Record Retention Under PMLA: What Every KYC-AML Banker Must Know

KYCAML By Ashish Jain · IIBF STORE Editorial · 26 August 2026 · Updated 10 Oct 2026 · 9 min read · 56 views
Record Retention Under PMLA: What Every KYC-AML Banker Must Know

Every reporting entity in the Indian banking system operates under a strict record retention under PMLA mandate that decides how long customer files, transaction vouchers and identification documents must stay on record before they can legally be destroyed. For KYC-AML candidates, this is one of the most testable corners of the Prevention of Money Laundering Act, because two different clocks run in parallel and examiners love mixing them up. This article walks through both timelines and what banks must do to stay audit-ready.

📜 What the PMLA Record Retention Rule Requires

Section 12 of the PMLA, 2002, read with the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, places a binding obligation on every "reporting entity" — banks, financial institutions and notified intermediaries — to preserve two broad categories of records. The first is a record of every transaction, maintained in a form detailed enough to reconstruct that transaction independently if a regulator or investigator ever asks for it later.

The second is a record of the documents used to establish customer identity, including account-opening forms, officially valid documents, and correspondence generated during the relationship. Both obligations sit alongside the reporting duties already covered under the LEGISLATION AT NATIONAL LEVEL chapter, and RBI's Master Direction on KYC reinforces the same retention discipline for every regulated bank, NBFC and payment entity.

💡 Exam Tip: PMLA record-keeping questions almost always test which of the two timelines applies — transaction records versus identification records — so read the stem carefully before picking an option.
Key Concepts — KYC, AML and CFT
Key Concepts — KYC, AML and CFT

🗂️ Which Records Fall Under the Retention Mandate

Not every document a bank generates falls under the same retention clock, so compliance teams classify records into distinct buckets before deciding how long to keep them. Transaction-level records include deposit and withdrawal vouchers, remittance instructions, cheque images, and any internal note created to explain an unusual transaction pattern.

Identification-level records include the officially valid documents collected at account opening, photographs, signatures, risk-categorisation notes, and periodic KYC-update forms gathered as part of the bank's KYC Policy and Customer Acceptance Policy. A third bucket — correspondence and internal analysis linked to suspicious transaction reports already filed — is preserved separately because it may be called for by FIU-IND or law-enforcement agencies well after the underlying account has closed.

  • Account-opening forms and officially valid documents
  • Transaction vouchers, remittance advices and cheque records
  • Risk profiles and periodic KYC-update records
  • Correspondence tied to filed regulatory reports

Keeping these buckets separate matters because a bank that mixes them up often ends up destroying identification records too early, since the account-closure trigger for that bucket runs on a completely different clock from the transaction-date trigger for the other.

Exam Focus — KYC, AML and CFT
Exam Focus — KYC, AML and CFT

⏳ The Two Distinct Timelines Banks Must Track

The first timeline covers transaction records: these must be preserved for five years counted from the date of each individual transaction, regardless of whether the account itself remains open. A payment made in year one of a ten-year account relationship must still be retrievable in year six, even though the account continues to operate normally.

The second timeline covers client identification and account-opening records: these must be preserved for five years from the date the business relationship ends or the account is closed, whichever is later — not five years from the date the account was opened. So a customer who banks with the same branch for fifteen years generates identification records that must be kept for five years after that fifteen-year relationship finally ends, not five years after it began.

Record TypeRetention TriggerRetention PeriodElectronic Format Accepted
Transaction records (vouchers, remittances, cheques)Date of each transaction5 years from the transaction date✅ Yes, if retrievable
Client identification records (OVDs, account files)End of relationship or account closure, whichever is later5 years from that later dateYes, if retrievable
Records under active investigationRegulatory or law-enforcement directionUntil the direction is lifted — no fixed ceiling❌ Early destruction not permitted
⚠️ Common Mistake: Candidates often assume both record types share a single "five years from opening" rule. They do not — the identification-record clock only starts running once the relationship or account has actually ended.

This distinction also connects to why banks maintain a live governance structure for compliance, as set out under the Organisational SET UP for KYC AML framework, so that record-destruction decisions are never left to a single branch official acting alone.

Quick Revision — KYC, AML and CFT
Quick Revision — KYC, AML and CFT

🏦 How Banks Must Store and Furnish Records

The law does not insist on paper. Records may be held electronically as long as the bank can retrieve them promptly, reconstruct the underlying transaction accurately, and produce them to FIU-IND, the banking regulator or law-enforcement authorities on request. What matters is retrievability and integrity, not the storage medium.

In practice this means banks build core-banking archives with restricted access, audit trails on who viewed or exported a record, and a documented retention schedule flagging which records are due for review each year. A board-approved record management policy typically sits alongside the bank's due diligence framework and cross-references the programme covered under AML / CFT Legislation in Major Countries / Region for banks with cross-border exposure. Regulators expect records to be furnished without unreasonable delay whenever a competent authority asks — a slow response during an inspection is itself treated as a control weakness.

⚖️ Consequences of Poor Record-Keeping

Weak record management rarely shows up as a single dramatic failure — it usually surfaces during a routine inspection when an auditor asks for a five-year-old transaction trail and the branch cannot produce it cleanly. That gap alone can trigger supervisory findings, monetary penalties, and closer ongoing scrutiny of the bank's wider compliance programme, even if no actual laundering is proven.

Poor archiving also degrades the value of every report the bank has already filed, because a report is only as useful to FIU-IND as the underlying documents that support it. Repeated gaps in record availability feed into a bank's broader risk rating with its regulator too, affecting everything from branch-expansion approvals to the intensity of future on-site inspections — making disciplined retention a genuine business priority, not a paperwork formality.

📌 Remember: Five years is a floor, not a ceiling — banks facing an ongoing investigation or a specific regulatory direction may need to hold records well beyond the standard retention period until told otherwise.

🧠 Practice MCQs: Record Retention Under PMLA

Q1. Under the PMLA (Maintenance of Records) Rules, for how long must a bank preserve records of individual transactions, counted from the date of the transaction? (a) 3 years (b) 5 years (c) 8 years (d) 10 years

Answer: (b) — Transaction records must be preserved for five years from the date of each transaction, independent of the account's status.

Q2. Records of client identification documents and account-opening files must be maintained for five years counted from which event? (a) Date of account opening (b) Date of the first transaction (c) Date the business relationship ends or the account is closed, whichever is later (d) Date of the most recent KYC update

Answer: (c) — The identification-record clock starts only once the relationship or account has actually ended, not from account opening.

Q3. Alongside the banking regulator, which authority is the primary recipient of reports and records maintained by banks under PMLA reporting obligations? (a) SEBI (b) FIU-IND (c) IRDAI (d) NPCI

Answer: (b) — The Financial Intelligence Unit-India is the central agency that receives and analyses reports filed by reporting entities under PMLA.

Q4. A bank closes a dormant savings account that had been open for three years. At the earliest, when may the related KYC identification records be legally destroyed? (a) Immediately on closure (b) 5 years after closure (c) 5 years after the account was opened (d) They may never be destroyed

Answer: (b) — Since closure is later than opening, the five-year identification-record clock runs from the closure date.

Q5. Which statement about the permissible format of records under PMLA/KYC norms is correct? (a) Only physical paper records are valid (b) Electronic records are acceptable if they can be retrieved and the transaction reconstructed when required (c) Records never need to be furnished to regulators (d) Banks may destroy records at their own discretion after one year

Answer: (b) — The law is medium-neutral: electronic storage is acceptable provided records remain retrievable and reconstructible on demand.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Which law governs KYC record retention for Indian banks?

Section 12 of the Prevention of Money Laundering Act, 2002, together with the PML (Maintenance of Records) Rules, 2005, sets the core obligation. RBI's Master Direction on KYC applies the same discipline to every regulated bank and NBFC.

How long must transaction records be kept?

Transaction records must be preserved for five years from the date of the individual transaction, regardless of whether the underlying account remains open or has since been closed.

How long must customer identification records be kept?

Identification and account-opening records must be preserved for five years from the date the business relationship ends or the account is closed, whichever occurs later — not five years from account opening.

What happens if a bank cannot produce these records when asked?

An inability to produce records promptly is treated as a control weakness in its own right, and can lead to supervisory findings, penalties, and closer regulatory scrutiny even where no actual laundering is established.

Record retention discipline is easy to underestimate until an inspection exposes a gap five years wide. Bankers preparing for KYC-AML exams should master both clocks precisely, alongside related themes such as PMLA provisional attachment order, officially valid documents for KYC and CKYC ID rules, all of which interact directly with how long a bank must hold onto customer data. Compliance frameworks across financial services rhyme with each other too — credit teams tracking income recognition and asset classification face similarly precise timelines, just for a different purpose.

Keep exploring the KYC, AML and CFT archive, browse the latest IIBF news and circulars, and verify the underlying legal text directly on the Reserve Bank of India website before your next exam attempt.

Prefer revising from a printed book?

Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.

All books →
KYCAML 2026 Edition
KYC, AML and CFT

117 pages · 236 MCQs

Learning Sessions · Ashish Sir

KYC, AML and CFT 16 chapters · 236 MCQs ₹1,199₹2,39850% off
MSME 2026 Edition
Micro, Small and Medium Enterprises (MSME)

132 pages · 225 MCQs

Learning Sessions · Ashish Sir

Micro, Small and Medium Enterprises (MSME) 15 chapters · 225 MCQs ₹1,199₹2,39850% off
CCP 2026 Edition
Certified Credit Professional (CCP)

188 pages · 435 MCQs

Learning Sessions · Ashish Sir

Certified Credit Professional (CCP) 29 chapters · 435 MCQs ₹1,199₹2,39850% off
TIRM 2026 Edition
Treasury, Investment and Risk Management (TIRM)

Learning Sessions · Ashish Sir

Treasury, Investment and Risk Management (TIRM) ₹1,199₹2,39850% off
ITSEC 2026 Edition
IT Security

118 pages · 299 MCQs

Learning Sessions · Ashish Sir

IT Security 20 chapters · 299 MCQs ₹1,199₹2,39850% off
RFS 2026 Edition
Risk in Financial Services

Learning Sessions · Ashish Sir

Risk in Financial Services ₹1,199₹2,39850% off
SFB 2026 Edition
Small Finance Banks

Learning Sessions · Ashish Sir

Small Finance Banks ₹1,199₹2,39850% off
TREASURY 2026 Edition
Treasury Management

Learning Sessions · Ashish Sir

Treasury Management ₹1,199₹2,39850% off
NBFC 2026 Edition
Non-Banking Financial Companies (NBFC)

115 pages · 255 MCQs

Learning Sessions · Ashish Sir

Non-Banking Financial Companies (NBFC) 17 chapters · 255 MCQs ₹1,199₹2,39850% off
ITF 2026 Edition
International Trade Finance

Learning Sessions · Ashish Sir

International Trade Finance ₹1,199₹2,39850% off
CAAP 2026 Edition
Certified Accounting and Audit Professional (CAAP)

334 pages · 936 MCQs

Learning Sessions · Ashish Sir

Certified Accounting and Audit Professional (CAAP) 63 chapters · 936 MCQs ₹1,199₹2,39850% off
RM 2026 Edition
Risk Management

Learning Sessions · Ashish Sir

Risk Management ₹1,199₹2,39850% off
FEFI 2026 Edition
Foreign Exchange Facilities for Individuals (FEFI)

115 pages · 344 MCQs

Learning Sessions · Ashish Sir

Foreign Exchange Facilities for Individuals (FEFI) 24 chapters · 344 MCQs ₹1,199₹2,39850% off
IIBF 2026 Edition
Debt Recovery Agents (DRA)

107 pages · 240 MCQs

Learning Sessions · Ashish Sir

Debt Recovery Agents (DRA) 16 chapters · 240 MCQs ₹1,199₹2,39850% off
DIGIBANK 2026 Edition
Digital Banking

90 pages · 150 MCQs

Learning Sessions · Ashish Sir

Digital Banking 10 chapters · 150 MCQs ₹1,199₹2,39850% off
BCP 2026 Edition
Banking Compliance Professional

Learning Sessions · Ashish Sir

Banking Compliance Professional ₹1,199₹2,39850% off
Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. A non-profit trust with valid MHA/FCRA approval receives a single overseas donation of ₹12 lakh equivalent into its designated FCRA account. Which FIU report(s) apply, assuming no independent grounds of suspicion?
Q2. At a single branch, eight current accounts share the same registered address, the same email ID, similar declared trade lines, and a common contact mobile that belongs to a third party who is himself a director in one entity, with funds funnelled into one account and RTGSed onward. Which typology does this MOST closely match?
Q3. A society registered under the Societies Registration Act, 1860 receives a single donation of Rs. 12 lakh in its account. The relationship manager is unsure which report applies. What is the correct reporting?
Q4. A bank's AML cell concludes on 1st June that a particular transaction is suspicious. The Principal Officer wants to know the regulatory timeline for filing the STR with FIU-IND. What is the prescribed timeline?
Q5. Mr. X has a personal savings account, is a partner in M/s ABC (partnership), and is sole proprietor of M/s XY. In one month he deposits ₹6 lakh cash in savings, ₹3 lakh in ABC and ₹2 lakh in XY. Which deposits are clubbed for CTR, and what is the result?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading