Direct Tax
Consulting
ESG Advisory
Indirect Tax
Growth Advisory
Internal Audit
BFSI Audit
Industry Audit
Valuation
RBI Services
SEBI Services
IRDA Registration
AML Advisory
IBC Services
Recovery of Shares
NBFC Compliance
IRDA Compliance
Finance & Accounts
Payroll Compliance Services
HR Outsourcing
LPO
Fractional CFO
General Legal
Corporate Law
Debt Recovery
Select Your Location
FIU-IND, or Financial Intelligence Unit – India, is an important financial intelligence agency in India. It receives, analyzes, and disseminates information related to suspicious financial transactions to the relevant authorities as required.
If a VDA service provider falls under the PMLA framework, then it has to register with FIU-IND. Once the registration is completed, the business acts as a reporting entity.
This does not mean just getting a registration number. The business has to verify the identity of the customer. It has to understand the beneficial owner. It is also important to monitor transactions, identify suspicious transactions, and report them when necessary.
However, one thing needs to be made clear. FIU-IND registration is not a general crypto license. It does not provide approval for the solvency of any token, investment product, or business.
Tax, GST, cybersecurity, consumer protection, and other applicable compliance requirements may also be required separately.
The key issue in FIU-IND registration is the service the business provides. It cannot be decided by looking at the company name, incorporation location, or “Web3 platform” identity alone.
As per the PMLA framework, certain VDA-related activities may fall under the Reporting Entity framework for a business.
This scope may include exchanges, custodial platforms, brokers, wallet services, OTC businesses, launchpads, and other VDA platforms.
So, it is not right to assume that registration is not required just because a business calls itself a “technology company”.
Just because a VASP is incorporated abroad does not mean that it is outside the Indian AML framework. In serving Indian users, an India nexus may be created with the business. So, it is important to assess whether an offshore platform needs registration or not at the outset.
Several factors should be considered during this assessment:
It is advisable to prepare a written India-nexus assessment before launching or continuing service in India. In addition, whether direct FIU-IND registration or an Indian operating structure is more appropriate should also be assessed separately.
Step 1: Determine Applicability and Map the Business Model
Before starting registration, VASPs need to clearly map their business model. It is necessary to document which VDA activities are being carried out, who the customers are, and which entities are providing the service.
Important factors to look at:
This scope assessment should be done before submitting the application. This reduces the possibility of clarification and compliance gaps later.
Step 2: Appoint the Designated Director and Principal Officer
The roles of the Designated Director and Principal Officer are different for FIU-IND compliance. The responsibilities of both need to be clearly defined.
Both should be formally appointed, and necessary details should be communicated to FIU-IND. The principal officer mustn’t be just appointed on paper. He/She should have sufficient authority, knowledge, and access. It is good to have a continuity plan for any change or absence of the officer.
Step 3: Build the AML/CFT Framework Before Applying
This is the most important preparation stage of registration. The VASP’s AML/CFT framework should be built according to its actual business and the 2026 VDA guidelines. Just copying the policy of another business and using it will not work.
The framework should include:
Step 4: Prepare and submit the FIU-IND Application
After the AML framework is ready, the necessary information and documents for the application need to be prepared. The general filing process has several key steps:
It is essential that the information in the application matches corporate records and AML policies. Having different information in different documents can create unnecessary questions.
Step 5: Demonstrate Reporting and Monitoring Readiness
Compliance readiness does not end with just submitting the application. The VASP’s reporting and monitoring system should be in a working state.
This may include:
Compliance is not just about purchasing screening or monitoring software. The real issue is who will review the alert once it is created, how the investigation will be conducted, and how the final decision will be recorded.
Step 6: Integrate Tax, Cybersecurity and Other Compliance Requirements
FiU-IND registration does not end a VASP’s other compliance obligations. Businesses need to create an integrated compliance framework.
This may include issues such as VDA taxation, the applicable 1% TDS framework, GST assessment, CERT-In requirements, data and transaction record retention, cyber incident reporting, privacy, and customer disclosures.
Banking and payment of partner requirements also need to be considered. It is more effective to have these under a single operational framework rather than having separate compliance checklists.
Recurring compliance starts after FIU-IND registration. So, a business should have a clear compliance calendar.
This should include the following regularly:
So, compliance is not just a policy document. It becomes part of the business’s daily operating process.
It is very important to organize the necessary documents before FIU-IND registration. If the documents are incomplete or there is different information in different places, clarification may be required. So, it is better to keep corporate, ownership, AML, and reporting-related records in an organized data room in advance.
Reporting compliance is an important responsibility after receiving FIU-IND registration. FINnet 2.0 is linked to the financial intelligence reporting process of the Reporting Entity. So, VASPs need to have accurate transaction data, customer information, and investigation records.
The key reporting categories include:
Each report should be based on reliable source data. Complete necessary validation before filing. Retain the submission acknowledgement.
Even if there is no reportable transaction, it is good to keep evidence of internal review. Even if there is “zero reporting”, there should be an internal compliance trail to show the business.
In the case of suspicious transactions, the applicable timeline is to file an STR within seven working days after confirming entity suspicion.
The updated AML/CFT Guidelines for 2026 have shifted the compliance approach of VDA businesses towards a more practical and technology-driven one. It is no longer enough to just have a policy document in place. How the business’s actual systems and controls are working is also important.
Key changes include:
● Technology-enabled AML controls: Greater emphasis on identifying and monitoring risk using automated tools and technology.
● Advanced VDA risk assessment: Assessing VDA-specific risks in addition to customer, product, geography, and transaction.
● Blockchain analytics: Using appropriate analytics to understand wallet and transaction activity.
● Self-hosted wallet risk management: Properly assessing the risk of transactions with self-hosted or Unhosted wallets.
● Travel Rule implementation: Having the necessary information-handling processes in place for applicable VDA transfers.
● Stronger transaction monitoring: Measures to quickly identify unusual activity.
● Better evidence: Maintain a proper audit trail of investigations, alerts, and decisions.
● Greater accountability: Ensure compliance responsibilities of the designated director and principal officer are effectively enforced.
● Offshore VASP scrutiny: Increased scrutiny of the compliance exposure of offshore platforms serving Indian users.
Business compliance work does not end after receiving FIU-IND registration. Rather, regular compliance begins here. Registered VASPs are required to keep their corporate and compliance information updated.
Key responsibilities include:
● Maintain designated director and principal officer details.
● Conduct Customer Due Diligence and Enhanced Due Diligence.
● Conduct regular transaction monitoring.
● Identify suspicious activity and file STRs where applicable.
● Maintain necessary customer and transaction records.
● Continue sanctions and relevant wallet screening.
● Periodically review enterprise-wide risk assessment.
● Provide regular training to the compliance team.
● Conduct independent testing, review, or audit.
● Maintain timely communication with FIU-IND when necessary.
Even if a new product, new country, or new transaction flow is added, the compliance framework should be reviewed. Because if the business changes, the risk profile can also change. So, it is very important to keep the compliance calendar active after receiving the registration certificate.
Some common mistakes during FIU-IND registration can create big compliance problems for the business later. So, it is better to avoid them from the beginning.
A serious gap in FIU-IND or PMLA compliance may not be the subject of a single warning. Depending on the situation, the business may face a variety of regulatory and commercial impacts.
So, compliance failure does not only create penalties. It can also impact business continuity and overall business value.
VASPs can verify their compliance with this checklist. If there are any gaps, it is better to fix them before submission.
● Readiness Area Ready
● VDA activity and India nexus mapped
● Appropriate entity structure identified
● Designated Director appointed
● Principal Officer appointed
● AML/CFT policy approved
● Enterprise-wide risk assessment completed
● KYC/EDD and beneficial ownership control operational
● Sanctions and blockchain screening implemented
● Transaction monitoring operational
● FINnet 2.0 reporting process tested
● Record-retention framework established
● Post-registration compliance calendar created
This checklist can also be useful for future ongoing compliance.
Viewing FIU-IND registration as just a filing service can leave out many important compliance areas. Enterslice can support VASPs in understanding their business model and risk profile, as well as in building broader AML/CFT readiness beyond registration.
Our Services:
● FIU-IND applicability and India-nexus assessment
● VDA activity mapping
● Entity and governance documentation
● Designated Director and Principal Officer support
● AML/CFT policy preparation
● Enterprise-wide AML risk assessment
● KYC, EDD, sanctions and transaction-monitoring framework
● FIU-IND application and clarification support
● FINnet 2.0 reporting readiness
● Post-registration compliance support
● Periodic AML review, training and AML audit readiness
● Coordination with tax, GST, and cybersecurity compliance
This can help to better organize the business’s ongoing compliance structure, in addition to registration.
India’s VDA compliance environment is no longer limited to registration alone. A VASP needs to understand its scope and India nexus at the outset. This is followed by proper governance, AML/CFT controls, transaction monitoring, and reliable reporting infrastructure.
Offshore VASPs should assess their exposure to Indian users separately. It is not right to assume that just because a company is registered abroad, it is exempt from Indian AML obligations.
A good compliance model requires proper coordination between legal, compliance, technology, tax, and operations teams. Enterslice can support businesses at various stages of AML compliance, starting from FIU-IND registration to ongoing AML compliance.
Through FIU-IND registration, eligible VDA service providers come under the AML/CFT reporting framework of India’s PMLA. After registration, the business acts as a reporting entity. So, customer due diligence, beneficial ownership verification, transaction monitoring, suspicious transaction reporting, record retention, and compliance governance are required to be maintained. However, FIU-IND registration is not a general cryptocurrency license, and it is not an approval of any token or investment product.
VASPs that provide specific services such as VDA-to-fiat exchange, VDA-to-VDA exchange, VDA transfer, custody, or administration may need FIU-IND registration. VDA exchanges, custodial platforms, brokers, and some Web3 businesses may also fall under this framework. However, the name of the business alone cannot be used to decide.
Just because a company is registered abroad does not mean that a crypto exchange is outside the AML framework of India. An India nexus can be created if it serves Indian customers, has an INR-related facility, or has an India-focused business arrangement. The exact requirement depends on the business model. So, it is better to conduct an India-nexus assessment before launching or continuing a service in the Indian market and seeking professional legal advice if necessary.
No, FIU-IND registration is not a comprehensive crypto license. It aims to bring qualifying VDA service providers under the AML/CFT reporting framework of PMLA. Registration does not approve any token, provide a solvency guarantee, or certify a custody model. Businesses will need to assess tax, GST, cybersecurity, data protection, consumer, and other applicable compliance requirements separately.
The Designated Director is responsible for the overall PMLA compliance framework of the Reporting Entity. The principal officer handles day-to-day AML operations, reporting, and regulatory communication with the FIU-IND. Both need to be formally appointed, and their roles clearly documented. The principal officer should have sufficient knowledge, authority, and relevant data access. It is also important that he/she can communicate with the FIU-IND quickly and accurately.
FIU-IND registration may generally require incorporation and constitutional documents, ownership and beneficial ownership details, tax information, board resolution, designated director and principal officer details, and business model information. In addition, AML/KYC policies, risk assessment and reporting, and monitoring readiness documents are also important. The exact documents may depend on the applicant’s structure and activities. It is important that the information in all documents be consistent with each other.
After receiving registration, the VASP’s compliance responsibility continues. The business has to continue customer due diligence, beneficial ownership checks, transaction monitoring, sanctions screening, and suspicious transaction reporting. The necessary records must also be kept as per the prescribed requirements. In addition, the risk assessment needs to be reviewed regularly; employees trained, and reporting systems maintained. It is also important to update the FIU-IND in applicable cases if there is a relevant change in the corporate or compliance structure.
Through the Travel Rule, there is a system to collect and transmit specific originators and beneficiary information in the case of qualifying VDA transfers. This cannot be done simply by writing it down in the compliance policy. VASP technology and compliance teams need to work together. Clear processes are required for data collection, transmission, incomplete information, counterparty handling, exception management, and record preservation. Therefore, Travel Rule compliance should be properly built into the product workflow.
There is no fixed universal timeline for FIU-IND registration. The time can depend on how complete the application is, how complex the business model is, ownership structure, offshore connection, custody arrangement, and whether clarification is required by FIU-IND. Simple and well-prepared applications can move forward relatively quickly. So, it is better to have documents and compliance systems ready in advance rather than planning a fixed deadline.
Yes, Enterslice can support VASPs at various stages of FIU-IND registration and ongoing compliance. This can include applicability and India-nexus assessment, documentation, governance appointments, AML/CFT framework, risk assessment, and FIU-IND application support. Reporting readiness and post-registration compliance can also be supported. The main goal is not just to complete registration but to help create a workable compliance framework according to the actual product and risk profile of the business.
FIU-IND, or Financial Intelligence Unit – India, is an important financial intelligence agenc...
On January 8, 2026, FIU-IND released new AML (Anti-Money Laundering) and CFT (Countering the Fi...
Mauritius has positioned itself as one of the most promising international financial centres by...
The UAE has become a global centre for media, digital, and creative enterprises with the increa...
Oman has positioned itself as an important energy centre in the Middle East region, p...
Are you human?: 8 + 7 =
Easy Payment Options Available No Spam. No Sharing. 100% Confidentiality
The Prevention of Money Laundering Act, 2002 (PMLA), and the Prevention of Money Laundering (Maintenance of Records...
07 Jul, 2023
On January 8, 2026, FIU-IND released new AML (Anti-Money Laundering) and CFT (Countering the Financing of Terrorism...
10 Aug, 2026