Understanding the New Regulatory Landscape
Since 2023, all VDA service providers—including exchanges, wallet providers, and custodians—have been designated as 'Reporting Entities' under the Prevention of Money Laundering Act, 2002 (PMLA). This move places the crypto industry under the same anti-money
laundering (AML) and counter-financing of terrorism (CFT) obligations as traditional financial institutions like banks. The Financial Intelligence Unit-India (FIU-IND) acts as the central regulator for this purpose. In January 2026, the FIU-IND released updated and more stringent guidelines, consolidating previous rules and making it clear that robust compliance is non-negotiable for any platform operating in India, even for offshore exchanges serving Indian users.
The First Step: Mandatory FIU-IND Registration
Before any other checks can be implemented, your exchange must be registered with the FIU-IND through its FINgate portal. This is not a business license, but a mandatory registration as a reporting entity. Operating without it is a direct violation of the PMLA and can lead to severe penalties, including monetary fines and having your platform's URL and app blocked in India. The registration process requires submitting detailed information about your company structure, beneficial ownership, and key personnel, including the appointment of a Designated Director and a Principal Officer who serves as the main point of contact with the FIU.
Building a Robust KYC Framework
Know Your Customer (KYC) is the foundation of FIU compliance. Anonymous or fictitious accounts are strictly forbidden. The 2026 guidelines have enhanced KYC requirements significantly. Exchanges must implement a multi-layered verification process that includes not only PAN and a secondary ID but also advanced technological checks. Mandatory components now include capturing a live selfie of the user with liveness detection to prevent fraud, recording the geo-coordinates (latitude and longitude) at the time of onboarding, and performing a 'penny-drop' verification to confirm the user's bank account.
Implementing Transaction Monitoring Systems
Once a user is onboarded, their activity must be monitored continuously. Exchanges are required to have robust systems in place to detect unusual or suspicious transaction patterns. This isn't just about flagging large amounts; it's about identifying behaviour that is inconsistent with a customer's known profile. High-risk scenarios that demand extra scrutiny include frequent transfers to unrelated wallets, transactions involving unhosted wallets, using mixers or tumblers, and rapid conversions between different digital assets with no clear economic purpose. Having an automated system that generates alerts for such activities is now a core operational requirement.
Mastering Reporting Obligations
Detecting suspicious activity is only half the battle; reporting it is the critical next step. The primary report is the Suspicious Transaction Report (STR), which must be filed with the FIU-IND promptly whenever a transaction gives rise to suspicion, regardless of the amount involved. Exchanges must also report all cross-border wire transfers exceeding ₹5 lakhs and any receipts by non-profit organisations greater than ₹10 lakhs. It is crucial to ensure these reports are accurate and filed within the prescribed timelines. Critically, staff are prohibited from 'tipping off' a customer that their transaction has been reported to the FIU.
The Importance of Record-Keeping
Your compliance duties don't end after a report is filed. Under the PMLA, all reporting entities must maintain records of all transactions and customer identification data for a period of five years from the date the transaction or business relationship ends. These records must be comprehensive, secure, and readily available should the FIU-IND or another law enforcement agency request them for an audit or investigation. This includes not just KYC documents but also transaction hashes, wallet addresses, and IP logs associated with user activity.
















