Reporting Entities under PMLA: Rights, Obligations and the Compliance Architecture
Reporting entities are the institutional gatekeepers of India’s anti-money-laundering framework. They are not investigators or courts, but Parliament has assigned them a preventive role: identify clients and beneficial owners, understand risk, preserve transaction trails, detect prescribed and suspicious transactions, and report relevant information to the Financial Intelligence Unit–India. Because these duties affect privacy, commercial relationships and access to financial services, the Prevention of Money-Laundering Act, 2002 also provides confidentiality safeguards, limited statutory protection and appellate remedies.
Who is a reporting entity?
Section 2(1)(wa) PMLA defines a reporting entity as a banking company, financial institution, intermediary, or a person carrying on a designated business or profession. The expression therefore extends beyond banks. Depending on the statutory definition and applicable notifications, it may cover non-banking financial companies, payment-system operators, securities-market intermediaries, insurers, casinos, notified real-estate participants, dealers in precious metals or stones, virtual digital asset service providers, and specified professional or corporate-service activities.
Status must be determined from the Act, the applicable Central Government notification and the directions of the relevant regulator or FIU-IND. An enterprise does not escape Chapter IV merely because it describes itself as a technology platform or consultant; the substance of the activity is decisive. Equally, professional status alone does not make every engagement reportable. The precise notified activity and its conditions must be examined.
The governance structure
The Prevention of Money-laundering (Maintenance of Records) Rules, 2005 require a reporting entity to establish internal responsibility. A Designated Director bears overall responsibility for compliance with Chapter IV and the Rules. A Principal Officer furnishes prescribed reports and acts as the operational point of contact with FIU-IND. Their appointment does not remove responsibility from the entity, its board, officers or employees.
An effective programme should include a board-approved AML and counter-terrorist-financing policy, enterprise-wide risk assessment, customer-acceptance controls, sanctions screening, transaction monitoring, escalation protocols, independent testing, employee training, record security and documented remediation. Sector-specific directions issued by RBI, SEBI, IRDAI or another competent regulator operate alongside PMLA and the Rules.
Client due diligence and beneficial ownership
Sections 11A and 12, read with Rule 9, require identification and verification of the client and beneficial owner through reliable and independent sources. Due diligence is required when an account-based relationship begins, for an occasional transaction of at least ₹50,000 whether single or apparently connected, and for international money-transfer operations. The entity must understand the purpose and intended nature of the relationship, the client’s business, ownership and control.
The beneficial owner is the natural person who ultimately owns or controls the client, the person on whose behalf a transaction is conducted, or a person exercising ultimate effective control over a juridical person. Merely collecting incorporation documents is therefore insufficient where the ownership chain leads through companies, partnerships, trusts or other arrangements. The prescribed thresholds and control tests must be applied and the analysis recorded.
Section 11A protects client choice in identity verification. Aadhaar is not the only permissible route: the statutory alternatives include offline Aadhaar verification, passport or another officially valid document or notified mode, as applicable. A client or beneficial owner cannot be denied services merely for not possessing or choosing not to use an Aadhaar number. Where Aadhaar authentication or offline verification is used, the reporting entity must not store the Aadhaar number or core biometric information.
Ongoing and enhanced due diligence
Compliance does not end at onboarding. A reporting entity must monitor the relationship and examine whether transactions are consistent with its knowledge of the client, the client’s business, risk profile and, where necessary, source of funds. Customer information and beneficial-ownership data must remain current.
Section 12AA requires enhanced due diligence before specified transactions. This includes additional examination of identity, ownership, financial position and source of funds, and recording the purpose of the transaction and intended relationship between the parties. If the statutory conditions are not fulfilled, the specified transaction must not be permitted. A suspicious specified transaction also requires greater future monitoring.
The controls should be risk-based, not mechanically document-heavy. Higher-risk relationships may justify senior-management approval, closer source-of-wealth examination, more frequent KYC updates and enhanced monitoring. Lower risk may justify simplified measures only where the governing law and regulator permit them.
Transaction records and reports to FIU-IND
Section 12 requires records capable of reconstructing individual transactions and obliges the entity to furnish prescribed information concerning attempted as well as completed transactions. Rule 3 includes, among other categories, suspicious transactions regardless of value, specified cash transactions, connected cash transactions, transactions involving counterfeit currency, prescribed receipts by non-profit organisations, qualifying cross-border wire transfers and registrable purchases or sales of immovable property at the prescribed value.
The Principal Officer must report a suspicious transaction promptly, and FIU-IND states that an STR is to be furnished not later than seven working days after the Principal Officer is satisfied that it is suspicious. Prescribed periodic reports are generally due within the timelines fixed by Rule 8. Delay in reporting or correcting a misreported transaction can be treated as a separate violation for each day beyond the prescribed period.
Suspicion is not proof of guilt. The statutory test includes a transaction, or attempted transaction, that in good faith raises reasonable grounds of suspicion concerning proceeds of a scheduled offence or terrorist financing, appears unusually or unjustifiably complex, or lacks economic rationale or bona fide purpose. The reporting entity should document the objective indicators and analysis without making unsupported accusations.
Confidentiality and prohibition on tipping off
Section 12(2) requires information maintained, furnished or verified to be kept confidential, subject to other applicable law. Information called for by the Director under Section 12A is similarly protected. KYC data, risk classifications and reports should therefore be accessible only on a need-to-know basis and secured against unauthorised disclosure.
The client must not be told that an STR has been or may be filed, or that related information has been supplied to FIU-IND. This prohibition on tipping off protects the intelligence process. Front-line staff may ask legitimate questions to complete due diligence, but they should not reveal internal suspicion, reporting decisions or an investigation.
Record-retention duties
Transaction records must ordinarily be preserved for five years from the date of the transaction. Identity documents, beneficial-ownership records, account files and business correspondence must ordinarily be retained for five years after the business relationship ends or the account is closed, whichever is later. Enhanced-due-diligence information under Section 12AA is maintained for five years from the relevant transaction. A longer period may apply under another law, regulatory direction, litigation hold or a competent authority’s requirement.
Rights and statutory protections of reporting entities
The compliance burden is accompanied by important protections.
First, Section 14 provides that, subject to Section 13, no civil or criminal proceedings shall lie against the reporting entity, its directors or employees for furnishing information under Section 12(1)(b). This protection supports good-faith statutory reporting; it is not immunity for fabrication, misuse of data or independent unlawful conduct.
Second, confidentiality is a statutory entitlement as well as an obligation. Information furnished under Chapter IV must be handled within the limits imposed by Sections 12 and 12A and other applicable law.
Third, where the Director orders a special audit under Section 13(1A), the auditor must be selected from the Central Government’s panel and the expenses of the audit are borne by the Central Government.
Fourth, a reporting entity affected by a Section 13 compliance order is entitled to the order and may challenge it before the Appellate Tribunal under Section 26. The ordinary limitation period is 45 days from receipt, with power to entertain a delayed appeal on sufficient cause. Section 39 permits assistance by an authorised representative. A further appeal lies to the High Court under Section 42 on a question of law or fact within the statutory period.
Fifth, enforcement remains subject to legality, relevance and procedural fairness. A reporting entity responding to an inquiry may place its policies, risk analysis, reporting trail, remedial measures and technical limitations before the Director. Sensitive material should be supplied securely while preserving the evidentiary record of what was requested and produced.
Consequences of non-compliance
Under Section 13, the Director may inquire into compliance and exercise civil-court powers for specified purposes, including compelling records and attendance. On finding a failure, the Director may issue a written warning, direct compliance with specified instructions, require periodic remedial reports, or impose a monetary penalty of not less than ₹10,000 and up to ₹1 lakh for each failure. Liability can extend to the reporting entity, its Designated Director or employees, depending on the finding.
The phrase “for each failure” makes weak systems particularly dangerous: repeated omissions or continuing reporting delays can multiply exposure. The defensible response is prompt preservation, root-cause analysis, correction of reports where necessary, documented remediation and candid engagement with FIU-IND or the regulator.
A practical compliance checklist
A reporting entity should be able to demonstrate its legal classification; FIU-IND registration where required; appointment and notification of the Designated Director and Principal Officer; current enterprise and customer risk assessments; KYC and beneficial-ownership verification; sanctions and adverse-information screening; ongoing monitoring; complete STR decision records; timely regulatory reports; five-year retention controls; restricted access and anti-tipping-off training; independent testing; and board-level oversight of deficiencies.
The governing principle is proportional vigilance. PMLA does not require a reporting entity to declare every unusual customer a criminal. It requires the entity to know its client, identify the true owner, understand the transaction, preserve the trail, recognise reasonable suspicion, report through the prescribed channel and protect the information. Sound compliance serves both public enforcement and the legitimate client’s rights.
Sources
Prevention of Money-Laundering Act, 2002, particularly Sections 2(1)(wa), 11A, 12, 12A, 12AA, 13, 14, 26, 39 and 42: https://www.indiacode.nic.in/handle/123456789/15402
Prevention of Money-laundering (Maintenance of Records) Rules, 2005, as amended: https://fiuindia.gov.in/files/AML_Legislation/notification.html
Financial Intelligence Unit–India, PMLA Frequently Asked Questions: https://fiuindia.gov.in/files/FAQs/faqs.html
Financial Intelligence Unit–India, PMLA statutory text and compliance framework: https://fiuindia.gov.in/files/AML_Legislation/pmla_2002.html
#PMLA #ReportingEntities #AMLCompliance