Live 17 practitioner certifications live · First lesson free on every course Back to main site →

The named Principal Officer under PMLA, and why your company must appoint one before the next FIU audit

The role at the centre of your organisation's PMLA compliance. What the Rules actually say about who the Principal Officer is, how he or she differs from the Designated Director, what the Board resolution must contain, and what personal liability looks like after a Section 13 inquiry.

Free preview 12 min read Verified

A friend of mine was appointed Principal Officer of a Pune-based NBFC on a Tuesday last September. By Friday afternoon he was sitting across from me in my office with a thick file, a confused expression and a single question. "What do I actually do on Monday?"

The Board resolution had been passed. The appointment letter was in his file. His LinkedIn had been updated. On paper he was the named Principal Officer under PMLA for a reporting entity with a Rs 1,200 crore gold-loan and personal-loan book across 48 branches. In practice he had a mandate he had never been trained for and a personal exposure under Section 13(2) PMLA [L1-C1] that he had not understood when he said yes.

If you have been asked to serve as Principal Officer, or you are the one asking someone to accept the role, this is the first lesson you must read. The role is not an honorific. It is a named compliance seat that FIU-IND will look up by designation when it opens an inquiry, and it is the seat that signs STR filings [L1-C2] and sits across from inspectors.

Two Rules define the role, and they are not the same

The PML (Maintenance of Records) Rules 2005 draw a sharp line between two roles. The first is the Principal Officer, defined at Rule 2(1)(f) [L1-C3]. The Principal Officer is the officer the reporting entity designates under Rule 7 to furnish information to the Director, FIU-IND. He operates. He signs. He is the daily custodian of the AML programme.

The second is the Designated Director, defined at Rule 2(1)(fa) [L1-C4]. The Designated Director is the person the reporting entity designates to ensure overall compliance with Chapter IV of the Act and the Rules. He is a Board-level person or equivalent. He is not expected to run day-to-day alerts. He is expected to answer, in writing, for the programme as a whole.

I have seen three variations go wrong in the last two years. The reporting entity names the same person as both. That is permissible in theory for very small entities, but it defeats the entire point of the two-role split, which is accountability at two levels. I have also seen entities name the Managing Director as Principal Officer. The MD does not have the time, which means the alerts stack up unreviewed and the STR window slips. And I have seen entities name a Junior Vice President with no reporting line to the Board. When the inquiry comes, the JVP has no authority to produce documents from engineering or treasury, and the whole AML programme reveals itself as paper.

The right pattern for a middle-layer NBFC the size of Pashupati Finserv is a senior Chief Compliance Officer or Head of Compliance as Principal Officer, reporting administratively to the MD but with a dotted line to the Audit Committee, with a non-executive director or the Chairman of the Audit Committee as Designated Director. Smaller NBFCs can combine, but then the Board resolution must spell out the dual mandate explicitly.

What the Board resolution must say

An FIU-IND inspector will ask to see the resolution. If the resolution is a one-line "Resolved that Mr X is appointed Principal Officer under PMLA", you have failed before the inquiry begins. The resolution must set out five things.

One, the name, designation and employee identifier of the Principal Officer. Two, the same for the Designated Director. Three, the authority delegated to the Principal Officer to access records, interview staff, direct freezes on an account under the UAPA Section 51A regime [L1-C5] and sign STR filings on behalf of the reporting entity. Four, the reporting line to the Board or Audit Committee, including the cadence of reporting. Five, the independence protections, including that the Principal Officer cannot be removed except by a Board resolution recorded in minutes, and that his compensation is not linked to origination targets.

Pashupati Finserv\'s revised resolution ran to eleven paragraphs. The eleven paragraphs are the artifact at the end of this lesson. Draft yours before you register with FIU-IND, not after.

FIU-IND registration is a named-person registration

FIU-IND registration happens on FINnet 2.0, the current reporting portal. You register the reporting entity, but FIU-IND actually tracks a named Principal Officer against that registration. If the Principal Officer changes, the registration must be updated promptly. If a reporting entity carries a Principal Officer who left eighteen months ago on the FIU-IND register, the entity has a documentation failure that will surface in the first inspection.

The FIU-IND registration checklist is simple on its face. You will supply the entity\'s name, registration under the sectoral regulator (RBI, SEBI, IRDAI or the Ministry of Finance notification that applies), the Principal Officer\'s identity and contact, the Designated Director\'s identity and contact, and the operating address. The complication is that the data must match exactly the data your sectoral regulator holds. One misspelled address, one old director name, and you will spend six weeks reconciling fields rather than running the programme.

Personal liability is real, and it is twofold

The Principal Officer carries personal exposure under Section 13(2) PMLA [L1-C1], which permits the Director, FIU-IND to impose a monetary penalty for each failure to comply with Section 12 obligations [L1-C6]. The slab under Section 13(2)(d) runs from Rs 10,000 per failure to Rs 1,00,000 per failure, and the aggregate in a compliance order can be as high as Rs 1 crore. Four of the 2024-2025 published orders sit in the crore-plus zone.

The second layer is Section 70 PMLA [L1-C7], which deems every person who was in charge of and responsible for the conduct of the business at the time of the offence as guilty. The Designated Director is almost always deemed in charge. The Principal Officer, by his operating role, is almost always "responsible". The defence under Section 70 is to prove that the offence took place without his knowledge or that he had exercised all due diligence. "I did not know" is only credible if the paper trail shows a working programme, documented decisions and timely escalation.

The practical consequence is that the Principal Officer must create a documented decision trail for every judgment call. Not for cover. For truth. If an alert was closed without an STR, the file must show who closed it, when, on what grounds and with what documents reviewed. The Section 70 defence lives in these files.

Five failure modes practitioners repeat

The Principal Officer who treats the role as "KYC Head renamed". The old KYC Head knew onboarding. The Principal Officer owns onboarding, monitoring, screening, reporting, records and policy. If your mental model is still "KYC checklist", you will miss transaction monitoring entirely.

The Principal Officer with no written policy. The internal AML policy is the artifact an inspector will ask for before the resolution. Without a policy, every judgment call is undefended. Draft the policy in Week 1, approve it by Board resolution by Week 3.

The Principal Officer who does not actually see the alerts. If the vendor product routes alerts to a shared mailbox read by three people and none of them is you, the Rule 7 clock on satisfaction is not running on your clock. It is running on whoever opened the mail first. Fix this before you accept the role.

The Principal Officer whose reporting line is purely administrative. If you report only to the Chief Risk Officer, your independence is a fiction. Insist on a dotted line to the Audit Committee and a direct right of access to the Chairman.

The Principal Officer who thinks "designation on paper, operations by committee" works. It does not. FIU-IND will look up the named Principal Officer and will ask the named Principal Officer. A compliance committee cannot sign an STR.

Your artifact from Lesson 1

Draft the Board resolution appointing the Principal Officer and Designated Director for your reporting entity, with the five contents listed above. Save it in your capstone workbook under Artifact 1. We will refine it in Module 6 and lock it in Module 12 before the final exam. Even if you are not personally the named Principal Officer, draft the resolution for your organisation. The exercise forces you to write the authority chain in plain English, and that is the muscle every other module will build on.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 11 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 11 paid modules (55 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
PMLA Act 2002, Section 13 (Powers of Director to impose fine) L1-C1
The Director may, after inquiry, impose a fine on a reporting entity, its designated director on the Board or any of its employees, which shall not be less than ten thousand rupees but may extend to one lakh rupees for each failure.
PML Rules 2005, Rule 7 (Procedure for furnishing information) L1-C2
Principal Officer shall furnish CTR, CBWTR, CCR and NTR to the Director by the 15th day of the succeeding month. STR shall be furnished promptly and not later than seven working days from the date of the Principal Officer being satisfied that the transaction is suspicious.
PML Rules 2005, Rule 2(1)(f) (Definition of Principal Officer) L1-C3
An officer designated by a reporting entity under Rule 7 to furnish information under Section 12 of the Act. Must be a management-level officer separate from the Designated Director.
PML Rules 2005, Rule 2(1)(fa) (Definition of Designated Director) L1-C4
A person designated by the reporting entity to ensure overall compliance with the obligations imposed under Chapter IV of the Act and the Rules. Must be a board-level person or equivalent and is directly liable under Section 13(2) and Section 70.
Related Statutes, UAPA Section 51A (UAPA Section 51A sanctions freezing) L1-C5
Powers of the Central Government to freeze, seize or attach funds and other financial assets or economic resources held by, on behalf of, or at the direction of persons listed as terrorists.
PMLA Act 2002, Section 12 (Reporting entity obligations) L1-C6
Maintain a record of all transactions, furnish information to the Director, verify identity of clients, identify the beneficial owner, and maintain records for five years from the date of transaction between the client and the reporting entity.
PMLA Act 2002, Section 70 (Offences by companies) L1-C7
Where an offence is committed by a company, every person who at the time of commission was in charge of and responsible for the conduct of the business of the company, as well as the company, shall be deemed guilty.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The PMLA Universe and Why You Are Reading This
Module 2: Know Your Customer, The Rule Book
  • Rule 9 and the three CDD tiers. When simplified, when regular, when enhanced
  • Officially valid documents and V-CIP under RBI MD Para 18
  • The CKYCR push-and-pull flow under Rule 9(1C), as GSR 419(E) rewrote it
  • Rule 9A, Section 11A PMLA and the two Aadhaar paths
  • The RBI KYC Second Amendment of 14 August 2025, provision by provision
Module 3: Customer Due Diligence in Practice
  • The onboarding workflow and Day 1 risk scoring, built around a Pashupati Finserv gold-loan customer
  • Beneficial-ownership tracing at the post-2023 thresholds, with a worked four-level corporate structure
  • PEP identification: foreign PEPs, domestic PEPs, family members and close associates, without the common-name false positives
  • Source of funds and source of wealth, as two separate documents on three distinct pieces of evidence
  • High-risk jurisdictions and sanctions screening: FATF lists, UNSC 1267, MHA UAPA Section 51A, and the Day 1 scoring call
Module 4: Transaction Monitoring and Red Flags
  • Scenario design that is tied to Rule 3 reporting categories, not to vendor presets
  • Alert triage, the 20-80 rule, and how to document closed alerts for the Section 70 defence
  • How to read FIU-IND typologies and feed them back into scenario design
  • Twenty case-study red flags drawn from FIU-IND published orders and ED prosecutions
  • The handoff from alert to STR, and how to preserve the Rule 7 satisfaction clock
Module 5: Reporting Obligations: STR, CTR, NTR, CBWTR, CCR
  • The five reports in Rule 3, and what each one is actually asking you to say
  • The STR filing window under Rule 7. Satisfaction is the clock, not the transaction
  • CTR, NTR, CBWTR and CCR mechanics. Thresholds, traps and the integrally-connected rule
  • FINnet 2.0 end to end. FINGate collection, FINCore processing, FINex dissemination
  • The STR narrative drill. Three worked examples a Principal Officer should be able to write in his sleep
Module 6: The Principal Officer's Playbook
  • The eleven-paragraph Board resolution appointing your Principal Officer, paragraph by paragraph
  • FIU-IND registration on FINnet 2.0, step by step, and how to keep it current when the Principal Officer changes
  • The internal AML policy, twelve non-negotiable clauses with specimen language
  • Board reporting cadence, the KPIs that matter and the six-slide deck template
  • The personal liability shield. Section 13(2), Section 70 and the senior-management due-diligence defence
Module 7: Record-Keeping, Retention and Audit Trail
  • Section 12 obligations and the five-year rule, from first touch to final deletion
  • Electronic storage, data residency and the audit trail that an inspector will actually trust
  • Inspection readiness, or the three questions an FIU-IND inspector opens with
  • The layered retention schedule across PMLA, RBI, SEBI, IRDAI and Companies Act
  • Reconstructing a customer file in under thirty minutes using an indexed record store
Module 8: Sanctions and Watchlist Screening
  • UNSC 1267 as the base list, and UAPA Section 51A as the Indian freezing power that actually bites
  • OFAC overlap, the correspondent-banking fault line, and the extraterritorial exposure every Indian reporting entity now carries
  • The screening SOP across three triggers: onboarding, periodic, event-driven
  • Fuzzy matching, transliteration, and the tuning problem of catching Mohammed Ali without freezing every Mohammed Ali in Pune
  • Remediation of a true hit. Freeze under UAPA 51A, report under Rule 7, close under regulator direction
Module 9: Sector Deep-Dives: Banks, Securities, Insurance, Fintech and VDA SPs
  • Banks and NBFCs after the RBI KYC Second Amendment of 14 August 2025, with the February 2026 non-compliant NBFC list on the Board table
  • Securities intermediaries under the SEBI AML Master Circular, with the October 2025 draft refresh on the horizon
  • Insurance under the IRDAI AML/CFT Master Guidelines 2022, with the 12 August 2024 CKYCR port in your calendar
  • Fintech, Payment Aggregators and PPIs, with the Paytm Payments Bank order of 1 March 2024 taught as case law
  • VDA Service Providers after S.O. 1072(E) of 7 March 2023, with Binance, Bybit and the October 2025 offshore notices on the record
Module 10: Enforcement, Penalties and Case Studies
  • ED powers under PMLA, and the Section 45 bail bar every Principal Officer must understand before the first summons
  • Section 63 PMLA and the Section 13(2)(d) penalty slabs, with a worked penalty computation for a mid-size NBFC
  • Vijay Madanlal Choudhary 2022, Pavana Dibbur 2023 and the Ganpati Dealcom recall. What the Supreme Court actually did to PMLA
  • Four live FIU-IND compliance orders dissected: Paytm, KuCoin, Binance, Bybit
  • ED statistics FY 2024-25, the FATF 2027 forcing function, and the Board-ready briefing format every Principal Officer must master
Module 11: AML for Non-Traditional Reporting Entities
  • S.O. 2036(E) of 3 May 2023. How a CA, CS or CMA firm became a Reporting Entity overnight
  • FIU-IND registration for a CA, CS or CMA firm. The walkthrough nobody wrote
  • Real-estate agents and developers under S.O. 1073(E). Why there is no threshold and what a Rs 15 crore Mumbai deal looks like in file form
  • Multi-State Co-operative Societies under the 11 October 2024 FIU-IND Guidelines. Gandhinagar Nagarik and Rajgurunagar Sahakari as teaching cases
  • Prevention of Corruption Act Section 10. Building the adequate-procedures defence and why PCA Sections 7, 8 and 13 are PMLA scheduled offences
Module 12: Capstone, Programme Build and Final Exam
  • Build your ten-week AML programme. The scope document and the stakeholder map
  • Weeks 1-10 Gantt and the twelve artifacts of the capstone workbook
  • The Board briefing deck and the year-1 operating calendar
  • The 25-anchor exam reference card
  • The final exam. 45 questions from a 70-item pool, 90 minutes, 75 percent pass