What is DigiKYC?

A complete guide to India's next-generation reusable KYC — how it works, why it's different from traditional and Video KYC, and what it means for regulated institutions.

FundamentalsAssureLocker Team·8 min read
Published: 9 January 2026Last updated: 20 March 2026Sources reviewed as of: 20 March 2026

The problem with KYC today

Every regulated institution in India — every bank, NBFC, insurer, and stock broker — must independently verify the identity of every customer they onboard. This means an individual who already has a savings account, a mutual fund SIP, and a demat account has almost certainly been KYC-verified three separate times. Each verification costs the institution between ₹150 and ₹800. Each one asks the customer to submit the same documents again. Each one stores a copy of the same Aadhaar card.

This is expensive, friction-heavy, and — since India's DPDP Act 2023 — increasingly a regulatory liability. The question the industry has been asking is: why can't KYC be done once and trusted everywhere?

DigiKYC is the answer.

What is DigiKYC?

DigiKYC provides cryptographically verifiable, tamper-evident, timestamped records of a completed, Aadhaar-anchored KYC verification — formally checked against authoritative sources of personally identifiable information — that the owner can share with anyone, at any time, entirely at their own discretion, through a portable wallet.

Each record captures three things that a scanned document never can: that the verification was performed against an authoritative source (not a self-declared upload), exactly when it was done (a trustworthy timestamp), and that it cannot later be repudiated by the issuer (a cryptographic signature). Instead of every institution rebuilding the same identity file, the assurance is captured once and the holder presents it on demand — much as a digitally-signed government PDF can be trusted without re-issuing it.

The credential contains no raw Aadhaar data, no document scans, and no PII beyond what the individual consents to share. It contains only a cryptographic assertion: "This individual has been verified to KYC assurance level X by AssureLocker, at time Y, with Aadhaar verification as the root of trust."

Key definition:In DigiKYC, the credential is the proof. A verifier does not need to see the underlying documents — they verify the credential’s cryptographic signature against the registry. This is the same principle as verifying a digital signature on a government-issued PDF.

Verify once, reuse everywhere

The core idea is a single verification that many institutions can rely on. The individual proves their identity once, an issuer signs a reusable credential, and the holder then presents it — with fresh consent each time — to as many verifiers as they choose. No verifier re-collects documents; each simply checks the signature and the assurance claim.

Verify once, reuse everywhere: one KYC verification becomes a reusable credential a holder presents with consent to many verifiersAn individual completes KYC once; an issuer signs a reusable verifiable credential held in the holder’s wallet; the holder then presents it with consent to a bank, an NBFC and a mutual fund, each of which verifies the signature without re-collecting documents.Individualcompletes KYConceIssuer signsreusable credentialheld in holder’s walletsignature + assurance claimBankverifies signatureNBFCverifies signatureMutual fundverifies signaturepresented with consent — no re-collection
One verification, many relying institutions: the holder re-uses a single signed credential, disclosing only what each verifier needs.

How DigiKYC differs from eKYC and Video KYC

DimensionTraditional KYC / eKYCVideo KYCDigiKYC
How long it takes1–7 days20–45 minutesFirst-time: minutes. Re-use: <200ms
Documents stored by institutionYes — copies retainedYes — video + screenshotsNo — only cryptographic assertions
Re-KYC required?Yes — each institutionYes — each institutionNo — credential is reusable
DPDP liabilityHighVery highMinimal
Regulatory standardRBI Master DirectionRBI Video KYC circularW3C VC + OID4VC + DPDP-aligned

The DigiKYC process — step by step

  1. Verification ceremony (once): The individual completes an Aadhaar OTP verification, face liveness check, and document proof collection with a AssureLocker-integrated institution or directly through AssureLocker. This is the only time raw identity data is used.
  2. Credential issuance: AssureLocker creates a W3C Verifiable Credential (VC) asserting the KYC outcome. The credential is cryptographically signed using AssureLocker's issuer key and recorded in an immutable registry for immutable audit integrity.
  3. Holder custody: The credential is delivered to the individual's wallet. The individual — not the institution — controls when and with whom it is shared.
  4. Presentation at a verifier: When onboarding at a new institution, the individual presents the credential via OID4VP (OpenID for Verifiable Presentations). Only the assurance claim is disclosed — not the underlying data.
  5. Instant verification: The verifying institution calls AssureLocker’s verification API. The API checks the credential’s signature against the registry and returns a pass/fail in under 200 milliseconds.

How individuals complete their first verification

The verification ceremony in step 1 is not a single fixed flow. An individual can prove their identity through whichever path they can complete, and every path resolves to the same signed, reusable credential. The paths below are live today; each anchors the verification to an authoritative source rather than a self-declared upload.

PathHow identity is provenBest for
DigiLockerGovernment-issued documents are pulled directly from the individual’s DigiLocker with their consent and checked against the issuing authority’s records, so the data is source-verified rather than uploaded.Individuals with an active DigiLocker and Aadhaar-linked documents who want a fast, fully self-service start.
Registry + OTPIdentity details are matched against an authoritative identity registry and confirmed with a one-time password sent to the individual’s registered mobile number.Remote, self-service onboarding where the individual controls the registered number on record.
Biometric matchA live face-liveness capture is compared against the authoritative photo held on record, binding the person present to the identity being claimed.In-person or assisted onboarding, and cases where a document pull is not available or is inconclusive.

A further path — CKYC (KIN + OTP), resolving an existing CKYC identifier against the central KYC registry — is planned but not yet live; it is deferred pending the relevant NBFC-license approval. It is listed here only so the roadmap is honest, not as an available option today.

Holder consent and selective disclosure

A reusable credential is only trustworthy if the holder — not the institution — decides what leaves their wallet. DigiKYC is built so that every presentation is a deliberate, per-verifier act of consent, and so that the holder can share the minimum needed to satisfy a given check.

Per-presentation consent. Nothing is shared in the background. Each time a verifier requests identity, the holder approves that specific request on their own device. Consent is scoped to one verifier and one purpose; it is not a standing authorisation, and the holder can decline without losing the credential.

Selective disclosure.A DigiKYC credential is structured so that individual claims can be revealed independently. A verifier that only needs to know the holder is over 18 and KYC-assured can be shown exactly those two facts — not a full name, address, or document number — while the issuer’s signature still validates over the disclosed subset. This means a low-touch check discloses far less than a full account opening, and the holder is never forced into over-sharing to clear a narrow requirement.

Bounded lifetime. Credentials carry an expiry and can be refreshed, so a verifier is always relying on a current assertion rather than a stale snapshot. Combined with consent and selective disclosure, this keeps the holder in control of what is shared, with whom, and for how long.

Who benefits from DigiKYC?

For regulated institutions

  • Eliminate per-onboarding KYC costs (₹150–₹800 per customer)
  • Reduce document storage liability under DPDP Act 2023
  • Accelerate customer onboarding from days to seconds
  • Access a pre-verified customer base through the AssureLocker network

For individuals

  • No more submitting the same documents to every institution
  • Faster account opening and loan processing
  • Full control over what identity data is shared and with whom
  • A portable digital identity that works across the regulated financial system

Is DigiKYC regulation-compliant?

AssureLocker's DigiKYC platform is designed to align with India's existing regulatory framework:

  • RBI: Aligned with the Master Direction on KYC and the account aggregator framework principle of customer consent-driven data sharing.
  • SEBI: Credential assurance levels map to SEBI KYC norms for investor onboarding.
  • IRDAI: Supports digital onboarding guidelines for insurance products.
  • DPDP Act 2023: Minimises data retention liability by design — institutions store an assertion, not a copy of Aadhaar or PAN documents.

We recommend institutions conduct their own legal review with their compliance counsel against their specific regulatory obligations and applicable RBI/SEBI/IRDAI circulars.

See it in action

Two short, interactive walkthroughs show what a DigiKYC credential does after it's issued — no account or real data required.

Consent-based sharing. When a verifier asks for identity, the holder approves on their phone and only the fields they consent to are shared — a cryptographic proof, not a raw document — an in-person QR scan or a remote approval.

Re-KYC without re-onboarding.Credentials carry an expiry, and DigiKYC refreshes them without starting over — an expiry reminder and a streamlined renewal that keeps the holder's reusable credential current.

Where AssureLocker sits — and where it does not

AssureLockeroperates as a technology service provider. It provides the identity and credential infrastructure — the verification ceremony, the signed reusable credential, the wallet, and the verification API — that lets a completed KYC be re-used with consent. It does not make lending, onboarding, or KYC-reliance decisions on any institution’s behalf, and it does not guarantee an outcome. Whether to rely on a presented credential, and on what terms to onboard a customer, remains entirely the relying institution’s own decision under its own policies and regulatory obligations.

In practice that means the platform makes the evidence checkable and portable, while the bank, NBFC, or mutual fund applies its own risk appetite and compliance judgement to it. See the DigiKYC platform for how the issuance and verification pieces fit together.

Getting started with DigiKYC

AssureLocker exposes a REST API for both credential issuance and verification. Integration does not require any special infrastructure or changes to your core banking system. A typical sandbox integration takes 2–3 developer days.

Explore the interactive KYC demos — consent sharing, re-KYC and vertical onboarding — or book a 30-minute demo with our team.


Primary sources

Continue reading

See AssureLocker in action

Book a 30-minute live walkthrough tailored to your lending use case.

Book a demo →
AssureLocker
AssureLocker Pvt Ltd. (inc. in progress)
3rd floor, Innov8, SKCL Tech Square, SIDCO Industrial Estate, Guindy,
Chennai, Tamil Nadu 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. AssureLocker Pvt Ltd. (inc. in progress), the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 AssureLocker Pvt Ltd.. All rights reserved. · Site version: al-20260905-192031-5156ce245