← Back to Insights
Backing Verifiable Credentials with Aadhaar: A Technical Overview for FI Architects
By AssureLocker Team

Backing Verifiable Credentials with Aadhaar: A Technical Overview for FI Architects

Aadhaar offline XML, the new Aadhaar Verifiable Credential and DigiLocker already give FI architects issuer-signed identity at the point of capture. The unsolved part is reusing that verification — with its provenance intact — so the next lender trusts it instead of rebuilding the pipeline.

A borrower walks into her third lender in eighteen months. She has already proven who she is — twice. The first time in 2023, opening a current account, she generated an Aadhaar offline XML, sat through a video call, and uploaded a PAN. The second time, a co-lending NBFC pulled her Central KYC record, then re-ran the whole liveness check anyway because it could not see how the first lender had verified her. Now, at the third, an architect somewhere is about to build the same pipeline a fourth time. Nothing about her identity has changed. The cost of proving it just keeps getting re-incurred.

For FI architects, this is the quiet tax that never shows up as a line item. Roughly 60% of digital onboarding cost sits in KYC, credit checks and regulatory approvals (Celusion). The technology to verify identity from source is excellent and getting better. What is missing is a way to reuse a verification with its provenance intact — so the second lender trusts the first lender's work without redoing it.

What Aadhaar now gives you at the point of capture

The raw materials for source-verified identity are stronger than most architecture reviews assume.

Aadhaar offline / paperless e-KYC lets a resident generate a UIDAI-signed XML containing name, date of birth, gender, address and photo, share-code protected, with no biometric authentication and no Aadhaar number exposed. Because it carries UIDAI's digital signature, an FI can validate the signature offline and treat the attributes as source-verified rather than user-asserted.

The Aadhaar Verifiable Credential (AVC) is the significant 2025 development. The Aadhaar (Authentication and Offline Verification) Amendment Regulations, 2025 substituted Regulation 3A to formally recognise multiple offline modes — QR-code verification, e-Aadhaar, paperless offline e-KYC and, newly, AVC verification (Mondaq). The AVC is a digitally signed, tamper-evident document issued solely by UIDAI, encapsulating minimal attributes — name, date of birth, photo, last four digits of the Aadhaar number. It is, in effect, a government-issued verifiable credential built for selective disclosure.

DigiLocker supplies the same pattern across the wider document estate — driving licence, PAN, education records — via its Authorised Partner API, which returns issued-document lists with issuer IDs and structured certificate data. At 51.3 crore users and over 5.6 billion issued documents (EveryCred), it is one of the largest issuer-signed credential estates in the world.

So the point-of-capture problem is largely solved. An architect in 2026 can obtain minimal, issuer-signed, cryptographically verifiable identity attributes without warehousing raw Aadhaar data at all.

Where the residual gap actually is

The gap is not getting a verified credential. It is what happens after.

Once your FI verifies a customer, that proof lives inside your systems. There is no portable object the next lender can independently trust. CKYC was built to close exactly this — and it helps: aggregated data from 150 BFSI firms showed CKYC sync cutting verification from 4:50 to 2:44 per customer, and Budget 2025 made CKYC uploads free (Signzy). CKYCRR 2.0 pushes further on data quality and real-time updates.

But CKYC is a records registry, not a chain of custody. Many records are still scanned PDFs, updated in isolation with no synchronisation between institutions (Shufti). Fetching another RE's record is consent-gated and gives you data — not a provable account of how that data was verified, by whom, against which source, on what date. And under the RBI (KYC) Amendment Directions, 2025 (in force 12 June 2025, implementation by 1 January 2026), the periodic re-KYC and audit-trail obligations still land on the RE relying on the record (Mondaq). If you cannot see the provenance, you re-verify to be safe. And so the tax recurs.

The architecture that closes it

The design principle is straightforward: bind the issuer-signed credential to a durable, tamper-evident registry record that any authorised relying party can check independently — without your FI ever exposing the underlying document or the customer re-consenting to a fresh pull.

Concretely, an FI architect wants three properties layered onto Aadhaar/DigiLocker capture:

  • Selective disclosure — share only the attributes a given check needs (a lender confirming name-and-DOB match should never receive a full address dump).
  • Verifiable provenance — a check that returns who verified this, against which issuer-signed source, when — as a signed, non-repudiable record, not a screenshot.
  • Scoped reuse — the second internal team, or an authorised partner in the same lending arrangement, verifies in seconds against the registered record instead of rebuilding the pipeline.

A necessary honesty: reuse today is lender-scoped — within your institution and its explicit arrangements. Genuine cross-sector portability of an identity credential is regulation-gated and remains an upside, not a claim.

Where AssureLocker fits

AssureVerifID is source-verified reusable identity built on exactly this pattern — DigiKYC for individuals, DigiKYB for businesses — capturing from Aadhaar, DigiLocker and other issuer-signed sources, then producing a selectively disclosable credential with checkable provenance on tamper-evident registry infrastructure. It never lends, prices or decides credit; it makes the lender's own judgement fast and provable, and lets a verification be trusted a second time instead of paid for twice.

For FI architects tired of building the fourth identical KYC pipeline, that is the difference worth designing for.

Explore AssureVerifID and reusable KYB →

About AssureLocker

AssureLocker is the independent evidence-and-control layer for regulated lending — starting with co-lending. Across four suites — AssureCLA (co-lending assurance), AssureSCF (supply-chain finance), AssureVerifID (reusable identity) and AssureLens(credit-velocity intelligence), on one neutral layer — we make a lender’s controls and evidence fast, reproducible and governed. We are a technology provider: we never lend, price, or decide credit.

Read more on the AssureLocker blog · assurelocker.com