Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · October 6, 2026

Aadhaar eKYC for businesses: KUA licensing, data and AML rules

Aadhaar eKYC explained for businesses: what users see, the data UIDAI returns, PMLA and Supreme Court limits, the KUA, Sub-KUA and ASA routes, offline XML and QR, and a fallback for everyone else.

By DiditUpdated
aadhaar-ekyc-cover.png

In short

Aadhaar eKYC is the electronic Know Your Customer (KYC) service of India's Unique Identification Authority (UIDAI): with consent, a licensed business sends an Aadhaar number, the person confirms with a one-time password (OTP) or a biometric, and UIDAI returns signed identity data. Online eKYC needs a legal basis and a licence; any entity may accept the signed offline XML or QR with consent.[8][9][15]

  • About 1.34 billion people hold a live Aadhaar number (March 2026).[1]
  • Aadhaar is a valid anti-money laundering (AML) route in India, and a voluntary one for the customer.[9]

Last reviewed: 5 October 2026 · Not legal advice

Aadhaar eKYC is the quickest way to verify most adults in India, and the most regulated. The hard part is the licence. This guide covers the user flow, the data, the law, the Authentication User Agency and eKYC User Agency (AUA and KUA) and Authentication Service Agency (ASA) routes, and what to do for everyone Aadhaar does not cover.

What Aadhaar is

Aadhaar is India's 12-digit identity number, backed by a central database of demographic and biometric data called the Central Identities Data Repository (CIDR). There is no mandatory card: the number, the database and the authentication service are the credential.[8][15]

Aadhaar

India's national identity number and authentication service

On request
CountryIndia
OperatorUnique Identification Authority of India (UIDAI), established under Section 11 of the Aadhaar Act[9]
LaunchedStatutory basis since the Aadhaar Act, 2016[8]
UsersAbout 134 crore (1.34 billion) live holders (PIB, 18 March 2026)[1]
CredentialA number plus central database; OTP, fingerprint, iris or face; signed offline XML and Secure QR[5][6][7]
Level of assuranceNo eIDAS level: an Indian scheme outside the EU framework, not EU-notified
Data returnedName, date or year of birth, gender, address, photo; offline files carry a reference ID, not the number[6]
Legal basisAadhaar Act, 2016, as amended by the Aadhaar and Other Laws (Amendment) Act, 2019[8][9]
Didit statusOn request

Adoption in numbers

The Press Information Bureau (PIB) and UIDAI count holders, authentications and eKYC calls separately, so each figure names its metric.

1.34 bnLive Aadhaar holders, March 2026
170 bn+Authentications to date, March 2026
2.31 bnAuthentications in November 2025
428.9 meKYC transactions in February 2025

Sources: PIB[1]; DD News[3]; PIB on eKYC volumes[4].

Authentications reached 221 crore in August 2025, up 10% in a year.[2] Face authentications rose to 28.29 crore in November 2025 from 12.04 crore in November 2024.[3] On 9 September 2026, with 500 crore+ (5 bn+) face authentications done by about 200 entities, UIDAI launched a Face Authentication SDK and sandbox to help banking and finance firms meet the Reserve Bank of India's (RBI) multi-factor authentication rules.[5] The sources we checked publish no share of adults covered, so this post gives none (5 October 2026).

What the user sees

Online eKYC: the user types an Aadhaar number or a Virtual ID, consents, then confirms with an OTP sent to the mobile registered with UIDAI, or with a fingerprint, iris or face. Face capture on a phone runs through UIDAI's AadhaarFaceRD app.[5][14]

Licensed KUA app

Enter Aadhaar or Virtual ID

I consent to share my Aadhaar KYC data for account opening.

Send OTP

1On the KUA's or Sub-KUA's page, the user enters the number or Virtual ID and consents.

Licensed KUA app

Enter the OTP

Sent by UIDAI to your registered mobile.

Verify

2UIDAI sends an OTP; the user types it here.

AadhaarFaceRD

Face authentication

An alternative to the OTP.

3Or the user authenticates with a face capture.

Licensed KUA app

KYC received

  • NameShared
  • Date of birthShared
  • AddressShared
  • BiometricsNot shared

4UIDAI returns signed KYC data to the licensed KUA.

Offline, UIDAI is not called. The user downloads a signed Paperless Offline eKYC file from the myAadhaar portal, protects it with a share phrase, and hands over both. The printed Secure QR on the Aadhaar letter, e-Aadhaar or PVC card is read with UIDAI's Secure QR reader.[6][7]

myAadhaar

Download offline eKYC

Set a share phrase to protect the file.

Download ZIP

1The user downloads a signed file on the UIDAI portal.

Your app

Upload your file

Add the ZIP file and your share phrase.

Upload

2The user shares the file and the phrase with you.

Your app

Signature checked

  • NameShared
  • PhotoShared
  • Aadhaar numberNot shared

3You check UIDAI's signature; only a reference ID arrives.

What a business receives from Aadhaar eKYC

Online, the KUA receives signed demographic data and a photo. Offline, the holder chooses which demographic fields, and whether the photo, go into the file.[6]

AttributeOffline file or QRNotes
Reference IDAlwaysLast four digits of Aadhaar plus a timestamp[6]
UIDAI signatureAlways344 characters; detects tampering[6]
NameHolder's choiceSigned by UIDAI[6]
Date or year of birthHolder's choiceAs UIDAI holds it[6]
GenderHolder's choiceM, F or T[6]
AddressHolder's choiceCare-of, house, street, locality, district, state, pincode, country[6]
PhotoHolder's choiceLow resolution; the QR photo is for visual inspection only[6]
Mobile and emailHashedLets you confirm a value you already hold[6]
Aadhaar numberNeverAn offline verifier may not collect or store it[9]
Core biometricsNeverNo fingerprint or iris data[6]

To bind an offline file to the person in front of you, add your own OTP check or a face match between a live selfie and the embedded photo.[6]

Watch out

Unlike most European eIDs, Aadhaar returns an address and a photo: use them only for the verification the person consented to.[9]

The law behind Aadhaar

The Aadhaar Act, 2016 governs authentication (Section 8), offline verification (Section 8A), limits on sharing (Section 29) and penalties (Section 40).[8] In Justice K.S. Puttaswamy (Retd.) v. Union of India, on 26 September 2018, the Supreme Court upheld Aadhaar for welfare but struck down Section 57 insofar as it let private entities demand or use Aadhaar authentication by contract, along with mandatory linking to bank accounts and SIM cards.[10]

The Aadhaar and Other Laws (Amendment) Act, 2019 rebuilt private use on a statutory footing: offline verification under Section 8A, and voluntary Aadhaar use for bank KYC under the Prevention of Money-laundering Act (PMLA) and for SIM cards under the Telegraph Act.[9] The Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Rules, 2020, as amended on 31 January 2025, let the Central Government approve private entities for uses such as hospitality, healthcare, credit bureaus, e-commerce, education, staff attendance, customer onboarding and eKYC, through the SWIK portal launched on 27 February 2025.[11][12]

Section 8A(4)Aadhaar Act, inserted in 2019

"No offline verification-seeking entity shall (a) subject an Aadhaar number holder to authentication; (b) collect, use, or store an Aadhaar number or biometric information of any individual for any purpose"

Source: UIDAI, Aadhaar and Other Laws (Amendment) Act, 2019[9]

Does Aadhaar satisfy AML customer due diligence in India

Yes, for the entities the law names. Section 11A of the PMLA, inserted in 2019, lists Aadhaar authentication for banking companies and offline verification for any reporting entity. Other reporting entities may authenticate only once the Central Government notifies them after consulting UIDAI and their regulator.[9][13]

Section 11A(1) and (3)Prevention of Money-laundering Act, 2002

"Every reporting entity shall verify the identity of its clients and the beneficial owner, by (a) authentication under the Aadhaar [...] Act, 2016 if the reporting entity is a banking company; or (b) offline verification [...] no client or beneficial owner shall be denied services for not having an Aadhaar number."

Source: UIDAI, Aadhaar and Other Laws (Amendment) Act, 2019, section 27[9]

The RBI's KYC FAQ of 9 June 2025 lists Aadhaar eKYC with OTP or biometrics, offline verification, a certified copy of an officially valid document, Digital KYC and Video-based Customer Identification Process (V-CIP) as bank onboarding routes, and says the Aadhaar number is not mandatory for KYC unless the customer claims a government benefit.[14]

How to connect to Aadhaar eKYC: KUA, Sub-KUA or offline

A requesting entity sends an Aadhaar number with demographic or biometric data to the CIDR. An AUA gets yes or no authentication; a KUA also receives eKYC data. Either reaches the CIDR through an ASA, by becoming one or contracting one. A Sub-AUA or Sub-KUA uses Aadhaar through an existing requesting entity.[15]

Direct licence

Become a KUA

  • Must meet UIDAI's Schedule A eligibility
  • Application, physical checks, UIDAI agreement
  • Your own ASA or a contracted one

Aadhaar Act, Section 8

Through a licensee

Sub-KUA of an existing KUA

  • Uses Aadhaar through an existing KUA
  • Still needs a legal basis to authenticate
  • UIDAI's security rules still apply

UIDAI requesting-entity rules

No licence

Offline verification

  • Any entity, with the person's consent
  • Check UIDAI's signature on XML or QR
  • Never store the Aadhaar number

Aadhaar Act, Section 8A

Becoming a KUA means applying under UIDAI's procedure, accepting physical verification of documents, infrastructure and technology, and signing an agreement that includes damages for non-performance. UIDAI may charge application, annual subscription and per-transaction fees.[15][16] This post quotes no amounts: check UIDAI's current fee circular. No onboarding lead time is published, and intermediary prices are not public in the sources this guide relies on (5 October 2026).

UIDAI's security rules apply on every authentication route: encrypt captured data at once, never store biometrics or OTPs, never use the Aadhaar number as your customer ID, and log responses for audit.[15]

User Your app KUA and ASA UIDAI CIDR
1Number and consent
2Encrypted request
3eKYC request

The user enters the OTP or gives a biometric

4Signed KYC data
5KYC response
6Account opened

Online eKYC as a Sub-KUA, simplified.

Use cases and sector rules

Each sector needs its own legal hook for online eKYC. Without one, the offline route is the only option.

Use caseRouteRule
Bank onboardingOnline eKYC or offlinePMLA Section 11A; RBI KYC FAQ[9][14]
Other AML reporting entitiesOffline; online once notifiedPMLA Section 11A proviso[9][13]
SIM cardsVoluntary Aadhaar use2019 Amendment Act, Telegraph Act[9]
E-commerce, hospitality, healthcare, educationOnline, once approvedGood Governance Rules via SWIK[11][12]
Age checks, gamingOffline date of birthNo Aadhaar-specific sector rule found[6]

For age, the offline file and the Secure QR carry the date or year of birth, so you can check 18+ without storing the Aadhaar number.[6][9] According to dpdpa.com, Rule 10 of the Digital Personal Data Protection (DPDP) Rules, 2025 accepts reliable age or identity details, or a virtual token mapped to them, for parental consent for under-18s, for example through DigiLocker. DigiLocker has more than 70 crore registered users; our DigiLocker API guide covers it.[17] For database checks, see our Aadhaar verification API post.

Limits and fallbacks

Aadhaar is for residents: the Act entitles every resident to a number and defines a resident as someone who lived in India for 182 days or more in the twelve months before enrolment.[8] Short-stay foreigners and many non-resident Indians will not have one. For a child, offline verification needs a parent's or guardian's consent.[9]

Aadhaar is a choice, not a gate. Under PMLA Section 11A, no client may be denied services for lacking an Aadhaar number, and an entity that uses authentication must also offer the other routes, including a passport.[9] We found no primary source on Aadhaar outages (5 October 2026).

1Offer Aadhaar first

Online eKYC where licensed, otherwise the offline file or QR.

Can the customer use Aadhaar

Yes

Verify with Aadhaar

Signed name, date of birth, address.

No

Verify a passport or ID

NFC chip reading, liveness and face match.

2Screen and decide

Sanctions and PEP screening; the decision stays with you.

Aadhaar first, with a document route for everyone else.

The document route reads the e-passport chip with near-field communication (NFC), checks liveness and matches the face to the chip photo. Our post on NFC eID verification explains why the chip is hard to forge.

Implementation checklist

  • Confirm your legal basis: PMLA, Good Governance approval, telecom licence, or offline only.
  • Choose the route: KUA, Sub-KUA or offline verification.
  • Write consent text naming the data, its use and the alternatives.
  • Offer a non-Aadhaar route to every customer.
  • Keep only the reference ID or last four digits, never the number.
  • Verify UIDAI's signature on every offline file or QR.
  • Never store biometrics or OTPs; log metadata for audit.

How Didit helps with Aadhaar eKYC

Didit adds Aadhaar on request. In India today, the eID verification workflow runs the document route: ID document capture, NFC chip reading, liveness and face match, plus AML screening against 1,300+ sanctions, PEP and watchlists. A full KYC check costs $0.33, NFC verification $0.15 and AML screening $0.20.

The same workflow already runs national eIDs in Europe; the digital ID wallets docs show how schemes are switched on.[18] The Aadhaar screens above belong to the licensed KUA or Sub-KUA requesting the data, not to a Didit Aadhaar flow.

Didit provides

  • Document, chip, liveness and face checks in India today
  • AML screening and ongoing monitoring
  • The evidence of every check

Stays with you

  • Your legal basis for using Aadhaar
  • Your UIDAI or KUA agreement and consent text
  • The onboarding decision and the liability

Bring Aadhaar to your sign-up

Tell us how your users in India verify today, and start with the document route now.

Talk to us about AadhaarStart free

Key takeaways

  • Online Aadhaar eKYC needs a legal basis and a KUA licence, directly or through an existing KUA.
  • Offline XML and Secure QR are open to any entity with consent, but never the Aadhaar number.
  • PMLA Section 11A makes Aadhaar a valid AML route and a voluntary one.
  • Plan a passport or document route for non-residents and anyone who declines Aadhaar.

Frequently asked questions

Can a private company use Aadhaar eKYC after the 2018 Supreme Court judgment?

Only with a legal basis. The Court struck down private use by contract under Section 57, so a company now needs a statute or a government approval, such as PMLA Section 11A or the Good Governance Rules. Any entity may still use offline verification with consent.[9][10][11]

What is the difference between online Aadhaar eKYC and offline XML or Secure QR?

Online eKYC calls UIDAI in real time and needs a KUA licence. Offline verification checks a UIDAI-signed file or QR the user already holds and needs no licence, but the verifier must not authenticate or store the Aadhaar number.[6][9]

How much does Aadhaar eKYC cost?

UIDAI may charge requesting entities application, annual subscription and per-transaction fees. This guide quotes no amounts; check UIDAI's current fee circular.[15]

What data does Aadhaar eKYC return?

The offline file holds name, date or year of birth, gender, address, a photo and hashed mobile and email, with a reference ID instead of the number. The holder chooses which fields to include.[6]

Can I store a customer's Aadhaar number?

Not as an offline verifier: Section 8A(4) bars collecting, using or storing it. UIDAI also says the number must never be used as a domain-specific identifier.[9][15]

Does Aadhaar satisfy AML customer due diligence?

Yes, under PMLA Section 11A: authentication for banking companies and notified reporting entities, offline verification for any reporting entity. The customer may choose another route.[9]

Do foreigners and NRIs have Aadhaar?

Aadhaar is for residents, defined as people who lived in India for 182 days or more in the year before enrolment. Plan a passport route for anyone without it.[8]

Can I verify a minor with Aadhaar?

For offline verification of a child, a parent or guardian must consent.[9]

Is Aadhaar face authentication accepted for RBI multi-factor authentication?

UIDAI launched its Face Authentication SDK on 9 September 2026 to help banking and finance firms meet RBI-mandated multi-factor authentication.[5]

How do I test Aadhaar eKYC?

UIDAI launched a sandbox with its Face Authentication SDK on 9 September 2026. Our sources show no public sandbox for OTP eKYC, so ask your KUA how it tests; offline files can be tested with your own downloaded XML.[5][6]

Sources

  1. Aadhaar holders and authentications to date, Press Information Bureau, 18 March 2026.
  2. Aadhaar authentications in August 2025, Press Information Bureau.
  3. UIDAI records 231 crore Aadhaar authentication transactions in November, DD News.
  4. Aadhaar eKYC transactions, Press Information Bureau, 2025.
  5. Aadhaar Face Authentication SDK and sandbox launch, Press Information Bureau, 9 September 2026.
  6. Aadhaar Paperless Offline e-KYC, UIDAI.
  7. Aadhaar online services, Secure QR, UIDAI.
  8. Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, as amended, UIDAI.
  9. Aadhaar and Other Laws (Amendment) Act, 2019, UIDAI.
  10. Justice K.S. Puttaswamy (Retd.) v. Union of India, judgment of 26 September 2018, Supreme Court of India.
  11. Aadhaar Good Governance authentication and the SWIK portal, Press Information Bureau, 2025.
  12. Amendment to the Aadhaar Authentication for Good Governance Rules, Press Information Bureau, 2025.
  13. Prevention of Money-laundering (Maintenance of Records) Rules, 2005, Financial Intelligence Unit India.
  14. FAQs on the Master Direction on KYC, Reserve Bank of India, 9 June 2025.
  15. Authentication Requesting Agency (AUA, KUA, ASA), UIDAI, updated 30 June 2026.
  16. AUA and KUA agreement, version 4.0, UIDAI.
  17. DigiLocker, National e-Governance Division, MeitY.
  18. Digital ID wallets, Didit documentation.

Compare national schemes on the eID verification page, and for Europe, see the EUDI Wallet page.

Verify customers in India and beyond

Start with documents, chip reading and liveness today, and tell us which national schemes your users need.

Start freeTalk to us

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page