CKYC Verification API Explained: What CKYC 2.0 Changes for Onboarding

CKYC Verification API Explained: What CKYC 2.0 Changes for Onboarding

October 09, 2026

A CKYC Verification API lets a bank, NBFC, or fintech check whether a customer already has a KYC record in India's Central KYC Records Registry (CKYCRR), then search, download, upload, or update that record without asking the customer to resubmit documents. It's built on top of CERSAI's centralised registry, and as of August 2026, that registry itself is in the middle of its biggest upgrade since it launched.

Banks and insurers have started moving onto CKYCRR 2.0 this month, replacing over a decade of batch-file uploads with real-time, API-first infrastructure. If your onboarding stack still talks to CKYC the old way, this is the moment to understand what's changing, what four services actually make up “CKYC verification,” and what it means for your compliance timeline.

What Is CKYC, in Plain Terms?

Central KYC (CKYC) is a single, government-backed registry that stores a customer's verified KYC record so it can be reused across every regulated financial institution in India, instead of being collected fresh each time. It's operated by CERSAI (Central Registry of Securitisation Asset Reconstruction and Security Interest of India) under the Prevention of Money-Laundering Rules, and applies to entities regulated by the RBI, SEBI, IRDAI, and PFRDA.

Once a customer's KYC is uploaded, CERSAI issues a 14-digit KYC Identifier Number (KIN). That KIN becomes the reference point every other regulated entity can use, with the customer's consent, to pull the same verified record instead of running fresh document checks.

Why CKYC 2.0 Matters Right Now

CKYCRR 2.0 was announced in the Union Budget 2025, and CERSAI awarded a roughly ₹161 crore contract to Protean eGov Technologies to build it. According to Reuters reporting, Indian banks and insurers began using the upgraded framework in August 2026, with mutual funds and brokerages expected to follow later in the year as sector-specific requirements are finalised.

The scale involved is significant: India recorded roughly 103 crore CKYC registrations in 2025 alone, and the existing registry holds close to 1.2 billion customer records. The upgrade replaces static, batch-based PDF/XML uploads with real-time, structured JSON API submissions, adds mandatory Aadhaar masking, introduces OTP-based consent for every time a record is accessed, and applies AI-assisted facial de-duplication to cut down on duplicate KYC records.

Because the rollout is phased and institution-specific, it's worth confirming your organisation's exact migration timeline directly with CERSAI rather than assuming a single fixed date applies across the board.

The Four CKYC API Services, Explained

“CKYC verification” isn't one single API call; it's typically four distinct services, each solving a different part of the onboarding and compliance workflow.

ServiceWhat It DoesWhen You'd Use It
CKYC SearchChecks whether a customer already has a KYC record in CERSAI's registry, using PAN, Aadhaar, or other identifiersFirst step in onboarding, before deciding whether fresh KYC is needed
CKYC DownloadRetrieves the customer's full verified KYC record using their CKYC number (KIN) and date of birth, with consentWhen a search confirms an existing record and you need the underlying data
CKYC UploadSubmits a new customer's verified KYC details to CERSAI after your own onboarding checksFirst-time onboarding of a customer with no existing CKYC record
CKYC UpdatePushes updated customer information (address, documents, risk category) to the existing registry recordPeriodic re-KYC or when a customer's details change

 Mapping your integration to these four services individually rather than treating CKYC as one generic “API” makes it much easier to scope what you actually need, especially if you only require search and download today but will need to upload and update later.

What Changes Under CKYC 2.0

 

AreaCKYCRR 1.0 (Legacy)CKYCRR 2.0 (2026 Upgrade)
Submission formatBatch PDF/XML file uploadsReal-time, structured JSON API submissions
Consent captureLargely institution-managed, inconsistentMandatory OTP-based consent on every access
Duplicate recordsManual reconciliation, common duplicationAI-based facial de-duplication at submission
Aadhaar handlingVaried masking practicesMandatory automated Aadhaar masking
Customer visibilityNo self-service accessConsumer self-service portal to view and manage records
TurnaroundDays, dependent on batch cyclesNear real-time, minutes in many cases

CKYC vs. Aadhaar eKYC vs. Video KYC

Teams often ask how CKYC fits alongside the other identity verification methods RBI permits. They're complementary, not competing, but each has a different role.

MethodWhat It VerifiesFace-to-Face Equivalent?Best Used For
CKYCWhether a verified KYC record already exists in the central registryNo relies on the original verification method usedReusing an existing customer's KYC across institutions
Aadhaar OTP eKYCIdentity via UIDAI's OTP-based Aadhaar authenticationNo carries a ₹1 lakh/year transaction capFast, low-friction onboarding for lower-value accounts
Video KYC (V-CIP)Live identity verification via recorded video interactionYes treated on par with in-person verificationFull-service account opening without transaction caps

 For a closer look at how the video-based route works, see LetsFin's Video KYC & Video PD API listing, or LetsFin's Aadhaar Tech API listing for OTP-based and offline Aadhaar verification options.

Compliance Timelines to Know

• Risk-based re-verification: high-risk customers require re-KYC every 2 years, medium-risk every 8 years, and low-risk customers every 10 years, under RBI's risk-tiered KYC directions.

• Upload and update windows: newly onboarded customer records are generally expected to reach the registry within days of account opening, with updates filed promptly after any change to customer details.

• Download consent: every time a regulated entity downloads a customer's CKYC record, current guidance requires fresh, auditable consent typically OTP-based rather than a one-time blanket authorisation.

• Confirm your own deadline: because CKYC 2.0 migration is being phased by CERSAI across banks, insurers, mutual funds, and other regulated entities, compliance and tech teams should confirm their institution's specific go-live and enforcement dates directly with CERSAI rather than relying on a single industry-wide date.

Benefits for Lenders and Fintechs

• Faster onboarding: a CKYC Search hit can let you skip full fresh KYC entirely for returning-to-the-system customers

• Lower document-collection cost: fewer repeat submissions of PAN, Aadhaar, and address proof across products

• Stronger compliance posture: structured, auditable submissions replace error-prone batch files

• Reduced duplicate-record risk: CKYC 2.0's facial de-duplication cuts down on the operational cleanup that duplicate KINs used to require

• Better customer experience: near real-time responses instead of multi-day batch turnarounds

Challenges to Plan For

• Migration effort: moving from batch XML/PDF submissions to real-time JSON APIs is a genuine integration project, not a config change

• Consent-flow redesign: OTP-based consent on every download changes onboarding UX and needs to be built into your customer journey, not bolted on afterward

• Phased rollout uncertainty: since banks, insurers, mutual funds, and brokerages are migrating on different timelines, teams working across product lines may need to support both legacy and 2.0 flows for a transition period

• Data quality debt: legacy records with inconsistent formatting are more likely to trigger validation failures under 2.0's stricter real-time checks

How to Choose a CKYC API Partner

When evaluating a CKYC integration partner, compare them on:

• Whether they support all four services Search, Download, Upload, and Update or only a subset

• Readiness for CKYCRR 2.0's real-time JSON architecture, not just legacy batch support

• Built-in OTP consent handling and Aadhaar masking, so you're not building compliance logic from scratch

• Response time and uptime guarantees, since a slow CKYC Search step delays your entire onboarding funnel

• Support for complementary verification layers Aadhaar-based eKYC or Video KYC for customers with no existing CKYC record

LetsFin's CKYC Verification API marketplace listing lets you compare vetted CKYC API partners across Search, Download, Upload, and Update capabilities side by side, rather than evaluating each vendor's 2.0-readiness claims independently. And since consent handling is now central to how CKYC 2.0 works, it's worth reading LetsFin's recent piece on how the DPDP Act is changing consent management for the broader compliance picture this connects to.

FAQs

What is the CKYC number (KIN)?

It's a 14-digit KYC Identifier Number assigned by CERSAI when a customer's KYC record is first uploaded to the registry. It's used to search for and retrieve that record across any regulated institution.

Is CKYC mandatory for all financial institutions?

Yes, for entities regulated by RBI, SEBI, IRDAI, or PFRDA. These institutions are required to check the registry and upload verified customer KYC data as part of standard onboarding.

What's the difference between CKYC and eKYC?

eKYC (like Aadhaar OTP verification) is a method of establishing a customer's identity for the first time. CKYC is the centralized registry that stores the outcome of that verification so it can be reused later by other institutions.

Do I need to migrate to CKYCRR 2.0 immediately?

Migration is being phased by CERSAI across sectors, with banks and insurers starting in August 2026 and other regulated entities following later in the year. Confirm your specific institution's timeline directly with CERSAI rather than assuming a blanket deadline.

Can a business build direct CERSAI integration instead of using an API partner?

Yes, but it requires meeting CERSAI's technical, security, and compliance specifications directly, which is a substantial engineering investment. Most NBFCs and fintechs integrate through a specialist API partner instead.

Does CKYC replace the need for Video KYC or Aadhaar eKYC?

No. CKYC only works if a verified record already exists in the registry. Customers without an existing record still need to complete identity verification through eKYC, Video KYC, or in-person verification first, which then gets uploaded to CKYC.

In Summary

CKYC 2.0 isn't a future change to plan around; it's actively rolling out with banks and insurers this month, and the rest of the regulated sector is expected to follow through 2026. For NBFCs and fintechs, the practical question is whether your Search, Download, Upload, and Update integrations are ready for a real-time, API-first registry, or whether you're still depending on legacy batch processes that CERSAI is actively phasing out. Compare vetted CKYC Verification API providers on LetsFin to find a partner that's built for where CKYC is headed, not just where it's been.