VDA service-provider AML obligations
VDA service providers performing notified activities are reporting entities and must implement FIU registration, CDD, travel-rule/wire information, monitor
Finin2min summary
VDA service providers performing notified activities are reporting entities and must implement FIU registration, CDD, travel-rule/wire information, monitoring, reporting and sanctions controls under sector guidance.
Legal anchors
- PMLA notification for VDA activities
- FIU AML/CFT Guidelines reviewed 8 January 2026
- PML Rules
How to analyse it
- Confirm service and territorial nexus.
- Register on FIU systems.
- Implement wallet/customer attribution and blockchain analytics.
- File reports and retain travel-rule data.
Practical illustration
An offshore exchange serving Indian users may have FIU obligations depending on notified activity and India-facing operations.
What can go wrong?
- Geo-blocking assumptions
- No unhosted-wallet risk process
- Weak sanctions screening
Evidence pack
- Product map
- FIU registration
- Wallet analytics
- Travel-rule records
Decision workflow
- Freeze the facts and effective date.
- Identify the controlling Act, rule, notification, circular and jurisdictional overlay.
- Prepare a calculation or exposure note.
- Collect the evidence pack before filing, payment, signing or response.
- Record reviewer conclusion and assumptions.
Quick Q&A
Is the result automatic?
No. Confirm service and territorial nexus.
What is the most important control?
File reports and retain travel-rule data.
What should be escalated?
Geo-blocking assumptions, especially where money, deadlines, enforcement, personal liability or irreversible transaction steps are involved.
Official source trail
- PMLA, 2002 — FIU-IND
- PMLA, 2002 PDF — FIU-IND
- PML Maintenance of Records Rules, 2005 — FIU-IND
- FIU-IND FAQs
Secondary commentary may help interpretation, but it is not the source of law.