Compliance · UIDAI AUA/KUA Audit Aadhaar Act 2016 · Data Security Regulations 2016 · CERT-In Empaneled

UIDAI AUA/KUA Compliance Security Audit

If your organisation performs Aadhaar authentication or e-KYC — or stores Aadhaar numbers — UIDAI expects you to prove, through an independent information security audit, that the Aadhaar data you touch is genuinely protected. As a CERT-In empaneled assessor, Intect conducts that audit and validates the controls that matter — the Aadhaar Data Vault, tokenisation, encryption and access — the way an attacker would test them, so the compliance you report to UIDAI is earned, not assumed.

CERT-In Empaneled. Aligned to the Aadhaar Act 2016 and the Aadhaar (Data Security) Regulations 2016. We test the controls we audit.

Aadhaar Act 2016 Aadhaar (Data Security) Regulations 2016 Authentication & Offline Verification Regulations 2021 CERT-In Empaneled
Audit type
UIDAI-mandated information security audit — not a certification
Who
AUA · KUA · Sub-AUA · ASA — and any agency storing Aadhaar numbers
Auditor
CERT-In Empaneled — the credential UIDAI requires
Validation
VAPT-backed technical control validation
02

The audit UIDAI expects — done so it actually holds up

The Aadhaar authentication ecosystem runs on trust. When an organisation becomes an Authentication User Agency (AUA) or e-KYC User Agency (KUA), it gains the ability to verify a resident's identity against UIDAI's Central Identities Data Repository — and, with that, custody of some of the most sensitive identity data in the country. The Aadhaar Act and its regulations answer that responsibility with a clear obligation: requesting entities and their service agencies must get their operations audited by a certified information systems auditor and furnish the report to UIDAI.

In practice, UIDAI requires that this audit be carried out by a CERT-In empaneled information security auditor, against UIDAI's own information security policy for the Aadhaar external ecosystem. The audit is not a formality. It examines whether the data-protection controls UIDAI mandates are real and working — that the Aadhaar Data Vault exists and is restricted, that Aadhaar numbers are tokenised behind reference keys, that PID blocks are encrypted in transit, that biometrics and PID are never stored, and that access and logging are controlled. A UIDAI compliance audit is how a requesting entity demonstrates — to UIDAI and to its own board — that it has earned the right to handle Aadhaar.

"A policy that says 'we tokenise Aadhaar numbers' is a claim. A vault we have probed, and a reference-key scheme we have tried to reverse, is assurance. UIDAI — and your board — should be able to tell the difference."
03

Where you sit in the ecosystem — and what you must protect

UIDAI's obligations attach to your role in the authentication ecosystem. Most organisations are an AUA or a KUA; many work through Sub-AUAs and connect via an ASA.

Wherever you sit, the same family of data-protection controls follows the Aadhaar number — and the same audit obligation follows you. We scope every engagement to the role, and the controls, that actually apply to you.

Different roles, one shared duty: protect the Aadhaar number and the identity data around it — with a Data Vault, tokenisation, encryption, no biometric storage, access control, logging, and a periodic audit by a CERT-In empaneled auditor.

04

The instruments this audit is built on

We anchor every engagement to the live UIDAI and Aadhaar text — so the audit you submit is current, defensible and mapped to the right source.

The Aadhaar Act, 2016

Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016).

The parent statute. It defines authentication and requesting entities, requires the security and confidentiality of identity information, restricts the sharing and use of Aadhaar data, and carries penalties for unauthorised access to or disclosure of identity information. Every control in the audit traces back to a duty under this Act.

Aadhaar (Authentication and Offline Verification) Regulations, 2021

The operating rules for the ecosystem — defining the AUA, KUA, Sub-AUA and ASA roles, the obligations of requesting entities, restrictions on storing PID and biometric data, and the maintenance of authentication logs. (These superseded the original Aadhaar (Authentication) Regulations, 2016.)

Aadhaar (Data Security) Regulations, 2016

The data-security backbone. Regulation 3 empowers UIDAI to specify an information security policy; Regulation 5 sets the security obligations of service providers; and Regulation 6 requires requesting entities, AUAs and ASAs to get their operations audited by a certified information systems auditor and furnish the report to UIDAI. This is the audit your organisation must produce.

CERT-In empanelment

UIDAI's information security policy and audit checklists require the audit to be performed by a CERT-In empaneled auditor. CERT-In empanelment is the recognised credential for this work — and Intect is CERT-In empaneled.

05

How a UIDAI compliance audit runs

A disciplined, evidence-led path from scoping to UIDAI submission — built so your team always knows where the audit stands and what to act on next.

01
Scoping
Confirm your role (AUA / KUA / Sub-AUA / ASA), the systems and environments in scope, the UIDAI checklist that applies, and what "compliant" looks like for each mandated control.
02
Architecture & Data-Flow Review
Map exactly where Aadhaar numbers, PID blocks, biometric data and e-KYC responses are captured, transmitted, processed and stored — so the audit follows the data, not just the documentation.
03
Control Testing
Test the mandated controls in operation (Vault / Tokenisation / Crypto / Access): the Aadhaar Data Vault and its network isolation, reference-key tokenisation, encryption of PID and stored Aadhaar data, no-storage of biometrics and PID, access control on the vault, and audit logging.
04 · VAPT
Technical Validation (VAPT)
Independently validate the controls by attacking them — vulnerability assessment and penetration testing of the Aadhaar-handling applications, APIs and infrastructure, so exposure of Aadhaar data is proven, not assumed.
05
Gap Analysis vs UIDAI Policy
Measure each finding against the applicable UIDAI checklist control, the Data Security Regulations and the Aadhaar Act, assign severity and risk, and separate true gaps from documentation issues.
06
Reporting
Deliver the UIDAI-format compliance report plus a clear, prioritized findings report — written for the engineers who will remediate and the leadership accountable for the risk, with evidence and concrete guidance.
07
Remediation
Work alongside your team as fixes are implemented — vault isolation, tokenisation, key management, access reviews — clarifying control intent so you close findings correctly the first time, then re-verify.
08
UIDAI Submission / Closure
Finalise the certified audit report for furnishing to UIDAI, confirm remediation is evidenced, and establish the cadence for the next periodic audit.

FIG. 02 — UIDAI audit lifecycle · 01–03 scope & test · 04 technical validation (the offensive edge) · 05–08 gap, report, remediate, submit

06

What we audit against

Our coverage maps to the controls UIDAI mandates for the Aadhaar external ecosystem — set out in the Aadhaar (Data Security) Regulations, the information security policy for AUAs/KUAs/Sub-AUAs, and UIDAI's AUA/KUA and ASA audit checklists. Across an engagement we systematically examine the following:

01 Aadhaar Data Vault A single, centralised, encrypted store for Aadhaar numbers and related data, kept in a highly restricted network segment with access strictly on a need-to-know basis — and never co-located with general business systems.
UIDAI Aadhaar Data Vault FAQ · Dec 2017
02 Tokenisation & Reference Keys Aadhaar numbers replaced everywhere in your ecosystem by unique reference keys, with the reference-key-to-Aadhaar mapping held only in the vault — and reference keys generated so the original number cannot be guessed or reverse-engineered.
UIDAI tokenisation circular K-11020/205/2017
03 Encryption & Key Management (HSM) Encryption of PID blocks in transit and of Aadhaar data at rest, with encryption keys protected in a FIPS 140-2 compliant HSM that is not shared across legal entities.
ASA Audit Compliance Checklist V3.0 · Nov 2022
04 No Storage of Biometrics & PID Verification that biometric data, OTP and the encrypted PID block are not retained on any permanent storage, consistent with the Aadhaar Act and the regulations.
Aadhaar Act 2016 · Sec 29
05 Access Control & Segregation Role-based, least-privilege access to the vault and Aadhaar-handling systems; segregation of the Aadhaar environment from the rest of the network; and controlled physical and logical access.
Aadhaar (Data Security) Regulations 2016 · Reg. 5
06 Logging, Audit Trail & Retention Authentication and access logs maintained and retained for the periods the regulations require, monitored for unauthorised use, with reference keys (not Aadhaar numbers) stored in logs.
Authentication & Offline Verification Regulations 2021
07 Secure Connectivity & Network Security Secure channels between AUA, ASA and CIDR (leased lines / TLS), network partitioning, and protection of the Aadhaar-handling perimeter.
ASA Audit Compliance Checklist V3.0
08 Information Security Policy & Governance A board-approved information security and data-privacy policy aligned to UIDAI's requirements, defined ownership, change and patch management, and incident reporting.
Aadhaar (Data Security) Regulations 2016 · Reg. 3
09 Sub-AUA & Third-Party Governance Due diligence and contractual security obligations over Sub-AUAs and service providers, and accountability for their compliance, since the AUA remains responsible for its Sub-AUAs.
Authentication & Offline Verification Regulations 2021 — Sub-AUA role
07

We don't just read your Aadhaar policy. We test the vault.

A document-only audit confirms that a control exists. An attacker doesn't care whether it exists — only whether it holds. With Aadhaar data, that difference is the whole point.

Confirms the claim

The document-only audit

A traditional UIDAI compliance audit reads your information security policy, interviews owners, and ticks the checklist to confirm that a Data Vault, tokenisation and encryption are "in place." It is necessary work — and it is where most audits stop. But a policy that says Aadhaar numbers are tokenised, and a reference-key scheme that an attacker can actually reverse, are not the same thing — and the gap between them is exactly where Aadhaar data leaks.

Proves the control

The technically validated audit

Intect comes from offensive security. So where it matters, we validate the controls by testing them — probing the Aadhaar Data Vault's isolation and access, attempting to reach Aadhaar numbers from the application tier, testing whether reference keys can be reversed, and pressure-testing the encryption and key handling with vulnerability assessment and penetration testing. You get findings backed by proof of real exposure, not a checklist of assertions — and a UIDAI report you can stand behind because it has been earned.

We are CERT-In empaneled, so the audit is the one UIDAI accepts — and we come from offensive security, so it is technically validated. With Aadhaar data, that combination is the point.

VAPT-BACKED VALIDATION
08

What you receive

Every engagement ends in an audit your team can act on and your organisation can furnish to UIDAI — written for the engineers who will remediate and the leadership accountable for the risk.

01

UIDAI compliance audit report

A certified report in the UIDAI/CERT-In format, covering each mandated control, compliance status and evidence, suitable for furnishing to UIDAI.

02

Detailed findings & risk report

Every gap with severity, risk and a clear remediation path, mapped to the applicable UIDAI checklist control, the Data Security Regulations and the Aadhaar Act.

03

Aadhaar data-flow & control map

A documented view of where Aadhaar numbers, PID and biometric data live and move across your systems — valuable well beyond the audit.

04

Technical validation evidence (the offensive edge)

VAPT findings with reproducible proof-of-concept and demonstrated impact, so control failures around the vault, tokenisation and crypto are evidenced, not asserted.

VAPT-BACKED
05

Remediation roadmap & re-audit

Prioritized, specific guidance; support through remediation; and re-verification so closure is evidenced before submission.

06

Direct assessor access

A debrief with the people who performed the audit, not a handoff to a call centre.

CERT-In Empaneled Aadhaar Act 2016 Aadhaar (Data Security) Regulations 2016 Aadhaar Data Vault Tokenisation VAPT-backed validation
09

Why requesting entities choose Intect

CERT-In Empaneled Researcher-led · offensive heritage

CERT-In Empaneled — The credential UIDAI requires for this audit. Real and regulator-recognised — so the report you furnish to UIDAI, and the technical validation behind it, are accepted where it counts.

Offensive heritage — We come from penetration testing and red teaming. We audit the Aadhaar Data Vault, tokenisation and encryption by testing them, surfacing the exposure a paper review misses.

Researcher-led, not checklist-led — Engagements are run by practitioners who understand both the UIDAI mandate and the adversary — so findings are accurate, contextual and defensible.

Delhi-based, regulation-fluent — An India-based team fluent in the Aadhaar Act, the UIDAI ecosystem and Indian data-protection supervision, available to your team through the engagement.

10

Frequently asked questions

Is the UIDAI AUA/KUA audit a certification?

No. It is an independent information security audit, not a certificate. It produces a certified audit report — which your organisation furnishes to UIDAI on request or at the periods UIDAI specifies — evidencing that your Aadhaar-handling controls comply with the Aadhaar Act, the Data Security Regulations and UIDAI’s information security policy. There is no "UIDAI certificate"; there is credible, independent compliance assurance.

Who is allowed to conduct it?

UIDAI requires the audit to be performed by a CERT-In empaneled information security auditor. Intect is CERT-In empaneled, so we can conduct the audit and the technical validation behind it.

How often do we need this audit?

The Aadhaar (Data Security) Regulations require requesting entities, AUAs and ASAs to get their operations audited and furnish the report to UIDAI upon request or at the periods UIDAI specifies; in practice this is run on an annual basis and on a need basis. We help you set a cadence that satisfies UIDAI and time engagements to your compliance calendar.

We only store Aadhaar numbers — we don't do live authentication. Are we in scope?

Likely yes. UIDAI requires any agency that stores Aadhaar numbers to implement an Aadhaar Data Vault and tokenisation, regardless of whether it is a live AUA/KUA. If you hold Aadhaar numbers, the data-security obligations — and an audit of them — apply to you. We confirm your exact scope during scoping.

What is the Aadhaar Data Vault, and do we have to have one?

The Aadhaar Data Vault is UIDAI's mandated model for storing Aadhaar numbers: a single, encrypted, access-restricted store, with every other system holding only a reference key (token) that maps back to the Aadhaar number inside the vault. If your systems store Aadhaar numbers, you must implement it. Our audit verifies the vault exists, is isolated, is encrypted with keys held in an HSM, and that no system outside it stores the Aadhaar number.

What happens if we are non-compliant?

The Aadhaar Act carries penalties — including imprisonment and fines — for unauthorised access to or disclosure of identity information, and UIDAI can act against ecosystem partners who fail their obligations, up to suspension of authentication services. The purpose of the audit is to find and close gaps before any of that is in question. We report factually and help you remediate.

What makes your audit different from a standard UIDAI audit?

We technically validate the controls we audit. Rather than confirming on paper that a Data Vault and tokenisation exist, we test whether they hold — probing the vault, attempting to reach Aadhaar numbers, and pressure-testing the encryption — using vulnerability assessment and penetration testing. You get assurance backed by proof, which is both stronger for your board and more defensible to UIDAI.

11

Related regulatory assurance

Aadhaar compliance rarely stands alone. If your organisation handles Aadhaar, it almost certainly handles other regulated personal data and reports to other regulators — and we cover those too.

Scope an engagement

Prove your Aadhaar controls. Satisfy UIDAI.

Tell us your role in the Aadhaar ecosystem and where you are in your UIDAI compliance cycle, and we'll scope an audit that fits — or connect you directly with an assessor.