Study Guide

NISM-IFSCA-01 Study Guide: AML/CFT in the IFSC

Apply AML/CFT concepts to IFSC scenarios for NISM-IFSCA-01: diligence tiers, risk-based decisions, suspicious transaction reporting, and IFSCA's unified role.

Updated September 202610 min readStudy GuideNISM Prep
Rachel Reynolds

Rachel Reynolds

NISM Prep Editorial Team

Study this exam by rehearsing decisions, not definitions. For every concept — laundering stages, CDD, risk rating, STR — practise attaching it to an IFSC-style scenario: a non-resident corporate customer, a cross-border funds flow, an ownership structure with layers. If you can name the concept but cannot decide which tier of diligence or which reporting step a situation calls for, keep drilling scenarios before the exam.

Why the IFSC setting changes how AML/CFT concepts apply

The GIFT IFSC is a cross-border financial hub supervised by IFSCA, a unified authority. AML/CFT ideas learned from a purely domestic banking angle must be re-anchored to non-resident counterparties, foreign-currency activity, and internationally aligned standards.

Before IFSCA was established in 2020 under the International Financial Services Centres Authority Act, 2019, business in the IFSC sat under multiple domestic regulators, including RBI, SEBI, PFRDA, and IRDAI. IFSCA now serves as the unified regulator for financial products, services, and institutions in the IFSC. This history matters when you reason about supervision: the question of who regulates a fund management entity or banking unit in the IFSC has a single correct authority, and mixing in the legacy sector regulators is the natural confusion to guard against.

Build the habit of reading every concept through the IFSC lens. A wire transfer is not a routine domestic payment; it is typically a cross-border flow. A customer is often a non-resident person or entity. Standards are designed to align with international expectations for global financial centres, so FATF-style concepts — risk-based approach, beneficial ownership, cooperation between authorities — carry direct weight here. When you review any topic, write one sentence explaining how it looks different in a cross-border, single-regulator centre, and test yourself against that framing.

Separating the three stages of laundering from terrorist financing behaviour

Money laundering moves criminal proceeds through placement, layering, and integration so illicit origin is concealed. Terrorist financing concerns the destination and purpose of funds, which may be entirely lawful in origin — so clean money can still finance terrorism.

Trace the laundering cycle with a concrete chain. Placement puts illegal cash into the financial system, for example through deposits or purchase of negotiable instruments. Layering obscures the trail through transfers between accounts, jurisdictions, or products. Integration returns the funds to the apparent criminal as legitimate-looking wealth, such as an investment or business receipt. Each stage suggests different red flags: large cash at placement, rapid structured movement at layering, investment activity with no credible commercial logic at integration. Knowing which stage a fact pattern describes tells you which red flags to look for.

Terrorist financing behaves differently in a critical way, and the difference is easy to miss because a clean source and modest size look innocuous. Its funds may come from lawful sources — salaries, donations, business profits — because the offence concerns using funds for terrorist purposes, not the tainted origin of the money. A transaction with a lawful origin can therefore still raise terrorism-financing concern if the intended use points that way. This means your analysis must run on two tracks: follow the origin of funds for laundering, and follow the purpose and destination for terrorist financing. Train yourself to state both conclusions explicitly for any scenario.

KYC versus CDD versus EDD: picking the diligence level a situation calls for

KYC is identifying who the customer is. CDD goes further: verifying identity, understanding the relationship's purpose, identifying beneficial ownership, and monitoring ongoing activity. EDD is the strengthened set of measures applied when risk is elevated.

The practical confusion is treating identification as the whole job. Collecting and verifying identity documents satisfies the KYC slice, but CDD additionally requires understanding the intended nature of the relationship and the source of funds, looking through corporate structures to the natural persons who ultimately own or control the customer — the beneficial owners — and keeping the picture current through ongoing monitoring. A fact pattern in which documents were collected but no beneficial owner was established is incomplete CDD, not completed onboarding.

EDD is triggered by elevated risk rather than by a fixed customer category: factors such as a customer linked to a higher-risk jurisdiction, an unusually complex or opaque ownership chain, a politically exposed connection, or activity inconsistent with the customer profile. Use the table below as a matching drill: given a scenario, first locate the trigger, then select the tier. When you evaluate any scenario after the fact, the correct diligence tier is the one whose components match the trigger — not necessarily the tier that happened to be performed.

LevelCore componentsTypical triggerScenario cue in a question
KYCIdentify and verify the customer's identityEstablishing any new relationshipThe facts mention ID documents only
Standard CDDKYC plus purpose and nature of relationship, beneficial ownership, ongoing monitoringNormal-risk customer with an understandable profileOwnership is simple and activity matches the stated business
EDDDeeper verification of source of funds and ownership, senior-level involvement, tighter ongoing monitoringHigher-risk jurisdiction links, opaque structures, PEP connections, unusual activityLayered holding companies or funds flows with no clear commercial rationale

Worked scenario: applying the risk-based approach to a layered corporate customer

The risk-based approach allocates stronger controls where risk is higher instead of treating all customers identically. Completeness of paperwork is not a risk assessment; the scenario below shows why the two must be judged separately.

Scenario: an IFSC entity onboards a trading company whose shares sit in a holding company in a jurisdiction with known secrecy practices; the declared business is commodity trading with several planned cross-border transfers soon after account opening. All requested documents were provided. A plausible mistake is concluding that the file is complete, so standard CDD suffices. That reasoning confuses documentary completeness with risk: a sealed, tidy file can still conceal the persons ultimately controlling the account.

The better decision is to escalate to enhanced due diligence: trace the chain to the natural-person beneficial owners, corroborate the source of funds behind the planned transfers, obtain appropriate internal approval for the higher-risk relationship, and apply intensified ongoing monitoring with a defined review point. Why it matters: the risk-based approach is the organising principle of modern AML supervision, so your analysis must allocate effort according to risk signals — jurisdiction, structure, purpose, expected activity — rather than according to whether the checklist was ticked. Rehearse stating the risk drivers before naming the response.

Worked scenario: deciding to report suspicion without tipping off the customer

Suspicion is judged against the customer's profile and the transaction's logic, not only its size. Once a report decision is in motion, disclosing that scrutiny to the customer — tipping off — is prohibited, and the report path runs through internal escalation.

Scenario: a customer whose profile describes modest consultancy income begins receiving multiple inward transfers from unrelated overseas senders, each quickly moved onward to a third party, with the amounts structured to stay individually unremarkable. A plausible two-part mistake occurs when a staff member both calls the customer to ask casually about the transfers and decides internally that no report is needed because each transfer is small. Both steps are wrong on different grounds.

The better course: the pattern — unexplained senders, rapid pass-through, structuring — is evaluated against the customer profile and points to suspicion; the matter goes through internal escalation for a suspicious transaction report, and the employee must not reveal the scrutiny to the customer, because tipping off can defeat the purpose of reporting regardless of the report's eventual outcome. Assessing whether facts amount to suspicion and knowing the conduct obligations that attach once suspicion exists are two separable skills; practise each explicitly. Rehearse the sequence in order: observe, compare with profile, escalate, report, stay silent.

Mapping the framework: PMLA, FATF, and IFSCA roles without mixing them up

Keep three layers distinct: FATF sets international AML/CFT standards and assesses countries; India's Prevention of Money Laundering Act, 2002 supplies the domestic legal offences and reporting machinery; IFSCA regulates and develops financial activity within the IFSC.

A workable mental map has a standards layer, a law layer, and a supervisor layer. FATF operates at the standards layer: its recommendations shape what jurisdictions are expected to do, and its mutual-evaluation process reviews how well they comply — which is why internationally oriented centres such as the IFSC design regimes aligned with those expectations. The Prevention of Money Laundering Act, 2002 operates at the law layer: it defines laundering offences, attaches to proceeds of crime, and underpins obligations such as record keeping and reporting to the designated financial intelligence authority.

IFSCA sits at the supervisor layer for the IFSC: it is the unified authority for regulating and developing financial products, services, and institutions in the centre, headquartered at GIFT City. The layers interact in practice — supervising an IFSC intermediary is IFSCA's job, while the reporting obligation traces back to the legal layer. The natural confusion is answering with a layer-adjacent name, such as citing a legacy sector regulator for an IFSC supervisory question. When you revise each framework element, attach to it one function, one layer, and one example of a question it would answer.

A preparation sequence and self-check drill you can run before exam day

Sequence your revision in three passes: concepts and distinctions first, the IFSC framework second, scenario drills last. Finish by scoring yourself on a short written drill; treat the score as a learning milestone, not a predicted result.

A realistic sequence for a working candidate: in pass one, build one-page notes for the core distinctions — laundering stages versus terrorist financing, KYC versus CDD versus EDD, rule-based versus risk-based thinking. In pass two, map the institutional framework: IFSCA's unified role, the PMLA's offence and reporting machinery, FATF's standards function, and how they connect. In pass three, drill scenarios daily: write a five-line customer fact pattern, then answer three questions in writing — risk level, diligence tier, and whether a report is warranted and why.

Run this self-check drill in the final week. Construct two profiles: a low-risk, plainly documented non-resident individual, and a layered corporate with a higher-risk jurisdiction link. Score each of your written answers against this rubric: named the correct diligence tier with its components (0–2); identified at least two specific risk drivers rather than generic unease (0–2); correctly stated the reporting conclusion and the no-tipping-off obligation where relevant (0–2); cited the correct authority or legal layer for the follow-up step (0–2). A total of six or more across both profiles signals concept-level readiness; lower totals tell you which pass to repeat. Readiness checks before booking: you can state each distinction unprompted, complete the drill within ten minutes per profile, and explain every row of the diligence table without looking.

  • Pass one: one-page notes on the core concept distinctions, written from memory and then corrected.
  • Pass two: an institutional map naming each authority's layer, function, and one example question it answers.
  • Pass three: daily written scenario drills using the three-question format — risk, tier, report.
  • Final week: run the two-profile drill, score against the rubric, and repeat the weakest pass.

References and further reading

Use these references to explore the concepts and check the latest information from the relevant organizations.

Continue your preparation

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for NISM-IFSCA-01: Anti Money Laundering and Counter Terrorism Financing in IFSC Certification Examination.

Can funds from a completely lawful source still count as terrorist financing?
Yes. Terrorist financing is defined by the intended use and destination of funds, not by their criminal origin. Donations, salaries, or business profits can become terrorist financing once directed toward terrorist purposes, which is why transaction monitoring must follow purpose as well as source.
Is collecting and verifying a customer's identity documents enough to complete CDD?
No. Identification and verification are the KYC component. Full customer due diligence additionally covers understanding the purpose and nature of the relationship, identifying beneficial owners behind legal persons, and ongoing monitoring of activity against the customer profile.
What does tipping off mean and why is it treated so seriously?
Tipping off is disclosing to a customer, directly or indirectly, that a suspicion report or related investigation is contemplated or has been made. It is prohibited because such disclosure can allow the subject to move or conceal funds before authorities act, defeating the report's purpose.
Do I need to memorise section numbers of the Prevention of Money Laundering Act, 2002?
Concept-level command matters more than citation: know the offence's attachment to proceeds of crime, the reporting and record-keeping machinery, and the roles of the designated authorities. Confirm the current syllabus depth yourself on the NISM certification portal, which lists the exam's official scope and administrative details.
How should I use practice questions in the final stretch?
Use them diagnostically rather than as bulk exposure. After each question, write why the correct option matches the scenario's risk drivers and why a plausible alternative fails — for example, confusing documentary completeness with low risk. Pair this with the two-profile written drill to test decision-making rather than recognition.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.