Fintech and lending
Onboard borrowers with decisions you can defend.
Lenders handle the most sensitive identity data there is. KYCVerify verifies Aadhaar against UIDAI's signature, validates the PAN, matches the selfie to the signed photo and screens the name, then keeps the evidence encrypted only as long as you set.
- 1Consent
- 2Aadhaar (Secure QR or Offline e-KYC)
- 3PAN
- 4Liveness
At submit
- Face match against the Aadhaar photo
- AML screening
- Age (18+)
- Duplicate detection
- steps in the hosted flow
- 4
- checks at submit
- 4
- automatic declines
- 0
decision.auto_decline: false · a person decides every failure
The problem
What this use case needs from verification.
Data you are accountable for
Every processor in the loop belongs in your privacy notice and your audit scope. KYCVerify runs every check on its own engine, with no third-party verification provider behind it, encrypts uploads at rest and purges them on your retention period.
Indian identity, done properly
Aadhaar Secure QR and Offline e-KYC are signed by UIDAI. Verifying that signature is stronger than OCR on a card photo, and keeping only the last four digits limits what you hold.
Decisions you can explain
Each decision carries the checks, scores and warnings behind it, and every manual decision is audited.
Recommended workflow
Steps the person sees, checks that decide.
Auto-decline off sends every failure to a reviewer, which suits lending where a false decline costs a customer.
In the hosted flow
- 1Consent
- 2Aadhaar (Secure QR or Offline e-KYC)
- 3PAN
- 4Liveness
At submit
- Face match against the Aadhaar photo
- AML screening
- Age (18+)
- Duplicate detection
- IP recorded for the audit trail
Keys left out of the config keep their defaults. Paste it into the workflow builder, or read every key on the workflows page.
{
"steps": {
"document": { "enabled": false },
"aadhaar": { "enabled": true, "methods": ["secure_qr", "offline_xml"],
"max_xml_age_days": 3, "require_signature": true },
"pan": { "enabled": true, "require_card_image": true },
"liveness": { "enabled": true, "challenges": 3 },
"face_match": { "enabled": true, "threshold": 0.363, "review_threshold": 0.30 },
"aml": { "enabled": true, "lists": ["ofac_sdn", "un_consolidated"] },
"age": { "enabled": true, "min_age": 18 },
"duplicate": { "enabled": true, "face_threshold": 0.55 }
},
"decision": { "auto_decline": false }
}Signals
What happens when something is off.
Real cases for this industry, the check that sees each one and what the engine records. Codes are exactly as they appear in the decision.
| When | Seen by | Outcome |
|---|---|---|
| The Aadhaar file was edited after download | aadhaar | failedaadhaar_signature_invalid, then review (auto-decline off) |
| The Offline e-KYC file is a week old | aadhaar | reviewaadhaar_xml_too_old |
| The PAN's fifth letter does not match the surname | pan | reviewpan_name_mismatch |
| The PAN belongs to a company, not a person | pan | reviewpan_not_individual |
| The selfie is a weak match for the Aadhaar photo | face_match | reviewface_match_weak |
| The name is close to an OFAC or UN entry | aml | reviewaml_potential_match |
| The same face applied last month under another name | duplicate | reviewduplicate_found |
Checks used
The capabilities behind it.
Each has its own page with an in-browser demo of the rule it applies.
Aadhaar
Secure QR and Offline e-KYC XML, verified against UIDAI's own signatures.
UIDAI RSA · XML-DSigPAN
Format, holder type and name-initial validation, with an optional card-image cross-check.
Income Tax Dept. formatLiveness
Active challenge-response: turn left, turn right, smile, move closer, in a random order.
Active challenge-responseFace match
1:1 comparison of the selfie with the document portrait, or the Aadhaar photo.
SFace cosine · 0.363AML screening
Fuzzy name and date-of-birth matching against OFAC SDN and the UN consolidated list.
OFAC SDN · UNDuplicate detection
Flags a document or a face already seen in another verification in the same app.
Fingerprints · embeddings
Regulatory context
Where the rules meet the product.
Lending in India sits under several overlapping regimes. Here is where KYCVerify fits in them, and where it does not. This is context, not legal advice.
Not legal advice. KYCVerify does not certify compliance with any law or regulator. Confirm how each rule applies to you with your compliance team and counsel.
RBI Master Direction on KYC (2016, as amended)
Sets customer due diligence for regulated entities and lists the officially valid documents and verification methods, including offline verification of Aadhaar. Which methods your product may use, and how they map to workflows, is a decision for your compliance team.
Prevention of Money Laundering Act, 2002 and its rules
Requires reporting entities to identify customers and keep records for a period after the relationship ends. Set the app's retention_days to that period: the purge worker will not delete earlier.
Aadhaar Act, 2016 (offline verification)
Allows offline verification of the UIDAI-signed artefacts KYCVerify checks. Under UIDAI's Regulation 13A (9 Dec 2025), an entity performing Aadhaar offline verification must register as an Offline Verification Seeking Entity. KYCVerify is software and confers no registration; confirm your position with counsel.
Digital Personal Data Protection Act, 2023
Asks for purpose limitation, a clear notice and erasure once the purpose is served. You remain the data fiduciary and KYCVerify acts as your processor; retention and purge settings make erasure routine.
What KYCVerify does not settle for you
- RBI's KYC directions decide which methods count for your product. Map each to a workflow with your compliance team; KYCVerify does not certify regulatory compliance.
- PAN is validated structurally, without a government lookup. Use a licensed provider if your policy requires PAN verification against the ITD.
- Aadhaar offline verification may require registration (for example as an OVSE) depending on your purpose. Confirm with counsel.
Integrate
One call starts it.
vendor_data comes back on every webhook, so the decision lands on the right application without a lookup.
- 1Create the session with this workflow and your own reference.
- 2Send the person the url, or open it on a device you control.
- 3Act on the signed session.status_updated webhook.
Create a session
curl -X POST https://kycverify.me/api/v1/sessions \
-H "x-api-key: $KYC_API_KEY" \
-H "content-type: application/json" \
-d '{
"workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
"vendor_data": "applicant-8812",
"contact": {
"email": "applicant@example.com"
},
"metadata": {
"product": "personal-loan",
"branch": "pune-02"
},
"expires_in_hours": 72
}'201 Created
{
"session_id": "ses_0k3v9x2m4a7qhd8f1rtb",
"status": "not_started",
"url": "https://kycverify.me/verify/q3Xf…",
"session_token": "q3Xf…",
"workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
"vendor_data": "applicant-8812",
"expires_at": "2026-10-06T09:12:44Z"
}FAQ
Questions.
Where is the data stored?
On KYCVerify's servers, encrypted at rest with AES-256-GCM and purged after each app's retention period. If your policy requires a specific region, ask us before you go live; we do not promise one on this site.
Can existing borrowers be re-verified?
Create a new session for the same vendor_data. Duplicate detection will link it to the earlier verification.
More solutions
Other ways teams use KYCVerify.
Build this workflow in the sandbox.
Set up the configuration above in the workflow builder and run a test session in minutes, then talk to us about going live.