Xflow compliance refers to how Xflow, a Reserve Bank of India (RBI) authorised cross-border payments platform, handles the regulatory work of receiving foreign payments so that an Indian exporter does not have to. Because the platform holds final Payment Aggregator-Cross Border (PA-CB) authorisation and routes funds through regulated banks, your money stays ring-fenced while it moves, and your FIRC, EDPMS, SOFTEX and GST steps continue exactly as they do today.
The first question most finance teams ask before moving cross-border collections off a bank wire is not about price. It is about safety and paperwork: is the money protected while it moves, and will dropping SWIFT break the workflow the business has run for years? Those are the right questions. The honest answer is that nothing downstream has to change.
How Xflow handles compliance
Xflow is a regulated cross-border payments platform for Indian exporters. It is built so that receiving money from abroad stays inside the rules the RBI sets, without adding work for your team.
As of February 2026, Xflow holds final Payment Aggregator-Cross Border (PA-CB) authorisation from the RBI for both exports and imports, one of a small set of firms licensed for both. It is ISO 27001 and SOC 2 certified, works with Authorised Dealer Category-1 (AD-1) banks for foreign exchange and settlement, and issues an automatic eFIRA on every receipt.
The table below maps the main obligations a services or IT exporter carries when receiving inward remittance against how the platform absorbs each one.
| RBI / FEMA requirement | What it means for an exporter | How Xflow handles it |
|---|---|---|
| Route FX through regulated banks | Foreign exchange must move through AD-1 banks, not an informal channel | Funds route through AD-1 banks (banking partner JP Morgan Chase) under Xflow's PA-CB authorisation |
| Proof of realisation | You need evidence that foreign currency was received and converted | An eFIRA is auto-issued on every receipt; the FIRC route stays available |
| Correct purpose code | Each inflow must carry the RBI code for why the money arrived | The purpose code tied to your business is captured and applied per payment |
| EDPMS / SOFTEX closure | Goods and software exports must be squared off in RBI systems | Xflow supplies the eFIRA and advice so realisation closes against your entry |
| KYC and AML screening | The platform must verify businesses and screen transactions | One-time Know Your Business (KYB) at onboarding; ongoing screening handled for you |
| Information security | Customer and payment data must be protected | ISO 27001 and SOC 2 certified controls |
| Regulatory reporting | Transactions reported to the RBI and FIU-India | Handled by the platform under its PA-CB obligations |
In plain terms: the money is ring-fenced while it moves, the regulator sees a compliant transaction, and you get the same certificates you file today.
Is your money safe with Xflow?
Fund safety comes down to where the money sits and who controls it. When an overseas client pays you, the funds land in a ring-fenced receiving account, a virtual account (vBAN) issued by the banking partner, JP Morgan Chase, purely to book the foreign exchange.
Xflow does not own that account, and funds can only move to the Indian bank account you registered during onboarding. The account does not hold your money as a deposit and does not earn interest. It is a routing account, not a wallet.
Two more layers back that up. The regulatory layer is the PA-CB authorisation, which means the RBI supervises how the platform handles customer funds and foreign exchange.
The security layer is backed by the fact that Xflow achieves SOC 2 and ISO compliance certification, the recognised standards for information security and controls. Together they answer the "is Xflow safe" question with structure rather than a slogan.
A fair follow-up is what happens to money in transit if the platform ever stopped operating. Because the receiving account is ring-fenced and funds are contractually limited to your registered Indian bank account, the money is not treated as the platform's own asset.
That separation is the reason the vBAN exists in the first place. It keeps your inflows attached to you, not to the platform's balance sheet, which is exactly the assurance an enterprise finance team looks for.
What a PA-CB is required to do
Understanding the licence helps explain why the platform behaves the way it does. A Payment Aggregator-Cross Border is an RBI-authorised entity, and the authorisation comes with obligations that protect the merchant.
- Routing through regulated banks: a PA-CB must move foreign exchange through AD-1 banks and cannot run an unregulated FX channel of its own.
- KYC and screening: it must verify the businesses it onboards and screen transactions, which is why onboarding asks for entity documents.
- Documentation: it must support export and import documentation, so you receive realisation proof rather than chasing it.
- Reporting: it reports to the RBI and to the Financial Intelligence Unit-India (FIU-India), which keeps your inflows on the right side of FEMA.
The framework also sets a per-transaction ceiling for goods or services under the cross-border aggregator route. Larger flows are handled through the appropriate banking channel, so it is worth confirming your ticket sizes at onboarding.
The wider payment compliance picture and the AML compliance rules set the context a PA-CB operates within.
What changes and what stays the same
The most common fear is that a new payment rail resets your compliance stack. It does not. Here is the split for a services exporter.
| Your compliance workflow | Status on Xflow |
|---|---|
| FIRC / eFIRA as proof of realisation | Issued automatically on each receipt |
| Purpose code on the inward remittance | Captured and applied per payment |
| EDPMS entry for goods exports | Unchanged; realisation still closes the item |
| SOFTEX filing for software exports | Unchanged; you file as before |
| GST refund on zero-rated exports | Unchanged; the eFIRA supports the claim |
| Your CA's or auditor's view of records | Unchanged; same documents, same format |
The platform absorbs the RBI-facing mechanics. Your filings, your certificates and your accountant's process stay where they are. That is the point of framing compliance as relief rather than a fresh burden.
For teams that want the underlying rules, cross border tax compliance covers the tax angle in full.
The compliance artefacts you receive
Every receipt on Xflow produces the documents your downstream workflow needs. Knowing what lands where removes most of the anxiety.
- eFIRA (electronic Foreign Inward Remittance Advice): issued automatically, this is the primary proof that foreign currency was received and converted. The detail is covered under eFIRA.
- FIRC (Foreign Inward Remittance Certificate): the certificate exporters lean on for GST and realisation records, explained under FIRC.
- Purpose code: the RBI code that classifies why the money arrived, so the credit clears cleanly. See the full RBI purpose code for inward remittance guide.
- Payment advice: the transaction-level record your finance team reconciles against the invoice.
Because these are generated on every receipt, there is no manual certificate request and no waiting on a bank to email a document weeks later.
Where a payment arrives over Vostro rails, how FIRC works with Vostro payments is worth reading before your first receipt.
Compliance starts at onboarding
Compliance is not only about the payment. It starts when you open the account, and getting this stage right prevents queries later.
Onboarding is a short online KYB process. You share your entity type, choose a fee plan, and submit KYC documents, after which an operations review activates the account.
Getting the entity and business profile right at this stage matters, because it sets how each future receipt is classified and reported. A sole proprietor, an LLP and a private limited company are treated differently, so the profile should match your registration exactly.
Once activated, you can usually transact from the next business day. The purpose codes tied to your business are applied automatically to incoming payments, which is what removes the per-transaction back-and-forth later.
How a compliant inward payment works, step by step
For a services or IT exporter, a single receipt runs through a clear sequence.
- Collection: your overseas client pays in their local currency into your Xflow receiving account. The account is ring-fenced and used only to book the foreign exchange.
- Conversion and cross-border leg: the funds are converted at a live mid-market rate and routed to India through AD-1 bank rails under the PA-CB framework, not through an unregulated FX channel.
- Settlement: the INR amount settles to your registered Indian bank account, typically on the next business day (T+1).
- Documentation: the eFIRA and payment advice are generated automatically, with the correct purpose code attached.
- Your filings: you close the SOFTEX filing for software exports or the EDPMS entry for goods, and use the eFIRA for the GST refund. This is where FIRC for GST refund closes the loop.
A worked example
A Pune IT services firm invoices a UK client 8,000 US dollars for a development retainer. At an illustrative mid-market rate of ₹95 to the dollar, the receipt is ₹7,60,000 before fees.
The client pays into the firm's receiving account. Xflow books the foreign exchange, routes it through the AD-1 bank, and settles INR to the firm's registered account the next business day.
Because Xflow converts at the live mid-market rate with no markup added, rather than a bank's own hidden rate, the exporter keeps more of the invoice value than on a typical SWIFT wire, though the exact gap varies by corridor and the sending bank's own spread.
An eFIRA is issued with purpose code P0802 for software services, which matches the firm's SOFTEX filing. The finance team uses the eFIRA for its GST refund claim.
There is no manual FIRC request and no separate reconciliation. The auditor sees the same document set as before, so the switch is invisible to the compliance process.
Compliance for goods versus services exporters
The workflow differs slightly by what you export, and picking the right track matters for how the item closes.
- Services and software exporters: realisation is reported through SOFTEX, and the common purpose codes sit in the P08 and P10 series. This is the primary segment Xflow serves for inward payments.
- Goods exporters: realisation closes against EDPMS, tied to the shipping bill, and codes sit in the P01 series.
If you are a freelancer below the GST threshold, the paperwork is lighter and the specifics are covered separately. Start with the segment that matches your registration, because the documents your bank expects follow from it. The FEMA framework sits underneath both tracks.
What about import payments?
Xflow's final PA-CB authorisation, as of February 2026, does cover imports as well as exports, so the licence itself extends to both directions.
Xflow's own product suite today, however, is inbound-focused: Receiving Accounts, Invoicing, FX AI Analyst, Stablecoin Payments and Xflow for Platforms. It is not built for sending money out of the country. The closest outward-adjacent offering is Global Payment Aggregators, a platform-collection API for foreign platforms collecting from Indian customers, not a self-serve way to pay overseas suppliers.
If your business both receives export income and pays foreign suppliers, the supplier payments currently need their own channel outside Xflow; only the export-side inward remittance runs through Xflow today.
Where to go deeper
This guide is the overview. For the long tail of specific questions on documents, timelines and edge cases, use the dedicated FAQs on Xflow compliance.
This is educational and not tax, legal or financial advice. For your specific filings, confirm the treatment with a chartered accountant or the official RBI and Income Tax guidance before you act.
The short version
Xflow is built so that switching your cross-border collections does not disturb your compliance stack. The money is ring-fenced and RBI-supervised while it moves, and the eFIRA and purpose code arrive automatically.
Your FIRC, EDPMS, SOFTEX and GST steps run exactly as they do now. The safety and the paperwork are handled, so your team can treat the switch as a cost and speed decision, not a compliance risk.
Receive cross-border payments with full compliance, end to end.
Frequently asked questions
Funds sit in a ring-fenced receiving account that Xflow does not own and can only move to your registered Indian bank account. Xflow holds final RBI PA-CB authorisation and is ISO 27001 and SOC 2 certified.
No. Xflow issues an automatic eFIRA on every receipt, which supports your GST refund and realisation records. Your filing process and the documents your CA reviews stay the same.
Your EDPMS and SOFTEX filings are unchanged. Xflow supplies the eFIRA, payment advice and correct purpose code so the realisation closes cleanly against your export entry.
The vBAN is a ring-fenced virtual account issued by the banking partner, JP Morgan Chase, to book the foreign exchange. It is not owned by you or Xflow, holds no deposit and earns no interest. Funds move only to your registered Indian account.
Yes. As of February 2026, Xflow holds final Payment Aggregator-Cross Border (PA-CB) authorisation for both exports and imports, and routes foreign exchange through AD-1 banks.
