Skip to main content
CERT-In Empanelled — Nationally recognised cybersecurity auditor designation under MeitY

UIDAI AUA/KUA Audit: Aadhaar Ecosystem Security and Compliance

Specialised Aadhaar compliance audit for AUA, KUA, Sub-AUA, and Sub-KUA entities. CERT-In empanelled auditors validate real Aadhaar authentication and eKYC flows, not just documentation, ensuring your UIDAI checklist is submission-ready.

AUA + KUA
Audit Coverage
UIDAI-Aligned
Methodology
6,700+
Assessments
Since 2008
CERT-In Empanelled

Security Brigade delivers the annual UIDAI compliance audit required for entities performing Aadhaar authentication, eKYC, or operating as Sub-AUA/Sub-KUA. Our auditors validate Aadhaar architecture, encryption-at-source, Aadhaar Vault, HSM controls, biometric and RD device security, OTP and eKYC flows, masked Aadhaar handling, data retention and deletion, and complete audit trails. Every checklist item carries the three columns UIDAI's compliance checklist requires: compliance status, the auditor's observation, and comments of AUA/KUA management, against version 2.0 of the checklist, issued in May 2025.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The document

Twelve control families, and the one most audits underestimate

UIDAI publishes the checklist your auditor completes: Version 2.0, issued May 2025. These are its sections, and where the effort actually goes.

FamilyWhat it asks forEvidenced by
A · Information Security Governance Opens with a designated CISO or equivalent function overseeing security governance and compliance, reporting independently to the Board. Governance is control 1 for a reason. Policy and governance review
B · Data Privacy The data protection policy, and the handling obligations that sit under the Aadhaar Act and the standards UIDAI issues under it. Policy review, data-flow mapping
C · Asset Management · D · Human Resource Security Asset inventory and ownership, then NDAs and background verification for personnel handling Aadhaar data, extended expressly to Sub-AUAs, Sub-KUAs and third-party contractors. Evidence review
E · Access Control · F · Physical Security Privileged access management, and physical protection of the environments where authentication happens. Configuration review, site review
G · Data Security The largest family in the checklist by some distance, and where an audit that has been scoped casually runs out of time. Infrastructure and application testing
H · Network Security Connectivity between the AUA/KUA and its Sub-AUAs, Sub-KUAs, sub-contractors and ASAs: connection to an ASA only over secure leased lines or similar private lines, and a secure channel where a public network is used. Network penetration testing
I · Operations Security · J · Application Security Operational hardening, and the application controls including control 69: SAST and DAST on the authentication application at least annually or at major changes, all vulnerabilities addressed, and no vulnerable third-party components in use. VAPT, SAST, DAST, code review
K · Logging and Monitoring · L · Fraud and Forensics What is recorded, for how long, and whether it would support an investigation after the fact. Logging review

A · Information Security Governance

What it asks for
Opens with a designated CISO or equivalent function overseeing security governance and compliance, reporting independently to the Board. Governance is control 1 for a reason.
Evidenced by
Policy and governance review

B · Data Privacy

What it asks for
The data protection policy, and the handling obligations that sit under the Aadhaar Act and the standards UIDAI issues under it.
Evidenced by
Policy review, data-flow mapping

C · Asset Management · D · Human Resource Security

What it asks for
Asset inventory and ownership, then NDAs and background verification for personnel handling Aadhaar data, extended expressly to Sub-AUAs, Sub-KUAs and third-party contractors.
Evidenced by
Evidence review

E · Access Control · F · Physical Security

What it asks for
Privileged access management, and physical protection of the environments where authentication happens.

G · Data Security

What it asks for
The largest family in the checklist by some distance, and where an audit that has been scoped casually runs out of time.
Evidenced by
Infrastructure and application testing

H · Network Security

What it asks for
Connectivity between the AUA/KUA and its Sub-AUAs, Sub-KUAs, sub-contractors and ASAs: connection to an ASA only over secure leased lines or similar private lines, and a secure channel where a public network is used.

I · Operations Security · J · Application Security

What it asks for
Operational hardening, and the application controls including control 69: SAST and DAST on the authentication application at least annually or at major changes, all vulnerabilities addressed, and no vulnerable third-party components in use.

K · Logging and Monitoring · L · Fraud and Forensics

What it asks for
What is recorded, for how long, and whether it would support an investigation after the fact.
Evidenced by
Logging review

The word that decides the audit

“Compliant” has a definition, and it is not “true on the day”

The checklist opens with a note most readers skip, and it is the sentence that separates an audit that holds from one that does not.

UIDAI’s instruction at the head of the checklist is that wherever a control requires the AUA/KUA to ensure or do anything, it shall be reported as compliant if and only if the auditor finds that it is being complied with and, further, that appropriate policies, procedures, mechanisms, resources and technical enablements are in place to secure compliance with it on an ongoing basis. Two tests, not one. The control has to be true, and the arrangements that keep it true have to exist. A firewall rule configured correctly the week before the audit satisfies the first and fails the second, and an auditor applying the note as written cannot mark it compliant. It is also why the checklist has three columns instead of a tick box: compliance status, the auditor’s observation, and the comments of AUA/KUA management. The observation column is where the second test is either evidenced or exposed, and a completed checklist whose observation column reads "verified" against seventy-odd controls is a document that tells UIDAI nothing and tells a reader rather a lot.

If something is found

Non-compliance has a procedure, and it is four steps you own

The Undertaking sets out what happens after a finding. Read it before the audit, not after, because it is written as your obligation and not your auditor’s.

The obligations

Who audits you, who audits your Sub-AUAs, and what reaches UIDAI

Two different audits with two different auditor standards, and both reports go to UIDAI. Groups routinely discover the second one late.

Your own audit: a CERT-In empanelled agency

The Undertaking requires operations and systems to be audited by an information systems auditor certified by a CERT-In empanelled audit agency, annually and on a need basis, with the report shared with UIDAI. Security Brigade has been CERT-In empanelled continuously since 2008.

Your Sub-AUAs: a different standard

The operations and systems of Sub-AUAs and Sub-KUAs are to be audited annually by an information systems auditor certified by a recognised body, with that report shared with UIDAI as well. A different qualification from the one set for your own audit, and a separate piece of work to plan.

Scope is the 2016 Data Security Regulations

The annual audit is to cover all security controls applicable under the Aadhaar (Data Security) Regulations, 2016. That is the boundary the checklist sets for the exercise, and it is wider than the authentication application alone.

Control 69: SAST and DAST

Application security assessment including static and dynamic testing, performed at least annually or at the time of major changes to the authentication application, with all vulnerabilities addressed and no vulnerable third-party components in use.

Risk assessment, including your vendors

At least annual information security risk assessment of the ICT infrastructure supporting the authentication application, and of third-party suppliers and vendors with access to the Aadhaar application or to holders’ data.

The completed checklist itself

Every control carried through the three columns UIDAI asks for (status, auditor’s observation and management comments) as the artefact that goes into the file, and not a report that has to be transcribed into one afterwards.

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade's UIDAI audit methodology goes beyond checklist completion. Our auditors validate actual Aadhaar authentication and eKYC application flows, test encryption implementations, review Aadhaar Data Vault architecture, and verify data handling practices through evidence and technical testing. Control 68 puts source code review on the modules and applications used for authentication and e-KYC, and control 69 puts SAST and DAST on the authentication application. UIDAI's own instruction to auditors is that a control is reported compliant only if the auditor finds it complied with and finds appropriate policies, procedures, mechanisms, resources and technical enablements in place to secure compliance on an ongoing basis.

Discovery
01

Scoping and Architecture Review

Document AUA/KUA/Sub-AUA/Sub-KUA role, Aadhaar integration architecture, ASA connectivity, application landscape, and all systems touching Aadhaar data. Collect authorisation agreements and prior audit reports.

02

Data-Flow and Encryption Validation

Map Aadhaar data flows across application, network, API, ASA, storage, logs, support, and reporting systems. Validate encryption-at-source, encryption-in-transit, Aadhaar Vault or reference-key architecture, and HSM key management controls.

03

Application and Device Security Testing

Test Aadhaar authentication and eKYC applications through VAPT, SAST and DAST, which control 69 requires at least annually or at the time of major changes to the authentication application. Review biometric device and registered-device (RD) controls. Validate OTP, biometric, demographic and eKYC flow integrity.

Testing
04

Access Control and Audit Trail Review

Review access control matrices, privileged access management, maker-checker controls, admin logging, audit trail completeness, log retention, monitoring, and incident response readiness.

05

Data Retention, Deletion, and Masking Review

Validate masked Aadhaar usage, storage minimisation, Aadhaar number and VID and UID token handling, eKYC XML/PDF data management, data retention schedules, and deletion controls.

Delivery
06

Gap Assessment and Remediation Support

Deliver risk-ranked gap report with specific observations and remediation guidance. Work with your engineering and compliance teams to close non-compliances before the final report.

07

Final Report and UIDAI Submission Pack

Issue the final UIDAI AUA/KUA Compliance Audit Report with the completed UIDAI checklist including compliance status, auditor observations, and management comments. Prepare the submission-ready pack for UIDAI.

"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
CTO, Enterprise SaaS Company
Chief Technology Officer

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

What AUAs and KUAs ask before scoping

Answered from UIDAI’s published checklist, Version 2.0 of May 2025, which is the document your auditor completes.

Contact us
Does our auditor have to be CERT-In empanelled?+
For your own audit, the Undertaking is explicit: operations and systems are to be audited by an information systems auditor certified by a CERT-In empanelled audit agency, on an annual basis and on a need basis, with the report shared with UIDAI. Note that the standard set for Sub-AUA and Sub-KUA audits is worded differently: an information systems auditor certified by a recognised body. The two are not interchangeable and repay reading side by side when you plan the year.
Do our Sub-AUAs need their own audit?+
Yes. The AUA/KUA is required to ensure that the operations and systems of its Sub-AUAs and Sub-KUAs are audited annually, and that those audit reports are shared with UIDAI. The obligation is yours and not theirs, which is the part that tends to surface late, usually when a Sub-AUA is asked for a report nobody commissioned.
How often is the audit, and what triggers one outside the cycle?+
Annually, and on a need basis. Separately, control 69 requires application security assessment including SAST and DAST at least annually or at the time of major changes to the authentication application, so a significant release is its own trigger, independent of where you are in the annual cycle.
What does the audit have to cover?+
The checklist states that the annual audit should cover all security controls applicable under the Aadhaar (Data Security) Regulations, 2016. In practice that is the twelve control families in the checklist, from information security governance through to fraud and forensics, applied to the systems and operations supporting authentication, not to the authentication application in isolation.
What does UIDAI actually receive?+
The audit report, shared with UIDAI. The completed compliance checklist carries every control through three columns: compliance status marked compliant, non-compliant or not applicable, the auditor’s observation, and the comments of AUA/KUA management. The Undertaking is printed on your own letterhead. The observation column is the part that carries weight, because it is where the evidence for each control is recorded instead of asserted.
We host the authentication application on cloud. Does anything change?+
The checklist addresses cloud hosting directly, including an annual SOC 2 expectation where the authentication-related deployment sits on cloud infrastructure. Scope it explicitly at the start: the boundary between what your cloud provider attests and what remains yours to evidence is where cloud-hosted audits lose time.
A finding came back non-compliant. What now?+
The Undertaking sets out four steps and they are yours, not your auditor’s: determine the causes, evaluate the need for actions to avoid recurrence, determine and enforce corrective and preventive actions, and review the corrective actions taken. A retest evidences that last step, so it belongs inside the engagement instead of being arranged afterwards.

Ready to Start Your UIDAI AUA/KUA Compliance Audit?

Get a CERT-In empanelled audit team, platform-backed execution, and a submission-ready report for UIDAI.

Typically responds within 1 business day · No commitment required

Request a Scoping Call