7.2 Client Onboarding & KYC

Key Takeaways

  • Onboarding an RIA client requires identity proof, address proof, PAN, photograph, a signed investment-advisory agreement, and a risk-disclosure document.
  • CKYC (Central KYC Records Registry, operated by CERSAI) enables one-time KYC — a 14-digit KYC Identifier lets clients reuse KYC across RBI, SEBI, IRDAI, and PFRDA entities.
  • FATCA/CRS self-certification (tax residency, country of birth, TIN) is mandatory for RIA clients; SEBI centralised its maintenance at KRAs effective July 1, 2024.
  • KRAs (KYC Registration Agencies — CAMS, Karvy/NSDL, NDML, etc.) maintain KYC records; in-person verification (IPV) and video-KYC are permitted verification methods.
Last updated: August 2026

7.2 Client Onboarding & KYC

Quick Answer: Onboarding an RIA client in India means collecting identity proof, address proof, PAN, photograph, obtaining a FATCA/CRS self-certification, signing an investment-advisory agreement and a risk-disclosure document, and verifying the client in person or by video. CKYC (run by CERSAI) makes this a one-time exercise through a 14-digit KYC Identifier, and KRAs (CAMS, Karvy, NDML) maintain the records for SEBI-registered intermediaries including RIAs.

The Onboarding Workflow

A typical RIA client onboarding has six sequential steps. The PAIA owns steps 1–4 and 6; the registered adviser owns step 5 (suitability sign-off, covered in 7.4).

  1. Client initiation — the PAIA explains the RIA's services, fee structure, and the boundary between advice and sales.
  2. KYC data and document collection — identity, address, PAN, photograph, and FATCA/CRS self-certification.
  3. Verification — in-person verification (IPV) or video-KYC, conducted by the PAIA or a KRA.
  4. Agreement and risk disclosure — the investment-advisory agreement and risk-disclosure document are signed.
  5. Client profiling and risk assessment — covered in 7.3.
  6. Record upload — KYC and FATCA/CRS data are uploaded to the KRA and (where applicable) the CKYC record is cited.

KYC Requirements for an Individual Client

The standard KYC document set for an individual RIA client is:

  • Identity proof — PAN is mandatory; Aadhaar, passport, driving licence, or voter ID also accepted.
  • Address proof — Aadhaar, passport, utility bill (not older than 3 months), bank statement, or rental agreement.
  • PAN — Permanent Account Number is compulsory for all financial transactions above the SEBI threshold and for FATCA/CRS reporting.
  • Photograph — recent passport-size photograph.
  • FATCA/CRS self-certification — tax residency, country/place of birth, TIN for each non-India residency.

PAN is the unique identifier that ties KYC, FATCA/CRS, and the CKYC record together. A client without a PAN cannot be onboarded by an RIA.

CKYC — One-Time KYC, Reusable Everywhere

The Central KYC Records Registry (CKYCRR) is operated by CERSAI (Central Registry of Securitisation Asset Reconstruction and Security Interest), a Government of India company, since 2016. It serves reporting entities across all four financial regulators — RBI, SEBI, IRDAI, and PFRDA.

Key features:

  • One-time KYC — once a client's KYC is uploaded, a 14-digit KYC Identifier is issued.
  • Inter-usability — the same KYC can be downloaded by any regulated entity the client later deals with, removing repeat submissions.
  • OTP-based consent — since 2025 the CKYCRR requires the client's OTP consent before an institution can download an individual KYC record; the record is released only after the OTP sent to the registered mobile is validated.
  • Scale — the CKYCRR is the de-facto national KYC warehouse for the whole regulated financial sector, which is why an RIA can usually pull an existing record rather than start from scratch.

When onboarding an RIA client, the PAIA can either perform fresh CKYC upload or pull an existing record using the client's 14-digit identifier.

FATCA/CRS — Tax Residency Self-Certification

FATCA (Foreign Account Tax Compliance Act, US) and CRS (Common Reporting Standard, OECD) require financial institutions to report accounts of tax residents of other jurisdictions. RIAs are SEBI-registered intermediaries and therefore Reporting Financial Institutions.

Per SEBI Circular SEBI/HO/MIRSD/SECFATF/P/CIR/2024/12 (February 20, 2024), effective July 1, 2024:

  • RIAs must collect FATCA/CRS self-certification from every client and upload the structured data to a KRA.
  • For clients whose tax residency is outside India, country of tax residency and TIN must be uploaded.
  • For clients whose tax residency is India only, the KRA marks them as India tax residency.
  • Existing certifications (pre-July 2024) had to be uploaded within 90 days.
  • The latest certification provided by any SRI takes precedence at the KRA.

The self-certification typically captures: place and country of birth, tax residency other than India (Y/N), up to four countries of tax residency, TIN for each, US person / US green-card flags, and the date of declaration.

KRAs — The Record Keepers

KYC Registration Agencies (KRAs) — CAMS, Karvy (now NSDL/Karvy), NDML (NSDL), and others — are SEBI-registered entities that maintain KYC records on behalf of SEBI intermediaries. Their role:

  • Store KYC records and FATCA/CRS data.
  • Distribute records (solicited or unsolicited downloads) to other SRIs with client consent.
  • Validate documents and flag mismatches.
  • Maintain the latest certification as the authoritative version.

The PAIA does not maintain KYC records personally; the PAIA collects and uploads them to the KRA, which becomes the system of record.

IPV and Video-KYC

In-Person Verification (IPV) confirms that the client is a real person who matches the documents. Traditionally done face-to-face, IPV is now permitted through:

  • Video-KYC — a live video call where the PAIA (or KRA agent) sees the client's face, their PAN/Aadhaar, and confirms liveness.
  • OTP-based authentication — for CKYC downloads, OTP to the client's registered mobile confirms consent.

Video-KYC has made remote onboarding practical, which matters because many RIA clients are geographically dispersed.

Why KYC Matters — AML/CFT and Investor Protection

KYC is not paperwork; it is the first line of defence against three risks:

  1. Money laundering and terrorist financing (AML/CFT) — KYC prevents the RIA from being used as a conduit for illicit funds. India's AML framework (PMLA, 2002) is enforced through SEBI for capital-market intermediaries.
  2. Investor protection — verified identity ensures the right person receives advice, statements, and redress.
  3. Tax transparency — FATCA/CRS enables cross-jurisdictional tax reporting and prevents evasion.

A PAIA who skips or shortcuts KYC exposes the RIA to SEBI enforcement, KRA rejection of the record, and — in serious cases — PMLA consequences.

Onboarding Documents Checklist

DocumentSourceMandatory?
PAN cardClientYes
Identity proof (Aadhaar/passport)ClientYes
Address proof (utility bill/bank statement)ClientYes
Passport-size photographClientYes
FATCA/CRS self-certificationClient, uploaded to KRAYes
Investment-advisory agreementRIA + ClientYes
Risk-disclosure documentRIA + ClientYes
CKYC 14-digit identifier (if existing)CKYCRRIf available
IPV / video-KYC recordPAIA or KRAYes
Loading diagram...
RIA Client Onboarding Workflow
Onboarding Documents — Mandatory vs Optional (100% = mandatory)
Test Your Knowledge

Which of the following is NOT part of the standard KYC document set for an individual RIA client in India?

A
B
C
D
Test Your Knowledge

What is the role of CKYC (the Central KYC Records Registry operated by CERSAI)?

A
B
C
D