Opening an account on an Indian crypto exchange now involves more than a PAN and a phone number. Under guidelines issued by the Financial Intelligence Unit-India (FIU-IND) on 8 January 2026, exchanges must take a live selfie with liveness detection, record where you are when you sign up, confirm your bank account with a penny-drop test, and repeat parts of the check every six or twelve months. Here is what crypto KYC in India covers, and why.

The document is the AML & CFT Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets, listed on FIU-IND’s downloads page as updated on 8 January 2026. It updates the first version of 10 March 2023 and sets out how the Prevention of Money Laundering Act, 2002 (PMLA) and its record-keeping rules apply to crypto businesses.

Why exchanges do KYC at all

For crypto exchanges, the legal hook is anti-money-laundering law. A government notification of 7 March 2023 (S.O. 1072(E)) made businesses that carry out any of five activities for others “reporting entities” under the PMLA:

  • exchanging virtual digital assets (VDAs) for rupees or other fiat currencies;
  • exchanging one VDA for another;
  • transferring VDAs;
  • holding or administering VDAs, or the keys that control them;
  • providing financial services around a token issuer’s offer or sale.

A second notification, of 9 November 2023 (S.O. 4877(E)), named the Director of FIU-IND as their regulator. The 2026 guidelines say the obligations follow the activity, not the address: any entity carrying out these activities must register with FIU-IND and follow these rules wherever it is incorporated. How to check that registration is covered in our guide to FIU-registered crypto exchanges.

What an exchange must collect from you

Paragraph 4.2.1 of the guidelines lists the minimum an exchange must capture when you open an account:

Group What is collected
Personal Full name as on the PAN, date of birth, gender, PAN, identity document type and number, nationality
Contact Address, mobile number, email ID
Financial Occupation, income range, bank account details
Other A selfie with liveness detection; latitude and longitude of the onboarding location with date, time and IP address

Source: FIU-IND AML & CFT Guidelines for VDA service providers, updated 8 January 2026, para 4.2.1.

PAN is mandatory, both to open an account and to carry out any VDA activity. Alongside it you must give one identity document: a passport, driving licence, proof of possession of an Aadhaar number, a voter ID card, or an equivalent e-document showing identity and address. Mobile number and email are verified by OTP or a verification link. The guidelines also allow exchanges to collect other identifiers such as device ID, wallet addresses and transaction hashes for verification and monitoring.

Selfie, location and penny drop

Three checks are new compared with the 2023 version, and each answers a specific risk.

Liveness. The exchange must make sure that the person whose documents are submitted is the one actually opening the account. The guidelines require a live photograph and liveness detection technology to confirm physical presence at onboarding, which is meant to stop accounts opened with someone else’s documents.

Location. The onboarding system must capture your geo-coordinates. If the location does not match the address you gave, the exchange must apply enhanced checks. Expect a location permission prompt during sign-up.

Penny drop. Your bank account must be verified through a penny-drop mechanism, a small test transaction, which the guidelines say is meant to confirm both who owns the account and that it is operational.

When the checks get stricter

The guidelines make enhanced due diligence mandatory in three situations: customers linked to high-risk jurisdictions, specifically tax havens and countries on the FATF grey and black lists; politically exposed persons; and non-profit organisations. Enhanced checks can include questions about your source of funds and the purpose of transactions, more frequent reviews and independent verification. If an exchange cannot complete them, it must end the relationship and file a suspicious transaction report with FIU-IND.

Re-KYC every six or twelve months

Crypto KYC is not one-off. Under paragraph 4.5.2, exchanges must update KYC at least once every six months for customers assessed as high risk, and at least once a year for everyone else, counted from account opening or the last update.

If nothing has changed, a self-declaration is enough. If any detail has changed, or a document on file has expired, the exchange must repeat the full onboarding check, verification included. You are also expected to tell the exchange promptly when your details change, rather than waiting for the next cycle.

Checks on your transfers

KYC continues after onboarding. Exchanges must screen customers against sanctions lists at onboarding, when KYC details change, when the lists change, and whenever a VDA transaction is initiated. For transfers to a wallet at another registered exchange, the sending exchange must pass on originator and beneficiary details before or at the time of the transfer, the “travel rule”; sending the data afterwards is not permitted.

Transfers to and from self-custody, or unhosted, wallets are treated as higher risk. Exchanges must collect data on them, may apply enhanced checks and may impose extra limits or allow only transfers they assess as reliable. The guidelines go further for privacy tools: exchanges must not permit deposits or withdrawals of anonymity-enhancing tokens, and must not facilitate transactions involving mixers or tumblers.

What happens to your data

Exchanges must keep the identity and address records gathered at onboarding and during the relationship for at least five years after the relationship ends, and transaction records for at least five years from the date of each transaction. Records linked to an ongoing investigation are kept until the case is closed.

The PMLA also prohibits “tipping off”. Exchanges and their staff must not tell a customer, or anyone else, that a suspicious transaction report has been or may be filed.

KYC sits beside the tax rules rather than replacing them. Your PAN is what links exchange activity to the 1% TDS on transfers, and gains are reported in your return; see our explainers on crypto tax in India and Schedule VDA in the ITR.

Sources

FIU-IND: AML & CFT Guidelines for Reporting Entities Providing Services Related to Virtual Digital Assets, updated 8 January 2026 (paras 1.2, 4.1 to 4.5, 5.3, 5.4, 5.6, 6 and 7), and the FIU-IND downloads list. The guidelines cite government notifications S.O. 1072(E) of 7 March 2023 and S.O. 4877(E) of 9 November 2023. Documents consulted on 11 October 2026; links appear beside the relevant discussion.