Last Updated  on: 21st August 2026       |        Last Reviewed on: 21st August 2026

Key Takeaways Briefly

  • Who is covered: depositdsories registered under the Depositories Act, 1996 and the SEBI (Depositories and Participants) Regulations, 2018, and, through them, their depository participants, as reporting entities under the PMLA.
  • Why they are caught: a depository is an intermediary registered under section 12 of the SEBI Act and so falls within section 2(1)(n) of the PMLA, making it a reporting entity under section 2(1)(wa). No section 2(1)(sa) designation is needed.
  • Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the SEBI Master Circular for Depositories, the SEBI AML/CFT Guidelines, 2024 and the SEBI KYC Master Circular; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
  • Supervisor: The Securities and Exchange Board of India (SEBI). Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
  • Core duties: an internal risk assessment, oversight of participant due diligence, beneficial-owner records, monitoring of demat accounts and transfers, prescribed-transaction reporting, five-year record-keeping and sanctions screening.

This guide is general information on Indian law, not legal advice. For your firm’s specific position, speak to a qualified AML professional.

Depositories are reporting entities under the Prevention of Money-Laundering Act, 2002. A depository holds securities in dematerialised form and enables their transfer, operating through depository participants who open and maintain the demat accounts of investors. Its AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the SEBI Master Circular for Depositories, the SEBI AML/CFT Guidelines for securities market intermediaries, the SEBI KYC Master Circular, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework. SEBI supervises depositories, and reports are filed with FIU-IND. This guide sits within the wider set of guides for securities market intermediaries.

The core instruments at a glance

Instrument 

What it does for a depository 

PMLA, 2002 

The parent Act. Brings the depository in as an intermediary and creates the duties of due diligence, record-keeping and reporting. 

PML (Maintenance of Records) Rules, 2005 

Set out what to report and when, how account holders and beneficial owners are identified, and the duty to appoint officers. 

SEBI Master Circular for Depositories 

The consolidated conduct rulebook for depositories, into which the KYC and AML obligations are read. 

SEBI AML/CFT Guidelines (6 June 2024) 

The working AML rulebook for every securities market intermediary, including depositories and their participants. 

UAPA Section 51A and WMD Act Section 12A 

Impose targeted financial sanctions for terrorism and proliferation financing. 

FATF Recommendations 9 to 23 

The international preventive-measure standards for financial institutions that India’s framework is built to meet. 

What Counts as a Depository in India?

A depository is an entity registered unsdsdder the Depositories Act, 1996 and regulated by SEBI under the SEBI (Depositories and Participants) Regulations, 2018. It holds securities of investors in electronic, dematerialised form and enables their transfer from one account to another. It operates through depository participants, which are the agents that open and maintain the demat accounts of beneficial owners and act as the interface between the investor and the depository. India’s depositories hold the central record of who beneficially owns dematerialised securities, so the depository sits at the heart of the ownership infrastructure of the securities market.

The money laundering risk of a depository is a demat account and ownership transfer risk. It sits in the demat accounts opened through participants, where benami or mule accounts can be used to hold securities in the name of others; in off-market transfers, which move ownership of securities between accounts without a market trade and can be used to layer value or disguise control; in the pledging and unpledging of securities; and in the accuracy of the central beneficial owner record. Because participants onboard the account holders, the depository’s role is to set the standards, oversee participant compliance, and use its central position to detect suspicious transfer patterns.

Are Depositories Reporting Entities Under the PMLA?

Yes. Depositories are reporting entities under the Prevention of Money-Laundering Act, 2002. Section 2(1)(wa) defines a reporting entity to include an intermediary, while section 2(1)(n) covers intermediaries associated with the securities market that are registered under section 12 of the SEBI Act, 1992, which takes in a depository. A depository is therefore a reporting entity by virtue of its registration; no notification under section 2(1)(sa) is needed, and the depository participants carry their own reporting entity duties.

This places a depository in the same broad category of reporting entities that file with FIU-IND as banks and other intermediaries, and within the wider AML laws and regulations for intermediaries in India. The obligations are calibrated to the depository’s central role, but the reporting entity status is not optional.

Supervisory authority for depositories in India

The Securities and Exchange Board of India is the supervisory authority for depositories. It registers and regulates them under the Depositories Act, 1996 and the SEBI (Depositories and Participants) Regulations, 2018, prescribes the regulatory framework applicable to their operations, and supervises their compliance. The SEBI Master Circular for Depositories serves as the consolidated rulebook governing depository operations and conduct. Its AML, CFT and CPF requirements are drawn from the SEBI master circular on AML Standards and CFT Obligations of Securities Market Intermediaries, dated 6 June 2024, read alongside the SEBI Master Circular on KYC Norms for the Securities Market. Together, these instruments translate the participant oversight, beneficial owner record, monitoring and reporting duties into the language of a depository.

The Financial Intelligence Unit – India receives, analyses and disseminates the reports a depository files, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. In short, SEBI sets and inspects the rules, FIU-IND receives the intelligence, and the ED enforces the criminal law.

Onboarding clients without a documented due-diligence process?

AML India can put client due diligence, beneficial-ownership checks and suspicious-transaction reporting in place for your practice, keeping you audit-ready without slowing your engagements down.

AML Regulatory Requirements for Depositories in India

The legal framework governing depositories does not sit within a single statute or regulatory instrument. It is layered across multiple sources and is best understood through the structure of core legislation, overarching obligations, miscellaneous official reports and guidance, sectoral regulator and its instruments, international standards, and allied laws.

Core Legislation

The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into three sets.

AML Legislation

Prevention of Money-Laundering Act, 2002 (PMLA)

The parent anti-money laundering law. It establishes the offence of money laundering and sets out the core obligations applicable to reporting entities, including client due diligence under Section 11A and record keeping under Section 12. A depository falls within the definition of a reporting entity through the definition of “intermediary” under section 2(1)(n). Accordingly, the PMLA applies directly to depositories, with its obligations implemented in a manner proportionate to the nature, scale and risks of the depository business.

The PML (Maintenance of Records) Rules, 2005 (PMLR)

The rules made under the PMLA set out the operational obligations for reporting entities. They prescribe what must be reported and when under Rule 3 and Rule 8, establish requirements for identification and verification of beneficial owners under Rule 9, and require the appointment of designated officers under Rule 7.

The PMLR has been amended through 31 Gazette notifications and orders, which are set out below in a legal history timeline.

The 31 PMLR Amendment Notifications, in Date Order:

Gazette notification and date 

Key change or rule touched 

G.S.R. 389(E), 24 May 2007 

This revision to the rules broadened the Rule 2 test for a suspicious transaction to reach dealings without economic rationale or bona fide purpose and those hinting at terrorism financing, recast Rule 3 for cash dealings in forged or counterfeit currency, substituted Rule 8 on furnishing information to the Director, and reduced the number of certified copies to be provide from 3 to 1 under Rule 9.  

G.S.R. 816(E), 12 November 2009 

This amendment added definitions of non-profit organisation and Regulator, restated the suspicious transaction, and required reporting of NPO receipts over Rupees 10 lakh. Under Rule 6 it set ten-year record retention, and it revised Rule 9 to require beneficial owner identification, ongoing due diligence, a ban on anonymous accounts and a Client Identification Programme. 

G.S.R. 76(E), 12 February 2010 

Revised Rules 3, 4, 5, 7 and 9 to strengthen record keeping requirements and reporting cross-references. Most notably, it inserted the first Explanation to Rule 9(1A), defining the beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction is conducted. 

G.S.R. 508(E), 16 June 2010 

Revised Rules 2, 9 and 10, clarifying transaction monitoring, the identification of beneficial owners, and the responsibilities of reporting entities when suspicion arises in relation to a transaction or customer. 

G.S.R. 980(E), 16 December 2010 

Inserted the small-account regime, defining the Designated Officer and the small account, adding the NREGA job card and the Aadhaar letter to the officially valid documents in Rule 2, and inserting Rule 9(2A) on how such an account is opened and monitored. 

G.S.R. 481(E), 24 June 2011 

Amended Rule 1 to condense the long 2005 name into the Prevention of Money-Laundering (Maintenance of Records) Rules, the PMLR shorthand used since. 

G.S.R. 576(E), 27 August 2013 

Amended Rules 2 and 3 and added provisions after Rule 10, addressing definitions, the cash and suspicious transaction reporting duties and the record keeping framework, so they matched the reporting obligations. 

G.S.R. 288(E), 15 April 2015 

Revised various Rule 2 definitions in accord with changing market and risk towards reporting entities.   

G.S.R. 544(E), 7 July 2015 

Revised Rules 2, 9, 10 and inserted Rule 9A updating provisions on definitions, customer due diligence and record-keeping. The amendments refined how reporting entities identify customers and maintain records.  

G.S.R. 730(E), 22 September 2015 

Added an explanation under Rule 2, addressing the name change issue after marriage regarding the officially valid document and authorising marriage certificate as valid.  

G.S.R. 882(E), 18 November 2015 

Amended the timeline for central government under Rule 9A clause 1 for incorporation of central KYC records registry.  

G.S.R. 347(E), 12 April 2017 

Revised Rule 2 and inserted Rule 9B, formally introducing the Central KYC Records Registry into the Rules. The amendment established the obligation to centrally file customer KYC records and enabled their reuse, laying the foundation for today’s CKYCR framework. 

G.S.R. 538(E), 1 June 2017 

Revised Rules 2 and 9 to issued Aadhaar into customer due diligence, prescribing Aadhaar-based identification and authentication for KYC, an approach the Supreme Court’s Aadhaar ruling later reshaped. 

G.S.R. 1038(E), 21 August 2017 

Revised Rule 2 definitions, updating the defined terms that govern how the operative rules apply, among several definition changes in 2017. 

G.S.R. 1318(E), 23 October 2017 

An amendment specifically for foreign nationals and their officially valid documents acceptance for AML compliance.  

G.S.R. 456(E), 16 May 2018 

Added a clause under Rule 9 requiring guidelines to be issued sector specifically and formation of CCD programme by all the reporting entities.  

G.S.R. 1078(E), 31 October 2018 

Substituted the timeline for filing electronic records on the registry from 3 days to 10 days under Rule 9. 

G.S.R. 108(E), 13 February 2019 

Updated definitions and ways of customer identification under Rules 2 and 9 to incorporate legislative changes to Aadhaar use. 

G.S.R. 381(E), 28 May 2019 

sharpened the identification and verification process and the routes to confirm a customer’s identity under Rule 9 part of the post-Aadhaar reshaping of CDD. 

G.S.R. 582(E), 19 August 2019 

Revised Rules 2 and 9 and inserted annexure after Rule 11, covering definitions, customer due diligence and the supporting provisions on information and records registry. 

G.S.R. 669(E), 18 September 2019 

Inserted depository receipts definition under Rule 2 and sharpened the customer due diligence process in dealing with depository receipt under Rule 9.  

G.S.R. 840(E), 13 November 2019 

Amended Rule 9 to make further updates to customer identification and verification requirements, bringing the 2019 series of CDD amendments to a close. 

G.S.R. 228(E), 31 March 2020 

Revised the operational timeline for small accounts for the year 2020 and any further period notified by the Central Government. 

G.S.R. 251(E), 13 April 2020 

Amended Rule 8, which governs the submission of transaction reports to the FIU, clarifying how and when reports must be furnished. Th amendment tweaked the timeline for the submission.  

G.S.R. 254(E), 16 April 2020 

A consecutive change in Rule 8 regarding timeline for prescribed transaction reporting. 

G.S.R. 798(E), 28 December 2020 

A landmark expansion of the regime. It introduced the activity based triggers under which DNFBPs i.e., dealers in precious metals and stones (DPMS) and real estate agents become subject to the PMLA framework, while also identifying their respective regulatory authorities. 

G.S.R. 575(E), 13 July 2022 

Inserted the International Financial Services Centre definition with a tailored beneficial owner provision for IFSC entities and added an IFSC proviso to Rule 9A on the CKYCR, aligning the Rules with the GIFT City regime, of note for a depository serving IFSC issuers and holders. 

S.O. 1074(E), 7 March 2023 

A major amendment under Rule 2 inserting definitions of politically exposed persons, group and non-profit organisations. added Rule 3A duty for group-wide AML policies and reduced the company beneficial ownership threshold from 25 to 10 per cent, with a matching change to Rule 9(3)(e), of direct relevance to a depository overseeing the beneficial ownership behind corporate demat account holders. 

G.S.R. 652(E), 4 September 2023 

The second major 2023 amendment. It mandated the Principal Officer to be at the management level, reduced the partnership beneficial ownership threshold from 15 to 10 per cent, added an Explanation of control, required trustees to disclose their status, and added the results of any Rule 3 and Rule 9 analysis to the maintained records, all of which bear on identifying who controls a non-individual demat account. 

G.S.R. 745(E), 17 October 2023 

Updated definitions, reporting obligations and customer due diligence requirements and coordinated those changes amongst Rules 2, 3, 8 and 9. 

G.S.R. 419(E), 19 July 2024 

Amended Rule 9(1C) on the KYC Identifier and set deadline of 7days for updating a CKYCR record after any change, also added a duty to fetch the updated record on reporting entities revised Rule 9A(2)(g) on filing, retrieving and using registry records, sharpening how current central KYC data is stored and reused. 

The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005

These Rules govern the acceptance of client records authenticated outside India and are relevant where a depository onboards non-resident clients or foreign portfolio investors. They provide the framework for relying on identification executed or authenticated abroad as part of the client onboarding and verification process.

CFT Legislation

The Unlawful Activities (Prevention) Act, 1967 (UAPA)

The counter terrorism law. Section 51A of the Act requires a depository to screen clients against the designated lists and to freeze, without delay, the funds and securities of listed persons and entities. The duty binds every depository, whatever its nature and size.

Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023 and 29 August 2023)

The procedure a depository follows to apply Section 51A, including how to act on a designated list match. The SEBI guidelines fold these steps into the depository to an issue’s screening and freezing controls.

CPF Legislation

The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)

The proliferation financing law. Section 12A of the Act provides the legal basis for targeted financial sanctions relating to the financing of weapons of mass destruction and applies to depositories alongside banks and financial institutions.

Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)

The procedure for applying Section 12A mirrors the screening and freezing steps that Section 51A sets for terrorism financing.

The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016

Rules implementing the WMD Act support India’s counter-proliferation financing framework and set out measures reporting entities must follow. Depositories align their operations with these requirements, particularly to sanctions screening.

Not registered with FIU-IND yet, or unsure whether you have to be?

AML India can confirm whether your firm qualifies as a reporting entity under the PMLA, complete your goAML registration and appoint your principal officer and designated director.

Overarching Obligations

The cross-cutting systems and procedures that sit above any single regulator and carry a depository’s KYC data and reports.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

These guidelines provide for the functions and duties of the reporting entities and the central registry that stores client KYC records for reuse across the financial system. A depository files client KYC data to the CKYCR, retrieves an existing record on onboarding, and updates it within the prescribed window when details change, cutting duplicate paperwork for investors.

FINnet 2.0 Reporting Formats (2024) and the FINGate 2.0 User Manuals

The instruments define the electronic formats and the gateway through which a depository files its cash, suspicious and other prescribed reports to FIU-IND, in the current FINnet 2.0 and FINGate 2.0 environment.

eKYC and Section 11A Aadhaar Authentication for the Securities Market

SEBI’s circular on the eKYC authentication facility under Section 11A of the PMLA enables depositories to use Aadhaar-based authentication for eligible resident clients, subject to the statutory framework and Supreme Court limits.

Sectoral

The regulator and the instruments it issue. This is the sector-specific layer, and the SEBI Master Circular for Depository and the SEBI AML/CFT Guidelines are the instruments a depository works from most closely.

Securities and Exchange Board of India (SEBI)

SEBI Master Circular for Depository

The principal regulatory instrument governing depositories. It consolidates the operational and conduct requirements applicable to depositories, including registration, net worth, reporting and maintenance of ownership records. Under paragraph 1.1.5.3, it specifically requires depositories to comply with SEBI AML/CFT guidelines for securities market intermediaries. Although the master circular refers to the 3 February 2023 AML/CFT guidelines, that instrument has been superseded by SEBI’s June 2024 guidelines. Accordingly, the reference must be read as referring to the latest 2024 guidelines.

SEBI Guidelines on AML Standards and CFT Obligations of Securities Market Intermediaries (6 June 2024)

The working AML rulebook for every SEBI-registered intermediary, updated on 6 June 2024. It carries the client identification, risk categorisation, beneficial ownership verification, ongoing monitoring, record keeping, reporting and sanctions screening requirements into the securities market, and it replaces the last 2023 guidelines. For a depository, it is the source of the detailed AML duties that sit alongside the conduct rulebook.

SEBI Master Circular on KYC Norms for the Securities Market (12 October 2023)

The consolidated KYC framework for the securities market, read alongside 12 October 2023 modification circular and the subsequent clarification on the use of technology for KYC. Together, these instruments set out how depositories identify and verify clients, maintain KYC records, and rely on the KYC Registration Agencies framework.

eKYC, KYC clarification circulars and SEBI FAQs

SEBI’s circular on the eKYC authentication facility under Section 11A, its clarification on the use of technology for KYC and the FAQs on KYC norms provide practical guidance on digital client onboarding, technology-enabled verification and the maintenance of KYC records by depositories and other securities market intermediaries.

Miscellaneous

Official reports and guidance that are not binding rules but shape how a depository reads its risk and the wider enforcement picture.

FIU-IND Annual Report 2024-25

The Financial Intelligence Unit’s annual account of reporting volumes, typologies and enforcement trends, useful for a depository to calibrate what unusual client or trading activity looks like across the market.

Directorate of Enforcement Annual Report 2025-26

The ED’s annual overview of the investigations, attachments and prosecutions conducted under PMLA. It provides insights into how the criminal enforcement side of India’s AML regime operates in practice.

FIU-IND and its Core Functions and FAQs

This instrument provides the unit’s role and core functions. The FAQ provides a simply understandable explanation to reporting entities on registration and reporting expectations.

MHA National Counter Terrorism Policy and Strategy

The Ministry of Home Affairs statement of national counter terrorism policy provides for broader policy context for the UAPA-related sanctions and counter terrorism obligations that depositories are required to implement.

International Standards

The global standards India’s framework is built to meet, and against which a depository’s controls are ultimately judged.

FATF Recommendations

These Recommendations are the international baseline for AML, CFT and CPF frameworks and have informed the development of India’s regime. Recommendations 9 to 23 set out preventive measures applicable to financial institutions and intermediaries, while Recommendation 6 was updated in June 2026 to strengthen the framework for targeted financial sanctions.

FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)

The peer assessment of India’s AML and CFT regime found the country largely compliant, while also identifying key gaps and areas for improvement. Its findings set the direction for ongoing reforms and continue to shape the supervision of depositories and other securities intermediaries.

IOSCO Objectives and Principles of Securities Regulation

The International Organisation of Securities Commissions standards provide a global benchmark for securities regulations. SEBI’s regulatory, conduct and AML expectations for depositories and other securities intermediaries are designed to align with these principles.

Basel Committee, Sound Management of Risks Related to Money Laundering and Financing of Terrorism (2014, revised July 2020)

This guidance serves as the supervisory benchmark for embedding effective AML risk management. Although developed primarily for banks, its principles can inform a depository’s AML risk management framework.

Allied Laws

The supporting body of law that defines the securities statutes, offences and enforcement machinery around money laundering. A depository operates under the securities statutes, while the predicate and enforcement Acts shape the risk it must assess and the conduct it may need to report.

These allied laws place a depository’s AML obligations within the wider legal, regulatory and enforcement framework governing India’s securities market.

The Securities and Exchange Board of India Act, 1992, the Securities Contracts (Regulation) Act, 1956, and the Depositories Act, 1996 establish the regulatory and operational framework within which depositories function, while the Companies Act, 2013 and the Foreign Exchange Management Act, 1999 are relevant to corporate ownership, beneficial ownership, securities holdings and cross-border investment.

The Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974, the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003 all this laws identify the underlying criminal, finanacial sanctions-related risks that may generate proceeds of crime or be linked to the misuse of securities accounts.

Together, they help explain the border sources of criminal and financial risk that may enter the securities system and reinforce the need for effective monitoring, sanctions screening, suspicious transaction reporting and accurate ownership record.

Core AML/CFT/CPF Obligations for Depositories in India

Across that framework, the regulations require a depository to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.

  • Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the depository can file its reports.
  • Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR and the SEBI Guidelines. The same person cannot hold both roles, and both are to be informed to FIU-IND and, where applicable, SEBI.
  • Conduct the internal risk assessment. Run an ML and TF risk assessment across clients, products, channels and geographies, document it, and take its outcome to the board, as the SEBI AML/CFT Guidelines require.
  • Document AML policy, controls and procedures. Adopt a board-approved policy that turns the risk assessment into the depository’s operating procedures.
  • Client identification and CDD. Identify and verify every client and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high-risk clients, under Section 11A of the PMLA, Rule 9 of the PMLR and the SEBI KYC Master Circular. Given the depository business, overseeing that participants carry out proper account holder due diligence, maintaining an accurate central beneficial owner record, and monitoring off-market transfers and demat activity are central.
  • Ongoing monitoring and periodic updates. Monitor demat account activity and off-market transfers on an ongoing basis, oversee participant KYC refresh at least once every 2, 8 and 10 years for high, medium and low-risk holders respectively, and review risk categorisation periodically.
  • Sanctions screening. Screen clients and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
  • Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, non-profit organisation receipt reports and counterfeit currency reports under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly once the Principal Officer is satisfied, through FINnet 2.0.
  • Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload client KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
  • Training and awareness. Train staff by role to apply the controls and recognise red flags in a depository, such as benami or mule demat accounts opened through participants, off-market transfers that move ownership without a market trade, and clusters of accounts or transfers linked to one controller.
  • Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
  • Run group-wide controls. Where the depository is part of a group, apply AML and CFT programmes at group level, including for subsidiaries, as the SEBI Guidelines require.

What This Article Does Not Cover

This article explains the laws and regulatory instruments applicable to depositories and their AML, CFT and CPF obligations. It does not provide a control-by-control compliance manual, nor does it restate the Depositories Act or the SEBI (Depositories and Participants) Regulations except where they bear on the AML duties. For implementation, a depository separately documents and operationalises controls relating to participant oversight, the central beneficial owner record, off-market transfer monitoring, sanctions screening, suspicious transaction reporting, staff training, audit testing and board reporting. Those controls are the subject of the companion compliance guide.

To see how the depository framework fits within the sector, see AML laws and regulations for intermediaries in India, and to place it within the national picture, see AML laws and regulations in India.

From Regulation to Compliance: Your Next Step

The legal obligations can only protect depositories when they are translated into an effective compliance programme of risk assessment, policy and procedure, participant oversight, ongoing monitoring, sanctions screening, reporting, training and independent review. For a depository, overseeing participant due diligence, maintaining an accurate beneficial owner record and monitoring off-market transfers are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.

Want to confirm what the SEBI framework means for your firm?

AML India can walk you through the SEBI Master Circular for Depositories and the AML/CFT Guidelines and build a proportionate participant oversight and transfer monitoring programme for your depository business.

Frequently Asked Questions

An entity registered under the Depositories Act, 1996 and the SEBI (Depositories and Participants) Regulations, 2018 that holds securities in dematerialised form and enables their transfer, operating through depository participants who maintain investors’ demat accounts. A depository is an intermediary and a reporting entity under the PMLA.

Yes. A depository is an intermediary associated with the securities market and registered under section 12 of the SEBI Act, so it falls within section 2(1)(n) and is a reporting entity under section 2(1)(wa).

The SEBI Master Circular for Depositories is the consolidated conduct rulebook, read with the SEBI AML/CFT Guidelines for Securities Market Intermediaries of 6 June 2024 and the SEBI Master Circular on KYC Norms for the Securities Market of 12 October 2023. Together, they carry the AML and KYC duties into the depository business.

Depository participants open and maintain investors’ demat accounts, so they carry out the front-line account holder KYC. The depository sets the standards, oversees participant compliance, holds the central record of beneficial ownership, and uses its central position to detect suspicious patterns such as off-market transfers or clusters of accounts under one controller. Both are reporting entities in their own right.

Suspicious transaction reports of any value, cash transaction reports where cash above Rupees 10 lakh is involved, non-profit organisation receipt reports and counterfeit currency reports. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly once the Principal Officer is satisfied, through FINnet 2.0.

Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every depository. A depository screens account holders and their beneficial owners against the United Nations and domestic designated lists and acts according to its procedure on any match without delay.

Official sources and review

Why work with AML India

AML India helps regional rural banks and other bank types meet their PMLA and RBI obligations, from risk assessment and policy through to CDD, screening, monitoring, reporting, training and independent review.

Industries we serve: regional rural banks, commercial banks, small finance banks, cooperative banks, local area banks, payments banks, NBFCs, insurers, DNFBPs and securities intermediaries.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik