Last Updated on: 22nd July 2026 | Last Reviewed on: 22nd July 2026
CKYCRR means the Central KYC Records Registry, India’s central repository of verified KYC records operated by CERSAI. This guide is written for reporting entities and compliance teams, including entities in GIFT IFSC regulated by the IFSCA. It sets out the legal basis, the filing and updating obligations, the operational workflow, the IFSC-specific position, and governance expectations. A short section for individuals explains the CKYC record and reference number.
A note on abbreviations. This guide uses CKYCRR for the Central KYC Records Registry. Some legislation and IFSCA instruments use CKYCR for the same registry; this guide uses CKYCR where it refers directly to the wording of an IFSCA clause.
CKYCRR does not mean “Central Know Your Customer Records Rules”
CKYCRR means Central KYC Records Registry, the repository operated by CERSAI under the PML Rules. The RBI may inspect the Registry under Rule 9B, but CKYCRR is not an RBI rulebook.
Legal position at a glance
| Issue | Position | Source | Entity action |
| CKYCRR Full form | Central KYC Records Registry, operated by CERSAI | PML Rules, r.2(1)(ac) | Use the correct name and operator |
| Filing timeline | File within ten days of the account-based relationship, where applicable | PML Rules, r.9(1A) | Upload within ten days |
| Update timeline | Furnish updated information within seven days | PML Rules, r.9(1D) | File updates within seven days |
| IFSC filing | For the eleven activities in clause 11.6(e): the heading refers to Indian-resident natural and legal entities, the Guidance Note requires filing for Indian nationals and exempts foreign-national natural persons | IFSCA Guidelines, clause 11.6 | Assess natural persons and legal entities separately, document NRI and foreign-entity treatment |
| General re-KYC cycle | Annually (high), three years (medium), five years (low) | IFSCA Guidelines, 2022 | Schedule periodic updating by risk |
| Resident-Indian re-KYC | Two, eight and ten years for certain resident Indians in the financial group | IFSCA circular, 2 January 2026 | Apply only to the eligible cohort |
| Consent and OTP | Explicit download consent, plus OTP where an individual record is fetched via API or screen | CERSAI Operating Guidelines | Keep consent and OTP separate |
Key points of CKYCRR Compliance Guide
- CKYCRR stands for Central KYC Records Registry. It is operated by CERSAI, not the RBI.
- The core duties sit in Rule 9 of the PML (Maintenance of Records) Rules, 2005, as amended by G.S.R. 419(E) dated 19 July 2024: file within ten days, update within seven days.
- For the eleven activities in clause 11.6(e), the IFSCA Guidance Note requires CKYCR filing for Indian-national clients and exempts foreign-national natural persons. The clause heading separately refers to Indian-resident natural and legal entities, so document the treatment of NRIs, resident foreign nationals and legal entities.
- IFSCA periodic updating is annually for high risk, every three years for medium and every five years for low, with a separate two, eight and ten year cycle for certain resident Indians in the financial group.
- Retrieving a CKYC record does not complete customer due diligence, and OTP validation is not the same as customer consent.
CKYCRR meaning and full form
CKYCRR meaning in short: CKYCRR is the Central KYC Records Registry, operated by CERSAI, where a customer’s KYC is stored once and reused across the regulated financial sector, with consent.
The Central KYC Records Registry stores verified KYC records of customers across India’s regulated financial sector, so that KYC can be completed once and reused. It is operated by CERSAI, set up under Section 20 of the SARFAESI Act, 2002, and authorised as the registry by a Government notification dated 26 November 2015. The expansion “Central Know Your Customer Records Rules”, seen on some sites, is incorrect.
The statutory framework
| Instrument | What it provides |
| Prevention of Money-Laundering Act, 2002 | Section 2(1)(ha) defines a client, Section 11A covers verification of client identity, and Section 12 sets the core record-keeping and reporting obligations of reporting entities. |
| PML (Maintenance of Records) Rules, 2005 | Define the registry at Rule 2(1)(ac) and set the filing, updating, retrieval and registry-function duties in Rule 9 and Rule 9A. Amended by G.S.R. 419(E) dated 19 July 2024. |
| Sectoral directions | The RBI Master Direction on KYC and the SEBI, IRDAI, PFRDA and IFSCA instruments operationalise these duties for each sector. |
Reporting-entity duties under Rule 9
| Rule 9 | Duty and who is bound |
| 9(1A) | Reporting entity files the client’s KYC record with CKYCRR within ten days of commencing the account-based relationship, where applicable under the PML Rules and the relevant sectoral directions. |
| 9(1B) | CKYCRR de-duplicates and issues a KYC Identifier, which the entity communicates to the client. |
| 9(1C) | Reuse the record via the identifier, without re-collecting documents, except on a change of information, an incomplete or outdated record, an expired document, a need for current-address verification, or where enhanced due diligence applies. |
| 9(1D) | On obtaining additional or updated information falling within Rule 9(1C), the reporting entity furnishes it to CKYCRR within seven days, after which CKYCRR informs all linked entities. Internal verification should be designed so as not to cause avoidable delay. |
| 9(1E) | The reporting entity that performed the last KYC verification or furnished the updated information is responsible for verifying the authenticity of the client’s identity or address. |
| 9(1F) | Use the record only to verify identity or address, and do not transfer it to a third party without authority. |
| 9(1G) | A duty on the regulator, not the entity: the regulator issues guidelines to enable real-time access to the records. |
| 9(1H) | On an update notification, the reporting entity retrieves and refreshes its own record. |
The registry's own functions
The statutory architecture has three related provisions. Rule 9 sets the reporting-entity duties on filing, retrieval, reuse and updating. Rule 9A sets the functions and obligations of the registry, including storage, safeguarding, de-duplication and issuing the KYC Identifier. Rule 9B authorises the Reserve Bank of India to call for information from, and inspect, the Central KYC Records Registry. This inspection function is distinct from the role of the RBI, SEBI, IRDAI, PFRDA and IFSCA in regulating reporting entities within their respective sectors.
Is Your CKYCRR Compliance Inspection-Ready?
From 10-day filing timelines to consent trails, our AML specialists help reporting entities close every gap before the regulator finds it.
CKYCRR legal hierarchy: Act, Rules, sectoral guidelines and CERSAI procedures
| Requirement | Source |
| Ten-day upload | PML Rules, Rule 9(1A) |
| Seven-day update | PML Rules, Rule 9(1D) |
| Real-time access implementation | Sectoral regulator, under Rule 9(1G) |
| Consent on every download | CERSAI Operating Guidelines |
| OTP for specified individual downloads | CERSAI Operating Guidelines |
| IFSC covered activities | IFSCA Guidelines, clause 11.6(e) |
| Foreign-national treatment | IFSCA Guidance Note and Rule 9A proviso |
| Periodic KYC cycles | IFSCA Guidelines, clause 5.11 |
How CKYCRR works in practice
Search
Search the registry by the 14-digit KYC Identifier or a valid officially valid document number before creating a new record.
Consent and download
Obtain and retain the customer’s explicit download consent. Where an individual record is fetched via API or a screen-based interface to establish an account-based engagement, the registry also triggers a one-time password to the registered mobile, and the download completes only after that OTP is validated. The OTP is an authentication control, it is not the consent. Other download modes may use different prescribed authentication factors.
Upload
Where no valid record exists, verify the documents and upload the record on the correct template, and the registry issues the identifier.
Update
Where you obtain additional or updated information falling within Rule 9(1C), furnish it to CKYCRR within seven days, or such other period as may be notified by the Central Government, and refresh your own record when a linked-entity update notification arrives.
The registry sends the customer a message whenever a record is fetched. In responses, the identifier may be masked and a CKYC reference ID provided, and either can be used to download.
When does the ten-day upload period begin?
The ten-day period begins on commencement of the account-based relationship, not merely when the application is received or KYC documents are collected. Each entity should define the commencement event for every product in its policy and system logic, for example account opening, activation or execution of the relationship, based on its legal and sectoral framework. Do not assume a single universal product event, and configure the deadline on calendar days unless an applicable authority expressly permits otherwise.
CKYC Number (KYC Identifier / KIN): Format, Prefixes and Masking
The statutory term is the KYC Identifier. It is commonly called the CKYC number, CKYC identifier number or KIN, and it has a 14-digit numeric core. Certain account categories carry an additional letter prefix: S for a Small Account, L for a Simplified Measures Account, O for an OTP-based e-KYC Account and M for a Minor Account. For security, the identifier may be masked in certain responses and paired with a unique CKYC reference ID.
CKYC Documents Requirement and templates
| Requirement | What it is |
| PAN or Form 60 | Provided separately where required. PAN is not itself an officially valid document. Legal-entity, foreign-national and sector-specific cases may differ. |
| One officially valid document | Passport, driving licence, proof of possession of Aadhaar number, voter identity card, a qualifying NREGA job card, or an NPR letter, or an equivalent e-document. |
| Aadhaar handling | Treated as proof of possession of the Aadhaar number, with the number redacted where authentication is not required. |
| Limited-purpose address | Where simplified measures are permitted and the customer cannot produce ordinary proof of address, specified documents, including a utility bill not more than two months old, may be treated as deemed OVDs for the limited purpose of address verification, subject to the updated-OVD requirements and exceptions in the applicable IFSCA or sectoral guidelines. |
| Templates and specifications | Individual or legal-entity CKYC template, with scans typically at 150 to 200 DPI, a photograph up to 100kb, and a record up to 350kb for an individual and up to 5MB for a legal entity. |
De-duplication, probable matches and remediation
Uploaded records are de-duplicated on demographic and identity parameters. An exact match returns the identifier for download. A probable match is flagged for the entity to reconcile, and must be resolved within ten days, or the record is withdrawn and can be re-uploaded only if no match is found. For legacy data, run a structured remediation programme: identify records not yet uploaded, correct data-quality defects, reconcile the registry against the core KYC system, and clear probable-match and update backlogs
CKYC Portal Registration, API and SFTP Access Management
Register on the CKYC portal at ckycindia.in with two Institutional Admin users, submit the signed form and supporting documents to CERSAI, complete testbed registration and testing, and receive live credentials. Access is by web application, API or SFTP, secured by a digital signature validated at login. Confirm the certificate class currently accepted by the portal. Admins create region and branch levels and maker and checker users, and every action follows a maker-checker process.
IFSC and GIFT City requirements for CKYCR
Register on the CKYC portal at ckycindia.in with two Institutional Admin users, submit the signed form and supporting documents to CERSAI, complete testbed registration and testing, and receive live credentials. Access is by web application, API or SFTP, secured by a digital signature validated at login. Confirm the certificate class currently accepted by the portal. Admins create region and branch levels and maker and checker users, and every action follows a maker-checker process.
The IFSCA framework
Entities licensed, recognised, registered or authorised by the IFSCA are governed by the IFSCA (AML, CFT and KYC) Guidelines, 2022, notified on 28 October 2022, modified by circular on 5 June 2025 and again by a circular dated 2 January 2026, and read as the consolidated text current as at 26 February 2026. The Guidelines now apply to every regulated entity unless specifically exempted, and an exempt entity must still conduct and document a business risk assessment.
CKYCR obligation for IFSC entities
In short: the CKYCR requirements apply to IFSCA entities carrying on the eleven activities listed in clause 11.6(e). The Guidance Note requires filing for Indian-national clients and expressly exempts foreign-national natural persons.
The CKYCR requirements in clause 11.6(a) to (d) apply to IFSCA-regulated entities undertaking the activities specifically listed in clause 11.6(e). Other IFSC entities should assess their position under the PML Rules, their applicable sectoral framework and any specific IFSCA directions, rather than assuming clause 11.6 applies identically to them.
The eleven specified activities
- Payment Service Provider
- Finance Company undertaking core activities
- IFSC Banking Unit
- Bullion Trading or Clearing Member
- Broker Dealer
- Clearing Member
- Depositary Participant (as worded in the current consolidated Guidelines)
- Investment Advisor
- Fund Management Entity
- General Insurance
- Life Insurance
Applicability at a glance
Question | Position |
Does clause 11.6 apply to every IFSCA entity? | No. Clause 11.6(e) lists specified regulated activities. |
Does it cover natural and legal persons? | The clause heading refers to Indian-resident natural and legal entities. |
Does it apply to foreign nationals? | The Guidance Note provides an exemption, with optional submission subject to specified documentation. |
Does it apply to NRIs? | Requires a documented interpretation, because the provision uses both residency and nationality terminology. |
What is the upload deadline? | Ten days from commencement of the account-based relationship. |
What is the update deadline? | Seven days after obtaining additional or updated information. |
Does clause 11.6 apply to every IFSCA-regulated entity? Direct answer. No, not to every IFSCA entity. Clause 11.6(e) applies the CKYCR requirements in clauses 11.6(a) to (d) to the eleven specified regulated activities. Other IFSC entities assess their obligations under the PML Rules, their sectoral framework and any specific IFSCA directions. Legal basis. IFSCA Guidelines, clause 11.6(e). Operational implication. Confirm the licensed activity before applying the CKYCR workflow. Evidence expected. An applicability assessment, policy mapping and a product-level implementation record. | |
Indian resident, Indian national and foreign-national treatment
Clause 11.6 is headed as applying to Indian-resident natural and legal entities, while its Guidance Note refers to Indian nationals and exempts foreign-national clients, with voluntary submission of a foreign national’s records contemplated subject to specified documents. Given this difference in terminology, an IFSC regulated entity should document how it applies the provision to resident Indians, NRIs, resident foreign nationals, Indian-incorporated legal entities and foreign legal entities, taking account of the customer category, the entity’s regulated activity and any clarification received from IFSCA. The Guidance Note expressly exempts natural-person clients who are foreign nationals; the treatment of legal entities should be assessed separately in light of the clause heading, Rule 9A and applicable IFSCA instructions.
Source: IFSCA (AML, CFT and KYC) Guidelines, 2022, clause 11.6, consolidated as at 26 February 2026, together with the underlying amendatory circulars of 5 June 2025 and 2 January 2026.
Indian-national beneficial owners
Where the beneficial owner of an entity is an Indian national, the Guidance Note requires the regulated entity to endeavour to establish the source of funds and apply the source-of-funds enhanced due diligence measure specified under clause 5.6(a)(ii), irrespective of the risk categorisation assigned to the non-resident customer. This is a specific measure to address round-tripping, not an unrestricted requirement to perform every form of enhanced due diligence for every entity with an Indian beneficial owner.
Related IFSCA KYC developments (2 January 2026 circular)
- KRAs are recognised under the IFSCA (KYC Registration Agency) Regulations, 2025 (Clause 1.3.24A).
- Risk categorisation and its reasons must be kept confidential, to prevent tipping off (Clause 4.1(d)).
- Further clarifications cover NRI V-CIP jurisdictions, Aadhaar Face Authentication, persons with disabilities and debit-freeze onboarding. See our IFSCA AML and KYC update guide for the detail.
Record retention in the IFSC
Clause 9.2 of the IFSCA Guidelines requires necessary records to be preserved for at least six years, or a longer period where required by another applicable law. Under the wider PMLA framework, the applicable retention trigger varies according to the type of record, for example completion of a transaction, the end of a business relationship, or closure of an account. The entity’s policy should specify both the retention period and the event from which it is calculated for each record category.
Periodic updating, KRA and CDD scope for IFSC entities
In short: review the CDD file annually for high risk, every three years for medium and every five years for low, with a separate two, eight and ten year cycle for certain resident Indians.
The IFSCA Guidelines set a risk-based periodic-updating cycle. The 2 January 2026 circular added a separate, more relaxed cycle for certain resident Indian customers who already hold a relationship within the financial group in India. Where the financial group and the IFSC entity assign different risk categories, the stricter periodicity applies.
Customer situation | Applicable IFSCA periodicity |
General high-risk customer | Annually |
General medium-risk customer | Every three years |
General low-risk customer | Every five years |
Resident Indian with an existing Financial Group relationship in India | Two, eight and ten years by risk category |
Different risk categories assigned by the group and the IFSC entity | Apply the stricter periodicity |
Where there is no change in the CDD information of an individual, a self-declaration suffices. For a non-natural person, obtain the prescribed self-declaration or an authorised-official confirmation with the requisite corporate approvals, and ensure beneficial-ownership information remains accurate and current. Where an identity document has expired, conduct the CDD process afresh.
Source: IFSCA (AML, CFT and KYC) Guidelines, 2022, and the IFSCA circular dated 2 January 2026. Note that the RBI Master Direction applies a separate two, eight and ten year cycle for RBI-regulated entities.
CKYC and KRA KYC
CKYCRR and the IFSCA KYC Registration Agency (KRA) framework are separate but related. The IFSCA (KYC Registration Agency) Regulations, 2025 establish the framework, and Regulation 25 sets KYC-upload obligations. The detailed arrangements for integrating regulated entities with an IFSCA-registered KRA were still at the consultation stage as at 22 July 2026 (consultation paper dated 26 June 2026), so those proposals should not be treated as final requirements until a final circular is issued. Even where a CKYC or KRA record exists, an entity must still perform the verification and additional information-gathering required for its own sector and customer.
Area | CKYCRR | IFSCA KRA |
Legal framework | PML Rules and CERSAI Operating Guidelines | IFSCA (KYC Registration Agency) Regulations, 2025 |
Operator | CERSAI | An IFSCA-registered KRA |
Identifier | KYC Identifier | KRA-assigned identifier |
Primary purpose | Cross-sector central KYC repository | Centralised KYC utility within the IFSC framework |
Current position | Established and operating | Regulations notified; integration arrangements under consultation as at 22 July 2026 |
Replaces CDD? | No | No |
What CKYC does not replace
Retrieving a CKYC record does not complete your customer due diligence.
It does not replace:
- Customer risk assessment and categorisation.
- Beneficial ownership identification and verification.
- Sanctions, PEP and adverse-media screening.
- Enhanced due diligence, including the source-of-funds measure where the beneficial owner is an Indian national.
- Periodic KYC updating and event-triggered re-KYC.
- Ongoing monitoring, suspicious-transaction detection and reporting to FIU-IND.
- Product-specific suitability or eligibility checks.
Drowning in Probable Matches and Legacy KYC Backlogs?
Get a structured CKYCRR remediation programme, reconciliation, data-quality fixes and closure tracking, led by a CAMS-qualified team.
Governance and internal controls For CKYC
- Governing Body-approved CKYC and KYC procedures within the AML/CFT and KYC policy, with operational procedures approved under the entity’s documented delegation framework and a designated Principal Officer.
- Clear ownership across compliance, operations and technology.
- Access on a least-privilege basis, with maker-checker segregation and periodic user-access reviews.
- Monitoring of unusual or excessive searches and downloads.
- Consent capture and retention, and purpose-limited use of records.
- Exception, ageing and probable-match reports with defined escalation.
- Training, periodic control testing and internal audit coverage.
Common exceptions and expected responses for CKYCRR
Exception | Expected response |
No record found | Verify the customer and create a new record |
Exact match found | Retrieve the existing record with consent |
Probable match | Reconcile within ten days before creating a new identifier |
OTP not received | Do not bypass OTP validation. Confirm the registered mobile details and use only the authentication factor prescribed for the relevant download mode. Where the registered mobile is incorrect, initiate the approved correction or grievance process. |
Record incomplete or document expired | Obtain current information and update the record |
Customer details differ | Investigate and update rather than creating a duplicate |
Upload rejected | Correct validation or format errors and resubmit |
Update alert received | Retrieve the updated record and refresh internal systems |
Handling CKYC update notifications
Treat linked-entity update notifications as a controlled workflow, not an ad hoc task:
- Capture update notifications daily and match them against the customer master.
- Retrieve the latest record and compare it field by field with your held data.
- Update connected systems, and re-screen where name, nationality or connected-party information has changed.
- Reassess risk where the change is material, and record evidence that the refresh was closed.
- Track ageing and escalate items that are not closed within the expected period.
Grievances and unauthorised access
Have a defined process for a customer complaint or an internal alert about an unexplained fetch:
- Intake the complaint and retrieve the relevant access logs.
- Identify the user and the business purpose, and verify the consent relied upon.
- Investigate and escalate, and assess whether a data breach has occurred.
- Respond to the customer, take corrective and disciplinary action, and report to the regulator where required.
CKYCRR Fees, incentives and accountability
Searches are free, uploads and updates are incentivised, and downloads are charged, with advance payment through the portal. A failure to meet CKYCRR and KYC obligations may lead to supervisory observations, remediation requirements or enforcement action under the PMLA, the PML Rules or the applicable sectoral framework including the IFSCA Guidelines, depending on the nature, materiality, duration and circumstances of the lapse.
CKYCRR 2.0 status as of 22 July 2026
As of 22 July 2026, the official CKYC portal lists a CKYCRR 2.0 API integration and reporting-entity onboarding guide dated 5 June 2026. This confirms that integration and onboarding material has been issued, but it does not by itself establish that the complete CKYCRR 2.0 environment and every proposed feature are in production. Confirm your applicable migration and go-live position directly with CERSAI.
Compliance checklist for CKYC
- Registered, tested and live on the CKYC portal, with two Institutional Admins and a valid digital signature.
- Search before onboarding, by identifier or a valid OVD number.
- Explicit download consent obtained and retained, with OTP validation where an individual record is fetched to establish a relationship.
- Records uploaded within ten days and updates filed within seven days of obtaining them.
- For the activities listed in clause 11.6(e), the entity has separately documented its treatment of Indian-national individuals, NRIs, resident foreign nationals, Indian legal entities and foreign legal entities, taking account of the clause heading, the Guidance Note and applicable regulatory clarification.
- Periodic updating scheduled on the correct cycle: annually, three years and five years generally, and two, eight and ten years for the eligible resident-Indian cohort.
- Probable matches resolved within ten days, and legacy remediation tracked to closure.
- Records used only for identity and address verification, and retained for the applicable minimum period.
- Full audit trail of searches, uploads, downloads, consents and updates.
Audit-readiness self-assessment
- Is CKYCRR searched before every new record is created?
- Is customer consent captured, retained and retrievable, and kept distinct from OTP validation?
- Are the filing, updating and periodic-updating timelines monitored and reported?
- Has the entity documented how clause 11.6 applies to each relevant natural-person and legal-entity customer category, including NRIs and foreign-national clients?
- Is the correct periodic-updating cycle applied to each customer cohort?
- Are probable matches and update notifications tracked to closure?
- Is the registry reconciled against the core KYC system, with independent sample testing?
What a record bearing reference means for individuals
A registration message such as “Your KYC record bearing no. [identifier] is registered with Central KYC Registry by [institution]” confirms that your record is in the registry. The number quoted may be your 14-digit KYC Identifier, or a CKYC reference ID where the identifier is masked. It is not a payment or transaction reference, and it is not a request for money or a one-time password. A message that your record was fetched means an institution retrieved it, usually because you applied for or updated a financial product.
Questions individuals commonly ask about CKYCRR
What is a CKYCRR number?
People sometimes call it a CKYCRR number, but the statutory term is KYC Identifier. It has a 14-digit numeric core and is commonly called the CKYC number or KIN. An institution uses it to retrieve your verified KYC, with your consent, instead of collecting your documents again.
How can I check my CKYC number online?
Give a missed call to 7799022129 for a CKYCRR reference number check, use the CKYC card link at ckycindia.in/kyc/getkyccard, or fetch your CKYC card through DigiLocker. You do not get direct login access to the registry itself.
What is the difference between CKYC and KYC?
KYC is the process of identifying and verifying a customer. CKYC is the centralised KYC framework under which a verified CKYC record can be reused across regulated institutions. CKYCRR is the registry, operated by CERSAI, in which that record is held.
Who regulates CKYCRR?
CERSAI operates the registry under the PML Rules. The RBI may inspect it under Rule 9B, while the RBI, SEBI, IRDAI, PFRDA and IFSCA regulate the reporting entities in their respective sectors.
How do I update or correct my CKYC record?
Approach a reporting entity where you hold a relationship. It verifies and files the change, and the registry then notifies the other institutions linked to your record.
How do I verify my CKYC number is correct and active?
Fetch your CKYC card by a missed call to 7799022129, at ckycindia.in/kyc/getkyccard, or through DigiLocker, and confirm that the 14-digit KYC Identifier on the card matches the number quoted in the registration or fetch message you received. If the details on the card are wrong or outdated, approach a reporting entity where you hold a relationship so it can verify and file the correction.
What does “CKYC / KIN, if available” mean on an application form?
The form is asking for your 14-digit KYC Identifier, commonly called the CKYC number or KIN, if one has already been issued to you. Quoting it lets the institution retrieve your verified KYC record from CKYCRR, with your consent, instead of collecting your documents afresh. If you do not know the number, you can leave the field blank and the institution will search the registry using an officially valid document number, or you can find it first through the missed-call, CKYC-card or DigiLocker route described above.
Find your CKYC card, and stay safe
You do not receive reporting-entity or back-office access to the registry, and you cannot edit the record yourself, but you can fetch your CKYC card by a missed call to 7799022129, at ckycindia.in/kyc/getkyccard, or through DigiLocker. To correct your details, approach a reporting entity where you hold a relationship. Never share an OTP, a payment credential or a record password with a caller. If a message names an institution you do not recognise, verify it through contact details you obtain independently, keep the message, and report suspected fraud on the National Cybercrime Helpline 1930 or at cybercrime.gov.in.
Glossary
Term | Meaning |
CKYCRR / CKYCR | Central KYC Records Registry, operated by CERSAI |
KYC Identifier (KIN) | The 14-digit number for a CKYC record, also called the CKYC number |
CKYC reference ID | Identifier shown when the KYC Identifier is masked |
OVD | Officially valid document |
IFSCA | International Financial Services Centres Authority |
KRA | KYC Registration Agency, recognised in the IFSC under the 2025 Regulations |
V-CIP | Video-based Customer Identification Process |
CDD / EDD | Customer due diligence and enhanced due diligence |
FIU-IND | Financial Intelligence Unit, India |
Preparing for CKYCRR 2.0 and API Integration?
We guide your compliance and technology teams through CERSAI onboarding, testing and go-live with the right controls in place.
Frequently Asked Questions
No. In the IFSC, the CKYCR requirements apply to entities carrying on the eleven activities listed in clause 11.6(e) of the IFSCA Guidelines. An entity outside that list assesses its position under the PML Rules, its sectoral framework and any specific IFSCA directions rather than assuming clause 11.6 applies to it.
Payment service providers, finance companies undertaking core activities, IFSC banking units, bullion trading or clearing members, broker dealers, clearing members, depository participants, investment advisers, fund management entities, and general and life insurers. Confirm your licensed activity against the current list before applying the workflow.
The Guidance Note exempts a foreign-national client from the CKYCR filing requirement, while allowing voluntary submission subject to specified documents. Because the clause heading uses Indian-resident language, document how you treat foreign nationals, NRIs and mixed cases and apply it consistently.
On the face of the Guidance Note, an NRI who remains an Indian national falls within the Indian-national filing requirement. However, clause 11.6 is headed as applying to Indian-resident natural and legal entities. The regulated entity should therefore document its interpretation, distinguish nationality from residence, and obtain regulatory clarification where the customer or product structure creates uncertainty.
Under the IFSCA Guidelines, the general cycle is annually for high-risk customers, once every three years for medium-risk and once every five years for low-risk. Where an identity document expires, conduct CDD afresh, and where nothing has changed, a self-declaration or authorised-signatory confirmation suffices.
Only to a resident Indian customer who already holds a client relationship within the regulated entity’s financial group in India, under the 2 January 2026 circular. Where the group and the IFSC entity assign different risk categories, the stricter periodicity applies. It is not the general IFSC cycle.
Yes. The CERSAI Operating Guidelines require the reporting entity to obtain and retain the customer’s download consent every time a record is downloaded. That consent is a separate control from any authentication step.
No. Where an individual record is fetched via API or a screen-based interface to establish an account-based engagement, CKYCRR triggers an OTP to the registered mobile as an authentication step. Consent is obtained and retained separately, and other download modes may use different authentication factors.
Yes, in the situations set out in Rule 9(1C): where the information has changed, the record is incomplete or does not meet current norms, a document has expired, current-address verification is needed, or enhanced due diligence applies. Otherwise the record is reused via the identifier.
Obtain the missing information from the customer, verify it, and update the record on CKYCRR within the applicable timeline, rather than proceeding on an incomplete record or creating a duplicate. Keep evidence of what was obtained and when the record was completed.
Capture it, match it to the customer master, retrieve the latest record, compare field by field, update connected systems, re-screen where identity or connected-party data has changed, reassess risk where material, and record that the refresh was closed.
No. Retrieving a CKYC record does not remove the obligation to identify and verify the customer’s beneficial owners, understand the ownership and control structure, and apply any enhanced measures, including the source-of-funds measure where a beneficial owner is an Indian national.
No. Sanctions, PEP and adverse-media screening, ongoing monitoring and suspicious-transaction reporting remain the entity’s own obligations. A CKYC record is a shared identity record, not a substitute for these controls.
The registry withdraws the record. It can be re-uploaded only if no match is then found. Searching before uploading and reconciling probable matches promptly avoids both duplicates and withdrawals.
Searches, consents, downloads, uploads, updates and reconciliation decisions should form part of the entity’s CDD and compliance audit trail and be retained under its record-retention policy. In the IFSC, necessary records must generally be retained for at least six years, or longer where another applicable law requires it.
It begins on commencement of the account-based relationship, not merely when the application is received or documents are collected. Each entity should define the commencement event for every product in its policy and system logic, for example account opening, activation or execution, based on its legal and sectoral framework.
The PML Rules state ten days and seven days without describing them as working days. A reporting entity should avoid configuring the deadlines as working-day periods unless an applicable regulator or official instruction expressly permits that interpretation.
The express exemption in the Guidance Note is worded for a client who is a foreign national, which naturally describes a natural person. The position of foreign legal entities should be assessed separately in light of the clause heading, Rule 9A and any applicable IFSCA instructions, rather than assumed.
Yes. The IFSCA Guidance Note contemplates voluntary submission of a foreign national’s KYC record, subject to the specified documents, even though filing is not mandatory for foreign-national clients.
Why work with AML India
AML India helps dealers in precious metals and stones meet their PMLA and DG Audit obligations, from registration and risk assessment through to CDD, screening, monitoring, reporting, training and independent review.
Industries we serve: jewellers, bullion dealers and gems traders, real estate agents, trust and company service providers, chartered accountants, company secretaries and cost and management accountants, virtual asset service providers, casinos and the gaming sector, and banks, financial institutions and IFSC and GIFT City entities.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik