PAN verification is the check a regulated entity runs against the Income Tax Department’s records to confirm that a Permanent Account Number exists, is operative, and matches the customer’s name and date of birth. It is different from PAN card KYC, which is the process an individual completes with a bank or KYC Registration Agency to become KYC compliant.
For banks, NBFCs and fintechs, the PAN check sits inside almost every onboarding journey, from savings accounts and personal loans to demat accounts and insurance policies. It is one of the cheapest checks in the stack and one of the most misunderstood. This guide covers how PAN verification works, what the check actually returns, how to handle name mismatches and inoperative PANs, and where a PAN check stops being enough on its own.
What is PAN verification?
PAN verification confirms a PAN against the issuing authority’s database. The regulated entity sends the PAN, the customer’s name and date of birth through an authorised channel, and receives the PAN’s status along with match results for the name and date of birth. It proves the record is real and consistent with what the customer declared.
A PAN is the 10-character alphanumeric identifier the Income Tax Department issues to taxpayers: individuals, companies, partnership firms, trusts, Hindu Undivided Families and other entities. Because every individual and business that earns, borrows or invests in India above certain thresholds is expected to hold one, PAN has become the common thread across credit bureaus, KYC registries and tax reporting.
Two terms get used interchangeably and shouldn’t be. PAN verification is the business-side check: a bank or lender confirming the PAN a customer gave them. PAN card KYC is the customer-side process: an individual completing KYC with a bank, broker or KRA using their PAN as one of the documents. This guide is about the first, with a short section on the second for individuals checking their own status.
Why do banks, NBFCs and fintechs have to verify PAN?
Indian KYC rules require it. The PML Rules and RBI’s KYC Directions require regulated entities to obtain a customer’s PAN, or a Form 97 declaration where the customer has none, and RBI expects PAN details to be verified from the issuing authority’s database. Beyond compliance, PAN anchors credit underwriting, tax deduction and fraud checks.
The obligation shows up in several places. RBI’s KYC Directions ask regulated entities to obtain PAN at account opening, or a declaration from customers without one. Under the Income-tax Rules, 2026, that declaration is Form 97, which replaced Form 60 from 1 April 2026 and covers a narrower set of transactions, with Form 98 used by the receiving entity to report them. When RBI introduced Video-based Customer Identification Process (V-CIP) in January 2020, it added that PAN details captured during the call must be verified from the issuing authority’s database. SEBI-registered intermediaries face a parallel expectation, since PAN is mandatory for KYC records held by KYC Registration Agencies.
There are business reasons too. A lender pulls bureau data against the PAN, so a wrong PAN means underwriting the wrong person. A PAN that turns out to be inoperative changes how tax is deducted on interest payouts. And because PAN card images are easy to edit, a PAN that has never been checked against the source is an open door for fabricated identities.
What is the difference between PAN validation, PAN verification and PAN authentication?
PAN validation checks that a number is well formed. PAN verification checks that it exists in the issuing authority’s records and matches the customer’s details. Binding the PAN to the person, through face match and liveness, checks that the customer presenting the PAN is its holder. Reliable onboarding uses all three, in that order.
| Check | What it confirms | How it is done | What it misses |
|---|---|---|---|
| Format validation | The PAN is structurally correct | Pattern check on the 10 characters, including the holder-type character | Whether the PAN exists or belongs to this customer |
| Database verification | The PAN exists, its status, and whether name and date of birth match | Lookup through an authorised channel such as Protean’s online PAN verification or a vendor API | Whether the person onboarding is the PAN holder |
| Binding to the person | The applicant is the holder of the PAN | Face match against a trusted photo source, liveness detection, or a video KYC call | Nothing about PAN status on its own |
Format validation is worth doing first because it is free and instant. A PAN has five letters, four digits and a final letter. The fourth character shows the holder type: P for an individual, C for a company, H for a Hindu Undivided Family, F for a firm or LLP, T for a trust, A for an association of persons, B for a body of individuals, L for a local authority, J for an artificial juridical person and G for government. For individuals, the fifth character is the first letter of the surname. A check on these rules catches typos and obvious fabrications before you spend an API call on them.
Database verification is where most teams stop, and the third check is where most fraud gets through. We come back to that below.
How does PAN verification work, step by step?
A PAN verification flow captures the PAN, validates its format, queries the issuing authority’s records through an authorised channel, compares the name and date of birth, checks operative and Aadhaar-seeding status, and then confirms the applicant is the holder. Each result is logged so the decision can be explained to an auditor later.
- Capture the PAN: The customer types it, uploads a card image for OCR, or shares an issued e-PAN through DigiLocker. A document fetched from DigiLocker comes from the issuer, so it removes the risk of an edited image. Where the card is shown on a V-CIP call, RBI expects a clear image to be captured unless the customer provides an e-PAN.
- Validate the format: Reject malformed numbers and check that the holder-type character fits the journey. A company PAN in a retail savings account flow is worth a second look.
- Query the issuing authority’s records: Send the PAN, name and date of birth through an authorised channel. For an entity, the date of incorporation replaces the date of birth.
- Compare name and date of birth: The response tells you whether each matches. Decide in advance which combinations pass, which go to review and which fail.
- Check operative and seeding status: An inoperative PAN or a missing Aadhaar link changes what happens next, as covered below.
- Bind the PAN to the person: Match the applicant’s selfie against a trusted photo, such as the photo returned by Aadhaar eKYC, and run liveness detection. For V-CIP, the official confirms the face on the call matches the Aadhaar or PAN photo.
- Decide and log: Route the case to straight-through approval, manual review or rejection, and store the request, response and timestamps for audit.
What does a PAN verification check return?
Through Protean’s online PAN verification service, a check on PAN, name and date of birth returns the PAN’s status, whether the name matches, whether the date of birth or incorporation matches, and the Aadhaar-PAN linking status. The response confirms or denies each match rather than handing back the holder’s full record.
Status values cover the cases a risk team cares about: a PAN that exists and is valid, a PAN that is not found or invalid, a deactivated PAN, and a PAN flagged as fake. For checks made by state commercial tax departments, the father’s name is an additional input and match result.
The match-flag design has a practical consequence. Because the service says yes or no rather than returning the name on record, the quality of your input decides the quality of your answer. A name keyed in by the customer with a typo, or read badly by OCR, will produce a mismatch on a perfectly genuine PAN. That is why capture and normalisation matter as much as the lookup itself.
Which PAN verification channels can regulated entities use?
Eligible entities can use Protean’s online PAN verification service, which the Income Tax Department authorised, in three modes: screen-based, file and screen-based for bulk checks, and software-based through an API. Individuals can check one PAN at a time on the e-filing portal. Most banks and fintechs reach these sources through a verification vendor’s API.
| Channel | Who uses it | Volume | Best for |
|---|---|---|---|
| Protean screen-based verification | Authorised entities | One PAN at a time | Occasional manual checks by operations teams |
| Protean file and screen-based verification | Authorised entities | Batches | Bulk PAN verification of an existing customer base |
| Protean software (API) verification | Authorised entities | Real time | Onboarding journeys built in-house |
| Income Tax e-filing ‘Verify Your PAN’ | Individuals and taxpayers | One PAN at a time | Personal checks, not production onboarding |
| Verification vendor API | Banks, NBFCs, fintechs, brokers, insurers | Real time and batch | Onboarding with orchestration, fallbacks and audit logs in one integration |
When is bulk PAN verification useful?
Bulk checks earn their keep on the back book. Typical uses include re-KYC campaigns, cleaning legacy records captured before digital checks were in place, sweeping for PANs that have become inoperative ahead of a tax deduction cycle, and onboarding merchant or distributor lists in one go. Running these in batches keeps the real-time channel free for live customers.
How should you handle PAN name mismatches?
Most PAN name mismatches trace back to how the name was captured: initials, salutations, spelling variants, surname changes after marriage and transliteration. Normalise names before the call, set a fuzzy-match threshold for near misses, and send only genuine conflicts to manual review. Treat a date of birth mismatch more seriously than a name mismatch.
| Cause | Example | How to handle it |
|---|---|---|
| Initials | R. Kumar against Rajesh Kumar | Expand or compare on surname plus initial; common in South Indian naming |
| Salutations | Mr, Dr, Smt or Shri in the captured name | Strip honorifics before sending the request |
| Name order | Surname written first | Compare tokens regardless of order |
| Change after marriage | New surname in the application, old one on PAN | Ask for the name as it appears on PAN; capture both if your policy allows |
| Transliteration | Mohammed and Mohammad, Lakshmi and Laxmi | Phonetic or edit-distance matching within a set threshold |
| Entity suffixes | Pvt Ltd against Private Limited | Standardise legal suffixes before comparison |
The problem should shrink over time. Under the Income-tax Rules, 2026, new PAN applications and corrections must carry the name exactly as it appears on Aadhaar, and the Aadhaar name is what gets printed on the card. Older PANs issued before the change will keep producing mismatches for years, so matching logic still matters. The cleanest fix is upstream. If the name comes from OCR of the card, or from an issued document via DigiLocker, rather than from a free-text field, many mismatches never happen. When they do, a short prompt asking the customer to confirm their name exactly as it appears on their PAN recovers most genuine applicants without a call centre in the loop.
“In our experience, most PAN checks that fail on the name belong to genuine customerswhose name was simply captured differently: an initial instead of a full name, a salutation left in, a spelling that shifted in transliteration. Treating every mismatch as a red flag sends good customers to a review queue and does nothing to stop fraud. The fix sits at capture. Read the name from the card or from DigiLocker, normalise it before the lookup, and keep manual review for the cases that genuinely conflict.”
-Vignesh Krishnakumar, CTO and Co-founder, HyperVerge
What happens when a customer’s PAN is inoperative?
A PAN becomes inoperative when an individual required to link it with Aadhaar has not done so. The PAN still exists, but the holder faces consequences under income tax law, including higher tax deduction rates and blocked refunds. For a bank or lender, it is a reason to pause the journey and prompt the customer to link.
Individuals who held a PAN on 1 July 2017 and are eligible for Aadhaar had to link the two, with consequences of non-linking applying from 1 July 2023. Holders whose PAN was allotted using an Aadhaar Enrolment ID had a later deadline of 31 December 2025, after which unlinked PANs in that group became inoperative from 1 January 2026. Non-residents and people who are not Indian citizens are among the exempt categories. A PAN becomes operative again after the holder pays the late fee of ₹1,000 and completes the link.
The Aadhaar-seeding status in the verification response is the signal to act on. A practical policy is to let the customer know why the journey has paused, link them to the e-filing portal’s Link Aadhaar service, and hold the application rather than reject it. For SEBI intermediaries, it is worth knowing that KRAs moved records held back only for PAN-Aadhaar non-linkage from On Hold to KYC Registered in June 2024, so the effect on an investor’s KYC status is narrower than it once was.
Where does PAN verification fall short as a fraud control?
A PAN check confirms that a record exists and matches the details entered. It cannot tell you who entered them. Fraud rings work around it with real PANs belonging to mule account holders, stolen identity details and edited card images. Pair PAN verification with face match, liveness detection and bank account verification to close the gap.
Three patterns come up repeatedly. The first is the edited card: a genuine PAN number and name with a swapped photograph. The database check passes because the number is real, and only a face match against an independent photo, or a document fetched from the issuer, catches it. The second is the borrowed identity: a complete set of real details used by someone else. A fraudster with a real PAN and a borrowed face will pass a PAN check every time. The face match is where the borrowing shows.
The third is the mule. Here the PAN, the face and the person all line up, because the account holder is real and has rented out their identity. PAN verification has nothing to say about that. Signals from bank account verification, device and behaviour analytics, and post-onboarding monitoring do. Treat the PAN check as the foundation of the identity stack, then build the rest of the stack on top of it.
How can individuals check their PAN KYC status?
Investors can check their PAN KYC status on any SEBI-registered KYC Registration Agency’s website by entering their PAN. The status shows as KYC Validated, KYC Registered, KYC On Hold or KYC Rejected. Banks keep their own KYC records, so for a bank account, the bank is the place to check.
- Open a KRA website. CVL KRA, NDML KRA, CAMS KRA, KFintech KRA and DotEx KRA all show the status regardless of which KRA holds your record.
- Select KYC inquiry. Enter your PAN and the verification code shown on screen.
- Read your status. The result shows your current status and, for negative statuses, which detail needs fixing.
| Status | What it means | What to do |
|---|---|---|
| KYC Validated | Your identity, address and contact details have been verified with the source | Nothing. Your KYC works with any SEBI-registered intermediary |
| KYC Registered | Your KYC is on record but not every detail has been validated, often because it used a document other than Aadhaar | You can keep investing with existing intermediaries. A new one may ask you to complete KYC again |
| KYC On Hold | A detail failed validation, such as an unverified mobile number or email, or a document no longer accepted | Update the flagged detail through your intermediary or the KRA portal |
| KYC Rejected | Your KYC could not be accepted | Complete KYC again through any SEBI-registered intermediary |
Completing KYC again with Aadhaar as the address document is usually the quickest way to move to Validated. For the full rules behind these statuses, see our guide to SEBI KYC guidelines.
How does HyperVerge handle PAN verification?
HyperVerge runs the whole sequence in a single journey: OCR or DigiLocker capture, format validation, a direct lookup against NSDL records for regulated entities, name and date of birth matching with configurable thresholds, Aadhaar-seeding status, and face match with liveness when the journey needs the person bound to the PAN. Automated fallbacks keep the journey moving when a source slows down, and every request and response is logged for audit.
Get in touch with us for a quick demo if you want to check out our PAN verification flow in detail.



