Every time a bank opens an account or processes a large transaction, it is not just performing a financial service – it is acting as a frontline guard against money laundering and terrorism financing. The Prevention of Money Laundering Act, 2002 (PMLA), which came into force on 1st July 2005, places a set of clearly defined legal obligations on banks as reporting entities. Backed by the Reserve Bank of India’s (RBI) KYC directions and the Financial Intelligence Unit – India (FIU-IND) framework, these responsibilities are not optional – non-compliance attracts serious financial and legal penalties. Here is a detailed look at what banks are required to do under PMLA, 2002 and how the KYC framework supports this effort.

Table of Contents

What makes banks “reporting entities” under PMLA?

Under the PMLA, 2002, a reporting entity is defined as a banking company, financial institution, intermediary, or any person carrying on a designated business or profession. A banking company under PMLA includes a co-operative bank to which the Banking Regulation Act, 1949 applies, along with all scheduled commercial banks, regional rural banks (RRBs), local area banks, and urban co-operative banks. This broad scope means that virtually every institution accepting deposits or offering financial services is bound by PMLA’s obligations under Chapter IV of the Act.

The primary obligations on reporting entities – including maintaining records, verifying client identity, and reporting transactions – are laid down under Section 12 of the PMLA. Failure to comply can result in the Director of FIU-IND issuing warnings, directing compliance, or imposing a monetary penalty of not less than ₹10,000 and up to ₹1 lakh for each failure.

The KYC framework: knowing the customer before serving them

Know Your Customer (KYC) is the starting point of all anti-money laundering (AML) compliance in banking. The RBI introduced KYC guidelines in 2002 under the Banking Regulation Act, 1949, and these have since been consolidated through the RBI’s Master Direction on KYC, 2016. The core objective is straightforward: prevent banks from being used, intentionally or unintentionally, by criminal elements for money laundering or terrorism financing activities.

Every bank is required to have a board-approved KYC policy with four essential components:

  • Customer Acceptance Policy (CAP): Sets clear criteria for who can open an account. No account can be opened in an anonymous, fictitious, or benami name. Banks must also ensure they are not onboarding individuals or entities on sanctions or watch lists.
  • Customer Identification Procedure (CIP): Requires banks to collect and verify identity and address documents – officially valid documents (OVDs) – before establishing an account-based relationship or executing transactions above prescribed thresholds.
  • Risk Management: Banks must categorize customers by risk level (low, medium, high) based on the nature of their business, transaction patterns, and geographic exposure, and apply corresponding due diligence measures.
  • Transaction Monitoring: Banks must continuously track account activity and flag transactions that deviate from a customer’s normal financial behavior.

Customer due diligence (CDD) and enhanced due diligence (EDD)

Customer Due Diligence (CDD) as outlined in the RBI’s Master Direction involves verifying the identity of customers, beneficial owners, and entities to prevent money laundering, terrorist financing, and other illicit activities. This includes cross-verifying PAN or Form 60 for accounts requiring tax identification and identifying beneficial owners – natural persons who own or control more than 10% of a company’s shares or voting rights.

For high-risk customers – such as Politically Exposed Persons (PEPs), non-resident Indians with large transactions, or customers from high-risk jurisdictions – banks are required to apply Enhanced Due Diligence (EDD). This involves collecting additional information about the source of funds, purpose of the relationship, and expected transaction activity. Banks must also carry out periodic Money Laundering and Terrorist Financing (ML/TF) Risk Assessments to evaluate institutional vulnerabilities and update their internal controls accordingly.

Importantly, KYC is not a one-time exercise. Banks are required to conduct periodic updation of KYC records, and for accounts that remain non-compliant despite reminders, RBI guidelines mandate “partial freezing” – initially allowing credits but disallowing debits – before the account is eventually rendered inoperative.

Maintenance of records: what banks must preserve and for how long

Section 12 of PMLA imposes a clear duty on all reporting entities to maintain records in a manner that allows reconstruction of individual transactions. Records of all transactions must be maintained for a minimum of five years from the date of the transaction, while records of client identity, account files, and business correspondence must be retained for five years after the business relationship has ended or the account has been closed, whichever is later.

As per Rule 3 of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, banks must keep records of:

  • All cash transactions exceeding ₹10 lakh or their equivalent in foreign currency.
  • Series of cash transactions individually below ₹10 lakh but aggregating to above that limit within a single month – a provision designed to catch deliberate structuring of transactions to avoid reporting thresholds.
  • Cross-border wire transfers of more than ₹5 lakh or equivalent in foreign currency, where the funds originated from or were destined for India.
  • All transactions involving forged or counterfeit currency notes.
  • Receipts by non-profit organisations (NPOs) of more than ₹10 lakh or its equivalent.

Reporting obligations: what goes to FIU-IND and when

The Government of India set up the Financial Intelligence Unit – India (FIU-IND) on 18th November 2004 as an independent body reporting directly to the Economic Intelligence Council (EIC), headed by the Finance Minister. FIU-IND is India’s central agency for receiving, processing, analysing, and disseminating information about suspect financial transactions to enforcement agencies including the Enforcement Directorate (ED).

Banks are required to file several types of reports with FIU-IND. Each report corresponds to a specific category of transaction – from routine large cash dealings to suspicious activities and cross-border movements:

Cash Transaction Report (CTR)

The CTR covers all cash transactions exceeding ₹10 lakh in a single transaction, or a series of integrally connected smaller transactions in a month that cumulatively exceed this limit. Banks must submit CTRs to the Director of FIU-IND by the 15th day of the succeeding month for all such transactions recorded in the previous month.

Suspicious Transaction Report (STR)

The STR is the most critical reporting tool under PMLA. It applies to any transaction – cash or non-cash – that appears suspicious regardless of the amount involved. Indicators of suspicious transactions include transactions with no economic rationale, activity inconsistent with a customer’s declared business, sudden activity in dormant accounts, values inconsistent with the customer’s apparent financial standing, or amounts structured just below reporting thresholds to avoid detection.

The STR must be filed through the bank’s designated Principal Officer, who is located at the head or corporate office and is responsible for all monitoring, reporting, and liaison with enforcement agencies. The STR must be furnished within 7 days of reaching a conclusion that the transaction is suspicious, and importantly, the bank and its employees are prohibited from “tipping off” the customer that an STR has been filed – before, during, or after the submission. Section 14 of PMLA provides that the reporting entity, its directors, and employees shall not be liable to any civil or criminal proceeding for furnishing information under Section 12, offering legal protection to those who report in good faith.

Cross-Border Wire Transfer Report (CBWTR)

Banks must report all cross-border wire transfers exceeding ₹5 lakh or their foreign currency equivalent to FIU-IND, where the funds originated from or were destined for India.

Counterfeit Currency Report (CCR) and Non-Profit Organisation Transaction Report (NTR)

The CCR is filed when a bank identifies forged or counterfeit currency notes during a transaction. The NTR covers receipts by non-profit organisations exceeding ₹10 lakh, given the heightened risk of NPOs being used as conduits for terrorism financing.

All these reports are submitted electronically through FIU-IND’s FINGate 2.0 portal. Once submitted, FIU-IND may follow up with the reporting entity for additional information, and the data must be retained for at least five years.

AML policy, internal controls, and staff training

Beyond KYC and reporting, banks are required to establish a robust internal Anti-Money Laundering (AML) programme. This includes appointing a Principal Officer and a Designated Director at the board level who is accountable for PMLA compliance. Reporting entities must have a board-approved KYC policy encompassing customer acceptance, risk management, customer identification, and ongoing monitoring.

Banks must also invest in employee training to create KYC/AML awareness across all branches and back-office functions. The RBI’s Master Circular specifically requires banks to pay special attention to all complex, unusually large transactions, and unusual patterns which have no apparent economic or visible lawful purpose, and to prescribe threshold limits for different account categories beyond which transactions receive enhanced scrutiny.

The RBI’s KYC guidelines have evolved significantly over time. In 2024, the RBI updated KYC norms to enhance compliance and integrate advanced technology, including Aadhaar-based e-KYC, the Central KYC Records Registry (CKYCR) to reduce duplication across financial institutions, and video KYC for non-face-to-face customer onboarding. These updates reflect the practical challenge of maintaining rigorous standards in an increasingly digital banking environment.

Penalties for non-compliance

PMLA does not leave enforcement to goodwill. The Director of FIU-IND can impose fines on banks and other entities if they, and their employees, fail to comply with the provisions of Section 12. The Adjudicating Authority and Appellate Tribunal have jurisdiction over such cases. In addition, non-compliance can result in fines, legal consequences, reputational damage, and even suspension or loss of operating licences – consequences that no institution can afford to ignore.

Importantly, under the banking regulatory framework, RBI guidelines on KYC and AML are issued under Section 35A of the Banking Regulation Act, 1949 – meaning any contravention also attracts penalties under that Act, adding a second layer of regulatory accountability alongside PMLA.

The bigger picture: banks as partners in financial security

India’s AML framework draws heavily from the recommendations of the Financial Action Task Force (FATF) and the Customer Due Diligence paper of the Basel Committee on Banking Supervision – reflecting international best practices adapted to the Indian context. Banks are not passive recipients of these rules; they are active participants in a national and global effort to keep financial systems clean. When a bank flags a suspicious transaction or updates a customer’s KYC, it is contributing to a chain of intelligence that helps the Enforcement Directorate, FIU-IND, and other agencies track and prosecute financial crime.

The responsibilities under PMLA are detailed, ongoing, and demanding – but they exist for good reason. Money laundering and terrorism financing thrive on weak gatekeeping. By maintaining robust KYC standards, reporting accurately, and building strong internal AML cultures, banks serve not just their regulatory obligations but also the broader public interest.

What do you think? Given how sophisticated money laundering schemes have become – including through digital wallets and crypto transactions – do you think the current PMLA framework gives banks sufficient tools to detect and report suspicious activity effectively? And with co-operative banks now brought under the same PMLA obligations as scheduled commercial banks, are smaller institutions adequately equipped to meet these compliance demands?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://fiuindia.gov.in/files/FAQs/faqs.html
  2. https://sathee.iitk.ac.in/article/banking-article/kyc_know_your_customer_notes_meaning__objectives__benefits__rbi_norms/
  3. https://elplaw.in/wp-content/uploads/2024/12/Analysis-of-RBI-Norms-on-KYC-Data-Privacy-and-Confidentiality-Obligations-in-Banking.pdf
  4. https://www.pib.gov.in/newsite/PrintRelease.aspx?relid=113246
  5. https://amlindia.in/reporting-with-fiu-ind-under-pmla/
  6. https://www.sebi.gov.in/sebi_data/commondocs/cashreport_h.html
  7. https://fiuindia.gov.in/pdfs/downloads/SBA.pdf
  8. https://fiuindia.gov.in/pdfs/downloads/RBI01072010UKY.pdf
  9. https://www.signzy.com/blogs/complete-fiu-ind-reporting-guide-what-you-need-to-know
  10. https://www.lexology.com/library/detail.aspx?g=051102c5-9058-43c8-99c0-9c1def734dc4
  11. https://www.iibf.org.in/documents/kyc-aml-cft-pmla.pdf
  12. https://elplaw.in/wp-content-/uploads/2024/12/Analysis-of-RBI-Norms-on-KYC-Data-Privacy-and-Confidentiality-Obligations-in-Banking.pdf
  13. https://amlwatcher.com/our-coverage/india/

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Business Law as Applicable to Co-operative- II

1 Trade Union Act, 1926 and Industrial Disputes Act, 1947

  1. Introduction to Labour Laws in India
  2. The Trade Union Act 1926
  3. Introduction to Industrial Disputes Act 1947
  4. Strike and Lockout
  5. Lay Off and Retrenchment

2 Standing Order Act, 1946

  1. Introduction to Industrial Employment (Standing Order) Act 1946
  2. Standing Orders
  3. Matters to be Provided in the Standing Order
  4. Obligation of the Employees in Respect of Certified Standing Order
  5. Offences and Penalties

3 Domestic Enquiry – Proceedings and Principles

  1. Domestic Enquiry
  2. Principles of Natural Justice
  3. Preliminary Enquiry
  4. Charge-Sheet
  5. Procedure of Enquiry

4 Other Labour Welfare Acts

  1. The Employees Provident Fund and Miscellaneous Provision Act 1952
  2. The Payment of Gratuity Act 1972
  3. The Payment of Bonus Act 1965
  4. The Minimum Wages Act 1948
  5. The Employees State Insurance Act 1948

5 Reserve Bank of India Act, 1934 and Nabard Act, 1982

  1. Salient Features
  2. Bank of Issue of Currency
  3. Banker Agent and Adviser to the Government
  4. Banker to the Bank and Lender in the Last Resort
  5. Controller of Credit
  6. Foreign Exchange Reserves Manager and Custodian
  7. Rural Credit and Development
  8. NABARD Act 1982
  9. Transfer of Business to NABARD
  10. Sources of Raising Funds by NABARD
  11. Credit Functions
  12. Other Functions of NABARD

6 Banking Regulation Act, 1949

  1. Banking Regulation in India
  2. Areas Covered and Excluded for Co-operative Societies
  3. Important Business which a Co-operative Bank can Engage in
  4. Use of the Word ‘Bank’, ‘Banker’, and ‘Banking’
  5. Requirement of Minimum Paid-up Capital and Reserves
  6. Requirement of Minimum Cash Reserve and Liquid Assets
  7. Restrictions on Loans and Advances and their Remission
  8. Licensing of a Co-operative Bank and its Branches
  9. Preparation, Audit, and Publication of Bank Accounts and Balance Sheet
  10. Inspection
  11. Powers of RBI to Issue Direction
  12. Cognizance of Offences and Power of RBI to Impose Penalties

7 Negotiable Instruments Act, 1881

  1. Negotiable Instrument Act: History and Salient Features
  2. Distinction among Promissory Notes Bills of Exchange and Cheques
  3. Negotiability of Instruments
  4. Kinds of Endorsements
  5. Crossing of Cheque
  6. Material Alteration
  7. Inchoate Instruments or Incomplete Instruments
  8. Dishonour of Negotiable Instruments
  9. Dishonour of Cheque as a Criminal Offence

8 Recovery of Debts Due to Banks and Financial Institutions Act, 1993 and Sarfaesi Act, 2002

  1. Recovery of Debts due to Banks and Financial Institutions (RDDBFI) Act 1993
  2. Formation and Composition of the Debt Recovery Tribunal
  3. Distinction between DRT and DRAT
  4. Procedure of Tribunals
  5. Schedule of Fees
  6. Recovery Process
  7. Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest (SARFAESI) Act 2002
  8. Enforcement of Security Interest Rules 2002
  9. Amendments to the SARFAESI Act 2002

9 Prevention of Money Laundering Act, 2002

  1. Money Laundering
  2. Proceeds of Crime
  3. Persons
  4. Intermediary
  5. Scheduled Offences
  6. Limit of Cognizance
  7. Stages/Phases in Money Laundering
  8. Know Your Customer (KYC) and RBI Guidelines
  9. Risks a Bank Faces for Violating KYC / AML Guidelines
  10. Concept of Customer in KYC
  11. Safeguards for Opening of Accounts
  12. Relaxations in KYC Procedure for Low Income Group Persons
  13. Responsibilities of Banks under PMLA 2002 and KYC Guidelines
  14. Punishments and Actions

10 Other Misc. Laws

  1. Nature of Partnership
  2. Relations of Partners to one another and to Third Parties
  3. Kinds of Partners
  4. Incoming and Outgoing Partners – Reconstitution of a Firm
  5. Dissolution of a Firm
  6. Registration of Firm
  7. Salient Features of Payment and Settlement Systems Act 2007

11 Grievances Redressal Forums in Banking Sector

  1. Banking Ombudsman Scheme and Amendments Thereto
  2. Persons who can Complaint
  3. Grounds of Complaints
  4. Procedure for Filing the Complaint
  5. Reasons/Conditions for Non-consideration of Compliant by Banking Ombudsman
  6. Rejection of Complaint by the Banking Ombudsman
  7. Other Important Provisions in the Banking Ombudsman
  8. Appeal against the Decision of Banking Ombudsman