Last Updated  on: 27th August 2026       |        Last Reviewed on: 27th August 2026

Onboarding Workflow at a Glance

Obtain or retrieve the identifier, retrieve the record, check identity, handle any exception, complete wider due diligence, record who verified, then file and communicate the identifier, preserving evidence throughout. The base duties come from Rule 9 of the PML Rules; each regulator prescribes how they apply.

Legal Position at a Glance

Rule 9(1A) requires filing within ten days, Rule 9(1B) requires written communication of the identifier, Rule 9(1C) governs retrieval and the four exceptions, Rule 9(1E) makes the entity that performed the last verification responsible for the authenticity of the identity or address, and Rule 9(1F) restricts use to identity or address verification with no unauthorised transfer.

This page is a focused onboarding workflow. It does not restate the full obligation set for CKYCR compliance, upload architecture, governance and control testing, or use the detailed CKYCR compliance guide, which remains the authoritative professional page. For the identifier itself, see the pillar guide.

The Base Obligations Come from the PML Rules

The workflow rests on Rule 9 of the PML Rules, which binds reporting entities subject to those provisions. Each regulator adds scope and procedure on top, so state the base rule first and then the overlay.

Source level 

Requirement 

General position 

PML Rules, Rule 9(1A) 

File a new KYC record 

Within ten days of the account-based relationship 

PML Rules, Rule 9(1B) 

Communicate the KYC Identifier 

In writing to the client 

PML Rules, Rule 9(1C) 

Retrieve and reuse an existing record 

No fresh documents unless one of the four exceptions applies 

PML Rules, Rule 9(1D) 

File additional or updated information 

Within seven days, or another notified period 

PML Rules, Rule 9(1E) 

Responsibility for authenticity 

The entity performing the last verification or update is responsible for verifying authenticity of identity or address 

PML Rules, Rule 9(1F) 

Restrict use and onward transfer 

Identity or address verification only 

PML Rules, Rule 9(1H) 

Act on a CKYCR update notification 

Retrieve and update the internal record 

Regulator overlay to verify

Regulator 

Overlay to verify against the current instrument 

RBI 

Master Direction on KYC: explicit-consent position and operational requirements 

SEBI 

KRA interaction, upload mechanism and registered-intermediary process 

IRDAI 

Insurer and intermediary scope and confidential policyholder communication 

PFRDA 

Covered NPS reporting entities and subscriber terminology under the current PFRDA Master Circular 

IFSCA 

The activities and customer categories in the current IFSCA Guidelines to which CKYCR uploading applies 

The Onboarding Workflow, Step by Step

  1. Obtain the identifier. Ask the customer for the KYC Identifier, or retrieve it from CKYCR using permitted identification information, before creating a new record.
  2. Obtain consent as required. Capture the consent your regulator requires before downloading the record. Explicit consent is required under the RBI and PFRDA frameworks; securities-market entities apply the consent requirements in the current SEBI and KRA framework; other entities follow their regulator’s consent, confidentiality and authentication requirements. Keep evidence.
  3. Retrieve the record. Download the record and confirm it belongs to the customer using appropriate authentication.
  4. Check identity and adequacy. Assess the record for completeness and currency. It is the information filed with CKYCR, not a guarantee of completeness.
  5. Handle exceptions. Do not recollect the same documents unless a Rule 9(1C) exception applies: the information has changed; the record is incomplete or does not meet current KYC norms; a document has expired; or further information is necessary to verify identity or address, perform enhanced due diligence or build a risk profile (PML Rules requirement).
  6. Complete wider due diligence. Identify beneficial owners, run PEP screening and sanctions checks, complete the customer risk assessment and apply enhanced due diligence where required.
  7. Record who verified. Record which reporting entity performed the verification or furnished the update, because that entity is responsible under Rule 9(1E) for verifying the authenticity of the client’s identity or address.
  8. File and communicate. For a new customer, file the record within ten days (Rule 9(1A)) and communicate the identifier in writing (Rule 9(1B)).
  9. Record the decision and preserve evidence. Log the retrieval, the consent, the exception reasoning, the responsible verifier and the outcome.

Two Different Questions: Using the KIN Versus Using the Downloaded Record

Keep two permissions separate. First, when may the identifier be used: under the RBI framework, for establishing an account-based relationship, KYC updates, periodic KYC updates and identity verification. Second, how may the downloaded information be used: under Rule 9(1F), a reporting entity must not use a CKYCR record for a purpose other than verifying the client’s identity or address, and must not transfer it to a third party unless the client authorises it, or as otherwise permitted by the regulator or the Director, FIU-IND under the applicable framework (PML Rules requirement).

Consent and OTP

Consent requirements are set by the applicable framework. Consent is required under the RBI and PFRDA frameworks. Meanwhile, securities-market entities apply the consent requirements in the current SEBI and KRA framework; other entities follow their regulator’s requirements. An OTP, in case of an individual, may authenticate the customer and, where the consent and audit trail are adequate, may form part of the consent process. Retain evidence of the consent presented, the customer’s affirmative action, the authentication event and the purpose of access.

Evidence Expectations

The following is a recommended evidence framework. This includes legislation, regulatory directions, operating procedures or good compliance practice, and should be mapped to the entity’s applicable requirements.

Control 

Evidence expected 

Consent 

Consent text, timestamp, channel and affirmative action 

Authentication 

OTP or other authentication log 

Retrieval 

User ID, date, purpose and KIN 

Completeness review 

Review result and exceptions identified 

Additional-document request 

The Rule 9(1C) exception relied on 

Upload 

CKYCR acknowledgement and timestamp 

Communication 

Evidence that the KIN was sent to the customer in writing 

Update 

Date received, date verified and date uploaded 

Access control 

Approved role and periodic user-access review 

Not Sure If Your Onboarding Steps Hold Up?

Description: Most teams retrieve the record and move on. We look at how yours captures consent, handles exceptions and files on time, then tell you what to fix.

Frequently Asked Questions

Rule 9(1A) of the PML Rules requires filing within ten days of commencement of the account-based relationship, for reporting entities subject to Rule 9. Each regulator’s procedure applies on top of this.

Consent depends on the framework. Explicit consent is required under the RBI and PFRDA frameworks, and securities-market entities apply the SEBI and KRA consent requirements. An OTP can authenticate and support consent where the wording and audit trail are adequate, but is not a substitute for a clear consent record.

A CKYCR record may be used only to verify the client’s identity or address. It must not be transferred to a third party unless the client, the regulator or the Director authorises the transfer (PML Rules, Rule 9(1F)).

No. Beneficial ownership, screening, risk assessment and, where relevant, enhanced due diligence remain the entity’s obligations. The entity that performed the last verification is responsible for the authenticity of the identity or address (Rule 9(1E)), and ultimate responsibility stays with the entity opening the relationship.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik