The problem with KYC today
Every regulated institution in India — every bank, NBFC, insurer, and stock broker — must independently verify the identity of every customer they onboard. This means an individual who already has a savings account, a mutual fund SIP, and a demat account has almost certainly been KYC-verified three separate times. Each verification costs the institution between ₹150 and ₹800. Each one asks the customer to submit the same documents again. Each one stores a copy of the same Aadhaar card.
This is expensive, friction-heavy, and — since India's DPDP Act 2023 — increasingly a regulatory liability. The question the industry has been asking is: why can't KYC be done once and trusted everywhere?
DigiKYC is the answer.
What is DigiKYC?
DigiKYC provides cryptographically verifiable, tamper-evident, timestamped records of a completed, Aadhaar-anchored KYC verification — formally checked against authoritative sources of personally identifiable information — that the owner can share with anyone, at any time, entirely at their own discretion, through a portable wallet.
Each record captures three things that a scanned document never can: that the verification was performed against an authoritative source (not a self-declared upload), exactly when it was done (a trustworthy timestamp), and that it cannot later be repudiated by the issuer (a cryptographic signature). Instead of every institution rebuilding the same identity file, the assurance is captured once and the holder presents it on demand — much as a digitally-signed government PDF can be trusted without re-issuing it.
The credential contains no raw Aadhaar data, no document scans, and no PII beyond what the individual consents to share. It contains only a cryptographic assertion: "This individual has been verified to KYC assurance level X by AssureLocker, at time Y, with Aadhaar verification as the root of trust."
Key definition:In DigiKYC, the credential is the proof. A verifier does not need to see the underlying documents — they verify the credential’s cryptographic signature against the registry. This is the same principle as verifying a digital signature on a government-issued PDF.
Verify once, reuse everywhere
The core idea is a single verification that many institutions can rely on. The individual proves their identity once, an issuer signs a reusable credential, and the holder then presents it — with fresh consent each time — to as many verifiers as they choose. No verifier re-collects documents; each simply checks the signature and the assurance claim.
How DigiKYC differs from eKYC and Video KYC
| Dimension | Traditional KYC / eKYC | Video KYC | DigiKYC |
|---|---|---|---|
| How long it takes | 1–7 days | 20–45 minutes | First-time: minutes. Re-use: <200ms |
| Documents stored by institution | Yes — copies retained | Yes — video + screenshots | No — only cryptographic assertions |
| Re-KYC required? | Yes — each institution | Yes — each institution | No — credential is reusable |
| DPDP liability | High | Very high | Minimal |
| Regulatory standard | RBI Master Direction | RBI Video KYC circular | W3C VC + OID4VC + DPDP-aligned |
The DigiKYC process — step by step
- Verification ceremony (once): The individual completes an Aadhaar OTP verification, face liveness check, and document proof collection with a AssureLocker-integrated institution or directly through AssureLocker. This is the only time raw identity data is used.
- Credential issuance: AssureLocker creates a W3C Verifiable Credential (VC) asserting the KYC outcome. The credential is cryptographically signed using AssureLocker's issuer key and recorded in an immutable registry for immutable audit integrity.
- Holder custody: The credential is delivered to the individual's wallet. The individual — not the institution — controls when and with whom it is shared.
- Presentation at a verifier: When onboarding at a new institution, the individual presents the credential via OID4VP (OpenID for Verifiable Presentations). Only the assurance claim is disclosed — not the underlying data.
- Instant verification: The verifying institution calls AssureLocker’s verification API. The API checks the credential’s signature against the registry and returns a pass/fail in under 200 milliseconds.
How individuals complete their first verification
The verification ceremony in step 1 is not a single fixed flow. An individual can prove their identity through whichever path they can complete, and every path resolves to the same signed, reusable credential. The paths below are live today; each anchors the verification to an authoritative source rather than a self-declared upload.
| Path | How identity is proven | Best for |
|---|---|---|
| DigiLocker | Government-issued documents are pulled directly from the individual’s DigiLocker with their consent and checked against the issuing authority’s records, so the data is source-verified rather than uploaded. | Individuals with an active DigiLocker and Aadhaar-linked documents who want a fast, fully self-service start. |
| Registry + OTP | Identity details are matched against an authoritative identity registry and confirmed with a one-time password sent to the individual’s registered mobile number. | Remote, self-service onboarding where the individual controls the registered number on record. |
| Biometric match | A live face-liveness capture is compared against the authoritative photo held on record, binding the person present to the identity being claimed. | In-person or assisted onboarding, and cases where a document pull is not available or is inconclusive. |
A further path — CKYC (KIN + OTP), resolving an existing CKYC identifier against the central KYC registry — is planned but not yet live; it is deferred pending the relevant NBFC-license approval. It is listed here only so the roadmap is honest, not as an available option today.
Holder consent and selective disclosure
A reusable credential is only trustworthy if the holder — not the institution — decides what leaves their wallet. DigiKYC is built so that every presentation is a deliberate, per-verifier act of consent, and so that the holder can share the minimum needed to satisfy a given check.
Per-presentation consent. Nothing is shared in the background. Each time a verifier requests identity, the holder approves that specific request on their own device. Consent is scoped to one verifier and one purpose; it is not a standing authorisation, and the holder can decline without losing the credential.
Selective disclosure.A DigiKYC credential is structured so that individual claims can be revealed independently. A verifier that only needs to know the holder is over 18 and KYC-assured can be shown exactly those two facts — not a full name, address, or document number — while the issuer’s signature still validates over the disclosed subset. This means a low-touch check discloses far less than a full account opening, and the holder is never forced into over-sharing to clear a narrow requirement.
Bounded lifetime. Credentials carry an expiry and can be refreshed, so a verifier is always relying on a current assertion rather than a stale snapshot. Combined with consent and selective disclosure, this keeps the holder in control of what is shared, with whom, and for how long.
Who benefits from DigiKYC?
For regulated institutions
- Eliminate per-onboarding KYC costs (₹150–₹800 per customer)
- Reduce document storage liability under DPDP Act 2023
- Accelerate customer onboarding from days to seconds
- Access a pre-verified customer base through the AssureLocker network
For individuals
- No more submitting the same documents to every institution
- Faster account opening and loan processing
- Full control over what identity data is shared and with whom
- A portable digital identity that works across the regulated financial system
Is DigiKYC regulation-compliant?
AssureLocker's DigiKYC platform is designed to align with India's existing regulatory framework:
- RBI: Aligned with the Master Direction on KYC and the account aggregator framework principle of customer consent-driven data sharing.
- SEBI: Credential assurance levels map to SEBI KYC norms for investor onboarding.
- IRDAI: Supports digital onboarding guidelines for insurance products.
- DPDP Act 2023: Minimises data retention liability by design — institutions store an assertion, not a copy of Aadhaar or PAN documents.
We recommend institutions conduct their own legal review with their compliance counsel against their specific regulatory obligations and applicable RBI/SEBI/IRDAI circulars.
See it in action
Two short, interactive walkthroughs show what a DigiKYC credential does after it's issued — no account or real data required.
Consent-based sharing. When a verifier asks for identity, the holder approves on their phone and only the fields they consent to are shared — a cryptographic proof, not a raw document — an in-person QR scan or a remote approval.
Re-KYC without re-onboarding.Credentials carry an expiry, and DigiKYC refreshes them without starting over — an expiry reminder and a streamlined renewal that keeps the holder's reusable credential current.
Where AssureLocker sits — and where it does not
AssureLockeroperates as a technology service provider. It provides the identity and credential infrastructure — the verification ceremony, the signed reusable credential, the wallet, and the verification API — that lets a completed KYC be re-used with consent. It does not make lending, onboarding, or KYC-reliance decisions on any institution’s behalf, and it does not guarantee an outcome. Whether to rely on a presented credential, and on what terms to onboard a customer, remains entirely the relying institution’s own decision under its own policies and regulatory obligations.
In practice that means the platform makes the evidence checkable and portable, while the bank, NBFC, or mutual fund applies its own risk appetite and compliance judgement to it. See the DigiKYC platform for how the issuance and verification pieces fit together.
Getting started with DigiKYC
AssureLocker exposes a REST API for both credential issuance and verification. Integration does not require any special infrastructure or changes to your core banking system. A typical sandbox integration takes 2–3 developer days.
Explore the interactive KYC demos — consent sharing, re-KYC and vertical onboarding — or book a 30-minute demo with our team.