Introduction
In January 2020, the RBI formally permitted the Video Customer Identification Process (V-CIP) as a valid alternative to physical KYC for regulated entities opening accounts and originating loans. This circular fundamentally changed digital onboarding for NBFCs, payment banks, and financial institutions that had previously required at least one physical touchpoint in the KYC process. Video KYC APIs make this compliant digital-first onboarding operationally scalable, enabling institutions to run VKYC sessions through integrated APIs rather than building custom video infrastructure.
This guide explains exactly how RBI-compliant Video KYC works, what the API integration covers, and what compliance teams must ensure to stay aligned with RBI’s V-CIP circular requirements.
What Is RBI’s Video KYC (V-CIP) Framework?
Video Customer Identification Process, as defined in RBI’s January 2020 circular and subsequent updates, permits regulated entities to complete KYC for individual customers through a live video interaction, replacing the physical branch visit. Key elements mandated by RBI:
- Live video interaction: The session must be a real-time, live video call, not a pre-recorded submission. The customer must be physically present and interacting with an agent or AI system.
- Identity document capture and verification: The customer must display their Aadhaar or OVD to the camera, and the system must capture a clear image for document verification.
- Geolocation capture: The customer’s geolocation at the time of the VKYC session must be captured and recorded.
- Data storage: All VKYC recordings must be stored for at least five years and must be available for regulatory inspection.
- AI or agent-led: RBI permits both agent-led VKYC (human agent conducting the session) and AI-led VKYC (automated system with liveness detection) for certain use cases.
How Video KYC APIs Work
Session Initiation
The Video KYC API generates a unique session token and a secure URL for the customer. The customer receives the link via SMS or in-app and initiates the session on their mobile or desktop browser. No app installation is required for well-architected VKYC implementations.
Pre-Session Checks
Before the live session begins, the API runs pre-session quality checks: device camera availability and quality, network bandwidth adequacy, and browser compatibility. Poor connectivity or camera quality is flagged before the session starts, preventing failed sessions that waste both customer and agent time.
Live Session Execution
During the live session: the customer is prompted to display their identity document to the camera; the API captures frames and runs real-time OCR and document verification; the system performs liveness detection to confirm the customer is physically present; a face match confirms the live customer matches the document photo; geolocation is captured in the background; and the agent (or AI system) confirms completion.
Session Recording and Storage
The complete session is recorded and stored with a session ID, timestamp, geolocation data, and all captured frames. This constitutes the audit record for regulatory compliance.
The Deepfake and Video Fraud Challenge in VKYC
As VKYC adoption has grown, so has the sophistication of fraud targeting video verification. The primary threats are: deepfake video injection, where a real-time AI-generated video of a synthetic or stolen face is inserted into the video stream rather than the actual user; pre-recorded video replay, where a recorded video of another person is played through the camera feed; and presentation attacks using printed photos or screen-displayed images.
Production-grade VKYC APIs must implement active liveness challenges prompting random, unpredictable actions (blink, turn left, smile) that synthetic or pre-recorded streams cannot respond to correctly. Passive liveness detection alone is no longer sufficient against advanced attack techniques.
RBI Compliance Checklist for Video KYC
- Live session only: No pre-recorded submissions accepted.
- Geolocation captured and stored with each session.
- OVD document captured and verified in real time.
- Face match performed between live face and document photo.
- Session recording stored for minimum five years.
- AI liveness detection active during session.
- Audit trail complete: session ID, timestamp, verification outcomes, agent ID (if applicable).
- Customer consent explicitly captured before session initiation.
Where BeFiSc Fits
BeFiSc’s Video KYC API provides a complete VKYC integration: session management, document capture and verification, active liveness detection, face match, geolocation capture, session recording, and structured audit trail output, all aligned with RBI’s V-CIP requirements. For NBFCs and lending platforms, BeFiSc’s VKYC API supports both AI-led and agent-assisted session configurations.
Key Takeaways
- RBI’s V-CIP framework permits Video KYC as a legally valid alternative to physical KYC.
- Active liveness detection is essential; passive detection is insufficient against deepfake and replay attacks.
- Geolocation capture, five-year session storage, and complete audit trails are mandatory RBI requirements.
- Both AI-led and agent-assisted VKYC configurations are permissible, with human oversight requirements.
Frequently Asked Questions
Can AI-led VKYC replace agent-led VKYC entirely?
RBI permits AI-led VKYC for certain use cases but requires human agent oversight and the ability to escalate to a live agent. Full autonomous AI VKYC without any human oversight capacity is not currently permitted for regulated entities.
What happens if a VKYC session fails mid-way?
Failed sessions must be handled gracefully — session state preserved, customer notified, and a fresh session initiated. Partial session data must not be used for compliance decisions. Well-designed VKYC APIs include session recovery logic to restart from pre-failure checkpoints.
Is Video KYC legally equivalent to physical KYC for account opening?
Yes, under RBI’s V-CIP circular (January 2020 and subsequent updates), Video KYC completed as per the specified requirements is legally equivalent to physical KYC for individual account opening and loan origination by regulated entities.
Conclusion
Video KYC API solutions have transformed digital onboarding by enabling RBI-compliant, remote customer verification without compromising security or compliance. By combining live video verification, document authentication, active liveness detection, face matching, geolocation capture, and secure audit trails, financial institutions can deliver a faster onboarding experience while meeting V-CIP requirements. Implementing a robust Video KYC API helps banks, NBFCs, and fintechs reduce onboarding friction, strengthen fraud prevention, and build a scalable, compliant digital KYC process