Delhi-focused information on PMLA, ED and economic-offence proceedings+91 82944 31232ankitsingh.legum@gmail.com

Money Laundering

FIU-IND Compliance for Virtual Digital Asset Service Providers in 2026: Registration, CDD, Travel Rule, STRs: Delhi Procedure and Defence Guide

India's 2026 VDA anti-money-laundering framework goes far beyond obtaining an FIU registration number. A Virtual Digital Asset Service Provider operating in the Indian market must be able to demonstrate who its customers and beneficial owners are, how transfer

By Advocate Ankit Kumar Singh

FIU-IND • VDA • PMLA • Crypto AML • CDD • Travel Rule • STR • Enforcement

India's 2026 VDA anti-money-laundering framework goes far beyond obtaining an FIU registration number. A Virtual Digital Asset Service Provider operating in the Indian market must be able to demonstrate who its customers and beneficial owners are, how transfers are monitored, what originator and beneficiary information travels with VDA transfers, how suspicious activity reaches FIU-IND and whether the complete transaction can later be reconstructed. Yet a compliance failure remains legally distinct from proof that the platform or its officers themselves committed the offence of money-laundering.

Research and professional guidance by

Current legal review: 19 August 2026

Direct Answer

A Virtual Digital Asset Service Provider carrying on the notified VDA activities in relation to the Indian market can fall within the PMLA reporting-entity framework even if the provider is incorporated outside India.

Registration with FIU-IND is mandatory for covered VDA SPs, but registration is only the beginning.

The current 8 January 2026 FIU-IND VDA framework requires an operational AML/CFT compliance system covering:

  • Designated Director and Principal Officer governance;
  • risk-based customer due diligence;
  • beneficial-owner verification;
  • enhanced onboarding controls;
  • ongoing KYC updates;
  • transaction monitoring and blockchain analysis;
  • sanctions screening;
  • Travel Rule-style originator and beneficiary data;
  • Suspicious Transaction Reports;
  • record reconstruction and retention;
  • controls concerning higher-risk VDA activity.

FIU-IND can use Section 13 PMLA to inquire into failures, issue warnings or directions, require remedial reporting and impose monetary penalties for compliance breaches.

But the criminal offence of money-laundering is different.

FIU-IND COMPLIANCE FAILURE

AUTOMATIC SECTION 3 MONEY-LAUNDERING

A criminal PMLA case must still independently identify the alleged proceeds of crime and the process/activity connected with those proceeds and establish the legally relevant involvement of the accused person.

Quick Navigation

  1. Which VDA businesses become reporting entities?
  2. Do offshore exchanges have to register?
  3. FIU-IND registration in 2026
  4. Designated Director and Principal Officer
  5. 2026 onboarding and KYC controls
  6. Beneficial-owner verification
  7. Risk classification and EDD
  8. Travel Rule for VDA transfers
  9. Unhosted wallets, P2P, mixers and anonymity
  10. Transaction monitoring
  11. Suspicious Transaction Reports
  12. Record retention and reconstruction
  13. Sanctions screening
  14. Section 13 enforcement
  15. Compliance breach vs money-laundering offence
  16. Responding to an FIU compliance notice
  17. 2026 compliance audit matrix
  18. Frequently asked questions

Which VDA Businesses Become Reporting Entities Under PMLA?

The starting point is the Central Government's 7 March 2023 notification concerning activities involving Virtual Digital Assets.

The notified business activities include:

VDA ↔ FIAT Exchange between virtual digital assets and fiat currencies. VDA ↔ VDA Exchange between one or more forms of virtual digital assets. TRANSFER Transfer of virtual digital assets. CUSTODY / CONTROL Safekeeping or administration of VDAs or instruments enabling control over them. ISSUER-RELATED FINANCIAL SERVICES Participation in or provision of financial services related to an issuer's offer and sale of a VDA.

The legal analysis is activity-based.

Do labels matter?

Calling the business:

  • technology provider;
  • Web3 platform;
  • token marketplace;
  • wallet infrastructure;
  • broker;
  • aggregator;
  • digital-assets portal

does not itself answer whether the notified activity is being carried on.

The correct question is:

WHAT DOES THE PLATFORM ACTUALLY DO FOR OR ON BEHALF OF ANOTHER PERSON IN THE COURSE OF BUSINESS?

Offshore VDA SPs: India Uses an Activity-Based Compliance Test

The Ministry of Finance has expressly taken the position that PMLA obligations for VDA SPs operating in the Indian market are activity-based and are not contingent upon physical presence in India.

That makes the following statement legally insufficient:

“Our company is incorporated offshore, therefore FIU-IND has nothing to do with us.”

Indian-market indicators

A compliance assessment should examine:

  • Indian customers;
  • Indian KYC documents accepted;
  • INR deposits/withdrawals;
  • Indian banking/payment partners;
  • India-specific website/app access;
  • marketing directed at India;
  • Indian customer-support infrastructure;
  • India-linked contractual relationships;
  • number and volume of Indian accounts;
  • whether India is restricted or actively serviced.

Enforcement has already reached offshore businesses

FIU-IND's enforcement history includes compliance notices to offshore platforms and requests for URL blocking where providers continued offering services into India without meeting the PMLA framework.

The more recent October 2025 action against 25 offshore VDA SPs reinforces that offshore incorporation is not treated as an automatic exemption.

FIU-IND Registration in 2026: The Regulator Wants to See a Working Compliance System

The 2026 Guidelines consolidate the increasingly rigorous VDA registration framework.

Registration should not be approached as:

UPLOAD FORM → RECEIVE NUMBER → START BUILDING AML SYSTEM.

The correct practical sequence is closer to:

BUILD AML FRAMEWORK → APPOINT DD / PO → IMPLEMENT KYC → IMPLEMENT TMS → TRAVEL RULE → BLOCKCHAIN ANALYTICS → APPLY / DEMONSTRATE

Registration documentation can include

  • business-model explanation;
  • mapping against the five notified VDA activities;
  • corporate organogram;
  • significant beneficial-ownership particulars;
  • incorporation documents;
  • annual returns;
  • balance sheets and profit/loss statements;
  • GST registrations and returns;
  • income-tax material;
  • VDA TDS-related material;
  • domestic/international contractual relationships;
  • custody/platform/intermediary agreements;
  • PACT documentation where applicable;
  • law-enforcement/criminal-proceeding declarations;
  • AML/CFT questionnaire;
  • CERT-In empanelled-auditor cybersecurity certification;
  • other information required by FIU-IND.

In-person meeting

The FIU registration framework contemplates an in-person meeting with compliance leadership.

The Designated Director and Principal Officer should be prepared to explain the system—not merely repeat the policy document.

Live system demonstration

The applicant may be required to demonstrate:

  • KYC workflow;
  • sanctions screening;
  • transaction monitoring;
  • alert creation;
  • blockchain-analysis capabilities;
  • Travel Rule controls;
  • case escalation;
  • STR workflow.
Registration should not be described as a Government guarantee that the crypto product is safe, lawful for every purpose, or investment-worthy. It is principally AML/CFT reporting-entity registration.

Designated Director and Principal Officer: Two Different Accountability Layers

Role Core Compliance Function
Designated Director Overall responsibility for compliance with Chapter IV reporting-entity obligations; governance, internal mechanisms and risk oversight.
Principal Officer Operational AML implementation, FIU liaison, alert governance, reporting, suspicious-transaction decisions and day-to-day control.

The PO should not be ornamental

Under the 2026 framework, the Principal Officer is expected to be a sufficiently senior compliance professional with meaningful AML/PMLA expertise, appropriate resources and genuine decision-making involvement.

The current framework requires the PO to be based in India.

The PO should also be operationally independent enough to:

  • review alerts;
  • challenge business teams;
  • require enhanced information;
  • determine reportability;
  • document non-reporting decisions;
  • file STRs;
  • respond to FIU-IND;
  • escalate weaknesses to senior governance.

Alert-governance responsibility

A particularly important 2026 focus is that an alert must have a traceable decision history.

For every material alert:

ALERT CREATED

ANALYST REVIEW

SOURCE DATA EXAMINED

CUSTOMER EXPLANATION, IF APPROPRIATE

PO DECISION

STR / NO STR

REASONS RETAINED.

2026 VDA Onboarding: Identity Is Becoming a Forensic Data Package

The updated VDA framework materially strengthens digital onboarding.

Individual customer data

Depending upon the applicable CDD route, the VDA SP should collect and verify the prescribed identity information and current VDA-specific onboarding data.

Important 2026 elements include:

  • PAN;
  • acceptable identity document;
  • full legal name;
  • date of birth;
  • address;
  • mobile;
  • email;
  • occupation;
  • income range;
  • bank account;
  • bank ownership and operational verification;
  • live selfie;
  • liveness check;
  • latitude/longitude;
  • date/time stamp;
  • IP address.

Penny-drop bank verification

The objective is to confirm:

  • that the bank account exists/operates; and
  • that account ownership aligns with the customer profile.

Why geo-location matters

If the customer declares:

Residential location: Delhi.

But repeated onboarding/access information shows:

Jurisdiction: high-risk foreign location.

That does not automatically prove crime.

It does create a potentially material CDD discrepancy requiring explanation and risk treatment.

Liveness detection

A static uploaded selfie can be:

  • stolen;
  • replayed;
  • synthetic;
  • deepfake-assisted.

A liveness check seeks additional assurance that a live person is participating in onboarding.

But even a successful liveness check does not prove:

THE PERSON IS THE TRUE BENEFICIAL OWNER OF ALL FUNDS LATER ROUTED THROUGH THE ACCOUNT.

That is why transaction monitoring remains necessary after KYC.

Beneficial-Owner Verification: Do Not Stop at the Name on the Corporate Account

Corporate VDA accounts can create multiple ownership layers.

The PML Rules require the reporting entity to identify and verify the ultimate natural person where the beneficial-ownership test is satisfied.

Customer Type Current PMLR Ownership Test — Broadly
Company Natural person with more than 10% share/capital/profit entitlement or control through other means.
Partnership Natural person with more than 10% capital/profit entitlement or other control.
Unincorporated association / body of individuals Natural person with more than 15% property/capital/profit entitlement.
Trust Author/settlor, trustee, specified beneficiaries and any natural person exercising ultimate effective control.

Control through other means

A 7% shareholder could still be relevant where evidence shows:

  • voting agreements;
  • management control;
  • appointment power;
  • nominee structure;
  • contractual control;
  • actual economic control.

Beneficial-owner matrix

ACCOUNT CUSTOMER: ________

LEGAL ENTITY: ________

DIRECT SHAREHOLDERS: ________

INTERMEDIATE ENTITIES: ________

NATURAL PERSON ABOVE THRESHOLD: ________

CONTROL THROUGH OTHER MEANS: ________

SENIOR MANAGING OFFICIAL, IF APPLICABLE: ________

SOURCE OF FUNDS: ________

WALLET CONTROLLER: ________

Risk Classification and Enhanced Due Diligence

The 2026 framework expects a formal, documented and Board-approved risk methodology.

A one-line declaration that every customer is “medium risk” will not meaningfully demonstrate a functioning risk-based system.

Risk factors can include

CUSTOMER PEP status, occupation, income, business, corporate complexity, adverse information. GEOGRAPHY Residence, IP/geolocation, high-risk jurisdictions, sanctions exposure. PRODUCT Spot trading, custody, P2P, token sale, staking-like product, transfer function. TRANSACTION Value, frequency, velocity, counterparties, rapid movement, structuring. BLOCKCHAIN Unhosted wallets, mixers, ransomware, darknet, theft, sanctioned addresses, chain hopping. BEHAVIOUR Multiple devices, unusual login patterns, abrupt profile changes, mule indicators.

Periodic review

The current guidance expects client-risk classification to be revisited periodically, with at least six-monthly review of the classification framework for clients.

KYC refresh under the current VDA framework is also materially more frequent than a traditional long-cycle re-KYC model.

EDD is evidence-driven

For a high-risk customer consider:

  • source of funds;
  • source of wealth;
  • business rationale;
  • counterparty identity;
  • bank-origin evidence;
  • tax/business documentation;
  • wallet ownership;
  • blockchain exposure;
  • transaction purpose;
  • senior-management approval where required;
  • enhanced monitoring.

The VDA Travel Rule: Identity Data Should Travel With Value

Blockchain transparency can show:

WALLET A → WALLET B.

But without customer attribution it may not answer:

WHO IS A?

WHO IS B?

That is the compliance gap addressed by the Travel Rule.

Originating VDA SP

For qualifying VDA transfers under the current framework, the originating reporting entity should obtain, hold and transmit the prescribed originator and beneficiary information.

Originator data

The operational data set can include:

  • verified full name;
  • PAN / identification number;
  • wallet address or account identifier;
  • verified physical address;
  • date of birth;
  • other prescribed identifying information.

Beneficiary data

The data set can include:

  • beneficiary name;
  • beneficiary wallet/account identifier;
  • data required for screening and matching;
  • transaction amount;
  • VDA type.

Timing

VALUE MOVES
WITH
IDENTITY DATA

The current VDA framework is reported as requiring transfer information before or contemporaneously with the VDA transfer rather than accepting an ordinary post-facto data exchange as equivalent compliance.

No simple small-transfer escape

The current Indian VDA implementation is reported as applying the Travel Rule without a de minimis VDA-transfer threshold.

Accordingly, the compliance engine should not assume:

“LOW VALUE = NO ORIGINATOR / BENEFICIARY DATA.”

Beneficiary VDA SP

The receiving reporting entity should:

  • receive/retain the required originator information;
  • identify the beneficiary;
  • match beneficiary information with its own KYC;
  • screen the parties;
  • monitor the transaction;
  • address incomplete information according to its risk policy.

Travel Rule is not proof of innocence

A transfer can have perfectly complete originator/beneficiary data and still be suspicious because:

  • criminal proceeds are being moved openly;
  • the declared parties are nominees;
  • the business rationale is false;
  • the wallet is linked to illicit activity.

Travel Rule compliance improves traceability.

It does not answer every Section 3 question.

Unhosted Wallets, P2P Structures, Mixers and Anonymity-Enhancing Activity

Unhosted / self-custody wallets

A transfer to a self-custody wallet is not intrinsically criminal.

The risk problem is that there may be no second reporting entity performing:

  • beneficiary KYC;
  • sanctions screening;
  • Travel Rule exchange;
  • transaction monitoring.

Accordingly, the VDA SP should assess:

  • who controls the wallet;
  • whether wallet ownership can be verified;
  • relationship to the customer;
  • beneficiary identity;
  • blockchain history;
  • high-risk exposure;
  • frequency and purpose.

P2P

Peer-to-peer activity can increase counterparty-opacity risk where the platform does not adequately identify both sides of the economic transaction.

The compliance objective remains:

EQUIVALENT CDD AND TRACEABILITY OUTCOME.

Mixers / tumblers

A mixer/tumbler is relevant because its purpose can include breaking or obscuring the observable link between incoming and outgoing blockchain flows.

The updated VDA framework treats such activity as a significant risk requiring detection through transaction monitoring/blockchain analytics and appropriate prevention or mitigation.

Anonymity-enhancing assets

Where the VDA architecture materially prevents the reporting entity from achieving transaction traceability, the risk may fall outside the VDA SP's acceptable compliance framework.

Important legal distinction: use of a self-custody wallet or privacy-enhancing technology may justify enhanced AML scrutiny, but the technology label itself should not be substituted for proof that a particular person's property represents proceeds of crime.

Transaction Monitoring: The Platform Must Understand Behaviour, Not Merely Amount

A modern VDA transaction-monitoring system should integrate:

CUSTOMER DATA + FIAT DATA + BLOCKCHAIN DATA + DEVICE DATA + GEOGRAPHIC DATA + COUNTERPARTY DATA.

Illustrative monitoring scenarios

Pattern Compliance Question
Large fiat deposit → immediate VDA purchase → immediate external withdrawal What explains the velocity and external destination?
Salary-profile customer suddenly trades very large volume Does source of funds align with declared profile?
Repeated transfers through multiple chains Commercial purpose or layering indicator?
Multiple unrelated users send to common wallet Mule / aggregator / legitimate business?
Customer repeatedly changes devices/IP geography Account sharing, compromise or legitimate travel?
Exposure to mixer / illicit cluster Direct, indirect, historic or explainable exposure?
High-value P2P activity Who are actual counterparties and payment sources?
Repeated failed sanctions-screening hits False positive, alias issue or prohibited party?

Alert ≠ STR

An automated rule may generate an alert.

The compliance team investigates.

The Principal Officer decides whether the facts create suspicion requiring reporting.

Therefore:

100 ALERTS ≠ 100 STRs.

But:

100 ALERTS CLOSED WITH NO REASONING = GOVERNANCE RISK.

Suspicious Transaction Reports: What, When and Why?

An STR is not merely a “large transaction report.”

Suspicion can arise from:

  • transaction behaviour;
  • customer information;
  • counterparty information;
  • blockchain analytics;
  • IP/device patterns;
  • sanctions indicators;
  • source-of-funds inconsistencies;
  • law-enforcement information;
  • attempted activity.

No fixed suspicion threshold

A small transaction can be suspicious.

A large transaction can be legitimate.

The question is whether the facts satisfy the suspicious-transaction criteria and the reporting entity's documented risk framework.

Seven-working-day rule

Under the FIU/PMLR reporting framework, the Principal Officer is expected to furnish an STR promptly and no later than seven working days after being satisfied that the transaction is suspicious.

A strong STR narrative

Should explain:

  • customer identity;
  • beneficial owner;
  • relevant accounts/wallets;
  • transaction chronology;
  • VDA type and amounts;
  • fiat leg;
  • blockchain counterparties;
  • IP/device/geographic anomalies;
  • customer explanation;
  • why that explanation is inadequate or suspicious;
  • relevant transaction hashes;
  • linked parties/accounts;
  • risk indicators.

STR filing is not a declaration of guilt

STR
=
FINANCIAL INTELLIGENCE

NOT

A CONVICTION

FIU-IND may analyse the information and disseminate appropriate intelligence to competent agencies.

Any subsequent criminal investigation must apply the statutory law relevant to the alleged offence.

No tipping-off

The customer-facing explanation for a compliance hold should not improperly reveal:

  • that an STR is being prepared;
  • that an STR has been filed;
  • confidential intelligence-reporting information.

Record Retention: Could the Platform Reconstruct the Transaction Three Years Later?

Transaction records

Section 12 requires records to be maintained so individual transactions can be reconstructed.

Transaction records must ordinarily be retained for at least five years from the date of the transaction.

CDD / identity records

Records concerning:

  • customer identity;
  • beneficial owner;
  • account files;
  • business correspondence;
  • CDD material

must ordinarily be retained for at least five years after the business relationship ends or the account closes, whichever is later.

VDA reconstruction package

For each material transfer, the platform should be able to reconstruct:

CUSTOMER → WALLET → HASH → COUNTERPARTY → TRAVEL RULE → SCREENING → ALERT → DECISION

Do not preserve only the analyst's Excel sheet

Keep source provenance.

For example:

BLOCKCHAIN SOURCE DATA

ANALYTICS OUTPUT

ALERT

INTERNAL CASE

STR.

That allows a later investigator, auditor or court to determine how the conclusion was reached.

Sanctions Screening Is Not a One-Time Onboarding Search

The current VDA framework expects sanctions screening to operate throughout the customer lifecycle.

Important screening moments can include:

  • onboarding;
  • KYC update;
  • change in sanctions lists;
  • wallet transfers;
  • material account changes;
  • alert investigation.

Screen more than the customer name

Depending upon the risk:

  • customer;
  • beneficial owner;
  • director;
  • counterparty;
  • recipient VDA SP;
  • wallet address;
  • blockchain cluster.

False positive vs true match

The system should retain:

  • name screened;
  • list matched;
  • match score;
  • analyst decision;
  • supporting identifiers;
  • reason for clearance or escalation.

FIU-IND Enforcement Under Section 13: Registration Failure Can Become Expensive

Section 13 gives the Director FIU-IND supervisory and enforcement powers concerning reporting-entity obligations.

Available compliance responses include

  • written warning;
  • specific compliance directions;
  • periodic remedial reporting;
  • monetary penalty.

The monetary penalty can range from:

₹10,000 TO ₹1,00,000 FOR EACH FAILURE.

The words “each failure” are important.

Where the regulator identifies:

  • multiple reporting failures;
  • repeated periods;
  • different breached obligations;

the aggregate exposure can become substantial.

Bybit

FIU-IND imposed a total penalty of ₹9.27 crore on Bybit in January 2025 after finding violations concerning PMLA/PML Rules reporting-entity obligations.

Offshore notices

The Ministry of Finance has publicly recorded:

  • nine offshore VDA SP notices in December 2023;
  • blocking-related action for non-compliant URLs;
  • 25 further offshore VDA SP notices in October 2025.

Registration can be denied or cancelled

The registration framework expressly reserves regulatory discretion where the applicant/reporting entity fails to fulfil its PMLA obligations.

The Most Important Legal Distinction: Compliance Failure Is Not the Same as Money-Laundering

This distinction should control both regulatory advice and criminal defence.

Compliance Proposition What It Can Show What It Does Not Automatically Prove
VDA SP did not register Potential reporting-entity non-compliance. That its transactions were proceeds of crime.
KYC was deficient CDD/control failure. That management knew a customer was laundering proceeds.
Travel Rule data missing Transfer-information compliance deficiency. Scheduled offence or criminal origin of the transferred VDA.
STR was not filed Potential reporting/monitoring failure. That officers knowingly participated in Section 3 activity.
Platform processed mixer exposure Potential high-risk control failure. That every asset involved was criminal property.
Records are incomplete Section 12 / compliance and evidentiary weakness. The missing fact automatically against the reporting entity.

What Section 3 requires

A criminal money-laundering theory must independently address:

  • scheduled offence;
  • property derived or obtained from criminal activity relating to that offence;
  • the particular process or activity connected with the proceeds;
  • the accused's relevant conduct;
  • knowledge/assistance/participation where required by the alleged route.

Director liability

Do not argue:

“Company's AML system failed, therefore every director committed PMLA money-laundering.”

Analyse:

  • role;
  • period of office;
  • authority;
  • compliance responsibility;
  • actual knowledge;
  • communications;
  • benefit;
  • transaction involvement;
  • Section 70 where company-offence allegations arise.

The converse

A registered and compliant platform may nevertheless contain transactions involving genuine proceeds of crime.

Compliance systems are designed to detect and report risk.

They are not a statutory certificate that every customer transaction is legitimate.

What Should a VDA SP Do After Receiving an FIU-IND Compliance Notice?

1. IDENTIFY THE LEGAL BASIS
Section 13 inquiry? Registration deficiency? PMLR reporting failure? Guideline breach? 2. PRESERVE THE SYSTEM STATE
Policies, TMS versions, KYC logs, alerts, STR records, Travel Rule logs and blockchain-analysis outputs should not be overwritten. 3. BUILD A REQUIREMENT-BY-REQUIREMENT RESPONSE
Do not send a generic “we maintain world-class AML controls” reply. 4. IDENTIFY THE RELEVANT PERIOD
Which Guidelines/circular/rule applied when the alleged failure occurred? 5. DISTINGUISH DESIGN FAILURE FROM OPERATIONAL FAILURE
Was there no control, or did a valid control fail in one case? 6. RECONSTRUCT THE TRANSACTIONS
Use raw customer, fiat, blockchain, device and alert records. 7. EXPLAIN REMEDIATION WITHOUT MAKING UNNECESSARY ADMISSIONS 8. IDENTIFY WHICH PERSON HELD WHICH COMPLIANCE ROLE
DD, PO, AML analysts, technology teams and business management should not be conflated. 9. ADDRESS OFFSHORE / INDIA NEXUS PRECISELY 10. KEEP REGULATORY DEFENCE SEPARATE FROM ANY CRIMINAL PMLA DEFENCE

Compliance-notice evidence folder

  • FIU registration;
  • application documents;
  • AML policy versions;
  • Board approvals;
  • DD/PO appointment records;
  • risk methodology;
  • KYC specifications;
  • sample onboarding logs;
  • liveness provider logs;
  • bank-verification records;
  • sanctions-screening logs;
  • TMS rules and versions;
  • alert disposition;
  • blockchain analytics;
  • Travel Rule records;
  • STR logs;
  • training records;
  • audit reports;
  • CERT-In audit material;
  • remediation evidence.

2026 FIU-IND VDA Compliance Audit Matrix

Control Question Status
Activity mapping Which of the five notified VDA activities are performed? ___
FIU registration Registration complete and current? ___
Designated Director Formally appointed, empowered and active? ___
Principal Officer India-based, qualified, full-time and adequately resourced? ___
AML policy Current, Board-approved and aligned with 2026 VDA Guidelines? ___
Enterprise risk assessment Documented and updated within required periodicity? ___
Client risk Board-approved classification and periodic review? ___
PAN / ID Verification workflow functional? ___
Liveness Live selfie and liveness evidence captured? ___
Geo / IP Latitude, longitude, timestamp and IP captured? ___
Bank verification Penny-drop/ownership validation functional? ___
Beneficial ownership Natural-person ownership/control identified? ___
PEP / sanctions Onboarding and ongoing screening? ___
EDD Source of funds/wealth and high-risk escalation? ___
Transaction monitoring Documented rules, alerts, audit trail and PO review? ___
Blockchain analytics Wallet-risk and illicit-exposure capability? ___
Travel Rule Originator/beneficiary data obtained and transmitted in time? ___
Unhosted wallets Ownership/counterparty and EDD controls? ___
Mixers / AECs Detection and risk-control framework? ___
STR Alert → investigation → PO decision → filing workflow? ___
Tipping-off Front-line confidentiality controls? ___
Record retention Five-year minimum periods implemented appropriately? ___
Reconstruction Can every transaction be linked to source records? ___
Cybersecurity audit Applicable CERT-In audit/certificate current? ___
Training Role-based AML/VDA training documented? ___
Independent review Control effectiveness tested rather than policy existence only? ___
FIU requests Response log and escalation procedure? ___
Offshore nexus India-facing activity accurately mapped? ___

Ten Compliance Mistakes That Matter in 2026

1. Treating FIU registration as a crypto operating licence

FIU registration concerns the reporting-entity AML framework. It should not be marketed as Government investment approval.

2. Appointing a nominal Principal Officer

A PO without independence, expertise, resources or operational authority creates governance risk.

3. Performing KYC only once

The 2026 framework requires continuing risk assessment and periodic KYC refresh.

4. Identifying the company but not the natural beneficial owner

The corporate name is not the end of Rule 9 analysis.

5. Using only transaction-value thresholds

VDA suspicion is highly behavioural and blockchain-specific.

6. Treating Travel Rule information as a post-transfer compliance clean-up

The identity data architecture is intended to accompany the transfer.

7. Treating every unhosted wallet as criminal

Use enhanced risk analysis rather than replacing evidence with labels.

8. Closing every automated alert without retaining reasons

The regulator should be able to audit why potentially suspicious activity was not reported.

9. Filing weak STR narratives

The report should explain the suspicion and preserve supporting transaction/customer context.

10. Assuming a Section 13 violation proves Section 3 PMLA

Reporting-entity compliance and criminal money-laundering liability are different statutory enquiries.

AI Search / Featured-Snippet Answers

Who must register with FIU-IND as a VDA Service Provider?

A business carrying on the notified VDA activities—such as VDA-fiat exchange, VDA-to-VDA exchange, transfer, custody/control services or specified issuer-related financial services—can fall within the PMLA reporting-entity framework and must assess FIU-IND registration.

Do offshore crypto exchanges have to register with FIU-IND?

The Government's stated position is activity-based: VDA SP obligations are not contingent upon physical presence in India. An offshore provider serving the Indian market can therefore be required to register and comply.

What changed in FIU-IND's 2026 VDA Guidelines?

The 8 January 2026 framework consolidates registration and governance requirements and strengthens operational KYC, including liveness/geo-data controls, risk classification, monitoring, sanctions screening, Travel Rule compliance and reporting expectations.

What is the VDA Travel Rule in India?

It requires prescribed identifying information concerning the originator and beneficiary to accompany VDA transfers so that value does not move between providers without attributable customer data. The current Indian VDA framework is reported as applying the requirement without a de minimis transfer threshold.

When must a crypto exchange file an STR?

When the Principal Officer is satisfied that an attempted or completed transaction is suspicious under the applicable framework. The FIU reporting framework requires prompt reporting and ordinarily no later than seven working days after that determination.

How long must a VDA SP keep transaction records?

Transaction records are ordinarily retained for at least five years from the transaction date, while customer/beneficial-owner identity and related account records are retained for at least five years after the relationship ends or account closes, whichever is later.

Does failure to register with FIU-IND prove money-laundering?

No. Non-registration can constitute reporting-entity non-compliance and trigger Section 13 enforcement. A criminal Section 3 case must separately establish proceeds of crime and the accused's legally relevant process/activity connected with those proceeds.

Frequently Asked Questions

Are crypto exchanges reporting entities under PMLA?

Covered VDA Service Providers carrying on the notified activities fall within India's PMLA reporting-entity framework.

Is FIU-IND registration mandatory?

Yes for covered VDA SPs. FIU-IND's registration circular expressly treats registration as a pre-requisite for reporting-entity compliance.

Does the company have to be incorporated in India?

Not necessarily. Government enforcement policy states that VDA obligations are activity-based and not contingent on physical presence in India.

Is FIU registration a licence to operate cryptocurrency in India?

It should principally be understood as AML/CFT reporting-entity registration. It is not a blanket Government endorsement of every product, token, investment or business model.

Who is the Principal Officer?

The PO is the senior operational AML/CFT compliance officer responsible for matters including alert governance, suspicious-transaction reporting and FIU interaction. The 2026 framework requires the PO to be based in India.

Can the Designated Director and Principal Officer be treated as the same compliance function?

No. The 2026 Guidelines distinguish overall governance/accountability of the DD from implementation and reporting functions of the PO.

Is live-selfie KYC required in 2026?

The current VDA guidance introduces live-selfie/liveness and associated onboarding data such as geolocation, time and IP information as part of strengthened VDA customer identification.

What is penny-drop verification?

It is a bank-account verification mechanism used to check account ownership/operational status against the customer's onboarding data.

Does a VDA SP need to identify a corporate customer's beneficial owner?

Yes. PML Rules require identification and verification of the ultimate natural beneficial owner using the applicable ownership/control tests.

What is the beneficial-owner threshold for a company?

Under the current PML Rules the controlling-ownership test for a company is more than 10% of shares, capital or profits, together with a separate control-through-other-means test.

How often should high-risk customer KYC be updated?

The 2026 VDA framework is reported as requiring at least six-monthly KYC refresh for high-risk clients and at least annual refresh for other clients, subject to the precise applicable guidance and circumstances.

What information travels under the crypto Travel Rule?

The required data set includes identifying information concerning the originator and beneficiary, wallet/account identifiers and transaction information so that the transfer remains attributable to identifiable parties.

Is there a minimum amount below which the Travel Rule does not apply?

The current 2026 FIU-IND VDA implementation is reported as having no de minimis VDA-transfer threshold. Platforms should verify the current technical schema and FIU implementation requirements when deploying their systems.

Are self-custody wallets illegal?

No such blanket proposition should be made. Unhosted wallets create greater AML traceability risk and therefore require enhanced monitoring and counterparty/ownership assessment.

Can a VDA SP deal with mixers?

The updated framework treats mixers/tumblers and anonymity-enhancing mechanisms as serious AML risk and expects controls designed to identify and prevent or appropriately mitigate such activity.

Does every transaction alert require an STR?

No. An alert triggers investigation. The PO should determine reportability and preserve the reasoning for either filing or closing the alert.

Is there a minimum transaction value for an STR?

No fixed value threshold governs suspicion. A small attempted transaction can still be suspicious.

How soon should an STR be filed?

The FIU/PMLR framework requires prompt filing and ordinarily no later than seven working days after the Principal Officer is satisfied that the transaction is suspicious.

Can a customer be told that an STR has been filed?

Compliance teams must observe applicable confidentiality and anti-tipping-off requirements and should not improperly disclose the existence or contemplated filing of an STR.

How long must crypto transaction records be retained?

At least five years from the transaction date under Section 12's transaction-record framework.

Can FIU-IND fine a VDA SP?

Yes. Section 13 permits compliance inquiries, warnings, directions, remedial reporting requirements and monetary penalties, including ₹10,000 to ₹1 lakh for each qualifying failure.

What happened to Bybit?

FIU-IND imposed a total ₹9.27 crore penalty in January 2025 for identified failures relating to its PMLA/PML Rules reporting-entity obligations.

Does an FIU penalty mean the company committed money-laundering?

No. A Section 13 reporting-entity penalty and a Section 3 criminal prosecution concern different legal questions. Criminal money-laundering liability requires separate proof of the statutory ingredients.

Official Legal and Regulatory Sources

Related Detailed Research

Related Delhi legal guides

Proceeds of crime analysis · Predicate and scheduled offences · Money-laundering defence guide

Document-first assessment

Start with the latest legal instrument and next deadline

Organise the current summons or order, case identifiers, a dated chronology and the transaction or property record before seeking case-specific advice.

Prepare for consultation