Policy

AML Policy Drafting

Regulatory-grade AML/CFT policy documents tailored to your business model

Overview

A well-drafted AML policy is the cornerstone of PMLA compliance. Estabizz drafts, reviews and updates AML/CFT policy documents that are regulator-ready, operationally practical and calibrated to your specific business model — whether you are an NBFC, payment aggregator, insurance entity, stockbroker or fintech platform.

What We Offer

Board-approved KYC/AML Policy compliant with PMLA Rules 2005
Customer Acceptance Policy (CAP) and Risk Categorisation framework
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) SOP
Combating Financing of Terrorism (CFT) procedures
STR/CTR escalation and filing procedure
Record Retention Policy (5-year PMLA requirement)
Politically Exposed Persons (PEP) and adverse media screening procedures

How It Works

1

Business Model Review

Understand your products, customer segments, geographies and distribution channels to calibrate the policy.

2

Regulatory Mapping

Map applicable PMLA Rules, sector-specific master directions (RBI/SEBI/IRDAI) and FATF guidance.

3

Draft & Review

Prepare first draft, share with your compliance/legal team, incorporate feedback and produce a final Board-ready version.

4

Board Adoption Support

Prepare Board note and resolution language; update policy schedule with version control.

Documents Required

  • Business model overview (products, geographies, customer types)
  • Existing AML policy (if being revised)
  • Organisational chart — compliance and senior management
  • Regulator-specific licence/registration details

Frequently Asked Questions

Is a separate CFT policy required or can it be part of the AML policy?+

Both approaches are acceptable. A combined AML/CFT policy is common and acceptable to regulators; some large entities maintain a separate CFT annex.

Does the Board need to formally approve the AML policy?+

Yes. Under PMLA Rules and most sector-specific directions, the AML/KYC policy must be approved and periodically reviewed by the Board.

Can the same policy apply to multiple regulated entities in a group?+

A group-level policy can set minimum standards, but each regulated entity typically needs its own adopted version reflecting its specific licence and customer base.

AML Policy Drafting — Start Today

Regulatory-grade AML/CFT policy documents tailored to your business model

Book a Free Consultation →