What is e-KYC?
e-KYC is the completion of customer identification using electronic records fetched from an authoritative source, rather than from photocopies handed over by the customer. In India the term most often refers to Aadhaar-based e-KYC, where UIDAI returns a digitally signed identity record after the resident authenticates, and to document e-KYC through DigiLocker.
The distinction that matters is provenance. A scanned document proves only that a file exists; an electronic record signed by the issuing authority proves the data came from the registry that created it, and has not been altered in transit.
The main forms of e-KYC
- OTP-based Aadhaar e-KYC — the resident consents and authenticates with a one-time password sent to the registered mobile number.
- Biometric Aadhaar e-KYC — authentication with a fingerprint or iris scan on certified capture hardware, typically at a branch or assisted point.
- Offline or paperless Aadhaar — the resident downloads a digitally signed XML or shares a secure QR code, which the entity validates locally without calling UIDAI.
- DigiLocker document fetch — the customer authorises release of an issuer-signed document such as a driving licence, PAN or education certificate.
- CKYC download — retrieving an existing KYC record from the Central KYC Registry using the customer’s identifier.
Who can use Aadhaar authentication
Direct Aadhaar authentication is not open to everyone. Access is restricted to entities permitted under the Aadhaar Act and its notifications, so a large share of platforms build their flows on offline Aadhaar, DigiLocker and registry lookups instead. This is a common source of confusion in product planning: “we will just do Aadhaar e-KYC” is a licensing question before it is an engineering one.
Limits on OTP-based e-KYC accounts
Where OTP-based Aadhaar e-KYC is used to open an account remotely, the RBI’s KYC Master Direction attaches conditions rather than treating it as equivalent to full verification. Such accounts carry caps on aggregate balance and on total credits in a financial year, and must be converted to a fully KYC-compliant account within a defined period, after which further transactions are restricted. Product teams should design for that conversion step from the outset rather than discovering it when accounts start freezing.
What e-KYC does not settle
e-KYC confirms identity. It does not confirm that a bank account belongs to that identity, that an employer relationship exists, or that a vehicle or utility connection is genuinely the customer’s. Those need separate lookups against the relevant registry, which is why most onboarding stacks combine an identity step with two or three attribute checks.
Related terms
- KYC (Know Your Customer)
- DigiLocker
- Video KYC (V-CIP)
- CKYC and the Central KYC Registry
- OTP (One-Time Password)
Verify it with Veriqos
The document and attribute checks that surround an e-KYC flow are available individually:
- Digilocker Verification API — Verify your customers’ government documents instantly through Digilocker with Veriqos’ Digilocker Verification API — real-time verification through the customer’s Digilocker account.
- SMS OTP Verification API — Secure user logins and verify phone numbers instantly with Veriqos’ SMS OTP Verification API — for account creation, transactions, or digital onboarding.
- Bank Account Verification API — Instantly confirm the authenticity of any bank account with Veriqos’ Bank Account Verification API — account number, holder name, and status in real time.
See how these checks are applied in Fintech & Digital Lending, Banks & NBFCs.
← Back to the verification glossary
This entry explains how the check works in practice. It is general information, not legal or compliance advice — confirm current requirements against the applicable regulation.