Insights

Automated KYC Workflow Design for Remote Customers 2026

Explore automated KYC workflow design for remote customers in India—V-CIP, CKYC, pKYC, metrics, and RBI 2025 rules. Get the complete 2026 glossary.
By
Awaaz AI Team
Sep 9, 2026
Share on:

TL;DR

Automated KYC workflow design for remote customers is the practice of building technology-driven sequences that identify, verify, and monitor customers who never visit a branch. This glossary covers every term Indian BFSI professionals encounter when designing these workflows, from CIP and CDD through V-CIP and CKYC to perpetual KYC. It maps how these terms connect into a single end-to-end flow, with India-specific regulatory context, drop-off benchmarks, and practical guidance on where voice AI fits as a coordination layer.


Contents

  1. Why This Glossary Exists
  2. Core KYC Concepts
  3. India-Specific KYC Methods for Remote Customers
  4. Workflow Design Terms
  5. Ongoing Compliance Terms
  6. Regulatory Framework (India Focus)
  7. Technology and Channel Terms
  8. Metrics That Matter
  9. How These Terms Connect: The End-to-End Workflow Map
  10. FAQ

Why This Glossary Exists

KYC was built for branches. A customer walks in, presents documents, a bank officer inspects them, and the file moves to the back office. That model is breaking down. India’s NBFC and microfinance sector serves millions of customers in Tier-2, Tier-3, and Tier-4 towns who may live hours from the nearest branch. Even large banks now onboard the majority of retail customers digitally.

The result is that compliance officers, operations leads, and product owners designing automated KYC workflow processes for remote customers encounter a thicket of terms: V-CIP, eKYC, CKYC, pKYC, STP, OVD, HITL, CDD, EDD. These terms come from different regulatory documents, technology vendors, and audit frameworks. No single resource connects them into a coherent picture of how a remote KYC workflow actually works.

This glossary fills that gap. It defines every key term, explains why it matters for remote workflow design, and shows how each piece fits into the larger system. The focus is India-specific, grounded in the RBI Master Directions and the 2025 amendments that are actively reshaping how banks and NBFCs handle KYC.

For a broader look at AI terminology in Indian banking, see our AI for banking glossary.


Core KYC Concepts

These are the foundational terms that every automated KYC workflow rests on, regardless of channel or geography.

KYC (Know Your Customer)

The regulatory obligation requiring financial institutions to verify the identity of their customers, understand the nature of their activities, and assess the risk they pose. In India, KYC is mandated under the Prevention of Money Laundering Act (PMLA) 2002 and operationalized through RBI’s Master Direction on KYC. It is not optional, it is not a best practice. It is the law.

CIP (Customer Identification Program)

The first step in any KYC workflow: collecting and verifying the customer’s identity information. For remote customers, this means capturing name, address, date of birth, and identity proof through digital channels rather than physical forms. CIP answers the question, “Who is this person, and can they prove it?”

CDD (Customer Due Diligence)

The risk assessment that follows identification. CDD evaluates the customer’s profile, the purpose of the account, the expected transaction patterns, and the source of funds. In an automated workflow, CDD often runs as a rules engine that scores the customer based on data collected during CIP and flags anything unusual.

EDD (Enhanced Due Diligence)

Deeper checks reserved for high-risk cases. If CDD flags a customer as a PEP, a resident of a high-risk jurisdiction, or someone with unusually complex transaction patterns, EDD kicks in. This typically means additional document requests, source-of-wealth verification, and senior management approval. In automated workflows, EDD is where human reviewers get involved.

OVD (Officially Valid Document)

The six documents the RBI accepts as proof of identity and address for KYC purposes: passport, driving licence, Aadhaar letter/card, Voter ID, NREGA job card, and National Population Register letter. PAN (or Form 60 in its absence) is required separately for financial transactions. Your automated document capture and OCR systems need to handle all six OVD types plus PAN.

AML (Anti-Money Laundering)

The broader fraud-prevention framework that KYC serves. AML encompasses KYC, transaction monitoring, suspicious activity reporting, and sanctions compliance. When people say “KYC/AML,” they mean the full regulatory apparatus, not just identity verification.

PEP (Politically Exposed Person)

An individual who holds or has held a prominent public function, domestically or internationally. PEPs and their close associates carry higher money laundering risk. Every automated KYC workflow must screen customers against PEP databases as part of CDD. This screening typically runs alongside sanctions list checks.

STP (Straight-Through Processing)

When a KYC application flows from initiation to approval without any human touching it. STP is the goal of automation: document submitted, OCR extracts data, face match confirms identity, risk score falls in the green zone, screening finds no hits, account opens. The STP rate is one of the most important metrics in automated KYC workflow design for remote customers.


India-Specific KYC Methods for Remote Customers

India has developed a unique set of digital identity verification methods, thanks largely to Aadhaar infrastructure. Understanding these is essential for anyone designing remote KYC workflows in the Indian market.

eKYC (Electronic KYC)

Digital identity verification using Aadhaar infrastructure. Three methods dominate for remote customers:

  • OTP-based eKYC: A one-time password sent to the Aadhaar-linked mobile number. The customer enters the OTP, UIDAI returns demographic data. Fast but limited, accounts opened via OTP-based eKYC have restricted functionality until full KYC is completed.
  • Biometric-based eKYC: Fingerprint or iris scan at an authorized center. Not truly remote, but included for completeness.
  • Video-based eKYC (V-CIP): See the detailed entry below. This is the method that makes fully functional remote account opening possible.

V-CIP (Video-based Customer Identification Process)

The RBI’s framework for verifying customer identity through a live, real-time video interaction. V-CIP is legally equivalent to face-to-face identification, which means banks and NBFCs can open fully functional accounts without the customer ever visiting a branch. This makes V-CIP the backbone of automated KYC workflow design for remote customers in India.

RBI requirements for V-CIP:

  • End-to-end encrypted video call
  • Geotagging to verify the customer is located in India
  • Real-time document verification using OCR
  • Liveness checks to confirm a live person (not a photo or recording)
  • Complete recording of the session
  • Concurrent audit by a trained official

Common failure points practitioners report:

Geo-tagging errors are a recurring inspection finding. One compliance discussion noted that some V-CIP implementations log the bank’s own server coordinates instead of the customer’s device GPS, which defeats the entire purpose of the check.

Liveness detection is another weak spot. The RBI mandates that V-CIP systems detect a live person and prevent spoofing but does not prescribe the specific method. Many implementations settle for a single blink test that a screen recording can defeat.

Customer drop-offs are significant. Practitioners report that fluctuating networks, poor image quality, limited agent training, and basic lack of trust in the digital process all drive abandonment. This is especially true in Tier-3 and Tier-4 locations where bandwidth is unreliable.

The penalty stakes are real. In FY 2024-25, the RBI imposed ₹54.78 crore in penalties across 353 regulated entities, with KYC violations near the top of the list.

Aadhaar OTP KYC

A subset of eKYC where verification happens solely through an OTP sent to the customer’s Aadhaar-linked mobile. Quick and frictionless, but the RBI treats it as “small KYC,” suitable only for lower-value accounts with transaction limits until full KYC is completed.

Offline KYC / DigiLocker

XML-based sharing of identity documents without live Aadhaar authentication. The customer downloads a digitally signed XML file from UIDAI or shares documents via DigiLocker. Useful for workflows where real-time Aadhaar authentication is not available or where the customer prefers not to share biometrics.

CKYC / CKYCR (Central KYC Records Registry)

India’s pan-regulator registry for customer KYC records, operated by CERSAI. Here is the idea: a customer completes KYC once with any regulated entity, the record gets uploaded to CKYC, and a unique 14-digit KYC Identification Number (KIN) is assigned. When that customer opens an account elsewhere, they share their KIN instead of resubmitting documents. The new institution fetches verified details directly from the registry after confirming consent.

For automated workflows, CKYC integration means checking the registry before starting a fresh verification. If a valid KIN exists, you skip redundant document collection entirely. This dramatically reduces friction for customers who already have a financial relationship with any regulated entity.

KRA (KYC Registration Agency)

SEBI-regulated KYC registries for capital markets participants. KRAs like KFintech, CAMS, and CDSL Ventures maintain KYC records for mutual fund and demat account holders. Distinct from CKYC, though the government has been working toward interoperability.


Workflow Design Terms

This is where the glossary gets operational. These terms describe the building blocks of an automated KYC workflow for remote customers.

KYC Orchestration

The engine that sequences checks, routes decisions, and manages the customer journey end-to-end. An orchestration layer decides: “This customer submitted Aadhaar, so run OTP verification. The risk score is low, so skip EDD. Screening returned clean, so approve via STP. Upload to CKYC.” Without orchestration, you have a collection of point tools. With it, you have a workflow.

For more on how these integrations work in practice, see our guide on integrating voice AI with core banking and CRM.

Risk-Based Routing

The principle of matching verification intensity to risk level. Roughly 95% of applicants are low-risk and should flow through a streamlined path. The remaining 5% warrant heavier checks, additional documents, or manual review. Risk-based routing is what makes automated KYC workflows economically viable: you spend human time only where it matters.

In practice, this means the orchestration engine assigns a risk score after CIP/CDD and routes accordingly. Low-risk goes to STP. Medium-risk might get an additional document request or a phone-based confirmation. High-risk goes to EDD with a human reviewer.

KYC Workflow Builder

No-code or low-code tools that let compliance teams design, test, and publish verification flows without writing code. These tools typically offer drag-and-drop interfaces for sequencing checks, setting rules, and defining escalation paths. The value for remote KYC is that compliance can iterate on the workflow as regulations change (which they do, frequently) without waiting for engineering cycles.

Automated KYC Verification

Using AI, OCR, and machine learning to process identity checks without manual intervention. This includes extracting data from uploaded documents, matching the face on the document to the selfie or video, cross-referencing data against government databases, and screening against sanctions and PEP lists. The goal is to make STP the default path for low-risk customers.

Human-in-the-Loop (HITL)

Where regulations mandate a human reviewer rather than full automation. V-CIP is the clearest example: even though the video call can be AI-assisted, the RBI requires a trained official to conduct concurrent audit. HITL also applies to EDD decisions, sanctions match resolution, and suspicious activity reporting.

Understanding where HITL is legally required versus optional is critical for automated KYC workflow design for remote customers. Automate everything you can, but know exactly where you cannot.

For a deeper exploration of this concept, read our guide on human-in-the-loop monitoring and quality assurance.

Document Follow-Up Workflow

Automated outreach to chase missing or incomplete documents. This is one of the highest-volume tasks in remote KYC. A customer uploads a blurry PAN image, or submits Aadhaar but forgets the address proof, or starts the process and drops off entirely. The follow-up workflow triggers voice calls, WhatsApp messages, or SMS nudges to bring them back.

Practitioners on forums note that a single personal loan application at a mid-sized NBFC can trigger four to six outbound calls before activation. Multiply that across thousands of daily applications and the staffing math stops working. This is precisely where automated outreach becomes necessary.

Pre-KYC Scheduling

A voice or chat-based pre-call to prepare the customer for V-CIP. The system confirms the customer has their documents ready, explains what will happen during the video call, schedules a V-CIP slot in the customer’s preferred language, and sends a WhatsApp or SMS deep-link to join. Pre-KYC scheduling dramatically reduces V-CIP failure rates by ensuring the customer is prepared before the regulated session begins.

For a step-by-step implementation guide, see how to implement voice-first KYC calls for customer onboarding.


Ongoing Compliance Terms

KYC does not end at onboarding. These terms cover what happens after the customer is verified.

Re-KYC / Periodic KYC Updation

The RBI mandates that customer KYC records be refreshed periodically: every 2 years for high-risk customers, every 8 years for medium-risk, and every 10 years for low-risk accounts. This creates a recurring compliance workload. For large banks with millions of accounts, re-KYC generates enormous operational volume.

The RBI’s 2025 KYC Amendment Directions now require institutions to send at least three reminders before or after the KYC due date, using SMS, email, letters, or postal services. If KYC remains pending, another round of three reminders must follow. That is a minimum of six outbound communications per customer. At scale, this is impossible to manage manually.

pKYC (Perpetual KYC)

The destination state for KYC maturity. Perpetual KYC is an event-driven approach that continuously monitors and updates customer information based on specific triggers (address change, new employment, significant transaction pattern shift) rather than relying on fixed periodic reviews.

According to PwC’s Financial Crime Report 2024, organizations adopting pKYC models can reduce KYC maintenance costs by up to 40% while improving detection accuracy. Early adopters report removing 70 to 90% of manual periodic review work.

Think of the progression this way: basic KYC is a one-time check, periodic re-KYC is a scheduled refresh, and pKYC is a living, continuously updated customer profile. Automated KYC workflow design for remote customers should aim for pKYC as the long-term architecture.

Ongoing Monitoring

Continuous surveillance of customer transactions and behavior after onboarding. This includes transaction pattern analysis, threshold alerts, and periodic risk reassessment. Ongoing monitoring feeds into pKYC by generating the events that trigger profile updates.

Adverse Media Screening

Checking news sources and media databases for negative information about a customer, either at onboarding or on an ongoing basis. Adverse media hits (fraud allegations, regulatory actions, criminal investigations) can trigger EDD or account review.


Regulatory Framework (India Focus)

Remote KYC workflows in India operate within a specific regulatory environment. Getting any of these wrong means penalties, audit findings, or worse.

RBI Master Direction on KYC (2016, amended through 2025)

The primary rule book. Originally issued in 2016, this direction consolidates all KYC requirements for RBI-regulated entities. It covers CDD procedures, risk categorization, record-keeping, V-CIP requirements, and eKYC norms. Every automated KYC workflow design decision traces back to this document.

RBI KYC Amendment Directions 2025

The most operationally significant recent change. Key provisions:

  • Low-risk individual customers can continue transacting even if KYC is pending, until June 30, 2026, or one year from the due date, whichever is later.
  • Banks can use their Business Correspondent (BC) network to facilitate KYC updates, especially in remote or underserved areas.
  • The mandated reminder system (minimum six communications per customer) creates a new compliance workflow that must be tracked and documented.

This amendment directly creates a high-volume automated reminder workflow need. The combination of extended deadlines and mandatory reminders means institutions need systems that can track KYC due dates, send reminders across channels, log delivery, and escalate non-responses, all at scale.

PMLA (Prevention of Money Laundering Act, 2002)

The statutory foundation for KYC obligations in India. PMLA defines the legal framework, and RBI Master Directions operationalize it for banking. Any KYC workflow design must ensure PMLA compliance as the baseline.

DPDP Act (Digital Personal Data Protection Act, 2023)

India’s data protection law, which introduces consent requirements that directly affect KYC workflows. Collecting Aadhaar numbers, biometric data, and identity documents requires explicit, informed consent. The consent must be specific to the purpose, and customers must be able to withdraw it. Automated KYC workflows need consent capture at the start of the journey, and consent records must be auditable.

For remote KYC specifically, this means the voice call or app flow must include a clear consent step before data collection begins, not buried in terms and conditions.

TRAI Commercial Communication Regulations

Calling window restrictions that constrain outbound KYC workflows. TRAI limits commercial communications to specific hours and requires DND compliance. KYC reminder calls and document follow-up calls must respect these windows. Automated voice systems need time-zone-aware scheduling to avoid violations.

For a detailed review of compliance requirements, see our RBI compliance review guide.

Fair Practice Code (FPC)

RBI guidelines on fair treatment that apply to all customer communications, including KYC. The FPC requires that language be clear, that customers not be harassed with excessive calls, and that communication happen through appropriate channels. This constrains how aggressive automated follow-up workflows can be.


Technology and Channel Terms

These are the technology components that make automated KYC workflow design for remote customers possible.

Voice AI Agent

An AI-powered voice system that handles KYC-related calls: reminders, document collection, scheduling, and data confirmation. Voice AI sits not as a replacement for V-CIP (which still requires a human-in-the-loop), but as the coordination layer that runs the conversational verification around it. It captures structured updates, routes regulated decision-points to the appropriate human reviewer, and handles the high-volume outbound work that would otherwise require large call center teams.

In practice, voice AI handles five distinct workload buckets in KYC: pre-V-CIP scheduling and document collection, periodic re-KYC reminders, event-based KYC updates, income verification, and address confirmation.

Learn more about how AI voice banking works across financial workflows.

OCR (Optical Character Recognition)

Extracts text data from identity documents automatically. In KYC workflows, OCR reads PAN cards, Aadhaar letters, driving licences, and passports, pulling out name, date of birth, document number, and address. Good OCR handles poor image quality, regional language text, and varied document formats. Bad OCR creates manual rework that defeats the purpose of automation.

Accuracy in financial data capture depends heavily on domain-specific NLU, not just generic text recognition.

Liveness Detection

Technology that confirms a real person is present during verification, not a photograph, video playback, or deepfake. Liveness checks range from simple (blink detection, head turn) to sophisticated (3D depth analysis, texture analysis). For V-CIP compliance, liveness detection is mandatory, but the RBI does not prescribe the specific method, leaving room for varying implementation quality.

Biometric Authentication

Verification using fingerprints, iris scans, or face matching. In remote KYC workflows, face matching (comparing the selfie or video frame to the document photo) is the most common biometric method. Fingerprint and iris require hardware that remote customers typically do not have.

Omnichannel KYC

Coordinating verification across phone, WhatsApp, SMS, app, and (when necessary) branch. A customer might start KYC on the app, receive a document follow-up via WhatsApp, complete V-CIP on a video call, and get their confirmation via SMS. Omnichannel orchestration ensures the customer’s state is consistent across all channels.

Vernacular and Code-Switching Support

The ability to handle KYC interactions in regional languages and mixed-language speech. This matters enormously for remote customers. A borrower in rural Maharashtra may speak Marathi with Hindi phrases and occasional English words like “PAN card” or “OTP.” A KYC system that only handles clean English or Hindi will fail these customers.

Practitioners on Reddit and in industry forums consistently flag language barriers as a primary cause of KYC drop-offs in Tier-2/3/4 markets. App-only flows with English-only interfaces simply do not work for a large segment of India’s population. Multilingual voice AI that handles code-switching is not a nice-to-have; it is a workflow necessity.

For a deeper exploration of this challenge, read our guide on building inclusive financial experiences across regions and cultures.


Metrics That Matter

If you are designing or evaluating an automated KYC workflow for remote customers, these are the numbers you should be tracking.

KYC Conversion Rate

Completed verifications divided by initiated verifications. This is the single most important metric for remote KYC workflows. Industry data suggests a reasonable benchmark for an optimized digital onboarding flow is 55 to 70% end-to-end conversion. Anything below 50% signals design problems.

Drop-Off Rate

Where and when customers abandon the KYC journey. Industry data shows drop-off rates of 40 to 60% for manual or poorly designed digital KYC processes. That means firms lose nearly half their prospective customers before the relationship begins. The breakdown is telling: up to 35% drop off after installing but not completing sign-up, 40 to 50% abandon during KYC itself due to unclear flows or lack of reminders, and 20% or more leave even after completing KYC while waiting for delayed activation.

Automated KYC with optimized UX, mobile-first document capture, real-time verification feedback, and intelligent data pre-fill can reduce drop-off rates by 30 to 50%.

For a deeper look at onboarding benchmarks across BFSI, see customer onboarding: process, metrics, and examples.

STP Rate

The proportion of applications fully auto-processed without human review. A higher STP rate means lower cost per verification and faster time to activation. The STP rate depends on the quality of your document capture, OCR accuracy, risk model calibration, and screening data. Optimized workflows achieve STP rates above 80% for low-risk customer segments.

Cost per Verification

The total cost to verify one customer identity, including technology, personnel, and operational overhead. Industry benchmarks from Indian implementations suggest ₹40 to ₹80 per customer for optimized automated flows. Compare that to the cost of a branch visit or a manually processed application, and the economics of automation become clear.

Time to Activation

The elapsed time from KYC initiation to account activation or loan disbursement. For remote customers, every hour of delay increases the chance they abandon the process. Best-in-class automated KYC workflows for remote customers complete verification in under 8 minutes for straightforward cases.


How These Terms Connect: The End-to-End Workflow Map

Here is how every term defined above fits into a single automated KYC workflow for a remote customer. This is the synthesis that no other glossary provides.

Stage 1: Trigger

A customer applies for a loan, account, or financial product through an app, website, or agent referral. The orchestration engine creates a KYC case.

Stage 2: Pre-KYC (Voice/Chat)

A voice AI agent or chatbot contacts the customer to confirm their identity documents are ready. The agent explains the V-CIP process, answers questions in the customer’s preferred language (including code-switching between Hindi and English or regional languages), and schedules a V-CIP slot. A deep-link is sent via WhatsApp or SMS.

This pre-KYC step is where most drop-off prevention happens. If the customer does not respond, the document follow-up workflow triggers automated reminders across channels, respecting TRAI calling windows and DPDP consent requirements.

Stage 3: eKYC / V-CIP

The customer joins the video call or completes OTP-based eKYC. During V-CIP, the system performs:

  • OCR extraction from presented documents (OVD + PAN)
  • Face matching between the live video and document photo
  • Liveness detection to prevent spoofing
  • Geotagging to confirm India location
  • Session recording for audit

A trained official conducts concurrent audit (HITL requirement).

Stage 4: CDD and Risk Scoring

The orchestration engine runs CDD: cross-referencing extracted data against databases, scoring the customer’s risk profile, and checking for inconsistencies. Risk-based routing determines the next step.

Stage 5: Screening

Automated screening against PEP lists, sanctions databases, and adverse media sources. If a match is found, the case escalates to a compliance officer for manual review.

Stage 6: Decision (STP or HITL)

Low-risk cases with clean screening results pass through STP, meaning the account is approved automatically. High-risk cases or screening hits route to a human reviewer for EDD.

Stage 7: CKYC Upload

The verified KYC record is uploaded to the Central KYC Registry. The customer receives their 14-digit KIN, which they can use for future account openings at any regulated entity.

Stage 8: Ongoing Monitoring and pKYC

Post-onboarding, transaction monitoring begins. The system watches for unusual patterns, threshold breaches, and adverse media. For re-KYC, the automated reminder workflow triggers at the appropriate interval (2 years for high-risk, 10 years for low-risk). Over time, the institution moves toward perpetual KYC, where events trigger profile updates rather than calendar dates.

The market for this capability is growing fast. India’s e-KYC market was valued at USD 26.3 million in 2024 and is projected to reach USD 139.3 million by 2033, growing at a 20.33% CAGR.


Building this entire workflow, from pre-KYC scheduling through document follow-up and re-KYC reminders, in 8+ Indian languages is exactly what multilingual voice AI is designed for. Book a demo with Awaaz AI to see how it works in practice.


FAQ

What is automated KYC workflow design for remote customers?

It is the practice of building a technology-enabled sequence that identifies, verifies, and continuously monitors customers who never visit a physical branch. The workflow combines digital identity verification (eKYC, V-CIP), automated document processing (OCR), risk-based routing, sanctions screening, and ongoing monitoring into a single orchestrated flow.

Is V-CIP legally equivalent to in-person KYC in India?

Yes. The RBI treats V-CIP as legally equivalent to face-to-face identification, meaning banks and NBFCs can open fully functional accounts through V-CIP without any branch visit. However, V-CIP has strict requirements around encryption, geotagging, liveness detection, and concurrent audit by a trained official.

What is the difference between eKYC and V-CIP?

eKYC is the broader category of electronic KYC, which includes OTP-based, biometric-based, and video-based methods. V-CIP is specifically the video-based method that involves a live video call with liveness checks and concurrent audit. OTP-based eKYC opens limited-functionality accounts, while V-CIP enables full account opening.

How does the RBI 2025 KYC Amendment affect automated workflows?

The amendment requires a minimum of six reminders per customer whose KYC is pending, sent across multiple channels. It also allows Business Correspondents to facilitate KYC updates in remote areas and extends deadlines for low-risk customers. These changes create significant automated outbound workflow requirements that are difficult to manage manually at scale.

What is a good KYC conversion rate for remote customers?

A reasonable benchmark for an optimized digital onboarding flow is 55 to 70% end-to-end conversion. Poorly designed flows see drop-off rates of 40 to 60%. The biggest levers for improvement are pre-KYC preparation (ensuring customers have documents ready), real-time verification feedback, and automated follow-up for incomplete applications.

What is perpetual KYC (pKYC) and why does it matter?

Perpetual KYC replaces fixed periodic reviews with event-driven, continuous monitoring. Instead of refreshing every customer’s KYC on a 2 or 10-year cycle, the system updates profiles when specific triggers occur (address change, new employment, unusual transactions). Organizations adopting pKYC report cost reductions of up to 40% and removal of 70 to 90% of manual periodic review work.

Where does voice AI fit in automated KYC workflows?

Voice AI operates as a coordination and data-capture layer. It handles pre-V-CIP scheduling, document follow-up, re-KYC reminders, income verification, and address confirmation. It does not replace V-CIP itself (which requires a human auditor), but it handles the high-volume conversational work that surrounds and supports the regulated verification steps.

What consent requirements apply to remote KYC under the DPDP Act?

The Digital Personal Data Protection Act 2023 requires explicit, informed consent before collecting identity data. The consent must be specific to the purpose of KYC, clearly communicated (not buried in terms and conditions), and withdrawable. Automated KYC workflows must include a consent capture step at the start of the journey, and consent records must be auditable.