Harun Raaj & AssociatesHarun Raaj & Associates
Business Compliance & Labour Lawvia FIU-IND Portal (goifc.gov.in)

PMLA & VASP Compliance — Anti-Money Laundering, KYC & FIU-IND Reporting

AML/CFT compliance for reporting entities under PMLA 2002 — KYC/CDD policy implementation, suspicious transaction reporting (STR) to FIU-IND, cash transaction reporting (CTR), VASP (Virtual Asset Service Provider) compliance for crypto exchanges and wallet providers, and internal audit of AML controls.

Talk to a CAWhatsApp us
STARTING FROM₹34,999
TYPICAL TIMELINE30 days
DOCS REQUIRED5 documents
APPLICABLE TOCompany, LLP, Individual

Regulatory Framework

Prevention of Money Laundering Act, 2002 (PMLA): Section 2(1)(wa) — definition of reporting entity; Section 12 — obligations of reporting entities (KYC, record maintenance, STR filing); Section 12A — enhanced due diligence; Section 13 — verification of records by Director, FIU-IND; Section 14A — prohibition on tipping off; Section 16 — powers of investigation; Section 19 — arrest without warrant. PMLA (Maintenance of Records) Rules, 2005: Rule 3 — suspicious transaction reports (STR) within 7 working days; Rule 3A — CTR for cash ≥₹10 lakh; Rule 9 — customer due diligence. VASPs notified under PMLA: Ministry of Finance Gazette Notification dated 7 March 2023 (S.O. 1072(E)) — virtual assets added to definition of 'property' under PMLA; entities providing services in relation to virtual assets are Reporting Entities. DNFBPs notified: MCA Gazette notification 2023 — CAs, CSs, and CWAs acting in professional capacity for real estate transactions, company incorporations, and client asset management are Reporting Entities. FATF Recommendation 16 — Travel Rule for virtual asset transfers ≥USD 1,000. FIU-IND Guidelines on identification of beneficial owners (2023 update): natural person holding ≥25% shareholding or effective control.

Overview

The Prevention of Money Laundering Act, 2002 (PMLA) imposes obligations on designated 'Reporting Entities' — banking companies, financial institutions, intermediaries, and certain designated non-financial businesses and professions (DNFBPs) including CA firms, real estate agents, and now Virtual Asset Service Providers (VASPs) — to implement Customer Due Diligence (CDD), maintain records, and report suspicious transactions to the Financial Intelligence Unit — India (FIU-IND).

Who are Reporting Entities under PMLA?
Section 2(1)(wa) and Schedule of PMLA, read with PMLA (Maintenance of Records) Rules, 2005 and FIU-IND guidelines:
(i) Banking companies and co-operative banks.
(ii) Financial institutions: NBFCs, housing finance companies, payment aggregators, payment gateways, and money changers.
(iii) Intermediaries: SEBI-regulated entities (stockbrokers, portfolio managers, depository participants, mutual funds, investment advisers, REITs, InvITs).
(iv) Designated Non-Financial Businesses and Professions (DNFBPs): CAs, company secretaries, and cost accountants in their professional capacity (notified vide MCA Gazette notification of 2023); real estate agents for transactions above a threshold; casino operators.
(v) Virtual Asset Service Providers (VASPs): notified under PMLA vide Ministry of Finance notification dated 7 March 2023 — all entities providing services relating to exchange, transfer, safekeeping, and administration of virtual assets (cryptocurrencies, NFTs, digital tokens) must register with FIU-IND and comply with full PMLA obligations.

Core PMLA Compliance Obligations:

1. Customer Due Diligence (CDD) / KYC:
Section 12 and PMLA Rules — verify customer identity (PAN, Aadhaar, passport), obtain beneficial ownership information (UBO: natural person owning ≥25% of a company or exercising effective control), perform risk categorisation (Low/Medium/High), and apply Enhanced Due Diligence (EDD) for Politically Exposed Persons (PEPs), high-risk countries, and complex ownership structures.

2. Suspicious Transaction Reports (STR):
Rule 3 of PMLA Rules — file STR with FIU-IND within 7 working days of forming a suspicion. STR is filed on the FIU-IND portal (goifc.gov.in). Indicators of suspicious transactions: unusual transaction patterns, structuring (splitting transactions below reporting thresholds), transactions with sanctioned countries or individuals, and inconsistency between transaction amounts and client's stated business or income.

3. Cash Transaction Reports (CTR):
File CTR with FIU-IND for all cash transactions of ₹10 lakh and above in a single day (per customer account) by the 15th of the following month. Applicable to banks, NBFCs, and money changers.

4. VASP-Specific Compliance:
VASPs notified under PMLA (March 2023) must: register with FIU-IND; implement full CDD/KYC for all users; file STR and CTR; implement Travel Rule (identify originator and beneficiary for virtual asset transfers ≥USD 1,000 equivalent); maintain records for 5 years; designate a Principal Officer responsible for PMLA compliance.

How It Works

  1. 1

    Reporting Entity Assessment & PMLA Applicability Mapping

    Determine whether the entity is a 'Reporting Entity' under PMLA. Map the entity's activities against Schedule I and Schedule II of PMLA and the PMLA (Maintenance of Records) Rules, 2005: banks and NBFCs (always covered); SEBI-regulated intermediaries (stockbrokers, investment advisers, portfolio managers, mutual fund distributors); DNFBPs — CA/CS/CWA firms involved in real estate transactions, company/LLP incorporation, management of client assets, or tax advice that creates reporting obligations under MCA 2023 notification; VASPs — all crypto exchanges, wallet providers, OTC desks, and DeFi platforms providing services to Indian customers. Identify the designated Principal Officer (a senior management individual responsible for PMLA compliance) and register them with FIU-IND.

    Government3-5 days
  2. 2

    KYC / CDD Policy Design & Risk Categorisation Framework

    Design the KYC/CDD policy manual: (i) Customer Identification Procedure (CIP) — documents to collect for individual (PAN + Aadhaar/Passport/Driving Licence), non-individual (COI, MOA/AOA, PAN, board resolution), foreign national, and NRI customers; (ii) Beneficial Ownership: for companies — natural person owning ≥25% directly or indirectly, or exercising effective control; for trusts — settlor, trustees, beneficiaries; (iii) Risk Categorisation: Low Risk (government entities, listed companies, domestic financial institutions), Medium Risk (standard retail customers), High Risk (PEPs, non-resident customers, complex ownership, high-value transactions); (iv) Enhanced Due Diligence (EDD) for High Risk: additional source of funds documentation, senior management approval. Implement periodic KYC re-verification: Low Risk — every 10 years; Medium Risk — every 8 years; High Risk — every 2 years.

    Government7-10 days
  3. 3

    STR & CTR Reporting Setup — FIU-IND Portal Registration

    Register the entity and the Principal Officer on the FIU-IND portal (goifc.gov.in). Configure STR reporting workflow: train compliance team on red flag indicators (from FIU-IND typologies and FATF guidance), establish internal escalation procedure (branch/relationship manager → compliance officer → Principal Officer → FIU-IND), and set 7-working-day filing deadline from suspicion formation. For financial entities: configure CTR reporting for cash transactions ≥₹10 lakh per day per customer — set up automated alerts in the CBS/core system, batch CTR filing by 15th of following month. Establish a non-tipping-off policy: under Section 14A of PMLA, the Principal Officer cannot disclose to the customer or any other person that an STR has been filed.

    Government5-7 days
  4. 4

    VASP-Specific Compliance (for Crypto/Digital Asset Entities)

    For Virtual Asset Service Providers notified under PMLA (Ministry of Finance notification dated 7 March 2023): register with FIU-IND (registration link: goifc.gov.in). Implement VASP-specific CDD: blockchain address screening against OFAC/UN/EU sanctions lists (using tools like Chainalysis, Elliptic, or TRM Labs); Travel Rule compliance (FATF Recommendation 16): for virtual asset transfers ≥USD 1,000 equivalent — collect and transmit originator name, account number (wallet address), and beneficiary information. Implement risk scoring of wallet addresses (exchange wallets vs. darknet market addresses). Designate a Reporting Entity Officer and Designated Director under PMLA. Establish transaction monitoring rules for structuring, mixing, and high-risk jurisdiction transfers.

    Government10-15 days
  5. 5

    AML Internal Audit & PMLA Compliance Programme Review

    Conduct an annual AML/CFT internal audit of the PMLA compliance programme: (i) KYC/CDD completeness — sample 5-10% of customer files and check for required documents, risk categorisation, and periodic re-verification; (ii) STR filing review — verify all flagged transactions were either reported within 7 days or the decision not to report was documented with rationale; (iii) CTR filing accuracy — reconcile CTR submissions against the entity's cash transaction records; (iv) record keeping — verify that all transaction records and customer identification documents are maintained for at least 5 years (PMLA Section 12: records to be maintained for 5 years from transaction date or 5 years from cessation of relationship); (v) training records — confirm PMLA training was conducted for all relevant staff at least annually. Prepare an AML internal audit report addressed to the Board/Audit Committee.

    Government5-10 days

Frequently Asked Questions

Are Chartered Accountants Reporting Entities under PMLA?
Yes — with effect from the MCA Gazette notification of 2023, Chartered Accountants (CAs), Company Secretaries (CSs), and Cost and Works Accountants (CWAs) are designated as Reporting Entities under PMLA when they carry out certain specified transactions on behalf of clients: (i) purchase or sale of real estate; (ii) management of client money, securities, or other assets; (iii) management of bank, savings, or securities accounts; (iv) organisation of contributions for the creation, operation, or management of companies/LLPs; (v) creation/operation of legal persons or legal arrangements (companies, trusts, partnerships), and buying/selling of business entities. CA firms that provide tax advice or audit without any of the above activities are not covered. For covered activities, the CA firm must register with FIU-IND, implement a KYC/CDD policy, file STRs, and maintain records for 5 years.
What is a Suspicious Transaction Report (STR) and when must it be filed?
An STR (Suspicious Transaction Report) is a report filed by a Reporting Entity with FIU-IND (Financial Intelligence Unit — India) when the entity forms a suspicion that a transaction or attempted transaction may be related to money laundering or terrorist financing — regardless of whether the transaction was completed. Filing deadline: within 7 working days of forming the suspicion (not from the date of the transaction). STR is filed electronically on the FIU-IND portal (goifc.gov.in) by the Principal Officer of the Reporting Entity. Common suspicion triggers: transactions inconsistent with the customer's profile or stated business; structuring (intentionally splitting transactions below reporting thresholds); transactions with countries on FATF grey/black lists; round-tripping of funds; transactions by PEPs from high-risk jurisdictions. Importantly: under Section 14A of PMLA, once an STR is filed, the Reporting Entity must not disclose to the customer or any other person that an STR has been filed (tipping-off prohibition).
What are the PMLA compliance requirements for crypto exchanges and VASP entities?
Since the Ministry of Finance Gazette Notification dated 7 March 2023 (S.O. 1072(E)), Virtual Asset Service Providers (VASPs) — including crypto exchanges, wallet providers, OTC desks, and NFT marketplaces — are Reporting Entities under PMLA with full compliance obligations: (i) FIU-IND registration: mandatory before commencing or continuing operations; (ii) KYC/CDD for all users — PAN and Aadhaar for Indian residents; (iii) Risk categorisation and EDD for high-risk wallets; (iv) Blockchain address screening against sanctions lists; (v) Travel Rule compliance for transfers ≥USD 1,000: collect originator and beneficiary name, wallet address, and transaction details; (vi) STR filing within 7 days of suspicion; (vii) CTR filing for transactions ≥₹10 lakh per day in cash (for fiat-to-crypto ramps); (viii) Record maintenance for 5 years. Non-compliance: PMLA enforcement including property attachment under Section 5, and prosecution.
What is the beneficial owner threshold under PMLA for companies?
Under the PMLA (Maintenance of Records) Rules, 2005 (as amended in 2023), the beneficial owner (BO) for a company is defined as the natural person who ultimately owns or controls the company. Thresholds: (i) for shares: natural person who directly or indirectly holds ≥25% of shares or voting rights; (ii) for indirect holdings: natural person who exercises control through a chain of ownership; (iii) residual control test: if no natural person is identified through shareholding, the natural person who exercises control through other means (e.g., through agreements, rights to appoint majority of directors); (iv) last resort: senior managing official (e.g., MD or CEO). For trusts: settlor, all trustees, the protector, all beneficiaries, or natural person exercising ultimate effective control. The Reporting Entity must obtain BO information at customer onboarding and update it whenever a change in BO is communicated or suspected.
What are the penalties for non-compliance with PMLA obligations?
PMLA penalties are among the most severe in Indian financial law: (i) Section 13 — failure to maintain records, file STR/CTR, or implement KYC: fine up to ₹1 lakh per default, in addition to regulatory directions from FIU-IND (which can direct discontinuation of services to specific customers); (ii) Section 16 — investigation powers: the Director of FIU-IND can search premises and seize records; (iii) Section 5 — provisional attachment of property: the Enforcement Directorate (ED) can provisionally attach any property believed to be 'proceeds of crime' for 180 days (extendable by PMLA Adjudicating Authority); (iv) Section 19 — arrest: the ED can arrest a person if they believe the person is guilty of a money laundering offence (Section 3 PMLA); (v) Section 4 — conviction: imprisonment of not less than 3 years (up to 7 years for certain scheduled offences) plus fine. For VASP-specific violations, SEBI can also delist/debar the VASP from operating.

Ready to get PMLA & VASP Compliance — Anti-Money Laundering, KYC & FIU-IND Reporting?

File a request in under 2 minutes. Our team contacts you within 24 hours.