A friend of mine was appointed Principal Officer of a Pune-based NBFC on a Tuesday last September. By Friday afternoon he was sitting across from me in my office with a thick file, a confused expression and a single question. "What do I actually do on Monday?"
The Board resolution had been passed. The appointment letter was in his file. His LinkedIn had been updated. On paper he was the named Principal Officer under PMLA for a reporting entity with a Rs 1,200 crore gold-loan and personal-loan book across 48 branches. In practice he had a mandate he had never been trained for and a personal exposure under Section 13(2) PMLA [L1-C1] that he had not understood when he said yes.
If you have been asked to serve as Principal Officer, or you are the one asking someone to accept the role, this is the first lesson you must read. The role is not an honorific. It is a named compliance seat that FIU-IND will look up by designation when it opens an inquiry, and it is the seat that signs STR filings [L1-C2] and sits across from inspectors.
Two Rules define the role, and they are not the same
The PML (Maintenance of Records) Rules 2005 draw a sharp line between two roles. The first is the Principal Officer, defined at Rule 2(1)(f) [L1-C3]. The Principal Officer is the officer the reporting entity designates under Rule 7 to furnish information to the Director, FIU-IND. He operates. He signs. He is the daily custodian of the AML programme.
The second is the Designated Director, defined at Rule 2(1)(fa) [L1-C4]. The Designated Director is the person the reporting entity designates to ensure overall compliance with Chapter IV of the Act and the Rules. He is a Board-level person or equivalent. He is not expected to run day-to-day alerts. He is expected to answer, in writing, for the programme as a whole.
I have seen three variations go wrong in the last two years. The reporting entity names the same person as both. That is permissible in theory for very small entities, but it defeats the entire point of the two-role split, which is accountability at two levels. I have also seen entities name the Managing Director as Principal Officer. The MD does not have the time, which means the alerts stack up unreviewed and the STR window slips. And I have seen entities name a Junior Vice President with no reporting line to the Board. When the inquiry comes, the JVP has no authority to produce documents from engineering or treasury, and the whole AML programme reveals itself as paper.
The right pattern for a middle-layer NBFC the size of Pashupati Finserv is a senior Chief Compliance Officer or Head of Compliance as Principal Officer, reporting administratively to the MD but with a dotted line to the Audit Committee, with a non-executive director or the Chairman of the Audit Committee as Designated Director. Smaller NBFCs can combine, but then the Board resolution must spell out the dual mandate explicitly.
What the Board resolution must say
An FIU-IND inspector will ask to see the resolution. If the resolution is a one-line "Resolved that Mr X is appointed Principal Officer under PMLA", you have failed before the inquiry begins. The resolution must set out five things.
One, the name, designation and employee identifier of the Principal Officer. Two, the same for the Designated Director. Three, the authority delegated to the Principal Officer to access records, interview staff, direct freezes on an account under the UAPA Section 51A regime [L1-C5] and sign STR filings on behalf of the reporting entity. Four, the reporting line to the Board or Audit Committee, including the cadence of reporting. Five, the independence protections, including that the Principal Officer cannot be removed except by a Board resolution recorded in minutes, and that his compensation is not linked to origination targets.
Pashupati Finserv\'s revised resolution ran to eleven paragraphs. The eleven paragraphs are the artifact at the end of this lesson. Draft yours before you register with FIU-IND, not after.
FIU-IND registration is a named-person registration
FIU-IND registration happens on FINnet 2.0, the current reporting portal. You register the reporting entity, but FIU-IND actually tracks a named Principal Officer against that registration. If the Principal Officer changes, the registration must be updated promptly. If a reporting entity carries a Principal Officer who left eighteen months ago on the FIU-IND register, the entity has a documentation failure that will surface in the first inspection.
The FIU-IND registration checklist is simple on its face. You will supply the entity\'s name, registration under the sectoral regulator (RBI, SEBI, IRDAI or the Ministry of Finance notification that applies), the Principal Officer\'s identity and contact, the Designated Director\'s identity and contact, and the operating address. The complication is that the data must match exactly the data your sectoral regulator holds. One misspelled address, one old director name, and you will spend six weeks reconciling fields rather than running the programme.
Personal liability is real, and it is twofold
The Principal Officer carries personal exposure under Section 13(2) PMLA [L1-C1], which permits the Director, FIU-IND to impose a monetary penalty for each failure to comply with Section 12 obligations [L1-C6]. The slab under Section 13(2)(d) runs from Rs 10,000 per failure to Rs 1,00,000 per failure, and the aggregate in a compliance order can be as high as Rs 1 crore. Four of the 2024-2025 published orders sit in the crore-plus zone.
The second layer is Section 70 PMLA [L1-C7], which deems every person who was in charge of and responsible for the conduct of the business at the time of the offence as guilty. The Designated Director is almost always deemed in charge. The Principal Officer, by his operating role, is almost always "responsible". The defence under Section 70 is to prove that the offence took place without his knowledge or that he had exercised all due diligence. "I did not know" is only credible if the paper trail shows a working programme, documented decisions and timely escalation.
The practical consequence is that the Principal Officer must create a documented decision trail for every judgment call. Not for cover. For truth. If an alert was closed without an STR, the file must show who closed it, when, on what grounds and with what documents reviewed. The Section 70 defence lives in these files.
Five failure modes practitioners repeat
The Principal Officer who treats the role as "KYC Head renamed". The old KYC Head knew onboarding. The Principal Officer owns onboarding, monitoring, screening, reporting, records and policy. If your mental model is still "KYC checklist", you will miss transaction monitoring entirely.
The Principal Officer with no written policy. The internal AML policy is the artifact an inspector will ask for before the resolution. Without a policy, every judgment call is undefended. Draft the policy in Week 1, approve it by Board resolution by Week 3.
The Principal Officer who does not actually see the alerts. If the vendor product routes alerts to a shared mailbox read by three people and none of them is you, the Rule 7 clock on satisfaction is not running on your clock. It is running on whoever opened the mail first. Fix this before you accept the role.
The Principal Officer whose reporting line is purely administrative. If you report only to the Chief Risk Officer, your independence is a fiction. Insist on a dotted line to the Audit Committee and a direct right of access to the Chairman.
The Principal Officer who thinks "designation on paper, operations by committee" works. It does not. FIU-IND will look up the named Principal Officer and will ask the named Principal Officer. A compliance committee cannot sign an STR.
Your artifact from Lesson 1
Draft the Board resolution appointing the Principal Officer and Designated Director for your reporting entity, with the five contents listed above. Save it in your capstone workbook under Artifact 1. We will refine it in Module 6 and lock it in Module 12 before the final exam. Even if you are not personally the named Principal Officer, draft the resolution for your organisation. The exercise forces you to write the authority chain in plain English, and that is the muscle every other module will build on.