Prevention of Money Laundering Act, 2002
Virtual Digital Assets, Crypto Exchanges and the PMLA
Since March 2023, crypto platforms in India have stood where banks stand under the PMLA: as reporting entities, bound to know their customers, keep records, report suspicion, and register with FIU-IND. The framework has since hardened. FIU-IND was designated their AML regulator in November 2023, acted against unregistered offshore exchanges from December 2023, issued a detailed registration circular in September 2025, and on 8 January 2026 issued updated AML and CFT Guidelines for VDA service providers, replacing the March 2023 version and consolidating the requirements into one document. This note covers the whole framework.
A crypto transfer through the PMLA filters, the high-risk lanes, governance, and the legal timeline
1. VDA Service Providers as Reporting Entities
§ The notification of 7 March 2023 (S.O. 1072(E)) Under Section 2(1)(sa)(vi), the Central Government notified the following activities, when carried on for or on behalf of another person in the course of business, as activities of a person carrying on a designated business or profession: (i) exchange between virtual digital assets and fiat currencies; (ii) exchange between one or more forms of virtual digital assets; (iii) transfer of virtual digital assets; (iv) safekeeping or administration of virtual digital assets or instruments enabling control over them; and (v) participation in and provision of financial services related to an issuer's offer and sale of a virtual digital asset. Consequence. Crypto exchanges, custodians, wallet providers and similar businesses became reporting entities, subject to all of Chapter IV. Regulator. By notification of 9 November 2023 (S.O. 4877(E)), FIU-IND was designated as the AML, CFT and counter-proliferation regulator for VDA service providers. |
2. Foreign Exchanges and Registration
§ Activity, not location • Obligations are activity-based. A VDA service provider incorporated abroad that provides notified services to persons in India must register with FIU-IND and comply, regardless of physical presence. • Enforcement. From December 2023, FIU-IND issued compliance notices to offshore platforms operating without registration and sought blocking of their websites; in October 2025 the Government reported notices to 25 offshore providers. • Registration as a gate. Under the 2025 registration circular, consolidated in the 2026 Guidelines, registration through FIU-IND's FINGate portal is a precondition to operating. An applicant receives a temporary reference; registration follows only after document review and an in-person meeting at which the Designated Director and Principal Officer demonstrate the entity's AML systems live. • Non-registration is a breach enforceable under Section 13. |
3. KYC and Enhanced Due Diligence for VDA Customers
Requirement | Under the 2026 Guidelines |
|---|---|
Identity | PAN mandatory for individual clients; identity and address documents; PAN of entities verified against the issuing database |
Liveness and location | A selfie with liveness detection; geo-location coordinates, timestamp and IP address at onboarding; device ID |
Bank account | Verified by penny-drop to confirm ownership and operation |
Contact details | Mobile and email verified by OTP or link |
Wallets | Wallet addresses mapped to the client profile |
Risk review | Client risk classification reviewed at least every six months |
KYC refresh | High-risk clients at least every six months; others at least yearly; full CDD on any material change |
Enhanced due diligence | For high-risk clients and transactions, including those involving unhosted wallets |
4. The Travel Rule and Wallet Screening
§ Information that travels with the transfer The rule. VDA transfers are treated like wire transfers under FATF Recommendation 16: originator and beneficiary information must accompany the transfer. What travels. The originator's verified name, PAN or identity number, wallet address, and physical address or date of birth; the beneficiary's name and wallet address. Timing. The information is sent before or at the same time as the transfer; the originating entity first conducts due diligence and sanctions screening on the counterparty; the beneficiary entity checks the data against its own records. Wallet screening. Blockchain analytics are used to screen wallets for links to fraud, darknet markets, mixers, sanctioned persons and other risks before and after transactions. |
5. Unhosted Wallets, Mixers and Privacy Tokens
Category | Treatment under the 2026 Guidelines |
|---|---|
Unhosted wallets | Self-custody wallets with no regulated counterparty: high risk; originator and beneficiary data collected; enhanced due diligence; the entity may restrict further on its own risk assessment |
Mixers and tumblers | Transactions involving them to be detected through monitoring and analytics and NOT facilitated |
Anonymity-enhancing tokens | Privacy coins designed to hide origin, ownership or value: deposits and withdrawals NOT to be permitted |
6. Suspicious Crypto Transactions and Reporting
§ What to watch and report • Indicators. Rapid movement between fiat and crypto with no apparent purpose; deposits from wallets linked to fraud or darknet activity; use of mixers; structuring across accounts; transfers to high-risk jurisdictions; mismatches between profile and activity. • STRs of any value. A suspicious transaction must be reported whatever the amount, including attempted transactions. • Content. Reports include KYC information, wallet addresses, counterparty details, device IDs, IP addresses and the grounds of suspicion. • Review. Alerts are reviewed by the compliance team and the Principal Officer; where no STR is filed, the reasons are recorded. • No tipping off, before, during or after filing. |
7. Governance under the 2026 Guidelines
Role or control | Requirement |
|---|---|
Designated Director | A board-level appointee responsible for overall compliance |
Principal Officer | Full-time, based in India, at least three years of relevant AML experience, no concurrent roles elsewhere; a permanent invitee to risk committees; reports to the board or a committee at least quarterly |
Independent audit | An annual audit of the AML framework by someone independent of those who designed it |
Cybersecurity | A CERT-In empanelled cybersecurity audit, at registration and on an ongoing basis |
Records | Kept for at least five years after account closure; longer where under investigation; audit trails in tamper-proof form |
8. Seizure and Freezing of Crypto Assets
§ Reaching the asset Property. A VDA is 'property' under Section 2(1)(v), so it can be proceeds of crime and can be attached under Section 5. Freezing. During a search, exchange balances and hosted wallets can be frozen under Section 17(1A) by order to the VDA service provider, as the ED has done in investigations involving crypto exchanges. Seizure. Where the ED obtains control of private keys or credentials, assets may be transferred to a government-controlled wallet and seized. Confirmation. As with any seizure or freeze, an application to the Adjudicating Authority must follow within thirty days under Section 17(4). VDAs and proceeds of crime. A VDA is proceeds only when derived from a scheduled offence, or used to launder such proceeds; lawfully acquired VDAs may be attached only as equivalent value where the conditions are met. |
9. Frequently Asked Questions
Are crypto exchanges reporting entities under the PMLA?
Yes. Since 7 March 2023, persons carrying on notified VDA activities for others, including exchange, transfer and custody, are reporting entities.
Must foreign crypto exchanges comply?
Yes, if they serve Indian users. Obligations are activity-based, and FIU-IND has acted against unregistered offshore platforms.
What changed in the 2026 FIU-IND Guidelines?
They replaced the March 2023 guidelines on 8 January 2026, consolidating registration requirements, a stricter Principal Officer standard, enhanced KYC including liveness and geo-location, the travel rule, and controls on unhosted wallets, mixers and privacy tokens.
What is the travel rule?
The requirement that verified originator and beneficiary information accompany a VDA transfer, as it does a wire transfer.