🏹 Happy Dussehra — victory of good over evil!

PMLA and the AML/CFT Framework in India 2026

KYCAML By Ashish Jain · IIBF STORE Editorial · 04 July 2026 · Updated 01 Oct 2026 · 6 min read · 55 views
PMLA and the AML/CFT Framework in India 2026

The AML/CFT framework in India is the legal and operational backbone that keeps the banking system clean of illicit money. Built around the Prevention of Money Laundering Act, 2002 (PMLA), this framework binds every bank, NBFC and reporting entity to a common set of customer due diligence, monitoring and reporting duties. For IIBF certification candidates, mastering how the AML/CFT framework fits together — from statute to regulator to the Financial Intelligence Unit — is essential, because examiners test both the legal provisions and their practical application at the branch counter. This article walks through PMLA, FIU-IND, STR and CTR reporting, the FATF global standards, and the due-diligence obligations that flow from them.

PMLA 2002: The Legal Foundation

The Prevention of Money Laundering Act, 2002 came into force on 1 July 2005 and is the principal statute governing anti-money-laundering efforts in India. Its core purpose is to prevent money laundering, confiscate property derived from laundered proceeds, and punish those who convert the proceeds of crime into ostensibly legitimate assets. Section 3 defines the offence of money laundering as any process or activity connected with the proceeds of crime — including concealment, possession, acquisition or use — and projecting it as untainted property. Section 4 prescribes rigorous imprisonment of three to seven years, extendable to ten years for offences linked to narcotics.

Crucially for bankers, the PMLA and the rules framed under it — the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 — impose obligations directly on reporting entities. Banks must verify customer identity, maintain records of prescribed transactions, and furnish information to the authorities. The Reserve Bank of India operationalises these duties through its Master Direction on KYC, which every candidate should read as the practical companion to the statute. Understanding PMLA at the section level is a recurring theme in exams — see how it connects to daily banking on our JAIIB course resources.

FIU-IND and the Reporting Architecture

The Financial Intelligence Unit — India (FIU-IND) was set up in 2004 as the central national agency responsible for receiving, processing, analysing and disseminating information relating to suspect financial transactions. It reports to the Economic Intelligence Council headed by the Finance Minister and acts as the nodal point between reporting entities and law-enforcement or intelligence agencies. Rather than investigating cases itself, FIU-IND builds a strategic picture of money-laundering and terror-financing trends and hands actionable intelligence to enforcement bodies such as the Enforcement Directorate.

Reporting entities file several return types with FIU-IND through the FINnet gateway. Cash Transaction Reports (CTRs) cover all cash transactions above ten lakh rupees, or a series of connected cash transactions crossing that threshold in a month. Suspicious Transaction Reports (STRs) flag transactions that appear to involve proceeds of crime regardless of amount. Counterfeit Currency Reports (CCRs) and cross-border wire-transfer reports complete the set. Timely, accurate filing is not optional — non-compliance attracts monetary penalties under PMLA. Candidates can test their recall of these thresholds on our mock test bank and keep up with regulatory changes via IIBF news updates.

Key Concepts — KYC, AML and CFT
Key Concepts — KYC, AML and CFT

FATF Standards and the Global Context

India's AML/CFT regime does not exist in isolation. The Financial Action Task Force (FATF), an inter-governmental body established in 1989, sets the global standards through its 40 Recommendations covering money laundering, terror financing and proliferation financing. India became a full FATF member in 2010 and undergoes periodic mutual evaluations that assess both technical compliance and the effectiveness of its framework. The 2024 mutual evaluation placed India in the regular follow-up category — the best outcome — reflecting a broadly sound system.

The FATF Recommendations shape domestic law directly: risk-based approach, customer due diligence, record-keeping, reporting of suspicious transactions, and correspondent-banking controls all trace back to these standards. A country that fails to comply risks being placed on the FATF grey or black list, which raises the cost of cross-border transactions for its banks. For bankers, the practical takeaway is that KYC and reporting duties are not mere paperwork but part of an international commitment. Reinforce these concepts alongside other banking topics on our exam preparation blog.

CDD, EDD, PEPs and Record Retention

Customer Due Diligence (CDD) is the process of identifying and verifying a customer using reliable, independent documents, and understanding the nature of the intended relationship. Under the risk-based approach, banks categorise customers as low, medium or high risk. Enhanced Due Diligence (EDD) applies to higher-risk categories — including Politically Exposed Persons (PEPs), non-face-to-face customers and those from higher-risk jurisdictions — and requires senior-management approval, deeper source-of-funds checks and closer ongoing monitoring. Simplified due diligence may be permitted for low-risk, low-value accounts.

PEPs are individuals entrusted with prominent public functions in a foreign country; the RBI Master Direction requires their identity, source of funds and dealings to be scrutinised more intensively. Record retention is equally prescriptive: banks must preserve transaction records for at least five years from the date of the transaction and customer-identification records for five years after the business relationship ends. A growing frontier is Trade-Based Money Laundering (TBML), where the trade system is misused through over- or under-invoicing, multiple invoicing or false description of goods to move value across borders. Vigilant CDD and transaction monitoring are the front-line defences. Sharpen your recall with our structured JAIIB modules.

Process & Framework — KYC, AML and CFT
Process & Framework — KYC, AML and CFT

Conclusion: Master the Framework, Ace the Exam

The AML/CFT framework rewards candidates who see the connections: PMLA provides the law, FIU-IND channels the reporting, FATF sets the global bar, and CDD/EDD translate all of it into branch-level action. Knowing the CTR threshold, the STR trigger, the five-year retention rule and the EDD triggers for PEPs will carry you through most exam questions on this subject. Put this knowledge to the test now — attempt a full-length mock on our IIBF test series and turn theory into confident, exam-ready recall.

What is the CTR reporting threshold under PMLA?

A Cash Transaction Report must be filed for all cash transactions of more than ten lakh rupees, or a series of integrally connected cash transactions that together exceed ten lakh rupees within a calendar month.

What is the difference between an STR and a CTR?

A CTR is threshold-based and covers large cash transactions above ten lakh rupees. An STR is suspicion-based and must be filed for any transaction that appears to involve proceeds of crime, irrespective of the amount involved.

How long must banks retain KYC and transaction records?

Transaction records must be kept for at least five years from the date of the transaction, and customer-identification records for at least five years after the end of the business relationship, as required by the PMLA rules and RBI Master Direction on KYC.

Who is a Politically Exposed Person (PEP)?

A PEP is an individual entrusted with prominent public functions in a foreign country, such as heads of state, senior politicians or judicial officials. Banks must apply Enhanced Due Diligence, obtain senior-management approval and scrutinise the source of funds for PEP accounts.

In Practice — KYC, AML and CFT
In Practice — KYC, AML and CFT
Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. An AML system generates such a high volume of alerts that over 90% are routinely closed as false positives, exhausting analyst capacity. Which fine-tuning approach is MOST appropriate?
Q2. A walk-in prospect makes detailed enquiries about cash-deposit limits and how to avoid reporting, then leaves without opening any account. Drawing on the Cobrapost precedent, what should the bank do?
Q3. Which statement about the Risk-Based Approach (RBA) to transaction monitoring is INCORRECT?
Q4. Eight current accounts opened at one branch share the same address and same email ID; cash deposits just below Rs. 10 lakh are made in seven of them, funds are immediately funnelled into one account and remitted out, and none of the companies exist at the given address. Which STR typology and key takeaway does this best illustrate?
Q5. A branch teller refuses to open an account for a customer who, on learning the KYC requirements, abandons the process; later the same person tries to operate someone else's locker daily. Which monitoring method is primarily responsible for capturing such 'attempted transaction' indicators?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading