In order to remove any difficulties or clarify any matter pertaining to application or interpretation of these regulations, the Authority may issue clarifications and guidelines in the form of circulars.
SCHEDULE A
Eligibility criteria for appointment as requesting entities
[See Regulation 10(1)]
1. Entities seeking to use authentication facility provided by the Authority as requesting entities are classified under following categories for appointment as Authentication User Agency (AUA) and/or e-KYC User Agency (KUA), as the case may be:
| Sl. No. |
Organisation Category |
| Category 1 |
Government Organisation |
| 1.1 |
A Central/State Government Ministry/Department and their attached or sub-ordinate offices. |
| 1.2 |
An undertaking owned and managed by Central/State Government (PSU) |
| 1.3 |
An Authority constituted under the Central/State Act/Special Purpose Organisation constituted by Central/State government. |
| Category 2 |
Regulated Service Providers |
| 2.1 |
Regulated/Licensed by RBI. Banks and Payment & Settlement System |
| |
2.1.1 |
Public Sector Banks (PSB) |
| |
2.1.2 |
Private Banks, Foreign Banks Licensed by RBI to operate in India, Payment Banks, Small Finance Banks |
| |
2.1.3 |
Regional Rural Banks |
| |
2.1.4 |
Co-operative Banks |
| |
|
5. |
State Co-operative Banks |
| |
|
6. |
District Co-operative Banks |
| |
|
7. |
Scheduled Urban Cop-operatives Banks |
| |
|
8. |
Non Scheduled Urban Co-operative Banks |
| |
2.1.5 |
Payment & Settlement System Network |
| |
|
1. |
Financial market infrastructure |
| |
|
2. |
Retails payments Organisation |
| |
|
3. |
Cards payment network |
| |
|
4. |
ATM networks |
| |
|
5. |
Pre-paid payment instruments |
| |
|
6. |
White label ATM operators |
| |
|
7. |
Instant Money Transfer |
| |
2.1.6 |
Non-Banking Financial Company |
| 2.2 |
Regulated by IRDA/PFRDA. Financial Institutions |
| 2.3 |
Regulated by TRAI. Telecom |
| 2.4 |
Regulated by CCA. Certifying Authority, Digital Locker providers, e-Sign providers |
| 2.5 |
Regulated by SEBI. KYC Registration Agency (KRA), Depository Participant (DP), Asset Management Company (AMC), Trading Exchanges, Registrar and Transfer Agents |
| 2.6 |
Regulated by National Housing Bank |
| Category 3 |
Other Entities |
| 3.1 |
3.1.1 |
Company registered in India under the Companies Act, 1956/The Companies Act, 2013 (Company under group of companies has to apply individually) |
| |
3.1.2 |
Partnership registered under the Indian Partnership Act, 1932 or under the Limited Liability Partnership Act, 2008 |
| |
3.1.3 |
Proprietorship firm |
| |
3.1.4 |
Not-for-profit Organisations (under Section 25 under The Companies Act, 1956) |
| |
3.1.5 |
Academic Institutions/Research and Development Organisations |
| |
3.1.6 |
Societies registered under Indian Societies Registration Act, 1860 or the Indian Trust Act, 1882 or the Companies Act, 2013 (Sec 8)/the Co-operative Societies Act, 1912 |
| |
3.1.7 |
Any entity other than above mentioned categories |
2. Technical and Financial criteria for entities for appointment as requesting entity are as under
| Category |
Authentication User Agency (AUA) |
Additional |
| |
Technical Requirements |
Financial Requirements |
requirements for eKYC User Agency (KUA) |
| Category 1 |
1. |
Backend infrastructure, such as servers, databases etc. of the entity, required specifically for the purpose of Aadhaar authentication, should be located within the territory of India. |
No financial requirement |
No additional requirement for KUA |
| Category 2 |
| No financial requirement |
No additional requirement for KUA |
| |
2. |
Entity should have IT Infrastructure owned or outsourced capable of carrying out minimum 1 Lakh Authentication transactions per month. |
|
|
| |
3. |
Organisation should have a prescribed Data Privacy policy to protect beneficiary privacy. |
|
|
| |
4. |
Organisation should have adopted data security requirements as per the IT Act, 2000. |
|
|
| Category 3 |
1. |
Backend infrastructure, such as servers, databases etc. of the entity, required specifically for the purpose of Aadhaar authentication, should be located within the territory of India. |
1. |
Paid up capital of minimum 1 (one) Crore. OR |
|
| |
2. |
Entity should have IT Infrastructure owned or outsourced capable of carrying out minimum 1 Lakh Authentication transaction per month. |
|
Annual turnover of minimum 5 (Five) Crore during the last Financial year. |
Entity should meet Authentication Transaction Criteria as laid down by the Authority from time to time. |
| 3. |
Organisation should have a prescribed Data Privacy policy to protect beneficiary privacy. |
| |
4. |
Organisation should have adopted Data security requirements as per the IT Act, 2000. |
|
|
|
| |
5. |
Entity should be in business for minimum of 1 year from date of commencement of Business. |
|
|
|
SCHEDULE B
Eligibility criteria of Authentication Service Agencies
[See Regulation 10(2)]
1. Entities seeking to provide secure access to CIDR to requesting entities for enabling authentication services are classified under following categories for appointment as Authentication Service Agency:
| Sl. No |
Organisation Category |
| Category 1 |
A Central/State Government Ministry/Department or an undertaking owned and managed by Central/State Government |
| Category 2 |
An Authority constituted under the Central/State Act |
| Category 3 |
Any other entity of national importance as determined by the Authority |
| Category 4 |
A company registered in India under the Indian Companies Act, 1956 |
| Category 5 |
AUA/KUA |
2. Technical and Financial criteria for entities for appointment as Authentication Service Agency are as under
| Category |
Financial Requirement |
Technical Requirement |
| Category 1, 2 and 3 |
No financial requirements |
No technical requirements |
| Category 4 |
An annual turnover of at least 100 crores in last three financial years |
A Telecom Service Provider (TSP) including All Unified Licensees (having Access Service Authorization)/Unified Licensees (AS)/Unified Access Services Licensees/Cellular Mobile Telephone Service Licensees operating pan-India fiber optics network and should have a minimum of 100 MPLS Points of Presence (PoP) across all states Or Should be a Network Service Provider (NSP) or System Integrator having pan-India network connectivity for data transmission and should have 100 MPLS PoPs in India, |
| Category 5 |
No Financial requirements |
Any AUA or KUA meeting authentication transaction criteria as laid down by the Authority from time to time |
NOTIFICATION
UIAI, Noti. No. 13012/79/2017/Legal-UIDAI (No. 4 of 2017), dated July 14, 2017, published in the Gazette of India, Extra., Part III, Section 4, dated 14th July, 2017, pp. 2-3, No. 284.
In exercise of Regulation 12-A of the Aadhaar (Enrolment and Update) (Second Amendment) Regulations, 2017 (No. 2 of 2017) and the Aadhaar (Enrolment and Update) (Third Amendment) (No. 3 of 2017), the Unique Identification Authority of India (UIDAI) hereby issues the following notification, namely:
1. Whereas the provisions of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 ( Aadhaar Act ), and Regulations framed thereunder the Aadhaar Act have come into effect from 14th September, 2016 and notifications to this effect have been published in the Official Gazette,
2. And Whereas the Prevention of Money Laundering (Maintenance of Records) Rules, 2005 ( PML Rules, 2005 ) have been amended with effect from June 1, 2017 to require Aadhaar for every bank account. All existing Bank accounts have to be verified with Aadhaar by the banks by 31st December, 2017, failing which the accounts will become inoperative,
3. And Whereas Regulation 12-A of the Aadhaar (Enrolment and Update) (Second Amendment) Regulations, 2017 (No. 2 of 2017) and the Aadhaar (Enrolment and Update) (Third Amendment) (No. 3 of 2017) provides that:
12-A. Entities requiring Aadhaar as condition for fulfillment of any obligation, etc. The Authority may require any Central or State department or agency or any Scheduled Bank or any other entity which requires an individual to undergo authentication or furnish proof of possession of Aadhaar number as a condition for receipt of any subsidy, benefit, service or fulfillment of any obligation pursuant to any Act or Rule or Regulation or order made thereunder, to ensure enrolment of such individual who is yet to be enrolled or update their Aadhaar details, by setting up enrolment centres at their premises. .
4. And Whereas there are more than 100 Crore bank accounts which will be required to be verified before the aforesaid date and every new customer will also be required to be verified with Aadhaar,
5. And Whereas Scheduled Commercial Banks have major share of bank account holders who will need to authenticate their bank accounts with their Aadhaar numbers,
6. Therefore, it is necessary to provide Aadhaar enrolment and update facilities in Scheduled Commercial Banks so that no undue hardship is caused to their customers owing to the aforesaid amendment of the PML Rules, 2005,
7. And Therefore Unique Identification Authority of India, in exercise of Regulation 12A of the Aadhaar (Enrolment and Update) (Second Amendment) Regulations, 2017 (No. 2 of 2017) and the Aadhaar (Enrolment and Update) (Third Amendment) (No. 3 of 2017), hereby directs that every Scheduled Commercial Bank shall provide Aadhaar enrolment and update facilities to its customers in the following manner:
i. Every Scheduled Commercial Bank shall set up Aadhaar enrolment and update facility inside its bank premises at a minimum of 1 out of their every 10 branches by 30th August, 2017.
ii. The selection of branches for enrolment and update facility shall be such that it covers all the district headquarters where it is present, and that there is maximum coverage of Talukas/Block in every district.
iii. The Scheduled Commercial Bank shall notify to its customers, the general public, and UIDAI of the locations of branches where Aadhaar enrolment and update facilities will be provided by them. The list of such branches shall be displayed on its websites. Any changes in locations shall be notified at the earliest in the aforesaid manner.
iv. The Banks may at its discretion provide the Aadhaar Enrolment and Update facility to customers of other banks.
v. The Bank may charge the customers for the Aadhaar enrollment and update services at the rate prescribed by UIDAI.
vi. The Scheduled Commercial Bank shall, if not already done so, become Registrar of UIDAI for providing enrolment and update facilities.
8. Any non-compliance of these directions shall be dealt under Section 42 of the Aadhaar Act.