PMLA Obligations for Banks: CAIIB BRBL Guide to KYC, AML and FIU-IND Reporting
For CAIIB candidates preparing Banking Regulations and Business Laws, few topics carry as much practical and exam weight as anti-money-laundering compliance. A strong grasp of PMLA obligations for banks is essential, because the Prevention of Money Laundering Act, 2002 sits at the heart of every bank's Know Your Customer (KYC) and Anti-Money Laundering (AML) framework. Understanding PMLA obligations for banks means knowing which records must be kept, what must be reported to the Financial Intelligence Unit-India (FIU-IND), and how the Reserve Bank of India enforces these duties through its Master Direction on KYC. This guide walks you through the statute, the reporting mechanics, penalties, and the exam-ready facts you must retain.
What the PMLA Requires of Banks
The Prevention of Money Laundering Act, 2002 came into force on 1 July 2005 and is the principal legislation criminalising money laundering in India. For a banker, the operative heart of the Act is Section 12, which lays down the core obligations of a "reporting entity" — a term that covers banks, financial institutions and intermediaries. Under Section 12, every reporting entity must maintain a record of all prescribed transactions, verify and record the identity of its clients and beneficial owners, and furnish information to the Director, FIU-IND, within the prescribed time.
These statutory duties translate into the day-to-day compliance activities every branch performs: customer due diligence at onboarding, ongoing monitoring of account behaviour, and escalation of anything that looks unusual. The Act does not operate in isolation — it is read together with the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, which spell out the transaction thresholds, formats and timelines. The RBI, as the sector regulator, converts these legal requirements into supervisory expectations through its Master Direction on KYC. For CAIIB, remember the chain of authority: Act → Rules → RBI Master Direction → bank's internal policy. Getting this hierarchy right is often the difference between a correct and an incorrect answer, and it mirrors the broader legal framework of regulation of banks that governs how banks are supervised in India.
KYC, Customer Due Diligence and Beneficial Ownership
KYC is the front line of AML defence, and the PMLA framework makes it mandatory rather than optional. Banks must carry out Customer Due Diligence (CDD) using an Officially Valid Document (OVD) — such as Aadhaar, passport, driving licence, voter ID or NREGA job card — to establish and verify identity and current address. Where the customer is a company, trust, partnership or other legal arrangement, the bank must go further and identify the beneficial owner: the natural person who ultimately owns or controls the entity, typically above the ownership thresholds set out in the Rules.
The framework is risk-based. Low-risk customers may receive Simplified Due Diligence, while high-risk customers — politically exposed persons, non-face-to-face clients, or those from higher-risk jurisdictions — attract Enhanced Due Diligence and closer ongoing monitoring. Periodic updation of KYC is required, with the frequency depending on the customer's risk category. Banks must also screen customers against sanctions and watch-lists and are prohibited from opening or maintaining anonymous or benami accounts. A recurring CAIIB theme is that KYC is not a one-time exercise at account opening; it is a continuous obligation that runs for the life of the relationship. This continuous-monitoring duty is what allows a bank to spot the change in behaviour that later becomes a suspicious transaction report. Candidates revising the control and organisation of banks should connect these customer-level duties to the wider prudential controls the RBI imposes on banking companies.

Reporting Obligations: CTR, STR, CCR and NTR
The reporting engine of the PMLA is FIU-IND, the central national agency that receives, analyses and disseminates information on suspect financial transactions. Banks file several categories of report, each with its own trigger. The most exam-relevant are the Cash Transaction Report (CTR) and the Suspicious Transaction Report (STR). A CTR captures cash transactions above the prescribed threshold — commonly cited as ₹10 lakh (or its foreign-currency equivalent) — as well as a series of integrally connected cash transactions that together cross that threshold within a month. An STR is filed whenever a transaction, regardless of amount, gives rise to a reasonable ground of suspicion that it may involve proceeds of crime.
Two other reports round out the set: the Counterfeit Currency Report (CCR) for forged or counterfeit notes, and the Non-Profit Organisation Transaction Report (NTR) for receipts by non-profit organisations above the threshold. The table below summarises the main report types for quick revision.
| Report | Trigger | Indicative Threshold | Filed With |
|---|---|---|---|
| CTR (Cash Transaction Report) | Cash transactions / connected cash transactions | Above ₹10 lakh in a month | FIU-IND |
| STR (Suspicious Transaction Report) | Reasonable ground of suspicion of proceeds of crime | No monetary threshold | FIU-IND |
| CCR (Counterfeit Currency Report) | Forged or counterfeit currency notes used as genuine | Any such instance | FIU-IND |
| NTR (NPO Transaction Report) | Receipts by a non-profit organisation | Above ₹10 lakh | FIU-IND |
A single transaction can be reported under both CTR and STR where a cash transaction is also suspicious. STRs must be filed promptly, and the very existence of a filing must be kept confidential — "tipping off" the customer is itself a breach. Reports are submitted electronically through the FIU-IND reporting portal in the prescribed formats.
Record-Keeping, Penalties and RBI Enforcement
Record retention is a favourite CAIIB numerical. Under the Maintenance of Records Rules, banks must preserve records of transactions for five years from the date of the transaction, and records of client identity and account files for five years after the business relationship ends or the account is closed, whichever is later. These records must be maintained in a manner that allows individual transactions to be reconstructed if called upon by an investigating authority.
Enforcement operates on two tracks. Under the PMLA itself, the offence of money laundering (Section 3) attracts rigorous imprisonment of three to seven years — extendable to ten years where the scheduled offence relates to narcotics — along with fine, plus attachment and confiscation of the proceeds of crime through the Adjudicating Authority and the Appellate Tribunal. Separately, failure by a bank to comply with its reporting and record-keeping duties can invite monetary penalties imposed by the Director, FIU-IND under Section 13. On the prudential side, the RBI can penalise banks for KYC/AML lapses using its powers under the Banking Regulation Act, 1949, and has done so repeatedly in real supervisory actions. For a well-rounded answer, always separate the criminal consequences that fall on launderers from the regulatory penalties that fall on non-compliant banks — the exam frequently tests that distinction. You can reinforce these ideas by revising how the RBI exercises control over the organisation of banks and the broader regulation of banking business.

Exam Focus and Common Traps
In the CAIIB paper, PMLA questions cluster around a few reliable points: the year of the Act (2002) and its commencement (2005); Section 12 as the source of bank obligations; the five-year retention rule; the role of FIU-IND as the recipient of reports; and the difference between CTR (threshold-based, cash) and STR (suspicion-based, no threshold). A common trap is confusing the reporting entity's duty to file with the customer's right to be told — remember that STRs are strictly confidential. Another trap is mixing up the criminal penalty on the launderer with the regulatory penalty on the bank.
Practise applying the framework to short scenarios: a customer structuring deposits just under ₹10 lakh, a sudden spike in an otherwise dormant account, or a mismatch between a client's profile and transaction volume. Each should trigger the "reasonable ground of suspicion" test and an STR, not merely a CTR. Reinforce your revision with targeted mock tests, quick recall games, and by keeping an eye on current RBI circulars, since AML rules are updated frequently. Building this habit of tracing a transaction from red flag to report is exactly the kind of applied reasoning the CAIIB examiners reward, and it also makes you a sharper compliance banker on the job. For authoritative primary-source reading, always cross-check the latest position on the Reserve Bank of India website.
Frequently Asked Questions
What is the main obligation of banks under Section 12 of the PMLA, 2002?
Section 12 requires every reporting entity, including banks, to maintain records of prescribed transactions, verify and record the identity of clients and beneficial owners, and furnish the required information to the Director, FIU-IND, within the time prescribed under the rules.
How long must banks retain PMLA records?
Transaction records must be kept for five years from the date of the transaction, and records of client identity and account files for five years after the business relationship ends or the account is closed, whichever is later, in a form that allows individual transactions to be reconstructed.
What is the difference between a CTR and an STR?
A Cash Transaction Report (CTR) is triggered by cash transactions above the prescribed threshold, commonly ₹10 lakh in a month. A Suspicious Transaction Report (STR) has no monetary threshold and is filed whenever there is a reasonable ground of suspicion that a transaction involves proceeds of crime.
Which authority receives AML reports from banks in India?
The Financial Intelligence Unit-India (FIU-IND) is the central national agency that receives, processes, analyses and disseminates information relating to suspect financial transactions reported by banks and other reporting entities.

Conclusion
PMLA compliance is where banking law meets everyday branch practice, and mastering these obligations gives you both exam marks and real supervisory awareness. Anchor your revision on Section 12, the five-year retention rule, the CTR-versus-STR distinction, and the central role of FIU-IND, then test yourself under time pressure. Ready to check your recall? Attempt a focused CAIIB practice set on our CAIIB mock tests or enrol in the full CAIIB course to cover Banking Regulations and Business Laws end to end. You can also browse more revision notes in the Banking Regulations and Business Laws tag hub.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.