IFSCA KRA integration: the September 1 deadline, and what GIFT IFSC entities should build now
IFSCA's KRA integration circular is still unnotified with days to go before September 1. What GIFT IFSC regulated entities must build for KYC Registration Agency integration.

Short answer. IFSCA's draft circular requires every regulated entity in GIFT IFSC to integrate with at least one IFSCA-registered KYC Registration Agency, upload KYC for all new clients onboarded from 1 September 2026, and migrate records for existing active clients by 30 October 2026. As of 27 August 2026 the circular has not been notified in final form. The consultation closed on 16 July. That leaves roughly 680 client-facing regulated entities preparing for a deadline whose legal instrument does not yet exist — and the sensible response is to build against the draft rather than wait.
Where the rules actually stand
Three things are settled, and one is not.
Settled. The IFSCA (KYC Registration Agency) Regulations, 2025 are notified. They create the registration and supervision framework for KRAs in the IFSC, and they carry the operative obligation that KYC data be uploaded within three working days of the process completing.
Settled. CDSL Ventures Limited (CVL) is registered with IFSCA as a KYC Registration Agency, registration number KRA2026KRA0985, dated 4 February 2026, operating from Pragya Tower in GIFT SEZ. CAMS announced in July that its subsidiary CAMS Investor Services had received IFSCA approval for the same activity; it had not appeared in the public directory at the time of writing.
Settled. On 20 August 2026, SEBI specified IFSCA under Regulation 16A(1) of the SEBI (KYC Registration Agency) Regulations, 2011. IFSCA-regulated entities may now access the systems of SEBI-registered KRAs for client KYC, subject to the KRA Regulations and SEBI's KYC master circular. For FPI clients, SEBI's data-security guidelines for FPIs, DDPs and eligible foreign investors also apply.
Not settled. The circular that actually mandates integration. IFSCA published the consultation paper on 26 June 2026 with comments due 16 July. IFSCA's own What's New feed, checked on 27 August, shows circulars dated 25 and 26 August on other subjects and nothing on KRA integration.
The date problem nobody has flagged
Read the draft's three clauses together and they no longer line up.
- Integration with a KRA: within two months from the date of the circular.
- New clients: KYC uploaded for everyone onboarded on or after 1 September 2026.
- Existing active clients: uploaded on or before 30 October 2026.
Those dates were drafted in June, when a July notification would have made them coherent. It is now late August. If the circular is notified in, say, mid-September, the new-client trigger date has already passed on the day the obligation begins, and the two-month integration window closes in November — after the 30 October backfile deadline it was supposed to precede.
Something has to move. IFSCA may re-date the milestones on notification, or hold 1 September and treat integration as the thing that must catch up. Either way the work does not change, and it is the work that takes time. Entities that wait for the notified text to start scoping will be doing a data migration under a compressed clock.
Who this actually applies to
We analysed the full IFSCA directory of regulated entities to size the population. Excluding schemes and products — an AIF scheme is not a separate integrator, its Fund Management Entity is — the count of client-facing entities that would need their own KRA connection comes to roughly 682:
| Category | Entities |
|---|---|
| Fund Management Entities (Registered, Authorised, Retail and Non-Retail) | 227 |
| Capital Market Intermediaries (broker dealers, clearing members, DPs, distributors, investment advisers) | 220 |
| Finance Companies and Finance Units | 101 |
| Banking (IBUs) | 45 |
| IFSC Insurance Offices | 39 |
| IFSC Insurance Intermediary Offices | 34 |
| Payment Service Providers and Payment System Providers | 10 |
| Market Infrastructure Institutions | 6 |
Behind those 227 FMEs sit a further 421 schemes — Category I, II and III AIFs, retail schemes, PMS and angel funds — whose investors are the records that actually have to move.
Two qualifications. The mandate does not apply to activities and entities exempted under the IFSCA (Anti Money Laundering, Counter-Terrorist Financing and Know Your Customer) Guidelines, 2022, so the real in-scope number is somewhat lower. And the directory is a point-in-time snapshot; IFSCA's own homepage cites 1,147 final registrations and authorisations as at March 2026, on a different basis.
The concentration is the part worth sitting with. Several hundred entities, most of them small, need to connect to one registered KRA — possibly two. Fund managers had already asked IFSCA to expand KRA presence in GIFT before any of this was proposed.
What integration actually requires
Every advisory published on this so far has restated the timeline. Here is the part that determines whether you make it.
1. Field mapping is the long pole
Your KYC record today is shaped by whatever you built it for. The KRA record is shaped by the IFSCA AML/CFT/KYC Guidelines, 2022 — prescribed proof of identity and proof of address, entity-type-specific fields, risk categorisation. The gap between those two shapes is where the work lives, and you cannot estimate it from a circular. You estimate it by pulling ten real client records and attempting the mapping by hand. Do that this week. Whatever it tells you, multiply.
2. The path is download-verify-update, not upload
The draft is specific: where a client's KYC already exists in the KRA system, you download it, verify it, and upload modifications so the latest information is on record. That is three operations with a decision in the middle, not a one-way push. Build it as a fetch-compare-patch flow. If you build it as an upload, you will overwrite another entity's more recent record, and that is a supervisory problem rather than a bug.
3. Three working days is a system requirement
Regulation 25(1) gives you three working days from completion of KYC to upload. If any part of your verification is asynchronous — a document check in review, a video KYC awaiting a slot, an EDD case with a compliance officer — then “completion” is an event your system has to detect and act on, not a step in someone's checklist. You need durable state, a retry path, and an alert when the clock is running out. A spreadsheet and good intentions will hold until your first busy week.
4. A UIN is a lookup key, not a verdict
The unique identification number the KRA assigns lets you find a client's existing record. It does not discharge your obligation to be satisfied with that record. Risk categorisation, screening and enhanced due diligence remain yours. Treat the UIN as the input to your decision, not the output.
5. The backfile is bigger than the new flow
New-client integration touches one path in your onboarding code. Migrating every active client onboarded before the cutoff touches your entire historical book — records captured under older policies, in inconsistent formats, some with documents that were adequate then and are not now. This is the deadline people miss. Start the extract now, even if the circular moves.
6. Sequence your lookups, cheapest first
With SEBI's 20 August circular, an Indian-resident client may already be KYC-verified in the domestic KRA ecosystem. Checking that before commissioning a fresh document-and-biometric verification is the difference between a lookup and a full verification, per client, across your book. The same logic runs through CKYC and, for eligible flows, Aadhaar-based e-KYC via NPCI's Setu platform, which IFSCA has made available to entities in the IFSC. Ordering these checks correctly is not a compliance nicety; it is most of your onboarding cost.
What to do in the next two weeks
- Confirm whether you are exempt under the AML/CFT/KYC Guidelines, 2022. Do this first — it determines everything else.
- Contact CVL's IFSC branch and start the POS access process. Access takes time you do not control.
- Hand-map ten real client records to the KRA schema and record how long it took.
- Count your active pre-cutoff clients. That number is your migration project.
- Decide who owns the three-working-day clock, and how they will know when it starts.
- Watch IFSCA's What's New for the notified circular, and re-check the dates against the draft when it lands.
Where Omnified fits
We are building a vendor-neutral orchestration layer for cross-border KYC: one API that resolves the applicable rulebook for a jurisdiction, routes each check to the appropriate verification rail, and returns a normalised verdict with a regulator-ready audit trail. GIFT IFSC is one of our first two corridors.
For this specific problem, the shape we think is right is KRA-first: look for an existing record before commissioning any fresh verification, run the download-verify-update path when one exists, and hold the three-working-day upload obligation in the platform rather than in someone's calendar. We hold no KYC repository of our own and have no plans to build one. The KRA is the system of record; we route to it.
We are resident at the GIFT International Fintech Innovation Hub, and our application for admission to the IFSCA sandbox is in process. If you are working through KRA integration and want to compare notes on the schema mapping, we would like to hear from you.
Frequently asked questions
When is the IFSCA KRA integration deadline?
Under the draft circular, KYC for new clients onboarded on or after 1 September 2026 must be uploaded to a KRA, and records for existing active clients by 30 October 2026, with integration completed within two months of the circular's date. The circular had not been notified as of 27 August 2026, so these dates may shift.
Which KRAs are registered with IFSCA?
CDSL Ventures Limited (CVL) is registered as an IFSC KRA, dated 4 February 2026. CAMS Investor Services announced IFSCA approval in July 2026. Check IFSCA's directory of regulated entities for the current list before relying on any count.
Does my entity have to integrate with a KRA?
If you are an IFSCA-regulated entity that onboards clients, most likely yes. Activities and entities exempted under the IFSCA (AML, CFT and KYC) Guidelines, 2022 are outside the mandate. Check your specific activity against the guidelines.
Can I use a SEBI-registered KRA instead of an IFSCA-registered one?
Since SEBI's 20 August 2026 circular, IFSCA-regulated entities can access SEBI-registered KRA systems for conducting client KYC. That is an access right for undertaking KYC; it is separate from the draft IFSCA circular's requirement to integrate with an IFSCA-registered KRA. Read them as complementary, not substitutable.
What is the UIN?
A unique identification number the KRA assigns to each client, allowing verified KYC credentials to be reused across regulated entities in GIFT IFSC without repeating the process.
How long do I have to upload a completed KYC?
Three working days from completion, under Regulation 25(1) of the IFSCA (KYC Registration Agency) Regulations, 2025.
Sources
- IFSCA — What's New (checked 27 August 2026)
- IFSCA — Directory of Regulated Entities
- IFSCA — AML, CFT and KYC Compliance
- Consultation paper on integration of Regulated Entities with KRAs, 26 June 2026 — summary
- SEBI permits IFSCA-regulated entities to access KRA records, 20 August 2026
- CVL KRA (IFSC) — access and process
Entity counts are our own analysis of the IFSCA directory of regulated entities and reflect a point-in-time snapshot. This post is not legal or compliance advice. Verify the notified circular text and your own exemption status before acting.
See the orchestration engine in action.
Interactive demo — no signup, no real data.

