RBI KYC Master Directions 2025: What Every Fintech and NBFC Needs to Know About Video KYC and CKYC

India’s KYC framework combines several regulatory and institutional requirements, including the Prevention of Money Laundering Act, RBI’s KYC Master Directions, UIDAI’s Aadhaar authentication guidelines, and the CKYC Registry operated by CERSAI. For any regulated entity bank, NBFC, payment aggregator, or licensed fintech navigating this architecture correctly determines both compliance standing and onboarding performance. The RBI’s KYC Master Directions have been amended multiple times since their original 2016 notification, with significant updates in 2023 and 2025 addressing Video KYC (V-CIP), digital onboarding, and CKYC obligations. This guide deconstructs what the Directions actually require, where organisations commonly fail, and how the CKYC system changes the verification workflow.

What the RBI KYC Master Directions Actually Cover

The RBI KYC Master Directions (updated through 2025) govern how Regulated Entities (REs), a category that includes commercial banks, cooperative banks, NBFCs, payment system providers, and account aggregators, must identify and verify their customers. The Directions cover four core areas: Customer Due Diligence (CDD), record-keeping, reporting obligations, and cross-border correspondent banking.

What the Directions do not cover: they do not prescribe specific technology vendors or API providers. They specify the required outcomes, verification standards, acceptable documents, and data fields while leaving implementation choices to the RE. This is important context for product teams building onboarding flows: compliance is about meeting defined verification standards, not about using any particular method.

The Directions apply at the point of account opening, at trigger events during the relationship (such as a transaction that breaches a risk threshold), and at periodic re-KYC intervals defined by the customer’s risk classification. A one-time onboarding check is not sufficient; the Directions require ongoing due diligence.

Customer Due Diligence: The Four-Level Risk Framework

The RBI’s CDD framework operates on risk-based principles aligned with FATF recommendations. Customers are classified into three risk categories: low, medium, and high, with Simplified Due Diligence (SDD) available for a specific subset of low-risk accounts (such as Basic Savings Bank Deposit Accounts with defined transaction limits), and Enhanced Due Diligence (EDD) mandated for high-risk categories.

High-risk designations apply automatically to Politically Exposed Persons (PEPs), their close associates, customers from jurisdictions on the FATF grey or blacklists, non-resident customers, and legal entities with complex or opaque ownership structures. For these customers, EDD requires not just identity verification but also source of funds verification, beneficial ownership identification (particularly for entities where ultimate ownership chains are long), and more frequent periodic review.

For product teams, the implication is architectural: the onboarding system must not just collect KYC data but also apply a risk score and route customers into the appropriate CDD tier. A single onboarding flow that treats all customers identically does not satisfy the RBI’s risk-based approach requirement.

Video KYC (V-CIP): RBI Guidelines and Technical Requirements

What V-CIP Allows and Requires

The RBI introduced Video-based Customer Identification Process (V-CIP) as a face-to-face equivalent for digital onboarding. Under V-CIP, a trained official of the RE conducts a live, audio-visual interaction with the customer, captures their Aadhaar or PAN details, geolocates the session, and records the interaction for audit purposes.

The 2025 guidelines reinforced several technical requirements. The video interaction must be live; pre-recorded responses are not permitted, and the system must include liveness detection to prevent replay attacks. Deepfake resistance has been explicitly flagged as a requirement, meaning passive or active liveness checks must be capable of detecting AI-generated synthetic faces. The interaction must be geolocated to confirm the customer is within India (for resident customers). The recording must be stored for at least five years.

Who Can Conduct V-CIP and Who Cannot

V-CIP must be conducted by the RE’s own officials. Although an LSP or Digital Lending App (DLA) can assist with KYC data collection, the RE must retain responsibility for the V-CIP interaction and the final identity verification decision. This creates an important operational boundary: technology vendors can provide the platform and biometric verification tools, but a trained RE official must be present in or monitoring the interaction.

NBFCs and smaller fintechs that rely entirely on LSPs for onboarding need to review their V-CIP workflow against this requirement. The RBI has issued guidance that the RE cannot entirely outsource the verification decision, even when the technology is provided by a third party.

What is CKYC? How the Central KYC Registry Works

CERSAI maintains CKYC (Central KYC), a centralised repository of KYC records, under a mandate from the Ministry of Finance. When a customer completes KYC with one Regulated Entity, their record is uploaded to the CKYC Registry and assigned a 14-digit KYC Identification Number (KIN).

When the same customer approaches a second RE, the second entity can retrieve the existing CKYC record using the customer’s PAN or Aadhaar, eliminating the need for the customer to submit documents again, provided the record is current and the risk classification is appropriate. This is the CKYC system’s primary value: reducing redundant verification for customers and reducing document handling costs for REs.

However, CKYC records have a shelf life tied to periodic re-KYC requirements. Compliance teams must refresh records that exceed 8 years for low-risk customers, 2 years for medium-risk customers, or 1 year for high-risk customers. REs cannot simply rely on a CKYC record without checking its age and validity against the applicable re-KYC schedule.

For fintechs building onboarding flows, CKYC integration via the CKYC search API allows the system to query for an existing record before initiating a full KYC collection. This reduces friction for returning customers and accelerates onboarding without compromising compliance.

Aadhaar-Based eKYC: Scope and Limitations

Aadhaar-based eKYC allows an RE to retrieve a customer’s demographic data (name, date of birth, address, photograph) from the UIDAI database using an OTP or biometric authentication. This is the fastest KYC pathway available in India; it can complete identity verification in seconds with a very high accuracy rate.

However, Aadhaar eKYC is not universally available. Only entities with a valid Aadhaar User Agency (AUA) or KYC User Agency (KUA) licence from UIDAI can access the authentication API directly. Many fintechs and NBFCs access this capability through licensed intermediaries. The DPDP Act 2023 and DPDP Rules 2025 have added consent and data governance obligations on top of UIDAI’s existing rules. Aadhaar data retrieved through eKYC
must only serve the purpose specified in the consent, and businesses must not retain it beyond the retention period permitted under the UIDAI framework and DPDP Rules.

For high-risk customers, Aadhaar eKYC alone is not sufficient; EDD requires additional verification steps beyond what Aadhaar provides. For BNPL and digital lending, where PAN is mandatory for all loans, PAN verification must accompany any Aadhaar-based flow.

Common Compliance Failures and How to Avoid Them

The most frequent KYC compliance failures identified in RBI inspections and enforcement actions cluster around four areas.

First, incomplete periodic re-KYC: REs often complete onboarding KYC correctly but fail to implement systematic re-KYC triggers for medium- and high-risk customers within the required intervals.

Second, beneficial ownership gaps: For corporate accounts, the Directions require identification of beneficial owners—individuals holding more than 10 per cent of shares or voting rights. However, REs often rely on superficial checks or self-declarations without independent verification against MCA21 or company registry data.

Third, incomplete PEP screening: Compliance teams must check PEP status during onboarding and re-screen customers whenever the relevant lists are updated. However, many systems screen customers only once and fail to re-screen them when lists change.

Fourth, inadequate documentation of enhanced due diligence: Compliance teams must document EDD procedures in the customer file. This documentation should include the additional steps they take and the rationale for the assigned risk rating.

Digital Lending and the KYC Stack: What Lenders Must Get Right

The RBI’s Digital Lending Guidelines, updated through 2024, have tightened the KYC requirements that apply specifically in the digital lending context, overlaying the general KYC Master Directions with additional obligations around borrower identification, data handling, and LSP oversight.

For digital lenders and their LSP partners, three requirements deserve particular operational attention.
First, the verification standard: the Guidelines require regulated entities to conduct identity verification according to the KYC Master Directions, using Aadhaar-based eKYC, Video KYC (V-CIP), or equivalent OVD-based verification. A lender that relies on an LSP-conducted KYC but does not have a process for ensuring that the LSP’s verification meets this standard faces compliance exposure, because the regulatory liability remains with the RE, not the LSP.

Second, the data minimisation requirement: the Guidelines require regulated entities to collect only the minimum data necessary for credit assessment. Therefore, businesses that request access to a borrower’s contacts, call logs, or location history beyond what they genuinely need for credit assessment violate both the Digital Lending Guidelines and the DPDP Act.

Third, the cooling-off period and loan contract: the Digital Lending Guidelines require that borrowers receive a Key Fact Statement (KFS) before accepting a loan, with a cooling-off period during which they can withdraw without penalty. The KYC verification event and the KFS delivery are sequential; a lender cannot proceed to disbursement without completing both.

Key Takeaways

  • The RBI KYC Master Directions apply throughout the customer lifecycle, not just at onboarding, requiring periodic re-KYC at intervals tied to risk classification.
  • V-CIP (Video KYC) now explicitly requires deepfake-resistant liveness detection; the 2025 guidelines treat this as a baseline requirement, not an optional enhancement.
  • CKYC integration lets REs retrieve existing KYC records using a 14-digit KIN, reducing friction for repeat customers. However, REs must verify these records against re-KYC schedules to ensure they remain valid.
  • Aadhaar eKYC provides fast, accurate verification, but businesses must obtain AUA/KUA licensing and add further checks for high-risk customers.
  • The most common compliance failures are in periodic re-KYC, beneficial ownership verification, and PEP re-screening, not in initial onboarding.

Frequently Asked Questions

What role does device intelligence play in fraud prevention?

Device intelligence identifies devices linked to multiple identities, applications, or suspicious activity. When combined with identity and behavioural signals, it helps businesses detect coordinated fraud and repeat attempts more effectively.

How can businesses detect synthetic identity fraud during onboarding?

Businesses can detect synthetic identity fraud by cross-checking PAN, Aadhaar, phone numbers, device history, address data, and application patterns. Combining these signals helps identify inconsistencies before account activation.

What are the RBI KYC Master Directions?

The RBI KYC Master Directions are a comprehensive regulatory framework that governs how Regulated Entities (banks, NBFCs, payment aggregators, and others) must verify customer identity, conduct due diligence, maintain records, and monitor accounts. First issued in 2016 and updated multiple times since, they align with FATF recommendations and apply throughout the customer relationship — not just at account opening.

What is CKYC and is it mandatory?

CERSAI maintains CKYC (Central KYC) as a centralised repository of KYC records. When an RE completes a customer’s KYC, it uploads the record and assigns a KIN. Subsequent REs can retrieve this record rather than re-collecting documents. CKYC submission is mandatory for Regulated Entities. However, REs must validate the age and status of a retrieved record before relying on it.

What is Video KYC and how does it work under RBI rules?

Video KYC (V-CIP) is an RBI-approved method of completing identity verification through a live audio-visual interaction between the customer and an official of the Regulated Entity. The system must include liveness detection, geolocation confirmation, PAN or Aadhaar verification, and recording storage for at least five years. The 2025 guidelines added explicit deepfake-resistance requirements.

Conclusion


The RBI KYC Master Directions require financial institutions to treat KYC as an ongoing compliance process, not a one-time onboarding checklist. They establish a continuous obligation to know who your customers are, to verify that knowledge periodically, and to escalate scrutiny when risk indicators appear. For NBFCs and fintechs operating under digital lending guidelines, the intersection of KYC requirements, DPDP Act data governance obligations, and PMLA reporting duties creates a compliance architecture that demands systematic, technology-supported implementation. The organisations that will avoid regulatory action are those that build re-KYC, beneficial ownership verification, and PEP screening into their operational workflows as automated, ongoing processes not as manual, triggered responses to inspection preparation.

Build smarter compliance with BeFisc.

Home Blog RBI KYC Master Directions
Previous Article

India Trust & Fraud Intelligence Report 2026: Deepfakes, Synthetic Identities, and the New Threat Landscape

Next Article

What is KYB Verification? A Complete Guide for Indian Businesses, Fintechs, and NBFCs

View Comments (1)
  1. […] The indicia and due diligence. Beyond self-certification, institutions apply due diligence procedures, checking for “indicia” (indicators) of tax residency in their records (addresses, phone numbers, and other information suggesting residency in particular jurisdictions), and reconciling these with self-certifications. If indicia suggest a tax residency not declared, the institution must resolve the discrepancy. This due diligence ensures tax residency is accurately identified, not just self-declared, connecting FATCA/CRS to the institution’s [KYC and customer information]. […]

Leave a Comment

Your email address will not be published. Required fields are marked *