On 7 March 2023, a gazette notification did something quiet and consequential. It pulled virtual digital asset service providers into the Prevention of Money Laundering Act, 2002 as reporting entities, which meant platforms that had never employed a compliance officer suddenly needed a team of them.
Fifteen months later, the Financial Action Task Force adopted India’s Mutual Evaluation Report at its June 2024 Plenary in Singapore and placed the country in the regular follow-up category, the lightest supervisory tier available. That outcome raised the bar rather than relaxing it. Staying in regular follow-up means demonstrating staffed, working compliance, not just good statutes.
In November 2024 the Reserve Bank amended its Know Your Customer Direction again. And by July 2025, a talent-solutions firm counting India’s financial-crime workforce put it at 25,543 people.
Four dates, one story. Each rule change converted a paragraph of regulation into a headcount line.
To become an AML analyst, you learn one workflow end to end: an automated system flags a transaction, you investigate it against the customer’s history, and you write a note that defends whatever you decide. Around that core you add a recognised AML/KYC certification, working knowledge of the customer due diligence rules your employer is graded on, and enough spreadsheet or SQL comfort to survive alert volumes. A banking degree isn’t required, and most entrants don’t have one.
Below: what the job involves day to day, which certification is worth paying for, and how to get past the CV filter that removes most first-time applicants.
Worth flagging one thing before you start. This is a written job pretending to be an analytical one. The investigation matters, but the artefact you’re judged on is a paragraph of prose that a regulator, an auditor, or a colleague three years from now has to be able to follow without asking you anything.
The work an AML analyst does
Your day starts with a queue of alerts you did not choose. A transaction monitoring system generates them overnight against configured rules and thresholds, and the queue is simply what the machine found interesting.
So what does that mean for you? Large banks run this on platforms like NICE Actimize, Oracle’s Financial Crime and Compliance Management suite (the product most people still call Mantas), or SAS. The vendor changes. The queue does not.
Triage comes first. Think of it this way: you open the alert, read what rule fired, and pull the customer’s profile and transaction history alongside it.
Most alerts are noise, and learning to prove that quickly is the actual skill. A salaried customer receiving an unusually large credit is interesting until you find the matching property sale on file. Then it’s explained, and you close it. The Financial Intelligence Unit of India sets the reporting obligations that make this triage matter: reporting entities must furnish details of all cash transactions above ten lakh rupees or the foreign-currency equivalent, and all suspicious transactions whether or not made in cash.
When the profile doesn’t explain the activity, you escalate into customer due diligence. That means going back to what the institution knows about the customer and asking whether it’s still true. The Reserve Bank’s Know Your Customer Direction, 2016, amended in October 2023, again in November 2024, and twice more during 2025, requires periodic updation on a risk-based cycle: every two years for high-risk customers, every eight for medium risk, every ten for low risk. Enhanced due diligence is the deeper version, applied where risk is higher, and it’s where you go hunting for source of funds.
Running parallel to all of it is screening. Every customer and counterparty gets checked against sanctions lists (the US Office of Foreign Assets Control lists are the ones most global institutions run against), politically exposed person databases, and adverse media, usually through a data layer like World-Check, LexisNexis, or ComplyAdvantage. Here’s the thing about screening: it produces false positives at industrial scale. A name transliterated from Arabic, Cyrillic, or Devanagari can match a sanctioned individual on spelling alone, and clearing that match properly is a real judgement call rather than a clerical one.
Then you write. And this is the part nobody warns you about: the disposition note is the deliverable, and it either survives review or it doesn’t.
Here’s what that actually looks like. A note escalating a structuring pattern might read:
Alert 44-2291, sole proprietorship in textile trading, account open 14 months. Rule triggered: eight cash deposits totalling Rs 9.6 lakh across five branches in 11 days, each individually below the ten lakh reporting threshold. Against a 12-month baseline of Rs 1.1 lakh in average monthly cash credits, with no matching rise in outward trade payments and deposit branches inconsistent with the registered business address, structuring indicators are present. Escalating to the Principal Officer for STR consideration.
Notice what that does. It names the rule, states the baseline it deviates from, and hands the next person a decision rather than an impression.
Escalation ends at the Principal Officer, the named individual every reporting entity must appoint as the nodal point for compliance. From there a clock starts. The FIU-IND guidance is specific: the Principal Officer must furnish information on suspicious transactions “promptly to the Director in respect of all suspicious transactions not later than seven working days” once satisfied that a transaction is suspicious. Filing happens online through the FINnet portal, and the report types you will hear named are the CTR for cash transactions, the STR for suspicious ones, and the CBWTR for cross-border wire transfers.
Bottom line: seven working days sounds generous until you’re the analyst whose note is holding it up.
Source: Financial Intelligence Unit India, Frequently Asked Questions, under the Prevention of Money Laundering Act, 2002 and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. Periodic updation cycles from the Reserve Bank of India, Know Your Customer Direction, 2016, as amended 6 November 2024.
Certifications and skills for AML work
Start with the cheapest credential that a hiring manager in India recognises, and that is almost always the Indian Institute of Banking and Finance route. The IIBF Certificate Examination in AML/KYC charges Rs 1,100 per attempt for members and Rs 1,600 for non-members, plus GST. The prescribed courseware is Anti-Money Laundering and Know Your Customer, 2023 edition, published by Macmillan Education India.
At that price, the calculation is not difficult. Frankly, this gets overlooked by applicants who spend months comparing international programmes they cannot yet qualify for.
The international ladder runs through ACAMS, and it’s worth understanding the order before you spend anything. CAMS, the Certified Anti-Money Laundering Specialist, is the senior credential and the one job descriptions name most often, but eligibility runs on qualifying credits drawn from education and work experience plus active membership, so it isn’t a first move for someone with no compliance history. ACAMS positions two foundational certifications below it: CKYCA for know-your-customer work and CTMA for transaction monitoring. Those are the entry-level rungs, and they’re priced in US dollars, which for most Indian entrants makes them a second-year decision rather than a first-month one.
Our recommendation for anyone starting cold: clear the IIBF certificate, get hired, then let an employer fund CAMS. Financial-crime teams routinely sponsor it, because a certified analyst improves how the function looks under supervisory review.
Now, the knowledge an interviewer will actually probe. They’ll ask you something with a rule buried in it, and they’re checking whether you know the rule or are performing confidence.
The RBI periodic-updation cycles are a favourite, because the numbers are precise and unguessable. So is the definition change from the November 2024 amendment, which added that customer due diligence must be carried out “using reliable and independent sources of identification”. And so is the seven-working-day window.
Beyond rules, three capabilities separate people who get promoted from people who process queues. The real question is which of them you can evidence today.
Written English is the first, and it’s undervalued by almost every applicant. You’re producing evidence, so ambiguity is a defect. Second is data handling: alert volumes arrive as exports, and being able to pivot a twelve-month statement, spot a pattern across branches, or write a SQL query against a case management extract turns a three-hour review into a forty-minute one. Third is screening logic, meaning you understand why a match fired and can articulate why it’s a false positive without simply asserting it.
What about the CV itself? This is where most applicants go wrong, because they describe ambition rather than knowledge.
A line that survives the filter reads more like this: Certificate Examination in AML/KYC (IIBF, 2026). Working knowledge of the PMLA reporting chain: cash transaction reporting above the ten lakh threshold, STR escalation through the Principal Officer, and the seven-working-day FIU-IND filing window under FINnet. Familiar with sanctions and PEP screening workflows, including transliteration-driven false positives on non-Latin names.
Nothing in that line is invented, and every clause is something the reader can test in an interview. But compare it to “passionate about compliance and eager to learn”, which tells a screener nothing and costs you the call. If you’re coming from an adjacent analytical background, the same framing logic applies that works for remote data analyst roles: name the specific thing you can already do.
Landing your first AML analyst role in India
Go where the desks are. Careernet’s FinCrime Talent Pulse: India’s Workforce Trends report, published on 25 July 2025, counted an active financial-crime talent pool of 25,543 professionals and found it heavily concentrated: Bengaluru holds 32 per cent, Delhi-NCR and Hyderabad 17 per cent each, Chennai 12 per cent, Mumbai 7 per cent, Pune 6 per cent, with the remaining 9 per cent spread across tier-II and smaller cities.
In practice, though, that concentration is your map. Two metros account for close to half the country’s financial-crime workforce, and a job search that ignores this geography is running at a fraction of its potential.
Four employer types hire at entry level, and they don’t hire the same way. Global capability centres running financial-crime operations for international banks are the largest doorway and the most process-driven, which works in a beginner’s favour because they train to a defined standard.
Indian banks and NBFCs hire into compliance teams that sit closer to the regulator, while consulting and managed-service firms staff client engagements. And virtual digital asset service providers, registered with FIU-IND since the March 2023 notification brought them into scope, are the newest category and often the most open to non-traditional backgrounds. A smarter strategy for a first job is to apply across all four rather than fixating on the bank logos.
Demand here isn’t sentiment. A compilation of Reserve Bank enforcement actions for FY 2024-25 recorded 353 penalties totalling Rs 54.78 crore, with KYC and AML lapses among the recurring grounds. Penalties like those get read in board meetings, and boards respond by funding headcount.
So why do so many capable applicants never get called? Because the CV filter is keyword-driven, and most non-banking graduates write around the keywords instead of into them.
If the job description says transaction monitoring, customer due diligence, sanctions screening and STR, and your CV says “worked in operations with a focus on quality”, you won’t clear an automated screen no matter how good you are. The fix isn’t dishonesty. It’s naming the specific rules and processes you’ve actually studied, exactly as in the CV line above.
Then comes the interview, and it usually contains one variant of the same question: when would you close an alert rather than escalate it? The weak answer recites a rule back. The strong answer shows a decision plus its evidence trail.
Something like: I would close it when the activity matches an explained profile and I can evidence that explanation in the file. A salaried customer receiving a single credit of Rs 12 lakh that reconciles to a documented property sale, with the sale deed on record and a consistent counterparty, is explained. I would still write down why I closed it, because the file has to defend itself later to a reviewer who was not there.
That answer works because it demonstrates the instinct the job runs on. Escalating everything isn’t caution, it’s a failure to decide, and it buries genuinely suspicious cases under volume.
One last thing about what happens after you’re hired. The practical reality is that the metric moving your career isn’t how many alerts you clear, it’s your quality-review pass rate, meaning the share of your dispositions that survive a second reviewer without rework.
Volume is measured. But quality is what gets you onto enhanced due diligence work, then quality control, then investigations or model tuning, and eventually onto the track that leads to a Principal Officer role. Analysts who chase throughput tend to plateau. Analysts who write notes nobody has to send back do not.
If compliance careers interest you more broadly, the same regulatory-demand logic drives adjacent paths, including the data privacy consultant route, SOC 2 and assurance work for Indian service providers, and remote cybersecurity roles. All of them grew for the same reason: someone wrote a rule, and the rule needed people.
Frequently asked questions
Can you become an AML analyst without a finance degree?
Yes. Financial-crime teams recruit from commerce, economics, law, arts and general graduate backgrounds, because the work is investigative and written rather than quantitative. What you do need is domain knowledge, which a certification like the IIBF AML/KYC examination supplies at low cost. A finance degree helps you read a statement faster, but it doesn’t decide the hire.
What is the difference between a KYC analyst and an AML analyst?
KYC work is front-loaded onto the customer relationship: verifying identity, collecting documents, assessing risk at onboarding, and refreshing that file on the periodic cycle the RBI prescribes. AML analysis is transaction-facing and runs continuously after onboarding, investigating alerts and deciding what gets reported. The two overlap heavily in practice, and analysts often move between them inside the same team.
Is an AML analyst job at risk from AI and automation?
Automation is reshaping the low end of the queue rather than removing the role. Systems already generate the alerts and increasingly help suppress obvious false positives, which shifts human time toward judgement calls and written justification. The reporting chain still requires a named accountable person, so the defensible-narrative part of the job is the least exposed part. Expect fewer routine reviewers and more skilled investigators.
Do AML analyst jobs allow remote or hybrid work?
Partly, and less than in most analytics careers. Alert investigation runs on systems holding customer identity and account data, so access is tightly controlled and often restricted to a managed office environment. Hybrid arrangements are common once an analyst is established and trusted with the tooling. Fully remote financial-crime work sits mainly in consulting, RegTech vendors and some fintech teams rather than in bank operations.
References
- Financial Intelligence Unit India, Frequently Asked Questions (obligations of reporting entities, CTR/STR/CBWTR, seven-working-day filing window, FINnet)
- Press Information Bureau, FATF adopts Mutual Evaluation Report of India, June 2024 Plenary
- Financial Action Task Force, India: measures to combat money laundering and terrorist financing, 2024
- Reserve Bank of India, Master Direction: Know Your Customer (KYC) Direction, 2016, as amended 17 October 2023, 6 November 2024, 12 June 2025 and 14 August 2025
- Ministry of Finance, Department of Revenue, Notification S.O. 1072(E) dated 7 March 2023, bringing virtual digital asset activities under the Prevention of Money Laundering Act, 2002
- Indian Institute of Banking and Finance, Certificate Examination in AML/KYC
- ACAMS, certification programmes (CAMS, CKYCA, CTMA)
- Careernet, FinCrime Talent Pulse: India’s Workforce Trends, H1 CY2025, published 25 July 2025
This article is for informational and educational purposes only and does not constitute professional, legal, financial or career advice. Regulatory requirements, examination fees and certification criteria change, so verify current details with the relevant authority before acting. Consult a qualified professional before making compliance or career decisions.



Allow notifications