KYC compliance is the single biggest legal risk for NBFCs operating in India. The rules are detailed, the penalties are severe, and regulators do check. For NBFCs that use third-party KYC APIs — which is now the norm — the compliance surface area is even bigger because you're responsible for your vendor's behavior too.
This guide is a complete compliance checklist for NBFCs using KYC APIs. It's written for compliance officers, CTOs, and founders who need to know exactly what to verify before going live with an API.
Nothing here is legal advice — always consult with your compliance team and legal counsel. But this is the checklist we've seen hundreds of NBFCs use successfully.
Introduction
Under RBI's KYC Master Directions, 2016 (as amended), every NBFC must:
- Conduct Customer Due Diligence (CDD) for all customers before establishing a business relationship
- Apply Enhanced Due Diligence (EDD) for high-risk customers
- Verify identity using specified documents and processes
- Maintain records for a minimum of 5 years
- Report suspicious transactions to FIU-IND
- Ensure data is processed within Indian data centres
If you're using a third-party KYC API to handle any of these, the API provider becomes part of your compliance chain — and you're still ultimately responsible for the outcome.
The Regulatory Framework
Compliance for NBFC KYC sits at the intersection of several regulations:
1. RBI KYC Master Directions, 2016
The primary framework. Defines:
- Minimum KYC documentation requirements
- Customer identification procedures (CIP)
- Ongoing due diligence obligations
- Record keeping and retention
- Reporting requirements
2. Prevention of Money Laundering Act (PMLA), 2002
Defines the AML obligations that KYC supports. Includes suspicious transaction reporting (STR) requirements to FIU-IND.
3. Aadhaar Act, 2016 (as amended) and UIDAI regulations
Defines the legal basis and processes for Aadhaar-based verification. Key requirements include user consent, OTP-based verification for e-KYC, and restrictions on storage of Aadhaar numbers.
4. Digital Personal Data Protection Act (DPDP), 2023
Defines consent, purpose limitation, and data principal rights for all personal data — including KYC data.
5. RBI Master Direction on Digital Lending, 2022
If you're a lending NBFC, this direction adds requirements on digital onboarding, KYC via V-CIP, and disclosure obligations.
Complete Compliance Checklist
Use this checklist before going live with any KYC API integration. Every item is required for RBI compliance.
Explicit consent must be obtained from the customer for KYC verification. For Aadhaar, consent must be documented per Aadhaar Act requirements. Store consent with timestamp, IP, device info, and the exact consent text shown.
OTP-based Aadhaar e-KYC is the standard for NBFC onboarding. Biometric e-KYC requires certification for V-CIP workflows and is often unnecessary for standard onboarding. OTP is triggered to the mobile linked with Aadhaar.
PAN must be verified against NSDL or Protean (formerly NSDL) databases — not against cached or third-party copies. PAN verification confirms the PAN number is valid and the name matches.
Verify that the name returned by the API matches the customer-provided name. Document your match tolerance (exact, partial, fuzzy) and the reasoning. Fuzzy matching must still reject genuine mismatches.
RBI requires liveness detection and face matching for digital onboarding. This is done during V-CIP (Video-based Customer Identification Process) or through certified liveness checks alongside Aadhaar verification.
Verify that your API provider processes all KYC data within Indian data centres. Ask for a written confirmation. Cross-border transfer of KYC data is prohibited without explicit regulatory approval.
Every KYC verification must be logged with: timestamp, method used, customer ID, verification result, name match status, and the specific data returned. Logs must be exportable and readable by regulators.
KYC records must be retained for at least 5 years after the business relationship ends. Some records (suspicious transactions, AML-related) must be retained longer. Retention applies to both raw data and derived audit trails.
Per UIDAI regulations, Aadhaar numbers must not be stored in plain text. Use a reference token or store only the last 4 digits. The reference token must be traceable for regulatory purposes.
Document your vendor evaluation: API provider's certifications, data residency guarantees, uptime SLAs, security posture, and regulatory standing. RBI expects NBFCs to perform vendor due diligence and retain documentation.
Document what happens when verification fails. Not every failure requires account rejection — some can be escalated to manual review, additional documentation, or V-CIP. Have a documented policy.
KYC isn't one-time. RBI requires ongoing monitoring based on risk category. Document your process for periodic re-verification, risk-based monitoring, and updating customer records.
Have a documented process for identifying and reporting suspicious transactions to FIU-IND. KYC data feeds this process — the audit trail must support STR filings.
RBI requires NBFCs to have a board-approved KYC policy. The policy must cover customer acceptance, risk categorization, and monitoring. Vendor selection (including API providers) falls under this policy.
Conduct regular internal audits of KYC compliance, including API-based verification workflows. Document findings and remediation. RBI can request audit reports during inspections.
KYC API Technical Requirements
Beyond the checklist above, here's what your KYC API integration must technically support:
| Requirement | Why It Matters |
|---|---|
| HTTPS with TLS 1.3 | All KYC data must be transmitted over encrypted channels. TLS 1.3 is the current standard. |
| API key authentication | Strong authentication prevents unauthorised access to KYC endpoints. |
| IP whitelisting | Restricts API calls to your infrastructure's IPs, preventing key misuse. |
| Request/response logging | Every API call must be logged with the full request and response for audit purposes. |
| Webhook support | For async KYC flows and bulk verification, webhooks ensure you don't miss results. |
| Bulk verification | For re-KYC and mass verification workflows, batch endpoints reduce cost and complexity. |
| Structured error codes | Specific error codes let you handle edge cases (name mismatch, account inactive) precisely. |
| Data masking on response | Sensitive fields must be masked per RBI and UIDAI standards. |
| Uptime SLA ≥ 99.9% | KYC is a hard dependency for customer onboarding — downtime blocks revenue. |
Data Residency & Storage
Data residency is non-negotiable for NBFC KYC. Here's what to verify:
Where is KYC data processed?
The API provider must process all KYC data within Indian data centres. This includes:
- Request processing and validation
- Database queries against UIDAI, NSDL, MoRTH, etc.
- Response assembly
- Audit logging
Where is KYC data stored?
- Raw Aadhaar data — Must not be stored. Use tokens or references only.
- PAN data — Can be stored within India; retention as per PMLA (5+ years).
- Audit logs — Must be stored in India for the retention period.
- Derived verification status — Can be stored as part of the customer profile.
Is data encrypted at rest?
Yes — and you should verify this with your provider. KYC data at rest must be encrypted. AES-256 is the current standard.
Audit Trails & Documentation
Audit trails are where most NBFCs get tripped up. RBI inspections frequently cite insufficient audit trails as a KYC compliance gap.
What every KYC verification must log
- Timestamp — Precise date and time (to the second)
- Customer ID — The internal ID of the customer being verified
- Method used — Aadhaar OTP, PAN, DL, etc.
- Consent reference — Link to the customer's recorded consent
- Request ID — From the API provider, for tracing
- Verification result — Success, failure, or partial
- Name match status — Exact, partial, or none
- Data returned — The specific fields returned by the API
- Analyst ID — If manually reviewed, who reviewed it
How long to retain
Minimum 5 years from the end of the business relationship. For AML-related records, longer — up to 10 years in certain cases. Retain everything until you're certain no regulatory inquiry will ever need it.
Exportability
Audit trails must be exportable in a format regulators can read. CSV is generally accepted. JSON is becoming more common. Whatever format you choose, ensure it's complete — partial exports won't satisfy an inspection.
Common Compliance Mistakes
These are the mistakes we've seen NBFCs make most often — and the ones that consistently come up in inspections:
1. Using cached PAN or Aadhaar data
Some providers return cached results instead of querying authoritative sources in real time. This is non-compliant. Every KYC verification must query the source database. Verify your provider queries real-time.
2. Storing full Aadhaar numbers
UIDAI prohibits storing full Aadhaar numbers in plain text. Store only tokens or last-4-digits. The reference token must be traceable through the API provider.
3. No documented consent process
Consent must be explicit, documented, and retrievable. A checkbox that says "I agree to KYC" is not sufficient. Document the exact consent text, timestamp, IP, and device.
4. Missing audit trails for rejected verifications
Many NBFCs log successful verifications but skip failed ones. Failed verifications are just as important for compliance — they show you're actively screening.
5. Cross-border data processing
Even if your provider is Indian, their sub-processors might not be. Verify the complete data flow, including any third-party databases or services they use.
6. No vendor due diligence documentation
RBI expects NBFCs to document why they chose a specific API provider. Vendor evaluation forms, security reviews, and compliance checks must be documented and retained.
7. One-time KYC without ongoing monitoring
KYC is not a one-time event. RBI requires ongoing monitoring based on the customer's risk category. Document your monitoring process and frequency.
Conclusion
KYC compliance for NBFCs is complex — but it's tractable with the right systems, documentation, and API provider. Key takeaways:
- You're ultimately responsible — even when using third-party APIs
- Data residency is non-negotiable — all KYC data within Indian data centres
- Audit trails are where most NBFCs fail — log everything, retain for 5+ years, ensure exportability
- Consent must be explicit and documented — not a generic checkbox
- Ongoing monitoring is required — KYC isn't a one-time event
- Vendor due diligence is your responsibility — document it
API Express is designed for compliance-first NBFCs. Our Verification API and UPI / Bank Verification API provide:
- All processing within Indian data centres
- Real-time verification against authoritative sources (UIDAI, NSDL, NPCI)
- Aadhaar OTP-based verification with consent tracking
- Complete audit trails, exportable in any format
- 99.9% uptime SLA with formal commitment
- Support from a team that understands NBFC compliance
If you're evaluating API providers for your NBFC, we'd be happy to walk you through our compliance documentation. Reach out to our team — we respond within 4 hours on business days.
Or start with a free account and see how the platform works for your use case. 1,000 free API calls, no credit card required.