Summary: The Delhi High Court has directed authorities across India not to grant any GST registration without biometric-based Aadhaar authentication until further orders. The direction arose from petitions, including W.P.(C) 12210/2026 filed by Smt. Neha and a connected petition by Mr. Kaushal, alleging misuse of frozen PAN and Aadhaar details for obtaining fraudulent GST registrations. Although the department stated that biometric verification was already operational, it acknowledged that such verification was required only when an application was classified as “high-risk” by an automated risk engine. Other applications could proceed through scanned documents and OTP-based authentication without establishing the applicant’s physical identity. The Court noted government figures showing detection of 2,800 fraudulent registrations involving tax evasion exceeding ₹15,000 crore in FY 2023–24 and another 1,654 registrations involving more than ₹13,000 crore in FY 2024–25. Senior Advocate Tarun Gulati, appointed as Amicus Curiae, also proposed a ten-point framework covering facial recognition, video verification, real-time alerts to identity-document holders, geo-location and IP tracking, universal physical site verification, express confirmation from Aadhaar holders, turnover-spike monitoring, document-lock checks, authorised-signatory audits and immutable digital approval trails. These safeguards seek to prevent identity-based registration fraud before fake entities enter the GST system and unlawfully pass Input Tax Credit.
- When a Fingerprint Becomes the First Line of Defence
- What the Court Has Ordered
- Why This Matters to an Officer Sanctioning Registrations
- Beyond Biometrics: The Ten-Point Framework
- 1. Mandatory Facial Recognition
- 2. Video-Based Verification
- 3. Digital Alerts to Document Holders
- 4. Geo-location and IP Tracking
- 5. Universal Pre-Registration Physical Site Verification
- 6. Aadhaar Holder Express Confirmation
- 7. Automated Spike Monitoring
- 8. Document Lock Checks
- 9. Authorized Signatory Audit
- 10. Chain-of-Custody Digital Trails
- A Welcome Course Correction
When a Fingerprint Becomes the First Line of Defence
GST registration is a gateway into India’s Indirect tax system. Once a business is granted a GSTIN, it can issue invoices, charge tax, and pass on Input Tax Credit to whoever buys from it. Because that gateway carries so much weight, how carefully it is guarded at the entry point decides how clean or how compromised everything that follows will be.
For years, that entry point has relied mainly on documents — a scanned PAN card, a scanned Aadhaar card, and an OTP sent to a mobile number. It has taken a Delhi High Court order to force a hard look at how thin that check really is, and why identity theft through fake GST registrations has become a problem worth ₹28,000 crore.
What the Court Has Ordered
The order was passed on September 08, 2026 by a Division Bench of the Delhi High Court comprising Justice Anil Kshetarpal and Justice Shail Jain, in writ petitions including W.P.(C) 12210/2026 (Smt. Neha) and a connected petition by Mr. Kaushal. Both petitioners had approached the Court after their frozen PAN and Aadhaar details were misused by unknown persons to create GST registrations without their knowledge, exposing them to tax demands and harassment for businesses they never ran.
The Bench directed that no GST registration be granted anywhere in the country without biometric-based Aadhaar authentication. This is not a suggestion or a best-practice recommendation; it is a direction to “all the authorities across the country,” worded plainly:
“Hence, for the time being, directions are issued to all the authorities across the country not to allow any GST registration without biometric-based AADHAR authentication henceforth.”
It takes effect with immediate effect, until the Court passes further orders.
The order exposes something officers on the ground have long suspected: the gap between what a policy says on paper and what actually happens at the counter. The tax department had told the Court that biometric verification was already in place. But it also admitted, in the same breath, that biometric checks were only triggered when an application was flagged “high-risk” by an automated risk engine. Everything else moved through on document-based verification alone — a scanned Aadhaar card, a scanned PAN card, and an OTP. None of that requires the applicant’s actual physical presence or their fingerprint.
That loophole is exactly what fraudsters have been exploiting. The Court also took note of a statement made by the Minister of State for Finance on the floor of the Rajya Sabha, in which biometric authentication was described as having already been made mandatory. Yet, as the Bench observed, more than a year after that statement, full implementation on the ground remained pending — the gap between the policy on record and the practice at the counter.
Why This Matters to an Officer Sanctioning Registrations
When I sit down to examine a fresh registration application, my job under the law is to satisfy myself that the applicant is who they claim to be and that the business described is genuine. Document verification helps, but documents can be copied, scanned, and reused. A stolen PAN card image looks exactly like a genuine one on a screen. An OTP sent to a mobile number tells me the mobile number is real — it tells me nothing about whether the person holding that mobile number is the person named on the Aadhaar card.
Biometric authentication under the GST registration process closes that gap because it ties the application to a living person’s fingerprint or facial match against the Aadhaar database itself, not to a photocopy of a document. It shifts the check from “does this paperwork look correct” to “is this person physically who they say they are.” For an officer, that is the difference between granting a registration on faith and granting it on verified fact.
The numbers the government itself placed before the Court make the stakes clear. In FY 2023–24, 2,800 fraudulent GST registrations were detected, involving tax evasion of over ₹15,000 crore. In FY 2024–25, another 1,654 such registrations were found, accounting for over ₹13,000 crore more. Together, that is close to ₹28,200 crore siphoned off through identity misuse in just two years — and this is only the fraud that was caught.
Beyond Biometrics: The Ten-Point Framework
What makes this order significant is not only the biometric mandate itself but the wider blueprint the Court has asked authorities to examine. The Court had appointed Senior Advocate Tarun Gulati as Amicus Curiae to assist it, and he placed before the Bench a detailed ten-point framework to fortify the registration process. It is worth setting out in full, because each point addresses a specific weakness officers encounter in day-to-day verification work:
1. Mandatory Facial Recognition
Cross-matching the applicant’s face in real time against the central Aadhaar database, rather than relying on a static photograph.
2. Video-Based Verification
Requiring applicants to upload a 20–30 second video in which they hold up their original PAN and Aadhaar cards (each visible for at least 5 seconds) and read out a system-generated code, making it far harder to apply using only scanned or stolen document images.
3. Digital Alerts to Document Holders
Sending real-time SMS, email, and DigiLocker notifications to the actual PAN/Aadhaar owner the moment their credentials are used in a GST application, so the person at risk finds out immediately rather than after the fraud has run its course.
4. Geo-location and IP Tracking
Capturing and preserving the device location and IP address used during filing, to build a reliable audit trail for later investigation.
5. Universal Pre-Registration Physical Site Verification
Conducting a physical site visit of the declared place of business for every applicant, not only those flagged “high-risk,” which is precisely the loophole this case exposed.
6. Aadhaar Holder Express Confirmation
Obtaining affirmative confirmation directly from the Aadhaar holder that they have actual knowledge of the business being registered under their identity.
7. Automated Spike Monitoring
Flagging any newly registered business that shows a sudden, unexplained spike in turnover for immediate administrative audit.
8. Document Lock Checks
Integrating verification with government databases to automatically reject applications that rely on stolen or frozen identity documents.
9. Authorized Signatory Audit
Tightening biometric checks and secondary authentication for multi-state entities that operate through a single authorized signatory.
10. Chain-of-Custody Digital Trails
Maintaining verifiable, immutable digital logs at every stage of the approval process, so that sanctioning officers can be held accountable where lapses occur.
Taken together, these are not new burdens dreamed up to inconvenience genuine taxpayers. They are meant to catch the fraud before it enters the system, rather than chasing it — usually unsuccessfully — after the firm has vanished with the ITC chain intact and the real owner nowhere to be found.
A Welcome Course Correction
Nine years into GST, this order corrects something that should have been tightened much earlier. Genuine businesses have nothing to fear from a fingerprint scan or a short verification video; if anything, it protects them, since it is ordinary citizens whose stolen identities are being used to open fake firms in their names. For officers, it means fewer registrations granted on the strength of a scanned document alone, and a system where verifying a person is finally treated as seriously as verifying their paperwork.
The Court has given authorities a clear direction and a detailed menu of safeguards to consider. How quickly and thoroughly these are implemented on the ground will decide whether this becomes a genuine turning point, or another well-intentioned order that takes years to translate into practice.
Author: Aijaz Hussain Malik, JKAS, State Taxes Officer, Circle-C, Srinagar writes about GST compliance.






