0tokens

Apply for AI Grants India

Financial support for innovators building the future of AI in India.

Apply now

Chat · regulatory norms crypto india

Regulatory Norms Crypto India: 2026 Compliance Guide

  1. aigi

    India’s approach to crypto regulation is compliance-led but not based on a single, comprehensive cryptocurrency statute. The regulatory norms crypto users and businesses face come from several sources: the Income-tax Act, the Prevention of Money-laundering Act (PMLA), Financial Intelligence Unit–India (FIU-IND) requirements, Reserve Bank of India (RBI) rules affecting banks and payment systems, consumer-protection principles, and general criminal and corporate law.

    For founders, exchanges, wallet providers, Web3 companies and investors, the key practical point is that legal treatment depends on the activity. Buying and holding a virtual digital asset (VDA) is treated differently from operating a trading platform, providing custody, facilitating transfers, issuing tokens or handling fiat payments. This article explains the main regulatory norms crypto stakeholders should understand in India and highlights where professional legal and tax advice is essential.

    Is cryptocurrency legal in India?

    Cryptocurrency is not banned in India. Individuals may generally buy, hold, sell and transfer crypto assets, subject to applicable tax, reporting and anti-money-laundering obligations. However, legal availability does not mean that crypto is recognised as legal tender or backed by the Indian government.

    The distinction is important:

    • Crypto is not legal tender: Businesses are not required to accept Bitcoin, Ether or other tokens as payment for goods and services.
    • Crypto is not sovereign money: Private virtual assets are not equivalent to the Indian rupee issued by the RBI.
    • Crypto ownership is not automatically unlawful: The legality of a transaction depends on the asset, activity, source of funds and compliance with applicable laws.
    • Regulation remains activity-specific: A token issuer, exchange, custodian and ordinary investor may have different obligations.

    India’s policy position can evolve through legislation, notifications, tax circulars, judicial decisions and regulatory guidance. Businesses should therefore avoid relying solely on older summaries of the law.

    What are the main regulatory norms crypto businesses must follow?

    The most significant compliance layer for many crypto businesses is the PMLA framework. In March 2023, activities involving virtual digital assets were brought within the scope of specified financial activities under India’s anti-money-laundering regime. This means covered virtual digital asset service providers can be treated as reporting entities.

    The relevant activities generally include:

    • Exchange between virtual digital assets and fiat currencies.
    • Exchange between one or more virtual digital assets.
    • Transfer of virtual digital assets.
    • Safekeeping or administration of virtual digital assets or instruments enabling control over them.
    • Participation in, or provision of financial services related to, an issuer’s offer and sale of a virtual digital asset.

    A business may be within scope based on what it actually does, not merely the label used on its website. A company describing itself as a technology provider could still have obligations if it controls onboarding, matching, custody, transfers, settlement or customer assets.

    FIU-IND registration and reporting duties

    Covered crypto service providers operating in India generally need to register with the Financial Intelligence Unit–India and comply with reporting-entity obligations. Registration is not a substitute for a business licence covering every aspect of a platform, but it is a central AML compliance requirement for in-scope activities.

    A compliant programme commonly includes:

    • Customer identification and verification.
    • Know Your Customer (KYC) procedures.
    • Customer due diligence and risk classification.
    • Enhanced due diligence for higher-risk customers or transactions.
    • Identification of beneficial owners.
    • Transaction monitoring and suspicious transaction detection.
    • Record retention and retrieval controls.
    • Suspicious transaction reporting where required.
    • Cash transaction reporting where applicable.
    • Appointment of responsible compliance personnel.
    • Written AML and counter-terrorist-financing policies.
    • Sanctions, politically exposed person and adverse-media screening.

    The exact controls should be proportionate to the business model, products, jurisdictions, customer base and transaction risk. A basic KYC checkbox is not an adequate AML system for a high-volume exchange or custodial wallet.

    KYC, AML and transaction monitoring for crypto platforms

    Crypto platforms need a risk-based compliance architecture. At onboarding, the business should collect and verify identity information using reliable documents and legally permitted processes. It should also understand the customer’s residence, occupation or business activity, expected transaction profile and source of funds where appropriate.

    Monitoring should not stop at the customer’s identity. Blockchain analytics can help identify exposure to:

    • Sanctioned wallets or jurisdictions.
    • Mixers and tumblers.
    • Ransomware addresses.
    • Dark-web markets.
    • Fraud and scam typologies.
    • Stolen funds.
    • High-risk bridges, protocols or counterparties.
    • Rapid layering through multiple wallets.

    A useful monitoring framework combines on-chain and off-chain signals. Examples include unusual deposit-and-withdrawal patterns, sudden changes in volume, repeated use of newly created wallets, inconsistent geolocation, account takeover indicators and activity that does not match the customer’s stated profile.

    Platforms should document alert thresholds, investigation steps, escalation rules and reporting decisions. Poor documentation can make a defensible compliance programme appear ineffective during an inquiry.

    Crypto taxation in India

    India’s tax rules classify specified crypto-related assets as “virtual digital assets” for income-tax purposes. The tax treatment is distinct from ordinary capital-gains rules and is particularly important for investors and trading businesses.

    Key provisions generally include:

    • Income from transferring a specified VDA is taxed at a flat rate of 30%, subject to applicable surcharge and cess.
    • The cost of acquisition is generally the principal deduction permitted for computing income from transfer.
    • Losses from VDA transfers generally cannot be set off against other income or carried forward for set-off against future VDA income.
    • A tax deducted at source (TDS) mechanism under Section 194S may apply to consideration for transferring specified VDAs, subject to thresholds and statutory conditions.
    • Gifts of VDAs may be taxable to the recipient in specified circumstances under the rules for gifts.

    Tax analysis can become complex when a person receives tokens for services, mining, staking, liquidity provision, airdrops, employment, referrals or business activity. The timing and character of income may differ from the later tax treatment on disposal.

    Businesses should maintain complete records of wallet addresses, transaction IDs, INR values, fees, counterparties, TDS calculations and the source of price data. Investors should not rely solely on exchange-generated profit statements, especially when using multiple platforms, self-custody wallets or decentralised protocols.

    TDS compliance for crypto transactions

    TDS can create operational obligations for exchanges, brokers, buyers and other intermediaries. The responsible party may depend on the transaction structure and whether an intermediary is involved. Businesses need a documented process for determining when TDS applies, calculating the amount, depositing it, filing returns and issuing relevant certificates or statements.

    Common implementation challenges include:

    • Determining whether a token falls within the statutory VDA definition.
    • Identifying the responsible deductor in multi-party transactions.
    • Handling transactions settled in crypto rather than INR.
    • Managing peer-to-peer or off-platform transfers.
    • Applying thresholds across linked transactions where required.
    • Reconciling refunds, failed trades and reversals.
    • Maintaining accurate customer tax records.

    Because errors can create interest, penalties, customer disputes and reconciliation problems, platforms should obtain tax advice before launching or changing a trading or settlement model.

    RBI rules, banking access and payment compliance

    The RBI does not regulate every crypto activity in the same way it regulates banks or payment systems. Nevertheless, its rules remain relevant where a business provides payment services, operates stored-value instruments, handles customer fiat balances, offers lending, or interacts with regulated financial institutions.

    The RBI has repeatedly communicated risks associated with private virtual currencies, including financial, consumer, monetary and operational risks. Banks and regulated entities must comply with RBI directions, customer due diligence requirements and applicable outsourcing, cybersecurity and payment-system rules.

    A crypto company should not assume that FIU-IND registration automatically grants:

    • A banking licence.
    • A payment-system operator authorisation.
    • Permission to issue prepaid instruments.
    • Authority to accept public deposits.
    • The right to provide lending or investment services.
    • Guaranteed access to bank accounts.

    If a platform touches fiat payments, it should map its flow of funds carefully and identify whether any regulated activity is being performed by the company or an outsourced partner. Contracts with banks and payment processors should clearly allocate KYC, fraud monitoring, chargeback, data-security and suspicious-activity responsibilities.

    Token issuance and Web3 project compliance

    Launching a token in India requires more than writing a white paper. The legal risk depends on the token’s rights, marketing, distribution, governance, redemption features, economic design and intended use.

    Founders should assess whether the token could be characterised as:

    • A virtual digital asset for tax and AML purposes.
    • A security or investment product under applicable securities law.
    • A derivative or financial contract.
    • A payment or stored-value instrument.
    • A collective investment arrangement.
    • A consumer product involving misleading claims or unfair practices.

    A token marketed with guaranteed returns, passive income, buyback promises or investment language may attract substantially greater scrutiny than a narrowly designed utility token. Calling a token a “utility token” does not determine its legal character.

    Before launch, a project should prepare a legal classification memo, review promotional claims, conduct sanctions and jurisdictional screening, define transfer restrictions where necessary, and establish governance for treasury assets and user complaints. Smart-contract audits are useful for technical risk but do not replace legal, tax or AML analysis.

    Data protection and cybersecurity obligations

    Crypto businesses process sensitive identity, financial and behavioural data. Their compliance programme should address privacy notices, lawful processing, purpose limitation, data minimisation, access controls, retention, breach response and vendor oversight under applicable Indian data-protection requirements and contractual commitments.

    Security controls should cover:

    • Multi-factor authentication for customers and administrators.
    • Hardware-security modules or equivalent key-management controls.
    • Segregation of hot and cold wallets.
    • Multi-signature approvals for treasury transfers.
    • Withdrawal risk scoring and velocity limits.
    • Privileged-access management.
    • Secure software development and code review.
    • Penetration testing and incident response.
    • Independent reconciliation of customer assets.
    • Business continuity and disaster recovery.

    Custodial businesses should be especially careful about proof-of-reserves claims. A reserve snapshot may not prove that all liabilities are covered, that assets are unencumbered or that customer funds are properly segregated.

    Consumer protection and advertising risks

    Crypto advertising should be accurate, balanced and capable of substantiation. Marketing that highlights returns while minimising volatility, fees, tax, custody risks or the possibility of total loss can create regulatory and litigation exposure.

    Businesses should avoid:

    • Guaranteed-profit claims.
    • Misleading “zero-risk” language.
    • Undisclosed influencer compensation.
    • Fake scarcity or countdown promotions.
    • Fabricated trading volume or user numbers.
    • Unclear fee and spread disclosures.
    • Ambiguous custody and withdrawal terms.
    • Marketing that suggests government approval without a factual basis.

    Terms of service should explain supported assets, forks, network fees, suspension rights, custody arrangements, dispute resolution, tax responsibilities and treatment of lost credentials. Consumer support processes should preserve complaint records and define escalation timelines.

    How Indian crypto businesses can build a compliance checklist

    A practical launch checklist should include the following stages:

    1. Define the product: Document whether the business exchanges, transfers, custodies, issues, brokers or merely provides software.
    2. Map jurisdictions: Identify customers, counterparties, servers, banking partners and restricted countries.
    3. Classify assets and services: Analyse VDA, securities, payment, lending and investment-product risks.
    4. Complete entity and tax setup: Establish the correct Indian entity, registrations, accounting and tax processes.
    5. Assess FIU-IND obligations: Determine whether the business is a reporting entity and complete required registration and controls.
    6. Design KYC and AML workflows: Include onboarding, beneficial ownership, monitoring, escalation and reporting.
    7. Secure custody and technology: Implement key-management, access, audit and incident-response controls.
    8. Review contracts: Prepare customer terms, privacy notices, vendor agreements and institutional onboarding documents.
    9. Test tax operations: Validate TDS, transaction reporting, valuation and reconciliation across representative scenarios.
    10. Maintain evidence: Keep policies, training records, alerts, investigations, reports and board-level approvals.

    Compliance should be treated as an operating system, not a one-time registration exercise.

    Risks of non-compliance

    Failure to meet applicable norms can result in investigations, penalties, account restrictions, customer claims, tax demands, reputational damage and loss of banking or payment relationships. AML failures can be particularly serious because they may expose a business and its officers to enforcement action, even where the underlying platform did not intentionally facilitate criminal activity.

    Investors also face risks from unregulated or poorly governed platforms, including frozen withdrawals, hacks, insolvency, opaque reserves, tax disputes and loss of access to transaction records. Before using a service, users should check its legal entity, disclosures, custody model, grievance process, AML posture and tax reporting support.

    What may change in India’s crypto regulatory framework?

    India’s framework is likely to continue developing through domestic legislation, tax changes, AML guidance, court decisions and international coordination. Global standards from bodies such as the Financial Action Task Force may influence licensing, travel-rule implementation, cross-border information sharing and virtual-asset risk controls.

    Founders should design for regulatory change by maintaining an asset-classification process, version-controlled policies, configurable transaction monitoring and board-level compliance oversight. A product that can adapt to new reporting fields, restricted-asset rules or customer-screening requirements will generally be more resilient than one built around informal processes.

    FAQ: Regulatory norms crypto India

    Is crypto banned in India?

    No. Crypto is not generally banned, but it is not legal tender, and users and businesses must comply with tax, AML, reporting and other applicable laws.

    Does every crypto company need FIU-IND registration?

    Not necessarily. The requirement depends on whether the company performs covered virtual digital asset service-provider activities. A detailed business-model assessment is essential.

    Is crypto income taxed at 30% in India?

    Income from transferring specified VDAs is generally subject to a 30% tax rate, plus applicable surcharge and cess, with restricted deductions and loss set-off rules. Individual circumstances can vary.

    Can Indian banks freely provide services to crypto businesses?

    Banking access is not automatic. Banks and payment providers must follow RBI rules, internal risk policies and AML obligations. FIU registration does not itself provide a banking or payment licence.

    What should a crypto startup do before launch?

    It should classify its services and tokens, assess FIU-IND and PMLA obligations, establish KYC and AML controls, obtain tax advice, secure custody infrastructure, review data protection and prepare accurate customer disclosures.

    Apply for AI Grants India

    Building compliance, risk-monitoring or cybersecurity technology for India’s digital-asset ecosystem? Indian AI founders can explore funding and support opportunities by applying to AI Grants India.

    Last updated 15 September 2026

AIGI may be inaccurate. Replies seeded from the guide above.