What Is eKYC? How Digital KYC Verification Works in India
eKYC is RBI’s term for Aadhaar-based e-authentication, not a synonym for ‘Digital KYC.’ How eKYC’s three modes work, who can use them, and where document and online verification fit in India.
eKYC, in India’s regulatory usage, means Aadhaar-based electronic authentication run through UIDAI, a specific mechanism rather than a catch-all term for every digital identity check[1]. The RBI’s Master Direction on Know Your Customer treats it as narrower than “Digital KYC,” a separate, broader term covering an officer-verified live photo capture plus a document or proof of Aadhaar possession[1]. In practice, only some of these methods qualify an account for full face-to-face KYC status, and eKYC completed remotely, on its own, does not[2][3][4][9].
The rest of this piece works through what eKYC actually covers, its three modes, how it fits inside RBI’s broader onboarding framework, who is authorised to run it, current adoption data, the end-to-end process, and where “document verification” and “online verification” sit relative to it.
eKYC vs. "Digital KYC": Two Different Regulatory Terms
The RBI’s KYC Master Direction doesn’t define “e-KYC” as a standalone entry with its own definitions-clause. Instead, “e-KYC” and “e-KYC authentication facility” appear throughout the Direction to mean specifically Aadhaar-based electronic authentication provided by UIDAI, run as OTP-based or biometric-based verification[1]. “Digital KYC,” by contrast, describes a different and broader process: capturing a live photo of the customer along with an Officially Valid Document (OVD) or proof of possession of Aadhaar, plus the latitude and longitude of the location, captured by an authorised officer of the Regulated Entity (RE)[1]. That Digital KYC Process is governed by paragraph 16 of the Master Direction[2].
| Term | RBI’s Actual Scope | Who’s Involved |
|---|---|---|
| e-KYC / e-KYC authentication facility | Aadhaar-based electronic authentication via UIDAI, OTP-based or biometric-based[1] | Customer, self-serve |
| Digital KYC / Digital KYC Process (para 16) | Live photo capture + OVD or proof of Aadhaar possession + geo-location, captured by an authorised officer[1][2] | Customer plus an authorised officer of the RE |
Vendors and media commonly use “digital KYC” as a general label for any electronic identity-verification method, including e-KYC, V-CIP, and document-upload flows. RBI’s own usage doesn’t support that interchangeability[1][3]. Per the RBI’s June 9, 2025 FAQ on the Master Direction, completing the Digital KYC Process allows an RE to treat onboarding as face-to-face when it’s done through any of three alternative methods: e-KYC authentication (OTP-based or biometric-based), offline verification of proof of possession of the Aadhaar number, or obtaining a certified copy of the OVD or an equivalent e-document[2][3][4]. Separately, when Aadhaar OTP-based e-KYC is used remotely without an RE officer present, RBI treats that as a distinct, lower-status onboarding mode from the in-person Digital KYC Process, even though both use the same underlying e-KYC authentication mechanism[3].
The Three Modes of Aadhaar e-KYC
UIDAI’s Aadhaar-based e-KYC authentication runs through three broad modes.
| Mode | How It Works | What It Requires |
|---|---|---|
| OTP-based | Customer enters their Aadhaar number and receives a one-time password on their Aadhaar-registered mobile number; on correct entry, UIDAI releases the customer's demographic details and photograph to the requesting entity as a digitally signed record[6] | An active Aadhaar-registered mobile number |
| Biometric-based | Fingerprint, iris, or face authentication matched against UIDAI's central database; per the RBI Master Direction, this can be conducted by a bank official, business correspondent, or business facilitator[6][7] | Live biometric capture |
| Aadhaar Paperless Offline e-KYC | A separate, non-realtime method: the customer downloads a UIDAI-issued, digitally signed XML file, or generates/scans a QR code from their Aadhaar card or e-Aadhaar PDF[5][6] | No live UIDAI connection at the point of verification |
Aadhaar Paperless Offline e-KYC works differently from the other two modes. The file or QR code contains identity and address data without transmitting the full Aadhaar number or any biometric data. The Aadhaar number is masked, with only the last four digits visible in the QR code, and biometric information is excluded entirely. Before generating the file, the person chooses which optional fields to include: photo, date of birth, email, mobile number, gender[5][6]. That doesn’t make offline Aadhaar an indefinitely reusable record, though. Under the RBI Master Direction’s V-CIP provisions, an offline Aadhaar XML or QR code used to support a V-CIP session must have been generated no more than three working days before the session date[7].
Aadhaar isn’t the only route into eKYC-adjacent onboarding. Officially Valid Documents (OVDs) under the RBI KYC framework are a closed list of exactly six: Passport, Voter ID (EPIC), Driving Licence, Aadhaar, NREGA Job Card (attested by a state government official), and a letter issued by the National Population Register. No other government-issued document qualifies[8].
Where eKYC Sits in RBI's Face-to-Face Framework
RBI classifies Aadhaar OTP-based e-KYC as a non-face-to-face (NFTF) onboarding method. Customers onboarded this way are classified as high-risk and made subject to Enhanced Due Diligence (EDD) until they’re upgraded through a face-to-face method: in-person verification, a compliant Digital KYC Process, or V-CIP[7][9]. Per the RBI’s June 2025 FAQ document, only three onboarding methods currently achieve full face-to-face status: physical in-person verification, the Digital KYC Process under paragraph 16, and a fully compliant V-CIP session[2][3][4]. Aadhaar OTP-based e-KYC conducted remotely, on its own, doesn’t reach that bar.
RBI does build in one accommodation for this mode specifically. For accounts opened via Aadhaar OTP-based e-KYC in non-face-to-face mode, the Master Direction permits the customer to self-declare a current address even where it differs from the address recorded in the Aadhaar database[9].
This piece stops at the summary level here. The concurrent-audit, VAPT, geo-tagging, session-rule, and sector-terminology (VBIP/VIPV) detail that separates V-CIP from Aadhaar OTP e-KYC in full is covered in What Is Video KYC (V-CIP) and How Does It Differ from e-KYC?[7].
Who's Authorised to Perform Aadhaar e-KYC
Not every business can run Aadhaar e-KYC directly. Only entities registered with UIDAI as a KYC User Agency (KUA) or Sub-KUA are permitted to perform Aadhaar-based e-KYC authentication, and for RBI-regulated entities other than banks, that authorisation also requires notification under Section 11A of the Prevention of Money-Laundering Act, 2002[10]. Banks receive distinct treatment under the KYC Master Directions; NBFCs, HFCs, and other RBI-regulated entities need separate Central Government notification[10]. Entities without direct authorisation typically access e-KYC by partnering with a licensed KUA and operating as its Sub-KUA, or through a licensed intermediary relationship[10].
This restricted-access model traces back to the Supreme Court’s 2018 Puttaswamy judgment, which found biometric data linked to Aadhaar to be sensitive personal data warranting heightened protection, and to the subsequent Aadhaar and Other Laws (Amendment) Act, 2019. Since that Act, private-sector entities can perform Aadhaar authentication only where specifically permitted by law or notified by the Central Government; they cannot self-register as AUAs/KUAs the way government entities can[11].
The November 2025 Regulatory Restructuring
In November 2025, RBI replaced its previously consolidated 2016 “Master Direction on KYC” with 10 separate, sector-specific KYC Master Directions, covering commercial banks, NBFCs, small finance banks, payments banks, cooperative banks, local area banks, regional rural banks, asset reconstruction companies, and all-India financial institutions, effective November 28, 2025[12]. Every RBI reference in this piece to “the Master Direction” reflects the framework as it stood before and through that restructuring; readers checking current text against a specific sector should confirm which of the 10 Directions now applies to their entity type.
How Much of India Runs on eKYC Today
“UIDAI recorded 231 crore total Aadhaar authentication transactions in November 2025, of which 47.19 crore were e-KYC transactions specifically, a year-on-year increase of over 24%.[13][14]”
| Metric (November 2025) | Volume | Year-on-Year Change |
|---|---|---|
| Total Aadhaar authentication transactions | 231 crore (2.31 billion)[13] | +8.47% vs. November 2024[13][14] |
| e-KYC transactions specifically | 47.19 crore (471.9 million)[13] | +24%+ vs. November 2024[13] |
| Aadhaar Face Authentication transactions | 28.29 crore[13] | Up from 12.04 crore in November 2024[13] |
UIDAI’s press materials name banks and financial institutions, fintech and digital lending platforms, telecom companies, insurance providers, and digital payment ecosystems as the primary sectors using e-KYC services, without publishing a numeric breakdown by sector[13]. UIDAI also states that over 100 entities across public and private sectors use Aadhaar Face Authentication[13]. How that mechanism is formally categorised relative to “e-KYC” as a defined term isn’t something the sources for this piece resolve with certainty, so it’s presented here as a separately reported figure rather than folded into the OTP/biometric e-KYC totals.
The scale predates November 2025 too. Cumulative Aadhaar authentication transactions crossed 150 billion (15,011.82 crore) by the end of April 2025, with cumulative e-KYC transactions specifically reaching 2,393 crore (23.93 billion) as of April 30, 2025[15]. Monthly e-KYC volume was already substantial earlier in the year: 44.63 crore transactions in March 2025, and 37.3 crore in April 2025, a 39.7% year-on-year increase for that month[16].
The End-to-End eKYC Flow
A typical customer-facing eKYC/digital onboarding flow in India runs through five steps[6][9].
Entry
The customer enters their Aadhaar number, or scans a QR code, or uploads an Offline Aadhaar XML, on the RE's app or portal.
Authentication
For OTP-based e-KYC, an OTP is sent to the Aadhaar-linked mobile number and entered by the customer as consent-plus-authentication.
Retrieval
The RE's system, directly or through its KUA/Sub-KUA partner, retrieves the demographic data and photograph from UIDAI as a digitally signed record.
Cross-check
The RE cross-checks this against any supporting document upload, if the flow also requires one.
Provisioning
The account or service is provisioned once the data passes the RE's internal verification and risk checks, with NFTF accounts opened this way immediately flagged for Enhanced Due Diligence.[9]
Document Verification and Online Verification: Where They Fit
Two related terms show up constantly around eKYC without meaning the same thing.
| Term | What It Actually Refers To | Regulatory Status |
|---|---|---|
| e-KYC | Aadhaar-based electronic authentication via UIDAI, OTP-based or biometric-based[1] | Specifically defined and used in RBI's Master Direction[1] |
| Document verification | Examining a customer-submitted physical or scanned government-issued document to confirm authenticity and extract identity/address data, historically through manual visual inspection, increasingly automated with OCR and image-forensics/AI-based checks that validate the document itself rather than authenticating the holder against a government database in real time[17][18] | A technique for verifying a submitted document's authenticity, not a single named regulatory process[17][18] |
| "Online verification" | An umbrella phrase for any remote, internet-based identity-check step, which can include eKYC/Aadhaar authentication, document upload and OCR extraction, selfie/liveness checks, or database cross-checks[17][18] | No formal regulatory definition in Indian KYC law[1][2] |
“Online verification” doesn’t appear in RBI’s KYC Master Direction as a defined process the way e-KYC and the Digital KYC Process do[1][2]. In market and industry usage, including on pages that rank for the term, it functions as a broad label for several distinct underlying methods rather than one specific regulatory process[17][18]. Document verification is closer to a technique than a compliance category: it validates the document presented, using OCR and automated checks where available, but that’s a separate function from authenticating the person against a live government database the way e-KYC does[17][18].
How eKYC Data Is Treated Under DPDP
Under India’s Digital Personal Data Protection (DPDP) Act, 2023, and its Rules, KYC data collected to satisfy a specific regulatory obligation, such as RBI/PMLA-mandated identity verification, doesn’t require separate DPDP consent for that collection, because the legal basis is the regulatory obligation itself. Any subsequent use of that same eKYC/KYC data for a different purpose, such as marketing segmentation, location analytics, or an alternative credit-scoring model not required by the regulatory mandate, requires its own specific, informed consent under the DPDP Act’s purpose-limitation principle[19][20].
The DPDP Rules, 2025 were notified by the Ministry of Electronics and Information Technology (MeitY) on 13 November 2025, on a staggered enforcement timeline: initial provisions (definitions, Data Protection Board setup) took effect 14 November 2025, consent-manager provisions take effect 13 November 2026, and full compliance obligations, including most operational data-fiduciary requirements, take effect 13 May 2027[21][22].
Retention obligations sit alongside DPDP rather than being replaced by it. KYC records collected via eKYC or any other method must still be retained per existing regulatory minimums: RBI’s KYC framework requires records be kept for at least five years after the end of the customer relationship, and PMLA-related transaction records for ten years, independent of DPDP’s own data-minimisation and retention-limitation principles[19].
Frequently Asked Questions
What the Adoption Numbers Actually Mean for Onboarding Decisions
Read together, November 2025’s figures show e-KYC growing faster than Aadhaar authentication overall: e-KYC transactions rose more than 24% year-on-year against 8.47% for total authentication volume, and e-KYC accounted for roughly a fifth of all Aadhaar authentication transactions that month (47.19 crore of 231 crore)[13][14]. This suggests eKYC’s share of India’s total Aadhaar-authentication footprint is expanding, not just its absolute volume.
That growth doesn’t change what eKYC is under RBI’s rules, though. A fast-growing OTP-based e-KYC flow is still a non-face-to-face method, and accounts opened through it still carry EDD status until upgraded[7][9][2][3][4]. The practical implication for a compliance or product team is that transaction-volume growth is a weak proxy for compliance exposure. The operational metric worth tracking is the share of eKYC-onboarded accounts that have actually been upgraded to a face-to-face-equivalent method over time.
The document-verification and online-verification landscape adds a related implication. Because “online verification” carries no RBI definition and covers several distinct underlying methods[1][2][17][18], a vendor pitch or RFP response that uses the phrase needs translating into RBI’s actual categories before it can be evaluated for compliance purposes. A claim of “online verification” could mean Aadhaar e-KYC, document OCR, or a database cross-check, and each of those carries a different face-to-face/NFTF status under RBI’s rules[7][9][2][3][4]. The practical implication is that the specific RBI-recognised method a vendor’s product actually runs, and the onboarding status that method produces, matters more than what marketing label is used to describe it.
How KYCKART Helps
KYCKART runs Aadhaar OTP, biometric, and offline e-KYC verification alongside Digital KYC Process and V-CIP capture, so an onboarding flow can be built around the specific RBI-recognised method a product actually needs rather than a generic “online verification” label. Speak with our team to see how it fits your onboarding stack. Regulatory compliance remains the responsibility of the regulated entity.
This piece summarises publicly available RBI, UIDAI, and MeitY material for informational purposes. It isn’t legal advice, and specific thresholds, entity-level obligations, and current sector-specific Master Direction text should be confirmed directly against the applicable regulatory instrument for your institution type.
Bhanujeet Choudhary
Head of Compliance, KYCKART
Published August 14, 2026
KYCKART Intelligence
Run the Right eKYC Mode for the Onboarding You’re Actually Doing
KYCKART supports Aadhaar OTP, biometric, and offline e-KYC verification alongside the Digital KYC Process and V-CIP, so your onboarding flow runs the method your compliance status actually requires. Speak with our team to see how it fits your stack.
Explore Onboarding Solutionsarrow_forward