← Industry Insights
Compliance Solution

AML in India: Regulations, Screening & 2026 Compliance Guide

Updated Jun 2026 · 10 min read
SHAREinXf
AML in India: Top 10 Predictions for 2025

AML in India is the framework of laws and controls that financial firms use to detect and report money laundering and terrorist financing. Built on the Prevention of Money Laundering Act, 2002, it runs through a handful of regulators that include the RBI and SEBI, with the Financial Intelligence Unit sitting in the middle of the reporting chain. For any reporting entity, getting this right is a legal duty. Done properly, it also keeps dirty money off the books.

A quick note on audience. This guide is written for compliance and AML teams, not for individuals. India's economy is growing fast and digital payments are everywhere now, so the risk picture keeps shifting under everyone's feet. New technology arrives. Regulation tightens. Criminals get smarter, and the definition of good AML moves with all three. What follows is the rulebook in plain terms, plus the screening and monitoring controls that turn it into daily practice.

What is AML in India?

AML in India means anti-money laundering. A set of legal obligations stops criminals from passing illegal funds off as clean income. That is the gist. At the core sits the Prevention of Money Laundering Act, 2002, backed by the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. Together they make money laundering a crime and spell out how the state attaches assets, then seizes them, then confiscates the proceeds.

Reporting entities carry the duty. Banks have it. So do NBFCs and payment firms, and now virtual digital asset providers have joined the same list. Every one of them has to verify who its customers really are. Watching how money moves through the accounts it holds is part of the job too. And each one has to report anything that looks off. Anti-Money Laundering is not only about fighting financial crime in isolation. Counter-Financing of Terrorism ties in directly, because the same controls trace both where suspect funds come from and where they end up.

Look at the global scale and you see why it matters so much. Money laundering is estimated at 2% to 5% of world GDP, roughly US$800 billion to US$2 trillion a year, and even that is a conservative figure. Serious crime feeds the activity. Drug trafficking generates proceeds that have to be cleaned, and so does arms dealing. Human trafficking, bribery, embezzlement, and large-scale fraud all lean on laundering to move the money they produce.

Where things stand in 2026

India's crypto sector now sits fully inside the PMLA. On 8 January 2026 the Financial Intelligence Unit (FIU-IND) updated its AML and CFT guidelines for virtual digital asset providers. Today 49 exchanges operate as registered reporting entities, 45 of them domestic and four offshore. Penalties levied for non-compliance have totalled around ₹28 crore.

Registration on the FINGate portal is now mandatory. Any VDA provider serving Indian users has to register, wherever the company itself is based. Operationally, the 2026 guidelines also raised the bar. Live-selfie verification with liveness detection became a requirement. So did geo-tagging of sessions. Penny-drop bank account validation rounds it out, and mixers and anonymity-enhancing tokens are now flatly prohibited.

Step back and there is a bigger backdrop here too. In its June 2024 plenary, the Financial Action Task Force placed India in the "regular follow-up" category, its highest rating, alongside a small group of G20 peers. Real praise came through for India's technical compliance and for the way financial intelligence shows up in investigations. Unfinished work got flagged as well. Two items stood out: fuller coverage of domestic politically exposed persons, and faster completion of money laundering trials.

AML regulators in India

Enforcing AML in India is a shared job. Several authorities each take a slice of the financial system, and keeping current with their guidance is not a nice-to-have. Compliance is a legal requirement. It is also, in equal measure, a way to protect the integrity of how a firm runs day to day.

Reserve Bank of India (RBI)

As the central authority for financial stability, the Reserve Bank of India sets the AML and CFT rules for banks and most financial institutions. Its Master Direction on KYC is the key instrument. Through it, the RBI requires customer identification across every entity it regulates, then layers risk categorisation on top, then mandates ongoing monitoring after that.

Financial Intelligence Unit (FIU-IND)

Sitting at the centre of the reporting framework, the Financial Intelligence Unit of India receives suspicious transaction reports, analyses them, and shares the results with others in the chain. Its job is to turn raw filings into intelligence that law enforcement can actually act on. Those 2026 VDA guidelines came from FIU-IND.

Enforcement Directorate (ED)

Investigating and prosecuting money laundering offences under the PMLA falls to the Enforcement Directorate. As the lead law-enforcement agency, it identifies entities involved in laundering and acts against them. That enforcement muscle is what gives the wider AML regime its teeth.

Securities and Exchange Board of India (SEBI)

SEBI regulates the securities market and issues AML/CFT guidelines for exchanges and intermediaries. Its rules keep securities transactions aligned with AML standards. They also support transparency across the market.

Insurance Regulatory and Development Authority of India (IRDAI)

Insurers fall under the IRDAI, which sets AML/CFT standards for the sector. It requires insurance companies to verify policyholders and to guard against laundering at two points: the moment of sale, and again at claim.

The PMLA and what it requires of reporting entities

Legal backbone of AML in India, the Prevention of Money Laundering Act makes money laundering a crime and obliges reporting entities to run real controls instead of ticking boxes. Sections 11A to 15 carry the core duties. A reporting entity has to verify the identity of clients and beneficial owners. Record-keeping is mandatory. And where the risk runs higher, enhanced due diligence becomes a requirement.

A standard AML programme under the PMLA rests on four elements. There is a customer acceptance policy. There is a customer identification procedure. Risk management sits alongside both, and ongoing monitoring of transactions ties the whole thing together. Records have to be kept for at least five years, so that filings can be reconstructed if an investigation ever calls for them.

Penalties here are serious. A money laundering conviction carries rigorous imprisonment of three to seven years, plus a fine. Lawmakers passed the 2023 amendments to the PMLA just ahead of the FATF evaluation. They widened the net of reporting entities. Politically exposed persons got a sharper definition. And a range of new activities came into scope.

AML screening in India

AML screening is how a reporting entity checks a customer or a transaction against risk, both before onboarding and after. Sitting at the operational heart of KYC and AML screening, it runs in several layers across most programmes. Here is the basic idea. Catch a high-risk party at the gate, then keep watching as the relationship goes on.

Screening tends to break into three jobs. One checks a customer against sanctions lists. Another looks for politically exposed persons and adverse media. Number three tracks transactions over time for the patterns that suggest laundering. Each layer answers a different question. Skip one and you leave a gap a launderer can walk straight through. Done well, name screening in AML produces fewer false positives, which means analysts get to spend their hours on the cases that actually matter rather than chasing noise.

Sanctions screening

Sanctions screening in AML checks customers and counterparties against lists of sanctioned individuals and entities, and against sanctioned jurisdictions too. In India that means the UNSC consolidated lists and the designations issued under the Unlawful Activities (Prevention) Act, plus the major international lists for firms with cross-border exposure. Onboarding is when the sanction screening process runs first. It runs again whenever lists change or a customer's details update, because a clean name today can land on a list tomorrow. A good sanctions screening setup uses fuzzy matching to catch spelling variants and transliterations, which becomes unavoidable once names start crossing scripts and languages.

PEP screening

A politically exposed person holds a prominent public role, and that raises the risk of bribery or corruption. Screening for PEPs identifies these customers and sorts them by risk level. Enhanced due diligence then follows on the higher-risk ones. Regulators are watching this area closely, since the FATF specifically asked India to improve its coverage of domestic PEPs. Effective PEP screening does more than flag a match. It assesses source of funds and source of wealth, and it keeps the classification under review as a person's role shifts over time.

Transaction monitoring

Sanctions and PEP checks catch risk at a single point in time. AML transaction screening, or transaction monitoring, watches behaviour across the whole life of the relationship. Its target is the patterns that point to laundering. Think structuring just under reporting thresholds, or sudden spikes in activity, or round-tripping, or money moving through accounts with no clear purpose behind it. Transaction monitoring generates alerts that analysts review, and the suspicious ones become STRs filed with FIU-IND. Tune the rules to Indian typologies and the noise drops. Genuine red flags then stand out.

AML testing and independent review

AML testing checks whether the controls actually work, instead of just assuming they do. Usually run by internal audit or an outside party, it is the independent review of an AML programme, and under a risk-based regime it ranks as a standard expectation for reporting entities. Expect hands-on work. Testing samples real cases, retests the screening and monitoring logic, and confirms that suspicious transactions got spotted and reported on time.

Out of it comes a clear picture of where the programme is strong and where it leaks. Maybe the sanctions list is out of date. Maybe alert thresholds are so tight that real activity slips through, or so loose that analysts drown in false positives. Regular testing catches these gaps before a regulator does, and it hands the board hard evidence that the AML function is pulling its weight. Treat it as a recurring cycle. A one-off audit tells you almost nothing.

Book an AML Screening Demo to see how screening, monitoring and testing fit together in one workflow.

Choosing AML screening software for India

Any AML screening software worth buying has to handle India's specific reality. Local identity documents such as Aadhaar and PAN have to be supported. Names cross multiple scripts here, and the software needs to cope with that. Sanctions and watchlists relevant to the country have to be covered, and the reporting has to line up with FIU-IND filing formats. A tool built for another market will miss things that matter on the ground here.

A few criteria separate a workable platform from a frustrating one. Match accuracy comes first. A high false-positive rate buries analysts and drags onboarding to a crawl. Coverage of the right lists matters next, domestic designations as much as global sanctions. After that, look at how cleanly the software fits your existing systems. Check whether it produces an audit trail a regulator will accept. And gauge how well it scales as onboarding volume climbs. Neutral comparisons of vendors are fair when you weigh up options, but the real test is always fit against your own risk profile and customer base.

Predictions for AML in India

Direction of travel here is clear, even if the pace varies. A handful of shifts look likely over the next stretch.

Technology keeps moving to the centre. Expect wider use of artificial intelligence and machine learning to sharpen detection and cut false positives, building on the tools the bigger institutions already run today. Data analytics will do more of the early spotting, surfacing laundering patterns before they harden into real losses.

Scope keeps widening too. Already the reporting-entity net has grown to cover crypto providers and a longer list of professional services, and that expansion looks set to continue as fresh risks surface. Cross-border cooperation should deepen as well, with smoother information exchange and joint investigations alongside foreign jurisdictions. Cybersecurity stays high on the list, given how much financial crime now starts online. And the FATF's feedback points to one near-term focus above the rest: closing the gap on domestic PEP coverage, and getting money laundering cases all the way through to a verdict.

How KYC Hub supports AML in India

KYC Hub offers a Digital KYC solution built for India that turns these AML obligations into a working flow. Identity verifications lead the platform. Financial verifications are handled too. Corporate verifications and employee verifications round out the set, alongside a defined list of identification documents the platform can validate. A regulated entity can confirm both the individuals and the businesses behind them, all in one place.

Verification is only half of it. On top, the platform pulls screening and monitoring together. Sanctions and PEP screening run at onboarding and on an ongoing basis after that. Adverse media checks flag reputational risk as it appears. Transaction monitoring watches behaviour over time and raises alerts for analyst review, with an audit trail that holds up to regulatory scrutiny. Accurate, fast onboarding that stays compliant is the goal. Automated checks replace slow manual review, and high-risk cases surface early instead of slipping through unnoticed. All of this works alongside existing systems rather than forcing a rebuild.

If AML in India is a compliance cost you want under control without weakening your defences, the fastest way to judge fit is to watch it run against your own use case. Book an AML Screening Demo and we will walk through the screening and monitoring flow.

Conclusion

AML in India keeps tightening as the economy grows and the rules race to catch up with new risk. Obligations come from the PMLA. A group of regulators enforces them. And the FATF's 2024 verdict shows India is largely on track, with real work still ahead. For reporting entities, the job comes down to a few steady habits. Know the rules. Screen and monitor properly. Test the controls so they hold when it counts. Get that right and AML stops being a drag on onboarding. Then it turns into proof that the business can be trusted.

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

What is AML screening?

AML screening is the process of checking a customer or transaction against risk indicators to detect money laundering. It typically covers three layers: sanctions screening against watchlists, PEP and adverse media screening, and transaction monitoring over the life of the relationship. Reporting entities run it at onboarding and on an ongoing basis to meet PMLA obligations.

What is sanctions screening in AML?

Sanctions screening in AML is the check that compares customers and counterparties against lists of sanctioned individuals, entities and countries. In India this includes the UNSC consolidated lists and designations under the Unlawful Activities (Prevention) Act, plus major international lists for firms with cross-border activity. It runs at onboarding and again whenever lists or customer details change.

What is AML sanctions screening in KYC?

Within a KYC process, sanctions screening is the step that confirms a customer is not on any applicable sanctions or watchlist before the account is approved. It sits alongside identity verification and PEP screening as part of customer due diligence, and it repeats periodically because sanctions designations change over time.

When is AML screening required?

AML screening is required at customer onboarding, before a reporting entity opens an account or provides a service. It is also required on an ongoing basis: sanctions and PEP checks repeat when lists or customer details change, and transaction monitoring runs continuously throughout the relationship. The PMLA and RBI rules make these checks mandatory for reporting entities.

What is AML testing?

AML testing is the independent review of an anti-money laundering programme to confirm the controls actually work. It is usually carried out by internal audit or an external party, and it samples real cases, retests screening and monitoring logic, and checks that suspicious transactions were reported on time. It is a recurring exercise that surfaces gaps before a regulator does.

Who controls AML in India?

AML in India is overseen by several regulatory bodies. The Reserve Bank of India sets the rules for banks and financial institutions, while the Financial Intelligence Unit receives and analyses suspicious transaction reports. The Enforcement Directorate investigates and prosecutes offences under the PMLA, and SEBI and the IRDAI cover the securities and insurance sectors respectively.

Does India have AML CFT laws in place?

Yes. India has a developed AML and CFT framework built on the Prevention of Money Laundering Act, 2002 and the rules issued under it. These laws criminalise money laundering and terrorist financing and are enforced by regulators including the RBI, FIU-IND, SEBI, the ED and the IRDAI. In 2024 the FATF placed India in its highest "regular follow-up" category.

Who issues AML guidelines in India?

AML guidelines in India come from the relevant sector regulators. The RBI issues them for banking institutions, the FIU-IND for reporting and suspicious transaction filing, SEBI for securities market participants, and the IRDAI for insurers. The Enforcement Directorate handles investigation and prosecution under the PMLA. Compliance with this guidance is mandatory for reporting entities.

[ KYC HUB ]

Screen and monitor for financial crime in real time

Sanctions, PEP and adverse-media screening with ongoing transaction monitoring and case management.

Explore the AML screening & monitoringBook a demo
[ RELATED READING ]
How Anti-Money Laundering Software Works: Your guide in 2026
[ Compliance Solution ]

Anti Money Laundering Tool: How It Works in 2026

An anti money laundering tool screens customers, watches their transactions, and reports what looks suspicious. Here is how the technology really works in 2026 and how to choose it.

Apr 2026 · 21 min read
AI in Transaction Monitoring by 2026: What Will Actually Work
[ Transaction Monitoring ]

AI in Transaction Monitoring by 2026: What Will Actually Work

Learn how AI in transaction monitoring by 2026 enables real-time detection, adaptive risk scoring, and next-gen AML compliance.

Jan 2026 · 14 min read
Top Revolutionary AML Trends Shaping Compliance in 2026
[ Compliance Solution ]

AML Trends in 2026: What Compliance Teams Need to Know

A practical guide to the AML trends shaping compliance programs in 2026, from AI-driven detection and risk-based strategy to crypto, sanctions, and trade-based laundering risk.

Dec 2025 · 6 min read