Who This Is Actually For
Not every crypto-adjacent business needs this, and we’d rather tell you that up front than sell you something you don’t need. You’re almost certainly in scope if you do any of the following for someone else, as a business:
- Let users swap fiat for crypto, or crypto for fiat
- Run crypto-to-crypto trading, spot or otherwise
- Move VDAs on a user’s behalf, through wallets or transfer services
- Hold custody of digital assets, retail or institutional
- Help a project sell tokens: launchpads, issuance advisory, certain brokerage setups
That last one catches people off guard. “FIU registration is for exchanges” is a common assumption that doesn’t hold up. NFT marketplaces, institutional custody products, token launch platforms: all likely in scope too. The test is what you do, not what you call yourself.
What We Do
Registration built around how crypto businesses actually work, not a copy-paste of the general FIU-IND process.
Map Your Five-Activity Exposure
Most businesses do more than one without realizing it. A wallet that also swaps tokens is doing two, not one.
Build the AML/CFT Framework FIU-IND Wants to See
Live-selfie KYC, transaction monitoring, and the supporting policy documentation, built to the current standard rather than the 2023 one.
Handle the Filing Itself
Including the compliance meeting FIU-IND runs for most VDA applicants.
Manage Offshore Filings
The obligation follows your Indian users, not your incorporation address.
Stay On After You’re Registered
STR filings, ongoing reporting, policy updates as the guidelines shift.
Benefits of Getting This Right
| Benefit | What It Means for Your Business |
|---|---|
| Banking relationships stay open | Registered VASPs don’t get the “produce your registration number” conversation that unregistered ones do |
| You stay off the enforcement list | FIU-IND names platforms publicly. Once you’re on that list, it’s hard to undo. Better to never be on it |
| Due diligence gets easier | Investors ask about this. Having it sorted beats explaining why it isn’t |
Do You Meet the Eligibility Bar?
FIU-IND wants a working compliance operation, not just a completed form. Before applying, you need:
- A live AML/KYC framework, running rather than drafted. Liveness-detection checks, real transaction monitoring, a policy that matches what your platform actually does.
- A Principal Officer and Designated Director who meet the bar specifically, not just names added to check a box. For VDA reporting entities, that generally means real AML/compliance experience, an India-based Principal Officer, and no conflicts of interest. Our Principal Officer services page covers appointment and qualification in full.
- A clear activity mapping: which of the five VDA activities you perform, and how.
- A banking plan, if you’re offshore. This is usually where international teams get stuck.
Documents You’ll Need
Baseline paperwork — incorporation, PAN, financials — is the same as any FIU-IND application; our FIU-IND registration page has the full list. On top of that, VDA businesses need:
| Document | Why FIU-IND Asks for It |
|---|---|
| Activity-mapping document | Shows which of the five activities you perform, and how |
| VDA-specific AML/CFT policy | Generic AML templates miss crypto risks like mixer exposure |
| Custody/wallet security documentation | Proof of how private keys and cold storage are handled |
| Source-of-funds policy | If you’re involved in token issuances or launches |
| Indian banking relationship (or a plan for one) | Especially scrutinized for offshore applicants |
| Principal Officer & Designated Director appointment | Board resolution plus KYC on both |
Thin documentation here is the single most common reason applications stall.
Why Choose Finlaw Consultancy?
We Specialize in This, Not Just General Compliance
The five-activity test, VDA-specific AML frameworks, custody documentation: this is what we do, not a service a generalist compliance firm added to its list.
We’ve Handled the Offshore Side Specifically
Banking gaps, foreign incorporation, the questions that come up when a platform has no Indian office but plenty of Indian users. We know where these applications typically get stuck.
We Stay Current So You Don’t Have To
The compliance bar has moved twice since 2023, most recently in January 2026. We track every update and build to the standard that’s actually in force, not the one from a year ago.
We Tell You the Truth About Scope
If your business doesn’t need this, we’ll say so. We’d rather earn the work that’s actually right for you than sell you something you don’t need.
We Stay Involved After Registration
STR filings, policy updates, keeping your framework current as the guidelines change: that’s an ongoing relationship, not a filing we hand off and forget.
The Process
Step One Is Scope, Honestly Assessed
We’ve seen founders convinced they needed this who didn’t, and others who had no idea a custody feature they’d shipped months earlier already put them in scope.
Then the Framework
Policies, a Principal Officer, monitoring that actually works rather than just a document that says it does.
Then the Application and Review
Which for VDA applicants usually means an actual meeting with FIU-IND, not just a form.
How Long It Actually Takes
| Stage | Roughly How Long |
|---|---|
| Getting your AML/CFT framework operational | Varies — must happen before you apply |
| Application and document prep | 2–4 weeks |
| FIU-IND’s document review | 4–8 weeks |
| Compliance meeting and follow-up queries | 1–3 months |
| Final approval | 2–4 weeks |
What Happens After You’re Registered
- STR filings continue. For crypto specifically, FIU-IND watches for wash trading, mixer-linked flows, and transfers through weak-reporting jurisdictions.
- Your AML policy has to keep up. The January 2026 update — liveness KYC, geo-tagging, penny-drop validation, no privacy-coin or mixer listings — isn’t a one-time requirement. It’ll change again, and you’re expected to keep pace.
- Record retention and reporting stay mandatory. So does keeping FIU-IND updated on changes to your Principal Officer or business activities.
Penalties for Getting This Wrong
The statutory penalty is modest on paper: ₹10,000 to ₹1,00,000 per failure under PMLA Section 13. Real enforcement orders run far higher, since they aggregate multiple failures across periods.
- Warnings and directions to comply, before monetary penalties are imposed
- Monetary penalties that compound across multiple failures and periods
- For offshore platforms, a direction to MeitY to block URLs and pull apps from Indian stores
Registering later doesn’t clear the record. Liability for your unregistered period survives, under the same PMLA Section 13(2) framework that applies to every reporting entity. That’s the real argument for doing this now.
Common Mistakes We See
- Treating registration as a license. It isn’t. Problems follow later with SEBI (security-like tokens) or RBI (unusual banking setups).
- Getting the activity mapping wrong. A platform that swaps tokens and also holds custody is performing two of the five activities, not one. Missing that means an incomplete application.
- Assuming offshore means exempt. It doesn’t. The enforcement record makes that clear by now.
- Applying with an outdated AML policy. The compliance bar has moved twice since 2023. A 2023-standard policy won’t clear a 2026 review.
- Underestimating the timeline. Plan for weeks, get surprised by months, usually right when the registration is needed for a banking relationship or a funding round.
- Going quiet after approval. Registration isn’t the finish line. Platforms that stop maintaining their AML program are the ones that end up back in an enforcement conversation.
Building or Running a Crypto Business in India?
Get ahead of this before it becomes a problem. We’ll tell you plainly whether you’re in scope, what it’ll take, and roughly how long. No pressure and no upsell if you don’t need this yet.