Last Updated on: 1st September 2026 | Last Reviewed on: 1st September 2026
KIN Across Financial Sectors: Key Takeaways
One KIN may support reuse of the same central KYC record through the applicable sectoral process, where the receiving entity is authorised and follows its sector’s requirements. The PML Rules provide the common statutory foundation, while RBI, SEBI, IRDAI, PFRDA and IFSCA apply different sectoral processes. KIN reuse does not transfer another institution’s approval or risk rating. CKYCR and KRA KYC are connected but distinct. Additional information may still be required under Rule 9(1C) or a sector-specific framework. Beneficial ownership, screening, risk assessment and ongoing monitoring remain the reporting entity’s responsibility, and a specific foreign-national treatment applies in an IFSC under the proviso to Rule 9A(1).
Does the Same KIN Work Across Financial Sectors?
A KIN identifies a customer’s record in the Central KYC Records Registry and is intended to support reuse of that record across participating financial sectors. However, a bank, insurer, securities intermediary, pension intermediary or IFSCA-regulated entity must apply its own regulator’s requirements concerning access, consent, verification, additional information and customer due diligence.
KIN Across Sectors: Key Position
Question | Short answer |
Can one KIN be used across sectors? | Potentially yes; the same CKYCR record is intended to support reuse, but the receiving entity must be authorised and follow its sector’s access, consent and verification requirements |
Is the process identical in every sector? | No |
Does every institution have unrestricted access? | No |
Does KIN remove sector-specific KYC? | No; it does not remove sector-specific onboarding and customer-due-diligence requirements |
Can the institution ask for more information? | Yes, where a Rule 9(1C) exception or a sector requirement applies |
Does KIN complete CDD? | No |
Does KIN determine customer risk? | No |
Are CKYCR and KRA KYC the same? | No |
Is there a special IFSC position? | Yes, including the foreign-national treatment under the proviso to Rule 9A(1) |
Why the KIN Process Differs Across Financial Sectors
CKYCR is intended to enable inter-usability of KYC records, so a record created once can be reused rather than rebuilt. The Prevention of Money-laundering (Maintenance of Records) Rules, 2005 provide the statutory baseline for filing, communicating, retrieving, updating and using those records. Each financial-sector regulator then overlays its own process on that baseline.
Retrieval of a record is not the same as automatic acceptance: the retrieving institution must still assess whether the record is complete, current and adequate, and it may require product-specific, risk-specific or sector-specific information. A KIN does not carry the customer’s risk rating, screening results or onboarding approval from one entity to another. The number may remain the same, but the legal obligations, the customer journey and the additional information required can differ across sectors.
What Remains Common for Reporting Entities Subject to the CKYCR Provisions?
PML Rules Baseline
Rule 9 of the PML Rules provides the principal framework for filing, communicating, retrieving, updating and using CKYCR records. Sectoral regulators then prescribe the scope, procedure, access requirements, consent arrangements and supplementary controls applicable to the entities they supervise.
Provision | Common statutory position |
Rule 2(1)(cc) | Defines the KYC Identifier |
Rule 9(1A) | Filing of a new electronic KYC record |
Rule 9(1B) | Written communication of the identifier |
Rule 9(1C) | Retrieval and restrictions on repeat collection |
Rule 9(1D) | Furnishing additional or updated information |
Rule 9(1E) | Responsibility for authenticity |
Rule 9(1F) | Restriction on use and onward transfer |
Rule 9(1H) | Action after a CKYCR update notification |
Proviso to Rule 9A(1) | IFSC treatment for a foreign-national client |
What a KIN can do
A KIN can locate the corresponding central KYC record, support retrieval by an authorised entity, reduce unnecessary repeat collection, assist with customer onboarding and updating, and facilitate cross-sector inter-usability of the record.
What a KIN cannot do
A KIN cannot approve the customer automatically, replace customer due diligence, identify beneficial owners by itself, complete sanctions, PEP or adverse-media screening, establish source of funds or source of wealth, transfer another institution’s risk rating, guarantee that the central record is current or adequate, or override sector-specific regulatory requirements.
KIN and CKYCR Across Sectors: Comparison Table
Each row should be confirmed against the current regulator instrument in force on the publication date, rather than filled from generic assumptions.
Sector | Principal regulator | Institutions covered | How KIN and CKYCR are used | Important sector difference |
Banking and NBFCs | RBI | Banks, co-operative banks, NBFCs and other covered entities | Retrieve and use CKYCR records under the RBI framework | RBI-specific consent and operational requirements |
Securities and mutual funds | SEBI | Mutual funds, brokers, depository participants and other intermediaries | CKYCR operates alongside the KRA framework | KRAs and CKYCR are connected but distinct |
Insurance | IRDAI | Insurers and covered intermediaries | Retrieve and use policyholder CKYCR records | Insurance-specific onboarding and communication |
Pension and NPS | PFRDA | Points of Presence and other covered NPS intermediaries | Retrieve and use subscriber CKYCR records | Subscriber terminology and PFRDA operational requirements |
Payment systems and PPIs | RBI | Covered payment-system and prepaid-instrument entities | CKYCR use depends on the product and KYC category | Product limits, permitted functionality and the applicable KYC category depend on the current RBI product framework |
GIFT IFSC | IFSCA | Applicable IFSCA-regulated entities and activities | CKYCR applies according to the IFSCA framework | Special foreign-national exemption under the IFSCA Guidelines |
Other PMLA reporting entities | Relevant authority | Sector-dependent | Applicability depends on legal and technical implementation | Do not assume banking-style access or use |
KIN for Banks, Co-Operative Banks and NBFCs
Banks, co-operative banks and NBFCs within the RBI’s scope retrieve and use CKYCR records under the RBI framework, applying the PML Rules baseline.
How the KIN is used
The customer may provide the KYC Identifier, or the entity may retrieve it through the permitted process. Explicit consent is required under the RBI framework. The entity assesses the record for completeness and currency, relies on the Rule 9(1C) exceptions where a fresh request is justified, and continues its own customer due diligence, screening and risk assessment (RBI requirement; PML Rules, Rule 9(1C)).
What the customer should expect
The same central record may reduce repeat documentation, but the institution can still request additional information where legally justified, and product-specific information may still be required. The bank’s approval and risk assessment remain independent. A KIN created through one RBI-regulated relationship may support onboarding with another authorised institution, but it does not guarantee account opening or eliminate the need for current and product-specific information. See find and download your KIN and the KYC Identifier onboarding workflow.
Need Help With Your KYC Process?
Our AML specialists work with reporting entities across banking, securities, insurance and pensions to get KYC and CKYCR handling right.
KIN for Mutual Funds, Demat Accounts and Securities Intermediaries
Securities onboarding sits where CKYCR meets the securities-market KYC framework, so a customer may encounter both systems.
CKYCR and KRA KYC are connected but different
CKYCR is the central registry under the PML Rules. KYC Registration Agencies operate under the securities-market framework. A KRA KYC status is not itself the KIN. SEBI has prescribed uploading to CKYCR through KRAs, so the two systems interact but remain distinct. The distinction is explained on the KIN versus KRA KYC page.
Can a bank-generated KIN be used for a mutual fund?
The applicable securities-market process uses information available through the KRA and CKYCR framework. The intermediary must verify the investor’s current KYC status, apply the SEBI requirements and obtain any securities-specific information, and may require remediation of an inadequate record. This is not a simple, unqualified yes.
Demat-account treatment
For a demat account, the central KYC record may be available for use through the applicable SEBI, KRA and CKYCR process, while the depository participant applies the current securities-market KYC requirements. FATCA and tax-residency declarations, financial details, nominee information and other product information may remain separate, and the KIN does not replace the securities-market risk assessment.
KIN for Insurance Policies
Insurers and covered intermediaries within the IRDAI framework use central KYC records for policyholder onboarding and updating.
How insurers use the central KYC record
An insurer may retrieve and assess the CKYCR record under the applicable IRDAI framework. The insurer remains responsible for determining whether the information is current and adequate and for completing insurance-specific customer due diligence, including product, beneficiary, nominee and risk information, and it communicates the KYC Identifier to the policyholder confidentially (IRDAI requirement).
Can an insurer use a KIN created by a bank?
The insurer may retrieve and assess the existing CKYCR record under the applicable insurance framework. It must still collect insurance-specific information and determine whether the record is current and adequate.
What KIN does not replace in insurance
A KIN does not replace beneficial-owner identification for entity policyholders, source-of-funds review where required, beneficiary and nominee information, sanctions and PEP screening, product suitability or underwriting information, or enhanced due diligence.
KIN for NPS and pension-sector onboarding
The pension framework commonly refers to the customer as the subscriber and may involve a Point of Presence or another authorised intermediary.
How CKYCR is used
Where a valid KYC Identifier is available, the reporting entity may retrieve the CKYCR record with the subscriber’s explicit consent and assess it under the current PFRDA framework. Where no identifier is available, the reporting entity captures and files the KYC record with CKYCR within the applicable period. Once an identifier is generated, it must be communicated immediately and confidentially to the subscriber. Updates must be furnished and acted upon in accordance with the applicable PFRDA and PML Rules requirements.
What remains separate
NPS registration information, bank and nomination information, tax and residency details, subscriber risk and verification steps, and product-specific declarations remain separate from the central KYC record.
KIN for Payment Systems and Prepaid Instruments
Application varies by product and KYC level, so this section is deliberately brief. RBI-regulated payment entities may use CKYCR where the applicable product and KYC framework require it. CKYCR recognises different record categories, including small, simplified and OTP-based records, but whether any such category is available or adequate for a particular payment or prepaid-instrument product depends on the current RBI product and KYC requirements. Not every wallet or payment relationship follows the same full-KYC journey, and limits, product type and any conversion to full KYC may affect the process. The record-category prefixes themselves are explained in the KIN number guide.
Caution
The availability of a KIN does not by itself determine the product limits or permitted functionality of a prepaid instrument. Those matters depend on the applicable RBI product and KYC framework.
KIN and CKYCR in GIFT IFSC
The IFSCA overlay
IFSCA-regulated entities and activities covered by the applicable CKYCR provisions must follow the IFSCA AML/CFT/KYC Guidelines. The applicable activities and customer categories must be checked, the RBI process should not be imported automatically, and Indian-resident and foreign-national treatment should be distinguished.
Foreign Nnational Treatment
Under the proviso to Rule 9A(1) of the PML Rules, CKYCR’s receiving, storing, safeguarding and retrieval functions are not required in an IFSC for a client who is a foreign national.
Although CKYCR submission is not required for a foreign-national client, the current IFSCA Guidelines contemplate that a regulated entity may choose to submit such a record. Where it does so, it must follow the documentation and address-proof requirements prescribed in the Guidelines.
Foreign legal entities
Do not assume that the foreign-national exception automatically applies to every foreign legal entity. The treatment should be determined under the IFSCA Guidelines and the applicable legal interpretation, distinguishing natural persons, legal entities, beneficial owners and authorised signatories. The IFSC position is set out further in the detailed CKYCR compliance guide.
Do DNFBPs and Other Reporting Entities Use CKYCR in the Same Way?
No. The fact that an entity is a reporting entity under the PMLA does not necessarily mean that its CKYCR access, filing process and technical implementation are identical to those of a bank or securities intermediary. Applicability depends on the PML Rules, the sectoral directions, technical registration and access, the customer and relationship type, and the current operational implementation, so uniform cross-sector functionality should not be assumed. Categories such as accountants, real-estate agents, dealers in precious metals and stones, virtual digital asset service providers and other notified businesses and professions should not be treated as having equal CKYCR access unless that is verified from an authoritative source. Our guide to DNFBPs subject to PMLA sets out who is covered.
What Stays the Same and What Differs Across Sectors?
Generally consistent across sectors | May differ by sector |
KIN refers to the CKYCR record | The consent mechanism |
The PML Rules form the statutory baseline | Who files or arranges the filing |
The record must be assessed for adequacy | The role of an intermediary such as a KRA or Point of Presence |
KIN does not complete CDD | Customer terminology |
The Rule 9(1C) exceptions remain relevant | Product-specific information |
Beneficial ownership remains separate | The technical access process |
Screening and risk assessment remain necessary | Foreign-national and residency treatment |
Use and transfer are restricted | Sectoral reporting and record-keeping requirements |
Examples of How One KIN May be Used Across Sectors
These are illustrative examples.
Scenario 1: bank customer investing in a mutual fund
A customer with an existing CKYCR record from a bank starts a mutual-fund investment. The investor’s KYC information is processed through the applicable SEBI, KRA and CKYCR framework, and the securities intermediary assesses whether the record is adequate for the proposed relationship. Securities-specific declarations may still be required, and the earlier bank onboarding does not automatically complete securities KYC.
Scenario 2: bank customer purchasing insurance
A bank customer buys an insurance policy. The insurer processes the available central KYC information under the applicable IRDAI framework and determines whether it is adequate for the proposed policy. Insurance-specific information, such as beneficiary and nominee details and product or underwriting information, remains necessary, and the insurer performs its own risk assessment. The same KIN can speed retrieval of identity and address, but it does not settle the insurance onboarding.
Scenario 3: NPS subscriber with an existing KIN
An NPS subscriber already has a KIN. A Point of Presence or authorised intermediary retrieves the record with the subscriber’s consent under the current PFRDA framework. NPS-specific onboarding information, nomination and bank details, and subscriber declarations are still gathered. The identifier supports reuse of the central record, while the pension onboarding follows the PFRDA process.
Scenario 4: foreign national onboarding in GIFT IFSC
A foreign national is onboarded by an IFSCA-regulated entity in GIFT IFSC. Under the proviso to Rule 9A(1), CKYCR’s receiving, storing, safeguarding and retrieval functions are not required for a foreign-national client. The entity applies the IFSCA Guidelines rather than importing the domestic CKYCR process and distinguishes the treatment of individuals from that of legal entities.
Common Misconceptions About KIN Across Sectors
Misconception | Correct position |
A bank KIN automatically completes mutual-fund KYC | The securities framework must still be applied |
One institution’s approval binds another | Each entity makes its own onboarding and risk decision |
The same KIN means the same customer risk rating | Risk assessment is institution-specific |
KRA KYC and CKYCR are the same database | They are related but distinct systems |
A KIN prevents all requests for further information | Rule 9(1C) and sector requirements permit justified requests |
Every reporting entity accesses CKYCR like a bank | Sectoral and technical implementation may differ |
A KIN proves beneficial ownership | Beneficial ownership must be established separately |
KIN reuse means records can be freely shared | Rule 9(1F) restricts use and onward transfer |
What Customers Should Do
Retain the KIN communication securely, use only official channels, keep the central record updated, ask why additional documents are required, verify unexpected access alerts, and do not assume that one onboarding approval applies everywhere. For the practical steps, see find and download your KIN, update your CKYC record.
What Reporting Entities Should Do
Identify the applicable PML Rules provision, identify the regulator overlay, obtain the required consent, retrieve and authenticate, assess completeness and currency, document the Rule 9(1C) exception relied on, complete independent customer due diligence, preserve evidence, apply sector-specific requirements, and avoid importing another regulator’s process. The workflow is on the KYC Identifier onboarding workflow page, consent and privacy on the CKYC consent and privacy page, and the full detail in the complete CKYCR compliance guide.
Want an Expert Review of Your Compliance?
We help teams check their onboarding, due diligence and record-keeping against what their regulator expects, and fix what is missing.
Frequently Asked Questions
Potentially yes. The record may be retrievable and usable through the applicable securities-market process, but the intermediary applies the SEBI and KRA requirements and may request securities-specific information, so it is not an automatic transfer.
An insurer may retrieve and assess the existing CKYCR record under the IRDAI framework. It must still collect insurance-specific information, such as beneficiary and nominee details, and determine whether the record is current and adequate before onboarding.
The central KYC record may be available for use through the applicable SEBI, KRA and CKYCR process when opening a demat account, while the depository participant applies the securities KYC process. Product information such as FATCA and tax-residency declarations and nominee details may still be needed, and the securities risk assessment is separate.
No. CKYCR is the central registry under the PML Rules, while a KYC Registration Agency operates under the securities-market framework. A KRA KYC status is not the KIN. The two systems interact because SEBI has prescribed uploading to CKYCR through KRAs, but they are distinct.
Potentially yes. Pension intermediaries within the PFRDA framework may retrieve and use the central record with the subscriber’s consent. NPS registration, nomination, bank and tax details, and subscriber declarations are still gathered separately under the current PFRDA framework.
They apply the same PML Rules baseline and the RBI framework, but operational details can differ between institutions. Each entity assesses the retrieved record and applies its own risk-based due diligence, so the customer journey is not always identical.
Yes. Each reporting entity assesses whether the record is complete, current and adequate for its own product, customer and risk profile. It may request information under Rule 9(1C) or a sector-specific requirement, and it may independently decide whether to establish the relationship.
No. A KIN supports retrieval of identity and address information, but the customer’s risk rating is assessed by each institution. Risk assessment, screening and enhanced due diligence remain institution-specific and are not transferred with the identifier.
Potentially yes. A legal entity’s CKYCR record may be retrievable and usable across participating sectors through the applicable process, but each entity must still verify authority and beneficial ownership and may require more information.
Under the proviso to Rule 9A(1) of the PML Rules, CKYCR’s receiving, storing, safeguarding and retrieval functions are not required in an IFSC for a client who is a foreign national. IFSCA-regulated entities apply the IFSCA Guidelines and distinguish resident from foreign-national customers.
Yes. Under Rule 9(1C) of the PML Rules, an entity may request more where the information has changed, the record is incomplete or does not meet current norms, a document has expired, or further information is needed to verify identity or address, perform enhanced due diligence or build a risk profile.
Not necessarily. CKYCR access, filing and technical implementation for a DNFBP depend on the PML Rules, the sectoral directions and the current operational position, and should not be assumed to match a bank. See DNFBPs subject to PMLA.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik