Banks as the First Line of Defence: The Complete PMLA Compliance Framework for Indian Banking
Indian banks occupy two legally distinct positions under the Prevention of Money-Laundering Act, 2002. They are reporting entities required to identify customers, understand beneficial ownership, monitor transactions, preserve records and report prescribed activity to the Financial Intelligence Unit–India. They may also become witnesses, document custodians, account-freezing intermediaries, secured creditors or third-party claimants when the Enforcement Directorate investigates and attaches alleged proceeds of crime.
Confusing these roles produces two opposite errors. A suspicious transaction report does not prove money-laundering, and a bank is not expected to adjudicate criminal guilt. But banking confidentiality cannot be used to avoid a lawful reporting, production or restraint duty. The correct approach is risk-based vigilance supported by documented decisions, accurate statutory reporting and procedural discipline when coercive orders arrive.
The controlling legal framework
Banking AML duties arise from an interlocking framework:
1. the Prevention of Money-Laundering Act, 2002, particularly Sections 2, 11A, 12, 12A, 13 and 14;
2. the Prevention of Money-laundering (Maintenance of Records) Rules, 2005, as amended;
3. the Reserve Bank of India (Know Your Customer) Direction, 2016, as amended from time to time; and
4. directions and guidance issued by the Financial Intelligence Unit–India concerning detection and reporting.
The PMLA supplies the statutory obligation. The Rules specify reportable transactions, customer-due-diligence processes, beneficial-ownership standards, internal responsibility and reporting timelines. RBI directions translate those duties into a continuing supervisory framework for regulated entities. A bank must read them cumulatively rather than treating completion of an account-opening form as complete AML compliance.
Banks as reporting entities
Section 2(1)(wa) defines a “reporting entity” to include a banking company, financial institution, intermediary and a person carrying on a designated business or profession. A bank therefore has direct statutory duties; it is not merely assisting the Enforcement Directorate.
Governance operates at two levels. The Designated Director bears institutional responsibility for overall compliance. The Principal Officer acts as the central point for furnishing prescribed information to the Director, FIU-IND. Board-approved policies, risk allocation, escalation channels, staff training, independent testing and auditable decision records are necessary because compliance cannot be outsourced entirely to software or a vendor.
Customer due diligence begins before risk monitoring
Section 11A requires verification of the identity of clients and beneficial owners through prescribed modes. Rule 9 and the RBI KYC Direction then require a risk-based Customer Acceptance Policy and Customer Identification Procedure.
For an individual, the bank must establish identity and address through legally permitted documents or digital processes. For a legal person, collecting incorporation papers is insufficient. The bank must understand who ultimately owns or controls the customer, who is authorised to act, the purpose and intended nature of the relationship, and whether the structure is consistent with the stated business.
Beneficial ownership is especially important for layered companies, partnerships, trusts and unincorporated associations. The applicable ownership thresholds and control tests must be taken from the current Rules and RBI Direction. Where no natural person is identified through ownership or control, the prescribed senior-managing-official fallback is not permission to stop inquiry prematurely; the bank should retain the analysis explaining why the earlier tests did not identify a person.
KYC is continuous, not a one-time event
The risk picture may change after onboarding. Banks must conduct ongoing due diligence to ensure that transactions remain consistent with the customer’s business, risk profile and known source of funds or wealth where appropriate. Periodic KYC updating must follow the customer’s risk category and current RBI requirements.
The RBI’s 2025 amendments added customer-protection measures for KYC updating, including additional facilities for self-declarations and an extended opportunity for low-risk individual customers whose periodic update had fallen due, while requiring continued monitoring. These accommodations do not abolish KYC; they regulate how a bank updates it without unnecessarily excluding a low-risk customer from banking services.
Enhanced due diligence is required where risk is higher—for example, complex or unusually large transactions, opaque ownership, non-face-to-face relationships, politically exposed persons as defined in the applicable framework, high-risk jurisdictions, correspondent banking, cash-intensive activity or transactions inconsistent with the customer profile. Risk categorisation must be reasoned and periodically reviewed; nationality, profession or geography alone should not become a crude substitute for assessment.
What banks must monitor
Section 12 requires records sufficient to reconstruct prescribed transactions and obliges reporting entities to furnish information to FIU-IND in the prescribed manner. Rule 3 identifies categories including specified cash transactions, integrally connected cash transactions, receipts by covered non-profit organisations, cross-border wire transfers above the prescribed threshold, transactions involving counterfeit currency or forgery, specified immovable-property transactions and suspicious transactions.
Suspicion is broader than a cash threshold. A transaction may be reportable regardless of whether it is cash, completed or merely attempted. The Rules focus on activity that gives reasonable grounds to suspect proceeds of a scheduled offence, appears unusually complex or lacks economic rationale or bona fide purpose, or gives reasonable grounds to suspect terrorist financing.
Useful red flags include rapid movement through newly opened accounts, funnel accounts, unexplained third-party receipts, round-number transfers with immediate withdrawal, dormant accounts suddenly receiving large credits, multiple entities sharing controllers and contact data, trade payments inconsistent with goods or invoices, circular transfers, mule-account patterns, unexplained changes in beneficial ownership and repeated transactions designed to remain below a reporting threshold.
A red flag is a trigger for inquiry, not a finding of guilt. The bank should obtain proportionate information, consider the complete relationship, document its reasoning and decide whether the statutory suspicion threshold has been reached.
STRs, CTRs and reporting discipline
The Principal Officer must ensure that reports are accurate, timely and complete. Cash Transaction Reports and other periodic reports follow the timelines prescribed by the Rules and FIU-IND reporting formats. A Suspicious Transaction Report must be furnished promptly—under the Rules, not later than seven working days after the reporting entity is satisfied that the transaction is suspicious.
The internal alert date is not always the legal satisfaction date. Automated systems may generate many false positives. But a bank cannot use prolonged internal review to defeat timely reporting. It should maintain an audit trail showing alert generation, investigation, escalation, the date suspicion crystallised, reasons for filing or closure, quality review and any subsequent supplemental report.
Reporting must remain confidential. The customer or an unauthorised employee should not be told that an STR was filed or that FIU-IND sought related information. This anti-tipping-off rule protects the investigation and the reporting system. It does not justify denying ordinary customer service without a separate lawful basis.
Record retention
Section 12 distinguishes transaction records from customer-identity and relationship records. Records enabling reconstruction of transactions must generally be maintained for five years from the transaction date. Identity records, account files and business correspondence must generally be preserved for five years after the business relationship ends or the account is closed, whichever applies under the statutory text.
Retention must preserve accessibility and integrity, not merely data existence. The bank should be able to retrieve account-opening documents, beneficial-ownership analysis, transaction data, alerts, review notes, reports, supporting correspondence and the identity of employees who made material decisions. Electronic retention should include access controls, logs, legal holds and defensible migration practices.
FIU-IND, RBI and ED perform different functions
FIU-IND receives, analyses and disseminates financial intelligence and exercises statutory compliance powers through the Director under Sections 12A and 13. RBI supervises regulated banks under banking law and its KYC Direction. ED investigates alleged money-laundering, traces proceeds, exercises statutory search, seizure, freezing, attachment and arrest powers, and prosecutes Section 3 offences.
An STR is intelligence, not an FIR, ECIR, attachment order or proof at trial. FIU-IND may disseminate information to an appropriate agency, but the recipient must independently act under its governing statute. Equally, a bank’s RBI compliance does not immunise it from Section 13 action if its PMLA reporting systems fail.
Consequences of non-compliance
Under Section 13, the Director may inquire into a reporting entity’s compliance and may issue a warning, direct compliance with specified instructions, require periodic reports or impose a monetary penalty of not less than ₹10,000 and up to ₹1 lakh for each failure. Orders are appealable through the statutory route.
Section 14 protects a reporting entity, its directors and employees from civil or criminal proceedings for furnishing information under Section 12 in good faith. The protection rewards honest statutory reporting; it does not cover bad faith, fabrication or unrelated misconduct.
RBI may separately impose supervisory or monetary consequences under banking legislation and its directions. The same control failure can therefore produce more than one regulatory response, although each authority must remain within its legal powers.
When ED seeks bank records
Section 50 empowers specified PMLA authorities to summon persons, including officers of reporting entities, to give evidence or produce records. A bank receiving a summons should preserve the requested material, identify the lawful custodian, produce complete records through an authorised officer and retain a record of what was supplied.
The Supreme Court in Vijay Madanlal Choudhary v. Union of India, 2022 INSC 757, upheld the statutory investigative scheme and explained that Section 50 proceedings are judicial proceedings for the limited statutory purposes identified there. The case does not turn every bank employee into an accused. The recipient’s status, scope of summons and privilege or confidentiality objection must be examined from the actual notice and investigation.
Freezing and attachment of bank accounts
The PMLA uses different powers that are often loosely described as an “account freeze”. Section 17 permits search, seizure and, where seizure is impracticable, freezing subject to recorded statutory satisfaction and subsequent procedural requirements. Section 5 concerns provisional attachment of property involved in money-laundering. Section 20 governs retention of property seized or frozen; it is not itself a general independent power to freeze any bank account.
In Opto Circuit India Ltd. v. Axis Bank, 2021 INSC 43, (2021) 6 SCC 707, the Supreme Court set aside an account restraint imposed without compliance with the PMLA’s prescribed procedure. The decision’s enduring principle is statutory fidelity: serious restraint powers must be exercised through the section that confers them and on its stated conditions.
A bank should therefore verify the issuing authority, statutory provision, account and amount, effective date, scope, service and any modification or release order. It should not extend a restraint beyond its text, but it must not permit dealings prohibited by a valid order.
Banks as secured creditors or innocent third parties
A bank may also claim an interest in property attached by ED. In Deputy Director, Directorate of Enforcement v. Axis Bank, 2019 SCC OnLine Del 7854, the Delhi High Court analysed competing claims of secured creditors and PMLA attachment. The judgment distinguishes actually tainted property from property attached as an equivalent-value substitute and emphasises chronology, bona fides and the nature of the creditor’s interest.
There is no safe universal statement that every mortgage defeats PMLA or that every attachment automatically extinguishes a prior security interest. The bank should place the loan sanction, disbursement trail, mortgage creation and registration, valuation, title due diligence, account conduct, default history and absence of collusion before the Adjudicating Authority or competent court. Section 8 notice and appellate remedies should be used promptly.
The limits of bank responsibility
PMLA does not require a bank to prove the predicate offence before filing an STR. Nor does every unusual transaction justify account closure or customer accusation. The institution’s duty is to identify and manage risk, conduct proportionate inquiry, report when the legal threshold is met, preserve records and obey lawful orders.
The Supreme Court’s central rule in Vijay Madanlal remains relevant: “proceeds of crime” must be property derived or obtained from criminal activity relating to a scheduled offence. An unexplained balance or regulatory breach may warrant scrutiny, but it is not automatically laundered property. Banks should avoid describing a customer as guilty in internal or external communication when the evidence establishes only a red flag or unresolved suspicion.
An effective compliance architecture
A legally defensible banking AML programme should contain:
1. board-approved customer acceptance, risk and transaction-monitoring policies;
2. clear Designated Director and Principal Officer accountability;
3. documented beneficial-ownership and source-of-funds analysis;
4. risk-calibrated monitoring with tested scenarios and governance over model changes;
5. a time-controlled alert-to-STR process with recorded reasons;
6. secure record retention and rapid lawful retrieval;
7. sanctions, UAPA and high-risk-jurisdiction controls integrated without conflating distinct laws;
8. staff training tailored to branches, trade finance, correspondent banking, digital channels and investigations;
9. independent audit and remediation tracking; and
10. a protocol for summonses, freezes, attachments, customer communication and third-party claims.
Conclusion
The bank is not the judge of money-laundering, but it is the financial system’s most important statutory observer. Its responsibility begins with knowing the customer and beneficial owner, continues through risk-based monitoring and timely confidential reporting, and extends to preserving and producing reliable evidence.
Good AML compliance is neither indiscriminate suspicion nor mechanical form collection. It is a documented process that distinguishes alerts from legal conclusions, protects legitimate customers, detects misuse early and enables FIU-IND, RBI, ED and the courts to perform their separate functions on trustworthy records.
Sources
Prevention of Money-Laundering Act, 2002, particularly Sections 2(1)(fa), 2(1)(u), 2(1)(wa), 3, 5, 11A, 12, 12A, 13, 14, 17, 20 and 50: https://www.indiacode.nic.in/handle/123456789/15402
Prevention of Money-laundering (Maintenance of Records) Rules, 2005, as amended: https://upload.indiacode.nic.in/showfile?actid=AC_CEN_2_2_00035_200315_1517807326550&filename=The+Prevention+of+Money-laundering+%28Maintenance+of+Records%29+Rules%2C+2005.pdf&type=rule
Reserve Bank of India, Master Direction – Know Your Customer (KYC) Direction, 2016, as amended through 14 August 2025: https://old.rbi.org.in/commonman/English/Scripts/MasterDirection.aspx
Reserve Bank of India (Know Your Customer (KYC)) (Amendment) Directions, 2025, dated 12 June 2025: https://www.rbi.org.in/scripts/NotificationUser.aspx?Id=12866
Vijay Madanlal Choudhary v. Union of India, 2022 INSC 757, (2023) 12 SCC 1: https://api.sci.gov.in/supremecourt/2014/19062/19062_2014_3_1501_36844_Judgement_27-Jul-2022.pdf
Opto Circuit India Ltd. v. Axis Bank, 2021 INSC 43, (2021) 6 SCC 707: https://api.sci.gov.in/supremecourt/2020/24551/24551_2020_33_1501_26050_Judgement_03-Feb-2021.pdf
Deputy Director, Directorate of Enforcement v. Axis Bank, 2019 SCC OnLine Del 7854, Delhi High Court: https://delhihighcourt.nic.in/app/showFileJudgment/58429042019LPA3402018_160704.pdf
This article provides general legal information and is not legal advice concerning any reporting decision, regulatory inquiry, account restraint or enforcement proceeding.
#PMLA #BankingLaw #AMLCompliance
← All articles