R & D Law Chambers LLP. It is not affiliated with or endorsed by GIFT City, the International Financial Services Centres Authority (IFSCA), or any government or regulatory authority.

Authored by R & D Law Chambers LLP  |  Practice led by Ravish Bhatt, Dual-qualified lawyer (India and England & Wales)  |  Bar Council of Gujarat, Enrolment G/504/2008  |  SRA (non-practising) Registration No. 492 477  |  ADIT, Chartered Institute of Taxation, London

Published: 3 August 2026  |  Last reviewed: 3 August 2026

This article states the position as at 3 August 2026 and covers obligations that are continuous rather than periodic. It reflects the IFSCA (AML, CFT and KYC) Guidelines 2022 as amended in October 2025, the certification requirement notified in November 2025, and the Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs dated 10 March 2025.

The short answer

Filing on time is not compliance. An IFSC entity must also maintain standing frameworks: an AML, counter-terrorist financing and KYC programme with a Designated Director and a Principal Officer, who must be different people; registration and reporting with FIU-IND; a cyber security and cyber resilience framework; board-approved governance policies; books in foreign currency; and genuine presence at its registered office. None of these has a due date, which is exactly why they are missed.

Why an obligation without a deadline is the dangerous kind

Periodic filings announce themselves. A month ends, a return falls due, and a calendar entry fires. Standing obligations do nothing of the sort. Nothing falls due, so nothing prompts action, and the absence of a policy or an appointment produces no error message. The first prompt is usually an inspection or a regulatory query, and by then the gap is historic rather than prospective.

The pattern is consistent across entities: the periodic filings are broadly in order, and the standing frameworks are either absent, inherited unchanged from a mainland parent, or adopted on paper without the appointments, training and records that make them real.

The AML, CFT and KYC programme

The IFSCA (AML, CFT and KYC) Guidelines 2022, notified on 28 October 2022, apply to every entity licensed, recognised, registered or authorised by IFSCA. They are principles-based rather than sector-specific, which means each entity must work out what they require of its own business rather than adopting a template.

Two appointments, two people

The Guidelines require a Designated Director and a Principal Officer. The Designated Director is the person designated by the regulated entity to ensure overall compliance with the obligations imposed under Chapter IV of the Prevention of Money Laundering Act, the Rules made under it, and the Guidelines. IFSCA has clarified in its FAQs that these must be separate individuals. Combining the roles in one person is not compliance.

A certification requirement now attaches to both roles. On 17 November 2025 IFSCA notified a mandatory AML and CFT certification for Designated Directors and Principal Officers, under clauses 8.2 and 8.4 of Chapter VIII of the Guidelines, which deal with training, competence and continuing education. The course was launched on 18 November 2025 and must be completed within four months of that date, or within four months of the individual’s appointment to the role, whichever is later. Other employees are encouraged rather than required to take it, but entities are expected to run ongoing capacity-building.

A separate programme, not the parent’s

An IFSC entity is expected to put in place policies, processes and systems distinct from those of its onshore Indian affiliates, with a separate reporting structure for the IFSC entity. Inheriting a group manual without adaptation does not discharge the obligation, because the Guidelines are addressed to the regulated entity in the IFSC and are applied to its own risk profile.

What the programme has to contain

On video-based customer identification, amendments notified on 31 October 2025 expanded the process so that it may be undertaken not only by an authorised official of the regulated entity but also by officials of its financial group entities in India supervised by a financial regulator, or of a KYC Registration Agency. Part A of Annexure II was substituted with detailed operational and technological requirements, including end-to-end encryption, geo-tagging with live coordinates and a date-time stamp, and compliance with the cyber guidelines. Generic platforms such as ordinary video-conferencing or social media applications are not acceptable for onboarding. The ultimate responsibility for customer due diligence remains with the regulated entity even where the technology sits with a group entity or a registration agency.

Cyber security and cyber resilience

IFSCA’s Guidelines on Cyber Security and Cyber Resilience for Regulated Entities in IFSCs, dated 10 March 2025, set the standards that apply across regulated entities. They are also incorporated by reference into the AML framework: video-based customer identification must meet these standards.

The practical significance is that cyber compliance is no longer a matter for the technology function alone. Because the onboarding process must satisfy the cyber standards, a deficiency in the cyber framework becomes a deficiency in customer due diligence, and therefore an AML issue. Entities that treat the two as separate workstreams tend to discover the connection at the wrong moment.

Governance, policies and fit and proper

A Finance Company or Finance Unit undertaking core activities is subject to the full corporate governance and disclosure requirements. An entity undertaking only non-core activities is exempted from those requirements and from the prudential regulations, but only on condition that it maintains a board-approved prudential policy and satisfies fit and proper criteria.

The exemption is often misread as an absence of obligation. It is not. The Schedule to the IFSCA (Finance Company) Regulations 2021 makes the exemption conditional: the entity must have a board-approved prudential policy in place, and its key persons must meet the fit and proper criteria set out by the Authority. An entity claiming the lighter treatment without the board policy has the burden without the benefit.

What fit and proper means

Fit and proper is a standard regulatory gatekeeping test, used by financial regulators worldwide, directed at whether the people who own, control or run a regulated entity are suitable. IFSCA applies it as a registration and continuing condition. The IFSCA (Market Infrastructure Institutions) Regulations 2021 contain the definitional formulation, treating a person as fit and proper who has a general reputation and record of fairness and integrity. The corporate governance circular for Finance Companies of 9 August 2021 requires board members and key persons to satisfy qualification, expertise, track record, integrity and other fit and proper criteria.

In substance the test runs to three clusters: integrity, honesty and reputation, including the absence of convictions for fraud or dishonesty and of serious regulatory sanction; competence and capability, meaning relevant qualification, experience and track record; and financial soundness. It is assessed at appointment and continues to apply, which means a change in a key person’s circumstances is a compliance event.

Books, currency and records

A Finance Company or Finance Unit transacts in freely convertible foreign currency and maintains its balance sheet in United States dollars, with an Indian rupee account permitted only to meet administrative and statutory expenses.

Regulation 6 of the Finance Company Regulations governs this, and Regulation 9 requires financial reporting to the Authority in dollars. The obligation is easy to state and easy to breach in practice, usually through rupee transactions that are neither administrative nor statutory being routed through the local account for convenience.

Physical substance

The registered office must be within the IFSC and cannot be shifted outside it. Manpower must be deployed commensurate with the scale of business operations. The Certificate of Registration must be displayed. These are continuing conditions of registration, not one-off setup steps.

Substance has consequences beyond the regulatory layer, and the distinction is worth stating precisely. Complying with IFSCA’s requirements is not the same as establishing entitlement to the tax holiday under section 147 (formerly section 80LA). The regulatory gate and the fiscal gate are separate, and are tested by different authorities at different times, the second usually years later at assessment. An entity whose presence is thin may satisfy neither, and clearing the first does not clear the second.

Two further points follow from the SEZ layer. Operating from premises not approved in the Letter of Approval is a violation and may attract monetary penalties or cancellation. And any change of directors, shareholding pattern, name or constitution requires intimation and approval by the Unit Approval Committee under Instruction 109 of 18 October 2021, which means governance changes are an SEZ compliance event as well as a Companies Act one.

A readiness table

The final column is the one that matters. An inspector does not ask whether a framework exists; they ask to see the artefact that proves it.

FrameworkWhat must existEvidence typically sought
AML governanceDesignated Director and Principal Officer, separate individualsBoard resolution, appointment letters, intimation, certification status
AML programmeEnterprise-wide risk assessment and board-approved policyDated risk assessment, minuted board approval, review history
Customer due diligenceCDD and beneficial ownership process; V-CIP if usedSample files, screening records, V-CIP recordings with geo-tag and timestamp
FIU-INDFINGate registration and reportingRegistration confirmation, filing acknowledgements
Sanctions screeningDocumented screening and escalation processScreening logs, evidence of action on hits
CyberFramework per the 10 March 2025 GuidelinesPolicy, testing records, incident register
Prudential policyBoard-approved policy where prudential regulations are exemptedMinuted board approval, current version
Fit and properAssessment of key persons at appointment and continuingDeclarations, verification records, refresh evidence
Books and currencyUSD balance sheet; INR limited to administrative expensesFinancial statements, bank account mandates
SubstanceRegistered office in IFSC, commensurate manpower, CoR displayedLease deed, payroll, site inspection

How we help

R & D Law Chambers LLP advises on the design and remediation of standing frameworks for IFSC entities: AML, CFT and KYC programmes and the associated appointments and registrations; the interaction of the cyber guidelines with customer onboarding; governance policies and the conditions attached to prudential exemptions; fit and proper assessment; and the substance requirements that bear on both the regulatory registration and the fiscal position.

Frequently asked questions

What AML requirements apply to a GIFT IFSC entity?

The IFSCA (AML, CFT and KYC) Guidelines 2022, notified on 28 October 2022, apply to every entity licensed, recognised, registered or authorised by IFSCA. They require a Designated Director and a Principal Officer, who must be separate individuals, an enterprise-wide risk assessment, board-approved policies, customer due diligence including beneficial ownership, registration and reporting with FIU-IND, sanctions screening, suspicious transaction reporting and record-keeping. The Guidelines are principles-based, so each entity must apply them to its own business and risk profile.

Who is the Designated Director under the IFSCA AML Guidelines?

The Designated Director is the person designated by the regulated entity to ensure overall compliance with the obligations imposed under Chapter IV of the Prevention of Money Laundering Act, the Rules made under it, and the IFSCA Guidelines. The Designated Director and the Principal Officer must be different people. Since November 2025 both roles carry a mandatory AML and CFT certification requirement under Chapter VIII of the Guidelines, to be completed within four months of the course launch or of appointment, whichever is later.

Does a GIFT City entity need its own AML policy separate from its parent?

Yes. An IFSC entity is expected to maintain policies, processes and systems distinct from those of its onshore Indian affiliates, with a separate reporting structure for the IFSC entity. Adopting a group manual without adapting it to the IFSC entity’s own business and risk profile does not discharge the obligation, because the Guidelines are addressed to the regulated entity in the IFSC.

Are non-core Finance Companies exempt from governance requirements?

An entity undertaking only non-core activities is exempted from the prudential regulations and from the corporate governance and disclosure requirements under the Schedule to the IFSCA (Finance Company) Regulations 2021, but the exemption is conditional. The entity must maintain a board-approved prudential policy and its key persons must satisfy the fit and proper criteria set by the Authority. Claiming the lighter treatment without the board policy leaves the entity with the burden and without the benefit.

What does fit and proper mean for an IFSC entity?

Fit and proper is the standard regulatory test of whether those who own, control or run a regulated entity are suitable. IFSCA applies it as a registration and continuing condition. In substance it covers integrity, honesty and reputation, including absence of fraud or dishonesty convictions and serious regulatory sanction; competence and capability, meaning qualification, experience and track record; and financial soundness. It applies at appointment and continues, so a change in a key person’s circumstances is a compliance event.

This article is for general information as at 3 August 2026 and is not legal advice. Regulatory requirements, forms and portals change frequently. Seek jurisdiction-specific advice before acting.

Leave a Reply

Your email address will not be published. Required fields are marked *