Financial Intelligence Unit

FIU India Registration for VASPs in 2026: Complete Step-by-Step Compliance Guide

FIU India Registration

FIU-IND, or Financial Intelligence Unit – India, is an important financial intelligence agency in India. It receives, analyzes, and disseminates information related to suspicious financial transactions to the relevant authorities as required.

If a VDA service provider falls under the PMLA framework, then it has to register with FIU-IND. Once the registration is completed, the business acts as a reporting entity.

This does not mean just getting a registration number. The business has to verify the identity of the customer. It has to understand the beneficial owner. It is also important to monitor transactions, identify suspicious transactions, and report them when necessary.

However, one thing needs to be made clear. FIU-IND registration is not a general crypto license. It does not provide approval for the solvency of any token, investment product, or business.

Tax, GST, cybersecurity, consumer protection, and other applicable compliance requirements may also be required separately.

What Is FIU-IND Registration for VASPs?

FIU-IND, or Financial Intelligence Unit – India, is an important financial intelligence agency in India. It receives, analyzes, and disseminates information related to suspicious financial transactions to the relevant authorities as required.

If a VDA service provider falls under the PMLA framework, then it has to register with FIU-IND. Once the registration is completed, the business acts as a reporting entity.

This does not mean just getting a registration number. The business has to verify the identity of the customer. It has to understand the beneficial owner. It is also important to monitor transactions, identify suspicious transactions, and report them when necessary.

However, one thing needs to be made clear. FIU-IND registration is not a general crypto license. It does not provide approval for the solvency of any token, investment product, or business.

Tax, GST, cybersecurity, consumer protection, and other applicable compliance requirements may also be required separately.

Who Needs FIU-IND Registration in India?

The key issue in FIU-IND registration is the service the business provides. It cannot be decided by looking at the company name, incorporation location, or “Web3 platform” identity alone.

As per the PMLA framework, certain VDA-related activities may fall under the Reporting Entity framework for a business.

VDA ActivityWhat It Covers
VDA–Fiat exchangeExchange between virtual digital assets and fiat currencies
VDA–VDA exchangeExchange between different forms of VDAs
VDA transferTransfer of VDAs on behalf of another person
Safekeeping/administrationCustody of VDAs or instruments enabling control
Issuer-related financial servicesFinancial services connected with an issuer’s offer and sale of a VDA

This scope may include exchanges, custodial platforms, brokers, wallet services, OTC businesses, launchpads, and other VDA platforms.

So, it is not right to assume that registration is not required just because a business calls itself a “technology company”.

Do Offshore VASPs Serving Indian Users Need to Register?

Just because a VASP is incorporated abroad does not mean that it is outside the Indian AML framework. In serving Indian users, an India nexus may be created with the business. So, it is important to assess whether an offshore platform needs registration or not at the outset.

Several factors should be considered during this assessment:

  • Are there Indian customers?
  • Are INR-related services being provided?
  • Is India-focused marketing being done?
  • Is the platform available to Indian users?
  • Are there any local business arrangements?
  • How are transaction and payment flows being managed?

It is advisable to prepare a written India-nexus assessment before launching or continuing service in India. In addition, whether direct FIU-IND registration or an Indian operating structure is more appropriate should also be assessed separately.

The 7-Step FIU-IND Registration Process for VASPs in 2026

Step 1: Determine Applicability and Map the Business Model

Before starting registration, VASPs need to clearly map their business model. It is necessary to document which VDA activities are being carried out, who the customers are, and which entities are providing the service.

Important factors to look at:

  • Indian customer exposure
  • Custody and transaction flow
  • Role of group companies
  • Relevant products and counterparties

This scope assessment should be done before submitting the application. This reduces the possibility of clarification and compliance gaps later.

Step 2: Appoint the Designated Director and Principal Officer

The roles of the Designated Director and Principal Officer are different for FIU-IND compliance. The responsibilities of both need to be clearly defined.

RolePrimary Responsibility
Designated DirectorOverall responsibility for PMLA/AML compliance
Principal OfficerDay-to-day AML operations, reporting, and FIU-IND communication

Both should be formally appointed, and necessary details should be communicated to FIU-IND. The principal officer mustn’t be just appointed on paper. He/She should have sufficient authority, knowledge, and access. It is good to have a continuity plan for any change or absence of the officer.

Step 3: Build the AML/CFT Framework Before Applying

This is the most important preparation stage of registration. The VASP’s AML/CFT framework should be built according to its actual business and the 2026 VDA guidelines. Just copying the policy of another business and using it will not work.

READ  Financial Intelligence Unit Registration – A mandate for Financial Institutions

The framework should include:

  • Enterprise-wide risk assessment
  • Customer Due Diligence and Enhanced Due Diligence
  • Beneficial ownership identification
  • PEP and sanctions screening
  • VDA-specific transaction monitoring
  • Blockchain analytics
  • Self-hosted wallet and high-risk exposure assessment
  • Applicable Travel Rule processes
  • Record preservation
  • Employee training
  • Independent testing and management oversight

Step 4: Prepare and submit the FIU-IND Application

After the AML framework is ready, the necessary information and documents for the application need to be prepared. The general filing process has several key steps:

  • Complete the reporting entity enrollment/application process.
  • Provide corporate and ownership information.
  • Provide details of the Designated Director and Principal Officer.
  • Upload the necessary supporting documents.
  • Submit declarations and authorizations.
  • Respond to clarifications from the FIU-IND promptly.

It is essential that the information in the application matches corporate records and AML policies. Having different information in different documents can create unnecessary questions.

Step 5: Demonstrate Reporting and Monitoring Readiness

Compliance readiness does not end with just submitting the application. The VASP’s reporting and monitoring system should be in a working state.

This may include:

  • Transaction monitoring
  • Alert generation
  • Investigation and case management
  • Sanctions screening
  • Blockchain analytics
  • Applicable Travel Rule processes
  • STR decision-making
  • FINnet 2.0 reporting readiness
  • Reporting acknowledgements and investigation records storage

Compliance is not just about purchasing screening or monitoring software. The real issue is who will review the alert once it is created, how the investigation will be conducted, and how the final decision will be recorded.

Step 6: Integrate Tax, Cybersecurity and Other Compliance Requirements

FiU-IND registration does not end a VASP’s other compliance obligations. Businesses need to create an integrated compliance framework.

This may include issues such as VDA taxation, the applicable 1% TDS framework, GST assessment, CERT-In requirements, data and transaction record retention, cyber incident reporting, privacy, and customer disclosures.

Banking and payment of partner requirements also need to be considered. It is more effective to have these under a single operational framework rather than having separate compliance checklists.

Recurring compliance starts after FIU-IND registration. So, a business should have a clear compliance calendar.

This should include the following regularly:

  • Ongoing transaction monitoring
  • Sanctions and wallet screening
  • STR review and filing
  • Periodic risk assessment
  • AML policy updates
  • FIU-IND officer details update
  • Employee training
  • Independent testing or audit
  • Board-level compliance reporting
  • Periodic review of new products, jurisdictions, and transaction flows

So, compliance is not just a policy document. It becomes part of the business’s daily operating process.

FIU-IND Registration Document Checklist

It is very important to organize the necessary documents before FIU-IND registration. If the documents are incomplete or there is different information in different places, clarification may be required. So, it is better to keep corporate, ownership, AML, and reporting-related records in an organized data room in advance.

Document CategoryKey Documents/Information
CorporateIncorporation documents, constitutional documents, registered-office details
TaxPAN, TAN, and applicable GST information
OwnershipDirectors, shareholders and beneficial ownership information
GovernanceBoard resolution, authorization, and officer appointments
OfficersDesignated Director and Principal Officer identification/details
BusinessBusiness model, products, VDA activities and transaction flows
AML/CFTKYC/AML policies and enterprise-wide risk assessment
TechnologyTransaction monitoring, screening and blockchain analytics framework
ReportingFINnet 2.0/reporting readiness and internal reporting procedures
Compliance evidenceTraining, testing and relevant audit/assessment records

FINnet 2.0 and VASP Reporting Obligations

Reporting compliance is an important responsibility after receiving FIU-IND registration. FINnet 2.0 is linked to the financial intelligence reporting process of the Reporting Entity. So, VASPs need to have accurate transaction data, customer information, and investigation records.

The key reporting categories include:

ReportBroad PurposeKey Compliance Point
STRSuspicious transactions/attempted transactionsPrompt investigation and filing
CTRPrescribed cash transactionsPeriodic reporting within applicable timelines
CBWTRQualifying cross-border wire transfersPeriodic reporting where applicable
NTRQualifying NPO transactionsReporting where applicable

Each report should be based on reliable source data. Complete necessary validation before filing. Retain the submission acknowledgement.

Even if there is no reportable transaction, it is good to keep evidence of internal review. Even if there is “zero reporting”, there should be an internal compliance trail to show the business.

In the case of suspicious transactions, the applicable timeline is to file an STR within seven working days after confirming entity suspicion.

What do the 2026 AML/CFT Guidelines Change for VASPs?

The updated AML/CFT Guidelines for 2026 have shifted the compliance approach of VDA businesses towards a more practical and technology-driven one. It is no longer enough to just have a policy document in place. How the business’s actual systems and controls are working is also important.

Key changes include:

●      Technology-enabled AML controls: Greater emphasis on identifying and monitoring risk using automated tools and technology.

●      Advanced VDA risk assessment: Assessing VDA-specific risks in addition to customer, product, geography, and transaction.

READ  FIU-IND AML & CFT Guidelines 2026: What Every Crypto Business in India Must Know

●      Blockchain analytics: Using appropriate analytics to understand wallet and transaction activity.

●      Self-hosted wallet risk management: Properly assessing the risk of transactions with self-hosted or Unhosted wallets.

●      Travel Rule implementation: Having the necessary information-handling processes in place for applicable VDA transfers.

●      Stronger transaction monitoring: Measures to quickly identify unusual activity.

●      Better evidence: Maintain a proper audit trail of investigations, alerts, and decisions.

●      Greater accountability: Ensure compliance responsibilities of the designated director and principal officer are effectively enforced.

●      Offshore VASP scrutiny: Increased scrutiny of the compliance exposure of offshore platforms serving Indian users.

FIU-IND Post-Registration Compliance

Business compliance work does not end after receiving FIU-IND registration. Rather, regular compliance begins here. Registered VASPs are required to keep their corporate and compliance information updated.

Key responsibilities include:

●      Maintain designated director and principal officer details.

●      Conduct Customer Due Diligence and Enhanced Due Diligence.

●      Conduct regular transaction monitoring.

●      Identify suspicious activity and file STRs where applicable.

●      Maintain necessary customer and transaction records.

●      Continue sanctions and relevant wallet screening.

●      Periodically review enterprise-wide risk assessment.

●      Provide regular training to the compliance team.

●      Conduct independent testing, review, or audit.

●      Maintain timely communication with FIU-IND when necessary.

Even if a new product, new country, or new transaction flow is added, the compliance framework should be reviewed. Because if the business changes, the risk profile can also change. So, it is very important to keep the compliance calendar active after receiving the registration certificate.

Common Mistakes That Delay FIU-IND Registration or Create Risk

Some common mistakes during FIU-IND registration can create big compliance problems for the business later. So, it is better to avoid them from the beginning.

  • Applying before the AML framework is created: Just filling out the form does not prove compliance with readiness.
  • Using a generic AML policy: It is necessary to have a VDA-specific risk policy.
  • Considering offshore incorporation as an exemption: If there are Indian users, an India nexus can be created.
  • Not giving sufficient authority to the principal officer: If there is responsibility but there are no necessary resources, it can be a problem.
  • Keeping blockchain analytics and transaction monitoring separate: An effective connection between the two systems is required.
  • Creating a policy only for travel rules: If there is no technical process in reality, the policy is not enough.
  • Mismatch between corporate and compliance information: This can increase confusion.
  • Considering registration as final compliance: Regular obligations remain even after approval.
  • Ignoring tax, cyber, and reporting requirements: These are also part of the wider compliance framework.
  • Not keeping investigation records: Evidence of an alert being issued and a decision being made is needed.

What Happens If a VASP Gets FIU-IND Compliance Wrong?

A serious gap in FIU-IND or PMLA compliance may not be the subject of a single warning. Depending on the situation, the business may face a variety of regulatory and commercial impacts.

  • Monetary penalties: There may be applicable penalties under the PMLA framework.
  • Remedial directions: The regulatory authority may ask for corrective action.
  • Greater scrutiny: The business may be subject to further compliance review.
  • Digital restrictions: Action may be taken on the website or digital channel in appropriate enforcement circumstances.
  • Banking difficulties: Problems may arise with banking or payment partners.
  • Investor concerns: Investors and counterparties may seek additional due diligence.
  • Higher remediation cost: It may take more time and money to fix controls later.

So, compliance failure does not only create penalties. It can also impact business continuity and overall business value.

FIU India Registration Readiness Checklist for VASPs

VASPs can verify their compliance with this checklist. If there are any gaps, it is better to fix them before submission.

●      Readiness Area Ready

●      VDA activity and India nexus mapped

●      Appropriate entity structure identified

●      Designated Director appointed

●      Principal Officer appointed

●      AML/CFT policy approved

●      Enterprise-wide risk assessment completed

●      KYC/EDD and beneficial ownership control operational

●      Sanctions and blockchain screening implemented

●      Transaction monitoring operational

●      FINnet 2.0 reporting process tested

●      Record-retention framework established

●      Post-registration compliance calendar created

This checklist can also be useful for future ongoing compliance.

How Can Enterslice Help with Compliance?

Viewing FIU-IND registration as just a filing service can leave out many important compliance areas. Enterslice can support VASPs in understanding their business model and risk profile, as well as in building broader AML/CFT readiness beyond registration.

READ  Does India’s FIU Ban Affect Your Crypto Investment?

Our Services:

●      FIU-IND applicability and India-nexus assessment

●      VDA activity mapping

●      Entity and governance documentation

●      Designated Director and Principal Officer support

●      AML/CFT policy preparation

●      Enterprise-wide AML risk assessment

●      KYC, EDD, sanctions and transaction-monitoring framework

●      FIU-IND application and clarification support

●      FINnet 2.0 reporting readiness

●      Post-registration compliance support

●      Periodic AML review, training and AML audit readiness

●      Coordination with tax, GST, and cybersecurity compliance

This can help to better organize the business’s ongoing compliance structure, in addition to registration.

Conclusion

India’s VDA compliance environment is no longer limited to registration alone. A VASP needs to understand its scope and India nexus at the outset. This is followed by proper governance, AML/CFT controls, transaction monitoring, and reliable reporting infrastructure.

Offshore VASPs should assess their exposure to Indian users separately. It is not right to assume that just because a company is registered abroad, it is exempt from Indian AML obligations.

A good compliance model requires proper coordination between legal, compliance, technology, tax, and operations teams. Enterslice can support businesses at various stages of AML compliance, starting from FIU-IND registration to ongoing AML compliance.

What is FIU-IND registration for VASPs?

Through FIU-IND registration, eligible VDA service providers come under the AML/CFT reporting framework of India’s PMLA. After registration, the business acts as a reporting entity. So, customer due diligence, beneficial ownership verification, transaction monitoring, suspicious transaction reporting, record retention, and compliance governance are required to be maintained. However, FIU-IND registration is not a general cryptocurrency license, and it is not an approval of any token or investment product.

Which VASPs need FIU-IND registration in India?

VASPs that provide specific services such as VDA-to-fiat exchange, VDA-to-VDA exchange, VDA transfer, custody, or administration may need FIU-IND registration. VDA exchanges, custodial platforms, brokers, and some Web3 businesses may also fall under this framework. However, the name of the business alone cannot be used to decide.

Does an offshore crypto exchange serving Indian users need FIU-IND registration?

Just because a company is registered abroad does not mean that a crypto exchange is outside the AML framework of India. An India nexus can be created if it serves Indian customers, has an INR-related facility, or has an India-focused business arrangement. The exact requirement depends on the business model. So, it is better to conduct an India-nexus assessment before launching or continuing a service in the Indian market and seeking professional legal advice if necessary.

Is FIU-IND registration a crypto license in India?

No, FIU-IND registration is not a comprehensive crypto license. It aims to bring qualifying VDA service providers under the AML/CFT reporting framework of PMLA. Registration does not approve any token, provide a solvency guarantee, or certify a custody model. Businesses will need to assess tax, GST, cybersecurity, data protection, consumer, and other applicable compliance requirements separately.

Who is a Designated Director and Principal Officer?

The Designated Director is responsible for the overall PMLA compliance framework of the Reporting Entity. The principal officer handles day-to-day AML operations, reporting, and regulatory communication with the FIU-IND. Both need to be formally appointed, and their roles clearly documented. The principal officer should have sufficient knowledge, authority, and relevant data access. It is also important that he/she can communicate with the FIU-IND quickly and accurately.

What documents are required for FIU-IND VASP registration?

FIU-IND registration may generally require incorporation and constitutional documents, ownership and beneficial ownership details, tax information, board resolution, designated director and principal officer details, and business model information. In addition, AML/KYC policies, risk assessment and reporting, and monitoring readiness documents are also important. The exact documents may depend on the applicant’s structure and activities. It is important that the information in all documents be consistent with each other.

What are the main post-registration obligations of a VASP?

After receiving registration, the VASP’s compliance responsibility continues. The business has to continue customer due diligence, beneficial ownership checks, transaction monitoring, sanctions screening, and suspicious transaction reporting. The necessary records must also be kept as per the prescribed requirements. In addition, the risk assessment needs to be reviewed regularly; employees trained, and reporting systems maintained. It is also important to update the FIU-IND in applicable cases if there is a relevant change in the corporate or compliance structure.

What is the Travel Rule and why is it important for VASPs?

Through the Travel Rule, there is a system to collect and transmit specific originators and beneficiary information in the case of qualifying VDA transfers. This cannot be done simply by writing it down in the compliance policy. VASP technology and compliance teams need to work together. Clear processes are required for data collection, transmission, incomplete information, counterparty handling, exception management, and record preservation. Therefore, Travel Rule compliance should be properly built into the product workflow.

How long does FIU-IND registration take for a VASP?

There is no fixed universal timeline for FIU-IND registration. The time can depend on how complete the application is, how complex the business model is, ownership structure, offshore connection, custody arrangement, and whether clarification is required by FIU-IND. Simple and well-prepared applications can move forward relatively quickly. So, it is better to have documents and compliance systems ready in advance rather than planning a fixed deadline.

Can Enterslice help with FIU-IND registration and ongoing VASP compliance?

Yes, Enterslice can support VASPs at various stages of FIU-IND registration and ongoing compliance. This can include applicability and India-nexus assessment, documentation, governance appointments, AML/CFT framework, risk assessment, and FIU-IND application support. Reporting readiness and post-registration compliance can also be supported. The main goal is not just to complete registration but to help create a workable compliance framework according to the actual product and risk profile of the business.

Trending Posted

Get Started Live Chat