| Authored by R & D Law Chambers LLP | Practice led by Ravish Bhatt. Dual-qualified lawyer (India and England & Wales) | Bar Council of Gujarat, Enrolment G/504/2008 | SRA (non-practising) Registration No. 492 477 | ADIT, Chartered Institute of Taxation, LondonPublished: 6 August 2026 | Last reviewed: 6 August 2026 | Estimated reading time: 11 minutes |
| This article states the position under the IFSCA FinTech Sandbox Framework, 2026 (circular dated 16 March 2026), the IFSCA (TechFin and Ancillary Services) Regulations, 2025, and the Income-tax Act, 2025 as amended by the Finance Act, 2026. References to the tax holiday are to section 147 of the Income-tax Act, 2025 (formerly section 80LA of the Income-tax Act, 1961, repealed with effect from 1 April 2026). |
| Short answer. A FinTech business cannot operate commercially in GIFT IFSC on a sandbox authorisation. The FinTech Sandbox Framework, 2026 grants a Limited Use Authorisation for testing only, capped at twelve months and extendable by six. Commercial operation requires separate authorisation under the sectoral regime the activity actually falls into, or a certificate of registration under the TechFin and Ancillary Services Regulations, 2025. Sandbox entry and market entry are two different gates. |
Index of Topics
- The single mistake that derails FinTech entry into GIFT IFSC
- What changed on 16 March 2026, and why it matters
- Which regime governs your activity: FinTech, TechFin or a regulated financial service
- The four sandbox routes under the 2026 Framework
- How the sandbox application actually works
- Obligations during the testing stage
- Building the exit: what happens when the Limited Use Authorisation ends
- Tax and the operating environment
- Frequently asked questions
- How R & D Law Chambers works on these matters
1. The Single Mistake That Derails FinTech Entry Into GIFT IFSC
| Short answer. Treating the regulatory sandbox as the licence. It is not. It is a time-limited testing permission with an expiry date, and every relaxation granted with it falls away when it ends. Businesses that plan only for the sandbox reach the end of their testing window with no authorisation to trade. |
GIFT IFSC is marketed to founders on the strength of its sandbox. The pitch is accurate as far as it goes: a unified regulator, a defined testing route, relaxations from requirements that would otherwise apply, and a jurisdiction actively courting financial technology. What the pitch omits is the structure underneath.
Under the IFSCA FinTech Sandbox Framework, 2026, an applicant admitted to the Regulatory Sandbox receives a Limited Use Authorisation and becomes a FinTech Sandbox Entity. That authorisation permits testing, within a defined perimeter, on a limited customer base, for a limited period. It is not a licence to carry on business. When the testing stage concludes, the authorisation and the relaxations granted under it come to an end.
The question that decides whether a GIFT IFSC entry succeeds is therefore not how to get into the sandbox. It is what the business will hold on the day the sandbox authorisation expires. That question has to be answered before the application is filed, because the answer determines the corporate structure, the capital, the substance and the timeline.
2. What Changed on 16 March 2026, and Why It Matters
| Short answer. The IFSCA FinTech Sandbox Framework, 2026 superseded both the FinTech Entity Framework of 2022 and the Regulatory Sandbox framework of 2020. The 2022 Framework had contained a direct-entry route to full authorisation as a FinTech Entity. That route is no longer part of the sandbox framework, and its TechFin limb has migrated to a separate set of regulations. |
The 2022 Framework did two jobs at once. It provided a sandbox for entities wanting to test, and it provided a direct authorisation route for entities ready to operate. Advisers and applicants grew used to treating FinTech authorisation in the IFSC as a single subject with a single application.
That is no longer the position. The 2022 Framework has been taken apart and its two limbs sent in different directions. The TechFin limb now sits under the IFSCA (TechFin and Ancillary Services) Regulations, 2025, which came into force on 8 July 2025 and require a certificate of registration. The sandbox limb sits under the 2026 Framework. A business that arrives with a mental model formed before March 2026, or with advice drafted against the 2022 Framework, is planning against a structure that no longer exists.
The practical consequence is a sequencing problem. Under the old model it was possible to think of the sandbox and the licence as two doors into the same room. Under the new model they are two rooms, and the passage between them has to be built deliberately.
3. Which Regime Governs Your Activity: FinTech, TechFin or a Regulated Financial Service
| Short answer. Three different regimes may apply, and the distinction turns on what the business actually does. If it carries on a regulated financial service, it needs authorisation under that sectoral regime. If it supplies technology to regulated financial institutions without itself carrying on a financial service, it falls under the TechFin and Ancillary Services Regulations, 2025. If it wants to test before committing to either, it applies to the sandbox. |
This classification is the first piece of work on any GIFT IFSC FinTech mandate, and it is frequently done wrong because the commercial description of a business rarely matches its regulatory description. A payments product, a lending platform, a trading interface and an insurance distribution tool are all called FinTech in the market. In regulatory terms they sit in different places and attract different requirements.
| If the business… | Then the governing regime is… |
|---|---|
| Carries on banking, insurance, capital market intermediation, fund management or lending as principal | The relevant IFSCA sectoral regime for that activity. There is no standalone FinTech licence that substitutes for it. |
| Supplies technology or ancillary services to financial institutions without itself carrying on a financial service | The IFSCA (TechFin and Ancillary Services) Regulations, 2025, requiring a certificate of registration. |
| Wants to test an innovative product or solution before commercial launch | The IFSCA FinTech Sandbox Framework, 2026, giving a Limited Use Authorisation as a FinTech Sandbox Entity. |
The error we see most often is a business assuming that because its product is innovative, it belongs in the FinTech category and outside the sectoral regimes. Innovation is not a regulatory classification. If the activity is a regulated financial service, it is regulated as one, however it is delivered.
Entities already holding authorisations under the superseded framework should note that the TechFin and Ancillary Services Regulations, 2025 contain transitional requirements, including a window within which existing participants must obtain registration. Those timelines are activity-specific and should be checked against the entity’s own authorisation rather than assumed.
4. The Four Sandbox Routes Under the 2026 Framework
| Short answer. The 2026 Framework provides four distinct routes: the Regulatory Sandbox for live testing with real customers, the Innovation Sandbox for testing in an isolated environment without real customers, the Inter-Operable Regulatory Sandbox for products spanning more than one Indian financial regulator, and an overseas referral mechanism operating through IFSCA’s FinTech Bridge arrangements. |
Regulatory Sandbox
Live testing with a defined and limited set of real customers, under relaxations granted by IFSCA for the testing period. This is the route most applicants have in mind when they refer to the sandbox. Because real customers and, in some configurations, customer funds are involved, this route carries the heaviest conditions.
Innovation Sandbox
Testing in an isolated environment without live customers. Useful where a product needs validation against data and infrastructure rather than market response, and where the applicant is not ready to expose customers to an untested solution.
Inter-Operable Regulatory Sandbox
For products whose regulatory perimeter crosses more than one Indian financial sector regulator. The mechanism exists because a single product can engage banking, securities and insurance regulation simultaneously, and testing it under one regulator alone would leave the other exposures unresolved.
Overseas referral and the FinTech Bridge
A referral mechanism operating through IFSCA’s cooperation arrangements with overseas regulators, allowing entities to be referred between jurisdictions. For a foreign FinTech, this is the route that connects a home-jurisdiction regulatory relationship to an Indian testing environment, and for an Indian FinTech it works in the opposite direction.
5. How the Sandbox Application Actually Works
| Short answer. Two stages. An application is filed through the Single Window IT System, with a preliminary review at the first stage and in-principle approval at the second. The Framework sets out indicative timelines of thirty days for preliminary review and sixty days for in-principle approval, running from a complete application. |
The timelines are stated from a complete application, and that qualification does most of the work in practice. Applications are delayed far more often by incomplete submissions and by mismatch between the described activity and the route applied for than by regulatory processing. The preparatory work, classifying the activity, defining the testing perimeter, identifying the relaxations sought and justifying them, determines the timeline more than the filing does.
Eligibility extends to Indian and foreign applicants, and to entities that are not themselves financial institutions. Foreign applicants should note the jurisdictional screening built into the Framework, which excludes applicants connected with jurisdictions subject to a call for action under the Financial Action Task Force listings. Fees are those prescribed under IFSCA’s fee circular applicable to sandbox applicants.
On physical presence, the position is more accommodating than many applicants expect. The Framework does not impose a general physical presence requirement for entities operating under the Innovation Sandbox, and treats presence requirements under the Regulatory Sandbox by reference to the nature of the testing, with the handling of customer funds being the factor that changes the analysis. This should be confirmed against the applicant’s own configuration rather than assumed, because it is one of the areas where the answer is activity-dependent.
6. Obligations During the Testing Stage
| Short answer. Testing runs for up to twelve months, extendable by a further six. Reporting is monthly, due before the tenth of the following month, with a final report within thirty days of the end of testing. Records must be retained for seven years. IFSCA may revoke a Limited Use Authorisation, including for breach of the conditions on which it was granted. |
The reporting cadence is worth planning for at the outset. Monthly reporting through an eighteen-month maximum testing period is a sustained compliance obligation, not an administrative afterthought, and it runs alongside the product development the sandbox exists to permit. Founders consistently underestimate it.
The revocation power matters for a different reason. A Limited Use Authorisation is granted on stated conditions and within a defined perimeter. Testing that drifts outside that perimeter, whether by expanding the customer base, altering the product or extending into activities not covered by the authorisation, puts the authorisation at risk. The perimeter should be drawn at the application stage with the intended development path in mind, because amending it later is harder than defining it correctly at the start.
7. Building the Exit: What Happens When the Limited Use Authorisation Ends
| Short answer. Nothing automatic. The Limited Use Authorisation ends and the relaxations end with it. Continuing to serve customers after that point requires authorisation under the applicable sectoral regime, or registration under the TechFin and Ancillary Services Regulations, 2025. That application should be in preparation well before the testing period closes. |
This is the point at which the analysis in section 3 becomes operational. A business that has classified its activity correctly at the outset knows which authorisation it will need, what capital and substance that authorisation requires, and how long the application takes. It can run the authorisation process in parallel with the back end of its testing period and move from testing to commercial operation without a gap.
A business that has not done that work faces a harder position. Its testing period expires, its authorisation lapses, its customers must be told that the service is suspended, and it begins an authorisation process from a standing start with no revenue and a product it can no longer offer. The commercial damage is not regulatory in origin. It is a planning failure.
The practical discipline is to treat the sandbox application and the eventual authorisation application as one project with two filings, rather than as two separate exercises separated by a year. The corporate structure, the capital plan, the key personnel and the substance in the IFSC should all be designed against the authorisation the business will ultimately need, not against the lighter requirements of the testing stage.
8. Tax and the Operating Environment
| Short answer. An IFSC unit may claim a full deduction of eligible business income for twenty consecutive years out of twenty-five under section 147 of the Income-tax Act, 2025, following the Finance Act, 2026 amendment. Business income after the deduction period is taxed at fifteen per cent. The deduction attaches to the unit, and does not depend on the sandbox. |
Two points of precision matter here. First, the provision is section 147 of the Income-tax Act, 2025. The Income-tax Act, 1961 was repealed with effect from 1 April 2026, and section 80LA, under which this incentive was historically claimed, ceased to be operative law on that date. Material still citing section 80LA as the current provision has not been updated.
Second, the Finance Act, 2026 extended the deduction from ten consecutive years out of fifteen to twenty consecutive years out of twenty-five, and fixed the post-deduction rate at fifteen per cent. For a business with a long build cycle, which describes most FinTech, that extension materially changes the economics of locating in the IFSC. It also introduced a condition for units commencing operations on or after 1 April 2026, that the unit must not be formed by splitting up, reconstruction, reorganisation or transfer of a business already existing in India. Groups restructuring an existing Indian operation into an IFSC unit should take that condition seriously at the design stage.
On the wider environment, an IFSC unit carrying on permitted financial services is treated as a person resident outside India for exchange control purposes, which is what allows foreign currency operation and unrestricted cross-border transactions. That treatment is a regulatory and operational advantage. It does not convert the unit into a non-resident for income tax purposes, and it does not create treaty access. The IFSC is an operating platform, not a treaty jurisdiction.
9. Frequently Asked Questions
Do I need a licence to operate a FinTech business in GIFT City?
Yes, if the activity is a regulated financial service. There is no single standalone FinTech licence. The authorisation required depends on the activity: banking, insurance, capital market intermediation, fund management and lending each have their own regime. Technology and ancillary service providers to financial institutions require a certificate of registration under the IFSCA (TechFin and Ancillary Services) Regulations, 2025.
Is the regulatory sandbox a licence?
No. Admission to the sandbox produces a Limited Use Authorisation as a FinTech Sandbox Entity, permitting testing within a defined perimeter for a limited period. It is not authorisation to carry on business commercially, and it expires at the end of the testing stage together with the relaxations granted under it.
How long can a FinTech test in the GIFT IFSC sandbox?
The testing stage runs for up to twelve months, extendable by a further six months, giving a maximum of eighteen months. Monthly reports are due before the tenth of the following month, and a final report within thirty days of the end of testing.
Can a foreign FinTech company apply?
Yes. The 2026 Framework is open to foreign applicants, and to applicants that are not themselves financial institutions. Applicants connected with jurisdictions subject to a Financial Action Task Force call for action are excluded. An overseas referral mechanism operates through IFSCA’s FinTech Bridge arrangements with foreign regulators.
Do I need a physical office in GIFT City to enter the sandbox?
Not in every case. The Framework does not impose a general physical presence requirement for the Innovation Sandbox, and treats presence under the Regulatory Sandbox by reference to the nature of the testing, with the handling of customer funds being the decisive factor. The answer is activity-specific and should be confirmed against the particular configuration before an application is filed.
What tax benefit applies to an IFSC FinTech unit?
A full deduction of eligible business income for twenty consecutive years out of twenty-five, under section 147 of the Income-tax Act, 2025, as amended by the Finance Act, 2026, with business income thereafter taxed at fifteen per cent. This was formerly section 80LA of the Income-tax Act, 1961, which was repealed with effect from 1 April 2026.
10. How R & D Law Chambers Works on These Matters
We advise on Indian law for businesses in India and internationally, wherever a matter has an India connection. On GIFT IFSC FinTech mandates the work begins with regulatory classification, because that determines everything downstream: which authorisation the business will ultimately hold, what the sandbox application should say, and how the corporate and capital structure should be built.
Our GIFT IFSC practice covers entity establishment and IFSCA authorisation, regulatory and compliance design, fund structuring and documentation, and the transactional and contractual layer. Where a dispute arises, we act on it, which informs how we draft in the first place.
Related services
- Regulatory & Compliance Advisory in GIFT IFSC: structural compliance design, IFSCA authorisation and governance architecture.
- Fund Structuring in GIFT IFSC: legal, tax and regulatory design for funds and managers.
- Transaction & Contractual Advisory: cross-border commercial documentation for IFSC entities.
- Fund Documentation & Legal Structuring for FMEs: placement memoranda, constitutional documents and investor agreements.
| This article is for informational purposes only and does not constitute legal or tax advice. The views expressed are those of the author. Specific legal or tax matters should be referred to qualified advisers. Practice led by Ravish Bhatt, dual-qualified lawyer (India and England & Wales), Bar Council of Gujarat (Enrolment G/504/2008), SRA (non-practising) Registration No. 492 477, ADIT (CIOT, London). |