One Monday morning in September, a client reached out to me. The Managing Director of his NBFC in Pune had just received a notice from FIU-IND. Among other details, the notice requested the name, designation, employee ID, and appointment date of the company's Principal Officer as required by the PML Rules 2005. The company had never officially appointed anyone to this role. For years, the compliance team simply assigned whoever was handling KYC that week. Now, they had thirty days to respond.
This kind of situation is happening more often. In 2023, many more companies became Reporting Entities under the Prevention of Money Laundering Act, 2002. The 2024 CKYCR requirements made compliance even stricter. Recent FIU-IND penalties in 2024 and 2025 against Paytm Payments Bank, KuCoin, Binance, Bybit, and two co-operative banks show that enforcement is serious. If your organization is a Reporting Entity under PMLA and you do not have a named Principal Officer registered with FIU-IND and supported by a current Board resolution, your next audit could be problematic.
In this article, I will explain what the Principal Officer role involves, who needs to appoint one, what the appointment resolution should include, and how to build a practical AML program that stands up to an audit.
The Rules draw a sharp line between two roles
The PML (Maintenance of Records) Rules, 2005 require every Reporting Entity to fill two key roles. The first is the Principal Officer, as defined in Rule 2(1)(f). Rule 7 officially names this person to provide information to the Director, FIU-IND. The Principal Officer handles operations, signs STR filings, and manages the AML program day-to-day.
The second role is the Designated Director, defined in Rule 2(1)(fa). This person ensures the company complies with Chapter IV of the Act and the Rules. The Designated Director is usually a Board member or someone at that level. They do not handle daily alerts but are accountable in writing for the entire compliance program.
These two roles are meant to create both operational and governance accountability. In very small companies, one person might handle both roles, but they must cover all responsibilities. For most mid-sized NBFCs or brokerages, the Principal Officer is usually a senior Chief Compliance Officer or Head of Compliance, reporting directly to the Managing Director and also to the Chairman of the Audit Committee. The Designated Director is often a non-executive director or the Chairman of the Audit Committee.
Who must appoint one
Section 2(1)(wa) of PMLA defines a Reporting Entity as a banking company, a financial institution, an intermediary, or anyone running a designated business or profession under Section 2(1)(sa). For over a decade, banks, NBFCs, insurers, brokers, DPs, Mutual Funds, and AIFs have all been Reporting Entities. In 2023, the big change was the Central Government’s expanded notification power under Section 2(1)(sa)(vi).
In 2023, three notifications under Section 2(1)(sa)(vi) significantly expanded the scope of who is covered.
S.O. 1072(E) dated 7 March 2023 brought Virtual Digital Asset Service Providers under PMLA for five activities: fiat-to-VDA exchange, VDA-to-VDA exchange, VDA transfer, safekeeping and administration of VDAs, and participation in or provision of financial services related to an issuer's offer and sale of a VDA.
S.O. 1073(E), also dated 7 March 2023, includedreal-estate agents and developers for transactions where they buy or sell real estate for clients. This system is based on risk, not on transaction thresholds.
S.O. 2036(E) dated 3 May 2023 brought Chartered Accountants, Company Secretaries, and Cost Accountants under PMLA for five specific client-service activities: buying and selling property, managing client money, securities, or assets, managing bank, savings, or securities accounts, organizing contributions for creating or running companies, and creating or managing companies, LLPs, or trusts. This notification does not cover pure statutory audit or tax-return work, only operational client-service engagements.
On 11 October 2024, the FIU-IND AML/CFT Guidelines for Multi-State Co-operative Societies came into effect, applying Rule 3, Rule 7, and Rule 9 obligations to these organizations. The December 2025 penalty orders against Gandhinagar Nagarik Co-operative Bank and Rajgurunagar Sahakari Bank show that co-operative banks, which previously had lighter AML requirements, are now under stricter enforcement.
If your organisation falls into any of these categories, you currently need to appoint a Principal Officer.
The appointment resolution must say five specific things
From my experience reviewing Board resolutions on this topic, I know what works and what doesn't. A one-line resolution like, "Resolved that Mr X is appointed Principal Officer under PMLA," does not help the Principal Officer or the inspector. A good resolution clearly lists five specific authorities.
Access to records: The Principal Officer can access any record or system in the organization for AML purposes without needing extra permission.
Interview authority: The Principal Officer can interview any employee for AML purposes.
Freezing authority: The Principal Officer can order the freezing of any account immediately if there is a confirmed UNSC 1267 or MHA UAPA Section 51A designation.
Signing authority: The Principal Officer can sign and submit STR, CTR, NTR, CBWTR, and CCR filings for the organization under Rule 7 of the PML Rules.
Independence protections: The Board can remove the Principal Officer or reduce their authority only by a resolution recorded in the minutes. Their compensation is not tied to any business line’s origination targets.
If a Managing Director is unwilling to grant any of these five authorities, it shows the organization is not prepared for an FIU inspection.
The rules changed in 2024 and 2025, so the course materials you are using might be outdated.
Two important amendments have been made since the last major training session.
GSR 419(E) dated 19 July 2024 inserted Rule 9(1C). Reporting Entities must now upload updated KYC to the Central KYC Records Registry and pull updated KYC from the CKYCR before onboarding or on any KYC refresh. This closed the stale-KYC gap that the FATF Mutual Evaluation Report on India (adopted June 2024, published 19 September 2024) had flagged. IRDAI ported the Rule 9(1C) obligation into the insurer regime through circular IRDAI/IID/CIR/MISC/112/8/2024 dated 12 August 2024.
The RBI (KYC) (Second Amendment) Directions, 2025, DOR.AML.REC.46/14.01.001/2025-26 dated 14 August 2025, added Persons with Disabilities to the disadvantaged-groups list under Para 11, tightened Para 14 on occasional transactions of Rs 50,000 or more, added Aadhaar face authentication as an acceptable mode in Explanation 2 of Para 16, and refined periodic updation under Para 18.
Another detail that often causes confusion is the beneficial-ownership thresholds under Rule 9(1A). Since 2023, the threshold is now more than 10 percent for a company and more than 15 percent for a partnership or trust. If your template still uses the old 25 percent figure from before 2023, it is outdated and will not pass inspection.
Rule 7(3) is the most commonly misunderstood rule in Indian AML.
If you were told that an STR must be filed "within seven days of the transaction," that is incorrect. Rule 7(3) says the timeline starts when the Principal Officer decides the transaction is suspicious. The STR must be filed as soon as possible, and no later than seven working days from that decision. Filing promptly is the main requirement. The seven working days is the maximum limit.
This means the Principal Officer’s review process is more important than the online submission time. For example, if an alert comes up on Monday and the Principal Officer is satisfied by Wednesday, the timeline starts on Wednesday. The Board must record the date and time of this decision in its decision log. The Section 70 PMLA defence, which shows that officers acted with due diligence, depends on this log.
What the FIU-IND penalty ladder actually looks like
Four published orders from March 2024 to January 2025 set the current enforcement standard. Every Principal Officer should read these orders in full on the FIU-IND compliance orders page.
Paytm Payments Bank received an order on 1 March 2024 for Rs 5,49,00,000. The order found major problems with identity verification, identifying beneficial owners for business accounts, STR escalation, and the internal AML policy. The main lesson is that even a large, tech-focused platform is not automatically compliant with AML rules.
KuCoin (Peken Global Limited) received an order on 22 March 2024 for Rs 34,50,000. This was the first penalty for an offshore VDA SP under the March 2023 notification.
Binance received an order on 19 June 2024 for Rs 18,82,00,000. This was the most significant order of the year. Binance later paid the penalty, was registered with FIU-IND, and resumed its operations in India.
Bybit received an order on 31 January 2025 for Rs 9,27,00,000. Like Binance, Bybit paid the penalty and registered.
Also review the Union Bank of India Order 01/DIR/FIU-IND/2025 dated 8 April 2025, and the two orders from December 2025 against Gandhinagar Nagarik Co-operative Bank and Rajgurunagar Sahakari Bank. Each order is a free training resource written by the regulator. As a Principal Officer, you can see which sub-rule was broken, which part of your policy could have prevented it, and how the penalty range of Rs 10,000 to Rs 1 crore per failure adds up in practice.
What to expect during a ten-week engagement
Appointing a Principal Officer is just the first step. Building a solid programme usually takes about ten weeks and happens in four phases.
Weeks 1 and 2: Appoint. Define the engagement clearly on a single page. Get the Board resolution approved. Finish the FIU-IND registration on FINnet 2.0. Set up the stakeholder RACI by role. Address three common problems by Week 2: unclear Principal Officer authority, missing Board decision log, and no agreed onboarding approach.
Weeks 3 to 5: Draft. This is the most intensive phase. Write the twelve-clause internal AML policy. Create the KYC intake form using Rule 9’s three-tier structure. Prepare the beneficial ownership tracing worksheet using the latest thresholds. Develop the EDD questionnaire. Write the sanctions screening SOP. Set up the five-year retention schedule that combines PMLA and sectoral regulator requirements. Get the policy approved by the Board at the end of Week 5.
Weeks 6 to 8: Operate. Train the branches and operations team. Adjust the transaction-monitoring scenarios using test data. Submit three practice STR filings. File the first monthly CTR, NTR, and CBWTR by the 15th of the next month. Hold an operations review at the end of Week 8.
Weeks 9 and 10: Review. Conduct a mock FIU inspection with either an external advisor or your internal audit team. Fix any policy gaps you find. Prepare a six-slide Board deck and a twelve-month operating calendar. Get final Board approval at Checkpoint 4.
By the end of Week 10, the entity has moved from a project to a full programme.
Understanding the current enforcement approach
With a 93.6 percent conviction rate at the Enforcement Directorate (according to the ED Annual Report for FY 2024-25, with 44 convictions out of 47 cases) and ongoing Section 13 penalties at FIU-IND, AML is currently the biggest enforcement risk in Indian financial regulation. The FATF 2024 Mutual Evaluation put India under regular follow-up, with the first self-assessment due in 2027. This means more rule changes are likely. It is best to formalise your Principal Officer appointment before the next FIU inspection.
Our new course on dcomply Academy covers all these requirements step by step. The AML / PMLA Compliance Officer India Practitioner course has 12 modules and 65 lessons, each linked to a specific Section, Rule, Gazette notification, Master Direction, Master Circular, FIU-IND guideline, or compliance order. You can preview Module 1 for free. When you enroll, you get access to a workbook with twelve browser-fillable tools, including the Board resolution, FIU-IND registration checklist, twelve-clause policy, KYC intake form, BO tracing worksheet, EDD questionnaire, sanctions SOP, red-flag typology library, STR narrative and 24-hour checklist, layered retention schedule, operating calendar, and Board deck.
Further reading
PMLA Act 2002 consolidated text: India Code
PML Rules master index: FIU-IND
FIU-IND compliance orders page: FIU-IND
RBI Master Direction KYC consolidated: RBI
FATF Mutual Evaluation Report India 2024: FATF
This article is a practitioner guide, not legal advice. For a specific compliance decision affecting your organisation, retain a qualified advocate. All statutory references are to the Prevention of Money Laundering Act, 2002, the PML (Maintenance of Records) Rules, 2005 as amended through GSR 419(E) of 19 July 2024, and the RBI Master Direction on KYC as amended by the Second Amendment Directions of 14 August 2025, as in force on 9 October 2026.