India’s Financial Intelligence Unit (FIU) has issued non-compliance notices to 15 crypto exchanges, specifically, Virtual Digital Asset Service Providers (VDASPs) under the country’s Anti-Money Laundering (AML) law. The notice includes shutting down their apps and URLs from public access in India.
The Origin Story
In India, VDASPs must comply with the Prevention of Money Laundering Act, 2002 (PMLA) regulations. Businesses offering services such as crypto-to-fiat exchanges, virtual-asset transfers, or digital asset administration typically fall within the PMLA reporting-entity framework.
The case centers on Section 13 of the PMLA, which allows India’s FIU Director to impose fines. It can also enforce disciplinary action on companies that fail to meet full AML obligations. Notably, the 15 companies involved in the case do not all necessarily have physical offices in India. Most operate across several jurisdictions and serve global customer bases.
As such, crypto firms face a clear warning. India’s AML and Counter-Terrorism Financing (CTF) rules apply, regardless of any physical presence. Any crypto exchange that provides services to customers in India must comply with local laws or could face potential enforcement action.
Details on the 15 Crypto Exchanges Involved
The notice covers 15 different exchanges and how their existing compliance framework satisfied India’s PMLA. However, the authorities did not explicitly state the exact violations. The companies involved spanned derivatives platforms, centralized exchanges, and other virtual-asset services..

The range of businesses the FIU targets tells a compelling story. Authorities are focusing not only on the label a company uses to describe its operations, but also on the actual activities or services it offers. You can learn more here: Cryptocurrency Regulation in India.
India’s Stringent Stance Around Crypto
India’s latest crackdown on 15 crypto platforms is easier to understand when viewed as part of a broader regulatory campaign. Indian authorities have progressively broadened the AML perimeter around Virtual Digital Assets (VDAs).
However, the government takes an unusually clear position on one point: a crypto company’s AML obligations depend on its activity, not its jurisdiction. That matters to international compliance teams. Over the last 20 months, India has shown that this stance is not just theory.
In 2025, India’s FIU updated its VDA-registration framework twice. First on 20 January and the next on 15 September. This happened before it targeted 25 more offshore crypto providers on 1 October 2025 and issued notices to take down their apps and URLs.
On January 8, 2026, the regulator took another step by issuing updated AML guidelines for businesses providing VDA-related services. The framework is not just telling an exchange to register. It covers key regulatory mandates on governance, Due Diligence della clientela (CDD), ongoing monitoring, the crypto Travel Rule, and higher-risk areas such as unhosted wallets and anonymity-enhancing products.
Cosa succede dopo?
The 15 platforms named by the FIU will likely prioritize regulatory engagement and remediation. India’s previous reaction to offshore VDASP suggests the way ahead may be to respond to FIU notices, assess whether registration as a reporting entity is necessary, correct flaws in Controlli AML, and pay financial penalties if violations are proven.
The commercial risk is immediate market access. If takedown notices are implemented, affected platforms could find it harder for Indian users to access their websites or apps while proceedings continue.
Avoiding Scrutiny from India’s Financial Intelligence Unit
The importance for compliance teams at international crypto businesses extends far beyond these 15 companies. The first question should be: Are we serving Indian customers even if we don’t have a legal entity, office, or staff in India? Here are the three key takeaways all AML teams must learn from this case:
1. Localize AML controls for every jurisdiction: Regulations can evolve quickly and vary drastically from country to country. Businesses must tailor every workflow, policy, and monitoring process to each jurisdiction’s requirements. Combining ongoing monitoring and policy assurance solutions equips firms to identify regulatory changes early and assess whether existing controls still meet local laws.
2. Technology only works when backed by strong governance: Sophisticated AML and monitoring tools cannot compensate for weak oversight or poor compliance culture. Companies need clear ownership, effective escalation processes, regular testing, and evidence that controls are working. Additionally, firms should test compliance controls continuously against evolving risks.
3. Regulators look at what you do, not simply where you are based: The FIU’s action reinforces that regulatory exposure can be driven by the services a company provides and the customers it serves. For crypto firms operating across borders, this means assessing obligations market by market rather than assuming that a lack of physical presence removes local compliance responsibilities.

Scopri altre notizie sull'AML in ComplyCube Newsletter Trust Edition. Analizziamo gli ultimi sviluppi in materia di verifica dell'identità e antiriciclaggio a livello globale.



