← Industry Insights
Compliance Solution

AML Regulations in India: Laws, Regulators, and Compliance Obligations

Updated Jun 2026 · 7 min read
SHAREinXf
AML Regulations in India [AML in India]

AML regulations in India set the legal obligations that financial institutions and other regulated businesses must meet to detect, prevent, and report money laundering. The Prevention of Money Laundering Act, 2002 (PMLA) anchors the framework, backed by its supporting rules and enforced through a mix of sector regulators and a central financial intelligence agency. For compliance teams, the practical takeaway is simple. Customer due diligence, record-keeping, and suspicious transaction reporting are statutory duties, not optional best practices.

This guide walks through what AML regulations in India cover: the primary legislation and its rules, the regulators and authorities involved, the KYC and record-keeping obligations placed on reporting entities, how reporting works, the penalties for non-compliance, and how firms put Indian AML compliance into practice.

What Are AML Regulations in India?

These are the body of law, rules, and regulatory guidance that require reporting entities to identify their customers, monitor transactions, keep records, and report activity that may be linked to money laundering or the financing of crime. The aim is to protect the integrity of the financial system, which means making it harder to hide where illicit funds came from and easier for authorities to follow the trail.

These obligations apply to banks and financial institutions, plus a growing range of other businesses that handle customer money or move transactions along. At the center sits a primary statute, with the detail filled in by specific rules and by sector guidance from individual regulators. What any one firm actually has to do, then, depends on two things: the central law and the regulator that supervises its sector. As India works to keep its financial ecosystem transparent, AML compliance has become a baseline requirement for operating in regulated markets.

The Primary Legislation: PMLA, 2002 and Its Rules

The Prevention of Money Laundering Act, 2002 (PMLA) is the cornerstone of India's anti-money laundering framework. Lawmakers built it to combat the offense of legalizing income or profits obtained illegally, and it gives the government and public authorities the power to attach, seize, and confiscate property derived from the proceeds of crime. The Prevention of Money Laundering Act, 2002 defines the offense of money laundering and sets up the institutional machinery for investigation, adjudication, and appeal.

Over the years, a run of amendments and supporting rules has reinforced the Act, widening its reach and tightening what reporting entities owe:

  • PML (Maintenance of Records) Rules, 2005: Reporting entities must maintain records of transactions, report suspicious transactions to the FIU-IND, and retain customer due diligence records.
  • PML (Amendment) Act, 2009: Broadened the framework and added provisions that let India share information with corresponding foreign law enforcement agencies.
  • PML (Amendment) Act, 2012: Clarified and enhanced provisions across the board. It lowered the threshold for identifying beneficial owners, introduced the concept of politically exposed persons (PEPs), and expanded the set of reporting entities.
  • PML (Amendment) Act, 2015: Pulled Indian AML law closer to international standards, closing gaps and improving transparency.
  • PML (Maintenance of Records) Amendment Rules, 2023: Widened the scope of reporting entities and tightened customer due diligence. It mandates disclosure of beneficial owners and applies stricter customer due diligence norms, with measures reaching virtual digital asset transactions.

Several features sit at the heart of the PMLA. There is defined punishment for money laundering and the power to seize and attach tainted property. An Adjudicating Authority decides whether property is involved in money laundering, an Appellate Tribunal hears appeals, and Special Courts try the offenses themselves.

The Regulators and Authorities

India does not rely on a single AML regulator. Instead, enforcement and supervision are spread across sector regulators and a central intelligence agency, each with a defined role.

The Reserve Bank of India (RBI) issues Know Your Customer and AML guidelines for banks and financial institutions. They require due diligence procedures, customer profiling, and transaction monitoring so banks can spot and head off suspicious activity.

Securities fall to the Securities and Exchange Board of India (SEBI), which sets KYC standards and guidelines for financial intermediaries and investors. Customer verification and due diligence keep the securities sector secure.

For insurers, the Insurance Regulatory and Development Authority of India (IRDAI) issues AML requirements that feed the broader effort to stop insurance products from being misused for financial crime.

Then there is the Financial Intelligence Unit – India (FIU-IND), the central national agency that receives, processes, analyzes, and disseminates information about suspicious financial transactions. Sitting under the Department of Revenue in the Ministry of Finance, it passes financial intelligence to law enforcement at home and to counterparts abroad. Enforcement is a separate job. The Enforcement Directorate (ED) investigates the offense of money laundering under the PMLA and handles actions against offenders and the attachment of proceeds of crime.

KYC, CDD, and Record-Keeping Obligations

Customer due diligence and record-keeping sit at the operational core of AML regulations in India. Reporting entities must verify the identity of their customers before opening a relationship, understand the nature of the customer's business, and identify the beneficial owners behind legal entities. Higher-risk customers, including politically exposed persons, trigger enhanced due diligence.

Under the PML (Maintenance of Records) Rules, reporting entities have to maintain records of transactions and of the documents collected during customer identification and verification. Those records must stay available to authorities for investigation. Monitoring matters too. Identifying a customer once at onboarding is not enough; firms have to keep customer information current and watch transaction patterns over the life of the relationship. The 2023 amendment rules sharpened the beneficial ownership and CDD expectations, raising the bar for how thoroughly reporting entities must look behind their customers.

Book an India KYC Demo

Reporting Entities and STR/CTR Reporting

A reporting entity is any business the PMLA and its rules bring within scope, and that category has widened over successive amendments. Banks, financial institutions, and intermediaries in the securities and insurance sectors all qualify. Later rule changes extended the net to a broader range of businesses and professionals.

Every reporting entity carries a statutory duty to file reports with the FIU-IND. Two report types dominate. The Suspicious Transaction Report (STR) goes in when a transaction or attempted transaction gives rise to a reasonable suspicion that it may involve the proceeds of crime. The Cash Transaction Report (CTR) covers cash transactions above the prescribed threshold. The FIU-IND analyzes both and passes intelligence to enforcement agencies. Suspicious activity can surface at any point in a relationship, so effective AML screening and transaction monitoring is what lets a reporting entity catch reportable activity in the first place.

Penalties for Non-Compliance

The PMLA defines the offense of money laundering and the consequences for committing it. The Act punishes money laundering with imprisonment together with a fine, and it provides for enhanced terms in connection with certain serious predicate offenses such as drug-related crimes. Sections 3 and 4 of the PMLA set out the specific imprisonment and fine ranges.

Imprisonment and fines are only part of the picture. The Act also lets authorities attach, seize, and confiscate property that represents the proceeds of crime, and it provides for forfeiture of those assets. For regulated firms, the exposure runs past the criminal liability of individuals. Miss your AML obligations and the business itself faces regulatory and supervisory consequences from its sector regulator. Criminal penalties, asset confiscation, and regulatory action together are what push AML compliance into the boardroom rather than leaving it a purely operational matter.

How Firms Operationalize Indian AML Compliance

In practice, meeting these obligations comes down to building a compliance program that translates the law into controls you can run again and again. In most cases that means a documented AML policy, risk-based customer due diligence at onboarding, ongoing transaction monitoring, a clear process for identifying and filing STRs and CTRs, disciplined record-keeping, staff training, and independent testing of the program. The risk-based approach is what does the heavy lifting. Put your resources where money laundering risk runs highest: higher-risk customers, products, and geographies.

None of this scales without technology. Manual identity checks and spreadsheet-based monitoring give way under the volume and speed of modern transactions, and they turn consistent record-keeping into a slog. Automated KYC and AML tooling helps firms apply controls uniformly, keep audit-ready records, and surface suspicious activity for review. It also helps to read the regulatory framework next to related obligations, because AML compliance in India is really one part of a wider set of financial crime controls.

KYC Hub for India AML Compliance

KYC Hub provides India-specific KYC and AML capabilities built around four verification pillars that map to how reporting entities actually onboard and monitor customers:

  • Identity verification: Confirm who a customer is using document checks and digital identity verification, including Aadhaar OKYC for India-based onboarding.
  • Financial verification: Validate financial details to support risk assessment and due diligence.
  • Corporate verification: Look behind legal entities to identify beneficial owners and corporate structures, which supports the beneficial ownership requirements under Indian AML rules.
  • Employee verification: Run checks that support internal risk and due diligence needs.

The pillars do not stand alone. KYC Hub also runs AML screening and ongoing monitoring against sanctions lists, watchlists, and PEP data, so reporting entities can flag higher-risk customers and catch activity that may need to be reported to the FIU-IND. Because it is built for the Indian regulatory environment, the India KYC solution hands compliance teams one workflow for identity, due diligence, and monitoring instead of a patchwork of disconnected tools.

Book an India KYC Demo

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

What are the AML regulations in India?

AML regulations in India are the laws, rules, and regulatory guidance that require financial institutions and other reporting entities to detect and prevent money laundering. The Prevention of Money Laundering Act, 2002 (PMLA) and its supporting rules anchor the framework, imposing duties around customer due diligence, record-keeping, and suspicious transaction reporting. Sector regulators such as the RBI, SEBI, and IRDAI add further requirements for the firms they supervise.

What is the PMLA?

The PMLA is the Prevention of Money Laundering Act, 2002, India's principal anti-money laundering statute. It defines the offense of money laundering, sets out penalties, and gives authorities the power to attach, seize, and confiscate property that represents the proceeds of crime. The Act also stands up the institutional machinery behind enforcement: the Adjudicating Authority, the Appellate Tribunal, and Special Courts.

Who regulates AML in India?

AML in India is regulated by several bodies, not a single one. The Reserve Bank of India (RBI), the Securities and Exchange Board of India (SEBI), and the Insurance Regulatory and Development Authority of India (IRDAI) issue AML and KYC requirements for their sectors. The Financial Intelligence Unit – India (FIU-IND) receives and analyzes suspicious transaction information, while the Enforcement Directorate (ED) investigates money laundering offenses under the PMLA.

What are the KYC requirements under Indian AML law?

Under Indian AML law, reporting entities must verify the identity of their customers, identify the beneficial owners behind legal entities, and apply enhanced due diligence to higher-risk customers such as politically exposed persons. They also have to keep records of customer identification and transactions and monitor the relationship on an ongoing basis. The PML (Maintenance of Records) Rules and the 2023 amendment rules spell out these obligations in detail.

What is STR and CTR reporting in India?

A Suspicious Transaction Report (STR) goes to the FIU-IND when a transaction gives rise to a reasonable suspicion that it may involve the proceeds of crime, attempted transactions included. A Cash Transaction Report (CTR) covers cash transactions above the prescribed threshold. Reporting entities carry a statutory duty to file both, which lets the FIU-IND analyze them and share intelligence with enforcement agencies.

What are the penalties for AML non-compliance in India?

Money laundering under the PMLA is punishable by imprisonment together with a fine, with the relevant terms set out in Sections 3 and 4 of the Act and enhanced penalties available for certain serious predicate offenses. Authorities can also attach, seize, and confiscate property that represents the proceeds of crime. For regulated firms, missing AML obligations can trigger regulatory and supervisory action from the relevant sector regulator on top of that.

[ KYC HUB ]

Screen and monitor for financial crime in real time

Sanctions, PEP and adverse-media screening with ongoing transaction monitoring and case management.

Explore the AML screening & monitoringBook a demo
[ RELATED READING ]
How Anti-Money Laundering Software Works: Your guide in 2026
[ Compliance Solution ]

Anti Money Laundering Tool: How It Works in 2026

An anti money laundering tool screens customers, watches their transactions, and reports what looks suspicious. Here is how the technology really works in 2026 and how to choose it.

Apr 2026 · 21 min read
AI in Transaction Monitoring by 2026: What Will Actually Work
[ Transaction Monitoring ]

AI in Transaction Monitoring by 2026: What Will Actually Work

Learn how AI in transaction monitoring by 2026 enables real-time detection, adaptive risk scoring, and next-gen AML compliance.

Jan 2026 · 14 min read
Top Revolutionary AML Trends Shaping Compliance in 2026
[ Compliance Solution ]

AML Trends in 2026: What Compliance Teams Need to Know

A practical guide to the AML trends shaping compliance programs in 2026, from AI-driven detection and risk-based strategy to crypto, sanctions, and trade-based laundering risk.

Dec 2025 · 6 min read