October 09, 2026
A CKYC Verification API lets a bank, NBFC, or fintech check whether a customer already has a KYC record in India's Central KYC Records Registry (CKYCRR), then search, download, upload, or update that record without asking the customer to resubmit documents. It's built on top of CERSAI's centralised registry, and as of August 2026, that registry itself is in the middle of its biggest upgrade since it launched.
Banks and insurers have started moving onto CKYCRR 2.0 this month, replacing over a decade of batch-file uploads with real-time, API-first infrastructure. If your onboarding stack still talks to CKYC the old way, this is the moment to understand what's changing, what four services actually make up “CKYC verification,” and what it means for your compliance timeline.
Central KYC (CKYC) is a single, government-backed registry that stores a customer's verified KYC record so it can be reused across every regulated financial institution in India, instead of being collected fresh each time. It's operated by CERSAI (Central Registry of Securitisation Asset Reconstruction and Security Interest of India) under the Prevention of Money-Laundering Rules, and applies to entities regulated by the RBI, SEBI, IRDAI, and PFRDA.
Once a customer's KYC is uploaded, CERSAI issues a 14-digit KYC Identifier Number (KIN). That KIN becomes the reference point every other regulated entity can use, with the customer's consent, to pull the same verified record instead of running fresh document checks.
CKYCRR 2.0 was announced in the Union Budget 2025, and CERSAI awarded a roughly ₹161 crore contract to Protean eGov Technologies to build it. According to Reuters reporting, Indian banks and insurers began using the upgraded framework in August 2026, with mutual funds and brokerages expected to follow later in the year as sector-specific requirements are finalised.
The scale involved is significant: India recorded roughly 103 crore CKYC registrations in 2025 alone, and the existing registry holds close to 1.2 billion customer records. The upgrade replaces static, batch-based PDF/XML uploads with real-time, structured JSON API submissions, adds mandatory Aadhaar masking, introduces OTP-based consent for every time a record is accessed, and applies AI-assisted facial de-duplication to cut down on duplicate KYC records.
Because the rollout is phased and institution-specific, it's worth confirming your organisation's exact migration timeline directly with CERSAI rather than assuming a single fixed date applies across the board.
“CKYC verification” isn't one single API call; it's typically four distinct services, each solving a different part of the onboarding and compliance workflow.
| Service | What It Does | When You'd Use It |
| CKYC Search | Checks whether a customer already has a KYC record in CERSAI's registry, using PAN, Aadhaar, or other identifiers | First step in onboarding, before deciding whether fresh KYC is needed |
| CKYC Download | Retrieves the customer's full verified KYC record using their CKYC number (KIN) and date of birth, with consent | When a search confirms an existing record and you need the underlying data |
| CKYC Upload | Submits a new customer's verified KYC details to CERSAI after your own onboarding checks | First-time onboarding of a customer with no existing CKYC record |
| CKYC Update | Pushes updated customer information (address, documents, risk category) to the existing registry record | Periodic re-KYC or when a customer's details change |
Mapping your integration to these four services individually rather than treating CKYC as one generic “API” makes it much easier to scope what you actually need, especially if you only require search and download today but will need to upload and update later.
| Area | CKYCRR 1.0 (Legacy) | CKYCRR 2.0 (2026 Upgrade) |
| Submission format | Batch PDF/XML file uploads | Real-time, structured JSON API submissions |
| Consent capture | Largely institution-managed, inconsistent | Mandatory OTP-based consent on every access |
| Duplicate records | Manual reconciliation, common duplication | AI-based facial de-duplication at submission |
| Aadhaar handling | Varied masking practices | Mandatory automated Aadhaar masking |
| Customer visibility | No self-service access | Consumer self-service portal to view and manage records |
| Turnaround | Days, dependent on batch cycles | Near real-time, minutes in many cases |
Teams often ask how CKYC fits alongside the other identity verification methods RBI permits. They're complementary, not competing, but each has a different role.
| Method | What It Verifies | Face-to-Face Equivalent? | Best Used For |
| CKYC | Whether a verified KYC record already exists in the central registry | No relies on the original verification method used | Reusing an existing customer's KYC across institutions |
| Aadhaar OTP eKYC | Identity via UIDAI's OTP-based Aadhaar authentication | No carries a ₹1 lakh/year transaction cap | Fast, low-friction onboarding for lower-value accounts |
| Video KYC (V-CIP) | Live identity verification via recorded video interaction | Yes treated on par with in-person verification | Full-service account opening without transaction caps |
For a closer look at how the video-based route works, see LetsFin's Video KYC & Video PD API listing, or LetsFin's Aadhaar Tech API listing for OTP-based and offline Aadhaar verification options.
• Risk-based re-verification: high-risk customers require re-KYC every 2 years, medium-risk every 8 years, and low-risk customers every 10 years, under RBI's risk-tiered KYC directions.
• Upload and update windows: newly onboarded customer records are generally expected to reach the registry within days of account opening, with updates filed promptly after any change to customer details.
• Download consent: every time a regulated entity downloads a customer's CKYC record, current guidance requires fresh, auditable consent typically OTP-based rather than a one-time blanket authorisation.
• Confirm your own deadline: because CKYC 2.0 migration is being phased by CERSAI across banks, insurers, mutual funds, and other regulated entities, compliance and tech teams should confirm their institution's specific go-live and enforcement dates directly with CERSAI rather than relying on a single industry-wide date.
• Faster onboarding: a CKYC Search hit can let you skip full fresh KYC entirely for returning-to-the-system customers
• Lower document-collection cost: fewer repeat submissions of PAN, Aadhaar, and address proof across products
• Stronger compliance posture: structured, auditable submissions replace error-prone batch files
• Reduced duplicate-record risk: CKYC 2.0's facial de-duplication cuts down on the operational cleanup that duplicate KINs used to require
• Better customer experience: near real-time responses instead of multi-day batch turnarounds
• Migration effort: moving from batch XML/PDF submissions to real-time JSON APIs is a genuine integration project, not a config change
• Consent-flow redesign: OTP-based consent on every download changes onboarding UX and needs to be built into your customer journey, not bolted on afterward
• Phased rollout uncertainty: since banks, insurers, mutual funds, and brokerages are migrating on different timelines, teams working across product lines may need to support both legacy and 2.0 flows for a transition period
• Data quality debt: legacy records with inconsistent formatting are more likely to trigger validation failures under 2.0's stricter real-time checks
When evaluating a CKYC integration partner, compare them on:
• Whether they support all four services Search, Download, Upload, and Update or only a subset
• Readiness for CKYCRR 2.0's real-time JSON architecture, not just legacy batch support
• Built-in OTP consent handling and Aadhaar masking, so you're not building compliance logic from scratch
• Response time and uptime guarantees, since a slow CKYC Search step delays your entire onboarding funnel
• Support for complementary verification layers Aadhaar-based eKYC or Video KYC for customers with no existing CKYC record
LetsFin's CKYC Verification API marketplace listing lets you compare vetted CKYC API partners across Search, Download, Upload, and Update capabilities side by side, rather than evaluating each vendor's 2.0-readiness claims independently. And since consent handling is now central to how CKYC 2.0 works, it's worth reading LetsFin's recent piece on how the DPDP Act is changing consent management for the broader compliance picture this connects to.
What is the CKYC number (KIN)?
It's a 14-digit KYC Identifier Number assigned by CERSAI when a customer's KYC record is first uploaded to the registry. It's used to search for and retrieve that record across any regulated institution.
Is CKYC mandatory for all financial institutions?
Yes, for entities regulated by RBI, SEBI, IRDAI, or PFRDA. These institutions are required to check the registry and upload verified customer KYC data as part of standard onboarding.
What's the difference between CKYC and eKYC?
eKYC (like Aadhaar OTP verification) is a method of establishing a customer's identity for the first time. CKYC is the centralized registry that stores the outcome of that verification so it can be reused later by other institutions.
Do I need to migrate to CKYCRR 2.0 immediately?
Migration is being phased by CERSAI across sectors, with banks and insurers starting in August 2026 and other regulated entities following later in the year. Confirm your specific institution's timeline directly with CERSAI rather than assuming a blanket deadline.
Can a business build direct CERSAI integration instead of using an API partner?
Yes, but it requires meeting CERSAI's technical, security, and compliance specifications directly, which is a substantial engineering investment. Most NBFCs and fintechs integrate through a specialist API partner instead.
Does CKYC replace the need for Video KYC or Aadhaar eKYC?
No. CKYC only works if a verified record already exists in the registry. Customers without an existing record still need to complete identity verification through eKYC, Video KYC, or in-person verification first, which then gets uploaded to CKYC.
CKYC 2.0 isn't a future change to plan around; it's actively rolling out with banks and insurers this month, and the rest of the regulated sector is expected to follow through 2026. For NBFCs and fintechs, the practical question is whether your Search, Download, Upload, and Update integrations are ready for a real-time, API-first registry, or whether you're still depending on legacy batch processes that CERSAI is actively phasing out. Compare vetted CKYC Verification API providers on LetsFin to find a partner that's built for where CKYC is headed, not just where it's been.