Anti-Money Laundering in India: KYC, AML and CFT Guide
The anti-money laundering framework in India is the legal. Supervisory architecture that stops criminals from disguising illicit funds as legitimate income. For candidates preparing the IIBF KYC.
AML and CFT certification. A firm command of the anti-money laundering regime is essential. Because the exam tests not just definitions.
How Know Your Customer rules. The Prevention of Money Laundering Act. FIU-India reporting fit together in daily branch practice.
This guide unpacks the RBI KYC Master Direction. Customer due diligence, statutory obligations and risk categorisation in plain language.
The RBI KYC Master Direction and Customer Identification
The foundation of the Indian anti-money laundering system is the RBI Master Direction on Know Your Customer. Issued under the Banking Regulation Act. The Prevention of Money Laundering Act (PMLA). It directs every regulated entity to frame a board-approved KYC policy covering four elements: a customer acceptance policy.
Customer identification procedures, monitoring of transactions, and risk management. Before opening any account. A bank must establish the identity. Address of the customer using Officially Valid Documents (OVDs) such as the passport. Voter ID, driving licence, Aadhaar or NREGA job card.
The Direction also permits Video-based Customer Identification Process (V-CIP). The Central KYC Records Registry (CKYCR). Which lets institutions share verified records and avoid duplication.
Periodic updation is mandatory — every two years for high-risk customers. Eight years for medium-risk and ten years for low-risk. A clear understanding of acceptable documents.
The difference between OVDs and deemed OVDs. And the timelines for re-KYC is heavily examined.
Candidates should also note that no account may be opened in an anonymous or fictitious name. And that simplified measures apply to small accounts. Basic savings deposit accounts to balance inclusion with control. The Direction further requires that customers be informed of the KYC requirements at the time of onboarding.
That a unique customer identification code be allotted to every customer. And that the same code be used across all relationships the customer holds with the institution. For legal entities.
Additional documents such as the certificate of incorporation. Memorandum of association and a board resolution are required. Reinforcing why the anti-money laundering process begins long before the first transaction is ever recorded.

Customer Due Diligence and Enhanced Due Diligence
Customer Due Diligence (CDD) is the engine of any anti-money laundering programme. At onboarding, a bank conducts standard CDD: verifying identity, understanding the nature of the customer's business, and assessing the expected pattern of transactions. Where the risk is higher — for politically exposed persons (PEPs), non-face-to-face customers, complex ownership structures or customers from higher-risk jurisdictions — the bank must apply Enhanced Due Diligence (EDD), which means obtaining additional information, senior-management approval and closer ongoing monitoring. A critical CDD requirement is identifying the beneficial owner: the natural person who ultimately owns or controls a customer, generally a holding of more than 10 per cent in a company or 15 per cent in a partnership or trust. Banks must look through layered corporate structures to reach this real human owner rather than stopping at a shell entity. Ongoing due diligence requires the institution to scrutinise transactions throughout the relationship to ensure they are consistent with its knowledge of the customer, their business and risk profile. When due diligence cannot be completed, the account must not be opened and the bank should consider filing a suspicious transaction report. Examiners frequently test the distinction between standard and enhanced measures, so candidates should be able to list the specific categories that automatically trigger EDD and the additional safeguards each one demands. Equally important is the concept of ongoing monitoring thresholds, where the bank sets transaction limits appropriate to each risk category and flags activity that breaches the expected profile for review by the compliance team. You can reinforce these layered concepts with structured revision on the CAIIB and certification course and reinforce recall using our term-matching games.

PMLA Obligations and FIU-India Reporting
The Prevention of Money Laundering Act, 2002 is the statutory spine of India's anti-money laundering effort, supported by the PML Rules. It defines money laundering, prescribes attachment and confiscation of proceeds of crime, and imposes hard obligations on every reporting entity. Banks must maintain records of all transactions for at least five years from the date of the transaction, preserve customer identification records for five years after the relationship ends, and report prescribed transactions to the Financial Intelligence Unit-India (FIU-IND). The key reports are the Cash Transaction Report (CTR) for cash transactions above ten lakh rupees in a month, the Suspicious Transaction Report (STR) regardless of amount whenever a transaction appears linked to crime, the Counterfeit Currency Report (CCR), and the Non-Profit Organisation Transaction Report (NTR). An STR must be filed within seven working days of establishing suspicion, and tipping off the customer is itself an offence. The designated Principal Officer is responsible for monitoring and filing these reports. Failure to comply attracts monetary penalties from the regulator and the FIU, and persistent lapses can invite supervisory action against the bank itself. Reporting entities must also ensure their core systems generate alerts automatically rather than relying solely on staff judgement, and they must train frontline employees so that suspicious patterns are escalated promptly to the Principal Officer for a filing decision. You can follow regulatory updates on our IIBF news page and confirm the statutory mandate directly on the FIU-India official website.

Risk Categorisation, CFT and Examination Tips
Combating the Financing of Terrorism (CFT) sits alongside anti-money laundering because the same controls catch both dirty money and funds destined for terror. A core obligation is screening customers and transactions against the UAPA designated lists and the United Nations Security Council sanctions lists; any match requires freezing of assets and immediate reporting. Risk-based categorisation underpins the entire framework: banks classify customers as low, medium or high risk based on identity, social and financial status, nature of business and geography, and then calibrate the depth of due diligence and the frequency of review accordingly. The Financial Action Task Force (FATF) sets the global standards that India implements, and India's mutual evaluations measure how well these controls work in practice. For the IIBF exam, focus on the numeric triggers — the ten-lakh CTR threshold, the seven-day STR deadline, the five-year record-retention rule and the beneficial-ownership percentages — because these are tested almost every cycle. Practise applying them to short case studies rather than memorising in isolation. It also helps to remember the institutional architecture: the Principal Officer files reports, the Designated Director takes overall responsibility for compliance, FIU-India receives and analyses the reports, and the Enforcement Directorate investigates and prosecutes offences under the Act. Knowing who does what prevents the common mistake of confusing the reporting entity's duties with those of the investigating agencies. A strong anti-money laundering answer in the exam links a control to its purpose, its legal source and the body that enforces it. Time-bound revision on our mock test series and quick reference to current policy on the RBI rates and resources tracker will sharpen both speed and accuracy.
Frequently Asked Questions
What is the difference between CDD and EDD?
Customer Due Diligence is the standard process of verifying identity. Understanding a customer's transactions applied to every account. Enhanced Due Diligence is a deeper layer reserved for higher-risk customers such as politically exposed persons. Requiring extra information, senior-management approval and closer ongoing monitoring of activity.
When must a bank file an STR with FIU-India?
A Suspicious Transaction Report must be filed whenever a transaction appears connected to the proceeds of crime. Regardless of the amount involved. The reporting entity must file it with FIU-India within seven working days of forming the suspicion. And warning the customer. Known as tipping off, is itself a punishable offence.
Who is a beneficial owner under the KYC rules?
A beneficial owner is the natural person who ultimately owns or controls a customer. The thresholds are generally a holding of more than ten per cent in a company. Fifteen per cent in a partnership or trust. Banks must look through layered structures to identify this real individual.
How long must banks retain transaction records under PMLA?
Under the Prevention of Money Laundering Act. Banks must preserve records of all transactions for at least five years from the date of the transaction. Customer identification. Account-opening records must be kept for five years after the business relationship with the customer has ended.
Conclusion
The anti-money laundering framework is best mastered as one connected chain: KYC identifies the customer, due diligence understands them, risk categorisation calibrates the scrutiny, and FIU-India reporting closes the loop when something looks wrong. Anchor every rule to a numeric trigger and a real branch scenario, and the KYC, AML and CFT paper becomes far more predictable. Ready to convert this into marks? Attempt a full-length KYC AML mock test and explore more exam-ready notes on our banking exam blog today.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Use the free tests to check what you know.
Watch the video if a part feels hard.
Do a bit each day.
Ask us on WhatsApp if you get stuck.
You can pass this exam.
Stay calm and trust your prep.
Come back to this guide often.
Small steps add up fast.
Skim the box below first.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Watch the video if a part feels hard.
Do a bit each day.
Ask us on WhatsApp if you get stuck.
You can pass this exam.
Stay calm and trust your prep.
Come back to this guide often.
Small steps add up fast.
Skim the box below first.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Watch the video if a part feels hard.
Do a bit each day.
Ask us on WhatsApp if you get stuck.
You can pass this exam.
Stay calm and trust your prep.
Come back to this guide often.
Small steps add up fast.
Skim the box below first.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Watch the video if a part feels hard.
Do a bit each day.
Ask us on WhatsApp if you get stuck.
You can pass this exam.
Stay calm and trust your prep.
Come back to this guide often.
Small steps add up fast.
Skim the box below first.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading