0tokens

Apply for AI Grants India

Financial support for innovators building the future of AI in India.

Apply now

Chat · regulatory norms crypto

Regulatory Norms Crypto in India: A Practical Guide

  1. aigi

    India’s crypto sector operates in a complex compliance environment. The country does not treat cryptocurrencies as legal tender, yet virtual digital asset (VDA) activity is subject to taxation, anti-money-laundering obligations, advertising standards, cybersecurity expectations, and—depending on the business model—additional financial and technology regulations. For founders, investors, exchanges, custodians, and Web3 developers, understanding regulatory norms crypto businesses must follow is essential to avoid enforcement risk and build investor confidence.

    The most important principle is that crypto compliance in India is activity-specific. A software developer building a non-custodial protocol may face a different risk profile from a platform that converts tokens into rupees, holds customer assets, or facilitates transfers. This article explains the current framework, key obligations, practical compliance controls, and the issues Indian AI and blockchain startups should consider before launching.

    What Are Regulatory Norms for Crypto?

    “Regulatory norms crypto” refers to the laws, rules, reporting requirements, and supervisory expectations that apply to virtual digital assets and businesses involved with them. These norms typically cover:

    • Legal classification: How tokens and crypto assets are defined under Indian law.
    • Taxation: Income tax on transfers, withholding tax, and reporting obligations.
    • Anti-money laundering (AML): Customer identification, transaction monitoring, and suspicious transaction reporting.
    • Consumer protection: Fair disclosures, risk warnings, complaint handling, and advertising restrictions.
    • Cybersecurity and custody: Safeguarding wallets, private keys, data, and customer funds.
    • Foreign exchange and cross-border activity: Rules affecting offshore entities, imports, exports, and remittances.
    • Corporate governance: Accounting, audit, beneficial ownership, and board-level oversight.

    India’s approach has generally been to regulate specific risks rather than create a single comprehensive crypto licensing statute. As a result, businesses must interpret multiple legal frameworks together and obtain professional advice for their particular activities.

    Is Cryptocurrency Legal in India?

    Cryptocurrency is not banned in India, but it is also not recognised as legal tender. The Reserve Bank of India issues the country’s currency, and private crypto assets cannot be used as a substitute for the rupee’s official monetary status.

    This distinction matters. A business may legally develop blockchain software or facilitate certain VDA-related services while still being subject to strict tax and AML compliance. Legal availability does not mean regulatory approval, investor protection, price stability, or government endorsement.

    Crypto businesses should avoid describing their products as “government-approved,” “risk-free,” or equivalent to bank deposits. Marketing should clearly explain volatility, liquidity risk, technology risk, fraud risk, custody arrangements, and the absence of sovereign backing.

    The Prevention of Money Laundering Act and Crypto Businesses

    One of the most significant developments in India’s crypto framework was the inclusion of specified VDA activities under the Prevention of Money Laundering Act, 2002 (PMLA). Businesses conducting covered activities may be treated as reporting entities and must meet AML and counter-terrorist financing obligations.

    Covered activities can include, depending on the facts and business model:

    • Exchange between virtual digital assets and fiat currencies.
    • Exchange between one or more virtual digital assets.
    • Transfer of virtual digital assets.
    • Safekeeping or administration of virtual digital assets or related instruments.
    • Participation in financial services connected with the offer or sale of a virtual digital asset.

    A covered entity generally needs to register with the Financial Intelligence Unit–India (FIU-IND), establish a compliance programme, conduct customer due diligence, maintain records, and report prescribed transactions. Offshore platforms serving Indian customers may also face scrutiny when their activities have a sufficient connection with India.

    Core AML controls

    A practical AML framework should include:

    1. Know Your Customer (KYC): Verify identity using reliable, independent sources before enabling regulated or high-risk activity.
    2. Customer risk rating: Classify customers according to geography, product, transaction behaviour, source of funds, and other risk indicators.
    3. Enhanced due diligence: Apply deeper checks to politically exposed persons, high-risk jurisdictions, complex structures, and unusual activity.
    4. Transaction monitoring: Detect rapid movement of assets, mixer exposure, sanctioned addresses, structuring, layering, and anomalous withdrawals.
    5. Suspicious transaction reporting: Escalate and file reports where activity creates reasonable suspicion, following FIU requirements.
    6. Record retention: Preserve KYC, transaction, beneficial ownership, and investigation records for the required period.
    7. Compliance governance: Appoint responsible personnel and document escalation, review, and approval procedures.

    Blockchain analytics can support monitoring, but it is not a substitute for a complete AML programme. On-chain data must be combined with customer information, device intelligence, transaction context, and documented case management.

    Crypto Taxation Rules in India

    India introduced a specific tax regime for income from the transfer of VDAs. Under Section 115BBH of the Income-tax Act, income from VDA transfers is generally taxed at a flat rate of 30%, subject to applicable provisions. The regime also restricts deductions: taxpayers generally cannot reduce VDA gains using expenses other than the permitted cost of acquisition, and losses from VDA transfers cannot ordinarily be set off against other income or carried forward in the same way as many business losses.

    Section 194S provides for tax deduction at source (TDS) on consideration paid for the transfer of a VDA, subject to statutory conditions and thresholds. Exchanges, brokers, payment intermediaries, and users should determine who bears the withholding and reporting responsibility in each transaction flow.

    Important operational considerations include:

    • Maintain the acquisition cost and transfer history for every taxable transaction.
    • Reconcile wallet, exchange, bank, and ledger records.
    • Track token-to-token swaps, which may still constitute transfers.
    • Document airdrops, staking rewards, mining income, liquidity incentives, and employment-related token compensation separately.
    • Review GST treatment with a qualified tax professional; income tax and indirect tax analysis are separate questions.
    • Keep evidence supporting valuation, transaction dates, fees, and counterparties.

    Tax rules and interpretations can change. Crypto businesses should use India-specific tax counsel rather than relying on generic offshore exchange guidance.

    FIU-IND Registration and Compliance Readiness

    A platform covered by India’s AML framework should assess FIU-IND registration early, not after launch. Registration itself is not an endorsement of a business model; it is a compliance requirement for eligible reporting entities.

    Before applying or operating, a business should prepare:

    • Incorporation and ownership documents.
    • Details of directors, partners, beneficial owners, and key managerial personnel.
    • A description of products, transaction flows, jurisdictions, and customer segments.
    • AML, KYC, sanctions, and transaction-monitoring policies.
    • A suspicious transaction escalation and reporting process.
    • Data retention and privacy controls.
    • Details of the principal compliance officer and nominated officer, where applicable.
    • A system for responding to law-enforcement and regulatory requests.

    The compliance function should have sufficient independence, authority, staffing, and access to data. A nominal compliance officer without adequate systems or decision-making power creates significant enforcement risk.

    Advertising and Consumer Protection Expectations

    Crypto advertising must not mislead consumers about returns, risk, regulation, or product features. Marketing campaigns should avoid guaranteed profits, exaggerated historical returns, urgency-based claims, and comparisons that conceal volatility.

    Every customer-facing product should disclose:

    • The nature of the asset and its underlying utility, if any.
    • Price volatility and potential total loss.
    • Custody arrangements and withdrawal limitations.
    • Fees, spreads, liquidation rules, and conflicts of interest.
    • Whether the platform is a principal, agent, broker, software provider, or custodian.
    • Complaint and support channels.
    • Relevant jurisdictional restrictions.

    Influencer and celebrity promotions deserve additional scrutiny. Written approvals, risk disclosures, substantiation for claims, and monitoring of published content should be part of the campaign process. Advertising standards may apply even where the promotion is conducted through social media rather than traditional media.

    RBI, SEBI, and Other Regulatory Touchpoints

    India’s regulators may become relevant based on the product rather than its branding. The Reserve Bank of India is particularly relevant where a crypto business involves payment systems, stored value, lending, banking relationships, foreign exchange, or regulated financial institutions.

    The Securities and Exchange Board of India may become relevant if a token, investment arrangement, or platform activity falls within securities or collective investment concepts. A token’s label—such as “utility token” or “governance token”—does not determine its legal character. Economic rights, investor expectations, governance, profit participation, and the structure of the offering matter.

    Other institutions and laws may also be relevant, including:

    • Ministry of Finance and income-tax authorities.
    • Financial Intelligence Unit–India.
    • Ministry of Corporate Affairs.
    • Consumer protection authorities.
    • CERT-In and cybersecurity requirements.
    • Data protection and privacy laws.
    • Foreign exchange and cross-border payment rules.
    • State-level or sector-specific licensing requirements.

    Founders should create a regulatory map before accepting funds, issuing tokens, onboarding Indian customers, or integrating with payment providers.

    Data Protection, Cybersecurity, and Custody Controls

    Crypto businesses are attractive targets for phishing, account takeover, insider abuse, smart-contract exploits, and private-key theft. Regulatory compliance therefore requires more than policy documents; it requires verifiable technical controls.

    Recommended safeguards include:

    • Hardware security modules or multi-party computation for treasury and custody wallets.
    • Multi-signature approvals for withdrawals and administrative actions.
    • Segregation of customer and company assets.
    • Withdrawal velocity limits and step-up authentication.
    • Privileged-access management and immutable audit logs.
    • Independent smart-contract audits and formal testing for critical code.
    • Incident-response playbooks, breach notification procedures, and disaster recovery.
    • Regular penetration testing and vulnerability management.
    • Secure software development lifecycle controls.
    • Vendor due diligence for custodians, analytics providers, KYC vendors, and cloud services.

    Customer data should be collected only for legitimate purposes, protected against unauthorised access, and retained according to legal and operational requirements. Businesses should also assess where data is stored, which vendors can access it, and how deletion or correction requests are handled.

    How Crypto Startups Can Build a Compliance-First Model

    Compliance should be designed into the business model, not added after product-market fit. Indian founders can reduce risk with the following sequence:

    1. Define the activity precisely

    Map whether the product is an exchange, wallet, custody service, protocol, analytics tool, token issuer, marketplace, payment interface, or software-only product.

    2. Identify customer and jurisdiction exposure

    Document where users, counterparties, servers, directors, banking partners, and service providers are located. Restrict jurisdictions that the business cannot lawfully serve.

    3. Conduct a legal classification review

    Analyse tokens, contracts, fees, custody, returns, governance rights, and marketing claims. Obtain written legal opinions for material launches.

    4. Build AML and sanctions controls

    Implement onboarding, risk scoring, transaction monitoring, wallet screening, case management, reporting, and periodic review.

    5. Separate assets and authority

    Use clear treasury policies, approval matrices, wallet segregation, reconciliation, and independent review. Never rely on a single private key or administrator account.

    6. Prepare tax and accounting systems

    Record every transfer, wallet movement, fee, token grant, and customer liability. Design ledgers that can generate audit-ready reports.

    7. Establish governance

    Assign responsibility to the board, compliance officer, security lead, and finance team. Maintain written policies and evidence of training and testing.

    8. Test before scaling

    Run compliance simulations, incident-response exercises, withdrawal stress tests, and regulatory-request drills before expanding customer volume.

    Common Compliance Mistakes to Avoid

    Crypto businesses often create avoidable exposure through:

    • Launching in India without assessing FIU-IND obligations.
    • Assuming offshore incorporation removes Indian regulatory risk.
    • Treating KYC as a one-time form instead of an ongoing process.
    • Failing to screen wallet addresses and transactions.
    • Promising returns or using misleading risk language.
    • Mixing customer assets with treasury funds.
    • Issuing a token before analysing securities, tax, and consumer implications.
    • Keeping incomplete records of token grants and airdrops.
    • Relying on unaudited smart contracts or centralised administrator keys.
    • Ignoring complaints, withdrawal delays, or suspicious account activity.

    A strong compliance programme is also a commercial advantage. Institutional partners, banks, enterprise customers, and investors increasingly evaluate governance, security, auditability, and regulatory readiness before entering a relationship.

    Regulatory Outlook for Crypto in India

    India’s crypto policy is likely to continue developing through a combination of domestic rules, international coordination, tax administration, AML enforcement, and sector-specific supervision. The global direction is toward greater transparency around beneficial ownership, travel-rule information, cross-border transfers, stablecoins, custody, market integrity, and consumer protection.

    Founders should monitor official notifications from the Government of India, FIU-IND, RBI, SEBI, tax authorities, CERT-In, and other relevant bodies. Policies should be reviewed whenever the company adds a new token, country, payment rail, custody feature, lending product, or institutional customer segment.

    FAQ: Regulatory Norms Crypto in India

    Are crypto assets legal tender in India?

    No. Crypto assets are not legal tender and are not sovereign currency. However, certain crypto-related activities may be conducted subject to applicable laws and compliance obligations.

    Does every blockchain startup need FIU-IND registration?

    Not necessarily. Registration depends on whether the startup conducts covered VDA activities under the AML framework. A technical assessment is required, especially where the product enables exchange, transfer, or custody.

    Are crypto profits taxable in India?

    Income from VDA transfers is subject to the applicable Indian tax regime, including the specified tax rate and restrictions on deductions and loss set-off. Tax treatment can differ for mining, staking, employment compensation, and business activity.

    Can an offshore exchange serve Indian users?

    Offshore incorporation does not automatically remove Indian obligations. Customer location, service delivery, solicitation, payment flows, and the nature of activities should be analysed before serving Indian residents.

    What should investors check before backing a crypto startup?

    Investors should review the company’s regulatory classification, AML status, tax controls, custody architecture, security audits, token rights, data practices, banking relationships, and jurisdictional strategy.

    Last updated 16 September 2026

AIGI may be inaccurate. Replies seeded from the guide above.