UIDAI AUA/KUA Compliance Security Audit
If your organisation performs Aadhaar authentication or e-KYC — or stores Aadhaar numbers — UIDAI expects you to prove, through an independent information security audit, that the Aadhaar data you touch is genuinely protected. As a CERT-In empaneled assessor, Intect conducts that audit and validates the controls that matter — the Aadhaar Data Vault, tokenisation, encryption and access — the way an attacker would test them, so the compliance you report to UIDAI is earned, not assumed.
CERT-In Empaneled. Aligned to the Aadhaar Act 2016 and the Aadhaar (Data Security) Regulations 2016. We test the controls we audit.
The audit UIDAI expects — done so it actually holds up
The Aadhaar authentication ecosystem runs on trust. When an organisation becomes an Authentication User Agency (AUA) or e-KYC User Agency (KUA), it gains the ability to verify a resident's identity against UIDAI's Central Identities Data Repository — and, with that, custody of some of the most sensitive identity data in the country. The Aadhaar Act and its regulations answer that responsibility with a clear obligation: requesting entities and their service agencies must get their operations audited by a certified information systems auditor and furnish the report to UIDAI.
In practice, UIDAI requires that this audit be carried out by a CERT-In empaneled information security auditor, against UIDAI's own information security policy for the Aadhaar external ecosystem. The audit is not a formality. It examines whether the data-protection controls UIDAI mandates are real and working — that the Aadhaar Data Vault exists and is restricted, that Aadhaar numbers are tokenised behind reference keys, that PID blocks are encrypted in transit, that biometrics and PID are never stored, and that access and logging are controlled. A UIDAI compliance audit is how a requesting entity demonstrates — to UIDAI and to its own board — that it has earned the right to handle Aadhaar.
"A policy that says 'we tokenise Aadhaar numbers' is a claim. A vault we have probed, and a reference-key scheme we have tried to reverse, is assurance. UIDAI — and your board — should be able to tell the difference."
Where you sit in the ecosystem — and what you must protect
UIDAI's obligations attach to your role in the authentication ecosystem. Most organisations are an AUA or a KUA; many work through Sub-AUAs and connect via an ASA.
Wherever you sit, the same family of data-protection controls follows the Aadhaar number — and the same audit obligation follows you. We scope every engagement to the role, and the controls, that actually apply to you.
AUA — Authentication User Agency — Sends Aadhaar authentication requests to CIDR via an ASA to enable its services.
KUA — e-KYC User Agency — An AUA that also uses UIDAI's e-KYC facility to fetch resident demographic data.
Sub-AUA — Uses an existing AUA's authentication facility under UIDAI authorization; the AUA remains accountable for it.
ASA — Authentication Service Agency — Provides secure connectivity to CIDR for requesting entities (leased line / MPLS), routing requests.
What every role must protect — verified in the audit
Different roles, one shared duty: protect the Aadhaar number and the identity data around it — with a Data Vault, tokenisation, encryption, no biometric storage, access control, logging, and a periodic audit by a CERT-In empaneled auditor.
The instruments this audit is built on
We anchor every engagement to the live UIDAI and Aadhaar text — so the audit you submit is current, defensible and mapped to the right source.
The Aadhaar Act, 2016
Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016).
The parent statute. It defines authentication and requesting entities, requires the security and confidentiality of identity information, restricts the sharing and use of Aadhaar data, and carries penalties for unauthorised access to or disclosure of identity information. Every control in the audit traces back to a duty under this Act.
Aadhaar (Authentication and Offline Verification) Regulations, 2021
The operating rules for the ecosystem — defining the AUA, KUA, Sub-AUA and ASA roles, the obligations of requesting entities, restrictions on storing PID and biometric data, and the maintenance of authentication logs. (These superseded the original Aadhaar (Authentication) Regulations, 2016.)
Aadhaar (Data Security) Regulations, 2016
The data-security backbone. Regulation 3 empowers UIDAI to specify an information security policy; Regulation 5 sets the security obligations of service providers; and Regulation 6 requires requesting entities, AUAs and ASAs to get their operations audited by a certified information systems auditor and furnish the report to UIDAI. This is the audit your organisation must produce.
CERT-In empanelment
UIDAI's information security policy and audit checklists require the audit to be performed by a CERT-In empaneled auditor. CERT-In empanelment is the recognised credential for this work — and Intect is CERT-In empaneled.
How a UIDAI compliance audit runs
A disciplined, evidence-led path from scoping to UIDAI submission — built so your team always knows where the audit stands and what to act on next.
FIG. 02 — UIDAI audit lifecycle · 01–03 scope & test · 04 technical validation (the offensive edge) · 05–08 gap, report, remediate, submit
What we audit against
Our coverage maps to the controls UIDAI mandates for the Aadhaar external ecosystem — set out in the Aadhaar (Data Security) Regulations, the information security policy for AUAs/KUAs/Sub-AUAs, and UIDAI's AUA/KUA and ASA audit checklists. Across an engagement we systematically examine the following:
01 Aadhaar Data Vault A single, centralised, encrypted store for Aadhaar numbers and related data, kept in a highly restricted network segment with access strictly on a need-to-know basis — and never co-located with general business systems.
02 Tokenisation & Reference Keys Aadhaar numbers replaced everywhere in your ecosystem by unique reference keys, with the reference-key-to-Aadhaar mapping held only in the vault — and reference keys generated so the original number cannot be guessed or reverse-engineered.
03 Encryption & Key Management (HSM) Encryption of PID blocks in transit and of Aadhaar data at rest, with encryption keys protected in a FIPS 140-2 compliant HSM that is not shared across legal entities.
04 No Storage of Biometrics & PID Verification that biometric data, OTP and the encrypted PID block are not retained on any permanent storage, consistent with the Aadhaar Act and the regulations.
05 Access Control & Segregation Role-based, least-privilege access to the vault and Aadhaar-handling systems; segregation of the Aadhaar environment from the rest of the network; and controlled physical and logical access.
06 Logging, Audit Trail & Retention Authentication and access logs maintained and retained for the periods the regulations require, monitored for unauthorised use, with reference keys (not Aadhaar numbers) stored in logs.
07 Secure Connectivity & Network Security Secure channels between AUA, ASA and CIDR (leased lines / TLS), network partitioning, and protection of the Aadhaar-handling perimeter.
08 Information Security Policy & Governance A board-approved information security and data-privacy policy aligned to UIDAI's requirements, defined ownership, change and patch management, and incident reporting.
09 Sub-AUA & Third-Party Governance Due diligence and contractual security obligations over Sub-AUAs and service providers, and accountability for their compliance, since the AUA remains responsible for its Sub-AUAs.
We don't just read your Aadhaar policy. We test the vault.
A document-only audit confirms that a control exists. An attacker doesn't care whether it exists — only whether it holds. With Aadhaar data, that difference is the whole point.
The document-only audit
A traditional UIDAI compliance audit reads your information security policy, interviews owners, and ticks the checklist to confirm that a Data Vault, tokenisation and encryption are "in place." It is necessary work — and it is where most audits stop. But a policy that says Aadhaar numbers are tokenised, and a reference-key scheme that an attacker can actually reverse, are not the same thing — and the gap between them is exactly where Aadhaar data leaks.
The technically validated audit
Intect comes from offensive security. So where it matters, we validate the controls by testing them — probing the Aadhaar Data Vault's isolation and access, attempting to reach Aadhaar numbers from the application tier, testing whether reference keys can be reversed, and pressure-testing the encryption and key handling with vulnerability assessment and penetration testing. You get findings backed by proof of real exposure, not a checklist of assertions — and a UIDAI report you can stand behind because it has been earned.
We are CERT-In empaneled, so the audit is the one UIDAI accepts — and we come from offensive security, so it is technically validated. With Aadhaar data, that combination is the point.
VAPT-BACKED VALIDATIONWhat you receive
Every engagement ends in an audit your team can act on and your organisation can furnish to UIDAI — written for the engineers who will remediate and the leadership accountable for the risk.
UIDAI compliance audit report
A certified report in the UIDAI/CERT-In format, covering each mandated control, compliance status and evidence, suitable for furnishing to UIDAI.
Detailed findings & risk report
Every gap with severity, risk and a clear remediation path, mapped to the applicable UIDAI checklist control, the Data Security Regulations and the Aadhaar Act.
Aadhaar data-flow & control map
A documented view of where Aadhaar numbers, PID and biometric data live and move across your systems — valuable well beyond the audit.
Technical validation evidence (the offensive edge)
VAPT findings with reproducible proof-of-concept and demonstrated impact, so control failures around the vault, tokenisation and crypto are evidenced, not asserted.
Remediation roadmap & re-audit
Prioritized, specific guidance; support through remediation; and re-verification so closure is evidenced before submission.
Direct assessor access
A debrief with the people who performed the audit, not a handoff to a call centre.
Why requesting entities choose Intect
CERT-In Empaneled — The credential UIDAI requires for this audit. Real and regulator-recognised — so the report you furnish to UIDAI, and the technical validation behind it, are accepted where it counts.
Offensive heritage — We come from penetration testing and red teaming. We audit the Aadhaar Data Vault, tokenisation and encryption by testing them, surfacing the exposure a paper review misses.
Researcher-led, not checklist-led — Engagements are run by practitioners who understand both the UIDAI mandate and the adversary — so findings are accurate, contextual and defensible.
Delhi-based, regulation-fluent — An India-based team fluent in the Aadhaar Act, the UIDAI ecosystem and Indian data-protection supervision, available to your team through the engagement.
Frequently asked questions
Is the UIDAI AUA/KUA audit a certification?
No. It is an independent information security audit, not a certificate. It produces a certified audit report — which your organisation furnishes to UIDAI on request or at the periods UIDAI specifies — evidencing that your Aadhaar-handling controls comply with the Aadhaar Act, the Data Security Regulations and UIDAI’s information security policy. There is no "UIDAI certificate"; there is credible, independent compliance assurance.
Who is allowed to conduct it?
UIDAI requires the audit to be performed by a CERT-In empaneled information security auditor. Intect is CERT-In empaneled, so we can conduct the audit and the technical validation behind it.
How often do we need this audit?
The Aadhaar (Data Security) Regulations require requesting entities, AUAs and ASAs to get their operations audited and furnish the report to UIDAI upon request or at the periods UIDAI specifies; in practice this is run on an annual basis and on a need basis. We help you set a cadence that satisfies UIDAI and time engagements to your compliance calendar.
We only store Aadhaar numbers — we don't do live authentication. Are we in scope?
Likely yes. UIDAI requires any agency that stores Aadhaar numbers to implement an Aadhaar Data Vault and tokenisation, regardless of whether it is a live AUA/KUA. If you hold Aadhaar numbers, the data-security obligations — and an audit of them — apply to you. We confirm your exact scope during scoping.
What is the Aadhaar Data Vault, and do we have to have one?
The Aadhaar Data Vault is UIDAI's mandated model for storing Aadhaar numbers: a single, encrypted, access-restricted store, with every other system holding only a reference key (token) that maps back to the Aadhaar number inside the vault. If your systems store Aadhaar numbers, you must implement it. Our audit verifies the vault exists, is isolated, is encrypted with keys held in an HSM, and that no system outside it stores the Aadhaar number.
What happens if we are non-compliant?
The Aadhaar Act carries penalties — including imprisonment and fines — for unauthorised access to or disclosure of identity information, and UIDAI can act against ecosystem partners who fail their obligations, up to suspension of authentication services. The purpose of the audit is to find and close gaps before any of that is in question. We report factually and help you remediate.
What makes your audit different from a standard UIDAI audit?
We technically validate the controls we audit. Rather than confirming on paper that a Data Vault and tokenisation exist, we test whether they hold — probing the vault, attempting to reach Aadhaar numbers, and pressure-testing the encryption — using vulnerability assessment and penetration testing. You get assurance backed by proof, which is both stronger for your board and more defensible to UIDAI.
Related regulatory assurance
Aadhaar compliance rarely stands alone. If your organisation handles Aadhaar, it almost certainly handles other regulated personal data and reports to other regulators — and we cover those too.
Prove your Aadhaar controls. Satisfy UIDAI.
Tell us your role in the Aadhaar ecosystem and where you are in your UIDAI compliance cycle, and we'll scope an audit that fits — or connect you directly with an assessor.