Aadhaar Based e-KYC for Banks: Modes, Consent and Rules (IIBF)
Aadhaar based e-KYC for banks is one of the highest-scoring topics in the IIBF KYC, AML and CFT paper, and also one of the most misunderstood at the branch counter. The reason is simple: the law shifted twice — once through a Supreme Court judgment and once through Parliament — yet a lot of desk-level practice still carries habits from the pre-2018 era. If you can separate the four permitted modes, quote the enabling provision and explain exactly what a bank may store, you have locked in a clean set of marks.
This guide takes you through the statutory footing, the four modes, the consent and redaction discipline, the link with the Central KYC Records Registry, and the audit points where branches most often slip.
⚖️ The Statutory Spine: 2016 Act, 2018 Judgment, 2019 Amendment
The parent statute is the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016. Its original design was narrow: Section 7 allowed the State to require Aadhaar authentication for subsidies, benefits and services funded from the Consolidated Fund of India, while Section 57 permitted any body corporate or person to use Aadhaar to establish identity under any law or contract. Banks leaned heavily on Section 57.
In the Puttaswamy (Aadhaar) judgment of September 2018, the Constitution Bench struck down Section 57 as unconstitutional and, applying the proportionality test, held that compulsory linking of bank accounts to Aadhaar could not stand. That single ruling removed the contractual basis on which private and even public sector banks had been running authentication, and made Aadhaar linkage voluntary rather than mandatory.
Parliament restored a lawful route through the Aadhaar and Other Laws (Amendment) Act, 2019. It inserted Section 4(4) into the Aadhaar Act, allowing an entity to perform authentication only where it is compliant with UIDAI's privacy and security standards and is either permitted by a law made by Parliament or seeking authentication for a purpose notified by the Central Government in the interest of the State. In parallel it inserted Section 11A into the Prevention of Money-Laundering Act, which is the provision your examiner wants: a reporting entity may verify a client's identity through Aadhaar authentication only if it is a banking company notified by the Central Government after consultation with UIDAI and the appropriate regulator. The same amendment created the statutory concept of offline verification and the offline verification seeking entity, and added a penalty chapter under which a requesting entity can face a civil penalty running into crores plus a daily amount for continuing default, appealable to TDSAT. For the wider statutory map, work through the chapter on legislation at the national level.

🔑 The Four Modes You Must Be Able to Distinguish
Examiners rarely ask "what is e-KYC". They ask which mode a given bank may lawfully use in a given fact pattern. There are four distinct routes, and they carry different eligibility conditions, different data flows and different account limits.
Mode 1 — Authentication-based e-KYC. The customer gives consent, the bank sends an OTP or biometric to UIDAI, and UIDAI returns a digitally signed demographic packet with name, date or year of birth, gender, address and photograph. This is available only to a bank notified under Section 11A of the PMLA and registered with UIDAI as a KYC User Agency.
Mode 2 — Offline verification. The customer generates an Aadhaar Paperless Offline e-KYC XML protected by a share code, or presents the secure QR code printed on e-Aadhaar or the PVC card. The bank verifies UIDAI's digital signature locally. No biometrics, no live call to UIDAI, and non-notified entities may use it as an offline verification seeking entity.
Mode 3 — Digital KYC. The PML Rules prescribe a procedure in which an authorised officer of the bank captures a live photograph of the customer along with the officially valid document or proof of possession of Aadhaar, and the application stamps the latitude and longitude of the location where that photograph is taken. Geotagging plus the live image is what makes it acceptable.
Mode 4 — Aadhaar as a physical officially valid document. The customer simply submits proof of possession of the Aadhaar number, and the bank keeps a copy with the first eight digits blacked out. Any bank may accept this; no UIDAI registration is involved. Getting Aadhaar based e-KYC for banks right in an exam answer means naming the mode first and only then describing the process.
| Mode | Enabling provision | UIDAI registration needed? | Data returned to bank | Key limitation |
|---|---|---|---|---|
| Authentication-based e-KYC (OTP / biometric) | PMLA s.11A; Aadhaar Act s.4(4) | ✅ KUA / Sub-KUA | Signed demographic packet from UIDAI | Only for banks notified by the Central Government |
| Offline verification (XML, QR code) | Aadhaar Act (offline verification, 2019 amendment) | ❌ OVSE role only | UIDAI-signed file shared by the customer | Share code / QR must be verified for signature validity |
| Digital KYC (live photo + geotag) | PML (Maintenance of Records) Rules | ❌ | Live photograph, document image, coordinates | Must be done by an authorised officer of the bank |
| Aadhaar as physical OVD | PML Rules — proof of possession of Aadhaar | ❌ | Redacted paper or scanned copy | First eight digits must be blacked out |
💡 Exam Tip: Where an account is opened through OTP-based e-KYC in non-face-to-face mode, the RBI Master Direction on KYC imposes caps — an aggregate balance ceiling of ₹1 lakh, aggregate credits in a financial year not exceeding ₹2 lakh, term loans capped at ₹60,000 in a year, no foreign remittance credits, and completion of full CDD within one year, failing which the account is closed. Biometric e-KYC done face to face at the branch does not attract these caps.

🧾 Consent, Redaction and the Limits on Data Storage
Consent is not a formality here; it is the legal foundation. Section 8 of the Aadhaar Act requires the requesting entity to obtain the individual's consent before collecting identity information, and to inform the individual of the nature of the information that will be shared, the uses to which it will be put, and the alternatives available if authentication is declined. A branch that treats Aadhaar as the default and offers no alternative document has already failed the test.
Redaction is the second pillar. Wherever the Aadhaar number is stored, copied or scanned, the first eight digits must be blacked out so that only the last four remain visible. This applies to physical photocopies, to imaged documents in the document management system, and to any printout retained in the account opening file.
Storage restrictions are the third. Core biometric information can never be shared, and the UIDAI regulations bar a requesting entity from retaining biometrics beyond the transaction. Where the Aadhaar number itself has to be retained, it must sit in an encrypted Aadhaar Data Vault with only a reference key exposed to the core banking and downstream systems. Layered on top is the Digital Personal Data Protection Act, 2023 framework, which independently demands purpose limitation, storage limitation and a clear consent notice. Handled properly, Aadhaar based e-KYC for banks is both a compliance control and a data protection obligation, and examiners increasingly frame questions at that intersection.
⚠️ Common Mistake: Assuming that because a customer voluntarily hands over an Aadhaar copy, the bank may store the full twelve digits in the CBS customer master. It may not. Voluntary submission removes the compulsion objection; it does not remove the redaction and vaulting obligations.

🗂️ UIDAI Roles, KUA Status and the CKYCR Handoff
The Unique Identification Authority of India sits at the centre of the ecosystem as the issuing and authenticating authority. A bank that wants to run live authentication connects through an Authentication Service Agency and is itself onboarded as an Authentication User Agency; the moment it wants the demographic e-KYC packet rather than a bare yes/no response, it must hold KYC User Agency status. Business correspondents and group entities plug in as Sub-AUA or Sub-KUA under the parent bank's licence, and the parent remains accountable for their conduct. Notification under Section 11A of the PMLA and registration with UIDAI are two separate gates — clearing one does not clear the other, and Aadhaar based e-KYC for banks is lawful only when both are in place.
The output then has to travel onward. KYC records of individual and legal entity customers are uploaded to the Central KYC Records Registry operated by CERSAI, within the timeline prescribed under the PML Rules, and the registry returns a KYC Identifier. Once that identifier exists, another regulated entity can pull the record instead of re-collecting documents — provided the customer has not changed address and the record is not flagged for updation. You can read the RBI's consolidated instructions directly on the RBI Master Directions page, and revise the supervisory architecture in the chapter on organisation structure in India.
🔍 Audit Traps Where Branches Most Often Go Wrong
Inspection findings on this subject are remarkably repetitive, which is good news for you. First, consent records: the authentication log exists but the signed or digital consent capturing purpose and alternatives is missing. Second, unredacted copies sitting in account opening files or scanned into the document repository. Third, offline XML files accepted without verifying the UIDAI digital signature, which reduces a cryptographic control to a photocopy. Fourth, digital KYC photographs taken without geotagging, or taken by a business correspondent who is not an authorised officer for that purpose.
Fifth, and the costliest, is treating e-KYC as the end of due diligence rather than the identification step within it. Identity verification does not by itself establish source of funds, expected activity or the risk band of the relationship — you still have to complete risk categorisation of customers, run name checks as part of sanctions screening in banks, and apply the heightened scrutiny required for politically exposed persons in KYC. A clean Aadhaar authentication response tells you the person is who they claim to be; it tells you nothing about what they intend to do with the account.
Sixth, the operational risk angle: OTP interception, SIM swap and social engineering around the authentication step have become live fraud vectors, which is why the controls in this cyber crime prevention checklist for bankers belong in the same conversation. Finally, cross-border relationships add another layer — revise the chapter on correspondent banking, because an Aadhaar-verified domestic identity does nothing for a respondent bank's own due diligence chain. Treat Aadhaar based e-KYC for banks as one controlled input into a wider risk assessment and the audit findings largely disappear.
🧠 Practice MCQs: Aadhaar e-KYC and the Legal Framework
Q1. Under the Prevention of Money-Laundering Act, a bank may verify a client's identity through Aadhaar authentication only if it is — (a) registered as an Authentication Service Agency with UIDAI (b) notified by the Central Government under Section 11A of the PMLA (c) a scheduled commercial bank with net worth above a prescribed threshold (d) licensed as a payment system operator
Answer: (b) — Section 11A, inserted by the Aadhaar and Other Laws (Amendment) Act, 2019, permits Aadhaar authentication only by a banking company notified by the Central Government after consultation with UIDAI and the appropriate regulator.
Q2. In the Puttaswamy (Aadhaar) judgment of 2018, the Supreme Court struck down which provision that had allowed private entities to seek Aadhaar authentication under a contract? (a) Section 7 (b) Section 29 (c) Section 57 (d) Section 33
Answer: (c) — Section 57 of the Aadhaar Act, 2016 was held unconstitutional, which removed the contractual basis banks had used for authentication until then.
Q3. Where a customer submits a physical copy of Aadhaar as proof of possession, the bank must — (a) redact or black out the first eight digits (b) redact the last four digits (c) store the full number unmasked in the CBS customer master (d) obtain prior UIDAI approval before accepting the copy
Answer: (a) — Only the last four digits may remain visible; the first eight digits must be blacked out wherever the number is copied, scanned or stored.
Q4. Which feature is essential to the digital KYC procedure prescribed under the PML Rules? (a) The customer uploads a scanned PDF from home (b) The bank stores the customer's biometrics for future authentication (c) It applies only to accounts with a balance above ₹1 lakh (d) An authorised officer captures a live photograph along with the latitude and longitude of the location
Answer: (d) — The live photograph taken by an authorised officer plus geotagging of the location is precisely what distinguishes digital KYC from an ordinary document upload.
Q5. An account opened through OTP-based Aadhaar e-KYC in non-face-to-face mode attracts which restriction under the RBI Master Direction on KYC? (a) Aggregate balance not exceeding ₹50,000 at any point of time (b) Aggregate credits in a financial year not exceeding ₹1 lakh (c) Aggregate balance not exceeding ₹1 lakh and aggregate credits in a financial year not exceeding ₹2 lakh (d) No restriction, since Aadhaar is a strong identifier
Answer: (c) — The Master Direction caps the aggregate balance at ₹1 lakh and yearly aggregate credits at ₹2 lakh, and requires full CDD to be completed within a year.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
❓ Frequently Asked Questions
Is Aadhaar mandatory for opening a bank account?
No. Since the 2018 Supreme Court judgment, linkage is voluntary and consent-based. A customer may offer any other officially valid document, and the bank must inform the customer that alternatives exist.
Can a cooperative bank or an NBFC do OTP-based Aadhaar authentication?
Only if it has been notified by the Central Government under Section 11A of the PMLA and is registered with UIDAI in the appropriate user agency role. Entities without that status must rely on offline verification, digital KYC or a redacted physical copy.
What is the difference between e-KYC and offline verification?
e-KYC is a live authentication call to UIDAI that returns a signed demographic packet. Offline verification uses a UIDAI-signed XML file or secure QR code that the customer supplies, with no live call and no biometrics.
Does an Aadhaar e-KYC record still have to go to the CKYCR?
Yes. The mode of identification does not change the reporting obligation — the KYC record is uploaded to the Central KYC Records Registry within the prescribed timeline and a KYC Identifier is generated.
🎯 Revise It, Then Test It
Reduce the topic to a four-line memory hook: statute in 2016, Section 57 struck down in 2018, Section 11A and offline verification added in 2019, and four modes with different eligibility gates. Add the redaction rule, the vaulting rule and the consent-with-alternatives rule, and you can answer almost any framing the examiner chooses. Remember that Aadhaar based e-KYC for banks is examined as a legal-plus-operational subject, so quote the provision and then describe the branch control.
Now convert the reading into recall. Attempt a timed set on chapter-wise KYC and AML mock tests, then browse the rest of the KYC, AML and CFT article hub to close the gaps the test exposes.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading