On 8 January 2026, India’s Financial Intelligence Unit (FIU-IND) issued updated anti-money laundering, counter-terrorist financing and counter-proliferation financing (AML/CFT/CPF) guidelines for reporting entities handling virtual digital assets. The update consolidates and strengthens requirements set out across the 2023 guidelines and later circulars. One part stands out for privacy coin compliance. FIU-IND’s 2026 guidelines treat transactions involving anonymity-enhancing crypto tokens or AECs as unacceptably high risk and state that such transactions should not be facilitated.
Many VDA service providers (VDA SPs, referred to internationally as VASPs) spent 2025 adapting to evolving FIU-IND registration and compliance expectations, including changes to registration procedures, Travel Rule implementation and enhanced due diligence requirements. However, regulators will test these controls closely. Privacy-preserving tools keep showing up in laundering typologies that FATF has flagged for years.
This article covers what the January 2026 guidelines say about anonymity-enhancing tokens and mixing services. It also explains why regulators treat them so cautiously. Finally, it sets out what practical privacy coin compliance looks like for a reporting entity in India.
| Compliance area | Key requirement | Why it matters |
|---|---|---|
| Anonymity-enhancing crypto tokens (AECs) | Transactions deemed unacceptably high risk; related transactions should not be facilitated | Outside acceptable risk appetite; EDD does not override the requirement not to facilitate covered transactions |
| Mixers, tumblers and similar services | Must be identified through monitoring and analytics; detected transactions should not be facilitated | Can significantly reduce transaction traceability |
| Unhosted wallets | Present elevated risk; require information collection, monitoring and risk-based enhanced measures | No regulated counterparty service provider may be available to provide or independently verify information about the wallet holder or transaction |
| Travel Rule data | Originator and beneficiary information required for relevant VDA transfers between service providers | Supports traceability across the transaction chain; post-facto submissions not permitted where guidelines require prior or concurrent transmission |
| Principal Officer | Senior governance role with location and eligibility requirements, kept separate from the Designated Director | Supports direct accountability; both roles participate in FIU-IND’s in-person registration process |
| Regulatory reporting | Prescribed transaction reports furnished under the PMLR, alongside suspicious transaction reports (STRs) and other applicable FIU-IND reports | Supports FIU-IND’s monitoring and analysis of reportable and suspicious activity |
What changed in FIU-IND’s January 2026 guidelines
FIU-IND has regulated entities conducting notified virtual digital asset activities since March 2023. That is when the government brought VDA SPs under the Prevention of Money Laundering Act. However, requirements and guidance were spread across the 2023 guidelines and subsequent circulars issued between 2023 and 2025.
On 8 January 2026, FIU-IND consolidated that patchwork into one document. It folds in the FINgate registration process from September 2025 and the Principal Officer rules from February 2025. In addition, it consolidates and expands operational expectations around due diligence, monitoring and reporting.
Several changes stand out. For example, registration now includes an in-person meeting as part of FIU-IND’s registration process. Firms should be prepared to demonstrate their compliance framework and operational capabilities where requested.
Furthermore, the guidelines impose specific governance and eligibility requirements on the Principal Officer, including their location and role within the reporting entity. The 2023 guidelines already required the Principal Officer and Designated Director to be separate individuals. That separation carries through.
Meanwhile, client risk categorisation frameworks need approval through the reporting entity’s governance structure. In addition, firms must review high-risk clients periodically, in line with FIU-IND’s requirements and the entity’s own risk framework. Notably, the guidelines consolidate and strengthen expectations relating to higher-risk products, services and transaction types. That list includes initial coin offerings, unhosted wallet transfers and, most importantly here, AECs and mixing services. As a result, a compliance function that passed muster under the 2023 guidance may fall short today.
Why anonymity-enhancing crypto tokens count as unacceptable risk
Anonymity-enhancing crypto tokens or AECs are often called privacy coins by the industry. They use cryptography to hide the sender, the receiver or the amount. Monero and Zcash are commonly cited examples. FIU-IND has not published a named list of tokens classified as AECs. Instead, the guidelines focus on whether a VDA is designed to conceal or obfuscate the origin, ownership or value of transactions. Where that criterion is met, FIU-IND treats related transactions as unacceptably high risk and outside a reporting entity’s acceptable risk appetite.
This position tracks global standards closely. FATF has warned that anonymity-enhanced transactions carry higher money laundering and terrorist financing risk. This is especially true when they stop a provider from identifying who receives a transfer.
FATF’s risk-based framework does not itself impose a universal ban on privacy-enhancing assets, though. It highlights the risk and leaves individual jurisdictions to decide how strictly to respond. India’s approach, in that sense, reflects a national regulatory choice rather than a direct FATF mandate.
What this means in practice for a VDA SP (VASP)
For a VDA SP, the practical effect still matters. The guidelines indicate that AEC-related deposits, withdrawals and transaction facilitation fall outside acceptable risk appetite. In practice, this can significantly restrict the ability of a regulated platform to support deposits, withdrawals and other transactions involving such assets and may affect decisions about listing, trading or custody support.
The guidelines do not create a general statutory ban on AECs. However, for FIU-IND-regulated reporting entities, the requirement not to facilitate relevant transactions creates a significant practical restriction on listing, deposit, withdrawal and other supported services involving AECs. Therefore, firms should treat asset listing, custody and transaction processes as needing a clear AEC screen, not just a policy statement.
Reporting entities should also consider how their risk assessment addresses attempts to circumvent AEC controls through indirect transaction structures or intermediary assets. The guidelines do not prescribe a specific methodology for identifying such indirect exposure, so firms should document their risk-based approach.
FIU-IND’s guidelines treat AEC-related transactions as outside the reporting entity’s acceptable risk appetite. For transactions involving AECs within the scope of the guidelines, enhanced due diligence alone is not sufficient to overcome the requirement that such transactions should not be facilitated. That sits apart from the general risk-based framework, where firms apply EDD and can continue a relationship once satisfied. Firms should instead follow documented procedures for detection, escalation, risk assessment and any required reporting.
This is a stricter stance than some countries take. A handful of exchanges elsewhere still allow limited privacy coin trading under heavy monitoring. However, FIU-IND’s framing leaves far less room for that middle ground. Indian VDA SPs should therefore treat identified AEC-related activity as a matter requiring escalation and documented handling. It is not ordinary exposure to accept after a round of enhanced due diligence.
Mixers, tumblers and other anonymity-enhancing services
Mixers and tumblers pool crypto from many users, then redistribute it. In doing so, they break the link between the original source of funds and where the funds end up. Criminals have used these services for years to obscure transaction trails linked to hacks, scams, sanctions evasion and other illicit activity.
FIU-IND’s guidelines expect reporting entities to use appropriate monitoring and analytical tools to identify transactions involving mixers, tumblers and similar services. Once detected, such transactions should not be facilitated. Firms must trigger suitable risk-mitigation measures. In other words, this is a firm position, closely aligned with the approach taken for AECs.
Consequently, transaction-monitoring capability matters, whatever the size of the VDA SP. For many reporting entities, third-party blockchain analytics tools will provide a practical way to build that capability. The guidelines describe an outcome, namely sufficient capability to detect this activity, rather than mandating a specific vendor. Where firms use blockchain analytics to identify indirect exposure or risk indicators, they should document how their detection parameters and escalation criteria are calibrated. However, once a transaction is identified as involving a mixer, tumbler or similar anonymity-enhancing service within the scope of the guidelines, the transaction should not be facilitated. Because wallet addresses and exposure indicators change over time, firms should keep monitoring data and detection capabilities up to date.
Where a transaction involves mixer exposure, reporting entities should follow documented escalation and risk-mitigation procedures rather than allowing the activity to pass through without review. Although paragraph 7.5 does not prescribe a specific documentation format, maintaining a clear decision trail will help a reporting entity demonstrate how it identified and handled such activity during regulatory review or inspection.
Building privacy coin compliance into your AML program
Turning these expectations into a working program takes more than a policy update. A few practical steps separate privacy coin compliance on paper from privacy coin compliance that survives an audit. These are recommended practices, not a restatement of the guidelines themselves.
First, start with your asset listing process. A VDA SP should document how it vets new tokens before launch. That check should test whether a token conceals origin, ownership or value, which are FIU-IND’s core criteria for AECs. This stops such a token from slipping onto the platform just because a product team wants more trading pairs.
Second, build transaction monitoring capable of flagging mixer and tumbler exposure specifically. Do not rely only on generic high-value or high-velocity alerts. Instead, several blockchain analytics vendors track wallet clusters tied to known mixing services. That intelligence should feed into an effective monitoring and escalation process rather than sitting in a separate report.
Third, train frontline compliance staff on handling AEC-related requests. A client may ask to convert into or out of a privacy coin through an intermediary token. Because attempts to circumvent transaction restrictions may arise in practice, staff need clear escalation paths rather than authority to clear unusual requests themselves.
Finally, document everything. FIU-IND’s guidelines place heavy weight on audit trails, governance oversight and Principal Officer reporting. A framework built only on informal practice will not hold up under review. The Designated Director, Principal Officer and any reviewer should be able to access evidence supporting the firm’s compliance decisions.
None of this needs building from scratch. Firms already running FIU-IND-aligned due diligence can extend those controls to cover these asset types instead. Compliance7 helps VDA SPs and fintechs translate regulatory requirements into practical controls, including risk assessments, monitoring frameworks and governance processes.
Travel Rule and unhosted wallets: the wider picture
AEC and mixer restrictions do not sit in isolation. Instead, they form part of a broader effort to improve traceability and risk management for VDA transactions. One clear example is the Travel Rule.
The updated guidelines consolidate and further operationalise Travel Rule obligations for relevant VDA transfers between service providers. The exact information required and the timing of transmission depend on the role each service provider plays and the nature of the transfer. For that detail, firms should consult the guidelines directly. Even so, the direction of travel is clear. Where the guidelines require Travel Rule information to be transmitted, reporting entities should ensure the information is available and transmitted in accordance with the applicable timing and procedural requirements. Firms should not rely on post-transfer information sharing where the guidelines require information to be transmitted before or during the transfer process.
Unhosted wallets receive similar attention. FIU-IND’s guidelines present transfers to or from unhosted wallets as elevated risk, since either wallet may sit outside an obliged entity’s custody. Firms should collect information where required under the applicable framework and apply appropriate monitoring and risk-based measures. This is not a one-size-fits-all procedure. Firms should instead choose controls case by case, based on the risk assessment.
Taken together, these requirements aim to improve information availability and traceability across VDA transactions. Platforms must identify and manage risks associated with technologies and transaction structures that can reduce traceability, including AECs, mixers and higher-risk unhosted wallet flows. Firms should treat privacy coin compliance as one piece of this wider agenda, not an isolated checkbox.
What banks, fintechs and DNFBPs should take from this
The January 2026 guidelines apply directly based on the activities being conducted, rather than the commercial label attached to a business. A bank, fintech, law firm or accounting firm does not automatically fall within the scope of the VDA-SP guidelines simply because it has crypto-related exposure. However, an entity conducting a notified VDA activity may fall within scope regardless of how it describes itself. Depending on the entity and activities involved, separate PMLA, RBI or professional AML/CFT obligations may apply.
That said, indirect exposure is real. A bank that provides accounts or other services to a crypto exchange may face elevated financial crime risk through the customer relationship and should assess that exposure under its own risk-based AML/CFT framework. The same is true for a fintech offering crypto-adjacent products. However, a bank or fintech does not become subject to these VDA-SP-specific guidelines merely because it provides services to, or has indirect exposure to, a crypto business. Banks and other regulated financial institutions remain subject to their own applicable AML/CFT obligations under the PMLA, PMLR, RBI framework and other relevant regulatory requirements.
A bank onboarding a crypto exchange as a client can reasonably ask pointed questions as part of standard due diligence. What is that exchange’s approach to AECs? Can it screen for mixer exposure?
Similarly, an accounting or legal firm may advise a crypto business or otherwise have commercial exposure to VDA-related activity. The nature of the firm’s activities and any applicable professional or statutory AML obligations should be assessed separately. A client’s FIU-IND compliance posture still shapes the risk attached to that relationship.
For any institution with crypto exposure, these guidelines remain a useful reference point. They inform how to assess a counterparty’s compliance posture, even where they do not apply directly. Global regulatory expectations concerning anonymity-enhancing technologies and VDA-related financial crime risks continue to evolve. Firms that build these controls now will spend less time retrofitting them later.
Key takeaways on privacy coin compliance
FIU-IND’s January 2026 guidelines leave little room for doubt. Transactions involving AECs are deemed unacceptably high risk and outside the acceptable risk appetite of FIU-IND-regulated reporting entities. Transactions involving mixers or tumblers require active detection and appropriate handling, and identified transactions should not be facilitated in accordance with the guidelines. Both sit inside a wider effort toward stronger Travel Rule compliance and unhosted wallet due diligence.
For VDA SPs, the task ahead is easier to describe than to deliver. Build asset-listing checks against FIU-IND’s AEC criteria and put in place transaction monitoring that can flag mixer and tumbler exposure. Then train staff on escalation paths and document the whole process for FIU-IND’s Principal Officer and Designated Director to review.
Banks, fintechs and DNFBPs with crypto exposure should treat this guidance as a benchmark for their own risk assessments. The guidelines still apply directly only to FIU-IND’s reporting entities.
Does your VDA service provider, bank or fintech need help turning these guidelines into a working privacy coin compliance program? Compliance7’s AML consulting team can help. Book a free consultation to talk through where your current controls stand.
This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.



