Anti-Money Laundering Framework for Bankers 2026: PMLA Guide

KYCAML By Ashish Jain · IIBF STORE Editorial · 13 June 2026 · Updated 30 Jul 2026 · 11 min read · 32 views
Anti-Money Laundering Framework for Bankers 2026: PMLA Guide

The anti-money laundering framework has turned every Indian banker into a frontline guardian of the financial system, and for candidates sitting the IIBF KYC, AML and CFT certification it is the single most important topic to master. From the branch teller flagging an unusual cash deposit to the compliance officer filing a report with the regulator, the rules of this framework decide how clean money stays separated from criminal proceeds. This guide walks you through the entire machinery, the law, the reporting duties, the customer checks, and the global standards, in plain, exam-ready English.

Whether your goal is to clear the paper in one attempt or to discharge your real compliance duties with confidence, understanding how the Prevention of Money Laundering Act (PMLA) sits at the centre of it all is non-negotiable. Let us build that understanding from first principles.

Anti-money laundering framework for bankers: PMLA, KYC and FIU-IND reporting explained
The anti-money laundering framework links PMLA, KYC due diligence and FIU-IND reporting into one chain.

Key Takeaways

  • The anti-money laundering framework is anchored by the PMLA, 2002, which criminalises laundering and empowers asset attachment.
  • Money laundering moves through three stages: placement, layering and integration.
  • Banks report to FIU-IND through CTR, STR, CCR and NTR filings; the STR is suspicion-driven, not threshold-driven.
  • KYC and Customer Due Diligence (CDD) form the first line of defence, with Enhanced Due Diligence for high-risk customers.
  • India's regime aligns with the FATF forty recommendations; record-keeping runs for a prescribed period (commonly cited as five years).

What Money Laundering Actually Means

Money laundering is the process of disguising the illegal origins of criminal proceeds so that tainted wealth re-enters the economy looking perfectly legitimate. The entire anti-money laundering framework exists to detect and disrupt this process before that happens. Criminals target banks precisely because banks provide the accounts, transfers and instruments needed to move money quietly.

The classic, examiner-favourite model breaks the activity into three sequential stages:

  • Placement — introducing illicit cash into the formal financial system, for example through structured deposits.
  • Layering — moving the funds through a web of complex transactions to obscure the audit trail.
  • Integration — bringing the now-disguised money back into the economy as apparently clean, spendable wealth.

If you can identify which stage a given scenario describes, you can answer a large share of conceptual questions in the paper. The same three-stage logic underpins why each control in the framework exists, so it is worth over-learning.

The PMLA, 2002: The Parent Law

The Prevention of Money Laundering Act, 2002 is the backbone of India's anti-money laundering framework. It does three big things at once: it makes money laundering a criminal offence, it allows the State to attach and confiscate the proceeds of crime, and it obliges banks and other reporting entities to keep records and report suspicious activity.

For the exam, lock down these core features of PMLA:

  • It defines money laundering and ties it to scheduled (predicate) offences listed under the Act.
  • It empowers the Enforcement Directorate (ED) to investigate offences and attach assets.
  • It mandates reporting entities — banks, financial institutions and intermediaries — to verify customer identity and maintain records.
  • It establishes the Financial Intelligence Unit (FIU-IND) as the central agency that receives transaction reports.

Think of PMLA as the parent law from which every bank-level obligation flows, with RBI's Master Direction on KYC then operationalising these duties for banks. Remember that PMLA has been amended several times; for the exact, current scheduled offences and thresholds, confirm against the latest released IIBF notification rather than memorising figures that may have moved on.

FIU-IND and the Reporting Obligations

The Financial Intelligence Unit-India (FIU-IND) is the national agency that receives, analyses and disseminates information about suspicious or large financial transactions. Under the anti-money laundering framework, every bank must file specific reports with FIU-IND, and knowing each one cold is a guaranteed scorer in the paper.

The table below summarises the four reports candidates are most often tested on. Treat the amounts as the commonly cited figures and verify the current thresholds in the latest PMLA rules and IIBF notification.

Report What It Covers Trigger
CTR — Cash Transaction Report High-value cash transactions in a month Cash above the prescribed limit (commonly cited as INR 10 lakh)
STR — Suspicious Transaction Report Any transaction raising suspicion of laundering or terror financing Suspicion — no minimum amount
CCR — Counterfeit Currency Report Forged or counterfeit notes detected Detection of counterfeit currency
NTR — Non-profit Transaction Report Receipts by non-profit organisations NPO receipts above the prescribed limit

The Suspicious Transaction Report (STR) deserves special attention because suspicion — not a rupee threshold — triggers it. Each bank designates a Principal Officer who is responsible for filing these reports, while a board-level Designated Director carries overall compliance responsibility. Examiners love to test who does what, so commit those two roles to memory. You can drill the report types quickly with our KYC AML mock tests before moving on.

KYC and Customer Due Diligence (CDD)

Know Your Customer (KYC) is the first line of defence in the anti-money laundering framework. RBI's Master Direction on KYC requires banks to identify and verify every customer and to understand the nature of their dealings through Customer Due Diligence. Get the customer-onboarding gate right, and most laundering attempts never make it through the door.

The core CDD elements you must be able to list are:

  1. Identity verification using Officially Valid Documents (OVDs).
  2. Beneficial owner identification — the natural person who ultimately owns or controls the account.
  3. Purpose and intended nature of the business relationship.
  4. Ongoing monitoring of transactions for consistency with the customer's profile.

Customers are placed into low, medium or high risk categories. High-risk customers — including Politically Exposed Persons (PEPs) — attract Enhanced Due Diligence (EDD), which means closer verification and tighter monitoring. This risk-based approach is the philosophical heart of the syllabus and appears year after year. For a deeper treatment of how CDD ties into the law, read our companion guide on the PMLA, FATF and Customer Due Diligence framework.

Record-Keeping, Beneficial Ownership and CFT

A disciplined paper trail is what allows investigators to reconstruct how money moved. Banks must therefore retain transaction records and customer identification records for a prescribed period — commonly cited as five years, though you should confirm the current period against the latest PMLA rules. Identifying the beneficial owner behind every account is equally vital, because shell companies and layered ownership structures are favourite tools for hiding the real controller.

KYC due diligence, beneficial ownership and CFT controls in the anti-money laundering framework
Record-keeping and beneficial-ownership checks let investigators reconstruct the money trail.

Combating the Financing of Terrorism (CFT) runs in parallel with AML. Here, banks must screen customers against designated sanctions lists — such as those notified under the Unlawful Activities (Prevention) Act — and freeze assets where the law requires. Because CFT focuses on the destination of funds rather than their origin, scenario questions often test whether you can tell an AML duty apart from a CFT duty. Keep that distinction crisp.

Exam tip: If a question describes hiding the source of dirty money, think AML. If it describes funding a future illegal or terror activity, think CFT. The same KYC machinery supports both, but the trigger and intent differ.

FATF, Global Standards and Recent Reforms

India's anti-money laundering framework is built to align with the Financial Action Task Force (FATF), the global standard-setter whose forty recommendations shape national laws around the world. India's strong showing in its FATF mutual evaluation reflects a maturing, credible regime — a point worth knowing for current-affairs-style questions.

Reforms relevant to recent candidates have broadened the net. As per the latest released notifications, these include bringing Virtual Digital Asset (VDA) service providers and certain professionals under PMLA reporting, tightening beneficial-ownership thresholds, and strengthening PEP screening. Because this area moves quickly, treat any specific date or figure as time-sensitive and always confirm it on the official IIBF notification. To see how these themes recur across recent papers, browse all our KYC AML exam guides.

A Practical Study Plan for the AML Paper

Knowledge without a method rarely survives exam pressure. Here is a focused, four-step plan that consistently works for one-attempt achievers in the KYC, AML and CFT module.

  1. Build a one-page master sheet covering the three laundering stages, PMLA's key features, the four FIU-IND reports, the CDD and EDD elements, the record-retention rule and the FATF link.
  2. Anchor the roles — Principal Officer files reports, Designated Director owns overall compliance, ED investigates and FIU-IND receives. Mix-ups here cost easy marks.
  3. Drill with timed mocks. Aim to finish full papers with time to spare, then review every wrong answer until recall is instant. Start with our IIBF practice tests.
  4. Reinforce vocabulary with active recall. Our KYC AML matching game is a fast way to lock in terms like layering, EDD, beneficial owner and predicate offence.

Spend your first week building first-principles intuition before piling on mock tests; the case-study section rewards conceptual clarity far more than rote memorisation. For an overview of the certification itself, the KYC AML course hub maps every module in order, and our deep dive on FIU-India reporting: STR, CTR and CDD is the perfect next read.

Common Mistakes to Avoid

  • Confusing CTR with STR. A CTR is threshold-based (high-value cash), while an STR is suspicion-based with no minimum amount. This single distinction is tested almost every cycle.
  • Memorising stale figures. Thresholds and scheduled offences change with amendments. Learn the concept, then verify the current number on the official notification.
  • Treating KYC as a one-time formality. CDD includes ongoing monitoring, not just onboarding checks.
  • Ignoring beneficial ownership. Many scenario questions hinge on identifying the natural person behind a corporate account.
  • Blurring AML and CFT. They share machinery but address different problems — source of funds versus destination of funds.

Frequently Asked Questions

What is the anti-money laundering framework?

It is the legal and procedural system, anchored by the PMLA, 2002, that requires banks and other reporting entities to detect, deter and report attempts to disguise the illegal origins of criminal proceeds. It combines the law, FIU-IND reporting, KYC due diligence and FATF-aligned global standards. Together these controls keep tainted money out of the legitimate economy.

What is the CTR threshold under PMLA?

A Cash Transaction Report is filed with FIU-IND for high-value cash transactions in a month, whether a single transaction or a connected series. The figure is commonly cited as INR 10 lakh, but because PMLA rules are amended periodically, always confirm the current threshold on the official IIBF notification before relying on it in practice.

How is a Suspicious Transaction Report different from a CTR?

An STR is triggered by suspicion of money laundering or terror financing, regardless of the amount involved, whereas a CTR is triggered purely by a cash value crossing a prescribed limit. In other words, the STR is judgement-based and the CTR is threshold-based. Examiners frequently test this exact contrast.

What is Enhanced Due Diligence (EDD)?

EDD is the deeper level of scrutiny applied to high-risk customers, including Politically Exposed Persons. It involves closer identity verification, additional information on the source of funds, and more frequent ongoing monitoring. It is the natural escalation from standard Customer Due Diligence under a risk-based approach.

Who is responsible for AML compliance in a bank?

The Principal Officer is responsible for filing reports such as STRs and CTRs with FIU-IND, while a board-level Designated Director carries overall responsibility for the bank's AML and CFT compliance. The Enforcement Directorate investigates offences, and FIU-IND receives and analyses the reports. Knowing who does what is a reliable source of easy marks.

Is the AML framework important for the IIBF KYC AML paper?

Yes — it is the core of the KYC, AML and CFT certification. Expect regular questions on PMLA, FIU-IND reporting, customer due diligence, beneficial ownership and FATF standards. Mastering this framework not only lifts your score but also prepares you for genuine compliance responsibilities at the branch.

Conclusion

The anti-money laundering framework transforms every banker into a custodian of the financial system's integrity. Learn PMLA as the parent law, master the FIU-IND reporting regime, internalise the KYC and CDD machinery, and connect it all to the global FATF standards — do that, and you will answer exam questions and discharge real-world duties with equal confidence. Treat this as career-defining knowledge, revise it with active recall, and walk into the hall knowing you have covered the highest-yield topic in the paper. For the official source, always cross-check the latest rules and notifications on the IIBF official website.

Related Guides

📚 Free Learning Sessions resources — connect & crack your exam

💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.

📱 Study on the go — get our iOS & Android app at iibf.store/app.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. A large bank with straight-through processing and millions of customer-initiated transactions wants to justify investing in AML software rather than relying on manual scrutiny. Which benefit set best supports this, per the chapter?
Q2. An auditor asks why STR cannot be generated centrally by software the way CTR, NTR and CBTR are. Which explanation is most accurate as per the chapter?
Q3. A customer's account shows transactions always conducted through third parties, the account holder is not contactable and unwilling to meet, and complaints arrive from people who deposited money in response to a 'job offer.' Which conclusion and action align with the chapter?
Q4. Among the five FIU reports, why is the STR described as the 'keystone' that consumes the maximum resources of a reporting entity, while CTR/NTR/CBWTR carry only supplementary AML value?
Q5. Counterfeit currency is detected during a cash deposit, and separately a forged valuable security is used in another cash transaction. How are these reported to FIU-IND under CCR norms?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading