News Summary:
Recent industry analyses indicate that banks and non-banking financial companies (NBFCs) are at the highest risk for compliance with the DPDP Act, particularly given their extensive processing of sensitive personal data such as KYC documents, transaction histories, and credit information across various complex systems. This assessment, published on August 21, 2026, emphasizes the involvement of core banking platforms, third-party KYC vendors, payment processors, and collection agencies. Earlier, on July 24, 2026, several industry guides focused on Video KYC (VKYC) in India, highlighting its status as the default expectation for digital onboarding among regulated financial institutions. These discussions explored how VKYC allows for remote customer identity verification at scale while aiming to maintain compliance and mitigate fraud. Related insights from the same day detailed that the primary threat to VKYC in 2026 stems from synthetic attacks, with fraudsters increasingly employing AI-generated faces, voice clones, and replayed video to circumvent verification processes using accessible deepfake technology. Further analysis from July 24, 2026, differentiated VKYC use cases and requirements across diverse financial entities, noting that a single VKYC flow is unsuitable for institutions ranging from banks onboarding thousands of customers daily to mutual funds with a few weekly new investors, as this can lead to drop-offs, compliance gaps, or undetected fraud. A pricing guide also published on July 24, 2026, highlighted the inconsistency in VKYC solution costs in India, attributing the lack of upfront pricing to the numerous variables that influence provider rates.