Aml/Cft Compliance In Banking .
1. Meaning of AML and CFT
A. Anti-Money Laundering — AML
Money laundering broadly means dealing with the proceeds of criminal activity in a manner intended to conceal their illicit origin and make them appear legitimate.
In India, the principal legislation is the Prevention of Money-Laundering Act, 2002 (PMLA).
The PMLA defines "proceeds of crime" as property derived or obtained, directly or indirectly, from criminal activity relating to a scheduled offence, including the value of such property in the circumstances specified by the Act. A banking company is expressly a "reporting entity" under the PMLA.
B. Combating Financing of Terrorism — CFT
CFT focuses on preventing the financial system from being used to provide funds or financial services for:
- terrorist organisations;
- terrorist acts;
- persons involved in terrorism;
- recruitment or facilitation of terrorism; and
- other prohibited activities.
An important distinction is:
AML asks: "Where did this money come from?"
CFT asks: "Where is this money going, and who will use it?"
Money used for terrorism does not necessarily have to originate from criminal proceeds. Legitimate funds can also be diverted towards terrorist financing.
2. Why banks are at the centre of AML/CFT
Banks are particularly vulnerable because they provide:
- current and savings accounts;
- cash deposits and withdrawals;
- domestic and international transfers;
- RTGS/NEFT/IMPS;
- foreign exchange;
- trade finance;
- correspondent banking;
- credit facilities;
- remittances;
- cards and digital payment facilities;
- securities/investment-related services; and
- access to the international financial system.
Consequently, a bank can become either:
- an unwitting intermediary for criminal money, or
- a deliberate participant in laundering.
The RBI therefore treats KYC/AML/CFT as an integral part of banking risk management rather than merely a documentation exercise.
The RBI's KYC framework expressly states that its purpose is to prevent banks and other financial institutions from being used as channels for money laundering and terrorist financing and to protect the integrity and stability of the financial system.
3. Legal framework governing AML/CFT in Indian banking
The principal framework consists of:
1. Prevention of Money-Laundering Act, 2002
The PMLA creates the substantive offence of money laundering and imposes obligations on reporting entities.
Important provisions include:
- Section 3 — offence of money laundering;
- Section 4 — punishment;
- Section 5 — attachment of property involved in money laundering;
- Sections 17–18 — search and seizure;
- Section 19 — arrest;
- Section 24 — burden of proof;
- Section 43 — Special Courts;
- Section 44 — jurisdiction of Special Court;
- Section 45 — bail;
- Section 50 — powers regarding summons/evidence;
- Section 12 — obligations of reporting entities;
- Section 12A/12AA — enhanced customer due diligence and related measures.
2. Prevention of Money-Laundering (Maintenance of Records) Rules, 2005
These Rules operationalise the reporting and record-keeping requirements of the PMLA.
They deal with matters such as:
- customer identification;
- beneficial ownership;
- transaction records;
- suspicious transactions;
- reporting to FIU-IND;
- record preservation;
- Principal Officer and Designated Director responsibilities.
3. RBI Master Direction – Know Your Customer (KYC) Direction, 2016
This is the principal regulatory framework for banks and other RBI-regulated entities.
The current RBI framework covers:
- Customer Acceptance Policy;
- risk categorisation;
- Customer Identification Procedure;
- Customer Due Diligence;
- Enhanced Due Diligence;
- beneficial ownership;
- PEPs;
- correspondent banking;
- wire transfers;
- transaction monitoring;
- record keeping;
- FIU reporting;
- sanctions screening;
- UAPA obligations;
- WMD-related sanctions;
- money-mule accounts; and
- new-technology risks.
RBI amended the KYC Direction in 2025, including provisions concerning periodic KYC updation for low-risk individual customers and use of Business Correspondents for certain KYC-updation activities.
4. The three stages of money laundering
A traditional AML analysis identifies three stages.
Stage 1 — Placement
The criminal introduces illicit money into the financial system.
Example
A person has ₹50 lakh in cash generated from illegal activity.
Instead of depositing ₹50 lakh at once, the person may:
- use several bank accounts;
- make multiple cash deposits;
- use third-party accounts;
- purchase financial instruments; or
- route money through businesses.
This is called placement.
Stage 2 — Layering
The objective is to make tracing the original source difficult.
The person may:
Account A → Account B → shell company → foreign account → investment → Account C
Methods may include:
- multiple bank transfers;
- shell companies;
- fictitious invoices;
- trade-based laundering;
- loans between related entities;
- circular transactions;
- offshore entities;
- cryptocurrency/virtual assets;
- purchase and sale of securities; and
- rapid movement through different jurisdictions.
Stage 3 — Integration
The money ultimately appears to have a legitimate source.
For example:
Illegal money → shell company → investment in property → sale of property → legitimate-looking business income.
At this stage, the criminal attempts to explain the money as:
- business profit;
- investment income;
- loan proceeds;
- property sale proceeds;
- consultancy fees; or
- other apparently legitimate income.
5. KYC is the foundation of AML compliance
KYC = Know Your Customer.
But modern AML compliance goes substantially beyond simply obtaining Aadhaar/PAN.
A bank must understand:
Who is the customer?
Who ultimately owns or controls the customer?
What does the customer do?
What is the expected transaction pattern?
Where does the customer's money come from?
Where is the money going?
Is the activity consistent with the customer's profile?
RBI requires regulated entities to conduct CDD using reliable and independent sources and to understand the customer's business, ownership and control and identify the beneficial owner.
6. Customer Due Diligence — CDD
CDD generally involves:
Step 1 — Identification
Identify the customer.
For an individual:
- name;
- identity;
- address;
- PAN/Form 60;
- applicable KYC documents;
- other required information.
Step 2 — Verification
The bank verifies the information through reliable and independent sources.
Step 3 — Purpose of relationship
The bank should understand:
- why the account is being opened;
- nature of business;
- expected transaction volume;
- expected geographical exposure;
- source of funds.
Step 4 — Beneficial ownership
For companies, partnerships, trusts and other legal structures, the bank must identify the natural person(s) who ultimately own or control the entity.
For example:
Company A → owned by Company B → owned by Company C → ultimately controlled by Mr X.
The bank cannot simply stop at Company A.
It must establish the ultimate beneficial owner.
RBI's framework defines beneficial ownership using ownership/control concepts and includes specific rules for companies, partnerships, unincorporated associations and trusts.
7. Risk-Based Approach
AML compliance is not supposed to operate on a simple:
"KYC document present = low risk"
basis.
Banks must assess ML/TF risk.
RBI requires risk categorisation based on factors including:
- customer identity;
- social/financial status;
- nature of business;
- geographical risk;
- products/services;
- delivery channels;
- cash transactions;
- wire transfers;
- foreign exchange activity; and
- other transaction characteristics.
Customers may therefore be classified as:
Low risk
Ordinary customers with straightforward activity and relatively low ML/TF risk.
Medium risk
Customers requiring greater monitoring.
High risk
Examples may include:
- PEPs;
- complex corporate structures;
- high-risk jurisdictions;
- unusual cash-intensive businesses;
- high-value cross-border transactions;
- customers with unexplained source of wealth;
- certain non-face-to-face relationships; and
- customers exhibiting unusual transaction patterns.
8. Enhanced Due Diligence — EDD
High-risk customers require Enhanced Due Diligence.
This can involve:
- additional identification documents;
- source of funds;
- source of wealth;
- beneficial ownership investigation;
- senior-management approval;
- enhanced transaction monitoring;
- more frequent KYC review;
- adverse-media checks;
- sanctions screening.
For PEP relationships, RBI specifically requires appropriate risk-management systems, reasonable measures to establish source of funds/wealth, senior-management approval and enhanced ongoing monitoring. These requirements also extend to family members and close associates in the circumstances specified by the Direction.
9. Politically Exposed Persons — PEPs
PEPs receive special AML treatment because public office can create increased corruption/bribery and financial-crime risks.
Examples include certain:
- senior politicians;
- senior government officials;
- senior judicial/military officials;
- senior executives of state-owned corporations; and
- important political party officials.
Important: Being a PEP does not mean the person is a criminal.
The correct principle is:
PEP status = enhanced risk assessment, not automatic rejection.
10. Transaction Monitoring
This is one of the most important parts of AML compliance.
A bank must compare actual activity against the customer's expected profile.
Example
Customer profile:
Annual income: ₹8 lakh
Business: small local retailer
Expected monthly turnover: ₹5 lakh
Suddenly:
₹2 crore received through 35 accounts
₹1.8 crore transferred overseas
multiple cash withdrawals
This creates an AML red flag.
The bank should investigate:
- source of money;
- purpose;
- counterparties;
- economic rationale;
- relationship between parties;
- supporting invoices/contracts;
- geographical exposure;
- beneficial ownership.
11. What is a Suspicious Transaction?
A very important examination point is that suspicion is not dependent solely on transaction value.
Under the RBI KYC framework, a suspicious transaction includes an actual or attempted transaction which, acting in good faith:
- gives reasonable ground to suspect proceeds of a scheduled offence;
- appears unusually or unjustifiably complex;
- appears to lack economic rationale or bona fide purpose; or
- gives reasonable ground to suspect terrorist financing.
Thus:
A small transaction can be suspicious.
and
A large transaction is not automatically suspicious.
12. STR — Suspicious Transaction Report
If the bank concludes that a transaction is suspicious, it must report it to FIU-IND.
The Principal Officer is responsible for the reporting function.
An STR must generally be furnished not later than seven working days after the reporting entity is satisfied that the transaction is suspicious. The requirement can cover attempted transactions as well.
Important distinction
A bank should not think:
"The customer conducted a ₹10 lakh transaction, therefore STR."
Instead:
"Based on the customer's profile and circumstances, there are reasonable grounds to suspect the transaction."
13. STR does not mean "customer is guilty"
This is extremely important.
An STR is essentially an AML intelligence/reporting mechanism.
The bank is not deciding:
"This customer committed money laundering."
It is reporting:
"These circumstances give rise to a suspicion that requires consideration by the competent authorities."
Therefore, a bank must avoid treating the STR itself as proof of criminal guilt.
14. No tipping-off
One of the most important AML principles is prohibition of tipping-off.
A bank employee should not tell the customer:
"We have filed an STR against you."
Nor should the employee reveal confidential AML reporting information in a manner prohibited by law.
FIU guidance expressly emphasises that reporting entities, directors, officers and employees must not disclose that an STR or related information has been furnished to FIU-IND.
15. Record Keeping
Banks must maintain appropriate transaction and identification records.
RBI requires regulated entities to maintain transaction records for at least five years from the date of the transaction, and customer-identification records for at least five years after the business relationship ends.
Records should enable reconstruction of:
- nature of transaction;
- amount;
- currency;
- date;
- parties;
- customer identity; and
- relevant analysis.
16. Sanctions Screening — CFT
CFT compliance requires banks to screen customers and transactions against relevant sanctions lists.
RBI requires banks to comply with Section 51A of the Unlawful Activities (Prevention) Act, 1967 (UAPA) and relevant Government/UN sanctions requirements.
The KYC Direction requires checking relevant sanctions lists and says the lists must be verified daily, with additions/deletions/changes incorporated into screening.
A bank must therefore have an effective:
Name Screening → Alert → Investigation → Match determination → Freeze/report/escalate
process.
17. True match versus false positive
Suppose a bank's screening system produces:
"MOHAMMED ALI"
and the sanctions list also contains:
"MOHAMMED ALI"
The bank cannot automatically freeze every person with that name.
It must investigate additional identifiers such as:
- date of birth;
- nationality;
- passport;
- address;
- aliases;
- organisation;
- country;
- other identifying information.
This is the difference between:
name match and confirmed sanctions match.
18. UAPA and CFT
Section 51A of UAPA is particularly important for banks.
RBI requires regulated entities to ensure that accounts are not maintained in the names of persons/entities appearing on relevant terrorist/sanctions lists and requires reporting and freezing procedures to be followed as prescribed.
This means CFT compliance is not merely a "KYC issue"; it is closely connected with:
- sanctions;
- asset freezing;
- national security;
- international sanctions;
- UN Security Council resolutions.
19. Correspondent Banking
Correspondent banking presents a major AML/CFT risk because one bank may provide services to another bank's customers.
RBI requires banks to conduct enhanced scrutiny of correspondent relationships, including understanding:
- respondent bank's business;
- management;
- reputation;
- quality of supervision;
- AML/CFT controls;
- regulatory environment;
- purpose of the relationship.
Senior-management approval is required for establishing new correspondent relationships, and relationships with shell banks are prohibited.
20. Wire Transfers
International wire transfers are particularly important because money can move rapidly between jurisdictions.
AML controls should examine:
- originator;
- beneficiary;
- account numbers;
- country;
- purpose;
- transaction amount;
- intermediary banks;
- sanctions status;
- unusual transaction patterns.
RBI requires cross-border wire transfers to carry appropriate originator and beneficiary information.
21. Money Mule Accounts
A money mule is generally a person whose account is used to receive and move illicit funds, often in exchange for compensation or sometimes without fully understanding the criminal scheme.
Example:
Fraudster → Mule Account → Multiple Accounts → Cryptocurrency/foreign account
RBI specifically requires banks to monitor for money-mule accounts and take appropriate action, including STR reporting where required. RBI further states that where an account is established to be a money-mule account and the bank failed to file an STR, the bank would be regarded as non-compliant with the KYC directions.
22. Trade-Based Money Laundering
Banks involved in trade finance must be alert to:
- over-invoicing;
- under-invoicing;
- phantom shipments;
- duplicate invoices;
- unrelated parties;
- unusual jurisdictions;
- circular trade;
- false descriptions of goods.
Example
Actual value of goods:
₹20 lakh
Invoice value:
₹2 crore
The excess ₹1.8 crore can potentially be used to move illicit value.
Therefore, AML compliance extends beyond account opening into trade finance and transaction-level investigation.
23. Shell Companies
A shell company is not automatically illegal.
A legitimate company may have:
- few employees;
- limited operations;
- holding-company functions;
- special-purpose structures.
The AML concern arises where the corporate structure is used to:
- conceal beneficial ownership;
- circulate money;
- create fictitious transactions;
- disguise proceeds of crime;
- move money offshore.
Therefore:
Shell company ≠ automatically money laundering.
The question is whether the structure has a legitimate economic purpose and whether the beneficial owner and transaction rationale can be established.
24. AML Governance within a Bank
Effective AML compliance requires three levels.
Board
The Board should establish:
- AML/CFT policy;
- risk appetite;
- governance;
- oversight;
- resources.
Senior Management / Compliance
Responsible for:
- implementation;
- risk assessment;
- monitoring;
- escalation;
- training;
- regulatory compliance.
Principal Officer / Designated Director
The Principal Officer has a critical reporting and implementation role.
FIU guidance states that the Principal Officer should be at management level and should be responsible for implementation of obligations concerning record-keeping, CDD, transaction monitoring and reporting.
25. Three Lines of Defence
A modern bank's AML framework can be understood as:
First line — Business/Operations
- account opening;
- customer interaction;
- transaction processing;
- initial red flags.
Second line — Compliance/AML
- customer risk assessment;
- transaction monitoring;
- investigation;
- sanctions screening;
- STR decision;
- regulatory reporting.
Third line — Internal Audit
Independent testing of:
- AML controls;
- compliance systems;
- effectiveness;
- governance;
- regulatory adherence.
RBI's KYC framework expressly contemplates independent evaluation and internal/concurrent audit of KYC/AML policies and procedures.
26. Important AML/CFT Red Flags
A bank should pay particular attention to:
Customer-related
- unwillingness to provide KYC;
- inconsistent identity information;
- complex ownership;
- unexplained beneficial owner;
- nominee/shareholder structures lacking economic rationale;
- high-risk jurisdiction.
Transaction-related
- sudden large credits;
- rapid movement of funds;
- round-number transactions;
- multiple cash deposits;
- structuring below thresholds;
- dormant account suddenly becoming active;
- transactions inconsistent with profile;
- circular transactions;
- unexplained foreign remittances.
Behavioural
- customer refuses to explain transaction;
- contradictory explanations;
- repeated changes in address/business;
- unnecessary involvement of third parties.
27. Case Law
Now we come to the most important part for a law examination, banking compliance interview, LLB/LLM paper or compliance memo.
Case 1 — Vijay Madanlal Choudhary v. Union of India
Supreme Court of India, 27 July 2022, 2022 INSC 757
This is the leading constitutional case on PMLA.
The Supreme Court considered challenges to several provisions of the PMLA concerning:
- Section 3;
- attachment;
- search and seizure;
- arrest;
- bail;
- burden of proof;
- summons;
- ED investigation;
- ECIR;
- Special Courts.
The Court substantially upheld the validity of the challenged PMLA framework, including the ED's statutory powers and the stringent bail framework under Section 45 as it stood after amendment.
Importance for banks
Although the case was principally about the powers of the Enforcement Directorate rather than ordinary bank KYC procedures, it is important because a bank's AML reporting may become part of a larger PMLA investigation.
It establishes the seriousness with which Indian law treats money laundering as an economic offence.
Current status
The 2022 judgment is currently operative, but review petitions are pending. On 20 August 2026, the Supreme Court reconstituted the Bench hearing those review proceedings.
Therefore, compliance professionals should monitor developments closely.
28. Case 2 — Nikesh Tarachand Shah v. Union of India
Supreme Court, 2017
This case concerned the constitutional validity of the stringent twin conditions for bail under Section 45 PMLA.
The Supreme Court held the then-existing formulation unconstitutional, particularly in light of Articles 14 and 21.
The decision is historically important because Parliament subsequently amended the relevant statutory framework, and the Supreme Court in Vijay Madanlal Choudhary upheld the amended position.
AML lesson
The case illustrates that:
AML enforcement must operate within constitutional limitations.
Strong AML legislation does not mean that fundamental rights disappear.
29. Case 3 — M/s S.A. Enterprises v. Reserve Bank of India
Allahabad High Court, 29 April 2026
This is particularly interesting from a banking-compliance perspective.
The petitioner maintained a bank account into which ₹23 lakh was credited. The bank froze the account because it considered the transaction suspicious.
The bank attempted to rely on Section 12(2) PMLA.
The High Court held that Section 12 does not itself authorise a bank to freeze a customer's account merely because the bank considers a transaction suspicious. The Court found that the bank had effectively undertaken its own investigation and frozen the account without sufficient legal basis in the circumstances.
The Court specifically noted that Section 12 concerns reporting-entity record-keeping and confidentiality and does not itself provide a general power for a bank to freeze an account.
Why this case is important
This gives an important compliance principle:
AML suspicion does not automatically equal unlimited banking power.
A bank must distinguish between:
- monitoring a transaction;
- filing an STR;
- restricting/closing an account under applicable regulatory/legal provisions; and
- freezing assets pursuant to competent statutory authority/order.
These are legally distinct actions.
30. Case 4 — Binoy Viswam v. Union of India
Supreme Court, 2017
This case concerned the Aadhaar/PAN linking requirement and the interaction between banking/KYC requirements and constitutional rights.
It is relevant to AML compliance because KYC measures must be implemented consistently with applicable privacy and constitutional principles.
The larger lesson is:
KYC is a regulatory necessity, but collection and use of customer information must remain within the legal framework governing privacy, data and identity.
31. Case 5 — Kalyan Singh v. Union of India / PMLA jurisprudence on proceeds of crime
A recurring principle in PMLA litigation is that money laundering is connected to the existence and handling of "proceeds of crime" arising from a scheduled offence.
This is important for banks because a suspicious transaction should not be mechanically equated with money laundering.
There must be a legally relevant connection with the statutory AML framework.
The Supreme Court's later PMLA jurisprudence has repeatedly emphasised the significance of the "proceeds of crime" concept.
32. The banking lesson from the case law
The cases collectively establish a useful distinction:
| Bank action | Legal concept |
|---|---|
| Identify customer | KYC/CDD |
| Identify beneficial owner | AML |
| Assess customer risk | Risk-based AML |
| Monitor transactions | Ongoing CDD |
| Identify suspicious activity | AML monitoring |
| File STR | PMLA/FIU obligation |
| Screen sanctions | CFT/UAPA |
| Freeze under statutory order | Legal enforcement mechanism |
| ED investigation | PMLA enforcement |
| Criminal conviction | Judicial determination |
The bank should not assume the role of the criminal court.
33. AML vs KYC vs CDD vs CFT
These terms are often confused.
KYC
Know Your Customer
Primarily concerned with identifying and understanding the customer.
CDD
Customer Due Diligence
Broader process involving:
- customer identification;
- verification;
- beneficial ownership;
- purpose;
- risk assessment.
AML
Anti-Money Laundering
Framework designed to prevent and detect laundering of criminal proceeds.
CFT
Countering Financing of Terrorism
Framework designed to prevent funds/resources from reaching terrorists or terrorist organisations.
Sanctions compliance
Ensures the bank does not provide prohibited financial services to designated persons/entities.
34. Practical AML compliance lifecycle
A useful way to remember the entire process is:
ONBOARD
↓
IDENTIFY
↓
VERIFY
↓
UNDERSTAND BUSINESS
↓
IDENTIFY BENEFICIAL OWNER
↓
RISK-RATE
↓
SCREEN SANCTIONS/PEP
↓
MONITOR TRANSACTIONS
↓
GENERATE ALERT
↓
INVESTIGATE
↓
ESCALATE
↓
FILE STR / OTHER REPORT
↓
CONTINUE MONITORING / TAKE LAWFUL ACTION
This is the operational heart of AML compliance.
35. Example — Complete AML scenario
Suppose ABC Exports Pvt. Ltd. opens a current account.
Step 1 — KYC
Bank obtains:
- incorporation documents;
- PAN;
- registered address;
- directors;
- authorised signatories;
- beneficial-owner information.
Step 2 — Business understanding
ABC claims:
"We export agricultural equipment."
Expected annual turnover:
₹5 crore.
Step 3 — Risk assessment
Bank determines:
Medium risk.
Step 4 — Transaction pattern
After six months:
₹40 crore received from unrelated foreign companies.
Immediately after receipt:
₹38 crore transferred to another offshore entity.
Step 5 — Alert
Transaction monitoring generates an alert because:
- turnover is inconsistent with profile;
- counterparties are unrelated;
- transactions are cross-border;
- money moves rapidly;
- economic purpose is unclear.
Step 6 — Investigation
Bank requests:
- invoices;
- bills of lading;
- contracts;
- beneficial-owner information;
- source of funds;
- purpose of payment.
Step 7 — Customer explanation
ABC provides documents, but investigation discovers:
Seller and buyer are ultimately controlled by the same person.
This creates a significant AML red flag.
Step 8 — Compliance decision
The Principal Officer considers whether the circumstances satisfy the STR standard.
If satisfied:
STR → FIU-IND.
Step 9 — Confidentiality
The bank must not improperly tell ABC:
"We filed an STR against you."
Step 10 — Further action
Depending on facts and applicable law:
- enhanced monitoring;
- restriction/closure where legally justified;
- cooperation with authorities;
- preservation of records.
36. What constitutes good AML compliance?
A bank with good AML compliance should be able to answer five questions about a transaction:
1. Who?
Who is the customer and beneficial owner?
2. What?
What transaction is taking place?
3. Why?
What is its legitimate economic purpose?
4. Where?
Where are the funds coming from and going?
5. Whether?
Is the transaction consistent with the customer's risk profile?
If the bank cannot answer these questions, the AML framework has a weakness.
37. AML compliance failures
Typical bank failures include:
- opening accounts without adequate KYC;
- failure to identify beneficial owners;
- inadequate risk classification;
- failure to update KYC;
- inadequate transaction monitoring;
- failure to investigate alerts;
- failure to file STRs;
- late STR filing;
- tipping-off;
- poor sanctions screening;
- inadequate record keeping;
- failure to monitor correspondent banking;
- ineffective money-mule detection;
- over-reliance on automated systems;
- excessive manual overrides;
- inadequate employee training.
38. Important principle: STR is not based on a fixed amount
This is frequently tested.
Suppose:
A. ₹5 crore legitimate property transaction
may not necessarily be suspicious.
Whereas:
B. ₹2 lakh suspicious transfer through multiple unrelated accounts
may justify an STR.
Therefore:
Suspicion depends on circumstances, not merely amount.
FIU guidance specifically recognises suspicious transactions irrespective of value where the statutory suspicion criteria are met.
39. AML/CFT and technology
Modern banks increasingly use:
- transaction-monitoring engines;
- AI/ML models;
- sanctions-screening software;
- graph analytics;
- behavioural analytics;
- device intelligence;
- adverse-media screening;
- network analysis.
But technology does not eliminate legal responsibility.
RBI specifically requires banks to identify ML/TF risks associated with new products, delivery mechanisms and technologies and to undertake risk assessments before deploying them.
40. FATF and international standards
Indian AML/CFT compliance also operates within the broader international AML architecture, particularly the Financial Action Task Force (FATF) framework.
The FATF approach emphasises:
- risk-based AML;
- CDD;
- beneficial ownership transparency;
- suspicious transaction reporting;
- sanctions;
- international cooperation;
- targeted financial sanctions;
- terrorist-financing prevention.
RBI's KYC Direction expressly incorporates consideration of FATF statements and requires enhanced due diligence for certain high-risk jurisdictions.
41. AML/CFT compliance — concise legal framework
For an examination, you can remember:
PMLA
Creates the legal AML offence and reporting-entity obligations.
PML Rules
Provide detailed operational reporting and record-keeping requirements.
RBI KYC Direction
Translates AML/CFT obligations into practical banking procedures.
FIU-IND
Receives and analyses financial intelligence reports.
ED
Investigates/enforces PMLA in appropriate cases.
UAPA
Provides an important framework for terrorist financing and sanctions-related freezing obligations.
RBI
Supervises regulated banking entities and prescribes KYC/AML/CFT controls.
42. Key case-law principles to remember
| Case | Principle |
|---|---|
| Nikesh Tarachand Shah v. Union of India (2017) | Original PMLA twin bail conditions declared unconstitutional |
| Vijay Madanlal Choudhary v. Union of India (2022) | Substantially upheld amended PMLA framework and ED powers |
| S.A. Enterprises v. RBI (Allahabad HC, 2026) | Section 12 PMLA does not itself give a bank a general power to freeze an account merely because it regards a transaction as suspicious |
| Binoy Viswam v. Union of India (2017) | KYC/identity requirements must operate within constitutional/legal framework |
The Vijay Madanlal position should presently be read with the important qualification that review proceedings are pending before the Supreme Court in 2026.
43. Conclusion
AML/CFT compliance in banking is not merely a KYC-documentation exercise. It is a continuous risk-management system covering the entire customer relationship:
Identification → Verification → Beneficial Ownership → Risk Assessment → Screening → Transaction Monitoring → Investigation → STR/Regulatory Reporting → Ongoing Monitoring
The fundamental principle is that banks must prevent themselves from becoming vehicles for:
- laundering criminal proceeds;
- terrorist financing;
- sanctions evasion;
- proliferation financing;
- fraud-related fund movement; and
- concealment of beneficial ownership.
At the same time, the recent S.A. Enterprises decision illustrates an equally important legal safeguard: a bank's AML obligations do not automatically confer unlimited investigative or freezing powers. The bank must act within the authority granted by the PMLA, RBI directions and other applicable laws.
For a law/banking examination, the strongest way to frame the subject is:
"AML/CFT compliance represents the intersection of preventive banking regulation, financial intelligence, criminal law, sanctions law, regulatory supervision and constitutional safeguards."

comments