Skip to content

Corporate and Economic Laws · Laws and Regulations related to Anti-Money Laundering

Obligations of Reporting Entities and FIU-India under PMLA

Updated 11 October 2026 · Fact-checked

Under the PMLA, 2002, a reporting entity must keep transaction records, verify client and beneficial owner identity, apply enhanced due diligence to specified transactions, and furnish prescribed transaction information to the Director (FIU-IND). Records are kept for five years. Information is confidential. Exam answers should name the duty, the section, the period and the consequence.

Understand Obligations of Reporting Entities and Financial Intelligence Unit

A reporting entity is a person, such as a bank or financial institution, on whom the PMLA places duties to help detect money-laundering. The idea is simple: these entities sit where money moves, so they must leave a trail and tell the authorities about certain transactions.

The duties fall into four groups. First, identity verification (Section 11A). Second, record keeping and reporting (Section 12). Third, enhanced due diligence for high-risk transactions (Section 12AA). Fourth, the power of the Central Government to prescribe the procedure and manner (Section 15) and to make rules (Section 73).

The Financial Intelligence Unit-India (FIU-IND) is the agency that receives the information. The Act speaks of furnishing information to the "Director". The Act's text supplied here does not give the details of the Director's office, so in the exam describe FIU-IND as the national agency that receives, analyses and shares information on suspicious and prescribed transactions. Keep that description general.

Note what the Act leaves to rules. The nature and value of reportable transactions, the time limit for furnishing them, and the detailed manner of due diligence are all "as may be prescribed". Do not quote rupee thresholds unless the question gives them.

Key rules to remember

Section 12(1)(a): transaction records
Maintain a record of all transactions so that individual transactions can be reconstructed
The test is reconstruction. The record must be good enough to rebuild each transaction.
Section 12(1)(b): reporting to the Director
Furnish prescribed information on transactions, attempted or executed, within the prescribed time
Attempted transactions are covered. Nature, value and time are fixed by rules (Section 73(2)(i)).
Section 12(1)(e): client records
Keep identity documents of clients and beneficial owners, account files and business correspondence
All four items matter: client ID, beneficial owner ID, account files, correspondence.
Section 12(3): retention of transaction records
5 years from the date of transaction between client and reporting entity
The clock runs from the transaction.
Section 12(4): retention of client records
5 years after the business relationship has ended or the account was closed, whichever is later
The clock runs from the end of the relationship. Do not mix it up with Section 12(3).
Section 12(2): confidentiality
Information maintained, furnished or verified is kept confidential, save as otherwise provided under any law
The exception is only where another law provides otherwise.
Section 11A(1): modes of identity verification
Aadhaar authentication (banking company), Aadhaar offline verification, passport, or other officially valid document notified by the Central Government
Other reporting entities may be allowed Aadhaar authentication by notification, after consulting UIDAI and the regulator.
Section 11A(3) and (4): voluntary choice and no storage
Mode of identification is the client's voluntary choice; no denial of service for lacking Aadhaar; core biometric information and Aadhaar number not stored
Storage bar applies where authentication or offline verification is used.
Section 12AA(1): enhanced due diligence before a specified transaction
(a) Aadhaar authentication of identity; (b) examine ownership and financial position, including source of funds; (c) record purpose and intended nature of the relationship
Done before each specified transaction commences.
Section 12AA(2)-(4)
Client fails conditions: transaction not allowed. Suspicious: increase future monitoring. EDD information kept 5 years from the date of transaction
Specified transactions: cash withdrawal or deposit above a prescribed amount, forex transactions above a prescribed amount, high value imports or remittances, and other prescribed high-risk transactions.

How to solve Obligations of Reporting Entities and Financial Intelligence Unit questions

Use this method for any question on duties of reporting entities, whether it is a short note, a case scenario or an MCQ.

  1. 1Identify the duty being tested: identity verification, record keeping, reporting, enhanced due diligence or confidentiality.
  2. 2Recall the section: 11A for identity, 12 for records and reporting, 12AA for enhanced due diligence, 15 and 73 for procedure and rules.
  3. 3State the rule in plain words with its exact condition, such as banking company for Aadhaar authentication or specified transaction for 12AA.
  4. 4Apply the retention period correctly: 5 years from the transaction for transaction records; 5 years after the relationship ends or account closes, whichever is later, for client records.
  5. 5Check whether the facts involve an attempted transaction, a client who refuses verification, or a suspicious pattern, and apply the matching consequence.
  6. 6Mention what is left to rules, such as value limits and time limits, rather than inventing figures.
  7. 7Close with a one-line conclusion that answers the question asked.

Quickest way: Section-to-duty map

When to use it: Use this in Section A MCQs and when you have under two minutes for a short note.

  1. Think 11A = who are you (identity). 12 = keep and report. 12AA = extra checks before risky transactions.
  2. For any period, ask: is it a transaction record or a client record? Transaction: from the date of transaction. Client: after relationship ends or account closes, whichever is later.
  3. For any refusal by the client, check: if it is a specified transaction and conditions are not met, the entity must not allow it. If only Aadhaar is missing, service cannot be denied.
  4. Eliminate options that quote rupee limits or say the entity may share information freely.

Common mistakes in Obligations of Reporting Entities and Financial Intelligence Unit

  • Saying all records are kept for five years from the date of transaction.

    Section 12(3) is remembered and Section 12(4) is forgotten.

    Fix: Client identity records and account files run five years from the end of the relationship or closure of the account, whichever is later.

  • Saying a bank can refuse service to a client who has no Aadhaar number.

    Students link KYC with Aadhaar as compulsory.

    Fix: Under Section 11A(3), the mode is the client's voluntary choice and no one is denied services for not having Aadhaar. Passport or another notified officially valid document can be used.

  • Quoting a fixed rupee limit for cash transactions reportable to FIU-IND.

    Students mix the Act with rules or circulars.

    Fix: The Act says the nature and value are prescribed. State that the limits are in the rules unless the question supplies them.

  • Forgetting that attempted transactions are also reportable.

    The word 'transactions' suggests completed ones only.

    Fix: Section 12(1)(b) covers transactions 'whether attempted or executed'.

  • Treating enhanced due diligence as applicable to every transaction.

    Students merge KYC with 12AA.

    Fix: Section 12AA applies before each specified transaction, such as large cash, forex or high value import or remittance transactions, as prescribed.

  • Saying the entity may store the client's Aadhaar number after authentication.

    Records are assumed to include everything seen during verification.

    Fix: Section 11A(4): where authentication or offline verification is used, neither core biometric information nor the Aadhaar number is stored.

Worked examples

Example 1

Mehta Finance Ltd., a reporting entity, closed the account of a client, Ravi Nair, on 31 March 2027. The client's last transaction was on 15 January 2027, and the account had been opened in 2020. Until what date must Mehta Finance keep (a) the record of the 15 January 2027 transaction and (b) Ravi's identity documents and account file? Assume the account closure is the later of the two events that end the relationship.

Show the solution
  1. Step 1: The transaction record falls under Section 12(1)(a) and Section 12(3). The period is five years from the date of transaction.
  2. Step 2: Five years from 15 January 2027 gives 15 January 2032.
  3. Step 3: Identity documents and account files fall under Section 12(1)(e) and Section 12(4). The period is five years after the relationship ended or the account was closed, whichever is later.
  4. Step 4: Account closure on 31 March 2027 is the later date as given. Five years after this gives 31 March 2032.

Answer: (a) The transaction record must be kept until 15 January 2032. (b) The identity documents and account file must be kept until 31 March 2032.

Example 2

A bank wishes to carry out a cash deposit that is a specified transaction for a client. The client agrees to give the details of her identity but refuses to explain the source of her funds or the purpose of the transaction. What must the bank do under the PMLA? Would your answer change if the client simply had no Aadhaar number for ordinary account opening?

Show the solution
  1. Step 1: A cash deposit above the prescribed amount is a specified transaction under the Explanation to Section 12AA. Enhanced due diligence applies before the transaction starts.
  2. Step 2: Section 12AA(1) requires the bank to verify identity by Aadhaar authentication, to examine ownership and financial position including source of funds, and to record the purpose and intended nature of the relationship.
  3. Step 3: The client refuses to give the source of funds and purpose, so the conditions of Section 12AA(1) are not met.
  4. Step 4: Under Section 12AA(2), the bank must not allow the specified transaction to be carried out.
  5. Step 5: For ordinary identity verification at account opening, Section 11A(3) says no client is denied services for not having an Aadhaar number. Other modes such as a passport or another notified officially valid document are available.
  6. Step 6: Any information obtained under the enhanced due diligence must be kept for five years from the date of transaction (Section 12AA(4)). Where the transaction is suspicious, the bank must also increase future monitoring (Section 12AA(3)).

Answer: The bank must not allow the specified transaction, as the client has not satisfied Section 12AA(1). If the client merely lacks an Aadhaar number for ordinary account opening, the bank cannot deny service on that ground and must accept another permitted mode of identification under Section 11A.

Exam tips

  • Learn the section map cold: 11A identity, 12 records and reporting, 12AA enhanced due diligence, 15 procedure, 73 rules. MCQs often ask which section covers a duty.
  • Write both retention periods side by side in your notes. The trap is the starting point of the five years.
  • In case scenarios, check whether the transaction is a specified transaction before applying Section 12AA.
  • Do not quote rupee thresholds or time limits unless the question gives them. Say they are prescribed by rules.
  • For a note on FIU-IND, link it to the duty in Section 12(1)(b): reporting entities furnish information to the Director.

Practice questions from Laws and Regulations related to Anti-Money Laundering

Obligations of Reporting Entities and Financial Intelligence Unit in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Obligations of Reporting Entities and Financial Intelligence Unit: frequently asked questions

Who is a reporting entity under the PMLA?

It is a person on whom the Act places duties of identity verification, record keeping and reporting, such as a bank or financial institution. The sections supplied here do not list the types, so in the exam describe it by its duties and give examples like banks and financial institutions.

How long must a reporting entity keep records under the PMLA?

Transaction records must be kept for five years from the date of transaction. Client identity documents, account files and business correspondence must be kept for five years after the business relationship has ended or the account has been closed, whichever is later.

Is Aadhaar compulsory for KYC under the PMLA?

No. Section 11A allows Aadhaar authentication (for banking companies), offline Aadhaar verification, a passport, or another notified officially valid document. The choice is the client's, and services cannot be denied for not having an Aadhaar number. Enhanced due diligence for specified transactions, however, begins with Aadhaar authentication, with another prescribed mode for persons not entitled to an Aadhaar number.

What is the role of FIU-IND in the reporting process?

Reporting entities furnish prescribed transaction information to the Director under Section 12(1)(b). FIU-IND is the agency that receives and analyses this information. The nature, value and time limits for reporting are set by rules.