What is V-CIP?
Video-based Customer Identification Process (V-CIP) is a method of KYC introduced by RBI in January 2020 and updated in its 2024 Master Directions on KYC. It allows regulated entities — NBFCs, banks, payment companies — to complete customer onboarding through a live video interaction instead of a physical branch visit.
V-CIP is now a mainstream onboarding method for NBFCs. Done correctly, it is faster than branch KYC, cheaper than physical document collection, and fully compliant with RBI requirements. Done incorrectly, it is the single most common cause of RBI audit observations in lending operations.
What RBI mandates for V-CIP
As per the 2024 Master Directions, a compliant V-CIP session must include:
- Live video interaction — AI-assisted with human review capability. The session must be live; recorded-and-reviewed flows are not compliant without live element.
- Liveness detection — to prevent photo or video spoofing. RBI does not mandate a specific standard but ISO 30107-3 is widely accepted by auditors.
- Face match — the face captured in the video must be matched against the Aadhaar photo or officially valid document photo.
- Geo-tagging — the customer's location must be captured and logged during the session.
- Document capture and OCR — officially valid document (OVD) must be captured and verified.
- Audit trail — a tamper-proof log of the session including timestamp, geo-tag, liveness result, face match score and consent must be stored for 5 years.
The five most common V-CIP audit failures
1. Liveness not meeting standard
Many early V-CIP implementations used basic movement challenges ("blink" or "turn your head") that can be defeated with a printed photograph mounted on a servo. RBI auditors now expect passive liveness detection with a documented technical standard. ISO 30107-3 Level 1 or Level 2 compliance is the benchmark auditors look for.
2. Geo-tag not captured or not logged
The customer's location at the time of the V-CIP session must be captured via GPS (not IP geolocation) and stored in the session audit log. Missing or IP-only geo-tags have been called out in multiple RBI examination reports.
3. Face match score not stored
It is not sufficient to run a face match and store pass/fail. The numerical confidence score must be logged. RBI auditors want to see the score distribution across your V-CIP sessions to assess whether your threshold is appropriately calibrated.
4. Consent not explicitly captured in session
Consent obtained at account creation or in T&Cs does not satisfy V-CIP consent requirements. Consent for the V-CIP session specifically — including the video recording and data processing — must be captured within the session and logged with timestamp.
5. No maker-checker on reviewed sessions
For AI-assisted V-CIP where sessions are reviewed by an officer (rather than live), a maker-checker workflow must be in place. The reviewing officer is the maker; a senior officer must be the checker for high-risk or borderline cases.
Veriflow V-CIP bundle: Face match (ISO 30107-3), Aadhaar OTP, DigiLocker, eSign NACH, geo-tagging, DPDP consent logging, and maker-checker ops dashboard — all in one API call.
Technical implementation checklist
- Integrate ISO 30107-3 compliant liveness (passive preferred)
- Capture and store face match confidence score (not just pass/fail)
- Geo-tag via GPS at session start, store in audit log
- Capture V-CIP-specific consent within the session
- Complete Aadhaar OTP within the same session
- Pull OVD from DigiLocker or capture via camera with OCR
- Store full session recording for 5 years (encrypted, tamper-proof)
- Implement maker-checker for AI-reviewed sessions
- Export CERSAI-format audit log on demand