PMLA & VASP Compliance — Anti-Money Laundering, KYC & FIU-IND Reporting
AML/CFT compliance for reporting entities under PMLA 2002 — KYC/CDD policy implementation, suspicious transaction reporting (STR) to FIU-IND, cash transaction reporting (CTR), VASP (Virtual Asset Service Provider) compliance for crypto exchanges and wallet providers, and internal audit of AML controls.
Regulatory Framework
Prevention of Money Laundering Act, 2002 (PMLA): Section 2(1)(wa) — definition of reporting entity; Section 12 — obligations of reporting entities (KYC, record maintenance, STR filing); Section 12A — enhanced due diligence; Section 13 — verification of records by Director, FIU-IND; Section 14A — prohibition on tipping off; Section 16 — powers of investigation; Section 19 — arrest without warrant. PMLA (Maintenance of Records) Rules, 2005: Rule 3 — suspicious transaction reports (STR) within 7 working days; Rule 3A — CTR for cash ≥₹10 lakh; Rule 9 — customer due diligence. VASPs notified under PMLA: Ministry of Finance Gazette Notification dated 7 March 2023 (S.O. 1072(E)) — virtual assets added to definition of 'property' under PMLA; entities providing services in relation to virtual assets are Reporting Entities. DNFBPs notified: MCA Gazette notification 2023 — CAs, CSs, and CWAs acting in professional capacity for real estate transactions, company incorporations, and client asset management are Reporting Entities. FATF Recommendation 16 — Travel Rule for virtual asset transfers ≥USD 1,000. FIU-IND Guidelines on identification of beneficial owners (2023 update): natural person holding ≥25% shareholding or effective control.
Overview
The Prevention of Money Laundering Act, 2002 (PMLA) imposes obligations on designated 'Reporting Entities' — banking companies, financial institutions, intermediaries, and certain designated non-financial businesses and professions (DNFBPs) including CA firms, real estate agents, and now Virtual Asset Service Providers (VASPs) — to implement Customer Due Diligence (CDD), maintain records, and report suspicious transactions to the Financial Intelligence Unit — India (FIU-IND).
Who are Reporting Entities under PMLA?
Section 2(1)(wa) and Schedule of PMLA, read with PMLA (Maintenance of Records) Rules, 2005 and FIU-IND guidelines:
(i) Banking companies and co-operative banks.
(ii) Financial institutions: NBFCs, housing finance companies, payment aggregators, payment gateways, and money changers.
(iii) Intermediaries: SEBI-regulated entities (stockbrokers, portfolio managers, depository participants, mutual funds, investment advisers, REITs, InvITs).
(iv) Designated Non-Financial Businesses and Professions (DNFBPs): CAs, company secretaries, and cost accountants in their professional capacity (notified vide MCA Gazette notification of 2023); real estate agents for transactions above a threshold; casino operators.
(v) Virtual Asset Service Providers (VASPs): notified under PMLA vide Ministry of Finance notification dated 7 March 2023 — all entities providing services relating to exchange, transfer, safekeeping, and administration of virtual assets (cryptocurrencies, NFTs, digital tokens) must register with FIU-IND and comply with full PMLA obligations.
Core PMLA Compliance Obligations:
1. Customer Due Diligence (CDD) / KYC:
Section 12 and PMLA Rules — verify customer identity (PAN, Aadhaar, passport), obtain beneficial ownership information (UBO: natural person owning ≥25% of a company or exercising effective control), perform risk categorisation (Low/Medium/High), and apply Enhanced Due Diligence (EDD) for Politically Exposed Persons (PEPs), high-risk countries, and complex ownership structures.
2. Suspicious Transaction Reports (STR):
Rule 3 of PMLA Rules — file STR with FIU-IND within 7 working days of forming a suspicion. STR is filed on the FIU-IND portal (goifc.gov.in). Indicators of suspicious transactions: unusual transaction patterns, structuring (splitting transactions below reporting thresholds), transactions with sanctioned countries or individuals, and inconsistency between transaction amounts and client's stated business or income.
3. Cash Transaction Reports (CTR):
File CTR with FIU-IND for all cash transactions of ₹10 lakh and above in a single day (per customer account) by the 15th of the following month. Applicable to banks, NBFCs, and money changers.
4. VASP-Specific Compliance:
VASPs notified under PMLA (March 2023) must: register with FIU-IND; implement full CDD/KYC for all users; file STR and CTR; implement Travel Rule (identify originator and beneficiary for virtual asset transfers ≥USD 1,000 equivalent); maintain records for 5 years; designate a Principal Officer responsible for PMLA compliance.
How It Works
- 1
Reporting Entity Assessment & PMLA Applicability Mapping
Determine whether the entity is a 'Reporting Entity' under PMLA. Map the entity's activities against Schedule I and Schedule II of PMLA and the PMLA (Maintenance of Records) Rules, 2005: banks and NBFCs (always covered); SEBI-regulated intermediaries (stockbrokers, investment advisers, portfolio managers, mutual fund distributors); DNFBPs — CA/CS/CWA firms involved in real estate transactions, company/LLP incorporation, management of client assets, or tax advice that creates reporting obligations under MCA 2023 notification; VASPs — all crypto exchanges, wallet providers, OTC desks, and DeFi platforms providing services to Indian customers. Identify the designated Principal Officer (a senior management individual responsible for PMLA compliance) and register them with FIU-IND.
Government3-5 days - 2
KYC / CDD Policy Design & Risk Categorisation Framework
Design the KYC/CDD policy manual: (i) Customer Identification Procedure (CIP) — documents to collect for individual (PAN + Aadhaar/Passport/Driving Licence), non-individual (COI, MOA/AOA, PAN, board resolution), foreign national, and NRI customers; (ii) Beneficial Ownership: for companies — natural person owning ≥25% directly or indirectly, or exercising effective control; for trusts — settlor, trustees, beneficiaries; (iii) Risk Categorisation: Low Risk (government entities, listed companies, domestic financial institutions), Medium Risk (standard retail customers), High Risk (PEPs, non-resident customers, complex ownership, high-value transactions); (iv) Enhanced Due Diligence (EDD) for High Risk: additional source of funds documentation, senior management approval. Implement periodic KYC re-verification: Low Risk — every 10 years; Medium Risk — every 8 years; High Risk — every 2 years.
Government7-10 days - 3
STR & CTR Reporting Setup — FIU-IND Portal Registration
Register the entity and the Principal Officer on the FIU-IND portal (goifc.gov.in). Configure STR reporting workflow: train compliance team on red flag indicators (from FIU-IND typologies and FATF guidance), establish internal escalation procedure (branch/relationship manager → compliance officer → Principal Officer → FIU-IND), and set 7-working-day filing deadline from suspicion formation. For financial entities: configure CTR reporting for cash transactions ≥₹10 lakh per day per customer — set up automated alerts in the CBS/core system, batch CTR filing by 15th of following month. Establish a non-tipping-off policy: under Section 14A of PMLA, the Principal Officer cannot disclose to the customer or any other person that an STR has been filed.
Government5-7 days - 4
VASP-Specific Compliance (for Crypto/Digital Asset Entities)
For Virtual Asset Service Providers notified under PMLA (Ministry of Finance notification dated 7 March 2023): register with FIU-IND (registration link: goifc.gov.in). Implement VASP-specific CDD: blockchain address screening against OFAC/UN/EU sanctions lists (using tools like Chainalysis, Elliptic, or TRM Labs); Travel Rule compliance (FATF Recommendation 16): for virtual asset transfers ≥USD 1,000 equivalent — collect and transmit originator name, account number (wallet address), and beneficiary information. Implement risk scoring of wallet addresses (exchange wallets vs. darknet market addresses). Designate a Reporting Entity Officer and Designated Director under PMLA. Establish transaction monitoring rules for structuring, mixing, and high-risk jurisdiction transfers.
Government10-15 days - 5
AML Internal Audit & PMLA Compliance Programme Review
Conduct an annual AML/CFT internal audit of the PMLA compliance programme: (i) KYC/CDD completeness — sample 5-10% of customer files and check for required documents, risk categorisation, and periodic re-verification; (ii) STR filing review — verify all flagged transactions were either reported within 7 days or the decision not to report was documented with rationale; (iii) CTR filing accuracy — reconcile CTR submissions against the entity's cash transaction records; (iv) record keeping — verify that all transaction records and customer identification documents are maintained for at least 5 years (PMLA Section 12: records to be maintained for 5 years from transaction date or 5 years from cessation of relationship); (v) training records — confirm PMLA training was conducted for all relevant staff at least annually. Prepare an AML internal audit report addressed to the Board/Audit Committee.
Government5-10 days
Frequently Asked Questions
Ready to get PMLA & VASP Compliance — Anti-Money Laundering, KYC & FIU-IND Reporting?
File a request in under 2 minutes. Our team contacts you within 24 hours.