Custodial wallet / SaaS in India
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in India with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Registration with FIU-IND as a VDA Service Provider (reporting entity) under the Prevention of Money Laundering Act (PMLA), 2002 (amended March 7, 2023) — mandatory for custodial wallet/SaaS operators that hold keys on behalf of end users
- Implement transaction monitoring systems as required by FIU-IND AML & CFT Guidelines for VDA Service Providers — risk-based, real-time, AI-powered systems to flag suspicious activities (large transfers, structuring, high-risk patterns)
- Deploy blockchain analytics tools (e.g., SaaS models analyzing wallets, histories, chain-hopping, mixers) as an essential part of VASP compliance
- Adopt Travel Rule solutions — share originator/beneficiary details (name, account, address) for virtual asset transfers via secure channels, with screening, recordkeeping, and rejection of incomplete data
- Screen wallets, addresses, and counterparties against OFAC SDN List (https://sanctionssearch.ofac.treas.gov), EU Consolidated Financial Sanctions List, and UN Consolidated List; apply 50% ownership rule
- Freeze sanctioned cryptoassets immediately and report to authorities
- File Suspicious Transaction Reports (STRs) to FIU-IND; maintain records as per PMLA
- Comply with Finance Act 2022 — 30% flat tax on virtual digital assets (Section 115BBH) and 1% TDS on transactions above INR 50,000
- Penalties for non-compliance: PMLA fines up to 3× contravention value + 3–7 years imprisonment; FEMA violations up to 3× amount; potential OFAC secondary sanctions exposure
Key Restrictions
- No specific custody/qualified-custodian licensing framework exists — custodial wallet/SaaS operators rely on general FIU-IND VDA SP registration
- No regulatory framework for stablecoins, DeFi, or token issuance — operators dealing with these face significant legal uncertainty
- Offshore (non-Indian-incorporated) custodial wallet providers face blocking by the Indian government if not FIU-IND registered — local incorporation and registration are effectively mandatory
- RBI maintains historically hostile stance toward private crypto (attempted ban in 2018, reversed by Supreme Court in 2020) — payment integration risks remain
- Securities-classified tokens fall under SEBI jurisdiction — custodians handling tokenized securities may face dual regulation
- Travel Rule applies to all VDA transfers with no specific threshold mentioned for India — effectively applies to all transactions
Key Risks
- Regulatory ambiguity: No comprehensive crypto legislation enacted despite being 'upcoming' since 2021 — operators face shifting regulatory expectations
- RBI hostility: Central bank opposed to private crypto; risk of further payment/banking restrictions for VASPs
- Enforcement precedent: 9 offshore exchanges (including Binance, KuCoin) blocked in January 2024 for non-compliance — demonstrates aggressive enforcement posture
- Tax burden: 30% flat tax on VDA gains + 1% TDS creates compliance overhead and may deter user adoption
- AML/CTF guidelines post-amendment lack explicit FIU-IND-specific published guidance — operators must infer requirements from FATF standards and global precedent
- White-label structure risk: Custodial SaaS provider may bear primary AML responsibility even where white-label client performs front-end KYC — unclear allocation of liability under PMLA
- Secondary sanctions exposure: OFAC/EU/UN screening obligations create cross-jurisdictional enforcement risk
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
FIU-IND — VDA Service Provider registration, AML/CFT, blocked 9 offshore exchanges in Jan 2024
RBI — Stablecoins, payments, Digital Rupee CBDC pilot — historically hostile to private crypto
Prevention of Money Laundering Act (amended 2023) (2023) — VDA SP registration with FIU-IND — mandatory
Finance Act 2022 (Section 115BBH) (2022) — 30% flat tax on virtual digital assets; 1% TDS on transactions above INR 50,000
VASP: VDA Service Provider registration with FIU-IND (1-3 months, no minimum capital). Offshore exchanges blocked in 2024 for non-compliance (Binance, KuCoin, etc.) — most subsequently registered. No comprehensive crypto legislation despite being 'upcoming' since 2021.
CUSTODY: No specific custody framework; covered under FIU registration. No framework for stablecoins, DeFi, or token issuance.
EXCHANGE: FIU-IND registration required; offshore exchanges blocked if non-compliant. RBI attempted outright ban in 2018 (reversed by Supreme Court 2020).
Transaction Monitoring Systems: Confirmed as a standard requirement for VASPs. Sources describe risk-based, real-time, AI-powered systems to flag suspicious activities like large transfers, structuring, or high-risk patterns, tailored to customer risk levels.
Blockchain Analytics Tools: Supported indirectly. Sources highlight blockchain monitoring (e.g., SaaS models analyzing wallets, histories, and typologies like chain-hopping or mixers) as essential for VASP compliance, often integrated with transaction monitoring.
Travel Rule Solutions: Explicitly required under FATF standards. VASPs must share originator/beneficiary details (e.g., name, account, address) for virtual asset transfers via secure channels, with screening, recordkeeping, and rejection of incomplete data.
Adopted and Effective Date: Adopted via PMLA amendment on March 7, 2023, explicitly to comply with the FATF Travel Rule by including VDA service providers (often termed VASPs) in the PMLA framework.
Threshold Amounts: No specific threshold is detailed in the provided sources for India; FATF globally recommends $1,000/€1,000, but countries like India set their own (or none), with requirements potentially applying to all transactions.
VASPs Covered: All Virtual Digital Asset Service Providers (also called VDA-SPs), now classified as reporting entities under PMLA. Several VASPs have registered with the Financial Intelligence Unit - India (FIU-IND), while non-compliant ones faced website blocks.
Technical Implementation Requirements: FIU-IND issued specific AML & CFT Guidelines for VDA-related service providers, covering transaction monitoring systems, blockchain analytics tools, and Travel Rule compliance. VASPs must adhere to these and any subsequent FIU-IND directives on implementation status.
Prevention of Money Laundering Act (PMLA), 2002 (amended March 7, 2023): Core legislation extending AML/CFT to VDAs and VASPs. https://www.ikigailaw.com/article/592/the-implementation-of-the-fatf-travel-rule-to-vasps-in-india
FIU-IND AML & CFT Guidelines for VDA Service Providers: Operational guidance post-amendment. https://fiuindia.gov.in/pdfs/downloads/VDA08012026.pdf
Screening obligations: Continuous screening of wallets, addresses, and counterparties against the Specially Designated Nationals (SDN) List (https://sanctionssearch.ofac.treas.gov), plus the 50% Rule (block entities owned ≥50% by SDN-listed persons) (https://ofac.treasury.gov/faqs/topic/1626). No crypto exceptions; includes sanctioned jurisdictions like Iran, North Korea, Syria, Cuba, Crimea/Donbas (https://ofac.treasury.gov/sanctions-programs-and-country-information).
Blocking: Immediately freeze sanctioned cryptoassets (e.g., from designated wallets/exchanges like Blender.io or SUEX) and report to OFAC; no trading/transfer allowed without license (https://www.elliptic.co/blockchain-basics/what-are-ofac-crypto-sanctions).
Penalties: Civil fines up to $1M+ per violation (e.g., Binance $3.4B in 2023 for Iran/Russia/Cuba dealings; Bittrex $24M) (https://sanctionslawyers.net/ofac-lawyers/ofac-cryptocurrency-sanctions/); criminal penalties possible. Indian VASPs risk secondary sanctions or PMLA fines up to ₹10 lakh + imprisonment.
Screening obligations: Screen against EU Consolidated Financial Sanctions List (https://data.europa.eu/data/datasets/consolidated-list-of-persons-groups-and-entities-subject-to-eu-financial-sanctions?locale=en); ≥50% ownership threshold codified in 19th Russia package (Oct 2025), banning crypto exchanges/transactions with targets like Rosneft (https://amlwatcher.com/blog/ofac-ofsi-eu-un-sanctions-screening-guide/). Sectoral bans (e.g., Russian LNG/crypto) apply.
Blocking: Freeze assets of listed persons/entities; report to EU authorities.
Screening obligations: Screen against UN Consolidated List (https://www.un.org/securitycouncil/content/un-sc-consolidated-list); covers terrorists, proliferators (e.g., North Korea).
Blocking: Freeze assets and prohibit dealings.
Penalties: PMLA fines (up to 3x contravention value) + 3-7 years imprisonment; FEMA violations up to 3x amount.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS operators are permitted in India through FIU-IND VDA SP registration (no specific custody framework), but must maintain local incorporation, implement transaction monitoring, blockchain analytics, and Travel Rule solutions, and comply with PMLA AML obligations and Finance Act 2022 taxation, against a backdrop of regulatory ambiguity and historically hostile central bank posture.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?