Last Updated on: 27th August 2026 | Last Reviewed on: 27th August 2026
Onboarding Workflow at a Glance
Obtain or retrieve the identifier, retrieve the record, check identity, handle any exception, complete wider due diligence, record who verified, then file and communicate the identifier, preserving evidence throughout. The base duties come from Rule 9 of the PML Rules; each regulator prescribes how they apply.
Legal Position at a Glance
Rule 9(1A) requires filing within ten days, Rule 9(1B) requires written communication of the identifier, Rule 9(1C) governs retrieval and the four exceptions, Rule 9(1E) makes the entity that performed the last verification responsible for the authenticity of the identity or address, and Rule 9(1F) restricts use to identity or address verification with no unauthorised transfer.
This page is a focused onboarding workflow. It does not restate the full obligation set for CKYCR compliance, upload architecture, governance and control testing, or use the detailed CKYCR compliance guide, which remains the authoritative professional page. For the identifier itself, see the pillar guide.
The Base Obligations Come from the PML Rules
The workflow rests on Rule 9 of the PML Rules, which binds reporting entities subject to those provisions. Each regulator adds scope and procedure on top, so state the base rule first and then the overlay.
Source level | Requirement | General position |
PML Rules, Rule 9(1A) | File a new KYC record | Within ten days of the account-based relationship |
PML Rules, Rule 9(1B) | Communicate the KYC Identifier | In writing to the client |
PML Rules, Rule 9(1C) | Retrieve and reuse an existing record | No fresh documents unless one of the four exceptions applies |
PML Rules, Rule 9(1D) | File additional or updated information | Within seven days, or another notified period |
PML Rules, Rule 9(1E) | Responsibility for authenticity | The entity performing the last verification or update is responsible for verifying authenticity of identity or address |
PML Rules, Rule 9(1F) | Restrict use and onward transfer | Identity or address verification only |
PML Rules, Rule 9(1H) | Act on a CKYCR update notification | Retrieve and update the internal record |
Regulator overlay to verify
Regulator | Overlay to verify against the current instrument |
RBI | Master Direction on KYC: explicit-consent position and operational requirements |
SEBI | KRA interaction, upload mechanism and registered-intermediary process |
IRDAI | Insurer and intermediary scope and confidential policyholder communication |
PFRDA | Covered NPS reporting entities and subscriber terminology under the current PFRDA Master Circular |
IFSCA | The activities and customer categories in the current IFSCA Guidelines to which CKYCR uploading applies |
The Onboarding Workflow, Step by Step
- Obtain the identifier. Ask the customer for the KYC Identifier, or retrieve it from CKYCR using permitted identification information, before creating a new record.
- Obtain consent as required. Capture the consent your regulator requires before downloading the record. Explicit consent is required under the RBI and PFRDA frameworks; securities-market entities apply the consent requirements in the current SEBI and KRA framework; other entities follow their regulator’s consent, confidentiality and authentication requirements. Keep evidence.
- Retrieve the record. Download the record and confirm it belongs to the customer using appropriate authentication.
- Check identity and adequacy. Assess the record for completeness and currency. It is the information filed with CKYCR, not a guarantee of completeness.
- Handle exceptions. Do not recollect the same documents unless a Rule 9(1C) exception applies: the information has changed; the record is incomplete or does not meet current KYC norms; a document has expired; or further information is necessary to verify identity or address, perform enhanced due diligence or build a risk profile (PML Rules requirement).
- Complete wider due diligence. Identify beneficial owners, run PEP screening and sanctions checks, complete the customer risk assessment and apply enhanced due diligence where required.
- Record who verified. Record which reporting entity performed the verification or furnished the update, because that entity is responsible under Rule 9(1E) for verifying the authenticity of the client’s identity or address.
- File and communicate. For a new customer, file the record within ten days (Rule 9(1A)) and communicate the identifier in writing (Rule 9(1B)).
- Record the decision and preserve evidence. Log the retrieval, the consent, the exception reasoning, the responsible verifier and the outcome.
Two Different Questions: Using the KIN Versus Using the Downloaded Record
Keep two permissions separate. First, when may the identifier be used: under the RBI framework, for establishing an account-based relationship, KYC updates, periodic KYC updates and identity verification. Second, how may the downloaded information be used: under Rule 9(1F), a reporting entity must not use a CKYCR record for a purpose other than verifying the client’s identity or address, and must not transfer it to a third party unless the client authorises it, or as otherwise permitted by the regulator or the Director, FIU-IND under the applicable framework (PML Rules requirement).
Consent and OTP
Consent requirements are set by the applicable framework. Consent is required under the RBI and PFRDA frameworks. Meanwhile, securities-market entities apply the consent requirements in the current SEBI and KRA framework; other entities follow their regulator’s requirements. An OTP, in case of an individual, may authenticate the customer and, where the consent and audit trail are adequate, may form part of the consent process. Retain evidence of the consent presented, the customer’s affirmative action, the authentication event and the purpose of access.
Evidence Expectations
The following is a recommended evidence framework. This includes legislation, regulatory directions, operating procedures or good compliance practice, and should be mapped to the entity’s applicable requirements.
Control | Evidence expected |
Consent | Consent text, timestamp, channel and affirmative action |
Authentication | OTP or other authentication log |
Retrieval | User ID, date, purpose and KIN |
Completeness review | Review result and exceptions identified |
Additional-document request | The Rule 9(1C) exception relied on |
Upload | CKYCR acknowledgement and timestamp |
Communication | Evidence that the KIN was sent to the customer in writing |
Update | Date received, date verified and date uploaded |
Access control | Approved role and periodic user-access review |
Not Sure If Your Onboarding Steps Hold Up?
Description: Most teams retrieve the record and move on. We look at how yours captures consent, handles exceptions and files on time, then tell you what to fix.
Frequently Asked Questions
Rule 9(1A) of the PML Rules requires filing within ten days of commencement of the account-based relationship, for reporting entities subject to Rule 9. Each regulator’s procedure applies on top of this.
Consent depends on the framework. Explicit consent is required under the RBI and PFRDA frameworks, and securities-market entities apply the SEBI and KRA consent requirements. An OTP can authenticate and support consent where the wording and audit trail are adequate, but is not a substitute for a clear consent record.
A CKYCR record may be used only to verify the client’s identity or address. It must not be transferred to a third party unless the client, the regulator or the Director authorises the transfer (PML Rules, Rule 9(1F)).
No. Beneficial ownership, screening, risk assessment and, where relevant, enhanced due diligence remain the entity’s obligations. The entity that performed the last verification is responsible for the authenticity of the identity or address (Rule 9(1E)), and ultimate responsibility stays with the entity opening the relationship.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.
Reach Out to Pathik