Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Indian Markets, Regulation & Professional Standards
1Registration, Professional Standards and the Rulebook
Portfolio ManagerResearch AnalystActs, Rules, Regulations, Circulars…Financial Regulators in IndiaCompliance FunctionInvestment AdviceResearch Analyst vs Adviser…NISM CertificationRecord RetentionLicence, Recognition and What…Risk ProfilingHow to Map a…
2Intermediaries
UnderwriterDebenture TrusteeInvestment ManagerForeign Portfolio Investor vs…Merchant BankerRegistrar to an Issue…Stock BrokerCredit Rating Agency
3Market Infrastructure, Settlement and Technology
Market Infrastructure InstitutionAlgorithmic Trading in IndiaAlgorithmic Trading vs API TradingDematerialisationPay-In and Pay-OutBeneficial OwnerCybersecurity for Regulated EntitiesSettlement FinalityDepository ParticipantsForeign Portfolio InvestorInvestor Protection FundPrepaid Payment InstrumentHow Payment-System Regulation Works…Securities Appellate TribunalSelf-Regulatory Organisation
4Issuance
Offer DocumentHow to Read a…Public Issue TypesListingLock-InAnchor InvestorBook Building and the Price BandQualified Institutions PlacementRed Herring Prospectus
5Listed Markets
Compliance OfficerDisclosure ObligationsHow to Map a…Listing ObligationsListed Entity vs Intermediary
6Market Conduct
Market ConductSupervisory ActionsEnforcement OrdersAdjudication and PenaltyInsider TradingAnti-Money LaunderingHow to Identify a…How Financial-Promotion Rules Differ…
7Pensions and Insurance
Insurance IntermediariesHow Insurance and Pension…The NPS ArchitectureNPS vs APYPension AdviserPension Fund Under the NPS

Anti-Money Laundering: The Obligations on a Financial Intermediary

Anti-money laundering obligations require a financial intermediary to establish who its customers are, monitor activity against what it knows about them, report defined categories of transaction and suspicion, and keep records of all of it. The obligations come from the governing law and from the regulator's directions, read at sebi.gov.in and rbi.org.in, and they apply because the firm is a route through which money moves.

Start with a toll plaza on a state highway. Nobody built it to find anybody. The plaza exists because two cities are joined by one road and the road has to be paid for. But because every vehicle travelling between those two cities has to slow down at the same set of booths, the plaza becomes the only place on the whole route where somebody could reliably be required to look at who is passing. A chokepoint is exactly that: not a trap, and not an accusation, just a place where everything narrows to a point at which looking becomes possible.

A financial intermediary is a chokepoint in exactly that sense, and every anti-money laundering obligation follows from that one structural fact. Money moving through the regulated system has to pass somebody. The whole apparatus of anti-money launderingThe set of obligations requiring an intermediary to know its customers, to watch their activity, to report defined matters, and to keep the record of all three. obligation is built on making that somebody look, keep looking, and write down what they saw. The apparatus is not built on making that somebody solve anything. The distinction sounds small at first and it turns out to be the difference between a duty a compliance function can actually discharge and one that would be impossible.

Anti-money laundering obligations are Indian and do not travel. The obligations sit in the governing Indian anti-money laundering law and in the directions and circulars made under it, applied to market intermediaries by the Securities and Exchange Board of India and to the entities it supervises by the Reserve Bank of India. India implements standards that originate with the Financial Action Task Force, a body addressing countries rather than firms.

Every reporting threshold, limit, retention period and interval is read from the live text at the source. Thresholds move, they move without announcement, and a reader who carries away a threshold learned from teaching material will apply it with more confidence than anybody who never learned it at all. The shape is what can be carried away safely: what the four obligations are, how they connect, and which of them a firm is most likely to get wrong.

No customer, no occupation, no place and no pattern of activity is suspicious in itself. Whether anything is suspicious is judged inside a firm, with that one customer's facts in front of it.

Bhadra Securities Private Limited, an invented broker that is also a depository participant, carries these obligations inside the compliance function that Yashodhan Pai runs, alongside everything else that function carries. One inspection there looked at 3 areas of the firm's activity and wrote up 5 observations. The firm answered 3 of the 5 well enough that those 3 closed. The remaining 2 stayed open. Of the 2 left open, 1 was settled with no investigation at all, and 1 turned into an investigation covering a single matter. The investigation ended in one order. A sequence of that shape says nothing about which obligation was at issue. An inspection looks across everything a firm does, and an order names only the matter it decides.

What do anti-money laundering obligations require, in four groups?

Four groups, and they are worth learning as four because a firm can be strong in some and hollow in others without anybody noticing from the outside. Identify: establish who the customer is and who stands behind the customer. Monitor: compare what the customer actually does against what the firm already knows about them. Report: notify the designated authority of the categories of transaction and the kinds of suspicion the rules define. Record: retain the evidence that the first three happened, in a form somebody who was not there can read afterwards.

Look at the order before anything else. The order is doing work. Identification comes first because monitoring has nothing to compare against until it exists. Monitoring comes before reporting because reporting is what happens when monitoring produces something. And recording sits underneath all three rather than after them. Each of the first three produces evidence at the moment it happens and produces none at all if nobody captures it then.

The four groups are one chain rather than four separate duties, and a break anywhere in the chain makes the parts on either side of the break worth much less than they look. A firm with excellent identification and no monitoring has a chain broken at the first joint. A firm that monitors well and records nothing has one broken at the last. Both firms can describe a complete process in a policy document, and both are missing the step that turns the process into a control.

Four groups, arranged as one chain rather than four separate duties. Read the top row left to right, then look at what runs underneath all of it. GROUP 1 IDENTIFY who the customer is, and who stands behind them GROUP 2 MONITOR what they do, against what is already known GROUP 3 REPORT the defined categories, to the named authority GROUP 4, RECORD the evidence that each of the three above happened, captured while it happened Break the chain anywhere and both sides of the break are worth less than they look. Monitoring has nothing to compare against until identification exists.
Identification, monitoring and reporting run in sequence while record keeping sits underneath all three, so the four groups behave as one chain rather than as four independent duties.
Try it out

Which set below names the four groups of obligation?

Financial Literacy Bootcamp — Fin Maverick

Why does a risk based approach mean the effort is deliberately unequal?

A risk based approachApplying more effort where the assessed risk is higher, rather than applying identical effort to everybody. means the firm applies more effort where the assessed risk is higher and less where it is lower, and this is the design rather than a compromise with it. The standard being aimed at looks at first like uniformity, in which every customer is treated identically and any variation is a lapse somebody will be pulled up for. The opposite is closer to the truth.

The everyday version is a hospital triage counter. Everybody who walks in is seen. Nobody is turned away and nobody is judged at the door. But the person with a cut finger and the person with chest pain do not get the same amount of the doctor's time, and a hospital that insisted on giving them the same amount would be worse at its job, not fairer at it. Effort is finite, and spreading it evenly across a queue guarantees nothing except that it is thin everywhere.

Unequal effort is what the obligations ask for, so a firm that treats every customer identically has not achieved a higher standard, it has spent the same total attention less usefully. Two consequences follow. One is that an unequal allocation with no stated basis is indistinguishable from an arbitrary one, so the firm has to be able to say how it assessed risk. The other is that the assessment is not a permanent label. A firm's knowledge of a customer changes, and an approach that graded everybody once and never again has quietly become a uniform approach with a historical accent.

Two ways to spend the same total attention across a customer base. The rising line is what the obligations describe. The flat line is what feels fair. EFFORT APPLIED, LIGHTER AT THE BOTTOM TO HEAVIER AT THE TOP identical effort for every customer effort proportionate to assessed risk LOWER ASSESSED RISK MIDDLE HIGHER ASSESSED RISK ASSESSED RISK, ACROSS THE CUSTOMERS THE FIRM HAS The flat line is not a higher standard. It is the same attention spread thinner, and the firm still has to say on what basis it graded anybody at all.
Effort rises with assessed risk instead of staying flat across everybody, which is why unequal treatment is the design of a risk based approach rather than a defect in one.
Try it out

A firm applies noticeably more effort to some customers than to others. Is that a failing?

Mutual Funds Bootcamp — Fin Maverick

Who do the obligations apply to, and why an intermediary rather than everybody?

The obligations apply to the firms through which money and instruments move under a licence: banks and the other entities the Reserve Bank of India supervises, and market intermediaries such as brokers, depository participants, portfolio managers and mutual fund distributors on the securities side. Bhadra Securities Private Limited is caught by both descriptions in different parts of its business. Being caught by both is ordinary rather than unusual, and it is one reason a compliance function carries two rulebooks at once.

The reason the duty attaches there and not everywhere is the toll plaza point made concrete. There is no point at which anybody could check a rule requiring every person in the country to establish the source of everybody they dealt with, so such a rule would be unenforceable and would achieve almost nothing. The small number of licensed firms through which money enters and leaves the regulated system are identifiable, inspected and already keeping records. A rule requiring them to establish who is using them is therefore enforceable.

An intermediary is the one place in the route where looking is structurally possible, so the obligations sit there. The duty is a consequence of holding the licence rather than a suspicion attached to anybody. The distinction matters for how a firm talks to its own customers. Being asked for documents is not an accusation and being asked again later is not an escalation. The licence is doing what the licence requires, in the same way that a pharmacy asking for a prescription is not a comment on the person holding it.

Why the duty attaches here and not everywhere. Everything narrows to the middle panel, which is the only place where looking is possible. THE PUBLIC anybody with money to move through a regulated route THE INTERMEDIARY the one place where somebody is required to know who is moving it and to keep looking THE SYSTEM the market, the banking system, and everything beyond Every licensed route into the system passes one party required to establish who is using it. The duty follows the licence, not any view about the person at the counter. Being asked for documents is the licence working, not an accusation.
Money moving through the regulated system has to pass an intermediary required to know who is moving it, and that position is the reason these obligations attach where they do.
Try it out

Why do these obligations sit on licensed intermediaries rather than on everybody?

What does identifying a customer actually involve?

Customer identificationEstablishing who a customer is and who ultimately stands behind that customer, rather than collecting a set of documents. is the group that feels most familiar. Everybody has handed documents across a counter and watched somebody photocopy them. The counter experience teaches the wrong lesson. The obligation is not to collect a set of documents. The obligation is to establish who the customer is and who stands behind the customer, with the documents as evidence of the establishing rather than the establishing itself.

For an individual customer the two questions collapse into one. The individual case is therefore a poor guide to the rest. For anything that is not an individual, a company, a partnership, a trust, a society, the two questions come apart immediately. A company is a legal person and it can be identified perfectly well by name, registration and address, and none of that names a single human being. Behind it there are holders, and behind some of those holders there may be other entities, and behind those there are eventually people.

Reaching those people is the whole object of identification. The beneficial ownerThe person who ultimately holds or controls a customer, reached by working through any entities that sit in between. is the person who ultimately holds or controls the customer, and identifying them means working through each layer rather than stopping at the first one that has a name and a certificate. Identification works through to people, and a file that stops at a company name has recorded the customer without ever establishing who is behind the customer. The obligation is unmet however thick the file is.

Identification does not stop at the first name with a certificate behind it. Follow it left to right. The obligation is met at the fourth box, not the first. STEP 1 THE CUSTOMER a company, a trust, a partnership STEP 2 WHO CONTROLS IT the holders and controllers named STEP 3 THE LAYER ABOVE where a holder is itself an entity STEP 4 PEOPLE named individuals, which is the point Stopping here leaves the obligation unmet. Reaching people is what the obligation asks for. A company can be identified precisely and still name nobody at all. The documents are evidence of the establishing, never the establishing itself.
Establishing a company customer means working through each layer until people are reached, and a file that stops at the company name leaves the obligation unmet.
Try it out

A customer is a company. Does identifying the company discharge the obligation?

What is monitoring, and what is the activity compared against?

MonitoringComparing what a customer actually does against what the firm already knows about that customer, on a continuing basis rather than once. is comparing what a customer actually does against what the firm already knows about that customer. The second half of that sentence is where all the content is. Monitoring is not watching activity in the abstract, and it is not looking for activity that seems odd in general. Nothing is odd in general. Activity is compared against a specific expectation that identification produced, for a specific customer.

Think of a landlord who has rented the same shop unit for eleven years. He is not watching the street for anything unusual. Watching a whole street would be exhausting and would tell him nothing. He knows one tenant, he knows what that tenant's business looks like across a normal month, and what he notices is the shape changing: shutters down on the days that were always the busiest, a delivery pattern that inverted. He is not more observant than anybody else on that street. He simply has one thing to compare against, and nobody else on the street has it.

Monitoring is continuing rather than periodic in principle, and what it detects is not activity that is strange in itself but activity that does not fit what the firm already knew. Notice how much this depends on the earlier group. A firm that recorded a customer's expected activity thinly at the start has given its monitoring nothing to work with, and no amount of attention later recovers a comparison that was never set up. The dependence of monitoring on identification is why the order of the two groups is not arbitrary.

Breaking Into Quants Bootcamp — Fin Maverick

Why are identification and monitoring two obligations rather than one?

Because one of them establishes a baseline and the other one uses it, and the second is not implied by the first. The distinction between a baseline and the use of it is the single most useful one here, and it is also the one most often collapsed. Firms collapse it by treating the onboarding pack as the obligation, on the reasonable sounding view that knowing who somebody is must be the substance of the know your customer obligation. Knowing who somebody is begins that obligation rather than completing it.

Take two firms holding identical files. Both have complete identification for every customer, worked through to people, with everything evidenced. The first firm compares nothing that happens afterwards against those files. The second firm compares activity against them continuously. On paper, at an inspection that only asks to see files, the two firms look the same. In substance one of them has a control and the other has a very well organised set of paper.

A baseline that nothing is ever measured against is not a baseline, it is just information, so identification without monitoring produces a filing cabinet rather than a control. The word control is doing precise work here. A control is something that would produce a different outcome if something were wrong. A file that sits in a cabinet produces the same outcome in every state of the world, and an unchanging outcome is exactly what a control does not have, however complete and however well indexed the file is.

Two firms, identical files, and only one of them has a control. IDENTIFICATION WITHOUT MONITORING WHAT THE FIRM HOLDS a complete onboarding file WHAT ACTIVITY IS COMPARED WITH nothing WHAT THE FIRM CAN NOTICE nothing, because nothing is measured WHAT IT HAS BUILT A FILING CABINET IDENTIFICATION WITH MONITORING WHAT THE FIRM HOLDS a complete onboarding file WHAT ACTIVITY IS COMPARED WITH what the firm already knows WHAT THE FIRM CAN NOTICE activity that does not fit the file WHAT IT HAS BUILT A CONTROL The first row is identical in both panels. Every row after it comes apart, and an inspection that asks only to see files cannot tell the two apart.
Two firms hold identical onboarding files, and only the one that compares activity against what it knows has built a control rather than a filing cabinet.
Try it out

A firm identifies every customer thoroughly and monitors nothing. What has it built?

What must be reported, and to whom?

ReportingNotifying the designated authority of the categories of transaction and the kinds of suspicion that the rules define. means notifying a designated authority of two different things, and separating them is worth doing because they behave differently. The first is a set of defined categories of transaction. The rules describe those categories and the firm identifies them mechanically. The second is suspicion, and suspicion is not mechanical. Suspicion arises when something the firm observes does not fit what the firm knows, and it is formed inside the firm on the facts in front of it.

Where the categories are defined, the firm has no discretion and needs none. Something either falls in the defined category or it does not, and the report follows without anybody forming a view about the customer. The absence of discretion is deliberate. A duty that depended entirely on the judgement of individuals would produce completely different behaviour in two identical firms, and the defined categories are the part of the system that does not vary.

The suspicion route is different in kind. The suspicion route depends on monitoring having happened, and the chain shows itself here for the second time. A firm that never compares activity against what it knows has no mechanism by which a suspicion could form in the first place, so its reporting will consist entirely of the defined categories. Such a firm is not quietly deciding not to report. The firm has removed its own capacity to reach the second route at all, usually without ever intending to.

The reporting obligation runs to a designated authority rather than to the customer, to the market, or to anybody else in the firm's commercial world, and the route is fixed by the rules rather than chosen by the firm. The authority, the form and the channel are all specified where the obligations are read, at sebi.gov.in for a market intermediary and at rbi.org.in for an entity the Reserve Bank of India supervises.

Try it out

A firm makes a report about a customer. What does it tell that customer?

What happens after a report, and what may the firm not do?

Here is the part that surprises people, and it surprises them because instinct points the other way. After a report is made the firm tells the customer nothing. Not a hint, not a change of tone, not a helpful suggestion that the customer might want to move elsewhere. Telling a customer that they have been reported is tipping offTelling a customer, directly or by implication, that they have been reported. It is prohibited., and it is prohibited. The prohibition is one of the firmest rules anywhere in this area.

The second half is stranger still on first meeting. The firm does not decide whether a crime occurred. The firm does not investigate, it does not build a case, and it does not reach a conclusion about the customer. The firm reports what it is required to report, and unless it is told otherwise by somebody entitled to tell it, it carries on dealing with the customer normally. The report is not a verdict and the firm is not a court.

Reading the duty as decide whether this is a crime is what makes anti-money laundering feel impossible, and the duty has never said that. Sit with how much that removes. The firm is not asked to be certain. The firm is not asked to be right about the customer. The firm is asked to look, to compare, to report what the rules say to report, to say nothing to anybody it should not, and to keep the record. Every one of those is a thing a compliance function can actually do on a Tuesday morning. Determining whether a crime occurred is not, and was never on the list.

Three things a firm could do next, and only one of them is the answer. A REPORT HAS BEEN MADE. What does the firm do next? RULED OUT TELL THE CUSTOMER specifically prohibited, including by implication RULED OUT DECIDE THE CASE whether a crime occurred is settled elsewhere WHAT ACTUALLY HAPPENS CARRY ON NORMALLY unless the firm is told otherwise by somebody The report is not a verdict and the firm is not a court. It looked, it compared, it reported. The deciding sits with people whose work that is.
After a report the firm tells the customer nothing, decides nothing about whether a crime occurred, and carries on acting normally unless it is told otherwise.

What records must sit behind all of it?

Record keepingRetaining the evidence of identification, monitoring and reporting, in a form somebody who was not there can read afterwards. is the fourth group and it is the one every firm believes it is good at, usually with justification. Filing is the oldest skill a back office has. The trap is narrower than it looks. Firms are good at retaining the documents identification produced. Firms are much weaker at retaining the evidence that monitoring happened and produced a result, partly because that evidence is a process leaving traces rather than a document arriving in an envelope.

Three questions define what has to survive. Who was identified, and how was the identification established. Establishing an identification is a different question from taking documents. Then what was monitored, against what, and what came out of the comparison, including the comparisons where nothing came out. Last, what was reported and when, held somewhere a person who was not present can find it afterwards.

Unrecorded work is indistinguishable from work that was never done, so the record is not administration that follows the obligation but the only form in which the obligation can be shown to have been met. The position is uncomfortable and it is also fair. Nobody reviewing the function later has access to what anybody remembers. A reviewer has access to what was written down at the time, and the honest position is that a firm which did excellent work and captured none of it is in the same evidential place as a firm that did none.

What the file has to be able to show, and what usually goes missing from it. WHAT THE FILE MUST SHOW 1 IDENTIFICATION who was identified, and how it was established 2 MONITORING what was compared, and against what 3 REPORTING what was reported, and when 4 RECORD KEEPING that each of the three above is kept and findable Unrecorded work looks exactly like work not done. 1 The documents are the easy half. How the firm established the identity is the half that goes missing. 2 A log with nothing in it is still evidence, and what it evidences is that nothing was ever compared. 3 What was reported and when, held where a person who was not there can find it afterwards. 4 Retention is not filing. The test is whether the work can be shown to somebody who asks a long time later.
A file has to show who was identified and how, what was compared and against what, and what was reported and when, because unrecorded work cannot be told apart from work never done.
Try it out

A firm did the work well and recorded none of it. What can it show?

Equity Research Bootcamp — Fin Maverick

How does an inspector actually test whether the four groups are working?

The way the function is tested matters to anybody who sits inside a compliance function, reviews one, or simply wants to understand why a firm asks for the same document twice in five years. Somebody testing the function does not read the four groups in the order set out above. A tester reads them in the order that separates a working function from a described one, and that order starts in the middle.

The first request is rarely the customer files. Customer files are what every firm has ready. The more searching request is for the monitoring output: what comparisons ran, over what period, what they produced, and what happened to each thing they produced. A function that can hand that over in an afternoon is almost certainly working. A function that has to build it after the request is saying something without meaning to. Output assembled retrospectively is output that nobody was using.

The second question follows the first thing the output produced. Somebody picks one item and asks what happened to it next, then follows it to whatever it became, including if it became nothing. A comparison that produced a question, a question that somebody answered, and an answer somebody recorded is a complete loop. An inspector is not testing whether the firm has the four groups. Every firm has the four groups on paper. The test is whether anything ever travels between them.

GroupWhat the function at Bhadra Securities doesWhat the record has to show afterwards
IdentifyEstablishes who each customer is and, where the customer is not an individual, works through the layers to peopleWho was identified, and how the identification was established rather than only which documents were taken
MonitorCompares what customers do against what the firm already knows about them, continuously rather than at a fixed review point onlyWhat was compared and against what, including the comparisons that produced nothing
ReportNotifies the designated authority of the defined categories, and separately where a suspicion is formed on the facts in front of the firmWhat was reported and when, findable by somebody who was not present
RecordRetains the evidence of all three above in a form that survives the people who created itThat each of the three above can be produced on request, long after everybody involved has moved on

The household version of this is the request a customer receives. When a firm asks a customer to confirm details given years ago, it is not reacting to anything about that customer. The firm is refreshing a baseline that has aged. A baseline set once and never revisited slowly stops describing anybody. The annoyance is real and the alternative is worse. The alternative is a firm comparing today's activity against an expectation formed about a different stage of a person's life.

What are these obligations not for?

The confusion does real damage to how the duty feels, so it is worth saying plainly. The obligations are not a mechanism for the firm to determine whether a crime occurred. Nor are they a mechanism for the firm to investigate anybody, to gather evidence for a proceeding, or to reach a conclusion about a customer's character or business. And they are not a licence for a firm to decide that some category of person is inherently suspect. No rule asks for that, and no rule could sensibly ask for it.

The purpose is narrower and much more achievable. The obligations put a party who can see something in a position to see it, require that party to look in a defined way, and require what is seen to reach somebody whose work it is to do something with it. The firm is one part of a longer arrangement, and it is the part with the visibility rather than the part with the authority.

Knowing where the firm's part stops is what makes these obligations bearable, and a function that has quietly taken on the deciding will be exhausted, slow and wrong about its own duty at the same time. There is a practical tell for this. When a compliance function starts arguing internally about whether a customer is probably innocent, it has drifted across a boundary that the rules drew for it. Probably innocent and probably not are both determinations, and neither is on the firm's list.

Where the firm's part ends. Everything to the right of the line belongs elsewhere. THE BOUNDARY THE FIRM'S PART NOT THE FIRM'S PART identify the customer, and who is behind it monitor activity against what is known report what has to be reported keep the record of all three decide whether a crime occurred investigate what happened act on the report, or not act on it reach any view about the customer Four things on the left, each of which a function can do on an ordinary working day. A function that quietly takes on the right hand side will be exhausted, slow, and wrong about its own duty at the same time.
The firm identifies, monitors, reports and records, and everything on the far side of the boundary, including deciding whether a crime occurred, belongs to somebody else.
Try it out

Does a firm have to decide whether a crime occurred?

Rebalancing: When, Why and What It Costs — free micro-course from Fin Maverick

Where are the obligations read, and why is the shape taught rather than the figure?

Two rulebooks, and a firm like Bhadra Securities Private Limited sits under both without either one mentioning the other. For its activity as a market intermediary the obligations and the directions on how to discharge them are read at sebi.gov.in, in the governing anti-money laundering law and in the master circular and guidelines the Securities and Exchange Board of India issues to intermediaries. For activity that falls under the Reserve Bank of India, the equivalent directions are read at rbi.org.in. India implements standards that originate with the Financial Action Task Force at fatf-gafi.org. The Task Force sets standards for countries and imposes nothing directly on any firm.

The obligations are stable in shape and unstable in detail. The shape can be learned once. The detail has to be read at the source every time. Identification, monitoring, reporting and recording have been the four groups for a long time and are unlikely to stop being them. Every threshold, every limit, every retention period and every form is a moving part, and each moves without anybody sending a notice to whoever learned the old one. A reader who has the shape can read the live text intelligently. A reader carrying a number away from teaching material will apply it confidently long after it stopped being true.

India, and where the current text is read

The obligations arise under the Indian anti-money laundering statute and the rules made under it, and they reach a market intermediary through the directions, master circular and guidelines that the Securities and Exchange Board of India issues to them, whose current text sits at sebi.gov.in. Where the same firm carries on activity supervised by the Reserve Bank of India, the corresponding directions are read at rbi.org.in. India implements standards originating with the Financial Action Task Force at fatf-gafi.org. The Task Force addresses countries rather than firms. Every threshold, limit, retention period, reporting interval and form specification is read from the live text at the site shown for each, against the version date that text carries.

Try it out

A firm carries on activity supervised on both the securities side and the banking side. Which site carries its obligations?

The failure: the firm that treats identification as the whole obligation

Here is what it looks like from inside, and it rarely looks like negligence. Documents are collected carefully at onboarding, checked by somebody who takes the checking seriously, indexed and filed. The pack for every customer is complete. Monitoring exists as a paragraph in a policy document, an owner, and a line in an annual plan. Nobody made a decision to skip it. Monitoring simply never became anybody's work on any particular day. Unlike onboarding, it had no event to attach itself to.

The wrong reading underneath is that knowing who somebody is discharges the duty. The reading is intuitive, and it is reinforced every time somebody uses the phrase know your customer as though the knowing were the endpoint. Identification establishes a baseline and monitoring uses the baseline, and without the second the first is a filing exercise that nothing depends on.

The cost lands in a specific and uncomfortable place. The firm ends up able to produce complete, well organised records about customers whose activity it never once compared against those very records. A complete file with nothing measured against it is a worse position than an incomplete file honestly maintained. The claim sounds like a paradox and the reason is worth being clear about. An incomplete file is a gap, and gaps get closed. A complete file with no comparison behind it is a demonstration: it shows, in the firm's own handwriting, that the information was gathered and never used. The record does not hide the failure, it documents it.

Count the filled rows on the left, then look for them on the right. ONBOARDING FILE, COMPLETE MONITORING LOG, EMPTY Everything the firm collected at the start. Nothing it was ever compared against since. An incomplete file is a gap, and gaps get closed. A complete file with nothing measured against it is a demonstration, in the firm's own handwriting, that the information was gathered and never once used.
A complete onboarding file beside an empty monitoring log shows a firm that collected information thoroughly and never once measured anything against it.

Covered elsewhere. Retention periods, and what must be kept for how long, are set out under record retention. Every threshold, reporting limit and interval is read from the live text at the sources named below. Why anybody behaves as they do is taken up under behavioural finance, and what makes a person or a firm cut a corner under ethics and conduct. Where a matter goes once it leaves the firm is set out under supervisory actions and under enforcement orders, and the criminal law behind the statute is applied by the courts rather than by the regulator or by the firm.

Two rulebooks apply and neither mentions the other. See where the obligations are read.

References

SourceDocumentWhere
Government of IndiaThe governing anti-money laundering statute and the rules framed under it, the source in law of the obligations on a reporting entitygov.in
Securities and Exchange Board of IndiaThe master circular and guidelines addressed to registered intermediaries on anti-money laundering obligations, covering the four groups of obligation and the risk based approachsebi.gov.in
Reserve Bank of IndiaThe directions applying the same obligations to the entities it supervises, read alongside the securities directions by a firm carrying on both kinds of activityrbi.org.in
Financial Action Task ForceThe published international standards on combating money laundering and terrorist financing, the origin of the standards India implements and addressed to countries rather than to firms directlyfatf-gafi.org
International Organization of Securities CommissionsIts principles on the conduct expected of market intermediaries, treating customer due diligence as part of that conductiosco.org

Bhadra Securities Private Limited and Yashodhan Pai are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.