0tokens

Apply for AI Grants India

Financial support for innovators building the future of AI in India.

Apply now

Chat · regulatory compliance crypto

Regulatory Compliance Crypto: India Founder’s Guide

  1. aigi

    Crypto businesses operate at the intersection of financial regulation, technology risk, taxation, cybersecurity, and consumer protection. For Indian founders, regulatory compliance crypto is not a single licence or checklist: it is an operating framework that determines whether your exchange, wallet, token, custody product, Web3 platform, or blockchain service can launch and scale responsibly.

    The regulatory position can also change as governments issue notifications, courts interpret existing laws, and global standards evolve. Treat this article as a practical planning guide, not legal advice. Before launch, obtain advice from an Indian lawyer and qualified tax professional familiar with virtual digital assets (VDAs), payments, AML, data protection, and technology businesses.

    What regulatory compliance crypto means

    Regulatory compliance crypto means designing and operating a crypto product in accordance with the laws, rules, regulatory notices, tax provisions, and risk-management expectations that apply to its activities and users.

    A useful compliance programme usually covers:

    • Business classification: exchange, broker, custodian, wallet provider, token issuer, marketplace, protocol operator, payment service, or software provider.
    • Customer controls: identity verification, sanctions screening, age checks, jurisdiction restrictions, and enhanced due diligence.
    • Financial crime controls: anti-money laundering (AML), counter-terrorist financing (CFT), transaction monitoring, suspicious transaction reporting, and record retention.
    • Tax compliance: VDA income tax, tax deducted at source (TDS), goods and services tax (GST) analysis, accounting, and reporting.
    • Technology controls: wallet security, smart-contract reviews, access management, incident response, and business continuity.
    • Privacy and consumer protection: lawful data handling, transparent terms, risk disclosures, complaints, refunds where applicable, and advertising discipline.

    The correct requirements depend on what your company actually does—not merely whether it describes itself as a “Web3 protocol.”

    India’s regulatory starting point for crypto businesses

    India generally refers to crypto assets as virtual digital assets, or VDAs, under the Income-tax Act. The tax framework includes provisions commonly associated with VDA income and TDS on certain transfers. Tax treatment does not automatically make a token a permitted investment, payment instrument, or regulated security. Each product still needs a separate legal analysis.

    A major compliance development is the application of anti-money-laundering obligations to specified VDA activities. Businesses carrying out activities such as exchange between VDAs and fiat currencies, exchange between VDAs, transfer of VDAs, custody or administration of VDAs, and financial services connected with an issuer’s offer or sale of VDAs may fall within the reporting-entity framework under the Prevention of Money Laundering Act and related rules.

    Eligible reporting entities are expected to register with the Financial Intelligence Unit–India (FIU-IND), implement AML/CFT systems, maintain records, verify customers, and report relevant information. Registration should not be treated as a universal crypto licence or endorsement. It is one part of a broader compliance architecture.

    The regulatory perimeter can involve multiple authorities and legal regimes, including:

    • FIU-IND and PMLA-related obligations for covered VDA service activities.
    • Income-tax authorities for VDA taxation and TDS compliance.
    • RBI-related rules where the business touches payment systems, banking channels, foreign exchange, or regulated financial entities.
    • SEBI-related analysis if a token, product, or arrangement has characteristics of a security, collective investment, derivative, or investment product.
    • GST and company-law requirements depending on the revenue model, entity structure, and services supplied.
    • Data-protection and cybersecurity requirements relevant to personal information, financial data, and incident management.

    Because crypto products can perform several functions at once, a written regulatory perimeter memo should be prepared before development is complete.

    Determine your crypto product’s regulatory perimeter

    Start by documenting the product in plain language. Avoid relying on labels such as “decentralised,” “non-custodial,” or “utility token.” Regulators and courts usually examine actual functions, control, economic substance, and user outcomes.

    Answer these questions:

    1. What is the asset? Is it a VDA, a stablecoin, a tokenised claim, a security-like instrument, a loyalty unit, or another digital representation?
    2. Who controls the system? Identify the company, foundation, multisig signers, administrators, governance participants, and service providers with practical control.
    3. Who holds customer assets? Distinguish self-custody from hosted wallets, omnibus wallets, smart-contract custody, and third-party custody.
    4. How does value enter and leave? Map INR rails, cards, bank transfers, payment gateways, crypto transfers, and cross-border flows.
    5. Does the platform match or execute trades? An order book, brokerage function, OTC desk, swap interface, or routing service may create different risks.
    6. Where are users located? Geo-blocking and eligibility controls are important when activities could trigger foreign, sanctions, securities, or financial-services rules.
    7. How does the business earn revenue? Consider trading fees, spreads, staking commissions, token sales, subscriptions, custody fees, protocol fees, and referral income.

    Create a transaction-flow diagram showing users, wallets, smart contracts, fiat accounts, exchanges, custodians, and vendors. This diagram often reveals compliance responsibilities that are missed in product documentation.

    AML, KYC and FIU-IND readiness

    For a covered crypto business, AML compliance should be operational rather than a policy stored in a shared drive. Core components include:

    Customer identification and verification

    Build a risk-based onboarding process that captures identity information, verifies documents and liveness where appropriate, identifies beneficial owners, and prevents duplicate or synthetic accounts. Establish separate workflows for individuals, companies, trusts, partnerships, politically exposed persons, and high-risk customers.

    Do not collect more information than you can secure and justify. Your privacy notice should explain the purpose, legal basis, retention period, and sharing arrangements for KYC information.

    Risk scoring

    Use a documented methodology to score customers and activity. Relevant variables may include jurisdiction, product usage, transaction size, wallet exposure, sanctions risk, source of funds, source of wealth, and typologies associated with mixers, darknet markets, ransomware, scams, or stolen assets.

    Risk scores should trigger actions such as standard due diligence, enhanced due diligence, transaction limits, manual review, or account restriction. Avoid an opaque automated model that compliance staff cannot explain or audit.

    Transaction monitoring

    Monitoring rules should cover both fiat and blockchain activity. Examples include rapid deposits and withdrawals, structuring, unusual velocity, new-wallet exposure, chain hopping, high-risk counterparties, sanctions matches, and activity inconsistent with a customer’s profile.

    Use blockchain analytics carefully. A vendor score is an investigation lead, not conclusive proof of wrongdoing. Preserve the transaction hash, asset, network, addresses, timestamps, screening result, rule triggered, investigator notes, decision, and escalation history.

    Suspicious transaction reporting and records

    Establish procedures for internal escalation and regulatory reporting within applicable timelines. Restrict unauthorised disclosure of reports and investigations. Maintain records of customer identification, transactions, risk assessments, alerts, decisions, training, policies, and compliance testing for the required period.

    Appoint accountable personnel, including a compliance officer and appropriate principal or designated officers where required. Define their authority, independence, access to data, and escalation path to the board or founders.

    Crypto tax and accounting controls in India

    Tax compliance can fail even when AML controls are strong. Indian crypto companies should maintain asset-level and wallet-level records rather than relying only on bank statements.

    A robust tax data model should capture:

    • Date and time of each acquisition, disposal, transfer, fee, reward, and airdrop.
    • Asset, quantity, network, wallet address, transaction hash, and rupee valuation methodology.
    • Customer identity or account reference, where legally permissible.
    • Fees charged, fees paid in crypto, and platform revenue.
    • TDS calculation, deduction, deposit, certificates, and reconciliation.
    • Customer statements and adjustments for reversals, failed transactions, and forks.

    For users, VDA taxation may involve a flat-rate framework, restrictions on loss set-off, and TDS obligations, subject to current law and applicable facts. For platforms, the analysis may also involve GST classification, place of supply, export questions, and whether the company acts as principal, agent, intermediary, or technology provider. Obtain a written tax position before choosing the accounting treatment.

    Custody, wallet security and technology compliance

    Crypto custody creates a concentrated operational and legal risk. A founder should define whether the company can move customer assets, approve transactions, recover keys, freeze accounts, or upgrade smart contracts.

    Minimum technical controls should include:

    • Hardware security modules or equivalent protection for private keys.
    • Multi-party approval for withdrawals and treasury movements.
    • Segregation of hot, warm, and cold wallets.
    • Role-based access, phishing-resistant multi-factor authentication, and privileged-access logging.
    • Withdrawal velocity limits, address allow-listing, cooling-off periods, and anomaly detection.
    • Independent smart-contract audits plus internal code review and formal change control.
    • Tested backup and recovery procedures, including key-shard restoration.
    • Reconciliation between on-chain balances, customer liabilities, and general-ledger records.
    • Incident response for key compromise, exploit, fraud, chain reorganisation, vendor outage, and data breach.

    An audit report is not a guarantee. Compliance requires evidence that controls operate continuously, exceptions are investigated, and material issues reach decision-makers.

    Data protection and consumer protection

    Crypto platforms process identity documents, financial information, device data, blockchain addresses, behavioural profiles, and sometimes biometric information. Design privacy into the product from the start.

    Use data minimisation, encryption in transit and at rest, retention schedules, vendor due diligence, access reviews, deletion workflows where legally possible, and a documented breach-response process. Consider that blockchain data is difficult or impossible to erase; avoid putting personal information directly on-chain.

    Customer terms should clearly explain:

    • Asset and protocol risks, including volatility and smart-contract failure.
    • Whether assets are held in custody and whether customer assets are segregated.
    • Withdrawal limits, suspension rights, fees, spreads, and settlement timing.
    • Forks, airdrops, staking, governance, and protocol upgrades.
    • Insolvency, counterparty, bank, oracle, bridge, and cyber risks.
    • Complaints, support channels, governing law, and dispute resolution.

    Marketing must not promise guaranteed returns, imply government approval, conceal fees, or present speculative assets as equivalent to bank deposits. Influencer and affiliate campaigns should undergo legal and compliance review before publication.

    Build a compliance programme before launch

    A practical implementation roadmap for an Indian crypto startup is:

    1. Map activities and jurisdictions. Prepare the regulatory perimeter memo and product-flow diagram.
    2. Select the entity and governance model. Document ownership, control, directors, responsible officers, and vendor dependencies.
    3. Complete AML and tax design. Write policies, risk methodology, KYC standards, monitoring rules, reporting procedures, and tax data requirements.
    4. Design compliance into the product. Add geo-controls, account states, transaction holds, approval workflows, audit logs, and consent records.
    5. Perform vendor due diligence. Assess KYC providers, blockchain analytics firms, custodians, cloud providers, payment partners, and auditors.
    6. Test with controlled limits. Run sanctions tests, false-positive tests, withdrawal simulations, key-recovery drills, and incident exercises.
    7. Obtain required registrations and approvals. Confirm the current requirements with counsel and the relevant authorities before serving customers.
    8. Monitor continuously. Report compliance metrics to management, conduct independent testing, update rules, and document remediation.

    Useful board-level metrics include onboarding rejection rates, alert ageing, suspicious-activity escalations, sanctions hits, withdrawal exceptions, reconciliation breaks, security incidents, complaints, regulatory requests, and overdue remediation items.

    Common compliance mistakes to avoid

    • Treating FIU-IND registration as a complete licence to operate.
    • Assuming a decentralised interface has no operator or compliance responsibility.
    • Launching token sales before securities, AML, tax, and consumer-law analysis.
    • Using KYC only at onboarding without transaction monitoring.
    • Ignoring customers’ source of funds and beneficial ownership.
    • Keeping incomplete wallet, tax, and TDS records.
    • Commingling customer and company assets.
    • Advertising returns or using vague “risk-free” language.
    • Outsourcing compliance without retaining oversight and audit rights.
    • Failing to test incident response, key recovery, and business continuity.

    FAQ: regulatory compliance crypto in India

    Is crypto legal in India?

    India’s treatment is activity-specific. VDAs are recognised for tax purposes, but that does not mean every crypto activity, token, payment arrangement, or investment product is authorised. Analyse the exact business model and current rules before launch.

    Does every crypto startup need FIU-IND registration?

    Not necessarily. Registration generally depends on whether the business performs activities covered by the AML framework for VDA service providers. Obtain a current legal assessment based on actual functions, custody, transfers, and customer flows.

    Are non-custodial wallets outside compliance requirements?

    Non-custodial design may reduce some risks, but it does not automatically eliminate obligations. The platform’s control over interfaces, transfers, fees, users, routing, or related services remains relevant.

    What should an Indian crypto startup prepare first?

    Begin with a regulatory perimeter memo, transaction-flow map, AML risk assessment, tax data design, privacy assessment, custody model, security threat model, and written customer terms.

    Can compliance be outsourced?

    Specialist providers can support KYC, screening, analytics, and audits, but the company remains responsible for governance, decisions, data quality, reporting, and control effectiveness.

    Apply for AI Grants India

    If you are an Indian AI founder building compliance, fraud detection, blockchain intelligence, cybersecurity, or financial infrastructure, apply through AI Grants India to explore grant opportunities and support for your venture. Submit your application today and turn a high-impact technical solution into a fundable, scalable product.

    Last updated 17 September 2026

AIGI may be inaccurate. Replies seeded from the guide above.