Axis Bank · Cards · Proposal v0.1

Credit card re-KYC journey

A proposed flow for periodic KYC updation on Axis credit cards — built around the insight that most customers have nothing to update, and should be finished in under a minute.

For alignment Not a build spec August 2026

Walk the paths yourself

An installable prototype with a scenario picker up front. Five scenarios — no change, address changed, identity changed, post KYC due date, and ReKYC verification failed. The argument for this design is the gap between 60 seconds and five minutes, and that gap has to be walked rather than described.

Open the prototype →
The problem

Most customers have nothing to update

Under the RBI Master Direction, a customer whose KYC details are unchanged can close out periodic updation with a self-declaration and nothing else — no documents, no branch, no video call. That is the large majority of any re-KYC cohort.

The reason completion rates stay low is that this path is usually buried inside a flow designed for the minority who do have something to change. The customer opens the link, sees a document upload screen, and leaves. Months later the bank deactivates a card it never wanted to deactivate, and pays for the resulting call.

The proposal inverts that. The default path is a 60-second self-declaration. Address changes and full re-verification become branches off it, not the trunk everyone walks.

Context

Why card re-KYC is not savings-account re-KYC

Five differences that change the design, rather than just the branding:

  1. Card-only customers have no branch relationship. A meaningful share of Axis card holders have no Axis savings account — no net banking, no branch, no RM. For them the only viable channels are the card app, an SMS or WhatsApp deep link, and a secure web link. A branch-first fallback quietly excludes exactly the people hardest to reach.
  2. The card is a live credit line. Deactivating it mid-cycle breaks standing instructions, EMI auto-debits and utility mandates — generating disputes and inbound calls that cost more than the re-KYC did. The deactivation ladder has to be designed, not inherited from the deposit-account playbook.
  3. The trigger is a date, not an intent. Unlike an upgrade or limit-increase journey, nobody wakes up wanting to do re-KYC. Everything rests on notification quality and on the first screen answering why am I here and how long will this take.
  4. Add-on cardholders carry their own obligation. Separate notification, separate completion, visible to the primary cardholder.
  5. There is a natural carrot. Limit review, a reward bonus, or a fee waiver on completion — a lever savings-account re-KYC simply does not have.
The flow

One screen decides everything

The regulation defines three legally distinct routes, not one. The whole journey therefore turns on a single fork — a pre-filled review screen where the customer says whether anything has changed. Cost, completion rate and time-to-finish are all set at that one moment.

Entry point push · SMS/WhatsApp · email · letter QR · statement Authenticate in-app MPIN, or card last-4 + DOB + OTP Why you’re here due date · what lapses · “about a minute” Review your details — the fork pre-filled from CKYCR · “has anything changed?” Path A — Nothing changed target 70–80% of volume Self-declaration declaration text + explicit consent OTP to registered mobile Done — card untouched zero documents · 60–90 seconds Path B — Address only self-declaration permitted New address DigiLocker (1 tap) · PIN autofill · OVD Self-declaration + OTP same consent step as Path A Done — card stays active bank confirms address within 2 months Path C — Full re-verification also forced for high-risk customers Route selector Aadhaar OTP → DigiLocker → Face Auth → V-CIP Capture + refresh selfie · occupation, income, PEP, FATCA In review — SLA shown verified · or failed with a stated reason Next due date set · record pushed to CKYCR consent timestamped · audit trail written · deactivated cards reactivated instantly

Scroll the diagram sideways to see all three paths.

The three paths are not design variants — they are the three routes the RBI Master Direction actually defines. The design choice is which one the interface makes easiest.

The three paths

What each route actually costs the customer

Path A — No change in KYC information
Target: 70–80% of volume
  1. Self-declaration — declaration text with an explicit consent checkbox
  2. OTP to the registered mobile
  3. Confirmation, new next-due date, reference number, CKYCR updated
No documents · 60–90 seconds
Path B — Change only in address details
Self-declaration permitted
  1. New address via DigiLocker (Aadhaar address, pre-verified, one tap), PIN-code autofill, or OVD upload
  2. Self-declaration + OTP
  3. Recorded and card stays active; bank confirms the address within two months, status surfaced to the customer
DigiLocker sub-path ≈ Path A speed
Path C — Change in KYC information
Forced for high-risk customers
  1. Route selector, ordered by friction — the goal is deflecting volume away from V-CIP
  2. Selfie and signature capture where applicable
  3. Refresh of occupation, income band, source of funds, PEP declaration, FATCA/CRS
  4. Submit → pending, verified, or failed with a stated reason
Agent-capacity bound — deflection is the objective

Path C route selector, ordered by friction

V-CIP requires a live agent, liveness check, geotagging and recording. It does not scale with the monthly due cohort, so the selector should push volume up this table, not down it.

RouteWhen it appliesFriction
Aadhaar OTP e-KYCDefault, non-face-to-faceLowest
DigiLocker pullAadhaar, PAN and other OVDs, consent-basedLow
Aadhaar Face AuthenticationRecognised Aug 2025; accessibility-friendly alternative to V-CIPLow–medium
V-CIP video callWhere identity itself changed, or risk is highHigh — needs slot booking and a callback fallback
Branch or doorstepLast resortHighest
Entry points

Six mandated touchpoints, one journey

re-KYC is pushed, so the notification is part of the journey rather than a precondition to it. The 2025 amendment requires three advance intimations before the due date and three reminders after, each set including at least one physical letter. That is six designed touchpoints, all of which should land on the same authenticated flow.

ChannelRole
In-app banner + pushPrimary for app-active customers
SMS / WhatsApp deep linkPrimary for card-only and app-dormant customers
Email with secure linkSupporting
Letter with QR codeMandated; the QR carries them into the same digital flow rather than to a branch
Statement interstitialHigh-intent moment — they are already looking at the card
IVR / contact centreRescue channel for repeat non-responders

Language standard

Six touchpoints only read as one product if they share one vocabulary. Checked against the RBI FAQs on the Master Direction on KYC (9 June 2025), the KYC (Amendment) Directions, 2025, HDFC Bank’s credit-card re-KYC customer document (Dec 2025), and a live SBI Card KYC mailer series.

The three cases have official names. RBI puts the first two in quotation marks and HDFC’s card forms use the same words. They are the legal fork, so the proposal uses them verbatim rather than paraphrasing — customer-facing buttons stay plain English.

CaseOfficial labelWhat may be accepted
1“no change in KYC information”Self-declaration. HDFC’s form is literally Self-Declaration – No Change in KYC Information.
2“change only in address details”Self-declaration; declared address verified by positive confirmation within two months.
3change in KYC informationFresh KYC — OVDs, Aadhaar OTP e-KYC, V-CIP, DigiLocker, or CKYCR download.

What to call the process. RBI’s formal term is “periodic updation of KYC”, and its FAQ concedes the shorthand in the same breath — “such periodic updation of KYC records (at times referred to as re-KYC)”. So re-KYC is not informal: HDFC titles its credit-card customer document “Periodic Updation of KYC/ Re-KYC”, and Axis’s own site runs an explainer called “What is re-KYC”. SBI Card’s “KYC renewal” is the outlier of the three, not the standard.

Do not saySayWhy
Document rejectedCould not be verified · ReKYC verification failedRBI does use “rejected”, but bars automated rejection and requires an officer’s recorded reasons. To the customer, naming the failed check beats a verdict on them.
AcceptedVerifiedPairs with the above — one axis, not two.
Re-upload, redoSubmit againIssuer language is submit / receive: “we have not received your document(s)”.
KINCKYC Identifier (14 digits)RBI’s FAQ says “KYC Identifier”; CERSAI’s full form is KYC Identification Number. “KIN” alone means nothing to a customer.
Keep your card activeContinue enjoying uninterrupted services on your cardThe standard motivation line across issuers; states the stake without threatening.
Consent to update CKYCShare consent for CKYC updateVerbatim from SBI Card’s live step list.
Because RBI requires itAs per the ‘Know Your Customer’ guidelines of the Reserve Bank of IndiaThe standard citation sentence — use it once, on the status screen.
We will confirm by postVerify by positive confirmation within two months“Positive confirmation” is RBI’s term for this check.

What this proposal uses. The process is re-KYC, with KYC updation where a formal register is wanted. That is RBI’s own term and Axis’s own; SBI Card’s “KYC renewal” is a house term we should not borrow. The lapsed state is deactivated, and its resolution reactivated, following SBI Card’s wording rather than HDFC’s “restriction placed in the account”: it is the more precise of the two for a card, and it pairs with the reactivation moment this design is built around. One thing still to confirm with Axis: that deactivated / reactivated is what their ops and disputes teams already say, since it is the word that will appear in complaints.

Cross-cutting

The states that separate a demo from something shippable

Save and resume

Partial completion is the norm on pushed journeys. State is preserved and the resume link is re-sent on the channel the customer originally came from.

Verification failed, with the reason

The 2025 amendment bars rejection without application of mind and requires recorded reasons. The customer sees the specific reason and gets a one-tap route back to fix it.

A risk-aware deactivation ladder

Pre-due nudge → due → grace → deactivated → reactivated. Low-risk customers get a full year of grace past the due date under the 2025 amendment — no abrupt cut-off.

Instant reactivation

A customer who completes re-KYC on a deactivated card should see it live immediately, not next-day. This is the difference between a rescue and a complaint.

Add-on cardholders

Their own obligation, their own notification and completion, visible to the primary cardholder so they can chase it.

Accessibility

PwD safeguards were written into the Aug 2025 amendment explicitly. They bind hardest on V-CIP, which is why Face Authentication matters as an alternative.

Instrumentation to agree up front

Completion rate split by path; drop-off by screen; channel attribution across the six mandated touchpoints; time-to-complete by path; V-CIP deflection rate; and completions driven by deactivation versus completed voluntarily before the due date. That last split is the real health metric — a journey that only completes under threat has not worked.

Next

Open decisions for Axis

These block scoping rather than design — the flow above holds either way, but the build estimate does not.

Channels in v1

App-only, or SMS and secure web from day one so card-only customers are reachable?

CKYCR pull

Is it live today, and can it pre-fill the review screen? The whole fork depends on the data being there and being right.

V-CIP ownership and capacity

In-house agents or vendor — and what is peak capacity measured against the monthly due cohort?

Deactivation policy for cards

Full deactivation or new-transactions-only, and how existing EMIs and standing instructions are treated.

Risk category at card level

Is it available to drive path selection, or does every customer get the same flow regardless of risk?

Incentive

Is a limit review, reward bonus or fee waiver on the table to lift voluntary completion?

Proposed prototype scope

Six to eight clickable screens: the status screen, the fork, Path A end-to-end, the Path B DigiLocker sub-path, the Path C route selector, V-CIP pre-call, submitted/pending, and the post-due-date deactivated state. Enough to make all three paths tangible in a room without building the whole thing.