UIDAI · Aadhaar Ecosystem
AUA and KUA: Full Form, Meaning and Audit Requirements
AUA stands for Authentication User Agency and KUA for eKYC User Agency — entities permitted to use UIDAI's Aadhaar authentication and e-KYC services. Both must be audited annually by a certified information systems auditor.
Reviewed by Sharwan Jha, CyberSigma — CERT-In Empanelled & PCI QSA Authorised firm
AUA is the full form of Authentication User Agency and KUA of eKYC User Agency. An AUA is a requesting entity that uses UIDAI's Yes/No Aadhaar authentication; a KUA is an AUA that additionally uses the e-KYC service to fetch a resident's verified details after consent. Both operate under a UIDAI agreement that requires their operations to be audited annually by a certified information systems auditor, with the report shared with UIDAI on request. CyberSigma is CERT-In empanelled and PCI QSA authorised (CEMEA, Asia Pacific and the USA).
What AUA, KUA, Sub-AUA and ASA actually mean
The Aadhaar authentication ecosystem uses a small set of role names that are easy to confuse. Precisely:
- AUA — Authentication User Agency. A requesting entity permitted to use UIDAI's authentication service, which returns a Yes/No answer confirming whether the submitted Aadhaar credentials match.
- KUA — eKYC User Agency. An AUA that is additionally permitted to use e-KYC, which returns the resident's verified demographic details and photograph after the resident consents, typically via OTP or biometric.
- Sub-AUA — an entity that uses Aadhaar authentication through an existing AUA rather than holding its own permission. It inherits obligations contractually through that AUA, which remains accountable to UIDAI.
- ASA — Authentication Service Agency. The entity with secure connectivity to UIDAI's Central Identities Data Repository, through which an AUA's requests are routed. A KSA plays the equivalent role for e-KYC traffic.
- The practical point: whichever role you hold, the security obligations follow the Aadhaar data you touch, and an audit is how you evidence them.
What the audit obligation actually says
The requirement sits in the AUA/KUA agreement and UIDAI's information security expectations for the ecosystem rather than in a single standalone circular. In substance:
- Operations must be audited by an information systems auditor certified by a recognised body, on an annual basis and additionally on a need basis.
- The audit tests compliance with UIDAI standards and specifications — not a generic security baseline.
- The audit report must be shared with UIDAI on request, so it needs to be written to survive that scrutiny.
- UIDAI's guidance points to auditors certified or empanelled by CERT-In. It is worth being precise here: a CERT-In empanelled firm is not universally mandated for every AUA/KUA audit, but it is what regulators and ecosystem partners increasingly expect, and it removes an argument you do not need to have.
- Sub-AUAs are not exempt in practice — the sponsoring AUA carries the accountability and will pass the requirement down contractually.
What we test in an AUA / KUA audit
Aadhaar audits fail on the same things repeatedly, and almost none of them are exotic:
- Aadhaar data handling end to end — where the Aadhaar number, demographic data and biometric data enter, where they are stored, and whether they are being retained when they should not be.
- Encryption of the authentication request at capture, and the handling of the PID block, so that plaintext biometric or demographic data never persists outside the permitted window.
- Logging and audit trails of every authentication and e-KYC transaction, and their retention.
- Access control over the systems and staff that can reach Aadhaar-related data, including privileged access and third-party developers.
- Application and infrastructure security of the client application performing authentication, tested rather than assumed.
- Consent capture for e-KYC, and the disclosure shown to the resident before authentication.
- Exception and incident handling, including how a suspected compromise would be reported.
How the audit runs, and what it costs
Scope drives the effort: the number of applications performing authentication, the environments involved, and whether you hold AUA, KUA or Sub-AUA status. We agree the scope in writing and quote fixed before starting, then deliver a report mapped to UIDAI's expectations with findings ordered by risk, and re-test after remediation so you can evidence closure. If you are working to a UIDAI or sponsoring-AUA deadline, tell us the date and we will say plainly whether it is achievable.
Why CyberSigma for an AUA / KUA audit
We are CERT-In empanelled, which is the credential the Aadhaar ecosystem increasingly expects of the auditor, and we test the client application rather than reviewing documents about it. You get an assessor who understands the difference between an AUA and a KUA obligation, a report written for UIDAI's scrutiny, and a re-test after you fix what we find.
Related services
System Audit Report (SAR)
Regulator-mandated system audits for RBI, NPCI and SEBI entities.
ISNP audit
IRDAI Insurance Self Network Platform security audit and readiness.
VAPT services in India
CERT-In empanelled penetration testing across web, mobile, API, network and cloud.
Cybersecurity audit
Independent audit against CERT-In, RBI, SEBI and ISO 27001.
Frequently asked questions
What is the full form of AUA?
AUA stands for Authentication User Agency — a requesting entity permitted by UIDAI to use Aadhaar authentication, which returns a Yes/No response confirming whether the submitted credentials match the resident's record.
What is the full form of KUA?
KUA stands for eKYC User Agency, also written KYC User Agency. A KUA is an AUA that is additionally permitted to use UIDAI's e-KYC service, which returns the resident's verified demographic details and photograph after the resident consents.
What is the difference between an AUA and a KUA?
An AUA can only verify — it asks UIDAI whether the Aadhaar credentials match and receives a Yes or No. A KUA can additionally retrieve: with the resident's consent it obtains verified demographic details and a photograph for onboarding. Every KUA is an AUA; not every AUA is a KUA. The KUA role touches more personal data, so the security and consent obligations are correspondingly heavier.
Is an annual audit mandatory for an AUA or KUA?
Yes. The AUA/KUA agreement requires operations to be audited by a certified information systems auditor annually, and additionally on a need basis, to confirm compliance with UIDAI standards and specifications. The report must be shared with UIDAI on request.
Does the auditor have to be CERT-In empanelled?
UIDAI's guidance points to auditors certified by CERT-In, and empanelment is what regulators and sponsoring entities increasingly expect — but it is not universally mandated in every case. Using a CERT-In empanelled firm removes the question entirely. CyberSigma is empanelled.
Do Sub-AUAs need an audit too?
In practice yes. A Sub-AUA operates under a sponsoring AUA's permission, and that AUA remains accountable to UIDAI for the Aadhaar data handled beneath it — so the obligation is passed down contractually. We regularly audit Sub-AUAs at the sponsoring entity's request.
How long does an AUA / KUA audit take?
It depends on how many applications perform authentication and how many environments are in scope. A single-application AUA is a short engagement; a multi-product KUA with several integrations takes longer. We scope it, quote fixed, and tell you honestly whether your deadline is reachable.
Sources & references
- UIDAI — Unique Identification Authority of India — the authority governing Aadhaar authentication and the AUA/KUA ecosystem
- UIDAI AUA / KUA Agreement (v4.0) — the agreement setting out a requesting entity's obligations, including audit
- CERT-In (Indian Computer Emergency Response Team) — the national nodal agency; maintains the empanelled auditor list

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
