NISM Professor

Regulated Entity

Also written RE

IFSCA's term for a unit that holds its licence, recognition, registration or authorisation — the entity the IFSCA (AML, CFT and KYC) Guidelines, 2022 place their duties on.

In plain language

The PMLA speaks of a reporting entity. The IFSCA Guidelines speak of a Regulated Entity, and mean something narrower: a unit or entity that has been granted licence, recognition, registration or authorisation by the Authority.

The two circles overlap heavily but are not the same circle. A GIFT City banking unit is both. A crypto exchange serving Indian customers is a reporting entity under the PMLA and no concern of IFSCA's. A foreign university's branch campus in the IFSC is a Regulated Entity that IFSCA has largely exempted from the AML Guidelines.

Exam questions live in that gap.

How it works

Three duties define a Regulated Entity, and the first sample question of Chapter 5 tests the third:

  1. Formulate an AML-CFT policy, approved by the Governing Body or a committee to which the Governing Body has delegated the power.
  2. Develop a KYC Policy, which is part of the AML-CFT policy — not a separate document.
  3. Every member of Senior Management is responsible for the Regulated Entity's compliance, exercising due skill, care and diligence. Not the Compliance Officer alone, not the Principal Officer alone, not the Designated Director alone.

On top of that sit the running obligations: a documented business risk assessment; a customer risk rating of high, medium or low before due diligence begins; a risk assessment reviewed at least once every two years or on a material trigger event, whichever is earlier; records preserved for at least six years from the end of the relationship or completion of the transaction; and an independent audit function.

By an IFSCA circular dated 18 November 2024, certain entities and activities are exempt from the Guidelines — international branch campuses of foreign universities, and service providers within the same financial group not located in FATF high-risk jurisdictions. The exemption is not a holiday: they must still conduct and document a business risk assessment, and if any AML/CFT risk is identified, the full obligations under the PMLA and the Guidelines resume.

A worked example

Prowess Insurance Brokers Pvt. Ltd. held an IRDAI certificate of registration as a Direct Broker valid from 22 September 2018 to 21 September 2021, and an IRDAI approval dated 17 August 2020 to run a branch in GIFT IFSC as an IFSC Insurance Intermediary Office. Under clause 11 of the IRDAI IIIO Guidelines, 2019, that approval was co-terminus with the underlying certificate — so it died on 21 September 2021 too.

The IFSCA (Insurance Intermediary) Regulations, 2021 then superseded the IRDAI guidelines, and Prowess was required to renew with IRDAI and then apply to IFSCA for a certificate for the GIFT branch. On 6 January 2022 the branch told IFSCA the renewal was still pending with IRDAI. On 12 January 2022 IFSCA directed it not to write any fresh insurance business, only to service existing policyholders. The branch did not even acknowledge the email, and carried on trading.

IFSCA cancelled the authorisation to operate the GIFT IFSC branch office. Crucially, the order recorded that despite cancellation the entity remains liable for everything done or omitted as an insurance intermediary, remains responsible for outstanding fees, dues and interest, and must still maintain and preserve the records the regulations require.

Surrendering the licence does not surrender the six-year record-keeping obligation. That is the examinable sting.

Why NISM asks about it

Chapter 5 opens on the Duties of a Regulated Entity and its first sample question asks who is responsible for compliance — the answer is every member of Senior Management. Chapter 2 (section 2.2.4) lists the IFSC compliance requirements and the exemptions; Chapter 7 supplies the Prowess order. Expect at least one question that hinges on Regulated Entity versus reporting entity.

Common exam traps

  • Regulated Entity is IFSCA's word; reporting entity is the PMLA's. A question that says "under the Guidelines" wants Regulated Entity; one that says "under the Act" wants reporting entity.
  • Compliance is Senior Management's, collectively. Naming only the Principal Officer, the Designated Director or the Compliance Officer is the distractor in the workbook's own sample question.
  • An exempted entity still owes a business risk assessment, and the exemption evaporates the moment an AML/CFT risk is identified.
  • The KYC Policy is part of the AML-CFT policy, approved by the Governing Body — not a standalone document approved by management.
  • Records survive cancellation of the licence. Prowess is the authority for that.
  • The risk assessment review clock is two years or a material trigger event, whichever is earlier — do not confuse it with the customer periodic-updation cycles of one, three and five years.

Check yourself

  1. 1.Which of the following is correct about the duty of a Regulated Entity?

    1. a)Every member of the Regulated Entity's Senior Management shall be responsible for the Regulated Entity's compliance under the IFSCA (AML, CFT and KYC) Guidelines
    2. b)Only the Compliance officer shall be responsible for the Regulated Entity's compliance
    3. c)Only the Designated Director shall be responsible for the Regulated Entity's compliance
    4. d)Only the Principal Officer shall be responsible for the Regulated Entity's compliance
    Show the answer

    Answer: (a) Every member of the Regulated Entity's Senior Management shall be responsible for the Regulated Entity's compliance under the IFSCA (AML, CFT and KYC) Guidelines

    Every member of Regulated Entity's Senior Management shall be responsible for the Regulated Entity's compliance under these Guidelines. While carrying out their responsibilities under these Guidelines every member of a Regulated Entity's Senior Management shall exercise due skill, care, and diligence.

    "Every member" — which is why all three "only" options fail. Compliance is not delegable to a single officer.

    **The standard imposed on them is due skill, care, and diligence.

    The other two duties: every Regulated Entity shall formulate an AML-CFT policy, which shall be duly approved by the Governing Body or by a committee to whom such power has been delegated by the Governing Body, incorporating the key principles or elements of these Guidelines; and every Regulated Entity shall develop a KYC Policy which shall be the part of its AML-CFT policy.

    The KYC policy sits inside the AML-CFT policy, not beside it.

    The theme recurs throughout the Guidelines. The risk-based approach must trickle down from the level of Senior Management to the rest of the organization; the AML/CFT policies, procedures and controls shall be approved by Senior Management; correspondent banking requires approval from the Senior Management; and systems must include a provision enabling its Senior Management to regularly review the information on operations and effectiveness of its AML systems and controls.

    The Principal Officer's role is operational and upward-reportingtaking overall charge of all AML/CFT matters within the organisation and reporting to Senior Management on the outcome of reviews.

    And who this applies to: a Regulated Entity means a unit/entity which has been granted license, recognition, registration or authorisation by the Authority.

  2. 2.While implementing the Risk Based Approach, a Regulated Entity must ensure which of the following?

    1. a)All of the above
    2. b)The RBA is objective and proportionate to the risks
    3. c)The RBA is based on reasonable grounds
    4. d)The RBA is reviewed and updated at appropriate intervals
    Show the answer

    Answer: (a) All of the above

    A Regulated Entity while adopting RBA shall ensure that: i. The RBA is objective and proportionate to the risks; ii. The RBA is based on reasonable grounds; and iii. The RBA is reviewed and updated at appropriate intervals.

    Three conditions, all required.

    What the RBA is for: the primary thrust of these guidelines is to enable a Regulated Entity to adopt Risk-Based Approach (RBA) to identify and assess the Money Laundering (ML) and Terrorist Financing (TF) risk to which the Regulated Entity is exposed, depending upon its nature of business and exposure to or involvement with certain types of clients, countries or geographic areas, products, services, transactions, or delivery channels, etc. and document the same.

    Note "and document the same" — an undocumented approach does not satisfy the requirement.

    Proportionality is restated: the RBA shall be appropriate to the nature and size of the business. While implementing the RBA, the Regulated Entity shall consider all relevant risk factors before deciding overall risk.

    And it operates at two levels: in addition to assessing the ML/TF risks presented by an individual customer, a Regulated Entity shall also identify and assess ML/TF risks at an enterprise-wide level, Financial Group-wide level or Group-wide level, wherever applicable.

    Its output is a classification: the result of the risk assessment shall be used to classify the ML/TF risks as low, medium, and high. The general principle of this classification is to apply enhanced measures in case of high-risk customers and simplified measures in case of low-risk customers.

    And the review cycle is fixed: at least once every two years or when a material trigger event occurs, whichever is earlier, with the outcome put up to the Governing Body.

    A footnote sets the tone: the RBA should be an essential foundation in Regulated Entity's AML-CFT compliance culture, and it must trickle down from the level of Senior Management to the rest of the organization.

  3. 3.For how long must a Regulated Entity preserve records under the IFSCA (AML, CFT and KYC) Guidelines?

    1. a)At least six years from the date on which the business relationship has ended or the transaction is completed
    2. b)Three years from account opening
    3. c)Five years from the date of the transaction only
    4. d)Until the next inspection by the Authority
    Show the answer

    Answer: (a) At least six years from the date on which the business relationship has ended or the transaction is completed

    The Regulated Entity shall preserve all necessary records, for at least six years or for such period as prescribed under the applicable laws, from the date on which business relationship has ended or transaction is completed.

    Six years — longer than the PMLA's five, so the IFSC standard is the stricter one. Section 12 of the Act requires five years from the date of transaction for transaction records and five years after the business relationship... has ended or the account has been closed, whichever is later for identity records, which makes option C the natural trap.

    Where the end date is uncertain: where the date on which the business relationship with a customer has ended remains unclear, it may be taken to have ended on the date of the completion of the last transaction.

    What must be kept: a copy of all documents and information obtained in undertaking initial and ongoing Customer Due Diligence; records of customer business relationships (both original and certified copies) including correspondence, adequate records of transactions to enable standalone transactions to be reconstructed, and internal findings and analysis... whether or not it results in a Suspicious Transactions Report; the internal notifications; Suspicious Transactions Reports and any relevant supporting documents; and any relevant communications, if made with the FIU.

    Note that last phrase in the analysis limb — the reasoning is kept even where the decision was not to report.

    Option D misunderstands the purpose. Records are not kept until inspected but for a fixed period, and the Regulated Entity shall provide to the Authority or any law enforcement agency immediately on request, a copy of a records maintained by it.

    Electronic storage is permitted where records are readily accessible and promptly made available.

    And six years appears again for intermediary institutions in wire transfers — where technical limitations intervene, a record shall be preserved by the receiving intermediary institution for at least six years.

Where this is taught

Free preparation for NISM Series IFSCA-01

Related terms

← All terms
Something look wrong? Report it