed persons and entities, whatever the size of the transaction.

Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023 and 29 August 2023)

The procedure an authorised person follows to apply Section 51A. The RBI Directions fold the screening and freezing steps into the institution’s controls, turning the statutory order into a workable process.

CPF Legislation

The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)

India’s proliferation financing statute. Section 12A of the Act provides the legal basis for targeted financial sanctions relating to the financing of weapons of mass destruction, and reaches an authorised person directly, because currency exchange and cross-border remittance are documented channels for moving value for a sanctioned network.

Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)

The procedure for applying Section 12A, it provides reporting entities with the sanctions screening and freezing process that mirrors the Section 51A screening and freezing steps, to be applied by an authorised person for designated list screening.

The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016

Rules implementing the WMD Act and supporting the proliferation financing controls an authorised person must operate.

Not registered with FIU-IND yet, or unsure whether you have to be?

AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.

Overarching Obligations

The shared national instruments that an authorised person plugs into as a reporting entity.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

The guidelines provide functions and obligations of the Central KYC Records Registry, which stores customer KYC records centrally. An authorised person uploads to it and can reuse a customer’s existing record, keeping KYC consistent and reducing duplication. Getting beneficial ownership and identity data right for an institutional customer at onboarding is what makes the registry useful.

FINnet 2.0 Reporting Formats (2024) and the FINGate 2.0 User Manuals

The FIU-IND’s current reporting platform and prescribed reporting formats through which an authorised person enrols as a reporting entity and submits the required transaction reports. The FINGate 2.0 user manuals cover enrolment, request response and reports, making them an important operational reference for authorised persons’ reporting function.

Section 11A Aadhaar Authentication Procedure for Reporting Entities (9 May 2019)

The procedure for reporting entities other than banking companies to apply for usage of Aadhaar authentication services, relevant where an authorised person verifies an individual’s identity through Aadhaar.

Sectoral

The supervisor and its directions. The Reserve Bank of India regulates authorised persons and issues the KYC Directions the institution works from, read with its consolidated master directions and internal risk assessment guidance.

Reserve Bank of India

NBFC - RBI Know Your Customer Directions, 2025

The KYC and AML baseline for authorised persons and the principal compliance framework references in this section. The RBI issued its consolidated, category-specific KYC Directions on 28 November 2025, updated as of 29 December 2025. The requirements applicable to authorised persons are aligned with those applicable to other non-banking financial companies and apply to authorised persons through the master direction governing their activity. They set out requirements relating to customer identification and due diligence, beneficial owner identification, risk assessment, the appointment of a Designated Director and Principal Officer, reporting, record management and the implementation of Sections 51A and 12A of UAPA and WMD Act respectively. Where this article states a duty at the level of the law, the Directions read with the relevant master direction are where authorised persons will find the detail.

RBI circular on compliance with KYC norms for Authorised Persons (28 November 2025)

A circular addressed to all authorised persons, drawing their attention to the KYC obligations in the money changing, overseas investment, other remittance facilities and money transfer service scheme master directions, and confirming that the KYC Direction has been updated. It is the instrument that ties the general KYC framework to the authorised person business.

Master Directions on Money Changing Activities and the Money Transfer Service Scheme (MTSS)

The RBI master directions that govern the two core authorised person activities: money changing, where a full-fledged money changer buys and sells foreign currency, and the money transfer service scheme, under which agents pay out inbound cross-border personal remittances. Each carries the KYC and reporting obligations an authorised person applies in that activity.

Miscellaneous

Official reports and guidance that sit outside the binding rulebook but shape how an authorised person measures its risk and form its duties.

FIU-IND Annual Report 2024-25

The national FIU’s annual account of the transaction reports it receives, analyses and disseminates provides useful insight into reporting volumes, trends and priorities across all reporting entities. If offers practical context on the role of transaction reporting within India’s framework.

Directorate of Enforcement Annual Report 2025-26

The Enforcement Directorate’s annual account of investigations, provisional attachments and prosecutions under the PMLA provides insight into how the criminal enforcement framework operates; it offers typologies and the importance of effective preventive measures.

FIU-IND and its Core Functions and FAQs

This instrument provides a practical explanation of the unit’s role in receiving, analysing and disseminating transaction reports, as well as the registration and reporting responsibilities of reporting entities.

MHA National Counter Terrorism Policy and Strategy

The Ministry of Home Affairs statement of national counter terrorism policy provides broader policy context for the CFT obligations applicable to all the reporting entities. It supports the implementation of Section 51A of the UAPA, including the screening and freezing measures.

International Standards

The international measures India’s framework is judged against, and the sources an authorised person can use to calibrate a risk-based approach.

FATF Recommendations

The international benchmark for AML, CFT, and CPF controls and form the foundation on which India’s framework is built. For authorised persons. Recommendations 9 to 23 are particularly relevant because they establish the preventive measures for financial institutions. These standards are reflected in the PMLA, PMLR and the sectoral guidelines. The recommendations were last updated in June 2026, and one of the major changes it brought is that Recommendation 6, to incorporate humanitarian exemptions for targeted financial sanctions,

FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)

The peer assessment of India’s AML, CFT and CPF system evaluates both the country’s practical compliance with FATF recommendations and the effectiveness of its framework. It examined how the financial sector’s preventive measures and supervision work in practice, and it provided the improvement scope for the continuous development of India’s framework.

Basel Committee, Sound Management of Risks Related to Money Laundering and Financing of Terrorism (2014, revised July 2020)

The Basel Committee guidance on managing ML and TF risk, a benchmark for the risk-based approach and group-wide controls that an authorised person can read across to their own risk management.

FATF Risk-Based Approach Guidance for the Banking Sector (2014)

FATF sector guidance on applying the risk-based approach in banking and financial institutions, useful to an authorised person in shaping its customer due diligence and monitoring controls.

Allied Laws

The wider body of law that defines each institution’s own mandate, the predicate offences and enforcement machinery around money laundering.

The allied law most directly connected to an authorised person’s AML risk is the Foreign Exchange Management Act, 1999 (FEMA), under which the RBI authorises and regulates persons permitted to deal in foreign exchange. It also shapes the customer, transaction and cross-border risks that are addressed through the reporting entity’s controls.

Alongside FEMA, a supporting group of the predicate offence and enforcement laws that shape an authorised person’s money laundering risk include the Companies Act, 2013, the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Foreign Exchange Management Act, 1999, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974 (COFEPOSA), the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976(SAFEMA), the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003. These laws identify the criminal, corruption, foreign-exchange, tax smuggling, terrorism and proliferation financing risks that may generate illicit funds. Their practical relevance lies in helping authorised persons assess customer and transaction risk, identify suspicious activity and comply with lawful regulatory, investigative and freezing directions.

Core AML/CFT/CPF Obligations for Authorised Persons in India

Across that framework, the regulations require an authorised person to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.

  • Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the institution can file its reports.
  • Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR and the RBI Directions. The same person cannot hold both roles, and both are to be informed to FIU-IND and the RBI.
  • Conduct the internal risk assessment. Run an ML and TF risk assessment across customers, products, channels and geographies, document it, and take its outcome to the board, as the RBI Directions and the IRA Guidance require.
  • Document AML policy, controls and procedures. Adopt a board-approved policy that turns the risk assessment into the institution’s operating procedures.
  • Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high-risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the RBI authorised person KYC Directions 2025. Given the cash-intensive, cross-border nature of the business, customer identification at the point of exchange or remittance payout, and watching for structuring and third-party use, are central.
  • Ongoing monitoring and periodic updates. Monitor transactions on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low-risk customers respectively. Review each customer’s risk categorisation at least once every six months.
  • Sanctions screening. Screen customers and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
  • Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit-currency reports and, for cross-border remittance activity under the MTSS, cross-border wire transfer reports of Rupees 5 lakh or more where applicable, under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly, through FINnet 2.0.
  • Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
  • Training and awareness. Train staff by role to apply the controls and recognise red flags in currency exchange and cross-border remittance.
  • Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
  • Run group-wide controls. Where the institution has subsidiaries, apply AML and CFT programmes at group level, including for branches and majority-owned subsidiaries, as the RBI Directions require.

What This Article Does Not Cover

This article covers the laws and regulatory instruments that apply to authorised persons. It does not recommend a control-by-control compliance manual, nor does it restate each institution’s own establishing statute or its developmental mandate, except where they bear on the AML duties. For implementation, an authorised person shall separately document customer acceptance, KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction reporting, staff training, audit testing and board reporting. Those controls are the subject of the companion compliance guide.

To see how the authorised person framework fits within the sector, see AML laws and regulations for financial institutions in India, and to place it within the national picture, see AML laws and regulations in India.

From Regulation to Compliance: Your Next Step

Knowing the law is only the first step. These obligations only protect an institution when they are built into a working programme through risk assessment, policy and procedure, customer due diligence, monitoring, screening, reporting, training and independent review. For an authorised person, customer identification at the point of exchange or remittance payout, monitoring for structuring, and sanctions screening are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.

Want to confirm the 2025 directions for your institution?

AML India can walk you through the RBI authorised person KYC Directions and build a proportionate programme for all money movement services.

Frequently Asked Questions

A money changer, authorised dealer, offshore banking unit or other person authorised by the RBI under section 10 of FEMA to deal in foreign exchange, and it includes the agents of the money transfer service scheme who pay out inbound cross-border personal remittances. An authorised person is a reporting entity under the PMLA, named within the financial-institution definition, and does not take deposits from the public.

Yes. An authorised person is a reporting entity under section 2(1)(wa) of the PMLA because it is a financial institution within section 2(1)(l), which takes its meaning from section 45-I of the RBI Act, 1934. No separate notification is needed; an authorised person is inside the regime by virtue of what it is.

The RBI KYC Directions, 2025, issued on 28 November 2025 and updated as on 29 December 2025, applied to an authorised person through the Master Direction on Money Changing Activities and the Master Direction on the Money Transfer Service Scheme, and reinforced by the RBI circular to all authorised persons on compliance with KYC norms dated 28 November 2025.

Yes, and it is central to the business. A money changer or remittance agent deals directly with individual walk-in customers, so customer identification at the point of exchange or payout, watching for structuring below thresholds and screening against sanctions lists are the front-line controls. Where a customer is a company or acts on behalf of another, beneficial owner identification also applies.

Cash transaction reports for cash transactions of Rupees 10 lakh or more, suspicious transaction reports of any value, counterfeit currency reports and, for cross-border remittance activity under the MTSS, cross-border wire transfer reports of Rupees 5 lakh or more. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly, through FINnet 2.0.

Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every authorised person. An authorised person screens customers and beneficial owners against the United Nations and domestic designated lists and freezes and reports any match.

Official sources and review

Why work with AML India

AML India helps authorised persons meet their PMLA and RBI obligations, from risk assessment and policy development to CDD, screening, monitoring, report filing, staff training and independent review.

Industries we serve: Authorised Persons, NBFCs, Housing Finance, Mortgage Guarantee and Asset Reconstruction Companies, Insurers, Payment System Operators and Aggregators, Banks, DNFBPs, Securities Intermediaries and IFSC and GIFT City entities.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik