FAQs

General Questions

An Account Aggregator (AA) is an RBI-licensed intermediary that facilitates secure, consent-based financial data sharing across multiple institutions. OMS AA is an NBFC-AA. We enable seamless data access between FIPs and FIUs, but we never store, process, or analyze customer data.

Yes. OMS AA is licensed by the RBI as an NBFC Account Aggregator under the RBI AA Master Directions, 2025. We comply with the Digital Personal Data Protection Act, 2023.

OMS AA employs multiple layers of protection:
  • TLS 1.3 encryption for data in transit
  • Customer authentication required for consent approval
  • No data storage (consent-based, real-time data sharing only)
  • Audit logs of every consent and data-sharing session
  • Quarterly reports provided to Sahamati
  • RBI oversight and compliance monitoring

OMS AA facilitates sharing of financial data as per ReBIT-defined FI (Financial Information) Types, including:
  • Bank account details and statements (savings, current, FD, RD)
  • Loan account information
  • Mutual fund and investment data
  • Insurance policies
  • Tax information (Income Tax, GSTN)
  • EPFO data

Most requests are processed in real-time (within seconds). If a Financial Information Provider (FIP) is slower to respond, it may take a few minutes.
For Banks (FIPs)

As an FIP, your bank benefits from:
  • Reduced data sharing requests from customers (automated via OMS AA)
  • Compliance with RBI's open finance direction
  • Improved customer relationship (transparent data sharing)
  • Potential new revenue from data monetization (future models)

Banks need to:
  • Connect their core banking system to OMS AA's API
  • Set up data access endpoints for the requested data categories
  • Implement consent verification logic
  • Set up webhook listeners for consent notifications
OMS AA provides comprehensive integration guides and support.

Yes. FIPs must:
  • Verify customer consent before sharing data (per DPDP Act, 2023 Sec 5-6)
  • Share only the consented data
  • Maintain records of data shares for audit
  • Respond to data subject rights requests (access, correction, erasure)
  • Comply with RBI guidelines on data sharing

FIPs remain liable for the accuracy and security of their transmitted data. OMS AA provides:
  • Encrypted transmission channels
  • Receipt acknowledgments
  • Audit trails
  • Incident response coordination
FIPs should ensure their data is accurate before transmission.
For NBFCs & Lenders (FIUs)

Via OMS AA, FIUs (lenders/NBFCs) can:
  1. Access consented customer financial data (bank statements, income records) in real-time
  2. View income data across multiple FIPs
  3. Assess existing liabilities from consented loan account data
  4. Enable faster credit decisioning with real-time data access
  5. Reduce reliance on self-reported data through consent-based financial data sharing

Most requests are fulfilled within minutes to hours, depending on FIP response times. OMS AA operates in real-time; any delays are typically on the FIP side.

No. DPDP Act, 2023 Sec 8 requires that data be used only for the purpose stated in consent (Para 36, RBI AA Master Directions, 2025). Any secondary use requires explicit customer consent.

Once consent expires, you cannot access or use that customer's data. You must request fresh consent for any ongoing relationship (e.g., loan renewal).
For Developers

We also provide REST API documentation for any language.

Standard tier: 100 requests/minute. Higher limits available for enterprise customers.

Yes. OMS AA Sandbox provides:
  • Test API credentials
  • Mock FIPs with realistic data
  • Webhook testing tools
  • No charges for sandbox API calls

OMS AA uses OAuth 2.0 for authorization and API keys for authentication. See the API documentation for implementation details.
Compliance & Regulatory Questions

OMS AA compliance with the DPDP Act includes:
  • Sec 5 (Notice): We ensure clear, itemized notices are provided before consent is sought
  • Sec 6 (Consent): Granular, specific, informed, and revocable consent collection
  • Sec 8 (Data Fiduciary Duties): Security safeguards, accuracy, retention limits, erasure
  • Sec 13 (Grievance Redressal): We maintain an effective grievance mechanism
  • Sec 6(4): Withdrawal is as easy as giving consent (1-click revocation)

No, but you share responsibility. OMS AA is compliant with requirements. However:
  • FIPs must verify consent and share only consented data
  • FIUs must use data only for consented purposes
  • Both must comply with data subject rights requests
OMS AA provides audit trails and support to help you meet your obligations.

Yes. We proactively monitor emerging DPDP Rules and adjust our platform accordingly. We are already preparing for:
  • Rule 4 (Consent Manager registration, effective 13-Nov-2026)
  • Rule 6 (Data audit requirements)
  • Additional requirements for Significant Data Fiduciaries