Last Updated  on: 25th August 2026       |        Last Reviewed on: 25th August 2026

Key Takeaways at a Glance

  • Who is covered: small finance banks licensed under the Banking Regulation Act, 1949 to serve unserved and underserved customers with a priority sector and small ticket lending focus, as banking companies and reporting entities under the PMLA.
  • Why they are caught: a small finance bank is a banking company, which is the first named reporting entity in section 2(1)(wa) of the PMLA, so its AML duties apply directly. No section 2(1)(sa) designation is needed.
  • Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the RBI (Small Finance Banks – Know Your Customer) Directions, 2025; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
  • Supervisor: the Reserve Bank of India (RBI). Reports go to the Financial Intelligence Unit – India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA.
  • Core duties: an internal risk assessment, customer due diligence and KYC, beneficial owner identification, periodic updates, monitoring, prescribed transaction reporting, five year record-keeping and sanctions screening.

This guide is general information on Indian law, not legal advice. For your bank’s specific position, speak to a qualified AML professional.

A small finance bank is a bank licensed by the Reserve Bank of India to provide basic banking, savings and credit to unserved and underserved segments such as small businesses, marginal farmers, micro and small industries and the unorganised sector.

Its AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the RBI Small Finance Banks KYC Directions, 2025, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework. The Reserve Bank of India supervises small finance banks, and the prescribed reports are filed with FIU-IND. This guide is the small finance banks’ entry in the banking series.

The core instruments at a glance

Instrument 

What it does for a small finance bank 

PMLA, 2002 

The parent Act. Names the banking company as a reporting entity and creates the core duties of CDD, record-keeping and reporting. 

PML (Maintenance of Records) Rules, 2005 

Set out what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. 

RBI Small Finance Banks KYC Directions, 2025 

The bank’s working rulebook, issued by the RBI on 28 November 2025 and updated as of December 2025, tailored to small finance banks. 

RBI Internal Risk Assessment Guidance (2024) 

Requires the bank to run an ML/TF risk assessment whose outcome goes to the board. 

UAPA Section 51A and WMD Act Section 12A 

Impose targeted financial sanctions for terrorism and proliferation financing. 

FATF Recommendations 9 to 23 

The international preventive measure standards that India’s framework is built to meet. 

What Counts as a Small Finance Bank in India?

A small finance bank is licensed by the Reserve Bank of India under the Banking Regulation Act, 1949, to provide banking services to underserved and unserved sections of the population, including small businesses, marginal farmers, micro and small industries, and other unorganised sector entities. It accepts deposits from the public and provides credit and other banking services, with a focus on promoting financial inclusion and serving customers who may have limited access to mainstream banking services.

Small Finance Banks are subject to the applicable banking sector AML, CFT and CPF requirements, including customer due diligence, record-keeping, transaction monitoring, reporting and sanctions-related obligations. Although SFBs have a specific financial inclusion mandate and may operate at a smaller scale than some other banks, they remain subject to the full set of applicable AML, CFT and CPF obligations for banking companies, proportionate to the nature, scale and complexity of their business.

The money laundering risk of a Small Finance Bank is shaped by its financial inclusion mandate, small ticket lending, cash intensive activities and rapidly expanding customer base. Risks may arise from large volumes of small value transactions, cash disbursements and repayments, microfinance and group lending models, customers with limited financial and documentary histories, and the rapid onboarding of customers through digital channels.

Multiple small accounts, deposits or loan transactions may also be used to structure or layer illicit funds. The AML framework therefore emphasises reliable customer identification and verification, appropriate identification of group or connected customers where relevant, monitoring of cash and loan related transactions, effective transaction monitoring, and scaling AML controls in line with the bank’s customer base, products, delivery channels and risk profile.

Are Small Finance Banks Reporting Entities under the PMLA?

Yes. The Prevention of Money-Laundering Act, 2002 creates the offence of money laundering and places core duties on reporting entities. A small finance bank is a banking company, and a banking company is recognised as a reporting entity under the definition in section 2(1)(wa) of the PMLA. A small finance bank is therefore a reporting entity by virtue of what it is; no notification under section 2(1)(sa) is needed.

This places a small finance bank in the same core group of reporting entities that file with FIU-IND as every other bank, and within the wider AML laws and regulations for the banking sector in India.

Supervisory Authority for Small Finance Banks in India

The supervisor for small finance banks is the Reserve Bank of India, which licenses them, sets the AML rules they work from and inspects their compliance. On 28 November 2025, the RBI issued the RBI Small Finance Banks KYC Directions, 2025, updated as of December 2025, which is the instrument a small finance bank works with daily for AML compliance. The RBI Internal Risk Assessment Guidance of 2024 sits alongside them as the basis of the risk based approach, and the RBI Small Finance Banks Responsible Business Conduct Directions, 2025 cover the wider customer conduct rules.

The Financial Intelligence Unit – India receives, analyses and disseminates the reports a small finance bank files, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. In short, the RBI sets and supervises the rules, FIU-IND receives the intelligence, and the ED enforces the criminal law.

Not registered with FIU-IND yet, or unsure whether you have to be?

AML India can confirm your reporting entity status under the PMLA, complete your FINnet 2.0 enrolment and appoint your Principal Officer and Designated Director.

AML Regulatory Requirements for Small Finance Banks in India

The legal framework governing a Small Finance Bank is spread across several instruments, including core legislation, overarching obligations, sectoral regulations and directions, official guidance and reports, international standards, and allied laws. Each category below lists the instruments relevant to Small Finance Banks, with a short note on their practical application.

The framework runs from the core legislation to the allied laws. The PMLA provides the principal AML framework, while the PML Rules translate it into operational obligations; and the RBI’s Small Finance Banks – KYC Directions provide the sector specific KYC framework. The UAPA and WMD Act add requirements relating to counter terrorist financing and proliferation financing sanctions, while allied laws, including the Banking Regulation Act, 1949 and the Reserve Bank of India Act, 1934, provide the broader regulatory framework. The risk based approach is the common thread across these requirements.

Core Legislation

The primary statutes and rules that create a small finance bank’s AML, CFT and CPF duties, grouped into three categories, each of which covers money laundering, terrorism financing and proliferation financing.

AML Legislation

Prevention of Money-Laundering Act, 2002 (PMLA)

India’s principal anti money laundering statute and the source of a Small Finance Bank’s reporting entity status. It defines the offence of Money laundering, provides for attachment and confiscation of proceeds of crime, and establishes customer due diligence, record-keeping and reporting obligations for reporting entities, including Small Finance Banks.

Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (PMLR)

The operational framework of the PMLA. The PML Rules specify how a Small Finance Bank must conduct customer due diligence, identify beneficial owners, report prescribed transactions, maintain records, and appoint a Designated Director and Principal Officer. They translate the PMLA’s requirements into daily AML obligations.

The PML (Maintenance of Records) Rules, 2005 have been amended many times. The table below is a legal history timeline: each Gazette notification with a short note on what it changed.

The 31 PMLR Amendment Notifications, in Date Order:

Gazette notification and date 

Key change or rule touched 

G.S.R. 389(E), 24 May 2007 

Amended the PML Rules, 2005 to broaden the scope of suspicious transactions, strengthen reporting requirements for cash transactions involving counterfeit currency and forged documents, set clear reporting timelines for the Director, and reduce the number of certified copies required for certain filings from three to one. 

G.S.R. 816(E), 12 November 2009 

Introduced definitions for non profit organisation and Regulator, expanded the scope of suspicious transactions to cover unusual complexity, lack of economic rationale and links to terrorist financing, required reporting of NGO cash receipts exceeding ten lakh rupees, replaced specific references to RBI SEBI and IRDA with the broader term Regulator, and extended the record retention period to ten years from the date of the transaction. 

G.S.R. 76(E), 12 February 2010 

Strengthened Rules 3, 4, 5 and 7 of the PML Rules, 2005 by reinforcing record keeping and reporting requirements and inserted the first Explanation to Rule 9(1A), clarifying that the beneficial owner is the natural person who ultimately owns or controls a client or on whose behalf a transaction is conducted. 

G.S.R. 508(E), 16 June 2010 

Revised Rules 2, 9 and 10 of the PML Rules, 2005 to strengthen requirements relating to definitions, customer due diligence and record keeping, reinforcing customer identification and record preservation by reporting entities as part of the 2010 CDD and records reforms. 

G.S.R. 980(E), 16 December 2010 

Introduced the small account framework by defining Designated Officer and small account, expanding the list of officially valid documents under Rule 2 to include the NREGA job card and Aadhaar letter, and adding Rule 9(2A) to prescribe conditions and procedures for opening and monitoring such accounts. 

G.S.R. 481(E), 24 June 2011 

Amended Rule 1 of the PML Rules, 2005 to introduce the short title Prevention of Money Laundering Maintenance of Records Rules and establish the abbreviated PMLR reference used thereafter. 

G.S.R. 576(E), 27 August 2013 

Introduced the definition of Designated Director under Rule 2 and amended Rules 3, 7, 8, 9 and 10 of the PML Rules, 2005 to strengthen reporting obligations, governance requirements, customer due diligence and record keeping provisions. 

G.S.R. 288(E), 15 April 2015 

Specified the documents recognised as officially valid documents for customer identification under the PML Rules, 2005. 

G.S.R. 544(E), 7 July 2015 

Introduced the definition of Central KYC Records Registry and amended Rules 9 and 10 to strengthen the KYC framework and facilitate centralised KYC record management. 

G.S.R. 730(E), 22 September 2015 

Amended the definitions under Rule 2 and made related changes to the PML Rules, 2005 to align the framework with evolving KYC requirements. 

G.S.R. 882(E), 18 November 2015 

Extended the prescribed timeline under the relevant provisions of the PML Rules, 2005 from 90 days to 180 days, giving reporting entities additional time to complete the required compliance process. 

G.S.R. 347(E), 12 April 2017 

Introduced the definition of Regulator and inserted Rule 9B to further strengthen the customer due diligence framework and clarify the role of regulatory authorities in the AML framework. 

G.S.R. 538(E), 1 June 2017 

Amended Rules 2 and 9 of the PML Rules, 2005 by adding provisions to strengthen customer identification and other operational aspects of the AML and KYC framework. 

G.S.R. 1038(E), 21 August 2017 

Amended the definitions under Rule 2 of the PML Rules, 2005 by adding provisions to update and clarify key terms used by reporting entities for AML and KYC purposes. 

G.S.R. 1318(E), 23 October 2017 

Further amended Rule 2 by adding a proviso concerning the acceptance and treatment of officially valid documents for customer identification purposes. 

G.S.R. 456(E), 16 May 2018 

Amended Rule 9 by introducing additional requirements for customer due diligence and requiring reporting entities to establish and implement a customer due diligence programme. 

G.S.R. 1078(E), 31 October 2018 

Amended Rule 9(1A) by extending the prescribed period from three days to ten days, providing reporting entities with additional time to complete the specified customer due diligence requirements. 

G.S.R. 108(E), 13 February 2019 

Made substantial changes to Rule 9 to strengthen the customer due diligence framework and lay the groundwork for further amendments introduced in 2019. 

G.S.R. 381(E), 28 May 2019 

Introduced specific customer due diligence provisions for prisoners opening or maintaining bank accounts. The amendment allowed the officer in charge of the jail to certify signatures or thumb impressions and permitted continued operation of such accounts subject to annual submission of a proof of address certificate from the same authority. 

G.S.R. 582(E), 19 August 2019 

Amended the PML Rules, 2005 to introduce digital KYC, equivalent electronic documents and offline Aadhaar verification. The changes to Rule 9 recognised multiple methods of customer identification and established requirements for digital KYC, including live photographs, geotagging, OTP based authentication and other verification measures. 

G.S.R. 669(E), 18 September 2019 

Brought in the definition of depository receipt and streamlined customer due diligence requirements for specified foreign investments. The amendment permitted reliance on beneficial ownership standards in notified foreign jurisdictions for certain investments and provided specified exemptions for listed companies and their subsidiaries from identifying and verifying individual shareholders or beneficial owners. 

G.S.R. 840(E), 13 November 2019 

Allowed customers verified through Aadhaar based authentication to provide a current address different from the address recorded in the Central Identities Data Repository. Reporting entities could accept a self declaration of the current address for customer due diligence, simplifying address verification requirements. 

G.S.R. 228(E), 31 March 2020 

Provided temporary relief for small accounts approaching closure due to customer due diligence requirements. The amendment allowed these accounts to remain operational from 1 April 2020 to 30 June 2020, with provision for further extension by the Central Government in view of the COVID 19 pandemic. 

G.S.R. 251(E), 13 April 2020 

Extended the deadline for reporting entities to submit prescribed transaction reports under Rule 8. The temporary measure allowed eligible reports to be furnished by 30 June 2020 to address operational difficulties arising from the COVID 19 pandemic. 

G.S.R. 254(E), 16 April 2020 

Specified the transaction reports eligible for the temporary reporting extension under Rule 8. The measure covered reports under Rule 3(1)(A), (B), (BA), (C) and (E) for March, April and May 2020 and Rule 3(1)(F) reports for the January to March 2020 quarter, with submission permitted until 30 June 2020. 

G.S.R. 798(E), 28 December 2020 

Notified real estate agents with annual turnover of twenty lakh rupees or more as persons carrying on a designated business or profession under the PMLA, bringing them within the reporting entity framework and subjecting them to applicable AML obligations. 

G.S.R. 575(E), 13 July 2022 

Introduced specific AML and KYC provisions for reporting entities operating in an International Financial Services Centre. The amendment recognised the head of the reporting entity in India as the designated officer for IFSC entities, expanded the list of officially valid documents for foreign nationals, introduced the definition of International Financial Services Centre, and provided exemptions from certain Central KYC Records Registry requirements for foreign national clients. 

S.O. 1074(E), 7 March 2023 

Strengthened the AML framework by reducing the beneficial ownership threshold to ten percent, introducing group wide AML policies, and defining group, politically exposed person and non profit organisation. It also enhanced customer due diligence requirements for legal persons and trusts and introduced registration requirements for eligible non profit organisations. 

G.S.R. 652(E), 4 September 2023 

Further strengthened the AML framework by reinforcing beneficial ownership requirements, group wide AML policies and customer due diligence requirements for legal persons and trusts, while strengthening registration obligations for eligible non profit organisations. 

G.S.R. 745(E), 17 October 2023 

Strengthened customer due diligence by requiring identity verification through reliable and independent sources, expanding group wide AML programmes, requiring suspicious transaction reports to be filed promptly once suspicion arises, and reinforcing confidentiality requirements for AML records and reports. 

G.S.R. 419(E), 19 July 2024 

Enhanced the Central KYC Records Registry framework by requiring reporting entities to use the KYC Identifier to retrieve customer records, restricting requests for duplicate KYC documents to specified circumstances, introducing a seven day period for updating KYC records, and requiring reporting entities to retrieve and use updated KYC information maintained in the Central KYC Records Registry. 

PML (Manner of Receiving Records Authenticated Outside India) Rules, 2005

A narrow but useful companion set. It governs how documents executed or authenticated outside India are received and relied upon, which matters when a Small Finance Bank onboards a customer whose documents originate abroad.

CFT Legislation

Unlawful Activities (Prevention) Act, 1967 (UAPA)

The counter terrorist financing pillar. Section 51A requires a Small Finance Bank to implement measures to give effect to designated lists and to freeze, without delay, funds or accounts of persons or entities designated under the applicable United Nations Security Council resolutions, preventing financial services from being used to support terrorism.

Procedure for implementing Section 51A of the UAPA

The operating manual for those freezes. It sets out how the designated lists are circulated, how a match is to be handled and reported, and the timelines a small finance bank must meet when a name on its books coincides with a listing.

CPF Legislation

Weapons of Mass Destruction Act, 2005 (WMD Act)

The counter proliferation financing pillar. Section 12A prohibits any person, a small finance bank included, from making funds or financial services available to those connected with the financing of weapons of mass destruction and their delivery systems.

Procedure for implementing Section 12A of the WMD Act

The companion procedure that makes Section 12A workable, describing how proliferation related designations reach a small finance bank and the freezing and reporting steps it must take on a match.

WMD (Implementation) Rules, 2016

The detailed rules under the WMD Act that fill in the mechanics of implementation, giving a small finance bank certainty on how the proliferation financing controls are to be applied in practice.

Overarching Obligations

The overarching obligations sit above any single sector and apply to a small finance bank’s KYC data and reports.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

Govern the central registry that stores customer KYC records for reuse across the financial system. A small finance bank files its KYC data to the CKYCR, retrieves a customer’s existing record on onboarding, and updates it within the prescribed window when details change, cutting duplicate paperwork for customers.

FINnet 2.0 Reporting Formats and the FINGate 2.0 User Manuals

Defines the electronic formats and the gateway through which a small finance bank files its cash, suspicious and other prescribed reports to FIU-IND, replacing the older FINnet system with the current FINnet 2.0 and FINGate 2.0 environment.

Sectoral: The Reserve Bank of India

The supervisor for small finance banks and the directions it issues. This is the sector specific layer, and the RBI Small Finance Banks KYC Directions are the instrument a small finance bank works from most closely.

Reserve Bank of India, the Supervisor

RBI (Small Finance Banks - Know Your Customer) Directions, 2025

The star instrument for a small finance bank. Issued by the Reserve Bank on 28 November 2025 and updated as of December 2025, this category specific Direction is the working KYC and AML rulebook for a small finance bank. It carries the customer due diligence, risk categorisation, beneficial ownership, periodic updates, monitoring, record-keeping and reporting requirements into the language of a small local bank, and it is where a small finance bank should look first for a rule that applies to its deposit and priority sector lending business.

RBI Consolidated Master Directions and KYC Compliance Notification (28 November 2025)

The covering notification that consolidated the RBI’s KYC framework into category specific Directions on 28 November 2025 and confirmed how the earlier instructions stand repealed or superseded, so a small finance bank knows which text now governs and can retire the superseded circulars.

RBI Internal Risk Assessment Guidance for ML/TF Risks (2024)

The Reserve Bank’s 2024 guidance requiring a small finance bank to run a documented assessment of its money laundering and terrorism financing risks across customers, products, channels and geographies, and to place the outcome before its board, making the risk based approach concrete.

RBI (Small Finance Banks) Responsible Business Conduct Directions, 2025

The Reserve Bank’s 2025 directions consolidating customer service and fair conduct rules for small finance banks. They are not an AML specific instrument, but a small finance bank reads them alongside the KYC Directions because good conduct and reliable customer information reinforce its AML controls.

Miscellaneous Official Reports and Guidance

Official reports and guidance that are not binding rules but shape how a small finance bank reads its risk and the wider enforcement picture.

FIU-IND Annual Report 2024 to 2025

The Financial Intelligence Unit’s yearly account of reporting volumes, typologies and enforcement trends, useful for a small finance bank calibrating what unusual deposit, cash or transfer activity looks like across the sector.

Directorate of Enforcement Annual Report 2025 to 2026

The ED’s yearly summary of PMLA investigations, attachments and prosecutions, a reminder of how the criminal side of the regime operates and where enforcement attention has fallen.

FIU-IND and its Core Functions and FAQs

FIU-IND’s explanation of its own role and a set of frequently asked questions, a plain language reference a small finance bank can use to understand registration and reporting expectations.

MHA National Counter Terrorism Policy and Strategy

The Ministry of Home Affairs statement of national counter terrorism policy, background that frames the UAPA sanctions obligations a small finance bank must apply.

International Standards

The global standards India’s framework is built to meet, and against which a small finance bank’s controls are ultimately judged.

FATF Recommendations

The Financial Action Task Force’s forty Recommendations are the international baseline for AML and CFT. A small finance bank’s duties reflect, and FATF updated Recommendation 6 on targeted financial sanctions in June 2026.

FATF Mutual Evaluation Report on India, 2024

The peer assessment of India’s AML and CFT regime, including the Executive Summary, which found India largely compliant and set the direction of travel that continues to shape supervision of small finance banks.

Basel Committee Guidance on ML/TF risk (2014, Revised 2020)

The Basel Committee’s sound management guidance on money laundering and terrorism financing risk, a supervisory benchmark for how bank should embed AML risk management, informative for a small finance bank’s own framework.

FATF Risk-Based Approach Guidance for the Banking Sector (2014)

FATF’s guidance on applying the risk based approach in a lending and deposit context, directly transferable to a small finance bank weighing customer, product, channel and geographic risk across its branches.

Allied Laws

The wider body of Indian law that intersects with AML duties for small finance banks, from the statute under which it is licensed to the predicate offence and enforcement Acts that give money laundering its underlying crimes.

Banking Regulation Act, 1949

The foundational statute for banking in India. It defines the banking business, licenses banks and gives the Reserve Bank its powers of supervision, making it the source of a small finance bank’s status as a banking company and the primary allied law for the sector.

Companies Act, 2013

Governs the incorporation, ownership and control of the corporate customers a small finance bank deals with and supplies the beneficial ownership and significant control concepts that customer due diligence relies on.

Foreign Exchange Management Act, 1999 (FEMA)

Regulates cross border funds and foreign investment, which a small finance bank must observe when a customer or transaction has an overseas dimension.

Predicate Offence and Enforcement Statutes

Money laundering is the laundering of the proceeds of some other crime, so the schedule of predicate offences and the allied enforcement statutes matter to a small finance bank assessing why funds might be tainted. These include the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money Act, 2015, the Foreign Contribution (Regulation) Act, 2010, COFEPOSA 1974, SAFEMA 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.

Core AML/CFT/CPF Obligations for Small Finance Banks in India

Across that framework, the regulations require a small finance bank to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each.

  • Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the institution can file its reports.
  • Appoint officers. Appoint a Designated Director and a management level Principal Officer under Rule 7 of the PMLR and the RBI Directions. The same person cannot hold both roles, and both are informed to FIU-IND and the RBI.
  • Conduct the internal risk assessment. Run an ML and TF risk assessment across customers, products, channels and geographies, document it, and take its outcome to the board, as the RBI Directions and the IRA Guidance require.
  • Document AML policy, controls and procedures. Adopt a board approved policy that turns the risk assessment into the institution’s operating procedures.
  • Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the RBI Small Finance Banks KYC Directions 2025. Given the microfinance and small ticket lending business, reliable identification of borrowers and group members, beneficial owner checks for non individual borrowers, and monitoring of cash disbursements and collections, are central.
  • Ongoing monitoring and periodic updates. Monitor transactions on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low risk customers. Review each customer’s risk categorisation at least once every six months.
  • Sanctions screening. Screen customers and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily.
  • Correspondent banking and wire transfers. For domestic and cross border wire transfers and for any correspondent or partner bank arrangement, apply the specific due diligence the PMLR and the RBI Directions require, including gathering and passing on complete originator and beneficiary information. A small finance bank rarely runs large cross border networks, but the transfer information and screening duties apply wherever it moves funds.
  • Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit currency reports, and cross border wire transfer reports of Rupees 5 lakh or more where applicable, under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly once the Principal Officer is satisfied, through FINnet 2.0.
  • Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0.
  • Training and awareness. Train staff by role to apply the controls and recognise red flags in a small finance bank, such as ghost or duplicate borrowers in group lending, cash disbursements or repayments inconsistent with a borrower’s profile, many small accounts used to structure funds, and third party operation of inclusion accounts.
  • Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.
  • Run group wide controls. Where the bank is part of a group, apply AML and CFT programmes at group level, including for branches and majority owned subsidiaries, as the RBI Directions require.

What This Article Does Not Cover

This article explains the laws and regulatory instruments that apply to small finance banks. It does not provide a control by control compliance manual, and it does not restate the Banking Regulation Act or the RBI’s small finance bank and priority sector rules except where they bear on the AML duties. For implementation, a small finance bank separately documents customer acceptance, KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction escalation, staff training, audit testing and board reporting. Those controls are the subject of the companion compliance guide.

To see how the small finance bank framework fits within the sector, see AML laws and regulations for the banking sector in India, and to place it within the national picture, see AML laws and regulations in India. 

From Regulation to Compliance: Your Next Step

Knowing the law is step one. These obligations only protect an institution when they are built into a working programme of risk assessment, policy, customer due diligence, monitoring, screening, reporting, training and independent review. For a small finance bank, reliable borrower and group identification, monitoring of cash disbursements and collections, and scaling AML controls to a fast growing book are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.

Want to confirm the 2025 directions for your institution?

AML India can walk you through the RBI Small Finance Banks KYC Directions, 2025 and build a proportionate programme for a small finance bank.

Frequently Asked Questions

A bank licensed by the Reserve Bank of India under the Banking Regulation Act, 1949 with a financial inclusion mandate to provide savings and credit to small businesses, marginal farmers, micro and small industries and the unorganised sector, lending a large share to the priority sector in mostly small ticket loans. It is a banking company and a reporting entity under the PMLA.

Yes. A small finance bank is a banking company, which is the first category named in the reporting entity definition in section 2(1)(wa) of the PMLA, so its AML duties apply directly. No separate designation notification is needed.

The Reserve Bank of India (Small Finance Banks – Know Your Customer) Directions, 2025, issued on 28 November 2025 and updated as on December 2025, read with the RBI Internal Risk Assessment Guidance of 2024 and the RBI Small Finance Banks Responsible Business Conduct Directions, 2025.

Because a small finance bank makes very large numbers of small ticket, often cash handled loans through group lending and microfinance models to financial inclusion customers, its main risks are weak identity in group lending, ghost or duplicate borrowers, cash disbursement and collection inconsistent with a borrower’s profile, and many small accounts used to structure funds. Reliable KYC and cash and disbursement monitoring are the core controls.

Cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit currency reports and, where it makes a cross border transfer, cross border wire transfer reports of Rupees 5 lakh or more. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly, through FINnet 2.0.

Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every small finance bank. It screens customers and beneficial owners against the United Nations and domestic designated lists and freezes and reports any match without delay.

Official sources and review

Why work with AML India

AML India helps small finance banks and other bank types meet their PMLA and RBI obligations, from risk assessment and policy through to CDD, screening, monitoring, reporting, training and independent review.

Industries we serve: small finance banks, commercial banks, small finance banks, payments banks, regional rural and cooperative banks, NBFCs, insurers, payment system operators, DNFBPs, securities intermediaries and IFSC and GIFT City entities.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik