Account Aggregator

What is an Account Aggregator?

Understanding the Account Aggregator: India's Infrastructure for Secure Consent-Based Financial Data Sharing

An Account Aggregator (AA) is a non-bank financial entity, regulated by the Reserve Bank of India (RBI), licensed specifically to fetch, and present customer financial information across multiple Financial Information Providers (FIPs & FIUs) with explicit customer consent. Unlike traditional data brokers, an AA is prohibited from processing, analyzing, or retaining customer financial data—it acts purely as a secure conduit.

What is an Account Aggregator

Regulatory Context

The Account Aggregator Framework

RBI Authorization: The RBI Account Aggregator Framework, codified in the RBI AA Master Directions, 2025 [RBI/DoR/2025-26/368, effective 28-Nov-2025], establishes the operational rules for AAs. Key characteristics:

Para 8(4): Core AA Functions

  • Retrieve financial information from FIPs
  • Present it to authorized FIUs
  • Limitations: No storage, processing, or analysis

Para 14(6): Business Scope

  • “NBFC-AA shall not undertake any other business other than the business of account aggregator.”
  • Lending, underwriting, advisory, analytics, investment management—all prohibited
  • Consent management is within scope (We are implied consent managers under the DPDP Act.)

Para 36: Customer Data Protection

  • “Shall not use or access any customer information other than for performing the business of the account aggregator explicitly requested by the customer.”
  • Strict limitation on data access and use

Data Protection

DPDP Act 2023 Alignment

Sec 6: Consent Requirements

AAs facilitate consent that must be:

  • Free: Not conditional on unrelated services
  • Informed: With a clear, itemized notice of what data is requested and why
  • Specific: For particular purposes, not blanket consent
  • Unambiguous: Given through clear affirmative action (Sec 6(1))
  • Revocable: Withdrawal must be as easy as giving consent (Sec 6(4))

Sec 5: Notice Requirement

Before or at the time of seeking consent, FIUs must provide:

  • An itemized description of personal data to be collected
  • The specific purpose(s) for processing, as defined under ReBIT Purpose Codes
  • Clear and plain language
  • Information on how to exercise data rights (access, correction, erasure)

Comparison

How Account Aggregators Differ from Traditional Data Sharing

Aspect Traditional Data Sharing Account Aggregator Model
Authorization Often implicit or buried in ToS Explicit, granular, itemized consent per data category
Data Retention Data often stored and re-used No storage; real-time retrieval and transfer only
Processing Data processed for various purposes No processing; data pipe only
Revocation Difficult or cumbersome to withdraw Instant withdrawal via consent management
Regulatory Oversight Limited; varies by data type Direct RBI regulation and DPDP Act compliance
User Control Limited visibility and control Full visibility; customers see exactly what's shared, with whom, and when

Ecosystem

Account Aggregator Ecosystem: Key Players

Financial Information Providers (FIPs):

  • Banks, insurance companies, mutual fund houses, pension funds
  • Hold customer financial data at source
  • Share data only upon receiving AA notification of valid customer consent
  • Remain liable for accuracy of data provided

Financial Information Users (FIUs):

  • Banks, NBFCs, fintech platforms, insurance companies
  • Receive customer-consented financial data via AA
  • Perform their own underwriting, verification, or analysis
  • Cannot use data beyond the consented scope

Account Aggregators (like OMS AA):

  • Licensed by RBI
  • Intermediate between FIPs and FIUs
  • Manage consent lifecycle, fetch data, audit and report
  • No storage, analysis, or secondary use of data

Customers (Data Principals):

  • Decide which data to share, with whom, and for how long
  • Can withdraw consent instantly
  • Have the right to access, correct, and request erasure of their data

Impact

Benefits of the Account Aggregator Model

For Customers

  • Data Sovereignty: Full control over personal financial information
  • Transparency: Clear visibility into what data is shared, with whom, and when
  • Convenience: No need to download and manually upload statements
  • Security: Encrypted, regulated infrastructure
  • Rights: Easy-to-exercise data rights (access, correction, erasure)

For Financial Institutions (FIPs & FIUs)

  • Speed: Instant access to verified customer financial data
  • Compliance: Built-in DPDP Act and RBI AA compliance; reduced regulatory risk
  • Efficiency: Faster loan underwriting, KYC refresh, and credit decisioning
  • Cost Reduction: Lower operational costs vs. manual document handling
  • Customer Experience: Seamless, consent-first data sharing experience

For the Financial System

  • Financial Inclusion: Enables credit access for under-served segments (gig workers, small businesses)
  • Market Efficiency: More accurate credit decisioning based on real financial data
  • Risk Reduction: Better asset quality through improved underwriting
  • Systemic Stability: Regulated infrastructure reduces shadow banking and unverified lending