India is home to more digital identity checks than almost anywhere else in the world. At the centre of that system sits Aadhaar: a 12-digit identity number issued by India's Unique Identification Authority (UIDAI) to over a billion residents.
For businesses verifying customers in India, Aadhaar-based eKYC is often the fastest and most reliable option available. But it comes with a catch that most explanations skip over. Unlike many national identity systems compliance teams encounter elsewhere, private-sector access to Aadhaar isn't a simple, settled matter. It has a specific legal history, and that history still shapes what a business can and cannot rely on today.
This guide explains how Aadhaar eKYC actually works, why that legal history exists, and what it means for compliance teams verifying identities in Indiaright now.
How Aadhaar eKYC works mechanically
Aadhaar eKYC verifies a person's identity electronically, with their consent. There are two methods.
Online (live) eKYC works in real time:
- The individual provides their Aadhaar number or a Virtual ID
- They authenticate using a one-time password sent to their registered mobile number or via biometric verification.
- UIDAI returns a match confirmation, plus the demographic details that the requesting organisation is authorised to receive.
Offline eKYC works differently, with no real-time query to UIDAI:
- The individual downloads a digitally signed XML file from the UIDAI website, containing their demographic details.
- They share that file, along with a share code, with the requesting organisation.
- The organisation verifies the file's digital signature, rather than checking against UIDAI directly.
Why private-sector Aadhaar access has a specific legal history

This detail is often skipped in generic explanations of Aadhaar eKYC. It matters for any business assessing whether it can legally rely on Aadhaar authentication.
- September 2018, the Puttaswamy judgment. India's Supreme Court ruled in Justice K.S. Puttaswamy (Retd.) v. Union of India. It upheld the Aadhaar Act's constitutionality overall. But it struck down Section 57, the provision that had allowed private companies and individuals to use Aadhaar authentication under contract. The Court found this went beyond proportionate use of the scheme.
- 2019, the Amendment Act. Parliament passed the Aadhaar and Other Laws (Amendment) Act. This reintroduced a legal basis for private-sector use, but on narrower terms than before. It was voluntary and more tightly regulated. It specifically permitted banking and telecom companies to use Aadhaar-based authentication for KYC, under UIDAI licensing and oversight.
- Since 2019, continued to evolve. The amendment itself has faced ongoing legal challenges. The scope of private-sector access has kept evolving. Further rule changes have extended eligibility to additional sectors, still under UIDAI licensing.
What this means in practice for a compliance team
This legal history has two practical consequences.
First, customer willingness isn't enough. A customer providing their Aadhaar number doesn't automatically entitle a business to use Aadhaar-based eKYC. Eligibility depends on the organisation itself; it needs the appropriate UIDAI licensing, or it needs to fall within a sector specifically authorised to use it.
Second, the eligibility position keeps moving. Private-sector access has changed materially since 2018, and it remains an area of active regulatory and legislative activity. Confirm the current position directly against UIDAI and sector-regulator AML guidance rather than relying on older material, including much of what circulates in general online explanations of Aadhaar eKYC.
In practice, sector regulators have already stepped in. The Reserve Bank of India, SEBI, and IRDAI have each issued their own guidelines permitting or requiring Aadhaar-based eKYC within their regulated sectors. All of it still sits under UIDAI's overarching authentication framework and still requires user consent.

How MemberCheck fits
Once a customer's identity has been verified through Aadhaar eKYC, where an organisation is eligible to rely on it, MemberCheck supports the next stage of due diligence: PEP, sanctions, and adverse media screening for the verified individual. MemberCheck does not perform Aadhaar authentication itself. It's the screening layer that follows identity verification.



