AML Software: What It Does and How It Fits BFSI Compliance
AML software automates the four PMLA-mandated functions: transaction monitoring, PEP screening, risk scoring, and case management. What Indian BFSI compliance teams should check before buying.
AML software is the operational layer that lets a bank, NBFC, insurer, or securities intermediary meet its anti-money-laundering obligations under India’s Prevention of Money Laundering Act (PMLA) at the volume regulators now expect: screening transactions and customers, scoring risk, and managing the investigation trail that ends in a report to FIU-IND. It automates four core functions that reporting entities are legally required to perform regardless of whether they use software to do it: transaction monitoring, sanctions and PEP screening, customer risk scoring, and case management. Software changes the speed and auditability of that work. The underlying obligation itself is set by PMLA, RBI, IRDAI, or SEBI depending on the type of entity.
What AML Software Actually Does
AML vendors converge on the same four-part breakdown of what the software actually covers, corroborated across two independent sources.
| Component | What It Does |
|---|---|
| Transaction monitoring | Screens transaction patterns against configured rules and/or machine-learning models, generating alerts when activity exceeds defined risk thresholds |
| Sanctions and PEP screening | Checks customers and counterparties against government sanctions lists, PEP databases, and increasingly adverse-media sources |
| Customer risk scoring | Assigns a dynamic risk rating based on customer profile and transaction behaviour, feeding enhanced-due-diligence triggers |
| Case management | The investigation workflow layer where analysts review alerts, document their reasoning, and draft STR filings from retained evidence |
Tookitaki’s buyer guidedescribes well-integrated platforms as ones where a change in a customer’s risk score automatically reprioritises transaction-monitoring alerts. Disconnected, siloed point solutions, by contrast, create manual reconciliation work between screening hits and case-management queues.
The Legal Backbone: PMLA and RBI’s KYC Framework
RBI’s Master Direction on Know Your Customer (RBI/DBR/2015-16/18, issued 25 February 2016) required regulated entities to follow customer identification procedures, monitor customer transactions, and comply with AML standards, building on the Prevention of Money Laundering Act, 2002 and its 2005 Maintenance of Records Rules.
On 28 November 2025, RBI consolidated its regulatory instructions into a new set of Master Directions, replacing that single 2016 KYC Direction with 10 new sector-specific KYC Master Directions covering commercial banks, NBFCs, small finance banks, payments banks, urban and rural co-operative banks, local area banks, regional rural banks, asset reconstruction companies, and All India Financial Institutions. Secondary sources disagree on the scale of that consolidation: Taxscan reports 238 consolidated Master Directions and roughly 9,000 circulars reorganised, while TeamLease RegTech reports 244 Master Directions and 9,445 circulars repealed or withdrawn. Treat the headline count as reported rather than settled to one authoritative figure; specific circular or notification numbers for the 10 new sector-specific directions weren’t available in the sources reviewed for this piece.
Underneath that KYC framework, PMLA sets the substantive obligations. Section 12(1) requires reporting entities to maintain records of all transactions, attempted or executed, plus records identifying clients and beneficial owners, for five years from the transaction date, and to furnish that information to the Director, FIU-IND, within specified timelines. Section 12AA requires client due diligence: verifying client identity (which may include Aadhaar Act authentication), establishing source of funds, understanding the purpose of the transaction and the relationship between transacting parties, and identifying the beneficial owner. Section 13 empowers the Director, FIU-IND to impose monetary penalties of ₹10,000 to ₹1,00,000 per violation for failing to meet these recordkeeping and reporting obligations. Every reporting entity must also appoint a Principal Officer, responsible for filing statutory reports with FIU-IND and acting as the entity’s point of liaison with the regulator.
What gets reported, and when
Reporting entities file different statutory reports with FIU-IND depending on the nature of the transaction: Suspicious Transaction Report (STR), Cash Transaction Report (CTR), Non-Profit Organisation Transaction Report (NTR), Counterfeit Currency Report (CCR), and Cross-Border Wire Transfer Report (CBWTR). Two of these carry very different triggers.
| Report | Trigger | Deadline |
|---|---|---|
| STR | No minimum threshold, filed once the Principal Officer becomes satisfied a transaction is suspicious, cash or otherwise | Within seven working days of that determination, under Rule 8 of the PMLA Maintenance of Records Rules, 2005 (Notification No. 9/2005, dated 1 July 2005) |
| CTR | Cash transactions, single or a connected series within a calendar month, of ₹10 lakh or more | By the 15th of the following month |
Reporting entities register with, and file these reports through, FIU-IND’s FINGate 2.0 portal, the successor to the earlier FINnet system, using a Reporting Entity Identification Number issued at registration. FINGate 2.0 is documented as part of FIU-IND’s wider technology rollout.
Screening, PEP Handling, and Where the Regime Now Extends
Screening, PEP handling, and periodic KYC updates
Mandatory sanctions screening in India covers the UNSC Sanctions Lists, implemented domestically through orders under the UN (Security Council) Act and published in India’s Official Gazette, plus lists maintained under Section 51A of the Unlawful Activities (Prevention) Act, 1967, specifically UAPA’s Schedule I (banned organisations) and Schedule IV (banned individuals), administered by the Ministry of Home Affairs.
One AML-vendor source, Zigram, describes banks as required to verify customer databases against sanctions lists daily, and states that RBI’s KYC Master Direction (as amended, described there as last amended in October 2023) encourages regulated entities to use “technological innovations and tools for effective name screening.” That specific daily-verification detail comes from a single vendor source and wasn’t independently corroborated against RBI’s own circular text for this piece.
A circular effective around January 2024 redefined Politically Exposed Persons as individuals entrusted with prominent public functions by a foreign country (heads of state or government, senior politicians, senior government, judicial, or military officers, senior state-owned-corporation executives, and important political-party officials), narrowing an earlier, more open-ended definition. PEP accounts require Enhanced Due Diligence, including verification of source of wealth and source of funds, and require senior-management approval to open.
RBI’s KYC norms, per amendments reported effective 6 November 2024, also set risk-tiered periodic KYC-updation cycles: at least once every two years for high-risk customers, eight years for medium-risk customers, and ten years for low-risk customers.
Crypto exchanges are now inside the same regime
A Ministry of Finance notification dated 7 March 2023 brought virtual digital asset (VDA) and cryptocurrency exchanges and related service providers within PMLA’s reporting-entity regime, subjecting them to the same KYC, AML due-diligence, recordkeeping, and STR-filing obligations as banks and other financial institutions.
AML Rules Aren’t the Same Across Every BFSI Segment
| Segment | Regulator and Key Instrument | Distinguishing Requirement |
|---|---|---|
| Banks and NBFCs | RBI, KYC Master Direction (2016), restructured Nov 2025 + PMLA | STR/CTR filing, periodic risk-based KYC updation |
| Insurers | IRDAI, Master Guidelines on AML/CFT, effective 1 August 2022, consolidating a Feb 2013 general-insurer instrument and a Sept 2015 life-insurer circular | A separate track from banking AML, run under IRDAI rather than RBI |
| Securities intermediaries | SEBI, Master Circular on AML/CFT Standards, dated 6 June 2024, superseding its February 2023 version | Requires real-time suspicious-transaction monitoring and reporting |
| Fintech lending partnerships | Indirect, via the partnering bank/NBFC, under RBI’s 2022 Digital Lending Guidelines | Only the Regulated Entity may extend credit directly; the fintech functions as a Lending Service Provider, and the partnering RE remains responsible for compliance and for disbursing funds directly into the borrower’s account |
FATF’s Scorecard and What Happens When Software Is Missing
Where India stands on FATF’s scorecard
FATF’s Mutual Evaluation Report on India, adopted at FATF’s Plenary in Singapore in June 2024, placed India in “regular follow-up,” FATF’s highest rating tier, finding India compliant or largely compliant with 37 of the 40 FATF Recommendations, one of only a small number of G20 countries holding that status at the time.
Two of those Recommendations map directly onto what AML software is built to do. Recommendation 10 (Customer Due Diligence) requires financial institutions to identify and verify customers and beneficial owners, understand the business relationship, and conduct ongoing due diligence. Recommendation 20 (Reporting of Suspicious Transactions) requires institutions that suspect proceeds of crime or terrorist financing to report that suspicion promptly to their national Financial Intelligence Unit. FATF’s risk-based approachprinciple asks institutions to identify, assess, and understand the money-laundering and terrorist-financing risks they face, and to apply enhanced measures to higher-risk relationships and simplified measures to lower-risk ones. This summary of the FATF Recommendations is sourced to compliance-explainer coverage of FATF’s text rather than FATF’s own primary document, which wasn’t independently checked against this wording for this piece.
“Money laundering is estimated by UNODC to total roughly 2-5% of global GDP each year, or US$800 billion to US$2 trillion, a range UNODC itself describes as difficult to establish precisely given the clandestine nature of money laundering. This is a global figure, not an India-specific one.”
When missing software becomes an enforcement finding
On 10 July 2026, RBI imposed a ₹5.80 lakh penalty on Muthoot Finance Ltd, one of six NBFCs penalised in the same enforcement round, specifically citing the company’s failure to carry out periodic review of customer risk categorisation and its non-deployment of “robust software for effective identification and reporting of suspicious transactions.”The other five NBFCs penalised in the same round were Avail Financial Services (₹6.20 lakh), Muthoot Vehicle and Asset Finance (₹2.70 lakh, also cited for risk-categorisation-review lapses), Dhani Loans and Services (₹2.70 lakh), PAN Emami Cosmed (₹3.10 lakh), and Satya MicroCapital (₹3.10 lakh).
What This Means for Compliance Teams Evaluating AML Software
Read together, the Muthoot Finance enforcement action and the four-part AML-software architecture that Tookitaki and sanctions.io describe show the same pattern. In this enforcement round, RBI treated the absence of adequate detection and case-management systems as a compliance failure in its own right. RBI’s stated grounds for the penalty (failure to review customer risk categorisation, and non-deployment of software for identifying and reporting suspicious transactions) map closely onto two of the four functional components described earlier: customer risk scoring and transaction monitoring. The practical implication for a compliance team is to check a vendor’s coverage against these specific functions before treating “we have AML software” as a satisfied checkbox.
The STR and CTR requirements illustrate two different enforcement logics sitting inside the same reporting regime. A CTR is a fixed-threshold, largely mechanical filing: ₹10 lakh or more in cash, filed by the 15th of the following month. An STR carries no minimum threshold at all and depends entirely on the Principal Officer’s judgment that a transaction looks suspicious, filed within seven working days of that judgment forming. Software tuned only to flag threshold-crossing transactions covers the CTR side of the obligation; the STR side depends on risk-scoring and pattern logic feeding a human decision-maker, a different capability. A vendor evaluation built only around threshold-rule performance is testing half the reporting requirement.
The regulatory split between RBI, IRDAI, and SEBI, combined with the accountability question RBI’s Digital Lending Guidelines raise for fintech Lending Service Providers, means a BFSI group that spans a bank, an insurance arm, and a fintech-partnership channelanswers to more than one AML rulebook at once. The practical implication is that software procurement decisions need to trace back to which regulator, and which specific reporting entity, actually carries the compliance obligation for each business line. One AML platform configuration won’t necessarily satisfy every entity in the group.
How KYCKART Helps
KYCKART is a unified KYC and fraud intelligence platform for India’s BFSI sector, built so a change in a customer’s risk score feeds directly into transaction-monitoring and case-management workflows instead of sitting in a separate, disconnected tool. Speak with our team to see how it maps to your AML compliance obligations.
Frequently Asked Questions
Bhanujeet Choudhary
Head of Compliance, KYCKART
Published August 25, 2026
Disclaimer: This piece summarizes publicly available regulatory guidance (RBI, PMLA/FIU-IND, IRDAI, SEBI, FATF) and third-party industry commentary for informational purposes. It is not legal, tax, or compliance advice. Institutions should confirm current regulatory requirements directly with the relevant regulator and evaluate vendor claims against their own compliance obligations before acting on anything summarized here.
KYCKART Intelligence
Screen, Score, and Report Without the Manual Reconciliation
KYCKART’s fraud intelligence platform brings transaction monitoring, sanctions and PEP screening, and case management into one system, so a change in a customer’s risk score doesn’t sit stuck in a queue between disconnected tools.
Explore AML & Fraud Intelligencearrow_forward