KYCKART
KYCKART Guide · August 2026Guide

AML Software: What It Does and How It Fits BFSI Compliance

AML software automates the four PMLA-mandated functions: transaction monitoring, PEP screening, risk scoring, and case management. What Indian BFSI compliance teams should check before buying.

calendar_monthAugust 2026
schedule10 min read
library_books34 Cited Sources
personBhanujeet Choudhary, Head of Compliance

AML software is the operational layer that lets a bank, NBFC, insurer, or securities intermediary meet its anti-money-laundering obligations under India’s Prevention of Money Laundering Act (PMLA) at the volume regulators now expect: screening transactions and customers, scoring risk, and managing the investigation trail that ends in a report to FIU-IND. It automates four core functions that reporting entities are legally required to perform regardless of whether they use software to do it: transaction monitoring, sanctions and PEP screening, customer risk scoring, and case management. Software changes the speed and auditability of that work. The underlying obligation itself is set by PMLA, RBI, IRDAI, or SEBI depending on the type of entity.

01

What AML Software Actually Does

AML vendors converge on the same four-part breakdown of what the software actually covers, corroborated across two independent sources.

Tookitaki’s buyer guidedescribes well-integrated platforms as ones where a change in a customer’s risk score automatically reprioritises transaction-monitoring alerts. Disconnected, siloed point solutions, by contrast, create manual reconciliation work between screening hits and case-management queues.

03

Screening, PEP Handling, and Where the Regime Now Extends

Screening, PEP handling, and periodic KYC updates

Mandatory sanctions screening in India covers the UNSC Sanctions Lists, implemented domestically through orders under the UN (Security Council) Act and published in India’s Official Gazette, plus lists maintained under Section 51A of the Unlawful Activities (Prevention) Act, 1967, specifically UAPA’s Schedule I (banned organisations) and Schedule IV (banned individuals), administered by the Ministry of Home Affairs.

One AML-vendor source, Zigram, describes banks as required to verify customer databases against sanctions lists daily, and states that RBI’s KYC Master Direction (as amended, described there as last amended in October 2023) encourages regulated entities to use “technological innovations and tools for effective name screening.” That specific daily-verification detail comes from a single vendor source and wasn’t independently corroborated against RBI’s own circular text for this piece.

A circular effective around January 2024 redefined Politically Exposed Persons as individuals entrusted with prominent public functions by a foreign country (heads of state or government, senior politicians, senior government, judicial, or military officers, senior state-owned-corporation executives, and important political-party officials), narrowing an earlier, more open-ended definition. PEP accounts require Enhanced Due Diligence, including verification of source of wealth and source of funds, and require senior-management approval to open.

RBI’s KYC norms, per amendments reported effective 6 November 2024, also set risk-tiered periodic KYC-updation cycles: at least once every two years for high-risk customers, eight years for medium-risk customers, and ten years for low-risk customers.

Crypto exchanges are now inside the same regime

A Ministry of Finance notification dated 7 March 2023 brought virtual digital asset (VDA) and cryptocurrency exchanges and related service providers within PMLA’s reporting-entity regime, subjecting them to the same KYC, AML due-diligence, recordkeeping, and STR-filing obligations as banks and other financial institutions.

04

AML Rules Aren’t the Same Across Every BFSI Segment

SegmentRegulator and Key InstrumentDistinguishing Requirement
Banks and NBFCsRBI, KYC Master Direction (2016), restructured Nov 2025 + PMLASTR/CTR filing, periodic risk-based KYC updation
InsurersIRDAI, Master Guidelines on AML/CFT, effective 1 August 2022, consolidating a Feb 2013 general-insurer instrument and a Sept 2015 life-insurer circularA separate track from banking AML, run under IRDAI rather than RBI
Securities intermediariesSEBI, Master Circular on AML/CFT Standards, dated 6 June 2024, superseding its February 2023 versionRequires real-time suspicious-transaction monitoring and reporting
Fintech lending partnershipsIndirect, via the partnering bank/NBFC, under RBI’s 2022 Digital Lending GuidelinesOnly the Regulated Entity may extend credit directly; the fintech functions as a Lending Service Provider, and the partnering RE remains responsible for compliance and for disbursing funds directly into the borrower’s account
05

FATF’s Scorecard and What Happens When Software Is Missing

Where India stands on FATF’s scorecard

FATF’s Mutual Evaluation Report on India, adopted at FATF’s Plenary in Singapore in June 2024, placed India in “regular follow-up,” FATF’s highest rating tier, finding India compliant or largely compliant with 37 of the 40 FATF Recommendations, one of only a small number of G20 countries holding that status at the time.

Two of those Recommendations map directly onto what AML software is built to do. Recommendation 10 (Customer Due Diligence) requires financial institutions to identify and verify customers and beneficial owners, understand the business relationship, and conduct ongoing due diligence. Recommendation 20 (Reporting of Suspicious Transactions) requires institutions that suspect proceeds of crime or terrorist financing to report that suspicion promptly to their national Financial Intelligence Unit. FATF’s risk-based approachprinciple asks institutions to identify, assess, and understand the money-laundering and terrorist-financing risks they face, and to apply enhanced measures to higher-risk relationships and simplified measures to lower-risk ones. This summary of the FATF Recommendations is sourced to compliance-explainer coverage of FATF’s text rather than FATF’s own primary document, which wasn’t independently checked against this wording for this piece.

Money laundering is estimated by UNODC to total roughly 2-5% of global GDP each year, or US$800 billion to US$2 trillion, a range UNODC itself describes as difficult to establish precisely given the clandestine nature of money laundering. This is a global figure, not an India-specific one.

When missing software becomes an enforcement finding

On 10 July 2026, RBI imposed a ₹5.80 lakh penalty on Muthoot Finance Ltd, one of six NBFCs penalised in the same enforcement round, specifically citing the company’s failure to carry out periodic review of customer risk categorisation and its non-deployment of “robust software for effective identification and reporting of suspicious transactions.”The other five NBFCs penalised in the same round were Avail Financial Services (₹6.20 lakh), Muthoot Vehicle and Asset Finance (₹2.70 lakh, also cited for risk-categorisation-review lapses), Dhani Loans and Services (₹2.70 lakh), PAN Emami Cosmed (₹3.10 lakh), and Satya MicroCapital (₹3.10 lakh).

06

What This Means for Compliance Teams Evaluating AML Software

Read together, the Muthoot Finance enforcement action and the four-part AML-software architecture that Tookitaki and sanctions.io describe show the same pattern. In this enforcement round, RBI treated the absence of adequate detection and case-management systems as a compliance failure in its own right. RBI’s stated grounds for the penalty (failure to review customer risk categorisation, and non-deployment of software for identifying and reporting suspicious transactions) map closely onto two of the four functional components described earlier: customer risk scoring and transaction monitoring. The practical implication for a compliance team is to check a vendor’s coverage against these specific functions before treating “we have AML software” as a satisfied checkbox.

The STR and CTR requirements illustrate two different enforcement logics sitting inside the same reporting regime. A CTR is a fixed-threshold, largely mechanical filing: ₹10 lakh or more in cash, filed by the 15th of the following month. An STR carries no minimum threshold at all and depends entirely on the Principal Officer’s judgment that a transaction looks suspicious, filed within seven working days of that judgment forming. Software tuned only to flag threshold-crossing transactions covers the CTR side of the obligation; the STR side depends on risk-scoring and pattern logic feeding a human decision-maker, a different capability. A vendor evaluation built only around threshold-rule performance is testing half the reporting requirement.

The regulatory split between RBI, IRDAI, and SEBI, combined with the accountability question RBI’s Digital Lending Guidelines raise for fintech Lending Service Providers, means a BFSI group that spans a bank, an insurance arm, and a fintech-partnership channelanswers to more than one AML rulebook at once. The practical implication is that software procurement decisions need to trace back to which regulator, and which specific reporting entity, actually carries the compliance obligation for each business line. One AML platform configuration won’t necessarily satisfy every entity in the group.

verified

How KYCKART Helps

KYCKART is a unified KYC and fraud intelligence platform for India’s BFSI sector, built so a change in a customer’s risk score feeds directly into transaction-monitoring and case-management workflows instead of sitting in a separate, disconnected tool. Speak with our team to see how it maps to your AML compliance obligations.

Frequently Asked Questions

person

Bhanujeet Choudhary

Head of Compliance, KYCKART

Published August 25, 2026

Disclaimer: This piece summarizes publicly available regulatory guidance (RBI, PMLA/FIU-IND, IRDAI, SEBI, FATF) and third-party industry commentary for informational purposes. It is not legal, tax, or compliance advice. Institutions should confirm current regulatory requirements directly with the relevant regulator and evaluate vendor claims against their own compliance obligations before acting on anything summarized here.

KYCKART Intelligence

Screen, Score, and Report Without the Manual Reconciliation

KYCKART’s fraud intelligence platform brings transaction monitoring, sanctions and PEP screening, and case management into one system, so a change in a customer’s risk score doesn’t sit stuck in a queue between disconnected tools.

Explore AML & Fraud Intelligencearrow_forward