Introduction to NBFC-AA License
The Account Aggregator (AA) framework is one of the most transformative regulatory innovations in India's financial sector in recent years. Introduced by the Reserve Bank of India (RBI) through its Master Direction on Non-Banking Financial Companies ā Account Aggregator (Reserve Bank) Directions, 2016, the Account Aggregator framework enables secure, consent-based sharing of financial data between regulated entities. An Account Aggregator is a specific category of NBFC ā classified as NBFC-AA ā that acts as a data intermediary. It neither stores nor processes financial data but facilitates the secure sharing of data from Financial Information Providers (FIPs) to Financial Information Users (FIUs) based on explicit, time-bound customer consent. š Key Insight: The Account Aggregator framework is the foundational layer of India's Open Finance initiative. As of 2024, the AA ecosystem has enabled over 100 crore consents and is being used by banks, insurance companies, NBFCs, and AMFs for KYC, loan underwriting, and portfolio monitoring.
What is an Account Aggregator?
An Account Aggregator under the RBI framework is an entity that: Aggregates financial information of a customer held by regulated financial entities (FIPs) Shares that information with other regulated entities (FIUs) based on the customer's explicit, digitally-signed, and time-bound consent Operates as a pure data conduit ā it does not access, store, process, or analyze the actual financial data Is registered as an NBFC with RBI under the specific NBFC-AA category Operates on a technology-first, API-driven architecture aligned with ReBIT (Reserve Bank Information Technology Private Limited) specifications The Account Aggregator model is distinct from existing data aggregators or credit bureaus. Unlike credit bureaus that store and analyze data, the AA is a consent-management layer ā a digital infrastructure for financial data portability.
Regulatory Framework for NBFC-AA
The primary regulatory instruments governing NBFC-AA entities include: Regulation / Direction Key Provisions RBI Master Direction on NBFC-AA, 2016 Defines NBFC-AA, eligibility, registration, conduct, and compliance obligations ReBIT Technical Specifications API standards, data security protocols, encryption standards for AA ecosystem DEPA (Data Empowerment and Protection Architecture) India's open data framework within which AA operates Digital Personal Data Protection Act, 2023 Overarching data privacy framework applicable to AA entities IT Act, 2000 (as amended) Data security, electronic signatures, information technology compliance RBI Circular on FIP/FIU Onboarding Governs onboarding of financial institutions into the AA ecosystem
Account Aggregator Ecosystem Participants
Understanding the AA ecosystem requires clarity on the roles of each participant: 1 Account Aggregator (AA) ā NBFC-AA The licensed intermediary that facilitates consent management and data flow. Acts as a neutral data conduit between FIPs and FIUs. Must be registered with RBI as NBFC-AA. 2 Financial Information Provider (FIP) Entities that hold customer financial data ā banks, NBFCs, insurance companies, mutual funds, pension funds, and securities depositories. They are the data sources in the AA ecosystem. 3 Financial Information User (FIU) Regulated entities that consume aggregated financial data for specific purposes ā lenders using bank statement data for loan underwriting, insurers for risk assessment, or AMFs for financial planning. 4 Customer (Data Principal) The individual or entity whose financial data is being shared. Holds complete control over consent ā can grant, pause, revoke, and review all consents in real-time through the AA app. 5 Central Registry (Sahamati) Sahamati is the industry alliance (now operational as an industry body) that maintains the AA ecosystem registry, technical standards, and inter-operability between multiple AAs.
Eligibility Criteria for NBFC-AA License
To apply for an NBFC-AA license from RBI, the applicant entity must satisfy the following eligibility conditions: Incorporation: The entity must be incorporated as a company under the Companies Act, 2013 (or earlier Companies Act, 1956) Registered in India: The principal place of business must be in India Object Clause: The MoA must include account aggregation as a core business objective Net Owned Fund: Minimum NOF of ā¹2 crore at the time of application Fit and Proper: Promoters, directors, and key management personnel must satisfy RBI's Fit and Proper criteria No Criminal Record: No criminal prosecution or regulatory adverse orders against promoters/directors in the last 5 years Technology Readiness: Applicant must demonstrate a credible technology architecture aligned with ReBIT specifications Business Plan: Submission of a detailed 5-year business plan demonstrating viability ā ļø Important: NBFC-AA is a highly specialized category. RBI scrutinizes the technology architecture, data security protocols, and the overall viability of the business model with particular rigor. Only technology-first entities with a clear path to ecosystem integration are likely to receive in-principle approval.
Net Worth and Capital Requirements
Requirement Threshold Notes Minimum Net Owned Fund (at application) ā¹2 Crore Must be maintained at all times Minimum Net Owned Fund (within 3 years) ā¹2 Crore Ongoing maintenance required Capital for Technology Infrastructure No specific minimum Must demonstrate adequacy in business plan CRAR Not separately mandated General NBFC prudential norms apply Investment in FIPs/FIUs (prohibited) Nil AA cannot hold equity in its ecosystem participants
Application Process for NBFC-AA License
Phase 1 Pre-Application Preparation Incorporate the company with AA-specific objects in the MoA. Build minimum NOF of ā¹2 crore. Develop technology architecture aligned with ReBIT AA API specifications. Prepare a detailed business plan and financial projections. Phase 2 Application to RBI Submit application to the Department of Regulation (DoR), Reserve Bank of India. The application must be submitted physically at the RBI's Mumbai headquarters along with all prescribed documents. Phase 3 In-Principle Approval RBI reviews the application and may seek additional information. If satisfied, RBI grants an In-Principle Approval (IPA) valid for 12 months. During this period, the AA must build and test its technology infrastructure. Phase 4 Technology Build & Compliance Build the AA platform compliant with ReBIT API specifications. Integrate with the central registry. Complete security audits, penetration testing, and data security compliance assessments. Phase 5 Certificate of Registration Upon satisfactory completion of technology and compliance requirements, apply for final Certificate of Registration (CoR) as NBFC-AA. RBI issues CoR upon final review.
Documents Required for NBFC-AA Application
Application form as prescribed by RBI Certificate of Incorporation and MoA/AoA Board resolution authorizing the application Audited financial statements for last 3 years (or from incorporation) Net Worth Certificate from statutory auditor Fit and Proper declarations from all directors/promoters Banker's certificate confirming paid-up capital Detailed business plan with 5-year financial projections Technology architecture document and ReBIT API compliance plan Data security policy and information security framework Details of proposed key management personnel with CVs Privacy policy and customer consent management framework Proposed consent artifact template compliant with RBI standards Details of planned FIP and FIU integrations
Technology and API Requirements
The AA's technology infrastructure is central to its regulatory approval. RBI and ReBIT mandate specific technology standards: 1 ReBIT AA API Specifications The AA must implement APIs compliant with ReBIT's published technical specifications for consent creation, consent revocation, data fetch requests, and data sharing flows. 2 End-to-End Encryption All financial data flowing through the AA ecosystem must be end-to-end encrypted using cryptographic standards specified by ReBIT. The AA must not be able to decrypt the financial data in transit. 3 Digital Signature on Consent Artifacts Consent artifacts must be digitally signed by the customer and countersigned by the AA. The AA must maintain an immutable audit trail of all consent creation, modification, and revocation events. 4 ISO 27001 Certification The AA must demonstrate compliance with ISO 27001 information security management standards or equivalent, validated through an independent security audit. 5 Business Continuity Plan (BCP) A robust BCP and Disaster Recovery (DR) plan must be in place, with RTO (Recovery Time Objective) and RPO (Recovery Point Objective) meeting RBI's IT framework requirements.
Consent Architecture in the AA Framework
The consent architecture is the defining feature of the Account Aggregator model. Every data sharing transaction requires a structured consent artifact: Consent Attribute Description Purpose Specific purpose for which data is being shared (e.g., loan underwriting) Data Range Time period of data being shared (e.g., last 12 months of bank statements) Consent Duration Period for which consent is valid (one-time, recurring, or specific duration) Fetch Frequency How often the FIU can fetch data under a single consent (once or periodic) Data Life How long the FIU can retain the data after fetching Revocability Customer can revoke consent at any time through the AA app
Compliance Obligations for NBFC-AA
Post-registration, NBFC-AAs must comply with a comprehensive set of ongoing obligations: Annual submission of audited financial statements to RBI Quarterly returns on operational metrics as prescribed by RBI Maintenance of minimum NOF at all times Prohibition on accessing, storing, or monetizing customer financial data Customer grievance redressal mechanism with resolution timelines Annual information security audit by a CERT-In empaneled auditor Compliance with the Digital Personal Data Protection Act, 2023 Participation in Sahamati ecosystem and adherence to technical standards Annual board review of the compliance framework Prompt reporting of data breaches to RBI and affected customers
Timeline and Fees
Stage Estimated Duration Notes Pre-application preparation 3ā4 Months Company incorporation, NOF build-up, business plan Application filing to RBI 1 Month Document compilation and submission RBI review and In-Principle Approval 4ā6 Months May include queries and additional submissions Technology build and testing 6ā12 Months Depends on technology stack and team readiness Final CoR from RBI 1ā2 Months Post-technology compliance demonstration Total Timeline 12ā24 Months End-to-end from preparation to CoR
Business Opportunities in the Account Aggregator Ecosystem
The NBFC-AA framework unlocks significant commercial opportunities for licensed entities: š” Market Opportunity: India's AA ecosystem is projected to enable financial data sharing worth trillions of rupees annually. With 100+ crore consents already processed, the AA infrastructure is becoming as critical as Aadhaar or UPI in India's financial stack. Transaction Fees: AAs charge FIUs per consent or per data fetch transaction Platform Licensing: White-label AA infrastructure for banks and NBFCs API Monetization: Premium API services for advanced data analysis workflows Embedded Finance: Integration with lending, insurance, and wealth management platforms Financial Inclusion: Enabling thin-file borrowers to share alternative data for credit access
Frequently Asked Questions
Can any company become an Account Aggregator? No. Only entities licensed by RBI as NBFC-AA can operate as Account Aggregators. The entity must be incorporated as a company in India, maintain a minimum NOF of ā¹2 crore, and receive a Certificate of Registration from RBI under the NBFC-AA Master Direction, 2016. Can an NBFC-AA also be a Financial Information User (FIU)? No. RBI explicitly prohibits an NBFC-AA from acting as an FIU to prevent conflicts of interest. The NBFC-AA must operate solely as a consent management and data routing intermediary. It cannot use the data flowing through it for its own benefit. How does an NBFC-AA make money? NBFC-AAs primarily generate revenue through transaction fees charged to FIUs for each consent or data fetch request. They may also charge monthly/annual platform access fees to FIPs and FIUs, or offer value-added services around data analytics infrastructure (without accessing the underlying data). What data types can be shared through the AA framework? The AA framework currently supports bank account data (statements, transactions), deposit accounts, SIP/mutual fund accounts, insurance policy data, pension fund data, and securities demat account data. SEBI has also onboarded its regulated entities as FIPs/FIUs, expanding the ecosystem beyond RBI-regulated entities. Is Estabizz able to assist with the full NBFC-AA license process? Yes. Estabizz Fintech provides end-to-end support for NBFC-AA license applications including company incorporation, MoA drafting, business plan and financial model preparation, RBI application filing, technology architecture advisory, compliance framework setup, and post-licensing regulatory support.