Sign up on a crypto platform that serves Indian users today and the process goes well past uploading a PAN card. The app asks you to look into the camera for a live check, it wants to read your location, and it checks your bank account before you can add a rupee. This is not the platform being fussy. The steps come from the Financial Intelligence Unit-India, the Finance Ministry body that receives reports on suspicious money flows.

FIU-IND's AML and CFT guidelines for entities providing services related to virtual digital assets were last updated on 8 January 2026. The document runs to 33 pages and is written for compliance officers, not customers. This explainer pulls out the parts that decide what you see on your phone and what the platform has to do in the background, as of 8 October 2026.

Why crypto platforms answer to FIU-IND

Crypto businesses came under India's anti-money laundering law on 7 March 2023. A Finance Ministry notification issued that day, S.O. 1072(E), brought five activities under the Prevention of Money-laundering Act, 2002 when they are carried out for someone else in the course of business: exchanging virtual digital assets for fiat currency, exchanging one VDA for another, transferring VDAs, safekeeping or administering VDAs or the tools that control them, and taking part in financial services linked to an issuer's offer or sale of a VDA.

Anyone doing these things is a reporting entity under the PMLA. The guidelines call registration with FIU-IND a "mandatory pre-requisite" and say non-registration is a violation of the Act that can invite action under section 13. The duty is tied to the activity, not the address. A platform run from overseas that lets people in India trade is covered in the same way as one with an office in Bengaluru.

Registration is not a quick online form. The applicant first enters its details on FIU-IND's FINGate portal and gets a temporary reference ID. It is formally registered only after it submits the listed documents, attends an in-person meeting and gets the Director's approval, after which it is given an FIU Reporting Entity ID. One of the documents is a cyber security audit certificate from a CERT-In empanelled auditor, confirming compliance with CERT-In's directions of 28 April 2022.

What you will be asked at sign-up

The guidelines set a minimum list of details a platform must collect from an individual customer: full name as it appears on the PAN, date of birth, gender, PAN, an identity document and its number, nationality, address, mobile number, email ID, occupation, income range and bank account details. PAN is compulsory both for opening the account and for any VDA activity after that.

Along with the PAN, you give one identity document: a passport, driving licence, proof of possession of an Aadhaar number or a voter ID card, or the equivalent e-document. The mobile number and email ID are confirmed through an OTP or a verification link.

Then come the three checks that catch most first-time users off guard. The first is a selfie with liveness detection. The platform has to be satisfied that the person whose documents are being used is the same person holding the phone and creating the account, so it captures a live photograph and uses software to confirm a real person is present. A printed photo or someone else's picture is meant to fail.

The second is location. The onboarding system has to record the latitude and longitude of the place where you complete verification, with the date, the time and your IP address. If those coordinates do not match the address you have given, the platform must apply enhanced due diligence. Signing up while visiting your hometown is not against any rule, but a mismatch can mean extra checks.

The third is the bank account. It has to be verified through a penny-drop, a very small test transfer that confirms the account exists, is working and is in your name. Behind the scenes the platform also collects device IDs, IP addresses with timestamps, wallet addresses and transaction hashes for monitoring and risk assessment.

KYC is not a one-time job

Because the guidelines treat VDAs as high risk, customer details have to be refreshed regularly. Customers rated high risk must go through KYC updation at least once every six months and all others at least once a year, counted from the date the account was opened or last updated. If an app asks you to redo the selfie a year after you joined, this is the reason. Customers are also expected to tell the platform promptly when their details change.

Platforms must keep identity records for at least five years after the relationship ends, and transaction records for at least five years from the date of the transaction, in enough detail to rebuild any single trade. They file suspicious transaction reports with FIU-IND, send it a monthly report and are barred from tipping off a customer that a report has been made.

What platforms are told to refuse

Some activity is off limits. Platforms must not allow deposits or withdrawals of anonymity-enhancing crypto tokens, which the guidelines call AECs, or of any VDA designed to hide the origin, ownership or value of a transaction. Transfers routed through mixers or tumblers, services that blend coins to obscure where they came from, must be picked up by monitoring tools and not processed. Initial coin and token offerings are "strongly discouraged".

Transfers to and from wallets you control yourself, called unhosted wallets, are not banned. The platform has to collect data on them, judge the risk and may add its own limits or block some transfers. When crypto moves from one registered platform to another, the sending platform must pass on the sender's PAN, identity document number, name, wallet address, verified address and date of birth, along with the receiver's name and wallet address, before or at the same time as the transfer. This is India's version of what regulators call the travel rule.

Each platform also has to display a summary of its AML policies prominently on its website or app, which is a quick thing to look for before you sign up.

A simple check before you sign up

Registration with FIU-IND is the floor the law sets, and a registered platform holds an FIU Reporting Entity ID, so asking for it is a fair question. The guidelines say an unregistered VDA service provider is liable to compliance action under section 13 of the PMLA. It is also a useful scam filter, because many investment frauds start with an app that only looks like a real trading platform, as in the case of a Varanasi man who lost Rs 13 lakh to a fake trading app. Market regulators in India and the US used World Investor Week to warn about impersonation scams as well.

None of this changes how crypto is taxed, which is a separate matter under the Income-tax Act, 2025. What the guidelines do is tie a crypto account in India to your PAN, your face, your bank account and the place you signed up from. The full text is on FIU-IND's website under Downloads. This is information, not advice.