Skip to content

Fintech and lending

Onboard borrowers with decisions you can defend.

Lenders handle the most sensitive identity data there is. KYCVerify verifies Aadhaar against UIDAI's signature, validates the PAN, matches the selfie to the signed photo and screens the name, then keeps the evidence encrypted only as long as you set.

Recommended workflowFintech and lending
  1. 1Consent
  2. 2Aadhaar (Secure QR or Offline e-KYC)
  3. 3PAN
  4. 4Liveness

At submit

  • Face match against the Aadhaar photo
  • AML screening
  • Age (18+)
  • Duplicate detection
steps in the hosted flow
4
checks at submit
4
automatic declines
0

decision.auto_decline: false · a person decides every failure

The problem

What this use case needs from verification.

  • Data you are accountable for

    Every processor in the loop belongs in your privacy notice and your audit scope. KYCVerify runs every check on its own engine, with no third-party verification provider behind it, encrypts uploads at rest and purges them on your retention period.

  • Indian identity, done properly

    Aadhaar Secure QR and Offline e-KYC are signed by UIDAI. Verifying that signature is stronger than OCR on a card photo, and keeping only the last four digits limits what you hold.

  • Decisions you can explain

    Each decision carries the checks, scores and warnings behind it, and every manual decision is audited.

Recommended workflow

Steps the person sees, checks that decide.

Auto-decline off sends every failure to a reviewer, which suits lending where a false decline costs a customer.

In the hosted flow

  1. 1Consent
  2. 2Aadhaar (Secure QR or Offline e-KYC)
  3. 3PAN
  4. 4Liveness

At submit

  • Face match against the Aadhaar photo
  • AML screening
  • Age (18+)
  • Duplicate detection
  • IP recorded for the audit trail

Keys left out of the config keep their defaults. Paste it into the workflow builder, or read every key on the workflows page.

Workflow config · json
{
  "steps": {
    "document":   { "enabled": false },
    "aadhaar":    { "enabled": true, "methods": ["secure_qr", "offline_xml"],
                    "max_xml_age_days": 3, "require_signature": true },
    "pan":        { "enabled": true, "require_card_image": true },
    "liveness":   { "enabled": true, "challenges": 3 },
    "face_match": { "enabled": true, "threshold": 0.363, "review_threshold": 0.30 },
    "aml":        { "enabled": true, "lists": ["ofac_sdn", "un_consolidated"] },
    "age":        { "enabled": true, "min_age": 18 },
    "duplicate":  { "enabled": true, "face_threshold": 0.55 }
  },
  "decision": { "auto_decline": false }
}

Signals

What happens when something is off.

Real cases for this industry, the check that sees each one and what the engine records. Codes are exactly as they appear in the decision.

Signals and outcomes
WhenSeen byOutcome
The Aadhaar file was edited after downloadaadhaarfailedaadhaar_signature_invalid, then review (auto-decline off)
The Offline e-KYC file is a week oldaadhaarreviewaadhaar_xml_too_old
The PAN's fifth letter does not match the surnamepanreviewpan_name_mismatch
The PAN belongs to a company, not a personpanreviewpan_not_individual
The selfie is a weak match for the Aadhaar photoface_matchreviewface_match_weak
The name is close to an OFAC or UN entryamlreviewaml_potential_match
The same face applied last month under another nameduplicatereviewduplicate_found

Regulatory context

Where the rules meet the product.

Lending in India sits under several overlapping regimes. Here is where KYCVerify fits in them, and where it does not. This is context, not legal advice.

Not legal advice. KYCVerify does not certify compliance with any law or regulator. Confirm how each rule applies to you with your compliance team and counsel.

  • RBI Master Direction on KYC (2016, as amended)

    Sets customer due diligence for regulated entities and lists the officially valid documents and verification methods, including offline verification of Aadhaar. Which methods your product may use, and how they map to workflows, is a decision for your compliance team.

  • Prevention of Money Laundering Act, 2002 and its rules

    Requires reporting entities to identify customers and keep records for a period after the relationship ends. Set the app's retention_days to that period: the purge worker will not delete earlier.

  • Aadhaar Act, 2016 (offline verification)

    Allows offline verification of the UIDAI-signed artefacts KYCVerify checks. Under UIDAI's Regulation 13A (9 Dec 2025), an entity performing Aadhaar offline verification must register as an Offline Verification Seeking Entity. KYCVerify is software and confers no registration; confirm your position with counsel.

  • Digital Personal Data Protection Act, 2023

    Asks for purpose limitation, a clear notice and erasure once the purpose is served. You remain the data fiduciary and KYCVerify acts as your processor; retention and purge settings make erasure routine.

What KYCVerify does not settle for you

  • RBI's KYC directions decide which methods count for your product. Map each to a workflow with your compliance team; KYCVerify does not certify regulatory compliance.
  • PAN is validated structurally, without a government lookup. Use a licensed provider if your policy requires PAN verification against the ITD.
  • Aadhaar offline verification may require registration (for example as an OVSE) depending on your purpose. Confirm with counsel.

Integrate

One call starts it.

vendor_data comes back on every webhook, so the decision lands on the right application without a lookup.

  1. 1Create the session with this workflow and your own reference.
  2. 2Send the person the url, or open it on a device you control.
  3. 3Act on the signed session.status_updated webhook.

Create a session

curl -X POST https://kycverify.me/api/v1/sessions \
  -H "x-api-key: $KYC_API_KEY" \
  -H "content-type: application/json" \
  -d '{
    "workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
    "vendor_data": "applicant-8812",
    "contact": {
      "email": "applicant@example.com"
    },
    "metadata": {
      "product": "personal-loan",
      "branch": "pune-02"
    },
    "expires_in_hours": 72
  }'

201 Created

{
  "session_id": "ses_0k3v9x2m4a7qhd8f1rtb",
  "status": "not_started",
  "url": "https://kycverify.me/verify/q3Xf…",
  "session_token": "q3Xf…",
  "workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
  "vendor_data": "applicant-8812",
  "expires_at": "2026-10-06T09:12:44Z"
}

FAQ

Questions.

Where is the data stored?

On KYCVerify's servers, encrypted at rest with AES-256-GCM and purged after each app's retention period. If your policy requires a specific region, ask us before you go live; we do not promise one on this site.

Can existing borrowers be re-verified?

Create a new session for the same vendor_data. Duplicate detection will link it to the earlier verification.

Build this workflow in the sandbox.

Set up the configuration above in the workflow builder and run a test session in minutes, then talk to us about going live.