← Back to blog
IFSCAGIFT CityAMLKYCCompliance

KYC and AML at IFSCA: onboarding investors from everywhere, under one rulebook

IFSCA-regulated entities in GIFT City routinely onboard investors from a dozen jurisdictions in a single fund close. Here's a field-tested breakdown of where the KYC/AML pressure actually sits — and how it maps to the IFSCA AML/CFT & KYC Guidelines.

SK
Shubham Khandelwal
Regulatory Strategy Lead, Omnified · July 11, 2026 · 11 min read
Stylized dusk skyline of GIFT City IFSC with warm gold lights against a deep navy sky

GIFT City has quietly become India's most interesting piece of financial infrastructure. Fund managers registered as FMEs, banking units set up as IBUs, capital-markets intermediaries operating as CMIs, and insurers running as IIOs are all sitting inside a single International Financial Services Centre — but their investors, counterparties, and beneficial owners are scattered across the US, EU, UK, Middle East, Africa, and South-East Asia. That is the entire commercial pitch of IFSC, and it is also the source of every hard KYC and AML problem that GIFT City compliance teams deal with.

IFSCA's AML/CFT & KYC Guidelines pull directly from PMLA, FATF Recommendations, and UAPA — but they land on entities whose investor books look nothing like a domestic Indian fund or a purely offshore Cayman feeder. This piece walks through the six pressure points we see most often, and maps each one to the specific rulebook obligations Omnified encodes in its IFSCA rulebook.

1. Investor identity across incompatible ID rails

A single AIF close at GIFT City can include an Indian resident LP verified via PAN and Aadhaar, a US LLC producing a W-9 and SSN-based control persons, a UAE family office presenting Emirates IDs and a UBO chart routed through a DIFC prescribed company, a UK-domiciled pension trust with FCA-regulated trustees, and a Mauritian feeder with a Category-1 GBC licence. Every one of those requires a different primary ID, a different address-proof standard, and a different acceptable liveness or in-person equivalent.

IFSCA does not let entities pick one country's standard and apply it globally. The Guidelines require a documented Customer Due Diligence (CDD) programme that captures identity, address, and beneficial ownership per PMLA, but explicitly allows equivalent foreign identity evidence for non-resident clients — provided the entity can justify equivalence in writing and the risk assessment supports it. In practice this means every new jurisdiction added to your investor book adds a fresh document matrix, a fresh authenticity check, and a fresh audit line.

Abstract diagram of investor flows from US, EU, UK, Middle East, and Africa converging into a single IFSC regulatory hub
One IFSCA licence, dozens of investor jurisdictions — each with its own KYC vocabulary.

2. Beneficial ownership at PMLA thresholds, not FATF defaults

This is the single biggest surprise for teams moving into GIFT City from a purely offshore setup. IFSCA aligns beneficial-ownership identification to India's PMLA rules: 10% for companies and 15% for partnerships and trusts — materially stricter than the 25% FATF default many offshore administrators are used to. A UBO chart that was acceptable for a Cayman feeder often needs to be re-cut for the IFSC entity.

  • Companies: identify every natural person who ultimately owns or controls ≥ 10% (PMLA Rule 9).
  • Partnerships and trusts: threshold drops to ≥ 15% of capital or profits.
  • Where no natural person meets the threshold, identify the senior managing official — and document why.
  • Layered structures (LLC → LP → trust → individual) must be walked in full; "we stopped at the fund" is not a valid answer.

The operational cost of this is real. An SPV structure that looks clean at 25% can produce three or four additional natural persons at 10%. Multiply that by every corporate LP in a fund close and the CDD file for a single subscription can easily run to 40+ verified individuals.

3. Risk-based CDD, per investor — not per fund

IFSCA requires a documented, defensible risk rating for every customer, and the rating drives whether Simplified, Standard, or Enhanced Due Diligence applies. The risk model must consider customer type, geography, product, delivery channel, and PEP status — and it must be re-scored on trigger events, not just at onboarding.

For a multi-jurisdictional investor book that looks like this: an Indian HNI LP through a domestic RM is usually Standard, a US LLC with clean W-9s is Standard, a UAE family office with a foreign PEP as UBO is Enhanced, an African corporate LP from a FATF grey-listed jurisdiction is Enhanced with mandatory source-of-wealth evidence, and a Mauritian feeder without look-through is often Enhanced by default. There is no shortcut here — the rating must be per investor, evidenced, and versioned.

4. Sanctions and PEP screening against the right lists

IFSCA-regulated entities cannot rely on a single sanctions list. Compliance requires screening against the UN Security Council Consolidated List and the UAPA lists published by MHA, at a minimum — but any investor exposure to US persons, EU persons, or UK counterparties effectively drags OFAC (SDN and sectoral), EU consolidated, and HMT/OFSI into scope commercially. Screening must run at onboarding, on every material change, and on a periodic cadence that the risk model justifies.

"The mistake we see most is treating sanctions as a one-time check at KYC. IFSCA reads it as a continuous obligation — and the audit will ask for the exact timestamp of the last screening against every relevant list."

Rohan Mehta, Regulatory Strategy Lead
  • UN Consolidated List — mandatory, updated on issue.
  • UAPA Section 35 & 51A lists (MHA) — mandatory for all Indian-nexus entities including IFSCs.
  • OFAC SDN + sectoral — commercially unavoidable for USD flows and US-person investors.
  • EU Consolidated + HMT/OFSI — required where investor or counterparty nexus exists.
  • Local adverse-media and PEP databases — best practice for Enhanced Due Diligence.

5. V-CIP and non-face-to-face onboarding done properly

IFSCA permits Video-based Customer Identification Process (V-CIP) and non-face-to-face onboarding — critical for a Centre whose entire investor base is remote — but with hard operational requirements. The V-CIP session must be initiated by an authorised official of the regulated entity, must be geo-tagged inside India (or a permitted equivalent), must capture live proof-of-life and independent document verification, and must be retained as an auditable recording. Reusing a vendor's off-the-shelf V-CIP without confirming these controls fails audit.

For investors who cannot practically do V-CIP — many institutional LPs will not put a signatory on a live video call — the alternative is a documented equivalent: notarised copies, apostilled where required, plus independent verification via a reliable and independent source. IFSCA does not accept "the investor is big and reputable" as evidence.

6. Record-keeping, reporting, and the five-year rule

The Guidelines require CDD records and transaction records to be retained for at least five years from the end of the business relationship or the transaction date, whichever is later. STRs must be filed with FIU-IND, CTRs and CBWTRs where applicable, and the internal audit trail must be sufficient to reconstruct the KYC decision on any given day for any given investor. In a multi-jurisdiction investor book, this is where lightweight KYC tooling breaks — because a five-year lookback across a dozen vendor formats is effectively unusable without a normalised event log.

How Omnified's IFSCA rulebook encodes this

Our IFSCA rulebook (`ifsca-gift-v1.0.0`) is a machine-evaluable version of the obligations above. Each requirement carries its regulatory citation, its applicability matrix (IBU, FME, CMI, IIO, sandbox), its evidence rules, and its decision thresholds. It produces the same normalised verification verdict Omnified emits for every jurisdiction — so a US LLC and an Indian HNI in the same fund close land in a single audit-ready case file.

Reference

IFSCA (GIFT City) rulebook — full requirement map

Entity matrix (IBU · FME · CMI · IIO · sandbox), PMLA-aligned BO thresholds, V-CIP evidence rules, sanctions lists, scenarios, and the full decision tree — versioned and citation-linked.

Open the IFSCA rulebook

What good looks like, operationally

  • A single case file per investor that carries the CDD verdict, the BO chart at PMLA thresholds, every screening timestamp, and the reasoning behind the risk rating.
  • Waterfall routing that picks the right identity rail per jurisdiction — Aadhaar/PAN for India, Emirates ID for UAE, document + liveness for the rest — without changing the schema the compliance team reads.
  • Sanctions screening that runs on a scheduled cadence per risk tier and stores every hit with disposition, not just the last one.
  • V-CIP sessions retained as evidence and cryptographically linked to the underlying case, so the five-year audit is a query rather than an expedition.
  • A four-eyes escalation path for every Enhanced Due Diligence outcome, with clear owner, timestamp, and rationale.

IFSCA has been deliberate about pulling GIFT City up to FATF-grade standards while keeping the door open to global investors. The regulatory bar is high, the investor mix is wide, and the operational cost is real — but the whole thing is tractable if the tooling treats "multi-jurisdiction" as the default case rather than an edge case. That is the design brief Omnified was built to answer.

See the orchestration engine in action.

Interactive demo — no signup, no real data.

Keep reading