Account Aggregator (AA) Framework
An Account Aggregator (AA) is a special kind of company, licensed by the RBI, that helps you share your financial information safely from one institution to another, only with your permission. For example, your bank statement can travel from your bank to a lender who is checking your loan application, through the AA. The AA works like a postman carrying a sealed envelope: it moves your data but cannot open or read it. The system is India's version of what the world calls "open banking" or "open finance".
Why does it exist?
Before AAs, if you wanted a loan, you had to download bank statements as PDFs, print them, sign them and hand them over. This was slow, easy to fake and unsafe, because copies of your data lay around in many offices. Small borrowers, who often have no credit history, could not easily prove their income.
The AA system solves this. It lets you share verified, digital data directly from the source, in minutes, and it keeps you in control of who sees what, for how long and for what purpose.
Where did it come from?
The RBI created the AA as a new category of Non-Banking Financial Company (NBFC) through the Master Direction on NBFC-Account Aggregators, issued on 2 September 2016. The technical standards (the common "language" the systems use to talk to each other) are set by ReBIT (Reserve Bank Information Technology Pvt Ltd), a wholly owned subsidiary of the RBI. The idea is built on the Data Empowerment and Protection Architecture (DEPA), a consent-based data-sharing design promoted by NITI Aayog.
The AA network went live for the industry on 2 September 2021, with a handful of large banks joining first. In June 2026, the RBI recognised Sahamati Foundation, the industry alliance of the AA ecosystem, as the Self-Regulatory Organisation for Account Aggregators (SRO-AA).
Who are the players?
There are three types of participants:
- Financial Information Provider (FIP): the institution that holds your data, such as your bank, mutual fund, insurer, pension fund or depository.
- Financial Information User (FIU): the institution that wants your data to give you a service, such as a lender checking your loan application or a wealth manager. An FIU must be regulated by a financial sector regulator.
- Account Aggregator (AA): the consent manager that carries the data from the FIP to the FIU after you say yes.
How does it work, step by step?
- You apply for a loan with a lender (the FIU) and agree to share your bank statement.
- The lender sends a request through your chosen AA.
- The AA shows you a consent request on its app: what data is asked for, by whom, for what purpose and for how long.
- You approve. This approval becomes a digital consent artefact (a signed, standard electronic record of your permission).
- The AA asks your bank (the FIP) for the data. The bank sends it encrypted (locked in code).
- The AA passes it to the lender, which alone can unlock it. You can revoke (take back) your consent at any time.
Key rules to remember
- An AA is "data blind": it only carries encrypted data and cannot see, store or sell it.
- An AA can do no other business except account aggregation.
- An NBFC-AA needs a certificate of registration from the RBI and a minimum net owned fund of Rs 2 crore.
- Data is shared only with explicit consent, and every consent is logged so it can be audited.
- AAs are regulated by the RBI, but FIPs and FIUs can be regulated by any of the four financial regulators: RBI, SEBI (markets), IRDAI (insurance) and PFRDA (pensions). This is why the system covers banking, stocks, mutual funds, insurance and pensions together.
India's position and Indian examples
The AA network is part of India's Digital Public Infrastructure (DPI), alongside Aadhaar (identity) and UPI (payments). As of March 2026, the Ministry of Finance reported 179 institutions live as FIPs, 989 as FIUs, 17 companies holding AA registration, and about 284.6 million accounts linked by users. MSMEs use it to get cash-flow based loans, where the lender looks at actual bank and GST-linked cash flows rather than asking for property as security.
What is interoperability, and why does it matter?
Even though all AAs use the same ReBIT technical standards, in practice each AA had to sign separate agreements and finish separate onboarding with each bank and lender. So if your lender worked with AA "X" but you used AA "Y", your request could fail. This made the system patchy, like a phone network where you could only call people on the same operator.
Interoperability means any AA can reach any FIP and FIU on the network, so the customer's choice of app no longer matters.
Commonly confused concepts
- Account Aggregator vs Credit Information Company (like CIBIL): A credit bureau collects and stores your loan repayment history and sells credit reports. An AA stores nothing; it only carries your data, with your consent, each time.
- Account Aggregator vs Payment Aggregator: A payment aggregator (like a payment gateway) helps shops collect money. An account aggregator moves information, never money.
- Account Aggregator vs Consent Manager under the DPDP Act: Both manage consent. The AA is an RBI-regulated NBFC for financial data. A consent manager under the Digital Personal Data Protection Act, 2023 is registered with the Data Protection Board and can cover any kind of personal data.
- Open banking in India vs in the UK/EU: In the UK and EU, open banking is mostly forced on banks through regulation and runs bank to third party. India's model runs through a separate, regulated consent layer (the AA).
Issues, criticism and the way forward
- Low success rates: Many data requests failed because of technical gaps at some FIPs, which hurt user trust. Sahamati has been working on common standards and testing to improve this.
- Patchy coverage: Not every bank, cooperative bank or NBFC is live as an FIP, so some customers cannot share all their data.
- Awareness and consent fatigue: Many users click "approve" without reading what they are sharing or for how long. Critics say real, informed consent needs simpler screens and local languages.
- Privacy and misuse: Even with consent, lenders may ask for more data than they need. The DPDP Act's principles of purpose limitation and data minimisation are expected to add another layer of protection.
- Way forward: Interoperability, the SRO's oversight, bringing in GST and tax data, and better grievance redressal are seen as the next steps to make the AA system as widely used as UPI.
Concepts to Know
- Non-Banking Financial Company (NBFC): A company that does financial work like lending but is not a bank. It cannot accept demand deposits (like a savings account) or issue cheques drawn on itself.
- Consent artefact: A standard digital record of your permission. It says what data, for whom, for what purpose and until when.
- Encryption: Turning data into a secret code that only the person with the right key can read.
- Digital Public Infrastructure (DPI): Shared digital systems built for the whole country, open for many companies to use, like Aadhaar, UPI and DigiLocker.
- Self-Regulatory Organisation (SRO): An industry body, recognised by a regulator, that sets standards and checks discipline among its own members.
- Cash-flow based lending: Giving a loan based on the money actually flowing into a business's accounts, instead of asking for land or gold as security.
- Legal basis: RBI Master Direction, Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions, 2016 (issued 2 September 2016)
- Technical standards: ReBIT, a wholly owned subsidiary of the RBI
- Network go-live: 2 September 2021
- Minimum net owned fund for an NBFC-AA: Rs 2 crore
- Three participants: FIP (data holder), FIU (data user), AA (consent manager)
- Regulators covered: RBI, SEBI, IRDAI, PFRDA
- Sahamati Foundation recognised as SRO-AA: June 2026
- As of 31 March 2026: 179 FIPs, 989 FIUs live; 17 AA registrations; about 284.6 million accounts linked
● Tracked since October 07, 2026 · last seen October 07, 2026 · updates as the daily brief publishes