Last updated: 2026
Author: EDITORIAL TEAM
Affiliate disclosure: This article may contain affiliate links. We may receive a commission if a reader opens an account through one of these links, at no additional cost to the reader. Affiliate relationships do not change the verification process, risk warnings or evidence standards described below. No exchange can pay to bypass a check or receive an unverified compliance claim.
Important risk notice: This guide is for general educational purposes and is not financial, investment, tax or legal advice. Crypto assets can be highly volatile, and using an exchange can expose you to market, custody, cybersecurity, liquidity and regulatory risks. FIU-IND registration should not be interpreted as a government guarantee that an exchange is solvent, secure or suitable for you.
Quick Answer
To check the FIU registration of a crypto exchange, do not rely on a logo, homepage badge, influencer post or comparison website.
Complete these four checks instead:
- Find the exact legal entity operating the exchange.
- Look for registration evidence connected to that same entity through official FIU-IND or other Government of India material.
- confirm that the website domain belongs to the real exchange rather than a phishing copy.
- Check that the mobile app’s developer, seller, privacy-policy domain and website details are consistent with the verified business.
The important word is consistent. A brand name alone proves very little. You need the company name, official evidence, website and app identity to form one connected chain.
FIU-IND is India’s national agency for receiving, analysing and disseminating information relating to suspicious financial transactions. Virtual Digital Asset Service Providers operating in India are subject to anti-money-laundering and counter-terrorist-financing obligations under the Prevention of Money Laundering Act framework.
However, registration is not the same as an investment licence, deposit guarantee, cybersecurity certificate or government recommendation. It is primarily evidence that a named reporting entity has entered the AML and CFT compliance framework administered by FIU-IND.
The Four Checks at a Glance
| Verification layer | What you are checking | Strong evidence | Common red flag |
|---|---|---|---|
| Legal entity | The company operating the exchange | Terms, legal notice, privacy policy and corporate records use the same company name | Only a brand name is disclosed |
| FIU evidence | Whether that legal entity has registration or official compliance evidence | FIU document, government release, compliance order or verifiable registration communication | A cropped badge with no entity name or reference |
| Domain | Whether you are using the genuine website | Exact domain, consistent legal pages, app-store developer website and official communications | Misspelling, extra hyphen or unrelated domain extension |
| App publisher | Whether the installed app belongs to the verified business | Matching developer or documented group company, official website and privacy-policy domain | APK from Telegram, WhatsApp or an unrelated publisher |
Completing only one of these checks is not enough.
A real company can be impersonated by a fake website. A real website can be copied into a malicious app. A legitimate app can be promoted through a fraudulent login page. A platform can also use a consumer brand that is completely different from its incorporated company name.
The purpose of the process is to make those substitutions easier to detect.
What FIU-IND Registration Actually Means
A crypto exchange or other Virtual Digital Asset Service Provider may fall within the AML and CFT framework when it carries out activities such as:
- exchanging virtual digital assets for fiat currency;
- exchanging one virtual digital asset for another;
- transferring virtual digital assets;
- safeguarding or administering virtual digital assets or instruments that provide control over them; or
- participating in financial services connected to an issuer’s offer or sale of a virtual digital asset.
These activities were specifically addressed when VDA service providers were brought within the PMLA reporting framework. The registration obligation is activity-based and can apply to both onshore and offshore businesses serving Indian users; it is not determined only by whether the company has a physical office in India.
A reporting entity is expected to establish compliance systems that can include customer due diligence, record keeping, internal controls, employee training and the filing of reports concerning suspicious transactions. The current FIU registration process is considerably more detailed than submitting an online form and receiving an automated reference number.
FIU’s September 2025 registration circular states that registration involves an in-person meeting attended by designated compliance officials. Applicants may be asked to provide information about their services, corporate structure, beneficial ownership, incorporation documents, financial statements, GST returns, tax returns, VDA TDS filings and arrangements with other exchanges, custodians or intermediaries.
The circular also calls for a cybersecurity audit certificate from a CERT-In-empanelled auditor and a live walkthrough of systems covering areas such as KYC, transaction monitoring, blockchain analysis, Travel Rule processes and sanctions screening.
That depth matters because it shows why a homepage statement reading “FIU registered” is not enough. Registration is tied to a specific applicant, corporate structure and compliance process.
The same circular makes another important distinction: a system-generated FIU reference identifier is for reference purposes and is not, on its own, final registration. Registration is granted only after the required process is completed and in-principle approval is provided. FIU-IND also reserves the right to deny or cancel registration where obligations are not fulfilled.
What FIU Registration Does Not Prove
Even a clean registration check does not establish all of the following:
- that customer assets are held one-to-one;
- that the exchange has enough liquid assets to meet every withdrawal;
- that it has never suffered a security incident;
- that its proof-of-reserves statement includes all liabilities;
- that every token listed on the platform is legitimate;
- that prices will be fair during periods of extreme volatility;
- that INR withdrawals will always be processed quickly;
- that your account will never be frozen for a compliance review;
- that the exchange will remain registered indefinitely;
- that the Government of India will reimburse customers if the platform fails.
FIU registration is therefore one part of due diligence, not the end of it.
A user should still consider custody arrangements, security history, withdrawal terms, complaint handling, fee transparency, tax reporting, liquidity and whether holding a large balance on a centralised exchange is necessary.
A Critical 2026 Note About the “FIU Registered Exchange List”
Many online guides tell readers to open a public FIU list, press Ctrl + F, enter an exchange name and treat any result as conclusive.
The real process may not always be that simple.
At the time of this 2026 update, the public FIU-IND downloads section prominently provides the current AML and CFT guidelines for VDA reporting entities and the latest registration circulars. The page lists VDA guidelines updated on 8 January 2026 and the third revision of the registration circular dated 15 September 2025. A simple, always-current consumer-facing master list may not be displayed in the same obvious format at all times. This could change as the website and its publications are updated.
For that reason, a responsible verification process should not fabricate certainty when a public list is unavailable, inaccessible or unclear.
Your evidence may instead come from:
- a document or notice published by FIU-IND;
- a Government of India or Press Information Bureau release naming the entity;
- an FIU compliance or enforcement order;
- the exchange’s registration letter or official compliance communication;
- a registration reference that can be independently connected to the correct legal entity;
- a direct response from the platform’s compliance team supported by verifiable documentation.
A blog post saying “Exchange X is registered” is not official evidence. It can help you locate a possible source, but it should not be the final source.
Step 1: Find the Exchange’s Exact Legal Entity
Why the Legal Entity Comes First
Consumers usually know an exchange by its trading name. Government and corporate documents usually identify it by its incorporated company name.
Those names may be completely different.
For example, a fictional platform called “FastCoin” might be operated by “ABC Digital Markets Private Limited.” Searching an official source for “FastCoin” could return no result even if ABC Digital Markets Private Limited has completed registration.
The opposite problem is also possible. You may find a similar brand or company name that belongs to an unrelated entity and mistakenly treat it as confirmation.
Your first job is therefore to answer this question:
Which legal entity enters into the contract with the user and operates the service being checked?
Step 1.1: Type the Website Address Yourself
Open a clean browser window and type the exchange’s known domain into the address bar.
Avoid beginning with:
- a sponsored search result;
- a Telegram link;
- an SMS promotion;
- a shortened URL;
- a WhatsApp message;
- an influencer’s referral redirect;
- a link in an unsolicited email.
A paid advertisement can lead to the genuine exchange, but it can also be imitated. Starting from a domain that you independently recognise reduces one avoidable source of risk.
Do not enter your password at this stage. Verification should happen before login.
Step 1.2: Open the Legal Documents
Scroll to the website footer and look for pages labelled:
- Terms of Service;
- User Agreement;
- Terms and Conditions;
- Legal;
- Regulatory;
- Privacy Policy;
- Risk Disclosure;
- Company Information;
- About Us.
The Terms of Service or User Agreement is usually the most useful because it identifies the company entering into the agreement with you.
Step 1.3: Search the Page for Entity Language
On a desktop computer, use Ctrl + F or Cmd + F and search for terms such as:
- operated by;
- incorporated;
- registered office;
- private limited;
- company number;
- legal entity;
- contracting party;
- these terms are between;
- service provider.
You are looking for a sentence similar to:
These services are provided and operated by [full legal entity name].
Copy the name exactly. Preserve words such as “Private Limited,” “Limited,” “Pte. Ltd.,” “LLP,” “B.V.” or other corporate suffixes.
Do not simplify it.
Step 1.4: Record Every Relevant Entity
Some exchanges use more than one company.
One company may operate the order book, another may provide custody, and a third may handle INR deposits or a particular product. Offshore groups may use separate contracting entities for users in different countries.
Create a small record:
| Item | What to record |
|---|---|
| Consumer brand | The name displayed to users |
| Contracting entity | Company named in the Terms of Service |
| Custody entity | Company named in custody or wallet terms |
| Payment entity | Company shown on bank or payment disclosures |
| Registered address | Address shown in legal documents |
| Company identifier | CIN, registration number or equivalent, where displayed |
| Date checked | The day you performed the review |
A group structure is not automatically suspicious. The problem arises when the platform provides no understandable explanation of which entity performs which role.
Step 1.5: Compare the Legal Pages
The company name should not change inexplicably from one page to another.
Compare:
- Terms of Service;
- Privacy Policy;
- risk disclosures;
- complaints or grievance page;
- payment instructions;
- app-store privacy policy;
- emails sent after registration.
An outdated document can contain the previous company name after a restructuring or acquisition. That does not prove fraud, but it requires clarification before you deposit.
Screenshot 1: Legal Entity Evidence
Capture a screenshot containing:
- the page heading, such as “Terms of Service”;
- the sentence naming the operator;
- the exact legal company name;
- the browser address bar;
- the date visible on the document, where available.
Do not crop out the domain. A screenshot showing only a company name can be taken from almost anywhere and is weak evidence.
Suggested file name:
01-exchange-legal-entity-2026-07-17.png
Using numbered files makes the final evidence folder easier to review.
Step 2: Verify the Registration Evidence
Once you have the legal entity name, you can begin checking the FIU claim.
Step 2.1: Use the Official Government Website
Navigate to the official FIU-IND website directly.
Check that:
- the domain is the official Government of India FIU domain;
- the connection is encrypted;
- the page identifies the Ministry of Finance or Government of India;
- you are not on a similarly named commercial website;
- the URL has not been altered by a redirect.
FIU-IND describes itself as the national agency that receives, processes, analyses and disseminates information relating to suspicious financial transactions.
Step 2.2: Check Current VDA Publications
Open the sections for downloads, publications, notices, compliance orders or archived announcements.
Look for:
- VDA service provider guidelines;
- registration circulars;
- revisions to registration requirements;
- compliance orders;
- penalty announcements;
- notices naming non-compliant entities;
- government statements naming registered or non-compliant providers.
Always check the date.
The FIU downloads page identifies VDA AML and CFT guidelines updated in January 2026, while the current registration process was revised in September 2025. A screenshot from an older article may therefore omit important requirements or reflect a previous process.
Step 2.3: Search Using the Legal Entity, Not Only the Brand
Search for the exact company name gathered in Step 1.
Try sensible variations without changing its identity:
- full legal entity name;
- name without punctuation;
- “Private Limited” and “Pvt Ltd” versions;
- brand name plus legal entity;
- company name plus FIU;
- company name plus PMLA;
- company name plus VDA SP.
A brand search may find a government press release, while an entity search may find an order or registration reference. Review both, but make sure the final evidence relates to the correct company.
Step 2.4: Use an Evidence Hierarchy
Not every document has the same weight.
Strong official evidence
- A current FIU-IND document naming the legal entity.
- An FIU compliance order naming the entity and its status.
- A Government of India release describing the entity’s registration or compliance position.
- A registration communication whose reference and company details can be independently verified.
Supporting evidence
- The exchange’s regulatory or compliance page.
- A registration letter published by the exchange.
- A current Terms of Service statement.
- A response from the exchange’s compliance department.
- A recognised news report linking to an official document.
Weak evidence
- A badge in the website footer.
- A claim in an affiliate comparison article.
- A screenshot with no source URL.
- A customer-support chat message without supporting documentation.
- An influencer video.
- A social-media post from an unverified account.
Strong evidence should lead your conclusion. Supporting evidence should help connect the legal entity, brand, domain and app. Weak evidence should never be used alone.
Step 2.5: Inspect Any Registration Letter Carefully
An exchange may publish a registration certificate, letter or approval communication.
Check:
- exact legal entity name;
- date;
- FIU reference number;
- subject line;
- address;
- signatory or issuing office;
- whether the document refers to an application, reference ID, in-principle approval or completed registration;
- whether pages are missing;
- whether sensitive information was redacted without removing the key status wording;
- whether the document is hosted on the verified domain.
Be careful with documents showing only an FIU reference identifier. The current registration circular expressly states that a system-generated reference ID is for reference and that registration in letter and spirit follows completion of the prescribed process and FIU approval.
In other words:
Application evidence is not necessarily registration evidence.
Step 2.6: Look for Conflicting Government Information
Search recent FIU and Government of India announcements for the entity.
FIU-IND has issued notices, penalties and URL-blocking requests concerning VDA providers that did not meet PMLA obligations. Official action has included show-cause notices against offshore platforms and monetary penalties for operating without required registration or failing to meet compliance obligations.
This matters because a registration claim may have changed after an old article was published.
Check for:
- penalties;
- cancellation;
- non-compliance notices;
- show-cause proceedings;
- blocking action;
- later registration;
- changes in the legal entity;
- acquisition or restructuring.
A 2024 status claim should not automatically be reused in a 2026 article.
Step 2.7: Ask the Exchange Precise Questions
When the official evidence is unclear, contact support through the verified website and ask:
- What is the full legal name of the FIU-registered reporting entity?
- Is that the same entity named in the current user agreement?
- What is the registration or official reference number?
- On what date was registration completed?
- Does the registration cover the service and domain currently offered to Indian users?
- Which entity publishes the Android and iOS applications?
- Where can the registration claim be independently verified?
- Has the entity received any subsequent cancellation or non-compliance notice?
Save the response.
A vague answer such as “We follow all regulations” is not a substitute for an entity name and verifiable evidence.
Screenshot 2: Registration Evidence
Capture:
- the official document or government page title;
- the legal entity name;
- the relevant registration, compliance or status wording;
- document date;
- official domain;
- reference number, where available.
Suggested file name:
02-fiu-registration-evidence-2026-07-17.png
When the evidence comes from the exchange rather than an official public page, add a note:
Platform-provided evidence; independent confirmation still required.
That label prevents you from accidentally treating self-published material as government confirmation later.
Step 3: Verify the Exchange Domain
A legitimate company can still be impersonated.
Phishing sites often reproduce the colours, logo, login form and support language of a real exchange. Some are convincing enough that a user may complete a legal-entity check on the real company but then deposit through the fake domain.
Step 3.1: Read the Domain Character by Character
Do not judge the URL by its general appearance.
Look for:
- repeated letters;
- missing letters;
- substituted numbers;
- inserted hyphens;
- additional words;
- unusual subdomains;
- a different top-level domain;
- characters from another alphabet that resemble English letters.
A fake site might use a variation such as:
examp1e.cominstead ofexample.com;example-login.cominstead ofexample.com;example.com.fake-domain.net;secure-example.netinstead of the official domain.
The registered domain is the part immediately before the top-level extension, not whichever brand word appears first.
Step 3.2: Understand What HTTPS Proves
Open the browser’s site information or security panel and confirm that the connection is encrypted and the certificate is valid for the domain being visited.
However, do not overstate this check.
HTTPS generally confirms that the connection between your browser and that domain is encrypted. It does not prove that the business operating the domain is honest. Phishing websites can also obtain valid certificates.
Treat the result this way:
- No secure connection: immediate red flag for a financial platform.
- Secure connection: necessary, but not sufficient.
- Correct domain plus secure connection plus matching legal pages: stronger evidence.
Step 3.3: Compare the Domain Across Independent Locations
Check whether the same domain appears in:
- the official mobile-app listing;
- the app developer’s website field;
- the app privacy-policy link;
- the exchange’s verified social profile;
- official government documents, where a domain is named;
- account-opening emails;
- support emails;
- corporate legal documents.
A privacy policy hosted on an unrelated free website, document-sharing service or newly created domain deserves investigation.
Step 3.4: Check the Email Domain
Customer-support messages should normally come from an address connected to the official domain or a clearly documented support provider.
Be cautious when:
- support uses a free consumer email account;
- the sender domain differs by one character;
- the message asks you to install remote-access software;
- the message requests an OTP;
- the sender asks for a seed phrase or private key;
- the message provides a “special” deposit address;
- the email creates artificial urgency.
FIU-IND itself warns that it does not seek information directly from individuals and that communications purporting to do so may be fraudulent.
An exchange employee should also never need your wallet seed phrase.
Step 3.5: Bookmark the Verified Domain
After completing the domain check, create a bookmark and use it for future visits.
Do not repeatedly access the exchange through search advertisements. A bookmarked URL reduces the chance of entering a convincing sponsored phishing page during a rushed login.
Screenshot 3: Domain Verification
Capture:
- the complete address bar;
- the exact domain;
- the browser security panel;
- certificate validity information, where visible;
- the legal page or homepage in the background.
Suggested file name:
03-official-domain-check-2026-07-17.png
Do not crop the screenshot so tightly that the page context disappears.
Step 4: Verify the Mobile App Publisher
The company, website and app are separate verification objects.
A real exchange can have fake apps imitating its name and logo. The risk is higher when users install software from unofficial APK websites, forwarded files or messaging groups.
Step 4.1: Begin From the Verified Website
Open the exchange’s verified domain from Step 3.
Use its official Google Play or Apple App Store button. Avoid searching the app store by brand name as your first step because impersonators may use similar icons and keyword-stuffed titles.
The safest route is:
Verified domain → official download page → app-store listing.
Step 4.2: Record the Publisher or Seller
On the listing, find:
- developer name;
- seller name;
- developer contact;
- developer website;
- privacy-policy link;
- support link;
- app identifier or package name, where visible.
Compare the publisher with the legal entity from Step 1.
An exact match is the simplest result, but some legitimate groups publish an app through a subsidiary or associated technology company. Where the names differ, look for an explanation in the legal documents.
Do not assume that two companies are related because they share a similar word.
Step 4.3: Compare the Developer Website and Privacy Policy
The app-store listing should lead back to the verified domain or to a clearly documented corporate domain belonging to the same group.
Check whether:
- the developer website opens correctly;
- the privacy policy names the same operator;
- support email addresses use the expected domain;
- the app name and logo are consistent;
- the country and business information make sense;
- the terms accessed from the app match the web terms.
A cloned app may copy the description and screenshots while using a different privacy-policy website or developer email. Those smaller fields are often where the mismatch becomes visible.
Step 4.4: Treat Download Counts and Reviews as Supporting Clues
Download volume, rating and review history can be useful, but they do not prove authenticity.
Look for unusual patterns:
- a famous exchange with very few downloads;
- a recent publication date with claims of years of history;
- large numbers of repetitive five-star reviews;
- reviews warning that the app is a clone;
- complaints about stolen login details;
- a publisher with unrelated apps;
- a description filled with spelling errors;
- screenshots that do not match the installed app.
Reviews can be manipulated. Use them as a warning system, not as regulatory evidence.
Step 4.5: Do Not Install a Random APK
Avoid APK files distributed through:
- Telegram;
- WhatsApp;
- SMS;
- file-sharing sites;
- unofficial download portals;
- pop-up advertisements;
- influencer folders;
- direct messages from “support.”
An APK can imitate the genuine interface while stealing passwords, OTPs, device data or wallet credentials.
Where an exchange legitimately provides an Android APK, confirm all of the following before considering it:
- the download starts from the verified official domain;
- the website clearly explains why an APK is offered;
- the file is signed by the expected publisher;
- the requested permissions are reasonable;
- the file is not delivered through a redirect to an unknown host;
- the exchange provides a verifiable checksum or signature where applicable;
- the app can be updated through a secure official process.
For most users, an official app-store version or secure web application is easier to verify than a sideloaded file.
Screenshot 4: App Publisher Verification
Capture:
- app name and icon;
- developer or seller name;
- developer website;
- privacy-policy link;
- download or listing information;
- app-store domain.
Suggested file name:
04-app-publisher-check-2026-07-17.png
How the Four Pieces Should Connect
A completed review should form this chain:
Consumer brand
↓
Legal entity named in the user agreement
↓
Official FIU or government evidence for that entity
↓
Verified website operated by or connected to that entity
↓
App publisher belonging to that entity or a documented group company
A broken link does not automatically prove fraud, but it does mean the verification is incomplete.
Example of a Clean Match
- Brand: Example Exchange
- Terms operator: Example Digital Assets Private Limited
- Official evidence: Example Digital Assets Private Limited is named
- Website: Legal pages use the same entity
- App publisher: Example Digital Assets Private Limited
- Developer website: Same verified exchange domain
- Privacy policy: Same entity and domain
Example of an Unresolved Match
- Brand: Example Exchange
- Terms operator: ABC Holdings Ltd
- Registration screenshot: XYZ Technologies Pvt Ltd
- Website: No explanation connecting ABC and XYZ
- App publisher: Fast Mobile Apps LLC
- Privacy policy: Free document-hosting page
There may be a legitimate corporate explanation, but the user should not supply that explanation on the exchange’s behalf. The platform should document it.
Verification Status: Green, Amber or Red
Green: Evidence Aligns
Use a green result only when:
- the legal entity is clearly disclosed;
- official or independently verifiable registration evidence exists;
- the evidence refers to the same entity;
- the domain is consistent across official materials;
- the app publisher matches or has a documented relationship;
- no newer government notice contradicts the claim.
Green means the registration and identity checks align. It does not mean the investment is safe.
Amber: Evidence Is Incomplete
Use amber when:
- the platform claims registration but public evidence is unclear;
- the entity name differs slightly;
- a group company publishes the app;
- the exchange supplies a letter that cannot be independently confirmed;
- a government document is old;
- a corporate restructuring has not been fully reflected in all legal pages.
Pause and ask for clarification.
Red: Material Mismatch or High-Risk Behaviour
Use red when:
- the platform refuses to identify its legal entity;
- the “registration certificate” contains a different company;
- only an application number is presented as final approval;
- the domain is misspelled or unrelated;
- the app is distributed only through messaging apps;
- the publisher cannot be connected to the exchange;
- support requests an OTP, seed phrase or remote device access;
- a newer official notice reports non-compliance;
- you are pressured to deposit before verification.
Do not send funds while a red flag remains unresolved.
Screenshot-Ready Verification Worksheet
Copy this into your notes and complete it before depositing.
FIU CRYPTO EXCHANGE VERIFICATION RECORD
Exchange brand:
Website checked:
Date checked:
Checked by:
PART 1 — LEGAL ENTITY
[ ] I typed the domain directly into my browser.
[ ] I opened the Terms of Service or User Agreement.
[ ] I recorded the exact contracting entity.
[ ] I checked the Privacy Policy for the same entity.
[ ] I recorded any separate custody or payment companies.
[ ] I saved a screenshot showing the entity and domain.
Legal entity:
Registration/company number:
Registered address:
Screenshot file:
PART 2 — FIU-IND EVIDENCE
[ ] I visited the official FIU-IND website.
[ ] I checked current VDA guidelines and registration circulars.
[ ] I searched the exact legal entity name.
[ ] I looked for recent compliance orders or government releases.
[ ] I recorded the document date.
[ ] I distinguished an application/reference ID from final registration.
[ ] I saved the official evidence.
[ ] I contacted the exchange where evidence was incomplete.
Evidence type:
Official source:
Reference number:
Evidence date:
Status wording:
Screenshot file:
PART 3 — DOMAIN
[ ] I checked every character in the domain.
[ ] I confirmed an encrypted connection.
[ ] I compared the domain with the app-store developer website.
[ ] I checked the privacy-policy domain.
[ ] I checked the support email domain.
[ ] I bookmarked the verified website.
Verified domain:
Certificate checked:
Developer website match:
Support email domain:
Screenshot file:
PART 4 — MOBILE APP
[ ] I opened the app-store listing from the verified website.
[ ] I recorded the developer or seller name.
[ ] I compared it with the legal entity.
[ ] I checked the developer website.
[ ] I checked the app privacy policy.
[ ] I reviewed the app identifier where available.
[ ] I did not install a forwarded or third-party APK.
Platform:
Developer/seller:
Relationship to legal entity:
Developer website:
Privacy-policy domain:
Screenshot file:
FINAL RESULT
[ ] Green — all key evidence aligns
[ ] Amber — clarification is required
[ ] Red — material mismatch or risk found
Unresolved questions:
Final decision:
Next review date:
Common Verification Mistakes
Searching Only the Brand Name
Government records are generally connected to legal entities rather than marketing names. Always identify the operator before searching.
Treating a Logo as Proof
A graphic reading “FIU Registered” can be copied in seconds. It has little evidentiary value without an entity name, date, reference and official source.
Treating an Application ID as Approval
A generated reference may show that an application or account exists. FIU’s registration circular clarifies that a reference ID is not, by itself, final registration.
Assuming HTTPS Means the Website Is Genuine
A valid certificate protects the connection to a domain. It does not confirm that the domain belongs to the business you intended to visit.
Ignoring the Mobile App
Verifying the company and then downloading the first app-store result leaves a major gap in the process.
Trusting an Old “Best Exchange” List
Registration, enforcement status, ownership and app listings can change. Always check the date and look for newer official information.
Assuming Registration Guarantees Withdrawals
Registration does not promise instant withdrawals or prevent compliance holds. A withdrawal can be delayed by bank processing, enhanced due diligence, source-of-funds checks, blockchain risk screening, account limits or technical problems.
Leaving Large Balances on an Exchange
A successful FIU check does not remove custody risk. Consider whether funds that are not actively being traded need to remain on a centralised platform.
Additional Checks Before Depositing INR
FIU verification tells you about AML registration and platform identity. Before depositing rupees, also check the practical account conditions.
KYC Requirements
Review:
- which identity documents are accepted;
- whether PAN is mandatory;
- whether bank ownership must match the account holder;
- whether video verification is required;
- what triggers enhanced due diligence;
- whether source-of-funds evidence may be requested;
- how long manual reviews normally take.
A registered reporting entity is expected to apply customer due diligence. A request for additional information is not automatically suspicious, but documents should only be uploaded through the verified application or domain.
INR Deposit Methods
Confirm:
- supported bank-transfer methods;
- beneficiary name;
- whether third-party deposits are prohibited;
- minimum and maximum amounts;
- deposit fees;
- expected processing window;
- what happens if the bank account name does not match;
- whether UPI support is direct, partner-based or unavailable.
Payment methods can change. Do not rely on an old review claiming that UPI or instant deposits are always available.
Withdrawal Conditions
Check:
- minimum withdrawal;
- platform fee;
- blockchain network fee;
- daily limits;
- cooling-off periods;
- bank verification requirements;
- compliance review triggers;
- supported networks;
- destination-address restrictions;
- whether address whitelisting is available.
A promise of “guaranteed instant withdrawal” should be treated cautiously. No exchange controls every bank, blockchain or compliance review.
Security Features
Prefer accounts supporting:
- authenticator-based two-factor authentication;
- passkeys where available;
- withdrawal-address whitelisting;
- anti-phishing codes;
- new-device alerts;
- login-history review;
- biometric or local app lock;
- session management;
- withdrawal confirmation;
- account recovery controls.
SMS OTP is better than no second factor, but authenticator apps or stronger phishing-resistant methods generally reduce exposure to SIM-swap attacks.
Crypto Tax and TDS Checks in 2026
FIU compliance and tax compliance are related but separate.
A platform appearing in an AML framework does not mean every tax figure shown in its dashboard is automatically correct for your circumstances. Keep your own transaction records and consult a qualified Chartered Accountant where needed.
India’s official Income Tax information states that income from the transfer of virtual digital assets is generally taxed at 30%, with only the cost of acquisition permitted as a deduction under the stated VDA framework. The department also identifies 1% TDS on qualifying payments for VDA transfers.
The 2026 transition requires extra care with terminology.
Transactions and withholding events up to 31 March 2026 are governed by the applicable provisions of the Income-tax Act, 1961. For events from 1 April 2026, the corresponding withholding rules of the Income Tax Act, 2025 apply. The Income Tax Department states that TDS rates and thresholds were retained while the provisions were reorganised, including consolidation under Section 393.
For specified individual or HUF reporting, the previous Form 26QE process for VDA transfers has been incorporated into the new Form 141 framework. Crypto exchanges that have agreed to deposit tax under the applicable exchange mechanism may have quarterly reporting obligations through Form 142.
For users, the practical record-keeping lesson is more important than memorising a section number:
Keep:
- trade confirmations;
- INR deposit and withdrawal records;
- token quantities;
- transaction timestamps;
- purchase costs;
- sale consideration;
- fees;
- TDS statements;
- Form 26AS or AIS information where relevant;
- wallet transfer records;
- exchange CSV exports;
- records of crypto-to-crypto transactions;
- evidence of gifts or transfers between your own wallets.
Do not assume that moving to an offshore platform removes Indian tax obligations.
What to Do After a Successful Verification
A successful result should be followed by a cautious first transaction.
1. Create the Account From the Verified Domain or App
Do not return to a referral message or advertisement after completing the check. Use the domain or app listing you already verified.
2. Use a Unique Password
Do not reuse a banking, email or social-media password. A password manager can generate and store a unique credential.
3. Enable Strong Two-Factor Authentication
Use an authenticator or another strong option offered by the platform. Save backup codes offline in a secure location.
4. Add an Anti-Phishing Code
Where supported, this adds a custom phrase to legitimate exchange emails, making basic impersonation easier to detect.
5. Make a Small Test Deposit
Send only an amount you can afford to place at risk. Confirm that the account is credited correctly.
6. Make a Small Test Withdrawal
Test the full withdrawal process before committing a larger balance.
Check:
- processing time;
- fees;
- KYC prompts;
- bank or wallet arrival;
- blockchain network selected;
- support response where something is delayed.
A successful small withdrawal does not guarantee every future withdrawal, but it provides more information than relying on marketing claims.
7. Set a Recheck Date
Review the exchange periodically, especially after:
- a change in Terms of Service;
- a new app publisher;
- a domain migration;
- an acquisition;
- a major security incident;
- an FIU announcement;
- a prolonged withdrawal issue;
- a change in the company named on your bank statement.
Verification is a dated result, not a permanent certificate.
Frequently Asked Questions
How do I check whether a crypto exchange is FIU registered?
First identify the exact legal entity in the platform’s Terms of Service. Then search official FIU-IND publications, Government of India announcements and compliance material for that entity. Compare the resulting evidence with the exchange’s domain and mobile-app publisher. Do not rely solely on an FIU badge or affiliate list.
Is there an official FIU registered crypto exchange list?
Official materials and government announcements may identify registered, penalised or non-compliant VDA service providers. However, the public FIU website may not always present a simple, continuously updated consumer-facing master list in the format described by third-party articles. Check current FIU publications and do not claim verification where the official evidence remains unclear.
Can I search the FIU website using the exchange name?
You can, but also search the incorporated company name. Government evidence may identify the reporting entity rather than the public brand.
Where can I find a crypto exchange’s legal entity?
Start with the Terms of Service, User Agreement, Privacy Policy and legal footer. Look for wording such as “operated by,” “contracting entity” or “services provided by.”
What if the Terms of Service lists several companies?
Record each company and identify its role. One may operate the exchange, another may provide custody, and another may handle payments. Ask support which specific entity holds the FIU registration relevant to your account.
Does an FIU reference number prove registration?
Not necessarily. A reference can relate to an application or system record. FIU’s current registration circular states that a generated FIU reference identifier is for reference and that registration follows completion of the prescribed process and approval.
Does FIU registration mean a crypto exchange is legal in India?
It means the named VDA service provider is participating in the applicable AML and CFT reporting framework, subject to the status and date of the evidence checked. It should not be turned into a blanket statement that every product, token, activity or future operation is fully licensed or legally risk-free.
Does FIU registration make an exchange safe?
No. It does not guarantee solvency, asset backing, cybersecurity, fair pricing or successful withdrawals. It is one compliance check.
Can an offshore crypto exchange register with FIU-IND?
The AML obligation is activity-based and may apply to an offshore VDA provider serving Indian users, even without a physical presence in India. Official government statements have described compliance obligations for both onshore and offshore providers.
What happens if an offshore exchange does not comply?
FIU-IND can initiate action under the PMLA framework. Past official action has included show-cause notices, penalties and requests to block access to non-compliant services.
Is an SSL certificate enough to prove the exchange website is official?
No. SSL helps confirm that your connection to the domain is encrypted. A scam website can also obtain a valid certificate. Verify the spelling, legal pages, developer website, privacy policy and official communications.
Why should I verify the mobile app separately?
A fraudulent app can impersonate a real registered company. The app publisher, developer website and privacy-policy domain must therefore be checked independently.
What if the app publisher does not exactly match the FIU entity?
It may be a documented subsidiary, technology company or group entity. Look for a clear corporate explanation in the legal documents. Do not assume a relationship without evidence.
Is it safe to install an exchange APK?
An APK is harder for an ordinary user to verify than an official app-store listing. Never install one from a message, third-party mirror or unknown download site. Where the exchange offers an APK, access it only through the verified domain and check its signature, permissions and update process.
How often should I repeat the FIU verification?
Check before the first deposit and periodically afterwards. Repeat it whenever the operator, domain, app publisher or Terms of Service changes, or when new enforcement or security information appears.
What should I do if I cannot find the entity?
Check the spelling, corporate suffix and group structure. Ask the exchange for the exact registered entity, registration date and evidence. Until the discrepancy is resolved, classify the result as unconfirmed rather than assuming registration.
Should I deposit while support is “checking” the registration question?
There is no need to rush. Wait for a clear response and independently review the evidence before funding the account.
Does FIU registration remove the need for KYC?
No. Customer due diligence and monitoring form part of the AML framework. Registered exchanges may request identity, bank ownership, source-of-funds or enhanced due-diligence information.
Does FIU registration mean INR withdrawals will be instant?
No. Withdrawals can be affected by bank availability, platform liquidity, account limits, compliance reviews and technical processing. Avoid claims that a withdrawal is guaranteed to be instant.
Is 1% TDS the same as my final crypto tax?
No. TDS is a withholding mechanism, not necessarily the final tax liability. VDA income calculations, losses, reporting and return filing can be more complex. Consult a qualified tax professional for advice about your records.
Can I verify an exchange once and rely on that result forever?
No. Registration, ownership, domains, apps and compliance status can change. Save the date of every check and review the platform again periodically.
Final Verification Rule
Never base a financial decision on a single badge.
A credible FIU registration check should give you four matching answers:
- Who is the legal entity?
- What official evidence supports its FIU claim?
- Am I using that entity’s genuine domain?
- Was the app published by that entity or a documented related company?
When those answers align, you have a stronger basis for deciding whether to continue your review.
When they do not align, stop and investigate.
FIU registration is valuable compliance information, but it should remain in its proper place: one layer of a wider assessment that also considers custody, security, fees, withdrawals, tax records, customer support and the risks of holding virtual digital assets.
Official Sources for Further Checking
- FIU-IND official homepage and public notices.
- FIU-IND downloads, current VDA guidelines and registration circulars.
- Third revision of the VDA service provider registration circular.
- Government information on FIU action involving VDA service providers.
- Income Tax Department guidance on VDA tax and TDS.
- Income Tax Department guidance on the 2026 Act transition and new VDA reporting forms.
