Why Cross-Border BFSI Customers Get KYC’d Twice: and What the vLEI Could Change
Cross-border customers get KYC’d repeatedly because countries enforce rules differently. GLEIF’s vLEI is a proposed fix, not required in India yet.

A business operating across borders must prove who it is, who owns it, and who can act for it, separately, to every bank and regulator. Each jurisdiction runs its own KYC, sanctions and beneficial-ownership checks, with no shared way to say “already verified.” GLEIF’s verifiable Legal Entity Identifier (vLEI), a digital credential layered on the existing LEI system, is one fix the Financial Stability Board (FSB) has flagged. India doesn’t require it yet.
Where things stand (October 2026)
- •India mandates the plain Legal Entity Identifier (LEI) for large corporate borrowers, under two RBI circulars (2017 and 2022). It does not mandate, reference or pilot the vLEI in any instrument found in this research.
- •The FSB has only recommended that regulators explore the vLEI's role in KYC and sanctions screening. No regulator is bound to act on it.
- •The EU's own digital-identity wallet law is referenced below from a secondary explainer, not the EU's official text, so treat its exact dates as approximate.
- •This article explains the standard and the current rules. It isn't legal, regulatory, tax or compliance advice.
Why the same business keeps getting KYC'd from scratch
Cross-border payments run into a patchwork of rules, including AML, counter-terrorist-financing checks, sanctions screening, KYC, data-localisation, tax and forex requirements, that differ by jurisdiction. Global standards like the FATF Recommendations exist, but countries implement them inconsistently. Deloitte’s September 2026 report on cross-border payments in India finds this pushes banks into duplicate compliance checks, re-verifying the same customer repeatedly. That adds cost and slows payments down.
A separate industry report, PwC’s “Making trust portable,” covers a different problem: regulators relying on each other’s licensing decisions, not the repeat checks a business customer faces. Keep the two apart if you read both.
The LEI system GLEIF already runs
The Global Legal Entity Identifier Foundation (GLEIF) was set up by the FSB to run the worldwide Legal Entity Identifier system, a unique code identifying a specific legal entity (a company, fund or trust) in financial transactions anywhere in the world. The FSB’s progress report on LEI implementation points to the LEI’s potential to cut data-related friction in cross-border payments, speed up straight-through processing, and help with KYC and sanctions screening. Separately, the FSB has flagged the verifiable LEI as a way to add trust through verifiable authentication, on top of what the plain LEI already does.
What a vLEI actually is
The vLEI takes an entity’s existing LEI and wraps it in a cryptographically signed digital credential. GLEIF describes it as:
“a secure, user-controlled, digitally trustworthy counterpart to an entity's LEI.”
In practice, it combines three things in one verifiable package: the entity’s identity (its LEI), the individual’s personal identity, and the official role that person holds at the entity. Only accredited Qualified vLEI Issuers (QVIs), operating under GLEIF’s own governance rules, can issue one. Every vLEI traces back cryptographically to the entity’s LEI record, with GLEIF acting as the root of trust.
| LEI | vLEI | |
|---|---|---|
| What it is | A 20-character code identifying a legal entity | That same code, issued as a cryptographically signed digital credential |
| Can it be verified by computer, instantly? | No, it's a static code | Yes, that's the point of the credential |
| Who issues it | LEI issuing organisations (Local Operating Units) | Accredited Qualified vLEI Issuers (QVIs) |
| Required in India today | Yes, for large corporate borrowers (RBI circulars) | No, not mandated, referenced or piloted anywhere found in this research |
Is this coming to India, or anywhere?
Not as a rule yet, anywhere. In its 21 October 2024 progress report, the FSB recommended that member jurisdictions explore ways to build awareness and adoption of the vLEI. It also recommended that standard-setters consider issuing guidance on how the LEI, and possibly the vLEI, could help with KYC, sanctions screening and fraud prevention. No regulator is required to act on either recommendation.
Outside the vLEI specifically, Deloitte’s 2026 report names the EU’s work on cross-border digital identity interoperability as a real-world example. A standardised digital identity, it says, can cut repeat verification and simplify compliance for cross-border payments. The EU does have a relevant law: the eIDAS 2.0 regulation, which requires every member state to offer a digital identity wallet that works across all EU countries. This is very likely the initiative Deloitte describes, though Deloitte’s own text doesn’t name the regulation directly.
India's current rule is the plain LEI, not the vLEI
RBI first required the LEI for large corporate borrowers in a November 2017 circular. It covered banks’ existing large borrowers above a set exposure threshold, phased in starting with the biggest borrowers. A borrower who didn’t comply couldn’t get new or renewed credit. RBI then extended the requirement to co-operative banks and NBFCs and lowered the exposure threshold in an April 2022 circular, phased in through 2025.
So India already has the identity-data foundation, the LEI, that a future vLEI credential would build on. What it doesn’t have, as far as this research found, is any commitment to add the verifiable layer itself. Any claim that an Indian institution already uses or supports vLEI verification would be unsourced.
What this means for you
Read together, GLEIF’s QVI governance structure and India’s LEI mandate point to a specific, narrow gap. A QVI-issued vLEI would let a bank, NBFC or cross-border counterparty cryptographically check that an entity’s identity and a signatory’s authority are genuine, without re-running the identity check from scratch. A plain LEI code can’t do that on its own: it identifies the entity, but a relying party still has to re-verify it manually each time. That’s a description of the mechanism, not a prediction of when or whether India adopts it.
How KYCKART Helps
KYCKART’s business-KYC and beneficial-ownership work tracks standards like this one as they develop. For now, there is nothing to act on regulatorily.
For now, there’s nothing to act on regulatorily. If your team handles cross-border KYB or beneficial-ownership checks, it’s worth tracking GLEIF and FSB announcements on vLEI adoption. The underlying LEI data your large corporate borrowers already hold would carry over directly if a verifiable layer is added later.
Frequently Asked Questions
Bhanujeet Choudhary, Head of Compliance, KYCKART
KYCKART Intelligence
Need business KYC that holds up across jurisdictions?
Talk to KYCKART about verifying businesses and their beneficial owners with the documentation your regulators expect.
Talk to our teamarrow_forward