FIU-IND registration requirements for offshore crypto exchanges in India
Blogs

Does an Offshore Crypto Exchange Need FIU-IND Registration?

India’s Financial Intelligence Unit (FIU-IND) issued compliance notices to 15 offshore crypto platforms on 9 September 2026. In addition, the Director of FIU-IND issued notices seeking the takedown of their applications and URLs from public access in India. This follows a pattern of escalating enforcement. It includes earlier action against offshore platforms and the initial compliance notices issued in December 2023. The latest enforcement action makes one point clear. Being incorporated outside India does not, by itself, place a VDA service provider outside FIU-IND’s regulatory framework. As a result, where an offshore provider carries out covered VDA activities in India, FIU-IND registration and applicable PMLA obligations may apply.

However, many offshore VASPs still believe that operating without an Indian office keeps them beyond the regulator’s reach. That belief is wrong. For VDA service providers, the FIU-IND framework under the PMLA is activity-based. It applies irrespective of physical presence in India. This article explains which offshore crypto exchanges need FIU-IND registration. It also covers what triggers the obligation and what happens to platforms that ignore it.

Area Key requirement Why it matters
Registration Register with FIU-IND as a reporting entity before carrying out covered VDA activities in India Operating without registration can trigger penalties and URL blocking
Jurisdictional trigger Activity-based: covered VDA activities can bring an offshore VDA SP within India’s PMLA framework regardless of incorporation Physical presence in India is not the test
KYC/CDD Risk-based customer due diligence, transaction monitoring and sanctions screening under the applicable PMLA and FIU-IND guidance Obligations apply to all registered reporting entities
Reporting File STRs and other reports required under the PMLA/PML Rules and FIU-IND framework within applicable timelines Failure to comply with reporting obligations can result in regulatory action and penalties
Enforcement Monetary penalties, URL/app takedown notices and other regulatory directions FIU-IND has imposed substantial penalties on VDA SPs to date

Why FIU-IND registration requirements apply to certain offshore VASPs

India brought specified virtual digital asset (VDA) activities within its AML framework through a Ministry of Finance notification (S.O. 1072(E)) dated 7 March 2023. Specifically, the notification identified five categories of VDA-related activity. These apply when carried out for or on behalf of another person in the course of business, for purposes of Section 2(1)(sa)(vi) of the PMLA. As a result, entities carrying out those activities within the reporting-entity framework must meet the applicable PMLA and AML/CFT obligations.

Importantly, this classification applies to any entity that performs specified VDA activities for or on behalf of another person. It does not distinguish between Indian-incorporated companies and foreign ones. Therefore, an offshore exchange carrying out covered VDA activities within India’s PMLA framework may face the applicable PMLA, PML Rules and AML/CFT obligations.

Furthermore, FIU-IND reinforced this position through its updated AML/CFT Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets on 8 January 2026. These updated guidelines set out detailed AML/CFT obligations for VDA service providers. Since then, the regulator’s enforcement actions confirm that it applies FIU-IND registration obligations to offshore platforms carrying out covered VDA activities.

Is FIU-IND registration based on physical presence in India?

No. India’s AML framework for virtual digital assets is activity-based. The PMLA’s reporting entity definition focuses on the activities an entity performs. It does not depend on where the entity is incorporated or where its servers sit.

Consequently, an offshore crypto exchange does not avoid India’s PMLA framework merely because it is incorporated outside India. If it carries out covered VDA activities within the Indian reporting-entity framework, FIU-IND registration obligations may apply. The test is functional. Does the platform carry out any of the five specified VDA activities within India’s PMLA framework?

Which crypto activities trigger PMLA obligations?

The March 2023 notification specifies five categories of VDA-related activity. These fall within Section 2(1)(sa)(vi) of the PMLA when carried out for or on behalf of another person in the course of business:

  • Exchange between virtual digital assets and fiat currencies
  • Exchange between one or more forms of virtual digital assets
  • Transfer of virtual digital assets
  • Safekeeping or administration of virtual digital assets or instruments enabling control over them
  • Participation in and provision of financial services related to an issuer’s offer and sale of a virtual digital asset

Entities carrying out these notified VDA activities for or on behalf of another person in the course of business fall within the reporting-entity framework. They must meet the applicable PMLA, PML Rules and AML/CFT/CPF obligations. Because the framework is activity-based, it applies regardless of the entity’s legal structure or domicile.

For offshore exchanges, relevant activities may include crypto-to-fiat conversion, VDA-to-VDA exchange and transfers of virtual digital assets. Custodial or administrative services involving VDAs also fall within scope. Where an entity carries out these activities for or on behalf of another person in the course of business, the provider may fall within the PMLA reporting-entity framework.

Do Offshore VASPs Serving Indian Users Need FIU-IND Registration?

Yes, if an offshore VDA service provider carries out any of the specified VDA activities in the course of business and falls within the PMLA reporting-entity framework. In that case, it must register with FIU-IND and comply with the applicable AML/CFT obligations. The regulator has made this expectation clear through both its guidelines and its enforcement actions.

VDA service providers that fall within the reporting-entity framework must register with FIU-IND as reporting entities. The registration process requires relevant corporate, ownership and compliance information. In addition, VDA service providers must appoint a Designated Director and Principal Officer in accordance with the applicable requirements.

Moreover, the January 2026 AML/CFT guidelines set out detailed requirements for registered VDA service providers. These cover customer due diligence, risk classification, transaction monitoring, suspicious transaction reporting and record-keeping. The guidelines also require VDA REs to furnish a monthly report as prescribed by FIU-IND. Platforms must retain records for at least five years.

Importantly, submitting a registration application and receiving a temporary FINGate Reference ID does not itself constitute formal FIU-IND registration. Formal registration comes only after the prescribed process. This includes document submission, an in-person meeting and Director FIU-IND approval.

FIU-IND’s registered-entity framework includes both Indian and foreign-incorporated VDA service providers. For example, Binance and Bybit have subsequently registered after FIU-IND enforcement action.

What the recent FIU-IND notices to 15 VASPs tell us

On 9 September 2026, FIU-IND issued compliance notices under Section 13 of the PMLA to 15 offshore crypto platforms.

In addition, the Director of FIU-IND issued notices seeking takedown of the applications and URLs associated with the 15 entities. These notices were issued under Section 79(3)(b) of the Information Technology Act, 2000, read with the applicable intermediary rules.

FIU-IND has previously imposed substantial penalties on VDA service providers. These include a ₹18.82 crore (INR 188.2 million) penalty on Binance and a ₹9.27 crore (INR 92.7 million) penalty on Bybit. Recent enforcement actions show that FIU-IND may use a combination of Section 13 proceedings, monetary penalties and directions seeking removal of access to non-compliant platforms. Notably, enforcement may address non-registration as well as failures to comply with underlying PMLA/PML Rules obligations.

What happens if an offshore VASP operates without FIU-IND registration?

The consequences are significant and escalating. FIU-IND’s enforcement toolkit under the PMLA includes several measures.

First, the Director of FIU-IND may take action under Section 13 of the PMLA. This includes imposing monetary penalties for specified contraventions of the PMLA and applicable rules.

Second, FIU-IND can seek URL and application takedowns under Section 79(3)(b) of the Information Technology Act. This can effectively cut off the platform from the Indian market.

Third, failure to comply can expose the VDA service provider to further enforcement action under the PMLA. This may include monetary penalties and other regulatory directions.

FIU-IND registration is only the first step: ongoing AML obligations

Registration with FIU-IND creates continuing compliance obligations. Importantly, FIU-IND registration is an AML/reporting-entity registration. It should not be treated as a general licence or regulatory approval for all aspects of a crypto business. Depending on the business model, separate requirements may apply. These include tax, TDS, foreign exchange, corporate law, data protection and other sector-specific frameworks. The January 2026 guidelines set out detailed operational requirements that extend well beyond the initial registration step.

Customer due diligence must follow a risk-based approach with tiered risk classification. Specifically, the guidelines require review of customer risk classification at least once every six months. KYC updating must occur at least every six months for high-risk clients and at least annually for other clients. In addition, registered entities must implement transaction monitoring systems capable of identifying suspicious patterns.

Transaction monitoring should also address crypto-specific risk indicators. These include patterns associated with mixers, chain-hopping, wallet clustering and unusual on/off-ramp activity. Entities should tailor their monitoring to their risk assessment and applicable FIU-IND requirements. Platforms must file STRs with FIU-IND within prescribed timelines and maintain records for at least five years.

Registered entities must conduct sanctions screening at onboarding, when KYC information changes, when sanctions lists change and when a VDA transaction is initiated. They should also maintain appropriate ongoing screening controls based on the applicable requirements. The guidelines further address risks associated with unhosted wallets, ICOs/ITOs, anonymity-enhancing crypto-assets and mixers/tumblers. In particular, anonymity-enhancing crypto-assets fall outside acceptable risk appetite. Entities should not facilitate transactions involving mixers or tumblers once detected. Finally, the January 2026 guidelines require an independent annual audit of the RE’s AML/CFT/CPF controls, systems, procedures and safeguards.

How offshore crypto exchanges can assess their FIU-IND obligations

Start by determining whether the platform carries out any of the VDA activities specified under Section 2(1)(sa)(vi) of the PMLA. Consider whether these are carried out for or on behalf of another person in the course of business. Then assess whether those activities bring the platform within India’s reporting-entity framework. Factors such as the nature of the customers served, transactions conducted and connections to the Indian market may be relevant. However, they should not be treated as standalone statutory tests.

Next, conduct a gap assessment against the January 2026 AML/CFT guidelines. Evaluate your customer due diligence procedures, transaction monitoring capabilities, STR filing readiness and record-keeping infrastructure. Identify where your current controls fall short of the applicable requirements.

If registration is required, complete the FIU-IND registration process before commencing the relevant covered activities in India. Appoint a Designated Director and Principal Officer. Prepare the required documentation and build reporting connectivity. For a detailed registration walkthrough, see our guide: How Offshore Crypto Exchanges Can Achieve FIU-IND Registration & Compliance.

If your platform has already received a notice, obtain appropriate professional advice promptly. Respond within the applicable timeframe while addressing the identified compliance deficiencies.

FAQ: FIU-IND registration for offshore crypto exchanges

Does my offshore crypto exchange need FIU-IND registration if I have no office in India?

Yes, if your offshore VDA service provider carries out one or more of the specified VDA activities for or on behalf of another person in the course of business. If it falls within India’s reporting-entity framework, FIU-IND registration is required. The obligation does not depend solely on where the entity is incorporated or whether it maintains a physical office in India.

What happens if I ignore the FIU-IND registration requirement?

FIU-IND can impose monetary penalties under Section 13 of the PMLA. It can also seek takedown of your platform’s URLs and applications under Section 79(3)(b) of the Information Technology Act. Other enforcement action may also apply.

How long does FIU-IND registration take?

The timeline depends on the completeness of the application and the entity’s AML/CFT readiness. FIU-IND’s review process also affects timing. Platforms should allow sufficient time to prepare the required documentation and compliance infrastructure before commencing covered activities in India.

What are the key compliance requirements after FIU-IND registration?

VDA service providers must implement appropriate customer due diligence, risk assessment, transaction monitoring, sanctions screening, record-keeping and suspicious transaction reporting controls. These must align with the applicable PMLA, PML Rules and FIU-IND guidance.

Can FIU-IND block my platform’s website and app in India?

Yes. FIU-IND can issue notices seeking takedown of applications and URLs under Section 79(3)(b) of the Information Technology Act, 2000. These notices go to intermediaries and can result in the platform becoming inaccessible to Indian users.

For professional support with FIU-IND registration, AML program design or enforcement remediation, contact Compliance7 for a readiness assessment.

This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.

Ajith Abraham is a Financial Crime Compliance professional with over 14 years of experience in Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), KYC, Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), Transaction Monitoring, Sanctions Screening and Financial Crime Investigations. He is a Certified Anti-Money Laundering Specialist (CAMS) and Merkle Science Certified Crypto Investigator (CCI). Ajith has worked with Big Four consulting firms and advises Financial Institutions, fintechs, DNFBPs and Virtual Asset Service Providers (VASPs) on AML/CFT compliance, risk assessments, regulatory audits, financial crime risk management, crypto compliance, blockchain investigations and FATF-aligned compliance frameworks through Compliance7 Consulting LLP.

Leave a Reply

Your email address will not be published. Required fields are marked *