India KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in India.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 38 implementation checks
Last reviewed: 22 September 2026 · Version 1.0
Download the checklistDirect answer
What does the India compliance checklist cover?
The India checklist translates primary KYC, KYB and AML rules into 11 control areas and 38 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Financial Intelligence Unit - India (FIU-IND)
- Primary AML rules
- PMLA 2002 and PML (Maintenance of Records) Rules 2005, as amended
- STR timing
- Promptly and no later than seven working days after satisfaction that a transaction is suspicious
- Monthly reports
- Applicable prescribed reports by the 15th day of the succeeding month
- AML retention
- Five years from transaction or relationship-end trigger, according to record type
- RBI BO tests
- More than 10% for companies and trusts; more than 15% for unincorporated associations, plus control/fallback rules
- Privacy transition
- DPDP Act and Rules 2025 commence in phases; map each operative provision before relying on it
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
India compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify the entity, activity and supervisor before relying on any sector control.4 items+
Determine whether each activity is within the PMLA reporting-entity perimeter.
- Implementation action
- Map banking, financial, securities, gaming, property, precious-metals, professional, trust-and-company-service and virtual-digital-asset activities to the current statutory definition and notification.
- Evidence to retain
- Entity chart, activity inventory, statutory analysis, notification register and counsel sign-off.
- Primary citation
- PMLA, sections 2(1)(sa), 2(1)(wa), 11A and 12; applicable Central Government notifications
Identify the competent supervisor and permission for every regulated service.
- Implementation action
- Confirm whether RBI, SEBI, IRDAI, FIU-IND or another authority licenses, registers or supervises the activity before launch or material change.
- Evidence to retain
- Perimeter memorandum, licence or registration, conditions, regulator correspondence and renewal calendar.
- Primary citation
- PML Rules, rule 9(14); applicable sector law and supervisory direction
Register with FIU-IND where the reporting regime requires it.
- Implementation action
- Complete the current FINnet/FINGate registration, appoint the required Designated Director and Principal Officer, and keep contact and entity information current.
- Evidence to retain
- Registration acknowledgement, appointments, portal access record and change log.
- Primary citation
- PML Rules, rules 7 and 9; FIU-IND registration materials
Treat notified VDA services as reporting-entity activity.
- Implementation action
- For exchange, transfer, custody or issuer-related VDA services carried on for another person in the course of business, assess the 7 March 2023 notification and current FIU-IND registration and AML/CFT guidance, including offshore service into India.
- Evidence to retain
- Service and geography map, VDA analysis, registration, control gap assessment and ongoing compliance record.
- Primary citation
- Ministry of Finance notification dated 7 March 2023; FIU-IND VDA guidelines updated 8 January 2026
02Governance and risk assessmentControls must be entity-specific, risk-based, approved and independently tested.3 items+
Maintain a documented ML, TF and PF risk assessment.
- Implementation action
- Assess customer, geography, product, service, transaction, delivery-channel and technology risks and update the assessment after material change.
- Evidence to retain
- Methodology, current assessment, data sources, approvals, residual-risk decisions and remediation plan.
- Primary citation
- PML Rules, rule 9; RBI KYC Direction, sections 4 and 5; FATF India MER 2024, Recommendations 1 and 15
Assign accountable AML leadership.
- Implementation action
- Appoint a Designated Director and Principal Officer with documented authority, resources, independence and escalation to senior management or the board.
- Evidence to retain
- Appointments, notifications, role descriptions, reporting lines and committee minutes.
- Primary citation
- PML Rules, rules 2(1)(ba), 2(1)(f) and 7
Approve and independently test the AML programme.
- Implementation action
- Maintain policies for CDD, monitoring, reporting, sanctions, records, employee screening, training, group controls and quality assurance; independently test design and operation.
- Evidence to retain
- Policy suite, approval, training, audit plan, samples, findings and verified closure.
- Primary citation
- PML Rules, rule 9; RBI KYC Direction, Chapters II and X
03Natural-person identificationCDD applies at relationship, occasional-transaction, suspicion and doubt triggers under the governing sector rule.4 items+
Configure CDD triggers from the applicable sector instrument.
- Implementation action
- Map account or relationship opening, occasional transactions, international money transfer, suspicion and doubt about previous identification; aggregate linked transactions where the rule requires it.
- Evidence to retain
- Trigger matrix, sector-rule version, aggregation tests, timestamps and exception log.
- Primary citation
- PML Rules, rule 9; RBI KYC Direction, sections 14 and 23
Identify and verify each natural-person customer.
- Implementation action
- Obtain prescribed identity and address information and verify it through permitted official documents, digital KYC, CKYCR records, Aadhaar routes or other reliable independent means applicable to the entity.
- Evidence to retain
- Customer record, verification source, authentication or retrieval result, timestamp and discrepancy resolution.
- Primary citation
- PMLA, section 11A; PML Rules, rule 9; RBI KYC Direction, sections 16 and 18
Verify representatives and authority.
- Implementation action
- Identify the person acting for a customer, verify identity and confirm documentary authority before allowing instructions or access.
- Evidence to retain
- Representative KYC, mandate, verification result, scope limits and activity log.
- Primary citation
- PML Rules, rule 9; RBI KYC Direction, section 14
Stop onboarding or restrict activity when required CDD cannot be completed.
- Implementation action
- Do not open or continue an account or execute the transaction where the applicable rule prohibits it; assess an STR without tipping off the customer.
- Evidence to retain
- CDD gap, restriction or exit, approval, suspicion assessment and filing receipt where applicable.
- Primary citation
- PML Rules, rule 9; RBI KYC Direction, sections 39 and 41
04KYB, registries, and beneficial ownershipVerify legal existence, authorised persons, ownership and control; keep AML tests separate from company filings.4 items+
Verify legal-person existence, purpose and authority.
- Implementation action
- Obtain current incorporation, registered-office, tax, constitutional, director or partner and authorisation information from reliable sources such as the MCA registry and applicable regulator.
- Evidence to retain
- Registry extract, constitutional documents, PAN, licence, officer list, mandates and discrepancy log.
- Primary citation
- PML Rules, rule 9; RBI KYC Direction, sections 27-30
Identify the natural-person AML beneficial owner using the applicable cascade.
- Implementation action
- For RBI-regulated entities apply the current ownership thresholds, then control by other means, and the senior-managing-official fallback only where no natural person is identified; apply sector-specific exemptions carefully.
- Evidence to retain
- Layered ownership chart, percentage calculations, control analysis, verified identities, exemption and fallback rationale.
- Primary citation
- PML Rules, rule 9(3); RBI KYC Direction, section 33
Apply trust and legal-arrangement party identification.
- Implementation action
- Identify the author or settlor, trustees, beneficiaries meeting the applicable threshold and any other natural person exercising ultimate effective control.
- Evidence to retain
- Trust deed, party schedule, ownership or entitlement calculations, authority records and verified identities.
- Primary citation
- PML Rules, rule 9(3); RBI KYC Direction, section 33
Maintain company significant-beneficial-owner compliance separately.
- Implementation action
- Assess Companies Act section 90 and the current Significant Beneficial Owners Rules, obtain BEN-1 declarations, maintain BEN-3 and file BEN-2 within the applicable time; do not substitute this registry test for AML CDD.
- Evidence to retain
- SBO analysis, notices, declarations, register, filings and change log.
- Primary citation
- Companies Act 2013, section 90; Companies (Significant Beneficial Owners) Rules 2018, as amended
05PEPs, enhanced due diligence, and remote onboardingHigher-risk and non-face-to-face relationships require stronger measures under the applicable sector rule.3 items+
Identify politically exposed customers and beneficial owners.
- Implementation action
- Use declarations and reliable sources to identify covered foreign PEPs and related family or close-associate relationships; assess domestic prominent public functions under the entity's risk framework and sector rules.
- Evidence to retain
- Screening result, declaration, relationship map, source, rationale and refresh history.
- Primary citation
- RBI KYC Direction, section 35; FATF India MER 2024, Recommendation 12
Apply enhanced measures to higher-risk relationships.
- Implementation action
- Obtain required senior approval, establish source of funds and source of wealth where applicable, corroborate purpose and increase the degree and frequency of monitoring.
- Evidence to retain
- Risk decision, approval, source corroboration, enhanced monitoring plan and reviews.
- Primary citation
- PML Rules, rule 9; RBI KYC Direction, sections 34-37
Use permitted remote-onboarding methods and control impersonation risk.
- Implementation action
- Select a permitted V-CIP, digital KYC or equivalent route; verify liveness, location, audit trail, consent and document authenticity and retain the prescribed record.
- Evidence to retain
- Method decision, session record, liveness and location results, document checks, consent and QA review.
- Primary citation
- RBI KYC Direction, sections 18 and Annex I
06Monitoring and suspicious reportingMonitor against expected activity and report suspicion to FIU-IND within the statutory clock.4 items+
Monitor transactions and keep customer information current.
- Implementation action
- Scrutinise transactions for consistency with customer profile, business, risk and source of funds and refresh records at the risk-based frequency required by the supervisor.
- Evidence to retain
- Monitoring scenarios, alerts, case analysis, refresh schedule and dispositions.
- Primary citation
- PMLA, section 12; PML Rules, rule 9; RBI KYC Direction, sections 38 and 39
Report suspicious transactions promptly.
- Implementation action
- Once the Principal Officer is satisfied that a transaction or attempted transaction is suspicious, file the STR with FIU-IND promptly and no later than seven working days; do not wait for proof or a threshold.
- Evidence to retain
- Suspicion chronology, decision, STR, FINGate acknowledgement and supplemental responses.
- Primary citation
- PML Rules, rules 3(1)(D), 7 and 8; FIU-IND FAQs
Preserve confidentiality and prevent tipping off.
- Implementation action
- Restrict knowledge of an STR, FIU request or related analysis and do not disclose information that would prejudice reporting or investigation, except where lawfully authorised.
- Evidence to retain
- Need-to-know matrix, access logs, communication controls, training and incident register.
- Primary citation
- PMLA, sections 12 and 14; PML Rules, rule 7
Respond to FIU-IND and competent-authority requests through controlled channels.
- Implementation action
- Authenticate the request, preserve relevant records, produce complete information promptly and log disclosure while maintaining report confidentiality.
- Evidence to retain
- Request register, validation, production index, secure delivery and acknowledgement.
- Primary citation
- PMLA, sections 12 and 13; PML Rules, rule 7
07Threshold reports, payments, and transfersThreshold reporting and transfer controls are report- and sector-specific.3 items+
File applicable monthly transaction reports by the statutory deadline.
- Implementation action
- Determine whether CTR, connected cash, NPO receipt, counterfeit-currency or cross-border wire reporting applies and submit the prescribed report by the 15th day of the succeeding month.
- Evidence to retain
- Report-scope matrix, aggregation tests, source data, validation output, submission and acknowledgement.
- Primary citation
- PML Rules, rules 3 and 8; FIU-IND FAQs and Reporting Format Guide
Do not generalise one monetary threshold across all controls.
- Implementation action
- Apply each amount, currency, aggregation period, product scope and exemption only to the specific report or sector rule that creates it.
- Evidence to retain
- Threshold inventory, legal source, rule version, test cases and exception approvals.
- Primary citation
- PML Rules, rule 3; applicable sector direction
Carry required originator and beneficiary information through transfers.
- Implementation action
- Collect, validate, retain and transmit prescribed payer and payee data; repair, reject or restrict transfers with missing information as required by the applicable payment rule.
- Evidence to retain
- Field matrix, message samples, validation rules, repair queue and rejection record.
- Primary citation
- RBI KYC Direction, wire-transfer provisions; FATF India MER 2024, Recommendation 16
08Targeted financial sanctionsUse current UN and Indian designation mechanisms and verified sector procedures.3 items+
Screen relevant parties and transactions against current designations.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, during the relationship and whenever applicable UN or Indian lists change.
- Evidence to retain
- List inventory, update logs, screening configuration, tests, match analysis and dispositions.
- Primary citation
- UAPA, section 51A; Government procedure order dated 2 February 2021 as corrected; RBI KYC Direction, section 52
Freeze covered assets without delay on a confirmed designation.
- Implementation action
- Follow the current section 51A procedure to prevent dealing in covered funds or assets, report through the competent route and release only under verified authority.
- Evidence to retain
- Match analysis, freeze timestamp, ownership-control analysis, report, system blocks and authority correspondence.
- Primary citation
- UAPA, section 51A; Government procedure order dated 2 February 2021 as corrected
Document proliferation-financing sanctions coverage.
- Implementation action
- Map applicable UN proliferation designations, domestic implementation orders and sector instructions and test ownership, control and indirect-availability scenarios.
- Evidence to retain
- Legal map, list update record, screening tests, escalation procedure and training.
- Primary citation
- Weapons of Mass Destruction and their Delivery Systems Act 2005, section 12A; FATF India MER 2024, Recommendation 7
09Records and regulator accessRecords must reconstruct transactions and remain available for the correct five-year period.3 items+
Retain transaction records for five years from the transaction date.
- Implementation action
- Preserve information sufficient to reconstruct individual transactions, including parties, nature, amount, currency, date and channel, subject to any longer lawful hold.
- Evidence to retain
- Retention schedule, archive sample, reconstruction test, legal holds and deletion approvals.
- Primary citation
- PMLA, section 12(1)(a) and 12(3); PML Rules, rule 10
Retain identity and relationship records for five years after the relationship ends or account closes.
- Implementation action
- Start the retention clock from the correct relationship-end trigger and keep CDD, beneficial ownership, correspondence and analysis retrievable.
- Evidence to retain
- Trigger calculations, customer archive, retrieval test, holds and deletion log.
- Primary citation
- PMLA, section 12(1)(e) and 12(3); PML Rules, rule 10
Maintain records in a form promptly producible to authorities.
- Implementation action
- Use stable identifiers and controlled access so identity, ownership, risk, transactions, alerts, reports and approvals can be reconstructed and securely produced.
- Evidence to retain
- Sample case pack, access review, request register, production index and delivery receipt.
- Primary citation
- PMLA, sections 12 and 13
10Privacy, biometrics, and cyber incidentsApply currently commenced privacy provisions and track the DPDP transition precisely.4 items+
Map commencement before applying the DPDP Act or Rules.
- Implementation action
- For each processing obligation, identify whether the relevant Act section and Rule is in force on the processing date; do not present future-phase duties as already operative.
- Evidence to retain
- Commencement matrix, Gazette copies, legal analysis, owner and transition plan.
- Primary citation
- Digital Personal Data Protection Rules 2025, rule 1; commencement notifications dated 13 November 2025
Document lawful, necessary and secure handling of KYC data.
- Implementation action
- Map purpose, notice or statutory basis, fields, access, accuracy, security, retention and deletion for identity, biometric, screening and monitoring data under operative law and sector directions.
- Evidence to retain
- Data inventory, lawful-basis map, notices, access reviews, security tests and retention configuration.
- Primary citation
- DPDP Act 2023 and Rules 2025 as commenced; Information Technology Act 2000; applicable sector directions
Report specified cyber incidents to CERT-In within six hours.
- Implementation action
- Classify incidents against Annexure I and notify CERT-In within six hours of noticing or being informed of a covered incident while preserving required logs and continuing other applicable notifications.
- Evidence to retain
- Incident classification, notice time, submission, logs, containment record and follow-up.
- Primary citation
- CERT-In Directions under IT Act section 70B(6), 28 April 2022, direction (ii)
Control processors, vendors and cross-border access.
- Implementation action
- Contract for confidentiality, security, audit, incident cooperation, deletion and subprocessing; assess localisation or transfer constraints under the applicable sector and currently operative privacy rule.
- Evidence to retain
- Vendor assessment, contract, subprocessor register, data-flow map, transfer analysis and monitoring.
- Primary citation
- DPDP Act 2023 and Rules 2025 as commenced; RBI outsourcing and KYC directions where applicable
11Practical evidence packsEvidence should reproduce onboarding, reporting and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, representative authority, KYB, beneficial ownership, PEP and sanctions screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting PMLA sections 11A-12 and PML Rules rule 9
Maintain a reconstructable reporting and sanctions pack.
- Implementation action
- Link transactions, alerts, analysis, statutory timing, report, acknowledgement, supplements, freeze actions, authority communications and access logs.
- Evidence to retain
- Complete sampled case pack, timeline and controlled access log.
- Primary citation
- Operational control supporting PML Rules rules 3, 7 and 8; UAPA section 51A
Maintain a regulator-scoped launch pack.
- Implementation action
- Record activity classification, permissions, current sources, filing readiness, ownership duties, sanctions procedure, privacy transition, vendor controls and validation before launch or material change.
- Evidence to retain
- Signed launch pack, source register, regulator map, uncertainty log, tests and approvals.
- Primary citation
- Official sources listed below
Primary-source register
17 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Prevention of Money-laundering Act 2002India Code · Primary legislation
- FIU-IND frequently asked questionsFinancial Intelligence Unit - India · Official FIU guidance
- FIU-IND Reporting Format Guide version 2.2Financial Intelligence Unit - India · Official reporting specification
- FIU-IND downloads and current sector guidanceFinancial Intelligence Unit - India · Official guidance index
- VDA service-provider registration circularFinancial Intelligence Unit - India · Official registration circular
- RBI KYC Amendment Directions 2025Reserve Bank of India · Official supervisory direction
- RBI KYC Direction 2016 consolidated to November 2024Reserve Bank of India · Official supervisory direction
- Companies Act 2013Ministry of Corporate Affairs · Primary legislation
- Digital Personal Data Protection Rules 2025Ministry of Electronics and Information Technology · Official Gazette rules
- MeitY acts and policies indexMinistry of Electronics and Information Technology · Official legal index
- CERT-In cyber-security directions dated 28 April 2022CERT-In · Binding official direction
- UAPA section 51A sanctions procedure referenceReserve Bank of India · Official supervisory notification
- FATF India country profile and 2024 mutual evaluationFATF · Authoritative current assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
- National Flag, Emblem and Anthem materialsMinistry of Home Affairs · Official national-symbol guidance
Direct answers
India KYC, KYB and AML questions
Who receives suspicious transaction reports?+
Financial Intelligence Unit - India through its current authorised electronic reporting system.
When must an STR be filed?+
Promptly and no later than seven working days after the Principal Officer is satisfied that the transaction or attempted transaction is suspicious.
When are monthly reports due?+
Applicable cash, connected-cash, NPO, counterfeit-currency and cross-border-wire reports are due by the 15th day of the succeeding month under the PML Rules and FIU-IND guidance.
Is there one universal KYC threshold?+
No. Relationship opening, suspicion and doubts about prior data can trigger CDD without a monetary threshold; occasional-transaction and reporting amounts depend on the specific rule and sector.
How is beneficial ownership determined?+
Apply the reporting entity's current sector test. RBI directions use ownership thresholds plus control by other means and a senior-managing-official fallback. Company SBO filings are separate and do not replace AML CDD.
How long are AML records retained?+
Generally five years, but the start event differs: transaction records run from the transaction date, while identity and relationship records run from relationship termination or account closure. Longer lawful holds may apply.
Are VDA businesses reporting entities?+
Specified exchange, transfer, custody and issuer-related VDA services performed for another person in the course of business were brought into the PMLA reporting perimeter; use current FIU-IND registration and 2026 guidance.
What happens on a sanctions match?+
Confirm identifiers, apply the current section 51A or proliferation-financing procedure, freeze covered assets without delay where required, report through the competent route and release only under verified authority.
Does the DPDP regime apply in full?+
Do not assume so. The Act and Rules use phased commencement. Map the operative provision on the processing date and continue to apply sector and cyber-security duties.
Is India on a FATF public list?+
No. India was absent from both FATF public lists dated 19 June 2026. India remains subject to regular FATF follow-up, and absence from a public list is not a low-risk finding.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 22 September 2026. Confirm later Gazette amendments, the reporting entity's sector directions, FIU-IND filing specifications, sanctions implementation orders, phased DPDP commencement and state-specific requirements with the competent authority and qualified Indian counsel before launch.