Introduction to NBFC-AA License
The Account Aggregator (AA) framework is one of the most transformative regulatory innovations in India's financial sector in recent years. Introduced by the Reserve Bank of India (RBI) through its Master Direction on Non-Banking Financial Companies — Account Aggregator (Reserve Bank) Directions, 2016, the Account Aggregator framework enables secure, consent-based sharing of financial data between regulated entities.
An Account Aggregator is a specific category of NBFC — classified as NBFC-AA — that acts as a data intermediary. It neither stores nor processes financial data but facilitates the secure sharing of data from Financial Information Providers (FIPs) to Financial Information Users (FIUs) based on explicit, time-bound customer consent.
What is an Account Aggregator?
An Account Aggregator under the RBI framework is an entity that:
- Aggregates financial information of a customer held by regulated financial entities (FIPs)
- Shares that information with other regulated entities (FIUs) based on the customer's explicit, digitally-signed, and time-bound consent
- Operates as a pure data conduit — it does not access, store, process, or analyze the actual financial data
- Is registered as an NBFC with RBI under the specific NBFC-AA category
- Operates on a technology-first, API-driven architecture aligned with ReBIT (Reserve Bank Information Technology Private Limited) specifications
The Account Aggregator model is distinct from existing data aggregators or credit bureaus. Unlike credit bureaus that store and analyze data, the AA is a consent-management layer — a digital infrastructure for financial data portability.
Regulatory Framework for NBFC-AA
The primary regulatory instruments governing NBFC-AA entities include:
| Regulation / Direction | Key Provisions |
|---|---|
| RBI Master Direction on NBFC-AA, 2016 | Defines NBFC-AA, eligibility, registration, conduct, and compliance obligations |
| ReBIT Technical Specifications | API standards, data security protocols, encryption standards for AA ecosystem |
| DEPA (Data Empowerment and Protection Architecture) | India's open data framework within which AA operates |
| Digital Personal Data Protection Act, 2023 | Overarching data privacy framework applicable to AA entities |
| IT Act, 2000 (as amended) | Data security, electronic signatures, information technology compliance |
| RBI Circular on FIP/FIU Onboarding | Governs onboarding of financial institutions into the AA ecosystem |
Account Aggregator Ecosystem Participants
Understanding the AA ecosystem requires clarity on the roles of each participant:
Account Aggregator (AA) — NBFC-AA
The licensed intermediary that facilitates consent management and data flow. Acts as a neutral data conduit between FIPs and FIUs. Must be registered with RBI as NBFC-AA.
Financial Information Provider (FIP)
Entities that hold customer financial data — banks, NBFCs, insurance companies, mutual funds, pension funds, and securities depositories. They are the data sources in the AA ecosystem.
Financial Information User (FIU)
Regulated entities that consume aggregated financial data for specific purposes — lenders using bank statement data for loan underwriting, insurers for risk assessment, or AMFs for financial planning.
Customer (Data Principal)
The individual or entity whose financial data is being shared. Holds complete control over consent — can grant, pause, revoke, and review all consents in real-time through the AA app.
Central Registry (Sahamati)
Sahamati is the industry alliance (now operational as an industry body) that maintains the AA ecosystem registry, technical standards, and inter-operability between multiple AAs.
Eligibility Criteria for NBFC-AA License
To apply for an NBFC-AA license from RBI, the applicant entity must satisfy the following eligibility conditions:
- Incorporation: The entity must be incorporated as a company under the Companies Act, 2013 (or earlier Companies Act, 1956)
- Registered in India: The principal place of business must be in India
- Object Clause: The MoA must include account aggregation as a core business objective
- Net Owned Fund: Minimum NOF of ₹2 crore at the time of application
- Fit and Proper: Promoters, directors, and key management personnel must satisfy RBI's Fit and Proper criteria
- No Criminal Record: No criminal prosecution or regulatory adverse orders against promoters/directors in the last 5 years
- Technology Readiness: Applicant must demonstrate a credible technology architecture aligned with ReBIT specifications
- Business Plan: Submission of a detailed 5-year business plan demonstrating viability
Net Worth and Capital Requirements
| Requirement | Threshold | Notes |
|---|---|---|
| Minimum Net Owned Fund (at application) | ₹2 Crore | Must be maintained at all times |
| Minimum Net Owned Fund (within 3 years) | ₹2 Crore | Ongoing maintenance required |
| Capital for Technology Infrastructure | No specific minimum | Must demonstrate adequacy in business plan |
| CRAR | Not separately mandated | General NBFC prudential norms apply |
| Investment in FIPs/FIUs (prohibited) | Nil | AA cannot hold equity in its ecosystem participants |
Application Process for NBFC-AA License
Pre-Application Preparation
Incorporate the company with AA-specific objects in the MoA. Build minimum NOF of ₹2 crore. Develop technology architecture aligned with ReBIT AA API specifications. Prepare a detailed business plan and financial projections.
Application to RBI
Submit application to the Department of Regulation (DoR), Reserve Bank of India. The application must be submitted physically at the RBI's Mumbai headquarters along with all prescribed documents.
In-Principle Approval
RBI reviews the application and may seek additional information. If satisfied, RBI grants an In-Principle Approval (IPA) valid for 12 months. During this period, the AA must build and test its technology infrastructure.
Technology Build & Compliance
Build the AA platform compliant with ReBIT API specifications. Integrate with the central registry. Complete security audits, penetration testing, and data security compliance assessments.
Certificate of Registration
Upon satisfactory completion of technology and compliance requirements, apply for final Certificate of Registration (CoR) as NBFC-AA. RBI issues CoR upon final review.
Documents Required for NBFC-AA Application
- Application form as prescribed by RBI
- Certificate of Incorporation and MoA/AoA
- Board resolution authorizing the application
- Audited financial statements for last 3 years (or from incorporation)
- Net Worth Certificate from statutory auditor
- Fit and Proper declarations from all directors/promoters
- Banker's certificate confirming paid-up capital
- Detailed business plan with 5-year financial projections
- Technology architecture document and ReBIT API compliance plan
- Data security policy and information security framework
- Details of proposed key management personnel with CVs
- Privacy policy and customer consent management framework
- Proposed consent artifact template compliant with RBI standards
- Details of planned FIP and FIU integrations
Technology and API Requirements
The AA's technology infrastructure is central to its regulatory approval. RBI and ReBIT mandate specific technology standards:
ReBIT AA API Specifications
The AA must implement APIs compliant with ReBIT's published technical specifications for consent creation, consent revocation, data fetch requests, and data sharing flows.
End-to-End Encryption
All financial data flowing through the AA ecosystem must be end-to-end encrypted using cryptographic standards specified by ReBIT. The AA must not be able to decrypt the financial data in transit.
Digital Signature on Consent Artifacts
Consent artifacts must be digitally signed by the customer and countersigned by the AA. The AA must maintain an immutable audit trail of all consent creation, modification, and revocation events.
ISO 27001 Certification
The AA must demonstrate compliance with ISO 27001 information security management standards or equivalent, validated through an independent security audit.
Business Continuity Plan (BCP)
A robust BCP and Disaster Recovery (DR) plan must be in place, with RTO (Recovery Time Objective) and RPO (Recovery Point Objective) meeting RBI's IT framework requirements.
Consent Architecture in the AA Framework
The consent architecture is the defining feature of the Account Aggregator model. Every data sharing transaction requires a structured consent artifact:
| Consent Attribute | Description |
|---|---|
| Purpose | Specific purpose for which data is being shared (e.g., loan underwriting) |
| Data Range | Time period of data being shared (e.g., last 12 months of bank statements) |
| Consent Duration | Period for which consent is valid (one-time, recurring, or specific duration) |
| Fetch Frequency | How often the FIU can fetch data under a single consent (once or periodic) |
| Data Life | How long the FIU can retain the data after fetching |
| Revocability | Customer can revoke consent at any time through the AA app |
Compliance Obligations for NBFC-AA
Post-registration, NBFC-AAs must comply with a comprehensive set of ongoing obligations:
- Annual submission of audited financial statements to RBI
- Quarterly returns on operational metrics as prescribed by RBI
- Maintenance of minimum NOF at all times
- Prohibition on accessing, storing, or monetizing customer financial data
- Customer grievance redressal mechanism with resolution timelines
- Annual information security audit by a CERT-In empaneled auditor
- Compliance with the Digital Personal Data Protection Act, 2023
- Participation in Sahamati ecosystem and adherence to technical standards
- Annual board review of the compliance framework
- Prompt reporting of data breaches to RBI and affected customers
Timeline and Fees
| Stage | Estimated Duration | Notes |
|---|---|---|
| Pre-application preparation | 3–4 Months | Company incorporation, NOF build-up, business plan |
| Application filing to RBI | 1 Month | Document compilation and submission |
| RBI review and In-Principle Approval | 4–6 Months | May include queries and additional submissions |
| Technology build and testing | 6–12 Months | Depends on technology stack and team readiness |
| Final CoR from RBI | 1–2 Months | Post-technology compliance demonstration |
| Total Timeline | 12–24 Months | End-to-end from preparation to CoR |
Business Opportunities in the Account Aggregator Ecosystem
The NBFC-AA framework unlocks significant commercial opportunities for licensed entities:
- Transaction Fees: AAs charge FIUs per consent or per data fetch transaction
- Platform Licensing: White-label AA infrastructure for banks and NBFCs
- API Monetization: Premium API services for advanced data analysis workflows
- Embedded Finance: Integration with lending, insurance, and wealth management platforms
- Financial Inclusion: Enabling thin-file borrowers to share alternative data for credit access