Last Updated  on: 21th August 2026       |        Last Reviewed on: 21th August 2026

Key takeaways at a glance

Who is covered: payments banks licensed under the Banking Regulation Act, 1949 to accept deposits up to the prescribed per-customer limit and to provide payments and remittance services, as banking companies and reporting entities under the PMLA.

Why they are covered: a payments bank is a banking company, which is the first-named reporting entity in section 2(1)(wa) of the PMLA, so its AML duties apply directly. No section 2(1)(sa) designation is needed.

Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the RBI (Payments Banks – Know Your Customer) Directions, 2025; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).

Supervisor: the Reserve Bank of India (RBI). Reports go to the Financial Intelligence Unit of India (FIU-IND); the Enforcement Directorate (ED) enforces the PMLA. 

Core duties: internal risk assessment, customer due diligence and KYC, beneficial owner identification, periodic updation, monitoring, prescribed transaction reporting, five-year record-keeping and sanctions screening.

This guide is general information on Indian law, not legal advice. For your bank’s specific position, speak to a qualified AML professional.

A payments bank is a differentiated bank licensed by the Reserve Bank of India to accept small deposits and provide payments and remittance services, but which cannot lend or issue credit cards. Its AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the RBI Payments Banks KYC Directions, 2025, Section 51A of the UAPA, Section 12A of the WMD Act, and the FIU-IND reporting framework. The Reserve Bank of India supervises payments banks, and reports are filed with FIU-IND. This guide is the payments banks’ entry in the banking series; other bank types, such as commercial, small finance, payments and cooperative banks, have their own guides.

The core instruments at a glance

Instrument  What it does for a payments bank 
PMLA, 2002  The parent Act. Names the banking company as a reporting entity and creates the core duties of CDD, record-keeping and reporting. 
PML (Maintenance of Records) Rules, 2005  Set out what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. 
RBI Payments Banks KYC Directions, 2025  The bank’s working rulebook, issued by the RBI on 28 November 2025 and updated as on December 2025, tailored to payments banks. 
RBI Internal Risk Assessment Guidance (2024)  Requires the bank to run an ML and TF risk assessment whose outcome goes to the board. 
UAPA Section 51A and WMD Act Section 12A  Impose targeted financial sanctions for terrorism and proliferation financing. 
FATF Recommendations   The international preventive measure standards for financial institutions that India’s framework is built to meet. 

What counts as a payments bank in India?

A payments bank is a small bank set up under the payments bank scheme and licensed by the Reserve Bank of India under the Banking Regulation Act, 1949, to operate within a compact area of a few contiguous districts. It accepts deposits from the public and lends to local individuals and small businesses, with a mandate to channel savings into the local economy and to serve areas that larger banks reach less easily. Local area banks are few in number and small in size, but they carry the full set of banking company AML duties, scaled to their business. 

The money laundering risk of a payments bank is a high-volume, small-value payments risk. It sits in the very large number of accounts, wallets and prepaid instruments onboarded at scale, often digitally, where identity can be weak; in the use of many small accounts or prepaid instruments to structure and layer funds below reporting thresholds; in mule accounts operated by third parties; and in domestic and cross-border remittance flows that can move value quickly. The framework therefore leans on robust digital KYC, on limits and monitoring across accounts and instruments, and on watching remittance and pass-through patterns. 

Are payments banks reporting entities under the PMLA?

Yes. Payments banks are reporting entities under the PMLA. Section 2(1)(wa) of the Prevention of Money-Laundering Act, 2002 expressly includes a banking company within the definition of reporting entity. A payments bank is a banking company and therefore falls within the PMLA reporting entity framework by virtue of its statutory status.

This places a payments bank in the same core group of reporting entities that file with FIU-IND as every other bank, and within the wider AML laws and regulations for the banking sector in India. The obligations are scaled to the bank’s size and risk, but the reporting entity status is not optional.

Supervisory authority for payments banks in India

The Reserve Bank of India (RBI) is the sectoral supervisor for payments banks. It licenses and regulates them and prescribes the KYC and AML requirements they must follow. The RBI Payments Banks KYC Directions, 2025, issued as part of the RBI’s consolidated, category-specific KYC framework and updated in December 2025, provide the principal original KYC requirements for payments banks. The RBI Internal Risk Assessment Guidance, 2024 supports the risk- based approach to managing money laundering and terrorist financing risk, while the Payments Banks Responsible Business Conduct Directions, 2025 address broader customer conduct requirements.

The Financial Intelligence Unit of India receives, analyses and disseminates the reports a payments bank files, and the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA. In short, the RBI sets and supervises the rules, FIU-IND receives the intelligence, and the ED enforces the criminal law.

AML Regulatory Requirements for Payments Banks in India

The law that governs a payments bank is spread across several instruments rather than gathered in one code. It is easiest to read as a layered framework, grouped as the core legislation, the overarching obligations, the sectoral supervisor and its directions, the miscellaneous official reports, the international standards, and the allied laws.

Core Legislation

The primary statutes and rules that create a payments bank’s AML, CFT and CPF duties, grouped into three subsets covering money laundering, terrorism financing and proliferation financing.

AML Legislation

Prevention of Money of Laundering Act, 2002 (PMLA)

India’s parent anti-money laundering statute and the source of a payments bank’s reporting entity status. It defines the offence of money laundering, empowers attachment and confiscation of the proceeds of crime, and casts the standing duties of customer due diligence, record-keeping and reporting onto every reporting entity, a payments bank among them.

Prevention of Money Laundering (Maintenance of Records) Rules, 2005 (PMLR)

The operational instrument of the Act. The PML Rules tell a payments bank how to verify a customer and identify the beneficial owner behind a corporate or non-individual account (Rule 9), which transactions must be recorded (Rule 3) and reported, and the applicable reporting timelines (Rules 7 and 8). Rule 9 also covers ongoing due diligence and risk assessment. Client identity records are maintained under Rule 10.

The PMLR amendment timeline

The PML (Maintenance of Records) Rules, 2005 have been amended many times. The table below is a legal-history timeline:

Gazette notification and date  Key change or rule touched 
G.S.R. 389(E), 24 May 2007  The earliest revision of the 2005 Rules. It extended the Rule 2 definition of a suspicious transaction to include dealings with no economic rationale or bona fide purpose and those pointing to terrorism financing, revised Rule 3 for cash tied to forged or counterfeit currency, substituted Rule 8 on furnishing information to the Director, and cut the Rule 9 requirement from three certified copies to one. 
G.S.R. 816(E), 12 November 2009 It added the non-profit organisation and Regulator definitions, revised the suspicious transaction test, and required non-profit receipts above Rupees 10 lakh to be reported. It set a ten-year record retention period under Rule 6 and Rule 9 around beneficial owner identification, ongoing due diligence, prohibition on anonymous accounts and a Client Identification Programme. 
G.S.R. 76(E), 12 February 2010  Amended Rules 3, 4, 5, 7 and 9 to reinforce record-keeping and the reporting references and, above all, introduced the first Explanation to Rule 9(1A), which treats the beneficial owner as the natural person who ultimately owns or controls a client or for whose benefit a transaction is undertaken. 
G.S.R. 508(E), 16 June 2010  Revised Rules 2, 9 and 10 covering definitions, customer due diligence and record-keeping, reshaping how a reporting entity identifies its customers and preserves the records.  
G.S.R. 980(E), 16 December 2010  Established the small account regime, defining the Designated Officer and the small account, including the NREGA job card and the Aadhaar letter into the officially valid documents in Rule 2, and adding Rule 9(2A) on how such accounts are opened and supervised. 
G.S.R. 481(E), 24 June 2011  Introduced the short title, edited Rule 1 to compress the long 2005 name into the Prevention of Money Laundering (Maintenance of Records) Rules, the PMLR shorthand adopted from then on. 
G.S.R. 576(E), 27 August 2013  Amended Rules 2 and 3 and added provisions after Rule 10, covering definitions, the cash and suspicious transaction reporting duties and the records framework so they are aligned with the reporting obligations. 
G.S.R. 288(E), 15 April 2015  Revised the Rule 2 definitions; since definitions decide who and what the operative rules capture, the change carried through the framework and started a run of 2015 updates. 
G.S.R. 544(E), 7 July 2015  Revised Rules 2, 9, 10 and inserted Rule 9A on definitions, customer due diligence and record-keeping, reconsidering how a reporting entity identifies customers and the records it maintains.  
G.S.R. 730(E), 22 September 2015  Inserted an explanation under Rule 2 stating that marriage certificate can be accepted as a supporting document for a subsequent name change in an officially valid document.  
G.S.R. 882(E), 18 November 2015  Revised the timeline under Rule 9A for the establishment of the central KYC records registry from 90 days to 180 days from the commencement of the amendment rules.  
G.S.R. 347(E), 12 April 2017  Amended Rule 2 and inserted Rule 9B, bringing the Central KYC Records Registry into the Rules, creating the duty to file customer KYC records centrally and the basis to reuse them, the structural groundwork of today’s CKYCR. 
G.S.R. 538(E), 1 June 2017  Amended Rules 2 and 9 to build Aadhaar into customer due diligence, prescribing Aadhaar-based identification and authentication for KYC, an approach the Supreme Court’s Aadhaar ruling later reshaped. 
G.S.R. 1038(E), 21 August 2017  Amended the Rule 2 definitions, reconsidering the defined terms that decide how the operative rules apply, one of several definition changes across 2017. 
G.S.R. 1318(E), 23 October 2017  A later 2017 amendment to the Rule 2 definitions, keeping the defined terms current as the framework kept moving. 
G.S.R. 456(E), 16 May 2018  Inserted a clause under Rule 9 obligating reporting entities to align their customer due diligence programme with their sector-specific guidelines and what must those guidelines cover. 
G.S.R. 1078(E), 31 October 2018  Revised the timeline under Rule 9 for filing a customer’s electronic CDD records on the registry from 3 days to 10 days.  
G.S.R. 108(E), 13 February 2019  Amended Rules 2 and 9 on definitions and customer due diligence, after the legislative changes to Aadhaar use, reconsidering the permitted means of identification. 
G.S.R. 381(E), 28 May 2019  Amended Rule 9, reconsidering the identification and verification process and the routes for confirming a customer’s identity, part of the post-Aadhaar reshaping of CDD. 
G.S.R. 582(E), 19 August 2019  Amended Rules 2 and 9 and added provisions after Rule 11, covering definitions, customer due diligence and the supporting provisions on information and records, among the broader 2019 updates. 
G.S.R. 669(E), 18 September 2019  Further revised Rule 2 and 9 to update key definitions and strengthen customer due diligence requirements relating to depository receipts. 
G.S.R. 840(E), 13 November 2019  Amended Rule 9 with additional edits to the identification and verification requirements. 
G.S.R. 228(E), 31 March 2020  Revised the validity of small accounts for the year 2020 and any subsequent period notified by the government.  
G.S.R. 251(E), 13 April 2020  Amended Rule 8, governing the submission of transaction reports to FIU-IND by revising the prescribed reporting timeline. 
G.S.R. 254(E), 16 April 2020  A follow-up Rule 8 amendment days after the previous one for the extension of the timeline for that specific quarter. 
G.S.R. 798(E), 28 December 2020  A landmark widening of the regime beyond the financial sector. Read with G.S.R. 799(E) and 800(E) of the same day, it designated real estate agents and dealers in precious metals and stones and appointed their regulator, reaching into the non-financial businesses. 
G.S.R. 575(E), 13 July 2022  Added the International Financial Services Centre definition with a purpose-built beneficial-owner provision for IFSC entities, and inserted an IFSC proviso into Rule 9A on the CKYCR, so the Rules matched the GIFT City regime, of note for a payments bank with an IFSC presence. 
S.O. 1074(E), 7 March 2023  A major amendment adding definitions of politically exposed persons, non-profit organisations and group and a Rule 3A duty for group-wide AML policies, and lowering the company beneficial ownership threshold from 25 to 10 per cent, with a matching edit to Rule 9(3)(e), squarely relevant to a payments bank identifying who controls a corporate or non-individual account holder. 
G.S.R. 652(E), 4 September 2023  The second major 2023 amendment. It placed the Principal Officer at management level, lowered the partnership beneficial ownership threshold from 15 to 10 per cent, added an Explanation of control, obliged trustees to disclose their status, and included the outcome of any Rule 3 and Rule 9 analysis in the records retained, all of which bear on a payments bank onboarding firms and partnerships as account holders. 
G.S.R. 745(E), 17 October 2023  Amended Rules 2, 3, 8 and 9 in a single notification, covering definitions, the reporting duties and customer due diligence, adjusting several operative provisions at once to close the 2023 changes. 
G.S.R. 419(E), 19 July 2024  Revised Rule 9(1C) on the KYC Identifier and set a seven-day deadline to update a CKYCR record after any change, added a duty to pull the updated record, and amended Rule 9A(2)(g) on filing, retrieving and using registry records, sharpening how current central KYC data is held. 

PML (Manner of Receiving Records Authenticated Outside India) Rules, 2005

A narrow but useful companion set. It fixes how records executed or authenticated outside India are to be received and relied on, which matters when a payments bank onboards a customer whose documents originate abroad.

CFT Legislation

Unlawful Activities (Prevention) Act, 1967 (UAPA)

The counter-terrorism financing statute. Its Section 51A obliges a payments bank to screen customers against the designated lists and to freeze, without delay, funds or accounts belonging to persons or entities named under United Nations Security Council resolutions, so that credit and investment products cannot service terrorism.

Procedure for implementing Section 51A of the UAPA

The operating manual for those freezes. It sets out how the designated lists are circulated, how a match is to be handled and reported, and the timelines a payments bank must meet when a name on its books coincides with a listing.

CPF Legislation

Weapons of Mass Destruction Act, 2005 (WMD Act)

The counter-proliferation financing statute. Its Section 12A prohibits any person, a payments bank included, from making funds or financial services available to those connected with the financing of weapons of mass destruction and their delivery systems.

Procedure for implementing Section 12A of the WMD Act

The companion procedure that makes Section 12A workable, describing how proliferation financing designations reach a payments bank and the freezing and reporting steps it must take on a match.

WMD (Implementation) Rules, 2016

The detailed rules under the WMD Act that fill in the mechanics of implementation, giving a payments bank certainty on how the proliferation-financing controls are to be applied in practice.

Overarching Obligations

The cross-cutting systems and procedures that sit above any single sector and carry a payments bank’s KYC data and reports.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

It sets out the operational framework for reporting entities, including payment banks to upload, retrieve, update and maintain customer KYC records through the central KYC records registry operated by CERSAI. They specify how KYC records are submitted, how existing records are retrieved and reused, and the process and timelines for updating records when customer information changes. For a payment bank, the guidelines make CKYCR the central mechanism for sharing and reusing verified KYC information across the financial system, reducing repetitive KYC collection while maintaining consistent customer records.

FINnet 2.0 reporting formats and the FINGate 2.0 user manuals

These instruments define the electronic formats and the gateway through which a payments bank files its cash, suspicious and other prescribed reports to FIU-IND, replacing the older FINnet system with the current FINnet 2.0 and FINGate 2.0 environment.

Sectoral Guidelines

The supervisor for payments banks and the directions it issues. This is the sector-specific layer, and the RBI Payments Banks KYC Directions are the instrument a payments bank works from most closely.

Reserve Bank of India, the supervisor

RBI (Payments Banks - Know Your Customer) Directions, 2025

The principal operational KYC and AML framework for payments banks. Issued by the RBI on 28 November 2025 and updated in December 2025, they set out the requirements for customer due diligence, risk categorisation, beneficial ownership, periodic updation, monitoring, record-keeping and reporting. For a payments bank, these directions should be the first point of reference for applying KYC and AML requirements to its deposit, payment and remittance activities.

RBI Consolidated Master Directions and KYC compliance notification (28 November 2025)

The covering notification that consolidated the RBI’s KYC framework into category-specific Directions on 28 November 2025 and confirmed how the earlier instructions stand repealed or superseded, so a payments bank knows which text now governs and can retire the superseded circulars.

RBI Internal Risk Assessment Guidance for ML/TF Risks (2024)

The Reserve Bank’s 2024 guidance requires a payments bank to run a documented assessment of its money laundering and terrorism financing risks across customers, products, channels and geographies, and to place the outcome before its board, making the risk-based approach concrete.

RBI (Payments Banks) Responsible Business Conduct Directions, 2025

The Reserve Bank’s 2025 directions consolidating customer service and fair conduct rules for payments banks. They are not an AML-specific instrument, but a payments bank reads them alongside the KYC Directions because good conduct and reliable customer information reinforce its AML controls.

Miscellaneous official reports and guidance

Official reports and guidance that are not binding rules but shape how a payments bank reads its risk and the wider enforcement picture.

FIU-IND Annual Report 2024-25

The Financial Intelligence Unit’s yearly account of reporting volumes, typologies and enforcement trends, useful for a payments bank calibrating what unusual deposit, cash or transfer activity looks like across the sector.

Directorate of Enforcement Annual Report 2025-26

The ED’s yearly summary of PMLA investigations, attachments and prosecutions, a reminder of how the criminal side of the regime operates and where enforcement attention has fallen.

FIU-IND and its Core Functions and FAQs

FIU-IND’s explanation of its own role and a set of frequently asked questions, a plain-language reference a payments bank can use to understand registration and reporting expectations.

MHA National Counter Terrorism Policy and Strategy

The Ministry of Home Affairs statement of national counter terrorism policy, background that frames the UAPA sanctions obligations a payments bank must apply.

International Standards

The global standards India’s framework is built to meet, and against which a payments bank’s controls are ultimately judged.

FATF Recommendations

The Recommendations provide the international baseline for AML, CFT and CPF. Recommendations 9 to 23 set out the preventive measures for financial institutions, which are reflected in the AML obligations applicable to payments banks. The Recommendations were last updated in June 2026, with a significant amendment to Recommendation 6 on targeted financial sanctions.

FATF Mutual Evaluation Report on India, 2024

The peer assessment of India’s AML and CFT regime, including the Executive Summary, which found India largely compliant and set the direction of travel that continues to shape supervision of financial institutions, including payments banks.

Basel Committee guidance on ML/TF risk (2020)

The Basel Committee’s sound management guidance on money laundering and terrorism financing risk, a supervisory benchmark for how a regulated financial institution should embed AML risk management, is informative for a payments bank’s own framework.

FATF Risk-Based Approach Guidance for the Banking Sector (2014)

FATF’s guidance on applying the risk-based approach in a lending and deposit context, directly transferable to a payments bank weighing customer, product, channel and geographic risk across its branches.

Allied Laws

The supporting body of Indian law that intersects with a payments bank’s AML duties, from the statute under which it is licensed to the predicate offence and enforcement Acts that give money laundering its underlying crimes.

Banking Regulation Act, 1949

The foundational statute for banking in India. It defines the banking business, licenses banks and gives the Reserve Bank its powers of supervision, making it the source of a payments bank’s status as a banking company and the primary allied law for the sector.

Reserve Bank of India Act, 1934

The central banking statute under which the RBI regulates the monetary and banking system, providing the supervisory backdrop against which a payments bank operates.

Companies Act, 2013

Governs the incorporation, ownership and control of the corporate customers a payments bank deals with, and supplies the beneficial ownership and significant control concepts that customer due diligence relies on.

Foreign Exchange Management Act, 1999 (FEMA)

Regulates cross-border funds and foreign investment, which a payments bank must observe when a customer or transaction has an overseas dimension.

Predicate offence and enforcement statutes

Money laundering is the laundering of the proceeds of some other crime, so the schedule of predicate offences and the allied enforcement statutes matter to a payments bank assessing why funds might be tainted. These include the Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023, the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money Act, 2015, the Foreign Contribution (Regulation) Act, 2010, COFEPOSA 1974, SAFEMA 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003.

Core AML/CFT/CPF Obligations for Payments Banks in India

Across that framework, the regulations require a payments bank to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each. 

  • Register with FIU-IND. Enrol on the FINnet 2.0 / FINGate 2.0 portal so the institution can file its reports. 
  • Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR and the RBI Directions. The same person cannot hold both roles, and both are to be informed to FIU-IND and the RBI. 
  • Conduct the internal risk assessment. Run an ML and TF risk assessment across customers, products, channels and geographies, document it, and take its outcome to the board, as the RBI Directions and the IRA Guidance require. 
  • Document AML policy, controls and procedures. Adopt a board-approved policy that turns the risk assessment into the institution’s operating procedures. 
  • Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals, with the separate trust test), with enhanced due diligence for politically exposed persons and high-risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the RBI Payments Banks KYC Directions 2025. Given the payments and remittance business at scale, robust digital identification of account, wallet and prepaid-instrument holders and any beneficial owner, and monitoring across accounts and instruments, are central. 
  • Ongoing monitoring and periodic updation. Monitor transactions on an ongoing basis, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low-risk customers respectively. Review each customer’s risk categorisation at least once every six months. 
  • Sanctions screening. Screen customers and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act, and freeze and report any match, verifying the relevant UNSC and domestic lists daily. 
  • Correspondent banking and wire transfers. For any correspondent banking relationship and for cross-border and domestic wire transfers, apply the specific due diligence the PMLR and the RBI Directions require, including gathering and passing on complete originator and beneficiary information and assessing the respondent institution. A payments bank rarely runs large correspondent networks, but the duty applies wherever it moves funds across borders or for another institution. 
  • Regulatory reporting. File cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit currency reports, and cross-border wire transfer reports of Rupees 5 lakh or more where applicable, under Rule 3 and Rule 8 of the PMLR. Cash and related reports are filed monthly, by the 15th day of the succeeding month; suspicious transaction reports are filed promptly once the Principal Officer is satisfied, through FINnet 2.0. 
  • Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction, and identity records, account files and correspondence for five years after the relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the CKYCR under Rule 9A, and file all prescribed reports through FINnet 2.0. 
  • Training and awareness. Train staff by role to apply the controls and recognise red flags in a payments bank, such as many small accounts or prepaid instruments used to structure funds, mule accounts operated by third parties, rapid pass-through of remittances, and onboarding patterns that suggest weak or shared identities. 
  • Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding. 
  • Run group-wide controls. Where the bank is part of a group, apply AML and CFT programmes at group level, including for branches and majority-owned subsidiaries, as the RBI Directions require. 

What this article does not cover

This article explains the laws and regulatory instruments applicable to payments banks from an AML, CFT and CPF perspective. It is not a control-by-control compliance manual and does not restate the Banking Regulation Act or the RBI’s payments bank operating rules except where they directly affect AML duties. For implementation, a payments bank separately documents customer acceptance, KYC and CDD procedures, beneficial owner identification, sanctions screening, transaction monitoring, suspicious transaction reporting, staff training, audit testing and board reporting. Those controls are the subject of the companion compliance guide.

To see how the payments bank framework fits within the sector, see AML laws and regulations for the banking sector in India, and to place it within the national picture, see AML laws and regulations in India.

From regulation to compliance: your next step

Understanding the law is only the first step. These obligations only protect an institution when they are built into a working programme of risk assessment, policy, customer due diligence, monitoring, screening, reporting, training and independent review. For a payments bank, robust digital KYC, limits and monitoring across accounts and instruments, and complete remittance information are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.

Frequently Asked Questions

A bank licensed by the Reserve Bank of India under the Banking Regulation Act, 1949 that can accept small deposits up to a prescribed limit per customer and provide payments, remittance and prepaid-instrument services, but which cannot lend or issue credit cards. It is a banking company and a reporting entity under the PMLA.

Yes. A payments bank is a banking company, which is the first category named in the reporting entity definition in section 2(1)(wa) of the PMLA, so its AML duties apply directly under the PMLA.

The Reserve Bank of India (Payments Banks – Know Your Customer) Directions, 2025, issued on 28 November 2025 and updated as of December 2025, read with the RBI Internal Risk Assessment Guidance of 2024 and the RBI Payments Banks Responsible Business Conduct Directions, 2025.

Because a payments bank onboards very large numbers of accounts, wallets and prepaid instruments, often digitally, and moves small-value payments and remittances at scale, its main risks are weak digital identity, structuring across many small accounts or instruments, mule accounts, and rapid pass-through of remittances. Robust KYC, limits and cross-account monitoring are the core controls.

Cash transaction reports for cash above Rupees 10 lakh, suspicious transaction reports of any value, counterfeit currency reports and cross-border wire transfer reports of Rupees 5 lakh or more where applicable. Cash and related reports are filed monthly by the 15th of the succeeding month, and suspicious transaction reports promptly, through FINnet 2.0.

Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every payments bank. It screens customers and beneficial owners against the United Nations and domestic designated lists and freezes and reports any match without delay.

Official Sources and Review

Why work with AML India

AML India helps payments banks and other bank types meet their PMLA and RBI obligations, from risk assessment and policy through to CDD, screening, monitoring, reporting, training and independent review.

Industries we serve: Payments Banks, Commercial Banks, Small Finance Banks, Regional Rural and Cooperative Banks, NBFCs, Insurers, Payment System Operators, DNFBPs, Securities Intermediaries and IFSC and GIFT City entities.

Want to confirm the 2025 directions for your institution?

AML India can walk you through the RBI Payments Banks KYC Directions, 2025 and build a proportionate programme for a payments bank.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik