PMLA, FATF and the Customer Due Diligence Framework Explained

KYCAML By Ashish Jain · IIBF STORE Editorial · 16 June 2026 · Updated 31 Jul 2026 · 11 min read · 20 views
PMLA, FATF and the Customer Due Diligence Framework Explained

The customer due diligence framework is the backbone of every bank's anti-money-laundering programme in India, and it is the single most heavily tested theme in the IIBF KYC, AML and CFT certificate. If you understand how the Prevention of Money Laundering Act, 2002 (PMLA) connects to the global FATF standard and to the RBI Master Direction on KYC, you can reason your way through most exam questions instead of memorising disconnected facts.

This guide walks you through the legal obligations, the difference between ordinary and enhanced due diligence, how customers are placed in risk buckets, how politically exposed persons and beneficial owners are treated, and the reporting chain that ends at FIU-India. Read it once carefully, then use the linked drills and a structured KYC, AML and CFT course to lock the concepts in.

Customer due diligence framework linking PMLA, FATF and the RBI KYC Master Direction
How the customer due diligence framework links PMLA, FATF and the RBI KYC Master Direction

Key takeaways

  • PMLA 2002 is the parent statute; the RBI KYC Master Direction turns it into day-to-day banking procedure.
  • The FATF 40 Recommendations set the global benchmark and put a risk-based approach at the centre of due diligence.
  • CDD is the baseline; EDD applies to higher-risk customers, PEPs and complex ownership structures.
  • Every customer is sorted into low, medium or high risk, which decides how closely the account is monitored.
  • FIU-India receives CTRs, STRs and other prescribed reports, and the tipping-off ban is absolute.

PMLA obligations and the RBI KYC Master Direction

The Prevention of Money Laundering Act, 2002 is the primary anti-money-laundering statute in India. It criminalises the laundering of proceeds of crime and casts statutory duties on every reporting entity, a category that includes banks, NBFCs, payment system operators and several designated non-financial businesses. The operational rulebook for banks is the RBI Master Direction on KYC, which translates the PMLA and its Maintenance of Records Rules into procedures a branch can actually follow.

Under these obligations, a regulated entity must do four core things, and the customer due diligence framework rests on each of them:

  • Verify identity of every customer using an Officially Valid Document (OVD) when opening an account or establishing a business relationship.
  • Maintain records of transactions and identity documents for at least five years from the end of the relationship or the transaction.
  • Appoint a Principal Officer and a Designated Director who are responsible for AML compliance and reporting.
  • File prescribed reports with the Financial Intelligence Unit within the stipulated timelines.

The Master Direction builds the entire KYC policy on four pillars: the Customer Acceptance Policy, Risk Management, the Customer Identification Procedure and ongoing Monitoring of Transactions. Failure to comply attracts monetary penalties and supervisory action, so examiners love to test whether you can name these pillars and link them to a real banking scenario. To check your grasp under timed conditions, try the topic-wise drills on the KYC, AML and CFT mock tests, which mirror the certificate pattern.

FATF Recommendations and the global AML standard

The Financial Action Task Force (FATF) is the inter-governmental body that sets the global standard for combating money laundering and terrorist financing. Its 40 Recommendations are the benchmark against which member countries, including India, are evaluated through periodic Mutual Evaluations. India has aligned its legal framework with FATF expectations and undergone comprehensive assessment, and the certificate syllabus expects you to know how domestic law maps to these recommendations.

Four FATF concepts come up again and again in the exam:

  • Risk-Based Approach (RBA) — resources must be concentrated where money-laundering and terrorist-financing risk is highest, rather than treating every customer identically.
  • Customer Due Diligence (Recommendation 10) — identify and verify customers and understand the purpose and intended nature of the relationship.
  • Targeted financial sanctions — freeze assets linked to terrorism and proliferation financing under United Nations Security Council resolutions.
  • Grey list and black list — FATF places jurisdictions with strategic deficiencies under increased monitoring, which raises compliance friction for cross-border business.

Because terrorist financing is a constantly evolving threat, banks track FATF advisories alongside domestic circulars. For a deeper look at how these standards feed the reporting chain, read our companion guide on FATF Recommendations and FIU-India reporting, and confirm the latest position on the official IIBF website when a notification changes.

FATF 40 Recommendations and the risk-based approach within the customer due diligence framework
The FATF 40 Recommendations and the risk-based approach to AML and CFT

CDD, EDD and the customer due diligence framework in practice

At the heart of the customer due diligence framework is a simple idea: identify the customer, verify that identity from reliable and independent sources, and understand the nature of the relationship. That baseline process is Customer Due Diligence (CDD). Where risk is higher, the bank must step up to Enhanced Due Diligence (EDD) — collecting more information, obtaining senior-management approval and monitoring the account more closely. For genuinely low-risk situations, the RBI permits Simplified Due Diligence, which lightens the documentation burden without removing the duty to stay alert.

The decision about how much diligence to apply flows from risk categorisation. Banks classify every customer into one of three buckets:

  • Low risk — salaried individuals, government departments and entities with transparent ownership.
  • Medium risk — customers whose profile or activity warrants periodic review.
  • High risk — non-resident customers, trusts, customers from high-risk jurisdictions and politically exposed persons.

The table below summarises how the level of diligence tracks the risk category — a comparison that examiners frequently disguise inside a case-style question.

Risk categoryTypical customersLevel of due diligenceMonitoring intensity
LowSalaried persons, government bodies, transparent companiesSimplified / standard CDDRoutine periodic review
MediumProfiles needing closer reviewStandard CDDMore frequent periodic review
HighPEPs, non-residents, trusts, high-risk jurisdictionsEnhanced Due Diligence (EDD)Close, ongoing monitoring

PEPs, beneficial ownership and periodic re-KYC

Politically Exposed Persons (PEPs) are individuals entrusted with prominent public functions in a foreign country. Because of the heightened corruption and bribery risk, a relationship with a PEP always demands EDD, senior-management sign-off and close ongoing monitoring — there is no low-risk PEP. Knowing this single rule answers a surprising number of exam questions.

Equally important is beneficial ownership. For a company, the bank must identify every natural person who ultimately owns or controls more than the prescribed threshold; for trusts and partnerships, it must trace control to the real individuals behind the legal veil. The principle is that a corporate structure must never become a curtain that hides the human being who truly benefits.

None of this is a one-time exercise. Periodic re-KYC keeps customer records current, with the frequency itself driven by the risk category — high-risk customers are refreshed far more often than low-risk ones. Sharpen your recall of these definitions with the interactive match-the-concept game, and reinforce the statutory side with our detailed note on AML compliance under PMLA.

Politically exposed persons and beneficial ownership checks inside enhanced due diligence
Identifying PEPs and beneficial owners during enhanced due diligence

FIU-India reporting: CTR, STR and trade-based money laundering

The Financial Intelligence Unit-India (FIU-IND) is the national agency that receives, analyses and disseminates information about suspect financial transactions. Reporting entities transmit prescribed reports to FIU-India, which then shares actionable intelligence with enforcement and intelligence agencies. The certificate exam frequently tests the principal report types, so commit these to memory:

  • Cash Transaction Report (CTR) — for cash transactions above ten lakh rupees, or a series of integrally connected cash transactions that together cross that limit within a month.
  • Suspicious Transaction Report (STR) — filed whenever a transaction gives rise to a reasonable ground of suspicion, regardless of amount; STRs must be filed promptly, typically within seven working days of forming suspicion.
  • Counterfeit Currency Report (CCR) and the Non-Profit Organisation Transaction Report (NTR) for the relevant categories.

A critical principle runs alongside all of this: the tipping-off prohibition. A bank must never alert a customer that an STR has been filed, because doing so would defeat the investigation. Treat any exam option that suggests informing the customer as automatically wrong.

Finally, the syllabus expects familiarity with Trade-Based Money Laundering (TBML), an advanced technique in which criminals disguise illicit proceeds through trade transactions — using over-invoicing, under-invoicing, multiple invoicing or phantom shipments to move value across borders. Detecting TBML requires scrutiny of trade documents, pricing benchmarks and the underlying goods, and strong transaction-monitoring systems flag these red flags for analyst review before an STR is filed. For the full reporting workflow, see our guide to FIU-India reporting of STR, CTR and CDD.

A practical study plan for this topic

This is a high-yield area, so structure your revision rather than reading passively. A simple three-pass plan works well for most candidates preparing in a couple of weeks:

  1. Pass one — build the map. Spend a sitting connecting PMLA to the RBI Master Direction and the FATF Recommendations, so the framework feels like one system, not three silos.
  2. Pass two — drill the definitions. Write the four KYC pillars, the CDD/EDD/SDD distinction and the report thresholds from memory, then check yourself with the matching game.
  3. Pass three — test under time. Attempt full mock sets, review every wrong answer, and revisit the relevant section above before moving on.

Always confirm time-sensitive specifics — thresholds, timelines and section references — against the latest released IIBF notification, and browse the complete library of KYC, AML and CFT guides to fill any gaps. The official syllabus with a free PDF is the right place to start a fresh study cycle.

Common mistakes candidates make

  • Confusing the parent law with the rulebook. PMLA is the statute; the RBI Master Direction is the implementing guidance. Mixing them up costs easy marks.
  • Treating some PEPs as low risk. A PEP relationship is always high risk and always needs EDD — there are no exceptions to apply.
  • Linking STRs to an amount. An STR is driven by suspicion, not by a rupee threshold; only the CTR has the ten-lakh trigger.
  • Forgetting the tipping-off ban. Suggesting that a customer be told about a filed STR is a classic trap option.
  • Stopping at the front person. Diligence is incomplete until the real beneficial owner behind a company or trust is identified.

Frequently asked questions

What is the difference between CDD and EDD?

Customer Due Diligence (CDD) is the baseline process of identifying and verifying a customer and understanding the relationship. Enhanced Due Diligence (EDD) applies to higher-risk customers and requires more information, senior-management approval and closer ongoing monitoring. In short, EDD is CDD turned up for situations where the money-laundering risk is greater.

What is the cash threshold for filing a CTR with FIU-India?

A Cash Transaction Report is filed for cash transactions exceeding ten lakh rupees. It also applies to a series of integrally connected cash transactions that together cross that limit within a month. Always reconfirm the exact figure against the latest IIBF notification, as thresholds can be revised.

Who is a Politically Exposed Person (PEP)?

A PEP is an individual entrusted with prominent public functions in a foreign country. Relationships with PEPs require enhanced due diligence, senior-management approval and continuous monitoring. The reason is the higher exposure to corruption and bribery risk that such positions carry.

Why does beneficial ownership matter in the customer due diligence framework?

Beneficial ownership ensures the bank knows the real natural person who ultimately owns or controls a customer, not just the legal entity on paper. For companies, trusts and partnerships, control must be traced to the individuals behind the structure. This stops criminals from using corporate layers to hide who truly benefits.

What is Trade-Based Money Laundering?

Trade-Based Money Laundering disguises proceeds of crime through trade transactions. Techniques include over-invoicing, under-invoicing, multiple invoicing and phantom shipments that move value across borders while appearing legitimate. Banks counter it by scrutinising trade documents, pricing benchmarks and the underlying goods.

How does FATF influence India's AML rules?

FATF sets the global standard through its 40 Recommendations and evaluates member countries, including India, in periodic Mutual Evaluations. India aligns its legal framework, such as the PMLA and the RBI Master Direction, with these expectations. The risk-based approach championed by FATF is therefore woven directly into Indian due-diligence practice.

Conclusion

The customer due diligence framework ties together PMLA obligations, the FATF Recommendations, the RBI KYC Master Direction, risk-based diligence, beneficial-ownership identification and FIU-India reporting into one coherent system. Internalise the report triggers, the EDD rules for PEPs and high-risk customers, and typologies such as trade-based money laundering, and the certificate questions will start to feel predictable. Keep your prep active, confirm every figure against the official source, and convert this knowledge into exam-ready marks.

Related Guides

📚 Free Learning Sessions resources — connect & crack your exam

💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.

📱 Study on the go — get our iOS & Android app at iibf.store/app.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. While compiling a CTR, an analyst is reviewing a customer who in one month made several cash deposits of Rs. 40,000 and Rs. 45,000 each plus one deposit of Rs. 9 lakh. The analyst wants to know how the sub-Rs. 50,000 transactions should be handled. Which treatment is correct?
Q2. A cashier detects a single counterfeit Rs. 500 note across the branch in a month, and separately, a cash transaction where a forged valuable security was used. How must these be reported under the CCR framework?
Q3. Which of the following is a defining indicator of a money-mule account as opposed to a genuine high-volume account?
Q4. A bank decides to use a single common software suite and one common team for both AML monitoring and internal fraud detection. How should this decision be evaluated?
Q5. Which combination of red flags is MOST distinctive of Trade-Based Money Laundering (TBML) as opposed to generic AML alerts?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading