KYC has now almost become the mandatory process for any sort of formal financial system in India. Be it opening a bank account, applying for a debit or credit card, registering for any government schemes or establishing a business unit, KYC is required for everything.     

In an exclusive talk with The Daily Jagran Advocate, Mayank Arora, Partner, The Chambers of Bharat Chugh, explained the key reasons behind the development and whether KYC guidelines serve the desired purpose.  

According to Arora, one has to trace it back to understand where this mandate actually comes from. India's KYC framework emerges directly from the Financial Action Task Force, which is the global standard on anti-money laundering and counter-terrorism financing. 

India Joins FATF In 2010

India became a FATF member in 2010, and with that came binding expectations wherein every regulated entity was required to know who the customer is that it is dealing with before they are allowed to transfer or deal with money. 

The Prevention of Money Laundering Act, 2002, and RBI's master directions on KYC are a legislative translation of our commitments under FATF. Similarly, SEBI, IRDAI and other agencies have their own parallel frameworks for KYC, but their underlying core is the same, i.e. financial anonymity is treated as a threat, and not a right of privacy for any customer.

In the last decade, entities which are now classified as reporting entities under PMLA have expanded from only banks and financial institutions to brokers, mutual fund houses, insurance companies, etc., including online payment aggregators and fintech wallets.

Here is the excerpt from the conversation….

Ques: If a person has already completed KYC once, why do they still have to repeat it across different platforms or institutions? What is driving this duplication?

The answer to this question lies in the architecture and non-centralisation of different entities which are obligated to conduct KYC. Each regulator has its own KYC rules, and they are all liable for compliance and verifications at their individual level.  The law does not permit them to say that since one entity has already verified its customer, no further KYC is required. Under the current framework of laws, each entity must conduct its own due diligence, maintain its own records, and be independently accountable if something goes wrong. 

There is also another dimension to this: KYC data is enormously valuable. Knowing your customer is not just a compliance exercise, but it is also a means to collect data demographics and profiling for these entities to cross-sell other offerings by the entities to their customers.

Ques: India already has systems like Aadhaar, CKYC and DigiLocker. In theory, these should allow one-time verification. So why is a truly unified KYC system still not a reality in practice?

Infrastructure and interoperability are the key concerns around this issue. Aadhaar-based e-KYC allows an institution to verify the identity of a customer against the UIDAI database. But as per the Supreme Court's judgment in Justice K.S. Puttaswamy v. Union of India (2018), the hon’ble court has restricted mandatory Aadhaar-based authentication by private entities. 

CKYC, i.e., the Central KYC Records Registry managed by CERSAI, was conceived to eliminate duplication of KYC exercise in the securities and financial services space. The idea was that once you complete KYC with one SEBI-registered intermediary, a KYC ID is generated, and every other entity can simply pull the verified record of the customer with the same ID. 

However, in practice, the data quality and completeness of data are inconsistent across all the different entities, and different regulators have different levels of detail that are required to be furnished as part of the KYC exercise. 

Digilocker, on the other hand, allows citizens to hold verified digital documents that can be shared with institutions on demand. But it is merely a document-sharing tool which enables one to not carry the physical copies of those documents. It was never meant to be a KYC tool that can be seamlessly integrated across entities. 

Ques: From a regulatory standpoint, how important is KYC in preventing fraud, money laundering and financial crime? Has it delivered on that objective?

KYC is vital to prevent fraud, money laundering and other crimes; however, even the exercise of KYC does not make the situation foolproof.  KYC effectively creates a paper trail of persons involved in any transaction, and if a crime occurs, the investigative agencies can trace the funds trail to the origin. 

But the unfortunate part is that in a vast country such as ours, KYC records and details are easily available for sale. Mule accounts, where a verified individual's account is used by a criminal network is one of the most persistent challenges in digital financial crime today, and most investigative agencies are struggling. 

The common financial frauds that are happening today usually end up leading to poor segments of society who have nothing to do with the crime and whose KYC records were either taken without their knowledge or bought from them for a song.

Over and above this, practices such as shell companies and layered ownership are known to operate entirely within the KYC framework but are not simple to trace. So while KYC is a vital foundation of preventing crimes, treating it as sufficient is not enough. 

Ques: Are there any data points or trends that show how KYC has improved financial safety or reduced fraud in India?

The Financial Intelligence Unit publishes reports that track suspicious transaction reports ( STRs) and cash transaction reports filed by reporting entities. 

The trend shows a consistent increase in the volume of STRs, which can either imply that KYC is being effective in monitoring suspicious transactions or it may even imply that KYC is penetrating further and showing what was already there. To me, as a lawyer, it appears that the crime and criminals are way ahead of the game. UPI fraud and OTP fraud are the new-age crimes and are becoming extremely common, and are on the rise. 

Especially the vulnerable groups of citizens, like the elderly or those with a lack of education and resources, are the biggest victims of these crimes.  At the same time, many users feel there is 'KYC fatigue'. 

Ques: Is India overdoing KYC, or is this level of verification necessary in a fast-growing digital economy? Is India overdoing it? 

I think yes. However, the problem now is that data is the new gold and everyone wants their share of it. Data can be analysed, sold and can become training material for machine learning to deliver insights to organizations and hence there is high insistence on KYC even when the transaction risk is not high, merely for want of data the solution can be to create a mechanism and infrastructure that can operate across entities and that can preserve privacy and data leaks while also guarding the country against financial frauds and money laundering.

Ques: What are the key risks around data privacy and security when so many institutions are collecting and storing KYC information repeatedly?

As I have stated above, every entity that collects KYC information for reasons beyond just compliance is motivated by other reasons for commercial exploitation of such data. This commercial exploitation may lead to data leaks and consequently spam calls & mails, vulnerability to online fraud for such uses, amongst others, especially for the vulnerable groups.

The Digital Personal Data Protection Act, 2023, is a step in the right direction since it creates obligations around consent, purpose limitation, and data minimisation. There is also the question of what happens to KYC data after the relationship ends. 

Ques: What changes or reforms could make KYC simpler for users without compromising security, for example, a true one-time or portable KYC system?

A regulatory and operational integration of KYC data is the solution. There should be a defined baseline standard for capturing the KYC under a centralised agency, which is portable across all entities. For the entities that require more information than the baseline, a risk-proportionate KYC must be implemented under the strict control and monitoring of the centralised agency. 

Finally, an expansion of CERSAI's CKYC registry with a standardised data quality protocol can be a fast and effective solution. The underlying principle should be that the state has a legitimate interest in knowing who is participating in the financial system, and at the same time, the citizens also have an equally legitimate right to privacy and not disclose their identity to anyone they do not wish to, at least not more than is required for availing any service.