U 110, First Floor, Shakarpur, Delhi 110092, Indiacontact@cssunnygupta.comMon - Sat: 10:00 AM - 7:00 PM
Follow Us:
RBI / SEBI / NBFC Updates

Account Aggregator Business in India: NBFC-AA Registration, Eligibility and Compliance Explained

An entity operating an Account Aggregator under RBI’s NBFC-AA framework needs to assess registration and the current minimum net owned fund, which the direction specifies as ₹2 crore. An AA enables consent-based transfer of financial information between providers and users; it is not automatically a lender, data owner or payment operator. The real role determines the licence and controls.

CS Sunny Gupta, ACS 01 October 2026 5 min read
Account Aggregator Business in India: NBFC-AA Registration, Eligibility and Compliance Explained - RBI / SEBI / NBFC Updates blog cover image
Last updated 01 Oct 2026

“We only move data” is not enough to classify an account-aggregator product. RBI created a specific NBFC-AA framework for consent-based retrieval and presentation of financial information, with defined roles and restrictions.

A founder should first decide whether the company will operate the AA layer, supply technology to an authorised AA, analyse data for a permitted user, or lend money. Those are not interchangeable businesses.

Quick Answer

An entity operating an Account Aggregator under RBI’s NBFC-AA framework needs to assess registration and the current minimum net owned fund, which the direction specifies as ₹2 crore. An AA enables consent-based transfer of financial information between providers and users; it is not automatically a lender, data owner or payment operator. The real role determines the licence and controls.

1. What an Account Aggregator does

The AA system gives a customer a way to authorise transmission of specified financial information from a financial information provider to a financial information user. The consent artefact defines scope, purpose and duration. The AA is a regulated intermediary, not an owner free to sell the customer’s records.

Draw the exact provider, AA and user journey. Explain what the customer sees before consent, how revocation is handled and what data the operator can access or retain. A product screen that combines several permissions into a vague blanket consent deserves redesign.

  • Map each FIP, FIU and AA party.
  • Record consent purpose and expiry.
  • Plan revocation and audit logs.

2. Registration and capital

RBI’s NBFC-AA directions cover the eligible company, certificate of registration and minimum net owned fund. The ₹2 crore requirement is a regulatory calculation rather than a figure that can be satisfied by authorised capital alone. Founders must check current RBI text and evidence requirements before an application.

Ownership and governance also matter. A foreign-funded structure may have separate FDI and FEMA questions. The application should match the actual technology and contractual architecture, including which group company operates the consent layer.

  • Calculate net owned fund accurately.
  • Document ownership and decision-makers.
  • Align application, contracts and software.

3. What AA is not

An AA is not a shortcut to accept deposits, make loans or run payments. A lender that consumes information through an AA may have its own RBI obligations. A SaaS vendor that builds a dashboard for a licensed participant can occupy a different position from the AA operator.

The distinction affects customer claims. Saying the app is “RBI approved” because it connects to an AA ecosystem can mislead users if the startup itself has no such registration. Identify the regulated legal entity by name in contracts and product disclosures.

  • Separate AA and lending roles.
  • Avoid implying customer funds are held by AA.
  • Check claims made by distribution partners.

4. Continuing controls

An AA design needs consent records, information security, participant contracts, grievance handling and operational resilience. Data minimisation and access controls should be tested with actual use cases, not a generic privacy policy. Audit trails should show when a request was made and under which consent.

The operating model may change as new financial information categories or use cases are added. Review those changes against RBI directions before release. A bank or regulated FIU may impose additional contractual controls.

  • Test consent and revocation end to end.
  • Restrict staff access to customer information.
  • Assign owners for complaints and incident response.

How to record the decision

A short decision note should explain why the chosen route fits the facts, which authority controls the point, what was checked and which assumptions remain open. For Account Aggregator business, the note should also identify the responsible person, the next filing or approval event and the evidence that supports each conclusion.

Keep the note with board materials, agreements, portal acknowledgements and professional advice. This simple record helps founders answer investor, lender and regulator questions without reconstructing the reasoning months later. Update it whenever the business model, ownership, money flow, instrument terms or scheme status changes.

Documents to keep in one working file

The exact set depends on the transaction, but the working file should make the facts easy to test. Start with these records and add authority-specific forms or declarations where required:

  • Map every provider, AA and user.
  • Describe consent collection and revocation.
  • Check company, capital and registration status.
  • Review FDI/FEMA if foreign-funded.
  • Prepare security, contracts and grievance controls.

Use dated versions and keep a clear approval trail. A missing email, valuation input or portal receipt can become a material due-diligence issue even when the commercial decision itself was sound.

Decision table

Use the facts of the proposed transaction to test each row before choosing a route.

ModelCore regulatory question
AA operatorDoes NBFC-AA registration apply?
AA technology vendorWho is the licensed customer-facing operator?
Financial data analyticsWho may receive and use consented information?
Lending appWhich lender and digital-lending rules apply?

Practical checklist

Work through these steps using dated documents, not assumptions made in a pitch deck.

  1. Map every provider, AA and user.
  2. Describe consent collection and revocation.
  3. Check company, capital and registration status.
  4. Review FDI/FEMA if foreign-funded.
  5. Prepare security, contracts and grievance controls.
  6. Validate customer claims before launch.

Mistakes that create avoidable delay

The following shortcuts frequently create avoidable legal or filing work later.

  • Treating an AA connection as authority to lend.
  • Using blanket consent for unrelated purposes.
  • Claiming RBI registration belonging to a partner.

When professional review is useful

A fact-specific review should test the chosen route, evidence and filing sequence before money or customer commitments make a correction expensive.

For a fact-specific review, share the proposed activity, ownership, funding instrument and present stage with Sunny G And Co. at contact@cssunnygupta.com. The scope and professional fee should be agreed only after the facts and required filings are clear.

If the issue involves actual filings or structuring, these service pages describe the relevant scope of work. They do not change the eligibility and approval tests explained above; the right route still depends on the company’s documents and intended activity.

Official sources and last review

This article was last reviewed on 15 September 2026. Rules, portal status and filing practices can change, so check the current authority before acting.

Frequently Asked Questions

Short answers for the questions readers usually ask after reading this guide.

It enables consent-based transfer of financial information between authorised ecosystem participants.

RBI has a specific NBFC-AA registration framework for the operator.

The direction specifies ₹2 crore; verify current rules before applying.

AA registration itself does not authorise lending.

Its role is controlled by consent and RBI restrictions, not unrestricted ownership.

Yes, but the vendor and operator roles must be clearly separated.

Assess FDI and FEMA conditions alongside RBI rules.

Consent must be controllable and evidenced through the customer journey.

Related Blogs

Continue reading practical guides on this topic.

LET'S GET STARTED

Need help with registration or compliance?

Talk to an experienced company secretary about your next step.