Every time a new bank account is opened in India, a quiet but important legal process kicks in. Before a single rupee is deposited, the bank is legally required to ask: Who are you, really? This isn’t mere bureaucratic formality. It is a direct mandate under the Prevention of Money Laundering Act, 2002 (PMLA), which came into force on July 1, 2005. The account-opening stage is where money laundering can be stopped before it even begins – and the law takes that seriously.
Table of Contents
- Why the account-opening stage matters so much
- The KYC framework: the backbone of account-opening safeguards
- Customer acceptance policy
- Customer identification procedure
- Risk-based approach to due diligence
- Standard due diligence
- Enhanced due diligence
- Prohibition on fictitious and benami accounts
- Identifying the beneficial owner
- Record-keeping obligations
- Ongoing monitoring: safeguards don’t stop at account opening
- Small accounts and limited KYC
- Consequences of non-compliance
Why the account-opening stage matters so much
Money laundering, at its core, is about disguising illegally obtained funds as legitimate income. One of the easiest ways to do this is to park dirty money in a bank account opened under a false identity or through a front person. Once money enters the formal banking system, tracing it back to its criminal origins becomes significantly harder. This is why safeguards at the account-opening stage are treated as the first line of defence in India’s anti-money laundering framework.
Sections 11A to 15 of the PMLA impose a range of obligations on what the law calls reporting entities – banks, financial institutions, non-banking financial companies (NBFCs), and certain intermediaries. These obligations include verifying the identity of clients and beneficial owners, maintaining records, and conducting enhanced due diligence where the risk demands it.
The KYC framework: the backbone of account-opening safeguards
The primary tool through which account-opening safeguards are implemented is the Know Your Customer (KYC) framework. As directed by the Reserve Bank of India (RBI) under its Master Circular on KYC norms, banks and financial institutions are required to follow a specific customer identification procedure when opening accounts and to monitor transactions of a suspicious nature for reporting to the appropriate authority.
The RBI’s KYC guidelines are issued under Section 35A of the Banking Regulation Act, 1949, and are read alongside Rule 7 of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005. Non-compliance can attract penalties under both these statutes.
Customer acceptance policy
Every bank must have a board-approved Customer Acceptance Policy (CAP). This policy lays down who may open an account, what information is required, and which categories of customers demand greater scrutiny. Reporting entities are required to have a board-approved KYC policy covering four key elements: customer acceptance policy, risk management, customer identification policy, and monitoring of transactions.
A fundamental rule under the CAP – and one that directly addresses the risk of laundering – is that no account shall be opened in anonymous or fictitious names, or in benami names. Rule 9(11) of the PML (Maintenance of Records) Rules, 2005 explicitly provides that no reporting entity shall allow the opening of, or keep, any anonymous account or account in fictitious names, or an account on behalf of other persons whose identity has not been disclosed or cannot be verified. This prohibition is absolute and non-negotiable.
Customer identification procedure
Once a prospective customer approaches a bank, the institution must collect sufficient information to establish the person’s identity beyond reasonable doubt. For individual customers, this means obtaining identity proof, address proof, and a recent photograph. For customers who are natural persons, banks must obtain sufficient identification data to verify the customer’s identity, address or location, and also a recent photograph. For legal persons or entities, the bank must verify the legal status of the entity and that any person purporting to act on its behalf is duly authorised.
Officially Valid Documents (OVDs) that banks typically accept include Aadhaar, Passport, Voter ID Card, Driving Licence, and PAN Card. With technological advancement, Digital KYC is now also permitted. Under the PML Rules, digital KYC involves capturing a live photograph of the customer along with their OVD, recording the latitude and longitude of the location, all done by an authorised officer of the reporting entity.
Risk-based approach to due diligence
Not every customer carries the same level of money laundering risk. The law recognises this and prescribes a risk-based approach to due diligence. Banks are required to prepare a risk profile for each customer at the time of account opening, categorising them as low, medium, or high risk based on factors such as their background, nature of business, source of funds, and geographic location.
Standard due diligence
For most customers – salaried individuals, small traders, and others whose financial profile is straightforward – standard Customer Due Diligence (CDD) applies. This involves identity verification, address verification, and understanding the expected nature and volume of transactions in the account.
Enhanced due diligence
Certain categories of customers attract a higher level of scrutiny. Examples of customers requiring higher due diligence include non-resident customers, high net worth individuals, trusts, charities, NGOs and organisations receiving donations, companies with close family shareholding or beneficial ownership, firms with sleeping partners, politically exposed persons (PEPs) of foreign origin, non-face-to-face customers, and those with a dubious reputation as per publicly available information.
For Politically Exposed Persons (PEPs) – individuals who hold or have held prominent public positions – the decision to open an account must be taken at a senior management level, and such accounts are subject to enhanced ongoing monitoring. The same standards extend to the immediate family members and close associates of PEPs.
Prohibition on fictitious and benami accounts
The prohibition on fictitious and benami accounts is one of the most critical safeguards in the PMLA framework. A benami account is one held in the name of one person but operated on behalf of – and for the benefit of – another, whose identity is deliberately concealed. Such accounts are classic vehicles for layering illegally obtained funds.
The law goes further. Professional intermediaries such as lawyers and chartered accountants are not permitted to open accounts on behalf of clients if they are unable to disclose the true identity of the account owner, or if any professional obligation of confidentiality prevents the institution from knowing who ultimately controls the funds. The bank’s ability to verify the true beneficial owner is paramount, and any arrangement that undermines this must be refused.
Identifying the beneficial owner
Modern financial structures – companies, trusts, partnerships – can obscure who actually controls an account or benefits from it. This is why the concept of beneficial ownership is central to account-opening safeguards. KYC procedures require identification of the ultimate or end beneficiary or controlling interest, with beneficial ownership defined as holding more than 25% of the shares, capital, or profits of a company, or more than 15% in a partnership firm or body of individuals.
When a client purports to act on behalf of another person, juridical entity, or trust, the reporting entity must verify that the person is actually authorised to do so, and must separately verify the identity of the person on whose behalf the account is being opened. Trustees, in particular, must disclose their status at the time of commencing an account-based relationship.
Record-keeping obligations
Opening an account creates a record-keeping obligation that persists long after the account is closed. Under Section 12 of the PMLA, reporting entities must maintain records of documents evidencing the identity of clients and beneficial owners, as well as account files and business correspondence. These records must be retained for five years after the business relationship has ended or the account has been closed, whichever is later.
Transaction records – particularly those involving cash transactions exceeding โน10 lakh, or suspicious transactions of any amount – must also be maintained and reported to the Financial Intelligence Unit – India (FIU-IND). A Suspicious Transaction Report (STR) must be filed within seven days of the transaction being identified as suspicious.
Ongoing monitoring: safeguards don’t stop at account opening
Account-opening safeguards are only effective if complemented by continuous monitoring. Ongoing monitoring is an essential element of effective KYC procedures. Banks can effectively control and reduce their risk only if they have a clear understanding of the normal and reasonable activity of the customer, enabling them to identify transactions that fall outside the regular pattern. Banks set threshold limits for account categories and are required to pay particular attention to transactions that exceed these limits or show no apparent economic rationale.
The RBI mandates robust KYC and AML standards including continuous transaction monitoring using technology, periodic risk assessments, identification of unusual patterns, and enhanced due diligence for high-risk accounts. Risk categorisation of accounts is also subject to periodic review, ensuring that a customer whose profile has changed – say, due to a sudden surge in deposits or a shift in business activity – is reassessed appropriately.
Small accounts and limited KYC
The law also addresses financial inclusion. Not everyone, particularly in rural or semi-urban India, can produce a full set of OVDs. For such individuals, banks are permitted to open small accounts with limited KYC compliance, subject to conditions. Where a person cannot produce the required documents, a bank may open an account provided there is an introduction from an existing account holder who has undergone full KYC, whose account is at least six months old and shows satisfactory transactions, and who certifies the new customer’s photograph and address. Such small accounts come with caps on balance and annual credits, and must be converted to full KYC accounts once the limits are approached.
Consequences of non-compliance
Failure to implement these safeguards is not a minor procedural lapse. Banks and their officers who do not comply with PMLA obligations face inquiry by the Enforcement Directorate (ED) and can attract penalties under both the PMLA and the Banking Regulation Act. The PMLA prescribes imprisonment ranging from three to ten years for the offence of money laundering itself, along with fines. Beyond individual penalties, institutions that fail to maintain robust account-opening safeguards expose themselves to regulatory action, reputational damage, and the very real risk of being used as conduits for financial crime.
What do you think? If a bank fails to detect that an account was opened using a fictitious identity, should the primary legal liability rest with the bank, the customer who provided false information, or both – and how should the law balance accountability in such cases? Also, as digital banking and video KYC become more common, do you think the current safeguards are sufficient to handle identity fraud in a fully paperless account-opening process?
References
- https://fiuindia.gov.in/files/AML_Legislation/pmla_2002.html
- https://globalinvestigationsreview.com/guide/the-guide-anti-money-laundering/third-edition/article/india-deep-dive-the-prevention-of-money-laundering-act-and-compliance-requirements
- https://fiuindia.gov.in/pdfs/downloads/85549.pdf
- https://www.lexology.com/library/detail.aspx?g=051102c5-9058-43c8-99c0-9c1def734dc4
- https://fiuindia.gov.in/files/AML_Legislation/notification.html
- https://fiuindia.gov.in/pdfs/downloads/RBI01072010UKY.pdf
- https://advocategandhi.com/section-12aa-pmla-understanding-enhanced-due-diligence-in-indias-anti-money-laundering-framework/
- https://www.helpagefinlease.com/policy/KYC_Policy.pdf
- https://www.nirmalbang.com/files/KYC-Policy-based-on-PMLA.pdf
- https://indiankanoon.org/doc/290623/
- https://www.rbi.org.in/commonman/Upload/English/Notification/PDFs/73IKYC010709_F.pdf
- https://www.biocatch.com/blog/india-money-mules-paradox
Leave a Reply