Banks and FinTechs race to meet CKYC 2.0 compliance

CKYC

Banks, NBFCs, FinTechs and insurers across India are racing against the clock as CKYC 2.0 (CKYCRR 2.0) approaches its rollout, expected by the end of July 2026 subject to institutional readiness.

According to ZIGRAM, with supervisory expectations from the Reserve Bank and other regulators intensifying, firms that fall short of readiness benchmarks face submission failures, regulatory penalties and disrupted customer onboarding at scale.

ZIGRAM recently put together a CKYC 2.0 compliance checklist for banks, NBFCs & FinTechs, and detailed five essential readiness areas.

The most visible change is the shift away from batch PDF uploads towards a real-time, API-first architecture, but the upgrade reaches far deeper, touching data quality, identity verification, audit trails, operational workflows and ongoing risk management. The scale of the transformation is underlined by India recording 103 crores of CKYC registrations in 2025, alongside CERSAI awarding a Rs. 161 crore contract for CKYCRR 2.0.

The regulatory backdrop is tightening too. The RBI KYC Master Direction was refreshed on 6 November 2024, while a PMLA notification from 19 July 2024 now obliges regulated entities to synchronise record changes within seven days. Layered on top is the Digital Personal Data Protection (DPDP) Act 2023, with rules notified on 13 November 2025 and hard enforcement, carrying penalties of up to ₹250 crore, beginning on 13 May 2027.

Data quality sits at the foundation of readiness. Institutions must convert millions of legacy PDF records into structured XML or JSON formats, audit records for gaps in demographic data, resolve duplicate CKYC IDs through PAN, Aadhaar and demographic matching, and meet imaging standards including 150–200 DPI scans and photo files capped at roughly 100 KB.

Aadhaar masking must extend beyond image layers into logs, analytics and data warehouses. Remediation can take four to 12 weeks, making an early start essential.

On the technology side, firms must test all CKYCRR 2.0 API endpoints, from Search and Download to Upload and Update, with OTP-based customer consent mandatory before full records are released.

The new registry is built to handle at least 40 lakh KYC uploads daily, and institutions must match that resilience, deploying AES-256 encryption at rest, TLS 1.2 or higher in transit, and Indian data residency. DigiLocker integration enables real-time fetching of Officially Valid Documents directly from issuing authorities.

Documentation demands are equally rigorous. Every registry interaction must generate immutable, tamper-evident logs tied to operator identity, timestamps and consent IDs, with access logs retained for at least a year. Consent must be explicit, revocable and audit-logged, aligned with DPDP principles of purpose limitation and data minimisation.

Operationally, onboarding workflows need redesigning for structured data capture and real-time validation, with staff trained on masking procedures, consent flows and new data fields. Risk-based periodic updates apply, with high-risk customers reviewed every two years, medium-risk every eight and low-risk every ten.

Finally, CKYC 2.0 should feed a wider financial crime prevention strategy, with AI-driven deduplication, enriched sanctions screening and transaction monitoring integration. Institutions treating the migration as strategic infrastructure rather than a regulatory checkbox stand to gain lasting advantages in onboarding efficiency and fraud prevention.

Read the full ZIGRAM post here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.