PMLA Compliance for Reporting Entities: KYC, Record-Keeping, and STRs Under Section 12

Introduction

For years, PMLA compliance felt like a banking problem. That has changed. Today, the law reaches fintechs, payment companies, crypto platforms, and even chartered accountants and company secretaries. If your business handles other people’s money or helps set up companies, you may now be a reporting entity — and Section 12 of the PMLA imposes real, ongoing duties on you.

This guide explains those duties in simple language. It covers who is a reporting entity, what KYC and record-keeping require, the different reports you must file with FIU-IND, the important 2023 changes, and the penalties for getting it wrong. I have written it as a practical compliance guide, not a theory lecture.

For the wider picture of how the ED and the PMLA work, you can also read my cornerstone guide: Introduction to PMLA and ED Law in India.

Who Is a Reporting Entity?

The starting point is the definition. Section 2(1)(wa) of the PMLA says a reporting entity means a banking company, a financial institution, an intermediary, or a person carrying on a designated business or profession.

Break that down into plain categories:

  • Banking companies — banks and cooperative banks.
  • Financial institutions — NBFCs, insurers, chit-fund companies, payment system operators, and similar.
  • Intermediaries — stockbrokers, sub-brokers, mutual funds, portfolio managers, and others registered with SEBI.
  • Persons carrying on a designated business or profession — a wide, growing category that the Central Government keeps expanding by notification.

That last category is the reason so many new businesses are now covered. It already includes real-estate agents, dealers in precious metals and stones, casinos, and persons who form or manage companies and trusts. And, as we will see, the government added important new groups in 2023.

The Core Duties Under Section 12

Section 12 sits at the heart of the compliance regime. It places three main duties on every reporting entity. Read alongside the PML (Maintenance of Records) Rules, 2005, these duties become detailed and specific.

Duty one — verify identity (KYC). You must verify the identity of every client, and of the beneficial owner behind that client, before you deal with them. Section 11A backs this up, allowing verification through Aadhaar, passport, or other notified documents.

Duty two — maintain records. You must keep records of prescribed transactions, and of client identity and account files, for the period the Rules require. The standard retention period is five years.

Duty three — report to FIU-IND. You must furnish prescribed transaction reports, and reports of suspicious transactions, to the Financial Intelligence Unit – India (FIU-IND) within the prescribed time. You must also keep this information confidential from the client.

These three duties — verify, record, report — are the spine of PMLA compliance. Everything else builds on them.

KYC and Client Due Diligence in Detail

KYC is the foundation. Before onboarding a client, and on an ongoing basis, a reporting entity must carry out client due diligence. In practice, this means several things.

First, identify and verify the client using reliable documents — identity proof, address proof, and PAN. Secondly, identify the beneficial owner — the real natural person who ultimately owns or controls the client, especially where the client is a company, LLP, or trust. Thirdly, understand the purpose of the business relationship and the nature of the client’s activity. Finally, monitor the relationship on an ongoing basis, and apply enhanced checks to higher-risk clients.

Two categories deserve special care. Politically Exposed Persons (PEPs) — people entrusted with prominent public functions — attract enhanced due diligence, a definition the 2023 rules sharpened in line with global standards. And non-profit organisations attract specific record-keeping, because they can be misused for laundering.

Getting KYC right protects you twice over. It stops bad actors at the door, and it gives you a clean record if the ED ever questions a transaction. On the flip side, weak KYC is the first thing an investigator attacks.

Record-Keeping — What, and For How Long

The Rules require a reporting entity to maintain records that let the authorities reconstruct individual transactions. In simple terms, keep enough detail that someone could later trace exactly what happened.

You must maintain records of the nature and value of transactions, whether a single transaction or a series of connected transactions. You must keep client identity records and account files and business correspondence. And you must preserve these for five years — from the date of the transaction, and from the end of the business relationship for client records.

Many reporting entities also file client identity records with the Central KYC Records Registry (CKYCR), which centralises KYC data. Good record-keeping is not just a legal duty; it is your best defence if a transaction is later questioned.

The Reports You Must File With FIU-IND

This is where many businesses get confused. The PML Rules prescribe several types of reports, each triggered by a different situation. Here are the main ones in plain terms:

  • STR — Suspicious Transaction Report. File this whenever you have reasonable grounds to suspect that a transaction, attempted or completed, involves proceeds of crime — whether it is one transaction or a linked series. Suspicion is the trigger, not a fixed amount.
  • CTR — Cash Transaction Report. File this for cash transactions above the prescribed threshold, generally more than ten lakh rupees, or a series of connected cash transactions crossing that value in a month.
  • CCR — Counterfeit Currency Report. File this where forged or counterfeit currency is used.
  • NTR — Non-Profit Organisation Transaction Report. File this for prescribed receipts by non-profit organisations.
  • CBWTR — Cross-Border Wire Transfer Report. File this for cross-border wire transfers above the prescribed value.

The STR is the most important and the most judgment-based. It does not depend on an amount. It depends on your reasonable suspicion. Filing a good STR, promptly, is both a legal duty and a shield — it shows you acted responsibly.

The Compliance Machinery — Designated Director and Principal Officer

Section 12 compliance is not left to chance. Every reporting entity must put two named people in place.

The Designated Director carries overall responsibility for ensuring the entity complies with the PMLA and the Rules. This is usually a senior person — a whole-time director or an equivalent.

The Principal Officer handles the day-to-day reporting. This officer files the STRs, CTRs, and other reports with FIU-IND, and acts as the point of contact.

You must communicate the name, designation, and address of both officers to FIU-IND. Appointing them properly, and empowering them to do their job, is a basic first step of any compliance program.

The 2023 Amendments — Crypto, Professionals, and Company Agents

The year 2023 widened the PMLA’s compliance net dramatically. Three changes matter most, and every affected business should know them.

Virtual Digital Assets (crypto). By a notification of March 2023, the government brought Virtual Digital Asset Service Providers — crypto exchanges, wallet providers, and similar businesses — within the PMLA as reporting entities. They must now register with FIU-IND, carry out KYC, keep records, and file reports like any other reporting entity. FIU-IND registration became a pre-requisite for operating. This was a landmark moment for the crypto industry in India.

Professionals — CA, CS and CMA. By a notification of 3 May 2023, practising chartered accountants, company secretaries, and cost accountants became reporting entities when they carry out certain financial transactions on behalf of clients — such as buying and selling property, managing client money or assets, or helping form and manage companies. Notably, lawyers were not included. This change surprised many professionals, who now carry KYC and reporting duties for the covered activities.

Company formation agents and nominee directors. By a notification of 9 May 2023, persons who help form companies, act as directors or secretaries or nominee directors, or provide registered offices and business addresses for companies, LLPs, or trusts, were also brought in. This targets the shell-company route that launderers often use.

Together, these changes mean that PMLA compliance is no longer only for big banks. It now touches a huge range of businesses and professionals. If you fall in any of these groups, you must set up a compliance program now.

Penalties for Non-Compliance — Section 13

What happens if a reporting entity fails to comply? Section 13 sets out the consequences, and they are civil, not criminal.

The Director of FIU-IND can call for records, order an audit, and examine officers. Where there is a failure, the Director can issue a written warning, direct the entity to comply with specific instructions, direct a report on the steps taken, or impose a monetary penalty. That penalty ranges from ten thousand to one lakh rupees for each failure.

Two points give comfort, and one gives caution. The comfort: there is no imprisonment for a compliance failure by the reporting entity itself, and the penalty per failure is capped. The caution: penalties apply per failure, so systemic lapses across many transactions can add up, and reputational damage with the regulator is real. Moreover, officers can be summoned under Section 50, and serious involvement in laundering is a different, far graver matter — the criminal side of the PMLA that I cover across my other guides, including arrest under Section 19 and bail in PMLA cases.

Building a Practical Compliance Program

From advising businesses, here is a simple framework any reporting entity can follow:

  1. Appoint your officers — a Designated Director and a Principal Officer, and register with FIU-IND.
  2. Write a PMLA policy — a clear internal policy covering KYC, record-keeping, and reporting.
  3. Set up KYC and CDD procedures — for onboarding, beneficial-owner identification, and PEP checks.
  4. Build a monitoring system — to spot unusual or suspicious transactions in real time.
  5. Create a reporting workflow — so STRs, CTRs, and other reports reach FIU-IND on time and are logged.
  6. Maintain records for five years — securely and retrievably, and file with CKYCR where required.
  7. Train your staff — because most lapses come from front-line staff who do not recognise red flags.
  8. Audit regularly — review your compliance, fix gaps, and document that you did so.

A well-run program does more than avoid penalties. It gives you a clean, credible record if the ED ever comes calling — which, as I explain in my guide on what to do if the ED contacts you, is the strongest position any business can be in.

Why This Matters — Compliance Is Cheaper Than Defence

The cost of a good compliance program is small. The cost of getting it wrong is large. A single ignored red flag can turn into an FIU-IND penalty, a summons to your Principal Officer, or worse — an allegation that the business itself was part of the laundering.

For banks, NBFCs, fintechs, crypto platforms, and covered professionals, compliance is now a core business function, not a formality. Building it properly, and reviewing it regularly, is the wisest investment you can make. For a full map of how the courts have shaped the PMLA, see my PMLA case laws digest and my overview of the leading case laws on ED and PMLA matters.

Frequently Asked Questions (FAQ)

Q1. Who is a reporting entity under the PMLA? Under Section 2(1)(wa), a banking company, financial institution, intermediary, or a person carrying on a designated business or profession. Since 2023, this includes crypto service providers and practising CAs, CSs, and CMAs who carry out specified financial transactions for clients.

Q2. What are the main duties under Section 12? Verify the identity of clients and beneficial owners (KYC), maintain transaction and client records for the prescribed period, and report prescribed and suspicious transactions to FIU-IND, keeping the information confidential.

Q3. What is an STR, and when must I file it? A Suspicious Transaction Report. File it whenever you have reasonable grounds to suspect a transaction, attempted or completed, involves proceeds of crime — whether a single transaction or a connected series. It is based on suspicion, not a fixed amount.

Q4. How long must a reporting entity keep records? Generally five years — from the date of the transaction, and from the end of the business relationship for client identity records.

Q5. Are chartered accountants and company secretaries covered? Yes. By the notification of 3 May 2023, practising CAs, CSs, and CMAs became reporting entities for specified financial transactions carried out for clients. Lawyers were not included.

Q6. Are crypto exchanges covered by the PMLA? Yes. Since March 2023, Virtual Digital Asset Service Providers must register with FIU-IND and comply with KYC, record-keeping, and reporting obligations.

Q7. What is the penalty for non-compliance? Under Section 13, FIU-IND can warn, direct compliance, or impose a monetary penalty of ten thousand to one lakh rupees per failure. There is no imprisonment for the compliance failure itself.

Conclusion

PMLA compliance has grown far beyond banking. It now binds fintechs, crypto platforms, and professionals who never thought the law applied to them. The core duties are simple to state — verify your clients, keep your records, report the suspicious — but they demand real systems and real discipline. Section 13 penalties may be civil and capped, but the reputational and criminal risks of a serious lapse are not.


Leave a Comment

Are you human? Please solve:Captcha