RBI Makes Account Aggregators Interoperable: One App to Share All Your Financial Data
On 7 October 2026, the Reserve Bank of India (RBI) announced that NBFC Account Aggregators (NBFC-AAs) will be made interoperable. Interoperable means different systems can work with each other.
After this change, a customer registered with any licensed Account Aggregator app can share data with any regulated lender, bank, insurer or wealth manager on the network, no matter which Account Aggregator that institution uses.
The RBI also helped SEBI-regulated depositories (the bodies that hold shares in electronic form) add a customer's bank deposit information to their Consolidated Account Statement (CAS) through Account Aggregators. So a demat account holder can see shares and bank deposits in one statement.
Both measures are to be put in place by 31 December 2026.
The move is expected to make it easier for banks, insurers, pension funds and investment platforms to sign up and serve new customers, because one consent dashboard can now reach the whole system.
In 2025-26, loans of about Rs 3.82 lakh crore (3.68 crore loans) were given using the Account Aggregator system, about 8.4% of India's retail and MSME lending by value.
Account Aggregator (AA) Framework
An Account Aggregator (AA) is a special kind of company, licensed by the RBI, that helps you share your financial information safely from one institution to another, only with your permission. For example, your bank statement can travel from your bank to a lender who is checking your loan application, through the AA. The AA works like a postman carrying a sealed envelope: it moves your data but cannot open or read it. The system is India's version of what the world calls "open banking" or "open finance".
The RBI's decision to make NBFC-AAs interoperable fixes the biggest practical gap in the AA system: the need for separate tie-ups between every AA and every institution. Now one AA app can act as a single consent dashboard for a customer's entire financial life, which is why the move is expected to ease customer acquisition across banking, insurance, pensions and investments.
Digital Personal Data Protection (DPDP) Act, 2023
The Digital Personal Data Protection Act, 2023 is India's first full law to protect people's personal data in digital form. Personal data means any information that can identify you: your name, phone number, Aadhaar number, bank details, location or photos. The law tells companies and the government how they may collect and use such data, and it gives you rights over your own data. If a company misuses your data or fails to protect it, it can be fined up to Rs 250 crore.
The Account Aggregator system is India's most widely used consent-based data-sharing model, and it now has to work alongside the DPDP Act's rules on consent, purpose limitation and data security. As AAs become interoperable and carry more data across banking, markets, insurance and pensions, the DPDP Act's protections become even more important for the customers whose data is moving.
- RBI announcement on AA interoperability: 7 October 2026; deadline 31 December 2026
- Depositories to include bank deposit information in the Consolidated Account Statement through NBFC-AAs: by 31 December 2026
- AA-enabled lending in FY26: about Rs 3.82 lakh crore across 3.68 crore loans; 8.4% of retail and MSME lending by value, 11.8% by volume
- NBFC-AA Master Direction: 2 September 2016; network go-live: 2 September 2021
- Technical standards: ReBIT; SRO-AA: Sahamati Foundation (recognised June 2026)
- As of 31 March 2026: 179 FIPs, 989 FIUs, 17 AA registrations, about 284.6 million accounts linked
- DPDP Act, 2023: assent 11 August 2023; maximum penalty Rs 250 crore