Last Updated  on: 2nd September 2026       |        Last Reviewed on: 2nd September 2026

Key Takeaways at a Glance

  • Who is covered: non-banking financial companies of every category and layer, from lenders and investment companies to microfinance and factoring companies, as reporting entities under the PMLA and subject to RBI directions and supervision.
  • Why they are caught: a non-banking financial company is expressly named within the financial institution definition in section 2(1)(l) of the PMLA, so it is a reporting entity under section 2(1)(wa). No separate designation is needed.
  • Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the RBI (Non-Banking Financial Companies – Know Your Customer) Directions, 2025; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
  • Supervisor: the Reserve Bank of India (RBI). Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
  • Core duties: an internal risk assessment, customer due diligence and KYC, beneficial owner identification, periodic updation, monitoring, prescribed transaction reporting, five year record keeping and sanctions screening.

This guide is general information on Indian law, not legal advice. For your company’s specific position, speak to a qualified AML professional.

Non-banking financial companies, known as NBFCs, are reporting entities under the Prevention of Money Laundering Act, 2002. An NBFC is a company that carries on a financial business, such as lending, investment, asset finance or microfinance, without holding a banking licence.

Its AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the RBI Non-Banking Financial Companies KYC Directions, 2025, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework. The Reserve Bank of India supervises NBFCs, and reports are filed with FIU-IND. This guide covers NBFCs generally; the specialised categories, such as housing finance, mortgage guarantee, asset reconstruction and hire purchase companies, have their own guides.

The core instruments at a glance

Instrument 

What it does for an NBFC 

PMLA, 2002 

The is the parent Act that recognises the non-banking financial company within the financial institution definition and creates the core duties of CDD, record-keeping and reporting. 

PML (Maintenance of Records) Rules, 2005 

Outlines what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. 

RBI NBFC KYC Directions, 2025 

The NBFC’s working rulebook, issued by the RBI on 28 November 2025 and updated as on 29 December 2025, applicable to all categories and layers of NBFC. 

RBI Internal Risk Assessment Guidance (2024) 

Requires the NBFC to run an ML/TF risk assessment whose outcome goes to the board. 

UAPA Section 51A and WMD Act Section 12A 

Impose targeted financial sanctions for terrorism and proliferation financing. 

FATF Recommendations 9 to 23 

The international preventive measure standards for financial institutions that India’s framework is built to meet. 

What Counts as an NBFC in India?

A non-banking financial company is a company registered under the Companies Act whose principal business is financial, whether lending and providing advances, acquiring shares and securities, asset finance, microfinance, factoring or similar activity, and which is registered with and regulated by the Reserve Bank of India but does not hold a banking licence.

The Reserve Bank classifies NBFCs by activity and by a layered structure that scales supervision to size and systemic importance. This guide covers NBFCs as a class; the specialised categories that the RBI regulates under their own directions, such as housing finance, mortgage guarantee, asset reconstruction and hire purchase companies, are addressed in their own guides.

The money laundering risk of an NBFC is a lending and investment risk across a wide product range. It sits in the source of loan repayments and investments, which may involve cash; in the use of credit and investment products to layer and integrate illicit funds; digital and app based lending that can weaken face to face identification; and in the identity and beneficial ownership of corporate borrowers and investors.

The AML framework therefore leans on identifying the customer and any beneficial owner, on understanding the source of funds, and on monitoring for unusual borrowing, repayment and investment patterns.

Are NBFCs Reporting Entities under the PMLA?

Yes. The Prevention of Money-Laundering Act, 2002 creates the offence of money laundering and places core duties on reporting entities. A non-banking financial company is expressly named within the financial institution definition in section 2(1)(l) of the PMLA, and a non-banking financial company takes its meaning from the Reserve Bank of India Act, 1934, so an NBFC is a reporting entity under section 2(1)(wa). No notification under section 2(1)(sa) is needed; an NBFC is inside the regime by name.

This places an NBFC in the same broad category of reporting entities that file with FIU-IND as banks and other financial institutions, and within the wider AML laws and regulations for financial institutions in India. The obligations are calibrated to the NBFC’s category, layer and scale, but the status is not optional.

Supervisory Authority for NBFCs in India

The supervisor for NBFCs is the Reserve Bank of India, which registers and supervises them and issues the KYC and AML directions they work from. On 28 November 2025, the RBI issued its consolidated, category specific KYC Directions, and the Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Directions, 2025, updated as of 29 December 2025, apply to all categories and layers of NBFC. The RBI Internal Risk Assessment Guidance of 2024 sits alongside them as the basis of the risk based approach, and the RBI publishes frequently asked questions on NBFCs for reference.

The Financial Intelligence Unit – India receives, analyses and disseminates the reports an NBFC files, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. In short, the RBI sets and supervises the rules, FIU-IND receives the intelligence, and the ED enforces the criminal law.

Not Sure Which Rules Apply to Your NBFC?

There are many laws and RBI rules for NBFCs, and not all of them apply the same way to every company. Get a free 15-minute call with our AML expert to find out exactly what applies to you.

AML Regulatory Requirements for NBFCs in India

The law that governs a non-banking financial company is spread across several instruments rather than gathered in one code. It is easiest to read as a layered framework, grouped the way the official source set groups it: the core legislation, the overarching obligations, the sectoral supervisor and its directions, the miscellaneous official reports, the international standards, and the allied laws. Each category below lists the instruments that bind an NBFC, with a short note on what each one does in practice.

The framework reads from the core outward. The PMLA is the parent Act; the PML Rules convert it into working duties; the RBI NBFC KYC Directions translate both into instructions an NBFC can operate; the UAPA and the WMD Act layer on counter terrorism and proliferation financing sanctions; and the allied laws, including the Reserve Bank of India Act under which the company is registered, shape the risk it must manage. The risk based approach is the common thread.

Core Legislation

The primary statutes and rules that create an NBFC’s AML, CFT and CPF duties, grouped into three categories covering money laundering, terrorism financing and proliferation financing.

AML Legislation

Prevention of Money-Laundering Act, 2002 (PMLA)

India’s parent anti money laundering statute and the source of an NBFC’s reporting entity status. It defines the offence of money laundering, empowers attachment and confiscation of the proceeds of crime, and casts the standing duties of customer due diligence, record-keeping and reporting onto every reporting entity, a non-banking financial company among them.

Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (PMLR)

The operational engine of the Act. The PMLR tell an NBFC how to verify a customer, how to find the beneficial owner behind a corporate borrower, which transactions to report and by when, how long to preserve records, and that it must appoint a Designated Director and a Principal Officer. Almost every day AML task an NBFC performs traces back to these Rules.

The PML (Maintenance of Records) Rules, 2005 have been amended many times. The table below is a legal history timeline: each Gazette notification with a short note on what it changed. For an NBFC the important through line is the steady tightening of customer due diligence, beneficial ownership and reporting, and the two 2023 amendments that cut the beneficial ownership thresholds, which bear directly on lending to companies and partnerships.

The 31 PMLR amendment notifications, in date order:

Gazette notification and date 

Key change or rule touched 

G.S.R. 389(E), 24 May 2007 

Expanded the definition of a suspicious transaction under the PML Rules, 2005 to cover transactions lacking an economic rationale or having links to terrorist financing. It also extended reportable cash transactions to include forged currency and documents, specified reporting timelines for submissions to the Director, and reduced the requirement for certified copies in certain filings from three copies to one. 

G.S.R. 816(E), 12 November 2009 

Introduced definitions for non-profit organisation and Regulator, while broadening the scope of suspicious transactions to cover those involving unusual complexity, a lack of economic rationale, or connections to terrorist financing. It further mandated reporting of cash receipts exceeding ten lakh rupees by NGOs, replaced specific references to RBI, SEBI and IRDA with the term Regulator, and extended the record retention period to ten years from the transaction date. 

G.S.R. 76(E), 12 February 2010 

Reinforced the provisions relating to record keeping and reporting under Rules 3, 4, 5 and 7 of the PML Rules, 2005. It also inserted the first Explanation to Rule 9(1A), clarifying that the beneficial owner is the natural person who ultimately owns or controls a client or on whose behalf a transaction is conducted. 

G.S.R. 508(E), 16 June 2010 

Modified Rules 2, 9 and 10 of the PML Rules, 2005 concerning definitions, customer due diligence and record keeping. These amendments strengthened customer identification procedures and requirements for preserving records by reporting entities as part of the 2010 reforms to the CDD and record-keeping framework. 

G.S.R. 980(E), 16 December 2010 

Established the small account framework by introducing definitions for Designated Officer and small account. It also expanded the list of officially valid documents under Rule 2 to include the NREGA job card and Aadhaar letter and inserted Rule 9(2A), which prescribed conditions and procedures for opening and monitoring small accounts. 

G.S.R. 481(E), 24 June 2011 

Renamed the PML Rules, 2005 through an amendment to Rule 1 by introducing the short title Prevention of Money Laundering Maintenance of Records Rules and replacing the earlier longer title. This established the abbreviated PMLR reference used subsequently. 

G.S.R. 576(E), 27 August 2013 

Established the definition of Designated Director under Rule 2 and revised Rules 3, 7, 8, 9 and 10 of the PML Rules, 2005. The amendments enhanced reporting requirements, governance arrangements, customer due diligence measures and record keeping obligations. 

G.S.R. 288(E), 15 April 2015 

Specified the documents recognised as officially valid documents for the purposes of customer identification under the PML Rules, 2005. 

G.S.R. 544(E), 7 July 2015 

Established the definition of Central KYC Records Registry and amended Rules 9 and 10 of the PML Rules, 2005 by introducing additional provisions to strengthen the KYC framework. The amendments also supported the centralised collection, maintenance and management of KYC records for reporting entities. 

G.S.R. 730(E), 22 September 2015 

Revised several definitions under Rule 2 and introduced corresponding amendments across the PML Rules, 2005 to align the regulatory framework with evolving KYC requirements. The changes helped provide greater clarity on key terms and strengthened the application of customer identification and due diligence requirements. 

G.S.R. 882(E), 18 November 2015 

Extended the prescribed period under the relevant provisions of the PML Rules, 2005 from 90 days to 180 days. The amendment provided reporting entities with additional time to comply with the applicable procedural and reporting requirements within the prescribed framework. 

G.S.R. 347(E), 12 April 2017 

Introduced the definition of Regulator and inserted Rule 9B to further strengthen the customer due diligence framework under the PML Rules, 2005. The amendment also provided additional regulatory provisions relating to the identification and verification of customers. 

G.S.R. 538(E), 1 June 2017 

Revised Rules 2 and 9 of the PML Rules, 2005 by introducing additional provisions to enhance the operational AML framework. The changes further developed the requirements relating to customer identification, due diligence and compliance procedures applicable to reporting entities. 

G.S.R. 1038(E), 21 August 2017 

Updated the definitions under Rule 2 of the PML Rules, 2005 by introducing additional provisions to clarify and refine key terms used within the regulatory framework. These changes helped improve consistency in the interpretation and implementation of the applicable AML and KYC requirements. 

G.S.R. 1318(E), 23 October 2017 

Further revised Rule 2 by introducing a proviso concerning the acceptance and treatment of officially valid documents. The amendment clarified the way such documents were to be considered for customer identification and verification purposes under the PML Rules, 2005. 

G.S.R. 456(E), 16 May 2018 

Strengthened Rule 9 by introducing additional provisions requiring reporting entities to establish and implement a formal customer due diligence programme. The amendment reinforced the need for reporting entities to maintain appropriate procedures for identifying and verifying customers as part of their AML framework. 

G.S.R. 1078(E), 31 October 2018 

Extended the prescribed period under Rule 9(1A) from three days to ten days. This change provided reporting entities with additional time to complete the specified requirements within the customer due diligence framework. 

G.S.R. 108(E), 13 February 2019 

Enhanced Rule 9 through significant amendments aimed at strengthening the customer due diligence framework. The changes introduced additional requirements relating to customer identification and verification and established the foundation for subsequent amendments made to the PML Rules in 2019. 

G.S.R. 381(E), 28 May 2019 

Established a specific customer due diligence framework for prisoners opening or maintaining bank accounts. The amendment permitted the officer in charge of the jail to certify the customers signature or thumb impression and allowed such accounts to remain operational subject to the annual submission of a proof of address certificate issued by the same authority. 

G.S.R. 582(E), 19 August 2019 

Introduced digital KYC, equivalent electronic documents and offline Aadhaar verification into the PML Rules, 2005. The amendment revised Rule 9 to recognise multiple modes of customer identification and introduced a detailed digital KYC process involving live photographs, geotagging, OTP based authentication and prescribed verification procedures. 

G.S.R. 669(E), 18 September 2019 

Introduced the definition of depository receipt and streamlined customer due diligence requirements applicable to certain foreign investments. The amendment permitted reporting entities to rely on beneficial ownership requirements prescribed by notified foreign jurisdictions for specified investments. It also provided exemptions for listed companies and their subsidiaries from identifying and verifying individual shareholders or beneficial owners in certain circumstances. 

G.S.R. 840(E), 13 November 2019 

Enabled customers undergoing Aadhaar based identity verification to declare a current address that differed from the address available in the Central Identities Data Repository. The amendment permitted reporting entities to accept a self declaration of the customers current address for customer due diligence purposes, thereby simplifying the process for establishing and updating address details. 

G.S.R. 228(E), 31 March 2020 

Granted temporary relief to small accounts that were scheduled for closure due to pending customer due diligence requirements. The amendment permitted these accounts to remain operational from 1 April 2020 to 30 June 2020, with the Central Government authorised to extend the period further in view of the COVID 19 pandemic. 

G.S.R. 251(E), 13 April 2020 

Extended the deadline for reporting entities to submit prescribed transaction reports under Rule 8. The temporary relaxation allowed eligible reports to be furnished by 30 June 2020, recognising the operational difficulties faced by reporting entities during the COVID 19 pandemic. 

G.S.R. 254(E), 16 April 2020 

Clarified the categories of transaction reports eligible for the temporary extension provided under Rule 8. The amendment covered reports under Rule 3(1)(A), (B), (BA), (C) and (E) for March, April and May 2020, as well as reports under Rule 3(1)(F) for the January to March 2020 quarter, permitting their submission up to 30 June 2020. 

G.S.R. 798(E), 28 December 2020 

Notified real estate agents with an annual turnover of Rupees 20 lakh or more as persons carrying on a designated business or profession under the PMLA. This brought such real estate agents within the reporting entity framework and made them subject to the applicable AML and customer due diligence obligations. 

G.S.R. 575(E), 13 July 2022 

Established specific AML and KYC requirements for reporting entities operating in an International Financial Services Centre. The amendment designated the head of the reporting entity in India as the designated officer for IFSC entities, expanded the list of officially valid documents available to foreign nationals, introduced the definition of International Financial Services Centre into the Rules, and provided exemptions from certain Central KYC Records Registry requirements for foreign national customers of IFSC reporting entities. 

S.O. 1074(E), 7 March 2023 

Lowered the beneficial ownership threshold to 10 percent and introduced requirements for group wide AML policies. The amendment also added definitions for group, politically exposed person and non profit organisation, strengthened customer due diligence requirements applicable to legal persons and trusts, and introduced registration requirements for eligible non profit organisations 

G.S.R. 652(E), 4 September 2023 

Further strengthened the AML framework by incorporating enhanced requirements relating to beneficial ownership, group wide AML policies and customer due diligence. The amendment also addressed the definitions of group, politically exposed person and non profit organisation, expanded due diligence requirements for legal persons and trusts, and introduced registration related obligations for eligible non profit organisations. 

G.S.R. 745(E), 17 October 2023 

Enhanced customer due diligence by requiring customer identity to be verified through reliable and independent sources. The amendment also strengthened group wide AML programmes, required suspicious transaction reports to be submitted promptly once suspicion was established, and reinforced confidentiality requirements relating to AML records and reporting. 

G.S.R. 419(E), 19 July 2024 

Strengthened the Central KYC Records Registry framework by requiring reporting entities to use the KYC Identifier when retrieving customer records. The amendment also restricted requests for duplicate KYC documents to specified circumstances, introduced a seven day period for updating KYC records, and required reporting entities to retrieve, update and rely on revised customer information maintained in the Central KYC Records Registry. 

PML (Manner of Receiving Records Authenticated Outside India) Rules, 2005

A narrow but useful companion set. It fixes how records executed or authenticated outside India are to be received and relied on, which matters when an NBFC onboards a borrower or investor whose documents originate abroad.

CFT Legislation

Unlawful Activities (Prevention) Act, 1967 (UAPA)

The counter terrorism financing pillar. Section 51A obliges an NBFC to screen customers against the designated lists and to freeze, without delay, funds or accounts belonging to persons or entities named under United Nations Security Council resolutions, so that credit and investment products cannot service terrorism.

Procedure for implementing Section 51A of the UAPA

The operating manual for those freezes. It sets out how the designated lists are circulated, how a match is to be handled and reported, and the timelines an NBFC must meet when a name on its books coincides with a listing.

CPF Legislation

The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)

The counter proliferation financing pillar. Section 12A prohibits any person, an NBFC included, from making funds or financial services available to those connected with the financing of weapons of mass destruction and their delivery systems.

Procedure for Implementing Section 12A of the WMD Act

The companion procedure that makes Section 12A workable, describing how proliferation related designations reach an NBFC and the freezing and reporting steps it must take on a match.

The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016

The detailed rules under the WMD Act that fill in the mechanics of implementation, giving an NBFC certainty on how the proliferation financing controls are to be applied in practice.

Overarching Obligations

The cross cutting systems and procedures that sit above any single sector and carry an NBFC’s KYC data and reports.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

Govern the central registry that stores customer KYC records for reuse across the financial system. An NBFC files its KYC data to the CKYCR, retrieves a customer’s existing record on onboarding, and updates it within the prescribed window when details change, cutting duplicate paperwork for borrowers and investors.

FINnet 2.0 Reporting Formats and the FINGate 2.0 User Manuals

Define the electronic formats and the gateway through which an NBFC files its cash, suspicious and other prescribed reports to FIU-IND, replacing the older FINnet system with the current FINnet 2.0 and FINGate 2.0 environment.

Section 11A Aadhaar Authentication Procedure for Reporting Entities

Sets the conditions under which an NBFC may use Aadhaar authentication for customer verification, following the statutory and Supreme Court limits, giving a lawful digital route to confirm identity at onboarding.

New RBI Directions, Same Old Confusion?

The 2025 KYC Directions changed a lot for NBFCs. If you’re unsure what’s changed for your company specifically, our AML consultants can walk you through it.

Sectoral: The Reserve Bank of India

The supervisor for NBFCs and the directions it issues. This is the sector specific layer, and the RBI NBFC KYC Directions are the instrument an NBFC works from most closely.

Reserve Bank of India, the Supervisor

RBI (Non-Banking Financial Companies - Know Your Customer) Directions, 2025

The star instrument for a non-banking financial company. Issued by the Reserve Bank on 28 November 2025 and updated as of 29 December 2025, this category specific Direction is the working KYC and AML rulebook for every category and layer of NBFC. It translates customer due diligence, risk categorisation, beneficial ownership, periodic updates, monitoring, record-keeping, and reporting requirements into the language of NBFC operations, and it is where an NBFC should look first for a rule that applies to its lending, investment, or asset finance business.

RBI Consolidated Master Directions and KYC compliance notification (28 November 2025)

The covering notification that consolidated the RBI’s KYC framework into category specific Directions on 28 November 2025 and confirmed how the earlier instructions stand repealed or superseded, so an NBFC knows which text now governs and can retire the superseded circulars.

RBI Internal Risk Assessment Guidance for ML/TF Risks (2024)

The Reserve Bank’s 2024 guidance requiring an NBFC to run a documented assessment of its money laundering and terrorism financing risks across customers, products, channels and geographies, and to place the outcome before its board, making the risk based approach concrete.

RBI Frequently Asked Questions on NBFCs

The Reserve Bank’s published questions and answers on non-banking financial companies, a practical reference that helps an NBFC read the registration and conduct requirements consistently with the supervisor’s own interpretation.

RBI Non-Banking Financial Companies Compliance Function Directions, 2026

These directions establish the governance framework for the compliance function of NBFCs. They set out requirements for compliance oversight, responsibilities, monitoring and reporting to strengthen regulatory compliance and accountability.

Miscellaneous Official Reports and Guidance

Official reports and guidance that are not binding rules but shape how an NBFC reads its risk and the wider enforcement picture.

FIU-IND Annual Report 2024 to 2025

The Financial Intelligence Unit’s yearly account of reporting volumes, typologies and enforcement trends, useful for an NBFC calibrating what unusual borrowing, repayment or investment activity looks like across the sector.

Directorate of Enforcement Annual Report 2025 to 2026

The ED’s yearly summary of PMLA investigations, attachments and prosecutions, a reminder of how the criminal side of the regime operates and where enforcement attention has fallen.

FIU-IND and its Core Functions and FAQs

FIU-IND’s explanation of its own role and a set of frequently asked questions, a plain language reference an NBFC can use to understand registration and reporting expectations.

MHA National Counter Terrorism Policy and Strategy

The Ministry of Home Affairs statement of national counter terrorism policy, background that frames the UAPA sanctions obligations an NBFC must apply.

International Standards

The global standards India’s framework is built to meet, and against which an NBFC’s controls are ultimately judged.

FATF Recommendations

The Financial Action Task Force’s forty Recommendations are the international baseline for AML and CFT. Recommendations 9 to 23 set the preventive measures for financial institutions that an NBFC’s duties reflect, and FATF updated Recommendation 6 on targeted financial sanctions in June 2026.

FATF Mutual Evaluation Report on India, 2024

The peer assessment of India’s AML and CFT regime, including the Executive Summary, which found India largely compliant and set the direction of travel that continues to shape supervision of financial institutions, NBFCs included.

Basel Committee Guidance on ML/TF risk (2014, revised 2020)

The Basel Committee’s sound management guidance on money laundering and terrorism financing risk, a supervisory benchmark for how a regulated financial institution should embed AML risk management, informative for an NBFC’s own framework.

FATF Risk Based Approach Guidance for the Banking Sector (2014)

FATF’s guidance on applying the risk based approach in a lending and deposit context, directly transferable to an NBFC weighing customer, product and channel risk in its credit and investment book.

Allied Laws

The wider body of Indian law that intersects with an NBFC’s AML duties, from the statute under which it is registered to the predicate offence and enforcement Acts that give money laundering its underlying crimes.

Reserve Bank of India Act, 1934

The Act under which an NBFC is registered and regulated, and the source of the statutory meaning of a non-banking financial company that the PMLA borrows, making it the foundational allied law for the sector.

Factoring Regulation Act, 2011

The Act that regulates factoring business and the factors that carry it on, relevant where an NBFC operates as a factor and must read its AML duties alongside its factoring obligations.

Companies Act, 2013

Governs the incorporation, ownership and control of the companies an NBFC deals with and supplies the beneficial ownership and significant control concepts that customer due diligence relies on.

Foreign Exchange Management Act, 1999 (FEMA)

Regulates cross border funds and foreign investment, which an NBFC must observe when a borrower, investor or transaction has an overseas dimension.

Predicate Offence and Enforcement Statutes

Money laundering is the laundering of the proceeds of some other crime, so the schedule of predicate offences and the allied enforcement statutes matter to an NBFC assessing why funds might be tainted. These include the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money Act, 2015, the Foreign Contribution (Regulation) Act, 2010, COFEPOSA 1974, SAFEMA 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.

Core AML/CFT/CPF Obligations for NBFCs in India

Across that framework, the regulations require an NBFC to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.

  • Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the institution can file its reports.
  • Appoint officers. Appoint a Designated Director and a management level Principal Officer under Rule 7 of the PMLR and the RBI Directions. The same person cannot hold both roles, and both are informed to FIU-IND and the RBI.
  • Conduct the internal risk assessment. Run an ML and TF risk assessment across customers, products, channels and geographies, document it, and take its outcome to the board, as the RBI Directions and the IRA Guidance require.
  • Document AML policy, controls and procedures. Adopt a board approved policy that turns the risk assessment into the institution’s operating procedures.
  • Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the RBI NBFC KYC Directions 2025. Given the lending and investment business, the identification of borrowers and investors and any beneficial owner, and the scrutiny of the source of loan repayments and investment funds, are central.
  • Ongoing monitoring and periodic updates. Monitor transactions on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low risk customers. Review each customer’s risk categorisation at least once every six months.
  • Sanctions screening. Screen customers and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
  • Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value and counterfeit currency reports under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly once the Principal Officer is satisfied, through FINnet 2.0.
  • Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
  • Training and awareness. Train staff by role to apply the controls and recognise red flags in lending and investment, such as cash repayments, rapid loan pre closure and mismatched source of funds.
  • Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
  • Run group wide controls. Where the institution has subsidiaries, apply AML and CFT programmes at group level, including for branches and majority owned subsidiaries, as the RBI Directions require.

What This Article Does Not Cover

This article explains the laws and regulatory instruments that apply to NBFCs. It does not provide a control by control compliance manual, and it does not restate each institution’s own establishing statute or its developmental mandate, except where they bear on the AML duties. For implementation, an NBFC separately documents customer acceptance, KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction escalation, staff training, audit testing and board reporting. Those controls are the subject of the companion compliance guide.

To see how the NBFC framework fits within the sector, see AML laws and regulations for financial institutions in India, and to place it within the national picture, see AML laws and regulations in India.

From Regulation to Compliance: Your Next Step

Knowing the law is step one. These obligations only protect an institution when they are built into a working programme of risk assessment, policy, customer due diligence, monitoring, screening, reporting, training and independent review. For an NBFC, the identification of borrowers and investors and their beneficial owners and the scrutiny of the source of loan repayments and investment funds are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.

Want to confirm the 2025 directions for your institution?

AML India can walk you through the RBI NBFC KYC Directions, 2025 and build a proportionate programme for your category and layer of NBFC.

Frequently Asked Questions

A non-banking financial company is a company registered under the Companies Act whose principal business is financial, such as lending, investment, asset finance, microfinance or factoring, and which is registered with and regulated by the Reserve Bank of India without holding a banking licence. It is a reporting entity under the PMLA.

Yes. A non-banking financial company is expressly named within the financial institution definition in section 2(1)(l) of the PMLA, so it is a reporting entity under section 2(1)(wa). No separate designation notification is needed; an NBFC is inside the regime by name.

The Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Directions, 2025, issued on 28 November 2025 and updated as on 29 December 2025. They apply to all categories of NBFC, including all layers of NBFC, and their branches and majority owned subsidiaries, and are read with the RBI Internal Risk Assessment Guidance of 2024.

Yes. Many NBFCs lend to and invest with individuals as well as businesses, so ordinary customer KYC applies at onboarding, alongside beneficial owner identification for any corporate borrower or investor and scrutiny of the source of funds. The full AML framework applies whatever the customer type.

Cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value and counterfeit currency reports. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly once the Principal Officer is satisfied, through FINnet 2.0.

Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every NBFC, whatever the size of the exposure. An NBFC screens customers and beneficial owners against the United Nations and domestic designated lists and freezes and reports any match.

Official sources and review

Why work with AML India

AML India helps NBFCs meet their PMLA and RBI obligations, from risk assessment and policy through to CDD, screening, monitoring, reporting, training and independent review.

Industries we serve: hire purchase and asset-finance companies, NBFCs, housing finance, mortgage guarantee and asset reconstruction companies, insurers, payment system operators and aggregators, banks, DNFBPs, securities intermediaries and IFSC and GIFT City entities.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik