The Prevention of Money-laundering (Maintenance of Records) Rules, 2005
The Prevention of Money-laundering (Maintenance of Records) Rules, 2005, serves as the operational backbone for implementing the PMLA. While the Act provides the legal framework, these Rules define the specific procedures and standards reporting entities must follow to detect and prevent financial crimes.
3.1 Introduction to the Maintenance of Records Rules
Rules are secondary to the Act and are designed to provide flexibility in implementation. The 2005 Rules were created by the Central Government in consultation with the Reserve Bank of India (RBI) to govern how banking companies, financial institutions, and intermediaries maintain records of transaction nature and value. These rules were notably amended in March 2023 to further strengthen the financial sector's security.
Core Requirements for Reporting Entities
Reporting entities are mandated to:
- Develop Internal Controls: Establish policies and systems to prevent money laundering.
- Conduct Customer Due Diligence (CDD): Follow rigorous processes before onboarding or executing transactions.
- Report Suspicious Activity: Notify authorities of transactions that lack economic rationale or suggest illicit origin.
- Maintain Identity Records: Keep digital or physical records of client identities as specified by regulators.
3.2 Maintenance of Records of Transactions (Rule 3)
Rule 3 outlines the specific categories of transactions for which records must be kept.
Transaction Thresholds and Categories
| Transaction Type | Threshold/Requirement |
|---|---|
| All Cash Transactions | Value exceeding INR 10 lakh or foreign equivalent. |
| Connected Cash Series | Individually below 10 lakh but aggregating above 10 lakh in a month. |
| Non-Profit Organisations (NPO) | Receipts exceeding INR 10 lakh. |
| Counterfeit Currency | All transactions involving forged notes or security documents. |
| Suspicious Transactions | All attempted or executed transactions regardless of amount. |
| Cross-border Wire Transfers | Value exceeding INR 5 lakh where origin or destination is India. |
| Immovable Property | Purchase/sale valued at INR 50 lakh or more. |
Reporting Timelines (Rule 8)
- Monthly Reports: Transactions under Rule 3 (A, B, BA, C, and E) must be furnished by the 15th day of the succeeding month.
- Suspicious Transaction Reports (STR): Must be reported within seven working days after the Principal Officer is satisfied of the suspicion.
- Quarterly Reports: Immovable property transactions (Rule 3F) are due by the 15th day of the month succeeding the quarter.
Rule 9: Client Due Diligence (CDD) Framework
Reporting entities must identify clients and verify their identity using reliable and independent sources at the start of an account-based relationship or for occasional transactions exceeding INR 50,000.
Identification of Beneficial Owners (BO)
The rules specify thresholds for determining who ultimately controls a client:
- Companies: Natural persons with more than 10% shares, capital, or profits.
- Partnership Firms: Natural persons with more than 10% of capital or profits.
- Unincorporated Associations/Body of Individuals: Persons with more than 15% of property or capital.
- Trusts: Identification includes the settlor, trustees, and beneficiaries with 10% or more interest.
Central KYC Records Registry (CKYCR)
Reporting entities must file an electronic copy of a client's KYC records with the CKYCR within ten days of starting an account-based relationship. The Registry issues a unique KYC Identifier to the client. Entities must retrieve records online using this identifier and are generally prohibited from requiring additional documents unless there is a change in information or records are incomplete.
3.3 Digital Know Your Customer (KYC) Procedure
Digital KYC is a technology-driven process allowing for remote or streamlined onboarding.
The Digital Onboarding Process
- Authenticated Application: Process must occur through a secured, login-controlled app developed by the reporting entity.
- Live Photo Capture: The authorized officer must take a live photograph of the client against a white background.
- Watermarking: The photo must be embedded with a watermark containing the CAF number, GPS coordinates (latitude/longitude), name of the official, employee code, date, and time stamp.
- Document Verification: Live photos of original Officially Valid Documents (OVD) are captured vertically to ensure readability.
- OTP Validation: An OTP sent to the client's mobile number acts as a digital signature on the Customer Application Form (CAF).
- Official Declaration: The authorized officer provides a verified declaration and a live photo of themselves to conclude the process.
Key Takeaways
- Record Retention: Records must generally be maintained for five years from the date of transaction or the end of the business relationship.
- Confidentiality: The fact that a record is being maintained or an STR has been filed must remain strictly confidential to prevent tipping-off.
- Small Accounts: Can be opened with self-attested photos but have limits on credits (INR 1 lakh/year) and balances (INR 50k).
Important Terms
- Principal Officer: A management-level officer responsible for reporting suspicious transactions to FIU-IND.
- Designated Director: Ensures overall compliance with PMLA obligations.
- Officially Valid Document (OVD): Includes passport, driving license, Aadhaar, or Voter Identity Card.
- Tipping-off: Disclosing to a client that their transaction is being monitored or reported, which is prohibited.