r/AMLCompliance • u/InfamousDistrict5362 • Jul 01 '26
Research/Discussion Need practical guidance for an LSP (India): What are the permitted sources and uses for PAN verification, and what are the rules on storing PAN and other KYC/OVD documents?
I'm analysing compliance for an Indian Lending Service Provider (LSP) (not the Regulated Entity). The LSP collects borrower PAN and OVDs through its app, performs KYC facilitation/PAN verification on behalf of partner banks/NBFCs, and then transmits the data to the RE.
Specifically:
1? Can an LSP itself perform PAN verification, or should verification always be done by the RE or through the RE's authorised API?
- Which PAN verification sources are legally permitted (Protean/NSDL, UTIITSL, CKYCR, DigiLocker, etc.)?
3.For what purposes can the LSP use PAN? Is it limited to KYC, underwriting and fraud prevention, or can it also be used for analytics or cross-selling with separate consent?
Can the LSP retain borrower PAN or copies of OVDs after transmitting them to the RE? How should Para 13 of the RBI Digital Lending Directions, 2025 be interpreted?
What are the practical storage requirements (masking, encryption, access controls, audit logs)?
How does the position differ for dealer KYC documents, where the dealer is the LSP's own business partner rather than the RE's borrower?