India is home to more digital identity checks than almost anywhere else in the world. At the centre of that system sits Aadhaar: a 12-digit identity number issued by India's Unique Identification Authority (UIDAI) to over a billion residents.
For businesses verifying customers in India, Aadhaar-based eKYC is often the fastest and most reliable option available. But it comes with a catch that most explanations skip over. Unlike many national identity systems compliance teams encounter elsewhere, private-sector access to Aadhaar isn't a simple, settled matter. It has a specific legal history, and that history still shapes what a business can and cannot rely on today.
This guide explains how Aadhaar eKYC actually works, why that legal history exists, and what it means for compliance teams verifying identities in India right now.
Aadhaar eKYC verifies a person's identity electronically, with their consent. There are two methods.
Online (live) eKYC works in real time:
Offline eKYC works differently, with no real-time query to UIDAI:

This detail is often skipped in generic explanations of Aadhaar eKYC. It matters for any business assessing whether it can legally rely on Aadhaar authentication.
This legal history has two practical consequences.
First, customer willingness isn't enough. A customer providing their Aadhaar number doesn't automatically entitle a business to use Aadhaar-based eKYC. Eligibility depends on the organisation itself; it needs the appropriate UIDAI licensing, or it needs to fall within a sector specifically authorised to use it.
Second, the eligibility position keeps moving. Private-sector access has changed materially since 2018, and it remains an area of active regulatory and legislative activity. Confirm the current position directly against UIDAI and sector-regulator AML guidance rather than relying on older material, including much of what circulates in general online explanations of Aadhaar eKYC.
In practice, sector regulators have already stepped in. The Reserve Bank of India, SEBI, and IRDAI have each issued their own guidelines permitting or requiring Aadhaar-based eKYC within their regulated sectors. All of it still sits under UIDAI's overarching authentication framework and still requires user consent.

Once a customer's identity has been verified through Aadhaar eKYC, where an organisation is eligible to rely on it, MemberCheck supports the next stage of due diligence: PEP, sanctions, and adverse media screening for the verified individual. MemberCheck does not perform Aadhaar authentication itself. It's the screening layer that follows identity verification.
No. Customer consent alone isn't enough. The business also needs UIDAI licensing, or it needs to operate in an authorised sector.
No. It changed after 2018. Courts and Parliament reshaped who can use it, and on what terms.
Banking, telecom, and other UIDAI-licensed sectors qualify. Regulators like RBI, SEBI, and IRDAI have issued their own rules for their sectors.
No. It keeps changing. Always check current UIDAI and sector-regulator guidance before relying on it.
No. RBI, SEBI, and IRDAI guidelines sit on top of UIDAI's framework. UIDAI's authentication rules and consent requirements still apply.
Yes. Consent is required under UIDAI's framework, regardless of which sector or regulator is involved.
It risks legal and regulatory consequences. Unauthorised use isn't just a compliance gap, it can breach the Aadhaar Act itself.
UIDAI is a national authority. Its licensing and rules apply across India, not state by state.
If your organisation is eligible to rely on Aadhaar-based eKYC for identity verification, explore how MemberCheck supports PEP, sanctions, and adverse media screening as the next stage of your AML due diligence process.