India's banks and insurers are set to launch a shared customer identification system in August 2026, with mutual funds and brokerages following later in the year. CKYC 2.0 promises the fix that millions of Indians have wanted for years: fill out know-your-customer paperwork once, and every bank, insurer and fund manager can pull the same verified record instead of asking for the same documents again.
That is the part worth sitting with before the launch date arrives. The registry CKYC 2.0 is built on is not new or small. It already holds records for nearly 1.2 billion customers, but wide adoption never really took hold: data-quality problems, duplication and incomplete records meant the Reserve Bank of India routinely rejected registry-sourced data and made banks demand fresh paperwork anyway. CKYC 2.0 is the attempt to make that same billion-plus-record registry actually work as a shared utility.

Sources: Business Today, on the CKYC registry's scale and Business Today, on the 2023 dark web leak. Chart: The Signal.
CKYC's current base, at nearly 1.2 billion records, is already larger than the 815 million records that a hacker offered for sale on a dark web forum in 2023. Making the registry work better does not shrink it. It makes the one number tied to it matter more.
One number instead of many
The mechanism behind the fix is a single identifier. Under the RBI's Master Direction on KYC, every customer's record in the Central KYC Records Registry carries one unique code called the KYC Identifier, or KIN. Today, a bank, an insurer and a mutual fund each run their own separate verification on the same person. Once CKYC 2.0 is live for banks and insurers in August 2026, with mutual funds and brokerages joining later, all of them are meant to pull the same record using the same KIN. That is the entire point of the redesign: one verified identity, reusable everywhere, instead of a dozen separate paper trails.
It is also a structural change in what a single credential can unlock. A password compromised at one bank exposes an account at that bank. Compromise a KIN, and what leaks is the pointer to a customer's record across every regulated entity that has adopted the registry.
The safeguard is a consent click, not a secret
The rule meant to keep this safe is consent, not obscurity. A regulated entity cannot simply pull a customer's existing KYC record from the registry on its own; RBI rules require it to first obtain that customer's explicit consent to use the KIN before downloading the record. That is a real, legally mandated control, and it does not exist in today's fragmented system, where each institution simply collects whatever documents a customer hands over.
But the consent RBI requires is a gate a person clicks through, not a wall. It stops an institution from pulling a record unprompted; it does not stop a criminal who has phished, socially engineered or coerced that one consent action, and it does nothing if the registry holding the records is itself compromised. Neither risk is hypothetical. The RBI has had to repeatedly warn the public about exactly this kind of fraud: scammers impersonating a KYC-updation request to phish personal details, login credentials and one-time passwords out of customers, or to trick them into installing unauthorised apps. And the registry side has already slipped once, too: in July 2025, CERSAI had to issue a formal advisory after receiving complaints of unauthorized CKYC downloads and updates traced to a technical glitch at a third-party vendor engaged by a reporting entity, and ordered reporting entities to tighten access controls. The table below sets out what actually changes.
CKYC 2.0 consolidates a fragmented process into one shared, consent-gated record.
| Existing CKYC registry | CKYC 2.0, launching 2026 | |
|---|---|---|
| Records held | Nearly 1.2 billion customer records | Same registry, relaunched as the shared base |
| Adoption | Stalled: the RBI routinely rejected stale or duplicate registry records | Phased mandatory rollout: banks and insurers from August 2026, mutual funds and brokerages later |
| Identifier | A unique KYC Identifier, or KIN, assigned per customer record | Same KIN, now the working key across sectors |
| Access control | Each institution re-verifies its own documents | Any regulated entity may pull the record via the KIN, but only with the customer's explicit consent |
Sources: Business Today, The Star, and the Reserve Bank of India's Master Direction and FAQs on KYC.
India has already leaked at this scale
This is not a hypothetical concern in a country with no history of data compromise at scale. In 2016, malware inside Hitachi Payment Services, a payments processor used across multiple banks, compromised roughly 3.2 million debit cards issued by banks including SBI, HDFC Bank, ICICI, Yes Bank and Axis Bank, forcing a mass block-and-reissue. Seven years later, in October 2023, a hacker offered a dataset of 815 million Indians' Aadhaar- and passport-linked personal records for sale on a dark web forum, which the cybersecurity firm Resecurity verified as authentic by checking sampled Aadhaar IDs against government systems.
3.2 million against 815 million: India's worst confirmed personal-data exposure to date is already close to 255 times the size of its worst confirmed card breach.

Sources: Business Today, on the 2016 Hitachi breach and Business Today, on the 2023 dark web leak. Chart: The Signal.
The 2016 breach was recoverable in a way the 2023 leak was not. A compromised card can be blocked and reissued in days; the bank simply cuts a new number. Aadhaar and passport identifiers are not designed to be swapped out the same way, and neither, on current evidence, is a KIN: it is meant to be the one permanent pointer to a customer's financial identity, precisely so it never has to be reissued.
The honest objection
The strongest case for CKYC 2.0 is that concentration can make security better, not worse. A single registry, built and defended by one team to one standard, can plausibly be hardened harder than dozens of unevenly resourced KYC databases scattered across banks, insurers, NBFCs and fund houses. And the explicit-consent requirement RBI has written into the rules is a genuine addition: no such logged, per-transaction consent step exists in today's fragmented process, where a customer hands over documents once and has little visibility into which institutions hold copies afterward.
That case is real, but it answers a question about average security, not about what happens on the day the defense fails. A well-built vault can be safer to use every single day and still be the single worst place for everything to be kept, precisely because there is only one door. India's dark web market has already shown that a dataset in the hundreds of millions of Aadhaar-linked records can leak and be verified as genuine. A registry that consolidates the pointer to a citizen's entire financial life does not remove that risk. It raises what is behind the door.
The Signal
CKYC 2.0 launches for banks and insurers in August 2026, with mutual funds and brokerages to follow, built on a registry that already holds close to 1.2 billion records and carries a documented history of data-quality failure. It replaces fragmented, repetitive verification with one identifier and a mandatory consent step, which is a real improvement over asking nothing at all. But the reason the old system was safer in one specific sense is the same reason it was so inefficient: a breach of one bank's records exposed one bank's customers. Against the shared registry, that same breach, or one coerced consent, exposes the record that every one of those institutions now points to. Watch two things once the rollout is mandatory: how hard it actually is to phish or coerce a customer's one-time consent at scale, and whether anyone builds a way to freeze or reissue a compromised KIN the way a bank reissues a card. Until one exists, the identifier meant to end repetitive paperwork is also the one credential in the system that cannot be changed after it fails.
Reporting basis: the CKYC 2.0 launch timeline and the existing registry's scale and adoption problems are per Reuters wire reporting, carried by The Star and by Business Today respectively, from the same underlying Reuters story. The definition of the KYC Identifier and the customer-consent requirement for downloading records from the registry are from the Reserve Bank of India's Master Direction on KYC and its accompanying FAQs, both primary regulatory documents. The RBI's warnings against KYC-updation phishing scams are from the Reserve Bank's own press release, another primary regulatory document. The July 2025 CKYC download-and-update incident is per TeamLease RegTech's summary of CERSAI's advisory CKYC/2025/10, a primary registry communique verified through that secondary summary. The 2016 debit-card breach figure is per Business Today's reporting of the SISA Information Security forensic audit of Hitachi Payment Services. The 2023 dark web leak figure is per Business Today's reporting of Resecurity's threat-intelligence findings. The comparison of the 2016 and 2023 breach scales, and the comparison of CKYC's current record base to the 2023 leak, are The Signal's calculations from those figures.



