A payment aggregator can be fully RBI-authorised and still be out of compliance with FIU-IND.
These are two different registrations, two different regulators, and two different failure modes. Most PSPs treat FIU-IND as a formality that happens once, after the harder RBI authorisation is settled.
That assumption is where the exposure starts.
RBI's Master Direction governs whether a payment aggregator can operate at all. FIU-IND registration governs whether that aggregator is meeting its obligations under the Prevention of Money Laundering Act once it is operating.
An entity can clear the first and still be non-compliant on the second. Reporting entities under PMLA - including payment aggregators and other payment system operators - are required to register with FIU-IND and file Suspicious Transaction Reports on an ongoing basis. This obligation applies to PAs operating under RBI’s Master Direction regardless of transaction volume. Skipping this, or treating it as a one-time filing, is a separate violation from any RBI compliance gap.
The confusion is understandable. Both frameworks use similar language: due diligence, monitoring, reporting. They are not asking the same question. RBI asks whether the aggregator is fit to operate. FIU-IND asks whether the aggregator can detect and report money laundering moving through it.
Registration is the entry point, not the obligation itself. Once registered, a PA takes on ongoing duties that do not end at signup:
Each of these is a standing obligation, not a checkbox cleared at registration. A Principal Officer appointed on paper but not actually monitoring alerts satisfies the letter of the requirement and fails the actual purpose of it.
STR filing sounds procedural. In practice, it depends entirely on whether suspicious activity was ever identified as suspicious in the first place.
A transaction monitoring system can flag an anomaly without anyone recognising it as something that meets the STR threshold. That gap sits between fraud detection and AML judgment - and it is exactly where PSPs with siloed fraud and AML functions lose the thread.
Consider a sub-merchant whose payout pattern trips a fraud rule for unusual velocity. The fraud team clears it as an operational false positive. Nobody asks whether the same pattern, viewed through an AML lens, describes classic layering behaviour. The STR that should have been filed never gets considered, because the alert was resolved by the wrong team asking the wrong question.
This is not a filing failure. It is a judgment failure upstream of filing - and it happens more often in PSPs where fraud and AML operate as separate functions with separate escalation paths.
An FIU-IND review does not primarily ask how many STRs were filed. It asks whether the entity can demonstrate a consistent process for identifying suspicious activity and escalating it correctly.
An aggregator with a low STR count and no documented reasoning for why more activity was not escalated looks worse under review than one with a higher count and a clear rationale for every decision. Volume was never the metric. Defensibility was.
This is where the gap between RBI authorisation and FIU-IND compliance becomes expensive. An entity can be fully licensed, fully operational, and still fail an FIU-IND review because its STR process cannot show its reasoning - only its outcomes.
FIU-IND compliance depends on the quality of judgment upstream of filing - the ability to identify suspicious activity accurately, route it to the right team, and document the reasoning behind every decision. That chain is where PSPs with siloed fraud and AML functions lose the thread. Verafye's transaction monitoring and investigation intelligence connects the signals that should be informing that judgment: merchant transaction patterns, network-level relationships, entity connections to prior cases, behavioural anomalies.
When a sub-merchant's payout pattern triggers a monitoring flag, Verafye surfaces the full relationship context - whether that merchant shares infrastructure with entities already flagged, whether the beneficiary account has appeared in prior suspicious activity, whether the pattern fits known layering typologies. That context is what bridges the gap between a fraud team clearing an alert as a false positive and an AML team recognising the same pattern as possible layering. For payment aggregators managing large and growing merchant books, that bridge is not a nice-to-have. It is the operational difference between a programme that actually identifies suspicious activity and one that processes alerts too slowly to file STRs within required timelines.
Verafye does not replace AML judgment. It ensures that judgment is being applied to the right information, at the right moment. The audit trail Verafye generates at every step - flag, investigation, decision, rationale - is the documentation an FIU-IND review is looking for when it asks whether the STR process can show its reasoning, not just its outcomes.
To see where your current monitoring has gaps between fraud detection and AML escalation, the Verafye Risk Shadowing Review scopes your signal coverage with no commitment required.
FIU-IND registration is not the finish line. It is the point where the actual obligation begins - and the obligation is judgment, not paperwork.
If your STR process cannot explain why a transaction was or was not escalated, the registration was never the hard part. The reasoning behind every decision was.
The aggregators that treat FIU-IND compliance as a monitoring and judgment problem - not a registration and filing problem - are the ones whose processes hold up under review. The others discover the gap the first time an examiner asks them to show their work.
Abhishek Tuppada
Founder & CEO, Verafye
Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.
See where your monitoring stack has blind spots
The Risk Shadowing Review maps your current coverage against relationship-level gaps.