A founder of a mid-size auto-components MSME in Pune raises working capital from four lenders in the same year. Each one asks for the same things: the certificate of incorporation, the GST registration, the board resolution, the beneficial-owner declaration, two years of audited financials, the authorised signatory's PAN and address proof. She has assembled this exact pack four times. Nothing about her company has changed between the first request and the fourth — but every lender treats her as a stranger, because every lender's system has never seen her before.
This is the friction that portable, verifiable credentials are meant to remove. It is worth understanding what they actually do, and — just as importantly — what already exists in India that does part of the job.
What a verifiable credential really is
A verifiable credential (VC) is a digitally signed statement issued by one party (the issuer), held by the subject (the holder), and checked by anyone the holder chooses to show it to (the verifier). The W3C published the Verifiable Credentials Data Model v2.0 as a formal Recommendation in May 2025 — the first major update to the standard since 2019, and a signal to institutions that the format is stable enough to build on.
The mechanics matter less than three properties. A VC is tamper-evident: the verifier can confirm the content has not been altered since the issuer signed it. It is holder-presented on consent: the subject decides who sees it, and can present only the fields required — proving they are GST-registered without exposing turnover, or proving an address without revealing an account balance. And it is portable: the same signed credential can be shown to lender two, three and four without re-contacting the original source.
That third property is the one that dissolves the Pune founder's problem — if the reuse is allowed to happen.
India already has most of the plumbing
It would be dishonest to pretend this is a greenfield. India has built more identity infrastructure than almost any economy on earth.
The Central KYC Records Registry, run by CERSAI, crossed 103 crore records in 2025, and CKYCRR 2.0 — announced in the Union Budget 2025 and targeted to go live around February 2026 — moves to real-time APIs, structured JSON submission, Aadhaar masking and facial de-duplication. DigiLocker has issued more than 9.81 billion documents to over 550 million users, with 2,131 issuers connected. Aadhaar eKYC can verify an individual for ₹3–7 a check, against ₹50–150 for video KYC and ₹200–500 for physical KYC.
So the raw material — source-authentic documents, a central record store, cheap identity checks — exists. The residual gap is narrower and more specific than "India needs digital identity."
The gap the registries do not close
Two structural limits remain.
First, reuse is bounded to the institution that collected it. The RBI's November 2024 KYC amendments confirm that a customer who has completed KYC need not repeat it — but explicitly within the same regulated entity. CKYC is a store the second lender can query, yet in practice most lenders still re-run their own collection and verification rather than accept a record they did not originate. The founder's pack gets rebuilt because trust does not travel with the data.
Second, business verification is far messier than individual KYC. There is no single "business VC." A lender assembles a KYB view from the MCA registry, GSTN, the beneficial-owner declaration, director PANs and a board resolution — and the RBI's periodic-update cadence (every 2 to 10 years by risk, with high-risk entities refreshed every two years) means freshness is a live compliance question, not a one-time box tick. A stored PDF cannot tell the next lender whether the underlying registration was suspended last month.
A portable credential closes both gaps precisely because it carries its own proof. It is source-verified at issuance, it states when it was checked, it can be revoked at source, and it is presented on the holder's consent — so the second lender accepts a fresh, tamper-evident statement instead of restarting from raw documents.
Where this fits, honestly
Cross-sector reuse — a bank credential accepted by an insurer, a telco, a securities house — is regulation-gated in India, requiring harmonisation across RBI, SEBI, IRDAI and TRAI that does not exist yet. Anyone promising it today is overclaiming. The realistic, available win is lender-scoped reuse: a business or individual verified once, holding a source-verified credential they can re-present to the next lender in the same regulatory perimeter, on consent, with freshness and revocation intact.
That is exactly the boundary AssureVerifID is built for. AssureVerifID assembles source-verified reusable identity — DigiKYB for businesses, DigiKYC for individuals — as tamper-evident credentials the holder controls, so a lender's judgement is made fast and provable without rebuilding the pack from zero. AssureLocker never lends, prices or decides credit; it makes the verification the lender already owes reusable.
If your onboarding team re-collects the same documents every quarter, that is the friction to attack first.
See how source-verified reusable identity works → · Read the reusable-KYB primer →
