How It Works

How OMS AA Enables Secure Consent-Based Financial Data Sharing

Our platform guides customers through a seamless, transparent consent process, enabling secure financial data transfer in full compliance with the DPDP Act, 2023, and RBI Directions, 2025.


The Consent Flow

The Six-Step Process

Step 1: Consent Initiation by FIU

What Happens: A financial institution (FIU) — such as an NBFC lending platform or a bank's loan processing system — initiates a customer's consent request via OMS AA's API. The FIU specifies:

  • Which financial data categories are needed (bank statements, income, investment details, etc.)
  • The purpose(s) of data access (loan underwriting, insurance underwriting, etc.)
  • The time period for which the FIU needs the data
  • The validity period for the consent (e.g., 1 year, with auto-expiry)
DPDP Act, 2023 (Sec 6): The consent request is framed with:
  • Specificity: Only the data needed for the stated purpose is requested, not blanket access
  • Clarity: Purpose is clearly articulated in plain language
  • Itemization: Each data category is listed separately so the customer sees exactly what's being requested

Step 2: Consent Presentation to Customer

What Happens: OMS AA displays the consent request to the customer via a secure, user-friendly consent interface. The consent artifact includes:

  • Itemized Data Request: A clear list of every data category being requested (e.g., "Bank Statement (6 months)", "Income Details", "Loan Account Summary")
  • Purpose Disclosure: Why the FIU needs this data (e.g., "To process your loan application" or "To verify your KYC information")
  • Data Source Selection: If the customer has multiple accounts at different banks, they select which accounts to share
  • Validity Period: How long this consent remains valid (e.g., "Valid for 1 year, or until revoked")
  • Withdrawal Notice: Clear information that consent can be revoked anytime, instantly
  • FIU Identity: Clear identification of the institution requesting the data
DPDP Act, 2023 Compliance Note (Sec 5, Sec 6):
  • Clear Affirmative Action: Customers must actively select each account and click "Approve" to give consent. No pre-ticked boxes, no bundled consent, no default acceptance.
  • Plain Language: All disclosures are in simple English and regional languages as applicable.
  • User Rights Information: Embedded reference to customer's rights under Sec 11-14 (access, correction, erasure, grievance, nomination).
Technical Security:
  • TLS encrypted connection
  • Session timeout after inactivity

Step 3: Customer Approves Consent

What Happens: The customer reviews the consent request and makes a decision:

  • Approve: Customer selects accounts to share and clicks “Approve” option
  • Decline: Customer rejects the consent request entirely
  • Consent can either be “Paused” or “Revoked”
DPDP Act, 2023 (Sec 6(4)): If the customer approves, OMS AA records:
  • Timestamp of consent
  • Exact data categories approved
  • Selected accounts
  • Validity period

This record is immutable and available for audit by RBI, DPBI, or the customer.

Step 4: OMS AA Facilitates Data Sharing from FIP

What Happens (Automated): Once consent is approved, OMS AA:

  1. Sends a consent notification to the relevant Financial Information Provider (FIP), e.g., the customer's bank
  2. The FIP verifies the consent (checks the digital signature, confirms the customer authorized it)
  3. The FIP prepares the requested financial data from its systems
  4. The data is transmitted to OMS AA via API using the ReBIT-specified protocols (from RBI AA Master Directions, 2025)
What OMS AA Does NOT Do:
  • Does NOT store or cache the customer's financial data
  • Does NOT process, analyze, or modify the data
  • Does NOT retain copies after the FIU receives it
  • Does NOT use the data for any purpose other than this specific transfer
Compliance Note (Para 8(4), Para 14(7), Para 36, RBI Directions):
  • “Customer information never resides with the NBFC-AA” (Para 14(7))
  • “No use or access beyond the customer's explicitly requested business” (Para 36)

Step 5: OMS AA Presents Data to FIU

What Happens: OMS AA:

  1. Receives the financial data from the FIP(s)
  2. Transmits it to the FIU
Security & Audit Trail:
  • Every consent-based session is logged with timestamp, FIP, FIU, customer ID, and data categories
  • Logs are maintained and retained per regulatory requirements
  • Real-time monitoring for anomalies or unauthorized access attempts

Compliance Note (Para 8(4)): This is "presentation"—making the data available in a usable format, not analyzing or processing it.

Step 6: FIU Uses Data for Stated Purpose

What Happens: The FIU (bank, NBFC, fintech) receives the consolidated financial data and uses it for the purpose stated in the consent:

  • Loan Underwriting: Assess creditworthiness based on income, existing liabilities, asset details
  • KYC Refresh: Update customer information for regulatory compliance
  • Insurance Underwriting: Verify income and asset details for premium calculation
  • Credit Decisioning: Feed data into risk models for approval/rejection decision
  • Customer Onboarding: Verify identity and financial capacity
What the FIU Must NOT Do:
  • Use the data for any purpose other than the consented one
  • Share the data with third parties without explicit customer consent
  • Retain the data beyond the consent validity period
  • Combine the data with non-consensual sources for unauthorized analysis

Compliance Note: The FIU is now a "Data Fiduciary" under the DPDP Act, 2023 and must comply with Sec 8 (data security, accuracy, retention, and erasure requirements).


Your Control

Consent Withdrawal & Data Erasure

Customer Revokes Consent

At any point, the customer can withdraw their consent via OMS AA's customer dashboard (1-click revocation).

OMS AA Notifies FIP & FIU:
  • FIP is notified that the customer's consent has been revoked and no further data access is permitted.
  • FIU is notified that the consent is revoked
  • Both parties must stop accessing the consented data (though past usage remains valid)

Data Erasure

  • FIP must erase its transmission logs per regulatory retention requirements
  • OMS AA erases its audit logs after the regulatory retention period
DPDP Compliance Note (Sec 6(4), Sec 8(7)):
  • “Withdrawal must be as easy as giving consent” — ✓ OMS AA's 1-click revocation meets this
  • “Erasure once purpose is served or consent is withdrawn” — ✓ Enforced via automated workflows

In Practice

Real-World Example: Loan Application via Account Aggregator

Scenario: Rajesh, a small business owner, applies for a ₹5 lakh loan at FinTechBank. Traditionally, he'd need to download 6 months of bank statements from 3 different banks and manually upload them. With OMS AA:

  1. FinTechBank initiates consent:
    • "We need your bank statements (6 months) from all your banks to process your loan."
    • "Purpose: Loan underwriting and credit decisioning."
    • "Validity: 1 year or until you revoke."
  2. Rajesh reviews and approves:
    • Sees itemized request: "Bank Statement (6 months) from ICICI Bank", "Bank Statement (6 months) from HDFC Bank", "Bank Statement (6 months) from Axis Bank"
    • Clicks approve; consent is recorded with timestamp
  3. OMS AA facilitates data sharing:
    • Sends consent notification to the relevant FIPs (e.g., the customer's banks)
    • Each bank verifies the consent and sends statements to OMS AA
  4. OMS AA passes through the data:
    • Forwards raw financial data as-is, received from the FIPs
    • Sends to FinTechBank's API
  5. FinTechBank underwriting:
    • Receives consolidated data immediately (vs. 1-2 days with manual process)
    • Runs creditworthiness assessment
    • Loan decision within hours
  6. Result:
    • Rajesh's loan is approved and disbursed faster
    • He retained full control of his data (could have excluded any account)
    • FinTechBank got reliable, verified data
    • No sensitive documents left on file systems or emails

Trust & Compliance

Security & Regulatory Framework

Encryption

  • TLS 1.3 for all API communications
  • AES-256 for data at rest (though OMS AA doesn't store data—only audit logs)
  • HMAC-SHA256 for data integrity verification

Data Minimization

  • Only the data covered under the customer's consent is made accessible to the FIU.
  • No unnecessary data collection
  • Automatic deletion of interim logs per RBI retention policy

Audit & Monitoring

  • Real-time logging of every consent event, data relay, and session activity
  • Quarterly reports provided to Sahamati

Regulatory Oversight

  • RBI supervision under RBI AA Master Directions, 2025
  • DPDP Act, 2023 compliance monitored by eventual DPIB
  • Customer grievance redressal per Sec 13 (DPDP Act) and Para 9 (RBI Directions)