Chapter 3: Complete Study Notes on PML (Maintenance of Records) Rules, 2005: Part 4 - Entity KYC, Ongoing Monitoring, CDD Programs, & Periodic Updation

Complete Study Notes on PML (Maintenance of Records) Rules, 2005: Part 4 - Entity KYC, Ongoing Monitoring, CDD Programs, & Periodic Updation

This final section completes the operational notes on Chapter 3 of the Prevention of Money-laundering (Maintenance of Records) Rules, 2005 (PMLR) and its integration with the International Financial Services Centres Authority (IFSCA) guidelines. It details the specific documentation required to verify non-individual clients (such as companies, partnerships, and trusts), the statutory duties for ongoing transaction monitoring, the setup of senior-management-approved Customer Due Diligence (CDD) programs, and the risk-based timelines for periodic KYC updates.

1. Statutory KYC Documentation for Legal Entities and Arrangements

When the client is a non-natural person, the reporting entity must obtain and verify certified copies (or equivalent electronic documents) of specific constitutional, financial, and operational records to establish the entity's legal existence, structure, and authorization.

Table: Mandatory Onboarding Documents by Entity Type

Client Legal Structure Mandatory Constitutional & Tax Documents Authorisation & Operational Documents Associated Individual KYC Requirements
Company • Certificate of Incorporation• Memorandum of Association (MoA)• Articles of Association (AoA)• Permanent Account Number (PAN) • Board of Directors resolution• Power of Attorney (PoA) granted to managers/officers to transact on its behalf• Registered office and principal place of business address (if different) • Names of senior management officials• Individual KYC (under Rule 9(4)) for ultimate beneficial owners (UBOs), managers, and attorneys
Partnership Firm • Registration Certificate• Partnership Deed• PAN of the partnership firm • Power of Attorney or authority letters granted to partners or employees to transact on its behalf • Individual KYC (under Rule 9(4)) for UBOs, partners, managers, and authorized attorneys
Trust • Registration Certificate• Trust Deed• PAN or Form No. 60 of the trust • List of current trustees• Address of the registered office of the trust • Names and addresses of beneficiaries, trustees, settlor, and authors• Individual KYC (under Rule 9(4)) for trustees and authorized transacting officials
Unincorporated Association or Body of Individuals • PAN or Form No. 60 of the association• Documents establishing collective existence • Resolution of the managing body• Power of Attorney granted to authorized transacting individuals • Individual KYC (under Rule 9(4)) for UBOs, managers, officers, and authorized attorneys

The 30-Day Document Update Rule

Under Rule 9(9B), if any document submitted by a client for onboarding undergoes an update or change, the client is legally required to submit the updated document to the reporting entity within 30 days of that change.

2. Authorization, Trust Status Disclosure, and the Ban on Anonymous Accounts

To prevent the use of front companies or fictitious names, the PMLR establishes strict rules on representation and transparency.

Verifying Representation Authority

Under Rule 9(10), whenever a person purports to act on behalf of a juridical person, individual, or trust, the reporting entity must perform a two-step check:

  1. Verify Authority: Verify that the representative is properly authorized to act on the client's behalf.
  2. Verify Identity: Confirm the identity of the representative using standard individual verification methods.

Mandatory Status Disclosure by Trustees

Trusts present high money laundering risks due to their potential for hiding ownership. To address this, the PMLR requires trustees to explicitly disclose their status as trustees to the reporting entity at the time of opening an account or executing any high-value occasional transaction.

Complete Prohibition on Anonymous and Fictitious Accounts

Under Rule 9(11), reporting entities are strictly prohibited from:

  • Opening or maintaining anonymous accounts.
  • Opening or maintaining accounts in fictitious or dummy names.
  • Maintaining accounts on behalf of other persons whose identities are undisclosed or cannot be verified.

3. Rule 9(12) & 9(13): Ongoing Due Diligence and Enterprise-Wide Risk Assessments

Customer due diligence is an ongoing obligation that requires continuous monitoring and risk evaluation.

No. ODD Component What It Involves Purpose
1 🔎 Transaction Monitoring Examine account activity to determine whether transactions are consistent with the client's profile, business, and risk level. Detect unusual or potentially suspicious activity.
2 🚨 Trigger-Based Reviews Re-verify the customer's identity when suspicion arises or the accuracy/veracity of existing information is doubted. Ensure customer information remains reliable.
3 👤 Existing Client Re-Review Apply appropriate CDD measures to existing customers based on the materiality of information and customer's risk rating. Keep customer due diligence current and risk-appropriate.

Ongoing Due Diligence Requirements (Rule 9(12))

  • Transaction Consistency: Reporting entities must closely monitor and examine transactions to ensure they match their knowledge of the client, the client's business, their risk profile, and, where necessary, their source of funds.
  • Triggers for Immediate Identity Re-verification: Entities must review due diligence records and re-verify client identities if:
    1. They suspect money laundering or terrorist financing.
    2. They doubt the adequacy or truthfulness of previously obtained client identification data.
  • Existing Client Reviews: CDD measures must be applied to existing clients based on risk and materiality, at times appropriate to the risk level.

Documented Risk Assessment Mandate (Rule 9(13))

Every reporting entity must carry out and document a comprehensive risk assessment to identify, assess, and mitigate its money laundering and terrorist financing risks. This assessment must:

  • Scope: Analyze risk across clients, countries/geographic areas, and products, services, transactions, or delivery channels.
  • National Alignment: Align with any national risk assessment conducted by the Central Government.
  • Maintenance: Be documented, kept up to date, and made readily available to competent authorities and self-regulating bodies upon request.

4. Rule 9(14): Formulating the Client Due Diligence (CDD) Programme

Under Rule 9(14)(ii), every reporting entity must formulate and implement a structured Client Due Diligence Programme.

Core Requirements of the CDD Programme

  • Board and Senior Management Approval: The program's policies, controls, and procedures must be approved by senior management.
  • Risk Mitigation Systems: It must include operational systems to manage and mitigate the risks identified by the entity's own risk assessments and the national risk assessment.
  • The Simplified CDD Exception: While simplified measures can be used for low-risk clients, simplified measures are strictly prohibited if:
    • There is any suspicion of money laundering or terrorist financing.
    • Specific high-risk scenarios apply.
    • The identified risk is inconsistent with the national risk assessment.

5. Periodic Updation of KYC: Risk-Based Timelines & Workflows

To ensure customer information remains accurate, reporting entities must update client records on a scheduled, risk-based timeline.

Table: Periodic Updation Timelines (Standard vs. Indian Financial Group Resident)

Customer Risk Categorisation Standard Periodic Updation Frequency Resident Indian Customer with Financial Group Key Operational Verification Requirements
High Risk Annually (Once every year) Once in every two years Requires comprehensive verification of documents, source of wealth, and live updates. Stricter timeline applies in case of conflict.
Medium Risk Once in three years Once in every eight years Update of records; verification of changed details.
Low Risk Once in every five years Once in every ten years Simplified update; can use self-declarations for unchanged information.

Updation Workflows for Individual Customers

  • Scenario A: No Change in CDD Information:
    • The client can submit a self-declaration stating that their information has not changed.
    • This declaration can be submitted digitally via the client's registered mobile number, email, or digital banking applications.
  • Scenario B: Change in Address Only:
    • The client can submit a self-declaration of the new address through registered digital channels.
    • Positive Confirmation Mandate: The reporting entity must verify this new address within two months using methods like address verification letters, contact point verification, or physical mail deliveries.
    • The client must also provide a copy of an OVD (or equivalent e-document) for the new address as specified in the entity's KYC policy.

Updation Workflows for Non-Natural Persons

  • No Change in Information: The entity must submit a self-declaration through registered digital channels or a physical letter signed by an authorized official, along with the necessary board resolutions. The reporting entity must also verify that the beneficial ownership (BO) records on file are accurate and up to date.
  • Change in Information: If any information has changed, the reporting entity must conduct a fresh CDD process equivalent to onboarding a new non-natural customer.

6. Failure to Conduct or Complete CDD & Tipping-Off Safeguards

If a reporting entity cannot complete the required Customer Due Diligence, it must apply strict risk-mitigation measures.

Required Actions on CDD Failure

Under the guidelines, if a reporting entity cannot complete initial CDD or periodic updates, it must:

  • Refuse to open the account or provide the requested service.
  • Refuse to execute any transactions for the customer.
  • Decline to establish or continue the business relationship.
  • Terminate or suspend any existing business relationship.
  • Return any money or assets received from the customer.
  • Evaluate whether the failure to complete CDD requires filing a Suspicious Transaction Report (STR) with FIU-IND.

The "Tipping Off" Override

A reporting entity is exempted from blocking transactions or terminating the relationship if doing so would result in tipping off the customer (alerting them to regulatory suspicion) or if the Director of FIU-IND explicitly instructs the entity to maintain operations.

7. Key Terms and Definitions Reference

  • Fictitious Name Account: An account opened under an invented, false, or dummy identity to hide the true owner's name, which is strictly prohibited under Rule 9(11).
  • CDD Programme: A risk-management framework containing policies, controls, and procedures approved by senior management to mitigate money laundering risks.
  • Simplified Customer Due Diligence (SCDD): A simplified verification process permitted for low-risk customers, which is prohibited in any high-risk or suspicious transaction scenario.
  • Tipping-Off: The illegal act of disclosing to a customer that their transactions are being analyzed or reported as suspicious, which would compromise active financial investigations.

8. Exam-Focused Practice Questions

Question 1

Under Rule 9(9B) of the PML (Maintenance of Records) Rules, 2005, if a client's submitted KYC documents are updated, within how many days must the client submit the updated records to the reporting entity?

  • A) 7 days
  • B) 10 days
  • C) 30 days
  • D) 60 days

Answer: C Explanation: Rule 9(9B) states that where the client has submitted documents for verification, they must submit any update to those documents within 30 days of the update to the reporting entity.

Question 2

Under the PMLR and regulatory guidelines, under which of the following scenarios is a reporting entity permitted to apply Simplified Customer Due Diligence (SCDD) measures?

  • A) When there is a minor suspicion of tax evasion but no terror financing links.
  • B) When a client is categorized as low-risk and there are no suspicions of money laundering.
  • C) When the client is a foreign non-profit organization registered on the DARPAN portal.
  • D) When the transaction involves an occasional cross-border wire transfer under USD 1,000.

Answer: B Explanation: Under Rule 9(14), simplified measures are acceptable only for low-risk clients and are explicitly not permitted if there is any suspicion of money laundering or terrorist financing.

Question 3

If a client changes their address and submits a self-declaration, the reporting entity must complete positive confirmation and verification of the new address within:

  • A) 30 days
  • B) 2 months
  • C) 3 months
  • D) 6 months

Answer: B Explanation: In case of a change in address during periodic updates, a self-declaration can be accepted, but the new address must be verified through positive confirmation within two months.

 

Practice with a Free Mock Test

Ready to test your NISM IFSCA 01: Anti Money Laundering and Counter Terrorist Financing Certification in the IFSC preparation? Start with Test 1 — no payment required.

Notify me when you update the Notes

Free account · No payment needed for Test 1

Create a free PassNISM account

Continue with Google to start a free NISM mock test (Test 1) for this subject, save scores, and compare attempts.

Continue with Google