CKYC 2.0 is a structural reset, not a UI update. Get the timeline, impact by sector, and a 6-step playbook to migrate without stalling onboarding.
CKYC 2.0 Migration: What Changes & How to Prepare
A true blue millennial trying to engineer her full time-career around the world of content. How cliché is that?
Table of Contents

| TL;DR |
| CKYC 2.0 is live from August 2026, jointly driven by RBI, SEBI, and IRDAI under a “One Nation, One KYC” push. Banks and insurers onboard first; mutual funds and brokers follow by year-end. |
| The architecture is changing fundamentally: batch PDF/XML uploads are being replaced by real-time, API-first data exchange with transaction-level, OTP-based consent for every record pull. |
| Scale is the reason this can’t wait: 103 crore records already sit in the registry, and CKYCRR 2.0 is built for 40 lakh+ uploads a day, roughly 8x the old system’s design load. |
| The compliance clock is tightening on two fronts: PMLA now mandates 7-day record synchronisation, and DPDP Act penalties (up to ₹250 crore) activate from May 2027. |
| Data quality remediation alone takes 4–12 weeks per institution, so the realistic starting point is now, not when a regulator sends a notice. |
| Fintechs and lenders are exposed indirectly through their banking, NBFC, or TSP partners; if that partner isn’t 2.0-ready, onboarding funnels stall regardless of how good your own product is. |
| Migration fails when it’s owned by one team. Tech, compliance, and operations all need to move together, or gaps surface late and are expensive. |
Summary
CKYC 2.0, the upgraded Central KYC Registry, started rolling out from August 2026, jointly driven by the RBI, SEBI, and IRDAI under a “One Nation, One KYC” push. Banks and insurers are onboarding first; mutual funds and brokers follow by year-end.

The registry is moving from batch PDF/XML uploads to a real-time, API-first, consent-based model, and every regulated entity that touches customer identity data needs a migration plan. This playbook breaks down what’s changing, who it hits hardest, and how to get ahead of it, whether you’re a bank compliance lead or a fintech founder building on top of CKYC.
The Numbers That Set the Stage

Before we get into the how, here’s why this matters at scale:
- 103 crore CKYC registrations were logged in 2025 alone. This isn’t a niche database; it’s foundational infrastructure for Indian finance.
- CERSAI has awarded a ₹161 crore contract to rebuild the registry’s backend for CKYC 2.0.
- The new system is engineered for at least 40 lakh record uploads a day, roughly 8x the throughput assumptions the old registry was built around.
- PMLA rules now mandate 7-day record synchronisation, down from the looser cadence institutions were used to.
- The DPDP Act’s enforcement window opens in May 2027, with penalties of up to ₹250 crore for serious data-handling failures.
If your business touches customer onboarding in India, whether that’s lending, insurance, broking, payments, or wealth, these numbers aren’t background noise. They’re your new operating constraints.
What Is CKYC?

Central KYC (CKYC) is India’s single, centralised repository of customer identity records, managed by CERSAI. Complete your KYC once with any regulated entity, and you get a 14-digit CKYC number that any other bank, NBFC, insurer, or fund house can reference, instead of asking you to redo the entire process. It’s the infrastructure behind “do KYC once, use it everywhere.”
We have extensively covered its features, benefits and how it works in this guide. Feel free to check it out.
CKYC 1.0 vs CKYC 2.0: What Actually Changes
| CKYC 1.0 | CKYC 2.0 | |
|---|---|---|
| Data exchange | Batch PDF/XML uploads | Real-time, API-first architecture |
| Consent model | Permission-on-file; records pulled with minimal friction | Transaction-level, OTP-based consent for every record retrieval |
| Search | ID-based only (PAN, Aadhaar last 4, Voter ID) | ID-based, plus photo, mobile-number, and Verifiable Credential search |
| Data quality | Manual dedup, inconsistent formatting | AI-aligned deduplication, field-level validation, Aadhaar masking |
| Update cadence | Loosely enforced | 7-day synchronisation mandated under PMLA |
| Regulatory owner | RBI-led | Joint mandate: RBI, SEBI, IRDAI |
| Throughput | Legacy 2016-era load assumptions | Built for 40 lakh+ uploads/day |
The short version: CKYC 2.0 isn’t a UI refresh. It’s a structural shift from “submit a file, wait for a response” to “call an API, get an answer in seconds,” with far less tolerance for messy legacy data.
Why Now? Why the Urgency?
Three forces are converging at once:
- Regulatory alignment. RBI, SEBI, and IRDAI have never before run a joint KYC mandate at this scale. That coordination itself signals how seriously this is being enforced.
- Scale pressure. With over a billion records and growing, the old batch-upload architecture was becoming a genuine bottleneck, both for the registry and for every institution feeding it.
- Compliance exposure. Between the tightened PMLA sync window and the DPDP Act’s 2027 penalty regime, the cost of dragging your feet on CKYC 2.0 compliance is no longer abstract. It’s a number on a balance sheet.
The Timeline
- August 2026: Banks and insurers begin onboarding to CKYCRR 2.0.
- Through late 2026: Mutual funds, brokers, and other capital market entities phase in.
- Ongoing: Data quality remediation typically takes 4 to 12 weeks per institution, according to industry compliance assessments. That means the window to start is now, not when your regulator sends a notice.
- May 2027: DPDP Act enforcement provisions activate, raising the stakes on any KYC data-handling gaps left unresolved.
Who’s Impacted, and How

Banks and NBFCs
Compliance and risk teams face the heaviest lift: legacy record remediation, new audit-trail obligations (CKYC access is now more visible to the customer, inviting more scrutiny), and mandatory correction cycles when CKYCRR flags a discrepancy. Technology teams need to rebuild data pipelines around real-time APIs instead of batch jobs, with stronger encryption and access logging.
Insurance Companies
IRDAI’s direct involvement means insurers face the same consent and data-quality bar as banks, but often with less mature integration infrastructure. Many still lean on manual or semi-automated onboarding, which won’t hold up under 2.0’s field-level validation.
Fintechs, Lenders, and Online Businesses
If you’re a founder running a lending, payments, or wealth product, you likely don’t operate the registry directly. You rely on a partner bank, NBFC, or a Technical Service Provider (TSP) for CKYC access. Your exposure here is indirect but real: if your integration partner isn’t 2.0-ready, your onboarding funnel stalls the moment their sync breaks. This is the moment to ask your KYC or onboarding vendor directly: “are you live on CKYC 2.0, or still queued behind it?”
Operations and Onboarding Teams (across the board)
The shift from batch to real-time changes daily workflows more than any other function. Field-level validation means a single formatting slip can trigger a rejection that used to slide through in a batch file. Dedup logic needs a rebuild to match CKYCRR’s stricter, AI-aligned matching.
Your Migration Playbook: 6 Steps

1. Audit where you stand today
Before changing anything, get a clear picture of your current CKYC operation: how records are generated, your current rejection rate and its main causes, which data sources feed your CKYC file, and how much of the process is still manual.
2. Fix your legacy data before you touch new APIs
Most CKYC 2.0 rejections will trace back to old, uncorrected data problems: missing mandatory fields, inconsistent names or addresses, poor-quality scans, and demographic details that don’t match across records. This is usually the slowest step (4–12 weeks), so start it in parallel with everything else, not after.
3. Move your data pipeline to real-time, structured formats
Batch PDFs are being retired. Build (or upgrade) the templates and workflows that produce and consume real-time XML/JSON records, and add automated quality checks before anything gets submitted, not after it bounces back.
4. Rebuild your deduplication logic
CKYCRR 2.0 matches records using AI-driven logic across face, Aadhaar, PAN, and demographic fields. Align your internal dedup checks to that same standard now, or expect a spike in failed submissions once you go live.
5. Redesign how you handle errors, in real time
Real-time validation means real-time rejections; there’s no batch job to quietly retry overnight. Put updated SOPs, faster dashboards, and a clear escalation path in place so a flagged record gets resolved in hours, not days.
6. Test in a sandbox, early and often
Don’t wait for “final guidelines” before you start testing. Run sandbox integrations and error simulations well ahead of your go-live date, and stress-test for the volumes you’ll actually see. The institutions that get caught flat-footed are almost always the ones that treated this as a routine update instead of a structural rebuild.
CKYC 2.0 Readiness Checklist

Use this as a working checklist across tech, compliance, and operations:
- Map current CKYC workflows end-to-end, including every manual touchpoint
- Quantify your current rejection rate and root-cause the top failure reasons
- Identify specific legacy data gaps that will fail 2.0’s field-level validation
- Kick off data clean-up (missing fields, formatting, scan quality) immediately
- Build or upgrade real-time XML/JSON templates matching CKYCRR’s structure
- Add automated pre-submission quality checks to catch errors before they’re sent
- Align internal deduplication logic with CKYCRR’s AI-driven matching approach
- Set up a sandbox/staging environment for API integration testing
- Run error simulations and volume/stress tests ahead of go-live
- Update SOPs and dashboards for real-time error resolution and escalation
- Confirm your bank, NBFC, or TSP partner’s CKYC 2.0 readiness, in writing
- Assign joint ownership across tech, compliance, and operations, not just one team
Common pitfall to avoid: Treating this as a single team’s problem. CKYC 2.0 touches tech, compliance, and operations at the same time, and migration plans owned by just one function consistently run into delays the other two didn’t see coming.
Where Decentro Fits In
Building or rebuilding this integration in-house takes real engineering time that most founders and lean compliance teams don’t have to spare. That’s the gap a ready-made API layer is meant to close.

Decentro is among the first Technical Service Providers (TSPs) with a production-ready CKYC 2.0 stack for its customers, covering Search, Download, Create, and Update on the new APIs, backed by the OTP-based consent flow the new registry requires. You don’t have to migrate everything overnight, either. Decentro supports high-volume bulk onboarding on 1.x and real-time 2.0 journeys side by side, so you can move at the pace your business needs without stalling customer onboarding in the meantime.
If your onboarding funnel depends on CKYC and you’re not sure where your current vendor stands on 2.0 readiness, it’s worth finding out before the deadline finds out for you.
Conclusion
CKYC 2.0 is less a compliance checkbox and more an infrastructure reset. It touches how banks validate identity, how NBFCs manage risk, and how every fintech founder’s onboarding funnel actually performs. The institutions that treat this as a genuine migration project, starting with data clean-up and API readiness today, will onboard faster and reject less. The ones that wait for a final push from their regulator will spend 2026 firefighting instead. Start the audit now. The rollout clock is already running.
Frequently Asked Questions
1. What is the deadline for CKYC 2.0 compliance?
Banks and insurers began onboarding to CKYCRR 2.0 from August 2026, with mutual funds and brokers expected to follow by the end of the year. Exact institutional timelines vary, so check directly with your CKYC integration partner or regulator.
2. Is CKYC 2.0 mandatory for NBFCs and fintechs?
Yes. Any entity regulated by RBI, SEBI, or IRDAI that relies on the Central KYC Registry needs to migrate. Fintechs that don’t operate the registry directly are still affected through their banking or TSP partners.
3. What’s the biggest technical change in CKYC 2.0?
The shift from batch PDF/XML uploads to real-time, API-first data exchange, combined with mandatory OTP-based consent for every record retrieval.
4. How long does CKYC 2.0 migration typically take?
Data quality remediation alone can take 4 to 12 weeks depending on the state of your legacy records, before you even begin API integration and testing. That’s why early action matters.
5. Can I keep using CKYC 1.0 during the transition?
In most cases, yes. Providers like Decentro support both 1.x and 2.0 simultaneously, so you can keep bulk onboarding running on 1.x while piloting 2.0 for real-time use cases.