[codicts-css-switcher id=”346″]

Global Law Experts Logo
vda registration india

Talk with Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

How to Complete VDA Registration in India FIU‑IND VASP Registration & Finnet/fingate Enrolment

By Jonathon Richards
– posted 2 hours ago

If you operate a crypto exchange, custodial wallet, or any other virtual digital asset platform in India, VDA registration India with the Financial Intelligence Unit (FIU‑IND) is no longer optional it is a legal prerequisite. The Government of India has designated Virtual Digital Asset Service Providers (VASPs) as reporting entities under the Prevention of Money‑Laundering Act, 2002 (PMLA), and FIU‑IND now requires every qualifying VASP to register, implement AML/CFT controls, and file transaction reports through the FINnet 2.0 and FINGate portals. This guide walks you through every stage of the process from eligibility confirmation to post‑registration reporting grounded in official FIU‑IND circulars, user manuals, and PMLA provisions.

What FIU‑IND Registration Is and Who Must Register

FIU‑IND registration is the formal enrolment process through which entities engaged in specified VDA activities become Reporting Entities (REs) under the PMLA framework. Once registered, a VASP is obligated to conduct customer due diligence, maintain prescribed records, and file Suspicious Transaction Reports (STRs) and other reports with FIU‑IND.

The requirement applies to every entity domestic or foreign‑operated but serving Indian users that carries out activities identified in the FIU‑IND circular dated 4 July 2023. Those activities include exchange between virtual digital assets and fiat currencies, exchange between one or more forms of VDAs, transfer of VDAs, safekeeping or administration of VDAs or instruments enabling control over VDAs, and participation in and provision of financial services related to a VDA issuer’s offer or sale.

Legal Basis: PMLA & PML Rules

The statutory foundation rests on two pillars. First, the PMLA 2002 empowers the Government to notify categories of reporting entities and imposes obligations regarding record‑keeping, customer identification, and suspicious‑transaction reporting. Second, the Prevention of Money‑Laundering (Maintenance of Records) Rules, 2005 prescribe the granular CDD procedures, record‑retention durations, and report‑filing formats that VASPs must follow. The Government’s March 2023 gazette notification formally brought VDA service activities within the PMLA’s reporting‑entity definition, and the FIU‑IND circular operationalised that notification.

Step‑by‑Step FINnet / FINGate Enrolment for VDA Registration India

The registration process is conducted primarily through FIU‑IND’s digital infrastructure FINnet 2.0 (the reporting platform) and FINGate 2.0 (the secure communication and enrolment gateway). Below is a detailed, numbered walkthrough based on the official FINGate 2.0 User Manual and FIU circulars.

  1. Step 1 Confirm You Qualify as a VASP / Reporting Entity. Review the list of VDA activities in the FIU‑IND VASP circular. If your business undertakes any of the five specified activities whether as a primary service or ancillary feature you are required to register. Entities unsure of their classification should map each product line against the circular’s definitions before proceeding.
  2. Step 2 Prepare Company & KYC Documentation. Assemble the following: certificate of incorporation, Memorandum and Articles of Association (MoA/AoA), PAN card of the entity, GST registration (if applicable), board resolution authorising registration and appointing the Principal Officer (PO) and Designated Director, KYC of all promoters, directors, and the PO/Compliance Officer (Aadhaar, PAN, passport‑sized photographs, address proof), and evidence of VDA activity such as exchange ledger screenshots, wallet transaction logs, or product flow diagrams.
  3. Step 3 Draft and Finalise Your AML/CFT Policy. Before portal enrolment, you must have a board‑approved AML/CFT and Know Your Customer (KYC) policy. This policy should cover customer identification procedures (CID), ongoing transaction monitoring parameters, enhanced due diligence (EDD) triggers for high‑risk customers, suspicious‑transaction identification criteria, record‑keeping standards aligned with PML Rules, and internal escalation protocols. Map your policy headings to the fields expected in the FINnet reporting templates so that your compliance programme and your technical reporting outputs are fully consistent.
  4. Step 4 Create Your FINnet 2.0 Account and Complete FINGate Enrolment. Navigate to the FINnet 2.0 portal. Register for an institutional account using the entity’s official email and mobile number. Upon account creation, proceed to the FINGate 2.0 enrolment module. Complete user management setup this involves SSO (single sign‑on) configuration, creation of user roles (Administrator, Principal Officer, Report Uploader), and, where applicable, mobile‑app registration for the FINGate mobile interface. Each user role requires unique credentials; ensure every nominated individual verifies their account independently.
  5. Step 5 Upload Documents and Complete the Reporting Entity Profile. Within FINGate, navigate to the RE Profile section. Fill in entity details (registered name, CIN, PAN, registered address, communication address, nature of VDA activities undertaken). Upload scanned copies of all documents prepared in Step 2. Designate the Principal Officer and Compliance Officer by entering their personal details, KYC references, and contact information. Nominate additional contact points for FIU correspondence. Ensure every mandatory field (marked with an asterisk in the portal) is populated incomplete profiles are a leading cause of delays.
  6. Step 6 Schedule and Attend the In‑Person Meeting. The FIU‑IND circular requires VASPs to attend an in‑person meeting at the FIU‑IND office (or as otherwise directed). Prepare a compliance pack that includes a printed copy of your AML/CFT policy, a live demonstration or screenshots of your transaction‑monitoring system, evidence of customer on‑boarding flow (KYC screens), a description of your technology architecture and wallet custody arrangements, and a sample Standard Operating Procedure (SOP) for STR filing. The meeting allows FIU officials to verify that the entity has operational AML controls not merely paper policies.
  7. Step 7 FIU Review and Clarification Rounds. After the meeting, FIU‑IND reviews the submitted application. Queries or requests for additional information are communicated through the Request/Response module in FINGate 2.0. Common queries include requests for clarification on transaction volumes, additional director KYC, updated AML policies reflecting recent FIU guidelines, or supplementary evidence of VDA activity. Respond promptly and comprehensively delayed or incomplete responses extend the review cycle.
  8. Step 8 Completion and RE‑Registration Acknowledgement. Upon satisfactory review, FIU‑IND issues an RE‑registration acknowledgement. At this point, the entity must set up its reporting cadence configuring STR and CTR (Cash Transaction Report) templates within FINnet 2.0, activating report‑upload permissions, and running a test submission through the validation utility. The VASP is now a fully registered reporting entity, subject to ongoing obligations.

Troubleshooting: Common Portal Errors & Quick Fixes

  • SSO Login Failures: Clear browser cache, use a supported browser (Chrome or Edge recommended), and ensure pop‑ups are enabled for the FINnet domain.
  • Document Upload Rejections: Verify file size limits (typically under 5 MB per file) and acceptable formats (PDF, JPEG). Re‑scan documents at 200–300 DPI if quality is flagged.
  • Missing Mandatory Fields: The portal will not allow submission if any asterisk‑marked field is blank. Use the field‑by‑field checklist in the FINGate user manual to audit your RE profile before final submission.
  • Mobile App Sync Issues: Ensure the app version matches the current FINGate 2.0 release; re‑register the device if OTP verification fails repeatedly.

FINnet 2.0 vs FINGate: Quick Comparison

Understanding the distinction between FIU‑IND’s two portals avoids confusion during the VASP registration process and day‑to‑day reporting.

Component Purpose Who Uses It Key Modules Typical Action
FINnet 2.0 Secure reporting platform for filing STRs, CTRs and other prescribed reports Principal Officer, Report Uploaders Report Upload, Validation Utility, Report Status, Data Analytics Upload STR/CTR files, run validation checks, track submission status
FINGate 2.0 Secure communication, enrolment and user‑management gateway Administrator, Principal Officer, Compliance Officer RE Profile & Enrolment, User Management (SSO), Request/Response, Alerts & Notices Complete RE registration, respond to FIU queries, manage user roles, receive circulars

Both portals are accessed through the FINnet 2.0 resource page. Industry observers expect continued enhancements to both platforms as FIU‑IND refines its digital infrastructure.

Key Requirements and Eligibility for VDA Registration India

Before initiating the FINnet/FINGate enrolment, confirm that your entity meets every eligibility criterion and has the required documentation ready.

Eligibility Tests Qualifying VASP Activities

Per the FIU‑IND VASP circular, the following activities trigger mandatory registration:

  • VDA‑to‑Fiat Exchange: Facilitating conversion between virtual digital assets and government‑issued currencies.
  • VDA‑to‑VDA Exchange: Enabling swaps or trades between different virtual digital assets.
  • Transfer of VDAs: Conducting or facilitating transfers of virtual digital assets on behalf of customers.
  • Safekeeping / Administration: Providing custodial services or instruments that enable control over VDAs.
  • Financial Services Related to VDA Issuance: Participating in or providing services connected to an issuer’s offer or sale of VDAs.

Mandatory Documents Checklist

  • Corporate Documents: Certificate of Incorporation, MoA/AoA, CIN.
  • Tax Identifiers: PAN of the entity, TAN, GST registration certificate.
  • Board Resolution: Resolution authorising FIU‑IND registration, naming the Principal Officer and Designated Director.
  • KYC of Key Persons: PAN, Aadhaar, address proof, and photographs of all promoters, directors, PO, and Compliance Officer.
  • AML/CFT Policy: Board‑approved policy document covering CDD, EDD, transaction monitoring, record‑keeping, and STR filing procedures.
  • Transaction Evidence: Screenshots, ledger extracts, or system logs demonstrating active VDA operations.
  • Technology Architecture Description: System diagrams covering wallet custody arrangements, hot/cold storage, and API integrations.
  • Customer On‑Boarding Flow: Documentation or screenshots of the KYC journey presented to end‑users.
  • Auditor Reports: Audited financial statements (if available) and any independent AML audit reports.
  • Sample STR SOP: Standard operating procedure for identifying and filing suspicious transaction reports.

AML / KYC Controls & Reporting Obligations Under PMLA

Registration is only the starting gate. Once enrolled, a VASP must operationalise a full suite of virtual digital asset compliance controls in line with the PML (Maintenance of Records) Rules, 2005 and the FATF’s risk‑based guidance for VASPs.

Minimum CDD and Ongoing Monitoring

  • Customer Identification: Verify identity using officially valid documents (OVDs) before establishing a business relationship. For individuals: PAN, Aadhaar, passport. For legal entities: registration certificate, board resolution, beneficial ownership declaration.
  • Ongoing Transaction Monitoring: Implement rule‑based and behavioural analytics to flag unusual patterns rapid movement of large volumes, structuring below reporting thresholds, transactions involving sanctioned jurisdictions.
  • Enhanced Due Diligence (EDD): Apply EDD when a customer is a Politically Exposed Person (PEP), when the transaction involves a high‑risk jurisdiction, or when the risk assessment indicates elevated ML/TF risk.
  • Record Retention: Maintain records of all transactions and CDD documents for a minimum of five years from the date of the transaction, as prescribed by PML Rules.

Internal Controls and Governance

  • Principal Officer / Designated Director: Appoint and register a Principal Officer responsible for furnishing information to FIU‑IND and a Designated Director responsible for overall compliance.
  • Staff Training: Conduct periodic AML/CFT training covering typologies specific to VDA transactions, red‑flag indicators, and reporting procedures.
  • Independent Audit / Testing: Subject the AML programme to independent testing at least annually to assess effectiveness of controls.

Reporting Flows: STR and Other FIU Formats

Registered VASPs file reports through FINnet 2.0. Suspicious Transaction Reports must be filed within seven working days of forming a suspicion. Cash Transaction Reports (CTRs) are filed for transactions exceeding prescribed thresholds. FIU‑IND provides updated reporting templates and a validation utility always download the latest version from the FINnet resources page before batch uploads.

Timelines, Processing Expectations & Common Reasons for Rejection

FIU‑IND does not publish a fixed service‑level agreement for VASP registration. However, a realistic timeline framework based on practical experience is as follows:

  • Preparation Phase (2–6 weeks): Drafting AML/CFT policies, collating corporate and KYC documents, building or configuring transaction‑monitoring systems, and completing FINnet/FINGate enrolment.
  • FIU Review & In‑Person Meeting (variable): Scheduling depends on FIU workload and the quality of the initial submission. Expect at least one round of clarification queries through FINGate before the meeting is confirmed.
  • Post‑Meeting Completion (2–4 weeks): Additional document uploads or policy revisions requested during or after the meeting, followed by issuance of the RE acknowledgement.

Common Reasons for Rejection or Delay

  • Insufficient AML Policy: A generic or templated policy that does not address VDA‑specific risks will be flagged. Tailor the policy to your actual product suite.
  • Incomplete Director KYC: Missing PAN, expired Aadhaar, or unsigned declarations for any director or promoter.
  • Inconsistent Transaction Evidence: Declared products or services that do not match the transaction logs or system screenshots provided.
  • Mismatch in Product/Service Description: If the RE profile states “exchange services” but the system evidence shows only custodial activity (or vice versa), FIU will seek clarification.
  • Technical Portal Errors: Incomplete uploads due to file‑format issues or abandoned form submissions.

Mitigation is straightforward: audit every submission element against the FIU circular’s requirements before clicking “Submit,” and respond to FINGate queries within the timeframe specified.

Costs, Third‑Party Integrations & Technical Readiness Checklist

While FIU‑IND does not charge a registration fee, the overall cost of achieving compliance readiness spans several categories:

  • Internal Legal & Compliance Preparation: Staff time for policy drafting, document collation, and system configuration.
  • External Advisory Support: Engaging qualified professionals for AML programme design, gap analysis, and FINnet enrolment assistance. A scoping exercise is recommended before budgeting.
  • Technology Integrations: Blockchain analytics tools, transaction‑correlation engines, and reporting‑export modules to produce FIU‑compliant CSV/XML files.

Technical Readiness Checklist

  • Logging & Audit Trail: Full transaction and user‑activity logs with tamper‑evident storage.
  • Chain Analytics Integration: On‑chain monitoring for counterparty risk assessment and sanctions screening.
  • File Format Compatibility: Ability to export STR/CTR data in the CSV/XML schema specified by FIU validation utilities.
  • Transaction Correlation: System capability to link VDA transactions to identified customers for reporting purposes.

Use Cases: VASP Registration in Practice

Case 1 Domestic Crypto Exchange

A mid‑sized Indian crypto exchange offering INR‑to‑VDA trading pairs identified that it performed three of the five notified VDA activities. The entity drafted a tailored AML/CFT policy, implemented automated transaction‑monitoring rules calibrated to its average trade volume, and designated its Head of Compliance as Principal Officer. After completing FINGate enrolment and attending the in‑person meeting during which they demonstrated live KYC screens and a sample STR workflow the exchange received its RE acknowledgement and commenced regular STR/CTR filings within weeks.

Case 2 Cross‑Border Remittance VASP

A fintech company facilitating cross‑border VDA transfers for Indian users faced additional scrutiny during registration due to the involvement of overseas counterparties. The entity proactively prepared a detailed correspondent‑relationship register, mapped its transaction flows to FATF Travel Rule expectations, and provided evidence of sanctions screening at both originator and beneficiary ends. The additional preparation addressed FIU queries pre‑emptively, resulting in a smoother review cycle despite the inherent complexity of cross‑border operations.

Closing Summary: Preparing for VDA Registration India

VDA registration India through FIU‑IND is a structured but achievable process when approached methodically. The critical success factors are clear: confirm your VASP classification early, invest in a genuine not templated AML/CFT programme, prepare comprehensive documentation before touching the FINnet/FINGate portals, and treat the in‑person meeting as an operational demonstration rather than a formality.

With FIU‑IND continuing to update its FINnet 2.0 infrastructure and tighten AML/CFT expectations in line with FATF standards, the compliance bar for VDA service providers will only rise. Entities that build robust internal controls now rather than retrofitting them after registration position themselves for sustainable operations in India’s evolving digital‑asset landscape. Early engagement with experienced compliance advisors for Crypto Licensing & AML Compliance India and PMLA obligations for VASPs can materially reduce preparation time and the risk of rejection or enforcement action.

Sources

FAQs

What is FIU‑IND registration?
FIU‑IND registration is the process by which entities carrying out VDA activities identified under the PMLA enrol as Reporting Entities with the Financial Intelligence Unit — India. It is a mandatory prerequisite for complying with AML/CFT reporting obligations.
Prepare corporate and KYC documents, draft an AML/CFT programme, create an account on FINnet 2.0 / FINGate, complete the Reporting Entity profile, upload documents, designate a Principal Officer, and attend the in‑person meeting or clarification round as directed. Detailed field‑level guidance is in the FINGate 2.0 User Manual.
Yes. The Government notified VDA service activities under the PMLA, and FIU‑IND requires registration of qualifying VASPs as Reporting Entities. Failure to register may attract action under section 13(2) of the PMLA and related enforcement measures.
Key documents include the certificate of incorporation, PAN/TAN, board resolution naming the Principal Officer and Designated Director, audited financials (if available), a board‑approved AML/CFT policy, KYC of key persons, technology architecture descriptions, and evidence of VDA activity. Refer to the FIU circular for the complete list.
There is no fixed public SLA. Preparation typically takes two to six weeks depending on compliance readiness, while FIU review and clarification rounds can extend the overall timeline. Always confirm current processing timelines on the FIU‑IND portal.
Suspicious Transaction Reports are filed through FINnet 2.0 using the prescribed templates. Download the latest reporting template and validation utility from the FINnet resources page, populate the required fields, run the validation check, and upload the file. STRs must be filed within seven working days of forming a suspicion.
The FIU‑IND circular applies to entities engaged in notified VDA activities with respect to Indian users. Foreign‑operated platforms providing services in India are expected to register. FIU‑IND has taken enforcement action against non‑compliant offshore platforms, reinforcing the breadth of the requirement.

Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

company formation romania
company formation bulgaria
By Jonathon Richards

posted 18 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Complete VDA Registration in India FIU‑IND VASP Registration & Finnet/fingate Enrolment

Send welcome message

Custom Message