Back to All Blogs

Digital KYC for NBFCs in India: V-KYC, Aadhaar eKYC, and Compliance Requirements

Chailsee Yadav's avatar
Chailsee Yadav
Risk & Compliance

Customer identification is the first step in lending. Digital KYC has transformed how NBFCs complete this step from a branch visit with physical documents to a video call or Aadhaar OTP completed in minutes.

Digital KYC for NBFCs in India is now as much a regulatory framework as a technology choice. The RBI has specified which digital KYC methods are permitted, what each requires, and what fraud prevention controls must accompany them. This guide covers the complete digital KYC landscape.

The Three RBI-Approved Digital KYC Methods for NBFCs in India

Digital KYC for NBFCs in India operates within a framework of three RBI-approved identity verification methods. Each has different authentication strength, documentation requirements, and permitted use cases.

  • Aadhaar eKYC (OTP or biometric): the most streamlined method. The borrower’s Aadhaar number is authenticated via OTP to the registered mobile number or biometric (fingerprint/iris scan). The UIDAI returns the Aadhaar-stored demographic data: name, date of birth, address, photo. This constitutes an official identity verification for KYC purposes. Only licensed eKYC service providers or AUA (Authentication User Agencies) can perform Aadhaar eKYC.
  • Video KYC (V-KYC): a live video call between a trained NBFC official and the customer. The official verifies the customer’s identity document against their live appearance, captures a still image of the document and the customer, and verifies a randomly generated code displayed by the customer to confirm live presence. V-KYC is the RBI-approved method for remote in-person equivalent verification.
  • OTP-based video eKYC: a lighter video-based process using automated systems the customer films themselves holding their identity document, with liveness checks performed by AI. This is permitted for certain onboarding use cases but has specific RBI conditions on document quality, liveness detection accuracy, and fraud monitoring requirements.

Video KYC (V-KYC): Requirements and Best Practices

Video KYC for NBFCs in India must satisfy specific RBI requirements under the KYC Master Direction 2023.

Mandatory V-KYC requirements:

  • The video interaction must be conducted by a trained NBFC official, not an automated system or an outsourced agent without NBFC oversight.
  • The customer must present their original Aadhaar (or equivalent) during the video call. The NBFC official must confirm that the document is original by checking security features and that it is not a photocopy or a screen-displayed image.
  • A randomly generated code must be displayed by the customer during the interaction. The customer must speak the code aloud. This confirms live interaction, not a recorded video.
  • The full V-KYC interaction must be recorded and retained as part of the customer’s KYC documentation for the required retention period.
  • The NBFC must have a geotagging capability that records the customer’s location during the V-KYC interaction, verifying that the interaction is not taking place in a jurisdiction that the NBFC has identified as high-risk for KYC fraud.

Best practices beyond minimum requirements: AI-assisted document authenticity check during the V-KYC call (font analysis, hologram detection), face-match between the Aadhaar photo and the live video, and periodic quality audit of V-KYC recordings for compliance and accuracy.

Aadhaar eKYC for NBFCs: The OTP and Biometric Paths

Aadhaar eKYC provides two authentication paths for NBFCs.

OTP-based eKYC authenticates through the OTP sent to the mobile number registered with UIDAI. The OTP confirms that the person providing the Aadhaar number has access to the registered mobile number, a reasonable but not absolute identity confirmation. A significant proportion of Indian adults have their Aadhaar linked to a family member’s mobile, creating an OTP authentication gap.

Biometric-based eKYC authenticates through a fingerprint or iris scan matched against UIDAI’s biometric database. This is the highest-assurance digital identity verification available in India; the biometric cannot be easily transferred to a different person. Biometric eKYC requires authorised biometric device hardware and is typically deployed in physical branch or business correspondent contexts rather than fully remote onboarding.

The combination of Aadhaar OTP eKYC with a liveness check (a short video confirming the customer is physically present) provides a practical middle-ground authentication strength for remote digital onboarding.

PAN Verification and PAN-Aadhaar Linking

PAN verification is mandatory for all loan products in India above Rs 50,000 in value. The NBFC must verify that the PAN submitted by the applicant exists, belongs to the declared individual, and is valid.

PAN verification is performed through the Income Tax Department’s PAN verification API. The verification confirms the PAN exists, the date of birth, name, and PAN-Aadhaar linking status. PAN cards linked to Aadhaar have higher verification assurance; the Aadhaar link creates a cross-governmental identity cross-reference.

For NBFCs, a PAN that is not linked to Aadhaar is a verification flag that warrants additional identity confirmation. The RBI has made PAN-Aadhaar linking mandatory for financial services purposes, and an unlinked PAN limits the depth of identity verification available.

Fraud Prevention in Digital KYC for NBFCs

Digital KYC fraud targeting NBFCs operates through several specific mechanisms:

  • Deepfake liveness attacks: AI-generated video of a real person’s face overlaid on a fraudster’s video stream attempts to pass V-KYC liveness checks. Detection requires active liveness challenges (head turns, blink commands) that are harder for deepfakes to replicate in real-time, and AI-based deepfake detection models.
  • Aadhaar OTP interception: SIM swap fraud allows a fraudster who controls the victim’s phone number to receive the Aadhaar OTP. OTP-based eKYC alone is vulnerable to SIM swap attacks. Combining OTP with liveness and face-match provides additional layers against this attack.
  • Printed photo attacks on biometric systems: presenting a high-quality printed photograph or video screen to a biometric capture device instead of a live face. Prevented by infrared liveness detection hardware that distinguishes live skin from printed or screen-displayed images.
  • Identity aggregation fraud: building a synthetic identity using a real PAN, a real Aadhaar, and fabricated financial documents. Bureau analysis and bank statement cross-verification are the detection mechanisms for the financial data component of this fraud.

Key Takeaways

  • Digital KYC for NBFCs in India uses three RBI-approved methods: Aadhaar eKYC (OTP or biometric), Video KYC, and OTP-based video eKYC each with different assurance levels and compliance requirements.
  • V-KYC requires a trained NBFC official, original document presentation, a randomly generated live confirmation code, full interaction recording, and geotagging, all of which are mandatory RBI requirements.
  • Biometric Aadhaar eKYC provides the highest identity verification assurance for remote onboarding. OTP eKYC is more accessible but vulnerable to SIM swap attacks without additional liveness controls.
  • PAN-Aadhaar linking status is a verification quality signal linked PAN provides cross-governmental identity cross-reference; unlinked PAN warrants additional verification.
  • Deepfake liveness attacks, Aadhaar OTP interception, and synthetic identity fraud are the three primary digital KYC attack vectors requiring specific technical countermeasures.

Frequently Asked Questions

What digital KYC methods are permitted for NBFCs in India?

The RBI’s KYC Master Direction 2023 permits three digital KYC methods for NBFCs: (1) Aadhaar eKYC OTP or biometric authentication through UIDAI, performed by licensed eKYC agencies; (2) Video KYC (V-KYC)  live video interaction with a trained NBFC official verifying original documents and live presence; and (3) OTP-based video eKYC automated video with liveness checks, permitted for certain onboarding contexts with specific fraud monitoring requirements.

What is Video KYC and what does the RBI require for V-KYC compliance?

Video KYC is a live video call between the customer and a trained NBFC official that substitutes for an in-person branch visit. RBI requirements include: conducted by a trained NBFC official (not automated), original identity document presented during the call, randomly generated code spoken by the customer for liveness confirmation, full recording retained, and customer geotagging during the interaction.

Can an NBFC do completely paperless digital onboarding in India?

Yes. An NBFC can onboard a borrower completely paperlessly through Aadhaar eKYC for identity verification, Account Aggregator consent for bank statement data collection, GSTN API for GST data (SME borrowers), and CIBIL API for credit bureau data with the customer never submitting a physical document. The NBFC must maintain digital records of all consent events and KYC interactions as the audit trail.

What is the difference between OTP-based Aadhaar eKYC and biometric Aadhaar eKYC?

OTP-based eKYC authenticates through the OTP sent to the mobile number registered with Aadhaar. It verifies access to the registered mobile reasonable but not biometric confirmation of identity. Biometric eKYC authenticates through fingerprint or iris scan matched against UIDAI’s biometric database a higher-assurance verification that cannot be easily transferred to a fraudster. Biometric eKYC requires authorised biometric capture hardware and is typically used in physical or business correspondent contexts.

What are the most common digital KYC fraud attacks against NBFCs?

The three most common digital KYC fraud attacks are: deepfake liveness attacks (AI-generated video attempting to pass V-KYC liveness checks), SIM swap attacks enabling Aadhaar OTP interception, and synthetic identity fraud combining real identity documents with fabricated financial data. Countermeasures include active liveness challenges for deepfake detection, OTP combined with face-match for SIM swap protection, and cross-verification of KYC data against bureau and bank statement data for synthetic identity detection.

Conclusion

Digital KYC for NBFCs in India is a technology and compliance framework simultaneously. The technology enables remote, instant customer onboarding. The compliance framework ensures the verification is genuine and fraud-resistant.

The NBFCs that get digital KYC right are those that treat it as a risk management function, not just a customer experience function. Faster onboarding that admits more fraudsters does not serve the NBFC or the honest borrower.

Verify rigorously. Onboard fast. The two are not in conflict when the KYC infrastructure is properly designed.

Chailsee Yadav's avatar

Chailsee Yadav

Discover more from FinEye

Subscribe now to keep reading and get access to the full archive.

Continue reading