FIU-IND issued updated AML, counter-terrorist financing and counter-proliferation financing guidelines for virtual digital asset service providers, replacing its March 2023 guidelines. The guidelines cover registration, governance, customer due diligence, transaction monitoring, the travel rule, sanctions screening and reporting. They add operational detail such as liveness checks and geolocation at onboarding.
Why it matters: India still has no crypto law, so FIU-IND's AML rulebook remains the only binding framework for exchanges operating in the country.
FIU-IND has been the AML regulator for virtual digital asset service providers since November 2023 (para 1.2.3). The 2026 guidelines consolidate its earlier circulars into one document (para 1.2.6). They apply to any provider offering exchange between crypto and fiat, exchange between crypto assets, transfers, safekeeping, or services linked to a token offering.
Selected requirements:
Onboarding. Providers collect PAN plus one identity document (para 4.2.2), verify mobile and email by one-time password (para 4.2.3), and confirm the client is present using a live photo with liveness detection (para 4.2.4). They also record the latitude, longitude, date, time and IP address of the onboarding (para 4.2.1).
Travel rule. For transfers between service providers, the originating provider must obtain, hold and send the originator’s PAN, identity document number, name, wallet address, physical address and date of birth, plus the beneficiary’s name and wallet address (para 5.3.5). The information must travel before or with the transfer, and after-the-fact submission is not allowed (para 5.3.4). Providers should use a technical solution, with self-declaration allowed only where that is not feasible (para 5.3.3).
Sanctions screening at onboarding, on changes to KYC or sanctions lists, and at the start of every transaction (para 5.4.1).
Implications
For registered exchanges, most of this codifies what FIU-IND already expected through circulars and inspections. The new detail is at onboarding, where liveness checks and geolocation capture are now spelled out.
For offshore platforms, the guidelines matter because FIU-IND enforces registration against them. The September notices to 15 platforms rest on the same obligations.
The travel rule section (para 5.3) addresses transfers between service providers. It does not say how the rule applies to transfers to or from self-hosted wallets.
What to watch
FIU-IND inspections and penalties that apply the new onboarding and travel rule requirements, and whether the Parliamentary Standing Committee’s study of virtual digital assets leads to a regulator beyond FIU-IND.