AML Compliance in Indian Banks: IIBF KYC AML Guide 2026
Strong AML compliance sits at the very heart of every banking relationship in India. And it is one of the most heavily tested areas in the IIBF KYC AML certification 2026. Anti-money laundering.
Combating the financing of terrorism (AML/CFT) controls protect the financial system from being misused for laundering proceeds of crime or funding terror. For bankers. Mastering customer due diligence.
Risk categorisation. Reporting obligations under the Prevention of Money Laundering Act (PMLA). The role of FIU-IND is non-negotiable.
This guide breaks the framework down exactly as the exam expects.
What Anti-Money-Laundering Means in Indian Banking
This anti-money-laundering discipline is the structured set of policies. Procedures and controls a bank applies to detect. Prevent and report money laundering and terror financing.
It flows from the PMLA. 2002 and the RBI Master Direction on Know Your Customer (KYC). The objective is simple: ensure the bank knows who its customer is.
Understands the nature of their dealings. And can spot transactions that do not fit their profile. The framework rests on four interlocking pillars that every reporting entity must operate continuously.
- Customer acceptance policy (CAP). Defines who the bank will and will not onboard.
- Customer due diligence (CDD) — identity verification and risk profiling at onboarding.
- Ongoing monitoring — watching transactions against the expected profile.
- Reporting — filing prescribed reports with the Financial Intelligence Unit (FIU-IND).
A bank that fails on these obligations exposes itself to heavy monetary penalties, reputational damage and regulatory action, and individual officers can also face accountability. Globally, weak controls have led to billion-dollar fines, which is why Indian regulators treat the area as a priority supervisory theme. To keep pace with evolving rules, candidates should track the latest circulars via IIBF news and updates and revise frequently.
CDD, EDD and Risk Categorisation
The backbone of AML compliance is customer due diligence. At onboarding. The bank verifies identity and address using officially valid documents.
Establishes the beneficial owner, and assigns a risk category. Customers are placed into low. Medium and high risk buckets based on identity.
Occupation, geography, products used and expected activity.
- Low risk — salaried individuals, government departments, well-regulated entities.
- Medium risk — customers needing slightly closer monitoring.
- High risk — non-resident customers, trusts, politically exposed persons (PEPs) and cash-intensive businesses.
High-risk customers attract Enhanced Due Diligence (EDD): additional documentation, senior-management sign-off, source-of-funds checks and more frequent review. Low-risk customers may be onboarded with simplified measures. You can sharpen recall of these tiers with the match-the-pairs revision game before the exam.

STR and CTR Reporting to FIU-IND
Reporting is where the framework becomes operational. Under PMLA rules. Every banking company is a reporting entity.
Must file prescribed reports with FIU-IND. The central national agency that receives. Analyses and disseminates financial intelligence to enforcement bodies.
- CTR (Cash Transaction Report). All cash transactions above the prescribed threshold (and integrally connected transactions). Filed monthly.
- STR (Suspicious Transaction Report) — any transaction that appears suspicious regardless of amount. Filed promptly once suspicion is formed.
- CCR — counterfeit currency reports.
- NTR / CBWTR — non-profit and cross-border wire transfer reports.
An STR is triggered by red flags such as transactions with no economic rationale, structuring to avoid thresholds, or activity inconsistent with the customer profile. Importantly, the bank must not tip off the customer that an STR has been filed. Practising mock questions on these report types at IIBF practice tests helps lock in the differences.
PMLA Obligations, Record-Keeping and PEPs
The PMLA imposes concrete statutory duties that underpin AML compliance. Banks must maintain records of all transactions. The documents obtained for identity.
Preserve them for the prescribed period (generally five years from the date of transaction or end of relationship). And make them available to authorities on demand. The bank must appoint a Principal Officer.
A Designated Director responsible for reporting and overall compliance.
Politically Exposed Persons (PEPs) — individuals entrusted with prominent public functions abroad — always attract EDD, including establishing source of wealth and senior-management approval. The framework is benchmarked against the Financial Action Task Force (FATF) 40 Recommendations, the global standard that India follows as a member. Staying current with regulatory rates and thresholds is easier using the RBI rates reference.

Why This Matters for the IIBF KYC AML Certification Paper
The KYC AML paper rewards candidates who can connect concepts to obligations rather than memorise definitions in isolation. Expect questions linking a customer scenario to the correct risk category, asking which report (STR vs CTR) applies, or testing record-keeping periods and the role of the Principal Officer. Many questions hinge on the distinction between CDD and EDD, and on FATF/PMLA terminology. Build a one-page summary of the reporting matrix, revise PEP rules, and read banking case studies on the IIBF preparation blog. A useful technique is to draw the customer journey end to end: acceptance policy, identity verification, risk grading, ongoing monitoring, alert generation and finally reporting, so each concept slots into a logical sequence rather than floating in isolation. Pay special attention to the wording of PMLA definitions, the threshold-and-timeline detail of each report type, and the responsibilities of the Principal Officer and Designated Director, since these precise points are exactly what multiple-choice questions probe. A confident grasp of AML compliance can comfortably secure a large block of marks in this paper.
For authoritative source material, always cross-check with the Reserve Bank of India Master Direction on KYC and the certification syllabus published by the Indian Institute of Banking & Finance.
Frequently Asked Questions
What is the difference between CDD and EDD?
Customer Due Diligence (CDD) is the standard identity verification. Risk profiling applied to all customers at onboarding and during the relationship. Enhanced Due Diligence (EDD) is the deeper scrutiny reserved for high-risk customers such as PEPs.
Non-residents. Involving extra documentation. Source-of-funds checks, senior-management approval and more frequent ongoing monitoring of the relationship.
When must a bank file an STR?
A bank files a Suspicious Transaction Report whenever a transaction or attempted transaction appears suspicious. Regardless of the amount involved. Triggers include activity with no clear economic rationale.
Structuring to dodge reporting thresholds, or behaviour inconsistent with the customer's profile. The STR is filed promptly with FIU-IND. And the bank must never tip off the customer that a report has been made.
How long must AML records be retained?
Under PMLA rules. Banks must preserve transaction records and identification documents for the prescribed period. Generally five years from the date of the transaction or from the end of the business relationship.
Whichever applies. These records must be kept retrievable. Authorities.
FIU-IND can access them on demand during any investigation or audit.
What is FIU-IND's role in the framework?
The Financial Intelligence Unit-India (FIU-IND) is the central national agency responsible for receiving. Processing, analysing and disseminating information relating to suspicious financial transactions. Banks.
As reporting entities, submit CTRs, STRs and other prescribed reports to FIU-IND. The unit then shares actionable intelligence with enforcement. Intelligence agencies to combat money laundering and terror financing.
Conclusion: Turn AML Mastery into Exam Marks
AML compliance is both a real-world responsibility and a high-yield exam topic. Lock in CDD/EDD, the low-medium-high risk tiers, PMLA reporting and FATF benchmarks, then test yourself relentlessly. Start your revision with free IIBF mock tests and deepen your conceptual base on the IIBF preparation blog to walk into the 2026 certification exam fully prepared.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Use the free tests to check what you know.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.