Back to Interaction with Other Laws

FIU-IND Cybersecurity Audit Mandate

FIU-IND's mandatory cybersecurity audits for Virtual Digital Asset Service Providers and their interaction with DPDPA requirements.

6 min read

Cybersecurity Audit Mandate

The Financial Intelligence Unit-India (FIU-IND) has mandated cybersecurity audits for registered Virtual Digital Asset Service Providers (VDA SPs). These audits must be performed specifically by CERT-In empanelled auditors. VDA SPs handle cryptocurrency and other digital assets, processing significant volumes of personal and financial data. The audit requirements cover data protection, access controls, incident response, and transaction monitoring - areas that directly overlap with DPDPA obligations. The audit must also certify compliance with the 'Travel Rule' (Originator/Beneficiary data exchange).

Scope of Cybersecurity Audits

FIU-IND audits assess: (a) data protection measures including encryption and access controls; (b) incident response capabilities and procedures; (c) transaction monitoring systems for AML/CFT compliance; (d) identity verification and KYC processes; (e) cybersecurity governance and risk management; and (f) Travel Rule compliance for Originator/Beneficiary data exchange. Many of these assessment areas mirror DPDPA's security safeguard requirements under Rule 6, creating opportunities for harmonised compliance.

Interaction with DPDPA

VDA SPs must comply with both FIU-IND cybersecurity requirements and DPDPA obligations. Key intersection points: (a) security safeguards - R.6 requirements for encryption, masking, and access controls align with FIU-IND audit criteria; (b) the Rule 6 logging mandate, which specifically requires technical measures to retain logs for one year for security detection; (c) breach notification - both frameworks require incident reporting; (d) data retention - transaction monitoring records must be balanced against R.8 retention limits; and (e) KYC data - processing falls under legitimate use (Section 7) for legal compliance. The stricter standard applies at each overlap point.

Practical Compliance Steps

VDA SPs should: (a) align their cybersecurity framework with both FIU-IND and DPDPA requirements simultaneously; (b) conduct integrated audits covering both frameworks; (c) document the lawful basis for transaction monitoring data retention; (d) implement breach notification processes meeting both timelines; and (e) maintain separate consent for any processing beyond regulatory mandates.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.