Auditor’s Responsibility during Bank Audit under the Prevention on Money-Laundering Act (PMLA), 2002
Introduction
When one opens a digital or print media, they may find news on Money Laundering and actions taken by the Enforcement Directorate against economic offenders which may include white-collar persons. Money laundering has a significant impact on the economy of our nation as well as other countries. The proceeds of crime earned are layered and reintroduced into the regular economy in different ways, showing that the money has been earned or received through legitimate sources. The process is called money laundering.
To control money laundering activities, it was identified that banks and financial institutions are essential sources of information about money laundering and other financial crimes, and banking frauds investigated by law enforcement agencies. From this perspective, it increases an auditor’s responsibility to be aware of the provisions of PMLA, observe the same, and report with due diligence during bank audits.
[1] Definitions under The Prevention of Money Laundering Act, 2002
Every Auditor must be familiar with some of the following terms and definitions of PMLA which will help to start an audit of banks or financial institutions, mitigate the risk and find out the account and suspicious transactions if some money laundering is being done:
Section 2(y) – “Scheduled offence”: Means—
- the offences specified under Part A of the Schedule; or
- the offences specified under Part B of the Schedule if the total value involved in such offences is one crore rupees or more; or
- the offences specified under Part C of the Schedule.
Section 3 – “Offence of money-laundering”: Whosoever directly or indirectly attempts to indulge or knowingly assists or knowingly is a party or is actually involved in any process or activity connected with the proceeds of crime including its concealment, possession, acquisition or use and projecting or claiming it as untainted property shall be guilty of offence of money-laundering.
Explanation (added w.e.f. 01.08.2019):
- A person shall be guilty of the offence of money laundering if such person is found to have directly or indirectly attempted to indulge or knowingly assisted or knowingly is a party or is involved in one or more of any of the processes or activities connected with proceeds of crime such as concealment, possession, acquisition, use, projecting as untainted property; or claiming as untainted property, in any manner whatsoever;
- The process or activity connected with proceeds of crime is a continuing activity. It continues still such time a person is directly or indirectly enjoying the proceeds of crime by its concealment or possession or acquisition or use or projecting it as untainted property or claiming it as untainted property in any manner whatsoever.
Process and Methods of Money Laundering
The Auditor should know the process of money laundering which generally comprises three stages:
Some of the methods in money laundering are popular through which one may carry out their activities through the banking channel such as:
Development of KYC and CDD Processes
The Auditor should know the background of global initiatives. The Basel Committee on Banking Supervision (BCBS), established in 1974 following the collapse of Herstatt Bank in West Germany, recognized the banking system as a primary channel exploited for money laundering. The Basel Committee issued its landmark “Statement on the prevention of criminal use of banking system for the purpose of money laundering”, recommending strict customer identification and ethical banking procedures.
In 1989, the G-7 Summit in Paris established the Financial Action Task Force (FATF), which formulated the 40 Recommendations on Money Laundering and combating terrorist financing. One key recommendation was to bring professional accountants under the ambit of AML reporting entities. In 1995, the Egmont Group was formed, now comprising 164 Financial Intelligence Units (FIUs) globally to exchange financial intelligence securely.
In India, FIU-IND was established in 2004 by the Government of India as the central national agency responsible for receiving, processing, analyzing, and disseminating information relating to suspect financial transactions.
Regulatory Guidelines: RBI Master Direction on KYC
The Reserve Bank of India has issued several circulars on ‘Know Your Customer’ (KYC) and transaction monitoring, consolidated in its Master Direction (updated 4th May 2023 via Circular No. RBI/DBR/2015-16/18).
Definition of Customer: “Customer means a person who is engaged in a financial transaction or activity with a Regulated Entity (RE) and includes a person on whose behalf the person who is engaged in the transaction or activity, is acting.”
Mandatory KYC Documents (PML Rules 9(4 to 10)): Proof of Identity (Passport, Voter’s ID card, PAN card, Driving License) and Proof of Residence (utility bills, ration card, employer letter). For legal entities: Certificate of Incorporation, MOA/AOA, Partnership Deed, or Trust Deed. Additionally, the Video-based Customer Identification Process (V-CIP) has been introduced for digital customer onboarding.
Client Due Diligence (CDD): Defined under Rule 2(1)(b) and Rule 14(ii)/(iii) of the amended PML (Maintenance of Records) Rules, 2013, requiring every reporting entity to formulate and execute a comprehensive CDD Programme to manage and mitigate risks.
Mandatory Transaction Reports Furnished to FIU-IND (Section 12, PMLA)
Under Section 12(1)(b) of the PMLA and PML Rules, banks, financial institutions, and intermediaries must submit periodic regulatory reports to FIU-IND:
| Report Type | Reporting Threshold & Description | Statutory Timeline |
|---|---|---|
| Cash Transaction Reports (CTRs) | • Total cash credit or debit transactions in an account exceeding ₹10 Lakhs in a calendar month. • Individual transactions of ₹50,000 and above are reported. • Transactions below ₹50,000 are also reported if the monthly account aggregate exceeds ₹10 Lakhs. • Cash deposits/withdrawals across all accounts of a single customer must be aggregated. • Compulsory monthly filing; NIL report required if no reportable transactions occur. | By the 15th day of the succeeding month |
| Non-Profit Organization Transaction Reports (NTRs) | • Any account of a Non-Profit Organization (NPO) receiving credit of ₹10 Lakhs or more in a month. • Compulsory monthly filing; NIL report required if no reportable credits occur. | By the 15th day of the succeeding month |
| Counterfeit Currency Reports (CCRs) | • Any forged or counterfeit banknotes detected at the cash counter. • Police FIR Requirement: If counterfeit notes detected exceed 4 pieces in a single transaction, an FIR must be lodged and a copy enclosed with the CCR. | By the 15th day of the succeeding month |
| Cross Border Wire Transfer Reports (CBWTR) | • All cross-border wire transfers exceeding ₹5 Lakhs (or equivalent foreign currency) where origin or destination is in India. • Purchase/sale of immovable property valued at ₹50 Lakhs or more registered by the reporting entity. | By the 15th day of the succeeding month |
| Suspicious Transaction Reports (STRs) | • Any transaction or business dealing raising suspicion of being linked to proceeds of crime, money laundering, terrorist financing, or lacking economic rationale. • Includes attempted transactions, whether or not made in cash. • ANTI-TIPPING OFF MANDATE: Banks/FIs must not put any operational restrictions on accounts where an STR has been filed. | Within 7 days of arriving at suspicion |
Red Flags and Identification of Suspicious Transactions
Auditors should review the following indicators of suspicious transactions during statutory and concurrent bank audits:
- False identification documents or documents that could not be verified within a reasonable time.
- Non-face-to-face clients and doubt over the Ultimate Beneficial Owner (UBO).
- Accounts opened with names deceptively close to established corporate entities.
- Multiple Accounts: Large number of accounts sharing a common account holder, introducer, or authorized signatory with no commercial rationale.
- Unexplained transfers between multiple accounts without clear rationale.
- Sudden, massive activity in long-dormant accounts.
- Transactions completely inconsistent with the client’s declared business turnover or financial standing.
- Accounts utilized for circular trading, insider trading, or off-market block deals executed at non-market prices.
Chartered Accountants as Reporting Entities and Professional Misconduct
Notifications S.O. 2036(E) and S.O. 2135(E) (May 2023)
Recently, two notifications Nos. S.O. 2036(E) and 2135(E) were issued by the Ministry of Finance, Department of Revenue on 3rd May 2023 and 9th May 2023, respectively, to include professionals (practicing Chartered Accountants, Company Secretaries, Cost Accountants) and company formation agents as Reporting Entities under the Prevention of Money Laundering Act. FIU-IND has issued guidelines detailing customer KYC and due diligence obligations for CAs.
Keeping the provisions of PMLA in mind, the Auditor should verify all potential areas where suspicious transactions come to notice and verify whether banks have submitted all required statutory reports. In case of failure by banks, the Auditor is supposed to report.
Now the question arises: if the bank has already reported the matter, is the Auditor required to report the same matter again as a reporting entity to FIU-IND or the Self-Regulatory Body (SRB)? This remains a critical area requiring regulatory clarification. If the Auditor fails to discharge their duties during an audit, they shall be guilty of professional misconduct and liable to disciplinary action by the competent authority. Substantial accountability and penal provisions now exist for both auditors and bank officials who fail to discharge their statutory PMLA obligations strictly.
Conclusion
While auditing banks, the Auditor should ensure that the bank has an effective AML/CFT program in place by establishing appropriate procedures and ensuring their effective implementation. It should cover proper management oversight, internal control systems, segregation of duties, staff training, and quarterly compliance submissions to the Audit Committee. Incorporating a risk-based audit approach and conducting rigorous verification of KYC/AML mechanisms is vital to safeguarding the integrity of India’s banking ecosystem.