KYC API for NBFC: Complete RBI Compliance Checklist

A complete compliance checklist for NBFCs using KYC APIs — RBI Master Directions, data residency, audit trails, consent requirements, and regulator-ready documentation.

KYC compliance is the single biggest legal risk for NBFCs operating in India. The rules are detailed, the penalties are severe, and regulators do check. For NBFCs that use third-party KYC APIs — which is now the norm — the compliance surface area is even bigger because you're responsible for your vendor's behavior too.

This guide is a complete compliance checklist for NBFCs using KYC APIs. It's written for compliance officers, CTOs, and founders who need to know exactly what to verify before going live with an API.

Nothing here is legal advice — always consult with your compliance team and legal counsel. But this is the checklist we've seen hundreds of NBFCs use successfully.

Introduction

Under RBI's KYC Master Directions, 2016 (as amended), every NBFC must:

  • Conduct Customer Due Diligence (CDD) for all customers before establishing a business relationship
  • Apply Enhanced Due Diligence (EDD) for high-risk customers
  • Verify identity using specified documents and processes
  • Maintain records for a minimum of 5 years
  • Report suspicious transactions to FIU-IND
  • Ensure data is processed within Indian data centres

If you're using a third-party KYC API to handle any of these, the API provider becomes part of your compliance chain — and you're still ultimately responsible for the outcome.

⚠️
RBI's stance on outsourcing: The NBFC remains fully responsible for KYC compliance even when using third-party services. "The vendor did it wrong" is not a valid defense. Vetting your provider is a core part of your compliance obligation.

The Regulatory Framework

Compliance for NBFC KYC sits at the intersection of several regulations:

1. RBI KYC Master Directions, 2016

The primary framework. Defines:

  • Minimum KYC documentation requirements
  • Customer identification procedures (CIP)
  • Ongoing due diligence obligations
  • Record keeping and retention
  • Reporting requirements

2. Prevention of Money Laundering Act (PMLA), 2002

Defines the AML obligations that KYC supports. Includes suspicious transaction reporting (STR) requirements to FIU-IND.

3. Aadhaar Act, 2016 (as amended) and UIDAI regulations

Defines the legal basis and processes for Aadhaar-based verification. Key requirements include user consent, OTP-based verification for e-KYC, and restrictions on storage of Aadhaar numbers.

4. Digital Personal Data Protection Act (DPDP), 2023

Defines consent, purpose limitation, and data principal rights for all personal data — including KYC data.

5. RBI Master Direction on Digital Lending, 2022

If you're a lending NBFC, this direction adds requirements on digital onboarding, KYC via V-CIP, and disclosure obligations.

Complete Compliance Checklist

Use this checklist before going live with any KYC API integration. Every item is required for RBI compliance.

✓
1. Customer consent captured and stored

Explicit consent must be obtained from the customer for KYC verification. For Aadhaar, consent must be documented per Aadhaar Act requirements. Store consent with timestamp, IP, device info, and the exact consent text shown.

✓
2. Aadhaar verification via OTP (not biometric)

OTP-based Aadhaar e-KYC is the standard for NBFC onboarding. Biometric e-KYC requires certification for V-CIP workflows and is often unnecessary for standard onboarding. OTP is triggered to the mobile linked with Aadhaar.

✓
3. PAN verification against authoritative source

PAN must be verified against NSDL or Protean (formerly NSDL) databases — not against cached or third-party copies. PAN verification confirms the PAN number is valid and the name matches.

✓
4. Name matching with documented tolerance

Verify that the name returned by the API matches the customer-provided name. Document your match tolerance (exact, partial, fuzzy) and the reasoning. Fuzzy matching must still reject genuine mismatches.

✓
5. Face matching (for digital onboarding)

RBI requires liveness detection and face matching for digital onboarding. This is done during V-CIP (Video-based Customer Identification Process) or through certified liveness checks alongside Aadhaar verification.

✓
6. Data processed within Indian data centres

Verify that your API provider processes all KYC data within Indian data centres. Ask for a written confirmation. Cross-border transfer of KYC data is prohibited without explicit regulatory approval.

✓
7. Audit trail for every verification

Every KYC verification must be logged with: timestamp, method used, customer ID, verification result, name match status, and the specific data returned. Logs must be exportable and readable by regulators.

✓
8. Record retention for minimum 5 years

KYC records must be retained for at least 5 years after the business relationship ends. Some records (suspicious transactions, AML-related) must be retained longer. Retention applies to both raw data and derived audit trails.

✓
9. Aadhaar number not stored in full

Per UIDAI regulations, Aadhaar numbers must not be stored in plain text. Use a reference token or store only the last 4 digits. The reference token must be traceable for regulatory purposes.

✓
10. Vendor due diligence on the API provider

Document your vendor evaluation: API provider's certifications, data residency guarantees, uptime SLAs, security posture, and regulatory standing. RBI expects NBFCs to perform vendor due diligence and retain documentation.

✓
11. Clear escalation for verification failures

Document what happens when verification fails. Not every failure requires account rejection — some can be escalated to manual review, additional documentation, or V-CIP. Have a documented policy.

✓
12. Ongoing due diligence process

KYC isn't one-time. RBI requires ongoing monitoring based on risk category. Document your process for periodic re-verification, risk-based monitoring, and updating customer records.

✓
13. Suspicious Transaction Reporting (STR)

Have a documented process for identifying and reporting suspicious transactions to FIU-IND. KYC data feeds this process — the audit trail must support STR filings.

✓
14. Board-approved KYC policy

RBI requires NBFCs to have a board-approved KYC policy. The policy must cover customer acceptance, risk categorization, and monitoring. Vendor selection (including API providers) falls under this policy.

✓
15. Regular KYC compliance audits

Conduct regular internal audits of KYC compliance, including API-based verification workflows. Document findings and remediation. RBI can request audit reports during inspections.

KYC API Technical Requirements

Beyond the checklist above, here's what your KYC API integration must technically support:

Requirement Why It Matters
HTTPS with TLS 1.3 All KYC data must be transmitted over encrypted channels. TLS 1.3 is the current standard.
API key authentication Strong authentication prevents unauthorised access to KYC endpoints.
IP whitelisting Restricts API calls to your infrastructure's IPs, preventing key misuse.
Request/response logging Every API call must be logged with the full request and response for audit purposes.
Webhook support For async KYC flows and bulk verification, webhooks ensure you don't miss results.
Bulk verification For re-KYC and mass verification workflows, batch endpoints reduce cost and complexity.
Structured error codes Specific error codes let you handle edge cases (name mismatch, account inactive) precisely.
Data masking on response Sensitive fields must be masked per RBI and UIDAI standards.
Uptime SLA ≥ 99.9% KYC is a hard dependency for customer onboarding — downtime blocks revenue.
💡
Ask for the API provider's compliance documentation. A compliant provider should be able to hand you: data residency confirmation, security certifications, SLA documentation, and a sample audit trail export. Our Verification API provides all of these.

Data Residency & Storage

Data residency is non-negotiable for NBFC KYC. Here's what to verify:

Where is KYC data processed?

The API provider must process all KYC data within Indian data centres. This includes:

  • Request processing and validation
  • Database queries against UIDAI, NSDL, MoRTH, etc.
  • Response assembly
  • Audit logging

Where is KYC data stored?

  • Raw Aadhaar data — Must not be stored. Use tokens or references only.
  • PAN data — Can be stored within India; retention as per PMLA (5+ years).
  • Audit logs — Must be stored in India for the retention period.
  • Derived verification status — Can be stored as part of the customer profile.

Is data encrypted at rest?

Yes — and you should verify this with your provider. KYC data at rest must be encrypted. AES-256 is the current standard.

⚠️
Beware of global API providers. Some globally popular API providers route data through Singapore, the US, or Europe. This violates RBI data localisation requirements. Always verify where data is processed and stored.

Audit Trails & Documentation

Audit trails are where most NBFCs get tripped up. RBI inspections frequently cite insufficient audit trails as a KYC compliance gap.

What every KYC verification must log

  • Timestamp — Precise date and time (to the second)
  • Customer ID — The internal ID of the customer being verified
  • Method used — Aadhaar OTP, PAN, DL, etc.
  • Consent reference — Link to the customer's recorded consent
  • Request ID — From the API provider, for tracing
  • Verification result — Success, failure, or partial
  • Name match status — Exact, partial, or none
  • Data returned — The specific fields returned by the API
  • Analyst ID — If manually reviewed, who reviewed it

How long to retain

Minimum 5 years from the end of the business relationship. For AML-related records, longer — up to 10 years in certain cases. Retain everything until you're certain no regulatory inquiry will ever need it.

Exportability

Audit trails must be exportable in a format regulators can read. CSV is generally accepted. JSON is becoming more common. Whatever format you choose, ensure it's complete — partial exports won't satisfy an inspection.

✅
Build the audit trail export as a feature, not a script. When RBI requests documentation, they expect it within days — not weeks. Having a one-click audit trail export for any date range is a compliance superpower.

Common Compliance Mistakes

These are the mistakes we've seen NBFCs make most often — and the ones that consistently come up in inspections:

1. Using cached PAN or Aadhaar data

Some providers return cached results instead of querying authoritative sources in real time. This is non-compliant. Every KYC verification must query the source database. Verify your provider queries real-time.

2. Storing full Aadhaar numbers

UIDAI prohibits storing full Aadhaar numbers in plain text. Store only tokens or last-4-digits. The reference token must be traceable through the API provider.

3. No documented consent process

Consent must be explicit, documented, and retrievable. A checkbox that says "I agree to KYC" is not sufficient. Document the exact consent text, timestamp, IP, and device.

4. Missing audit trails for rejected verifications

Many NBFCs log successful verifications but skip failed ones. Failed verifications are just as important for compliance — they show you're actively screening.

5. Cross-border data processing

Even if your provider is Indian, their sub-processors might not be. Verify the complete data flow, including any third-party databases or services they use.

6. No vendor due diligence documentation

RBI expects NBFCs to document why they chose a specific API provider. Vendor evaluation forms, security reviews, and compliance checks must be documented and retained.

7. One-time KYC without ongoing monitoring

KYC is not a one-time event. RBI requires ongoing monitoring based on the customer's risk category. Document your monitoring process and frequency.

Conclusion

KYC compliance for NBFCs is complex — but it's tractable with the right systems, documentation, and API provider. Key takeaways:

  • You're ultimately responsible — even when using third-party APIs
  • Data residency is non-negotiable — all KYC data within Indian data centres
  • Audit trails are where most NBFCs fail — log everything, retain for 5+ years, ensure exportability
  • Consent must be explicit and documented — not a generic checkbox
  • Ongoing monitoring is required — KYC isn't a one-time event
  • Vendor due diligence is your responsibility — document it

API Express is designed for compliance-first NBFCs. Our Verification API and UPI / Bank Verification API provide:

  • All processing within Indian data centres
  • Real-time verification against authoritative sources (UIDAI, NSDL, NPCI)
  • Aadhaar OTP-based verification with consent tracking
  • Complete audit trails, exportable in any format
  • 99.9% uptime SLA with formal commitment
  • Support from a team that understands NBFC compliance

If you're evaluating API providers for your NBFC, we'd be happy to walk you through our compliance documentation. Reach out to our team — we respond within 4 hours on business days.

Or start with a free account and see how the platform works for your use case. 1,000 free API calls, no credit card required.

AE
API Express Team
Engineering & Product

The API Express engineering and product team writes about API integration, developer workflows, and building for the Indian B2B market. We've processed over 10 million API calls for 500+ businesses.

Ready to comply?

Get RBI-Compliant KYC APIs for Your NBFC

Start free with 1,000 API calls. All processing within Indian data centres. Complete audit trails. 99.9% uptime SLA. No credit card required.

RBI-compliant India data residency Full audit trails Live in under a day