KYC AML CFT and PMLA 2002: 2026 Compliance Guide for Bankers

Every banker who opens an account, monitors a transaction, or files a suspicious activity report is working inside the kyc aml framework, whether they realise it or not. For candidates preparing for the IIBF Certificate in KYC, AML and CFT, mastering kyc aml controls is not an abstract policy subject — it is the operational spine of modern compliance in Indian banking. Know Your Customer (KYC), Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT) together form an integrated defence that protects the financial system from misuse.
The legal backbone of this entire structure is the Prevention of Money Laundering Act, 2002 (PMLA 2002), supported by the PMLA Rules, 2005 and the RBI Master Direction on KYC. In 2026 the rules are tighter than ever: video-based customer identification (V-CIP), real-time transaction monitoring, periodic re-KYC, and beneficial-owner identification are all enforceable expectations. This guide breaks down the concepts you must know for the exam and the branch floor alike.
Understanding KYC, AML and CFT as One System
The three pillars are distinct but interlocking. KYC is the front door: it establishes who the customer is, verifies identity and address, and assesses the risk the customer poses. AML is the surveillance layer that watches money movement for laundering patterns — placement, layering and integration. CFT narrows the lens to detect funds destined for terrorism, however small the amount.
For the IIBF exam, remember the core KYC elements mandated by the RBI Master Direction:
- Customer Acceptance Policy (CAP) — rules on who may be onboarded and who may not (e.g. anonymous or fictitious accounts are prohibited).
- Customer Due Diligence (CDD) — identifying and verifying the customer and beneficial owner using Officially Valid Documents (OVDs).
- Risk Management — categorising customers as low, medium or high risk.
- Ongoing Monitoring — reviewing transactions against the expected profile.
A strong grasp of how these four kyc aml elements connect is exactly what the certificate tests. If you want to drill this with practice questions, the mock papers on our IIBF practice tests portal mirror the real exam pattern closely.
PMLA 2002: The Statutory Backbone
The PMLA 2002 came into force on 1 July 2005 and defines money laundering as the process of concealing the proceeds of crime and projecting them as untainted property. It is the law that gives KYC and AML their teeth. Key provisions every candidate should memorise:
- Section 3 defines the offence of money laundering; Section 4 prescribes punishment (rigorous imprisonment of 3 to 7 years, extendable to 10 years for certain scheduled offences, plus fine).
- Section 12 imposes obligations on reporting entities — banks, financial institutions and intermediaries — to maintain records, verify identity and report prescribed transactions.
- Section 5 and 8 empower attachment and confiscation of property involved in laundering.
- The Financial Intelligence Unit-India (FIU-IND) is the central national agency that receives, analyses and disseminates information about suspicious financial transactions.
Under the PMLA Rules, reporting entities must file the Cash Transaction Report (CTR) for cash transactions above ₹10 lakh, the Suspicious Transaction Report (STR) regardless of amount, the Counterfeit Currency Report (CCR), and the Cross-Border Wire Transfer Report. Records must be retained for five years from the date of transaction or account closure. Aspirants moving from JAIIB to specialised certificates often build this foundation through our JAIIB preparation course before tackling the KYC/AML certificate.

Risk Categorisation and Customer Due Diligence in 2026
A risk-based approach is now non-negotiable. Banks must profile every customer and apply diligence proportionate to the risk. Simplified Due Diligence applies to low-risk customers such as salaried individuals with stable profiles. Enhanced Due Diligence (EDD) is mandatory for high-risk categories — Politically Exposed Persons (PEPs), non-face-to-face customers, trusts, NGOs and customers from high-risk jurisdictions flagged by the FATF.
Periodic updation (re-KYC) timelines are a favourite exam point: every 2 years for high-risk, 8 years for medium-risk, and 10 years for low-risk customers. Where there is no change in details, even a self-declaration through internet banking, mobile app, email or letter is accepted in 2026, easing the customer burden.
Modern onboarding leans heavily on technology. V-CIP (Video-based Customer Identification Process) allows fully digital, RBI-compliant onboarding with live photo, OTP and geo-tagging. The Central KYC Records Registry (CKYCR), operated by CERSAI, stores a unique 14-digit KYC Identifier so a customer verified once need not repeat KYC across institutions. Aadhaar e-KYC, offline Aadhaar XML and DigiLocker-fetched OVDs all feed this ecosystem. Test your speed on these definitions with our quick-recall KYC term match game, a painless way to lock in the jargon.
Beneficial Ownership, Sanctions and CFT Controls
Identifying the beneficial owner — the natural person who ultimately owns or controls a customer — is central to defeating shell-company laundering. For companies, the threshold is ownership of more than 10% of shares or capital; for partnerships and trusts the rules differ slightly, and bankers must drill down through layers until a real human is identified.
On the CFT side, banks must screen customers and transactions against the UNSC sanctions lists (the consolidated list circulated by the Ministry of Home Affairs under UAPA), and freeze funds linked to designated individuals and entities without delay. The FATF (Financial Action Task Force) 40 Recommendations set the global standard; India is a member and its mutual-evaluation ratings directly shape RBI policy. Candidates should know the difference between FATF "grey list" and "black list" designations and their consequences.
Practical red flags that trigger an STR include structuring (splitting cash to dodge the ₹10 lakh CTR threshold), sudden high-value activity inconsistent with the profile, reluctance to provide KYC, and rapid movement of funds in and out of an account. A banker who spots and escalates these protects both the institution and the wider system. Stay current with circulars and notifications through the latest IIBF and RBI news page, which we update regularly.

Penalties, Governance and the Banker's Responsibility
Non-compliance is expensive. The RBI has levied crores in penalties on banks for KYC and AML lapses, and the PMLA empowers FIU-IND to impose monetary penalties on reporting entities and their designated directors. Every bank must appoint a Principal Officer responsible for filing CTRs and STRs, and a Designated Director accountable to the regulator. The board-approved kyc aml policy, staff training, and an independent audit of the compliance function are all mandatory.
For the IIBF candidate, the takeaway is that compliance is a shared duty — not just the Principal Officer's job. The teller who completes CDD properly, the relationship manager who questions an unusual remittance, and the operations officer who files an STR on time are all part of the same defence. Authoritative source material is published directly by the regulator; bookmark the Reserve Bank of India website for the live Master Direction on KYC, which is amended frequently. Those advancing to higher certifications can deepen risk and governance concepts through our CAIIB preparation course.
Frequently Asked Questions
What is the difference between CTR and STR under PMLA 2002?
A Cash Transaction Report (CTR) is filed for all cash transactions above ₹10 lakh in a month, regardless of suspicion. A Suspicious Transaction Report (STR) is filed whenever a transaction appears suspicious, irrespective of the amount. Both go to FIU-IND, but the STR is triggered by judgement, not a fixed threshold.
How often must banks update customer KYC records?
Periodic re-KYC follows risk category: every 2 years for high-risk customers, 8 years for medium-risk, and 10 years for low-risk customers. If customer details are unchanged, a self-declaration via internet banking, mobile app, email or letter is sufficient in 2026, avoiding a fresh branch visit.
Who is a beneficial owner in KYC norms?
A beneficial owner is the natural person who ultimately owns or controls a customer. For a company, it means anyone holding more than 10% of shares or capital, or exercising effective control. Banks must look through ownership layers until a real individual, not another entity, is identified and verified.
What is V-CIP and why does it matter for AML?
V-CIP, the Video-based Customer Identification Process, is an RBI-approved method of onboarding customers digitally through a live, consent-based video interaction with OTP and geo-tagging. It enables paperless, fraud-resistant KYC, supports remote account opening, and strengthens AML controls by capturing a verifiable live image and audit trail.
Final Takeaways
Mastering kyc aml cft compliance means understanding the law (PMLA 2002), the regulator's expectations (RBI Master Direction), and the practical red flags that protect your bank. Build your kyc aml knowledge around the reporting thresholds, the re-KYC timelines, beneficial-ownership rules, and the FATF context cold — these themes recur in every exam sitting. Ready to test yourself? Attempt a full-length mock on our IIBF certificate practice tests and review more concept guides on the iibf.store blog to walk into the exam hall confident.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading