Skip to content
Ritesh FirodiyaGet in touch

Work / Chitragupt / Wiki / Concepts

kyc

Conceptcanonicalverified 2026-09-01

CONCEPT.KYC

KYC — identity verification gated on money flow

Summary

KYC (Know-Your-Customer) verification is required for any Chitragupt user who hires a CA via the marketplace, because money flows from user → Chitragupt escrow → CA. Verification is a one-time PAN (NSDL) + Aadhaar (UIDAI OTP) check.

Why it matters

  • Regulatory: Money flowing to a third party via a platform triggers Prevention of Money Laundering Act 2002 KYC duties. Razorpay and the RBI both require verified customer identity for any escrow/payout product.
  • Trust: CAs in the marketplace want to know they're working with a real identifiable person before they file an ITR on that person's behalf.
  • Anti-fraud: PAN ↔ Aadhaar matching catches stolen-PAN signups.

Implications

  • KYC is not required for Free / Self / AI Self / Pro Family unlocks. Those money flows are user → Chitragupt only — covered by Razorpay's own KYC on the merchant side.
  • KYC IS required at the moment a user clicks "Hire" on a CA marketplace listing. If unverified, the hire flow detours through /kyc/start → /kyc/verify → /kyc/otp → success, then resumes hire.
  • KYC is a one-time event per PAN. Once verified, the user can hire any number of CAs without re-verifying (unless name/PAN/Aadhaar changes — then re-verify).
  • The Aadhaar number is hashed only, never stored in cleartext (UIDAI rule). Correction 2026-09-01: this page previously claimed "PAN is stored encrypted" — it isn't. PAN is a plain, format-validated string (PanSchema, a regex check only) on both identities/self.pan and the legacy users/{uid}.pan; no encryption utility exists anywhere in this codebase today. See 2026-09-01-broker-token-encryption for the finding and the fix direction (Cloud KMS envelope encryption, first built for broker access tokens).
  • Failure modes: pan_not_found (NSDL), pan_dob_mismatch (NSDL), aadhaar_otp_failed (UIDAI), name_mismatch (PAN ↔ Aadhaar). Each has an actionable retry path.

Related

Sources

  • User decision 2026-06-27 to add KYC scope.
  • Prevention of Money Laundering Act 2002 (KYC for financial intermediaries).
  • UIDAI Aadhaar Authentication API guidelines (no Aadhaar number storage).

Every project of mine is written down like this.

Read the résumé