Skip to content
FinHubBy HabileLabs

KYC & Onboarding

How PAN verification works in Indian KYC — the PAN format decoded, database checks via Protean and UTIITSL, name-matching, and PAN–Aadhaar linkage rules.

FinHub Identity Desk

KYC & verification · 23 June 2026 · 8 min read

Last updated 16 August 2026

The PAN (Permanent Account Number) is the backbone of identity in Indian finance. It ties a person or entity to the tax system, and it's a mandatory data point in almost every KYC and lending flow. But 'we collected a PAN' is not the same as 'we verified it' — a well-formed PAN can still be fake, inoperative, or belong to someone other than your applicant. Here's what real PAN verification involves.

Decoding the PAN format

A PAN is ten characters in the pattern AAAAA9999A — five letters, four digits, then a final letter. The structure carries meaning. The fourth character identifies the holder type: 'P' for an individual, 'C' for a company, 'H' for a Hindu Undivided Family, 'F' for a firm or LLP, 'T' for a trust, and other letters for associations, bodies of individuals, government and so on. The fifth character is the first letter of the holder's surname (for individuals) or of the entity's name. The last character is a check digit computed from the rest.

This structure lets you catch a whole class of errors instantly. A format and check-digit validation confirms the PAN is internally consistent and rejects typos and obviously fabricated numbers — before you spend anything on a database call. But it can't tell you whether the PAN actually exists or is active.

Database verification against the ITD

For that, you verify the PAN against the Income Tax Department's records. This is done through authorised intermediaries — Protean eGov Technologies (formerly NSDL e-Gov) and UTIITSL — which offer API and bulk verification. A database check returns the PAN's status (valid, invalid or inoperative), the name as recorded by the tax department, and its Aadhaar-seeding status. This is what separates a real, active PAN from a well-formed but fictitious one.

Why name-match is the real control

The name returned by the verification is where fraud gets caught. Synthetic-identity fraud frequently pairs a genuine PAN with fabricated application details, so a name that doesn't reconcile across the PAN, the Aadhaar and the application is a strong signal something is wrong. As with bank-account verification, exact string matching is too brittle — you need fuzzy matching that tolerates initials, middle names and transliteration differences while still flagging genuine mismatches. A robust KYC flow cross-checks PAN-name against Aadhaar-name against the name the customer entered, and escalates inconsistencies.

PAN–Aadhaar linkage and 'inoperative' PANs

Under Section 139AA of the Income-tax Act, PAN and Aadhaar must be linked for most taxpayers. A PAN that isn't linked becomes 'inoperative', and the consequences are real: higher TDS and TCS rates under Sections 206AA and 206CC, blocked refunds, and an inability to complete PAN-based transactions until it's reactivated (which involves a fee and re-linking). Deadlines have shifted over time — for example, PANs issued via an Aadhaar Enrolment ID faced a linkage deadline at the end of 2025, after which they risked becoming inoperative — so verifying seeding status is worth doing at onboarding.

For a lender, an inoperative PAN is a double problem: it's a KYC red flag, and it breaks the TDS treatment on any interest you pay out. Checking operative status up front avoids servicing headaches later.

FinHub's PAN Verification API combines format and check-digit validation, live database verification and built-in fuzzy name-matching in one call — so you confirm the PAN is real, active and actually your customer's, not just well-formed.

FAQ

PAN verification for KYC: format & name-match: common questions

A PAN is ten characters in the pattern AAAAA9999A — five letters, four digits, then a final letter. The fourth character identifies the holder type: 'P' for an individual, 'C' for a company, 'H' for a Hindu Undivided Family and 'F' for a firm.

Talk to our product experts

See how these ideas apply to your institution's specific workflows.