“We only move data” is not enough to classify an account-aggregator product. RBI created a specific NBFC-AA framework for consent-based retrieval and presentation of financial information, with defined roles and restrictions.
A founder should first decide whether the company will operate the AA layer, supply technology to an authorised AA, analyse data for a permitted user, or lend money. Those are not interchangeable businesses.
Quick Answer
An entity operating an Account Aggregator under RBI’s NBFC-AA framework needs to assess registration and the current minimum net owned fund, which the direction specifies as ₹2 crore. An AA enables consent-based transfer of financial information between providers and users; it is not automatically a lender, data owner or payment operator. The real role determines the licence and controls.
1. What an Account Aggregator does
The AA system gives a customer a way to authorise transmission of specified financial information from a financial information provider to a financial information user. The consent artefact defines scope, purpose and duration. The AA is a regulated intermediary, not an owner free to sell the customer’s records.
Draw the exact provider, AA and user journey. Explain what the customer sees before consent, how revocation is handled and what data the operator can access or retain. A product screen that combines several permissions into a vague blanket consent deserves redesign.
- Map each FIP, FIU and AA party.
- Record consent purpose and expiry.
- Plan revocation and audit logs.
2. Registration and capital
RBI’s NBFC-AA directions cover the eligible company, certificate of registration and minimum net owned fund. The ₹2 crore requirement is a regulatory calculation rather than a figure that can be satisfied by authorised capital alone. Founders must check current RBI text and evidence requirements before an application.
Ownership and governance also matter. A foreign-funded structure may have separate FDI and FEMA questions. The application should match the actual technology and contractual architecture, including which group company operates the consent layer.
- Calculate net owned fund accurately.
- Document ownership and decision-makers.
- Align application, contracts and software.
3. What AA is not
An AA is not a shortcut to accept deposits, make loans or run payments. A lender that consumes information through an AA may have its own RBI obligations. A SaaS vendor that builds a dashboard for a licensed participant can occupy a different position from the AA operator.
The distinction affects customer claims. Saying the app is “RBI approved” because it connects to an AA ecosystem can mislead users if the startup itself has no such registration. Identify the regulated legal entity by name in contracts and product disclosures.
- Separate AA and lending roles.
- Avoid implying customer funds are held by AA.
- Check claims made by distribution partners.
4. Continuing controls
An AA design needs consent records, information security, participant contracts, grievance handling and operational resilience. Data minimisation and access controls should be tested with actual use cases, not a generic privacy policy. Audit trails should show when a request was made and under which consent.
The operating model may change as new financial information categories or use cases are added. Review those changes against RBI directions before release. A bank or regulated FIU may impose additional contractual controls.
- Test consent and revocation end to end.
- Restrict staff access to customer information.
- Assign owners for complaints and incident response.
How to record the decision
A short decision note should explain why the chosen route fits the facts, which authority controls the point, what was checked and which assumptions remain open. For Account Aggregator business, the note should also identify the responsible person, the next filing or approval event and the evidence that supports each conclusion.
Keep the note with board materials, agreements, portal acknowledgements and professional advice. This simple record helps founders answer investor, lender and regulator questions without reconstructing the reasoning months later. Update it whenever the business model, ownership, money flow, instrument terms or scheme status changes.
Documents to keep in one working file
The exact set depends on the transaction, but the working file should make the facts easy to test. Start with these records and add authority-specific forms or declarations where required:
- Map every provider, AA and user.
- Describe consent collection and revocation.
- Check company, capital and registration status.
- Review FDI/FEMA if foreign-funded.
- Prepare security, contracts and grievance controls.
Use dated versions and keep a clear approval trail. A missing email, valuation input or portal receipt can become a material due-diligence issue even when the commercial decision itself was sound.
Decision table
Use the facts of the proposed transaction to test each row before choosing a route.
| Model | Core regulatory question |
|---|---|
| AA operator | Does NBFC-AA registration apply? |
| AA technology vendor | Who is the licensed customer-facing operator? |
| Financial data analytics | Who may receive and use consented information? |
| Lending app | Which lender and digital-lending rules apply? |
Practical checklist
Work through these steps using dated documents, not assumptions made in a pitch deck.
- Map every provider, AA and user.
- Describe consent collection and revocation.
- Check company, capital and registration status.
- Review FDI/FEMA if foreign-funded.
- Prepare security, contracts and grievance controls.
- Validate customer claims before launch.
Mistakes that create avoidable delay
The following shortcuts frequently create avoidable legal or filing work later.
- Treating an AA connection as authority to lend.
- Using blanket consent for unrelated purposes.
- Claiming RBI registration belonging to a partner.
When professional review is useful
A fact-specific review should test the chosen route, evidence and filing sequence before money or customer commitments make a correction expensive.
For a fact-specific review, share the proposed activity, ownership, funding instrument and present stage with Sunny G And Co. at contact@cssunnygupta.com. The scope and professional fee should be agreed only after the facts and required filings are clear.
Related service paths
If the issue involves actual filings or structuring, these service pages describe the relevant scope of work. They do not change the eligibility and approval tests explained above; the right route still depends on the company’s documents and intended activity.
Official sources and last review
This article was last reviewed on 15 September 2026. Rules, portal status and filing practices can change, so check the current authority before acting.