Last Updated  on: 17th August 2026       |        Last Reviewed on: 17th August 2026

Key Takeaways

  • A KIN is the KYC Identifier for a customer’s record in CKYCR, operated by CERSAI, and is commonly called the CKYC number.
  • It is generally a 14-digit identifier, sometimes with a category prefix such as S, L, O or M for different identifications.
  • An authorised reporting entity may retrieve the record subject to the consent and authentication requirements applicable to that entity, for a permitted purpose.
  • Its core obligations come from Rule 9 of the PML Rules, with each regulator prescribing how they apply. It reduces repeat document collection but does not complete customer due diligence.
  • Use the child pages for checking, updating, complaints, legal entities, comparisons, the onboarding workflow, privacy and the cross-sector treatment of KIN and CKYCR.

KIN Number: Short Definition

A KIN, commonly expanded as KYC Identification Number and legally referred to as the KYC Identifier, is the unique number or code assigned to a customer by the Central KYC Records Registry. It is ordinarily a 14-digit identity number and is used by authorised reporting entities to locate and retrieve the corresponding KYC record, subject to the applicable legal, consent and authentication requirements.

KIN at a Glance

Questions Short Answer
What is the full form of KIN? KYC Identification Number
What is the official legal term? KYC Identifier
Who generates it? Central KYC Records Registry (CKYCR)
Who operates CKYCR? CERSAI
What is its normal format? A 14-digit identifier, sometimes with a category prefix
What is it used for? Locating and retrieving the corresponding CKYCR record
Is it proof of identity? No
Does it complete KYC or CDD? No
Can institutions retrieve it freely? No; access is subject to authorisation and the applicable consent and authentication requirements

This is the overview. For the practical steps and the compliance detail, each section links to a focused page: finding and downloading a KIN, updating or correcting a record, resolving duplicates and complaints, KIN for legal entities, comparisons with PAN and Aadhaar, the onboarding workflow, and consent and privacy. Sector-specific treatment should be checked under the relevant RBI, SEBI, IRDAI, PFRDA or IFSCA framework.

Two readers use this cluster. If you are an individual customer, start with the meaning here and follow the links on checking, downloading, updating and protecting your KIN. If you work in a reporting entity, read the brief obligations here, then the onboarding-workflow page, and rely on the existing detailed CKYCR compliance guide for the full compliance treatment.

KIN Meaning and Full Form

KIN stands for “KYC Identification Number”, and the legal term for the same is KYC Identifier, defined in Rule 2(1)(cc) of the PML Rules.

KIN, KYC Identifier and CKYC number

KIN, KYC Identifier, CKYC number and CKYC ID are the different names for the same unique identifier assigned to a customer’s CKYCR record. SEBI’s guidance confirms that a unique KYC Identification Number (KIN), also referred to as CKYC Number, is generated for the customer. Different reporting entities may use different labels on their forms, but they all refer to the same identifier.

The identifier is used to retrive the the corresponding record. Possessing the number alone does not provide access to the record. Access remains subject to the reporting entity’s authorisation, a permitted purpose and the applicable consent and authentication requirements. For the differences between PAN, Aadhaar and KRA KYC see the comparisons page.

Who Issues the KIN Number?

The KIN is generated through the Central KYC Records Registry (CKYCR), which is operated by the Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI). It is not issued by your bank or directly by the Reserve Bank of India. Instead, a reporting entity, or a designated KYC intermediary, where permitted under the applicable sectoral framework, submits the customer’s KYC record to CKYCR. After validating and de-duplicating the record, CKYRS generates and assigns the KIN (CKYCR Operating Guidelines). In the securities market, for example, SEBI requires KYC records to be uploaded to CKYCR through KYC Registration Agencies. The RBI prescribes CKYCR obligations for regulated entities, while SEBI, IRDAI, PFRDA and IFSCA prescribe corresponding requirements for entities within their respective sectors.

The 14-Digit Format and Prefixes

The standard KYC Identifier generated for a new customer record is 14 digits. This is what people mean by the 14-digit CKYC number. The CKYCR Operating Guidelines also provide single-letter prefixes for certain account categories, which sit in front of the identifier.

Prefix Account Category
S Small Account
L Simplified Measures Account
O OTP based e-KYC Account
M  Minor Account 

The underlying identifier remains 14 digits, and the prefix marks the account category. The number should not be read as a code that contains your date of birth, PAN, Aadhaar, gender or risk category. Unless an official specification says a digit carries meaning, treat the KIN as a plain reference. A masked example looks like 12XXXXXXXXXX45, and a full KIN should not be disclosed publicly or shared where it is not necessary.

Who Can Receive a KIN?

Both natural persons and legal entities may receive a KIN, subject to the applicable legal and regulatory requirements. For natural persons, this includes resident individuals, non-resident individuals, minors, joint account holders, sole proprietors, and any beneficial owners or authorised signatories whose individual KYC is required under the applicable sectoral framework. KYC is conducted for each person, so on a joint account each holder has their own record and KYC identifier. A minor’s KYC is generally issued with an “M” prefix. When the minor attains majority, the reporting entity must complete the applicable re-verification and update the records. To determine whether the existing identifier continues unchanged or requires operational treatment, the current CKYCR operating procedure must be checked.

An NRI may receive a KIN where a reporting entity uploads the individual’s KYC record to CKYCR in accordance with the applicable sectoral framework. The documents, verification method and filing treatment may differ according to residency, the product and the regulator governing the reporting entity. A specific exception applies in an International Financial Services Centre; under the proviso to Rule 9A (1) of the PML Rules, CKYCR’s receiving, storing, safeguarding and retrieval functions are not required for a client who is a foreign national (PML Rules requirement). IFSCA-regulated entities should therefore distinguish Indian resident customers from foreign national customers when determining CKYCR applicability. The existence of a technical record template should not be treated as meaning that every foreign customer is required or entitled to have a KIN.

Legal entities can also hold a KIN. Companies, LLPs, partnership firms, trusts, societies and other juridical persons may have CKYCR records, subject to the applicable rules. A legal entity’s record is separate from the individual KYC of its signatories and beneficial owners, and the reporting entity identifies beneficial owners independently. The detail sits on the legal entities page.

Not Sure If Your AML Compliance Is Complete?

We review your KYC and AML process, point out the gaps, and tell you exactly what to fix.

How a KIN is Generated

Legal Position at a Glance

Rule 9(1A) of the PML Rules requires a reporting entity subject to the provision to file the electronic KYC record with CKYCR within ten days after commencement of an account-based relationship, and Rule 9(1B) requires the KYC Identifier to be communicated in writing to the client. Sectoral regulators prescribe the applicable scope, procedure and supplementary requirements.

A KIN is generated after the KYC record is filed, or its filing is arranged, under the applicable sectoral process, and CKYCR determines after de-duplication that no existing record applies. The identifier is then returned to the reporting entity, which communicates it to the customer.

  1. The customer approaches a reporting entity.
  2. The entity checks whether an existing KIN is already available for the customer.
  3. The customer provides KYC information and documents where required.
  4. The entity verifies the customer and opens the account-based relationship, subject to the applicable requirements.
  5. The record is filed with CKYCR under the applicable sectoral process, which in the securities market is through a KYC Registration Agency.
  6. CKYCR validates and de-duplicates the record, evaluating exact and probable matches.
  7. A new identifier is generated where no existing record applies.
  8. The identifier is communicated to the entity, and then to the customer.

Searching for an existing identifier before creating a new record is what keeps a single customer from collecting several KINs. During de-duplication, an exact match may return an existing identifier, a probable match may need reconciliation, and a confirmed no-match results in a new identifier.

How a KIN is Used

A reporting entity that is registered and authorised to access CKYCR may retrieve the customer’s KYC record using the KIN, subject to the applicable regulatory framework. Under the RBI framework, the KYC Identifier may be used for establishing an account-based relationship, KYC updating, periodic KYC updating, and verification of identity.

The retrieved record is the KYC information filed with CKYCR. The retrieving entity must still assess it for completeness and suitability rather than assuming it is complete or final. Under Rule 9(1F) of the PML Rules, a reporting entity must not use a KYC record obtained from CKYCR for a purpose other than verifying the client’s identity or address, and must not transfer the record or the information in it to a third party unless the client authorises the transfer, or as otherwise permitted by the regulator or the Director, FIU-IND under the applicable framework

Customer consent requirements are determined under the applicable regulatory and data-protection framework. RBI-regulated entities must obtain explicit customer consent before downloading the CKYCR record. Other reporting entities apply the consent, confidentiality and authentication requirements prescribed by their regulator and applicable law. An OTP may authenticate the customer and, where the consent wording and audit trail are adequate, may form part of the consent process. Consent, authentication and record security are covered on the consent and privacy page.

Does a KIN mean no further documents can be requested?

No. Under Rule 9(1C) of the PML Rules, a reporting entity that retrieves a valid record should not require the client to submit the same KYC records or additional identification documents again unless one of four stated exceptions applies: the client’s information has changed; the retrieved record is incomplete or does not meet the current applicable KYC norms; the validity period of a downloaded document has lapsed; or additional information is necessary to verify the client’s identity or address, including current address, to perform enhanced due diligence, or to build an appropriate risk profile.  

Checking, updating and troubleshooting in brief

You can find your KIN in the communication the reporting entity sent you, by fetching the CKYC card through the official CKYC customer facility using your registered mobile number, or by asking the institution that created the record. The step-by-step methods, including whether a PAN search helps, are on the find, check and download page.

To update or correct a record, you approach a reporting entity with which you hold an account-based relationship, submit the updated details and documents, and the entity verifies and uploads the change, so CKYCR updates the central record. The full process is on the update and correction page. If your KIN did not arrive, a duplicate appears, details are wrong, or a record was rejected, the problems and complaints page sets out the causes and the escalation path.

Reporting-entity obligations in brief

For reporting entities, the KIN sits inside a set of anti-money laundering obligations that retrieval alone does not discharge. The base obligations come from Rule 9 of the PML Rules and apply to reporting entities subject to those provisions: file a new record within ten days (Rule 9(1A)), communicate the KYC Identifier to the customer in writing (Rule 9(1B)), retrieve and reuse an existing record subject to the four exceptions (Rule 9(1C)), furnish updates within seven days (Rule 9(1D)), respect the use and transfer restriction (Rule 9(1F)), and act on a CKYCR update notification by retrieving and updating the record (Rule 9(1H)). The entity that performed the last verification or furnished the update is responsible for verifying the authenticity of the client’s identity or address (Rule 9(1E)), which is why retrieval is not the same as accepting a record without assessment. Each regulator adds scope, procedure and consent requirements on top, so the explicit consent position is a regulator overlay rather than the base rule.

Beneficial ownership, screening and risk assessment remain the entity’s responsibility. The onboarding workflow, the evidence checklist and the PML Rules base with the regulator overlay are on the onboarding-workflow page, and the full compliance treatment stays in the detailed CKYCR compliance guide, which remains the page that owns CKYCR compliance.

Inter-usability across sectors

CKYCR is intended to support inter-usability of KYC records across participating sectors. Actual reliance remains subject to the applicable regulator’s directions and the reporting entity’s access and verification process. How the KIN compares across banking, securities, insurance, pension, payments and IFSC is set out on the cross-sector page, and sector-specific treatment should be checked under the relevant RBI, SEBI, IRDAI, PFRDA or IFSCA framework.

KIN compared with PAN, Aadhaar and KRA KYC

A KIN is not the same as a PAN, an Aadhaar number or a KRA KYC record. A PAN is a tax identification number issued by the Income Tax Department. Aadhaar is a unique identity number issued by UIDAI and may also be used for identity verification and authentication where permitted by law. KRA KYC is the securities market KYC framework established under SEBI and operates separately from the central KYC records registry. For relationships governed by the RBI KYC framework, Aadhaar is not universally mandatory. It is required where a customer seeks a benefit or subsidy under a scheme notified by Section 7 of the Aadhaar Act and may otherwise be provided voluntarily, subject to the applicable legal requirements. Customers and reporting entities should also follow the requirements of the relevant sectoral regulator. For detailed comparison, including CIN and LEI, see the comparisons page.

CKYCRR 2.0: official technical preparation and reported rollout

As at 25 July 2026, the official CKYC portal lists an API document for CKYCRR 2.0 and states that reporting entities may use it for system integration, providing official evidence of technical preparation for the upgraded framework. Reuters separately reported that banks and insurers are expected to start using the upgraded system in August 2026, with capital-market entities expected to follow later, and noted that regulators had not responded to its requests for confirmation.

The reported rollout dates and features should not be treated as binding legal requirements merely because technical documents are available. Reporting entities should finalise system changes and compliance procedures against the operative notifications, regulator directions and implementation instructions applicable to them.

Need Help With Your AML Compliance?

From policies and risk assessment to training and software, our team supports you at every step.

Frequently Asked Questions

A KIN is the KYC Identifier assigned to a customer record by CKYCR, defined in Rule 2(1)(cc) of the PML Rules. It is ordinarily 14 digits, and a reporting entity authorised to access CKYCR may use it, subject to the applicable framework and the consent requirements that apply to it, to retrieve the KYC record for a permitted purpose.

The full form of KIN is KYC Identification Number. The PML Rules use the legal term KYC Identifier, defined in Rule 2(1)(cc), for the same identifier assigned by CKYCR.

Yes. KIN, KYC Identifier, CKYC number and CKYC ID all refer to the same identifier for a central KYC record. SEBI confirms that a unique KYC Identification Number, also called the CKYC Number, is generated.

CKYCR, operated under CERSAI, issues the KIN. A reporting entity, or the designated intermediary under the applicable sectoral process, files or arranges the filing of the record, and the KYC identifier is then communicated to the customer in writing.

Check the communication your reporting entity sent, fetch the CKYC card through the official CKYC customer facility using your registered mobile number, or ask the institution that created the record.

Yes, Certain institutions or KRA facilities allow a status search using PAN, but PAN is not the KIN, and a PAN search is not a universal public lookup. Use only official or institutional facilities.

Under the RBI KYC framework, Aadhaar is not universally mandatory. It is required where the customer seeks a benefit or subsidy under a notified Section 7 scheme and may otherwise be provided voluntarily. Check the relevant sectoral regulator’s requirements as well.

Yes. CKYCR holds legal-entity records, and covered legal-entity records are uploaded using the prescribed template. The entity record is separate from the individual KYC of its signatories and beneficial owners.

An NRI may receive a KYC Identifier where a reporting entity uploads the record to CKYCR under the applicable sectoral framework. The documents, verification method and filing treatment can differ by residency, product and regulator.

The KYC Identifier is not ordinarily assigned an expiry date. The underlying documents, information and KYC record may nevertheless become outdated or require periodic updating, which is why keeping the record current matters.

They should not. De-duplication is designed to prevent duplicates, and entities are expected to search for an existing identifier before creating a new record. Duplicates should be reported for resolution.

Under Rule 9(1C) of the PML Rules, an entity may ask for more where your information has changed, the retrieved record is incomplete or does not meet current KYC norms, a downloaded document has expired, or further information is necessary to verify your identity or address, perform enhanced due diligence or build an appropriate risk profile. You may ask the entity to state the specific reason.

No. A KIN helps retrieve identity information. It does not perform risk assessment, beneficial ownership identification, sanctions and PEP screening, source-of-funds enquiries, enhanced due diligence or transaction monitoring, which remain the reporting entity’s obligations.

No. The KRA framework operates within the securities market under SEBI, while CKYCR is a cross-sector registry. They are related but distinct, and a KRA KYC status is not a CKYC identifier.

Verify it with the institution named and escalate through the grievance mechanism if it cannot be explained. Preserve the alert, and monitor your accounts, because an unexpected download can signal misuse.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

 

Reach Out to Pathik