India to roll out common customer ID for banks, insurers; mutual funds to follow, sources say
Indian banks and insurers are set to roll out a unified Central Know-Your-Customer (Central KYC / CKYC) 2.0 system from August 2026, allowing customers to be onboarded using previously verified identity records instead of resubmitting documents each time.
The initiative is being jointly executed by the Reserve Bank of India (RBI), the Securities and Exchange Board of India (SEBI), and the insurance regulator.
Mutual funds and brokerages are expected to join the framework later in 2026, once sector-specific requirements are finalised.
The revamped system moves to a consent-based, real-time model: customers authorise data access via one-time password (OTP), and each retrieved record carries a confidence score indicating data accuracy and verification status.
Central KYC Records Registry (CKYCR) — Statutory Basis and Structure
The CKYCR is the central digital repository that stores KYC (Know Your Customer) records of financial services customers so they need not be re-verified by every institution separately. Its statutory basis lies in Section 73 of the Prevention of Money Laundering Act (PMLA), 2002, read with the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (specifically Rule 9A and clause (aa) of Rule 2(1)).
Key Details
- The Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) was authorised via Gazette Notification S.O. 3183(E) dated 26 November 2015 to function as the CKYCR.
- The registry went live in July 2016 and today holds KYC records of roughly 1.2 billion customers across regulated entities.
- It caters to reporting entities regulated by all four major financial regulators — RBI (banks/NBFCs), SEBI (securities market intermediaries), IRDAI (insurers), and PFRDA (pension sector).
- Every KYC-verified customer is issued a 14-digit KYC Identification Number (KIN) that can be used across institutions.
CKYC 2.0 upgrades this existing CERSAI-run registry from a static, PDF-based record system to a real-time, API-driven, consent-based framework — directly addressing the data-quality and duplication problems that limited adoption of the original 2016 registry.
RBI KYC Master Direction and eKYC
The RBI's Master Direction on KYC (last comprehensively updated in 2016 and periodically amended) lays down the regulatory framework for customer due diligence by banks and NBFCs, including risk-based categorisation of customers, periodic updation timelines, and use of Aadhaar-based electronic KYC (eKYC).
Key Details
- Customer due diligence is risk-categorised: low-risk customers require KYC updation every 10 years, medium-risk every 8 years, and high-risk every 2 years.
- Aadhaar-based eKYC (biometric or OTP-based) and Video-based Customer Identification Process (V-CIP) are RBI-recognised digital modes of KYC introduced to reduce physical paperwork, under powers derived from the PMLA Rules and the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016.
- The RBI regulates banks/NBFC KYC compliance, while CERSAI operationally maintains the shared registry that stores the resulting records.
CKYC 2.0's OTP-based consent model builds on this eKYC/V-CIP digital-verification lineage, extending it into a shared, cross-sector registry rather than institution-specific verification.
Financial Inclusion and the Digital Personal Data Protection Act, 2023
Reuse of previously verified KYC data through a shared registry supports financial inclusion by lowering onboarding friction, particularly relevant given India's high (around 89%) bank account penetration under the Pradhan Mantri Jan Dhan Yojana but comparatively lower participation in mutual funds, insurance, and pension products. Any such data-sharing framework operates within the consent, purpose-limitation, and data-minimisation principles laid down by the Digital Personal Data Protection (DPDP) Act, 2023.
Key Details
- The DPDP Act, 2023 requires "data fiduciaries" (here, the financial institutions and the registry) to process personal data only with informed consent and for specified purposes — mirrored in CKYC 2.0's requirement that institutions obtain fresh OTP-based authorisation before pulling a customer's stored KYC data.
- PMLA-mandated KYC itself is a statutory exception allowing regulated entities to collect and verify identity data for anti-money-laundering and combating-the-financing-of-terrorism (AML/CFT) compliance.
The shift to explicit, transaction-level consent (via OTP) in CKYC 2.0 reflects the broader regulatory trend toward consent-driven data architecture consistent with the DPDP Act's principles, even though CKYC itself derives its core mandate from the PMLA framework.
- CKYC 2.0 rollout for banks and insurers: from August 2026; mutual funds/brokerages to follow later in 2026.
- CKYCR is operated by CERSAI, authorised under PMLA Rules, 2005 via a November 2015 government notification; live since July 2016.
- Current registry size: approximately 1.2 billion customer KYC records.
- Coordinating regulators: RBI, SEBI, and the insurance regulator (IRDAI).
- Statutory basis: Section 73, Prevention of Money Laundering Act, 2002, read with Rule 9A of the PML (Maintenance of Records) Rules, 2005.
- India's bank account penetration is around 89% of adults, while participation in mutual funds/insurance/pension products remains comparatively low — the gap CKYC 2.0 aims to narrow.