education
Merchant KYC & UPI ID Verification in India — Complete Setup Guide
Merchant KYC guide for UPI ID setup in India. Covers NPCI onboarding, required documents, VPA creation, GSTIN linking, QR generation, and why unverified QR fails.
Setting up a UPI ID for your business seems simple — download PhonePe, link your account, share a QR code. But this approach leaves you operating as a personal UPI user, not as a verified merchant. The difference matters for transaction limits, GST compliance, business creditworthiness, and regulatory clarity. Here is how proper merchant KYC and UPI ID setup works in India.
Personal UPI vs Merchant UPI: Why It Matters
Most merchants start with a personal UPI ID because it requires no documentation and works immediately. But personal UPI IDs have significant limitations for business use:
- Subject to P2P daily limits (₹1 lakh cumulative)
- No merchant category code — NPCI cannot apply category-specific higher limits
- No GST invoice linkage capability
- Transaction data does not feed into merchant credit scoring systems
- Violates most banks’ terms of service for savings accounts
- No access to merchant analytics or settlement reports
A merchant UPI ID — registered through an acquiring bank with NPCI — operates on a different technical framework: P2M (person-to-merchant) rules apply, enabling higher per-transaction limits, merchant-specific features, and regulatory clarity.
The NPCI Merchant Onboarding Process
NPCI does not onboard merchants directly. The onboarding happens through a two-tier process:
Tier 1: Acquiring Bank or Payment Service Provider (PSP) The merchant applies to an acquiring bank (SBI, HDFC, ICICI, Axis, etc.) or a Payment Service Provider (like VyaparGateway or similar). The acquiring entity is responsible for merchant due diligence.
Tier 2: NPCI Registration The acquiring bank registers the merchant on NPCI’s system with:
- Unique Merchant ID (MID)
- Merchant Category Code (MCC)
- VPA (Virtual Payment Address) assigned to the merchant
- Bank account details for settlement
NPCI’s merchant registration completes the technical linkage between the merchant’s QR code and the payment routing infrastructure.
Documents Required for Merchant KYC
For Sole Proprietor Merchants:
- Identity proof: Aadhaar card (with Aadhaar-linked mobile number for OTP verification)
- PAN card: Mandatory for all merchant registrations
- Business proof (any one):
- GST Registration Certificate (preferred)
- Shop and Establishment Licence (state-issued)
- Udyam Registration Certificate (for MSME)
- Trade licence from municipal body
- Professional licence (for doctors, lawyers — Medical Council registration, Bar Council certificate)
- Bank account proof: Cancelled cheque from the bank account to be linked for settlements
- Address proof for business premises: Utility bill, property tax receipt, or rental agreement
For Private Limited Companies and LLPs: All documents above, plus:
- Certificate of Incorporation from MCA
- Board resolution authorising the designated signatory for UPI merchant account
- Company PAN (separate from promoter’s personal PAN)
- Director/Partner KYC for authorised signatories
For Partnership Firms:
- Partnership deed (registered or unregistered)
- All partner KYC documents
- Firm PAN
KYC for Different Business Types
Sole proprietor: KYC is straightforward — the proprietor’s personal identity documents serve as the business KYC since the firm and individual are legally the same entity.
Company or LLP: More documentation is required, and the KYC is at the entity level. The company PAN and incorporation documents establish the legal identity; director/partner KYC satisfies the beneficial ownership requirement under PMLA.
Unregistered trader without GST: Can use Shop and Establishment licence or Udyam Registration. Banks may request additional scrutiny for high-volume merchant registrations without GST registration.
VPA (Virtual Payment Address) Creation and Verification
Once KYC is complete, the acquiring bank or PSP assigns a VPA to your merchant account. This typically follows the format:
businessname@bankname (e.g., rahulstores@hdfcbank)
or
merchantid@psp (e.g., 12345678@vyapargateway)
VPA verification process:
- The acquiring bank validates that the VPA resolves to your registered bank account in NPCI’s system
- A test transaction (typically ₹1) is debited and credited to confirm end-to-end functionality
- The VPA is activated for live merchant transactions
Important: VPAs that have no transactions for 12+ consecutive months may be deactivated by NPCI or the bank. Inactive VPAs cause “VPA not found” errors for customers scanning your QR. Merchants should ensure at least one transaction per quarter to keep the VPA active.
Linking Your GSTIN to Your UPI ID
For GST-registered merchants, linking your GSTIN to your merchant UPI ID provides significant operational benefits:
- Customers scanning your QR can see your GSTIN in the payment preview
- Invoices generated at point of sale can carry GST details
- GSTN and bank statements can be cross-referenced for GST return filing
- B2B customers can claim ITC directly from the transaction metadata
The GSTIN linking process:
- Log in to your merchant portal (provided by your acquiring bank or PSP)
- Navigate to Business Profile → GST Details
- Enter your 15-digit GSTIN
- The system verifies your GSTIN against GSTN’s database
- Once verified, your QR metadata includes GSTIN
This feature is not universally available across all payment platforms but is increasingly standard in 2026.
QR Code Generation After KYC
After KYC is verified and VPA is active, your merchant QR code is generated. There are two types:
Static QR: A permanent QR containing only your VPA. Customers scan, enter the amount manually, and complete the payment. Suitable for physical checkout counters where amount varies per customer.
Dynamic QR: Generated per transaction, containing the specific amount, order reference, and expiry time. Customers scan, see the pre-filled amount, and only need to enter their PIN. Reduces wrong-amount payments and enables server-side confirmation.
QR codes should be:
- Printed at minimum 3cm x 3cm for reliable scanning
- Displayed at customer eye level, not flat on a surface requiring the customer to lean over
- Protected from UV damage (laminated) if displayed outdoors
- Refreshed if your bank account or VPA changes
Ongoing KYC Obligations
Merchant KYC is not a one-time event. NPCI and RBI guidelines require periodic updates:
- Annual review: Acquiring banks must verify high-volume merchant KYC annually (typically for merchants with annual UPI receipts above ₹1 crore)
- Change in business details: Name change, address change, proprietorship-to-company conversion, or change in settlement bank account require a fresh KYC update
- Change in mobile number: Since OTP-based verification ties to your Aadhaar-linked mobile, changing your mobile number requires updating it at both UIDAI (Aadhaar) and your acquiring bank
Failure to update KYC when required can result in temporary suspension of merchant settlement — payments will still come in but may be held pending re-verification.
Why Unverified QRs Fail for Large Amounts
Merchants sometimes create QR codes directly from UPI apps without going through acquiring bank merchant registration. These QRs fail for large amounts because:
- The VPA resolves to a personal savings account — subject to ₹1 lakh P2P daily limit
- No MCC is associated — NPCI defaults to lowest applicable limit
- For amounts above ₹50,000 on unverified QRs, some TPAPs display warnings to payers about unverified merchant status
- Banks may apply additional friction (extra authentication step) for high-value payments to unverified VPAs
Proper merchant KYC and registration is the only reliable path to accepting high-value UPI payments without friction. The process takes 3-10 business days at most acquiring banks — a minor one-time investment for a significantly better long-term payment experience.
Direct answers
Frequently asked questions
- What documents are required for merchant UPI KYC in India?
- For a sole proprietor, you need: Aadhaar card (for personal identity), PAN card, a business existence proof (GST certificate, Shop and Establishment licence, or Udyam registration), a cancelled cheque from your business bank account, and your mobile number linked to Aadhaar. Companies additionally need Certificate of Incorporation and a board resolution authorising the UPI account.
- What is the difference between a personal UPI ID and a merchant UPI ID?
- A personal UPI ID (VPA) is linked to a savings account and operates under P2P transaction limits. A merchant UPI ID is registered through an acquiring bank or payment service provider as a merchant entity — it attracts P2M limits (higher per-transaction caps), enables merchant-specific analytics, qualifies for GST invoice integration, and allows NPCI to track merchant category codes for appropriate limit application.
- Why does my merchant QR fail for large payment amounts?
- Unverified merchant QRs — those not registered through proper KYC with an acquiring bank — default to P2P transaction rules, which cap at ₹1 lakh. Additionally, if your VPA is inactive (no transactions for 12+ months), it may fail entirely. Properly KYC-verified merchant QRs with correct MCC classification access category-appropriate P2M limits and are refreshed regularly by the acquiring bank.
Build your payment flow
Explore the API and browser-only merchant tools.
Create UPI checkout orders, verify signed events, or test the free calculators and generators without exposing credentials.