What is DigiKYB? Verifiable Business Identity in India

A complete guide to business KYC done right — how DigiKYB anchors an entity to GSTN, MCA21, and Udyam, turns it into a reusable credential, and replaces weeks of document scrutiny with a verified pack.

Business IdentityAssureLocker Team·10 min read
Published: 13 January 2026Last updated: 3 April 2026Sources reviewed as of: 3 April 2026

The Problem With Business KYC Today

Every time a business in India approaches a new bank, NBFC, or buyer, it submits the same stack of documents — GSTIN certificate, MCA filing, Udyam registration, PAN, board resolutions, director KYC — from scratch. The receiving institution then runs its own KYB (Know Your Business) process: someone reads the PDFs, keys data into a system, cross-checks a registry or two, and files a report. This costs ₹5,000–₹25,000 in operational effort, takes two to four weeks, and produces a result that is siloed to that one institution and invisible to everyone else.

Worse, the report is built on documents that can be — and are — forged. A scanned GSTcertificate or a doctored incorporation page tells you nothing about whether the entity is actually active, who really controls it, or whether it can do what it claims.

The waste is structural, and it comes from fragmentation. There is no single place an institution can look up a business the way it looks up a person — entity facts are scattered across the GST network, the MCA registry, Udyam, the PAN database, EPFO and DGFT, each with its own identifier, format and access path. So every institution reassembles the same picture independently, from the same documents, and none of that work is reusable by the next one. The business re-pays in time; the institution re-pays in operational cost; and the result is stale the moment a director resigns or a GSTIN is suspended. Fragmentation, not document volume, is what makes business onboarding slow.

What DigiKYB Is

DigiKYB provides non-repudiable, assured, timestamped records of formal KYB verification — checked against authoritative sources of business identity (GSTN, MCA21, Udyam) — that the entity can share with anyone, at any time, at its own discretion, through a portable wallet.

It is the entity counterpart to DigiKYC. Where DigiKYC does this for personally identifiable information, DigiKYB does it for a business: every claim is pulled directly from the authoritative registry, cross-referenced across sources, and issued as a single cryptographically-signed credential the entity holds and presents on demand — carrying proof of which source verified it, when, and that the issuer cannot later repudiate it.

It is the institutional counterpart to DigiKYC (individual identity). Where DigiKYC verifies the people — directors and authorised signatories — DigiKYB verifies the entity itself. Together they form the intake layer for everything downstream, including pre-shipment PO financing.

One Credential, Assembled From Many Sources

The core move of DigiKYB is assembly. Instead of asking the business to gather documents and the institution to re-verify them, DigiKYB pulls each fact directly from the source that is authoritative for it, cross-checks the facts against one another, and issues a single reusable credential the entity holds. Every source is verified once, and the assembled credential is presented as many times as the business chooses.

How DigiKYB assembles one reusable entity credential from many authoritative sourcesSix authoritative sources — GSTN, the PAN database, MCA21 with its director register, Udyam, EPFO, and the entity bank via the Account Aggregator framework — each feed verified facts into a single source-verified assembly step, which issues one reusable, cryptographically-signed entity credential that the business shares with any institution under its own consent.GSTNstatus · legal namePAN databaseentity PANMCA21CIN · directors (DIN)UdyamMSME class · URNEPFOemployee headcountBank · AAcashflow signalSource-verifiedassemblycross-checkedReusable entitycredentialsigned · portableshared with any verifierunder the entity's consent
Each fact is verified once, at source; the assembled credential is presented as many times as the business chooses — replacing repeated, per-institution document scrutiny.

The Sources DigiKYB Anchors To

SourceWhat it verifies
GSTNGST registration, live status, legal & trade name, place of business, filing history
MCA21CIN, incorporation, registered office, and the director register (with DINs)
UdyamMSME classification and registration (Udyam URN)
PANEntity PAN and authorised-signatory PAN verification
EPFOActive employee headcount — an operational-scale and capacity signal
DGFTImport/Export Code (IEC) for exporters

Every Attribute, Traced to Its Source

Not every claim in a business credential carries the same weight, and DigiKYB does not pretend otherwise. Each attribute is tagged with the source it was checked against and an evidence tier that tells a relying institution exactly how strongly it is backed — from a live registry read, down to a fact the entity has simply declared. The tiers are, in descending strength: registry-verified (confirmed against an authoritative government registry API), issuer-confirmed (checked through a live channel such as an OTP or consented data pull), document-signed (a signed instrument such as a DSC or CS-certified resolution), and self-declared (asserted by the entity, corroborated where possible).

AttributeSourceEvidence tier
Legal & trade name, GSTIN, live statusGSTNregistry-verified
CIN, incorporation, registered officeMCA21registry-verified
Director register (with DINs)MCA21registry-verified
Entity & authorised-signatory PANPAN database (Income Tax)registry-verified
MSME classification (Udyam URN)Udyamregistry-verified
Import/Export Code (IEC)DGFTregistry-verified
Employee headcountEPFOregistry-verified
Control of the registered entityGSTIN OTP to authorised signatoryissuer-confirmed
Bank-cashflow signalAccount Aggregator (consented)issuer-confirmed
Authorised-signatory livenessVideo KYCissuer-confirmed
Board resolution authorising the signatoryCS-certified BR / DSCdocument-signed
Beneficial owner (≥10% holding)BO declarationself-declared

Carrying the tier alongside the value is the point. A verifier can decide, for its own risk appetite, that registry-verified facts are enough to onboard, while a self-declared beneficial-owner list warrants an extra corroboration step — without having to reopen the whole file.

Tiered, Proportionate Verification

A sole trader should not face the same verification stack as a listed company. DigiKYB scales the evidence requirement to the entity. A universal GSTIN OTP gate applies to everyone — confirming control of the registered entity — with deeper checks layered on by tier.

Tier 1 — Sole Trader

  • GSTIN OTP to the authorised signatory
  • PAN uniqueness (one PAN maps to one entity)

Tier 2 — MSME

  • Udyam URN verification
  • CIN and DIN match (if incorporated)
  • Abbreviated AML screening

Tier 3 — Large Corporate

  • Board Resolution and authorised-signatory Video KYC
  • Beneficial-owner declaration (≥10%)
  • Full AML with MLRO sign-off and audited financials

Tier 4 — Listed & BFSI

  • DSC-signed declaration and CS-certified board resolution
  • Disqualified-DIN check, exchange listing / regulator registration
  • DPDP Data Processing Agreement

Verifying the People Behind the Entity

An entity is only as trustworthy as the people who control it, so the hardest part of KYB is not the company — it is the directors and the ultimate beneficial owners (UBOs). DigiKYB approaches this in layers. The director register is read directly from MCA21, so the list of who is on the board — each with a Director Identification Number (DIN) — comes from the registry, not from a submitted PDF. For higher tiers, each DIN is run through a disqualified-DIN check, so a board seat held by someone disqualified under the Companies Act does not pass silently.

UBOs are harder, because ownership can be layered through holding companies and nominee arrangements specifically to obscure who benefits. Ownership below the corporate surface is not something a public registry fully exposes, so DigiKYB collects a beneficial-owner declaration at the ≥10% threshold, corroborates the named individuals against DigiKYC identity verification and shareholding evidence where available, and records the declaration at the self-declared evidence tier so a relying institution knows precisely how far the attestation goes. Directors and authorised signatories are verified as individuals through DigiKYC — with Video KYC liveness at the higher tiers — so the humans who can bind the entity are themselves source-verified, not merely named on a form.

What a Reusable Pack Actually Solves

The value of a reusable DigiKYB credential is not that it is digital — it is that the verification work is done once and trusted many times. Concretely, it collapses four separate problems at once:

  • Duplication.The second institution does not re-run the first one's checks; it verifies the credential and inherits the source-linked evidence.
  • Forgery. Because every claim is anchored to a live registry read rather than a scanned document, a doctored certificate has nothing to attach to.
  • Staleness. The credential reflects live registry state, and lifecycle workers move it out of good standing when the underlying source changes — so a relying party is not trusting a snapshot from onboarding day.
  • Control. The entity holds its own credential and presents it under consent, rather than leaving copies of its constitutional documents scattered across every counterparty it has ever dealt with.

Why Registry-Anchored Beats Document-Based

DimensionDocument-based KYBDigiKYB
Source of truthScanned PDF (forgeable)Live registry API (authoritative)
FreshnessSnapshot at submissionRe-polled by lifecycle workers
ReusabilitySiloed to one institutionPresent to any verifier
Cost per check₹5,000–₹25,000A fraction, repeatable
Time2–4 weeksHours

Always Current, Never Stale

A KYB report is only true on the day it is written. A GSTIN can be suspended, a director can resign, an Udyam registration can lapse. AssureLocker's lifecycle workers continuously re-poll GSTN status, the MCA director register, and Udyam registration, and transition the credential's state when something changes. A DigiKYB credential reflects live registry state — not a snapshot from issuance day.

DigiKYB as the Front Door to Credit

The real payoff comes downstream. Because a DigiKYB credential already carries verified identity, capacity, and trade history, it feeds directly into the Risk Signals Pack used for pre-shipment PO financing. An MSME that holds a DigiKYB credential can be screened for a loan in hours rather than weeks — and the lender approves on verified evidence, not on paperwork.

The Trust Boundary

DigiKYB attests to what can be verified against authoritative API sources — GSTN, MCA21, Udyam, PAN, EPFO, DGFT — plus consented data from DigiLocker and the Account Aggregatorframework. It deliberately does not attest to physical or scanned documents that cannot be independently confirmed. That boundary is what makes a DigiKYB credential trustworthy enough for a second institution to rely on it.

Where Right Vectors India Sits — and Where It Doesn't

It is worth being precise about the role AssureLocker plays. DigiKYB is a technology service provider: it verifies entity facts against authoritative sources — GSTN, MCA21, Udyam, PAN, EPFO, DGFT — and issues a reusable, source-linked credential the business controls and shares under consent. It does not lend, underwrite, approve, or guarantee anything. The relying institution reads the verified evidence and each tier attached to it, and makes its own onboarding and credit decision on its own criteria. DigiKYB makes that decision faster and better-evidenced; it does not make it for the institution.

That boundary is exactly what makes the credential reusable: a second institution can rely on it precisely because it attests only to what was independently verified, and leaves the judgement where it belongs.

See It In Action

Book a demo to see how DigiKYB turns weeks of business onboarding into a verified, reusable credential — read more on the DigiKYB platform, or see how it powers pre-shipment PO financing.


Primary sources

Continue reading

See AssureLocker in action

Book a 30-minute walkthrough — how to get demo-ready and financeable.

Book a demo →
AssureLocker
Right Vectors India
3rd floor, Innov8, SKCL Tech Square,
SIDCO Industrial Estate, Guindy,
Chennai, TN 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. Right Vectors India, the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 Right Vectors India. All rights reserved. · Site version: al-20260721-155225-34ff216c8

Aligned with India Stack. Made in India.