A proposed flow for periodic KYC updation on Axis credit cards — built around the insight that most customers have nothing to update, and should be finished in under a minute.
An installable prototype with a scenario picker up front. Five scenarios — no change, address changed, identity changed, post KYC due date, and ReKYC verification failed. The argument for this design is the gap between 60 seconds and five minutes, and that gap has to be walked rather than described.
Under the RBI Master Direction, a customer whose KYC details are unchanged can close out periodic updation with a self-declaration and nothing else — no documents, no branch, no video call. That is the large majority of any re-KYC cohort.
The reason completion rates stay low is that this path is usually buried inside a flow designed for the minority who do have something to change. The customer opens the link, sees a document upload screen, and leaves. Months later the bank deactivates a card it never wanted to deactivate, and pays for the resulting call.
The proposal inverts that. The default path is a 60-second self-declaration. Address changes and full re-verification become branches off it, not the trunk everyone walks.
Five differences that change the design, rather than just the branding:
The regulation defines three legally distinct routes, not one. The whole journey therefore turns on a single fork — a pre-filled review screen where the customer says whether anything has changed. Cost, completion rate and time-to-finish are all set at that one moment.
Scroll the diagram sideways to see all three paths.
The three paths are not design variants — they are the three routes the RBI Master Direction actually defines. The design choice is which one the interface makes easiest.
V-CIP requires a live agent, liveness check, geotagging and recording. It does not scale with the monthly due cohort, so the selector should push volume up this table, not down it.
| Route | When it applies | Friction |
|---|---|---|
| Aadhaar OTP e-KYC | Default, non-face-to-face | Lowest |
| DigiLocker pull | Aadhaar, PAN and other OVDs, consent-based | Low |
| Aadhaar Face Authentication | Recognised Aug 2025; accessibility-friendly alternative to V-CIP | Low–medium |
| V-CIP video call | Where identity itself changed, or risk is high | High — needs slot booking and a callback fallback |
| Branch or doorstep | Last resort | Highest |
re-KYC is pushed, so the notification is part of the journey rather than a precondition to it. The 2025 amendment requires three advance intimations before the due date and three reminders after, each set including at least one physical letter. That is six designed touchpoints, all of which should land on the same authenticated flow.
| Channel | Role |
|---|---|
| In-app banner + push | Primary for app-active customers |
| SMS / WhatsApp deep link | Primary for card-only and app-dormant customers |
| Email with secure link | Supporting |
| Letter with QR code | Mandated; the QR carries them into the same digital flow rather than to a branch |
| Statement interstitial | High-intent moment — they are already looking at the card |
| IVR / contact centre | Rescue channel for repeat non-responders |
Six touchpoints only read as one product if they share one vocabulary. Checked against the RBI FAQs on the Master Direction on KYC (9 June 2025), the KYC (Amendment) Directions, 2025, HDFC Bank’s credit-card re-KYC customer document (Dec 2025), and a live SBI Card KYC mailer series.
The three cases have official names. RBI puts the first two in quotation marks and HDFC’s card forms use the same words. They are the legal fork, so the proposal uses them verbatim rather than paraphrasing — customer-facing buttons stay plain English.
| Case | Official label | What may be accepted |
|---|---|---|
| 1 | “no change in KYC information” | Self-declaration. HDFC’s form is literally Self-Declaration – No Change in KYC Information. |
| 2 | “change only in address details” | Self-declaration; declared address verified by positive confirmation within two months. |
| 3 | change in KYC information | Fresh KYC — OVDs, Aadhaar OTP e-KYC, V-CIP, DigiLocker, or CKYCR download. |
What to call the process. RBI’s formal term is “periodic updation of KYC”, and its FAQ concedes the shorthand in the same breath — “such periodic updation of KYC records (at times referred to as re-KYC)”. So re-KYC is not informal: HDFC titles its credit-card customer document “Periodic Updation of KYC/ Re-KYC”, and Axis’s own site runs an explainer called “What is re-KYC”. SBI Card’s “KYC renewal” is the outlier of the three, not the standard.
| Do not say | Say | Why |
|---|---|---|
| Document rejected | Could not be verified · ReKYC verification failed | RBI does use “rejected”, but bars automated rejection and requires an officer’s recorded reasons. To the customer, naming the failed check beats a verdict on them. |
| Accepted | Verified | Pairs with the above — one axis, not two. |
| Re-upload, redo | Submit again | Issuer language is submit / receive: “we have not received your document(s)”. |
| KIN | CKYC Identifier (14 digits) | RBI’s FAQ says “KYC Identifier”; CERSAI’s full form is KYC Identification Number. “KIN” alone means nothing to a customer. |
| Keep your card active | Continue enjoying uninterrupted services on your card | The standard motivation line across issuers; states the stake without threatening. |
| Consent to update CKYC | Share consent for CKYC update | Verbatim from SBI Card’s live step list. |
| Because RBI requires it | As per the ‘Know Your Customer’ guidelines of the Reserve Bank of India | The standard citation sentence — use it once, on the status screen. |
| We will confirm by post | Verify by positive confirmation within two months | “Positive confirmation” is RBI’s term for this check. |
What this proposal uses. The process is re-KYC, with KYC updation where a formal register is wanted. That is RBI’s own term and Axis’s own; SBI Card’s “KYC renewal” is a house term we should not borrow. The lapsed state is deactivated, and its resolution reactivated, following SBI Card’s wording rather than HDFC’s “restriction placed in the account”: it is the more precise of the two for a card, and it pairs with the reactivation moment this design is built around. One thing still to confirm with Axis: that deactivated / reactivated is what their ops and disputes teams already say, since it is the word that will appear in complaints.
Partial completion is the norm on pushed journeys. State is preserved and the resume link is re-sent on the channel the customer originally came from.
The 2025 amendment bars rejection without application of mind and requires recorded reasons. The customer sees the specific reason and gets a one-tap route back to fix it.
Pre-due nudge → due → grace → deactivated → reactivated. Low-risk customers get a full year of grace past the due date under the 2025 amendment — no abrupt cut-off.
A customer who completes re-KYC on a deactivated card should see it live immediately, not next-day. This is the difference between a rescue and a complaint.
Their own obligation, their own notification and completion, visible to the primary cardholder so they can chase it.
PwD safeguards were written into the Aug 2025 amendment explicitly. They bind hardest on V-CIP, which is why Face Authentication matters as an alternative.
Completion rate split by path; drop-off by screen; channel attribution across the six mandated touchpoints; time-to-complete by path; V-CIP deflection rate; and completions driven by deactivation versus completed voluntarily before the due date. That last split is the real health metric — a journey that only completes under threat has not worked.
These block scoping rather than design — the flow above holds either way, but the build estimate does not.
App-only, or SMS and secure web from day one so card-only customers are reachable?
Is it live today, and can it pre-fill the review screen? The whole fork depends on the data being there and being right.
In-house agents or vendor — and what is peak capacity measured against the monthly due cohort?
Full deactivation or new-transactions-only, and how existing EMIs and standing instructions are treated.
Is it available to drive path selection, or does every customer get the same flow regardless of risk?
Is a limit review, reward bonus or fee waiver on the table to lift voluntary completion?
Six to eight clickable screens: the status screen, the fork, Path A end-to-end, the Path B DigiLocker sub-path, the Path C route selector, V-CIP pre-call, submitted/pending, and the post-due-date deactivated state. Enough to make all three paths tangible in a room without building the whole thing.