GS Paper 3 · 10 September 2026
FIU Notices to 15 VDA Providers Show Why Crypto Compliance Follows Activity, Not Location
The Financial Intelligence Unit-India issued non-compliance notices under Section 13 of the Prevention of Money Laundering Act, 2002 to 15 virtual digital asset service providers. FIU-IND also used its nodal-officer role under Section 79 of the Information Technology Act and the intermediary rules to seek takedown of applications or URLs found operating illegally without meeting Indian anti-money-laundering requirements. Virtual digital asset service providers were brought within India's anti-money-laundering and counter-financing-of-terrorism framework in March 2023. Providers serving Indian users must register with FIU-IND as reporting entities and meet reporting, record-keeping and related obligations whether they are based onshore or offshore. The action illustrates an activity-based regulatory approach: obligations arise from services offered into India rather than the provider's physical address. It also raises continuing questions about cross-border enforcement, due process, consumer awareness and coordination among financial-intelligence, technology and intermediary-regulation authorities.
Why UPSC cares
For GS Paper 3, this concerns money laundering, cyber-enabled finance, internal security and regulation of emerging markets. Answers should distinguish AML/CFT registration from a general approval of crypto products; explain why offshore digital services create jurisdictional problems; and evaluate proportional, reviewable takedown powers, beneficial-ownership transparency and international cooperation.
How to study this story
The enforcement action demonstrates why digital finance weakens location-based regulation. A platform can have no office in India and still solicit Indian customers, transfer value and create risks for the domestic financial system. Activity-based obligations respond to that reality by focusing on what a service does and whom it serves. Yet registration is only the first layer. Effective anti-money-laundering supervision needs reliable customer due diligence, suspicious-transaction reporting, preservation of records, beneficial-ownership visibility and cooperation when assets or operators cross borders. Takedown powers may reduce public access to a non-compliant service, but blocking a domain does not eliminate mirror sites, private applications or peer-to-peer channels. Enforcement should therefore combine technology measures with financial intelligence, international assistance and public risk communication. Due process matters because a mistaken or overbroad restriction can affect lawful users and businesses. Notices should specify the breach, offer a review path and distinguish non-compliance from proof that every transaction on the platform is criminal. A crucial Prelims trap is to treat FIU registration as a guarantee of investment safety; it is a reporting-entity obligation, not a price, solvency or consumer-protection endorsement. A strong Mains conclusion supports jurisdiction over India-facing activity while demanding proportionate enforcement, accountable blocking and cross-border regulatory cooperation.
The larger paper context
Read the GS Paper 3 stories through strategic capacity and implementation: separate announcements from operational capability, map the regulator or project chain, test security and environmental claims, and ask which measurable outcome would prove public value.
Probable question
Activity-based regulation can extend anti-money-laundering obligations to offshore digital-asset platforms, but enforcement remains difficult. Analyse India's regulatory options and safeguards.
Quick practice check
Q1
What does activity-based VDA regulation primarily focus on?
- Only the provider's registered office
- Only the nationality of its owners
- The services offered to Indian users and the risks they create
- Whether crypto prices are rising
Show answer
Correct answer: The services offered to Indian users and the risks they create
The obligations follow India-facing exchange, transfer, custody and related activity rather than physical presence alone.
Q2
Which statement about FIU registration is correct?
- It guarantees investment returns
- It converts every token into legal tender
- It removes the need for consumer caution
- It imposes reporting-entity duties but is not a general product-safety approval
Show answer
Correct answer: It imposes reporting-entity duties but is not a general product-safety approval
AML/CFT registration governs compliance duties; it does not certify price, solvency or consumer protection.
Related practice questions
- Examine how virtual assets complicate enforcement against money laundering and terror financing.
- What institutional coordination is needed to regulate cross-border digital financial services?