UIDAI AUA/KUA Audit: Aadhaar Ecosystem Security and Compliance
Specialised Aadhaar compliance audit for AUA, KUA, Sub-AUA, and Sub-KUA entities. CERT-In empanelled auditors validate real Aadhaar authentication and eKYC flows, not just documentation, ensuring your UIDAI checklist is submission-ready.
Security Brigade delivers the annual UIDAI compliance audit required for entities performing Aadhaar authentication, eKYC, or operating as Sub-AUA/Sub-KUA. Our auditors validate Aadhaar architecture, encryption-at-source, Aadhaar Vault, HSM controls, biometric and RD device security, OTP and eKYC flows, masked Aadhaar handling, data retention and deletion, and complete audit trails. Every checklist item carries the three columns UIDAI's compliance checklist requires: compliance status, the auditor's observation, and comments of AUA/KUA management, against version 2.0 of the checklist, issued in May 2025.
Trusted by India's leading enterprises
The document
Twelve control families, and the one most audits underestimate
UIDAI publishes the checklist your auditor completes: Version 2.0, issued May 2025. These are its sections, and where the effort actually goes.
| Family | What it asks for | Evidenced by |
|---|---|---|
| A · Information Security Governance | Opens with a designated CISO or equivalent function overseeing security governance and compliance, reporting independently to the Board. Governance is control 1 for a reason. | Policy and governance review |
| B · Data Privacy | The data protection policy, and the handling obligations that sit under the Aadhaar Act and the standards UIDAI issues under it. | Policy review, data-flow mapping |
| C · Asset Management · D · Human Resource Security | Asset inventory and ownership, then NDAs and background verification for personnel handling Aadhaar data, extended expressly to Sub-AUAs, Sub-KUAs and third-party contractors. | Evidence review |
| E · Access Control · F · Physical Security | Privileged access management, and physical protection of the environments where authentication happens. | Configuration review, site review |
| G · Data Security | The largest family in the checklist by some distance, and where an audit that has been scoped casually runs out of time. | Infrastructure and application testing |
| H · Network Security | Connectivity between the AUA/KUA and its Sub-AUAs, Sub-KUAs, sub-contractors and ASAs: connection to an ASA only over secure leased lines or similar private lines, and a secure channel where a public network is used. | Network penetration testing |
| I · Operations Security · J · Application Security | Operational hardening, and the application controls including control 69: SAST and DAST on the authentication application at least annually or at major changes, all vulnerabilities addressed, and no vulnerable third-party components in use. | VAPT, SAST, DAST, code review |
| K · Logging and Monitoring · L · Fraud and Forensics | What is recorded, for how long, and whether it would support an investigation after the fact. | Logging review |
A · Information Security Governance
- What it asks for
- Opens with a designated CISO or equivalent function overseeing security governance and compliance, reporting independently to the Board. Governance is control 1 for a reason.
- Evidenced by
- Policy and governance review
B · Data Privacy
- What it asks for
- The data protection policy, and the handling obligations that sit under the Aadhaar Act and the standards UIDAI issues under it.
- Evidenced by
- Policy review, data-flow mapping
C · Asset Management · D · Human Resource Security
- What it asks for
- Asset inventory and ownership, then NDAs and background verification for personnel handling Aadhaar data, extended expressly to Sub-AUAs, Sub-KUAs and third-party contractors.
- Evidenced by
- Evidence review
E · Access Control · F · Physical Security
- What it asks for
- Privileged access management, and physical protection of the environments where authentication happens.
- Evidenced by
- Configuration review, site review
G · Data Security
- What it asks for
- The largest family in the checklist by some distance, and where an audit that has been scoped casually runs out of time.
- Evidenced by
- Infrastructure and application testing
H · Network Security
- What it asks for
- Connectivity between the AUA/KUA and its Sub-AUAs, Sub-KUAs, sub-contractors and ASAs: connection to an ASA only over secure leased lines or similar private lines, and a secure channel where a public network is used.
- Evidenced by
- Network penetration testing
I · Operations Security · J · Application Security
- What it asks for
- Operational hardening, and the application controls including control 69: SAST and DAST on the authentication application at least annually or at major changes, all vulnerabilities addressed, and no vulnerable third-party components in use.
- Evidenced by
- VAPT, SAST, DAST, code review
K · Logging and Monitoring · L · Fraud and Forensics
- What it asks for
- What is recorded, for how long, and whether it would support an investigation after the fact.
- Evidenced by
- Logging review
The word that decides the audit
“Compliant” has a definition, and it is not “true on the day”
The checklist opens with a note most readers skip, and it is the sentence that separates an audit that holds from one that does not.
UIDAI’s instruction at the head of the checklist is that wherever a control requires the AUA/KUA to ensure or do anything, it shall be reported as compliant if and only if the auditor finds that it is being complied with and, further, that appropriate policies, procedures, mechanisms, resources and technical enablements are in place to secure compliance with it on an ongoing basis. Two tests, not one. The control has to be true, and the arrangements that keep it true have to exist. A firewall rule configured correctly the week before the audit satisfies the first and fails the second, and an auditor applying the note as written cannot mark it compliant. It is also why the checklist has three columns instead of a tick box: compliance status, the auditor’s observation, and the comments of AUA/KUA management. The observation column is where the second test is either evidenced or exposed, and a completed checklist whose observation column reads "verified" against seventy-odd controls is a document that tells UIDAI nothing and tells a reader rather a lot.
If something is found
Non-compliance has a procedure, and it is four steps you own
The Undertaking sets out what happens after a finding. Read it before the audit, not after, because it is written as your obligation and not your auditor’s.
-
Determine the causes of the non-compliance
Not the symptom. The checklist asks for causes, which is the difference between "the certificate had expired" and "nothing owns certificate renewal".
-
Evaluate the need for actions to avoid recurrence
An explicit step, and the one most remediation plans skip: they fix the instance and never ask whether the same gap exists elsewhere in the estate.
-
Determine and enforce corrective and preventive actions
Corrective and preventive are named separately. Closing the finding is corrective; stopping it recurring is preventive, and the Undertaking asks for both.
-
Review the corrective actions taken
The loop closes with a review, not with the fix. A retest evidences that review, and that is what puts the retest inside the engagement instead of after it.
The obligations
Who audits you, who audits your Sub-AUAs, and what reaches UIDAI
Two different audits with two different auditor standards, and both reports go to UIDAI. Groups routinely discover the second one late.
Your own audit: a CERT-In empanelled agency
The Undertaking requires operations and systems to be audited by an information systems auditor certified by a CERT-In empanelled audit agency, annually and on a need basis, with the report shared with UIDAI. Security Brigade has been CERT-In empanelled continuously since 2008.
Your Sub-AUAs: a different standard
The operations and systems of Sub-AUAs and Sub-KUAs are to be audited annually by an information systems auditor certified by a recognised body, with that report shared with UIDAI as well. A different qualification from the one set for your own audit, and a separate piece of work to plan.
Scope is the 2016 Data Security Regulations
The annual audit is to cover all security controls applicable under the Aadhaar (Data Security) Regulations, 2016. That is the boundary the checklist sets for the exercise, and it is wider than the authentication application alone.
Control 69: SAST and DAST
Application security assessment including static and dynamic testing, performed at least annually or at the time of major changes to the authentication application, with all vulnerabilities addressed and no vulnerable third-party components in use.
Risk assessment, including your vendors
At least annual information security risk assessment of the ICT infrastructure supporting the authentication application, and of third-party suppliers and vendors with access to the Aadhaar application or to holders’ data.
The completed checklist itself
Every control carried through the three columns UIDAI asks for (status, auditor’s observation and management comments) as the artefact that goes into the file, and not a report that has to be transcribed into one afterwards.
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
Security Brigade's UIDAI audit methodology goes beyond checklist completion. Our auditors validate actual Aadhaar authentication and eKYC application flows, test encryption implementations, review Aadhaar Data Vault architecture, and verify data handling practices through evidence and technical testing. Control 68 puts source code review on the modules and applications used for authentication and e-KYC, and control 69 puts SAST and DAST on the authentication application. UIDAI's own instruction to auditors is that a control is reported compliant only if the auditor finds it complied with and finds appropriate policies, procedures, mechanisms, resources and technical enablements in place to secure compliance on an ongoing basis.
Scoping and Architecture Review
Document AUA/KUA/Sub-AUA/Sub-KUA role, Aadhaar integration architecture, ASA connectivity, application landscape, and all systems touching Aadhaar data. Collect authorisation agreements and prior audit reports.
Data-Flow and Encryption Validation
Map Aadhaar data flows across application, network, API, ASA, storage, logs, support, and reporting systems. Validate encryption-at-source, encryption-in-transit, Aadhaar Vault or reference-key architecture, and HSM key management controls.
Application and Device Security Testing
Test Aadhaar authentication and eKYC applications through VAPT, SAST and DAST, which control 69 requires at least annually or at the time of major changes to the authentication application. Review biometric device and registered-device (RD) controls. Validate OTP, biometric, demographic and eKYC flow integrity.
Access Control and Audit Trail Review
Review access control matrices, privileged access management, maker-checker controls, admin logging, audit trail completeness, log retention, monitoring, and incident response readiness.
Data Retention, Deletion, and Masking Review
Validate masked Aadhaar usage, storage minimisation, Aadhaar number and VID and UID token handling, eKYC XML/PDF data management, data retention schedules, and deletion controls.
Gap Assessment and Remediation Support
Deliver risk-ranked gap report with specific observations and remediation guidance. Work with your engineering and compliance teams to close non-compliances before the final report.
Final Report and UIDAI Submission Pack
Issue the final UIDAI AUA/KUA Compliance Audit Report with the completed UIDAI checklist including compliance status, auditor observations, and management comments. Prepare the submission-ready pack for UIDAI.
"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
Continuous Compliance with ShadowMap
The audit gives you a snapshot. ShadowMap gives you the always-on view.
An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.
Threat Intelligence
1,000+ threat actor profiles, CVE tracking against your stack, IOC monitoring, and geographic threat analysis.
Know which threats are coming for you specifically.
Explore on ShadowMapDark Web Monitoring
12B+ breach records indexed; monitors Telegram, paste sites, criminal forums, and ransomware leak sites for credentials, leaked data, and threat actor mentions.
Find leaked data before regulators do.
Explore on ShadowMapFAQ
What AUAs and KUAs ask before scoping
Answered from UIDAI’s published checklist, Version 2.0 of May 2025, which is the document your auditor completes.
Contact usDoes our auditor have to be CERT-In empanelled?
Do our Sub-AUAs need their own audit?
How often is the audit, and what triggers one outside the cycle?
What does the audit have to cover?
What does UIDAI actually receive?
We host the authentication application on cloud. Does anything change?
A finding came back non-compliant. What now?
Ready to Start Your UIDAI AUA/KUA Compliance Audit?
Get a CERT-In empanelled audit team, platform-backed execution, and a submission-ready report for UIDAI.
Typically responds within 1 business day · No commitment required