If you operate a crypto exchange, custodial wallet, or any other virtual digital asset platform in India, VDA registration with the Financial Intelligence Unit (FIU‑IND) is no longer optional; it is a legal prerequisite. The Government of India has designated Virtual Digital Asset Service Providers (VASPs) as reporting entities under the Prevention of Money‑Laundering Act, 2002 (PMLA), and FIU‑IND now requires every qualifying VASP to register, implement AML/CFT controls, and file transaction reports through the FINnet 2.0 and FINGate portals. This guide walks you through every stage of the process from eligibility confirmation to post‑registration reporting grounded in official FIU‑IND circulars, user manuals, and PMLA provisions.
FIU‑IND registration is the formal enrolment process through which entities engaged in specified VDA activities become Reporting Entities (REs) under the PMLA framework. Once registered, a VASP is obligated to conduct customer due diligence, maintain prescribed records, and file Suspicious Transaction Reports (STRs) and other reports with FIU‑IND.
The requirement applies to every entity, domestic or foreign‑operated, but serving Indian users that carries out activities identified in the FIU‑IND circular dated 4 July 2023. Those activities include exchange between virtual digital assets and fiat currencies, exchange between one or more forms of VDAs, transfer of VDAs, safekeeping or administration of VDAs or instruments enabling control over VDAs, and participation in and provision of financial services related to a VDA issuer’s offer or sale.
The statutory foundation rests on two pillars. First, the PMLA 2002 empowers the Government to notify categories of reporting entities and imposes obligations regarding record‑keeping, customer identification, and suspicious‑transaction reporting. Second, the Prevention of Money‑Laundering (Maintenance of Records) Rules, 2005 prescribe the granular CDD procedures, record‑retention durations, and report‑filing formats that VASPs must follow. The Government’s March 2023 gazette notification formally brought VDA service activities within the PMLA’s reporting‑entity definition, and the FIU‑IND circular operationalised that notification.
The registration process is conducted primarily through FIU‑IND’s digital infrastructure FINnet 2.0 (the reporting platform) and FINGate 2.0 (the secure communication and enrolment gateway). Below is a detailed, numbered walkthrough based on the official FINGate 2.0 User Manual and FIU circulars.
Step 1: Confirm You Qualify as a VASP / Reporting Entity. Review the list of VDA activities in the FIU‑IND VASP circular. If your business undertakes any of the five specified activities, whether as a primary service or ancillary feature, you are required to register. Entities unsure of their classification should map each product line against the circular’s definitions before proceeding.
Step 2: Prepare Company & KYC Documentation. Assemble the following: certificate of incorporation, Memorandum and Articles of Association (MoA/AoA), PAN card of the entity, GST registration (if applicable), board resolution authorising registration and appointing the Principal Officer (PO) and Designated Director, KYC of all promoters, directors, and the PO/Compliance Officer (Aadhaar, PAN, passport‑sized photographs, address proof), and evidence of VDA activity such as exchange ledger screenshots, wallet transaction logs, or product flow diagrams.
Step 3: Draft and Finalise Your AML/CFT Policy. Before portal enrolment, you must have a board‑approved AML/CFT and Know Your Customer (KYC) policy. This policy should cover customer identification procedures (CID), ongoing transaction monitoring parameters, enhanced due diligence (EDD) triggers for high‑risk customers, suspicious‑transaction identification criteria, record‑keeping standards aligned with PML Rules, and internal escalation protocols. Map your policy headings to the fields expected in the FINnet reporting templates so that your compliance programme and your technical reporting outputs are fully consistent.
Step 4: Create Your FINnet 2.0 Account and Complete FINGate Enrolment. Navigate to the FINnet 2.0 portal. Register for an institutional account using the entity’s official email and mobile number. Upon account creation, proceed to the FINGate 2.0 enrolment module. Complete user management setup. This involves SSO (single sign‑on) configuration, creation of user roles (Administrator, Principal Officer, Report Uploader), and, where applicable, mobile‑app registration for the FINGate mobile interface. Each user role requires unique credentials; ensure every nominated individual verifies their account independently.
Step 5: Upload Documents and Complete the Reporting Entity Profile. Within FINGate, navigate to the RE Profile section. Fill in entity details (registered name, CIN, PAN, registered address, communication address, nature of VDA activities undertaken). Upload scanned copies of all documents prepared in Step 2. Designate the Principal Officer and Compliance Officer by entering their personal details, KYC references, and contact information. Nominate additional contact points for FIU correspondence. Ensure every mandatory field (marked with an asterisk in the portal) is populated; incomplete profiles are a leading cause of delays.
Step 6: Schedule and Attend the In‑Person Meeting. The FIU‑IND circular requires VASPs to attend an in‑person meeting at the FIU‑IND office (or as otherwise directed). Prepare a compliance pack that includes a printed copy of your AML/CFT policy, a live demonstration or screenshots of your transaction‑monitoring system, evidence of customer on‑boarding flow (KYC screens), a description of your technology architecture and wallet custody arrangements, and a sample Standard Operating Procedure (SOP) for STR filing. The meeting allows FIU officials to verify that the entity has operational AML controls, not merely paper policies.
Step 7: FIU Review and Clarification Rounds. After the meeting, FIU‑IND reviews the submitted application. Queries or requests for additional information are communicated through the Request/Response module in FINGate 2.0. Common queries include requests for clarification on transaction volumes, additional director KYC, updated AML policies reflecting recent FIU guidelines, or supplementary evidence of VDA activity. Respond promptly and comprehensively; delayed or incomplete responses extend the review cycle.
Step 8: Completion and RE‑Registration Acknowledgement. Upon satisfactory review, FIU‑IND issues an RE‑registration acknowledgement. At this point, the entity must set up its reporting cadence by configuring STR and CTR (Cash Transaction Report) templates within FINnet 2.0, activating report‑upload permissions, and running a test submission through the validation utility. The VASP is now a fully registered reporting entity, subject to ongoing obligations.
Understanding the distinction between FIU‑IND’s two portals avoids confusion during the VASP registration process and day‑to‑day reporting.
| Component | Purpose | Who Uses It | Key Modules | Typical Action |
|---|---|---|---|---|
| FINnet 2.0 | Secure reporting platform for filing STRs, CTRs and other prescribed reports | Principal Officer, Report Uploaders | Report Upload, Validation Utility, Report Status, Data Analytics | Upload STR/CTR files, run validation checks, track submission status |
| FINGate 2.0 | Secure communication, enrolment and user‑management gateway | Administrator, Principal Officer, Compliance Officer | RE Profile & Enrolment, User Management (SSO), Request/Response, Alerts & Notices | Complete RE registration, respond to FIU queries, manage user roles, receive circulars |
Both portals are accessed through the FINnet 2.0 resource page. Industry observers expect continued enhancements to both platforms as FIU‑IND refines its digital infrastructure.
Before initiating the FINnet/FINGate enrolment, confirm that your entity meets every eligibility criterion and has the required documentation ready.
Per the FIU‑IND VASP circular, the following activities trigger mandatory registration:
Registration is only the starting gate. Once enrolled, a VASP must operationalise a full suite of virtual digital asset compliance controls in line with the PML (Maintenance of Records) Rules, 2005 and the FATF’s risk‑based guidance for VASPs.
Registered VASPs file reports through FINnet 2.0. Suspicious Transaction Reports must be filed within seven working days of forming a suspicion. Cash Transaction Reports (CTRs) are filed for transactions exceeding prescribed thresholds. FIU‑IND provides updated reporting templates and a validation utility; always download the latest version from the FINnet resources page before batch uploads.
FIU‑IND does not publish a fixed service‑level agreement for VASP registration. However, a realistic timeline framework based on practical experience is as follows:
Mitigation is straightforward: audit every submission element against the FIU circular’s requirements before clicking “Submit,” and respond to FINGate queries within the timeframe specified.
While FIU‑IND does not charge a registration fee, the overall cost of achieving compliance readiness spans several categories:
A mid‑sized Indian crypto exchange offering INR‑to‑VDA trading pairs identified that it performed three of the five notified VDA activities. The entity drafted a tailored AML/CFT policy, implemented automated transaction‑monitoring rules calibrated to its average trade volume, and designated its Head of Compliance as Principal Officer. After completing FINGate enrolment and attending the in‑person meeting during which they demonstrated live KYC screens and a sample STR workflow, the exchange received its RE acknowledgement and commenced regular STR/CTR filings within weeks.
A fintech company facilitating cross‑border VDA transfers for Indian users faced additional scrutiny during registration due to the involvement of overseas counterparties. The entity proactively prepared a detailed correspondent‑relationship register, mapped its transaction flows to FATF Travel Rule expectations, and provided evidence of sanctions screening at both originator and beneficiary ends. The additional preparation addressed FIU queries pre‑emptively, resulting in a smoother review cycle despite the inherent complexity of cross‑border operations.
India VDA registration through FIU‑IND is a structured but achievable process when approached methodically. The critical success factors are clear: confirm your VASP classification early, invest in a genuine, not templated AML/CFT programme, prepare comprehensive documentation before touching the FINnet/FINGate portals, and treat the in‑person meeting as an operational demonstration rather than a formality.
With FIU‑IND continuing to update its FINnet 2.0 infrastructure and tighten AML/CFT expectations in line with FATF standards, the compliance bar for VDA service providers will only rise. Entities that build robust internal controls now rather than retrofitting them after registration position themselves for sustainable operations in India’s evolving digital‑asset landscape. Early engagement with experienced compliance advisors for Crypto Licensing & AML Compliance India and PMLA obligations for VASPs can materially reduce preparation time and the risk of rejection or enforcement action.
posted 35 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
posted 6 hours ago
posted 7 hours ago
posted 8 hours ago
posted 10 hours ago
posted 11 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message