You filed your crypto client’s ITR correctly, ensuring their Schedule VDA remains clean, and over the past two years they have maintained consistent compliance with no notices or discrepancies. Then, the 8th January 2026 FIU-IND guidelines land, a full overhaul of the AML/CFT framework for Virtual Digital Asset (VDA) service providers. Consequently, much of what you advised them on last year no longer meets the current compliance standard.
And that is your professional exposure. Not because you did anything wrong under the old framework, but because your client is a regulated reporting entity under the Prevention of Money Laundering Act (PMLA), 2002, and their obligations changed materially in January 2026. As such, if a FIU-IND review finds gaps that post-date your last advisory engagement, the onus of whether you identified and communicated those risks to the client falls on you.
What makes this particularly significant for CAs is the 3rd May 2023 notification. Since that date, a CA who executes financial transactions on behalf of a crypto client is a reporting entity under PMLA themselves and are subject to Section 13 penalties for each compliance failure. This guide covers what you need to verify, what you should document, and where your own liability begins and ends.
Key Takeaways
- CAs who execute financial transactions on behalf of crypto clients are reporting entities under PMLA as of Notification S.O. 2036(E) dated 3rd May 2023, advising alone does not trigger this status, but execution does.
- VDA service providers have been subject to PMLA reporting requirements since 7th March 2023; the 8th January 2026 FIU-IND guidelines are the current operative framework. So, if your advice references earlier guidelines, it is incomplete.
- When conducting a PMLA gap assessment, you should check for: the three-tier KYC, live-selfie verification, a functioning STR system, a Principal Officer appointment, tamper-proof records, and a public AML/CFT policy summary.
- The tipping-off prohibition under Section 8 of PMLA applies to you as well. So, if your client files an Suspicious Transaction Report (STR), you cannot inform the counterparty, even indirectly.
- Section 13 of PMLA allows FIU-India to fine non-compliant reporting entities INR 10,000 to 1,00,000 per failure; Section 4 convictions carry 3 to 7 years’ rigorous imprisonment, extendable to 10 years.
Traded All Year? Now File in Minutes.
Get ITR-ready tax reports now.
How did Crypto Come Under PMLA and Where Do You Sit in that Framework?
Your obligations and your client’s depend on the three notifications below. Most CAs know the first. Fewer have read the second carefully enough to understand what it means for their practice.
The 7th March 2023 Notification
The gazette notification of 7th March 2023 classified entities conducting any of the following five activities as reporting entities under the Prevention of Money Laundering Act, 2002. If your client conducts any of the following for or on behalf of another person, in the course of business, they will be considered a Virtual Asset Service Provider (VASP) and a PMLA reporting entity:
- Exchange between VDAs and fiat currencies
- Exchange between one or more forms of VDAs
- Transfer of VDAs
- Safekeeping or administration of VDAs, or instruments enabling control over them
- Participation in and provision of financial services related to a VDA issuer’s offer and sale
The obligation is activity-based; therefore, physical presence in India is not a precondition. As a result, a platform incorporated abroad that serves Indian users falls within the framework
The 3rd May 2023 Notification
On 3rd May 2023, practicing CAs, Company Secretaries, and Cost and Works Accountants were brought under PMLA as reporting entities, but only when executing specified financial transactions on behalf of clients. The specified transactions include:
- Buying and selling of real property on behalf of a client
- Managing client money, securities, or other assets
- Managing bank, savings, or securities accounts
- Organising contributions for company creation or fund pooling
- Incorporation, operation, and management of companies, LLPs, or trusts and buying and selling of business entities
Advising a client on any of these does not trigger reporting entity status. Only executing the transaction does. So, define that boundary in your engagement letter, before the work begins, not after FIU-IND raises an enquiry about your role
The 8th January 2026 Overhaul
The FIU-IND revised its AML/CFT guidelines three times between 2023 and 2026. The current framework, dated 8th January 2026, is a material overhaul. It introduces new technical verification requirements, a restructured KYC architecture, and explicit high-risk categorisations absent from earlier versions.
If your advisory to a VASP client is based on the 2023 or January 2025 guidelines, the gaps between what you advised and what FIU-IND now requires are your professional exposure. This is because the 2026 framework is the standard against which any compliance review of your client will be conducted.
What to Verify in Your Client's KYC Architecture?
When you conduct a PMLA gap assessment for a VASP client, KYC is the first area to review, and the 2026 framework restructures it into three formal tiers with four new technical requirements. Before signing off on any advisory position, confirm that your client’s onboarding system maps to each tier correctly.
The Three-Tier KYC Structure
When reviewing your client’s KYC architecture, verify that onboarding triggers are automated at the correct thresholds, not applied at case-by-case discretion. Each tier carries distinct documentation requirements, and a CA running all customers through standard KYC regardless of transaction volume will have a reportable gap.
Tier 1: Basic KYC (below INR 50,000 per year)
Simplified verification requires only basic identity documents. However, clients must still retain their records for five years, as reduced KYC requirements do not remove record-keeping obligations.
Tier 2: Standard KYC (INR 50,000 to INR 10 lakh)
Check that your client’s onboarding process collects, at minimum:
- PAN card or Form 60
- One of:
- Aadhaar,
- Passport,
- Driving Licence,
- Voter ID,
- NREGA Job Card, or
- National Population Register letter
Also Verify: CKYCR registration is in place, and electronic KYC records are being filed within 10 days of account opening. That 10-day window is a hard compliance deadline, so flag any manual process that creates a risk of missing the deadline.
Tier 3: Enhanced Due Diligence or EDD (above INR 10 lakh and all Politically Exposed Persons)
EDD applies to all PEPs regardless of transaction amount. Verify that your client’s system flags PEPs at onboarding, not when their transaction volume crosses INR 10 lakh.
At Tier 3, check that the process additionally captures: the source of funds, purpose of business relationship, and beneficial owner identity and background. Existing customers who migrate from a lower tier are not exempt, ensure you follow the EDD workflow with them.
The Four Technical Requirements: A Direct Verification Checklist for 2026
The 8th January 2026 guidelines also introduced four technical requirements that no prior version mandated. When conducting your gap assessment, check the following explicitly:
- Live-Selfie Verification with Liveness Detection: Confirm that static image uploads have been replaced; flag any onboarding flow that still accepts a photograph without liveness check
- Geo-Tagging of Platform sessions: Confirm that location data is being captured and logged at the point of verification
- Penny-Drop Bank Account Validation: Confirm that bank account ownership is verified via a small-value transfer before account linking, not assumed from document submission
- Removal of Privacy Coin Listings and Mixer-Related Services: Confirm that your client has audited their listed assets and removed any that fall within this category; this is not a risk-based recommendation under the 2026 guidelines but a mandatory delisting requirement
Document each finding as a specific gap or confirmed compliance in your advisory file. These four items are individually enforceable under Section 13(2) of PMLA.
Beneficial Owner Identification: What to Check in Your Client's Process?
Under Rule 9(1)(a) of the Prevention of Money-laundering Rules, 2005, your client must check whether a customer is acting on behalf of a beneficial owner when:
- Starting an account-based relationship,
- Carrying out a transaction of INR 50,000 or more (including multiple linked transactions), or
- Conducting an international money transfer.
If a beneficial owner is identified, your client must separately verify that person’s identity.
Customer self-declaration alone does not satisfy this requirement. Your client needs a documented process for identifying layered ownership structures, particularly for corporate customers, investment vehicles, and any entity where the transacting party may not be the ultimate beneficiary. Advise them to treat beneficial owner identification as a separate workflow, not a checkbox within the standard KYC form.
What to Verify in Your Client's STR and Monitoring System?
The monitoring and STR filing obligation is where most VASP compliance failures occur. It requires both a technical system and a well-defined operational process. Many clients underestimate how specific the 2026 requirements are, making this a common area of non-compliance.
What the Automated Monitoring System Must Flag and How to Verify It?
Your client cannot meet the monitoring standard through manual case review. Verify that their automated system is configured to generate alerts on at least the following:
- Large transactions inconsistent with the customer’s stated purpose or business profile
- Rapid movement of funds between wallets without apparent economic purpose, a layering indicator, the second stage of money laundering where illicit funds are moved repeatedly to obscure their origin.
- Transactions involving entities on OFAC, UN, or India-specific sanctions lists
- Any transaction routed through privacy coins or mixing services
- Transfers involving unhosted wallets may be treated as higher-risk transactions, depending on the circumstances. So, originator and beneficiary information must still be collected even when transmission to a counterparty VASP is not possible
- P2P transfers that are classified as high risk. Verify enhanced controls are applied and a documented risk assessment determines whether they are permitted, restricted, or prohibited
Each alert must route to the Principal Officer for manual review and a documented decision. When reviewing your client’s system, ask for a sample of recent alerts and trace each one to a documented outcome. If alerts are being generated but not actioned with a recorded decision, that is a compliance gap.
STR Filing: Two Points Your Client May Have Missed
When reviewing compliance under Section 12 of the PMLA and the PML Rules, the first step is to determine whether a transaction was identified as suspicious. This assessment forms the basis of the reporting obligation and should be documented carefully during internal reviews.
Once a transaction is classified as suspicious, the Principal Officer is required to file a STR with FIU-IND within seven working days of identification. As part of your gap assessment, two specific aspects of the 2026 reporting framework require close verification:
1. Attempted Transactions are Within Scope
The obligation does not require the transaction to have been completed. Verify that your client’s monitoring system captures attempted activity, transfers that were blocked or abandoned, and that these are included in the STR assessment process, not filtered out.
2. The Tipping-Off Prohibition Applies to Your Role as an Advisory
Section 8A of the PMLA prohibits informing a customer that an STR has been filed or that a transaction is under investigation. When reviewing compliance procedures, ensure this restriction is embedded in customer-response workflows and understood by staff handling client communications.
This becomes particularly important when customers ask about delayed withdrawals or flagged transactions. Even a routine explanation can amount to prohibited disclosure. The same restriction applies when advising clients on transactions that have already been reported through an STR.
Monthly Cross-Border Reporting
In addition to STRs, review whether your client has a documented process for reporting cross-border wire transfers exceeding INR 5,00,000 or the foreign currency equivalent to FIU-IND. This requirement applies regardless of whether any suspicion exists.
Unlike STR filings, this is a mandatory monthly reporting obligation under the PML Rules. Therefore, verify that the filing deadline is embedded in the compliance calendar as a fixed recurring requirement rather than a task dependent on manual follow-up.
What Governance Appointments You Should Verify and What You Should Watch Out for?
The 2026 framework requires two formal appointments that have been reported to FIU-IND and are actively performing their duties. When reviewing your client’s governance structure, you are not just confirming names on a form, you are assessing whether the people appointed can actually carry out the obligations the roles require. Such governance structure includes:
The Designated Director
The Designated Director carries board-level accountability for overall PMLA compliance. When verifying this appointment, check:
- The individual holds a board-level or senior management position, not a delegated appointment from a junior officer
- Their name, designation, and address have been formally communicated to FIU-IND at registration and are current
- They receive quarterly compliance reports from the Principal Officer and there is a record of this happening
- Internal systems for CDD, monitoring, reporting, and recordkeeping operate under their oversight, not independently of them
An appointment that exists only on paper, without the Designated Director having active oversight of the compliance programme, is a governance gap. Document it and advise your client accordingly.
The Principal Officer
The Principal Officer is the operational head of AML/CFT compliance. The 2026 guidelines require genuine experience in AML, financial crime, and regulatory reporting. Consequently, a junior or dual-function appointment does not satisfy this. When reviewing this role, the most important advisory question is whether a conflict of interest exists.
The 2026 guidelines explicitly prohibit conflicts of interest for the Principal Officer. An individual who simultaneously holds a revenue-generating commercial role has an inherent incentive to underreport suspicious activity. Verify that:
- The Principal Officer’s role is sufficiently senior and genuinely AML-focused
- No commercial accountability exists that could create an incentive to underreport
- Their details are formally notified to FIU-IND and updated via FINgate on any change
The Deputy Principal Officer
The 2026 guidelines introduced a mandatory Deputy Principal Officer requirement. When reviewing this appointment, the advisory question is not whether the role exists, it is whether the Deputy can actually operate if the Principal Officer is unavailable. Verify that the Deputy holds:
- Full access to the transaction monitoring system
- Access to the FIU-IND filing portal and all reporting credentials
- Familiarity with the STR filing process and the seven-day deadline
A Deputy who holds the title but lacks system access cannot cover the Principal Officer in a real compliance event. That gap needs to be flagged as an operational finding.
The Annual AML/CFT Audit
Your client must commission an annual independent audit of their AML/CFT programme by a PMLA-qualified auditor, with the report submitted to FIU-IND by 30th June of each year. When reviewing your client’s compliance calendar, verify this has been commissioned and that the previous year’s report was submitted on time.
This audit is entirely separate from your role as their tax advisor or statutory auditor. It requires a reviewer with specific PMLA compliance expertise. Advise your client explicitly that this engagement needs to be placed independently, and do not accept it yourself unless you hold a PMLA auditing qualification.
What to Check in Your Client's Record Retention Architecture?
When you review your client’s records as part of a PMLA gap assessment, you are not just checking that records exist. The 2026 framework specifies the technical standard to which those records must be maintained. A standard database with edit permissions does not satisfy it, and that is a gap you need to identify and document.
Transaction Records: Content and the Five-Year Clock
Before relying on transaction records, confirm that they satisfy the record-retention requirements under Section 12(1)(a), Section 12(3) of PMLA, and Rule 4 of the PML Rules. These provisions require transaction records to be preserved for 5 years from the date of the transaction. Check specifically for the presence of:
- Nature of the transaction
- Amount and currency denomination
- Date of transaction
- All parties involved
- IP addresses with timestamps and time zones
- Transaction ID
- Public keys or equivalent identifiers
- Addresses or accounts involved
An incomplete record, one that captures the amount and date but not the IP address and parties, is a partial compliance failure. Each missing field is a reportable gap in your advisory finding.
Client Identity Records: A Separate Five-Year Clock
Under Section 12(1)(e) and 12(4), PMLA, client identity records, account files, and business correspondence must be retained for 5 years after the business relationship ends or the account closes, whichever is later. This is a separate retention obligation from transaction records and starts a different clock.
When reviewing your client’s data architecture, verify that these two retention obligations are tracked independently. A single database where all records are deleted five years after the last transaction will inadvertently purge client identity files that are still within their retention window. Flag any system where the two clocks are not separated.
Travel Rule Data: Verify Retention for Unhosted Wallet Transfers Too
For transfers between VASPs, verify that originator and beneficiary information is transmitted and retained as required. This includes details such as name, account number, and address, along with maintaining records for the prescribed five-year retention period.
The same verification should not stop at VASP-to-VASP transfers. When a transaction involves an unhosted wallet, ensure that originator and beneficiary information is still collected and retained internally. The absence of a receiving VASP does not remove the underlying data collection obligation, despite this being a common misconception among clients.
How KoinX Helps Crypto Investors File Accurately Under Either Regime?
When your income spans crypto gains across multiple platforms and salary or business income subject to a regime decision, computing the correct liability is not a single-step process. KoinX is a global crypto tax platform trusted by over 1.5 million users across 100+ countries, with 800+ exchange and wallet integrations.
For Indian investors, it generates ITR-ready Schedule VDA reports, computes the 30% VDA tax accurately, and presents your figures in the exact format the ITD expects, regardless of which regime you file under.
Storage Standard: What Tamper-Proof Means in Practice
The 2026 guidelines require verification responses, authentication logs, timestamps, and related records to be retained in a tamper-proof format. When assessing a client’s systems, determine if the existing records can be modified post creation?
If the answer is yes, the requirement is unlikely to be met. Standard cloud storage with edit permissions or databases that allow historical changes create compliance concerns. Tamper-proof storage requires records and access logs to remain preserved without post-creation alteration, making infrastructure design a critical part of compliance.
How to Advise on High-Risk Categories?
When a client brings you a token offering, a P2P trading function, or a wallet integration that touches unhosted wallets, the 2026 guidelines require you to advise them on a specific enhanced compliance response, not a risk-based recommendation. These four categories are classified as high risk and therefore require enhanced controls beyond standard compliance measures:
Token Offerings: Advise Before Launch
When a client plans to facilitate a token offering, whether a public sale, private placement, or tokenised asset issuance, your advisory engagement should begin before the offering launches, not after. The 2026 guidelines classify this as high risk and require your client to apply:
- Full AML controls on all participants in the offering
- Investor disclosures on the nature and risks of the instrument being offered
- Market manipulation safeguards covering wash trading, front-running, and coordinated price activity
- Due diligence on the issuer, including beneficial ownership verification and source-of-funds checks for the issuing entity
When advising a client on a token offering, document your findings on each of these four requirements specifically. A general sign-off on the offering without addressing the AML framework is an advisory gap.
Unhosted Wallets: Build It into the Transfer Workflow
When reviewing unhosted wallet transfers, ensure that originator and beneficiary information is collected as part of the transfer process itself. Documentation gathered after the transaction is completed may not satisfy compliance expectations during a regulatory review.
Before a transfer is initiated, maintain records of the wallet address, supporting identity documents, and the stated purpose of the transaction. Importantly, the absence of a receiving VASP does not remove these obligations, a misconception that should be addressed clearly during compliance reviews.
P2P Transfers: The Risk Assessment Must Be on Record
P2P functionality requires heightened scrutiny regardless of transaction volume. Standard KYC procedures alone are generally insufficient because P2P transactions carry elevated money laundering and compliance risks that require additional monitoring and control measures.
The focus should be on whether a documented risk assessment exists and whether it addresses the platform’s P2P activity specifically. Equally important, the controls implemented on the platform should align with that assessment, as a risk analysis that is not reflected in operational practices provides little compliance value.
Smart Contracts: The Automation Misconception to Correct
The 2026 guidelines make one point clear: smart contract execution does not remove compliance obligations. Many VASPs assume that because a transaction is executed automatically by code, the associated AML and reporting responsibilities no longer apply.
The position is straightforward: Where transactions are facilitated through a platform or flow through smart contracts operated as part of a service, the full PMLA framework continues to apply, including KYC, transaction monitoring, STR filing, and recordkeeping. This interpretation should be documented in advisory files for clients whose business models rely on smart contract-executed transactions.
What to Check in Your Client's Written AML/CFT Policy?
When reviewing your client’s written AML/CFT policy, the first check is whether it is current and has it been updated since 8th January 2026. A policy last revised in 2023 or 2025 does not reflect the current framework. In your gap assessment, treat an out-of-date policy as a primary finding, not a secondary one.
The framework must cover the following at a minimum:
- Customer due diligence procedures for each KYC tier and each high-risk category
- Transaction monitoring procedures and the documented alert escalation protocol
- STR filing procedures, the seven-day timeline, and the tipping-off prohibition
- Record retention standards and the storage architecture they require
- Principal Officer and Deputy PO roles, responsibilities, and succession arrangements
- Employee training tailored to each role and provided since the 2026 overhaul
- Group-wide policies where your client operates across multiple legal entities
One requirement specific to 2026 with no equivalent in prior guidelines: a public summary of the AML/CFT policy must be displayed on the platform’s website or application. When conducting your review, check whether this summary is live. Its absence is immediately visible to FIU-IND in any compliance review, and it is a gap you should flag explicitly in your findings.
What are the Penalties and How Do they Apply to You Personally?
The penalty framework under PMLA is criminal, not administrative. When you advise a VASP client on their compliance position, part of that advisory is ensuring they understand the consequences specific failures attract. The other part is understanding your own exposure.
Section 13 Penalties: Per Failure, Not Per Audit Cycle
Under Section 13 of PMLA, each compliance failure carries a penalty of INR 10,000 to INR 1,00,000, independently. A VASP client with missed STR filings across multiple months, incomplete KYC records, and no appointed Principal Officer faces three distinct penalty categories simultaneously, each calculated per failure, not as a single aggregate.
When advising your client on their compliance position, quantify the exposure concretely. A client with 12 missed monthly STR obligations and a systematically incomplete KYC architecture is not facing one penalty, they are facing a penalty stack. Seeing the total exposure often encourages timely corrective action.
Criminal Prosecution: Who is at Personal Risk
Non-compliance that constitutes wilful evasion or active facilitation of money laundering exposes your client’s officers, the Designated Director and Principal Officer specifically, to imprisonment of up to seven years and fines of up to INR 1 lakh per violation.
The enforcement record is instructive. 9 offshore VDA SPs received show-cause notices and had their URLs blocked by MeitY for non-registration alone, before any allegation of money laundering arose. The trigger was the absence of FIU-IND registration. For context on the broader enforcement environment your client operates in, the crypto tax audit and enforcement landscape in India has shifted significantly in parallel with PMLA enforcement.
Registration Suspension and URL Blocking: Operational Consequences
FIU-IND’s enforcement powers extend beyond monetary penalties. Under Section 13, it can suspend or cancel a VASP’s registration, directly affecting its ability to operate within the regulatory framework.
Additionally, FIU-IND may recommend that MeitY block the platform’s URLs, effectively disrupting access to its services. For crypto businesses, this can result in immediate operational consequences, making registration compliance a core regulatory obligation rather than a routine filing requirement.
Your Personal Exposure: Where the Line Sits
The Madras High Court’s judgment in Murali Krishna Chakrala v. The Deputy Director, Directorate of Enforcement, Chennai ([2023] 457 ITR 579), endorsed by the Supreme Court’s dismissal of the ED’s SLP in March 2024, confirmed that issuing Form 15CB in the ordinary course of statutory duty does not constitute abetment of money laundering under Section 3 of PMLA.
The protection is not absolute. It applies only where the CA acted bona fide, without knowledge that the documents were forged or the transaction was fraudulent. Conscious involvement or intent to assist — mens rea — is what converts a professional act into a PMLA offence.
Active execution of transactions without maintaining required KYC records and documentation does not carry that protection. Maintain your own advisory file for every VASP engagement, advice given, gaps identified, client acknowledgements received, and scope of engagement documented. That file is your protection if a question about your role arises.
How to Structure Your PMLA Advisory Engagement?
Knowing the 2026 framework thoroughly is the foundation. Structuring your engagement so your advice is documented, your scope is defined, and your client has a clear, time-bound action plan is what makes that knowledge professionally defensible. Here’s how you can do that:
Define the Scope of Your Engagement Before Work Begins
Before accepting a PMLA engagement for a VASP client, clearly document whether your role is advisory or transactional. Defining the scope at the outset helps establish the applicable compliance obligations and reduces the risk of future disputes.
If your work is limited to reviewing controls, identifying gaps, and recommending procedures, you are generally not a reporting entity under the 3rd May 2023 notification. However, if the engagement expands to executing transactions or managing assets on the client’s behalf, the position changes. Reflect this distinction in the engagement letter and formally reassess it whenever the scope of work evolves.
Conduct a Structured Gap Assessment in a Fixed Sequence
When taking on a new VASP client, or reviewing an existing one under the 2026 framework, begin by assessing the following eight areas in sequence. This creates a structured foundation before forming a view on any specific compliance obligation.
Moreover, each area carries its own compliance significance and should be evaluated independently. Since every category can trigger separate consequences under Section 13, a step-by-step review helps identify gaps before they develop into penalty exposures.
- FIU-IND registration status, confirmed registered, or currently in violation
- KYC architecture, three-tier structure used, all four 2026 technical requirements implemented
- Principal Officer and Designated Director, appointed, notified to FIU-IND, conflicts of interest assessed
- Written AML/CFT policy, current as of 8th January 2026, board-approved, public summary live on the platform
- Transaction monitoring system, automated, covers all eight required flag categories
- STR procedures, seven-day timeline documented, attempted transaction scope understood, tipping-off prohibition embedded in response protocols
- Record retention system, tamper-proof storage confirmed, both five-year clocks tracked separately, Travel Rule data retained
- Annual audit, PMLA-qualified auditor engaged, previous report submitted to FIU-IND by 30th June
Document your findings against each area. A gap in any of them is a per-failure penalty exposure for your client, and, depending on your engagement scope, potentially for you.
Build a Compliance Calendar Your Client Can Actually Follow
PMLA obligations for a VASP run continuously alongside their tax obligations. When you conclude a PMLA advisory engagement, leave your client with a standing compliance calendar rather than a findings report alone:
- Monthly: Cross-border transfer report to FIU-IND for all transfers above INR 5,00,000
- Ongoing: STR filing within seven working days of each suspicious transaction identification
- Annually for high-risk customers: KYC refresh
- Every three years for standard customers: KYC refresh
- By 30th June annually: Independent AML/CFT audit report submitted to FIU-IND
- On each new product or technology launch: Written AML/CFT policy updated, board re-approved, public summary revised
As crypto compliance obligations expand across Schedule VDA, TDS reporting, and ITR filing, KoinX helps consolidate exchange records, FMV data, KYC details, and tax reports into a single verified dataset, reducing manual reconciliation errors and supporting consistent reporting across every compliance requirement.
How KoinX Supports Your PMLA Advisory Practice?
When crypto transaction data must support PMLA recordkeeping, Schedule VDA reporting, and TDS reconciliation at the same time, data quality becomes critical. Inaccurate or fragmented records can weaken advisory conclusions and make compliance positions harder to defend during scrutiny.
To address this challenge, KoinX consolidates transaction data from 800+ exchanges and wallets into a single verified source. As a result, CAs can work with standardized records that support multiple compliance requirements while reducing the effort involved in reconciliation and reporting.
Multi-Client Dashboard for CA Practices
KoinX for Tax Professionals gives you a dedicated multi-client dashboard from which you can manage all VASP and individual crypto clients in one portal. One-click client account access removes repeated authentication across engagements. When reviewing transaction records across multiple VASP clients during a compliance assessment or preparing findings for an ITR filing, the consolidated view removes the switching cost that separate system logins create.
ITR-Ready Schedule VDA Reports Mapped to the Correct Income Head
For your VASP clients who also carry employment or business income in crypto, KoinX generates ITR-ready Schedule VDA reports for both ITR-2 and ITR-3, with each transaction mapped to the correct income head, PGBP receipt, salary perquisite, or capital gain on disposal. The figures your client submits match what the ITD holds in their AIS. For the full income tax framework that runs alongside your PMLA advisory obligations, our complete guide to crypto tax in India covers both in detail.
KoinX Connect: Consolidated Transaction Data in One Step
KoinX Connect is an AI-powered agent that fetches transaction data from connected exchanges automatically, no manual CSV downloads, no API configuration per exchange. When you are reviewing a VASP client’s transaction history to support a PMLA gap assessment alongside their ITR preparation, KoinX Connect consolidates all activity into a single, verified dataset across all connected platforms in one step.
The compliance calendar of your VASP client, monthly FIU-IND reports, ongoing STR monitoring, annual AIS reconciliation, and Schedule VDA filing run on the same underlying transaction data. Sign up on KoinX and give your VASP clients a data foundation that supports every obligation at once, rather than pulling records separately for each framework.
Conclusion
The 8 January 2026 FIU-IND framework has significantly expanded compliance expectations for VASPs, making registration, KYC controls, governance appointments, STR procedures, record retention, and annual audits essential review areas for CAs. Missing obligations can lead to substantial penalties and, in serious cases, criminal exposure. A structured gap assessment and clearly documented advisory process are therefore critical for managing client risk and demonstrating professional diligence.
Accordingly, maintaining accurate and accessible transaction records becomes just as important as understanding the regulatory requirements themselves. KoinX helps consolidate the data required for PMLA recordkeeping, Schedule VDA reporting, and TDS reconciliation into a single verified source. This reduces duplication across compliance workflows and supports more efficient client reviews. Join KoinX today and strengthen your crypto compliance advisory practice with reliable reporting infrastructure.
Frequently Asked Questions
My Client is a Crypto Exchange Incorporated in Dubai but Serving Indian Users. Do I Need to Advise Them on PMLA Compliance?
Yes. PMLA obligations are activity-based, not determined by incorporation location. Any entity conducting notified VDA activities for Indian users must register with FIU-IND. Nine offshore platforms have already had their URLs blocked by MeitY for non-registration. Advise your client to register without delay.
If I Only Prepare My Client's ITR and Advise on Tax, am I a Reporting Entity Under the 3rd May 2023 Notification?
No. The 3rd May 2023 notification applies only when you execute specified financial transactions on behalf of a client, not when you advise or file returns. Document the advisory nature of your engagement in writing at the start of every VASP client relationship.
My Client Received an STR-Related Query From FIU-IND. What Should I Tell Them, and What Must I Avoid?
Tell your client to respond through their Principal Officer only and engage a PMLA-qualified legal advisor first. Neither you nor your client can disclose to the counterparty that an STR has been filed. The tipping-off prohibition under Section 8A applies even after the query is received.
What is the Difference Between the Designated Director and the Principal Officer, Can My Client Appoint the Same Person to Both Roles?
The Designated Director holds board-level compliance accountability. The Principal Officer handles day-to-day AML operations and STR filing. A dual appointment is not explicitly prohibited, but the conflict-of-interest prohibition on the Principal Officer makes it difficult to defend in practice. Advise your client to keep the roles separate.
My Client Listed a Privacy Coin Before the 2026 Guidelines. How Urgently Should I Advise Them to Delist?
Advise immediate delisting. The 8th January 2026 guidelines make this a baseline compliance requirement with no grace period stated. Continued listing after that date is an ongoing Section 13 failure. Include it in your gap assessment report with a specific remediation deadline attached.