DeFi protocol frontend in India
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in India with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- VDA SP registration with FIU-IND is mandatory under the Prevention of Money Laundering Act (amended March 7, 2023) — all VDA Service Providers must register as reporting entities
- Risk-based Customer Due Diligence (CDD) and KYC for users accessing the frontend; no specific threshold amount identified — may apply to all transactions
- Travel Rule compliance required — originator/beneficiary information must be shared for virtual asset transfers via secure channels with recordkeeping
- Transaction monitoring systems required — real-time, risk-based AI-powered systems to flag suspicious activities like large transfers, structuring, or high-risk patterns
- Blockchain analytics tools required — monitoring of wallets, addresses, and counterparties, including typologies like chain-hopping or mixers
- Suspicious Transaction Reports (STRs) to FIU-IND; ongoing compliance status reporting to FIU-IND not explicitly supported in sources
- Screening against OFAC SDN List (US sanctions), EU Consolidated Financial Sanctions List, and UN Consolidated List; blocking and freezing of sanctioned assets
- Penalties under PMLA — fines up to 3x contravention value + 3–7 years imprisonment; FEMA violations up to 3x amount
Key Restrictions
- DeFi frontend operator must register as a VDA Service Provider with FIU-IND — no exemption for 'decentralized' or 'non-custodial' frontends
- Fee-taking (e.g., frontend fees, swap fees) likely triggers classification as a VDA SP and brings the operator under PMLA obligations
- Offshore frontends serving Indian residents without FIU registration risk website blocks (e.g., Binance, KuCoin blocked Jan 2024 then re-registered)
- No specific DeFi or smart-contract framework exists — regulatory gap creates uncertainty
- 30% flat tax on virtual digital assets under Finance Act 2022 (Section 115BBH); 1% TDS on transactions above INR 50,000 applies to the operator's tax-withholding obligations
Key Risks
- Regulatory ambiguity — India has no comprehensive crypto legislation and no specific DeFi framework; FIU-IND has not issued guidelines distinguishing DeFi frontends from custodial VASPs
- Enforcement precedent — 9 offshore exchanges blocked in January 2024 for FIU non-compliance; frontends could face similar blocking orders
- RBI historically hostile to private crypto (attempted ban overturned by Supreme Court 2020); payments-focused regulators may treat DeFi frontends engaging with stablecoins or payment tokens as unregulated financial services
- Tax complexity — 30% flat tax + 1% TDS creates operational burden for frontend operators handling Indian-resident transactions
- Secondary sanctions risk — Indian VASPs dealing with sanctioned wallets/entities face OFAC enforcement (Binance $3.4B penalty precedent)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
FIU-IND — VDA Service Provider registration, AML/CFT, blocked 9 offshore exchanges in Jan 2024
RBI — Stablecoins, payments, Digital Rupee CBDC pilot — historically hostile to private crypto
Prevention of Money Laundering Act (amended 2023) (2023) — VDA SP registration with FIU-IND — mandatory
Finance Act 2022 (Section 115BBH) (2022) — 30% flat tax on virtual digital assets; 1% TDS on transactions above INR 50,000
VASP: VDA Service Provider registration with FIU-IND (1-3 months, no minimum capital). Offshore exchanges blocked in 2024 for non-compliance (Binance, KuCoin, etc.) — most subsequently registered. No comprehensive crypto legislation despite being 'upcoming' since 2021.
EXCHANGE: FIU-IND registration required; offshore exchanges blocked if non-compliant. RBI attempted outright ban in 2018 (reversed by Supreme Court 2020).
Transaction Monitoring Systems: Confirmed as a standard requirement for VASPs. Sources describe risk-based, real-time, AI-powered systems to flag suspicious activities like large transfers, structuring, or high-risk patterns, tailored to customer risk levels.
Blockchain Analytics Tools: Supported indirectly. Sources highlight blockchain monitoring (e.g., SaaS models analyzing wallets, histories, and typologies like chain-hopping or mixers) as essential for VASP compliance, often integrated with transaction monitoring.
Travel Rule Solutions: Explicitly required under FATF standards. VASPs must share originator/beneficiary details (e.g., name, account, address) for virtual asset transfers via secure channels, with screening, recordkeeping, and rejection of incomplete data.
Adopted and Effective Date: Adopted via PMLA amendment on March 7, 2023, explicitly to comply with the FATF Travel Rule by including VDA service providers (often termed VASPs) in the PMLA framework.
VASPs Covered: All Virtual Digital Asset Service Providers (also called VDA-SPs), now classified as reporting entities under PMLA. Several VASPs have registered with the Financial Intelligence Unit - India (FIU-IND), while non-compliant ones faced website blocks.
Technical Implementation Requirements: FIU-IND issued specific AML & CFT Guidelines for VDA-related service providers, covering transaction monitoring systems, blockchain analytics tools, and Travel Rule compliance. VASPs must adhere to these and any subsequent FIU-IND directives on implementation status.
Prevention of Money Laundering Act (PMLA), 2002 (amended March 7, 2023): Core legislation extending AML/CFT to VDAs and VASPs. https://www.ikigailaw.com/article/592/the-implementation-of-the-fatf-travel-rule-to-vasps-in-india
FIU-IND AML & CFT Guidelines for VDA Service Providers: Operational guidance post-amendment. https://fiuindia.gov.in/pdfs/downloads/VDA08012026.pdf
Screening obligations: Continuous screening of wallets, addresses, and counterparties against the Specially Designated Nationals (SDN) List (https://sanctionssearch.ofac.treas.gov), plus the 50% Rule (block entities owned ≥50% by SDN-listed persons) (https://ofac.treasury.gov/faqs/topic/1626). No crypto exceptions; includes sanctioned jurisdictions like Iran, North Korea, Syria, Cuba, Crimea/Donbas (https://ofac.treasury.gov/sanctions-programs-and-country-information).
Blocking: Immediately freeze sanctioned cryptoassets (e.g., from designated wallets/exchanges like Blender.io or SUEX) and report to OFAC; no trading/transfer allowed without license (https://www.elliptic.co/blockchain-basics/what-are-ofac-crypto-sanctions).
Penalties: Civil fines up to $1M+ per violation (e.g., Binance $3.4B in 2023 for Iran/Russia/Cuba dealings; Bittrex $24M) (https://sanctionslawyers.net/ofac-lawyers/ofac-cryptocurrency-sanctions/); criminal penalties possible. Indian VASPs risk secondary sanctions or PMLA fines up to ₹10 lakh + imprisonment.
Screening obligations: Screen against EU Consolidated Financial Sanctions List (https://data.europa.eu/data/datasets/consolidated-list-of-persons-groups-and-entities-subject-to-eu-financial-sanctions?locale=en); ≥50% ownership threshold codified in 19th Russia package (Oct 2025), banning crypto exchanges/transactions with targets like Rosneft (https://amlwatcher.com/blog/ofac-ofsi-eu-un-sanctions-screening-guide/). Sectoral bans (e.g., Russian LNG/crypto) apply.
Screening obligations: Screen against UN Consolidated List (https://www.un.org/securitycouncil/content/un-sc-consolidated-list); covers terrorists, proliferators (e.g., North Korea).
Penalties: PMLA fines (up to 3x contravention value) + 3-7 years imprisonment; FEMA violations up to 3x amount.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A DeFi protocol frontend serving Indian residents must register as a VDA Service Provider with FIU-IND, implement full AML/KYC/Travel Rule obligations, and comply with the 30% VDA tax regime, with no specific DeFi exemption and significant regulatory ambiguity around fee-taking and decentralization.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?