BankopediaBankopedia
JAIIB · PPB · Unit 1Chapter Notes5–7 Marks Expected

AML-KYC Guidelines

Principles & Practices of Banking | Unit 1 Chapter Notes

From the three stages of money laundering through PMLA provisions, KYC Policy elements, designated functionaries, risk-based approach, and FIU-Ind reporting obligations — everything you need for 5–7 marks from this chapter.

By Bankopedia.co.in Updated 2026 High weightage in JAIIB PPB

📌 Why This Chapter Matters in JAIIB

AML-KYC is one of the highest-weightage chapters in JAIIB PPB. Expect 5–7 questions every attempt — from stages of money laundering, PMLA provisions (Sections 3, 4, 45), KYC Policy elements (always 4), designated functionaries (DD vs PO), FIU-Ind report thresholds, and penal provisions. This chapter connects directly to your daily banking work, making it both easy to relate to and easy to score from.

Section 1

Money Laundering — What It Is and How It Works

Money laundering (ML) is the process of concealing the criminal origin of funds — generated from activities like drug trafficking, corruption, Ponzi schemes, or cybercrimes — and introducing them into the financial system so they appear to come from legitimate sources.

Three interconnected threats make up the AML-CFT landscape that every banker must understand:

🧹

Money Laundering (ML)

Concealing criminal origin of funds and introducing them into the financial system as legitimate.

💣

Terrorism Financing (TF)

Providing or collecting funds knowing they will be used for terrorist acts or organisations.

💸

Financial Crimes (FC)

Tax evasion, fraud, corruption — all closely connected with ML and TF.

💡 Who Runs the Network?

Criminals have organised themselves into Organised Crime Groups (OCGs) and Professional Money Launderers (PMLs). Together they form the network that propagates criminal activities and launders the funds. The Financial Action Task Force (FATF) — a global inter-governmental body — was set up to evolve global AML/CFT standards (FATF Standards 2012).

🧠 Mnemonic — 3 Stages of Money Laundering: PLI

P = Placement — dirty money enters the banking system
L = Layering — complex transactions hide its origin
I = Integration — clean money re-enters the economy

“Please Let It (into the economy)”

📥 1. Placement

Funds from criminal activity are introduced into the financial system — typically through multiple cash deposits in bank accounts. The primary goal: get the dirty money into the banking system without attracting attention.

⚠️ Exam Trap: Placement is the RISKIEST stage for the criminal — it is where they are most exposed to detection.

🔀 2. Layering

The funds are passed through numerous financial transactions — inter-account transfers, foreign remittances, shell company payments. Each layer creates more distance between the money and its criminal origin.

3. Integration

Funds lying in multiple accounts are collected into one or a few accounts, then deployed in legal business activity or used to acquire legitimate assets. At this stage, the money re-enters the economy appearing to come from a lawful source.

Section 2

Terrorism Financing & the PMLA Framework

Terrorist organisations have financial cycles similar to commercial entities. Unlike money laundering (which starts with dirty money becoming clean), terrorism financing can start with legitimate funds being channelled for criminal purposes.

🧠 Mnemonic — 4 Stages of Terrorism Financing: RUMP

R = Raising of Funds
U = Use of Funds
M = Movement of Funds
P = Parking of Funds

Note: The sequence in the textbook is R → M → P → U (Raising, Movement, Parking, Use)

StageDescriptionMethod
1. RaisingSourcing funds from sympathisers, donations, or criminal activitiesClandestine collection — true purpose concealed from authorities
2. MovementCross-border transfer to terrorist organisations across jurisdictionsHawala, informal channels, wire transfers
3. ParkingInterim storage of funds awaiting deploymentBank accounts, financial investments
4. UsePaying operatives, procuring equipment, funding propagandaTerror acts, organisational activities

The PMLA Legal Framework

India enacted the Prevention of Money Laundering Act, 2002 (PMLA) based on FATF Recommendations. Detailed rules are in the Prevention of Money Laundering (Maintenance of Records) Rules (PMLR).

Key PMLA Sections — Must Know

Section 3

Defines the Offence of Money Laundering — whosoever directly or indirectly attempts to indulge or knowingly assists in any process connected with proceeds of crime (concealment, possession, acquisition, use) is guilty.

Section 4

Punishment: Rigorous imprisonment not less than 3 years, up to 7 years + fine. For cases connected with NDPS (Narcotics), imprisonment may extend up to 10 years.

Section 45

All offences under PMLA are deemed COGNIZABLE and NON-BAILABLE.

Institutional Framework

FIU-Ind (Financial Intelligence Unit – India): Receives reports from banks and FIs, analyses and disseminates intelligence to law enforcement. Also has supervisory powers over Reporting Entities.

Enforcement Directorate (ED): Investigation and prosecution authority for ML crimes. Can track and attach crime-related assets.

Special Courts: Adjudicate ML cases. Have powers to freeze and confiscate assets proved to relate to money laundering.

⚠️ Exam Trap

Section 4 punishment: 3–7 years rigorous imprisonment (general). Up to 10 years only for NDPS-linked cases. Section 45 makes ALL PMLA offences cognizable and non-bailable — this is frequently tested.

Section 3

KYC Policy — Four Elements & Customer Definition

📜 Before KYC: The Introduction Practice

Prior to RBI’s KYC guidelines (2002), banks required an introduction from an existing account holder or staff member for new accounts — to obtain protection under the Negotiable Instruments Act. Post-KYC guidelines: introduction practice was discontinued. Every bank must now have a KYC Policy laying down KYC/AML norms.

Who is a ‘Customer’ Under PMLA?

“Client means a person who is engaged in a financial transaction or activity with a reporting entity and includes a person on whose behalf the person who engaged in the transaction or activity, is acting.” — Section 2(ha), PMLA

This is wider than the traditional banking definition. For KYC purposes, a bank must include:

Savings, current, and fixed deposit account holders
Credit facility users (fund-based and non-fund-based)
One-time remittance users (even a single transaction)
Demat account holders (when bank is Depository Participant)
PPF or Pension Fund account holders
Third-party product users (insurance, mutual funds)
Safe custody service and locker users
Beneficial owners of entities availing services
Beneficiaries of accounts maintained by Professional Intermediaries

The Four Key Elements of KYC Policy

🧠 Mnemonic — Always Four, Always in This Order

1. Customer Acceptance Policy (CAP)
2. Customer Identification Procedures (CIP)
3. Risk Management
4. Monitoring of Transactions

“Customers Come, Risk Monitored” — CAP · CIP · Risk · Monitoring

1.Customer Acceptance Policy (CAP)

Defines which customers the bank will and will not on-board. Sets risk thresholds, identifies prohibited categories (e.g., anonymous accounts), and lays out the conditions for accepting high-risk customers.

2.Customer Identification Procedures (CIP)

Process for verifying identity using Officially Valid Documents (OVDs), Aadhaar authentication, or offline verification. Also covers identification of beneficial owners — the actual person behind an entity.

3.Risk Management

Board-approved risk framework for classifying customers as High, Medium, or Low risk. Includes ML/TF risk assessment of the bank (at least annually) and enhanced due diligence for high-risk customers.

4.Monitoring of Transactions

Ongoing monitoring of account activity against the customer's known profile. Detection and reporting of suspicious transactions to FIU-Ind as per laid-down procedures.

⚠️ Exam Trap — Always Four

Questions on “how many elements does a KYC Policy have?” always appear. The answer is 4 — every time. Some banks maintain two documents (KYC Policy + AML/CFT Policy) but the elements remain 4. Policy must be reviewed at least once a year — also triggered by regulatory changes or new business lines.

Section 4

Designated Functionaries Under PMLA

PMLR requires every bank to designate two specific functionaries for PMLA compliance. Getting these confused is the most common exam error in this chapter.

AttributeDesignated Director (DD)Principal Officer (PO)
LevelBoard / Senior ManagementSenior Officer (below board)
Responsible forOVERALL PMLA compliance (Sections 11A, 12, 12A, 12AA)Day-to-day AML/CFT operations
FIU-Ind interfaceNo — policy level onlyYes — reports transactions, shares information
KYC PolicyEnsures it is updated and compliantMonitors implementation
Law enforcementNoMaintains liaison with agencies
Board reportsResponsible for getting them to BoardEnsures periodic reports are submitted

Who is the Designated Director? (Type-wise)

Type of EntityWho is the DD?
CompanyManaging Director or Whole-time Director authorised by Board
Partnership FirmManaging Partner
ProprietorshipProprietor
TrustManaging Trustee
Cooperative Banks / RRBsSenior management person designated as DD
Unincorporated association / Body of individualsPerson who controls and manages affairs of the entity

AML/CFT Compliance Function

A distinct functional unit (separate from DD and PO) that handles:

Review and update KYC Policy regularly
Guide business units on customer identification/due diligence
Undertake ML/TF risk assessment of the bank (at least annually)
Assist in customer risk categorisation
Monitor transactions for suspicious activity
Submit prescribed reports and information to FIU-India
Section 5

Risk-Based Approach & Customer Risk Categorisation

Banks are required to apply a Risk-Based Approach (RBA) — calibrating the intensity of due diligence and monitoring to the actual risk posed by each customer, product, and channel. This is far more effective than applying the same level of scrutiny to every account.

Sources of ML/TF Risk

Customers

PRIMARY source — criminals disguise identity and purpose. A salaried RM's savings account looks identical to a gambling racketeer's until you look at the transaction pattern.

Products / Services

Technology products (mobile wallets, net banking, RTGS/NEFT/IMPS, smart cards) carry inherent ML/TF risk from their speed and anonymity.

Country / Region

Bank's country of incorporation, branch location, and jurisdiction of connected transactions all affect risk.

Delivery Channels

Digital channels, Business Correspondents, DSAs — all introduce intermediary risk.

⚠️ Exam Trap — Two Different Timelines

ML/TF Risk Assessment of the bank

At least ANNUALLY (once a year)

Customer risk categorisation review

At least every SIX MONTHS

Customer Risk Categories

LOW RISK

Salaried individuals, pensioners, government employees — identity and sources of wealth easily verified, transactions conform to known profile.

MEDIUM RISK

Cash-intensive businesses (jewellers, petrol pump dealers), customers with higher-than-average transaction volumes.

HIGH RISK

Politically Exposed Persons (PEPs), NRIs, customers connected to FATF high-risk jurisdictions, trusts, shell companies, charitable organisations.

💡 Risk Categorisation — Key Rules

PEPs (Politically Exposed Persons) may be categorised ABOVE High if the bank considers necessary
Parameters: nature of business, location, mode of payments, volume of turnover, social and financial status
Also reviewed whenever new information about the customer is received or a change in conduct is noticed
Internal audit findings on KYC/AML compliance go to Board's Audit Committee at QUARTERLY intervals
Section 6

Reporting Obligations to FIU-Ind

Banks must file five types of reports with FIU-Ind. Threshold amounts and timelines differ — this is a favourite exam area.

No.ReportThreshold / ConditionWhen
1Cash Transaction Report (CTR)₹10 lakh or more in cash; OR a series of connected cash transactions in a month aggregating ₹10 lakh+Monthly
2Cross Border Wire Transfer Report (CBWTR)Cross-border wire transfers of more than ₹5 lakh (or equivalent) where origin or destination is in IndiaMonthly
3Non-Profit Organisation Report (NTR)Receipts by non-profit organisations of more than ₹10 lakh or equivalentMonthly
4Counterfeit Currency Report (CCR)ALL counterfeit currency notes received — no minimum valueAs detected
5Suspicious Transaction Report (STR)ANY transaction where suspicion is established — no minimum value, includes attempted and non-monetary transactionsWithin 7 days of suspicion

🚨 STR — The Most Important Report

No minimum valueEven a ₹1 transaction is reportable if suspicious — value is completely irrelevant for STR.
7-day deadlineFile with FIU-Ind within 7 days of establishing suspicion.
Attempted transactions includedIf a customer abandons account opening on being asked for documents — that is reportable.
Non-monetary transactions includedUnusual locker operations count — even if no money changes hands.
Strict confidentialityNEVER inform the customer that an STR has been filed. This is a legal requirement.

When is a Transaction ‘Suspicious’?

To a person acting in good faith, the transaction appears to:

1.Involve a reasonable doubt that it may relate to proceeds of an offence under PMLA Schedule (likely ML)
2.Be made in circumstances of unusual or unjustified complexity
3.Have no economic rationale or bona fide purpose
4.Involve a reasonable doubt that it may relate to financing of terrorism
Section 7

Penalties, Secrecy & International Standards

Penalties by Director, FIU-Ind

The Director of FIU-Ind can act against the bank, any of its employees, managers, or directors:

Penalty TypeDetails
Written WarningFor minor violations or first-time non-compliance
Remedial DirectionDirect to take specific remedial measures + submit Action Taken Report
Monetary PenaltyMinimum ₹10,000 — Maximum ₹1,00,000 per violation
Counting ViolationsEach day of delay in submission / rectification = one separate violation

⚠️ Exam Trap — Penalty Range

FIU-Ind monetary penalty: ₹10,000 minimum to ₹1,00,000 maximum per violation. The Director FIU can act against the bank, any employee, manager, OR director — “All of the above” is always the answer when asked who can be penalised.

Secrecy Obligations & Exceptions

Banks cannot use customer information for cross-selling or any other purpose without express permission. There are four exceptions — remember them as BLED:

🧠 Mnemonic — Secrecy Exceptions: BLED

B — By compulsion of LAW (statutory requirement)
L — Liability to PUBLIC (duty to disclose in public interest)
E — Explicit consent of the customer (express or implied)
D — Defence of bank's own INTEREST requires disclosure

International Standards

FATF High-Risk Jurisdictions

FATF issues statements on high-risk / non-compliant countries every FOUR MONTHS
Banks must give special attention to transactions with persons from FATF-listed countries
Banks are NOT prohibited from legitimate trade with these countries — only enhanced due diligence applies

UNSC Sanctions Lists

Banks must not open or maintain accounts for individuals/entities listed in:

ISIL (Da'esh) & Al-Qaida Sanctions List — persons associated with Al-Qaida
1988 Sanctions List — persons associated with the Taliban

On finding a match: advise FIU-IND + Ministry of Home Affairs, then freeze assets per MHA orders.

Correspondent Banking

Correspondent banking = one bank holds deposits for and provides services to another (respondent) bank
Banks CANNOT establish correspondent relationships with SHELL BANKS (no physical presence)
Due diligence must cover: business nature, management, AML/CFT compliance, regulatory framework of home country
Extra caution needed for correspondents in FATF-listed jurisdictions

FATCA & Common Reporting Standards (CRS)

StandardPurpose
FATCA (U.S. law)Requires FIs to identify U.S. accounts and report to IRS. Prevents U.S. persons hiding wealth in foreign banks.
CRS (OECD)Global automatic exchange of financial account information between countries for tax compliance.

In India: Income Tax Rules 114F, 114G, and 114H require banks to submit reports to the Income Tax Department for FATCA (U.S. taxable) and CRS (any foreign country taxable) customers.

Quick-Reference: All Key Numbers for the Exam

PMLA imprisonment (general)3–7 years rigorous
PMLA imprisonment (NDPS cases)Up to 10 years
Transaction records retention5 years from transaction date
Identity / account records retention5 years from closure or end of relationship (later)
STR filing deadlineWithin 7 days of establishing suspicion
ML/TF risk assessment frequencyAt least annually
Customer risk categorisation reviewAt least every 6 months
Audit findings to Board Audit CommitteeQuarterly
FATF statements on high-risk jurisdictionsEvery 4 months
CTR threshold₹10 lakh (cash)
CBWTR threshold₹5 lakh (cross-border wire)
NTR threshold₹10 lakh (NPO receipts)
CCR thresholdNo threshold — all counterfeit notes
STR value thresholdNo threshold — any amount
FIU-Ind monetary penalty — minimum₹10,000 per violation
FIU-Ind monetary penalty — maximum₹1,00,000 per violation
KYC Policy elements4 (always 4)

Practice Test Available

Chapter 2 Mock Test — 50 Questions

Test your knowledge with 50 exam-standard MCQs on AML-KYC Guidelines — timed, graded, PRO.

Start Mock Test →

Discussion

Sign in to join the discussion.

No comments yet. Be the first to share your thoughts.