Legally researched and updated: 6 October 2026
Virtual Digital Asset Service Provider Facing Section 13 PMLA Action: FIU Registration, 2026 AML Guidelines and Remediation
Create a current VDA compliance article using FIU-IND's updated 2026 AML/CFT guidance and registration framework. Cover the designated-business basis, mandatory registration, in-person registration process, significant beneficial ownership, Principal Officer and Designated Director, customer due diligence, wallet and transaction monitoring, suspicious transaction reporting and remediation after operating without full compliance. Use recent FIU Section 13 orders only as factual enforcement examples, not as universal precedent.
Legal research and analysis by Advocate Ankit Kumar Singh .
Direct Answer: Registration Alone Is No Longer the Entire VDA Compliance Question
A VDA Service Provider facing Section 13 action should not answer the notice only by saying:
βWE ARE NOW REGISTERED WITH FIU-IND.β
The relevant questions are wider:
- When did the covered VDA activity begin?
- When did Indian-client exposure begin?
- When was registration initiated?
- When was formal registration approved?
- Who controlled the entity?
- Who were the Significant Beneficial Owners?
- Who was the Designated Director?
- Who was the Principal Officer?
- What CDD existed during the charged period?
- Were wallet addresses and transaction hashes monitored?
- Was blockchain analytics deployed?
- Was Travel Rule information transmitted contemporaneously?
- Was sanctions screening conducted?
- Were alerts reviewed?
- Were STRs filed where required?
- Were records retained?
- What has been remediated?
Current registration is important.
But:
CURRENT REGISTRATION β AUTOMATIC RETROACTIVE CURE OF HISTORICAL NON-COMPLIANCE.
Which VDA Activities Are Covered?
On 7 March 2023, Notification S.O. 1072(E) brought specified VDA-related business activities within the designated-business framework where they are carried on:
FOR OR ON BEHALF OF ANOTHER NATURAL OR LEGAL PERSON IN THE COURSE OF BUSINESS.
The notified activities are:
- exchange between virtual digital assets and fiat currencies;
- exchange between one or more forms of virtual digital assets;
- transfer of virtual digital assets;
- safekeeping or administration of virtual digital assets or instruments enabling control over virtual digital assets; and
- participation in and provision of financial services related to an issuer's offer and sale of a virtual digital asset.
Therefore:
BUYING OR HOLDING CRYPTOCURRENCY PERSONALLY DOES NOT, BY ITSELF, MAKE A PERSON A VDA REPORTING ENTITY.
The actual business activity must fall within the notified framework.
FIU-IND Is the AML/CFT/CPF Regulator for VDA SPs
The Director, FIU-IND was notified as regulator for VDA SPs through S.O. 4877(E) dated 9 November 2023.
FIU-IND's updated 8 January 2026 Guidelines accordingly operate as the current sector-specific AML/CFT/CPF framework.
The framework now addresses:
- registration;
- governance;
- customer acceptance;
- CDD;
- enhanced CDD;
- periodic KYC;
- ongoing due diligence;
- transaction monitoring;
- blockchain analytics;
- Travel Rule;
- sanctions screening;
- STR;
- tipping-off;
- other reporting; and
- record retention.
FIU-IND Registration Is Mandatory
The current 2026 Guidelines state that registration with FIU-IND is a mandatory prerequisite for VDA SPs engaged in the notified activities.
The Guidelines further state that:
NON-REGISTRATION MAY INVITE ACTION UNDER SECTION 13(2).
The compliance question is therefore not:
βDID WE CREATE A FINGATE LOGIN?β
It is:
βDID WE COMPLETE THE FORMAL FIU-IND REGISTRATION PROCESS?β
Current Registration Process: Reference ID Is Not Final Registration
The present process can be understood as:
FINGATE APPLICATION β AWAITING APPROVAL β TEMPORARY REFERENCE ID β DOCUMENT REVIEW β IN-PERSON MEETING β DIRECTOR'S APPROVAL β FIU RE-ID.
Under the 2026 framework:
- the applicant initiates registration on FINGate;
- an βawaiting approvalβ status is generated;
- a temporary Reference ID is issued;
- FIU-IND examines the prescribed material;
- an in-person meeting follows where the file is considered ready;
- formal approval is required; and
- the FIU Reporting Entity ID is assigned after satisfactory completion.
A temporary Reference ID should therefore not be represented as conclusive proof that registration was formally completed.
The In-Person FIU-IND Registration Meeting
The current 2026 Guidelines require mandatory attendance by:
DESIGNATED DIRECTOR + PRINCIPAL OFFICER.
The purpose is not merely document verification.
The applicant must be capable of demonstrating its AML/CFT/CPF systems.
Prepare a Live Demonstration of:
- KYC systems;
- customer-risk assessment;
- transaction monitoring;
- blockchain analytics;
- Travel Rule compliance;
- sanctions screening;
- alert generation;
- case management;
- STR escalation; and
- other applicable AML tools.
The registration meeting therefore tests:
OPERATIONAL READINESS, NOT JUST POLICY DOCUMENTS.
Registration Documentation: Prepare the Corporate Story Before FIU Asks
The applicant should be capable of explaining:
- what VDA service it actually provides;
- which notified activity applies;
- when operations began;
- whether the business is currently operational;
- corporate structure;
- holding-company structure;
- group entities;
- Significant Beneficial Ownership;
- principal place of business;
- India operating structure;
- material service-provider arrangements;
- custodial arrangements;
- platform relationships;
- overseas affiliates;
- financial history;
- GST / tax records where applicable;
- VDA TDS filings where applicable;
- AML questionnaire responses; and
- cybersecurity audit material required by the current registration framework.
Current registration material should be internally consistent.
The corporate chart should not identify one controller while:
- MCA records;
- shareholding;
- voting agreements;
- bank mandates;
- founder rights; or
- other corporate records
tell a materially different story without explanation.
Significant Beneficial Ownership: Why FIU Wants to Know Who Really Controls the VDA SP
The registration framework requires disclosure concerning significant ownership of the reporting entity.
A proper ownership note should map:
DIRECT SHAREHOLDER β INTERMEDIATE ENTITY β HOLDING ENTITY β NATURAL-PERSON OWNERSHIP / CONTROL.
Consider:
- shareholding;
- capital rights;
- voting rights;
- right to appoint directors;
- shareholders' agreements;
- founder-control rights;
- convertible instruments;
- trust or nominee structures;
- overseas holding vehicles; and
- other forms of effective control.
Do Not Confuse Two Different Concepts
SBO OF THE VDA SERVICE PROVIDER
concerns ownership/control of the applicant itself.
BENEFICIAL OWNER OF A CUSTOMER
is a client due-diligence issue governed by the PML Rules and applicable CDD framework.
The two exercises should be documented separately.
Principal Officer: The 2026 Framework Raises the Governance Standard
The Principal Officer is not merely the person whose email ID appears on FINGate.
The 2026 Guidelines expect the PO to:
- be a management-level officer;
- preferably be at least Head Audit / Compliance / Risk level or equivalent;
- work exclusively and full-time for the reporting entity;
- have sufficient authority and independence;
- have at least three years of relevant experience;
- understand AML/CFT/CPF laws and reporting obligations;
- understand VDA-sector ML/TF vulnerabilities and typologies;
- have access to customer and transaction information;
- have adequate staff and technical resources;
- be capable of responding to FIU / LEA requests;
- be based in India;
- avoid conflicting active business/operational responsibility; and
- be separate from the Designated Director.
The PO should also have the organisational ability to escalate material issues to senior management and the Board / appropriate committee.
Designated Director: Overall Chapter IV Accountability
The Designated Director is responsible for overall compliance with Chapter IV.
Under the 2026 Guidelines this includes ensuring that appropriate internal mechanisms exist for:
- CDD records;
- transaction records;
- record maintenance;
- Rule 3 reporting;
- Section 12A responses;
- risk assessment;
- transaction monitoring;
- staff compliance;
- resources;
- controls;
- training; and
- accurate FIU reporting.
The correct governance model is:
DESIGNATED DIRECTOR = OVERALL OVERSIGHT PRINCIPAL OFFICER = OPERATIONAL AML IMPLEMENTATION / FIU REPORTING.
Customer Due Diligence Under the 2026 VDA Guidelines
The current VDA Guidelines emphasise that VDA transactions can be:
- rapid;
- cross-platform;
- pseudonymous;
- cross-border;
- wallet-based; and
- difficult to evaluate without combining on-chain and off-chain information.
The CDD framework therefore extends beyond collecting a name and PAN.
The 2026 Guidelines contemplate data including:
- client identity;
- verified PAN;
- beneficial ownership;
- risk profile;
- purpose / intended relationship;
- IP address with timestamp;
- geolocation;
- Device ID;
- VDA wallet addresses;
- transaction hashes;
- transaction history;
- behavioural indicators;
- source information where required; and
- ongoing due diligence.
The current Guidelines specifically require PAN to be obtained and verified for onboarding and/or undertaking VDA-related activity.
Periodic KYC and Enhanced CDD: The 2026 VDA Standard Is Tight
The updated VDA framework currently provides:
| Client Category | Minimum Periodic KYC Update |
|---|---|
| High Risk | At least once every 6 months |
| Other Clients | At least once every year |
Earlier updating may be required when material changes occur.
Enhanced Measures
The current Guidelines require enhanced measures in specified higher-risk cases including:
- customers connected with high-risk jurisdictions;
- relevant FATF grey / black-list jurisdictions;
- PEPs; and
- non-profit organisations.
A VDA SP should maintain evidence showing:
WHY THE CUSTOMER WAS RISK-RATED, WHAT ENHANCED CHECK WAS DONE, WHO APPROVED IT, AND HOW THE RELATIONSHIP WAS MONITORED.
Wallet and Transaction Monitoring: On-Chain and Off-Chain Data Must Connect
The 2026 Guidelines require continuous monitoring.
The transaction-monitoring framework should be able to analyse:
- fiat-to-fiat transactions relevant to the relationship;
- fiat-to-VDA;
- VDA-to-fiat;
- VDA-to-VDA;
- origin wallet;
- destination wallet;
- counterparty VDA SP;
- transaction hash;
- customer profile;
- volume;
- velocity;
- behavioural changes;
- blockchain exposure;
- sanctions links;
- known illicit-service exposure;
- high-risk counterparties;
- geographic risk; and
- relevant FIU red-flag indicators and typologies.
The 2026 Guidelines state that systems should be capable of identifying the:
ORIGIN AND DESTINATION OF A VDA.
Alerts should be reviewed without delay by the AML/CFT/CPF monitoring function and the Principal Officer.
Automation, risk-scoring and technologies such as AI/ML may support monitoring where appropriate to scale and risk.
Travel Rule: VDA Transfers Need Originator and Beneficiary Transparency
The Travel Rule is a major 2026 operational requirement.
For VDA transfers involving reporting entities, the framework requires collection, holding and transmission of prescribed:
- originator information;
- beneficiary information; and
- relevant account / wallet identifiers.
The originating RE should undertake appropriate CDD and sanctions screening concerning the counterparty.
The technological solution should permit the required information to be transmitted:
BEFORE, SIMULTANEOUSLY WITH, OR CONCURRENTLY WITH THE VDA TRANSFER.
POST-FACTO TRANSMISSION IS NOT THE CURRENT FIU STANDARD.
A historical remediation review should therefore identify:
- when Travel Rule capability became operational;
- which transfer categories were covered;
- which counterparty VDA SPs were supported;
- whether required originator/beneficiary information was captured;
- whether missing-data transfers were identified; and
- what controls now operate.
Sanctions Screening Must Operate at the Transaction Level
The current Guidelines require sanctions screening at minimum:
- at onboarding;
- when KYC information changes;
- when sanctions lists change; and
- when a VDA transaction is initiated.
The framework requires appropriate safeguards so a VDA transfer is not completed without the necessary sanctions screening.
Depending upon architecture, this may involve:
- transaction hold;
- wallet hold;
- pre-release screening;
- counterparty screening;
- blockchain-risk analysis; and
- escalation to the AML team.
The VDA SP should be able to demonstrate this functionality in the FIU in-person registration process.
STR: The Question Is Not Merely How Many Reports Were Filed
The current Guidelines expect robust alert generation and high-quality STR analysis.
A useful internal decision trail is:
ALERT β KYC CONTEXT β WALLET ANALYSIS β TRANSACTION HISTORY β BLOCKCHAIN ANALYTICS β COUNTERPARTY β IP / DEVICE DATA β BEHAVIOURAL CONTEXT β AML ANALYSIS β PRINCIPAL OFFICER DECISION β STR OR DOCUMENTED CLOSURE.
FIU's 2026 VDA framework expressly expects STR reporting to leverage information such as:
- KYC;
- wallets;
- transactions;
- counterparties;
- IP addresses;
- Device IDs;
- technical metadata;
- behavioural insights; and
- grounds of suspicion.
STR applies regardless of monetary value where the statutory suspicion test is reached.
Attempted transactions are included.
The reporting deadline remains:
PROMPTLY AND NOT LATER THAN 7 WORKING DAYS AFTER THE PRINCIPAL OFFICER IS SATISFIED THAT THE TRANSACTION IS SUSPICIOUS.
Remediation After Operating Without Full Compliance
A VDA SP that discovers historical non-compliance should avoid two extremes:
EXTREME 1: deny every issue even where records show a real gap.
EXTREME 2: make a blanket admission that every historic transaction was non-compliant.
Instead build a controlled remediation matrix.
| Area | Historic Position | Current Action | Evidence |
|---|---|---|---|
| FIU registration | _____ | _____ | _____ |
| DD | _____ | _____ | _____ |
| PO | _____ | _____ | _____ |
| CDD | _____ | _____ | _____ |
| BO | _____ | _____ | _____ |
| Transaction monitoring | _____ | _____ | _____ |
| Blockchain analytics | _____ | _____ | _____ |
| Travel Rule | _____ | _____ | _____ |
| Sanctions screening | _____ | _____ | _____ |
| STR | _____ | _____ | _____ |
| Record retention | _____ | _____ | _____ |
Step 1 β Determine the Actual Coverage Date
Identify:
- notified activity;
- business model;
- Indian-client nexus;
- operational start date;
- service launch dates;
- custodial/non-custodial role;
- transfer function; and
- issuer-service function, where relevant.
Step 2 β Complete Registration Properly
Registration should be taken through the current process rather than assuming a portal reference cures the deficiency.
Step 3 β Build the Historical Customer Universe
Determine:
- customer count;
- active / inactive accounts;
- verified PAN status;
- BO completeness;
- risk rating;
- PEP/sanctions review;
- wallet linkage;
- IP / Device information availability; and
- KYC deficiencies.
Step 4 β Reconstruct Transaction Monitoring
Map:
- fiat flows;
- VDA deposits;
- withdrawals;
- wallet addresses;
- transaction hashes;
- counterparties;
- historic alerts;
- blockchain-risk exposure;
- Travel Rule data; and
- sanctions results.
Step 5 β Conduct an STR Look-Back
Do not bulk-file STRs merely to appear cooperative.
Each potential STR should involve actual application of mind to:
- customer;
- transactions;
- wallets;
- counterparties;
- technical data;
- economic rationale;
- risk indicators; and
- grounds of suspicion.
Step 6 β Preserve Historic Truth
Do not backdate:
- PO appointment;
- DD appointment;
- Board approvals;
- AML policy;
- risk assessment;
- training;
- CDD review;
- sanctions screening;
- Travel Rule controls;
- blockchain monitoring; or
- STR analysis.
Current remediation must carry:
CURRENT DATES.
Recent FIU-IND VDA Section 13 Orders: Factual Enforcement Examples Only
Recent published FIU-IND orders demonstrate that VDA compliance failures can result in materially different Section 13 outcomes.
| Entity | Published Order Date | Published Outcome |
|---|---|---|
| KuCoin / Peken Global Ltd. | 22 March 2024 | βΉ34.50 lakh penalty |
| Binance | 19 June 2024 | βΉ18.82 crore aggregate penalty and directions |
| Bybit Fintech Ltd. | 31 January 2025 | βΉ9.27 crore aggregate penalty and specific directions |
| Coinbase | 6 March 2025 | Warning and specific compliance directions in the published summary |
FIU's published summaries expressly state that they are:
REPRESENTATIONAL AND NOT PRECEDENT.
Accordingly, these orders should be used to understand factual enforcement patterns.
They should not be cited as establishing that:
- every offshore VDA provider automatically incurs the same penalty;
- every delay equals the same number of failures;
- registration automatically removes historical liability;
- cooperation always results in warning;
- every VDA SP will receive monetary penalty; or
- the same factual matrix applies to another provider.
How to Prepare the Section 13 Response
Build the response charge by charge.
| Issue | FIU Allegation | Historic Position | Evidence | Remediation |
|---|---|---|---|---|
| Reporting-entity status | _____ | _____ | _____ | _____ |
| Registration | _____ | _____ | _____ | _____ |
| PO | _____ | _____ | _____ | _____ |
| DD | _____ | _____ | _____ | _____ |
| CDD / BO | _____ | _____ | _____ | _____ |
| Monitoring | _____ | _____ | _____ | _____ |
| Travel Rule | _____ | _____ | _____ | _____ |
| Sanctions | _____ | _____ | _____ | _____ |
| STR | _____ | _____ | _____ | _____ |
Separate:
- legal applicability dispute;
- factual denial;
- historic failure genuinely accepted;
- data discrepancy;
- subsequent remediation; and
- current operational status.
Do not rely on:
βWE ARE FULLY COMPLIANT NOW.β
Prove:
WHAT WAS IMPLEMENTED, WHEN, BY WHOM, IN WHICH SYSTEM, AND HOW IT WAS TESTED.
VDA Section 13 Remediation Flowchart
A VDA SP facing Section 13 action should separate statutory coverage, registration, historic controls and current remediation rather than relying on present registration as a complete answer to the historic period.Common Mistakes in VDA Section 13 Remediation
- Assuming a temporary FINGate Reference ID equals formal registration.
- Assuming later registration eliminates historic non-registration.
- Failing to disclose actual ownership/control.
- Confusing SBO of the VDA company with BO of a customer.
- Using the same individual as PO and DD despite the current VDA guideline expectation that they be separate.
- Appointing a nominal PO with no authority.
- Using a part-time external PO without checking current VDA requirements.
- Having the PO actively run conflicting business operations.
- Maintaining no historic version of the AML policy.
- Collecting only PAN and calling it complete CDD.
- Failing to preserve wallet addresses and transaction hashes.
- Having blockchain analytics but no documented alert escalation.
- Ignoring fiat-side transaction activity.
- Implementing Travel Rule only after transfers have completed.
- Screening sanctions only at onboarding.
- Having no control for sanctions screening at transaction initiation.
- Assuming every blockchain alert automatically requires an STR.
- Assuming no STR is required because transaction value is low.
- Bulk-filing historic STRs without application of mind.
- Backdating AML policies.
- Backdating PO/DD appointments.
- Backdating KYC refresh.
- Describing a retrospective blockchain review as contemporaneous monitoring.
- Failing to separate historic failure from present remediation.
- Treating Binance, Bybit or KuCoin penalty amounts as automatic precedents for another entity.
Frequently Asked Questions
1. Which VDA businesses fall under PMLA?
Specified VDA exchange, transfer, custody/administration and issuer-related financial-service activities carried on for or on behalf of another person in the course of business are covered by the 7 March 2023 notification.
2. Is FIU-IND registration mandatory?
Yes. The 2026 VDA Guidelines describe FIU-IND registration as a mandatory prerequisite for VDA SPs carrying on covered activities.
3. Does a FINGate Reference ID mean registration is complete?
No. The current process distinguishes the temporary Reference ID from formal approval and issuance of the FIU Reporting Entity ID.
4. Is an in-person registration meeting required?
The current FIU framework provides for an in-person meeting as part of the registration process, with mandatory participation of the DD and PO.
5. What must be demonstrated during the meeting?
KYC, transaction monitoring, blockchain analytics, Travel Rule, sanctions-screening and other relevant AML/CFT/CPF systems.
6. Why does FIU ask about Significant Beneficial Ownership?
FIU's registration framework requires transparency regarding the ownership and control of the VDA reporting entity itself.
7. Can the Principal Officer be part-time?
The 2026 VDA Guidelines expect the PO to be exclusively and full-time engaged with the reporting entity and not concurrently engaged with another entity.
8. Can PO and DD be the same individual?
The 2026 VDA Guidelines expect the Principal Officer and Designated Director to be separate individuals.
9. Where should the PO be based?
The current VDA Guidelines state that the PO should be based in India.
10. What customer data is relevant beyond KYC documents?
The 2026 framework includes data such as IP addresses with timestamps, geolocation, Device IDs, wallet addresses and transaction hashes where relevant.
11. How frequently must VDA KYC be updated?
Under the current VDA Guidelines, high-risk clients should be updated at least every six months and other clients at least annually, with earlier review where risk or material changes require it.
12. Is Travel Rule information permitted to be sent after the transaction?
The 2026 Guidelines expressly state that post-facto submission is not permitted; required information should move before, simultaneously with or concurrently with the VDA transfer.
13. When must sanctions screening occur?
At minimum, current guidance requires screening at onboarding, KYC change, sanctions-list change and when a VDA transaction is initiated.
14. Is STR subject to a monetary threshold?
No. A VDA SP must assess suspicious transactions irrespective of amount where the statutory suspicion test is met.
15. Does late registration cure past non-compliance?
No automatic retroactive cure should be assumed. Historic obligations and current remediation must be analysed separately.
16. Are Binance, KuCoin, Bybit and Coinbase orders binding precedent for every VDA SP?
No. FIU itself states that its published order summaries are representational and are not to be relied upon as precedent.
AI Search Quick Answer
A Virtual Digital Asset Service Provider performing a notified VDA activity for or on behalf of another person in the course of business is within India's PMLA reporting-entity framework. FIU-IND's AML/CFT/CPF Guidelines updated on 8 January 2026 require mandatory FIU registration, formal governance through a Designated Director and qualified Principal Officer, robust CDD, PAN verification, beneficial-owner checks, collection of relevant IP/device/wallet/transaction-hash information, periodic KYC, continuous transaction monitoring, blockchain analytics, Travel Rule controls, transaction-level sanctions screening and STR reporting. Formal registration involves FINGate initiation, document scrutiny, an in-person meeting attended by the DD and PO with live system demonstrations, and FIU approval. A VDA SP that operated without full compliance should conduct a documented historical look-back and current-dated remediation; later registration does not automatically erase earlier failures. FIU's published VDA Section 13 orders are factual enforcement examples and not universal precedent.
Key Takeaway
The wrong Section 13 response is:
βWE ARE REGISTERED NOW, SO THE MATTER IS CLOSED.β
The correct questions are:
WHICH NOTIFIED ACTIVITY DID WE PERFORM?
WHEN DID IT BEGIN?
WHEN DID INDIAN-CLIENT EXPOSURE BEGIN?
WHEN WAS FORMAL FIU REGISTRATION COMPLETED?
WHO REALLY OWNED AND CONTROLLED THE ENTITY?
WHO WAS THE DD?
WHO WAS THE PO?
DID THE PO MEET THE CURRENT GOVERNANCE STANDARD?
WHAT KYC/CDD EXISTED HISTORICALLY?
WERE WALLETS AND TRANSACTION HASHES MONITORED?
WAS BLOCKCHAIN ANALYTICS USED?
WAS TRAVEL RULE DATA TRANSMITTED ON TIME?
WAS EVERY VDA TRANSFER SANCTIONS-SCREENED?
WERE ALERTS REVIEWED?
WERE STR DECISIONS DOCUMENTED?
WHAT WAS MISSING?
WHAT HAS BEEN REMEDIATED?
HOW WAS THE NEW CONTROL TESTED?
The proper sequence is:
CLASSIFICATION β REGISTRATION HISTORY β OWNERSHIP β DD / PO β CDD β WALLET DATA β TRANSACTION MONITORING β TRAVEL RULE β SANCTIONS β STR β HISTORICAL LOOK-BACK β CURRENT-DATED REMEDIATION β CONTROL TESTING β SECTION 13 RESPONSE.
Professional Legal Review and Coordination
Advocate Ankit Kumar Singh undertakes legal research and regulatory-response work concerning VDA reporting-entity classification, FIU-IND registration issues, Section 13 proceedings, historical compliance review and AML/CFT/CPF remediation depending upon the facts, applicable jurisdiction and accepted professional engagement.
A VDA compliance / Section 13 review may include:
- S.O. 1072(E) activity classification;
- India-nexus analysis;
- registration chronology;
- FINGate status;
- FIU RE-ID status;
- Significant Beneficial Ownership mapping;
- corporate-structure review;
- Designated Director review;
- Principal Officer qualification review;
- AML policy versioning;
- CDD gap analysis;
- beneficial-owner review;
- PAN/KYC remediation;
- wallet and transaction mapping;
- blockchain-analytics controls;
- Travel Rule review;
- sanctions-screening review;
- STR decision-log review;
- historical STR look-back;
- record-retention review;
- Section 12A response;
- Section 13 show cause response;
- personal-hearing preparation;
- corrective-action tracker; and
- Section 26 appellate strategy where required.
Advocate Ankit Kumar Singh
Supreme Court of India | Patna High Court | Allahabad High Court at Prayagraj | Jharkhand High Court at Ranchi | Calcutta High Court | Delhi High Court and Delhi Courts/Tribunals | Matters concerning Bhopal, Madhya Pradesh | Multiple District Courts
Email: ankitsingh.legum@gmail.com
Website: advocateankitkumarsingh.in
Professional engagement depends upon the facts, entity structure, business activity, current FIU requirements and procedural stage. No registration approval, Section 13 closure, warning-only outcome, penalty reduction or appellate result can be guaranteed.
Official Sources
- FIU-IND β AML & CFT Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets, updated 8 January 2026
- FIU-IND β Third Revision of Circular for Registration of VDA Service Providers dated 15 September 2025
- FIU-IND β Official Downloads and Current VDA Guidance
- FIU-IND β Prevention of Money-Laundering Act, 2002
- FIU-IND β Prevention of Money-laundering (Maintenance of Records) Rules, 2005
- FIU-IND β Published Section 13 Compliance Orders
- FIU-IND β KuCoin / Peken Global Ltd. Section 13 Order
- FIU-IND β Binance Section 13 Order
- FIU-IND β Bybit Section 13 Order
- FIU-IND β Coinbase Section 13 Order
Add Advocate Ankit Kumar Singh as a Preferred Source on Google
Readers who want to see more legal research, court updates, cyber law, PMLA, ED, criminal-law and litigation content from Advocate Ankit Kumar Singh can add advocateankitkumarsingh.in as a Preferred Source on Google.
Add advocateankitkumarsingh.in as a Preferred Source on Google
Conclusion
The 2026 VDA compliance framework is no longer satisfied by a policy PDF and a registration application.
FIU-IND's current framework expects operational evidence.
A VDA SP should be able to demonstrate:
WHO OWNS THE ENTITY + WHO GOVERNS AML + WHO IS THE PRINCIPAL OFFICER + WHO THE CUSTOMERS ARE + WHO THE BENEFICIAL OWNERS ARE + WHICH WALLETS THEY USE + WHERE VDA COMES FROM + WHERE IT GOES + WHAT THE BLOCKCHAIN ANALYTICS SHOW + WHETHER TRAVEL RULE DATA MOVED WITH THE TRANSFER + WHETHER SANCTIONS SCREENING OCCURRED + WHY AN ALERT WAS CLOSED OR REPORTED + AND WHAT RECORD PROVES EACH STEP.
Where a business operated without full compliance, the strongest strategy is not to rewrite history.
It is to make the history:
TRACEABLE + DATED + EVIDENCED + RECONCILED + REMEDIATED + TESTED.
That is the difference between:
REGISTRATION AFTER A NOTICE
and:
A DEFENSIBLE SECTION 13 REMEDIATION PROGRAMME.
Professional / Legal Disclaimer: This article provides general legal and regulatory information concerning Virtual Digital Asset Service Providers under the PMLA framework and FIU-IND's AML/CFT/CPF Guidelines updated on 8 January 2026. The precise obligations applicable to a particular VDA business depend upon its services, corporate structure, customer nexus, operational history, registration status, technology architecture, wallet/custody model, transaction history and current FIU directions. Recent FIU-IND Section 13 orders mentioned in this article are used only as factual enforcement examples. FIU-IND's own published summaries state that they are representational and are not legal precedent. A live Section 13 matter should be reviewed from the original notice, complete administrative record and current law. No particular regulatory outcome can be guaranteed.
