WHEN KYC EXCLUDES: DISABILITY RIGHTS AND DIGITAL FINANCE

Devansh Awasthi, B.A. LL.B. (Hons.), III Year student at Dr. Ram Manohar Lohiya National Law University

Abstract

This blog argues that inaccessible digital Know Your Customer (“KYC”) systems are not isolated design flaws but barriers to financial inclusion. KYC is no longer merely the entry step to a financial institution; it is the gateway to banking, securities, insurance, social-service delivery and digital identity. To be excluded from verification is therefore to be excluded from full participation in economic life – a violation of the dignity that Article 21 protects. Drawing on the Rights of Persons with Disabilities Act, 2016 (“RPwD Act”) and Pragya Prasun v. Union of India, which held that access to digital services is part of the right to life, it argues that accessibility must shift from a matter of user experience to one of regulatory compliance, and that the “one-size-fits-all” KYC model must give way to a disability-inclusive, auditable and rights-based one.

Introduction 

The current model of digital KYC assumes a user who is tech-savvy, constantly online, and able to navigate biometric and video verification without difficulty. Many older, digitally inexperienced or disabled users find that every layer of verification becomes a barrier to financial participation, simply because it was not designed with their needs in mind.

A blind person may be unable to position their face correctly before the camera without auditory guidance. An acid-attack survivor may fail a facial recognition or liveness test, because the software was never trained to recognise faces altered by such injuries.

Time-limited One Time Passwords (“OTPs”), on-screen signatures and gesture prompts can disadvantage persons with motor disabilities, while fast-moving screens dense with instructions create real barriers for persons with cognitive disabilities. The common thread is that the verification step itself, not the user, is the point of failure.

This is not a mere inconvenience. KYC has evolved from a back-office compliance requirement into a precondition for accessing a wide range of services. A person who cannot complete it may be shut out of bank accounts, denied credit, insurance and pension products, and cut off from welfare entitlements increasingly routed through verified digital identity. Where identity verification is the gate to economic life, an inaccessible gate is exclusion from economic life.

A Constitutional, Not Technical, Problem

For this reason, the Supreme Court’s judgment in Pragya Prasun v. Union of India is significant. The petitions were brought by acid attack survivors with permanent facial and ocular disfigurement, and by Amar Jain, an advocate with complete blindness all of whom had been unable to clear the mandatory e-KYC ‘liveness’ checks (blinking, smiling or aligning the face before a camera) now standard across banking, insurance and telecom onboarding. The plaintiffs argued that the conditions imposed by each of the five banks excluded them from basic services, in violation of both the RPwD Act and the Constitution.

On 30 April 2025, the ruling read Article 21 in three ways for a digital economy: (a) recognising the role digital platforms play in delivering essential services, (b) treating digital access as part of the right to life with dignity, and (c) holding that exclusion from verification is a constitutional injury, not a mere commercial inconvenience.

Second, it subjected the State’s own justification to a proportionality analysis identity verification under the Prevention of Money Laundering Act, 2002 is a legitimate aim, but blink-based ‘liveness’ was not the least restrictive means of achieving it, since voice prompts, OTPs, thumb impressions and human-assisted review can confirm identity without excluding disabled users. Third, and most consequentially for regulators, it treated the RPwD Act as a ‘super-statute’ whose accessibility mandate building on Rajive Raturi v. Union of India, where accessibility was recognised as a cross-cutting right under Articles 14 and 21 overrides subordinate sectoral regulation, reading down the permissive framing of Rule 15 of the RPwD Rules so that ICT accessibility becomes obligatory rather than aspirational.

Crucially, the Court did not stop at declaration. It issued some twenty directions to the Union Government, the Reserve Bank of India, the Securities and Exchange Board of India (“SEBI”), the Insurance Regulatory and Development Authority, the Department of Telecommunications and other regulators, requiring them to redesign KYC in line with recognised accessibility standards, offer non-visual ‘liveness’ alternatives, accept thumb impressions as signatures, retain paper-based and assisted KYC for those who need it, conduct periodic accessibility audits, and establish nodal officers and grievance-redressal mechanisms. The significance lies less in any single direction than in the shift of register: accessibility moves from welfare gesture to enforceable legal obligation.

The False Neutrality of Uniform Verification

The usual defence of exclusion is formal neutrality – everyone takes the same steps. But disability rights law is built on the insight that identical treatment is not equal treatment. A rule that is neutral on its face can discriminate in effect when it is built on able-bodied assumptions, and the constitutional commitment to substantive equality under Articles 14 and 15reaches precisely this kind of disparate impact. The RPwD Act makes the response mandatory, binding every system to non-discrimination, reasonable accommodation and accessibility. The lawfulness of a verification system therefore turns on a single question: whether its design builds in reasonable accommodation. A system that excludes millions of users for want of it is not neutral, it is exclusion by design.

Accommodation and Regulatory Compliance

The RPwD (Amendment) Rules, 2023 established IS 17802 as a national accessibility benchmark for ICT products and services, binding on public and private entities alike. SEBI’s circular dated July 31, 2025 requires every regulated entity to make its digital services, KYC included, compliant with the RPwD Act, the Web Content Accessibility Guidelines(WCAG) and IS 17802, with audits that involve usability testing by persons with disabilities. The need is not marginal: India’s last census recorded more than 26 million persons with disabilities, the World Health Organisation estimates that nearly 16% of the world’s population lives with some form of disability, and in February 2025 the Chief Commissioner for Persons with Disabilities fined more than 150 establishments, including several central ministries, for failing to provide accessible services.

Yet a gap remains. The judgment mandated accessible alternatives but left the technical specifications and the monitoring mechanism to the regulators, and that is where compliance will be won or lost. A standard that exists on paper but is never audited or enforced changes nothing; the regulator’s task now is enforcement, not further norm-setting.

The Privacy Dimension

A privacy cost attaches to inaccessibility. If a user cannot verify their identity independently, they must route the process through a family member, agent or support staff, which requires handing that person access to their documents, passwords and biometric data. In other words, the information can no longer be kept private. By compelling persons with disabilities to surrender their privacy, a platform that defends rigid KYC as a security measure turns its own justification on its head. The damage is twofold: it strips the user of dignity and it exposes the institution to legal liability. The Digital Personal Data Protection Act, 2023 is premised on consent that is free, informed, specific and unambiguous. A person who cannot independently read a consent screen, and must rely on a third party to click through it, cannot give consent of that quality; accessible verification is therefore a precondition for valid consent and for the autonomy the RPwD Act guarantees. Inaccessible KYC does not merely make it harder for persons with disabilities to verify their identity. It makes them forfeit their right to privacy as the price of access.

A Rights-Based Model

A rights-based response need not be idealistic. The barriers persons with disabilities face in KYC verification can be met by five enforceable obligations:

  1. Accessibility by design. KYC systems must build in accessibility from the outset and test it continuously against assistive technologies, rather than re-engineering it only after complaints.
  2. Alternative routes as a right. Persons with disabilities must be entitled to verify their identity through alternative methods – assisted verification, audio-guided onboarding, in-person verification or document-based alternatives – as of right, not as a discretionary exception.
  3. Participation in audits. Persons with disabilities must be meaningfully involved at every stage of the audit process, as SEBI’s framework already requires through usability testing.
  4. Time-bound resolution. Verification failures must be resolved within a fixed timeline by officers trained to assist disabled customers, so that exclusion is never left open-ended.
  5. Penalties for repeated non-compliance. Without real penalties for persistent breaches, no meaningful change will follow.

Conclusion

The future of disability rights will be decided not only in courtrooms, but in KYC applications, verification flows and compliance audits. If the systems on which we rely do not acknowledge all bodies, faces and voices as equally valid, these systems cannot be classified as neutral; they are exclusionary by design. KYC was meant to identify the individual; yet, as it operates today, it indirectly identifies only the user’s ability to participate within normal society. The key question is not “how can we make the user more able?” but rather “how can we redesign the gate?