Video KYC & Digital Customer Onboarding: IIBF Exam Guide

DIGIBANK By Ashish Jain · IIBF STORE Editorial · 18 June 2026 · Updated 15 Sep 2026 · 13 min read · 44 views
Video KYC & Digital Customer Onboarding: IIBF Exam Guide

Video KYC (V-CIP) has quietly become the single most important onboarding innovation in Indian banking, letting a customer open a fully compliant bank account over a live video call without ever stepping into a branch. For anyone preparing for the IIBF Digital Banking certification, video KYC and digital customer onboarding sit at the heart of the syllabus, because they tie together identity verification, Aadhaar e-KYC, fraud control and the wider open-banking ecosystem. This guide walks you through every concept the examiner can test, in plain language, with a study plan and practice resources to back it up.

Video KYC and digital customer onboarding flow for IIBF Digital Banking exam
Video KYC (V-CIP) connects e-KYC, fraud controls and open banking into one digital onboarding journey.

Key takeaways

  • Video KYC is formally the Video-based Customer Identification Process (V-CIP), introduced by the RBI as a permitted Customer Due Diligence method.
  • It rests on the PML (Maintenance of Records) Rules, 2005 and the Master Direction on KYC, 2016, as amended.
  • The customer must be physically present in India, and the officer running the call must be a trained employee of the regulated entity — never an outsourced agent.
  • Aadhaar e-KYC comes in three flavours: OTP-based, biometric, and offline XML/QR.
  • Onboarding ends with a risk categorisation (Low / Medium / High) that decides how quickly the account goes live.
  • Fraud controls layer liveness detection, document-forgery AI, device intelligence and statutory fraud reporting.

What is Video KYC (V-CIP) and why does it matter?

Video KYC is a live, two-way, interactive video call in which a bank official verifies a customer's identity in real time, instead of meeting them in person at a branch. The RBI placed this on a legal footing by amending the KYC Master Direction to recognise the Video-based Customer Identification Process as a valid way of carrying out Customer Due Diligence (CDD) for an individual customer.

The significance is hard to overstate. A customer in a remote village and a customer in a metro now follow the same paperless path: capture, verify, record, activate. For the exam, remember the three pillars that make a V-CIP session legally valid — a genuine live human on the call, verified identity documents, and a tamper-proof recorded audit trail.

The regulatory framework behind video KYC

The legal backbone of video KYC in India rests on two instruments: the Prevention of Money Laundering (Maintenance of Records) Rules, 2005 and the RBI Master Direction — Know Your Customer (KYC) Direction, 2016, which the central bank amends from time to time. The amendment that inserted V-CIP allowed regulated entities — banks, NBFCs, payment system providers and certain insurers — to establish identity through a video call rather than a branch visit.

Several conditions are non-negotiable, and examiners love them:

  • The customer must be physically present in India when the call takes place, confirmed via device geo-location.
  • The officer conducting the session must be a trained employee of the regulated entity, not an outsourced agent.
  • The session must be recorded end-to-end in encrypted form with a clear, time-stamped audit trail.
  • The technology platform should follow recognised information-security standards (for example ISO 27001-class controls), and a failed session must be restarted afresh, never resumed midway.

Because circulars in this area are revised often, treat any specific threshold or date as time-sensitive: study the principle, then confirm the exact figure against the latest released IIBF/RBI notification before exam day. The consolidated KYC Master Direction is always published on the official regulator's site, which you can reach via IIBF's official website and its linked RBI references.

How a video KYC session actually works, step by step

Process sequencing is a recurring exam theme, so internalise the order. A compliant V-CIP session typically runs like this:

  1. The customer presents an Officially Valid Document (OVD) — Aadhaar, passport, driving licence or Voter ID — to the camera.
  2. The officer runs a liveness check to confirm a real person is on screen, not a photograph or a deepfake.
  3. A random question is asked to confirm the customer is conscious and responsive.
  4. The device's geo-location is captured to confirm the customer is within India.
  5. Aadhaar e-KYC is performed via OTP or offline XML/QR verification.
  6. The customer's PAN is validated against the income-tax database.

Every captured frame, the recording and the supporting documents are stored securely with hash values so nothing can be altered later. Regulated entities must also run a periodic audit of V-CIP cases and escalate any deviation to the compliance officer.

Aadhaar e-KYC: the three modes you must know

e-KYC is the electronic retrieval of a customer's demographic details from the Aadhaar database, and it is the engine inside most video KYC flows. The Unique Identification Authority of India (UIDAI) supports three modes, each with its own use case.

1. OTP-based Aadhaar e-KYC

The customer enters their 12-digit Aadhaar number, UIDAI sends a One-Time Password to the registered mobile, and on entering it the Central Identities Data Repository (CIDR) returns the customer's name, date of birth, gender, address and photograph. It is fast, needs no fingerprint scanner, and is the most common mode in remote onboarding — but it requires the Aadhaar-linked mobile number and depends on explicit voluntary customer consent.

2. Biometric Aadhaar e-KYC

Here a certified fingerprint or iris device captures biometric data that is matched against UIDAI's records. This mode is used mainly at Business Correspondent (BC) points where the customer is physically present but cannot reach a branch. The device must be registered with UIDAI and data must be encrypted, so it is not suited to purely remote digital onboarding.

3. Offline Aadhaar (XML / QR)

Built to address privacy concerns, offline verification lets the customer share a digitally signed XML file or QR code containing masked Aadhaar details. The bank verifies the digital signature using UIDAI's public key, and the full Aadhaar number is never exposed. This mode is V-CIP friendly — the customer simply holds the QR-printed card up to the camera for the officer to scan. To lock in the differences between these modes, run a quick drill on the Digital Banking matching games.

The end-to-end digital onboarding journey

Video KYC is one stage inside a larger onboarding architecture. Understanding the full journey helps you answer scenario questions that ask what obligation applies at which step.

  • Channel initiation: the customer lands on the app or website, shares a mobile number and email, and confirms ownership via OTP.
  • Document capture and OCR: uploaded OVDs are read by Optical Character Recognition and AI engines that extract data, flag tampering and cross-check government databases in real time.
  • V-CIP session: the live video call runs as described above, and the system auto-fills the form from OCR and Aadhaar data to cut manual errors. The officer signs the Customer Identification Record digitally.
  • Risk categorisation: the customer is mapped to a Low, Medium or High CDD risk band based on occupation, income, geography and expected transactions.
  • Activation and CRM: low-risk accounts can go live within minutes, while data flows into the Core Banking Solution and CRM to begin personalised servicing.

Politically Exposed Persons (PEPs) and high-risk customers always undergo Enhanced Due Diligence (EDD), which can mean extra documents, branch verification or senior sign-off, regardless of transaction size. You can drill the risk-based approach with targeted questions on the Digital Banking mock tests.

Fraud controls in video KYC

Going digital opens new attack surfaces, so the syllabus tests fraud typologies and the controls that counter them. Strong V-CIP systems defend in layers.

  • Liveness and anti-spoofing: passive checks read micro-movements, skin texture and depth in a frame; active checks ask the customer to blink, turn or smile. Deepfake detection and presentation-attack controls add another barrier.
  • Document-forgery detection: AI scans for pixel-level inconsistencies, font anomalies and metadata tampering, while database integrations (PAN, Aadhaar, DigiLocker) confirm the document genuinely exists and is not revoked.
  • Device intelligence and behavioural biometrics: device fingerprinting flags emulators, rooted devices and suspicious VPNs, while keystroke and swipe patterns build a baseline to catch later account takeover.
  • Statutory reporting: suspicious patterns feed Suspicious Transaction Reports to the Financial Intelligence Unit (FIU-IND), and fraud cases are reported to the RBI through the prescribed fraud-return mechanism within the stipulated timelines.

Exam tip: the bank's Board must periodically review KYC/AML control effectiveness, and the compliance officer signs off on the V-CIP audit. Reporting thresholds and timelines change — confirm exact figures against the latest released RBI/IIBF notification rather than memorising an old slide.

Open banking context: where video KYC connects

Video KYC feeds directly into India's open-banking stack. A freshly onboarded customer can immediately link an Account Aggregator (AA) consent to share financial data — bank statements, insurance, GST and tax records — with lenders through a digital consent artefact. Crucially, the AA does not store data; it is a pure consent and data-flow intermediary.

Open banking APIs also enable the Banking-as-a-Service model, where a fintech partner initiates the customer journey while the bank retains full legal responsibility for KYC — and the video officer remains a bank employee. The whole flow runs on the India Stack (Aadhaar, eSign, DigiLocker and UPI), which is why a V-CIP-onboarded account can be linked to UPI for instant payments. Candidates moving toward advanced Digital Banking guides should see onboarding as the backbone of this ecosystem.

Video KYC vs traditional branch KYC

Aspect Video KYC (V-CIP) Traditional branch KYC
Customer presence Remote, anywhere in India via live video In person at the branch
Identity proof Live document display plus Aadhaar e-KYC Physical photocopies, wet signature
Liveness / anti-fraud Liveness check, geo-tag, encrypted recording Manual visual check by staff
Speed Minutes for low-risk customers Hours to days, subject to branch hours
Audit trail Digital, hashed, tamper-evident Paper file, harder to audit at scale

A practical study plan for this topic

Treat video KYC as a high-yield chapter and give it a focused week:

  1. Day 1-2: map the regulatory framework — PML Rules 2005, KYC Master Direction 2016, and the V-CIP conditions. Write the six session steps in order from memory.
  2. Day 3: master the three Aadhaar e-KYC modes and when each applies. Reinforce the vocabulary with the matching games.
  3. Day 4: learn the onboarding journey and risk categorisation, then read the linked Account Aggregator framework guide for the open-banking link.
  4. Day 5: cover fraud controls and reporting, connecting them to the broader CBDC, Video-KYC and Account Aggregator picture.
  5. Day 6-7: attempt timed full-length mock tests and review every wrong answer.
Aadhaar e-KYC modes and V-CIP onboarding steps summary for Digital Banking revision
Revision snapshot: framework, e-KYC modes, onboarding steps and fraud controls.

Common mistakes candidates make

  • Confusing V-CIP with e-KYC. e-KYC is data retrieval from Aadhaar; V-CIP is the broader live identification process that uses e-KYC as one step.
  • Assuming the officer can be outsourced. The video officer must be a bank employee — the technology can be a partner's, the decision cannot.
  • Thinking an interrupted session can resume. A broken V-CIP session must be restarted from scratch.
  • Memorising stale thresholds. Reporting limits and timelines are revised; verify them on the latest released notification.
  • Ignoring the open-banking links. Questions increasingly connect onboarding to the Account Aggregator and UPI ecosystem.

Frequently asked questions

What is the difference between V-CIP and e-KYC?

V-CIP is a live, interactive video process in which a bank officer verifies a customer's identity in real time, complete with liveness and geo-tagging. e-KYC is narrower — it is the electronic retrieval of demographic details from the Aadhaar database via OTP, biometric or offline XML. V-CIP usually uses e-KYC as one of its steps, but the two are not the same thing.

Can a bank outsource the V-CIP officer role to a fintech?

No. The RBI requires that the official conducting the video session be a trained employee of the regulated entity, not of an outsourced provider. A fintech may build the platform and start the customer journey, but the live verification decision must be taken by a bank official. Legal responsibility for KYC stays with the bank and cannot be delegated.

What happens if a video KYC session is interrupted?

An interrupted or failed V-CIP session must be restarted entirely from the beginning; it cannot be resumed from where it dropped. This protects the integrity of the process and prevents tampering with partial data. The customer repeats every mandatory step, and the bank logs all attempts, including failed ones, in its audit trail.

Which Aadhaar e-KYC mode is used in remote video KYC?

Remote onboarding typically uses OTP-based e-KYC or offline XML/QR verification, both of which work over a video call. Biometric e-KYC needs a certified fingerprint or iris device and is used mainly at Business Correspondent points. Offline XML is especially V-CIP friendly because the customer can simply show the QR-printed card to the camera.

How does video KYC connect to the Account Aggregator framework?

Once a customer is onboarded through V-CIP and the account is active, they can register with an Account Aggregator and grant consent for lenders to access their financial data. The AA only facilitates a secure, consent-driven data transfer between providers and users; it never stores the data itself. This lets a freshly onboarded customer unlock pre-approved, data-backed credit offers.

Is video KYC heavily weighted in the IIBF Digital Banking exam?

Yes. V-CIP, Aadhaar e-KYC, risk categorisation and fraud controls are core, frequently tested areas, often through process-sequencing and scenario questions. The safest preparation is to learn the principles, confirm any time-sensitive figures against the latest notification, and rehearse with full-length mock tests. You can compare your readiness across topics on the Learning Sessions mock tests.

Conclusion

Master video KYC and you have mastered one of the most rewarding chapters of the Digital Banking syllabus — and a process that genuinely powers banking for millions. Hold on to the framework, the six-step session, the three e-KYC modes and the layered fraud controls, keep an eye on the latest IIBF notification for any updated figures, and put it all to the test in timed practice. Stay consistent, and exam day will feel like just another mock you have already aced.

Related Guides

📚 Free Learning Sessions resources — connect & crack your exam

💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.

📱 Study on the go — get our iOS & Android app at iibf.store/app.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

Digital Banking · 5 questions · instant result
Q1. Assertion (A): "Memory scraping" is the technique behind most major POS malware attacks. Reason (R): When a card is swiped, its details are briefly stored in the terminal's memory while being transmitted to the processor, giving malware a window to copy the data.
Q2. Within the card payment chain, what is the "interchange fee" and which direction does it flow on purchase transactions?
Q3. A customer in a Tier I centre uses a debit card to withdraw cash at a POS terminal. As per RBI norms cited in the chapter, what is the maximum per-day cash withdrawal limit, and what is the cap on customer charges for such a withdrawal?
Q4. Match the POS transaction type (Column I) with its description (Column II): Column I: (i) Void (ii) Refund (iii) Pre-authorization (iv) Cash advance Column II: (P) Amount blocked from customer's account for a specific period, typically in hotels (Q) Merchant gives cash instead of a product, like an ATM (R) Sale cancelled and amount returned before end-of-day settlement (S) Sale cancelled and amount refunded after end-of-day settlement
Q5. A restaurant wants a card terminal that the waiter can carry to any table inside the premises, but it only works within a limited range of a base unit wired to the outlet's telephone line. Which terminal does this describe?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading