Xflow Compliance Guide: How Your Money Stays Safe and RBI-Compliant
Xflow Compliance Guide: How Your Money Stays Safe and RBI-Compliant
Compliance / Tax

Published on 06/08/2026

Xflow Compliance Guide: How Your Money Stays Safe and RBI-Compliant

See it working on your own payments

Receive client payments at the mid-market rate with an eFIRA on every transaction.

Xflow compliance refers to how Xflow, a Reserve Bank of India (RBI) authorised cross-border payments platform, handles the regulatory work of receiving foreign payments so that an Indian exporter does not have to. Because the platform holds final Payment Aggregator-Cross Border (PA-CB) authorisation and routes funds through regulated banks, your money stays ring-fenced while it moves, and your FIRC, EDPMS, SOFTEX and GST steps continue exactly as they do today.


The first question most finance teams ask before moving cross-border collections off a bank wire is not about price. It is about safety and paperwork: is the money protected while it moves, and will dropping SWIFT break the workflow the business has run for years? Those are the right questions. The honest answer is that nothing downstream has to change.


How Xflow handles compliance

Xflow is a regulated cross-border payments platform for Indian exporters. It is built so that receiving money from abroad stays inside the rules the RBI sets, without adding work for your team.


As of February 2026, Xflow holds final Payment Aggregator-Cross Border (PA-CB) authorisation from the RBI for both exports and imports, one of a small set of firms licensed for both. It is ISO 27001 and SOC 2 certified, works with Authorised Dealer Category-1 (AD-1) banks for foreign exchange and settlement, and issues an automatic eFIRA on every receipt.


The table below maps the main obligations a services or IT exporter carries when receiving inward remittance against how the platform absorbs each one.

RBI / FEMA requirementWhat it means for an exporterHow Xflow handles it
Route FX through regulated banksForeign exchange must move through AD-1 banks, not an informal channelFunds route through AD-1 banks (banking partner JP Morgan Chase) under Xflow's PA-CB authorisation
Proof of realisationYou need evidence that foreign currency was received and convertedAn eFIRA is auto-issued on every receipt; the FIRC route stays available
Correct purpose codeEach inflow must carry the RBI code for why the money arrivedThe purpose code tied to your business is captured and applied per payment
EDPMS / SOFTEX closureGoods and software exports must be squared off in RBI systemsXflow supplies the eFIRA and advice so realisation closes against your entry
KYC and AML screeningThe platform must verify businesses and screen transactionsOne-time Know Your Business (KYB) at onboarding; ongoing screening handled for you
Information securityCustomer and payment data must be protectedISO 27001 and SOC 2 certified controls
Regulatory reportingTransactions reported to the RBI and FIU-IndiaHandled by the platform under its PA-CB obligations

In plain terms: the money is ring-fenced while it moves, the regulator sees a compliant transaction, and you get the same certificates you file today.


Is your money safe with Xflow?

Fund safety comes down to where the money sits and who controls it. When an overseas client pays you, the funds land in a ring-fenced receiving account, a virtual account (vBAN) issued by the banking partner, JP Morgan Chase, purely to book the foreign exchange.


Xflow does not own that account, and funds can only move to the Indian bank account you registered during onboarding. The account does not hold your money as a deposit and does not earn interest. It is a routing account, not a wallet.


Two more layers back that up. The regulatory layer is the PA-CB authorisation, which means the RBI supervises how the platform handles customer funds and foreign exchange.


The security layer is backed by the fact that Xflow achieves SOC 2 and ISO compliance certification, the recognised standards for information security and controls. Together they answer the "is Xflow safe" question with structure rather than a slogan.


A fair follow-up is what happens to money in transit if the platform ever stopped operating. Because the receiving account is ring-fenced and funds are contractually limited to your registered Indian bank account, the money is not treated as the platform's own asset.


That separation is the reason the vBAN exists in the first place. It keeps your inflows attached to you, not to the platform's balance sheet, which is exactly the assurance an enterprise finance team looks for.


What a PA-CB is required to do

Understanding the licence helps explain why the platform behaves the way it does. A Payment Aggregator-Cross Border is an RBI-authorised entity, and the authorisation comes with obligations that protect the merchant.

  • Routing through regulated banks: a PA-CB must move foreign exchange through AD-1 banks and cannot run an unregulated FX channel of its own.
  • KYC and screening: it must verify the businesses it onboards and screen transactions, which is why onboarding asks for entity documents.
  • Documentation: it must support export and import documentation, so you receive realisation proof rather than chasing it.
  • Reporting: it reports to the RBI and to the Financial Intelligence Unit-India (FIU-India), which keeps your inflows on the right side of FEMA.


The framework also sets a per-transaction ceiling for goods or services under the cross-border aggregator route. Larger flows are handled through the appropriate banking channel, so it is worth confirming your ticket sizes at onboarding.


The wider payment compliance picture and the AML compliance rules set the context a PA-CB operates within.


What changes and what stays the same

The most common fear is that a new payment rail resets your compliance stack. It does not. Here is the split for a services exporter.

Your compliance workflowStatus on Xflow
FIRC / eFIRA as proof of realisationIssued automatically on each receipt
Purpose code on the inward remittanceCaptured and applied per payment
EDPMS entry for goods exportsUnchanged; realisation still closes the item
SOFTEX filing for software exportsUnchanged; you file as before
GST refund on zero-rated exportsUnchanged; the eFIRA supports the claim
Your CA's or auditor's view of recordsUnchanged; same documents, same format

The platform absorbs the RBI-facing mechanics. Your filings, your certificates and your accountant's process stay where they are. That is the point of framing compliance as relief rather than a fresh burden.


For teams that want the underlying rules, cross border tax compliance covers the tax angle in full.


The compliance artefacts you receive

Every receipt on Xflow produces the documents your downstream workflow needs. Knowing what lands where removes most of the anxiety.

  • eFIRA (electronic Foreign Inward Remittance Advice): issued automatically, this is the primary proof that foreign currency was received and converted. The detail is covered under eFIRA.
  • FIRC (Foreign Inward Remittance Certificate): the certificate exporters lean on for GST and realisation records, explained under FIRC.
  • Purpose code: the RBI code that classifies why the money arrived, so the credit clears cleanly. See the full RBI purpose code for inward remittance guide.
  • Payment advice: the transaction-level record your finance team reconciles against the invoice.


Because these are generated on every receipt, there is no manual certificate request and no waiting on a bank to email a document weeks later.


Where a payment arrives over Vostro rails, how FIRC works with Vostro payments is worth reading before your first receipt.


Compliance starts at onboarding

Compliance is not only about the payment. It starts when you open the account, and getting this stage right prevents queries later.


Onboarding is a short online KYB process. You share your entity type, choose a fee plan, and submit KYC documents, after which an operations review activates the account.


Getting the entity and business profile right at this stage matters, because it sets how each future receipt is classified and reported. A sole proprietor, an LLP and a private limited company are treated differently, so the profile should match your registration exactly.


Once activated, you can usually transact from the next business day. The purpose codes tied to your business are applied automatically to incoming payments, which is what removes the per-transaction back-and-forth later.


How a compliant inward payment works, step by step

For a services or IT exporter, a single receipt runs through a clear sequence.

  • Collection: your overseas client pays in their local currency into your Xflow receiving account. The account is ring-fenced and used only to book the foreign exchange.
  • Conversion and cross-border leg: the funds are converted at a live mid-market rate and routed to India through AD-1 bank rails under the PA-CB framework, not through an unregulated FX channel.
  • Settlement: the INR amount settles to your registered Indian bank account, typically on the next business day (T+1).
  • Documentation: the eFIRA and payment advice are generated automatically, with the correct purpose code attached.
  • Your filings: you close the SOFTEX filing for software exports or the EDPMS entry for goods, and use the eFIRA for the GST refund. This is where FIRC for GST refund closes the loop.

A worked example

A Pune IT services firm invoices a UK client 8,000 US dollars for a development retainer. At an illustrative mid-market rate of ₹95 to the dollar, the receipt is ₹7,60,000 before fees.


The client pays into the firm's receiving account. Xflow books the foreign exchange, routes it through the AD-1 bank, and settles INR to the firm's registered account the next business day.


Because Xflow converts at the live mid-market rate with no markup added, rather than a bank's own hidden rate, the exporter keeps more of the invoice value than on a typical SWIFT wire, though the exact gap varies by corridor and the sending bank's own spread.


An eFIRA is issued with purpose code P0802 for software services, which matches the firm's SOFTEX filing. The finance team uses the eFIRA for its GST refund claim.


There is no manual FIRC request and no separate reconciliation. The auditor sees the same document set as before, so the switch is invisible to the compliance process.


Compliance for goods versus services exporters

The workflow differs slightly by what you export, and picking the right track matters for how the item closes.

  • Services and software exporters: realisation is reported through SOFTEX, and the common purpose codes sit in the P08 and P10 series. This is the primary segment Xflow serves for inward payments.
  • Goods exporters: realisation closes against EDPMS, tied to the shipping bill, and codes sit in the P01 series.


If you are a freelancer below the GST threshold, the paperwork is lighter and the specifics are covered separately. Start with the segment that matches your registration, because the documents your bank expects follow from it. The FEMA framework sits underneath both tracks.


What about import payments?

Xflow's final PA-CB authorisation, as of February 2026, does cover imports as well as exports, so the licence itself extends to both directions.


Xflow's own product suite today, however, is inbound-focused: Receiving Accounts, Invoicing, FX AI Analyst, Stablecoin Payments and Xflow for Platforms. It is not built for sending money out of the country. The closest outward-adjacent offering is Global Payment Aggregators, a platform-collection API for foreign platforms collecting from Indian customers, not a self-serve way to pay overseas suppliers.


If your business both receives export income and pays foreign suppliers, the supplier payments currently need their own channel outside Xflow; only the export-side inward remittance runs through Xflow today.


Where to go deeper

This guide is the overview. For the long tail of specific questions on documents, timelines and edge cases, use the dedicated FAQs on Xflow compliance.


This is educational and not tax, legal or financial advice. For your specific filings, confirm the treatment with a chartered accountant or the official RBI and Income Tax guidance before you act.


The short version

Xflow is built so that switching your cross-border collections does not disturb your compliance stack. The money is ring-fenced and RBI-supervised while it moves, and the eFIRA and purpose code arrive automatically.


Your FIRC, EDPMS, SOFTEX and GST steps run exactly as they do now. The safety and the paperwork are handled, so your team can treat the switch as a cost and speed decision, not a compliance risk.

Receive cross-border payments with full compliance, end to end.


Frequently asked questions

Funds sit in a ring-fenced receiving account that Xflow does not own and can only move to your registered Indian bank account. Xflow holds final RBI PA-CB authorisation and is ISO 27001 and SOC 2 certified.

No. Xflow issues an automatic eFIRA on every receipt, which supports your GST refund and realisation records. Your filing process and the documents your CA reviews stay the same.

Your EDPMS and SOFTEX filings are unchanged. Xflow supplies the eFIRA, payment advice and correct purpose code so the realisation closes cleanly against your export entry.

The vBAN is a ring-fenced virtual account issued by the banking partner, JP Morgan Chase, to book the foreign exchange. It is not owned by you or Xflow, holds no deposit and earns no interest. Funds move only to your registered Indian account.

Yes. As of February 2026, Xflow holds final Payment Aggregator-Cross Border (PA-CB) authorisation for both exports and imports, and routes foreign exchange through AD-1 banks.

Related Posts