Payment Aggregator Compliance: RBI Rules After Authorisation
Payment aggregator compliance starts the day RBI authorises you. You keep net worth at the required level, run the escrow account within strict credit and debit rules, vet every merchant, and file returns on fixed dates. We set up the calendar, prepare the filings and keep the evidence ready.
What it is
Getting authorised is one event. Staying compliant is every month after that. This page is about the second part: what the Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025 (RBI/DPSS/2025-26/141, 15 September 2025) expect once you are running. If you are still applying, read our payment aggregator licence page first.
The Directions come under the Payment and Settlement Systems Act, 2007. They cover net worth, governance, merchant onboarding, the escrow account, security audits and regular reports to RBI. Payment aggregators of all three kinds, online, physical and cross-border, follow the same compliance spine.
Who it applies to
Authorised non-bank aggregators
If RBI has authorised you as a PA-O, PA-P or PA-CB, every obligation here applies to you. Banks need no authorisation, so their regime differs.
Applicants awaiting approval
Your application can be rejected if the minimum net worth is not met. Build the controls early so they are in place from day one.
Fintechs that pay out for merchants
Picture a Gurugram app that collects customer payments and settles to sellers. Its merchant checks, settlement terms and escrow discipline are what RBI examines.
Why it matters
Authorisation can be revoked
Section 8 of the PSS Act lets RBI revoke authorisation if you contravene the Act, fail to follow directions, or operate against the conditions of your authorisation.
Banks and merchants audit you
Your escrow bank, large merchants and investors ask for your latest certificates. Clean files help.
Penalties are heavy
Section 26 of the PSS Act allows fines up to ₹10 lakh for not furnishing returns or documents, and imprisonment of up to ten years or fine up to ₹1 crore for contravening directions.
Documents required
Every month and quarter
- Monthly transaction statistics
- Monthly cyber security incident report
- Quarterly auditor certificate on the escrow balance
- Banker’s certificate on escrow debits and credits
Every year
- Audited net-worth certificate from the statutory auditor
- External information security audit
- Cyber security audit report
- Board-approved information security policy
Merchant file
- KYC retrieved from the Central KYC Records Registry with consent
- PAN verification and contact point verification
- Background and antecedent checks
- Merchant agreement with settlement timelines
How it works
Give every obligation an owner
We turn the Directions into a one-page register: what is due, who prepares it, who approves it. Gaps usually come from unclear ownership.
Test the escrow entries against the list
Only listed credits and debits are allowed in the escrow account. We review recent entries against the permitted list and flag anything outside it.
Sample your merchant files
From 1 January 2026, merchant due diligence applies on onboarding. Merchants onboarded up to 31 December 2025 get one year to be brought up to the same standard. We sample the files and fill the gaps.
Draft the returns and collect certificates
We draft the monthly statistics, collect the auditor and banker certificates and keep the cyber incident log. The authorised signatory reviews and files.
Review each quarter
A short review: net worth headroom, open grievances, pending audit observations. We write it up for the board.
Escrow account: what may go in and out
The Directions list permitted entries. Anything else needs to be fixed or explained.
| Permitted credits | Permitted debits |
|---|---|
| Funds from payers for merchant transactions | Payments to merchants for goods, services or investments |
| Transfers from other PAs | Refunds to payers for reversed transactions |
| Refunds from merchants for failed or disputed transactions | Payments to another PA or PA-CB for settlement |
| Pre-funding from own or merchant funds (domestic escrow only) | Commission to the PA; third-party payments for merchants above ₹40 lakh turnover, on the merchant’s direction |
Settlement timelines are set by the agreement between you and the merchant. The Directions require it to be fair, equitable and clear about timelines.
Timelines
Monthly: the 7th and cyber reports
Transaction statistics are due by the 7th of the following month. Cyber security incidents are reported monthly.
Quarterly: the 15th
The auditor’s certificate on the escrow account is due by the 15th of the month after each quarter.
Yearly: 30 September
The audited net-worth certificate is due by 30 September, with the external information security audit and cyber security audit.
What happens if you miss it
Authorisation at risk
RBI can revoke authorisation under Section 8 of the PSS Act if you do not follow directions or the conditions attached to your authorisation.
Fine for late returns
Section 26 allows a fine up to ₹10 lakh for failing to furnish returns or documents, plus up to ₹25,000 for each day the default continues.
Net worth shortfall
The applicable minimum, ₹15 crore at application and ₹25 crore by the end of the third financial year, must be held on an ongoing basis.
Frequently asked questions
What is payment aggregator compliance?
It is the set of ongoing duties under the RBI Directions of 15 September 2025 for authorised payment aggregators. They cover net worth, escrow operation, merchant due diligence, security audits and fixed reports to RBI. Authorisation is only the start. We build the calendar.
When are the main RBI reports due?
Transaction statistics are due by the 7th of the next month, and the auditor’s escrow certificate by the 15th of the month after each quarter. Cyber incidents are reported monthly, and the audited net-worth certificate is due by 30 September. We track all of them and prepare the drafts well ahead.
What net worth must I maintain?
You must hold ₹15 crore when you apply and ₹25 crore by the end of the third financial year, then keep the applicable minimum on an ongoing basis. Net worth follows RBI’s January 2015 circular, and a statutory auditor certifies it. We review headroom every quarter so capital planning is early.
What can go into the escrow account?
Only permitted credits, such as payer funds for merchant transactions, transfers from other PAs, merchant refunds and pre-funding, can enter the escrow. Debits are limited to merchant payments, refunds, inter-PA settlements, commission and certain third-party payments. We test your recent entries against the list.
How must merchants be vetted?
Retrieve KYC from the Central KYC Records Registry with consent, run background checks and, for merchants with annual turnover up to ₹40 lakh, verify PAN and carry out contact point verification. Merchants onboarded up to 31 December 2025 have one year to comply. We audit your files and close gaps.
Does a payment aggregator need security audits?
Yes. The Directions require an external information security audit and a cyber security audit every year, with observations and corrective actions. Merchants must also follow PCI-DSS and PCI-SSF as applicable. Cyber incidents go to RBI monthly. We collect the evidence and track corrective actions to closure.
Can RBI cancel an authorisation for non-compliance?
Yes. Section 8 of the PSS Act allows revocation if an authorised entity contravenes the Act, does not follow RBI directions or runs the system against its authorisation conditions. Regular filing and clean records are your best protection. We prepare a pre-inspection check so issues are fixed before RBI asks.
Do the rules differ for cross-border aggregators?
They are largely the same, with one clear difference: a PA-CB handles only current account transactions, and each transaction is capped at ₹25 lakh. Net worth, escrow, merchant checks and reporting follow the same Directions. We map your business model to the right category and obligations.
What it costs
Our fee plus the government fee that applies to your case, quoted before you commit. Tell us the situation and we will price it exactly.
Government exposure comes only from default. Section 26 of the PSS Act allows fines up to ₹10 lakh for not furnishing returns or documents.
Ready to begin?
Share your authorisation details and recent filings. We will build your compliance register and calendar.