Regulation & Compliance

KYC and AML Obligations That Sit on the Individual Advisor

A POSP collects KYC and forwards it; the engaging insurer or intermediary is the regulated entity that carries the obligation. What that division actually means for the documents in your phone, the records you keep, and the DPDP clauses arriving in your contract.

Tarun Kumar Singh
Tarun Kumar SinghStrategic Risk & Compliance SpecialistAIII · CRICP · CIAFP
10 min read

Listen to this article

Audio version • 10 min read

pospkycamldpdpclient-onboardingirdairegulation-compliance

Last reviewed: July 2026

Collect, Maintain, Forward

The point of sales person's KYC duty is short enough to state in one breath. You are required to collect and maintain KYC documentation and product sales records, and to submit KYC documents and declarations truthfully and promptly to the entity that engaged you.

Three verbs, each doing work.

Collect means the documents come from the client, through you, in a form that will stand up. Not a blurred photo taken across a table. Not a name spelled the way the client says it while the document spells it another way.

Maintain means you hold sales records and the documentation behind them. This is the verb advisors skip. The proposal goes in, the policy issues, the commission lands, and the file dissolves into a chat thread that gets cleared when the phone runs out of storage.

Forward carries two adverbs that are the actual compliance surface: truthfully and promptly. Truthfully rules out the small helpful edits that feel like service at the time, such as an address adjusted to match a document. Promptly rules out the file that sits with you for three weeks because you were chasing the next sale.

What the sentence does not say is that you are the entity the regulator is looking at. That distinction is the whole subject of this post, and getting it wrong in either direction is expensive.

The Documents, and Where the Rules Live

The POSP channel is not governed by IRDAI's 2024 consolidation. The nine consolidated, gazette-notified 2024 regulations contain no intermediary or point of sales instrument. What governs you is older and narrower: Circular No. IRDA/Int/GDL/ORD/183/10/2015 for non-life and health, the two guidelines dated 7 November 2016 for life, and the Master Circular on Point of Sales Products and Persons for Life Insurance, IRDAI/LIFE/CIR/MISC/215/12/2019, which consolidated the 2016 guidelines and the circulars that followed them.

The master circular names identity proofs directly. PAN Card and Aadhaar Card are among the identity documents it lists. The same instrument sets the entry conditions for the channel, which are worth restating because they are the first KYC event in your career and the one performed on you: 18 years of age completed, and 10th standard pass.

Beyond identity, what you are gathering is the material the underwriter and the compliance function need to believe the policy is what it appears to be: who the proposer is, that they exist, that the person signing is the person named, that the money is theirs, and that the cover has a plausible relationship to their life. A pure term proposal on a life with no evident income, paid by someone else, is not a KYC failure of documentation. It is a KYC failure of sense.

Who the Regulated Entity Actually Is

This is the structural point, and it is the one that changes how an advisor should think about the whole subject.

You are not an independent regulated firm. A POSP is tied to one insurer or intermediary at any given time, and the entity that engages you is the one that holds the licence, files the returns, answers the inspection, and carries the obligation. You collect and forward. Your principal is the regulated party.

The evidence for where liability sits is clearest on conduct, and it points the same way. The Master Circular for life is explicit that the life insurer is responsible for the conduct of the POSP representing it, and that misconduct by the POSP makes the insurer liable to penalty under Section 102 of the Insurance Act, 1938. Where an intermediary engages you, the intermediary is responsible for your conduct and is the one exposed to that penalty.

So a POSP's KYC failure shows up in two places, and neither is the one advisors expect:

  1. As your principal's regulatory exposure. Their obligation, their finding, their penalty. Not because they did the collecting, but because the framework makes them answerable for the person who did.
  2. As your contractual exposure. Termination, withheld remuneration, recovery of commission on a policy that should not have been written, and a conduct record that travels with you when you seek another tie.

Read carelessly, that looks like good news for the advisor. It is not. Because your principal wears a risk created by your hands, your principal will control it through the only instrument it has, which is your contract. The advisor who thinks "the compliance obligation is theirs, not mine" has correctly identified where the obligation sits and misread what follows from it. What follows is that the obligation reaches you as a contractual demand rather than a regulatory one, and a demand from the entity that owns your tie is not the softer of the two. The tie is the asset.

What Is Not Settled, and Why That Matters

Compliance content for this channel is full of confident numbers. Some of them are borrowed from the wrong shelf. Two points deserve honesty rather than a figure.

How long you must keep KYC records specifically is not something to state from the POSP instruments. There is a five-year retention requirement in the master circular, and it is real, but it attaches to training and examination records, not to KYC. Transplanting that number onto client KYC files is a plausible-sounding error, and it is one that content aimed at advisors makes routinely. The right answer to "how long do I keep this" comes from your engagement contract and your principal's record-retention instruction, which will reflect the retention rules that bind them as the regulated entity. Ask them. Do not infer a number from a rule about your exam papers.

How PMLA and anti-money-laundering liability divides between a POSP and the engaging entity is not something this post will assert. The precise allocation across that chain is not settled by any POSP-specific text that can be pointed to cleanly. What can be said without stretching is the shape: the engaging insurer or intermediary is the regulated entity with the AML obligation, the reporting relationship and the compliance function, and you are the pair of hands at the point of contact. That makes you the place where the information enters the system and, correspondingly, the place where a laundering attempt is first visible and most easily concealed.

Which is the practical point regardless of how the liability question resolves. Your value in the AML chain is not that you file anything. It is that you saw the client. Nobody at the principal's compliance desk did.

The DPDP Overlay

Every KYC document you touch is digital personal data, so the second framework arrived whether or not anyone told you.

MeitY notifications of 14 November 2025 brought both the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 into force on staggered timelines:

  1. 14 November 2025: foundational provisions commenced, and the Data Protection Board of India was formally established.
  2. 14 November 2026: enforcement powers, the penalty framework, and Consent Manager registration commence.
  3. 14 May 2027: the substantive provisions come into force, ending the 18-month transition.

The headline number attached to DPDP is a maximum penalty of up to INR 250 crore for major violations. Advisors should be told plainly that this figure is not pointed at them, and content implying otherwise is scaring the wrong person.

Here is the accurate posture, and it is derivative rather than free-standing. DPDP places obligations on the data fiduciary. For a POSP, the data fiduciary is realistically the insurer or the intermediary that engages you; you handle client personal data on behalf of that entity. Your position under DPDP mirrors your position under everything else in this post: the regulated party is upstream, and you are the hands.

So, and this matters because the opposite is asserted constantly in material sold to advisors: an individual POSP should not be told that they are a data fiduciary, that they must appoint a Data Protection Officer, or that they must register as a Consent Manager. A Consent Manager is a distinct registered entity under the framework and an advisor is not one. No IRDAI guidance addressing POSPs specifically under DPDP could be pointed to as of this writing, and the allocation of DPDP roles down the insurer to intermediary to POSP chain has not been squarely settled by any source worth citing.

What to actually expect is contractual, and it is already arriving. Ahead of November 2026 and May 2027, your principal will push its own obligations down to you through the engagement: consent capture in a prescribed form, purpose limitation on what you do with a client's details, retention and deletion instructions, restrictions on where documents may sit, and a breach-notification duty running upward to them on a clock. Those clauses are the shape DPDP takes in your life. Read them when they arrive, because they are enforceable against you in a way the Act is not.

Where It Actually Goes Wrong

The failures in this channel are rarely dramatic. They are ordinary, and they compound.

The document lives only in WhatsApp. A PAN photographed and sent in a chat, forwarded to the principal, never filed anywhere else. Chat is not a record system. It gets cleared, phones get replaced, and media auto-deletes on a setting nobody remembers changing. Then a query arrives 14 months later about a policy you barely remember and you have nothing.

Helpful correction. The client's address on the proposal does not match the document, so you adjust the proposal to match. It feels like removing friction. It is a declaration submitted untruthfully, and truthfulness is the one duty here stated in exactly those words.

The family shortcut. A husband hands you documents for his wife's policy and answers on her behalf. The proposal goes in with declarations she never made. This is the most common KYC problem in the retail book and almost nobody thinks of it as one.

The stale file. Documents collected at the first sale in 2022, reused for the third policy in 2026, with no thought about whether anything changed.

The unbanked premium. Cash handed to you, deposited by you, policy in someone else's name. Whatever else this is, it is the exact pattern the AML framework exists to catch, and you are the only person in the chain who can see it happening.

Storage nobody chose. Client documents in your personal cloud backup, syncing to a family tablet, because your phone gallery backs up by default. Nobody decided this, and it is precisely what the storage clauses coming down your contract are aimed at.

A Working Posture

None of this requires an advisor to build a compliance department. It requires a small number of habits held consistently.

  1. Ask your principal three questions in writing. How long do I retain KYC and sales records? Where may client documents be stored, and where may they not? How do I report a suspected problem, and to whom? These are their obligations shaping your conduct, and the answers should come from them rather than from a blog. This one included.
  2. Keep a record system that is not a chat thread. One place per client, holding the proposal, the documents forwarded, the policy, and the dates. It does not need to be sophisticated. It needs to survive a phone upgrade and answer a question 18 months later.
  3. Forward promptly, and forward what you received. Same day where possible. Unedited. If something does not match, raise the mismatch rather than resolving it yourself. Resolving it yourself is the failure.
  4. Meet the proposer. Especially where someone else is arranging, paying, or answering. The person whose life is being insured should be a person you have actually spoken to.
  5. Escalate the thing that feels wrong. Cash you did not expect, a payer with no relationship to the insured, a sum insured that does not fit the life. You are not required to conclude anything. You are required not to look away, and telling your principal costs you nothing.
  6. Do not build your own document library. Every retained copy is a liability you hold on someone else's behalf. Once it is forwarded and your retention instruction is met, extra copies scattered across devices are pure downside.

The underlying idea is unfashionable but sound. You are not the regulated entity, and pretending otherwise helps nobody. What you are is the only person in the chain who met the client, saw the documents in the client's hands, and noticed the thing that did not fit. Nothing upstream can replace that, which is why every obligation above eventually arrives at your door with someone else's name on the envelope.

About the Author

Tarun Kumar Singh

Tarun Kumar Singh

Strategic Risk & Compliance Specialist

  • AIII
  • CRICP
  • CIAFP
  • Board Advisor, Finexure Consulting
  • Developer of the Behavioural Underinsurance Risk Index (BURI)

Tarun Kumar Singh is a seasoned risk management and insurance professional based in Bengaluru. He serves as Board Advisor at Finexure Consulting, where he advises insurance, fintech, and regulated firms on governance, growth, and trust. His work spans insurance broker regulatory frameworks across India, UAE, and ASEAN, IRDAI compliance and Corporate Agency model reform, VC governance in insurtech, and MSME insurance gap analysis. He is the developer of the Behavioural Underinsurance Risk Index (BURI), a framework applying behavioural economics to underinsurance and insurance fraud risk.

Frequently Asked Questions

How long must a POSP keep client KYC records?
This post will not give you a number, because the POSP instruments do not settle it cleanly and the figure most often quoted is borrowed from the wrong rule. The five-year retention requirement in the master circular attaches to training and examination records, not to KYC files. The operative answer comes from your engagement contract and your principal's written record-retention instruction, which reflects the retention rules binding them as the regulated entity. Ask them, and get it in writing.
Am I personally liable under the PMLA if a client turns out to be laundering money?
The precise allocation of anti-money-laundering liability between a POSP and the engaging entity is not settled by any POSP-specific text that can be cited cleanly, so treat confident answers in either direction with suspicion. What is clear is the shape: the engaging insurer or intermediary is the regulated entity with the AML obligation, the reporting relationship and the compliance function. Your practical role is that you are the only person in the chain who met the client, which makes you where a problem is first visible and most easily concealed.
Am I a data fiduciary under the DPDP Act?
You should not be told that you are. DPDP places obligations on the data fiduciary, and for a POSP that is realistically the insurer or intermediary that engages you; you handle client personal data on behalf of that entity, so your position is derivative. An individual advisor does not appoint a Data Protection Officer or register as a Consent Manager, which is a distinct registered entity under the framework. The INR 250 crore maximum penalty is not pointed at you personally.
What does DPDP actually change for me day to day?
It reaches you through your contract rather than through the Act. Ahead of the enforcement and penalty phase on 14 November 2026 and the substantive provisions on 14 May 2027, your principal will push its own obligations down through the engagement: consent captured in a prescribed form, purpose limitation on what you do with client details, instructions on where documents may be stored and for how long, and a duty to notify them of a breach on a clock. Those clauses are enforceable against you in a way the Act is not.
The client's address does not match his document. Can I just correct the proposal?
No, and this is the failure that feels most like service at the time. Your duty is to submit KYC documents and declarations truthfully and promptly, and adjusting a proposal so that it matches a document is a declaration submitted untruthfully, whatever the intention. Raise the mismatch with your principal instead and let it be resolved upstream. The same applies to smoothing an occupation to fit a category or answering on behalf of a proposer you have not actually spoken to.

Related Glossary Terms

Related Insurance Types

Related Articles

Pratibimb by Sarvada

Bring your book to Pratibimb.

Every client, policy, renewal, and rupee of commission in one place, with Pratibimb on WhatsApp handling the follow-through.

Open Pratibimb