India's FIU Targets 15 Crypto Platforms in PMLA Crackdown
India's Financial Intelligence Unit has issued non-compliance notices to 15 crypto platforms and is actively seeking the removal of their applications and URLs from public access in India. The action, taken under the Prevention of Money Laundering Act, confirms that the country's AML enforcement regime now reaches offshore platforms serving Indian users, regardless of where those platforms are incorporated. For accounting firms, auditors, and CFOs whose clients interact with any of the named exchanges, the practical implications land immediately.
What the FIU Has Actually Done
India's Financial Intelligence Unit, the country's primary AML supervisor for designated non-financial businesses and professions including virtual digital asset service providers, issued the non-compliance notices on 9 September 2026. The notices target 15 platforms: Weex, Blofin, Bitunix, DigiFinex, Toobit, Rezorex, XT.com, Latoken, WOO X, Pionex, ChangeNow, SimpleSwap, FixedFloat, WhiteBIT, and Guardarian.
Beyond issuing the notices, the FIU is pursuing takedowns of each platform's mobile applications and website URLs from Indian app stores and internet service providers. The combination of a formal notice and a takedown request is a materially more aggressive posture than a registration warning alone.
The Legal Basis: PMLA and the 2023 Extension
The notices rest on the framework established in March 2023, when India's Finance Ministry expanded the Prevention of Money Laundering Act to bring virtual digital asset service providers explicitly within its scope. Under that expansion, any entity offering crypto exchange, transfer, custody, or related services to users in India must register with the FIU and comply with PMLA obligations, including transaction reporting, record-keeping, and customer due diligence requirements.
Critically, the Finance Ministry clarified that these obligations are not contingent on a platform having a physical office in India. An offshore exchange with Indian-resident users is as liable as a domestically incorporated one. The 15 platforms named in this action are alleged to have been operating in India without completing that registration or meeting the associated compliance requirements.
The FIU's Warning on Unregulated Products
Alongside the enforcement action, the FIU restated that crypto products and NFTs remain unregulated in India. It warned users explicitly that transactions on unregistered or non-compliant platforms may carry no regulatory recourse if something goes wrong. That warning has direct implications for how advisers assess client risk exposure to these platforms.
Context: How India Got Here
The March 2023 PMLA extension was the starting point, but enforcement has been building in stages. The pattern of prior actions shows the FIU is willing to move against even well-known global platforms when registration is incomplete.
Precedents That Shaped the Current Action
Several large exchanges previously restricted or paused services in India while completing their FIU registrations. One exchange temporarily suspended Indian user access in January 2025 before registering and restoring service. Another resumed Indian user onboarding only after completing registration. Binance returned to the Indian market in 2024 following payment of a penalty of $2.25 million tied to earlier non-compliance.
Those precedents established a clear message: register and comply, or face service restrictions and financial penalties. The current action against 15 platforms, including several that are considerably smaller than Binance, signals the FIU is now moving down the list to less prominent players who may have assumed they were below the enforcement threshold.
The pattern mirrors enforcement trends in other jurisdictions. The way AUSTRAC's 45-registration sweep reshaped AML obligations for crypto firms in Australia is instructive: regulators globally are treating registration non-compliance as a predicate risk, not merely a paperwork failure.
Accounting and Audit Implications for Firms
The FIU action creates a set of concrete tasks for accounting firms serving clients with Indian crypto exposure, and for CFOs whose treasury or trading operations touch any of the 15 named platforms.
Counterparty Risk in the Books
If a client holds assets on any of the named platforms, the takedown notices raise immediate questions about asset recoverability. From an accounting standpoint, management must assess whether assets held on a platform subject to access restrictions meet the recognition and measurement criteria under applicable standards. Where there is genuine uncertainty about access, disclosure obligations under IAS 1 or equivalent frameworks may be triggered.
For firms using crypto accounting software to track exchange balances, the first practical step is confirming whether the software has live API connections to any of the 15 platforms and flagging those balances for manual review. Automated feeds from non-compliant or inaccessible exchanges cannot be treated as reliable without independent verification.
Transaction History and Record-Keeping
PMLA obligations require registered entities to maintain records of all transactions for five years. For clients who transacted through any of the 15 platforms before a potential access block, preserving those transaction records now, while the platforms are still accessible, is a time-sensitive priority. Once URL takedowns and app removals are enforced, export functionality may become unavailable.
Digital asset accounting software that captures on-chain data independently of exchange APIs provides a fallback here. Blockchain-sourced records can corroborate or substitute for exchange-issued statements if platform access is cut off. Firms should document the data provenance clearly for any audit trail.
KYC and CDD Obligations for Registered VDA Intermediaries
Indian-registered VDA service providers (exchanges, brokers, custodians) that routed client orders through any of the 15 named platforms as liquidity or settlement venues face additional scrutiny. The FIU's non-compliance findings against a counterparty are relevant to a registered firm's own customer due diligence and business relationship risk assessments. Compliance teams should review any correspondent or API-level relationships with the named platforms and consider whether continued engagement is consistent with their own PMLA obligations.
AML Red Flags and Suspicious Transaction Reporting
For clients who have been actively trading on the named platforms, the FIU action is itself a risk indicator that compliance functions need to assess. It does not automatically mean client activity was illicit, but the combination of a non-compliant platform and high-frequency trading activity warrants a fresh review of the client's transaction profile. The AML red flags surfaced by the Xinbi Guarantee case offer a useful framework for structuring that review: volume concentration, counterparty opacity, and lack of verifiable KYC on the other side of trades are the metrics to stress-test.
What Comes Next: Likely Enforcement Trajectory
Based on the FIU's stated intentions and the precedent set by earlier actions, firms should plan for several possible developments over the coming weeks and months.
Access Restrictions and Their Timeline
The FIU's request for takedowns of apps and URLs will need to be actioned by app store operators and Indian internet service providers. The timeline for enforcement is not publicly specified, but prior experience with similar regulatory directions in India suggests that ISP-level blocks can be implemented within days of a formal government request, while app store removals may take slightly longer depending on platform co-operation.
Platforms that choose to engage with the FIU and initiate registration may be able to negotiate a temporary stay of access restrictions, as has happened previously. Firms advising clients with assets on these platforms should monitor for any announcements from the named exchanges about compliance steps they are taking in response.
Penalty and Registration Path
The Binance precedent, a $2.25 million penalty followed by re-registration and market re-entry, suggests a structured path exists for platforms willing to comply. However, that path requires the platform to proactively engage with the FIU, complete KYC and AML program requirements, and submit to ongoing supervision. Smaller platforms on the current list may lack the compliance infrastructure to move quickly through that process.
Broader Market Structure Consequences
If a significant portion of the 15 platforms exit the Indian market rather than comply, Indian retail and institutional users will concentrate further on the smaller group of FIU-registered exchanges. That concentration has accounting consequences: it may reduce the number of data sources available for price verification and increase reliance on a narrower set of exchange-quoted prices for fair value measurement purposes.
Practical Steps for Accounting Firms Right Now
Three immediate actions cover the most critical risks:
- Audit your client exchange exposure. Run a check across your client base to identify any holdings or recent transaction history on the 15 named platforms. Flag these for partner-level review, not just staff-level monitoring.
- Export transaction records immediately. Advise clients to download full transaction histories from any of the named platforms now, before potential access restrictions take effect. CSV exports, API data pulls, and on-chain verification should all be captured and stored securely.
- Review your own crypto bookkeeping software integrations. Confirm whether your digital asset accounting software has active integrations with any named platform. Where it does, verify that data captured to date is archived in a format that does not depend on continued API access.
Firms serving Indian clients or clients with Indian-user exposure should also review their own AML policies to confirm that engagement with non-FIU-registered platforms is addressed explicitly as a risk factor, both for client onboarding and for ongoing monitoring.
Source: The Block
Frequently Asked Questions
Does the PMLA registration requirement apply to platforms with no office in India?
Yes. The Finance Ministry confirmed in 2023 that the obligation applies to any virtual digital asset service provider serving users in India, regardless of where the entity is incorporated or physically located.
What should an accounting firm do if a client holds assets on one of the 15 named platforms?
The immediate priorities are to export all available transaction records while platform access remains open, assess whether asset recoverability uncertainty triggers any disclosure obligations under applicable accounting standards, and flag the position for inclusion in the next AML risk review of that client relationship.
How does a platform get back into the Indian market after a non-compliance notice?
Prior cases suggest the path involves proactive engagement with the FIU, completion of the PMLA registration process including KYC and AML program implementation, and in some cases payment of a financial penalty. There is no publicly stated guaranteed timeline for this process.
Are NFTs and crypto tokens regulated under the PMLA framework?
The FIU has confirmed that crypto products and NFTs remain unregulated in India under the current framework, though VDA service providers handling them are subject to PMLA registration and reporting obligations. Users on unregistered platforms have no regulatory recourse for losses.
What does "non-compliant platform" mean for a firm's own AML suspicious transaction reporting obligations?
A client's use of a platform that has received a formal FIU non-compliance notice is a risk indicator that should be factored into the client's transaction monitoring profile. It does not automatically require a suspicious transaction report, but it warrants a documented review of whether the client's activity on that platform meets the firm's risk appetite and whether any reporting thresholds are triggered.
