Record Keeping Obligations Under PMLA: What Bankers Must Know

KYCAML By Ashish Jain · IIBF STORE Editorial · 26 July 2026 · Updated 07 Sep 2026 · 11 min read · 43 views
Record Keeping Obligations Under PMLA: What Bankers Must Know

Every banker preparing for the JAIIB or CAIIB KYC-AML paper eventually runs into a deceptively simple question: how long must a record actually be kept, and who signs off on it? Record keeping obligations under PMLA are not a back-office footnote — they determine whether a bank can prove due diligence years after an account is closed, and whether investigators can reconstruct a money trail when it matters most. This article walks through what must be retained, who inside the bank is accountable, and what happens when the paperwork falls short.

📚 Record Keeping Obligations Under PMLA: The Legal Basis

Section 12 of the Prevention of Money Laundering Act, 2002 places three connected duties on every "reporting entity" — a term covering banking companies, financial institutions and intermediaries: maintain a record of prescribed transactions, verify the identity of clients, and furnish information to the Financial Intelligence Unit-India (FIU-IND) in the manner specified. The operational detail sits in the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, particularly Rule 3, which lists exactly which transactions trigger a recording duty and for how long the record must survive.

These obligations do not exist in isolation. They flow directly out of the bank's Board-approved KYC policy and customer acceptance policy, which must explicitly provide for document retention, and they are reinforced by the Central KYC Records Registry, which reduces duplicate paperwork by letting banks fetch a client's KYC record instead of re-collecting it. For exam purposes, remember that record keeping is a statutory obligation under the Act itself, not merely an RBI supervisory expectation — that distinction is what makes non-compliance a punishable offence rather than a mere lapse in prudential practice.

💡 Exam Tip: Questions often test whether a duty flows from PMLA/Rules (statutory, FIU-IND enforced) or from RBI Master Direction (regulatory, RBI enforced). Record retention periods are fixed by the PML Rules, not by RBI circulars.

🗂️ What Records Banks Must Maintain, and For How Long

Rule 3 requires reporting entities to record all cash transactions of value exceeding the prescribed threshold, a series of integrally connected cash transactions that individually fall below the threshold but aggregate above it within a month, transactions involving forged or counterfeit currency, all transactions reported as suspicious regardless of value, and cross-border wire transfers above the prescribed limit. Separately, every document collected during the customer identification procedure — proof of identity, proof of address, photographs, account-opening forms and correspondence — must be preserved as part of the client's KYC record.

The retention clock runs differently for the two categories. Transaction records must be kept for five years from the date the transaction was carried out. Client identification and account-opening records must be kept for five years from the date the business relationship ends or the account is closed, whichever is later — because a dormant account that is later reactivated, or a closed account that resurfaces in an investigation, still needs a traceable paper trail. Banks that batch-purge records on a fixed calendar date rather than tracking each account's actual closure date routinely fail this test during RBI and FIU-IND inspections.

Record CategoryRetention PeriodStarts FromApplies to Banks?
Cash transactions above threshold5 yearsDate of transaction
Suspicious transactions (any value)5 yearsDate of transaction
Cross-border wire transfers above limit5 yearsDate of transaction
Client identification / KYC documents5 yearsEnd of relationship or account closure
Internal analysis notes on flagged accounts5 yearsDate of closure of the case
Routine marketing correspondence (non-KYC)No statutory PMLA period
Key Concepts — KYC, AML and CFT
Key Concepts — KYC, AML and CFT

👤 Designated Director and Principal Officer: Who Owns What

Two roles sit at the centre of a bank's PMLA compliance architecture, and the exam loves to test the difference between them. The Designated Director is a person nominated by the Board of Directors — typically the Managing Director or a whole-time director duly authorised — who carries overarching, personal responsibility for ensuring the bank complies with every obligation under the Act and the Rules, including record keeping. The Principal Officer, by contrast, is the operational nerve centre: the officer who monitors transactions, decides which ones qualify as suspicious, and files reports with FIU-IND. Both roles are described in the bank's organisational set-up for KYC-AML, which also positions the internal audit and compliance functions that periodically test whether retained records actually meet the Rule 3 standard.

In practice, the Designated Director signs off on the policy framework and is accountable if the bank as a whole is found non-compliant, while the Principal Officer is judged on day-to-day execution — did the STR get filed on time, was the identification record actually retrievable when FIU-IND asked for it. A bank can have excellent policy and a weak Principal Officer function, or vice versa; examiners are specifically trained to test both layers independently.

⚠️ Common Mistake: Candidates frequently assume the Principal Officer and Designated Director are the same person or interchangeable titles. They are distinct roles with distinct accountability, even though one individual can sometimes hold both in a smaller entity.

🌍 Cross-Border Transfers, Correspondent Banking and Extra Records

Record-keeping duties intensify wherever cross-border money movement is involved, because that is precisely where trade-based and layering techniques are hardest to trace. Banks maintaining nostro and vostro relationships must apply enhanced record retention over and above the standard KYC file, documenting the respondent bank's ownership structure, its own AML controls, and the purpose of the relationship — a requirement covered in depth under correspondent banking. Similarly, understanding common money laundering methods — over- and under-invoicing, shell company layering, structuring deposits below the reporting threshold — helps a compliance officer decide which additional supporting documents to retain beyond the bare transaction ticket, since a laundering scheme rarely announces itself in a single record.

Reporting obligations for record keeping are not unique to banks. Under PMLA, "reporting entity" also covers non-banking financial companies, payment system operators and certain intermediaries, so a JAIIB or CAIIB candidate should not assume the framework is bank-exclusive; the same Rule 3 thresholds and retention clocks apply, for instance, to non-banking financial companies in India that accept deposits or extend credit. Country risk adds another layer: transfers routed through, or counterparties based in, high-risk jurisdictions typically call for supplementary retained documentation — source-of-funds notes, extended sanctions-screening logs and senior-management sign-off — over and above the standard wire-transfer ticket, precisely because such records are the first thing an examiner asks for when a cross-border flow is later questioned.

Process & Framework — KYC, AML and CFT
Process & Framework — KYC, AML and CFT

⚖️ Penalties When Records Fall Short

Section 13 of PMLA gives the Director, FIU-IND, power to call for records, inspect them, and — after giving the reporting entity a reasonable opportunity of being heard — impose a monetary penalty of not less than ten thousand rupees, extending up to one lakh rupees for each instance of non-compliance with the Section 12 obligations. Where the reporting entity is a banking company, the Director may also refer the matter to RBI for further regulatory action, which can range from a formal warning to more serious supervisory measures against the institution's licence. Because penalties attach per failure rather than per inspection, a bank that has systematically failed to retain records across hundreds of accounts is exposed to a correspondingly large cumulative liability, not a single flat fine.

This is also why the periodic KYC updation rules matter for record keeping in practice: every re-KYC cycle refreshes the documentary record and effectively resets the evidentiary trail an examiner will look for, so missed re-KYC deadlines compound into record-keeping gaps that are separately penalised.

📌 Remember: Section 13 penalties are levied by FIU-IND for the record-keeping and reporting failure itself, independent of whether any actual money laundering is later proven — the paperwork obligation stands on its own.
In Practice — KYC, AML and CFT
In Practice — KYC, AML and CFT

🔍 Why Records Matter Beyond Compliance Checklists

A retained record is only valuable if it can be produced fast and read correctly by an investigator years later. Money laundering cases are rarely solved from a single transaction; they are reconstructed from a chain of records across multiple accounts, sometimes multiple banks, built up over the placement, layering and integration stages of a scheme. A bank whose records are complete, correctly dated and easily retrievable materially shortens an FIU-IND or Enforcement Directorate investigation, while gaps or inconsistent formats can stall a case for months and expose the bank itself to scrutiny for facilitation, however unintentional. This is the practical reason record keeping obligations under PMLA are graded as core compliance infrastructure rather than a clerical afterthought — they are the institution's evidentiary memory, and memory that has been allowed to lapse cannot be recreated after the fact.

For day-to-day branch staff, the operational takeaway is simple: treat every document collected during account opening, every cash transaction ticket above threshold, and every suspicious-transaction note as something with a legal shelf life attached, not paperwork to be archived and forgotten. Systems should track retention dates against actual account-closure dates, not a fixed annual purge cycle, and periodic internal audits should sample-test whether records flagged for retention are genuinely retrievable within a reasonable time when requested.

🧠 Practice MCQs: Record Keeping Under PMLA

Q1. Under Rule 3 of the PML (Maintenance of Records) Rules, 2005, for how long must a bank preserve client identification records after the business relationship has ended? (a) 3 years (b) 5 years (c) 7 years (d) 10 years

Answer: (b) — Identification records must be retained for five years from the date the relationship ends or the account is closed, whichever is later.

Q2. Who is designated by the Board of Directors to hold overarching responsibility for a bank's PMLA compliance, including record keeping? (a) Branch Manager (b) Statutory Auditor (c) Designated Director (d) Chief Risk Officer

Answer: (c) — The Designated Director is nominated by the Board and is personally accountable for compliance with Act and Rules obligations.

Q3. Cash transactions of what value or above must mandatorily be recorded under the PML Rules? (a) ₹2 lakh (b) ₹5 lakh (c) ₹10 lakh (d) ₹50 lakh

Answer: (c) — Cash transactions of ten lakh rupees and above trigger a mandatory recording (and reporting) obligation under Rule 3.

Q4. The Principal Officer under PMLA is primarily responsible for: (a) Sanctioning credit proposals (b) Reporting suspicious and cash transactions to FIU-IND (c) Approving the bank's dividend (d) Conducting statutory audit

Answer: (b) — The Principal Officer is the operational point of contact who monitors and reports prescribed transactions to FIU-IND.

Q5. Under Section 13 of PMLA, failure to maintain records as prescribed can attract a monetary penalty of: (a) ₹1,000 to ₹10,000 (b) ₹10,000 to ₹1,00,000 (c) ₹1 lakh to ₹10 lakh (d) No monetary penalty, only a warning

Answer: (b) — The Director, FIU-IND may, after a hearing, levy a fine of not less than ten thousand rupees extending up to one lakh rupees per instance of non-compliance.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

What is the retention period for transaction records under PMLA?

Reporting entities must preserve records of prescribed transactions for five years from the date of the transaction, as set out in Rule 3 of the PML (Maintenance of Records) Rules, 2005.

What is the difference between a Designated Director and a Principal Officer?

The Designated Director, nominated by the Board, holds overarching accountability for the bank's PMLA compliance framework, while the Principal Officer handles day-to-day monitoring and reporting of suspicious and cash transactions to FIU-IND.

Which transactions must banks compulsorily record under PMLA?

Cash transactions of ten lakh rupees and above, integrally connected cash transactions aggregating above that threshold within a month, transactions involving forged currency, all suspicious transactions irrespective of value, and cross-border wire transfers above the prescribed limit.

What happens if a bank fails to maintain records as required under PMLA?

The Director, FIU-IND can, after giving the entity a hearing, levy a fine ranging from ten thousand rupees to one lakh rupees for each instance of non-compliance under Section 13 of the Act, and may refer banking companies to RBI for further action.

✅ Building Audit-Ready Records

Record keeping obligations under PMLA are ultimately a test of institutional discipline: can a bank prove, on demand and years after the fact, exactly what it knew about a client and when it knew it. Getting the retention clock right, keeping the Designated Director and Principal Officer roles clearly separated, and treating every KYC document as evidence rather than paperwork are the habits that turn compliance from a checklist into a defensible system. For a structured, exam-focused walkthrough of related KYC-AML topics, browse the full KYC-AML and CFT article hub, and when you are ready to test your recall under exam conditions, take a free chapter-wise mock test to see where your record-keeping fundamentals still need work.

Sources: Reserve Bank of India, Financial Intelligence Unit-India, Ministry of Finance.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. An NRI sends an inward foreign remittance of Rs. 6 lakh into a resident's account for a personal gift. The branch must decide on cross-border reporting. Which is correct?
Q2. Which of the following is the operative secure portal of FIU-IND for filing CTR, STR, CCR, NTR and CBWTR as of 2026?
Q3. A walk-in customer enquires about a remittance arrangement, the staff become suspicious about the purpose, and the customer leaves without completing any transaction. No money moved at all. Based on the chapter, what is the correct AML treatment?
Q4. A non-profit trust with valid MHA/FCRA approval receives a single overseas donation of ₹12 lakh equivalent into its designated FCRA account. Which FIU report(s) apply, assuming no independent grounds of suspicion?
Q5. A bank submits a CTR for a month three days late and argues the penalty should be a single violation. Under Rule 8(4) of PMLR as described, how is a reporting delay treated?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading