What Is Central KYC (CKYC) 2.0? India’s Unified KYC Platform Explained
CKYC 2.0 is a reported overhaul of India’s Central KYC Records Registry: real-time retrieval, AI-assisted deduplication, and per-record confidence scoring, with banks and insurers reported, but not officially confirmed, to launch from August 2026.
CKYC 2.0 is a reported overhaul of India’s Central KYC Records Registry that would let a bank, insurer, or (later) an asset manager or brokerage pull a customer’s verified identity details from one shared database instead of collecting fresh KYC documents at every institution, with each lookup requiring the customer’s one-time-password approval. The Reserve Bank of India (RBI), the Securities and Exchange Board of India (SEBI), and the Insurance Regulatory and Development Authority of India (IRDAI) are reported to be developing it jointly. No RBI, SEBI, or IRDAI press release, circular, or notification has confirmed CKYC 2.0’s design or rollout date. Everything below comes from Reuters-traced wire reporting and industry commentary, and this piece flags exactly which parts of that are attributed reporting versus confirmed regulatory fact.
“In December 2024, CERSAI awarded Protean eGov Technologies a work order worth roughly Rs 161 crore, covering 69 months, to build and run the upgraded Central KYC Records Registry (CKYCRR 2.0). Unlike the rest of this piece, that fact doesn’t trace back to anonymous sourcing; everything about what the upgrade actually does, and when it goes live, comes from the reported-not-confirmed sourcing covered in the rest of this piece.”
What Changes vs. Today's CKYC/CKYCRR
Today’s Central KYC Records Registry (CKYCRR), run by CERSAI, is already live and mandatory for entities regulated by RBI, SEBI, IRDAI, and PFRDA under the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. For the mechanics of how that registry, and the 14-digit KYC Identifier it issues, work today, see KYCKART’s CKYCRR full-form explainer; for definitions of related terms used throughout this piece, see KYCKART’s KYC/AML glossary. This piece covers only what’s reported to change under the 2.0 upgrade.
Per Reuters-traced reporting, each KYC record under CKYC 2.0 is expected to carry a “confidence score” reflecting how accurate the data is and whether a financial firm has verified it, a response to the existing registry’s duplicate and outdated records. The same reporting describes institutions retrieving a customer’s verified details directly from the central database, but only after the customer approves that specific access via a one-time password, rather than resubmitting documents at each new institution.
Separately, vendor and industry analysis, not an official RBI/SEBI/IRDAI/CERSAI specification, describes a more detailed technical picture. Zigram’s comparison of CKYC 1.0 and 2.0 describes the registry moving from batch file uploads (SFTP transfers of PDF/TIFF scans and flat CSV/XML files) to real-time API submissions using structured, immediately-validated JSON/XML data, replacing a process where errors previously surfaced only during batch cycles, sometimes days later. Signzy’s CKYCRR guide describes deduplication moving from rule-based PAN/Aadhaar matching to AI- and facial-recognition-assisted matching, letting an operator resolve a probable duplicate before submission instead of after rejection. And the same body of vendor commentary, corroborated across Zigram, Befisc, and ixsight, describes mandatory OTP-based, per-event consent (replacing the existing registry’s more basic record-level consent), DigiLocker integration, and automated Aadhaar masking on submissions. None of this vendor-level detail traces to a linked regulatory document.
Rollout Timeline: Reported, Not Confirmed
This is the part of the story with the least agreement across sources, and readers should treat every date below as reported, not scheduled.
The most widely corroborated figure comes from Reuters’ own reporting, syndicated across multiple outlets: banks and insurance companies are expected to launch CKYC 2.0 from August 2026, with asset managers, mutual funds, brokerages, and other capital-market entities joining “at a later stage” with no specific month named. That reporting itself traces to unnamed sources and “an operating guidelines document seen by Reuters,” not a public announcement, and RBI, SEBI, and the insurance regulator did not respond to Reuters’ queries at the time. Multiple secondary outlets covering the same story make the same point. BusinessToday reports that the launch timeline remains officially unconfirmed, and Times Bull notes that no official launch date has been announced.
A separate, conflicting date comes from a different chain of reporting. Finance Minister Nirmala Sitharaman called for “One Nation, One KYC” on 25 April 2026 and directed SEBI to implement a common KYC system, and SEBI responded that it expected to launch CKYC 2.0 in July 2026. A third outlet describes SEBI as having indicated a targeted timeline of July 31, 2026 for the upgraded framework. A separate, unverified Zigram piece appears to state a target of going live by the end of February 2026, this date could not be reconciled with the others and is treated here as an open gap, not a load-bearing claim.
August 2026, July 2026, July 31, 2026, and end-of-February 2026 are four different dates from four separate reporting chains, and none of them are official. This piece doesn’t pick one and treat it as settled; readers evaluating their own rollout planning should treat the August figure as the most widely reported one and the others as competing, unreconciled claims.
What’s Still Unconfirmed
- •No RBI, SEBI, or IRDAI circular, notification, or press release naming CKYC 2.0’s design or rollout date.
- •No specific month for when mutual funds, brokerages, and other capital-market entities join, beyond vague phrasing like “at a later stage.”
- •No primary regulatory document describing the “confidence score” mechanism, its scoring methodology, or how it would feed a regulated entity’s own risk categorization.
- •The commonly cited figure of nearly 1.2 billion existing CKYCR records comes from one outlet’s reporting and wasn’t independently cross-checked against a second source for this piece.
- •PFRDA is a mandatory CKYCRR-compliance regulator today, but no CKYC 2.0-specific reporting checked for this piece names PFRDA alongside RBI, SEBI, and IRDAI as one of the regulators jointly driving the 2.0 upgrade.
- •Real-time fraud-monitoring capabilities described by vendors, such as flagging synthetic or duplicate identities before an account opens or notifying connected institutions of a record update, are vendor commentary describing an expected or possible capability, not a documented regulatory requirement.
Operational Implications for BFSI Institutions
Today’s compliance baseline doesn’t change while CKYC 2.0’s timeline stays unconfirmed. CKYCRR compliance remains mandatory for entities regulated by RBI (banks, NBFCs, payment banks, cooperative banks), SEBI (stock brokers, depository participants, mutual funds, portfolio managers), IRDAI (insurers and intermediaries), and PFRDA (NPS intermediaries and pension fund managers), under the existing PMLA Maintenance of Records Rules. That baseline is what the 2.0 upgrade would build on, not replace.
For institutions planning ahead of any confirmed date, the CERSAI-Protean work order is the one concrete signal that infrastructure work is genuinely underway: a Rs 161 crore, 69-month system-integrator contract awarded in December 2024for the registry’s design, development, implementation, and ongoing operations. That contract, and the reported technical changes described above (real-time API submission, AI-assisted deduplication, per-event OTP consent, DigiLocker integration), point toward institutions eventually needing to update how they submit and retrieve records, moving away from batch file transfers toward structured, real-time API integration, if the reported design holds.
One limit worth flagging before any institution assumes CKYC 2.0 resolves its re-KYC burden: one outlet’s own editorial analysis of the reform argues that even once banking, securities, and insurance entities connect to the same upgraded registry, they don’t necessarily accept each other’s KYC records as sufficient, because differing regulatory standards across sectors, not just the registry’s technical limitations, also drive re-verification requirements. On that reading, a faster, more accurate shared registry doesn’t by itself guarantee an end to sector-to-sector re-KYC requests.
CKYC/CKYCRR Today vs. CKYC 2.0 (As Reported)
The “Sourcing status” column is the load-bearing part of this table: it separates confirmed baseline facts from reported-not-confirmed ones, row by row.
| Dimension | CKYC/CKYCRR Today | CKYC 2.0 (As Reported/Described) | Sourcing Status |
|---|---|---|---|
| Submission method | Batch file uploads (SFTP, PDF/TIFF scans, flat CSV/XML) | Real-time API submission, structured JSON/XML with immediate schema validation | Vendor/industry analysis, not an official spec |
| Deduplication | Rule-based matching on PAN/Aadhaar only | AI- and facial-recognition-assisted deduplication with confidence-scored match resolution | Vendor/industry analysis |
| Data-quality signal | None or minimal, no accuracy indicator attached to a record | Each record expected to carry a “confidence score” reflecting data accuracy and verification status | Reuters-traced wire reporting, reported, not yet confirmed by regulators |
| Consent for access | Record exists in registry; access mechanics less granular | OTP-based, per-access customer consent required before an institution can retrieve a record | Reuters-traced wire reporting plus vendor analysis |
| Regulatory scope | Mandatory under PMLA Rules for RBI/SEBI/IRDAI/PFRDA-regulated entities | RBI, SEBI, and IRDAI reported as jointly driving the upgrade; PFRDA’s specific 2.0 role not confirmed | Mixed, baseline confirmed, PFRDA's 2.0 role is an open gap |
| Rollout sequencing | Already live | Banks and insurers reported first; mutual funds and brokerages phased in later, no specific date found | Reuters-traced wire reporting, phasing described consistently, exact later date not found |
| Official confirmation status | Live, RBI Master Direction-governed | No press release or circular confirming date or design found | Confirmed absence of official confirmation, not confirmed presence of the feature itself |
What This Means for BFSI Compliance Teams
Read together, three cited facts support the same conclusion as KYCKART’s broader analysis of RBI’s ongoing due diligence rules, which frames KYC as a living customer record rather than a single point-in-time check. First, the reported confidence-score mechanism attaches to a record based on whether it has been verified, so it only holds meaning if updates keep flowing into the registry throughout the record’s life. Second, the reported per-access OTP consent model treats each new institution’s lookup as its own event requiring fresh customer approval, rather than a single gate cleared once at initial registration. Third, the editorial finding that a faster, more accurate registry still leaves cross-sector re-verification requirements in place suggests the registry’s technical quality and an institution’s own ongoing due diligence obligations are two separate things that both still need attention.
The practical implication is that even if CKYC 2.0 ships largely as reported, a BFSI compliance team’s work continues past confirming a customer’s record exists in the registry. Institutions still need to keep their own due-diligence and re-verification practices current against the registry’s latest state; a one-time registry check or a technically improved shared database covers only part of that work.
How KYCKART Helps
KYCKART’s onboarding platform treats a KYC record as something that stays current, not a one-time registry lookup, so a customer’s verification status stays accurate whichever registry version an institution is checking against.
Frequently Asked Questions
Bhanujeet Choudhary
Head of Compliance, KYCKART
Published August 27, 2026
Disclaimer: This piece summarizes reported and industry-sourced information about CKYC 2.0 for informational purposes. No RBI, SEBI, or IRDAI notification confirming CKYC 2.0’s design or rollout date was found in the research behind this piece, and it is not legal, tax, or compliance advice. Institutions should confirm current regulatory requirements directly with the relevant regulator before acting on anything summarized here.
KYCKART Intelligence
Keep Registry Records Current, Whatever CKYC 2.0’s Timeline Turns Out to Be
Whether CKYC 2.0 lands in August 2026 or later, a shared registry only holds meaning if your own onboarding and re-verification records stay current. KYCKART keeps KYC records live rather than treating a registry check as a one-time gate.
Explore Onboarding & KYC Verificationarrow_forward