RBI allowed e-KYC via Aadhaar for payment system operators (2013 circular)
No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2013-14/337 · issued 25 Oct 2013 · ~2 min read
Quick answerRBI permitted payment system operators to use UIDAI's e-KYC service for paperless KYC verification. Biometric authentication data (name, age, gender, photo) qualifies as an Officially Valid Document under PMLA rules, reducing fraud risk and enabling digital onboarding.
What changed
RBI expanded KYC acceptance to include UIDAI's e-KYC service, where demographic data and photos obtained via biometric authentication are treated as an Officially Valid Document under PML Rules. Previously, only physical Aadhaar letters were accepted. PSOs must sign a KUA agreement with UIDAI, deploy STQC-certified biometric scanners, and develop software for e-KYC across customer service points.
What it means for you
This move streamlined customer onboarding for payment system operators by eliminating paper-based KYC, cutting identity fraud and forgery risks. Banks and PSOs could verify customers instantly using Aadhaar biometrics, reducing operational costs and turnaround time. However, they must invest in certified hardware and secure networks to comply with UIDAI standards.
Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.
What banks were required to do at the time
Sign a KUA agreement with UIDAI to access e-KYC services.
Deploy STQC-certified biometric scanners at all customer service points.
Develop software applications compliant with UIDAI API protocols for e-KYC.
Update your KYC policy to include e-KYC as a valid verification process.
Ensure explicit user consent is obtained before biometric authentication.
Who it affects
All payment system operators (PSOs) under PSS Act, System participants and prospective prepaid payment instrument issuers, Banks offering digital payment services, Customers using Aadhaar-based e-KYC for onboarding
❓ Common questions
Regulatory timeline
Decoded by BankPulse2026-06-18 12:10 IST
Status change: withdrawn03 Aug 2026, 04:00 IST
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
What is the key change in this circular?
RBI now accepts UIDAI's e-KYC service (biometric authentication) as an Officially Valid Document for KYC under PMLA rules, alongside physical Aadhaar letters.
Do we still need to accept physical Aadhaar cards?
Yes, physical Aadhaar cards/letters continue to be accepted as Officially Valid Documents. e-KYC is an additional option.
What infrastructure is required for e-KYC?
PSOs must sign a KUA agreement with UIDAI, deploy STQC-certified biometric scanners, and develop software using UIDAI API protocols for secure data transfer.
📜 Read the original circular — full text as issued by RBI
RBI/2013-14/337
DPSS. CO. AD. No. /919/02.27.005/2013-14
October 25, 2013
To
All Payment System Providers, System Participants
and any prospective prepaid payment instrument Issuer
Madam/Dear Sir
Know Your Customer (KYC) Norms /Anti-Money Laundering (AML) Standards/ Combating of Financing of Terrorism (CFT)/Obligation of PSOs under Prevention of Money Laundering Act (PMLA), 2002 – e-KYC Service of UIDAI – Recognizing on-line Aadhaar authentication (electronic verification process) to be accepted as an ‘Officially Valid Document’ under PML Rules
Please refer to our circular DPSS.No.2174/02.14.004/2010-11 dated March 23, 2011 on Know Your Customer (KYC) Norms / Anti-Money Laundering (AML) Standards/ Combating of Financing of Terrorism (CFT) / Obligation of banks under PMLA, 2002 which states that letter issued by the Unique Identification Authority of India (UIDAI) containing details of name, address and Aadhaar number as quoted under para 2 (d) of PML Rules, 2005 may be accepted as an ‘Officially Valid Document’.
2. In order to reduce the risk of identity fraud, document forgery and have paperless KYC verification, UIDAI has launched its e-KYC services. Accordingly, it has been decided to accept e-KYC service as a valid process for KYC verification under Prevention of Money Laundering (Maintenance of Records) Rules, 2005. Further, the information containing demographic details and photographs made available from UIDAI as a result of e-KYC process (“which is in an electronic form and accessible so as to be usable for a subsequent reference”) may be treated as an ‘Officially Valid Document’ under PML Rules. In this connection, it is advised that while using e-KYC service of UIDAI, the individual user has to authorize the UIDAI, by explicit consent, to release her or his identity/address through biometric authentication to the Payment System Operators (PSOs). The UIDAI then transfers the data of the individual comprising name, age, gender and photograph of the individual, electronically to the PSOs, which may be accepted as valid process for KYC verification. The broad operational instructions to PSOs on Aadhaar e-KYC service is enclosed as Annex .
3. PSOs are advised to have proper infrastructure (as specified in Annex) in place to enable biometric authentication for e-KYC.
4. Physical Aadhaar card/letter issued by UIDAI containing details of name, address and Aadhaar number received through post would continue to be accepted as an ‘Officially Valid Document’.
5. PSOs authorised under the Payment and Settlement Systems Act, 2007 (PSS Act) may revise their KYC policy in the light of the above instructions and ensure strict adherence to the same.
Yours faithfully
(Vijay Chugh)
Chief General Manager
Encls: as above
Annex
Operational Procedure to be followed by PSOs for e-KYC exercise
The e-KYC service of the UIDAI may be leveraged by PSOs through a secured network. Any PSO willing to use the UIDAI e-KYC service is required to sign an agreement with the UIDAI. The process flow to be followed is as follows:
1. Sign KYC User Agency (KUA) agreement with UIDAI to enable the PSOs to specifically access e-KYC service.
2. PSOs to deploy hardware and software for deployment of e-KYC service across various delivery channels. These should be Standardisation Testing and Quality Certification (STQC) Institute, Department of Electronics & Information Technology, Government of India certified biometric scanners at PSO outlets/ agents / micro ATMs as per UIDAI standards. The current list of certified biometric scanners is given in the link below:
http://www.stqc.gov.in/sites/upload_files/stqc/files/UID_Auth_Certlist_250613..pdf
3. Develop a software application to enable use of e-KYC across various Customer Service Points (CSP) (including PSO outlets/ agents) as per UIDAI defined Application Programming Interface (API) protocols. For this purpose PSOs will have to develop their own software under the broad guidelines of UIDAI. Therefore, the software may differ from PSO to PSO.
4. Define a procedure for obtaining customer authorization to UIDAI for sharing e-KYC data with the PSOs. This authorization can be in physical (by way of a written explicit consent authorising UIDAI to share his/her Aadhaar data with the PSOs for the purpose of opening an account) / electronic form as defined by UIDAI from time to time.
5. Sample process flow would be as follows:
a. Customer walks into CSP of a PSO with his/her 12-digit Aadhaar number and explicit consent and requests to open an account with Aadhaar based e-KYC.
b. PSOs representative manning the CSP enters the number into PSO’s e-KYC application software.
c. The customer inputs his/her biometrics via a UIDAI compliant biometric reader (e.g. fingerprints on a biometric reader).
d. The software application captures the Aadhaar number along with biometric data, encrypts this data and sends it to UIDAI’s Central Identities Data Repository (CIDR).
e. The Aadhaar KYC service authenticates customer data. If the Aadhar number does not match with the biometrics, UIDAI server responds with an error with various reason codes depending on type of error (as defined by UIDAI).
f. If the Aadhaar number matches with the biometrics, UIDAI responds with digitally signed and encrypted demographic information [Name, year/date of birth, Gender, Address, Phone and email (if available)] and photograph. This information is captured by PSO’s e-KYC application and processed as needed.
g. PSO’s server auto populates the demographic data and photograph in relevant fields. It also records the full audit trail of e-KYC viz. source of information, digital signatures, reference number, original request generation number, machine ID for device used to generate the request, date and time stamp with full trail of message routing, UIDAI encryption date and time stamp, PSO’s decryption date and time stamp, etc.
h. The photograph and demographics of the customer can be seen on the screen of computer at PSO outlet or on a hand held device of their agents for reference.
i. The customer can open his/her account with the PSO subject to satisfying other requirements.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2013-14/337 · issued 25 Oct 2013. The plain-English explanation above is BankPulse’s own independent summary.
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8526&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.