The Problem With Business KYC Today
Every time a business in India approaches a new bank, NBFC, or buyer, it submits the same stack of documents — GSTIN certificate, MCA filing, Udyam registration, PAN, board resolutions, director KYC — from scratch. The receiving institution then runs its own KYB (Know Your Business) process: someone reads the PDFs, keys data into a system, cross-checks a registry or two, and files a report. This costs ₹5,000–₹25,000 in operational effort, takes two to four weeks, and produces a result that is siloed to that one institution and invisible to everyone else.
Worse, the report is built on documents that can be — and are — forged. A scanned GSTcertificate or a doctored incorporation page tells you nothing about whether the entity is actually active, who really controls it, or whether it can do what it claims.
The waste is structural, and it comes from fragmentation. There is no single place an institution can look up a business the way it looks up a person — entity facts are scattered across the GST network, the MCA registry, Udyam, the PAN database, EPFO and DGFT, each with its own identifier, format and access path. So every institution reassembles the same picture independently, from the same documents, and none of that work is reusable by the next one. The business re-pays in time; the institution re-pays in operational cost; and the result is stale the moment a director resigns or a GSTIN is suspended. Fragmentation, not document volume, is what makes business onboarding slow.
What DigiKYB Is
DigiKYB provides non-repudiable, assured, timestamped records of formal KYB verification — checked against authoritative sources of business identity (GSTN, MCA21, Udyam) — that the entity can share with anyone, at any time, at its own discretion, through a portable wallet.
It is the entity counterpart to DigiKYC. Where DigiKYC does this for personally identifiable information, DigiKYB does it for a business: every claim is pulled directly from the authoritative registry, cross-referenced across sources, and issued as a single cryptographically-signed credential the entity holds and presents on demand — carrying proof of which source verified it, when, and that the issuer cannot later repudiate it.
It is the institutional counterpart to DigiKYC (individual identity). Where DigiKYC verifies the people — directors and authorised signatories — DigiKYB verifies the entity itself. Together they form the intake layer for everything downstream, including pre-shipment PO financing.
One Credential, Assembled From Many Sources
The core move of DigiKYB is assembly. Instead of asking the business to gather documents and the institution to re-verify them, DigiKYB pulls each fact directly from the source that is authoritative for it, cross-checks the facts against one another, and issues a single reusable credential the entity holds. Every source is verified once, and the assembled credential is presented as many times as the business chooses.
The Sources DigiKYB Anchors To
| Source | What it verifies |
|---|---|
| GSTN | GST registration, live status, legal & trade name, place of business, filing history |
| MCA21 | CIN, incorporation, registered office, and the director register (with DINs) |
| Udyam | MSME classification and registration (Udyam URN) |
| PAN | Entity PAN and authorised-signatory PAN verification |
| EPFO | Active employee headcount — an operational-scale and capacity signal |
| DGFT | Import/Export Code (IEC) for exporters |
Every Attribute, Traced to Its Source
Not every claim in a business credential carries the same weight, and DigiKYB does not pretend otherwise. Each attribute is tagged with the source it was checked against and an evidence tier that tells a relying institution exactly how strongly it is backed — from a live registry read, down to a fact the entity has simply declared. The tiers are, in descending strength: registry-verified (confirmed against an authoritative government registry API), issuer-confirmed (checked through a live channel such as an OTP or consented data pull), document-signed (a signed instrument such as a DSC or CS-certified resolution), and self-declared (asserted by the entity, corroborated where possible).
| Attribute | Source | Evidence tier |
|---|---|---|
| Legal & trade name, GSTIN, live status | GSTN | registry-verified |
| CIN, incorporation, registered office | MCA21 | registry-verified |
| Director register (with DINs) | MCA21 | registry-verified |
| Entity & authorised-signatory PAN | PAN database (Income Tax) | registry-verified |
| MSME classification (Udyam URN) | Udyam | registry-verified |
| Import/Export Code (IEC) | DGFT | registry-verified |
| Employee headcount | EPFO | registry-verified |
| Control of the registered entity | GSTIN OTP to authorised signatory | issuer-confirmed |
| Bank-cashflow signal | Account Aggregator (consented) | issuer-confirmed |
| Authorised-signatory liveness | Video KYC | issuer-confirmed |
| Board resolution authorising the signatory | CS-certified BR / DSC | document-signed |
| Beneficial owner (≥10% holding) | BO declaration | self-declared |
Carrying the tier alongside the value is the point. A verifier can decide, for its own risk appetite, that registry-verified facts are enough to onboard, while a self-declared beneficial-owner list warrants an extra corroboration step — without having to reopen the whole file.
Tiered, Proportionate Verification
A sole trader should not face the same verification stack as a listed company. DigiKYB scales the evidence requirement to the entity. A universal GSTIN OTP gate applies to everyone — confirming control of the registered entity — with deeper checks layered on by tier.
Tier 1 — Sole Trader
- GSTIN OTP to the authorised signatory
- PAN uniqueness (one PAN maps to one entity)
Tier 2 — MSME
- Udyam URN verification
- CIN and DIN match (if incorporated)
- Abbreviated AML screening
Tier 3 — Large Corporate
- Board Resolution and authorised-signatory Video KYC
- Beneficial-owner declaration (≥10%)
- Full AML with MLRO sign-off and audited financials
Tier 4 — Listed & BFSI
- DSC-signed declaration and CS-certified board resolution
- Disqualified-DIN check, exchange listing / regulator registration
- DPDP Data Processing Agreement
Verifying the People Behind the Entity
An entity is only as trustworthy as the people who control it, so the hardest part of KYB is not the company — it is the directors and the ultimate beneficial owners (UBOs). DigiKYB approaches this in layers. The director register is read directly from MCA21, so the list of who is on the board — each with a Director Identification Number (DIN) — comes from the registry, not from a submitted PDF. For higher tiers, each DIN is run through a disqualified-DIN check, so a board seat held by someone disqualified under the Companies Act does not pass silently.
UBOs are harder, because ownership can be layered through holding companies and nominee arrangements specifically to obscure who benefits. Ownership below the corporate surface is not something a public registry fully exposes, so DigiKYB collects a beneficial-owner declaration at the ≥10% threshold, corroborates the named individuals against DigiKYC identity verification and shareholding evidence where available, and records the declaration at the self-declared evidence tier so a relying institution knows precisely how far the attestation goes. Directors and authorised signatories are verified as individuals through DigiKYC — with Video KYC liveness at the higher tiers — so the humans who can bind the entity are themselves source-verified, not merely named on a form.
What a Reusable Pack Actually Solves
The value of a reusable DigiKYB credential is not that it is digital — it is that the verification work is done once and trusted many times. Concretely, it collapses four separate problems at once:
- Duplication.The second institution does not re-run the first one's checks; it verifies the credential and inherits the source-linked evidence.
- Forgery. Because every claim is anchored to a live registry read rather than a scanned document, a doctored certificate has nothing to attach to.
- Staleness. The credential reflects live registry state, and lifecycle workers move it out of good standing when the underlying source changes — so a relying party is not trusting a snapshot from onboarding day.
- Control. The entity holds its own credential and presents it under consent, rather than leaving copies of its constitutional documents scattered across every counterparty it has ever dealt with.
Why Registry-Anchored Beats Document-Based
| Dimension | Document-based KYB | DigiKYB |
|---|---|---|
| Source of truth | Scanned PDF (forgeable) | Live registry API (authoritative) |
| Freshness | Snapshot at submission | Re-polled by lifecycle workers |
| Reusability | Siloed to one institution | Present to any verifier |
| Cost per check | ₹5,000–₹25,000 | A fraction, repeatable |
| Time | 2–4 weeks | Hours |
Always Current, Never Stale
A KYB report is only true on the day it is written. A GSTIN can be suspended, a director can resign, an Udyam registration can lapse. AssureLocker's lifecycle workers continuously re-poll GSTN status, the MCA director register, and Udyam registration, and transition the credential's state when something changes. A DigiKYB credential reflects live registry state — not a snapshot from issuance day.
DigiKYB as the Front Door to Credit
The real payoff comes downstream. Because a DigiKYB credential already carries verified identity, capacity, and trade history, it feeds directly into the Risk Signals Pack used for pre-shipment PO financing. An MSME that holds a DigiKYB credential can be screened for a loan in hours rather than weeks — and the lender approves on verified evidence, not on paperwork.
The Trust Boundary
DigiKYB attests to what can be verified against authoritative API sources — GSTN, MCA21, Udyam, PAN, EPFO, DGFT — plus consented data from DigiLocker and the Account Aggregatorframework. It deliberately does not attest to physical or scanned documents that cannot be independently confirmed. That boundary is what makes a DigiKYB credential trustworthy enough for a second institution to rely on it.
Where Right Vectors India Sits — and Where It Doesn't
It is worth being precise about the role AssureLocker plays. DigiKYB is a technology service provider: it verifies entity facts against authoritative sources — GSTN, MCA21, Udyam, PAN, EPFO, DGFT — and issues a reusable, source-linked credential the business controls and shares under consent. It does not lend, underwrite, approve, or guarantee anything. The relying institution reads the verified evidence and each tier attached to it, and makes its own onboarding and credit decision on its own criteria. DigiKYB makes that decision faster and better-evidenced; it does not make it for the institution.
That boundary is exactly what makes the credential reusable: a second institution can rely on it precisely because it attests only to what was independently verified, and leaves the judgement where it belongs.
See It In Action
Book a demo to see how DigiKYB turns weeks of business onboarding into a verified, reusable credential — read more on the DigiKYB platform, or see how it powers pre-shipment PO financing.