SEBI Guidelines for Anti Money Laundering (AML), Combating the Financing of Terrorism (CFT) and Proliferation Financing (PF)
This chapter provides a comprehensive overview of the guidelines issued by the Securities and Exchange Board of India (SEBI) to ensure that market intermediaries adhere to the legal framework established by the Prevention of Money Laundering Act, 2002 (PMLA) and the PML Rules, 2005.
6.1 Introduction to SEBI Guidelines on AML, CFT, and PF
The PMLA and PML Rules mandate every reporting entity, including intermediaries registered under Section 12 of the SEBI Act, 1992, to follow specific procedures for client account opening, record maintenance, and transaction reporting.
Key Entities Covered
Registered intermediaries include but are not limited to:
- Stockbrokers and Stock Exchanges.
- Share Transfer Agents and Bankers to an Issue.
- Asset Management Companies (AMCs) and Depository Participants.
- Portfolio Managers and Investment Advisers.
- Merchant Bankers and Trustees to a Trust Deed.
Core Regulatory Principles
- Adequacy of Measures: Intermediaries must satisfy themselves that the measures they take are adequate, appropriate, and follow the spirit of the PMLA requirements.
- Stringency Requirement: If there is a variance between SEBI standards and the host country's regulators for overseas branches, the more stringent requirement must be adopted.
- Reporting to SEBI: If a host country does not permit the implementation of AML/CFT measures consistent with Indian requirements, intermediaries must apply additional measures to manage risks and inform SEBI.
6.1.1 Obligation to Establish Policies and Procedures
The PMLA necessitates that all registered intermediaries establish internal procedures to prevent and impede money laundering and terrorist financing.
Responsibilities of Senior Management
Senior management must be fully committed to establishing and ensuring the effectiveness of these policies. Their obligations include:
- Information Sharing: Issuing policies for sharing information required for Client Due Diligence (CDD) and ML/TF risk management.
- Staff Awareness: Ensuring all staff members understand the content of these directives.
- Audit and Analysis: Conducting audits of unusual activities, including those reported by branches or subsidiaries.
- Regular Review: Policies must be reviewed regularly for effectiveness by a person different from the one who framed them.
- Risk Sensitivity: Adopting client acceptance and CDD measures that are sensitive to ML/TF risks.
Scope of Internal Policies
Internal policies must specifically cover:
- Communication of group policies to all relevant management and staff.
- Client acceptance and identification requirements.
- Record maintenance and compliance with statutory requirements.
- Cooperation with law enforcement and timely disclosure of information.
- Independent Internal Audit: An internal audit function that is adequately resourced and independent to test the system for detecting suspected transactions.
6.2 Written Anti-Money Laundering Procedures
Intermediaries must maintain written procedures to implement AML provisions, focusing on four specific parameters:
- Policy for acceptance of clients.
- Procedure for identifying the clients.
- Risk Management.
- Monitoring of Transactions.
6.2.1 Client Due Diligence (CDD)
CDD involves screening and background checks on existing and prospective clients using reliable, independent sources to ensure they are properly risk-assessed.
Beneficial Ownership Thresholds
Intermediaries must identify natural persons who ultimately own or control the client. The thresholds for "controlling ownership interest" are:
- Companies: Ownership of or entitlement to more than 10% of shares, capital, or profits.
- Partnership Firms: Ownership of or entitlement to more than 10% of capital or profits.
- Unincorporated Association/Body of Individuals: Ownership of or entitlement to more than 15% of property, capital, or profits.
- Trusts: Identification of the author, trustee, beneficiaries with 10% or more interest, and any natural person exercising ultimate effective control.
CDD Operational Requirements
- Ongoing Scrutiny: Perform ongoing due diligence to ensure transactions are consistent with the intermediary's knowledge of the client and their risk profile.
- No Tip-Offs: If an intermediary suspects ML/TF and believes performing CDD will tip off the client, they should stop the CDD process and file a Suspicious Transaction Report (STR) with FIU-IND.
- NPO Registration: Details of clients that are Non-Profit Organisations (NPOs) must be registered on the DARPAN Portal of NITI Aayog.
6.2.2 Policy for Acceptance of Clients
This policy helps intermediaries identify high-risk clients and apply sensitive CDD measures.
Safeguards for Client Acceptance
- No Anonymous Accounts: Opening accounts in fictitious names or for undisclosed persons is strictly prohibited.
- Risk Categorisation: Clients must be classified into Low, Medium, and High risk.
- Clients of Special Category (CSC): These require enhanced due diligence and include:
- Non-Resident Indians (NRIs) and High Networth Individuals (HNIs).
- Trusts, Charities, and NGOs.
- Politically Exposed Persons (PEPs).
- Companies with close family shareholdings.
- Clients from high-risk countries.
- Non-face-to-face clients.
6.2.3 Client Identification Procedure (CIP)
CIP must be carried out when establishing the relationship, during transactions, or when doubts arise regarding existing data.
Requirements for PEPs
- Risk Management Systems: Proactively determine if a client or beneficial owner is a PEP.
- Approval Process: Obtain senior management approval before establishing a relationship with a PEP or continuing one if a client becomes a PEP.
- Verification: Take reasonable measures to verify the source of funds and wealth of PEPs.
Reliance on Third Parties
Intermediaries may rely on third parties for client identification if:
- The third party is regulated and supervised for AML compliance.
- The third party is not based in a high-risk country.
- The intermediary remains ultimately responsible for CDD.
6.2.4 Risk Management and Assessment
Registered intermediaries must apply a Risk-Based Approach (RBA) for identifying and mitigating ML/TF risks.
Risk Assessment Factors
Intermediaries must document and update assessments considering:
- Clients, geographical areas, and countries.
- Nature and volume of transactions.
- Payment methods and new technologies/products.
- Country-specific information from the Government of India and SEBI.
6.2.6 Monitoring of Transactions
Regular monitoring is essential to identify deviations from normal activity.
Monitoring Focus
- Complex/Large Transactions: Pay special attention to unusually large or complex patterns with no apparent economic purpose.
- Internal Thresholds: Specify limits for different client classes and examine transactions exceeding these limits.
- Record Findings: All findings from transaction examinations must be recorded in writing and made available to authorities like SEBI and FIU-IND.
6.2.11 Reporting to Financial Intelligence Unit-India (FIU-IND)
Reporting requirements are strictly defined by the PML Rules.
| Report Type | Requirement | Deadline |
|---|---|---|
| Cash Transaction Report (CTR) | All cash transactions > ₹10 Lakhs (or equivalent) | 15th of the succeeding month |
| Suspicious Transaction Report (STR) | Any transaction of suspicious nature (cash or non-cash) | Within 7 days of arriving at a conclusion |
| Non-Profit Organisation Report (NTR) | All NPO receipts > ₹10 Lakhs | 15th of the succeeding month |
Important Reporting Rules
- Confidentiality: Filing of reports must be kept strictly confidential ("No Tipping Off").
- Attempted Transactions: All attempted suspicious transactions must be reported, even if not completed by the client.
- No NIL Reporting: Intermediaries do not need to file a report if there are no reportable transactions for that period.
6.2.9 Record Keeping and Retention
Intermediaries must maintain records sufficient to permit the reconstruction of individual transactions.
Retention Periods
- Transaction Records: Must be preserved for five years from the date of the transaction.
- Client Identity Records: Records of client identity (including account files and business correspondence) must be kept for five years after the business relationship has ended or the account is closed, whichever is later.
- Ongoing Investigations: If records relate to an ongoing investigation, they must be retained until the case is officially closed.
Key Takeaways
- Mandatory Compliance: Intermediaries must strictly implement CDD; no minimum investment threshold exists for exempting these measures.
- Principal Officer Responsibility: The Principal Officer is responsible for the timely submission of CTR, STR, and NTR to FIU-IND.
- Beneficial Owner Identification: Thresholds are generally 10% for companies/partnerships and 15% for unincorporated associations.
- Audit Trail: Records must allow for the reconstruction of financial profiles to assist investigating authorities.
Important Terms
- Client of Special Category (CSC): Higher-risk clients requiring enhanced due diligence (e.g., PEPs, NRIs).
- Politically Exposed Person (PEP): Individuals who are or have been entrusted with prominent public functions.
- Tipping Off: The prohibited act of disclosing to a client that a suspicious transaction report is being filed.
- DARPAN Portal: A NITI Aayog platform for registering NPOs.