Work / Chitragupt / Wiki / Concepts
kyc
Conceptcanonicalverified 2026-09-01
CONCEPT.KYCKYC — identity verification gated on money flow
Summary
KYC (Know-Your-Customer) verification is required for any Chitragupt user who hires a CA via the marketplace, because money flows from user → Chitragupt escrow → CA. Verification is a one-time PAN (NSDL) + Aadhaar (UIDAI OTP) check.
Why it matters
- Regulatory: Money flowing to a third party via a platform triggers Prevention of Money Laundering Act 2002 KYC duties. Razorpay and the RBI both require verified customer identity for any escrow/payout product.
- Trust: CAs in the marketplace want to know they're working with a real identifiable person before they file an ITR on that person's behalf.
- Anti-fraud: PAN ↔ Aadhaar matching catches stolen-PAN signups.
Implications
- KYC is not required for Free / Self / AI Self / Pro Family unlocks. Those money flows are user → Chitragupt only — covered by Razorpay's own KYC on the merchant side.
- KYC IS required at the moment a user clicks "Hire" on a CA marketplace listing. If unverified, the hire flow detours through
/kyc/start→/kyc/verify→/kyc/otp→ success, then resumes hire. - KYC is a one-time event per PAN. Once verified, the user can hire any number of CAs without re-verifying (unless name/PAN/Aadhaar changes — then re-verify).
- The Aadhaar number is hashed only, never stored in cleartext (UIDAI rule). Correction 2026-09-01: this page previously claimed "PAN is stored encrypted" — it isn't. PAN is a plain, format-validated string (
PanSchema, a regex check only) on bothidentities/self.panand the legacyusers/{uid}.pan; no encryption utility exists anywhere in this codebase today. See 2026-09-01-broker-token-encryption for the finding and the fix direction (Cloud KMS envelope encryption, first built for broker access tokens). - Failure modes:
pan_not_found(NSDL),pan_dob_mismatch(NSDL),aadhaar_otp_failed(UIDAI),name_mismatch(PAN ↔ Aadhaar). Each has an actionable retry path.
Related
- hire-a-ca — the flow that triggers KYC
- upload-only — KYC is the only place where the user enters identity numbers that are then validated externally (vs document-driven extraction everywhere else)
- data-residency-dpdp — DPDP Act 2023 §6 consent is captured inline on the KYC verify screen
- kyc-start, kyc-verify, kyc-otp, kyc-status — the four surfaces
- 2026-09-01-broker-token-encryption — corrects this page's false "PAN is encrypted" claim; PAN encryption is a real, separate gap this decision does not fix
Sources
- User decision 2026-06-27 to add KYC scope.
- Prevention of Money Laundering Act 2002 (KYC for financial intermediaries).
- UIDAI Aadhaar Authentication API guidelines (no Aadhaar number storage).
Every project of mine is written down like this.
Read the résumé