The first question most finance teams ask before moving cross-border payments off a bank wire is not about price. It is about safety and paperwork.
Is the money protected while it moves, and will dropping SWIFT break the FIRC, EDPMS or GST-refund workflow the business has run for years? Those are the right questions to ask. The honest answer is that nothing downstream has to change.
How Xflow handles compliance
Xflow is a regulated cross-border payments platform for Indian exporters. It is built so that receiving money from abroad stays inside the rules the Reserve Bank of India (RBI) sets, without adding work for your team.
As of February 2026, Xflow holds final Payment Aggregator-Cross Border (PA-CB) authorisation from the RBI for both exports and imports, one of a small set of firms licensed for both. It is ISO 27001 and SOC 2 certified, works with Authorised Dealer Category-1 (AD-1) banks for FX and settlement, and issues an automatic eFIRA on every receipt. This dual authorisation matters, and we explain what it covers in our note that xflow holds pacb license.
In plain terms: the money is ring-fenced while it moves, the regulator sees a compliant transaction, and you get the same certificates you file today. The rest of this guide explains how, for a services or IT exporter receiving inward remittance from overseas clients.
Is your money safe with Xflow?
Fund safety comes down to where the money sits and who controls it. When an overseas client pays you, the funds land in a ring-fenced receiving accounts setup, a virtual account (vBAN) issued by the banking partner purely to book the FX.
Xflow does not own that account, and funds can only move to the Indian bank account you registered during onboarding. The account does not hold your money as a deposit and does not earn interest. It is a routing account, not a wallet. That is a different structure from tokenized deposits, which represent an actual claim on money held at a bank rather than a pass-through FX booking account.
Two more layers back that up. The regulatory layer is the PA-CB authorisation, which means the RBI supervises how the platform handles customer funds and foreign exchange.
The security layer is ISO 27001 and SOC 2 certification, the recognised standards for information security and controls. Together they answer the "is Xflow safe" question with structure rather than a slogan.
A fair follow-up is what happens to money in transit if the platform ever stopped operating. Because the receiving account is ring-fenced and funds are contractually limited to your registered Indian bank account, the money is not treated as the platform's own asset.
That separation is the reason the vBAN exists in the first place. It keeps your inflows attached to you, not to the platform's balance sheet, which is exactly the assurance an enterprise finance team looks for.
For a fuller walkthrough of these safeguards, see our dedicated explainer on is xflow safe.
What a PA-CB is required to do
Understanding the licence helps explain why the platform behaves the way it does. A Payment Aggregator-Cross Border is an RBI-authorised entity, and the authorisation comes with obligations that protect the merchant.
- Routing through regulated banks: a PA-CB must move foreign exchange through AD-1 banks and cannot run an unregulated FX channel of its own.
- KYC and screening: it must verify the businesses it onboards and screen transactions, which is why onboarding asks for entity documents.
- Documentation: it must support export and import documentation, so you receive realisation proof rather than chasing it.
- Reporting: it reports to the RBI and to the Financial Intelligence Unit-India (FIU-IND), which keeps your inflows on the right side of FEMA.
The framework also sets a per-transaction ceiling for goods or services under the cross-border aggregator route. Larger flows are handled through the appropriate banking channel, so it is worth confirming your ticket sizes at onboarding. The PA-CB regime is India's route for this oversight; other jurisdictions rely on their own frameworks, such as a US money transmitter license.
What changes and what stays the same
The most common fear is that a new payment rail resets your compliance stack. It does not. Here is the split for a services exporter.
| Your compliance workflow | Status on Xflow |
|---|---|
| FIRC / eFIRA as proof of realisation | Issued automatically on each receipt |
| Purpose code on the inward remittance | Captured and applied per payment |
| EDPMS entry for goods exports | Unchanged; realisation still closes the item |
| SOFTEX filing for software exports | Unchanged; you file as before |
| GST refund on zero-rated exports | Unchanged; the eFIRA supports the claim |
| Your CA's or auditor's view of records | Unchanged; same documents, same format |
The platform absorbs the RBI-facing mechanics. Your filings, your certificates and your accountant's process stay where they are. That is the point of framing compliance as relief rather than a fresh burden.
The compliance artefacts you receive
Every receipt on Xflow produces the documents your downstream workflow needs. Knowing what lands where removes most of the anxiety.
- eFIRA (electronic Foreign Inward Remittance Advice): issued automatically, this is the primary proof that foreign currency was received and converted.
- FIRC (Foreign Inward Remittance Certificate): the certificate exporters lean on for GST and realisation records, explained under FIRC.
- Purpose code: the RBI code that classifies why the money arrived, so the credit clears cleanly. See the full RBI purpose code for inward remittance guide.
- Payment advice: the transaction-level record your finance team reconciles against the invoice.
Because these are generated on every receipt, there is no manual certificate request and no waiting on a bank to email a document weeks later.
Compliance starts at onboarding
Compliance is not only about the payment. It starts when you open the account, and getting this stage right prevents queries later.
Onboarding is a short online Know Your Business (KYB) process. You share your entity type, choose a fee plan, and submit KYC documents, after which an operations review activates the account. Our guide on mastering kyc to manage international payments without risks breaks down what reviewers actually check for at this stage. Our checklist of what documents do you need to open an xflow account covers exactly what to prepare beforehand.
Getting the entity and business profile right at this stage matters, because it sets how each future receipt is classified and reported. A sole proprietor, an LLP and a private limited company are treated differently, so the profile should match your registration exactly.
Once activated, you can usually transact from the next business day. The purpose codes tied to your business are applied automatically to incoming payments, which is what removes the per-transaction back-and-forth later.
How a compliant inward payment works, step by step
For a services or IT exporter, a single receipt runs through a clear sequence.
- Collection: your overseas client pays in their local currency into your Xflow receiving account. The account is ring-fenced and used only to book the FX.
- Conversion and cross-border leg: the funds are converted at a live mid-market rate and routed to India through AD-1 bank rails under the PA-CB framework, not through an unregulated FX channel.
- Settlement: the INR amount settles to your registered Indian bank account, typically on the next business day (T+1).
- Documentation: the eFIRA and payment advice are generated automatically, with the correct purpose code attached.
- Your filings: you close the SOFTEX filing for software exports or the EDPMS entry for goods, and use the eFIRA for the GST refund. This is where FIRC for GST refund closes the loop.
A worked example
A Pune IT services firm invoices a UK client 8,000 US dollars for a development retainer. At an illustrative mid-market rate of ₹95 to the dollar, the receipt is ₹7,60,000 before fees.
The client pays into the firm's receiving account. Xflow books the FX, routes it through the AD-1 bank, and settles INR to the firm's registered account the next business day.
An eFIRA is issued with purpose code P0802 for software services, which matches the firm's SOFTEX filing. The finance team uses the eFIRA for its GST refund claim.
There is no manual FIRC request and no separate reconciliation. The auditor sees the same document set as before, so the switch is invisible to the compliance process.
Compliance for goods versus services exporters
The workflow differs slightly by what you export, and picking the right track matters for how the item closes.
- Services and software exporters: realisation is reported through SOFTEX, and the common purpose codes sit in the P08 and P10 series. This is the primary segment Xflow serves for inward payments.
- Goods exporters: realisation closes against EDPMS, tied to the shipping bill, and codes sit in the P01 series.
If you are a freelancer below the GST threshold, the paperwork is lighter and the specifics are covered separately. Start with the segment that matches your registration, because the documents your bank expects follow from it.
What about import payments?
With final PA-CB authorisation covering imports as well as exports as of February 2026, Xflow can also support businesses paying overseas suppliers. The import side carries its own documentation, such as import declarations and the relevant purpose codes, and routes through AD-1 banks in the same regulated way. Whether a payment counts as a current or capital account transaction changes which documents apply, a distinction covered in our breakdown of capital and current account transactions under fema.
If your business both receives export income and pays foreign suppliers, keeping both legs on one authorised platform means one consistent set of records for your auditor rather than two disconnected trails.
Where to go deeper
This guide is the overview. For the long tail of specific questions on documents, timelines and edge cases, use the dedicated FAQs on Xflow compliance.
For the wider regulatory backdrop, payment compliance and AML compliance set the context that a PA-CB operates within.
The short version
Xflow is built so that switching your cross-border collections does not disturb your compliance stack. The money is ring-fenced and RBI-supervised while it moves, and the eFIRA and purpose code arrive automatically.
Your FIRC, EDPMS, SOFTEX and GST steps run exactly as they do now. The safety and the paperwork are handled, so your team can treat the switch as a cost and speed decision, not a compliance risk.
Receive cross-border payments with full compliance, end to end.
Frequently asked questions
Yes. Funds sit in a ring-fenced receiving account that Xflow does not own and can only move to your registered Indian bank account. Xflow holds final RBI PA-CB authorisation and is ISO 27001 and SOC 2 certified.
No. Xflow issues an automatic eFIRA on every receipt, which supports your GST refund and realisation records. Your filing process and the documents your CA reviews stay the same.
Your EDPMS and SOFTEX filings are unchanged. Xflow supplies the eFIRA, payment advice and correct purpose code so the realisation closes cleanly against your export entry.
The vBAN is a ring-fenced virtual account issued by the banking partner to book the FX. It is not owned by you or Xflow, holds no deposit and earns no interest. Funds move only to your registered Indian account.
Yes. As of February 2026, Xflow holds final Payment Aggregator-Cross Border (PA-CB) authorisation for both exports and imports, and routes foreign exchange through AD-1 banks.
Inward payments generally settle to your Indian bank account on the next business day (T+1), with the eFIRA and payment advice generated automatically.
No. An eFIRA is generated automatically on each receipt, so you do not raise a manual request. It is ready to use for your GST refund and realisation records.