We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CKYC · CERSAI · PML Rules

CKYC Compliance & CKYCR Audit

Independent review of your Central KYC Registry obligations — upload timeliness, template accuracy, KYC Identifier handling and the security of the KYC records you hold.

What the CKYCR actually is

The RBI Master Direction defines the Central KYC Records Registry as “an entity defined under Rule 2(1) of the Rules, to receive, store, safeguard and retrieve the KYC records in digital form of a customer”. The Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) was designated to perform those functions by Gazette Notification No. S.O. 3183(E) dated 26 November 2015.

In practice that makes CKYC a shared national KYC record store. A customer onboarded once can be identified by a KYC Identifier at any other regulated entity, which downloads the record rather than repeating collection — provided the customer gives explicit consent.

The obligation, and the clock

Under Rule 9(1A) of the PML Rules, regulated entities shall capture the customer’s KYC records and upload them onto the CKYCR within 10 days of commencement of an account-based relationship. Ten days is the part most programmes fail on — not because the requirement is unknown, but because nobody owns the exception queue when an upload is rejected for a template error.

Records must be submitted using the templates CERSAI publishes for Individuals and for Legal Entities, and those templates are revised from time to time. A template version you validated eighteen months ago is not evidence that today’s submissions are clean.

Who has been in scope, since when

  • The CKYCR live run began 15 July 2016, phased, starting with new individual accounts.
  • Scheduled Commercial Banks were required to upload KYC data for all new individual accounts opened on or after 1 January 2017.
  • Regulated entities other than SCBs were required to start uploading for new individual accounts opened on or after 1 April 2017.
  • KYC records for accounts of Legal Entities opened on or after 1 April 2021 must also be uploaded.

CERSAI additionally asks regulated entities to display the KYC Identifier to customers — on passbooks, account statements, mobile and internet banking, insurance policies and demat statements. It is a small obligation that is very visible when it is missing.

Where CKYC becomes a security and privacy problem

A CKYC programme is usually treated as an operations project, which is why the control gaps sit outside operations. The records are personal data — often including Aadhaar-derived identifiers — so the same estate is in scope for the DPDP Act, and the access, retention and audit-logging questions are the ones an examiner will actually ask.

  • Who inside the organisation can search CKYCR and download another institution’s KYC record, and is that access reviewed?
  • Is consent for a KYC Identifier download captured, stored and retrievable per customer?
  • Are downloaded records retained beyond the purpose that justified fetching them?
  • Is the CKYC integration’s API credential handling, logging and error queue covered by your IS audit scope, or has it fallen between the core banking and compliance teams?
  • Where Aadhaar is used for eKYC, do the AUA/KUA control obligations sit with someone who has read them?

What our review covers

We assess the CKYC control environment end to end rather than only the upload statistics: scope and data-flow mapping from onboarding to CKYCR submission; upload timeliness against the ten-day rule with a sample tested to source; template version control and rejection/exception handling; KYC Identifier issuance, display and consent capture; access control and logging over search and download; retention and deletion of downloaded records; and the overlap with your DPDP obligations and, where Aadhaar is used, the UIDAI AUA/KUA control set.

CyberSigma is a CERT-In empanelled information security auditing organisation, which matters because most RBI-regulated entities are required to have their information system audits performed by one.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 7 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • CERSAI operates the Central KYC Records RegistryEffective 26 November 2015

    The Master Direction defines the Central KYC Records Registry (CKYCR) as “an entity defined under Rule 2(1) of the Rules, to receive, store, safeguard and retrieve the KYC records in digital form of a customer”. The Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) was authorised to act as and perform the functions of the CKYCR by Gazette Notification No. S.O. 3183(E) dated 26 November 2015.

    “the Rules” means the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005.

  • KYC records must reach the CKYCR within 10 days

    Under Rule 9(1A) of the PML Rules, regulated entities shall capture the customer’s KYC records and upload them onto the CKYCR within 10 days of commencement of an account-based relationship with the customer.

    The ten days run from commencement of the relationship, not from when the record is judged complete — so a submission rejected on a template error still consumes the window.

  • Applicability was phased between 2016 and 2021Effective 1 April 2021

    The CKYCR live run began on 15 July 2016, phased, starting with new individual accounts. Scheduled Commercial Banks were required to upload KYC data for all new individual accounts opened on or after 1 January 2017 (with an initial allowance to 1 February 2017 for accounts opened during January 2017). Regulated entities other than SCBs were required to start uploading for new individual accounts opened on or after 1 April 2017. KYC records for accounts of Legal Entities opened on or after 1 April 2021 must also be uploaded.

    The Legal Entity obligation is the most recently added and the one most often missing from older CKYC programmes built around individual onboarding.

  • Submissions use CERSAI templates that change over time

    Regulated entities capture KYC information for sharing with the CKYCR as per the KYC templates prepared for “Individuals” and “Legal Entities”, and those templates may be revised from time to time as released by CERSAI. Operational Guidelines for uploading KYC data are published by CERSAI.

    Because the templates are revised, a validation performed against an older template version is not evidence that current submissions conform.

  • The KYC Identifier lets one entity retrieve another’s KYC record

    A customer may satisfy identification by submitting the KYC Identifier together with explicit consent for the regulated entity to download records from the CKYCR, instead of resubmitting officially valid documents. CERSAI asks regulated entities to display the KYC Identifier to customers on passbooks, account statements, mobile and internet banking, insurance policies and demat statements.

    The consent is the control that matters: a download without recorded, retrievable customer consent is an access to third-party personal data with no lawful basis to show an examiner.

Related

RBI KYC and video-based customer identification · UIDAI AUA/KUA audit · DPDP compliance services · RBI data localisation audit

Source: RBI Master Direction — Know Your Customer (KYC) Direction, 2016 (DBR.AML.BC.No.81/14.01.001/2015-16, 25 February 2016, updated as on 14 August 2025), and CERSAI. Verified 7 August 2026.

Free resource

RBI cybersecurity audit checklist

The control areas an RBI-regulated entity is examined on, with the evidence expected for each — useful whether your next audit is CKYC-related or the wider IS audit.

Excel · RBI-regulated entities
Email me the checklist
Free tool
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →