Virtual Digital Assets and AML Compliance: Crypto Rules for Banks (KYC AML)

KYCAML By Ashish Jain · IIBF STORE Editorial · 05 August 2026 · Updated 24 Sep 2026 · 10 min read · 31 views
Virtual Digital Assets and AML Compliance: Crypto Rules for Banks (KYC AML)

Crypto is no longer a regulatory blind spot for Indian banks. Since March 2023, the Prevention of Money Laundering Act, 2002 (PMLA) treats platforms dealing in cryptocurrency as full-fledged reporting entities, and virtual digital assets and AML compliance now sits squarely inside the KYC-AML syllabus every JAIIB and CAIIB candidate must master. Banks are not registered as VDA service providers themselves, but they touch this ecosystem every single day — customers move money in and out of exchanges through ordinary savings accounts, and branch staff must recognise the account patterns that betray crypto-linked layering.

This article walks through who counts as a reporting entity under the amended PMLA, how FIU-India registration and the travel rule work for crypto platforms, the common laundering typologies examiners test, and the bank account red flags your monitoring desk is expected to catch.

📜 VDA Service Providers as Reporting Entities under PMLA

On 7 March 2023, the Ministry of Finance issued a gazette notification bringing entities carrying on "virtual digital asset" (VDA) activities within the definition of a reporting entity under Section 2(1)(wa) of the PMLA. This closed a long-standing gap: crypto exchanges, custodial wallet providers, and VDA transfer platforms were till then largely outside the AML net that banks and NBFCs had operated under for years.

The notification covers five specific activities — exchange between VDAs and fiat currency, exchange between one or more forms of VDAs, transfer of VDAs, safekeeping or administration of VDAs (custodial wallet services), and participation in or provision of financial services related to an issuer's offer or sale of a VDA. Any entity performing these activities in India, including offshore exchanges serving Indian users, must comply with PMLA obligations exactly as a bank or payment aggregator does.

For candidates, the key link to build is this: the LEGISLATION AT NATIONAL LEVEL chapter already frames PMLA as India's core anti-money laundering statute — the 2023 VDA notification is simply an extension of that same law's reporting-entity net to a new sector, not a separate crypto law. Banks feel the downstream effect because VDA-SPs themselves need current accounts, nodal accounts, and payment gateway access, making the bank's own due diligence on these corporate customers a critical control point.

PMLA reporting entity obligations for VDA service providers
PMLA reporting entity obligations for VDA service providers
💡 Exam Tip: Remember the trigger date — 7 March 2023 — and the phrase "reporting entity" under Section 2(1)(wa). Examiners frequently test whether VDA-SPs report to RBI (they do not) or to FIU-India (correct).

🏛️ FIU-India Registration and Reporting Obligations for VDA-SPs

Once classified as a reporting entity, a VDA service provider must register with the Financial Intelligence Unit-India (FIU-IND) through the FINnet 2.0 gateway, exactly as banks do. Registration is not optional and is the gateway to filing Cash Transaction Reports (CTRs), Suspicious Transaction Reports (STRs), and Cross-Border Wire Transfer Reports.

Like banks, every registered VDA-SP must appoint a Principal Officer responsible for STR filing and a Designated Director accountable at the board level for AML compliance — the same governance structure candidates study under the designated director and principal officer framework. The VDA-SP's customer due diligence obligations mirror a bank's: identity verification, beneficial ownership checks, risk categorisation, and record retention of transaction data and KYC documents for the prescribed statutory period.

Enforcement has been visible. In December 2023, FIU-IND issued show-cause notices to several offshore exchanges — including large global platforms — for operating in India without registration, and the Ministry of Electronics and IT subsequently directed ISPs to block access to non-compliant apps. Some platforms later completed registration and paid compounding amounts to resume Indian operations. For the FIU-IND's own institutional placement in India's AML architecture, revisit the ORGANIZATION STRUCTURE IN INDIA chapter, which maps how FIU-IND sits above both banks and VDA-SPs as the central reporting authority.

FIU-India registration and reporting workflow for VDA-SPs
FIU-India registration and reporting workflow for VDA-SPs

🔄 The Travel Rule and Cross-Border VDA Transfers

The "travel rule" is FATF Recommendation 16 — originally written for bank wire transfers — extended to VDA transfers. It requires the originating VDA-SP to obtain and hold accurate originator information (name, account/wallet number, and address or identifier) and transmit it, along with beneficiary information, to the next institution in the transaction chain. This is the crypto-world equivalent of the originator-detail rule banks already follow for cross-border remittances under PMLA Rule 9.

FATF's interpretive note pegs the threshold for mandatory travel-rule data at the equivalent of USD/EUR 1,000 per transfer, below which simplified information may suffice, though supervisors in several jurisdictions apply it to all transfers. For Indian banks, the practical exposure comes when a VDA-SP's nodal account receives or sends funds tied to a cross-border VDA transfer — the same country-risk lens taught in COUNTRY RISK AND MONEY LAUNDERING applies, since VDA flows routed through high-risk or non-cooperative jurisdictions raise the same red flags as any other cross-border transaction.

Banks that maintain correspondent relationships or process settlement for VDA-SPs should also apply the due-diligence depth described in CORRESPONDENT BANKING, and align travel-rule expectations with FATF's broader framework covered in the INTERNATIONAL GUIDELINES & STANDARDS chapter.

⚠️ Common Mistake: Candidates often assume the travel rule is a new, standalone crypto law. It is not — it is FATF Recommendation 16 applied to VDAs, and it sits within the same international standards framework that already governs bank wire transfers.
Bank account red flags linked to crypto laundering typologies
Bank account red flags linked to crypto laundering typologies

🚩 Crypto Laundering Typologies and Bank Account Red Flags

Money launderers use VDAs precisely because value can move across borders and across chains faster than traditional banking rails, and because pseudonymous wallets complicate identification. Common typologies covered in the MONEY LAUNDERING SOME METHODS EDIT chapter translate directly into the crypto context: layering through multiple wallet hops, "chain-hopping" between different VDAs to break the audit trail, use of mixing or tumbling services, and peer-to-peer trading arranged to bypass exchange-level KYC entirely.

For a bank, the exposure is almost always at the fiat on-ramp and off-ramp — the point where crypto proceeds enter or leave the banking system. Frontline staff and transaction monitoring systems should watch for: multiple small credits from unrelated individuals followed by a prompt lump-sum debit to a known exchange's settlement account; a dormant account that suddenly shows high-frequency crypto-linked credits and debits; personal accounts used for volumes inconsistent with the customer's declared income or occupation; and structuring of deposits just below reporting thresholds ahead of a crypto purchase.

The table below summarises how core PMLA obligations apply on both sides of the crypto-banking interface.

PMLA / AML RequirementGoverning ReferenceApplies to VDA-SP
Registration as reporting entityPMLA Section 2(1)(wa), Mar 2023 notification
Principal Officer & Designated DirectorPMLA RulesYes
STR / CTR filing to FIU-INDPMLA reporting obligations
Travel rule (originator/beneficiary data)FATF Recommendation 16Yes
KYC record retention for prescribed periodPMLA record-keeping rules
Dedicated sectoral regulator like RBI for banksNo standalone VDA regulator
📌 Remember: A VDA-SP files STRs with FIU-IND, not with RBI — RBI has no licensing or supervisory role over crypto exchanges even though it regulates the banks that service them.

🧠 Practice MCQs: Virtual Digital Assets and AML Compliance

Q1. Under the PMLA, virtual digital asset service providers became reporting entities from which date? (a) 1 April 2022 (b) 7 March 2023 (c) 1 July 2024 (d) 26 January 2023

Answer: (b) — The Ministry of Finance notification bringing VDA activities under PMLA reporting-entity obligations was issued on 7 March 2023.

Q2. A VDA service provider operating in India must register with which authority to comply with PMLA? (a) RBI (b) SEBI (c) FIU-IND (d) IRDAI

Answer: (c) — VDA-SPs register with FIU-IND through the FINnet 2.0 gateway, the same authority that receives STRs and CTRs from banks.

Q3. The "travel rule" applied to virtual digital assets is based on which FATF standard? (a) Recommendation 10 (b) Recommendation 16 (c) Recommendation 24 (d) Recommendation 40

Answer: (b) — FATF Recommendation 16, originally written for wire transfers, was extended to require originator and beneficiary information for VDA transfers.

Q4. Which of the following is NOT one of the five VDA activities specified in the PMLA notification? (a) Exchange between VDA and fiat currency (b) Safekeeping or administration of VDAs (c) Mining of new VDA tokens (d) Transfer of VDAs

Answer: (c) — The notification lists exchange (VDA-fiat and VDA-VDA), transfer, safekeeping/administration, and participation in an issuer's offer or sale of a VDA — mining is not one of the five listed activities.

Q5. A bank account that receives multiple small unrelated credits followed by an immediate lump-sum transfer to a crypto exchange's settlement account is best described as a red flag for which typology? (a) Trade-based invoicing fraud (b) Layering through structured crypto on-ramping (c) Cheque kiting (d) Loan evergreening

Answer: (b) — This pattern is a classic layering indicator where funds are consolidated from multiple sources before converting to VDAs, breaking the audit trail at the fiat on-ramp.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

Frequently Asked Questions

Are cryptocurrency exchanges regulated by RBI in India?

No. RBI has no licensing or supervisory authority over crypto exchanges. VDA service providers are treated as reporting entities under the PMLA and register directly with FIU-India, though RBI continues to regulate the banks that provide accounts to these platforms.

What is a VDA service provider under Indian law?

A VDA service provider (VDA-SP) is any entity carrying out specified virtual digital asset activities — exchange, transfer, safekeeping, or facilitating an issuer's VDA offering — and is classified as a reporting entity under PMLA Section 2(1)(wa) since the March 2023 notification.

Why do banks need to worry about crypto AML rules if they don't handle crypto directly?

Banks provide the fiat accounts that VDA-SPs and their customers use to move money in and out of the crypto ecosystem. Weak due diligence at this on-ramp/off-ramp point exposes the bank to layering and structuring risk even though the bank never touches a VDA itself.

What happens if a VDA-SP does not register with FIU-IND?

Unregistered VDA-SPs operate in violation of PMLA reporting obligations. FIU-IND can issue show-cause notices, and government authorities can direct blocking of the platform's access in India, as happened with several offshore exchanges in December 2023.

Conclusion: Treat Crypto Exposure as a Core KYC-AML Control

Virtual digital assets and AML compliance is now a mainstream, examinable extension of the PMLA framework you already know — same reporting-entity concept, same FIU-India reporting chain, same Principal Officer and Designated Director governance, just applied to a new asset class. For working bankers, the real skill is spotting the fiat-side red flags before funds convert into VDAs and become far harder to trace.

Reinforce this with the related chapters on RBI KYC master direction and enhanced due diligence, browse more chapters under the KYC, AML and CFT tag, and don't overlook the parallel control environment covered in RBI cybersecurity framework for banks, since crypto-linked fraud increasingly rides on the same digital channels. Ready to test yourself? Explore the CAIIB course and attempt a full-length KYC-AML mock.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. A trade-finance branch reviews an account where inward remittances are immediately withdrawn, the goods description on documents is vague, the value/quantity of goods is not readily ascertainable, and LCs are repeatedly amended without justification. Which monitoring focus do these indicators point to?
Q2. A bank is designing its monitoring intensity under the Risk Based Approach (RBA) recommended by FATF. Which set of customers/products should attract the most intense monitoring as illustrated in the chapter?
Q3. Rule 8(4) of PMLR and Section 13 of PMLA together govern the consequences of reporting failures. Which statement is correct?
Q4. An AML analyst escalates a dormant account that suddenly receives multiple high-value RTGS credits remitted out within hours, with field verification showing the customer is not at the declared address. What is the correct next step?
Q5. A customer closes his current account on 1 April 2024. Under PMLA/PMLR, until when must the bank retain his KYC identity documents (assume no legal proceeding is pending)?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading