Last reviewed: September 2026. Based on the FIU-IND AML/CFT/CPF Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets (8 January 2026), the FIU-IND VDA SP registration circular (15 September 2025) and related PMLA provisions.
India’s VDA AML framework is activity-based rather than based solely on incorporation or physical presence. An offshore VDA service provider that carries out any of the notified activities for or on behalf of another person in the course of business may fall within the PMLA reporting-entity framework. In that case, it must register with FIU-IND as a Reporting Entity (RE). For example, FIU-IND imposed penalties of ₹18.82 crore (INR 188.2 million) on Binance and ₹9.27 crore (₹92.7 million) on Bybit. On 9 September 2026, FIU-IND also issued notices to 15 VDA service providers for non-compliance and issued takedown notices concerning their applications and URLs.
This guide covers the practical steps for achieving FIU-IND compliance. Specifically, it explains what triggers the registration obligation, how to register through FINGate 2.0 (FIU-IND’s registration portal), what compliance infrastructure to build and how to maintain it. For the full legal analysis of whether the obligation applies to your platform, see our companion article: Does an Offshore Crypto Exchange Need FIU-IND Registration?
What triggers FIU-IND registration for offshore VDA service providers?
The Ministry of Finance notification S.O. 1072(E) dated 7 March 2023 specified five categories of VDA-related activity under Section 2(1)(sa)(vi) of the PMLA. Specifically, these apply when carried out for or on behalf of another person in the course of business:
- Exchange between virtual digital assets and fiat currencies
- Exchange between one or more forms of virtual digital assets
- Transfer of virtual digital assets
- Safekeeping or administration of virtual digital assets or instruments enabling control over them
- Participation in and provision of financial services related to an issuer’s offer and sale of a virtual digital asset
As a result, an offshore VDA service provider that carries out any of these notified activities for or on behalf of another person in the course of business may fall within the PMLA reporting-entity framework. If it does, registration with FIU-IND as a Reporting Entity is required. The framework expressly applies irrespective of the entity’s physical presence in India.
FIU-IND registration is not a licence
An important distinction: registration with FIU-IND is an AML/CFT/CPF reporting-entity registration under the PMLA. It should not be treated as a general licence or regulatory approval for all aspects of a crypto business. FIU-IND registration should therefore not be marketed as an “Indian crypto licence” or as regulatory approval of the platform’s products, investments, securities-related activities or other services. Depending on the business model, separate requirements may apply in areas such as tax, TDS, foreign exchange, corporate law and data protection.
Pre-registration requirements
Before starting the FINGate application, prepare the following.
First, appoint the required compliance leadership. FIU-IND’s framework distinguishes between the Designated Director (DD), who is responsible for overall compliance with Chapter IV of the PMLA and the PML Rules and the Principal Officer (PO), who is responsible for operational AML/CFT/CPF compliance and reporting. These must be different individuals. Importantly, the Principal Officer must be based in India.
In addition, the PO should place a review and status of the AML/CFT/CPF function before the Board or a Board sub-committee, preferably on a quarterly basis. These reports should cover the effectiveness of the AML/CFT/CPF program, identified vulnerabilities, STRs and other reports filed, FIU-IND instructions and red flags and proposed policy changes. The PO should also focus exclusively on the responsibilities under Chapter IV of the PMLA and should not participate in the RE’s business or operational activities, helping to avoid conflicts of interest.
Second, prepare your documentation pack. The exact document set depends on the applicant’s structure, operating status and arrangements. FIU-IND may request additional information or documents. Required documents typically include:
- Corporate governance: Certificate of incorporation, constitutional documents, UBO/SBO identification and director KYC
- Financials, tax and contracts: Annual returns, balance sheets and profit-and-loss accounts for the last three financial years, GST returns and registrations where applicable, income-tax returns and applicable TDS filings relating to VDA transactions, together with copies of relevant domestic and international contracts or arrangements
- Compliance policies: AML/CFT/CPF policy handbook, risk assessment framework and completed FIU-IND questionnaire
- Technical certifications: Cyber Security Audit Certificate from a CERT-In empanelled auditor
- PACT certificate (where applicable): If the applicant has an ongoing or prospective B2B, broker or other business relationship with an FIU-IND-registered VDA SP, the registration framework requires the relevant PACT (Partner Accreditation for Compliance and Trust) certificate
- Declarations: A self-declaration confirming no pending proceedings with law enforcement agencies, nature-of-service explanation and detailed business model statement
Third, build your AML/CFT/CPF systems. FIU-IND expects operational readiness and FIU-IND compliance infrastructure at the time of registration. As a result, your KYC, transaction monitoring, sanctions screening and reporting systems should be functional before you apply. You will also need to demonstrate these systems during the in-person meeting.
Can an offshore exchange apply before launching in India?
Yes. The FIU-IND registration framework contemplates both operational and pre-operational applicants. Applicants must indicate whether they are currently operational or yet to commence operations, with an expected or tentative timeline. However, operational readiness remains relevant. FIU-IND assesses the applicant’s AML/CFT/CPF controls during the in-person meeting. Pre-operational applicants should therefore plan their FIU-IND compliance infrastructure early and ensure that the relevant systems are operationally ready before the in-person meeting.
FINGate registration process: step by step
The registration process runs through the FINGate 2.0 portal. It involves three stages.
Stage 1: Self-enrolment on FINGate. Create an organisational account on the FINGate 2.0 portal. Then fill in basic entity details including the entity name, category of reporting entity and contact information. Finally, confirm the account via your designated compliance email.
Stage 2: Document submission. Next, upload the complete documentation pack through the portal. Also complete the FIU-IND questionnaire covering your AML/CFT/CPF compliance arrangements. Then assign responsible users within the portal.
Stage 3: In-person meeting and approval. FIU-IND may then schedule an in-person meeting. Both the Designated Director and Principal Officer must attend. During this meeting, you must provide a live demonstration of your AML/CFT/CPF tools and systems. Specifically, this includes KYC, transaction monitoring, blockchain analysis, sanctions screening and Travel Rule compliance. Formal registration comes only after Director FIU-IND approval. Upon satisfactory completion, FIU-IND generates a formal RE-ID.
Importantly, submitting an application and receiving a temporary FINGate Reference ID does not itself constitute formal registration. The Reference ID is for reference and future correspondence only. FIU-IND does not prescribe a fixed approval timeline in the registration framework. The timeline can depend on the completeness of the submission, operational readiness, scheduling of the in-person meeting, follow-up queries and FIU-IND’s review.
Core FIU-IND compliance obligations after registration
FIU-IND’s updated AML/CFT/CPF Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets (8 January 2026) set out detailed operational requirements. These consolidate earlier circulars into a single FIU-IND compliance framework. Below are the key obligations.
Customer due diligence
CDD must follow a risk-based approach with tiered risk classification. Specifically, the FIU-IND compliance guidelines require two distinct periodic obligations. First, review of customer risk classification must occur at least once every six months. Second, KYC updation must occur at least every six months for high-risk clients and at least annually for other clients. UBO identification is also mandatory for entities and legal persons.
VDA-specific onboarding requirements
The 2026 framework goes beyond conventional KYC. In addition to standard identity verification, VDA REs must collect additional digital identifiers as part of CDD, including at onboarding and when undertaking VDA-related activity, as applicable. These include the client’s IP address with timestamp, geolocation, device ID, VDA wallet addresses and transaction hashes. Furthermore, mandatory PAN obtaining and verification applies for onboarding and VDA-related activity. These requirements are particularly relevant for offshore exchanges preparing to operate within India’s framework.
Transaction monitoring
Registered entities must implement transaction monitoring systems capable of identifying suspicious patterns. In addition, monitoring should address crypto-specific risk indicators. These include patterns associated with mixers, chain-hopping, wallet clustering and unusual on/off-ramp activity. Entities should tailor monitoring rules to their risk assessment and applicable FIU-IND compliance requirements.
Suspicious transaction reporting
Platforms must file Suspicious Transaction Reports (STRs) with FIU-IND within prescribed timelines. STRs should contain complete and accurate information relevant to the suspicion, including client KYC information, wallet and transaction details, counterparties and the grounds for suspicion. Blockchain-analysis findings should also be included where relevant. Moreover, the guidelines require VDA REs to furnish a monthly report in the form and manner prescribed by FIU-IND. This report covers key metrics, activity indicators, compliance status and other prescribed information.
Sanctions screening
Registered entities must conduct sanctions screening at four defined trigger points: onboarding, when KYC information changes, when sanctions lists change and when a VDA transaction is initiated. They should also maintain appropriate ongoing screening controls based on the applicable requirements.
Record-keeping
The guidelines distinguish two retention requirements. Client identification records must generally be retained for at least five years after the account-based relationship ends. In addition, transaction records must generally be retained for at least five years from the date of the transaction. Records relating to ongoing investigations or disclosed transactions may need to be retained longer. Also maintain records that are immutable, exportable and searchable, with audit trails for all compliance decisions.
Travel Rule
The January 2026 guidelines require the prescribed originator and beneficiary information to accompany VDA transfers between relevant reporting entities. Notably, the guidelines do not establish a monetary de minimis threshold that would exempt such transfers from the Travel Rule requirements. In addition, REs must transmit the required information before or when they conduct the VDA transfer. The guidelines do not permit post-facto submission.
Crypto-specific compliance requirements
The January 2026 FIU-IND compliance guidelines address several crypto-specific risks that traditional AML/CFT/CPF frameworks do not cover.
Anonymity-enhancing crypto-assets (AECs). These are considered unacceptably high risk. Consequently, REs should refrain from permitting deposits or withdrawals of AECs.
Mixers and tumblers. Similarly, transactions involving mixers, tumblers and other anonymity-enhancing services should not be facilitated once detected. Transaction monitoring systems should therefore flag patterns associated with mixing services.
Unhosted wallets. The guidelines do not impose a blanket prohibition on all transfers involving unhosted wallets. Instead, they require collection, monitoring, risk assessment and appropriate enhanced or risk-based controls. REs may also impose additional restrictions based on their risk assessment.
ICOs and ITOs. Finally, participation in initial coin offerings and initial token offerings carries specific risk factors. Entities should assess these within their overall risk framework.
Independent audit requirement
The January 2026 guidelines require an independent annual audit of the RE’s AML/CFT/CPF controls, systems, procedures and safeguards. This is separate from any financial audit. The audit should assess the effectiveness of the FIU-IND compliance program and identify gaps requiring remediation. Corrective action for deficiencies must be reported to the Board or designated Board committee.
What happens if you operate without registration?
FIU-IND’s enforcement toolkit has expanded significantly. Consequences for failing to achieve FIU-IND compliance include three categories of action.
First, the Director of FIU-IND may take action under Section 13 of the PMLA. This includes monetary penalties for specified contraventions.
Second, the Director of FIU-IND, acting as the relevant nodal officer, can issue notices for takedown of applications and URLs under Section 79(3)(b) of the Information Technology Act, 2000, under the applicable framework. Such notices can materially restrict public access to the platform in India.
Third, failure to comply can expose the entity to further enforcement action. This may include additional monetary penalties and other regulatory directions. Notably, enforcement may address non-registration as well as failures to comply with underlying PMLA/PML Rules obligations.
Readiness assessment: where to start
Start by confirming whether your platform carries out any of the five notified VDA activities for or on behalf of another person in the course of business. Then assess whether those activities bring you within India’s reporting-entity framework.
Next, conduct a gap assessment against the January 2026 FIU-IND compliance guidelines. Specifically, evaluate the following areas:
- KYC/CDD procedures, tiered risk classification and VDA-specific onboarding requirements
- Transaction monitoring capabilities and crypto-specific rules
- STR filing readiness and investigation workflows
- Sanctions screening at the four defined trigger points
- Record-keeping infrastructure (five-year retention, immutable logs)
- Travel Rule compliance for inter-RE transfers
- Designated Director and Principal Officer appointments
- CERT-In cyber security audit readiness
- PACT certificate arrangements where applicable
If registration is required, complete the process before commencing covered activities in India. Build your FIU-IND compliance infrastructure in parallel with the registration application, since FIU-IND expects operational readiness at the time of the in-person meeting.
FAQ: FIU-IND registration and compliance for offshore crypto exchanges
Does my offshore exchange need to register if I have no office in India?
The FIU-IND VDA framework is activity-based and expressly applies irrespective of the VDA SP’s physical presence in India. An offshore entity may therefore be required to register with FIU-IND as a Reporting Entity where it carries out any of the notified VDA activities for or on behalf of another person in the course of business within the scope of the PMLA framework.
What is the difference between a FINGate Reference ID and formal registration?
Submitting a registration application through FINGate generates a temporary Reference ID for reference and future correspondence. However, this does not constitute formal FIU-IND registration. Instead, formal registration requires completion of the prescribed process. This includes document submission, an in-person meeting with the Designated Director and Principal Officer and Director FIU-IND approval. A formal RE-ID is generated only after satisfactory completion.
Can the Principal Officer be based outside India?
No. The Principal Officer must be based in India. The Designated Director and Principal Officer must also be different individuals.
Can an offshore exchange apply before it starts operating in India?
Yes. The registration framework contemplates both operational and pre-operational applicants. However, FIU-IND assesses AML/CFT/CPF controls during the in-person meeting. Pre-operational applicants should therefore plan their AML/CFT/CPF infrastructure early and ensure the relevant systems are operationally ready before the in-person meeting.
What reports must I file after registration?
Registered VDA service providers must file Suspicious Transaction Reports (STRs) within prescribed timelines. In addition, they must submit a monthly report to FIU-IND covering key metrics, compliance status and reporting statistics. Furthermore, the Travel Rule requires the prescribed originator and beneficiary information to accompany VDA transfers between relevant reporting entities.
What happens if I receive an FIU-IND notice?
Obtain appropriate professional advice promptly. Then respond within the applicable timeframe and begin a documented remediation process. Also commission an expedited gap assessment. FIU-IND enforcement orders show that the circumstances of each case, including cooperation and remedial steps, can be relevant to the regulatory outcome. For example, both Binance and Bybit registered after receiving enforcement action.
How Compliance7 helps
Compliance7 supports offshore VDA service providers navigating FIU-IND compliance, from initial registration through ongoing AML/CFT/CPF obligations.
Registration support: FINGate readiness assessment, documentation preparation, questionnaire completion, CERT-In audit coordination and in-person meeting preparation.
AML/CFT/CPF program design: KYC/CDD policy development, transaction monitoring rule design, STR templates, sanctions screening procedures and Travel Rule implementation.
Ongoing compliance: Independent AML audit coordination, monthly reporting support, policy updates for new FIU-IND circulars and staff training.
Enforcement remediation: If your platform has received a notice, Compliance7 provides expedited gap assessments, remediation roadmaps and response support.
For an FIU-IND compliance readiness assessment, contact Compliance7.
Related Compliance7 guides
- Core guide: FIU-IND Registration: Applicability, Process and Compliance Guide
- Related: Does an Offshore Crypto Exchange Need FIU-IND Registration?
This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.


