Orkivanta
← All posts
7 min read

Automated KYC and identity verification in India

Automated KYC can take the mechanical, repeatable part of identity verification. Document capture and quality checks, face match, liveness, field matching against the ID. It turns a multi-minute manual onboarding into a fast, logged flow, while a share of cases still routes to human review.

What it cannot do is decide, on its own, that your onboarding is compliant. Whether a KYC flow satisfies the RBI's directions and DPDP is a question for your compliance and legal team. Orkivanta has built verification rails inside a regulated lending environment, not a packaged KYC product.

What automates cleanly

The rule-bound steps are where automation is strong. Document verification checks that an ID is genuine, readable, and not tampered with. Face match compares a selfie to the document. Liveness confirms a real person rather than a photo. Field matching lines up name and date of birth.

Underneath all of it, a complete audit log records every check and its result. That is the part that makes the rest defensible in a regulated setting.

The 70/30 reality

HyperVerge publicly reports that for ZestMoney, automated C-KYC took onboarding from around 10 minutes to under 10 seconds, with roughly 70% automated and about 30% going to manual review. Those are HyperVerge's reported figures for its client. Third-party public evidence, not an Orkivanta result.

The honest thing that 70/30 split tells you: the credible way to talk about KYC automation is not "100% automated." A residual share always needs a human. Plan for the manual-review queue as part of the design.

Where Orkivanta actually sits

We do not sell a packaged KYC product. What we have run is a bespoke build in a lending environment. Document verification, e-signature, credit-bureau integration, co-borrower flows, and full audit logging. The transferable discipline is auditability. In a setting where a wrong answer is a legal event, the log that lets you reconstruct any decision is the point of the build.

The compliance questions to keep open

These are decisions for your compliance and legal function. Does your flow meet the RBI's KYC directions for your product and customer type? What consent does DPDP require, and how long may you keep the data? Who reviews the roughly 30% that do not auto-clear, and against what criteria?

The system's job is to enforce whatever your counsel decides and to log it completely. It is not to author the policy or vouch that your use of it is lawful.

When automated KYC is wrong for you

When you are pre-product-market-fit with a handful of onboardings a day. Manual review is cheaper than a build.

When you are looking for a vendor to own compliance accountability. No vendor can take that off your institution. The accountability stays with you.

When you expect fully automated KYC. The residual human-review share is part of a defensible regulated flow, not a defect to engineer away.

Before you talk to anyone

Score your workflow first.

One number, already counted in your systems, that should move — and a switch to stop the thing if it misbehaves. Our readiness test checks exactly that, in a few minutes, with the result shown immediately.

Take the readiness test