Aml Obligations For Digital Platforms .

1. Legal framework

The principal legislation is the Prevention of Money Laundering Act, 2002 (PMLA), together with the Prevention of Money-laundering (Maintenance of Records) Rules, 2005, FIU-IND directions/guidance, and sector-specific regulatory requirements. The PMLA expressly provides for identity verification, transaction records, reporting, confidentiality, enhanced due diligence and regulatory access to information.

The statutory framework is particularly important for digital businesses such as:

  • cryptocurrency/Virtual Digital Asset (VDA) exchanges;
  • payment and money-transfer platforms;
  • certain financial intermediaries;
  • fintech businesses falling within the definition of reporting entity;
  • platforms facilitating transactions that fall within a regulated financial activity.

A conventional e-commerce or social-media platform, merely because it operates digitally, does not become a reporting entity solely by virtue of being an “online platform.”

2. Who is a “Reporting Entity”?

The PMLA framework places the principal AML obligations on reporting entities.

For a digital platform, the first legal question is therefore:

Does the nature of the platform's business bring it within the definition of a reporting entity under the PMLA?

This is especially significant for Virtual Digital Asset Service Providers (VDA SPs).

Since March 2023, specified VDA activities have been brought within the PMLA framework. These include activities such as:

  1. exchange between virtual digital assets and fiat currencies;
  2. exchange between one or more forms of virtual digital assets;
  3. transfer of virtual digital assets;
  4. safekeeping or administration of virtual digital assets or instruments enabling control over VDA; and
  5. participation in and provision of financial services related to an issuer's offer and/or sale of a virtual digital asset.

The Government has specifically stated that the obligation is activity-based and is not contingent upon physical presence in India.

This is particularly important for offshore digital platforms serving Indian customers.

3. KYC and customer identification

A reporting entity must establish and verify the identity of its customers in accordance with the PMLA framework.

For a digital platform, this generally translates into a robust KYC/CDD system, including:

  • identification of the customer;
  • verification of identity;
  • identification of beneficial ownership;
  • understanding the nature and purpose of the relationship;
  • appropriate risk classification;
  • ongoing monitoring where required;
  • enhanced scrutiny of higher-risk customers and transactions.

The PMLA specifically recognises a “beneficial owner” as the individual who ultimately owns or controls the client, including the person exercising ultimate effective control over a juridical person.

Practical implication

A digital platform cannot necessarily rely merely on:

“The user has created an account and provided an email address.”

For a regulated platform, the compliance system must be capable of determining who the customer actually is and, where relevant, who ultimately owns or controls the customer/entity.

4. Transaction monitoring

AML compliance is not limited to onboarding.

A digital reporting entity must have systems capable of identifying and monitoring transactions that may indicate money laundering or terrorist financing.

Section 12 requires reporting entities to maintain records of transactions in a manner that enables reconstruction of individual transactions and to furnish prescribed transaction information to the Director.

For a digital platform, this can require technological controls such as:

  • transaction monitoring;
  • suspicious-pattern detection;
  • unusual transaction alerts;
  • account-behaviour analysis;
  • identification of rapid movement of funds/assets;
  • monitoring of high-risk jurisdictions;
  • identification of unusual customer activity;
  • escalation of suspicious activity to the compliance team.

Thus, AML compliance for a digital platform is fundamentally both a legal and technological compliance obligation.

5. Suspicious Transaction Reports (STRs)

One of the most important obligations is reporting suspicious transactions to the Financial Intelligence Unit–India (FIU-IND) in accordance with the applicable PMLA framework.

A transaction does not have to be large to attract AML scrutiny. Suspicion can arise from the pattern, circumstances, source, destination or purpose of the transaction.

Consequently, a digital platform should maintain an effective internal mechanism for:

Detection → Investigation → Escalation → Compliance decision → STR filing where required

The platform should also maintain adequate records supporting the decision-making process.

6. Record keeping

Section 12 is particularly important for digital platforms.

A reporting entity must maintain:

  • transaction records;
  • information enabling individual transactions to be reconstructed;
  • prescribed transaction information;
  • identity documents relating to clients and beneficial owners;
  • account files; and
  • business correspondence relating to clients.

The Act requires relevant transaction records to be maintained for five years from the date of the transaction.

Digital-platform implication

The compliance architecture should therefore preserve an auditable trail, including where applicable:

  • customer onboarding records;
  • KYC documents;
  • beneficial-owner information;
  • transaction history;
  • wallet/account information;
  • IP/device information where legally collected and relevant;
  • alerts generated by AML systems;
  • investigation records;
  • STR-related records;
  • communications relevant to the customer relationship.

The exact data that may lawfully be collected and retained must, however, also be considered against applicable privacy/data-protection requirements.

7. Enhanced Due Diligence

Section 12AA of the PMLA deals with enhanced due diligence for specified transactions.

The legislation requires additional measures concerning matters such as:

  • identity verification;
  • ownership and financial position;
  • source of funds;
  • purpose of the transaction; and
  • intended nature of the relationship.

Where the applicable conditions are not satisfied, the reporting entity may be required not to permit the specified transaction. Where suspicious or potentially crime-linked transactions are identified, enhanced future monitoring may be required.

For digital platforms, this is particularly relevant to high-risk users and transactions.

8. Beneficial ownership

Beneficial ownership is especially important where a digital platform deals with:

  • companies;
  • LLPs;
  • trusts;
  • partnerships;
  • institutional customers;
  • corporate crypto accounts;
  • payment intermediaries.

The platform should not necessarily stop at identifying the company appearing on the account.

The compliance question is:

Who ultimately owns or controls the customer?

The statutory definition expressly focuses on ultimate ownership or control.

9. Principal Officer and compliance structure

A reporting entity must establish an appropriate internal AML compliance structure.

In practice, this includes designation of responsible compliance personnel and appropriate governance mechanisms.

A digital platform should have:

  • a board/senior-management AML framework;
  • designated compliance responsibility;
  • documented AML policies;
  • customer-risk methodology;
  • transaction-monitoring procedures;
  • suspicious-transaction escalation procedures;
  • employee training;
  • independent testing/audit;
  • mechanisms for regulatory cooperation.

For a technology company, AML cannot be treated merely as a legal department function. It generally needs to be incorporated into the product, engineering, risk and compliance architecture.

10. FIU-IND registration

For platforms falling within the relevant reporting-entity framework, registration with FIU-IND becomes an important compliance requirement.

This has particular significance for VDA platforms.

In December 2023, the Government stated that VDA service providers operating in India—including offshore entities serving the Indian market—are required to register with FIU-IND and comply with PMLA obligations.

The Government expressly stated that the framework applies to offshore crypto exchanges servicing the Indian market.

11. Offshore digital platforms

This is one of the most important developments for digital businesses.

An offshore platform cannot necessarily argue:

“We are incorporated outside India, therefore Indian AML law does not apply.”

For VDA service providers, the Government has expressly stated that the obligation is activity-based rather than dependent on physical presence in India.

In 2023–24, FIU-IND took compliance action against offshore VDA service providers, including issuing show-cause notices to nine offshore entities. The Government also stated that action could be taken under the PMLA against non-compliant offshore platforms.

This represents an important principle for digital-platform regulation:

Digital delivery does not necessarily eliminate territorial regulatory obligations.

12. Case law: PayPal

One of the most directly relevant Indian cases concerning a digital platform and PMLA is PayPal Payments Private Limited v. Financial Intelligence Unit India & Ors.

The case concerned the question of whether PayPal fell within the PMLA reporting framework.

The Delhi High Court proceedings are significant because they demonstrate how AML obligations can apply to a technology-enabled payment platform, rather than only to a conventional bank or physical financial institution.

In an interim order, the Court directed PayPal to maintain transaction records under Section 12(1)(a) electronically on a secure server located in India, pending the proceedings. The order also addressed the company's obligation to furnish data as required under the PMLA framework.

Significance

The case illustrates that:

digital architecture does not necessarily create an exemption from AML record-keeping requirements.

It also highlights the importance of data accessibility for regulatory purposes.

13. Supreme Court: Vijay Madanlal Choudhary

The leading constitutional case on the PMLA is:

Vijay Madanlal Choudhary & Ors. v. Union of India, (2022).

The Supreme Court considered extensive challenges to the PMLA framework, including issues concerning:

  • Section 3;
  • Section 5;
  • Section 8;
  • Section 19;
  • Section 24;
  • Section 43;
  • Section 45;
  • Section 50; and
  • the ECIR/investigation framework.

The Court's judgment is important for understanding the strength of the statutory AML enforcement architecture.

For digital-platform operators, its significance is broader than simply the constitutional validity of individual provisions: once a platform is properly brought within the PMLA framework, non-compliance can have substantial enforcement consequences.

14. Supreme Court: existence of “proceeds of crime”

Another important principle comes from recent Supreme Court jurisprudence.

The Supreme Court has reiterated that the existence of “proceeds of crime” is a condition precedent to the offence of money laundering under Section 3. In a 2024 order, the Court observed that where the material did not indicate proceeds of crime derived or obtained from criminal activity relating to a scheduled offence, the foundational requirement of PMLA money laundering was not established on the material before it.

This is important because AML compliance and the criminal offence of money laundering are not identical concepts.

A platform may have a regulatory duty to conduct KYC, maintain records and report suspicious transactions even though the platform itself is not guilty of money laundering.

15. Regulatory liability vs criminal liability

This distinction is crucial for understanding digital platforms.

Regulatory AML obligations

A reporting entity may be required to:

  • conduct KYC;
  • identify beneficial owners;
  • maintain records;
  • monitor transactions;
  • file prescribed reports;
  • cooperate with FIU-IND;
  • implement internal controls.

Money-laundering offence

The criminal offence under Section 3 requires the statutory ingredients of money laundering, including dealing with proceeds of crime in the manner contemplated by the provision.

Therefore:

Failure to comply with an AML obligation and committing the substantive offence of money laundering are legally distinct issues.

The Supreme Court's jurisprudence concerning proceeds of crime reinforces this distinction.

16. Consequences of non-compliance

PMLA provides enforcement mechanisms against reporting entities.

Section 13 empowers the Director to conduct proceedings and impose sanctions where applicable. The statutory framework also gives authorities powers concerning information, investigation, search and seizure, and other enforcement measures.

For a digital platform, potential consequences can therefore include:

  1. regulatory directions;
  2. monetary penalties;
  3. compliance proceedings;
  4. investigation by competent authorities;
  5. restrictions affecting the platform's operations;
  6. reputational damage;
  7. potential criminal exposure where the facts independently satisfy the elements of an offence.

The 2023 FIU-IND action against offshore VDA platforms demonstrates that enforcement is not merely theoretical.

17. AML compliance model for a digital platform

A useful way of analysing the obligations is:

Compliance areaObligation
Legal classificationDetermine whether platform is a reporting entity
RegistrationRegister with FIU-IND where required
KYC/CDDIdentify and verify customers
Beneficial ownershipIdentify ultimate owners/controllers
Risk assessmentClassify customers and activities according to risk
Transaction monitoringDetect unusual/suspicious activity
STR reportingReport suspicious transactions where legally required
Record keepingPreserve transaction and customer records
Enhanced DDApply additional scrutiny to specified/high-risk transactions
GovernanceAppoint responsible AML personnel and establish controls
TrainingTrain relevant employees
Audit/testingPeriodically test AML controls
Regulatory cooperationProvide information to competent authorities
Offshore complianceAssess Indian AML obligations even without Indian incorporation

18. Important distinction: “digital platform” is not itself a legal category

This is perhaps the most important point for an examination, research paper or legal opinion.

There is no general rule saying that every digital platform must comply with every AML obligation under the PMLA merely because it is digital.

The correct analytical sequence is:

Digital platform → nature of activity → statutory classification → reporting-entity status → applicable PMLA obligations → regulatory requirements → enforcement exposure.

For example:

Social-media platform

Ordinarily not a reporting entity merely because it hosts user-generated content.

E-commerce marketplace

Not automatically a PMLA reporting entity merely because users buy and sell goods.

Payment platform

Potentially subject to AML obligations depending on its regulatory/statutory status and activities.

Crypto/VDA exchange

Specified VDA activities are expressly brought within the PMLA framework and require FIU-IND compliance.

19. Key cases to cite

For an Indian law answer, I would focus on these authorities:

1. Vijay Madanlal Choudhary & Ors. v. Union of India (2022)
Leading Supreme Court authority on the PMLA's constitutional and enforcement framework.

2. PayPal Payments Private Limited v. Financial Intelligence Unit India & Ors. (Delhi High Court, 2023)
Highly relevant to AML obligations of digital/payment platforms and electronic maintenance/accessibility of transaction records.

3. Recent Supreme Court jurisprudence on “proceeds of crime”
Useful for distinguishing the regulatory AML obligations of a platform from the substantive offence of money laundering.

20. Conclusion

The Indian AML regime is increasingly technology-neutral and activity-focused. The important question is not whether a business calls itself a “digital platform,” fintech, marketplace, exchange or technology company. The critical question is what regulated activity it actually performs.

For platforms falling within the PMLA reporting-entity framework, the core obligations include KYC/CDD, beneficial-owner identification, transaction monitoring, record retention, suspicious-transaction reporting, enhanced due diligence, governance and cooperation with FIU-IND. Section 12 specifically requires transaction and customer records, while Sections 12A and 12AA strengthen the information-access and enhanced-due-diligence framework.

For VDA platforms, the regulatory position is especially clear: specified VDA activities have been brought within the PMLA regime, and the Government has expressly confirmed that the framework can apply to offshore platforms serving the Indian market, irrespective of physical presence in India.

LEAVE A COMMENT