Direct Tax
Consulting
ESG Advisory
Indirect Tax
Growth Advisory
Internal Audit
BFSI Audit
Industry Audit
Valuation
RBI Services
SEBI Services
IRDA Registration
AML Advisory
IBC Services
Recovery of Shares
NBFC Compliance
IRDA Compliance
Finance & Accounts
Payroll Compliance Services
HR Outsourcing
LPO
Fractional CFO
General Legal
Corporate Law
Debt Recovery
Select Your Location
On January 8, 2026, FIU-IND released new AML (Anti-Money Laundering) and CFT (Countering the Financing of Terrorism) Guidelines for Virtual Digital Asset Service Providers (VDASP). These guidelines create an important regulatory framework for crypto-related businesses operating in India.
Earlier, the rules were simple, but now each VDASP will have to develop a more well-organized and technology-based compliance system. Crypto businesses will also have to operate with the AML and CFT rules like banks and other regulated financial institutions.
In this blog, we will discuss the key points of the 2026 FIU-IND guidelines, updated as on 8 January, 2026. You will also know who is covered by these rules, the laws based on these guidelines, and what they mean for businesses.
The FIU-IND AML and CFT Guidelines 2026 are new compliance guidelines for Virtual Digital Asset Service Providers (VDASP). These guidelines reduce the risk of money laundering, terrorist financing, and other financial crimes.
These guidelines were released by the Financial Intelligence Unit-India (FIU-IND) on 8 January 2026. They explain how to comply with the PMLA and PMLR rules.
Now, businesses also have to follow those rules properly. For example, doing KYC of the customer, completing Customer Due Diligence (CDD), monitoring transactions, sending suspicious transaction reports when necessary, and maintaining all records properly. After these guidelines, compliance in the crypto business will have to be given more importance.
These guidelines by FIU-IND apply to organizations and businesses that provide virtual digital asset-related services. It is not the location of the organization, but the type of activities they are conducting.
The entities that fall under this guideline are:
Even when an entity is registered outside India and they provide notified VDA services to Indian customers, it will also have to comply with the FIU-IND rules. So, this guideline is called an activity-based compliance framework.
FIU-IND’s AML and CFT Guidelines of 2026 are based on multiple laws and government notifications. These laws set out the compliance, reporting, and AML/CFT responsibilities of Virtual Digital Asset Service Providers in India.
Through this legal framework, FIU-IND seeks to ensure that VDA services operating in India are operated in accordance with international AML and CFT standards.
(4.8) 15,000+ clients served
According to Section 2(47A) of the Income-tax Act in India, Virtual Digital Asset (VDA) means a digital asset that can be created, stored, bought, or transferred electronically. This includes digital assets like cryptocurrencies, some types of tokens, and NFTs (Non-Fungible Tokens). In addition, digital assets that the government may notify in the future may also come under the scope of the VDA.
However, the Digital Rupee (e₹) or Central Bank Digital Currency (CBDC) does not fall under these guidelines. It is the government digital currency issued by the Reserve Bank of India (RBI).
These Guidelines of FIU-IND apply to the purchase and sale of VDA, exchange from one VDA to another, VDA transfer, custody services, and financial services related to the issue of VDA.
As per the new guidelines of FIU-IND, a person carrying on notified VDA activities and falling within the PMLA framework must comply with FIU-IND registration requirements before commencing those activities. Without this registration, running VDA-related, notified services is not permitted as per the law.
The following steps are followed during registration:
Documents that may be required in general:
Through this registration, FIU-IND ensures that the organization is ready to comply with the required AML/CFT rules. When an organization provides such services without registration, then regulatory action can be taken against it under PMLA.
FIU-IND wants every VDASP to have a strong compliance system within it. So, not only technology, but also the division of responsibilities within the organization is important. Two important positions are mandatory.
These include:
Such a governance framework provides clarity to the organization’s responsibilities. It also increases the credibility of the organization with regulators and reduces compliance risks.
As per the FIU-IND Guidelines, each VDASP must develop a written AML, CFT, and CPF Policy. This policy should clearly outline the organization’s compliance measures, risk management, and reporting processes. It is not enough to just create a policy; it must be updated regularly.
A good policy usually includes the following:
The organization can work according to the same rules as such a policy. In addition, it helps to show the necessary documents during the inspection or audit of the FIU-IND.
Customer Due Diligence (CDD) is one of the most important parts of the FIU-IND Guidelines. It verifies the identity of the customer and provides services properly, understanding the level of risk. CDD starts at the time of new customer onboarding. Later, it has to be updated again when necessary.
The following issues are usually addressed during CDD:
Through this process, the institution can understand the risk of the customer in advance. This helps to identify suspicious transactions and comply with AML/CFT rules.
In some cases, regular CDD is not sufficient; Enhanced Due Diligence (EDD) is required. More detailed information about the customer is collected and verified through this.
EDD is applicable to the following cases:
The Tasks performed during EDD:
If this additional verification cannot be completed or satisfactory information is not obtained, the institution should terminate the business relationship with that customer and submit an STR to FIU-IND.
As per the FIU-IND Guidelines, each VDASP is required to regularly monitor the customer’s transactions. Not only large transactions, but also any unusual or suspicious activity should be monitored. Many organizations are now using automated monitoring systems.
This process usually includes:
In addition, the guidelines also have clear instructions on travel rules. It helps to store the necessary information of the sender and recipient during VDA transfers.
Travel Rules require the following information to be stored:
As a result of this rule, each transaction’s information can be easily found. It also helps to provide the necessary information quickly during investigations.
As per FIU-IND Guidelines, sanctions screening is mandatory before onboarding a customer and during the transaction. This checks whether an individual or entity is on the banned list.
During Sanctions Screening, the following points are usually followed:
If a transaction seems suspicious, then a Suspicious Transaction Report (STR) must be submitted to FIU-IND.
STR usually contains the following information:
The information must be correct and complete when submitting the STR. At the same time, the institution or employees can never inform the customer that an STR has been filed against him. This is called Prohibition on Tipping Off.
As per the FIU-IND Guidelines, every VDASP is required to maintain customer and transaction-related information for a specified period of time. Maintaining proper records is very useful during investigations and audits.
The organization generally has to ensure the following things:
Having a good record-keeping system helps to maintain compliance. It is also possible to provide information quickly when the regulatory agency asks for it.
FIU-IND has considered certain Virtual Digital Asset (VDA) activities to be at a higher risk. In these cases, institutions need to be extra vigilant and follow stronger compliance measures.
The above activities may pose a relatively high risk of money laundering and other financial crimes. So, FIU-IND has asked institutions to place greater emphasis on risk assessment, additional due diligence, and regular monitoring. More caution has been instructed to follow the use of privacy-focused crypto assets, mixers, and Tumblers.
After the 2026 Guidelines of FIU-IND, compliance is no longer just a legal formality. Now it has become an important part of an organization’s regular business operations. So, organizations need to build a strong compliance system from the beginning.
The issues that are gaining more importance because of this change:
Organizations that prioritize these issues from the beginning will be able to operate their business with less risk in the future.
Complying with the new FIU-IND Guidelines may not be easy for many organizations. Especially in the case of new virtual digital asset service providers, proper planning and documentation are very important. In this case, Enterslice provides the necessary compliance support.
Our Services:
FIU-IND’s AML and CFT Guidelines 2026 have brought a significant change in the crypto compliance system in India. Now virtual digital asset service providers will have to build a stronger compliance system across all areas- governance, customer onboarding, AML, CFT, CPF, transaction monitoring, reporting, and record keeping.
Organizations that adhere to these rules from the start will be able to reduce regulatory risks. It will also increase the credibility of the business and help to work with banks and other financial institutions.
Enterslice supports Virtual Digital Asset Service Providers with professional assistance to understand the FIU-IND rules, create the right compliance framework, and keep pace with the changing regulatory environment. Businesses can operate more securely in the long term.
The FIU-IND AML and CFT Guidelines 2026 are new compliance guidelines for Virtual Digital Asset Service Providers (VDASPs). This reduces the risk of money laundering, terrorist financing, and other financial crimes. According to these guidelines, organizations are required to properly follow issues such as KYC, customer due diligence (CDD), transaction monitoring, reporting, and recordkeeping.
Organizations that provide services related to Virtual Digital Asset (VDA) are required to comply with these guidelines. These include crypto exchanges, wallet service providers, custodians, NFT platforms, token issuers, brokers, and Web3 service providers. This rule may also apply when an organization registered outside India also provides these services to Indian customers.
Yes. As per the FIU-IND Guidelines, registration is mandatory before providing any notified VDA services. An application must be made through the FINGate Portal. After submitting the required documents, an FIU RE-ID is issued when everything is in order. Operating the service without registration may lead to regulatory action under PMLA.
Customer Due Diligence (CDD) is a process of verifying the identity and risk of the customer. It involves collecting KYC, PAN verification, identity card verification, and other necessary information. If the customer is an institution, then beneficial ownership is also verified. Through this process, the institution can reduce the risk of suspicious activities.
When a customer is considered to be at high risk, Enhanced Due Diligence (EDD) is required. This may apply to Politically Exposed Persons (PEPs), non-profit organizations, customers from high-risk countries, or suspicious transactions. During EDD, additional information is verified, and transactions are subject to increased scrutiny.
According to the Travel Rule, certain important information of the originator and beneficiary during the transfer of virtual digital assets must be stored and shared when necessary. This may include a name, wallet address, and other necessary information. This rule aims to make transactions more transparent and reduce the flow of illicit money.
According to the FIU-IND Guidelines, customer identity and important records related to transactions are generally required to be retained for at least 5 years. These records must be kept securely so that they can be easily viewed by regulatory agencies or investigative authorities when necessary. Proper record keeping is an important part of compliance.
If a transaction is suspicious or there is a risk of money laundering or terrorist financing, a Suspicious Transaction Report (STR) must be submitted to the FIU-IND. The STR contains the customer's KYC information, wallet address, transaction details, and the reason for the suspicion. The customer cannot be informed about this report.
FIU-IND has considered certain activities to be riskier. These include ICOs, ITOs, Unhosted wallets, unregistered VDASPs, privacy-focused crypto assets, and the use of mixers or tumblers. In these cases, the institution is required to follow additional verification, regular monitoring, and stronger compliance measures.
Enterslice supports Virtual Digital Asset Service Providers with FIU-IND registration, AML/CFT policy preparation, compliance gap assessment, KYC framework, risk assessment, and regulatory reporting. We also provide audit preparation and regular compliance advisory. We help organizations operate their businesses in compliance with regulations and reduce compliance risks.
On January 8, 2026, FIU-IND released new AML (Anti-Money Laundering) and CFT (Countering the Fi...
Mauritius has positioned itself as one of the most promising international financial centres by...
The UAE has become a global centre for media, digital, and creative enterprises with the increa...
Oman has positioned itself as an important energy centre in the Middle East region, p...
Alternative Investment Funds (AIFs) have become a popular investment vehicle in India. An AIF i...
Are you human?: 5 + 1 =
Easy Payment Options Available No Spam. No Sharing. 100% Confidentiality
The Prevention of Money Laundering Act, 2002 (PMLA), and the Prevention of Money Laundering (Maintenance of Records...
07 Jul, 2023
The main aim of criminal activity is to generate profit. The individuals or groups involved in such crime try to fi...
06 Jul, 2023