Analysis of PMLA Enforcement: Key Case Studies in Securities Markets (Part 2)
This section continues the exploration of landmark adjudicating orders and legal precedents regarding the Prevention of Money Laundering Act (PMLA). These cases delve into systemic failures in alert management, the nuances of penalty proportionality, and the emerging regulatory landscape for digital payment banks and virtual asset providers.
8.5 Case Study: SEBI vs. Shreepati Holdings & Finance Pvt. Ltd.
Background and Investigative Scope
SEBI inspected the books and records of Shreepati Holdings & Finance Pvt. Ltd. (SHF) in February 2015 to evaluate their compliance with Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT) norms. The inspection covered the period from April 2013 to December 2014.
Specific Allegations and Findings
The investigation revealed several critical lapses in the intermediary's internal control systems:
- Delay in Policy Updates: SHF admitted to a delay of eight months in updating their AML policy as required by the SEBI Circular dated March 12, 2014. The entity argued there was no fixed timeline, but SEBI maintained that immediate compliance with mandatory obligations is required.
- Failure to Document Alert Closures: During the inspection, it was found that SHF had received 83 alerts from BSE and 54 alerts from NSE. SHF closed all these alerts without recording any reasons or maintaining electronic/written records of the data examined.
- Lack of Financial Monitoring: The entity lacked a mechanism to monitor client transactions against their declared financial status.
- Belated Corrective Action: SHF only took corrective steps after the issuance of a Show Cause Notice (SCN) in 2017, remaining non-compliant for more than two years after the initial inspection.
Final Adjudication
SEBI concluded that such lapses pose a serious threat to the national economy. Consequently, a penalty of Rs. 3,00,000 was imposed under Section 15HB of the SEBI Act.
8.6 Case Study: BOI Shareholding Limited (BOISL) v/s SEBI
Facts of the Case
Following an inspection in June 2015, SEBI identified discrepancies in BOISL’s implementation of AML/CFT policies. The initial order found that the appellant had delayed the proper implementation of the required policy framework by two to four years.
Core Violations
The violations included non-incorporation of provisions from:
- The SEBI Master Circular on AML/CFT (December 2010).
- Guidelines on Identification of Beneficial Ownership (January 2013).
- Modifications to the AML Circular (March 2014).
Appeal and Proportionality of Penalty
SEBI originally imposed a penalty of Rs. 40 Lakh. BOISL appealed to the Securities Appellate Tribunal (SAT), arguing the following:
- The violations were procedural and did not adversely affect investors.
- The penalty was disproportionately high compared to other similar cases (e.g., IFCI Financial Services or Triveni Management).
SAT Decision
The Tribunal noted that while the implementation was delayed, BOISL was eventually in compliance with the required standards. SAT reduced the penalty from Rs. 40 Lakh to Rs. 6 Lakh, acknowledging the need for a deterrent but finding the original amount excessive.
8.7 Case Study: FIU-IND vs. Paytm Payments Bank Limited
Nature of the Syndicate and Fraud
This case began with law enforcement identifying extensive illegal activity involving online gambling, dating services, and fraudulent streaming services. The proceeds of these activities were routed through accounts maintained with Paytm Payments Bank.
Regulatory Breaches
FIU-IND found that the bank failed to discharge its duties as a Reporting Entity under Chapter IV of the PMLA. Specific violations included:
- Payout Service Failures: Failure to implement an internal mechanism to detect and report suspicious transactions related to its "Payout" services.
- Ongoing Due Diligence: Failure to exercise ongoing monitoring of accounts belonging to entities involved in the illegal syndicate.
- Third-Party KYC Non-Compliance: The bank relied on a non-compliant or unregulated entity for third-party KYC, violating Rule 9(2)(c) of the PML Rules.
- STR Filing Delays: Failure to file Suspicious Transaction Reports (STRs) for 34 beneficiary accounts within prescribed timelines.
Final Order
In March 2024, the Director of FIU-IND substantiated the charges and imposed a fine of Rs. 5,49,00,000 on the bank.
8.8 Case Study: FIU-IND vs. Bybit Fintech Limited
VDA Service Provider Obligations
Bybit Fintech Limited, a Virtual Digital Asset Service Provider (VDA SP), is classified as a "reporting entity" under the PMLA. This case highlights the requirement for all VDA SPs to adhere to AML/CFT guidelines issued on March 10, 2023.
Findings of Non-Compliance
The investigation revealed that Bybit:
- Expanded its services in India without securing mandatory registration with FIU-IND.
- Persistently failed to comply with reporting obligations, leading the Ministry of Electronics and Information Technology (MEITY) to block its websites.
Adjudication and Penalty
The Director of FIU-IND established that Bybit violated several rules of the PMLR, 2005, including those regarding the maintenance of records and furnishing of information. A total monetary penalty of Rs. 9,27,00,000 was imposed on January 31, 2025.
Key Takeaways for Compliance Officers
- Documented Closure of Alerts: It is not enough to investigate an alert; the rationale for closing it must be documented and available for audit.
- VDA Registration: Entities dealing with Virtual Digital Assets must prioritize registration with FIU-IND before offering services in the Indian market.
- Ongoing Monitoring: Due diligence is not a one-time onboarding task; reporting entities must monitor transactions against the client's declared profile continuously.
- Proportionality in Penalties: While SAT may reduce penalties for purely procedural delays, the initial fines imposed by SEBI and FIU-IND are substantial and can significantly impact a firm's reputation and finances.
Important Terms to Remember
- VDA SP (Virtual Digital Asset Service Provider): Entities providing exchange, transfer, or safekeeping services for digital assets.
- SAT (Securities Appellate Tribunal): The statutory body that hears appeals against SEBI and other regulatory orders.
- MEITY: The Ministry of Electronics and Information Technology, responsible for actions such as blocking non-compliant websites.
- Ongoing Due Diligence: The requirement to examine transactions throughout the course of a business relationship.
- SCN (Show Cause Notice): A formal notice issued by a regulator requiring an entity to explain why legal action should not be taken against them.