In brief: this KYC API integration checklist lists the decisions to make before writing any integration code, from which checks you need to how you will store the results. Work through the KYC API integration checklist with engineering, product and compliance together.
On this page
A practical pre-integration checklist for teams evaluating or building a KYC/identity-verification flow in India — what to decide before you write any integration code.
1. Which checks does your flow actually need?
- Identity: PAN and/or Aadhaar verification — decide whether you need basic verification or deeper checks (demographic match, identity match against other records).
- Document capture: if customers upload document photos, you need OCR extraction before verification, not after.
- Bank account: penny drop vs penny-less — penny-less avoids an actual transaction, penny drop is the more established method some risk teams still prefer.
- Business (KYB): if you onboard businesses, decide which of GST, CIN, or Udyam status you actually need to check — see the business verification API guide.
- Vehicle: only relevant for lending or insurance tied to a vehicle — chassis-to-RC and driving licence checks.

2. What’s your regulatory tier?
- If you’re a regulated entity under RBI’s KYC Master Direction, confirm whether OTP-based eKYC’s ₹1 lakh/year cap is workable for your product, or whether you need Video KYC (V-CIP) to remove it.
- Know your CKYC/CERSAI upload obligation and timeline (3 working days of account opening) before you finalize your onboarding flow’s data-handling steps.
- If onboarding businesses, confirm your UBO (beneficial ownership) disclosure requirement — this affects what KYB data you need to collect, not just verify.

3. Data handling before you integrate
- If you process Aadhaar numbers, confirm your storage design meets the Aadhaar Vault requirement — numbers stored only in a vault, referenced elsewhere by token.
- Map your data flow against the DPDP Act‘s consent and purpose-limitation requirements — KYC data is personal data.
- Decide your re-KYC cadence by customer risk tier before launch, not after your first audit.

4. Integration sequencing
- Document upload/capture → OCR extraction (if applicable)
- Identity verification (PAN/Aadhaar) against the extracted or entered fields
- Business verification (GST/CIN/Udyam) if onboarding a business entity
- Bank account verification for payout/mandate setup
- Sanctions/watchlist screening as a parallel check, not a blocking sequential step
Running these as parallel API calls where possible (rather than one long sequential chain) is what keeps real-time onboarding actually real-time.

5. Before you go live
- Test against real document formats your users will actually submit (low-light phone photos, not just clean scans).
- Confirm your fallback path when a check returns “not found” or “mismatch” rather than a clean pass/fail — re-collection flow, manual review queue, or decline.
- Confirm who owns re-verification when a document expires (especially driving licences and passports).
Ready to test this against a real integration? Get a free sandbox key and start testing the checks above directly.
Get Sandbox AccessSee how Veriqos pricing works before requesting a quote.
Using this checklist with your team
Share the KYC API integration checklist with product, engineering and compliance before you start, so everyone agrees on which checks are needed and why. Revisit the KYC API integration checklist after your first month live to see which steps need adjusting.
Keep it in the same place as your technical documentation so it stays current.
More about the KYC API Integration Checklist
Once you have worked through the KYC API Integration Checklist, explore our PAN Verification API and Aadhaar Verification API, or talk to our team. For the official KYC rules, see the RBI’s Master Direction on KYC.