CKYCRR 2.0: What Banks and NBFCs Need to Prepare For

CKYCRR 2.0 is the upgrade to the CKYCRR (Central KYC Records Registry) environment being introduced by CERSAI.
For Regulated Entities (REs), this means they need to review how they register customers, retrieve existing CKYC records, update customer information, secure access and integrate CKYC transactions with their internal systems.
As of September 23, 2026, the official CKYC website states that the CKYCRR 2.0 pilot-testing period has been extended to October 5, 2026. REs should treat this phase as a readiness and testing period and monitor CERSAI communications for production go-live instructions.
This blog explains the main regulatory, operational and technical areas banks and NBFCs should review while preparing for CKYCRR 2.0.
What is CKYCRR 2.0?
CKYCRR 2.0 is the next version of the Central KYC Records Registry platform.
CKYCR serves as a centralised database for KYC records within the financial sector. It ensures consistency in KYC records and minimises the need for customers to repeatedly provide and validate the same documents.
Under the RBI KYC framework, regulated entities can access an existing customer KYC record from CKYCR using the KYC Identifier. Customers generally don't need to resubmit KYC information unless exceptions apply, such as changes in information, incomplete or outdated records, expired documents, or the need for additional due diligence.
For a detailed explanation of the existing registry, read our article: What is CKYC? Why is it important?.
For the underlying regulatory requirements, refer to the RBI Master Direction - Know Your Customer (KYC) Direction, 2016.
What is the latest CKYCRR 2.0 migration status?
At the time of writing this blog, CERSAI announced a CKYCRR 2.0 pilot-testing window in September 2026, now extended to October 5, 2026. During this period, Reporting Entities must complete onboarding and testing activities relevant to their operations. Pilot transactions are not equivalent to completed production transactions, and institutions should follow the latest CERSAI instructions for live processing and production migration.
Because CKYCRR 2.0 timelines can change, banks and NBFCs should verify the latest status directly on the official CKYC website and the CKYCRR 2.0 portal before finalising implementation or migration schedules.
CKYCRR 2.0 readiness: 6 areas banks and NBFCs should review
The following six areas provide a practical framework for evaluating migration readiness.
Area 1. Complete CKYCRR 2.0 onboarding and access readiness
The first step is to ensure the institution can access and test the CKYCRR 2.0 environment per the latest CERSAI instructions, confirming authorised users, credentials, Digital Signature Certificate configuration, and other onboarding details.
Confirm that authorised users have the required access.
Validate DSC and credential configuration.
Complete the prescribed testing and onboarding activities.
Ensure compliance, technology and operations teams know who owns each migration task.
Area 2. Continue meeting existing CKYC upload and update timelines
RBI requires REs to capture and upload applicable customer KYC records to CKYCR within 10 days of commencement of an account-based relationship.
When a reporting entity (RE) receives additional or updated information from a customer under the conditions specified by the KYC Direction, it must submit this information to the CKYCR within 7 days, or within another timeframe specified by the Central Government. CKYCR will then update the customer's record and notify the reporting entities that have interacted with that customer.
These requirements make timeliness, follow-up and exception management important regardless of whether transactions are performed manually or through a CKYC gateway.
See the RBI November 2024 KYC amendment for the updated CKYCR provisions.
Area 3. Review how CKYCRR 2.0 connects with internal systems
A bank or NBFC may use various systems like Core Banking, Loan Origination, Loan Management, and cards platforms. CKYC information might be accessed from multiple systems based on onboarding and servicing workflows.
For CKYCRR 2.0 readiness, REs should evaluate system interactions with the registry, considering API compatibility, file-transfer processes, authentication, connectivity, transaction-response handling, and necessary integration changes.
The goal is to ensure the complete transaction flow from the source application to CKYCR and back to the system or user requiring the result.
Area 4. Review customer consent, access and data-security controls
CKYC records include personal and financial identity information. Therefore, institutions should examine how access to CKYCRR 2.0 is managed, how credentials and digital certificates are safeguarded, how downloaded records are stored, and how user activity is tracked.
When retrieving CKYC records, teams should verify the consent and authentication process relevant to their workflow. If APIs or other automated connections are used, institutions should directly validate the current technical requirements against the latest CERSAI specification instead of relying on outdated implementation assumptions.
Area 5. Test the complete CKYC transaction lifecycle
REs should test the relevant search, download, upload and update journeys specified for their implementation.
Search: Can the institution locate the appropriate CKYC record using supported search parameters?
Download: Can the record be retrieved after the applicable consent and authentication steps?
Upload: Can a new record be prepared, validated, submitted and tracked through the response?
Update: Can changes to a customer record be submitted and handled correctly?
Exceptions: Can teams identify and address failed, pending, or unresolved transactions?
Testing negative and exception scenarios is as important as testing successful transactions. A request that has been sent should not automatically be treated as a completed CKYC transaction until the relevant response and status have been processed.
Area 6. Define monitoring and operational accountability
CKYCRR 2.0 readiness continues after technical integration. REs need a process for monitoring completed, pending, failed and unresolved transactions and for taking action within applicable timelines. Responsibilities may be divided across IT, operations and compliance depending on the institution’s operating model. For example, IT may manage connectivity, operations may investigate processing exceptions, and compliance may oversee regulatory obligations and supporting evidence. For additional operational measures, read 5 Metrics to Measure CKYC Software Success.
How SimTrust can support CKYCRR 2.0 operations
SimTrust CKYC Gateway, is a software platform, designed to provide a central integration layer between an institution’s internal applications and CERSAI. The gateway supports CKYC search, consent-based download, upload and update workflows and can connect with systems such as CBS, LOS and LMS.
The platform is also designed to support built-in validation, transaction monitoring, exception reporting and audit trails. For institutions operating several customer-facing or lending systems, a central gateway can reduce the need to build and maintain separate CKYC integrations for each application.
A CKYC gateway can support an institution’s operational and compliance processes, but it does not by itself make an institution compliant. The regulated entity remains responsible for following RBI requirements, CERSAI instructions and its own governance and security obligations.
To learn more about the solution capabilities, deployment and integration options, explore SimTrust CKYC Gateway and request a demo.
FAQ (Frequently Asked Questions) about CKYCRR 2.0
1. What is CKYCRR 2.0?
CKYCRR 2.0 is the upgraded Central KYC Records Registry environment being introduced by CERSAI. It supports the registry processes used by Reporting Entities to search, retrieve, upload and update KYC records.
2. What is the current CKYCRR 2.0 pilot-testing deadline?
As of September 23, 2026, the official CKYC website states that the CKYCRR 2.0 pilot-testing period has been extended up to October 5, 2026. Institutions should monitor official CERSAI communications for subsequent production go-live instructions.
3. Does CKYCRR 2.0 introduce the 10-day upload requirement?
No. The requirement to upload applicable KYC records within 10 days of commencement of an account-based relationship comes from the existing RBI KYC framework and should not be described as a new CKYCRR 2.0 requirement.
4. How quickly must updated KYC information be sent to CKYCR?
RBI states that applicable additional or updated customer information must be furnished to CKYCR within seven days, or within another period that may be notified by the Central Government.
5. Does an existing CKYC record remove the need to collect KYC documents again?
In general, an RE can retrieve the customer’s KYC record from CKYCR and should not require the same KYC information again. RBI specifies exceptions, including changed, incomplete or outdated information, expired document validity and cases where additional information is required for verification, enhanced due diligence or risk profiling.
6. Can a CKYC gateway help with CKYCRR 2.0 readiness?
A CKYC gateway can support integration, transaction processing, validation, monitoring and exception management. The regulated entity must still complete the applicable CERSAI onboarding and testing activities and remains responsible for its regulatory obligations.
Sources
Read Further
Editorial note: Regulatory status and technical specifications can change. Verify the latest CERSAI and RBI communications before publication and before making implementation decisions.




Comments