PMLA and the AML/CFT Framework in India 2026
The AML/CFT framework in India is the legal and operational backbone that keeps the banking system clean of illicit money. Built around the Prevention of Money Laundering Act, 2002 (PMLA), this framework binds every bank, NBFC and reporting entity to a common set of customer due diligence, monitoring and reporting duties. For IIBF certification candidates, mastering how the AML/CFT framework fits together — from statute to regulator to the Financial Intelligence Unit — is essential, because examiners test both the legal provisions and their practical application at the branch counter. This article walks through PMLA, FIU-IND, STR and CTR reporting, the FATF global standards, and the due-diligence obligations that flow from them.
PMLA 2002: The Legal Foundation
The Prevention of Money Laundering Act, 2002 came into force on 1 July 2005 and is the principal statute governing anti-money-laundering efforts in India. Its core purpose is to prevent money laundering, confiscate property derived from laundered proceeds, and punish those who convert the proceeds of crime into ostensibly legitimate assets. Section 3 defines the offence of money laundering as any process or activity connected with the proceeds of crime — including concealment, possession, acquisition or use — and projecting it as untainted property. Section 4 prescribes rigorous imprisonment of three to seven years, extendable to ten years for offences linked to narcotics.
Crucially for bankers, the PMLA and the rules framed under it — the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 — impose obligations directly on reporting entities. Banks must verify customer identity, maintain records of prescribed transactions, and furnish information to the authorities. The Reserve Bank of India operationalises these duties through its Master Direction on KYC, which every candidate should read as the practical companion to the statute. Understanding PMLA at the section level is a recurring theme in exams — see how it connects to daily banking on our JAIIB course resources.
FIU-IND and the Reporting Architecture
The Financial Intelligence Unit — India (FIU-IND) was set up in 2004 as the central national agency responsible for receiving, processing, analysing and disseminating information relating to suspect financial transactions. It reports to the Economic Intelligence Council headed by the Finance Minister and acts as the nodal point between reporting entities and law-enforcement or intelligence agencies. Rather than investigating cases itself, FIU-IND builds a strategic picture of money-laundering and terror-financing trends and hands actionable intelligence to enforcement bodies such as the Enforcement Directorate.
Reporting entities file several return types with FIU-IND through the FINnet gateway. Cash Transaction Reports (CTRs) cover all cash transactions above ten lakh rupees, or a series of connected cash transactions crossing that threshold in a month. Suspicious Transaction Reports (STRs) flag transactions that appear to involve proceeds of crime regardless of amount. Counterfeit Currency Reports (CCRs) and cross-border wire-transfer reports complete the set. Timely, accurate filing is not optional — non-compliance attracts monetary penalties under PMLA. Candidates can test their recall of these thresholds on our mock test bank and keep up with regulatory changes via IIBF news updates.

FATF Standards and the Global Context
India's AML/CFT regime does not exist in isolation. The Financial Action Task Force (FATF), an inter-governmental body established in 1989, sets the global standards through its 40 Recommendations covering money laundering, terror financing and proliferation financing. India became a full FATF member in 2010 and undergoes periodic mutual evaluations that assess both technical compliance and the effectiveness of its framework. The 2024 mutual evaluation placed India in the regular follow-up category — the best outcome — reflecting a broadly sound system.
The FATF Recommendations shape domestic law directly: risk-based approach, customer due diligence, record-keeping, reporting of suspicious transactions, and correspondent-banking controls all trace back to these standards. A country that fails to comply risks being placed on the FATF grey or black list, which raises the cost of cross-border transactions for its banks. For bankers, the practical takeaway is that KYC and reporting duties are not mere paperwork but part of an international commitment. Reinforce these concepts alongside other banking topics on our exam preparation blog.
CDD, EDD, PEPs and Record Retention
Customer Due Diligence (CDD) is the process of identifying and verifying a customer using reliable, independent documents, and understanding the nature of the intended relationship. Under the risk-based approach, banks categorise customers as low, medium or high risk. Enhanced Due Diligence (EDD) applies to higher-risk categories — including Politically Exposed Persons (PEPs), non-face-to-face customers and those from higher-risk jurisdictions — and requires senior-management approval, deeper source-of-funds checks and closer ongoing monitoring. Simplified due diligence may be permitted for low-risk, low-value accounts.
PEPs are individuals entrusted with prominent public functions in a foreign country; the RBI Master Direction requires their identity, source of funds and dealings to be scrutinised more intensively. Record retention is equally prescriptive: banks must preserve transaction records for at least five years from the date of the transaction and customer-identification records for five years after the business relationship ends. A growing frontier is Trade-Based Money Laundering (TBML), where the trade system is misused through over- or under-invoicing, multiple invoicing or false description of goods to move value across borders. Vigilant CDD and transaction monitoring are the front-line defences. Sharpen your recall with our structured JAIIB modules.

Conclusion: Master the Framework, Ace the Exam
The AML/CFT framework rewards candidates who see the connections: PMLA provides the law, FIU-IND channels the reporting, FATF sets the global bar, and CDD/EDD translate all of it into branch-level action. Knowing the CTR threshold, the STR trigger, the five-year retention rule and the EDD triggers for PEPs will carry you through most exam questions on this subject. Put this knowledge to the test now — attempt a full-length mock on our IIBF test series and turn theory into confident, exam-ready recall.
What is the CTR reporting threshold under PMLA?
A Cash Transaction Report must be filed for all cash transactions of more than ten lakh rupees, or a series of integrally connected cash transactions that together exceed ten lakh rupees within a calendar month.
What is the difference between an STR and a CTR?
A CTR is threshold-based and covers large cash transactions above ten lakh rupees. An STR is suspicion-based and must be filed for any transaction that appears to involve proceeds of crime, irrespective of the amount involved.
How long must banks retain KYC and transaction records?
Transaction records must be kept for at least five years from the date of the transaction, and customer-identification records for at least five years after the end of the business relationship, as required by the PMLA rules and RBI Master Direction on KYC.
Who is a Politically Exposed Person (PEP)?
A PEP is an individual entrusted with prominent public functions in a foreign country, such as heads of state, senior politicians or judicial officials. Banks must apply Enhanced Due Diligence, obtain senior-management approval and scrutinise the source of funds for PEP accounts.

Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading