India's Financial Intelligence Unit (FIU) has introduced strict new regulations for cryptocurrency exchanges, aiming to combat illegal activities in the digital asset market. The updated guidelines, effective January 8, classify crypto exchanges as Virtual Digital Asset (VDA) service providers, requiring more than just simple document uploads. Users must now undergo a comprehensive onboarding process, including mandatory liveness detection and geographical tracking.
One of the key measures is the introduction of 'live selfies', where users must take a photo while blinking or moving their head to verify their presence. This prevents the use of static images or deepfakes, ensuring the user's identity is genuine. Additionally, exchanges must record the user's exact location, date, timestamp, and IP address during account creation.
The 'penny-drop' method is also mandated, which involves processing a small transaction to confirm the bank account's activity and ownership. Users are required to provide a Permanent Account Number (PAN) and a secondary ID such as a passport, Aadhaar, or voter ID. Email ID and phone number verification with OTP are also necessary.
The FIU, operating under the Union Finance Ministry, is taking a firm stance against tools designed to conceal crypto wealth. The new guidelines strongly discourage Initial Coin Offerings (ICOs) and Initial Token Offerings (ITOs) due to their high risk and lack of economic justification. These offerings are now subject to increased scrutiny and regulation.
As the primary regulator for cryptocurrency exchanges in India, the FIU mandates that all exchanges register as reporting entities and submit regular reports on suspicious transactions. They must also maintain client records to identify and prevent money laundering, terrorist financing, and proliferation financing risks associated with crypto assets, which are taxed under the Income-Tax law despite not being recognized as legal tender.
The guidelines emphasize the importance of verifying the client's identity and presence during the onboarding process. This includes capturing live photographs and using liveliness detection technology to ensure the client's physical presence. Exchanges are required to conduct Know Your Customer (KYC) updates for 'high-risk' clients every six months and for all others annually.
For high-risk individuals or entities with connections to tax haven countries or jurisdictions on the FATF grey or black list, as well as politically exposed persons (PEPs) or non-profit organizations (NPOs), an 'enhanced client due diligence' is mandated. This involves gathering details from open sources and consulting independent databases to ensure a thorough understanding of the client's background.
The guidelines also address the risks associated with ICOs/ITOs, which are considered 'heightened and complex' due to their lack of economic justification. Anonymity-enhancing crypto tokens (AECs), tumblers, and mixers are specifically designed to conceal transaction details, and their use is prohibited. Such transactions must trigger suitable risk mitigation measures to prevent money laundering and terror financing.
Crypto tumblers or mixers, as the name suggests, blend coins from different sources, making them extremely difficult to trace. The guidelines mandate that exchanges preserve client IDs, addresses, and transaction details for at least five years, retaining them until an investigation is concluded. This comprehensive approach ensures a robust regulatory framework for the cryptocurrency industry in India.