Understanding RBI's Account Aggregator Framework: A Complete Beginner's Guide

No jargon assumed. If you've ever wondered how a lending app "reads" your bank statement in seconds without you emailing a PDF, this is the framework behind it — explained from the ground up.

Quick Answer

The Account Aggregator (AA) framework is an RBI-regulated system that lets you share your own financial data — bank statements, tax filings, insurance policies, investments — digitally and securely, with your explicit consent, instead of emailing PDFs or standing in a bank queue. An Account Aggregator is a licensed NBFC that acts purely as a secure pipe: it moves data from the institution that holds it (called a Financial Information Provider) to the institution that needs it (a Financial Information User), but never actually reads or stores the data itself.

As of March 2026, 179 institutions are live as data providers, 989 as data users, and over 2.88 billion accounts are enabled for this kind of sharing across banking, investments, insurance and tax records.

What Is the Account Aggregator Framework?

Think about the last time you applied for a loan. Somewhere in that process, you probably had to download bank statements, dig up salary slips, or email PDFs of your investment holdings. Someone on the other end then had to manually check all of it. That's slow, easy to fake, and puts your financial documents in more inboxes than necessary.

The Account Aggregator framework is RBI's answer to that problem. Instead of you handling files, you give digital consent, and your data moves directly and securely between regulated institutions — never through your email, never through a shared drive.

It was formally introduced through the Master Direction – Non-Banking Financial Company – Account Aggregator (Reserve Bank) Directions, first issued on 2 September 2016, and went into real, commercial operation in September 2021 after several years of pilot testing across banks and technology providers. It's now one of the pillars of India's Data Empowerment and Protection Architecture (DEPA), built jointly with input from RBI, SEBI, IRDAI and PFRDA — which is why it now covers not just bank accounts, but investments, insurance policies, pensions and tax records too.

How It Actually Works

Every AA transaction involves three roles. It helps to give them names before anything else:

  • Financial Information Provider — the institution that already holds your data: your bank, insurer, mutual fund depository, or even the GST Network.

Account Aggregator — a licensed NBFC that carries your data from the FIP to the FIU, with your consent. It's "data-blind" by design: it can route the data, but it cannot read or store it.

Financial Information User — the institution that needs your data for a service you've asked for, like a lender assessing a loan application.

Step by Step Consent flow

  1. 1. You request a service

e.g. apply for a loan with an FIU

  1. 2. You approve a consent request

Scope, purpose and duration are all shown upfront

  1. 3. AA fetches your data

Encrypted, directly from the FIP

  1. 4. Data reaches the FIU

Still encrypted; the AA never reads it

The permission you give is called a consent artefact — a digitally signed, machine-readable record of exactly what you agreed to share, with whom, and for how long. You can revoke it at any time, and every step is logged, so there's a clear trail of who accessed what and when.

The Old Way vs. the Account Aggregator Way

What changes for the person sharing their data

FactorManual document sharingAccount Aggregator framework
How data movesPDF over email, printouts, USB drivesEncrypted, direct transfer between institutions
Who sees itAnyone in the email chainOnly the FIU you consented to — not even the AA can read it
ConsentImplicit, one-time, hard to trackExplicit, scoped, logged and revocable anytime
SpeedHours to daysSeconds to minutes
Risk of tamperingDocuments can be edited before sharingData comes directly from the source institution
Scope coveredWhatever document you can findBanking, investments, insurance, pensions and tax records

Who Regulates and Governs the AA Ecosystem?

The framework sits under the RBI as the primary regulator, since every Account Aggregator is licensed as an NBFC-AA. But because AA now spans banking, securities, insurance and pensions, it's genuinely cross-sectoral — developed jointly with SEBI, IRDAI and PFRDA under the DEPA umbrella.

Recent development

On 5 June 2026, RBI officially recognised Sahamati Foundation as the SRO-AA — the Self-Regulatory Organisation for the Account Aggregator ecosystem — following a framework RBI issued in March 2025 inviting applications via the PRAVAAH portal. Sahamati already acted as the industry alliance coordinating the ecosystem; this recognition gives that role formal regulatory standing for governance, technical standard-setting and compliance oversight.

On the technical side, every AA and every FIP/FIU integration is built to specifications published by ReBIT (Reserve Bank Information Technology Pvt Ltd) at api.rebit.org.in, covering consent management, data fetch, and encryption — and certified by a Sahamati-empanelled auditor before going live.

The AA Ecosystem in 2026

This isn't a niche pilot anymore — it's one of the largest consent-based financial data-sharing networks in the world.

179

Financial Information Providers live

989

Financial Information Users live

2.88B+

Accounts enabled for sharing

284.6M

Accounts linked by users

Figures as of 31 March 2026, per the Government of India's Department of Financial Services. Separately, Sahamati's own ecosystem count (as of its June 2026 SRO recognition) reported 17 operational, RBI-licensed Account Aggregators in production. Since RBI's October 2023 circular, any regulated entity that wants to consume data as an FIU must also contribute data as an FIP if it holds financial information — a bilateral rule designed to keep the ecosystem from becoming one-sided.

How Businesses Can Join the AA Ecosystem

As a Financial Information Provider or User

If you're a bank, NBFC, insurer, or another RBI/SEBI/IRDAI/PFRDA-regulated entity, joining as an FIP or FIU is primarily an integration exercise — building to ReBIT's API specifications and getting Sahamati-empanelled certification, rather than a fresh licensing process.

As an Account Aggregator (NBFC-AA)

  1. Incorporate a company and apply for an NBFC-AA Certificate of Registration from RBI.
  2. Meet the Net Owned Fund requirement — ₹2 crore for NBFC-AA, lower than the ₹10 crore bar for most lending NBFCs.
  3. Build your platform to ReBIT's technical specifications for consent management and data exchange.
  4. Complete certification with a Sahamati-empanelled auditor before onboarding live FIPs and FIUs.
  5. Onboard FIPs and FIUs and go live within the Sahamati-coordinated ecosystem.

Common Mistakes and Misconceptions

Thinking the AA can see or sell your data.

AAs are "data-blind" by design — they route encrypted data, they don't read or monetize it.

Confusing an Account Aggregator with a credit bureau.

An AA doesn't score or evaluate you — it just moves data you've approved, to a party you've chosen, for a purpose you've agreed to.

Assuming consent is permanent.

Every consent artefact has a defined scope and duration, and you can revoke it at any time.

Believing AA only covers bank accounts.

Insurance policies, mutual fund and depository holdings, pension data and even GST records are all in scope as FIP categories.

Skipping the bilateral FIP/FIU rule.

Since October 2023, an FIU that holds financial information must also register as an FIP — a detail that trips up businesses planning their AA integration scope too narrowly.

Best Practices for Businesses Building on AA

Design consent screens for clarity, not just compliance

— users should understand exactly what they're sharing and why.

Build for revocation, not just collection

— make it as easy to withdraw consent as it was to give it.

Plan your FIP obligations early

if you're joining as an FIU with your own financial data to contribute.

Treat ReBIT's specifications as the source of truth

not a summarised version from a blog or vendor.

Track Sahamati's ecosystem updates directly

now that it holds formal SRO status — standards and audit requirements will keep evolving.

Expert Tips

Pro tip

If you're a lender evaluating whether to build AA integration in-house or through a partner, weigh it against how you'd already use bank account verification and PAN verification APIs in your onboarding flow — AA consent data and identity verification are usually part of the same underwriting journey, and integrating them together avoids building two separate compliance and consent-management layers.

AOPAY supports the licensing side of this through our NBFC Account Aggregator license advisory, alongside GST and Aadhaar verification APIs that pair naturally with AA-based lending and onboarding workflows — so whether you're becoming an AA yourself or plugging into the ecosystem as an FIU, the compliance and integration groundwork can sit with one team.

Readiness Checklist

Clarified whether you need to join as an FIP, FIU, or full NBFC-AA
Reviewed ReBIT's technical specifications at api.rebit.org.in
Identified a Sahamati-empanelled auditor for certification
Confirmed whether the bilateral FIP/FIU rule applies to your business
Designed consent screens that are clear about scope, purpose and duration
Built a straightforward path for users to revoke consent

Frequently Asked Questions

Key Takeaways

  • The Account Aggregator framework lets you share financial data digitally, securely and with explicit, revocable consent.
  • Three roles matter: the FIP (holds data), the AA (moves it, data-blind), and the FIU (uses it with your consent).
  • It covers far more than banking — investments, insurance, pensions and tax records are all in scope.
  • Sahamati became the RBI-recognized SRO-AA in June 2026, formalizing governance that was previously industry-coordinated.
  • The ecosystem is large and growing: 2.88 billion+ accounts enabled, 989 live FIUs, 17 operational AAs as of early-to-mid 2026.
  • Businesses can join as an FIP, FIU, or by becoming a licensed NBFC-AA, depending on their role in the data flow.

Building something on the Account Aggregator framework?

Whether you're pursuing an NBFC-AA license or integrating as an FIU alongside verification APIs, AOPAY's team can walk through the compliance and technical path with you.

This article is for general information and does not constitute legal or regulatory advice. Details reflect RBI's Account Aggregator framework and Sahamati's SRO-AA status as of July 2026; confirm current requirements with RBI's official publications, Sahamati, or a licensed compliance advisor before acting. © 2026 AOPAY. All rights reserved.