Account Aggregator (NBFC-AA) Licence
An account aggregator license is a Certificate of Registration from the Reserve Bank as an NBFC-AA. It lets a company fetch a customer’s financial information from banks, insurers and other providers and pass it on, only with the customer’s explicit consent. You need net owned fund of ₹2 crore and a working technology platform within twelve months of in-principle approval. We prepare the PRAVAAH application and the policies behind it.
What it is
An account aggregator (AA) is a non-banking financial company that retrieves or collects a customer’s financial information and consolidates, organises and presents it to the customer or to a financial information user the customer chooses. Think of bank deposits, mutual fund units, shares, insurance policies, NPS balances and even GST returns, brought together with the customer’s consent. The AA does not keep the data, cannot access the customer’s login credentials and does not support transactions.
The rulebook is the Reserve Bank of India (Non-Banking Financial Companies – Account Aggregator) Directions, 2025, issued on 28 November 2025 (RBI/DoR/2025-26/368). Under paragraph 11, only a company can carry on the business, and only after obtaining a Certificate of Registration (CoR) from the Reserve Bank. Paragraph 12 says the application is made on the PRAVAAH portal to RBI’s Department of Regulation, Mumbai.
Who it applies to
You want to run an account aggregator
Any company that wants to carry financial information from providers to users, for a fee or otherwise, needs the CoR first.
Your group already runs another business
Paragraph 14 says an NBFC-AA shall not undertake any business other than account aggregation. Say your group already sells lending software from Faridabad. The AA cannot sit inside that company; it needs one of its own.
You only want to use AA data
A lender that wants AA data inside its loan management software does not need this licence. It joins as a financial information user, which must be registered with and regulated by a financial sector regulator. New lenders start with NBFC registration.
Why it matters
Operate legally from day one
No company can commence or carry on the business of an account aggregator without a CoR from the Reserve Bank, under paragraph 11.
Earn customer trust by design
Nothing moves without explicit consent, and the customer can revoke that consent, fully or for part of the information.
Plug into one technical standard
Regulated entities are expected to adopt the technical specifications published by ReBIT, so banks, insurers and lenders connect in the same format.
Documents required
About the company
- Certificate of incorporation, MOA and AOA
- Board resolution authorising the PRAVAAH application
- Audited financials or a certificate showing net owned fund of ₹2 crore
- Bank statements showing the source of capital
About promoters and management
- KYC documents of directors and promoters
- Profiles showing technology and finance experience
- Fit and proper declarations of promoters
- Shareholding pattern, with details of any foreign investors
About the platform
- Plan for a secure IT system built on ReBIT specifications
- Information security, disaster recovery and business continuity plans
- Consent flow design and customer terms
- Grievance redressal policy and pricing policy
Customer, FIP, FIU and AA: who does what
| Party | Role | Who it can be |
|---|---|---|
| Customer | Gives, and can revoke, consent | A person who has a contract with the AA for its services |
| Financial information provider (FIP) | Holds the data and sends it on consent | Banks, NBFCs, asset management companies, depositories and depository participants, insurers, insurance repositories, the Central Recordkeeping Agency, GSTN, CCIL and others RBI identifies |
| Financial information user (FIU) | Receives the data for the stated purpose | An entity registered with and regulated by any financial sector regulator |
| NBFC-AA | Obtains, submits and manages consent and moves the data | A company holding a CoR from RBI |
The AA sits in the middle. The data sits with the FIP and travels to the FIU only on the terms of the customer’s consent.
In practice, it works like this. A Faridabad auto-parts dealer applies to an NBFC for a working capital loan. Instead of emailing a year of bank statement PDFs and GST returns, the dealer approves a consent on the AA’s app. The bank and GSTN send the data through the AA to the NBFC, and nothing stays with the AA.
How it works
Test your model against paragraph 14
The AA cannot support transactions or run any other business. It cannot keep customer data, access login credentials or use a third-party service provider for the aggregation itself. We check your plan line by line.
Incorporate and bring in ₹2 crore
We handle company incorporation if needed and document the ₹2 crore net owned fund and its source.
File the application on PRAVAAH
The application goes to the Department of Regulation, Mumbai. Under paragraph 12(2), RBI checks resources and wherewithal, capital structure, fit and proper promoters, character of management and a plan for a secure IT system.
Build the platform within twelve months
After in-principle approval, the company has twelve months to put the technology platform in place, sign the legal documents and report its compliance to RBI.
Sign up FIPs and FIUs, then go live
With the CoR in hand, you sign agreements with customers and providers, publish your pricing policy and grievance officer details, and keep up with ongoing compliance and accounts.
Timelines
Be ready within twelve months
In-principle approval is valid for twelve months under paragraph 12(4). The platform and legal documents must be in place within that period.
Resolve complaints within one month
Grievances must be resolved within the time in your Board-approved policy, and in any case not beyond one month.
Run an IS audit every two years
An Information System Audit must be conducted at least once in two years by CISA certified external auditors.
What happens if you cross the line
Your in-principle approval runs out
Approval is valid for twelve months. A platform that is not ready by then runs out of approval before the CoR is granted.
You operate without a CoR
Paragraph 11 bars any company from commencing or carrying on the business of an account aggregator without a CoR.
You keep data you should only carry
Storing customer financial information, accessing credentials or moving data without consent breaks paragraphs 14 and 15. Here is the catch: a developer who caches fetched statements on the AA’s server “just for a day” to speed up retries has let data reside with the AA.
Frequently asked questions
How do you get an account aggregator license in India?
You apply to RBI for a Certificate of Registration as an NBFC-AA. The applicant must be a company with net owned fund of at least ₹2 crore. The application is made on the PRAVAAH portal to the Department of Regulation, Mumbai. RBI first grants in-principle approval, valid for twelve months, during which you build the platform and report compliance. The CoR follows once RBI is satisfied. We prepare the file and handle queries with you.
What is the minimum net owned fund for an NBFC-AA?
The minimum is ₹2 crore. Paragraph 11 of the AA Directions requires net owned fund of not less than ₹2 crore, or such higher amount as the Reserve Bank may specify. RBI’s NBFC registration directions set the same figure for NBFC-AA and NBFC-P2P. That is far below a lending NBFC-ICC, which must reach ₹10 crore by 31 March 2027. We help you document the capital and its source.
What must a consent artefact contain?
Paragraph 17 lists the contents. The consent must show the customer’s identity, the nature of financial information requested, the purpose of collecting it, the identity of the recipients, a URL for notifications on how the consent is used, the consent creation and expiry dates, and the identity and signature of the NBFC-AA. RBI may add more attributes. We design the consent flow around these fields.
Can a customer withdraw consent?
Yes. Paragraph 20 requires the NBFC-AA to give customers a functionality to revoke consent, including the ability to revoke consent for parts of the information. Before taking consent, paragraph 19 requires the AA to tell the customer all the necessary attributes and the right to file grievances. We map your consent screens to paragraphs 17 to 20 before launch.
Does an account aggregator store customer data?
No. Paragraph 14 says no financial information of the customer accessed by the NBFC-AA from providers shall reside with the NBFC-AA. The AA also cannot access the customer’s user authentication credentials. It passes information only to the customer or to a financial information user the customer authorises. So customers share data without leaving a copy with the middleman.
Who are FIPs and FIUs?
FIPs hold the data; FIUs use it. Financial information providers include banks, NBFCs, asset management companies, depositories, depository participants, insurers, insurance repositories, the Central Recordkeeping Agency, GSTN and CCIL. A financial information user is any entity registered with and regulated by a financial sector regulator. So a registered NBFC can use AA data, but an unregulated app cannot receive it as an FIU.
Can an NBFC-AA run another business or support payments?
No. Paragraph 14 says an NBFC-AA shall not undertake any business other than account aggregation and shall not support transactions by customers. It also cannot use a third-party service provider for the aggregation business itself. If your group runs lending, payments or software, keep the AA in its own company. We help you plan the structure.
What technology standards apply to an NBFC-AA?
Regulated entities are expected to adopt the technical specifications published by ReBIT, as updated from time to time. Paragraph 30 adds security: protect data against unauthorised access, alteration, destruction, disclosure or dissemination, and keep disaster risk management and business continuity in place. An Information System Audit is due at least once in two years by CISA certified external auditors. Plan the audit cycle from launch.
How quickly must an AA resolve complaints?
Within the time set in its Board-approved policy, and in any case not beyond one month. The AA must have a grievance redressal set-up and display its grievance officer’s details. Paragraph 41 also requires a Board-approved pricing policy that is transparent and available in the public domain. We draft both policies with you before launch.
What it costs
Our fee plus the government fee that applies to your case, quoted before you commit. Tell us the situation and we will price it exactly.
Ready to begin?
Tell us what data your platform will carry and for whom, and we will map your route to an NBFC-AA registration.