Is Digital Gold Regulated? What Your Compliance Team Will Ask
No. SEBI’s own words are that digital gold products “operate entirely outside the purview of SEBI”, and that none of the investor protection mechanisms available in securities markets apply to them. If you are adding metals to a product, that sentence is going to appear in your risk assessment, and it is better to write it yourself than to have your compliance team find it.
This is written for the person doing that assessment, not for a worried consumer. If you own some digital gold and read a headline, we wrote that one separately.
| Where does it sit with SEBI? | Entirely outside SEBI’s purview |
| Is it banned? | No. The release is a caution, and does not allege fraud |
| What SEBI names as regulated | Commodity derivatives, Gold ETFs, EGRs |
| Investor protection mechanisms | Do not apply |
| Named risks | Counterparty and operational |
| Industry self-regulation | IBJA’s SRD. Self-regulatory, not statutory |
| The real blocker on an integration | This review, not the API |
What the release actually says
On 8 November 2025 SEBI issued PR No. 70/2025, “Caution to public regarding dealing in ‘Digital Gold'”. It is one page. Because it is short, there is no excuse for working from someone’s summary of it, and a good deal of the coverage does exactly that.

The release opens by naming what SEBI does regulate:
These are exchange traded commodity derivative contracts, Gold Exchange Traded Funds (ETFs) offered by Mutual Funds and Electronic Gold Receipts (EGRs) tradeable on stock exchanges.
Then the operative paragraph:
such digital gold products are different from SEBI regulated gold products as they are neither notified as securities nor regulated as commodity derivatives. They operate entirely outside the purview of SEBI. Such digital gold products may entail significant risks for investors and may expose investors to counterparty and operational risks.
And the sentence your risk register needs:
Investors / participants are made aware that none of the investor protection mechanisms under securities market purview shall be available for investments in such Digital Gold/ E-Gold products.
Three things follow from reading it rather than a summary of it.
It is a caution, not a prohibition. SEBI did not ban digital gold, restrict who may offer it, or allege wrongdoing. Coverage that implies otherwise is overstating it.
It names the alternatives. SEBI points readers at commodity derivatives, Gold ETFs and EGRs. Those compete with every digital gold provider, including us, and a provider unwilling to tell you they exist is telling you something.
The named risks are counterparty and operational. Not fraud, not purity. That is a useful steer, because it says exactly where diligence should go: at the balance sheet holding the metal and the process around it.
Why this lands on your desk and not ours
Adding metals to an existing app is a modest engineering job. The integration is a couple of endpoints, and if you have a hosted flow it is less than that.
The part that takes the time is this review. A compliance function looking at an unregulated instrument inside a regulated or quasi-regulated product will ask where it sits, who holds the asset, and what happens when something breaks. Those questions are correct and they do not have API answers.
The mistake we see is teams treating this as a procurement formality and discovering three weeks in that nobody can answer question three. Front-load it.
The seven questions

These are provider-agnostic, and they should be put to everyone you evaluate including us. A checklist that only made one vendor look good would not be worth printing.
Who holds the metal, and under what title? “Fully backed” is not an answer. Backed by whom, held in whose name, and is the customer’s claim a property interest or an unsecured contractual one?
Is there an independent vault audit, and how often? “Audited” is not an answer either. By whom, to what standard, at what frequency, and is the result published or available on request?
What happens to holdings if the platform fails? This is the one that most often has no good answer anywhere in the category, and it is the direct consequence of the SEBI sentence above. If investor protection mechanisms do not apply, then insolvency treatment is governed by contract and general law rather than by a securities regime.
Is there insurance, and may we see the policy? An absolute insurance claim should make you ask more questions, not fewer. Against what perils, to what limit, and who is the named insured.
Who is the KYC obligor? A provider handling KYC operationally is not the same as a provider carrying the obligation. Establish which of you is answerable.
How is GST handled, and to whom is the invoice raised? 3% applies on precious metals in India. The question is who the taxable supply is between, and whether an invoice is issued at all.
What is the redemption and exit path? “Sell anytime” needs a spread, a settlement time, and a physical delivery route with its own charges.
Our own answers, including the awkward one
It would be inconsistent to publish that list and duck it.
Regulatory status. We are not SEBI regulated, not SEBI registered, and not supervised. The caution above applies to us as it does to the category. We do not claim otherwise anywhere, and if you find a page of ours that implies it, that page is wrong and we want to know.
Custody. Metal sits with our custody partners, and Augmont is the supplier across our live integrations.
Insurance. We say holdings are held in insured vaults. We do not publish a policy document, and we deliberately avoid absolute insurance language, because we have not put a policy in front of you. Ask us for it, and ask everyone else too.
Purity and GST. 24K for gold, 999 for silver, and 3% GST applies on purchase as it does across digital gold in India.
On the partner API specifically, invoicing exists: a buy generates an invoice showing GST split CGST and SGST, and a sell generates a settlement advice, both retrievable through the API.
That is a mixed answer rather than a clean one. A clean answer in this category would be a warning sign.
On IBJA’s self-regulatory division
You will encounter this in vendor decks, so it is worth being precise.
IBJA announced a Self-Regulatory Division for digital gold on 2 December 2025, with a framework and compliance date reported as 31 March 2026, covering minimum purity, insurance, full physical backing, independent quarterly vault audits, and disclosure and grievance systems.
Read that as what it is. It is self-regulation, not statute. It binds only entities that choose to register with it, and its enforcement is against its own members. An industry body is better than nothing and it is not a regulator.
Specifically: SRD membership does not fill the gap SEBI described, and does not restore investor protection mechanisms. If a provider presents it as though it does, that is the answer to your question about how carefully they read things.
What to write in the assessment
The defensible position, in our view, is not that the risk is absent. It is that the risk is named, understood, and proportionate to the role the product plays.
Digital gold is an unregulated instrument. It carries counterparty and operational risk, by SEBI’s own description. It is a reasonable component of a savings or rewards feature, and it is not a substitute for a regulated investment product for a user who needs one. If your product implies otherwise in its copy, that is a bigger problem than the integration.
If you want the regulated route instead, SEBI named it, and there is no shame in taking it.
Then the easy part
Once the assessment is done, the build genuinely is small. The sandbox is stateful and access is immediate, so your engineers can have the whole flow working, including the failure paths, while the review is still in progress. Nothing about that requires a commercial conversation first.
Run them in parallel. The review is the long pole.
The short version
Digital gold is not regulated by SEBI, and SEBI has said so in a one-page release worth reading in full. That is a fact to document, not a fact to argue with.
Ask every provider the seven questions. Be suspicious of clean answers, particularly on insurance and insolvency. And treat an industry self-regulatory body as what it says it is, rather than as the regulator it is not.
Run the review and the build in parallel
Sandbox access is immediate and needs no commercial conversation, so your engineers can have the whole flow working while compliance is still reading. The review is the long pole, not the integration.
Put this into practice on OroPocket
Buy 24K digital gold from ₹1. Earn Bitcoin cashback on every purchase.
GET THE APP
Join the Conversation
Be the first to share your thoughts.