Last Updated  on: 26th August 2026       |        Last Reviewed on: 26th August 2026

Key Takeaways Briefly

  • Who is covered: Businesses that exchange virtual digital assets for fiat or for other VDAs, transfer them, safekeep or administer them, or provide financial services on an issuer’s offer and sale of a VDA, during business, notified under section 2(1)(sa)(vi) of the PMLA.
  • The trigger: carrying out any of the notified VDA activities on behalf of another person during business, under S.O. 1072(E) of 7 March 2023. There is no turnover or transaction threshold; the activity is the trigger. A virtual digital asset takes the meaning given in section 2(47A) of the Income-tax Act, 1961.
  • Governing laws: the PMLA, 2002 and the PML (Maintenance of Records) Rules, 2005; the FIU-IND AML/CFT Guidelines for VDA reporting entities, updated 8 January 2026; the UAPA 1967 (Section 51A) and the WMD Act, 2005 (Section 12A).
  • Regulator: the Director, Financial Intelligence Unit of India, designated as Regulator on 9 November 2023. FIU-IND both supervises VDA SPs and receives their reports; the Enforcement Directorate (ED) enforces the PMLA.
  • Core duties: registration with FIU-IND, an internal risk assessment, customer due diligence and KYC, beneficial owner identification, ongoing monitoring, the travel rule on transfers, suspicious transaction reporting, five-year record-keeping and sanctions screening.

This guide is general information on Indian law, not legal advice. For your business’s specific position, speak to a qualified AML professional.

Virtual digital asset service providers, known as VDA SPs or VASPs, are reporting entities under the Prevention of Money Laundering Act, 2002. A business is caught by what it does rather than by a turnover or transaction figure: exchanging virtual digital assets for currency or for one another, transferring them, safekeeping or administering them, or providing financial services around an issuer’s offer and sale of a virtual digital asset. From the moment it carries out one of these activities, its AML, CFT and CPF duties flow from the PMLA, the PML (Maintenance of Records) Rules, 2005, the FIU-IND AML/CFT Guidelines for VDA reporting entities, the UAPA, the WMD Act and the FIU-IND reporting framework. Here, the Director of the Financial Intelligence Unit of India is both the regulator and the body that receives the reports.

The core instruments at a glance

Instrument 

What it does for a VDA SP 

PMLA, 2002 

The parent Act. Makes a VDA SP a reporting entity and creates the core duties of CDD, record-keeping and reporting. 

PML (Maintenance of Records) Rules, 2005 

establishes what to report and when, how to identify customers and beneficial owners, and the duty to appoint officers. 

S.O. 1072(E), 7 March 2023 

The notification that designates the certain VDA activities as triggers to be covered under PMLA.  

S.O. 4877(E), 9 November 2023 

Designates the Director of FIU-IND as the Regulator for VDA service providers. 

AML/CFT Guidelines for VDA reporting entities (FIU-IND) 

The VDA SP’s working rulebook, updated 8 January 2026, including the travel rule. 

UAPA Section 51A and WMD Act Section 12A 

Impose targeted financial sanctions for terrorism and proliferation financing on every VDA SP. 

What Counts as a Virtual Digital Asset Service Provider in India?

A virtual digital asset service provider is a person who, in the course of business and on behalf of another, carries out any of the following:

  1. The exchange between virtual digital assets and fiat currencies;
  2. The exchange between one or more forms of virtual digital assets;
  3. The transfer of virtual digital assets;
  4. The safekeeping or administration of virtual digital assets or of instruments enabling control over them;
  5. Participation in and the provision of financial services related to an issuer’s offer and sale of a virtual digital asset.

A virtual digital asset itself takes the meaning given in section 2(47A) of the Income Tax Act, 1961, which covers cryptocurrencies, non-fungible tokens and similar assets.

Because the trigger is the nature of the activity, rather than turnover or transaction value. Accordingly, an exchange, wallet or custody business carrying out a covered VDA service falls within the reporting entity framework. VDA service providers are covered because virtual assets can facilitate rapid, cross-border and pseudonymous transfers of value, creating risks of money laundering and sanctions evasion.

Are Virtual Digital Asset Service Providers Reporting Entities Under the PMLA?

Yes. Virtual digital asset service providers are a reporting entity under the Prevention of Money-Laundering Act, 2002 when they carry out the notified virtual asset activities. These activities were brought within the definition of specified business or profession under section 2(1)(sa)(vi) through S.O. 1072(E) of 7 March 2023, thereby bringing covered VDA SPs within the reporting entity definition under section 2(1)(wa)

Once covered, the service provider must register with FIU-IND and run a full AML working programme. This places an exchange or custodian in the same broad category of reporting entities that file with FIU-IND as banks and other professionals and connects it to the wider set of DNFBPs subject to the PMLA. The specific VDA activities subject to AML compliance are set out in the notification.

Supervisory authority for virtual digital asset service providers in India

The Director of the Financial Intelligence Unit of India is the designated regulator for VDA service providers. Notification S.O. 4877(E) of 9 November 2023 designated the Director, FIU-IND, appointed under section 49 of the PMLA, as the regulator for the notified VDA activities under Rule 2(1)(fa) of the PMLA Rules. FIU-IND also registers VDA service providers as reporting entities, issues AML, CFT and CPF guidance and receives their reports, combining regulatory and reporting functions in one authority.

The Financial Intelligence Unit of India therefore both sets the rules and takes the filings, while the Enforcement Directorate investigates and prosecutes the offence of money laundering under the PMLA.

AML Regulatory Requirements for Virtual Digital Asset Service Providers in India

The law that governs a virtual digital asset service provider does not sit in one place. It is a layered framework, and it helps to see it grouped as the core legislation, the overarching obligations, the sectoral regulator and its guidelines, the miscellaneous official reports, the international standards, and the allied laws.

Core Legislation

The primary statutes and rules that create the AML, CFT and CPF obligations, grouped into three subsets.

AML Legislation

Prevention of Money Laundering Act, 2002 (PMLA)

India’s parent anti-money laundering statute and the source of a provider’s reporting entity status. It defines the offence of money laundering and imposes the duties of customer due diligence under Section 11A and record-keeping under Section 12 that an exchange or custodian must apply to its business. The Act reaches virtual assets because their speed and cross-border reach let value be moved and layered faster than through the banking system, which is precisely why the perimeter was extended to the service providers.

The PML (Maintenance of Records) Rules, 2005 (PMLR)

The operational guidance made under the PMLA, and the layer a service provider applies in practice. It fixes what to report and when (Rule 3 and Rule 8), how to identify customers and beneficial owners (Rule 9), the duty to appoint a Principal Officer and Designated Director (Rule 7), and, in Rule 7(3), the obligation to run a mechanism to detect suspicious transactions.

The PMLR has been amended through 31 Gazette notifications and orders, set out below in a chronological manner.

The 31 PMLR amendment notifications, in date order:

Gazette notification and date 

Key change or rule touched 

G.S.R. 389(E), 24 May 2007 

The first amendment to the 2005 Rules expanded the Rule 2 definition of a suspicious transaction to include dealings lacking economic rationale or a bona fide purpose, as well as those indicating possible terrorism financing. It also revised Rule 3 on cash transactions involving forged or counterfeit currency, replaced Rule 8 on furnishing information to the Director, and reduced the Rule 9 requirement from three certified copies to one. 

G.S.R. 816(E), 12 November 2009 

A broad revision that introduced definitions for non-profit organisation and Regulator, revised suspicious transaction definition, and mandated reporting of NPO receipts exceeding Rupees 10 lakh. Rule 6 prescribed record retention period to ten years, while Rule 9 was comprehensively revised to require beneficial owner identification, ongoing due diligence, prohibition of anonymous accounts and a Client Identification Programme. 

G.S.R. 76(E), 12 February 2010 

Amended Rules 3, 4, 5, 7 and 9 to refine record-keeping and the reporting references and, most notably, added the first Explanation in Rule 9(1A), which fixes the beneficial owner as the natural person who ultimately owns or controls a client or on whose behalf a transaction is carried out. 

G.S.R. 508(E), 16 June 2010 

Revised Rules 2, 9 and 10, the provisions on definitions, customer due diligence and record-keeping, changing how a reporting entity identifies customers and what it must retain. 

G.S.R. 980(E), 16 December 2010 

Added the small account regime. It defined the Designated Officer and the small account, added the NREGA job card and the Aadhaar letter to the officially valid documents in Rule 2, and inserted Rule 9(2A) on how such an account is opened and watched. 

G.S.R. 481(E), 24 June 2011 

Created the short title. Through Rule 1 it shortened the long 2005 name to the Prevention of Money Laundering (Maintenance of Records) Rules, the PMLR shorthand used since. 

G.S.R. 576(E), 27 August 2013 

Amended Rules 2 and 3 and inserted provisions after Rule 10, addressing definitions, the cash and suspicious transaction reporting duties and the record framework so they matched the reporting obligations more closely. 

G.S.R. 288(E), 15 April 2015 

Amended the Rule 2 definitions. Since definitions decide who and what the operative rules capture, the change ran through the framework and started a series of 2015 updates. 

G.S.R. 544(E), 7 July 2015 

Amended Rules 2, 9, 10 and added Rule 9A covering definitions, customer due diligence and record maintenance, adjusting how a reporting entity identifies customers and what evidence it holds.  

G.S.R. 730(E), 22 September 2015 

Inserted an explanation specifying that a marriage certificate is an acceptable supporting document for a subsequent name change in an officially valid document list under rule 2. 

G.S.R. 882(E), 18 November 2015 

Extended the Rule 9A deadline for the Central Government to establish the Central KYC Records Registry from 90 to 180 days from the commencement of the PML Rules. 

G.S.R. 347(E), 12 April 2017 

Amended Rule 2 and added Rule 9B, incorporating the Central KYC Records Registry into the Rules, creating the duty to file customer KYC records centrally and the basis to reuse them, the structural addition behind today’s CKYCR. 

G.S.R. 538(E), 1 June 2017 

Amended Rules 2 and 9 to build Aadhaar into customer due diligence, prescribing Aadhaar-based identification and authentication for KYC, an approach later reshaped by the Supreme Court’s Aadhaar ruling. 

G.S.R. 1038(E), 21 August 2017 

Amended the Rule 2 definitions, updating the defined terms that govern how the operative rules apply, among several definition changes in 2017. 

G.S.R. 1318(E), 23 October 2017 

A later 2017 update to the Rule 2 definitions, keeping the defined terms current as the framework moved on. 

G.S.R. 456(E), 16 May 2018 

Inserted a clause in Rule 9 requiring reporting entities to develop their customer due diligence programmes in line with applicable sector-specific guidelines and setting out the matters those guidelines must cover. 

G.S.R. 1078(E), 31 October 2018 

Extended the Rule 9 timeline for filing electronic customer CDD records from 3 days to 10 days. 

G.S.R. 108(E), 13 February 2019 

Amended Rules 2 and 9 on definitions and customer due diligence, following the legislative changes to Aadhaar use, and updated the ways identification could be conducted. 

G.S.R. 381(E), 28 May 2019 

Amended Rule 9, sharpening the identification and verification process and the routes to confirm a customer’s identity, part of the post-Aadhaar reshaping of CDD. 

G.S.R. 582(E), 19 August 2019 

Amended Rules 2 and 9 and inserted annexure after Rule 11, covering definitions, customer due diligence and the supporting provisions on information and records, one of the broader 2019 updates. 

G.S.R. 669(E), 18 September 2019 

Further amended Rules 2 and 9 to update the definitions and the customer due diligence process for depository receipts. 

G.S.R. 840(E), 13 November 2019 

Amended Rule 9 with further refinements to the identification and verification requirements, closing the 2019 series of CDD changes. 

G.S.R. 228(E), 31 March 2020 

Extended the validity period for small accounts for 2020 and any subsequent period notified by the Central Government. 

G.S.R. 251(E), 13 April 2020 

Revised Rule 8 on furnishing transaction reports to FIU-IND by modifying the prescribed reporting timeline. 

G.S.R. 254(E), 16 April 2020 

A follow-up amendment to Rule 8, issued shortly after the previous change, further revised the transaction reporting timeline for a specific quarter. 

G.S.R. 798(E), 28 December 2020 

A landmark in extending the regime. Read with G.S.R. 799(E) and 800(E) of the same day, it designated real estate agents and dealers in precious metals and stones and named their regulator, beginning the reach into non-financial businesses that the 2023 notifications later carried to virtual assets. 

G.S.R. 575(E), 13 July 2022 

Added the International Financial Services Centre definition with a bespoke beneficial-owner provision for entities based in an IFSC and added an IFSC proviso to Rule 9A on the CKYCR, fitting the Rules to the GIFT City regime. 

S.O. 1074(E), 7 March 2023 

A major change made in the same window as the virtual-asset notification. It added definitions of politically exposed persons, non-profit organisations and group and a Rule 3A duty for group-wide AML policies and reduced the company beneficial-ownership threshold from 25 to 10 per cent, with a matching change to Rule 9(3)(e). 

G.S.R. 652(E), 4 September 2023 

The second major 2023 amendment. It put the Principal Officer at management level, cut the partnership beneficial ownership threshold from 15 to 10 per cent, inserted an Explanation of control, made trustees disclose their status, and brought the results of any Rule 3 and Rule 9 analysis into the records a reporting entity keeps. 

G.S.R. 745(E), 17 October 2023 

Amended Rules 2, 3, 8 and 9 together, covering definitions, the reporting duties and customer due diligence, refining several operative provisions in one notification and closing the 2023 changes. 

G.S.R. 419(E), 19 July 2024 

Revised Rule 9(1C) on the KYC Identifier and set a seven-day deadline to update a CKYCR record after any change, added a duty to fetch the updated record, and amended Rule 9A(2)(g) on filing, retrieving and using registry records, sharpening how current central KYC data is kept. 

The PML (Manner of Receiving the Records Authenticated Outside India) Rules, 2005

A short set of rules on accepting customer records authenticated outside India. For a VDA SP, they matter because the customer base is often global, so onboarding a non-resident user or a foreign corporate account means relying on identity and ownership documents executed and certified abroad rather than in India.

CFT Legislation

The Unlawful Activities (Prevention) Act, 1967 (UAPA)

India’s principal counter terrorism statute. Its Section 51A requires a service provider to screen customers and beneficial owners against the designated terrorism lists and to freeze, without delay, the funds, assets and virtual assets of any listed person or entity. This screening obligation binds every VDA SP from the first transaction, and it is sharpened by the pseudonymous nature of virtual asset transfers.

Procedure for implementation of Section 51A of the UAPA (order dated 2 February 2021; corrigendum dated 15 March 2023 and 29 August 2023)

The step-by-step procedure a service provider follows to give effect to Section 51A when a customer or counterparty matches a designated list. FIU-IND builds the screening and freezing steps into the AML/CFT Guidelines that VDA SPs work from, so the statutory order becomes a concrete workflow across the platform.

CPF Legislation

The Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005 (WMD Act)

India’s counter-proliferation financing statute. Its Section 12A supplies the legal basis for targeted financial sanctions aimed at the financing of weapons of mass destruction, and it reaches a service provider directly because virtual assets are a documented channel for sanctioned states and proliferation networks to raise and move funds.

Procedure for implementation of Section 12A of the WMD Act (dated 1 September 2023)

The implementation procedure for Section 12A, which provides screening and freezing steps for proliferation financing designations. For a service provider, it is applied through the same FIU-IND Guidelines, so terrorism and proliferation lists are both screened as part of transaction monitoring.

The WMD and their Delivery Systems (Prohibition of Unlawful Activities) Implementation Rules, 2016

The subordinate rules that put the WMD Act into operation and support the designated list handling, freezing and reporting actions a provider must be able to carry out the moment a proliferation financing designation match arises on the platform.

Overarching

The shared national obligations that a provider plugs into once it is a reporting entity.

CERSAI Central KYC Records Registry (CKYCR) Operating Guidelines, 2025

These guidelines govern the central KYC records registry operated by CERSAI. They set out the functions and responsibilities of the registry and reporting entities for uploading, retrieving and updating customer KYC records. A reporting entity can retrieve an existing KYC record filed by another reporting entity and use it for onboarding, reducing duplication and promoting consistency in customer and beneficial ownership information.

FINnet 2.0 Reporting Formats (2024) and the FINGate 2.0 User Manuals

The FIU-IND reporting platform, its 2024 reporting formats and the FINGate 2.0 user manuals through which a provider enrols and submits prescribed reports. FIU-IND has issued a dedicated FINnet 2.0 reporting format for virtual asset service providers, so a provider file in a format built for the sector.

Section 11A Aadhaar Authentication Procedure for Non-Banking Entities (9 May 2019)

The procedure by which an entity other than a banking company applies for permission to use Aadhaar authentication services for KYC. It matters to providers because they are precisely the non-banking reporting entities that must obtain approval before verifying a customer’s identity through Aadhaar.

Sectoral

The regulator and its provider-specific instruments. This is the layer that gives the VDA regime its distinct character.

Financial Intelligence Unit of India (Director, FIU-IND as Regulator)

AML/CFT Guidelines for reporting entities providing services related to virtual digital assets (updated 8 January 2026)

The principal operational guidance for VDA service providers. Issued by FIU-IND and updated on 8 January 2026, the guidelines set out requirements for AML, CFT and CPF policies, customer due diligence, beneficial owner identification, transaction monitoring and suspicious transaction reporting, record keeping and the appointment of a designated director and principal officer. They also establish the travel rule for virtual asset transfers, requiring the ordering provider to obtain and transmit prescribed originator and beneficiary information to the receiving provider, which must obtain and retain the information. Where the PMLA and the PMLR establish the legal obligations, these guidelines provide the operational detail for implementing them.

Circular for Registration of VDA SPs with FIU-IND as Reporting Entities

The FIU-IND circular, as revised, sets out the registration process for VDA service providers with FIU-IND as reporting entities. Registration is the gateway to fulfilling reporting obligations under the PMLA framework and also provides the basis for addressing VDA SPs operating without registration.

FINnet 2.0 reporting format for virtual asset service providers (13 June 2023)

The dedicated reporting format introduced for VASPs on the FINnet 2.0 platform, which structures how a provider submits its reports to FIU-IND in a form tailored to virtual asset activity.

Notifications S.O. 1072(E) (7 March 2023) and S.O. 4877(E) (9 November 2023)

The two instruments that build the regime: S.O. 1072(E) brings the virtual asset activities within section 2(1)(sa)(vi) of the PMLA, and S.O. 4877(E) designates the Director, FIU-IND as the Regulator for those activities under Rule 2(1)(fa) of the PMLR.

Miscellaneous

Official reports and guidance that sit outside the binding rulebook but shape how a provider reads its risk and its duties.

FIU-IND Annual Report 2024-25

The national FIU’s annual account of the reports it received, analysed and disseminated. As FIU-IND is also the provider’s regulator, this report is a direct read on the supervisor’s priorities, including its enforcement action against non-compliant virtual asset providers.

Directorate of Enforcement Annual Report 2025-26

The Enforcement Directorate’s annual account of investigations, provisional attachments and prosecutions under the PMLA, showing how the criminal enforcement end of the framework is used, including cases involving virtual assets and crypto exchanges.

FIU-IND and its Core Functions and FAQs

A simple explanation of what FIU-IND does and how reporting works, a practical first primer for a provider whose regulator and reporting hub are the same body, when registering its reporting function on FINnet 2.0.

MHA National Counter Terrorism Policy and Strategy

The Ministry of Home Affairs statement of national counter terrorism policy and strategy, which frames the wider intent behind the CFT duties that Section 51A places on a provider, a live concern given the use of virtual assets in terrorism financing.

International Standards

The global benchmarks India is measured against, and the sources a provider can use to calibrate a risk-based approach to virtual asset services.

FATF Recommendations

The international AML, CFT and CPF standards. Recommendation 15 applies the relevant requirements to virtual assets and virtual asset service providers, while Recommendation 16 establishes the travel rule, requiring specified originator and beneficiary information to accompany qualifying transfers. The recommendations were last updated in June 2026, including an update to Recommendation 6 on targeted financial sanctions. India’s designation of VDA service providers as reporting entities and its travel rule requirements reflect these international standards.

FATF Mutual Evaluation Report on India, 2024 (and Executive Summary)

The 2024 FATF peer review of India’s system, with a separate executive summary. It assessed how India supervises and reports on virtual asset service providers, a sector under close international scrutiny, and it signals where the regime is expected to tighten next.

Allied Laws

The wider body of law that defines the predicate offences and the enforcement machinery around money laundering. A provider does not administer these Acts, but they shape the risk it must assess and the conduct it may need to report.

The allied laws most relevant to a virtual digital asset service provider’s AML, CFT and CPF risk profile include:

The Companies Act, 2013: It provides requirements concerning shareholding, beneficial ownership, registers and corporate disclosures to support and understand identification of the ownership and control of corporate customers

The Bharatiya Nyaya Sanhita, 2023 and the Bharatiya Nagarik Suraksha Sanhita, 2023: which replaced the Indian Penal Code and Code of Criminal Procedure and provide a broader substantive criminal and procedural framework within which VDA-related fraud, cheating, forgery and other underlying offences are investigated and prosecuted.

The Foreign Exchange Management Act, 1999: It is particularly relevant where VDA SP facilitates or is exposed to cross-border transfers, foreign counterparties, offshore wallets, or movement of value involving India and other jurisdictions.

Other relevant laws include the Benami Transactions (Prohibition) Act, 1988, the Prevention of Corruption Act, 1988, the Narcotic Drugs and Psychotropic Substances Act, 1985, the Fugitive Economic Offenders Act, 2018, the Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015, the Foreign Contribution (Regulation) Act, 2010, the Conservation of Foreign Exchange and Prevention of Smuggling Activities Act, 1974, the Smugglers and Foreign Exchange Manipulators (Forfeiture of Property) Act, 1976, the Arms Act, 1959, the Chemical Weapons Convention Act, 2000 and the Central Vigilance Commission Act, 2003. These laws are primarily relevant as sources of predicate offence, ownership, cross-border, corruption and asset forfeiture risk rather than as standalone day-to-day compliance regimes.

Core AML/CFT/CPF Obligations for Virtual Digital Asset Service Providers in India

Across that framework, the regulations require a virtual digital asset service provider to do the following. This article keeps each at the level required by law; a compliance requirements guide explains how to do each. Correspondent banking is not included here because it does not apply to a VDA SP, though the travel rule is the sector’s counterpart for transfers.

  • Register with FIU-IND. Enrol with the Financial Intelligence Unit of India on the FINnet 2.0 / FINGate 2.0 portal, following the FIU-IND registration circular, before or as the provider begins offering the notified virtual asset services.
  • Appoint officers. Appoint a Designated Director and a management-level Principal Officer under Rule 7 of the PMLR. The same person cannot hold both roles, and both are to be informed to FIU-IND.
  • Conduct the internal risk assessment. Assess money laundering, terror financing and proliferation financing risk across customers, products, tokens, delivery channels and geographies, giving weight to the cross-border and pseudonymous nature of virtual assets, and keep it current.
  • Document AML policy, controls and procedures. Adopt an approved policy that turns the risk assessment into the platform’s operating procedures, as required by the FIU-IND Guidelines.
  • Customer identification and CDD. Identify and verify every customer and the beneficial owner (a controlling interest of more than 10 per cent for a company or partnership, and more than 15 per cent for an unincorporated association or body of individuals), with enhanced due diligence for politically exposed persons and high-risk customers, under Section 11A of the PMLA, Rule 9 of the PMLR and the FIU-IND Guidelines.
  • Apply the travel rule. On a virtual asset transfer, obtain and transmit the required originator and beneficiary information to the next provider, obtain it when receiving a transfer, and screen and handle transfers to or from unhosted wallets and unregistered providers in line with the Guidelines.
  • Ongoing monitoring and periodic updates. Monitor transactions on an ongoing basis, using blockchain analytics where appropriate, and refresh KYC at least once every 2, 8 and 10 years for high, medium and low-risk customers respectively. Review each customer’s risk categorisation at least once every six months and decide whether enhanced due diligence is required.
  • Sanctions screening. Screen customers, counterparties and beneficial owners against the designated lists under Section 51A of the UAPA and Section 12A of the WMD Act and freeze and report any match. Verify the relevant UNSC and domestic designated lists daily. This duty applies to every service provider, from the first transaction.
  • Regulatory reporting. File suspicious transaction reports of any value, including attempted transactions, promptly once the Principal Officer is satisfied that a transaction is suspicious, under Rule 8(2) of the PMLR, together with the other prescribed reports where they apply, using the dedicated FINnet 2.0 reporting format for virtual asset service providers.
  • Record management, CKYCR and FINnet 2.0. Keep transaction records for five years from the date of the transaction and keep identity records and business correspondence for five years after the business relationship ends, under Section 12 of the PMLA. Upload customer KYC records to the Central KYC Records Registry under Rule 9A, and file all prescribed reports through FINnet 2.0.
  • Training and awareness. Train staff by role to apply the controls and recognise the red flags of virtual-asset laundering and sanctions evasion.
  • Independent testing and audit. Test the programme through internal audit, compliance assurance or independent review, and close every finding.

What This Article Does Not Cover

This article explains the laws and regulatory instruments that apply to virtual digital asset service providers. It neither provides a control-by-control compliance manual nor does it cover the wider taxation, listing or prudential treatment of virtual digital assets, which are governed by other regimes. For implementation, a provider separately documents customer acceptance, KYC and CDD procedures, beneficial owner identification, the travel rule, sanctions and wallet screening, transaction monitoring, suspicious transaction reporting, staff training, audit testing and management reporting. These operational controls are addressed in the companion compliance guide.

To see how the provider framework fits within the national picture, see AML laws and regulations in India, and use the parent overview, AML laws and regulations for DNFBPs in India, to see how VDA service providers sit alongside the other designated businesses and professions.

From Regulation to Compliance: Your Next Step

Knowing the law is step one. These obligations only protect an institution when they are built into a working programme of risk assessment, policy, customer due diligence, monitoring, screening, reporting, training and independent review. For a payment system operator, identifying customers and participants and their beneficial owners, understanding the funds moving through the system and transaction monitoring for signs of misuse are the controls that matter most. Understanding the stages of money laundering and how the sanctions screening process works is a useful starting point.

Launching or scaling a virtual-asset business?

AML India can help you register with FIU-IND, implement the travel rule and build a proportionate programme for an exchange, wallet or custody service.

Frequently Asked Questions

When a VDA service provider carries out any of the notified virtual-asset activities in the course of business on behalf of another person, including exchanging virtual digital assets for fiat or for other VDAs, transferring them, safekeeping or administering them, or providing financial services on an issuer’s offer and sale of a VDA, they are covered under the PMLA as a reporting entity.

No. A VDA SP is covered by virtue of its activity itself, with no minimum turnover or transaction size. Carrying out any of the notified virtual-asset services makes the business a reporting entity.

The Director of the Financial Intelligence Unit of India is the designated Regulator by S.O. 4877(E) of 9 November 2023. FIU-IND issues the AML/CFT Guidelines, registers service providers as reporting entities and receives their reports, so the regulator and the reporting hub are the same body. The Enforcement Directorate investigates and prosecutes the offence of money laundering.

Yes. The travel rule requires that, on a virtual-asset transfer, the required originator and beneficiary information travels with the transfer between providers, so identity data is not lost the way it might be in a raw on-chain transfer. It is set out in the FIU-IND Guidelines and gives effect to the FATF standard for virtual assets.

Principally, suspicious transaction reports of any value, including attempted transactions, filed promptly once the Principal Officer is satisfied a transaction is suspicious, along with the other prescribed reports where they apply. Reports are filed through the dedicated FINnet 2.0 reporting format for virtual asset service providers.

Yes. The screening duties under Section 51A of the UAPA and Section 12A of the WMD Act apply to every VDA SP from the first transaction, without any threshold trigger. A service provider screens customers, counterparties and beneficial owners against the designated lists, freezes and reports any match found, a duty made more demanding by the pseudonymous nature of virtual-asset transfers.

The FIU-IND Guidelines set out a specific approach to unregistered VDA SPs. Operating the notified activities without registering as a reporting entity is a breach of the PMLA obligations that can attract action by FIU-IND and, in serious cases, blocking of the service, as India has done with non-compliant offshore platforms. Making registration the first step, not an optional one.

Official sources and review

Why work with AML India

AML India helps virtual digital asset service providers meet their PMLA and FIU-IND obligations, from registration and risk assessment to CDD, the travel rule compliance, screening, ongoing monitoring, reporting, training and independent review.

Industries we serve: Virtual Asset Service Providers, Trust and Company Service Providers, Real Estate Agents, Dealers in Precious Metals and Stones, Chartered Accountants, Company Secretaries and Cost and Management Accountants, Casinos and the Gaming Sector, and Banks, Financial Institutions and IFSC and GIFT City entities.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik