Record Retention Under PMLA: What Every KYC-AML Banker Must Know
Every reporting entity in the Indian banking system operates under a strict record retention under PMLA mandate that decides how long customer files, transaction vouchers and identification documents must stay on record before they can legally be destroyed. For KYC-AML candidates, this is one of the most testable corners of the Prevention of Money Laundering Act, because two different clocks run in parallel and examiners love mixing them up. This article walks through both timelines and what banks must do to stay audit-ready.
📜 What the PMLA Record Retention Rule Requires
Section 12 of the PMLA, 2002, read with the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, places a binding obligation on every "reporting entity" — banks, financial institutions and notified intermediaries — to preserve two broad categories of records. The first is a record of every transaction, maintained in a form detailed enough to reconstruct that transaction independently if a regulator or investigator ever asks for it later.
The second is a record of the documents used to establish customer identity, including account-opening forms, officially valid documents, and correspondence generated during the relationship. Both obligations sit alongside the reporting duties already covered under the LEGISLATION AT NATIONAL LEVEL chapter, and RBI's Master Direction on KYC reinforces the same retention discipline for every regulated bank, NBFC and payment entity.
💡 Exam Tip: PMLA record-keeping questions almost always test which of the two timelines applies — transaction records versus identification records — so read the stem carefully before picking an option.

🗂️ Which Records Fall Under the Retention Mandate
Not every document a bank generates falls under the same retention clock, so compliance teams classify records into distinct buckets before deciding how long to keep them. Transaction-level records include deposit and withdrawal vouchers, remittance instructions, cheque images, and any internal note created to explain an unusual transaction pattern.
Identification-level records include the officially valid documents collected at account opening, photographs, signatures, risk-categorisation notes, and periodic KYC-update forms gathered as part of the bank's KYC Policy and Customer Acceptance Policy. A third bucket — correspondence and internal analysis linked to suspicious transaction reports already filed — is preserved separately because it may be called for by FIU-IND or law-enforcement agencies well after the underlying account has closed.
- Account-opening forms and officially valid documents
- Transaction vouchers, remittance advices and cheque records
- Risk profiles and periodic KYC-update records
- Correspondence tied to filed regulatory reports
Keeping these buckets separate matters because a bank that mixes them up often ends up destroying identification records too early, since the account-closure trigger for that bucket runs on a completely different clock from the transaction-date trigger for the other.

⏳ The Two Distinct Timelines Banks Must Track
The first timeline covers transaction records: these must be preserved for five years counted from the date of each individual transaction, regardless of whether the account itself remains open. A payment made in year one of a ten-year account relationship must still be retrievable in year six, even though the account continues to operate normally.
The second timeline covers client identification and account-opening records: these must be preserved for five years from the date the business relationship ends or the account is closed, whichever is later — not five years from the date the account was opened. So a customer who banks with the same branch for fifteen years generates identification records that must be kept for five years after that fifteen-year relationship finally ends, not five years after it began.
| Record Type | Retention Trigger | Retention Period | Electronic Format Accepted |
|---|---|---|---|
| Transaction records (vouchers, remittances, cheques) | Date of each transaction | 5 years from the transaction date | ✅ Yes, if retrievable |
| Client identification records (OVDs, account files) | End of relationship or account closure, whichever is later | 5 years from that later date | Yes, if retrievable |
| Records under active investigation | Regulatory or law-enforcement direction | Until the direction is lifted — no fixed ceiling | ❌ Early destruction not permitted |
⚠️ Common Mistake: Candidates often assume both record types share a single "five years from opening" rule. They do not — the identification-record clock only starts running once the relationship or account has actually ended.
This distinction also connects to why banks maintain a live governance structure for compliance, as set out under the Organisational SET UP for KYC AML framework, so that record-destruction decisions are never left to a single branch official acting alone.

🏦 How Banks Must Store and Furnish Records
The law does not insist on paper. Records may be held electronically as long as the bank can retrieve them promptly, reconstruct the underlying transaction accurately, and produce them to FIU-IND, the banking regulator or law-enforcement authorities on request. What matters is retrievability and integrity, not the storage medium.
In practice this means banks build core-banking archives with restricted access, audit trails on who viewed or exported a record, and a documented retention schedule flagging which records are due for review each year. A board-approved record management policy typically sits alongside the bank's due diligence framework and cross-references the programme covered under AML / CFT Legislation in Major Countries / Region for banks with cross-border exposure. Regulators expect records to be furnished without unreasonable delay whenever a competent authority asks — a slow response during an inspection is itself treated as a control weakness.
⚖️ Consequences of Poor Record-Keeping
Weak record management rarely shows up as a single dramatic failure — it usually surfaces during a routine inspection when an auditor asks for a five-year-old transaction trail and the branch cannot produce it cleanly. That gap alone can trigger supervisory findings, monetary penalties, and closer ongoing scrutiny of the bank's wider compliance programme, even if no actual laundering is proven.
Poor archiving also degrades the value of every report the bank has already filed, because a report is only as useful to FIU-IND as the underlying documents that support it. Repeated gaps in record availability feed into a bank's broader risk rating with its regulator too, affecting everything from branch-expansion approvals to the intensity of future on-site inspections — making disciplined retention a genuine business priority, not a paperwork formality.
📌 Remember: Five years is a floor, not a ceiling — banks facing an ongoing investigation or a specific regulatory direction may need to hold records well beyond the standard retention period until told otherwise.
🧠 Practice MCQs: Record Retention Under PMLA
Q1. Under the PMLA (Maintenance of Records) Rules, for how long must a bank preserve records of individual transactions, counted from the date of the transaction? (a) 3 years (b) 5 years (c) 8 years (d) 10 years
Answer: (b) — Transaction records must be preserved for five years from the date of each transaction, independent of the account's status.
Q2. Records of client identification documents and account-opening files must be maintained for five years counted from which event? (a) Date of account opening (b) Date of the first transaction (c) Date the business relationship ends or the account is closed, whichever is later (d) Date of the most recent KYC update
Answer: (c) — The identification-record clock starts only once the relationship or account has actually ended, not from account opening.
Q3. Alongside the banking regulator, which authority is the primary recipient of reports and records maintained by banks under PMLA reporting obligations? (a) SEBI (b) FIU-IND (c) IRDAI (d) NPCI
Answer: (b) — The Financial Intelligence Unit-India is the central agency that receives and analyses reports filed by reporting entities under PMLA.
Q4. A bank closes a dormant savings account that had been open for three years. At the earliest, when may the related KYC identification records be legally destroyed? (a) Immediately on closure (b) 5 years after closure (c) 5 years after the account was opened (d) They may never be destroyed
Answer: (b) — Since closure is later than opening, the five-year identification-record clock runs from the closure date.
Q5. Which statement about the permissible format of records under PMLA/KYC norms is correct? (a) Only physical paper records are valid (b) Electronic records are acceptable if they can be retrieved and the transaction reconstructed when required (c) Records never need to be furnished to regulators (d) Banks may destroy records at their own discretion after one year
Answer: (b) — The law is medium-neutral: electronic storage is acceptable provided records remain retrievable and reconstructible on demand.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
❓ Frequently Asked Questions
Which law governs KYC record retention for Indian banks?
Section 12 of the Prevention of Money Laundering Act, 2002, together with the PML (Maintenance of Records) Rules, 2005, sets the core obligation. RBI's Master Direction on KYC applies the same discipline to every regulated bank and NBFC.
How long must transaction records be kept?
Transaction records must be preserved for five years from the date of the individual transaction, regardless of whether the underlying account remains open or has since been closed.
How long must customer identification records be kept?
Identification and account-opening records must be preserved for five years from the date the business relationship ends or the account is closed, whichever occurs later — not five years from account opening.
What happens if a bank cannot produce these records when asked?
An inability to produce records promptly is treated as a control weakness in its own right, and can lead to supervisory findings, penalties, and closer regulatory scrutiny even where no actual laundering is established.
Record retention discipline is easy to underestimate until an inspection exposes a gap five years wide. Bankers preparing for KYC-AML exams should master both clocks precisely, alongside related themes such as PMLA provisional attachment order, officially valid documents for KYC and CKYC ID rules, all of which interact directly with how long a bank must hold onto customer data. Compliance frameworks across financial services rhyme with each other too — credit teams tracking income recognition and asset classification face similarly precise timelines, just for a different purpose.
Keep exploring the KYC, AML and CFT archive, browse the latest IIBF news and circulars, and verify the underlying legal text directly on the Reserve Bank of India website before your next exam attempt.
Prefer revising from a printed book?
Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.
117 pages · 236 MCQs
Learning Sessions · Ashish Sir
132 pages · 225 MCQs
Learning Sessions · Ashish Sir
188 pages · 435 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
118 pages · 299 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
115 pages · 255 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
334 pages · 936 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
115 pages · 344 MCQs
Learning Sessions · Ashish Sir
107 pages · 240 MCQs
Learning Sessions · Ashish Sir
90 pages · 150 MCQs
Learning Sessions · Ashish Sir
Learning Sessions · Ashish Sir
131 pages · 672 MCQs
Learning Sessions · Ashish Sir
221 pages · 831 MCQs
Learning Sessions · Ashish Sir
128 pages · 524 MCQs
Learning Sessions · Ashish Sir
107 pages · 445 MCQs
Learning Sessions · Ashish Sir
148 pages · 478 MCQs
Learning Sessions · Ashish Sir
151 pages · 465 MCQs
Learning Sessions · Ashish Sir
148 pages · 375 MCQs
Learning Sessions · Ashish Sir
216 pages · 895 MCQs
Learning Sessions · Ashish Sir
109 pages · 300 MCQs
Learning Sessions · Ashish Sir
104 pages · 360 MCQs
Learning Sessions · Ashish Sir
82 pages · 297 MCQs
Learning Sessions · Ashish Sir
151 pages · 600 MCQs
Learning Sessions · Ashish Sir
98 pages · 282 MCQs
Learning Sessions · Ashish Sir
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.