PMLA Record Keeping Rules for KYC AML & CAIIB 2026
PMLA record keeping is the documentary spine of every bank's anti-money-laundering programme, and for KYC, AML and CFT certification and CAIIB candidates in 2026 it is one of the highest-yielding areas you can prepare. Once you understand exactly what must be preserved, how long it must survive, and who is entitled to demand it, a topic that looks like dense statutory language quietly turns into a cluster of reliable marks.
The reason examiners love this area is simple: it sits at the intersection of law, process and reporting. The Prevention of Money-Laundering Act, 2002 and the PMLA (Maintenance of Records) Rules, 2005 give banks a clear, testable set of duties, and almost every other AML obligation, from Customer Due Diligence to Suspicious Transaction Reporting, leans on the records you maintain. Get the foundations right and the rest of the syllabus becomes noticeably easier.

Key takeaways
- PMLA record keeping covers transaction records, identity (CDD) records, account files and beneficial-ownership details.
- Two separate five-year clocks: transaction records run from the date of the transaction; identity records run from when the relationship ends or the account is closed.
- Records must be produced on demand to FIU-IND, the Enforcement Directorate, RBI supervisors and internal audit, with the Principal Officer as the contact point.
- Good records power accurate STR, CTR, CCR and NTR reporting; weak records invite penalties under the Act.
- For the exam, focus on relationships and timelines rather than memorising exact penalty figures, which can change.
What PMLA Record Keeping Actually Covers
The PMLA and the Maintenance of Records Rules place a clear duty on every reporting entity — banks, NBFCs, payment system operators and other financial intermediaries — to capture and preserve specific information. The objective is to build an audit trail that lets investigators reconstruct a transaction long after it has taken place, sometimes years later. In other words, record keeping is not paperwork for its own sake; it is the evidence base that makes an investigation possible.
For anyone working through the KYC, AML and CFT module, it helps to see the records as four connected buckets rather than a single list. Each bucket answers a different investigative question, and questions in the exam are usually framed around one of them.
The four categories of records you must keep
- Transaction records: the nature, amount, currency, date and the parties to every transaction. This is the raw flow-of-funds data.
- Identity records: the documents collected during Customer Due Diligence — proof of identity and address through Officially Valid Documents (OVDs).
- Account files and business correspondence: account-opening forms, mandates, instructions and the risk-categorisation notes that justify how a customer was classified.
- Beneficial ownership records: details that identify the natural persons who ultimately own or control a company, partnership or trust account.
Together, these let a bank connect a named individual to a specific movement of money — which is precisely what the Financial Intelligence Unit needs when it analyses suspicious activity. A frequently overlooked point: beneficial-ownership records sit at the heart of corporate-account scrutiny, because launderers routinely hide behind layered legal entities. You can pressure-test your grasp of these definitions on the practice sets at the KYC AML mock tests.
Retention Periods: The Two Five-Year Clocks
The single most examined number in this topic is the retention period, and the trap is that there are two of them. Under the PMLA Rules, transaction records must be maintained for five years from the date of the transaction. The clock starts the moment the transaction happens, irrespective of whether the account stays open or shuts the following week.
Identity records behave differently. The CDD documents that prove who the customer is must be kept for five years after the business relationship ends or the account is closed. Here the clock starts at closure, not at onboarding. Candidates lose easy marks every cycle by assuming the identity clock begins at account opening — it does not. Anchor the distinction with one short sentence: transaction clock starts at the transaction; identity clock starts at closure.
This is exactly the kind of contrast that rewards a quick comparison rather than rote memorisation. The table below lays the two clocks side by side so the difference is impossible to forget.
| Aspect | Transaction records | Identity (CDD) records |
|---|---|---|
| Retention period | Five years | Five years |
| When the clock starts | Date of the transaction | Closure of account / end of relationship |
| What it captures | Amount, currency, date, parties | OVDs, proof of identity and address |
| Effect of periodic KYC | Not applicable | Refreshes data; does not reset the closure clock |
How CDD feeds record keeping
Record keeping is not a separate silo; it is the output of the Customer Due Diligence workflow. The depth of what you preserve is decided by how the customer is risk-rated.
- Customer acceptance: risk categorisation as low, medium or high determines how much documentation is captured at onboarding.
- Ongoing monitoring: periodic KYC updation refreshes the identity record but does not reset the closure-based five-year clock.
- Enhanced Due Diligence (EDD): for high-risk customers and Politically Exposed Persons, richer records — source of funds and source of wealth — must be obtained and retained.
Because of this dependency, strong record keeping is inseparable from the CDD and EDD process described in the PMLA, FATF and Customer Due Diligence framework guide. Reinforce the risk-tiering logic with the interactive drills in the KYC AML matching games.

Who Can Access PMLA Records
Records are worthless if they cannot be produced on demand, so the framework is precise about who may call for them. Reporting entities must furnish maintained information to the Director of the Financial Intelligence Unit-India (FIU-IND) and make records available to investigating and supervisory authorities. Within the bank, the Principal Officer is the designated point of contact who certifies and forwards information.
- FIU-IND: receives the prescribed reports and may seek additional records during its analysis.
- Enforcement Directorate (ED): investigates the predicate offence and the laundering trail using the preserved records.
- RBI as supervisor: inspects whether the bank's PMLA record keeping systems are adequate and can penalise gaps.
- Internal audit and the Designated Director: ensure board-level accountability for the compliance programme.
Exam tip: Do not confuse the Principal Officer (operational reporting and the contact for FIU-IND) with the Designated Director (overall board-level accountability for compliance). One files and furnishes; the other owns the policy. Mixing the two is a classic distractor.
Because a request can arrive years after an account has closed, banks store records in retrievable, tamper-evident formats — increasingly digital, with secure, redundant backups. The practical lesson is that retention is not just about time; it is about retrievability and integrity throughout that period.
Reporting Obligations That Depend on Good Records
Record keeping is the foundation on which the entire reporting machinery stands. Without complete records a bank simply cannot file accurate reports, and an incomplete report exposes it to penalties as surely as filing none at all. Every prescribed report that flows from a bank to FIU-IND draws directly on data the bank is already required to preserve.
The main report types
- Cash Transaction Report (CTR): cash transactions above the prescribed threshold, or integrally connected cash transactions, reported on a periodic (monthly) basis.
- Suspicious Transaction Report (STR): filed whenever there are reasonable grounds to suspect money laundering, regardless of amount.
- Counterfeit Currency Report (CCR): raised when forged or counterfeit notes are detected.
- Non-Profit Organisation Transaction Report (NTR): receipts by NPOs above the prescribed value.
An STR must be filed within the prescribed number of days of arriving at the conclusion of suspicion, and the supporting evidence sits inside the records the bank already maintains. That is precisely why examiners pair record keeping with reporting in a single question — the two are operationally inseparable. For the full reporting taxonomy and worked examples, read the STR and CTR reporting to FIU-IND guide and the broader AML compliance under PMLA guide.

A Simple Study Plan for This Topic
This is a topic you can genuinely master in a focused study block rather than weeks of reading. The trick is to learn the structure first and the detail second, because the structure is what the questions actually test.
- Day 1 — Map the four record categories. Write them from memory and attach one example to each. If you can list transaction, identity, account-file and beneficial-ownership records cold, you have covered the most common framing.
- Day 2 — Drill the two five-year clocks. Say aloud, ten times, "transaction clock from the transaction; identity clock from closure." Then attempt five timeline-based MCQs on the KYC AML mock tests.
- Day 3 — Lock the roles and the report types. Separate Principal Officer from Designated Director, then list CTR, STR, CCR and NTR with their trigger in one line each.
- Day 4 — Mixed revision. Take a full-length set, review every wrong answer, and skim the Anti-Money-Laundering obligations of banks guide to see the rules in context.
Time-sensitive specifics — exact thresholds, the precise STR filing window and penalty amounts — can be revised under the latest rules, so confirm the current figures against the official IIBF notification and source documents before exam day rather than trusting an old set of notes.
Common Mistakes to Avoid
Most marks lost on this topic come from a small, predictable set of errors. Knowing them in advance is half the battle.
- Starting the identity clock at account opening. It starts at closure or the end of the relationship — the most common single mistake.
- Believing an STR has a monetary threshold. It does not. Suspicion alone triggers it, regardless of the amount involved.
- Confusing the Principal Officer with the Designated Director. One reports and furnishes; the other carries board-level accountability.
- Ignoring beneficial-ownership records for corporate and trust accounts. These are frequently the decisive detail in a scenario question.
- Memorising exact penalty figures. Focus on the relationship — failure to maintain or furnish records attracts penalties under the Act — because the precise numbers can change.
Frequently Asked Questions
How long must transaction records be kept under PMLA?
Transaction records must be maintained for five years from the date of the transaction. The clock starts when the transaction takes place, not when the account is opened or closed. This makes it distinct from the identity-record retention rule, which is tied to closure.
How long are CDD identity records retained?
Records of a customer's identity collected during Customer Due Diligence must be kept for five years after the business relationship ends or the account is closed. Periodic KYC updation refreshes the data but does not reset this closure-based five-year period. Confirm the current rule against the official IIBF notification before your exam.
Who can demand the records and reports a bank maintains?
FIU-IND receives the prescribed reports and may request additional records during analysis. The Enforcement Directorate, RBI supervisors and internal audit can also access them, and the bank's Principal Officer is the designated contact for furnishing information. The Designated Director holds board-level accountability for the programme.
Does a Suspicious Transaction Report require a minimum amount?
No. An STR is triggered by reasonable grounds to suspect money laundering, irrespective of the transaction value. This contrasts with the Cash Transaction Report, which applies to cash transactions above a prescribed threshold. The distinction is a frequent exam point.
What is the difference between the Principal Officer and the Designated Director?
The Principal Officer handles operational reporting and is the day-to-day contact for FIU-IND, certifying and forwarding information. The Designated Director carries overall, board-level accountability for the bank's AML compliance. Examiners deliberately mix the two roles in distractor options.
What happens if a bank fails to maintain or furnish records?
Failure to maintain records, verify identity or furnish information can attract monetary penalties imposed by the Director under the PMLA, and persistent lapses can trigger supervisory action by the RBI. For the exam, focus on this relationship rather than exact figures, which can be revised — always confirm live values from official sources.
Conclusion
Master PMLA record keeping and you tie together CDD, retention clocks, access rights and reporting into one coherent, high-yield topic for KYC AML and CAIIB candidates in 2026. Lock in the two five-year clocks, separate the Principal Officer from the Designated Director, and remember that every report you file is only as strong as the records behind it. Put in a few focused sessions, test yourself on full-length KYC AML mock papers, browse every guide for this exam on the KYC AML blog hub, and verify time-sensitive rules on the official IIBF website. Consistent practice on these fundamentals is the surest route to a confident pass.
Related Guides
📚 Free Learning Sessions resources — connect & crack your exam
- 📝 Free mock tests — chapter-wise, exam-pattern, with instant solutions
- 🎮 Matching games — gamified revision of key terms & concepts
- 📄 Study notes & PDFs — downloadable chapter material
- 🎥 Video classes on YouTube — subscribe to @learningsessions
💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.
📱 Study on the go — get our iOS & Android app at iibf.store/app.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading