Aml/Cft Micro-Issues .
1. KYC versus AML: are they the same?
No.
KYC is principally about establishing who the customer is and understanding the customer, whereas AML is broader and encompasses prevention, detection, monitoring and reporting of money laundering.
A useful distinction is:
KYC = identification and understanding of the customer.
AML = identification, prevention, monitoring and reporting of financial crime risks.
The Supreme Court in Pragya Prasun v. Union of India, 2025 INSC 599 described the statutory framework under which financial/banking institutions conduct customer identity verification, maintain records and report information to FIU-IND, with RBI's KYC Directions providing the CDD and digital-KYC framework.
Micro-issue
A financial institution cannot reasonably argue:
"KYC was completed, therefore AML requirements were satisfied."
A customer can have perfectly valid identity documents and nevertheless present a significant money-laundering risk.
2. Is incomplete KYC automatically money laundering?
No.
This is a critical distinction.
A KYC deficiency may constitute:
- a regulatory violation;
- a compliance deficiency;
- grounds for restricting/ending a relationship in appropriate circumstances;
but it does not automatically establish the PMLA offence of money laundering.
The criminal offence under Section 3 PMLA requires the statutory ingredients of money laundering, including involvement with proceeds of crime and the activities specified in Section 3.
Therefore:
KYC violation ≠ automatically Section 3 PMLA offence.
This distinction becomes important where a bank or compliance officer is accused merely because an account subsequently became involved in a fraud.
A 2025 Gujarat High Court decision concerning a cooperative bank emphasized that allegations of negligent or permissive account opening, without allegations/evidence that the bank or its officers obtained or benefited from proceeds of crime or facilitated the laundering with the requisite mental element, require careful examination rather than automatically translating regulatory negligence into money-laundering liability.
3. Can a bank be liable merely because a fraudster used its account?
Again, not automatically.
This is one of the most important micro-issues for banks.
Consider:
Fraudster → opens account → receives ₹50 lakh → transfers money elsewhere.
The mere fact that the account was maintained by Bank X does not, by itself, mean Bank X committed money laundering.
The legal questions become:
- Did the bank know or have reason to suspect the activity?
- Were KYC/CDD obligations followed?
- Were suspicious transactions detected?
- Was appropriate monitoring undertaken?
- Was there deliberate facilitation?
- Did the bank or responsible person participate in the laundering?
- Did the bank obtain or benefit from proceeds of crime?
This distinction is particularly relevant when analysing the liability of regulated entities and their officers.
4. Beneficial ownership — the "real person behind the customer"
Beneficial ownership is one of the most important AML micro-issues.
Suppose:
Company A → 70% owned by Company B → 80% controlled by Person X
The institution cannot simply stop its inquiry at Company B.
The AML question is:
Who ultimately owns or controls the customer?
Validation should examine:
- ownership chain;
- control rights;
- voting rights;
- shareholders;
- trustees/beneficiaries where relevant;
- persons exercising ultimate control;
- unusual ownership structures.
Why it matters
Shell companies and layered ownership arrangements can be used to disguise the ultimate beneficiary of funds.
Therefore, beneficial-owner verification is not merely a documentation exercise. It is an anti-concealment control.
5. PEPs — does being a PEP mean the customer is suspicious?
No.
Being a Politically Exposed Person (PEP) is a risk factor, not proof of criminality.
The correct AML approach is:
PEP status → risk assessment → enhanced due diligence where required → appropriate ongoing monitoring.
A bank should not treat:
"PEP = criminal"
or
"PEP = STR"
as a legally correct proposition.
The risk-based approach requires assessment of the customer's circumstances, source of wealth/funds, transactions and other relevant factors.
6. High-risk customer does not automatically mean STR
This is another frequent micro-error.
High risk ≠ suspicious transaction.
For example, a customer may legitimately be:
- involved in international trade;
- operating in a high-risk jurisdiction;
- a PEP;
- involved in a cash-intensive business.
That may justify EDD and enhanced monitoring, but it does not automatically establish suspicious activity.
Conversely, a customer classified as "low risk" can conduct a transaction that is suspicious.
Thus:
Customer risk rating and transaction suspicion are separate analytical questions.
7. Does a transaction have to exceed a monetary threshold to be suspicious?
No.
Suspicion is not necessarily determined by amount.
An apparently small transaction can be suspicious when it forms part of a pattern.
For example:
₹95,000 + ₹95,000 + ₹95,000 + ₹95,000
may be more significant than one ₹3 lakh transaction if the pattern indicates deliberate structuring.
RBI's AML/CFT framework specifically emphasizes attention to complex, unusually large transactions and unusual patterns lacking an apparent lawful purpose, together with appropriate monitoring and STR reporting.
8. Attempted transactions
A particularly important micro-issue is whether an attempted but unsuccessful transaction can be suspicious.
Yes.
AML reporting is not necessarily confined to completed transactions.
RBI has expressly required certain reporting entities to report attempted transactions where there are reasonable grounds for believing that the transaction involves proceeds of crime, irrespective of amount.
Therefore:
"The transaction failed, so there is no AML issue"
is an unsafe assumption.
The circumstances surrounding the attempt may themselves be significant.
9. When must an STR be filed?
The basic conceptual sequence is:
Detection → investigation → formation of reasonable suspicion → STR decision → reporting within the prescribed period
The institution should maintain evidence showing:
- who identified the activity;
- what triggered the review;
- what transactions were examined;
- customer profile;
- source/use of funds;
- connected accounts;
- investigator's reasoning;
- Principal Officer's decision;
- date of decision;
- date of reporting.
RBI materials have emphasized that the Principal Officer should record reasons for treating a transaction or series of transactions as suspicious and that the STR should be filed within the prescribed period after the conclusion of suspicion.
10. "No STR" decision is itself an AML control
This is often overlooked.
Suppose the system generates 10,000 alerts and investigators close 9,900.
The regulatory question isn't simply:
"Were alerts closed?"
It is:
"Why were they closed?"
A defensible AML programme therefore needs adequate negative decision documentation.
For example:
Alert generated → investigator examines transaction → obtains customer profile/source-of-funds information → reviews related transactions → determines legitimate explanation → records rationale → closes alert.
A bare notation such as:
"No issue"
is weak evidence of effective AML investigation.
11. Can the bank tell the customer that an STR was filed?
Generally, no.
This is the fundamental anti-tipping-off principle.
The customer should not be informed that:
- an STR has been filed;
- an STR is being considered;
- FIU/ED/enforcement authorities have been alerted;
where disclosure is prohibited by the applicable framework.
The practical micro-issue is therefore:
How can customer service staff respond to questions about account restrictions without inadvertently tipping off the customer?
The institution should have approved communication scripts and escalation procedures.
12. Can a bank freeze a suspicious account?
This issue has become particularly important because of recent Indian litigation.
The PMLA/RBI framework permits various forms of action in relation to deficient KYC and suspicious activity, but the precise legal basis for freezing an account merely because it is considered suspicious is not identical to the statutory mechanisms for attachment/freezing exercised by competent authorities.
A significant 2025 Kerala High Court decision considered this issue in Anwar Sadath Puthar Kuzhikkal v. Union of India.
The Court held that banks could temporarily freeze suspicious accounts in appropriate circumstances for a reasonable period, considering the RBI framework and the need to prevent suspected proceeds from being withdrawn, while also limiting the duration and emphasizing law-enforcement verification. The Court discussed a three-month period in the circumstances before it.
But this should not be read as an unrestricted power to indefinitely freeze an account.
That distinction is critical.
13. KYC non-compliance versus suspicious-transaction freezing
These are different situations.
Situation A — KYC not updated
The applicable RBI KYC framework may provide mechanisms for:
- notice;
- KYC updation;
- restriction/temporary cessation;
- eventual closure in appropriate circumstances.
Situation B — suspicious transactions
The institution may have obligations to:
- monitor;
- investigate;
- report;
- take appropriate risk-control measures;
- cooperate with competent authorities.
The legal basis and procedural requirements for account restrictions can be different.
The Kerala High Court specifically noted that provisions concerning KYC non-completion/periodic updation did not themselves directly resolve the issue of freezing suspicious accounts.
14. Can an STR be filed without proving the predicate offence?
Yes, conceptually.
An STR is a suspicion-based regulatory report, not a criminal conviction.
The bank does not conduct an ED-style investigation to conclusively establish:
"This customer committed the scheduled offence."
Its role is to identify and report transactions giving rise to the required level of suspicion under the applicable framework.
This is why transaction monitoring should focus on risk indicators and reasonable grounds, rather than requiring proof beyond reasonable doubt.
15. AML investigation versus criminal investigation
The distinction is important.
Bank/compliance investigation
Purpose:
Determine whether the activity warrants internal escalation and regulatory reporting.
Enforcement investigation
Purpose:
Establish evidence relevant to a criminal offence and identify persons/assets connected with the offence.
Court
Purpose:
Determine legal liability based on the evidence and applicable statutory requirements.
Therefore, an AML investigator should not attempt to replicate the entire investigative function of the Enforcement Directorate.
16. Source of funds versus source of wealth
These are frequently confused.
Source of Funds (SoF)
Where did this particular money come from?
Example:
₹20 lakh received from sale of property.
Source of Wealth (SoW)
How did the customer accumulate overall wealth?
Example:
Wealth accumulated through 20 years of business ownership and investments.
For high-risk customers, these concepts can be particularly important.
A customer may legitimately have:
₹5 crore net worth
but a particular ₹2 crore transaction may still require explanation regarding its immediate source of funds.
17. Suspicious transaction can exist without cash
Absolutely.
AML monitoring must not equate:
cash = suspicious
and
non-cash = safe.
Money laundering can occur through:
- bank transfers;
- securities;
- trade transactions;
- digital payment systems;
- virtual/digital assets where applicable;
- shell-company structures;
- cross-border transfers;
- loans;
- investments;
- property transactions.
SEBI's AML/CFT framework, for example, expressly requires intermediaries to develop procedures for recognizing and reporting suspicious transactions and identifies numerous non-cash suspicious patterns.
18. Mule accounts
A mule account is an account used to receive, move or transfer funds for another person, often in connection with fraud or other illicit activity.
Indicators can include:
- newly opened account;
- sudden high-volume credits;
- immediate outward transfers;
- multiple unrelated counterparties;
- transaction activity inconsistent with stated occupation;
- common device/IP/contact information across apparently unrelated customers;
- rapid depletion of received funds.
This is both an AML and fraud-risk issue.
RBI's framework has specifically addressed monitoring of unusual activity and money-mule accounts in its banking guidance.
19. Sanctions screening and CFT
AML/CFT is not only about money laundering.
CFT = Combating the Financing of Terrorism.
The financial institution must therefore consider whether funds could be connected to:
- designated terrorist individuals;
- designated entities;
- terrorist organizations;
- prohibited financing activity.
RBI has required banks to maintain appropriate mechanisms for terrorist-linked accounts, update relevant designated-person/entity lists, screen new customers and existing accounts, and report relevant information.
The RBI's 2024 KYC amendment also specifically incorporated changes relating to implementation of Section 51A of UAPA.
20. Sanctions false positives
A name match does not automatically mean a sanctions hit.
Example:
Customer: "Mohammed Ahmed"
Sanctions list:
"Mohammad Ahmad"
The compliance team needs to investigate identifiers such as:
- date of birth;
- nationality;
- address;
- passport;
- entity information;
- aliases.
The opposite error—treating every potential match as a false positive without sufficient investigation—is equally dangerous.
21. Digital KYC/V-CIP
Digital onboarding creates its own AML micro-issues:
- identity authenticity;
- liveness;
- face matching;
- document integrity;
- geolocation;
- audit trail;
- video storage;
- spoofing;
- duplicate identities;
- data integrity.
The Supreme Court's Pragya Prasun judgment is particularly relevant because it discusses the statutory KYC framework and RBI's V-CIP/digital-KYC regime.
Thus:
Digital KYC is not a relaxation of CDD; it is another legally regulated method of performing CDD.
22. Outsourcing AML functions
An institution may outsource technology or operational functions, but outsourcing does not necessarily transfer the regulatory responsibility.
For example:
Bank → third-party AML screening vendor
If the vendor fails to screen sanctions lists correctly, the bank cannot simply say:
"The vendor was responsible."
The institution needs appropriate:
- vendor due diligence;
- contractual controls;
- service-level requirements;
- testing;
- audit rights;
- data-quality controls;
- oversight;
- contingency arrangements.
23. Reliance on automated AML systems
Automation does not eliminate human responsibility.
A system can:
- generate too many alerts;
- miss relevant transactions;
- use defective thresholds;
- receive incomplete data;
- incorrectly suppress alerts.
Therefore, model/system validation should examine:
Data → Rule → Alert → Investigator → Decision
rather than merely asking:
"Is the AML software certified?"
24. Data-quality failure can become an AML failure
This is a particularly important modern micro-issue.
Suppose:
- core banking system contains customer occupation;
- AML system receives customer name but not occupation;
- transaction-monitoring rules depend on occupation.
The scenario may technically function but produce poor risk detection.
Therefore, AML validation should test:
Completeness + accuracy + timeliness + integrity of AML data feeds.
25. Record keeping
PMLA compliance requires maintenance of prescribed records.
The practical micro-issue is not merely:
"Do we have records?"
but:
"Can we retrieve a complete and reliable audit trail when required?"
Validation should therefore test:
- retrieval;
- retention;
- alteration controls;
- access logs;
- version history;
- data integrity;
- linkage between customer and transaction records.
26. Confidentiality of AML information
AML information should be handled on a strict need-to-know basis.
Particular risk areas include:
- customer-service staff;
- relationship managers;
- branch personnel;
- outsourced staff;
- IT administrators;
- vendors.
The institution should control access to:
- STR information;
- investigation notes;
- sanctions alerts;
- law-enforcement requests;
- internal AML investigations.
This reduces tipping-off and confidentiality risks.
27. AML training
Training is not merely an HR requirement.
A good AML training programme should be role-specific.
Teller/branch staff
Focus on:
- suspicious behaviour;
- identity documents;
- cash patterns;
- mule accounts.
Relationship managers
Focus on:
- customer risk;
- source of wealth/funds;
- PEPs;
- beneficial ownership.
AML investigators
Focus on:
- transaction analysis;
- linked transactions;
- STR decisions;
- documentation.
Senior management
Focus on:
- risk appetite;
- regulatory obligations;
- governance;
- significant AML risks.
28. Principal Officer — an important micro-issue
The Principal Officer should not merely be a nominal designation.
The position needs adequate:
- authority;
- access to information;
- independence;
- resources;
- escalation ability;
- access to senior management.
If the Principal Officer receives an AML alert but cannot obtain necessary customer information from business units, the AML governance model is structurally weak.
29. Board responsibility
The Board's role is generally not to investigate individual transactions.
Its role is governance:
- approve AML policy;
- understand institutional AML risk;
- ensure adequate resources;
- receive significant compliance reporting;
- challenge material deficiencies;
- ensure remediation.
The distinction is:
Board oversight ≠ operational investigation.
30. Important PMLA case-law principles
1. Vijay Madanlal Choudhary v. Union of India
The Supreme Court's landmark PMLA decision remains foundational on the statutory architecture of money laundering, proceeds of crime, investigation and bail. The judgment should be read alongside later Supreme Court decisions rather than treated as the final word on every procedural question.
2. Nikesh Tarachand Shah v. Union of India
The Supreme Court invalidated the then-existing formulation of the twin bail conditions under Section 45. The subsequent legislative amendment and later Vijay Madanlal Choudhary decision mean that this case has to be understood historically and in its amended statutory context.
3. Pragya Prasun v. Union of India, 2025 INSC 599
Important for KYC, digital KYC and V-CIP, and for understanding the statutory/regulatory relationship between PMLA, PML Rules and RBI's KYC Directions.
4. Anwar Sadath Puthar Kuzhikkal v. Union of India, Kerala HC, 2025
Important for the practical issue of bank account freezing in the context of suspicious transactions, including the limits and duration of temporary restrictions.
5. Gujarat Mercantile Co-operative Bank Ltd. v. State of Gujarat, Gujarat HC, 2025
Important for examining the distinction between banking/KYC negligence and actual PMLA liability, particularly where allegations concern accounts allegedly used as conduits for proceeds of crime.
31. Practical AML/CFT micro-issue matrix
| Micro-issue | Correct AML question |
|---|---|
| Incomplete KYC | Is the deficiency regulatory, or does it indicate something more? |
| High-risk customer | Has appropriate EDD been performed? |
| PEP | Has risk-based EDD/monitoring been applied? |
| Beneficial owner | Who ultimately owns/controls the customer? |
| STR | Was suspicion properly investigated and documented? |
| No-STR decision | Is the closure rationale defensible? |
| Attempted transaction | Does the attempt itself indicate suspicious activity? |
| Mule account | Were transaction patterns inconsistent with customer profile detected? |
| Sanctions hit | Was the potential match properly investigated? |
| Account freeze | What is the precise statutory/regulatory authority for the restriction? |
| Digital KYC | Does the process satisfy CDD requirements? |
| AML vendor | Does outsourcing affect the institution's regulatory responsibility? |
| AML model | Are data, scenarios and thresholds functioning effectively? |
| Record keeping | Can the institution reconstruct the transaction and decision trail? |
| Tipping off | Could customer communication reveal AML reporting/investigation? |
| CFT | Are terrorist-financing and designated-person risks separately addressed? |
32. The most important conceptual distinction
For AML/CFT compliance in India, five concepts should never be collapsed into one:
KYC deficiency
↓
AML risk
↓
Suspicion
↓
STR/reporting
↓
PMLA criminal liability
They are related, but they are not legally synonymous.
For example:
Poor KYC may create AML risk.
But:
AML risk does not automatically equal suspicion.
And:
Suspicion/STR does not itself establish guilt.
And:
An STR does not itself prove the Section 3 PMLA offence.
Finally:
PMLA criminal liability requires the statutory ingredients to be established.
That separation is one of the most important principles when designing, auditing or defending an AML/CFT compliance programme.
Current-law note: Because the RBI KYC framework and PML Rules have been amended recently—including amendments in 2024 and 2025—any opinion, audit finding or litigation strategy should be checked against the version of the rules/directions applicable on the relevant transaction date.

comments