A founder of a small auto-components firm in Pune keeps a folder on her desktop called "KYC — final — v6." Inside are the same eight files she has now sent to five different lenders: the company PAN, the GST certificate, two years of the incorporation papers, the directors' Aadhaar, a cancelled cheque, a board resolution. Each lender re-collected them, re-verified them, and re-stored them. Each treated her as a stranger it had never met. The documents were identical every time. The trust was rebuilt from zero every time.
That gap — between a person or business that has already proved who they are, and an institution that insists on proving it again — is the problem a credential wallet exists to close.
What a credential wallet actually is
A credential wallet is a holder-controlled place to keep verified credentials — a KYC record, a company registration, a licence, a proof of address — issued by an authoritative source and presentable, on demand, to whoever needs to check them. The important word is holder-controlled. In the old model, your verified identity lives in each institution's database, one copy per relationship. In the wallet model, the verified credential lives with you, and you decide who sees it and which parts.
India already runs the largest working version of this idea. DigiLocker has over 51.3 crore users and more than 5.6 billion documents issued, according to figures cited across the ecosystem — a national credential store where government-issued documents can be fetched and shared. The direction of travel is unmistakable: in August 2026, Digi Yatra added the driving licence (accessed through DigiLocker) as a verified identity credential in its self-sovereign identity wallet, and in April 2026 Google added Aadhaar Verifiable Credentials to Google Wallet for India. Wallets are going mainstream because the alternative — every institution hoarding its own copy of everyone's identity — has become the expensive part.
Why financial institutions should care, in rupees
The cost of re-proving identity is not abstract. For well-optimised digital flows in India, an Aadhaar OTP eKYC runs roughly ₹3–7 per verification, while video KYC runs ₹50–150 per customer (HyperVerge, upGrowth). For low-ticket products — small personal loans, micro-insurance — KYC can consume 10–30% of first-year revenue per customer (upGrowth's KYC cost calculator). And digital KYC flows shed 20–35% of applicants to drop-off; video KYC sheds 30–45%. Every re-verification is a place where a good customer quietly disappears.
Re-KYC compounds it. RBI's periodic-update cycle means low-risk customers are re-verified every ten years, medium-risk every eight, high-risk every two — a recurring re-collection tax on relationships that were already established.
What already exists — and the honest residual gap
It would be dishonest to claim this is unsolved. India has real reuse infrastructure. CERSAI's Central KYC Registry gives each customer a 14-digit KIN so an institution can pull an existing record instead of re-running full KYC; under Budget 2025 CKYC uploads are free, and CKYC 2.0 is tightening data quality. A registry hit is genuinely cheaper than a fresh KYC run.
So where is the gap? Three places. First, selective disclosure: a CKYC pull or a shared PDF hands over the whole document. A credential wallet lets the holder present only the field a lender needs — "this entity is GST-registered and active" — without exposing the rest. Second, business identity: CKYC is built around individuals; the KYB layer for MSMEs and their directors, the thing that folder-on-the-desktop is full of, has no equivalent single reusable record. Third, consent as portable proof. India's Digital Personal Data Protection Rules, 2025 — notified on 14 November 2025, with phased compliance running to 13 May 2027 — make consent the primary basis for processing and require a clear, purpose-specific consent notice for every use. A credential wallet is the natural home for that: consent captured, scoped, and provable at the moment of sharing, rather than reconstructed from logs later.
The wallet as the lender's shortcut, not a leap of faith
The point of holder-controlled credentials is not to replace the lender's judgement — it is to make that judgement fast and provable. A source-verified credential, presented with the holder's consent and checkable against tamper-evident registry infrastructure, lets an institution accept a fact it did not personally collect without accepting risk it cannot audit. The credential is signed by its source; the disclosure is chosen by the holder; the consent is recorded. The lender still decides.
This is what AssureVerifID is built to do: source-verified reusable identity for individuals (DigiKYC) and businesses (DigiKYB), with selective disclosure and consent built into every presentation. Reuse today is lender-scoped — a credential a customer builds with one institution's cooperation, reusable within that relationship — with genuine cross-sector portability still gated on regulatory harmonisation. That boundary is the honest one to draw.
The folder called "KYC — final — v6" should have been version 1, shared five times with five different scopes and five recorded consents. See how reusable business identity works in the Indian context in our guide to reusable KYB.
