FIU Notices to Crypto Platforms: Activity-Based AML Obligations
Why in News?
On 9 September 2026, FIU-IND announced non-compliance notices to 15 virtual digital asset service providers, highlighting activity-based anti-money-laundering obligations for platforms operating in India.
- FIU-IND issued the notices under Section 13 of the PMLA; this announcement concerns compliance action against the named service providers.
- The Director also issued notices to take down applications and URLs associated with these entities; the release does not establish that every address became inaccessible.
- The government reiterated that onshore and offshore providers undertaking covered activities in India must register with FIU-IND and meet reporting and record-keeping obligations.
- Digital delivery can separate a firm’s headquarters from its users; compliance based on activity addresses that geographical gap.
- Financial-integrity supervision and investor protection answer different questions, making registration claims an important exam trap.
UPSC Relevance
Prelims Relevance
- FIU-IND and reporting entities
- Prevention of Money Laundering Act
- AML/CFT framework
- Activity-based obligations
- Offshore VDA service providers
Mains Relevance
GS Paper 3
- Preventing misuse of digital financial services for money laundering and terror financing
- Cross-border enforcement and the limits of registration-based consumer reassurance
GS Paper 2
- Distinguishing compliance proceedings, access restrictions and final findings
Essay
- Digital markets require institutions that follow activities across borders.
Background and Context
What makes the obligations activity-based?
The relevant test concerns covered services operating in India; a provider’s overseas address does not, by itself, remove the stated compliance requirement.
- VDA service providers entered the AML/CFT framework in March 2023. The framework addresses misuse of financial activity for money laundering and terrorism financing, rather than certifying whether an investment will retain its value.
- Exchange services connecting virtual digital assets with fiat currencies are among the covered activities identified in the release. The important relationship is between the service performed and the compliance duties attached to it.
- Transfer services are also identified as covered activity. A platform need not resemble a conventional bank for its handling of virtual assets to raise financial-integrity concerns under the framework described by the government.
- Safekeeping and administration cover services involving virtual assets or instruments enabling control over them. This widens the focus beyond buying and selling to the functions through which users hold or control their assets.
- Offshore status is not an automatic exemption for providers operating in India. In an exam scenario, examine the activity and Indian operational connection before assuming that the absence of local premises settles compliance.
How reporting-entity compliance works
Registration places a provider within a compliance relationship; ongoing reporting and record keeping remain distinct responsibilities under the framework described in the release.
- FIU-IND registration is a stated requirement for the covered service providers as reporting entities. Treat it as an entry into the compliance framework, rather than proof that every subsequent transaction satisfies the rules.
- Record keeping preserves information about financial activity for later examination. Its practical value is traceability: an inquiry needs usable records, not merely the knowledge that a platform or customer account once existed online.
- Reporting obligations require covered providers to supply information under the applicable framework. The release names reporting and record keeping together because information must both be retained and made available through the prescribed process.
- Compliance assessment concerns whether the provider meets its obligations, including registration. A platform’s popularity, overseas incorporation or technical sophistication cannot substitute for evidence that it meets the requirements applicable to its covered activities.
- AML registration does not establish product approval or guaranteed returns. The same government release warns that crypto products and NFTs are unregulated and highly risky, with potentially no regulatory recourse for transaction losses.
What the notices establish, and what they do not
Read the announcement as a specific compliance action; avoid converting a procedural development into a broader claim about guilt or successful access restriction.
- Non-compliance notices identify the action announced by FIU-IND against the listed providers. They should not be rewritten as criminal convictions or as proof that every user transaction on those platforms involved money laundering.
- Takedown notices concern public access to associated applications and URLs. Their issuance is a verifiable official action; successful removal across every app store, network or address would require separate evidence of implementation.
- Provider obligations and user losses are separate analytical questions. Even effective enforcement of reporting duties would not, by itself, remove volatility, guarantee custody safety or establish compensation for a failed crypto investment.
- Cross-border enforcement faces a practical gap between stating a duty and securing compliance. For analysis, distinguish the government’s activity-based rule from the operational challenge of obtaining cooperation from services with overseas organisational structures.
- Precise answer writing follows the evidence: name the authority, identify the compliance action, explain the covered activity and state the limit. Avoid presenting all crypto activity as either fully approved or universally prohibited.
Way Forward
Make compliance claims verifiable
- Supervisory communication should separate registration status, alleged failures, final findings and implemented access restrictions so readers can understand exactly what each announcement establishes.
- Platform disclosures should explain the scope of FIU registration without implying investment approval, guaranteed safety or compensation protection.
- Enforcement assessment should track usable records and compliance responses alongside access restrictions, because removing a URL alone does not establish financial traceability.
Conclusion
- Activity-based regulation follows covered services operating in India across organisational borders. The durable lesson is to test what a provider does before treating its physical location as decisive for its compliance obligations.
- Registration, enforcement and investor safety remain separate questions. Use this case to show why a sound regulatory answer must identify both the reach of an obligation and the limits of the evidence available.
UPSC Practice Questions
Prelims MCQ 1
With reference to VDA service providers operating in India, consider the following statements:
- Their AML/CFT obligations are activity-based.
- An offshore location automatically exempts them from FIU-IND registration requirements.
- The government’s release identifies safekeeping or administration of VDAs among covered activities.
How many of the above statements are correct?
(a) Only one (b) Only two (c) All three (d) None
Answer: (b) Only two
Explanation:
Statements 1 and 3 are correct. The release expressly includes offshore providers operating in India and says obligations do not depend on physical presence.
Prelims MCQ 2
Which conclusion is supported by the September 2026 FIU-IND announcement?
(a) Every listed platform has been criminally convicted. (b) FIU registration guarantees returns on crypto products. (c) Non-compliance notices and application/URL takedown notices were issued. (d) Every listed application is confirmed inaccessible everywhere.
Answer: (c) Non-compliance notices and application/URL takedown notices were issued.
Explanation:
The release establishes issuance of notices. It does not establish convictions, guaranteed returns or completed blocking of every application and URL.
UPSC Mains Questions
- Explain how activity-based AML/CFT obligations address offshore virtual digital asset service providers operating in India. What enforcement challenges remain?
- Distinguish reporting-entity registration from product approval and investor protection, using the FIU-IND notices to VDA platforms as an example.
Source: PIB, Ministry of Finance.
Frequently Asked Questions
Why did FIU-IND issue notices to crypto platforms?
FIU-IND announced non-compliance notices to 15 virtual digital asset service providers under the PMLA. The action concerns their compliance obligations and should not be described as a criminal conviction.
Can an offshore crypto platform avoid these obligations?
The release states that covered providers operating in India must comply whether onshore or offshore. Obligations are activity-based and do not depend on the entity having a physical presence in India.
Does FIU registration mean crypto products are approved?
No. Registration concerns the provider’s reporting-entity obligations. The government separately warns that crypto products and NFTs are unregulated and highly risky, and transaction losses may have no regulatory recourse.
Were all the named websites confirmed blocked?
The release reports notices seeking takedown of associated applications and URLs. Issuing those notices does not itself prove that every listed service became inaccessible; implementation needs separate evidence.
Which VDA activities does the release identify?
It identifies exchange between VDAs and fiat currencies, VDA transfers, and safekeeping or administration of VDAs or instruments enabling control over them. These illustrate why supervision focuses on functions performed.