CKYC · CERSAI · PML Rules
CKYC Compliance & CKYCR Audit
Independent review of your Central KYC Registry obligations — upload timeliness, template accuracy, KYC Identifier handling and the security of the KYC records you hold.
What the CKYCR actually is
The RBI Master Direction defines the Central KYC Records Registry as “an entity defined under Rule 2(1) of the Rules, to receive, store, safeguard and retrieve the KYC records in digital form of a customer”. The Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) was designated to perform those functions by Gazette Notification No. S.O. 3183(E) dated 26 November 2015.
In practice that makes CKYC a shared national KYC record store. A customer onboarded once can be identified by a KYC Identifier at any other regulated entity, which downloads the record rather than repeating collection — provided the customer gives explicit consent.
The obligation, and the clock
Under Rule 9(1A) of the PML Rules, regulated entities shall capture the customer’s KYC records and upload them onto the CKYCR within 10 days of commencement of an account-based relationship. Ten days is the part most programmes fail on — not because the requirement is unknown, but because nobody owns the exception queue when an upload is rejected for a template error.
Records must be submitted using the templates CERSAI publishes for Individuals and for Legal Entities, and those templates are revised from time to time. A template version you validated eighteen months ago is not evidence that today’s submissions are clean.
Who has been in scope, since when
- The CKYCR live run began 15 July 2016, phased, starting with new individual accounts.
- Scheduled Commercial Banks were required to upload KYC data for all new individual accounts opened on or after 1 January 2017.
- Regulated entities other than SCBs were required to start uploading for new individual accounts opened on or after 1 April 2017.
- KYC records for accounts of Legal Entities opened on or after 1 April 2021 must also be uploaded.
CERSAI additionally asks regulated entities to display the KYC Identifier to customers — on passbooks, account statements, mobile and internet banking, insurance policies and demat statements. It is a small obligation that is very visible when it is missing.
Where CKYC becomes a security and privacy problem
A CKYC programme is usually treated as an operations project, which is why the control gaps sit outside operations. The records are personal data — often including Aadhaar-derived identifiers — so the same estate is in scope for the DPDP Act, and the access, retention and audit-logging questions are the ones an examiner will actually ask.
- Who inside the organisation can search CKYCR and download another institution’s KYC record, and is that access reviewed?
- Is consent for a KYC Identifier download captured, stored and retrievable per customer?
- Are downloaded records retained beyond the purpose that justified fetching them?
- Is the CKYC integration’s API credential handling, logging and error queue covered by your IS audit scope, or has it fallen between the core banking and compliance teams?
- Where Aadhaar is used for eKYC, do the AUA/KUA control obligations sit with someone who has read them?
What our review covers
We assess the CKYC control environment end to end rather than only the upload statistics: scope and data-flow mapping from onboarding to CKYCR submission; upload timeliness against the ten-day rule with a sample tested to source; template version control and rejection/exception handling; KYC Identifier issuance, display and consent capture; access control and logging over search and download; retention and deletion of downloaded records; and the overlap with your DPDP obligations and, where Aadhaar is used, the UIDAI AUA/KUA control set.
CyberSigma is a CERT-In empanelled information security auditing organisation, which matters because most RBI-regulated entities are required to have their information system audits performed by one.
Related
RBI KYC and video-based customer identification · UIDAI AUA/KUA audit · DPDP compliance services · RBI data localisation audit
Source: RBI Master Direction — Know Your Customer (KYC) Direction, 2016 (DBR.AML.BC.No.81/14.01.001/2015-16, 25 February 2016, updated as on 14 August 2025), and CERSAI. Verified 7 August 2026.
RBI cybersecurity audit checklist
The control areas an RBI-regulated entity is examined on, with the evidence expected for each — useful whether your next audit is CKYC-related or the wider IS audit.
