Last Updated  on: 25th August 2026       |        Last Reviewed on: 25th August 2026

Key Takeaways at a Glance

  • Who is covered: securities market intermediaries of every kind, from credit rating agencies, custodians, depositories, foreign institutional investors, investment advisers, pension intermediaries, merchant bankers, mutual funds, portfolio managers, registrars to an issue, share transfer agents, stock brokers, stock exchanges, trustees to a trust deed and underwriters, as reporting entities under the PMLA.
  • Why they are caught: an intermediary is the third limb of the reporting-entity definition in section 2(1)(wa) of the PMLA, read with section 2(1)(n), which brings in intermediaries registered under section 12 of the SEBI Act, pension intermediaries registered with the PFRDA, and recognised stock exchanges. No section 2(1)(sa) designation is needed.
  • Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the SEBI AML/CFT Guidelines for Securities Market Intermediaries, 2024 and the SEBI KYC Master Circular; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
  • Supervisors: the Securities and Exchange Board of India (SEBI) for securities intermediaries, and the Pension Fund Regulatory and Development Authority (PFRDA) for pension intermediaries. Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
  • Core duties: an internal risk assessment, client due diligence and KYC, beneficial-owner identification, periodic updates, monitoring, prescribed-transaction reporting, five-year record-keeping and sanctions screening.

This guide is general information on Indian law, not legal advice. For your firm’s specific position, speak to a qualified AML professional.

Intermediaries operating in India’s securities and pension markets are reporting entities under the Prevention of Money-Laundering Act, 2002. The framework covers credit rating agencies, custodians, depositories, foreign institutional investors, investment advisers, pension intermediaries, merchant bankers, mutual funds, portfolio managers, registrars to an issue, share transfer agents, stock brokers, stock exchanges, trustees to a trust deed and underwriters.

Their AML, CFT and CPF obligations arise primarily from the PMLA, the PML (Maintenance of Records) Rules, 2005, the SEBI AML/CFT Guidelines for securities market intermediaries, the SEBI KYC Master Circular, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting requirements. The Securities and Exchange Board of India supervises the securities intermediaries, the PFRDA supervises the pension ones, and prescribed reports are filed with FIU-IND.

Introduction

Understand the common AML, CFT and CPF framework that applies across India’s securities and pension market intermediaries. If you need the detailed rulebook for one type, use the guide for credit rating agencies, custodians, depositories, foreign institutional investors, investment advisers, pension intermediaries, merchant bankers, mutual funds, portfolio managers, registrars to an issue, share transfer agents, stock brokers, stock exchanges, trustees to a trust deed and underwriters. This page explains the law, not how to apply it daily, while the companion compliance guide covers the controls.

An intermediary stands between an investor and the market, executing, advising, holding, registering, rating or settling securities transactions. That position, at the point where investor money enters and moves through the capital markets, is exactly what the law asks each intermediary to guard, which is why a defined set of anti money laundering duties sits on every registered intermediary, scaled to its size and risk. This is a sector level overview: it covers what is common to all intermediaries and then routes you to the rules for your specific type, and it sits within the wider AML laws and regulations framework in India.

What The Intermediaries Sector Covers and Why It Is Regulated for AML

The intermediaries sector spans the registered firms that make the securities and pension markets work. It includes stock brokers and the stock exchanges they trade on; portfolio managers and investment advisers; merchant bankers and underwriters who bring issues to market; mutual funds and their asset management companies; registrars to an issue and share transfer agents; custodians and depositories that hold and settle securities; credit rating agencies; foreign portfolio investors; trustees to a trust deed including debenture trustees; and the pension intermediaries that operate the National Pension System. They differ in function, yet each is registered with a market regulator, and each is a reporting entity under the anti money laundering law.

Intermediaries are regulated for AML because the securities markets might act as a natural medium for the layering and integration of illicit funds. Trades can be structured to move value, securities can be bought and sold to disguise ownership, and investment products can absorb and return money in a clean form.

The law therefore asks each intermediary to know its clients, understand the beneficial owners behind them, watch how funds and securities move and report suspicious or prescribed transactions, so that the stages of money laundering can be detected wherever they touch the market.

Are Intermediaries Reporting Entities under the PMLA?

Yes. The Prevention of Money-Laundering Act, 2002, known as the PMLA, is India’s parent anti money laundering law. It creates the offence of money laundering and imposes core duties on reporting entities. Under section 2(1)(wa), a reporting entity includes a banking company, a financial institution and an intermediary. Section 2(1)(n) then defines an intermediary to include a stock broker, sub broker, share transfer agent, banker to an issue, trustee to a trust deed including debenture trustees, registrar to an issue, merchant banker, underwriter, portfolio manager, investment adviser and any other intermediary associated with the securities market and registered under section 12 of the SEBI Act, 1992, together with pension intermediaries registered with the PFRDA and recognised stock exchanges.

This is a different route into the regime from the financial institutions, which enter through section 2(1)(l), and from the designated non financial businesses and professions, which are brought in by notification under section 2(1)(sa). An intermediary is inside the regime from the moment it registers with its market regulator, which is why AML compliance is a standing condition of a SEBI or PFRDA registration and why registered intermediaries make up a large share of the reporting entities that file with FIU-IND.

Supervisory Authority for Intermediaries in India

Intermediaries are supervised chiefly by the Securities and Exchange Board of India, which registers them, sets the AML rules they work from and inspects their compliance. The central AML instrument is the SEBI Guidelines on AML Standards and CFT Obligations of Securities Market Intermediaries, updated on 6 June 2024, read with the SEBI Master Circular on KYC Norms for the Securities Market and each intermediary type’s own Master Circular. The Pension Fund Regulatory and Development Authority plays the same role for the pension intermediaries that run the National Pension System, issuing AML and KYC guidance for that segment.

Whatever the supervisor, the destination of the reports is common. Every intermediary files its cash, suspicious transaction and other prescribed reports with the Financial Intelligence Unit – India, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. In short, the market regulator sets and inspects the rules for its intermediaries, FIU-IND receives the intelligence, and the ED enforces the criminal law.

Not sure which SEBI or PFRDA instrument binds your firm?

Intermediaries carry different registrations and regulators. Talk to an AML consultant if you would like help confirming the framework that applies to your intermediary.

AML Regulatory Requirements for Intermediaries in India

Read this framework as the intermediaries sector’s common legal basis; the structure is shared across intermediary types, while the SEBI or PFRDA instrument that applies differs by registration. The law that governs intermediaries is a layered framework and consists of the core legislation, the overarching obligations, the sectoral regulators and their instruments, the miscellaneous official reports, the international standards, and the allied laws.

The framework reads from the core outward. The PMLA is the parent Act; the PML Rules turn it into operational duties; the SEBI and PFRDA instruments translate both into instructions an intermediary can follow; the UAPA and the WMD Act add counter terrorism and proliferation financing sanctions; and the allied laws, including the securities statutes, shape the risk. The risk based approach is to be undertaken by all.

Core Legislation

The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into the three categories.

AML Legislation

Prevention of Money-Laundering Act, 2002 (PMLA)

The parent anti money laundering law. It creates the offence of money laundering and the core duties on reporting entities, including client due diligence under Section 11A and record-keeping under Section 12. An intermediary is a reporting entity by virtue of the definition in section 2(1)(n), so the Act applies to all intermediaries.

The PML (Maintenance of Records) Rules, 2005 (PMLR)

The rules made under the PMLA. Rule 3 and Rule 8 set what to report and when, Rule 9 defines how to identify clients and beneficial owners, and Rule 7 sets the duty to appoint officers. For an intermediary, the relevant Regulator named in Rule 2(1)(fa) is SEBI or the PFRDA. The PMLR has been amended through 31 Gazette notifications and orders, set out below as a legal history timeline.

The 31 PMLR Amendment Notifications, in Date Order:

Gazette notification and date 

Key change or rule touched 

G.S.R. 389(E), 24 May 2007 

Expanded the definition of a suspicious transaction under the PML Rules, 2005 to cover transactions lacking an economic rationale or having links to terrorist financing. It also extended reportable cash transactions to include forged currency and documents, specified reporting timelines for submissions to the Director, and reduced the requirement for certified copies in certain filings from three copies to one. 

G.S.R. 816(E), 12 November 2009 

Introduced definitions for non-profit organisation and Regulator, while broadening the scope of suspicious transactions to cover those involving unusual complexity, a lack of economic rationale, or connections to terrorist financing. It further mandated reporting of cash receipts exceeding ten lakh rupees by NGOs, replaced specific references to RBI, SEBI and IRDA with the term Regulator, and extended the record retention period to ten years from the transaction date. 

G.S.R. 76(E), 12 February 2010 

Reinforced the provisions relating to record keeping and reporting under Rules 3, 4, 5 and 7 of the PML Rules, 2005. It also inserted the first Explanation to Rule 9(1A), clarifying that the beneficial owner is the natural person who ultimately owns or controls a client or on whose behalf a transaction is conducted. 

G.S.R. 508(E), 16 June 2010 

Modified Rules 2, 9 and 10 of the PML Rules, 2005 concerning definitions, customer due diligence and record keeping. These amendments strengthened customer identification procedures and requirements for preserving records by reporting entities as part of the 2010 reforms to the CDD and record-keeping framework. 

G.S.R. 980(E), 16 December 2010 

Established the small account framework by introducing definitions for Designated Officer and small account. It also expanded the list of officially valid documents under Rule 2 to include the NREGA job card and Aadhaar letter and inserted Rule 9(2A), which prescribed conditions and procedures for opening and monitoring small accounts. 

G.S.R. 481(E), 24 June 2011 

Renamed the PML Rules, 2005 through an amendment to Rule 1 by introducing the short title Prevention of Money Laundering Maintenance of Records Rules and replacing the earlier longer title. This established the abbreviated PMLR reference used subsequently. 

G.S.R. 576(E), 27 August 2013 

Established the definition of Designated Director under Rule 2 and revised Rules 3, 7, 8, 9 and 10 of the PML Rules, 2005. The amendments enhanced reporting requirements, governance arrangements, customer due diligence measures and record keeping obligations. 

G.S.R. 288(E), 15 April 2015 

Specified the documents recognised as officially valid documents for the purposes of customer identification under the PML Rules, 2005. 

G.S.R. 544(E), 7 July 2015 

Established the definition of Central KYC Records Registry and amended Rules 9 and 10 of the PML Rules, 2005 by introducing additional provisions to strengthen the KYC framework. The amendments also supported the centralised collection, maintenance and management of KYC records for reporting entities. 

G.S.R. 730(E), 22 September 2015 

Revised several definitions under Rule 2 and introduced corresponding amendments across the PML Rules, 2005 to align the regulatory framework with evolving KYC requirements. The changes helped provide greater clarity on key terms and strengthened the application of customer identification and due diligence requirements. 

G.S.R. 882(E), 18 November 2015 

Extended the prescribed period under the relevant provisions of the PML Rules, 2005 from 90 days to 180 days. The amendment provided reporting entities with additional time to comply with the applicable procedural and reporting requirements within the prescribed framework. 

G.S.R. 347(E), 12 April 2017 

Introduced the definition of Regulator and inserted Rule 9B to further strengthen the customer due diligence framework under the PML Rules, 2005. The amendment also provided additional regulatory provisions relating to the identification and verification of customers. 

G.S.R. 538(E), 1 June 2017 

Revised Rules 2 and 9 of the PML Rules, 2005 by introducing additional provisions to enhance the operational AML framework. The changes further developed the requirements relating to customer identification, due diligence and compliance procedures applicable to reporting entities. 

G.S.R. 1038(E), 21 August 2017 

Updated the definitions under Rule 2 of the PML Rules, 2005 by introducing additional provisions to clarify and refine key terms used within the regulatory framework. These changes helped improve consistency in the interpretation and implementation of the applicable AML and KYC requirements. 

G.S.R. 1318(E), 23 October 2017 

Further revised Rule 2 by introducing a proviso concerning the acceptance and treatment of officially valid documents. The amendment clarified the way such documents were to be considered for customer identification and verification purposes under the PML Rules, 2005. 

G.S.R. 456(E), 16 May 2018 

Strengthened Rule 9 by introducing additional provisions requiring reporting entities to establish and implement a formal customer due diligence programme. The amendment reinforced the need for reporting entities to maintain appropriate procedures for identifying and verifying customers as part of their AML framework. 

G.S.R. 1078(E), 31 October 2018 

Extended the prescribed period under Rule 9(1A) from three days to ten days. This change provided reporting entities with additional time to complete the specified requirements within the customer due diligence framework. 

G.S.R. 108(E), 13 February 2019 

Enhanced Rule 9 through significant amendments aimed at strengthening the customer due diligence framework. The changes introduced additional requirements relating to customer identification and verification and established the foundation for subsequent amendments made to the PML Rules in 2019. 

G.S.R. 381(E), 28 May 2019 

Established a specific customer due diligence framework for prisoners opening or maintaining bank accounts. The amendment permitted the officer in charge of the jail to certify the customers signature or thumb impression and allowed such accounts to remain operational subject to the annual submission of a proof of address certificate issued by the same authority. 

G.S.R. 582(E), 19 August 2019 

Introduced digital KYC, equivalent electronic documents and offline Aadhaar verification into the PML Rules, 2005. The amendment revised Rule 9 to recognise multiple modes of customer identification and introduced a detailed digital KYC process involving live photographs, geotagging, OTP based authentication and prescribed verification procedures. 

G.S.R. 669(E), 18 September 2019 

Introduced the definition of depository receipt and streamlined customer due diligence requirements applicable to certain foreign investments. The amendment permitted reporting entities to rely on beneficial ownership requirements prescribed by notified foreign jurisdictions for specified investments. It also provided exemptions for listed companies and their subsidiaries from identifying and verifying individual shareholders or beneficial owners in certain circumstances. 

G.S.R. 840(E), 13 November 2019 

Enabled customers undergoing Aadhaar based identity verification to declare a current address that differed from the address available in the Central Identities Data Repository. The amendment permitted reporting entities to accept a self declaration of the customers current address for customer due diligence purposes, thereby simplifying the process for establishing and updating address details. 

G.S.R. 228(E), 31 March 2020 

Granted temporary relief to small accounts that were scheduled for closure due to pending customer due diligence requirements. The amendment permitted these accounts to remain operational from 1 April 2020 to 30 June 2020, with the Central Government authorised to extend the period further in view of the COVID 19 pandemic. 

G.S.R. 251(E), 13 April 2020 

Extended the deadline for reporting entities to submit prescribed transaction reports under Rule 8. The temporary relaxation allowed eligible reports to be furnished by 30 June 2020, recognising the operational difficulties faced by reporting entities during the COVID 19 pandemic. 

G.S.R. 254(E), 16 April 2020 

Clarified the categories of transaction reports eligible for the temporary extension provided under Rule 8. The amendment covered reports under Rule 3(1)(A), (B), (BA), (C) and (E) for March, April and May 2020, as well as reports under Rule 3(1)(F) for the January to March 2020 quarter, permitting their submission up to 30 June 2020. 

G.S.R. 798(E), 28 December 2020 

Notified real estate agents with an annual turnover of Rupees 20 lakh or more as persons carrying on a designated business or profession under the PMLA. This brought such real estate agents within the reporting entity framework and made them subject to the applicable AML and customer due diligence obligations. 

G.S.R. 575(E), 13 July 2022 

Established specific AML and KYC requirements for reporting entities operating in an International Financial Services Centre. The amendment designated the head of the reporting entity in India as the designated officer for IFSC entities, expanded the list of officially valid documents available to foreign nationals, introduced the definition of International Financial Services Centre into the Rules, and provided exemptions from certain Central KYC Records Registry requirements for foreign national customers of IFSC reporting entities. 

S.O. 1074(E), 7 March 2023 

Lowered the beneficial ownership threshold to 10 percent and introduced requirements for group wide AML policies. The amendment also added definitions for group, politically exposed person and non profit organisation, strengthened customer due diligence requirements applicable to legal persons and trusts, and introduced registration requirements for eligible non profit organisations 

G.S.R. 652(E), 4 September 2023 

Further strengthened the AML framework by incorporating enhanced requirements relating to beneficial ownership, group wide AML policies and customer due diligence. The amendment also addressed the definitions of group, politically exposed person and non profit organisation, expanded due diligence requirements for legal persons and trusts, and introduced registration related obligations for eligible non profit organisations. 

G.S.R. 745(E), 17 October 2023 

Enhanced customer due diligence by requiring customer identity to be verified through reliable and independent sources. The amendment also strengthened group wide AML programmes, required suspicious transaction reports to be submitted promptly once suspicion was established, and reinforced confidentiality requirements relating to AML records and reporting. 

G.S.R. 419(E), 19 July 2024 

Strengthened the Central KYC Records Registry framework by requiring reporting entities to use the KYC Identifier when retrieving customer records. The amendment also restricted requests for duplicate KYC documents to specified circumstances, introduced a seven day period for updating KYC records, and required reporting entities to retrieve, update and rely on revised customer information maintained in the Central KYC Records Registry. 

The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005

Rules for accepting client records authenticated outside India, relevant where an intermediary onboards a non resident investor or a foreign portfolio investor and must rely on documents executed abroad.

CFT Legislation

The Unlawful Activities (Prevention) Act, 1967 (UAPA)

The counter terrorism law. Section 51A requires an intermediary to screen clients against the designated lists and to freeze, without delay, the funds and securities of listed persons and entities. The duty binds every intermediary, whatever its size.

Procedure For Implementation of Section 51A Of the UAPA (Order Dated 2 February 2021; Corrigendum Dated 15 March 2023 and 29 August 2023)

The official procedure an intermediary follows to apply Section 51A, including how to act on a designated list match. The SEBI guidelines incorporate these steps into the intermediary’s screening and freezing controls.

CPF Legislation

The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)

The proliferation financing law. Section 12A provides the legal basis for targeted financial sanctions relating to the financing of weapons of mass destruction and applies to intermediaries.

Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)

The official procedure for applying Section 12A mirrors the screening and freezing steps that Section 51A sets for terrorism financing.

The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016

Rules implementing the WMD Act and supporting the proliferation financing controls that an intermediary must operate.

Overarching Obligations

The procedures that sit above any single regulator and carry an intermediary’s KYC data and reports.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

Govern the central registry that stores client KYC records for reuse across the financial system. An intermediary files client KYC data to the CKYCR, retrieves an existing record on onboarding, and updates it within the prescribed window when details change, cutting duplicate paperwork for investors.

SEBI KYC Registration Agency Regulations, 2011

Govern the KYC Registration Agencies that store and share client KYC records across SEBI-registered intermediaries. An underwriter uploads a new client’s KYC documents to a KRA, checks an incoming client’s KYC status before onboarding, and flags or updates the record when the client’s details change, so the same KYC is not repeated for every intermediary the client deals with.

FINnet 2.0 Reporting Formats (2024) and the FINGate 2.0 User Manuals

Define the electronic formats and the gateway through which an intermediary files its cash, suspicious and other prescribed reports to FIU-IND, in the current FINnet 2.0 and FINGate 2.0 environment.

eKYC and Section 11A Aadhaar Authentication for the Securities Market

SEBI’s circular on the eKYC authentication facility under Section 11A of the PMLA lets intermediaries use Aadhaar based verification for resident investors within the statutory and Supreme Court limits, giving a lawful digital onboarding route.

Sectoral

The market regulators and the instruments they issue. This is the sector specific layer, and the SEBI AML/CFT Guidelines are the instrument for SEBI regulated intermediaries, while the Master Guidelines by PFRDA are for PFRDA regulated intermediaries.

Securities and Exchange Board of India (SEBI)

SEBI Guidelines on AML Standards and CFT Obligations of Securities Market Intermediaries (6 June 2024)

The star instrument for a securities market intermediary. Updated on 6 June 2024, these Guidelines are the working AML rulebook for every SEBI registered intermediary. They carry the client due diligence, risk categorisation, beneficial ownership, ongoing monitoring, record-keeping, reporting and sanctions requirements into the language of the securities market, and they replace the earlier 2010 and 2014 master circulars. This is where an intermediary should look first for an AML rule to understand what applies to its business.

Circular on eKYC Authentication Facility Under Section 11A of PMLA, 2002 (5 November 2019)

The circular reinforces KYC and CDD policies as an integral part of the KYC that lays the foundation for an effective AML process, this includes incorporating technological innovations such as electronic signature and electronic document.

FAQs on KYC Norms

Addresses the queries that may arise on KYC norms and explains the next steps and measures to undertake.

SEBI Master Circular on KYC Norms for the Securities Market (12 October 2023)

The consolidated KYC framework for the securities market, read with the 12 October 2023 modification circular and the clarification on the use of technology for KYC, which sets how an intermediary identifies and verifies its clients and maintains their records through the KYC Registration Agencies

Per Intermediary SEBI Master Circulars and FAQs

Each intermediary type has its own SEBI Master Circular consolidating the conduct requirements for that activity, such as the Master Circular for Stock Brokers and the Master Circular for Mutual Funds.

Pension Fund Regulatory and Development Authority (PFRDA)

PFRDA AML/CFT Guidance for Pension Intermediaries

The PFRDA issues the AML and KYC guidance that binds the pension intermediaries operating the National Pension System, mirroring the PMLA duties for that segment and read with the PFRDA Act, 2013.

FAQs on AML CFT Guidelines

The FAQs simply outline the AML CFT measures that all PFRDA regulated entities must undertake.

Officially Valid Documents under PML Rules

Explicitly lists the valid documents that would support proof of address as per the Prevention of Money Laundering (Maintenance of Records) Rules, 2005.

Miscellaneous Official Reports and Guidance

Official reports and guidance that are not binding rules but shape how an intermediary reads its risk and the wider enforcement picture.

FIU-IND Annual Report 2024 to 2025

The Financial Intelligence Unit’s yearly account of reporting volumes, typologies and enforcement trends, useful for an intermediary calibrating what unusual client or trading activity looks like across the market.

Directorate of Enforcement Annual Report 2025 to 2026

The ED’s yearly summary of PMLA investigations, attachments and prosecutions, a reminder of how the criminal side of the regime operates.

FIU-IND and its Core Functions and FAQs

FIU-IND’s explanation of its own role and a set of frequently asked questions, a plain language reference on registration and reporting expectations.

MHA National Counter Terrorism Policy and Strategy

The Ministry of Home Affairs statement of national counter terrorism policy, background that frames the UAPA sanctions obligations an intermediary must apply.

International Standards

The global standards India’s framework is built to meet, and against which an intermediary’s controls are ultimately judged.

FATF Recommendations

The Financial Action Task Force’s forty Recommendations are the international baseline for AML and CFT. Recommendations In June 2026, the FATF updated Recommendation 6 on targeted financial sanctions.

FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)

The peer assessment of India’s AML and CFT regime, which found India largely compliant and set the direction of travel that continues to shape the supervision of securities market intermediaries.

Allied Laws

The wider body of law that defines the securities statutes and the predicate offences and enforcement machinery around money laundering. An intermediary operates under its own securities statute, while the predicate and enforcement Acts shape the risk it must assess and the conduct it may need to report.

The allied laws that most often bear on an intermediary’s risk are the Securities and Exchange Board of India Act, 1992 (which registers and empowers SEBI over intermediaries), the Securities Contracts (Regulation) Act, 1956 (which governs stock exchanges and securities contracts), the Depositories Act, 1996 (for depositories and their participants), the Pension Fund Regulatory and Development Authority Act, 2013 (for pension intermediaries).

In addition to this it includes the Companies Act, 2013, the Foreign Exchange Management Act, 1999, the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010.

Furthermore, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974, the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003 also play a key role.

How The Laws Fit Together

Taken together, these instruments are the AML laws and regulations for intermediaries in India. The PMLA creates the offence and the obligation, the PML Rules explain client due diligence, record-keeping and reporting, the SEBI and PFRDA instruments turn those duties into a detailed rulebook, FIU-IND receives the reports, the UAPA and the WMD Act impose sanctions duties, and the FATF Recommendations set the global benchmark. The table below maps each authority and instrument to its role.

Authority or instrument 

Role 

PMLA, 2002 

The parent anti money laundering law. Creates the offence and the core reporting entity duties. 

PML (Maintenance of Records) Rules, 2005 

Set out client due diligence, beneficial ownership, record keeping and reporting. 

SEBI 

Registers and supervises securities market intermediaries and issues the AML/CFT Guidelines, 2024 and the KYC Master Circular. 

PFRDA 

Supervises the pension intermediaries operating the National Pension System. 

FIU-IND 

Receives, analyses and disseminates the reports intermediary’s file. 

Enforcement Directorate 

Investigates and prosecutes the offence of money laundering under the PMLA. 

UAPA Section 51A / WMD Act Section 12A 

Impose counter terrorism and proliferation financing targeted financial sanctions. 

FATF Recommendations 

Set the international preventive measure standards for financial institutions. 

Core Obligations Across All Intermediaries At A Glance

Across that framework, the law requires every intermediary to do the following. This guide states each duty at the level set by the law; the companion compliance guidance explains how to carry each one out.

  • Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the intermediary can file its reports.
  • Appoint officers. Appoint a Designated Director and a management level Principal Officer under Rule 7 of the PMLR and the SEBI Guidelines. The same person cannot hold both roles, and both are informed to FIU-IND and, where applicable, SEBI.
  • Assess your risk. Conduct an internal risk assessment of money laundering, terror financing and proliferation financing risk across customers, products, channels and geographies, with its outcome going to the board, as the SEBI AML/CFT Guidelines require.
  • Know your customer. Identify and verify every client and the beneficial owner (more than 10 per cent for a company or partnership, more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high risk clients, under Section 11A of the PMLA, Rule 9 of the PMLR and the SEBI KYC Master Circular.
  • Keep KYC current. Carry out periodic updates at least once every 2, 8 and 10 years for high, medium and low risk clients, and review each client’s risk categorisation at least once every six months.
  • Monitor and report. Watch client accounts and transactions on an ongoing basis and file cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, non profit organisation receipt reports and counterfeit currency reports, under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th of the succeeding month; suspicious transaction reports are filed promptly.
  • Keep records. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA, and upload client KYC records to the CKYCR.
  • Screen against sanctions lists. Screen clients and beneficial owners against the UAPA and WMD Act designated lists daily and freeze any matched funds or securities without delay.
  • Run group wide controls. Where the intermediary is part of a group, apply AML and CFT programmes at group level, including for branches and majority owned subsidiaries.

CFT and CPF: Targeted Financial Sanctions

Anti money laundering is only part of the duty. An intermediary must also work on countering the financing of terrorism and the financing of weapons of mass destruction. This is done through targeted financial sanctions, which involve screening clients and transactions against designated lists and freezing any matched funds or securities without delay. The sanctions screening process is the same in principle across intermediary types and is scaled according to the business.

The CFT duty flows from Section 51A of the UAPA, as implemented by the 2 February 2021 procedure and its corrigendum and Section 12A of the WMD Act, applied through the procedure dated 1 September 2023. In practice, an intermediary screens against the United Nations Security Council lists and the relevant domestic lists, acts on matches disambiguated and identified, and reports as required, verifying the lists daily.

What Happens If an Intermediary Breaches AML Law?

A breach of the AML framework is not a single risk but several, because more than one body can act, each under its own power. The reporting duties also run continuously, so a missed or incorrect filing can be treated as an ongoing default rather than a one-off.

Body 

What it can do on a breach 

The market regulator (SEBI or PFRDA) 

Monetary penalties, directions and registration action on the intermediary under the SEBI Act, 1992 or the PFRDA Act, 2013. 

FIU-IND 

Compliance orders, monetary penalties and warnings on the reporting entity and its officers under Section 13 of the PMLA. 

Enforcement Directorate 

Investigation, provisional attachment of the proceeds of crime, and prosecution for the offence of money laundering under the PMLA. 

Beyond the formal penalties, a breach carries consequences that often prove more costly. This includes reputational damage, the loss of investor and market confidence when controls are questioned, and adverse findings in the next SEBI inspection or independent review. Because the framework runs on the live programme, the cheapest position is always to stay compliant rather than to remediate after an order.

From Regulation to Compliance: Your Next Step

Knowing the law is step one. These obligations only protect an intermediary when they are built into a working programme of risk assessment, policy, customer due diligence, monitoring, screening, reporting, training and independent review. To place your intermediary within the national picture, see AML laws and regulations in India, and use navigating the AML regulatory framework in India to orient your business within it.

Want to talk through what the SEBI 2024 Guidelines mean for your firm?

AML India can confirm which SEBI or PFRDA instrument applies to your intermediary and build a proportionate programme for it.

Frequently Asked Questions

Yes. Every registered intermediary is a reporting entity under the PMLA. The reporting entity definition in section 2(1)(wa) includes an intermediary, and section 2(1)(n) brings in stock brokers, share transfer agents, registrars, merchant bankers, underwriters, portfolio managers, investment advisers and other securities market intermediaries registered under section 12 of the SEBI Act, together with pension intermediaries and recognised stock exchanges.

The Securities and Exchange Board of India supervises securities market intermediaries and issues the AML/CFT Guidelines, 2024 and the KYC Master Circular they work from. The Pension Fund Regulatory and Development Authority supervises pension intermediaries in the National Pension System. The prescribed reports go to FIU IND, regardless of the regulator, and the Enforcement Directorate enforces the criminal law.

The SEBI Guidelines on AML Standards and CFT Obligations of Securities Market Intermediaries, updated on 6 June 2024, are the central AML rulebook. They are read with the SEBI Master Circular on KYC Norms for the Securities Market of 12 October 2023 and each intermediary type’s own Master Circular. The earlier 2010 and 2014 AML master circulars stand withdrawn.

Under Rule 9 of the PMLR and the SEBI framework, an intermediary looks through the non individual client to identify natural persons who ultimately own or control it. This is more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, and the separate test for a trust covering the author, trustees, beneficiaries with 10 per cent or more interest and any person with ultimate control. This matters when onboarding corporate clients, funds and foreign portfolio investors.

The prescribed reports under Rule 3 of the PMLR: cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, non profit organisation receipt reports and counterfeit currency reports. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly, through FINnet 2.0. Cross border wire transfer reporting is a bank and authorised person duty rather than a securities intermediary one.

Yes. A recognised stock exchange is a reporting entity, and depositories and their participants are intermediaries under the PMLA. Each applies the SEBI AML/CFT Guidelines, identifies and monitors its participants or clients, screens against the sanctions lists and files with FIU-IND, in addition to the surveillance and oversight roles they perform for the wider market.

Official sources and review

Why work with AML India

AML India helps securities and pension market intermediaries of every type meet their PMLA and SEBI or PFRDA obligations, from risk assessment and policy through to client due diligence, screening, monitoring, reporting, training, software selection and independent review.

Industries we serve: stock brokers, portfolio managers, merchant bankers, investment advisers, mutual funds and asset management companies, registrars, share transfer agents, trustee to a trust deed including debenture trustees, underwriters, custodians, depositories, credit rating agencies, foreign portfolio investors, stock exchanges and pension intermediaries, alongside banks, NBFCs, insurers, DNFBPs and IFSC and GIFT City entities.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik