Operations & Best Practices

CKYC 2.0 and the Single Customer ID: What Changes in Broker Onboarding, Re-KYC and Record Retention

India's central KYC registry moves to CKYC 2.0 in August 2026, with a single customer identifier reusable across banks, insurers and mutual funds. This post walks the broker onboarding workflow end to end: where the identifier replaces document collection, where it does not, and the SOP edits to make before the rollout.

Tarun Kumar Singh
Tarun Kumar SinghStrategic Risk & Compliance SpecialistAIII · CRICP · CIAFP
10 min read

Listen to this article

Audio version • 10 min read

ckyckycbroker operationsonboardingdpdpcompliance

Last reviewed: August 2026

What CKYC 2.0 Actually Changes in August 2026

India's Central KYC Records Registry is moving to its second generation. Reporting through late July 2026 (India Today and Business Today on 24 July, The Hindu on 25 July, Outlook Money on 26 July) describes a coordinated launch of CKYC 2.0 in August 2026: a single customer identifier that banks and insurers will share, with mutual fund integration also planned per The Hindu's report, so a customer verified once does not repeat identity checks at every institution. Business Today framed the objective as eliminating repetitive KYC verification across the financial system.

The first-generation CKYC, operated by CERSAI since 2016, issues a 14-digit KYC Identification Number that lets a reporting entity retrieve an existing verified record instead of collecting documents afresh. The stated point of CKYC 2.0 is to make the identifier the default path rather than the exception.

For a commercial insurance broker this is an operations question, not a consumer convenience story. The broker is a reporting entity under the Prevention of Money Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005, with its own due-diligence, screening and record-keeping duties layered under the IRDAI AML/CFT framework. The change touches four surfaces: onboarding of new clients, proposal-stage KYC on the individuals behind a corporate client, re-KYC at renewal, and record retention under the Digital Personal Data Protection Act, 2023 once the registry, not the broker, is the system of record.

The one-line summary: CKYC 2.0 compresses the individual-identity leg of onboarding and changes almost nothing else. A broker that treats the identifier as a full substitute for its onboarding workflow is building an inspection finding.

The Onboarding Workflow End to End: Where the Identifier Substitutes

Map the standard corporate onboarding workflow (set out in our broker client onboarding and KYC/AML workflow guide) and mark where a CKYC identifier can replace a step after August 2026.

  1. Initiation and registry lookup. Today's CKYC check is often treated as optional, because retrieval has frequently not returned a usable record. Under CKYC 2.0 the lookup becomes the first step for every natural person in the file: authorised signatories, directors whose KYC the insurer requires at proposal stage, beneficial owners, and proprietors or partners where the client is unincorporated. A valid identifier plus consent replaces collection of that individual's officially valid documents.

  2. Entity document capture. Unchanged. The corporate constitutional set (incorporation certificate, PAN, memorandum and articles, board resolution, GST registration) is collected and verified against MCA, GST and PAN sources as before.

  3. Individual identity verification. The step the identifier genuinely replaces. Where the signatory or director has a CKYC record, the broker retrieves it with consent instead of collecting a passport or driving licence copy. The burden shifts to validation: confirming the retrieved record matches the person and is current.

  4. Beneficial-ownership analysis. Unchanged in substance. The identifier tells you who a natural person is, not who controls the client. Tracing the ownership chain through MCA filings to named natural persons under the PML Rules thresholds remains the broker's own analysis. Only the final step changes: an identified owner's identity can be evidenced by retrieval.

  5. Sanctions and PEP screening. Unchanged. The registry verifies identity; it does not screen. UAPA and UNSC list screening and PEP checks, with documented dispositions, continue for every connected person.

  6. Risk categorisation, approval, activation. Unchanged. Risk rating, enhanced-due-diligence escalation and the completeness gate before binding operate as before.

The honest accounting: CKYC 2.0 compresses one stage (chasing individuals for attested identity documents, routinely the longest-running step in an onboarding file) and lightens the tail of a second. It is a compression of one leg, not a replacement of the workflow.

Where CKYC 2.0 Does Not Reach

The gap between what press coverage implies and what a compliance file requires is where mistakes will happen. Four boundaries matter.

Corporate entities. The single customer ID, as reported, is built around the individual moving between banks, insurers and mutual funds. The corporate client file is a different object: constitutional documents, signatory resolutions, shareholding records, financial statements corroborating the business profile. The reported design does not remove the broker's obligation to establish what the entity is, who may act for it, and what business it does. For a commercial broker, whose book is overwhelmingly corporate, the entity file survives intact.

UBO declarations. Beneficial ownership is an analysis, not an identity fact. The registry can confirm a named individual exists and has verified KYC; it cannot confirm that the individual ultimately owns or controls your client through three layers of holding structure. The UBO declaration, the shareholding trace and the documented basis of identification remain the broker's work product.

Sanctions and PEP screening. A CKYC identifier is not a clearance. A person can hold a valid KYC record and appear on a designation list the following week. Screening at onboarding and periodic rescreening against updated lists continue as before, and every hit still needs a recorded disposition. See our KYC and AML obligations in Indian insurance primer for the screening baseline.

Insurer-specific proposal requirements. Insurers will keep asking for what their own underwriting and compliance require: proposal forms, financials for credit-sensitive lines, claims history, and in some lines personal declarations from directors. The single customer ID ends one category of document requests, not all of them.

Proposal-Stage KYC and the Cover-Note Clock on Urgent Placements

Where the registry change earns its keep in commercial broking is the urgent placement: a client needs cover bound this week (a consignment sailing, a project condition precedent, a lender's insurance covenant). The insurer will not issue until proposal-stage KYC is complete, and on a corporate client that means KYC on individuals: the authorised signatory and, depending on the insurer's checklist, directors and beneficial owners.

Today that individual-KYC leg is the bottleneck. The signatory is travelling, a director's OVD copy comes back in the wrong format, the beneficial owner's family office answers document requests in its own time. Each round trip adds days, and the placement waits on paperwork that has nothing to do with the risk.

After August 2026 the same leg should compress to a lookup: identifier plus consent, retrieved in minutes rather than collected over days. The individuals on these checklists are the likeliest to hold current records, because directors and promoters already hold the bank accounts, demat accounts and mutual fund folios that feed the registry.

Two residual delays survive, and the SOP should anticipate both:

  • Consent logistics. Retrieval requires the individual's consent. The intake should capture it at the same moment as the proposal signature, otherwise the consent chase simply replaces the document chase.
  • Record gaps and mismatches. An individual with no record, a stale record or a name mismatch against the board resolution falls back to the document path. Build that fallback into the workflow, with the gap flagged on day one rather than discovered when the insurer bounces the file.

The win is conditional: the broker that pre-verifies identifiers for directors and signatories at onboarding, before any urgent placement exists, is the one whose cover notes stop waiting on KYC.

Re-KYC at Renewal: What the Registry Changes and What It Does Not

Re-KYC is the recurring cost the registry most directly attacks. KYC refresh runs on a periodicity set by risk category, and insurers also demand re-KYC at renewal when their records are stale. For a broker running a few hundred corporate clients, renewal-season re-KYC is a standing tax: the same directors' documents, collected again, because the record aged out.

With a live central registry the refresh logic should invert. The design as reported in July 2026 is verification once and reuse across institutions, so an individual who refreshes KYC at any reporting entity refreshes the record every relying institution reads. For the broker, renewal re-KYC on individuals moves from re-collection to re-retrieval: confirm the identifier resolves to a current record, log it, done.

What the registry does not do at renewal:

  • Entity-level refresh. The individual-identity registry does not surface changes in the client's constitution (new directors, a new holding structure, a merger). The renewal checklist still needs its MCA re-verification and change-in-control questions.
  • Beneficial-ownership re-verification. The PML Rules expectation that UBOs are re-checked at refresh and on trigger events is untouched. A promoter selling down below the control threshold, or a fund taking a controlling stake mid-term, changes the UBO record, and no registry lookup will reveal it.
  • Rescreening. Renewal remains the natural checkpoint to rescreen the client and its connected persons against updated sanctions lists.
  • Risk re-categorisation. The renewal file should record that the risk rating was reviewed where the client's profile, geography or ownership has moved.

Record Retention Under DPDP Once the Registry Holds the Record

CKYC 2.0 sharpens a question the DPDP Act already posed: what personal data may a broking firm keep, and for how long, once a central registry holds the verified record?

The two frameworks pull in opposite directions. The PML Rules require a reporting entity to maintain records of client identity and transactions for five years from the end of the relationship or the transaction, and to produce them to FIU-IND on request. The DPDP Act requires a data fiduciary to erase personal data once the purpose is served, unless retention is necessary for compliance with law. The reconciliation is in the Act itself: retention mandated by another law is a recognised ground. The broker's question is not whether to retain but what to retain, in what form.

Before CKYC 2.0 the pragmatic answer was to keep everything. After it, that justification weakens for one category: copies of individuals' identity documents the registry now holds authoritatively. A defensible post-rollout retention position looks like this:

  • Retain, for the PMLA period: the identifiers relied on with dated retrieval logs and consents; the entity's constitutional documents; the beneficial-ownership analysis and declarations; screening searches and dispositions; risk categorisations with rationale; approvals; and premium transaction records. This is the evidence the broker's controls operated; no registry holds it on the broker's behalf.
  • Stop accumulating: fresh scans of OVDs for individuals whose identity was established by identifier retrieval. Where a document was captured only as a fallback, tag it with a purpose and a review date.
  • Purge on schedule: identity artefacts whose retention clock has run. DPDP enforcement will eventually ask why a 2019 director's passport scan is still on a shared drive in 2027, and "we never delete anything" is not an answer the Act accepts.

The deeper point, covered in our DPDP Act and insurance data-privacy analysis, is that the registry converts identity documents from an asset a broker hoards into a liability it should hold only by exception. The firm's durable value is its own work product (screening dispositions, UBO analysis, risk rationale, approvals); those records it must keep. The passport scans, increasingly, it should not.

SOP Edits to Make Before the Rollout

The brokers that benefit in September 2026 will be the ones that edited the SOP before the switch, not after. The edits are specific:

  1. Make the registry lookup step one. Rewrite the onboarding SOP so every natural person in a new file is checked against the registry before any document request goes out. Add the identifier field to the intake form and the client master.
  2. Capture retrieval consent at intake. Add consent language for registry retrieval to the onboarding pack and the proposal-stage checklist, so consent never becomes the new bottleneck.
  3. Build the fallback branch. Document the path for no-record, stale-record and name-mismatch cases: who flags it, on what day, and how the document route runs in parallel so an urgent placement is not stranded.
  4. Backfill identifiers across the live book. Run a one-time sweep collecting identifiers for the directors, signatories and beneficial owners of existing clients, prioritising accounts with renewals or likely urgent placements in the next two quarters.
  5. Split the renewal checklist. Separate identity refresh (registry retrieval) from relationship refresh (entity changes, UBO re-verification, rescreening, risk review), each with its own owner and evidence trail.
  6. Rewrite the retention schedule. Distinguish the broker's own control evidence (retain for the PML Rules period) from identity document copies (hold by exception, tagged, with purge dates), and minute the change under the board-approved AML policy.
  7. Brief the front line. Tell producers and insurer-facing staff exactly what the identifier covers, so nobody promises a corporate client that KYC is now "one click".
  8. Log the transition. For two quarters after rollout, track identifier retrievals versus document fallbacks and elapsed times; that data shows where the registry is working and evidences a controlled transition at the next inspection.

None of this requires waiting for the go-live. The intake forms, consent language, fallback branch and retention schedule can be drafted against the framework as reported and adjusted when the operating guidelines land. Onboarding is only the first half of the placement: a clean client file still needs the right wording behind it. Sarvada gives commercial brokers structured, searchable access to insurer policy wordings, so the time CKYC 2.0 saves on identity paperwork goes into comparing triggers, sub-limits and exclusions across insurers. Request Access to evaluate it.

About the Author

Tarun Kumar Singh

Tarun Kumar Singh

Strategic Risk & Compliance Specialist

  • AIII
  • CRICP
  • CIAFP
  • Board Advisor, Finexure Consulting
  • Developer of the Behavioural Underinsurance Risk Index (BURI)

Tarun Kumar Singh is a seasoned risk management and insurance professional based in Bengaluru. He serves as Board Advisor at Finexure Consulting, where he advises insurance, fintech, and regulated firms on governance, growth, and trust. His work spans insurance broker regulatory frameworks across India, UAE, and ASEAN, IRDAI compliance and Corporate Agency model reform, VC governance in insurtech, and MSME insurance gap analysis. He is the developer of the Behavioural Underinsurance Risk Index (BURI), a framework applying behavioural economics to underinsurance and insurance fraud risk.

Frequently Asked Questions

Does CKYC 2.0 mean a broker no longer performs KYC on corporate clients?
No. The single customer identifier, as reported ahead of the August 2026 launch, addresses individual identity verification: a person verified once can be retrieved by other institutions with consent instead of resubmitting documents. The corporate client file is different work. The broker still collects and verifies the entity's constitutional documents (incorporation certificate, PAN, memorandum and articles, board resolution, GST registration), still traces beneficial ownership through the holding structure to named natural persons under the PML Rules thresholds, still screens the client and its connected persons against UAPA and UNSC lists, and still categorises risk and documents the rationale. What changes is that when those steps reach a natural person (a signatory, a director, a beneficial owner), that person's identity can be established by identifier retrieval rather than fresh document collection.
Will the single customer ID speed up cover notes on urgent placements?
It should compress the leg that most often delays them. Insurers require proposal-stage KYC on the individuals behind a corporate client, and collecting attested documents from travelling signatories, directors and promoter-side beneficial owners routinely adds days to a placement that needs cover bound within the week. After the rollout that leg becomes identifier retrieval plus consent, which runs in minutes when the record exists and is current. Two delays survive: consent must still be obtained from each individual, so it should be captured at intake rather than chased later, and individuals with no record, a stale record or a name mismatch fall back to the document path. Brokers that pre-verify identifiers for their clients' directors and signatories before an urgent placement arises will see the largest improvement.
What happens to re-KYC at renewal after August 2026?
The individual-identity half gets materially lighter. Because the registry record updates when the individual refreshes KYC at any institution, renewal re-KYC on signatories and directors should become a re-retrieval: confirm the identifier resolves to a current record and log it. The relationship half of renewal is untouched. The broker still re-verifies the entity against MCA for changes in directors or control, re-checks beneficial ownership on trigger events such as a stake sale or restructuring, rescreens against updated sanctions lists, and reviews the risk categorisation. Renewal checklists should be rewritten to separate the two halves so the automated half does not quietly absorb the half that still requires the broker's own work.
Can a broking firm delete client KYC documents once the registry holds the record?
Not on the PMLA side, and not immediately. The PML Rules require reporting entities to maintain records of client identity and transactions for five years from the end of the relationship or the transaction, and the DPDP Act expressly permits retention necessary for compliance with law, so the five-year obligation stands. What changes is what the file should contain. The broker's own control evidence (identifier retrieval logs, consents, sanctions and PEP screening dispositions, beneficial-ownership analysis, risk rationale, approvals) must be retained because no registry holds it on the broker's behalf. Copies of individuals' identity documents, where identity was established by registry retrieval, no longer need to accumulate, and legacy document scans should carry purge dates once their retention clock runs. A retention schedule that distinguishes the two categories is the defensible DPDP position.
What should a broker do before the August 2026 rollout rather than after?
Five things carry most of the value. First, rewrite the onboarding SOP so a registry lookup on every natural person is step one, with consent captured at intake. Second, build the fallback branch for no-record and mismatch cases so urgent placements are never stranded on the new path. Third, run a backfill sweep collecting identifiers for directors, signatories and beneficial owners across the live book, prioritising accounts renewing in the next two quarters. Fourth, split the renewal checklist into identity refresh and relationship refresh with separate owners. Fifth, update the record-retention schedule and minute it through the board-approved AML policy. All of this can be drafted against the framework as reported in July 2026 and adjusted when the operating guidelines are issued.

Related Glossary Terms

Related Insurance Types

Related Industries

Related Articles

Sarvada Intelligence

Ready to see Sarvada in action?

Explore the platform workflow or start a product conversation with our underwriting automation team.

Explore the platform