Inde KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Inde.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Guide d’implémentation portable
Obtenir la checklist PDF
11 domaines de contrôle · 38 contrôles d’implémentation
Dernière revue: 22 September 2026 · Version 1.0
Télécharger la checklistRéponse directe
Que couvre la checklist de conformité pour Inde ?
La checklist pour Inde traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 38 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- Financial Intelligence Unit - India (FIU-IND)
- Primary AML rules
- PMLA 2002 and PML (Maintenance of Records) Rules 2005, as amended
- STR timing
- Promptly and no later than seven working days after satisfaction that a transaction is suspicious
- Monthly reports
- Applicable prescribed reports by the 15th day of the succeeding month
- AML retention
- Five years from transaction or relationship-end trigger, according to record type
- RBI BO tests
- More than 10% for companies and trusts; more than 15% for unincorporated associations, plus control/fallback rules
- Privacy transition
- DPDP Act and Rules 2025 commence in phases; map each operative provision before relying on it
- FATF public lists
- Not listed at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Inde
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingClassify the entity, activity and supervisor before relying on any sector control.4 éléments+
Determine whether each activity is within the PMLA reporting-entity perimeter.
- Action d’implémentation
- Map banking, financial, securities, gaming, property, precious-metals, professional, trust-and-company-service and virtual-digital-asset activities to the current statutory definition and notification.
- Preuves à conserver
- Entity chart, activity inventory, statutory analysis, notification register and counsel sign-off.
- Source primaire
- PMLA, sections 2(1)(sa), 2(1)(wa), 11A and 12; applicable Central Government notifications
Identify the competent supervisor and permission for every regulated service.
- Action d’implémentation
- Confirm whether RBI, SEBI, IRDAI, FIU-IND or another authority licenses, registers or supervises the activity before launch or material change.
- Preuves à conserver
- Perimeter memorandum, licence or registration, conditions, regulator correspondence and renewal calendar.
- Source primaire
- PML Rules, rule 9(14); applicable sector law and supervisory direction
Register with FIU-IND where the reporting regime requires it.
- Action d’implémentation
- Complete the current FINnet/FINGate registration, appoint the required Designated Director and Principal Officer, and keep contact and entity information current.
- Preuves à conserver
- Registration acknowledgement, appointments, portal access record and change log.
- Source primaire
- PML Rules, rules 7 and 9; FIU-IND registration materials
Treat notified VDA services as reporting-entity activity.
- Action d’implémentation
- For exchange, transfer, custody or issuer-related VDA services carried on for another person in the course of business, assess the 7 March 2023 notification and current FIU-IND registration and AML/CFT guidance, including offshore service into India.
- Preuves à conserver
- Service and geography map, VDA analysis, registration, control gap assessment and ongoing compliance record.
- Source primaire
- Ministry of Finance notification dated 7 March 2023; FIU-IND VDA guidelines updated 8 January 2026
02Governance and risk assessmentControls must be entity-specific, risk-based, approved and independently tested.3 éléments+
Maintain a documented ML, TF and PF risk assessment.
- Action d’implémentation
- Assess customer, geography, product, service, transaction, delivery-channel and technology risks and update the assessment after material change.
- Preuves à conserver
- Methodology, current assessment, data sources, approvals, residual-risk decisions and remediation plan.
- Source primaire
- PML Rules, rule 9; RBI KYC Direction, sections 4 and 5; FATF India MER 2024, Recommendations 1 and 15
Assign accountable AML leadership.
- Action d’implémentation
- Appoint a Designated Director and Principal Officer with documented authority, resources, independence and escalation to senior management or the board.
- Preuves à conserver
- Appointments, notifications, role descriptions, reporting lines and committee minutes.
- Source primaire
- PML Rules, rules 2(1)(ba), 2(1)(f) and 7
Approve and independently test the AML programme.
- Action d’implémentation
- Maintain policies for CDD, monitoring, reporting, sanctions, records, employee screening, training, group controls and quality assurance; independently test design and operation.
- Preuves à conserver
- Policy suite, approval, training, audit plan, samples, findings and verified closure.
- Source primaire
- PML Rules, rule 9; RBI KYC Direction, Chapters II and X
03Natural-person identificationCDD applies at relationship, occasional-transaction, suspicion and doubt triggers under the governing sector rule.4 éléments+
Configure CDD triggers from the applicable sector instrument.
- Action d’implémentation
- Map account or relationship opening, occasional transactions, international money transfer, suspicion and doubt about previous identification; aggregate linked transactions where the rule requires it.
- Preuves à conserver
- Trigger matrix, sector-rule version, aggregation tests, timestamps and exception log.
- Source primaire
- PML Rules, rule 9; RBI KYC Direction, sections 14 and 23
Identify and verify each natural-person customer.
- Action d’implémentation
- Obtain prescribed identity and address information and verify it through permitted official documents, digital KYC, CKYCR records, Aadhaar routes or other reliable independent means applicable to the entity.
- Preuves à conserver
- Customer record, verification source, authentication or retrieval result, timestamp and discrepancy resolution.
- Source primaire
- PMLA, section 11A; PML Rules, rule 9; RBI KYC Direction, sections 16 and 18
Verify representatives and authority.
- Action d’implémentation
- Identify the person acting for a customer, verify identity and confirm documentary authority before allowing instructions or access.
- Preuves à conserver
- Representative KYC, mandate, verification result, scope limits and activity log.
- Source primaire
- PML Rules, rule 9; RBI KYC Direction, section 14
Stop onboarding or restrict activity when required CDD cannot be completed.
- Action d’implémentation
- Do not open or continue an account or execute the transaction where the applicable rule prohibits it; assess an STR without tipping off the customer.
- Preuves à conserver
- CDD gap, restriction or exit, approval, suspicion assessment and filing receipt where applicable.
- Source primaire
- PML Rules, rule 9; RBI KYC Direction, sections 39 and 41
04KYB, registries, and beneficial ownershipVerify legal existence, authorised persons, ownership and control; keep AML tests separate from company filings.4 éléments+
Verify legal-person existence, purpose and authority.
- Action d’implémentation
- Obtain current incorporation, registered-office, tax, constitutional, director or partner and authorisation information from reliable sources such as the MCA registry and applicable regulator.
- Preuves à conserver
- Registry extract, constitutional documents, PAN, licence, officer list, mandates and discrepancy log.
- Source primaire
- PML Rules, rule 9; RBI KYC Direction, sections 27-30
Identify the natural-person AML beneficial owner using the applicable cascade.
- Action d’implémentation
- For RBI-regulated entities apply the current ownership thresholds, then control by other means, and the senior-managing-official fallback only where no natural person is identified; apply sector-specific exemptions carefully.
- Preuves à conserver
- Layered ownership chart, percentage calculations, control analysis, verified identities, exemption and fallback rationale.
- Source primaire
- PML Rules, rule 9(3); RBI KYC Direction, section 33
Apply trust and legal-arrangement party identification.
- Action d’implémentation
- Identify the author or settlor, trustees, beneficiaries meeting the applicable threshold and any other natural person exercising ultimate effective control.
- Preuves à conserver
- Trust deed, party schedule, ownership or entitlement calculations, authority records and verified identities.
- Source primaire
- PML Rules, rule 9(3); RBI KYC Direction, section 33
Maintain company significant-beneficial-owner compliance separately.
- Action d’implémentation
- Assess Companies Act section 90 and the current Significant Beneficial Owners Rules, obtain BEN-1 declarations, maintain BEN-3 and file BEN-2 within the applicable time; do not substitute this registry test for AML CDD.
- Preuves à conserver
- SBO analysis, notices, declarations, register, filings and change log.
- Source primaire
- Companies Act 2013, section 90; Companies (Significant Beneficial Owners) Rules 2018, as amended
05PEPs, enhanced due diligence, and remote onboardingHigher-risk and non-face-to-face relationships require stronger measures under the applicable sector rule.3 éléments+
Identify politically exposed customers and beneficial owners.
- Action d’implémentation
- Use declarations and reliable sources to identify covered foreign PEPs and related family or close-associate relationships; assess domestic prominent public functions under the entity's risk framework and sector rules.
- Preuves à conserver
- Screening result, declaration, relationship map, source, rationale and refresh history.
- Source primaire
- RBI KYC Direction, section 35; FATF India MER 2024, Recommendation 12
Apply enhanced measures to higher-risk relationships.
- Action d’implémentation
- Obtain required senior approval, establish source of funds and source of wealth where applicable, corroborate purpose and increase the degree and frequency of monitoring.
- Preuves à conserver
- Risk decision, approval, source corroboration, enhanced monitoring plan and reviews.
- Source primaire
- PML Rules, rule 9; RBI KYC Direction, sections 34-37
Use permitted remote-onboarding methods and control impersonation risk.
- Action d’implémentation
- Select a permitted V-CIP, digital KYC or equivalent route; verify liveness, location, audit trail, consent and document authenticity and retain the prescribed record.
- Preuves à conserver
- Method decision, session record, liveness and location results, document checks, consent and QA review.
- Source primaire
- RBI KYC Direction, sections 18 and Annex I
06Monitoring and suspicious reportingMonitor against expected activity and report suspicion to FIU-IND within the statutory clock.4 éléments+
Monitor transactions and keep customer information current.
- Action d’implémentation
- Scrutinise transactions for consistency with customer profile, business, risk and source of funds and refresh records at the risk-based frequency required by the supervisor.
- Preuves à conserver
- Monitoring scenarios, alerts, case analysis, refresh schedule and dispositions.
- Source primaire
- PMLA, section 12; PML Rules, rule 9; RBI KYC Direction, sections 38 and 39
Report suspicious transactions promptly.
- Action d’implémentation
- Once the Principal Officer is satisfied that a transaction or attempted transaction is suspicious, file the STR with FIU-IND promptly and no later than seven working days; do not wait for proof or a threshold.
- Preuves à conserver
- Suspicion chronology, decision, STR, FINGate acknowledgement and supplemental responses.
- Source primaire
- PML Rules, rules 3(1)(D), 7 and 8; FIU-IND FAQs
Preserve confidentiality and prevent tipping off.
- Action d’implémentation
- Restrict knowledge of an STR, FIU request or related analysis and do not disclose information that would prejudice reporting or investigation, except where lawfully authorised.
- Preuves à conserver
- Need-to-know matrix, access logs, communication controls, training and incident register.
- Source primaire
- PMLA, sections 12 and 14; PML Rules, rule 7
Respond to FIU-IND and competent-authority requests through controlled channels.
- Action d’implémentation
- Authenticate the request, preserve relevant records, produce complete information promptly and log disclosure while maintaining report confidentiality.
- Preuves à conserver
- Request register, validation, production index, secure delivery and acknowledgement.
- Source primaire
- PMLA, sections 12 and 13; PML Rules, rule 7
07Threshold reports, payments, and transfersThreshold reporting and transfer controls are report- and sector-specific.3 éléments+
File applicable monthly transaction reports by the statutory deadline.
- Action d’implémentation
- Determine whether CTR, connected cash, NPO receipt, counterfeit-currency or cross-border wire reporting applies and submit the prescribed report by the 15th day of the succeeding month.
- Preuves à conserver
- Report-scope matrix, aggregation tests, source data, validation output, submission and acknowledgement.
- Source primaire
- PML Rules, rules 3 and 8; FIU-IND FAQs and Reporting Format Guide
Do not generalise one monetary threshold across all controls.
- Action d’implémentation
- Apply each amount, currency, aggregation period, product scope and exemption only to the specific report or sector rule that creates it.
- Preuves à conserver
- Threshold inventory, legal source, rule version, test cases and exception approvals.
- Source primaire
- PML Rules, rule 3; applicable sector direction
Carry required originator and beneficiary information through transfers.
- Action d’implémentation
- Collect, validate, retain and transmit prescribed payer and payee data; repair, reject or restrict transfers with missing information as required by the applicable payment rule.
- Preuves à conserver
- Field matrix, message samples, validation rules, repair queue and rejection record.
- Source primaire
- RBI KYC Direction, wire-transfer provisions; FATF India MER 2024, Recommendation 16
08Targeted financial sanctionsUse current UN and Indian designation mechanisms and verified sector procedures.3 éléments+
Screen relevant parties and transactions against current designations.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, during the relationship and whenever applicable UN or Indian lists change.
- Preuves à conserver
- List inventory, update logs, screening configuration, tests, match analysis and dispositions.
- Source primaire
- UAPA, section 51A; Government procedure order dated 2 February 2021 as corrected; RBI KYC Direction, section 52
Freeze covered assets without delay on a confirmed designation.
- Action d’implémentation
- Follow the current section 51A procedure to prevent dealing in covered funds or assets, report through the competent route and release only under verified authority.
- Preuves à conserver
- Match analysis, freeze timestamp, ownership-control analysis, report, system blocks and authority correspondence.
- Source primaire
- UAPA, section 51A; Government procedure order dated 2 February 2021 as corrected
Document proliferation-financing sanctions coverage.
- Action d’implémentation
- Map applicable UN proliferation designations, domestic implementation orders and sector instructions and test ownership, control and indirect-availability scenarios.
- Preuves à conserver
- Legal map, list update record, screening tests, escalation procedure and training.
- Source primaire
- Weapons of Mass Destruction and their Delivery Systems Act 2005, section 12A; FATF India MER 2024, Recommendation 7
09Records and regulator accessRecords must reconstruct transactions and remain available for the correct five-year period.3 éléments+
Retain transaction records for five years from the transaction date.
- Action d’implémentation
- Preserve information sufficient to reconstruct individual transactions, including parties, nature, amount, currency, date and channel, subject to any longer lawful hold.
- Preuves à conserver
- Retention schedule, archive sample, reconstruction test, legal holds and deletion approvals.
- Source primaire
- PMLA, section 12(1)(a) and 12(3); PML Rules, rule 10
Retain identity and relationship records for five years after the relationship ends or account closes.
- Action d’implémentation
- Start the retention clock from the correct relationship-end trigger and keep CDD, beneficial ownership, correspondence and analysis retrievable.
- Preuves à conserver
- Trigger calculations, customer archive, retrieval test, holds and deletion log.
- Source primaire
- PMLA, section 12(1)(e) and 12(3); PML Rules, rule 10
Maintain records in a form promptly producible to authorities.
- Action d’implémentation
- Use stable identifiers and controlled access so identity, ownership, risk, transactions, alerts, reports and approvals can be reconstructed and securely produced.
- Preuves à conserver
- Sample case pack, access review, request register, production index and delivery receipt.
- Source primaire
- PMLA, sections 12 and 13
10Privacy, biometrics, and cyber incidentsApply currently commenced privacy provisions and track the DPDP transition precisely.4 éléments+
Map commencement before applying the DPDP Act or Rules.
- Action d’implémentation
- For each processing obligation, identify whether the relevant Act section and Rule is in force on the processing date; do not present future-phase duties as already operative.
- Preuves à conserver
- Commencement matrix, Gazette copies, legal analysis, owner and transition plan.
- Source primaire
- Digital Personal Data Protection Rules 2025, rule 1; commencement notifications dated 13 November 2025
Document lawful, necessary and secure handling of KYC data.
- Action d’implémentation
- Map purpose, notice or statutory basis, fields, access, accuracy, security, retention and deletion for identity, biometric, screening and monitoring data under operative law and sector directions.
- Preuves à conserver
- Data inventory, lawful-basis map, notices, access reviews, security tests and retention configuration.
- Source primaire
- DPDP Act 2023 and Rules 2025 as commenced; Information Technology Act 2000; applicable sector directions
Report specified cyber incidents to CERT-In within six hours.
- Action d’implémentation
- Classify incidents against Annexure I and notify CERT-In within six hours of noticing or being informed of a covered incident while preserving required logs and continuing other applicable notifications.
- Preuves à conserver
- Incident classification, notice time, submission, logs, containment record and follow-up.
- Source primaire
- CERT-In Directions under IT Act section 70B(6), 28 April 2022, direction (ii)
Control processors, vendors and cross-border access.
- Action d’implémentation
- Contract for confidentiality, security, audit, incident cooperation, deletion and subprocessing; assess localisation or transfer constraints under the applicable sector and currently operative privacy rule.
- Preuves à conserver
- Vendor assessment, contract, subprocessor register, data-flow map, transfer analysis and monitoring.
- Source primaire
- DPDP Act 2023 and Rules 2025 as commenced; RBI outsourcing and KYC directions where applicable
11Practical evidence packsEvidence should reproduce onboarding, reporting and launch decisions end to end.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, representative authority, KYB, beneficial ownership, PEP and sanctions screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack and retrieval result.
- Source primaire
- Operational control supporting PMLA sections 11A-12 and PML Rules rule 9
Maintain a reconstructable reporting and sanctions pack.
- Action d’implémentation
- Link transactions, alerts, analysis, statutory timing, report, acknowledgement, supplements, freeze actions, authority communications and access logs.
- Preuves à conserver
- Complete sampled case pack, timeline and controlled access log.
- Source primaire
- Operational control supporting PML Rules rules 3, 7 and 8; UAPA section 51A
Maintain a regulator-scoped launch pack.
- Action d’implémentation
- Record activity classification, permissions, current sources, filing readiness, ownership duties, sanctions procedure, privacy transition, vendor controls and validation before launch or material change.
- Preuves à conserver
- Signed launch pack, source register, regulator map, uncertainty log, tests and approvals.
- Source primaire
- Official sources listed below
Registre des sources primaires
17 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Prevention of Money-laundering Act 2002India Code · Primary legislation
- FIU-IND frequently asked questionsFinancial Intelligence Unit - India · Official FIU guidance
- FIU-IND Reporting Format Guide version 2.2Financial Intelligence Unit - India · Official reporting specification
- FIU-IND downloads and current sector guidanceFinancial Intelligence Unit - India · Official guidance index
- VDA service-provider registration circularFinancial Intelligence Unit - India · Official registration circular
- RBI KYC Amendment Directions 2025Reserve Bank of India · Official supervisory direction
- RBI KYC Direction 2016 consolidated to November 2024Reserve Bank of India · Official supervisory direction
- Companies Act 2013Ministry of Corporate Affairs · Primary legislation
- Digital Personal Data Protection Rules 2025Ministry of Electronics and Information Technology · Official Gazette rules
- MeitY acts and policies indexMinistry of Electronics and Information Technology · Official legal index
- CERT-In cyber-security directions dated 28 April 2022CERT-In · Binding official direction
- UAPA section 51A sanctions procedure referenceReserve Bank of India · Official supervisory notification
- FATF India country profile and 2024 mutual evaluationFATF · Authoritative current assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
- National Flag, Emblem and Anthem materialsMinistry of Home Affairs · Official national-symbol guidance
Réponses directes
Questions KYC, KYB et AML pour Inde
Who receives suspicious transaction reports?+
Financial Intelligence Unit - India through its current authorised electronic reporting system.
When must an STR be filed?+
Promptly and no later than seven working days after the Principal Officer is satisfied that the transaction or attempted transaction is suspicious.
When are monthly reports due?+
Applicable cash, connected-cash, NPO, counterfeit-currency and cross-border-wire reports are due by the 15th day of the succeeding month under the PML Rules and FIU-IND guidance.
Is there one universal KYC threshold?+
No. Relationship opening, suspicion and doubts about prior data can trigger CDD without a monetary threshold; occasional-transaction and reporting amounts depend on the specific rule and sector.
How is beneficial ownership determined?+
Apply the reporting entity's current sector test. RBI directions use ownership thresholds plus control by other means and a senior-managing-official fallback. Company SBO filings are separate and do not replace AML CDD.
How long are AML records retained?+
Generally five years, but the start event differs: transaction records run from the transaction date, while identity and relationship records run from relationship termination or account closure. Longer lawful holds may apply.
Are VDA businesses reporting entities?+
Specified exchange, transfer, custody and issuer-related VDA services performed for another person in the course of business were brought into the PMLA reporting perimeter; use current FIU-IND registration and 2026 guidance.
What happens on a sanctions match?+
Confirm identifiers, apply the current section 51A or proliferation-financing procedure, freeze covered assets without delay where required, report through the competent route and release only under verified authority.
Does the DPDP regime apply in full?+
Do not assume so. The Act and Rules use phased commencement. Map the operative provision on the processing date and continue to apply sector and cyber-security duties.
Is India on a FATF public list?+
No. India was absent from both FATF public lists dated 19 June 2026. India remains subject to regular FATF follow-up, and absence from a public list is not a low-risk finding.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 22 September 2026. Confirm later Gazette amendments, the reporting entity's sector directions, FIU-IND filing specifications, sanctions implementation orders, phased DPDP commencement and state-specific requirements with the competent authority and qualified Indian counsel before launch.