Remote VASP serving residents in India
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in India without local incorporation, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- VDA Service Provider (VASP) registration with FIU-IND is mandatory under the Prevention of Money Laundering Act (PMLA), amended March 7, 2023 (in.aml.prevention-of-money-laundering-act)
- VASPs must implement transaction monitoring systems, blockchain analytics tools, and Travel Rule compliance solutions per FIU-IND AML/CFT Guidelines (in.aml.technical-implementation-requirements-fiu-ind-issued)
- Continuous screening of wallets, addresses, and counterparties against OFAC SDN List and other sanctions lists (in.aml.screening-obligations-continuous-screening-of)
- Travel Rule obligations apply: share originator/beneficiary information for VDA transfers — no specific de minimis threshold identified in Indian sources, though 1% TDS applies above INR 50,000 (in.travel-rule.threshold-amounts-no-specific-de)
- Blocking and freezing of sanctioned cryptoassets, with reporting obligations (in.aml.blocking-immediately-freeze-sanctioned-cryptoassets)
- PMLA penalties: fines up to 3x contravention value and/or 3-7 years imprisonment; FEMA violations up to 3x the contravention amount (in.aml.penalties-pmla-fines-up-to)
Key Restrictions
- Offshore exchanges that fail to register with FIU-IND face website blocking (as demonstrated with Binance, KuCoin, and 7 other exchanges in January 2024) (in.licensing.vasp)
- No comprehensive crypto-specific legislation — legal framework rests primarily on PMLA amendments and FIU-IND registration; stablecoins, DeFi, and token issuance lack dedicated frameworks (in.licensing.custody)
- RBI has historically been hostile to private crypto (attempted an outright ban in 2018, reversed by Supreme Court in 2020) — stablecoin/payment integration risk remains (in.licensing.exchange)
- 30% flat tax on virtual digital assets + 1% TDS on transactions above INR 50,000 under Finance Act 2022 (in.licensing.legislation-finance-act-2022-section-115bbh)
Key Risks
- Enforcement precedent: 9 offshore exchanges blocked in Jan 2024 for non-compliance; Binance subsequently registered. Operating without FIU-IND registration carries high enforcement risk (in.licensing.vasp)
- Regulatory ambiguity: no single comprehensive crypto law; the RBI, SEBI, and FIU-IND have overlapping or unclear jurisdictions over different crypto activities (in.licensing.regulator-rbi, in.licensing.regulator-sebi)
- Tax burden: 30% flat tax and 1% TDS create operational friction and may deter retail user adoption for remote VASPs (in.licensing.legislation-finance-act-2022-section-115bbh)
- Secondary sanctions risk for failure to screen OFAC/EU/UN sanctions lists (in.aml.penalties-civil-fines-up-to)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
VASP: VDA Service Provider registration with FIU-IND (1-3 months, no minimum capital). Offshore exchanges blocked in 2024 for non-compliance (Binance, KuCoin, etc.) — most subsequently registered. No comprehensive crypto legislation despite being 'upcoming' since 2021.
EXCHANGE: FIU-IND registration required; offshore exchanges blocked if non-compliant. RBI attempted outright ban in 2018 (reversed by Supreme Court 2020).
CUSTODY: No specific custody framework; covered under FIU registration. No framework for stablecoins, DeFi, or token issuance.
FIU-IND — VDA Service Provider registration, AML/CFT, blocked 9 offshore exchanges in Jan 2024
RBI — Stablecoins, payments, Digital Rupee CBDC pilot — historically hostile to private crypto
Prevention of Money Laundering Act (amended 2023) (2023) — VDA SP registration with FIU-IND — mandatory
Finance Act 2022 (Section 115BBH) (2022) — 30% flat tax on virtual digital assets; 1% TDS on transactions above INR 50,000
Travel Rule Solutions: Explicitly required under FATF standards. VASPs must share originator/beneficiary details (e.g., name, account, address) for virtual asset transfers via secure channels, with screening, recordkeeping, and rejection of incomplete data.
Transaction Monitoring Systems: Confirmed as a standard requirement for VASPs. Sources describe risk-based, real-time, AI-powered systems to flag suspicious activities like large transfers, structuring, or high-risk patterns, tailored to customer risk levels.
Blockchain Analytics Tools: Supported indirectly. Sources highlight blockchain monitoring (e.g., SaaS models analyzing wallets, histories, and typologies like chain-hopping or mixers) as essential for VASP compliance, often integrated with transaction monitoring.
Prevention of Money Laundering Act (PMLA), 2002 (amended March 7, 2023): Core legislation extending AML/CFT to VDAs and VASPs. https://www.ikigailaw.com/article/592/the-implementation-of-the-fatf-travel-rule-to-vasps-in-india
VASPs Covered: All Virtual Digital Asset Service Providers (also called VDA-SPs), now classified as reporting entities under PMLA. Several VASPs have registered with the Financial Intelligence Unit - India (FIU-IND), while non-compliant ones faced website blocks.
Technical Implementation Requirements: FIU-IND issued specific AML & CFT Guidelines for VDA-related service providers, covering transaction monitoring systems, blockchain analytics tools, and Travel Rule compliance. VASPs must adhere to these and any subsequent FIU-IND directives on implementation status.
Screening obligations: Continuous screening of wallets, addresses, and counterparties against the Specially Designated Nationals (SDN) List (https://sanctionssearch.ofac.treas.gov), plus the 50% Rule (block entities owned ≥50% by SDN-listed persons) (https://ofac.treasury.gov/faqs/topic/1626). No crypto exceptions; includes sanctioned jurisdictions like Iran, North Korea, Syria, Cuba, Crimea/Donbas (https://ofac.treasury.gov/sanctions-programs-and-country-information).
Blocking: Immediately freeze sanctioned cryptoassets (e.g., from designated wallets/exchanges like Blender.io or SUEX) and report to OFAC; no trading/transfer allowed without license (https://www.elliptic.co/blockchain-basics/what-are-ofac-crypto-sanctions).
Penalties: PMLA fines (up to 3x contravention value) + 3-7 years imprisonment; FEMA violations up to 3x amount.
Travel Rule adopted — threshold: INR 50,000 (1% TDS threshold)
Covered VASPs: All VDA service providers registered with the Financial Intelligence Unit - India (FIU-IND), including exchanges and other entities handling VDA activities; non-compliant VASPs have faced website blocks by FIU-IND.
Threshold Amounts: No specific de minimis threshold (e.g., FATF's recommended $1,000/€1,000) is detailed in available sources for India; requirements appear to apply broadly to VDA transactions under PMLA without a stated limit.
Technical Implementation Requirements: VASPs must implement Transaction Monitoring systems, Blockchain Analytics tools, and Travel Rule solutions, with ongoing compliance status reporting to FIU-IND as per periodic guidelines; FIU-IND issued specific AML/CFT Guidelines for VDA-related reporting entities post-amendment.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a foreign-incorporated remote VASP may serve Indian residents from abroad, provided it registers as a VDA Service Provider with FIU-IND, implements AML/CFT controls (transaction monitoring, blockchain analytics, Travel Rule compliance), screens sanctions lists, and complies with PMLA and the 30%/1% tax regime; unlicensed operators face website blocking and enforcement action as demonstrated in January 2024.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?