KYC AML Compliance: PMLA 2002, FATF and CFT for Bankers
Every banker today is a frontline defender against financial crime, and that role rests on solid KYC AML compliance. Effective KYC AML compliance combines customer due diligence. Transaction monitoring and reporting under the Prevention of Money Laundering Act (PMLA) 2002, all shaped by global FATF standards. This guide explains the legal framework. The role of FIU-IND, and the practical obligations that bankers and IIBF candidates must master to combat money laundering and terror financing.
The PMLA 2002 framework
The Prevention of Money Laundering Act, 2002 is India's principal anti-money-laundering statute, brought into force in 2005. It criminalises the laundering of proceeds of crime and imposes detailed obligations on banks. Financial institutions and intermediaries — the foundation on which all KYC AML compliance in India is built.
Under the PMLA. Money laundering involves the classic three stages of placement (introducing illicit cash into the system), layering (moving it through complex transactions to disguise its origin) and integration (returning it to the criminal as apparently legitimate wealth). The Act empowers authorities to attach and confiscate tainted property and prescribes rigorous imprisonment of three to seven years.
Crucially, the PMLA makes banks reporting entities, obliging them to verify customer identity, maintain records and report suspicious and high-value transactions. The detailed implementation is governed by RBI's Master Direction on KYC, which every banker preparing for IIBF exams should know intimately. You can test your grasp on the practice mock tests at iibf.store.
KYC, customer due diligence and risk categorisation
Know Your Customer (KYC) is the cornerstone of KYC AML compliance. It requires banks to establish and verify the identity and address of every customer before opening an account and to understand the nature of the customer's activities and the source of funds.
The process operates at three levels:
- Customer Identification Procedure (CIP) — collecting officially valid documents such as Aadhaar, PAN, passport or voter ID.
- Customer Due Diligence (CDD) — assessing the customer's risk profile and intended transactions.
- Enhanced Due Diligence (EDD) — applied to higher-risk customers such as politically exposed persons (PEPs) and non-face-to-face accounts.

Banks must classify customers as low, medium or high risk and apply due diligence proportionate to that risk. Periodic re-KYC keeps records current, while ongoing monitoring flags transactions inconsistent with the customer's known profile. For the latest regulatory changes, follow IIBF news and updates.
FATF, FIU-IND and reporting obligations
The Financial Action Task Force (FATF) is the global standard-setter for anti-money-laundering and counter-terror-financing (AML/CFT). Its 40 Recommendations shape national laws, and India aligns its anti-money-laundering regime with these standards as an FATF member, undergoing periodic mutual evaluations.
Domestically, the Financial Intelligence Unit – India (FIU-IND) is the central agency that receives, analyses and disseminates information on suspect financial transactions. Banks must file several reports with FIU-IND:
| Report | Trigger |
|---|---|
| CTR (Cash Transaction Report) | Cash transactions above Rs 10 lakh in a month |
| STR (Suspicious Transaction Report) | Any transaction suspected to involve proceeds of crime |
| CCR (Counterfeit Currency Report) | Detection of forged or counterfeit notes |
| NTR (Non-profit Org Transaction Report) | Receipts by non-profit organisations above the threshold |

Authoritative guidance on filing is published by the official Financial Intelligence Unit – India. Bankers preparing for certification can reinforce these topics through the JAIIB course at iibf.store.
CFT compliance and the banker's responsibilities
Counter-Financing of Terrorism (CFT) sits alongside AML in the same regulatory framework. Banks must screen customers and transactions against UN Security Council sanctions lists and the lists circulated under the Unlawful Activities (Prevention) Act. Freezing assets where a match is found.
A banker's practical duties under KYC AML compliance include appointing a Principal Officer and Designated Director. Maintaining transaction records for the prescribed period (generally five years), training staff, and ensuring timely filing of STRs and CTRs. Failure to comply attracts heavy monetary penalties from the regulator and reputational damage. Diligent KYC AML compliance therefore protects both the bank and the integrity of the financial system.

For deeper study, pair this article with explainers on the iibf.store blog, which break down PMLA case scenarios and re-KYC procedures in exam-friendly detail.
Red flags, penalties and emerging challenges
Frontline staff are the first line of defence, so recognising red-flag indicators is vital. Classic warning signs include transactions inconsistent with a customer's stated profile. Sudden high-value cash deposits followed by quick transfers, reluctance to provide identification, use of multiple accounts to break up large sums (structuring or smurfing), and funds routed through shell entities. Any of these should trigger enhanced scrutiny and, where warranted, a Suspicious Transaction Report.
The cost of getting compliance wrong is steep. RBI has imposed substantial monetary penalties on banks for KYC and AML lapses. And the PMLA allows attachment of property and criminal prosecution of complicit officials. Beyond fines, the reputational fallout from being associated with laundering can be far more damaging than the penalty itself.
New challenges keep the field dynamic: digital onboarding through video-KYC, the rise of crypto-assets, mule accounts used in cyber fraud, and trade-based money laundering all stretch traditional controls. Banks are responding with AI-driven transaction monitoring and stronger beneficial-ownership checks. Staying current with these trends, through the match-the-concept game at iibf.store and regular reading, keeps both bankers and exam candidates ahead of the curve.
A practical point examiners love to probe is the distinction between a reporting obligation and a tipping-off prohibition. When a bank files a Suspicious Transaction Report. It must do so confidentially; warning the customer that an STR has been filed is itself an offence, because it could help the launderer destroy evidence or move funds. Equally, the duty to report does not require the bank to conclude that a crime has occurred — a reasonable ground for suspicion is enough. Internalising these nuances, rather than memorising thresholds alone, is what turns rote knowledge into genuine compliance competence and earns marks in scenario-based questions.
What is the difference between KYC and AML?
KYC (Know Your Customer) is the process of identifying and verifying customers and understanding their risk profile. AML (Anti-Money Laundering) is the broader framework of laws and controls — including KYC, monitoring and reporting — designed to prevent the laundering of illicit money.
What is the threshold for a Cash Transaction Report?
Banks must file a Cash Transaction Report (CTR) with FIU-IND for all cash transactions exceeding Rs 10 lakh. Or a series of integrally connected cash transactions exceeding that amount, within a calendar month.
What role does FATF play in India's AML regime?
FATF sets the global AML/CFT standards through its 40 Recommendations. As a member, India aligns its laws and the PMLA framework with these standards and is periodically evaluated to confirm effective implementation.
Who is the Principal Officer in a bank?
The Principal Officer is the designated official responsible for monitoring transactions, ensuring KYC AML compliance and filing suspicious and cash transaction reports with FIU-IND. The bank also nominates a Designated Director accountable for overall compliance.
Conclusion: Strong KYC AML compliance under the PMLA 2002 and FATF standards is the banker's shield against financial crime. Lock in these concepts with timed practice — start your free KYC and AML mock tests at iibf.store and build the confidence to clear your IIBF exam.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading