V-CIP: How RBI-Compliant Video KYC Works and Where Banks Get It Wrong
V-CIP, the Video-based Customer Identification Process, is how the Reserve Bank of India lets banks and NBFCs verify a customer's identity over a live, audio-visual session instead of an in-person meeting. Think of it as the digital, remote way to complete Customer Identification within the broader KYC obligation. Done right, it gives a regulated entity the same legal assurance as physical verification. The branch visit is replaced by geo-tagging, liveness detection, and a concurrent audit trail.
The framework has been live since 2020. Every compliance team in India has had years to read it, test against it, and fold it into an audit cycle, and yet inspection teams keep turning up the same gaps. In FY 2024-25, the Reserve Bank of India imposed ₹54.78 crore in penalties across 353 regulated entities, with KYC violations near the top of the list. ICICI Bank was hit with ₹97.80 lakh, Union Bank with ₹1 crore, and Canara Bank with ₹41.80 lakh for failing to upload KYC records to the Central KYC Registry on time. None of those orders turned on obscure requirements. They came down to the basics of video KYC executed poorly.
What V-CIP Means in the KYC Process
These terms get used loosely, so it helps to place V-CIP inside the wider compliance vocabulary. The Customer Identification Program, or CIP, is the step where a regulated entity collects and verifies the identity attributes of a new customer before opening a relationship. V-CIP is simply how that CIP step gets done remotely, over video. The customer joins a live session and presents documents while an authorized official checks that the person on screen matches the identity on record.
Many programs drift by treating V-CIP as a standalone gadget rather than a CIP method. The video interaction is not a separate compliance product. It is the identification leg of KYC, performed remotely under conditions the RBI has specified. Every control the regulator expects, from capturing the customer's geolocation to recording a tamper-proof session, exists to give that remote identification the same evidentiary weight a face-to-face check would carry.
CIP vs CDD vs EDD: Where V-CIP Fits
Buyers evaluating onboarding platforms often ask how CIP, CDD, and EDD relate, and the distinction matters when you scope a V-CIP deployment. CIP is identification. It answers who the customer is and confirms the supporting documents are genuine. Customer Due Diligence, or CDD, comes next, assessing the risk the customer represents by reviewing the nature of the relationship, the expected activity, and any screening hits against sanctions or adverse media. Enhanced Due Diligence, or EDD, is the deeper layer reserved for higher-risk customers, adding source-of-funds checks and closer ongoing monitoring.
V-CIP belongs to the CIP stage, but a well-designed program does not stop there. Whatever the session captures should pass straight into the risk engine, so customer due diligence and any enhanced checks pick up without a manual handoff. Run CIP, CDD, and EDD on separate systems and customers slip through the gaps while audit trails splinter. Put them in one workflow and a single onboarding event produces a complete, reviewable risk picture.
The RBI Controls That Define Compliant V-CIP
The master direction is specific about what a compliant V-CIP system must do, and inspection findings cluster around a handful of these requirements.
The video application must be proprietary, built in-house or through a dedicated vendor, and deployed at controlled customer touchpoints. Generic conferencing tools do not qualify. They cannot geo-tag, run liveness detection, or integrate with CKYC. The system also has to capture the customer's geolocation and block connections originating outside India, including spoofed ones. One inspection finding recurs constantly: a geo-tag field carrying the bank's own server coordinates instead of the customer's device GPS, a mismatch that can sit unnoticed for months. The fix is to validate device GPS against IP geolocation in real time and flag any discrepancy automatically.
Liveness detection is another pressure point. The RBI mandates that V-CIP systems detect a live person and prevent spoofing, but it does not prescribe the method, so many implementations settle for a single blink test that a screen recording defeats. Against a threat this fast-moving, that is a thin defense. Deepfake-related cybercrime in India has grown 550% since 2019, with projected fraud losses reaching ₹70,000 crore in 2024. With over 11 lakh video KYC calls happening daily across Indian financial institutions, the attack surface is enormous. At that scale, liveness and biometric checks that combine active and passive signals stop being optional.
Audit, Testing, and Monitoring Obligations
Ending the call is not the end of compliance. The RBI requires that any account opened via V-CIP be activated only after a concurrent audit of the video interaction, meaning a second qualified official reviews the session before the account goes live. This is not periodic sampling. Run the review days after activation, once the customer has already transacted, and you fail the test. The durable fix is to lock account status to pending until a reviewer signs off, with no manual override.
V-CIP infrastructure must also undergo Vulnerability Assessment and Penetration Testing by CERT-In empaneled auditors, with critical gaps closed before go-live. Treating that as a one-time launch exercise is a mistake. What regulators look for is penetration testing on a regular cadence, with results tied to a compliance dashboard, because penalties often hinge on whether an institution can prove a testing rhythm rather than produce a single old report. Officer training follows the same logic. Refresh it as fraud techniques evolve rather than delivering it once at onboarding.
Failed sessions matter too. Customer drops, liveness failures, and document mismatches all have to be tracked and flagged within the AML framework. A customer who fails video verification three times might have a poor connection, or might be probing your rejection thresholds. Without monitoring that feeds into suspicious activity reporting, an institution cannot tell the difference. The cost of getting this wrong is real. The RBI cancelled X10 Financial Services' Certificate of Registration outright for outsourcing core KYC verification to third parties, and the FY 2024-25 penalty wave reached banks of every size, including Kotak Mahindra, IDFC First, and PNB.
How KYC Hub Delivers RBI-Compliant V-CIP
KYC Hub's V-CIP platform is built around the RBI requirements that inspection teams actually test, not compliance features bolted onto generic video infrastructure. It leads with biometric certainty, pairing facial matching with active and passive liveness so a recorded video or printed photo cannot pass. While the session is live, document forensics check submitted identity documents for tampering and confirm they are authentic. Through a configurable, modular workflow, compliance teams can wire the concurrent audit step, geo-tag validation, and approval gates straight into the onboarding path, so an account cannot activate until every control is satisfied.
Geo-location mismatches, liveness anomalies, and failed attempts trigger real-time alerts the moment they occur, rather than surfacing weeks later in an internal review. Identification carries into CDD and EDD with no manual handoff, since the V-CIP session connects to downstream risk scoring and due diligence. Tamper-proof session storage and full audit logging mean the evidence is there when an inspection team pulls a random sample. For Indian onboarding specifically, eKYC and Video KYC for India clears customers in minutes while holding to the RBI standard.



