AML in India: Regulations, Screening & 2026 Compliance Guide
AML in India is the framework of laws and controls that financial firms use to detect and report money laundering and terrorist financing. Built on the Prevention of Money Laundering Act, 2002, it runs through a handful of regulators that include the RBI and SEBI, with the Financial Intelligence Unit sitting in the middle of the reporting chain. For any reporting entity, getting this right is a legal duty. Done properly, it also keeps dirty money off the books.
A quick note on audience. This guide is written for compliance and AML teams, not for individuals. India's economy is growing fast and digital payments are everywhere now, so the risk picture keeps shifting under everyone's feet. New technology arrives. Regulation tightens. Criminals get smarter, and the definition of good AML moves with all three. What follows is the rulebook in plain terms, plus the screening and monitoring controls that turn it into daily practice.
What is AML in India?
AML in India means anti-money laundering. A set of legal obligations stops criminals from passing illegal funds off as clean income. That is the gist. At the core sits the Prevention of Money Laundering Act, 2002, backed by the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. Together they make money laundering a crime and spell out how the state attaches assets, then seizes them, then confiscates the proceeds.
Reporting entities carry the duty. Banks have it. So do NBFCs and payment firms, and now virtual digital asset providers have joined the same list. Every one of them has to verify who its customers really are. Watching how money moves through the accounts it holds is part of the job too. And each one has to report anything that looks off. Anti-Money Laundering is not only about fighting financial crime in isolation. Counter-Financing of Terrorism ties in directly, because the same controls trace both where suspect funds come from and where they end up.
Look at the global scale and you see why it matters so much. Money laundering is estimated at 2% to 5% of world GDP, roughly US$800 billion to US$2 trillion a year, and even that is a conservative figure. Serious crime feeds the activity. Drug trafficking generates proceeds that have to be cleaned, and so does arms dealing. Human trafficking, bribery, embezzlement, and large-scale fraud all lean on laundering to move the money they produce.
Where things stand in 2026
India's crypto sector now sits fully inside the PMLA. On 8 January 2026 the Financial Intelligence Unit (FIU-IND) updated its AML and CFT guidelines for virtual digital asset providers. Today 49 exchanges operate as registered reporting entities, 45 of them domestic and four offshore. Penalties levied for non-compliance have totalled around ₹28 crore.
Registration on the FINGate portal is now mandatory. Any VDA provider serving Indian users has to register, wherever the company itself is based. Operationally, the 2026 guidelines also raised the bar. Live-selfie verification with liveness detection became a requirement. So did geo-tagging of sessions. Penny-drop bank account validation rounds it out, and mixers and anonymity-enhancing tokens are now flatly prohibited.
Step back and there is a bigger backdrop here too. In its June 2024 plenary, the Financial Action Task Force placed India in the "regular follow-up" category, its highest rating, alongside a small group of G20 peers. Real praise came through for India's technical compliance and for the way financial intelligence shows up in investigations. Unfinished work got flagged as well. Two items stood out: fuller coverage of domestic politically exposed persons, and faster completion of money laundering trials.
AML regulators in India
Enforcing AML in India is a shared job. Several authorities each take a slice of the financial system, and keeping current with their guidance is not a nice-to-have. Compliance is a legal requirement. It is also, in equal measure, a way to protect the integrity of how a firm runs day to day.
Reserve Bank of India (RBI)
As the central authority for financial stability, the Reserve Bank of India sets the AML and CFT rules for banks and most financial institutions. Its Master Direction on KYC is the key instrument. Through it, the RBI requires customer identification across every entity it regulates, then layers risk categorisation on top, then mandates ongoing monitoring after that.
Financial Intelligence Unit (FIU-IND)
Sitting at the centre of the reporting framework, the Financial Intelligence Unit of India receives suspicious transaction reports, analyses them, and shares the results with others in the chain. Its job is to turn raw filings into intelligence that law enforcement can actually act on. Those 2026 VDA guidelines came from FIU-IND.
Enforcement Directorate (ED)
Investigating and prosecuting money laundering offences under the PMLA falls to the Enforcement Directorate. As the lead law-enforcement agency, it identifies entities involved in laundering and acts against them. That enforcement muscle is what gives the wider AML regime its teeth.
Securities and Exchange Board of India (SEBI)
SEBI regulates the securities market and issues AML/CFT guidelines for exchanges and intermediaries. Its rules keep securities transactions aligned with AML standards. They also support transparency across the market.
Insurance Regulatory and Development Authority of India (IRDAI)
Insurers fall under the IRDAI, which sets AML/CFT standards for the sector. It requires insurance companies to verify policyholders and to guard against laundering at two points: the moment of sale, and again at claim.
The PMLA and what it requires of reporting entities
Legal backbone of AML in India, the Prevention of Money Laundering Act makes money laundering a crime and obliges reporting entities to run real controls instead of ticking boxes. Sections 11A to 15 carry the core duties. A reporting entity has to verify the identity of clients and beneficial owners. Record-keeping is mandatory. And where the risk runs higher, enhanced due diligence becomes a requirement.
A standard AML programme under the PMLA rests on four elements. There is a customer acceptance policy. There is a customer identification procedure. Risk management sits alongside both, and ongoing monitoring of transactions ties the whole thing together. Records have to be kept for at least five years, so that filings can be reconstructed if an investigation ever calls for them.
Penalties here are serious. A money laundering conviction carries rigorous imprisonment of three to seven years, plus a fine. Lawmakers passed the 2023 amendments to the PMLA just ahead of the FATF evaluation. They widened the net of reporting entities. Politically exposed persons got a sharper definition. And a range of new activities came into scope.
AML screening in India
AML screening is how a reporting entity checks a customer or a transaction against risk, both before onboarding and after. Sitting at the operational heart of KYC and AML screening, it runs in several layers across most programmes. Here is the basic idea. Catch a high-risk party at the gate, then keep watching as the relationship goes on.
Screening tends to break into three jobs. One checks a customer against sanctions lists. Another looks for politically exposed persons and adverse media. Number three tracks transactions over time for the patterns that suggest laundering. Each layer answers a different question. Skip one and you leave a gap a launderer can walk straight through. Done well, name screening in AML produces fewer false positives, which means analysts get to spend their hours on the cases that actually matter rather than chasing noise.
Sanctions screening
Sanctions screening in AML checks customers and counterparties against lists of sanctioned individuals and entities, and against sanctioned jurisdictions too. In India that means the UNSC consolidated lists and the designations issued under the Unlawful Activities (Prevention) Act, plus the major international lists for firms with cross-border exposure. Onboarding is when the sanction screening process runs first. It runs again whenever lists change or a customer's details update, because a clean name today can land on a list tomorrow. A good sanctions screening setup uses fuzzy matching to catch spelling variants and transliterations, which becomes unavoidable once names start crossing scripts and languages.
PEP screening
A politically exposed person holds a prominent public role, and that raises the risk of bribery or corruption. Screening for PEPs identifies these customers and sorts them by risk level. Enhanced due diligence then follows on the higher-risk ones. Regulators are watching this area closely, since the FATF specifically asked India to improve its coverage of domestic PEPs. Effective PEP screening does more than flag a match. It assesses source of funds and source of wealth, and it keeps the classification under review as a person's role shifts over time.
Transaction monitoring
Sanctions and PEP checks catch risk at a single point in time. AML transaction screening, or transaction monitoring, watches behaviour across the whole life of the relationship. Its target is the patterns that point to laundering. Think structuring just under reporting thresholds, or sudden spikes in activity, or round-tripping, or money moving through accounts with no clear purpose behind it. Transaction monitoring generates alerts that analysts review, and the suspicious ones become STRs filed with FIU-IND. Tune the rules to Indian typologies and the noise drops. Genuine red flags then stand out.
AML testing and independent review
AML testing checks whether the controls actually work, instead of just assuming they do. Usually run by internal audit or an outside party, it is the independent review of an AML programme, and under a risk-based regime it ranks as a standard expectation for reporting entities. Expect hands-on work. Testing samples real cases, retests the screening and monitoring logic, and confirms that suspicious transactions got spotted and reported on time.
Out of it comes a clear picture of where the programme is strong and where it leaks. Maybe the sanctions list is out of date. Maybe alert thresholds are so tight that real activity slips through, or so loose that analysts drown in false positives. Regular testing catches these gaps before a regulator does, and it hands the board hard evidence that the AML function is pulling its weight. Treat it as a recurring cycle. A one-off audit tells you almost nothing.
Book an AML Screening Demo to see how screening, monitoring and testing fit together in one workflow.
Choosing AML screening software for India
Any AML screening software worth buying has to handle India's specific reality. Local identity documents such as Aadhaar and PAN have to be supported. Names cross multiple scripts here, and the software needs to cope with that. Sanctions and watchlists relevant to the country have to be covered, and the reporting has to line up with FIU-IND filing formats. A tool built for another market will miss things that matter on the ground here.
A few criteria separate a workable platform from a frustrating one. Match accuracy comes first. A high false-positive rate buries analysts and drags onboarding to a crawl. Coverage of the right lists matters next, domestic designations as much as global sanctions. After that, look at how cleanly the software fits your existing systems. Check whether it produces an audit trail a regulator will accept. And gauge how well it scales as onboarding volume climbs. Neutral comparisons of vendors are fair when you weigh up options, but the real test is always fit against your own risk profile and customer base.
Predictions for AML in India
Direction of travel here is clear, even if the pace varies. A handful of shifts look likely over the next stretch.
Technology keeps moving to the centre. Expect wider use of artificial intelligence and machine learning to sharpen detection and cut false positives, building on the tools the bigger institutions already run today. Data analytics will do more of the early spotting, surfacing laundering patterns before they harden into real losses.
Scope keeps widening too. Already the reporting-entity net has grown to cover crypto providers and a longer list of professional services, and that expansion looks set to continue as fresh risks surface. Cross-border cooperation should deepen as well, with smoother information exchange and joint investigations alongside foreign jurisdictions. Cybersecurity stays high on the list, given how much financial crime now starts online. And the FATF's feedback points to one near-term focus above the rest: closing the gap on domestic PEP coverage, and getting money laundering cases all the way through to a verdict.
How KYC Hub supports AML in India
KYC Hub offers a Digital KYC solution built for India that turns these AML obligations into a working flow. Identity verifications lead the platform. Financial verifications are handled too. Corporate verifications and employee verifications round out the set, alongside a defined list of identification documents the platform can validate. A regulated entity can confirm both the individuals and the businesses behind them, all in one place.
Verification is only half of it. On top, the platform pulls screening and monitoring together. Sanctions and PEP screening run at onboarding and on an ongoing basis after that. Adverse media checks flag reputational risk as it appears. Transaction monitoring watches behaviour over time and raises alerts for analyst review, with an audit trail that holds up to regulatory scrutiny. Accurate, fast onboarding that stays compliant is the goal. Automated checks replace slow manual review, and high-risk cases surface early instead of slipping through unnoticed. All of this works alongside existing systems rather than forcing a rebuild.
If AML in India is a compliance cost you want under control without weakening your defences, the fastest way to judge fit is to watch it run against your own use case. Book an AML Screening Demo and we will walk through the screening and monitoring flow.
Conclusion
AML in India keeps tightening as the economy grows and the rules race to catch up with new risk. Obligations come from the PMLA. A group of regulators enforces them. And the FATF's 2024 verdict shows India is largely on track, with real work still ahead. For reporting entities, the job comes down to a few steady habits. Know the rules. Screen and monitor properly. Test the controls so they hold when it counts. Get that right and AML stops being a drag on onboarding. Then it turns into proof that the business can be trusted.



