Legally researched and updated: 6 October 2026

Chartered Accountants, Company Secretaries and Cost Accountants Under PMLA: When Do Professional Financial Transactions Trigger Reporting Entity Duties?

Create a professional-services article based on the notified framework and FIU-IND AML/CFT guidelines for professionals holding certificates of practice from ICAI, ICSI and ICMAI. Distinguish routine audit, tax, legal or secretarial work from the specified financial transactions that trigger reporting duties. Cover client due diligence, beneficial ownership, internal AML/CFT/CPF policy, reporting route, records and professional-role attribution.

Legal research and analysis by Advocate Ankit Kumar Singh .

Direct Answer: Holding a Certificate of Practice Is Not Enough

The 3 May 2023 PMLA notification does not make every professional engagement of every practicing Chartered Accountant, Company Secretary or Cost Accountant a notified PMLA transaction.

The trigger is narrower.

A professional should test whether:

  1. the individual holds the relevant Certificate of Practice;
  2. a financial transaction is actually being carried out;
  3. the transaction is being carried out on behalf of the client;
  4. it is being carried out in the course of the profession; and
  5. it relates to one of the five activities notified in S.O. 2036(E).

The practical formula is:

CoP + ACTUAL FINANCIAL TRANSACTION + ON BEHALF OF CLIENT + IN COURSE OF PROFESSION + ONE OF FIVE NOTIFIED ACTIVITIES = PMLA REPORTING-ENTITY ANALYSIS.

The Legal Basis: S.O. 2036(E) Dated 3 May 2023

The Central Government notified specified financial transactions carried out by a β€œrelevant person” on behalf of a client in the course of the profession.

A relevant person includes an individual holding a Certificate of Practice under:

  • the Chartered Accountants Act, 1949;
  • the Company Secretaries Act, 1980; or
  • the Cost and Works Accountants Act, 1959,

practising individually or through a firm within the terms of the notification.

The notification is activity-specific.

It should therefore not be reduced to:

β€œALL CAs, CSs AND CMAs ARE PMLA REPORTING ENTITIES FOR EVERYTHING THEY DO.”

That formulation is too broad.

The Five Financial Activities That Trigger the Professional Framework

1. Buying and Selling of Immovable Property

The professional framework can apply where the relevant professional actually carries out a financial transaction on behalf of the client in relation to buying or selling immovable property.

The critical distinction is between:

ADVICE / CERTIFICATION / TAX CALCULATION

and:

ACTUAL EXECUTION OR MANAGEMENT OF THE CLIENT'S FINANCIAL TRANSACTION.

2. Managing Client Money, Securities or Other Assets

This is a significant trigger where the professional:

  • holds client money;
  • controls payment flows;
  • manages securities;
  • manages assets;
  • routes money connected with a covered transaction; or
  • otherwise assumes substantive management/control of client assets.

3. Management of Bank, Savings or Securities Accounts

Coverage can arise where the professional moves from advice to actual account management, such as:

  • operating authority;
  • transaction execution;
  • signatory authority;
  • management of withdrawals/transfers;
  • management of securities account activity; or
  • other substantive account-management functions.

4. Organisation of Contributions for Creation, Operation or Management of Companies

This can include professional involvement in arranging or organising funding/contributions used for:

  • creation;
  • operation; or
  • management

of companies.

5. Creation, Operation or Management of Companies, LLPs or Trusts, and Buying/Selling Business Entities

This category should be analysed where the professional is substantively involved in:

  • financial creation/operation of legal entities;
  • management of the financial affairs of companies or LLPs;
  • trust-management transactions;
  • purchase of businesses;
  • sale of businesses; or
  • other notified transaction activity.

Routine Audit and Attestation: When Is It Outside the 3 May Notification?

ICAI's published professional guidance states that all professional activities are not covered merely because they are performed by a practicing CA.

Examples identified as outside the notification, subject to the facts, include:

  • statutory auditing;
  • attestation;
  • certification;
  • tax audit;
  • other review services;
  • special-purpose audit reports; and
  • due-diligence reports.

The reason is:

THE PROFESSIONAL MUST ACTUALLY CARRY OUT THE NOTIFIED FINANCIAL TRANSACTION ON BEHALF OF THE CLIENT.

An audit of a transaction is different from executing that transaction.

A due-diligence report on a proposed acquisition is different from controlling the money used to acquire the target.

Routine Tax and Compliance Work

Professional guidance similarly distinguishes ordinary:

  • income-tax return filing;
  • GST return filing;
  • tax audit;
  • direct-tax compliance;
  • indirect-tax compliance;
  • PAN/TAN/GST applications;
  • PF/ESIC registrations;
  • trademark-number applications;
  • MCA compliance;
  • FEMA compliance;
  • RERA compliance; and
  • other professional filings

from a notified financial transaction.

The distinction changes where the professional also:

  • takes control of client funds;
  • operates the bank account;
  • manages securities/assets; or
  • executes another financial transaction falling within the five notified activities.

Paying Taxes or Government Fees for a Client

A professional frequently assists in paying:

  • income tax;
  • TDS;
  • GST;
  • MCA fees;
  • registration charges;
  • statutory fees; or
  • other Government dues.

This should not automatically be treated as a notified professional transaction.

The question becomes materially different where:

THE PROFESSIONAL MANAGES THE CLIENT'S BANK ACCOUNT, CLIENT MONEY OR CLIENT ASSETS

and the activity is also connected with one of the five notified categories.

The engagement file should therefore record:

  • who controlled the account;
  • who authorised the payment;
  • whether the professional merely uploaded a challan;
  • whether the client directly authorised payment;
  • whether client money was held; and
  • whether the payment related to a notified financial activity.

Project Financing and Organisation of Contributions

Project-financing mandates require particular attention.

There is a difference between:

PREPARING A PROJECT REPORT OR ADVISING ON CAPITAL STRUCTURE

and:

ORGANISING CONTRIBUTIONS FOR CREATION, OPERATION OR MANAGEMENT OF A COMPANY.

Where the professional actually organises contributions, fund flows or financing connected with the notified activity, the engagement may fall within S.O. 2036(E).

Prepare a transaction-role note identifying:

  • who sourced investors;
  • who negotiated funding;
  • who collected contributions;
  • who controlled the escrow/bank account;
  • who directed transfer of money;
  • who merely advised; and
  • who actually executed the financial transaction.

Company, LLP and Trust Formation: Check Both the 3 May and 9 May Notifications

This is one of the most important classification safeguards.

ICAI's professional FAQ indicates that incorporation work can fall outside the 3 May professional notification where the professional does not manage client funds/bank accounts or otherwise carry out the notified financial transaction.

But that does not end the legal analysis.

A separate Central Government notification dated:

9 MAY 2023 β€” S.O. 2135(E)

covers Trust and Company Service Provider activities including:

  • acting as a company/LLP formation agent;
  • arranging directors/secretaries/partners;
  • providing registered-office/address services;
  • trustee services; and
  • nominee-shareholder services,

subject to its express exclusions.

Therefore:

NOT COVERED UNDER S.O. 2036(E)

does not necessarily mean:

NOT COVERED UNDER S.O. 2135(E).

Professional firms should run both tests where corporate/trust services are offered.

Client Due Diligence: What Must the Professional Know?

Once the engagement falls within the reporting-entity framework, the professional should apply the current CDD requirements to the notified client relationship/transaction.

A defensible CDD file should establish:

  • who the client is;
  • identity verification;
  • address;
  • legal form;
  • nature of business;
  • purpose and intended nature of the engagement;
  • ownership structure;
  • control structure;
  • whether the person giving instructions is authorised;
  • whether the client is acting for another person;
  • beneficial owner;
  • expected transaction profile;
  • source information where risk requires it; and
  • client risk classification.

The professional should not treat:

PAN + ENGAGEMENT LETTER

as automatically sufficient CDD for a complex notified financial transaction.

Beneficial Ownership: Look Beyond the Signatory

Professional services frequently involve companies, LLPs, partnerships and trusts.

The person instructing the professional may not be the ultimate owner.

Companies

Current Rule 9 beneficial-owner analysis includes natural persons who ultimately own/control the client through the applicable ownership threshold or control through other means.

Partnerships

Look through partnership interests, profit entitlement and control.

Trusts

Relevant persons include:

  • settlor/author;
  • trustee;
  • relevant beneficiaries; and
  • natural persons exercising ultimate effective control.

Practical Professional File

Prepare:

LEGAL OWNER β†’ INTERMEDIATE OWNER β†’ ULTIMATE NATURAL PERSON β†’ CONTROL RIGHTS β†’ SOURCE OF INSTRUCTIONS.

Internal AML/CFT/CPF Policy

The FIU professional Guidelines require relevant persons/firms to establish appropriate policies, procedures and controls to prevent:

  • money laundering;
  • terrorist financing; and
  • proliferation financing.

The framework should include:

  • scope/classification procedure;
  • client acceptance;
  • KYC/CDD;
  • beneficial ownership;
  • risk assessment;
  • enhanced due diligence;
  • PEP controls;
  • sanctions screening;
  • transaction monitoring;
  • internal alert escalation;
  • STR decision-making;
  • reporting procedure;
  • confidentiality;
  • tipping-off controls;
  • record retention;
  • employee training;
  • role allocation;
  • periodic review; and
  • response to FIU/SRB information requirements.

For a firm, the policy should be appropriately approved at the governing/management level contemplated by the FIU Guidelines.

Principal Officer, Designated Director and Professional-Role Attribution

Individual Practitioner

Under the FIU professional Guidelines, where the relevant person is an individual practicing professional:

THE PROFESSIONAL HIMSELF/HERSELF FUNCTIONS AS THE PRINCIPAL OFFICER.

Firm

Where the notified professional practice operates through a firm, the Guidelines require appointment of:

  • Designated Director; and
  • Principal Officer.

The roles should not exist only on paper.

Engagement-Level Attribution

Maintain a clear role map:

Role Actual Function
Engagement PartnerProfessional oversight
Principal OfficerAML escalation and FIU reporting
Designated DirectorOverall Chapter IV compliance where applicable
Authorised SignatoryActual authority over transaction/account
EmployeeOperational processing
Client Director/OwnerCommercial decision and instruction

This matters because:

PROFESSIONAL TITLE DOES NOT SUBSTITUTE FOR EVIDENCE OF ACTUAL CONDUCT.

How Are Reports Furnished to FIU-IND?

The FIU professional Guidelines provide a sector-specific reporting architecture through the relevant Statutory Body:

  • ICAI;
  • ICSI; or
  • ICMAI.

The relevant person files the prescribed report through the applicable SRB mechanism.

The SRB verifies Certificate-of-Practice status before forwarding the report to FIU-IND under the prescribed arrangement.

Multiple Certificates of Practice

Where a relevant person holds CoPs from more than one SRB, the FIU Guidelines state that the relevant SRB should be determined according to:

THE NATURE OF SERVICES PROVIDED TO THE CLIENT.

Because institute-specific portals and procedures may change, verify the current:

  • ICAI AML compliance portal/process;
  • ICSI PMLA portal/process;
  • ICMAI reporting process;
  • reporting format;
  • registration procedure; and
  • acknowledgement mechanism

on the actual filing date.

Suspicious Transaction Reporting for Professionals

A professional should not equate:

SUSPICIOUS

with:

LARGE.

Suspicion is fact-specific.

Potential red flags can include:

  • client refuses beneficial-owner information;
  • ownership is unnecessarily opaque;
  • funds come from unrelated third parties;
  • transaction lacks apparent commercial rationale;
  • professional is asked to route money without legitimate reason;
  • rapid creation and sale of entities;
  • unusual use of trusts or nominees;
  • transaction inconsistent with known financial profile;
  • funds connected with high-risk jurisdictions;
  • unusual complexity;
  • structuring to avoid reporting/records;
  • false or unverifiable documents;
  • criminal-proceeds indicators;
  • terrorist-financing indicators; or
  • attempted transaction abandoned after compliance questions.

STR Timeline

Where the Principal Officer becomes satisfied that a transaction is suspicious:

REPORT PROMPTLY AND NOT LATER THAN 7 WORKING DAYS.

Document the Decision

Maintain:

RED FLAG β†’ CLIENT FILE β†’ BO β†’ TRANSACTION β†’ PURPOSE β†’ SOURCE / COUNTERPARTY β†’ ANALYSIS β†’ PO DECISION β†’ STR OR DOCUMENTED CLOSURE.

Tipping-Off and Professional Confidentiality

Professional confidentiality does not permit a reporting entity to warn a client that:

  • an STR is being considered;
  • an STR has been filed; or
  • information is being furnished to FIU-IND.

The FIU Guidelines prohibit tipping off:

BEFORE + DURING + AFTER THE STR PROCESS.

Professional firms should therefore train staff on how to respond when a client asks:

β€œWhy are you asking for these documents?”

without disclosing the existence of an STR review.

Records: What Should Be Preserved?

The statutory framework requires records capable of reconstructing individual transactions.

For covered professional engagements, preserve as applicable:

  • engagement letter;
  • KYC documents;
  • beneficial-owner analysis;
  • ownership chart;
  • risk assessment;
  • client instructions;
  • authorisation/power of attorney;
  • bank mandate;
  • payment instructions;
  • bank statements;
  • securities instructions;
  • property documents;
  • business purchase/sale documentation;
  • trust documents;
  • company/LLP records;
  • funding/contribution records;
  • emails;
  • internal memoranda;
  • alerts;
  • STR analysis;
  • reports furnished;
  • acknowledgements;
  • CDD refresh material; and
  • engagement closure record.

The statutory Section 12 structure generally requires:

TRANSACTION RECORDS: 5 YEARS FROM TRANSACTION.

and applicable client/beneficial-owner/account/business-correspondence records:

5 YEARS AFTER THE BUSINESS RELATIONSHIP ENDS OR ACCOUNT CLOSES, WHICHEVER IS LATER.

Professional PMLA Classification Flowchart

For practicing CAs, CSs and Cost Accountants, PMLA classification under the 3 May 2023 notification depends on the actual financial transaction carried out on behalf of the client, not merely the professional designation or routine advisory service.

Common Professional-Service PMLA Mistakes

  • Assuming every practicing CA, CS or CMA is a reporting entity for every engagement.
  • Assuming holding a CoP alone creates PMLA reporting duties for all clients.
  • Treating an audit as the same thing as executing the underlying transaction.
  • Treating certification as management of client assets.
  • Calling account-operation authority β€œroutine consultancy”.
  • Managing client money without documenting the role.
  • Operating a bank account but treating the engagement as only tax compliance.
  • Failing to distinguish project advice from organisation of funding contributions.
  • Ignoring the separate 9 May 2023 TCSP notification.
  • Assuming incorporation is outside PMLA merely because it falls outside S.O. 2036(E).
  • Failing to appoint the required PO/DD in a firm.
  • Maintaining no AML/CFT/CPF policy.
  • Collecting PAN but no beneficial-owner information.
  • Keeping no risk classification.
  • Keeping no record of who actually controlled client funds.
  • Keeping no STR decision log.
  • Assuming STR applies only above a monetary threshold.
  • Tipping off the client.
  • Using the wrong SRB reporting route.
  • Failing to preserve reporting acknowledgements.
  • Failing to distinguish the individual professional's role from the firm's role.
  • Backdating KYC or AML documentation after an FIU query.

Frequently Asked Questions

1. Are all practicing Chartered Accountants reporting entities under PMLA?

No. S.O. 2036(E) applies when a relevant professional carries out a financial transaction on behalf of a client in the course of the profession in relation to one of the five notified activities.

2. Are practicing Company Secretaries covered?

Yes, where they hold the relevant Certificate of Practice and satisfy the notified transaction test.

3. Are practicing Cost Accountants covered?

Yes, on the same activity-based basis under the notification.

4. Is statutory audit automatically covered?

No. Professional guidance distinguishes auditing from actually carrying out a notified financial transaction on behalf of the client.

5. Is tax-return filing covered?

Ordinary income-tax/GST return filing is not itself one of the five notified financial activities.

6. Is tax audit covered?

Tax audit/review by itself is not the transaction trigger identified in S.O. 2036(E).

7. What if the professional controls the client's bank account?

Management of bank, savings or securities accounts is expressly one of the notified activities and requires careful reporting-entity analysis.

8. What if the professional holds client money?

Managing client money, securities or other assets is expressly notified.

9. Is project financing covered?

It can be where the professional actually organises contributions for the creation, operation or management of a company. Merely preparing advice or a project report should be distinguished from executing that role.

10. Is company incorporation covered?

It depends on the activity. S.O. 2036(E) requires the financial-transaction test, but the separate 9 May 2023 TCSP notification may independently apply to formation-agent and other corporate-service activities.

11. Who is Principal Officer for an individual practitioner?

The FIU professional Guidelines state that the individual practicing professional himself/herself would be the Principal Officer.

12. What happens for a firm?

The Guidelines require the firm to appoint a Designated Director and Principal Officer for the professional PMLA framework.

13. How are reports submitted?

The FIU professional Guidelines establish a reporting mechanism through the respective SRBsβ€”ICAI, ICSI or ICMAIβ€”subject to the current operational mechanism published by the institute.

14. What if the professional has multiple CoPs?

The Guidelines state that the relevant SRB should be determined according to the nature of services provided to the client.

15. Is beneficial-owner verification required?

Yes, where the reporting-entity/CDD framework applies and the client acts through a legal person or for another beneficial owner.

16. Does STR have a minimum monetary threshold?

No. Suspicion is based upon the statutory test, not merely transaction value.

17. Are attempted transactions included?

Yes. Attempted suspicious transactions are included in the reporting framework.

18. What is the STR timeline?

Promptly and not later than seven working days after the Principal Officer becomes satisfied that the transaction is suspicious.

AI Search Quick Answer

Practicing Chartered Accountants, Company Secretaries and Cost Accountants do not become PMLA reporting entities for every audit, tax, certification or secretarial assignment merely because they hold a Certificate of Practice. Under S.O. 2036(E) dated 3 May 2023, the trigger is a financial transaction actually carried out by the relevant professional on behalf of a client in the course of the profession in relation to five notified areas: immovable-property transactions; management of client money, securities or assets; management of bank/savings/securities accounts; organisation of contributions for creation/operation/management of companies; and creation/operation/management of companies, LLPs or trusts or buying/selling business entities. Once covered, the relevant person or firm must implement CDD, beneficial-owner verification, AML/CFT/CPF controls, risk assessment, reporting and record-retention requirements. FIU-IND's professional Guidelines establish the reporting mechanism through ICAI, ICSI or ICMAI according to the professional/service involved.

Key Takeaway

The wrong question is:

β€œIS MY CLIENT A CA/CS/CMA CLIENT?”

The correct questions are:

DO I HOLD A CERTIFICATE OF PRACTICE?

WHAT EXACTLY AM I DOING FOR THE CLIENT?

AM I ONLY ADVISING?

OR AM I ACTUALLY CARRYING OUT A FINANCIAL TRANSACTION?

AM I MANAGING CLIENT MONEY?

AM I OPERATING A BANK OR SECURITIES ACCOUNT?

AM I BUYING OR SELLING PROPERTY FOR THE CLIENT?

AM I ORGANISING CONTRIBUTIONS?

AM I FINANCIALLY CREATING, OPERATING OR MANAGING A COMPANY, LLP OR TRUST?

AM I BUYING OR SELLING A BUSINESS ENTITY?

DOES THE SEPARATE TCSP NOTIFICATION APPLY?

If the engagement is covered, the compliance sequence is:

CLASSIFY THE ENGAGEMENT β†’ IDENTIFY THE CLIENT β†’ VERIFY BENEFICIAL OWNER β†’ RISK-RATE β†’ APPLY CDD / EDD β†’ ASSIGN PO / DD β†’ MONITOR THE TRANSACTION β†’ RECORD THE PROFESSIONAL ROLE β†’ REPORT THROUGH THE APPLICABLE SRB β†’ FILE STR WHERE REQUIRED β†’ PRESERVE THE RECORD.

Professional Legal Review and Coordination

Advocate Ankit Kumar Singh undertakes legal research and advisory work concerning PMLA reporting-entity classification, FIU-IND compliance and professional-services exposure involving Chartered Accountants, Company Secretaries, Cost Accountants and professional firms, depending upon the facts, statutory activity, procedural stage and accepted professional engagement.

A professional-services PMLA review may include:

  • S.O. 2036(E) classification;
  • engagement-by-engagement analysis;
  • routine service vs notified transaction analysis;
  • client-money analysis;
  • bank-account authority review;
  • securities/assets management analysis;
  • immovable-property transaction review;
  • project-financing/contribution analysis;
  • company/LLP/trust transaction classification;
  • S.O. 2135(E) TCSP overlap analysis;
  • Principal Officer / Designated Director review;
  • AML/CFT/CPF policy;
  • CDD programme;
  • beneficial-owner mapping;
  • risk assessment;
  • EDD;
  • sanctions screening;
  • STR decision framework;
  • SRB reporting route;
  • record-retention review;
  • Section 12A response;
  • Section 13 show cause response;
  • personal-hearing preparation; and
  • Section 26 appellate strategy where applicable.

Advocate Ankit Kumar Singh
Supreme Court of India | Patna High Court | Allahabad High Court at Prayagraj | Jharkhand High Court at Ranchi | Calcutta High Court | Delhi High Court and Delhi Courts/Tribunals | Matters concerning Bhopal, Madhya Pradesh | Multiple District Courts

Phone: 8294431232
Email: ankitsingh.legum@gmail.com
Website: advocateankitkumarsingh.in

Professional engagement depends upon the actual transaction, capacity in which the professional acted, the applicable notification, client structure, records and current FIU/SRB procedure. No FIU-IND or Section 13 outcome can be guaranteed.

Official Sources

Add Advocate Ankit Kumar Singh as a Preferred Source on Google

Readers who want to see more legal research, court updates, cyber law, PMLA, ED, criminal-law and litigation content from Advocate Ankit Kumar Singh can add advocateankitkumarsingh.in as a Preferred Source on Google.

Add advocateankitkumarsingh.in as a Preferred Source on Google

Conclusion

The professional-services PMLA framework should not be interpreted by professional title alone.

The decisive question is:

WHAT DID THE PROFESSIONAL ACTUALLY DO WITH THE CLIENT'S MONEY, ASSETS, ACCOUNT OR FINANCIAL TRANSACTION?

A professional may:

  • audit;
  • certify;
  • review;
  • advise;
  • prepare a return;
  • draft a compliance document; or
  • provide ordinary procedural assistance

without necessarily carrying out one of the five notified financial transactions.

But once the professional actually:

  • controls client money;
  • manages bank/securities accounts;
  • executes property transactions;
  • organises company contributions;
  • manages covered financial affairs of companies/LLPs/trusts; or
  • executes acquisition/sale of a business entity,

the PMLA analysis changes.

The defensible professional model is:

CLASSIFY THE ENGAGEMENT + DOCUMENT THE PROFESSIONAL ROLE + KNOW THE CLIENT + IDENTIFY THE BENEFICIAL OWNER + ASSESS RISK + CONTROL ACCESS TO CLIENT FUNDS + MAINTAIN AN AML/CFT/CPF PROGRAMME + REPORT THROUGH THE CORRECT SRB + FILE STRs WHEN REQUIRED + PRESERVE THE AUDIT TRAIL.

Professional / Legal Disclaimer: This article provides general legal and regulatory information concerning S.O. 2036(E), practicing Chartered Accountants, Company Secretaries and Cost Accountants, and the FIU-IND AML/CFT framework. Whether a particular professional or firm becomes a reporting entity depends upon the exact transaction, the client's instructions, the capacity in which the professional acted, whether client money/accounts/assets were managed, the notified activity, any separate TCSP exposure and the current FIU/SRB procedure. ICAI's FAQs contain practical and expressly fact-dependent professional guidance and should not be treated as replacing the statutory notification, PMLA, PML Rules or FIU directions. A live engagement or Section 13 matter should therefore be reviewed from its actual documents and current law.