← Back to Insights
The Business Case for OID4VP in Financial Services
By AssureLocker Team

The Business Case for OID4VP in Financial Services

OID4VP hit Final 1.0 in July 2025 — a frozen, format-agnostic standard for the moment a customer presents a verified credential with consent. Here is the cost, UX, and compliance case for Indian lenders, and the residual gap it closes that CKYCRR does not.

A borrower opens an NBFC's app at 11pm to apply for a personal loan. She is three screens in when it asks her to photograph her PAN, upload an address proof, and book a video call during business hours — the same documents she submitted to a different lender four months ago, verified against the same registries, unchanged since. She closes the app.

She has just joined a statistic. Industry digital-KYC drop-off runs 20–35%, and video-KYC abandonment climbs to 30–45%, according to onboarding-cost analyses (UpGrowth). The lender pays for that twice: once in the acquisition it just lost, and again on the applicants who do finish — a completed video KYC costs roughly ₹50–150 against ₹3–5 for Aadhaar eKYC. The frustrating part is that her data already exists, is already verified, and is reusable in principle. What is missing is a clean, standard way for her to present it.

What OID4VP actually standardises

OpenID for Verifiable Presentations (OID4VP) is the specification that fills exactly that gap. It reached Final 1.0 status at the OpenID Foundation on 9 July 2025 (OpenID Foundation), which matters commercially: a Final spec is frozen, carries IP protections for implementers, and is not subject to further breaking changes.

OID4VP is built on OAuth 2.0 and is deliberately format-agnostic — it carries SD-JWT VC, ISO mdoc, or W3C Verifiable Credentials over the same flow (OpenID Foundation spec). What it standardises is the presentation moment: how a wallet the holder controls presents a verified credential to a verifier (the relying party), with explicit consent, selective disclosure of only the fields requested, and a cryptographic proof the verifier can check independently. No screen-scraping, no re-upload, no fresh document collection for data that was verified once already.

Why this is a now problem, not a someday problem

The regulatory clock is already running elsewhere. Under eIDAS 2.0, private relying parties performing Strong Customer Authentication in the EU must accept the EU Digital Identity Wallet — which uses OID4VP for presentation — with a deadline landing around December 2027 for financial institutions (walt.id). India's own public infrastructure is quietly converging on the same primitives: DigiLocker documents are being wrapped in a W3C Verifiable Credential envelope for cryptographic interoperability, and Digi Yatra already runs decentralised identifiers and verifiable credentials at airport scale (Biometric Update). Building onboarding against a frozen, internationally-aligned presentation standard is now the low-regret option.

The residual gap CKYCRR does not close

Be precise here, because India is not starting from zero. CKYCRR — the Central KYC Records Registry run by CERSAI — already lets a customer complete KYC once and have any regulated entity retrieve that record against a 14-digit identifier. CKYCRR 2.0, announced in the Union Budget 2025, upgrades this further: real-time API submissions replacing static PDFs, Aadhaar masking, OTP-based consent for data access, and a consumer self-service portal, rolling out progressively through 2026 (ClearTax). That is real, and it is good.

But CKYCRR is a pull model: an institution retrieves a record from a central registry. It does not make the customer the presenter, and under the Rule 9(1C) exceptions the receiving entity must still top up and re-verify where a retrieved record is incomplete. OID4VP is the complementary push-from-holder model: the customer presents a credential they hold, discloses only the attributes asked for, and attaches a fresh proof that the presentation is consented and current. The residual gap is not "does verified data exist" — it does. The gap is proving that a given presentation is fresh, holder-consented, and independently verifiable, without re-pulling and re-checking the source every single time.

The cost and UX case, plainly

Every re-collection cycle a lender removes is money and conversion recovered. Periodic re-KYC obligations already recur every 2, 8, or 10 years by risk band, and since June 2025 can be completed digitally (Probe42) — so this is not a one-time onboarding cost, it is a repeating one. A consented, standards-based presentation collapses the "prove who you are again" step from a document-capture-and-verify journey (with its 20–45% attrition) into a tap-and-disclose that returns an already-verified credential. Fewer abandoned applications, lower per-verification spend, and a tamper-evident audit trail of exactly what the customer consented to share.

Where AssureLocker fits

AssureLocker supports OID4VP as the presentation layer for its reusable-identity product, AssureVerifID — source-verified business (DigiKYB) and individual (DigiKYC) credentials that a holder presents with consent, disclosing Full, Lite, or a custom field set. Reuse is lender-scoped today; the credential is verified against source, and every presentation carries a consent record on tamper-evident registry infrastructure so a compliance team can prove the who, what, and when.

The boundary is deliberate. AssureLocker is a technology provider: it never lends, prices, sanctions, or decides credit. It makes the lender's own judgement fast, consented, and provable — and lets the customer stop uploading the same PAN at 11pm.

Explore AssureVerifID and DigiKYC, or read the primer on reusable KYB in India.

About AssureLocker

AssureLocker is the independent evidence-and-control layer for regulated lending — starting with co-lending. Across four suites — AssureCLA (co-lending assurance), AssureSCF (supply-chain finance), AssureVerifID (reusable identity) and AssureLens(credit-velocity intelligence), on one neutral layer — we make a lender’s controls and evidence fast, reproducible and governed. We are a technology provider: we never lend, price, or decide credit.

Read more on the AssureLocker blog · assurelocker.com