Delta Filings
Governance Intelligence
Get Started
Compliance 8 min read · 2026-04-18

PMLA Compliance for CS in Practice: The DNFBP Regime and What It Asks of You

By Delta Filings Editorial

Anti-money-laundering compliance papers

Practising Company Secretaries, along with practising chartered accountants and cost accountants, are Designated Non-Financial Businesses and Professions under the Prevention of Money Laundering Act, 2002 — the DNFBP regime. The framework has been live for years, but enforcement attention has historically focused on banks and capital markets. Through 2024-25, FIU-IND and the ICSI have begun emphasising DNFBP compliance more directly. For most CS in practice, this is the year to build a working PMLA program. This article is the playbook.

What the PMLA actually requires of a CS in practice

  • Client identification and verification. KYC at engagement onboarding, refreshed at periodic intervals.
  • Risk-based approach. Categorise clients into low, medium, high risk based on objective criteria; calibrate due diligence accordingly.
  • Record-keeping. Five-year retention of client records, transactions advised, communications.
  • Suspicious Transaction Reports. When a transaction pattern triggers PMLA concern, file a STR with FIU-IND.
  • Designation of a Principal Officer. The PMLA contact for the firm.
  • PMLA policy and procedures. Documented framework adopted by the firm.
  • Annual training of staff.

Which engagements are in scope

Activities of a CS in practice that bring PMLA obligations include:

  • Acting as a formation agent (incorporating companies for clients).
  • Acting as a director or company secretary by way of arrangement.
  • Buying or selling of real estate on behalf of clients (where applicable).
  • Managing of client money, securities, or other assets.
  • Management of bank, savings, or securities accounts on behalf of clients.
  • Organisation of contributions for the creation, operation, or management of companies.
  • Creation, operation, or management of legal arrangements (trusts, similar).

Routine compliance filing services, by themselves, are not typically in scope — but where the broader relationship includes any of the above, the firm is in scope.

The five-step working program

Step 1 — Client risk categorisation

Build a simple matrix: client type (individual, corporate, trust), source of funds (clear, opaque), geography (domestic, OFAC-listed jurisdiction, etc.), nature of engagement, public profile (PEP exposure). Score and categorise. Document the score for every client.

Step 2 — Enhanced due diligence for high-risk clients

For clients in the high-risk bucket — politically exposed persons, complex offshore structures, opaque ownership — additional diligence. Senior approval to onboard. Documented justification on file.

Step 3 — Ongoing monitoring

Re-assess risk on every material change in the engagement, and at least annually. Update the file.

Step 4 — STR filing protocol

When a transaction or pattern raises a money-laundering or terror-financing concern, file a STR within the specified window. The CS should have the FIU-IND FINGate portal credentials, the form template, and an internal escalation path before the first trigger event.

Step 5 — Annual review and training

The Principal Officer reviews the program annually, identifies gaps, and updates. All staff receive annual PMLA training and acknowledge.

What an STR actually looks like in practice

  • The trigger event — what happened, when, with whom.
  • The pattern observed — series of transactions, structure, money movements.
  • The risk assessment — why this is suspicious.
  • Supporting documents.

STR confidentiality is statutory — the fact of filing cannot be disclosed to the subject. The CS must internalise this discipline.

The PEP layer

Politically Exposed Persons — current or former senior public officials, their family members, close associates — require enhanced due diligence at onboarding and ongoing monitoring. The PEP list maintained by RBI and various international sources is the operating reference.

The five common failures we see

  • No documented PMLA policy. The framework exists in someone's head, not on paper.
  • KYC files inconsistent across the firm. Engagement-level discipline varies by partner.
  • No risk categorisation done. All clients treated as same-risk.
  • STR never filed, despite likely triggers in the engagement history. Either no triggers ever existed (rare) or some were missed (common).
  • Principal Officer designated but not active. Title without function.

The ICSI's role

The ICSI's professional development arm runs PMLA training programs for members. The cost is small; the certification, if any, is reputational. The CS who is current is better positioned for the larger client mandates.

How Delta Filings supports PMLA for CS in practice

The Delta Filings practice management module ships a client risk-categorisation engine, a documented PMLA policy template adaptable to firm size, a STR submission tracker integrated with FIU-IND nomenclature, and an annual review reminder cycle. For a 5-15 person CS firm with 200+ clients, the consolidated PMLA dashboard is the artefact most cited as both compliance enabler and time-saver.

The closing note

PMLA compliance has been the regulatory area Indian professional firms have under-invested in for over a decade. The next cycle of enforcement attention is structurally directed at DNFBPs. The CS who has a working program in place this year is operating in a different category to the CS who is reacting to an FIU-IND notice in three years. The investment is small. The downside avoided is not.

Track filings without the manual work

Delta Filings ingests NSE & BSE corporate filings, drafts SEBI letters with AI, tracks insider trading windows, and runs your compliance calendar — all in one place.

Get Started for ₹4,999/year

Related articles