Business Enquiries
+91 9819 000 511 | +91 9821 83 26 83  +91 9167 058 000
 
     
   
 

NBFC Account Aggregator (AA) Compliance

N D Savla & Associates advises fintech promoters and financial institutions on NBFC Account Aggregator (AA) Compliance, covering RBI registration and the ongoing governance an Account Aggregator must maintain once operational. An Account Aggregator is a specific NBFC category created to let individuals consolidate and share their financial data across banks, NBFCs, mutual funds, and insurers through a consent-based digital framework, without the aggregator itself ever storing or reading that data. It's one of the more tightly conditioned NBFC licences RBI issues, and the compliance obligations are as much about data governance as they are about capital and prudential norms.

This page explains what an Account Aggregator does, the registration requirements, the consent architecture RBI mandates, and the ongoing compliance obligations. If you're building a fintech product around India's account aggregator ecosystem, this is where licensing and compliance planning should start.

?? Note: An Account Aggregator is prohibited from viewing, storing, or reading the financial data it transmits between institutions — its role is strictly a consent-based data pipe. Building any capability to read or retain customer data, even for analytics, breaches the core condition of the RBI licence.

What Is an Account Aggregator NBFC?

An Account Aggregator (NBFC-AA) is a non-deposit-taking NBFC that provides the service of retrieving and consolidating financial information of a customer, based on the customer's explicit consent, and transmitting it between financial information providers — banks, NBFCs, mutual funds, insurers, and pension funds — and financial information users, such as a lender assessing a loan application. Critically, the AA is a pure intermediary: it facilitates the data flow but is legally barred from accessing, viewing, storing, or using the financial data it transmits for any purpose beyond the specific consent given.

This model exists to let individuals and small businesses share verified financial data — bank statements, GST returns, mutual fund holdings, insurance policies — with a lender or other financial institution instantly and digitally, replacing the older process of manually collecting and uploading these documents. The AA framework only works because customers trust that their data isn't being read, retained, or repurposed by the aggregator itself, which is why RBI's conditions around this are unusually strict compared to most other NBFC categories.


RBI's Licensing Requirements for an Account Aggregator

  • Minimum Net Owned Fund as prescribed under RBI's Account Aggregator Master Directions, to be maintained on an ongoing basis.
  • A technology architecture that demonstrably prevents the AA from storing, reading, or processing the financial data it transmits, beyond what's needed for transient routing.
  • Data security and encryption standards for data in transit, since even momentary mishandling of unencrypted financial data would breach the core licence condition.
  • A board and management team with demonstrated technology and financial sector governance capability, evaluated as part of RBI's fit-and-proper review.
  • Empanelment or integration readiness with the Account Aggregator ecosystem's technical specifications, since interoperability across the network is a functional requirement, not an optional feature.

What Our Account Aggregator Compliance Services Include

  • Licensing Application Support: preparing and filing the NBFC-AA registration application with RBI, including technology architecture disclosures.
  • Consent Architecture Review: reviewing the proposed consent artefact design, data flow, and retention policy against RBI's Account Aggregator Master Directions before the application is filed.
  • Net Owned Fund Structuring: computing NOF and advising on capital structuring to meet the prescribed threshold.
  • Data Governance Policy Drafting: preparing the data protection, consent management, and grievance redressal policies RBI expects an AA to maintain.
  • Ongoing Compliance Support: managing periodic prudential returns, technology audits, and consent-handling compliance checks once the AA is operational.

Our Account Aggregator Registration Process

  1. Design the technology architecture and consent flow in line with RBI's Account Aggregator Master Directions and the ecosystem's technical specifications.
  2. Compute Net Owned Fund and confirm the entity meets or can be capitalised to meet RBI's prescribed minimum.
  3. Compile promoter, director, and technology governance documentation for the registration application.
  4. Submit the NBFC-AA registration application to RBI and respond to technology and governance clarifications raised during review.
  5. On approval, complete technical integration with the Account Aggregator ecosystem and finalise consent-handling operating procedures.

Documents Typically Required for AA Registration

  • Certificate of incorporation and Memorandum and Articles reflecting the account aggregation business as a permitted object.
  • Technology architecture documentation demonstrating compliance with data-handling restrictions under RBI's Master Directions.
  • Net Owned Fund computation certified by a Chartered Accountant.
  • Fit-and-proper declarations for directors and key management, with particular focus on technology and data governance experience.
  • Data protection and consent management policy documents for RBI's review.

Ongoing Compliance Obligations for a Registered AA

Once licensed, an Account Aggregator must maintain its Net Owned Fund above the prescribed threshold, undergo periodic technology and security audits confirming it continues to operate strictly as a data pipe without reading or storing transmitted information, and submit prudential returns to RBI on its financial position and operational metrics. The consent artefact — the digital record of what data a customer has agreed to share, with whom, and for how long — has to be maintained accurately and made available for audit, since disputes over what a customer actually consented to are one of the most common points of regulatory and customer friction in this business.

AAs also need robust grievance redressal mechanisms, since customers routing sensitive financial data through the AA ecosystem expect fast resolution when a data-sharing request appears incorrect or unauthorised, and RBI evaluates the responsiveness of this mechanism during supervisory reviews.


The Broader Account Aggregator Ecosystem and Interoperability

An individual AA doesn't operate as a standalone product — its value depends entirely on how well it interoperates with every other participant in the account aggregator network, since a lender using one AA needs to be able to pull data from a bank connected through a different AA seamlessly. This means technical compliance isn't just about satisfying RBI at the licensing stage; it's an ongoing requirement to keep pace with evolving technical specifications as the ecosystem's central infrastructure is updated and as new categories of financial information providers join the network.

For fintech promoters evaluating whether to build a standalone AA licence versus partnering with an existing licensed AA for a specific use case, this interoperability overhead is often the deciding factor — maintaining full ecosystem compliance requires dedicated technical and compliance resourcing that only makes sense at a certain scale. We advise promoters on this build-versus-partner decision as part of the initial NBFC Registration Services assessment, before committing to a full licensing process.


Timeline and Effort Involved in AA Registration

Because RBI's review of an AA application involves genuine technology due diligence — verifying the architecture actually prevents data storage and read access, not just reviewing a policy document that claims it does — the registration timeline tends to run longer than for a conventional lending NBFC. Promoters who invest in a technically sound, well-documented architecture before filing generally move through review faster than those who file first and attempt to retrofit compliance into an already-built system.

We recommend engaging on the technology architecture review well before the formal application is filed, since redesigning a data pipeline after RBI has already raised concerns during processing adds far more delay than getting the design right at the outset.


Frequently Asked Questions

Can an Account Aggregator store or view customer financial data?
No. An Account Aggregator is licensed on the specific condition that it acts purely as a consent-based data pipe, transmitting financial information between institutions without storing, reading, or using that data for any other purpose — this is a core condition of the RBI licence, not a best-practice recommendation.
What financial institutions can share data through an Account Aggregator?
Financial information providers in the AA ecosystem include banks, NBFCs, mutual funds, insurance companies, and pension funds, all of whom can share a customer's financial data with a financial information user once the customer has given explicit digital consent.
Is a minimum Net Owned Fund required to register as an Account Aggregator?
Yes. RBI prescribes a minimum Net Owned Fund under the Account Aggregator Master Directions that must be met at registration and maintained on an ongoing basis, similar to the capital requirements applicable to other NBFC categories.
What happens if an Account Aggregator's technology doesn't meet RBI's data-handling requirements?
RBI's registration review specifically evaluates the technology architecture for compliance with data-handling restrictions, and an application demonstrating inadequate safeguards will face delays or rejection until the architecture is corrected and re-verified.
Do customers pay to use an Account Aggregator's data-sharing service?
Pricing models vary across the ecosystem and are commercial decisions for each AA, though the underlying regulatory framework focuses on consent, data security, and interoperability rather than prescribing how the service is monetised.
Is it better to build a standalone AA licence or partner with an existing licensed AA?
This depends on scale and use case — maintaining full interoperability with the account aggregator ecosystem requires dedicated technical and compliance resourcing that only becomes cost-effective at a certain transaction volume, which is why many fintechs start by partnering with an existing licensed AA before evaluating a standalone licence.

Get Your Account Aggregator Licence and Compliance Right

NBFC-AA registration and consent architecture compliance services for fintech and financial data-sharing businesses.

Phone / WhatsApp: +91 98218 32683  |  +91 98190 00511  |  +91 91670 58000

Email: nainitsavla@savlagroup.in

Address: Suit No.102, L1, Ashok Premises, Nicholas Road, Andheri (East), Mumbai – 400069, Maharashtra

Contact Us Today