PMLA, FATF and the Customer Due Diligence Framework Explained
The customer due diligence framework is the backbone of every bank's anti-money-laundering programme in India, and it is the single most heavily tested theme in the IIBF KYC, AML and CFT certificate. If you understand how the Prevention of Money Laundering Act, 2002 (PMLA) connects to the global FATF standard and to the RBI Master Direction on KYC, you can reason your way through most exam questions instead of memorising disconnected facts.
This guide walks you through the legal obligations, the difference between ordinary and enhanced due diligence, how customers are placed in risk buckets, how politically exposed persons and beneficial owners are treated, and the reporting chain that ends at FIU-India. Read it once carefully, then use the linked drills and a structured KYC, AML and CFT course to lock the concepts in.

Key takeaways
- PMLA 2002 is the parent statute; the RBI KYC Master Direction turns it into day-to-day banking procedure.
- The FATF 40 Recommendations set the global benchmark and put a risk-based approach at the centre of due diligence.
- CDD is the baseline; EDD applies to higher-risk customers, PEPs and complex ownership structures.
- Every customer is sorted into low, medium or high risk, which decides how closely the account is monitored.
- FIU-India receives CTRs, STRs and other prescribed reports, and the tipping-off ban is absolute.
PMLA obligations and the RBI KYC Master Direction
The Prevention of Money Laundering Act, 2002 is the primary anti-money-laundering statute in India. It criminalises the laundering of proceeds of crime and casts statutory duties on every reporting entity, a category that includes banks, NBFCs, payment system operators and several designated non-financial businesses. The operational rulebook for banks is the RBI Master Direction on KYC, which translates the PMLA and its Maintenance of Records Rules into procedures a branch can actually follow.
Under these obligations, a regulated entity must do four core things, and the customer due diligence framework rests on each of them:
- Verify identity of every customer using an Officially Valid Document (OVD) when opening an account or establishing a business relationship.
- Maintain records of transactions and identity documents for at least five years from the end of the relationship or the transaction.
- Appoint a Principal Officer and a Designated Director who are responsible for AML compliance and reporting.
- File prescribed reports with the Financial Intelligence Unit within the stipulated timelines.
The Master Direction builds the entire KYC policy on four pillars: the Customer Acceptance Policy, Risk Management, the Customer Identification Procedure and ongoing Monitoring of Transactions. Failure to comply attracts monetary penalties and supervisory action, so examiners love to test whether you can name these pillars and link them to a real banking scenario. To check your grasp under timed conditions, try the topic-wise drills on the KYC, AML and CFT mock tests, which mirror the certificate pattern.
FATF Recommendations and the global AML standard
The Financial Action Task Force (FATF) is the inter-governmental body that sets the global standard for combating money laundering and terrorist financing. Its 40 Recommendations are the benchmark against which member countries, including India, are evaluated through periodic Mutual Evaluations. India has aligned its legal framework with FATF expectations and undergone comprehensive assessment, and the certificate syllabus expects you to know how domestic law maps to these recommendations.
Four FATF concepts come up again and again in the exam:
- Risk-Based Approach (RBA) — resources must be concentrated where money-laundering and terrorist-financing risk is highest, rather than treating every customer identically.
- Customer Due Diligence (Recommendation 10) — identify and verify customers and understand the purpose and intended nature of the relationship.
- Targeted financial sanctions — freeze assets linked to terrorism and proliferation financing under United Nations Security Council resolutions.
- Grey list and black list — FATF places jurisdictions with strategic deficiencies under increased monitoring, which raises compliance friction for cross-border business.
Because terrorist financing is a constantly evolving threat, banks track FATF advisories alongside domestic circulars. For a deeper look at how these standards feed the reporting chain, read our companion guide on FATF Recommendations and FIU-India reporting, and confirm the latest position on the official IIBF website when a notification changes.

CDD, EDD and the customer due diligence framework in practice
At the heart of the customer due diligence framework is a simple idea: identify the customer, verify that identity from reliable and independent sources, and understand the nature of the relationship. That baseline process is Customer Due Diligence (CDD). Where risk is higher, the bank must step up to Enhanced Due Diligence (EDD) — collecting more information, obtaining senior-management approval and monitoring the account more closely. For genuinely low-risk situations, the RBI permits Simplified Due Diligence, which lightens the documentation burden without removing the duty to stay alert.
The decision about how much diligence to apply flows from risk categorisation. Banks classify every customer into one of three buckets:
- Low risk — salaried individuals, government departments and entities with transparent ownership.
- Medium risk — customers whose profile or activity warrants periodic review.
- High risk — non-resident customers, trusts, customers from high-risk jurisdictions and politically exposed persons.
The table below summarises how the level of diligence tracks the risk category — a comparison that examiners frequently disguise inside a case-style question.
| Risk category | Typical customers | Level of due diligence | Monitoring intensity |
|---|---|---|---|
| Low | Salaried persons, government bodies, transparent companies | Simplified / standard CDD | Routine periodic review |
| Medium | Profiles needing closer review | Standard CDD | More frequent periodic review |
| High | PEPs, non-residents, trusts, high-risk jurisdictions | Enhanced Due Diligence (EDD) | Close, ongoing monitoring |
PEPs, beneficial ownership and periodic re-KYC
Politically Exposed Persons (PEPs) are individuals entrusted with prominent public functions in a foreign country. Because of the heightened corruption and bribery risk, a relationship with a PEP always demands EDD, senior-management sign-off and close ongoing monitoring — there is no low-risk PEP. Knowing this single rule answers a surprising number of exam questions.
Equally important is beneficial ownership. For a company, the bank must identify every natural person who ultimately owns or controls more than the prescribed threshold; for trusts and partnerships, it must trace control to the real individuals behind the legal veil. The principle is that a corporate structure must never become a curtain that hides the human being who truly benefits.
None of this is a one-time exercise. Periodic re-KYC keeps customer records current, with the frequency itself driven by the risk category — high-risk customers are refreshed far more often than low-risk ones. Sharpen your recall of these definitions with the interactive match-the-concept game, and reinforce the statutory side with our detailed note on AML compliance under PMLA.

FIU-India reporting: CTR, STR and trade-based money laundering
The Financial Intelligence Unit-India (FIU-IND) is the national agency that receives, analyses and disseminates information about suspect financial transactions. Reporting entities transmit prescribed reports to FIU-India, which then shares actionable intelligence with enforcement and intelligence agencies. The certificate exam frequently tests the principal report types, so commit these to memory:
- Cash Transaction Report (CTR) — for cash transactions above ten lakh rupees, or a series of integrally connected cash transactions that together cross that limit within a month.
- Suspicious Transaction Report (STR) — filed whenever a transaction gives rise to a reasonable ground of suspicion, regardless of amount; STRs must be filed promptly, typically within seven working days of forming suspicion.
- Counterfeit Currency Report (CCR) and the Non-Profit Organisation Transaction Report (NTR) for the relevant categories.
A critical principle runs alongside all of this: the tipping-off prohibition. A bank must never alert a customer that an STR has been filed, because doing so would defeat the investigation. Treat any exam option that suggests informing the customer as automatically wrong.
Finally, the syllabus expects familiarity with Trade-Based Money Laundering (TBML), an advanced technique in which criminals disguise illicit proceeds through trade transactions — using over-invoicing, under-invoicing, multiple invoicing or phantom shipments to move value across borders. Detecting TBML requires scrutiny of trade documents, pricing benchmarks and the underlying goods, and strong transaction-monitoring systems flag these red flags for analyst review before an STR is filed. For the full reporting workflow, see our guide to FIU-India reporting of STR, CTR and CDD.
A practical study plan for this topic
This is a high-yield area, so structure your revision rather than reading passively. A simple three-pass plan works well for most candidates preparing in a couple of weeks:
- Pass one — build the map. Spend a sitting connecting PMLA to the RBI Master Direction and the FATF Recommendations, so the framework feels like one system, not three silos.
- Pass two — drill the definitions. Write the four KYC pillars, the CDD/EDD/SDD distinction and the report thresholds from memory, then check yourself with the matching game.
- Pass three — test under time. Attempt full mock sets, review every wrong answer, and revisit the relevant section above before moving on.
Always confirm time-sensitive specifics — thresholds, timelines and section references — against the latest released IIBF notification, and browse the complete library of KYC, AML and CFT guides to fill any gaps. The official syllabus with a free PDF is the right place to start a fresh study cycle.
Common mistakes candidates make
- Confusing the parent law with the rulebook. PMLA is the statute; the RBI Master Direction is the implementing guidance. Mixing them up costs easy marks.
- Treating some PEPs as low risk. A PEP relationship is always high risk and always needs EDD — there are no exceptions to apply.
- Linking STRs to an amount. An STR is driven by suspicion, not by a rupee threshold; only the CTR has the ten-lakh trigger.
- Forgetting the tipping-off ban. Suggesting that a customer be told about a filed STR is a classic trap option.
- Stopping at the front person. Diligence is incomplete until the real beneficial owner behind a company or trust is identified.
Frequently asked questions
What is the difference between CDD and EDD?
Customer Due Diligence (CDD) is the baseline process of identifying and verifying a customer and understanding the relationship. Enhanced Due Diligence (EDD) applies to higher-risk customers and requires more information, senior-management approval and closer ongoing monitoring. In short, EDD is CDD turned up for situations where the money-laundering risk is greater.
What is the cash threshold for filing a CTR with FIU-India?
A Cash Transaction Report is filed for cash transactions exceeding ten lakh rupees. It also applies to a series of integrally connected cash transactions that together cross that limit within a month. Always reconfirm the exact figure against the latest IIBF notification, as thresholds can be revised.
Who is a Politically Exposed Person (PEP)?
A PEP is an individual entrusted with prominent public functions in a foreign country. Relationships with PEPs require enhanced due diligence, senior-management approval and continuous monitoring. The reason is the higher exposure to corruption and bribery risk that such positions carry.
Why does beneficial ownership matter in the customer due diligence framework?
Beneficial ownership ensures the bank knows the real natural person who ultimately owns or controls a customer, not just the legal entity on paper. For companies, trusts and partnerships, control must be traced to the individuals behind the structure. This stops criminals from using corporate layers to hide who truly benefits.
What is Trade-Based Money Laundering?
Trade-Based Money Laundering disguises proceeds of crime through trade transactions. Techniques include over-invoicing, under-invoicing, multiple invoicing and phantom shipments that move value across borders while appearing legitimate. Banks counter it by scrutinising trade documents, pricing benchmarks and the underlying goods.
How does FATF influence India's AML rules?
FATF sets the global standard through its 40 Recommendations and evaluates member countries, including India, in periodic Mutual Evaluations. India aligns its legal framework, such as the PMLA and the RBI Master Direction, with these expectations. The risk-based approach championed by FATF is therefore woven directly into Indian due-diligence practice.
Conclusion
The customer due diligence framework ties together PMLA obligations, the FATF Recommendations, the RBI KYC Master Direction, risk-based diligence, beneficial-ownership identification and FIU-India reporting into one coherent system. Internalise the report triggers, the EDD rules for PEPs and high-risk customers, and typologies such as trade-based money laundering, and the certificate questions will start to feel predictable. Keep your prep active, confirm every figure against the official source, and convert this knowledge into exam-ready marks.
Related Guides
📚 Free Learning Sessions resources — connect & crack your exam
- 📝 Free mock tests — chapter-wise, exam-pattern, with instant solutions
- 🎮 Matching games — gamified revision of key terms & concepts
- 📄 Study notes & PDFs — downloadable chapter material
- 🎥 Video classes on YouTube — subscribe to @learningsessions
💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.
📱 Study on the go — get our iOS & Android app at iibf.store/app.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading