Before CKYCRR, every bank, NBFC, insurance company, mutual fund house, and securities intermediary maintained its own customer KYC repository. This resulted in:
- The customer needing to submit KYC documents repeatedly.
- High operational costs and onboarding delays.
- Errors in customer information.
- High customer drop-off rates.
CKYCRR resolves all these issues by keeping verified customer information in one place. However, the system is only valuable if institutions use and maintain this repository carefully — not as a one-time process, but as an ongoing one.
The need for a centralized KYC repository becomes even clearer when compared with the cost of traditional KYC operations. At the launch of the Central KYC Registry in 2016, DotEx International CEO Mukesh Agarwal stated that the platform could process uploads, downloads, and updates at an average cost of around ₹1 per transaction. By contrast, manual KYC verification often involves significantly higher operational costs due to document handling, verification, storage, and compliance reviews.
What is CKYCRR?
The full form is Central KYC Records Registry (CKYCRR). It is the central registry that stores and manages customer KYC records, and it is operated by CERSAI (Central Registry of Securitisation Asset Reconstruction and Security Interest of India). Whenever a financial institution onboards a customer, it must upload the verified KYC information to this registry.
After submission, the registry generates a unique 14-digit KIN (KYC Identifier Number), which is then used to access that customer’s record across the financial system.

Who Must Comply with CKYCRR?
CKYCRR compliance is mandatory for the following organizations:
| Regulator | Entities Covered |
| RBI | Commercial Banks, Payment Banks, Small Finance Banks, all NBFCs (Asset, Investment, Loan, Infrastructure), Cooperative Banks |
| SEBI | Stock Brokers, Depository Participants, Mutual Funds, Portfolio Managers, Research Analysts, Investment Advisers |
| IRDAI | All insurance companies (Life, General, Health), Insurance Intermediaries, Corporate Agents |
| PFRDA | National Pension System (NPS) Intermediaries, Pension Fund Managers |
How to Conduct CKYCRR Process?
Here is the step-by-step process of how a financial institution uses CKYCRR:
Step 1: Customer Verification
When a customer completes KYC with a bank, NBFC, mutual fund, or insurance company, the organization collects and verifies their identity and address documents, such as:
- Aadhaar
- PAN
- Passport
- Voter ID
- Driving License
Step 2: Risk Categorization
After verification, the institution must categorise the customer’s account according to its risk level — Low, Medium, or High Risk. This classification decides how frequently the KYC record must be updated in the future.
Step 3: KYC Record Submission to CKYCRR
The financial institution submits the verified customer record to CERSAI through the CKYCRR platform. Under CKYCRR 2.0, this submission happens through a real-time API call in structured JSON format, replacing the older scheduled batch upload.
Step 4: Validation and Duplicate Check
Before creating a new record, CKYCRR validates the submitted information and checks whether the customer already exists in the registry. It compares the details to prevent duplicate KYC records. Under CKYCRR 2.0, this validation is instant (through the API) and de-duplication is AI-assisted.
Step 5: KIN Generation
Once the record is verified, CKYCRR generates a unique 14-digit KYC Identifier Number (KIN), also called the CKYC Number. The KIN acts as a permanent reference number for the customer’s KYC record.
Step 6: KYC Record Retrieval
When the customer connects with another financial institution, that institution can search for the existing CKYC record using details such as PAN, Aadhaar, Voter ID, or Driving License. After the customer gives consent (through an OTP), the institution can retrieve the existing KYC record instead of collecting documents again. The customer is also notified whenever their record is searched or downloaded. This reduces onboarding time and improves the customer experience.
Step 7: Periodic Re-Verification
Financial institutions must periodically review and update customer KYC records based on their risk category. High-risk customers require more frequent re-verification than low-risk customers. Institutions should also update the record whenever the customer’s information changes like address, contact details, or identity proof.
What Details Are Submitted to CKYCRR?
After collecting and verifying the details, the following information must be uploaded to the registry:
| Required Information | Description |
| Demographic Details | Full Name, Date of Birth, Gender, Nationality |
| Contact Information | Mobile Number, Email Address, Permanent and Current Address |
| Identity Documents | Document Type (PAN, Aadhaar, Passport, Voter ID, Driving License), Document Number, Issuing Authority, Expiry Date |
| Biometric / Photograph | Recent customer photograph (passport size) |
| Risk Classification | Low / Medium / High risk justification |
| FATCA / CRS Details | Tax residency and foreign account status |
| Beneficial Ownership | For legal entities |
Note for CKYC 2.0: Records must now be submitted in structured JSON format, and Aadhaar masking is automated — only the last four digits of the Aadhaar number remain visible.
Automate your KYC Process & Reduce Fraud!
We have helped 3000+ companies in reducing Fraud by 95%
Risk-Based Re-Verification in CKYCRR
CKYCRR follows a risk-based approach to keeping records up to date:
| Risk Category | Re-Verification Frequency |
| High Risk | Every 2 Years |
| Medium Risk | Every 8 Years |
| Low Risk | Every 10 Years |
Institutions are required to periodically review customer records based on the assigned risk category and applicable RBI KYC guidelines. (These periodic-updation timelines are set out in the RBI Master Direction on KYC.)

What is the CKYCRR Record Bearing Reference? (The 14-Digit KIN Explained)
The CKYCRR Record Bearing Reference is a unique 14-digit number officially called the KYC Identifier Number (KIN). It is generated by CERSAI after a customer’s KYC record is successfully uploaded for the first time.
- It is a unique, permanent identifier assigned to each customer.
- It is sent to the customer via SMS and email on their registered contact details.
- Customers share this number with financial institutions instead of resubmitting physical documents.
- It allows any regulated entity to retrieve the full verified KYC record with the customer’s OTP consent.
- It generally remains valid throughout the customer’s lifetime, unless the record is modified, deactivated, or found to contain discrepancies.
Example: If you open a savings account at HDFC Bank and receive a KIN, you can use that same 14-digit number when opening a demat account with Zerodha or buying a life insurance policy — without resubmitting the same KYC documents.
How Can a Customer Find Their CKYC Number?
You don’t apply for a CKYC number separately — it is created automatically when a regulated institution completes your KYC. To find yours:
- Check the SMS and email sent to your registered mobile number and email when your KYC was first filed.
- Ask the bank, NBFC, or mutual fund that completed your KYC — they can look it up against your PAN or Aadhaar.
- Use the CKYC number lookup facility offered by your bank or fund house, where available.
CKYCRR 1.0 vs CKYCRR 2.0
CKYCRR 2.0 is the current upgrade to the registry, being rolled out through 2026 by CERSAI under RBI’s updated KYC Master Direction. It moves CKYC from delayed, batch-based uploads to a real-time, API-first system, and adds stronger consent, masking, and security requirements.
| Criteria | CKYCRR 1.0 | CKYCRR 2.0 |
| Submission | Scheduled batch file | Real-time API call |
| Data format | Flat file (data + scanned images) | Structured JSON / XML |
| Validation | Batch report (delayed) | Instant, through the API |
| De-duplication | Manual review | AI-assisted matching |
| Aadhaar masking | Manual | Automated — only last 4 digits visible |
| Customer consent | Basic | OTP-based, revocable consent before download |
| Security & audit | Standard | AES-256 encryption, TLS 1.2+, Indian data residency, tamper-evident audit logs |
| Update cycles | Risk-based (2 / 8 / 10 years) | Same risk-based cycles (2 / 8 / 10 years) |
What CKYCRR 2.0 Means for Institutions
Moving to CKYCRR 2.0 is not just a format change — it brings new obligations. Institutions must integrate real-time APIs into onboarding, submit records in structured JSON, capture OTP-based revocable consent before downloading a record, apply automated Aadhaar masking, and maintain tamper-evident audit logs with strong encryption. For teams still on older, batch-based systems, this migration is the biggest challenge — which is exactly where an API-first CKYC 2.0 platform helps.
What Common Challenges Occur while Conducting CKYCRR Process?
From what we see while helping institutions integrate CKYC, the most common challenges are:
- Duplicate KIN generation: Minor differences in names, addresses, or identity documents can lead to duplicate records. (In CKYCRR 2.0, AI-assisted matching reduces this, but clean data at source still matters most.)
- Data entry errors: Incorrect customer information leads to validation failures or record mismatches.
- System integration: Organizations using older onboarding systems face integration challenges while adopting CKYC 2.0’s real-time API workflows.
- Delayed record updates: Customer information must be updated on time to keep records accurate and compliant.
Legal Framework: What Laws Govern CKYCRR?
CKYCRR operates within a regulatory framework supported by:
- Prevention of Money Laundering Act, 2002 (PMLA): Provides the AML foundation that makes KYC mandatory for financial institutions. The Act came into force in 2005.
- Rule 9A of the PML (Maintenance of Records) Rules, 2005: This is the specific rule that requires reporting entities to file KYC records with the Central KYC Records Registry.
- SARFAESI Act, 2002 (Section 20): Authorised the creation of CERSAI as the central registry administrator.
Key regulatory notifications and milestones:
- 2015–2016: The Government of India authorised CERSAI to operate the Central KYC Records Registry, which became operational in July 2016
- December 2020 (effective April 1, 2021): RBI extended CKYCRR requirements to legal entities such as companies and trusts.
- 2024–2025: RBI amended the KYC Master Direction to align periodic-updation procedures with the PMLA rules and to introduce customer-friendly measures for low-risk customers.
How Can Surepass Streamline the CKYCRR Process with the Unified CKYC 2.0 Platform?
CKYC 2.0 introduces real-time validation, structured JSON submission, Aadhaar masking, facial de-duplication checks, and continuous lifecycle synchronization with CERSAI.
The Surepass CKYC 2.0 Platform simplifies this entire process with a single, automated solution. Organizations can search, download, upload, and update KYC records from one platform, and the system automatically validates data against CKYC 2.0 requirements to reduce rejection rates. Institutions can submit records, track application status, and receive updates without relying on manual processes — which means faster onboarding and higher conversion.
FAQs
Ques: Is CKYCRR mandatory for all financial institutions?
Ans: Yes, CKYCRR compliance is mandatory for reporting entities regulated by RBI, SEBI, IRDAI, and PFRDA under the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005. All reporting entities must upload and maintain KYC records in the Central KYC Records Registry (CKYCRR).
Ques: Can a customer have multiple KINs?
Ans: No, A customer should have only one KIN. However, duplicate KINs can sometimes occur due to discrepancies in submitted information, such as name mismatches or document inconsistencies, which are then resolved through reconciliation.
Ques: What documents are accepted for CKYCRR?
Ans: CKYCRR accepts all officially valid documents (OVDs), such as Aadhaar, PAN, Passport, Driving License, Voter ID, and NREGA Job Card.
Ques: How can I find my CKYC number?
Ans: Your CKYC number is generated when a regulated institution completes your KYC. You can find it in the SMS/email sent when your KYC was first filed, or by asking the institution that completed your KYC to look it up against your PAN or Aadhaar.
Ques: Can a financial institution access an existing CKYCRR record without the customer’s consent?
Ans: No, Financial institutions cannot access or download an existing CKYCRR record without the customer’s explicit consent, and the customer is notified whenever their record is searched or retrieved.