How It Works
How OMS AA Enables Secure Consent-Based Financial Data Sharing
Our platform guides customers through a seamless, transparent consent process, enabling secure financial data transfer in full compliance with the DPDP Act, 2023, and RBI Directions, 2025.
The Consent Flow
The Six-Step Process
Step 1: Consent Initiation by FIU
What Happens: A financial institution (FIU) — such as an NBFC lending platform or a bank's loan processing system — initiates a customer's consent request via OMS AA's API. The FIU specifies:
- Which financial data categories are needed (bank statements, income, investment details, etc.)
- The purpose(s) of data access (loan underwriting, insurance underwriting, etc.)
- The time period for which the FIU needs the data
- The validity period for the consent (e.g., 1 year, with auto-expiry)
- Specificity: Only the data needed for the stated purpose is requested, not blanket access
- Clarity: Purpose is clearly articulated in plain language
- Itemization: Each data category is listed separately so the customer sees exactly what's being requested
Step 2: Consent Presentation to Customer
What Happens: OMS AA displays the consent request to the customer via a secure, user-friendly consent interface. The consent artifact includes:
- Itemized Data Request: A clear list of every data category being requested (e.g., "Bank Statement (6 months)", "Income Details", "Loan Account Summary")
- Purpose Disclosure: Why the FIU needs this data (e.g., "To process your loan application" or "To verify your KYC information")
- Data Source Selection: If the customer has multiple accounts at different banks, they select which accounts to share
- Validity Period: How long this consent remains valid (e.g., "Valid for 1 year, or until revoked")
- Withdrawal Notice: Clear information that consent can be revoked anytime, instantly
- FIU Identity: Clear identification of the institution requesting the data
- Clear Affirmative Action: Customers must actively select each account and click "Approve" to give consent. No pre-ticked boxes, no bundled consent, no default acceptance.
- Plain Language: All disclosures are in simple English and regional languages as applicable.
- User Rights Information: Embedded reference to customer's rights under Sec 11-14 (access, correction, erasure, grievance, nomination).
- TLS encrypted connection
- Session timeout after inactivity
Step 3: Customer Approves Consent
What Happens: The customer reviews the consent request and makes a decision:
- Approve: Customer selects accounts to share and clicks “Approve” option
- Decline: Customer rejects the consent request entirely
- Consent can either be “Paused” or “Revoked”
- Timestamp of consent
- Exact data categories approved
- Selected accounts
- Validity period
This record is immutable and available for audit by RBI, DPBI, or the customer.
Step 4: OMS AA Facilitates Data Sharing from FIP
What Happens (Automated): Once consent is approved, OMS AA:
- Sends a consent notification to the relevant Financial Information Provider (FIP), e.g., the customer's bank
- The FIP verifies the consent (checks the digital signature, confirms the customer authorized it)
- The FIP prepares the requested financial data from its systems
- The data is transmitted to OMS AA via API using the ReBIT-specified protocols (from RBI AA Master Directions, 2025)
- Does NOT store or cache the customer's financial data
- Does NOT process, analyze, or modify the data
- Does NOT retain copies after the FIU receives it
- Does NOT use the data for any purpose other than this specific transfer
- “Customer information never resides with the NBFC-AA” (Para 14(7))
- “No use or access beyond the customer's explicitly requested business” (Para 36)
Step 5: OMS AA Presents Data to FIU
What Happens: OMS AA:
- Receives the financial data from the FIP(s)
- Transmits it to the FIU
- Every consent-based session is logged with timestamp, FIP, FIU, customer ID, and data categories
- Logs are maintained and retained per regulatory requirements
- Real-time monitoring for anomalies or unauthorized access attempts
Compliance Note (Para 8(4)): This is "presentation"—making the data available in a usable format, not analyzing or processing it.
Step 6: FIU Uses Data for Stated Purpose
What Happens: The FIU (bank, NBFC, fintech) receives the consolidated financial data and uses it for the purpose stated in the consent:
- Loan Underwriting: Assess creditworthiness based on income, existing liabilities, asset details
- KYC Refresh: Update customer information for regulatory compliance
- Insurance Underwriting: Verify income and asset details for premium calculation
- Credit Decisioning: Feed data into risk models for approval/rejection decision
- Customer Onboarding: Verify identity and financial capacity
- Use the data for any purpose other than the consented one
- Share the data with third parties without explicit customer consent
- Retain the data beyond the consent validity period
- Combine the data with non-consensual sources for unauthorized analysis
Compliance Note: The FIU is now a "Data Fiduciary" under the DPDP Act, 2023 and must comply with Sec 8 (data security, accuracy, retention, and erasure requirements).
Your Control
Consent Withdrawal & Data Erasure
Customer Revokes Consent
At any point, the customer can withdraw their consent via OMS AA's customer dashboard (1-click revocation).
- FIP is notified that the customer's consent has been revoked and no further data access is permitted.
- FIU is notified that the consent is revoked
- Both parties must stop accessing the consented data (though past usage remains valid)
Data Erasure
- FIP must erase its transmission logs per regulatory retention requirements
- OMS AA erases its audit logs after the regulatory retention period
- “Withdrawal must be as easy as giving consent” — ✓ OMS AA's 1-click revocation meets this
- “Erasure once purpose is served or consent is withdrawn” — ✓ Enforced via automated workflows
In Practice
Real-World Example: Loan Application via Account Aggregator
Scenario: Rajesh, a small business owner, applies for a ₹5 lakh loan at FinTechBank. Traditionally, he'd need to download 6 months of bank statements from 3 different banks and manually upload them. With OMS AA:
- FinTechBank initiates consent:
- "We need your bank statements (6 months) from all your banks to process your loan."
- "Purpose: Loan underwriting and credit decisioning."
- "Validity: 1 year or until you revoke."
- Rajesh reviews and approves:
- Sees itemized request: "Bank Statement (6 months) from ICICI Bank", "Bank Statement (6 months) from HDFC Bank", "Bank Statement (6 months) from Axis Bank"
- Clicks approve; consent is recorded with timestamp
- OMS AA facilitates data sharing:
- Sends consent notification to the relevant FIPs (e.g., the customer's banks)
- Each bank verifies the consent and sends statements to OMS AA
- OMS AA passes through the data:
- Forwards raw financial data as-is, received from the FIPs
- Sends to FinTechBank's API
- FinTechBank underwriting:
- Receives consolidated data immediately (vs. 1-2 days with manual process)
- Runs creditworthiness assessment
- Loan decision within hours
- Result:
- Rajesh's loan is approved and disbursed faster
- He retained full control of his data (could have excluded any account)
- FinTechBank got reliable, verified data
- No sensitive documents left on file systems or emails
Trust & Compliance
Security & Regulatory Framework
Encryption
- TLS 1.3 for all API communications
- AES-256 for data at rest (though OMS AA doesn't store data—only audit logs)
- HMAC-SHA256 for data integrity verification
Data Minimization
- Only the data covered under the customer's consent is made accessible to the FIU.
- No unnecessary data collection
- Automatic deletion of interim logs per RBI retention policy
Audit & Monitoring
- Real-time logging of every consent event, data relay, and session activity
- Quarterly reports provided to Sahamati
Regulatory Oversight
- RBI supervision under RBI AA Master Directions, 2025
- DPDP Act, 2023 compliance monitored by eventual DPIB
- Customer grievance redressal per Sec 13 (DPDP Act) and Para 9 (RBI Directions)