Home / NBFC & Fintech / Account Aggregator License
RBI’s 2025 Account Aggregator Directions consolidated the framework and locked NBFC-AAs permanently into the lightest regulatory layer — but the “data-blind” architecture requirement is stricter than most fintech teams initially design for. CS Chetna Shoor structures your application and consent architecture together.
An Account Aggregator (NBFC-AA) is a distinct NBFC category for consent-based financial data sharing — retrieving financial information from Financial Information Providers (banks, insurers, depositories, and others) and sharing it with Financial Information Users, based entirely on the customer’s explicit, revocable consent. RBI introduced this framework in 2016 and consolidated it under the Account Aggregator Directions, 2025, which permanently places NBFC-AAs in the lightest-touch Base Layer of Scale Based Regulation, regardless of asset size.
The defining structural requirement is that an NBFC-AA must be “data-blind” — it passes financial data between institutions without ever storing or reading it — and its business must be restricted solely to account aggregation, with no lending or other financial activity permitted in the same entity. This page is for founders building a consent-based financial data product who need the NBFC-AA application, technical architecture, and Sahamati ecosystem integration structured correctly. Chetna reviews your business plan and consent architecture before the application goes to RBI’s Department of Regulation.
Minimum Net Owned Fund required at final registration
Maximum leverage ratio permitted for an NBFC-AA
Business restricted solely to account aggregation; no lending or investment activity permitted
A structural requirement that the AA never stores, reads, or uses the financial data it passes through
NBFC-AAs sit in RBI's Base Layer under SBR regardless of asset size
Window after in-principle approval to complete technology and operational tie-ups before final CoR
RBI rejects over 40% of NBFC applications on the first attempt. Here’s what actually causes it.
RBI expects the technical design itself to prevent the AA from ever reading or storing customer financial data, not just a privacy policy stating it won't. Applications that describe data-blindness without the underlying encryption and access-control architecture to back it up face scrutiny at the technical review stage.
Between in-principle approval and final registration, an NBFC-AA must complete ReBIT API integration, digital certificate management, and Sahamati ecosystem onboarding — a genuine technology build, not paperwork, on a fixed clock.
Promoters building a broader fintech group sometimes want the AA function alongside lending or other NBFC activity in the same entity. RBI's framework requires the AA to be a standalone, single-purpose company, which usually means a separate group entity dedicated solely to AA operations.
Not every financial data product needs a standalone NBFC-AA license — it’s worth confirming which route actually applies.
The standard route for a company whose sole business is consent-based financial data aggregation across institutions.
Available to entities already regulated by another financial sector regulator, if they aggregate only that sector's customer data — worth checking before assuming a full NBFC-AA license is required.
If you're part of a broader fintech or NBFC group, the AA function typically needs to sit in its own dedicated company, given the AA-only business restriction.
We confirm your NOF position and whether your business model genuinely fits the AA-only restriction.
Business plan and consent architecture documentation prepared, including the technical proof points RBI will review.
Filing via the PRAVAAH portal to RBI's Department of Regulation.
RBI reviews the application, often with follow-up queries, before granting in-principle approval.
ReBIT API integration, Sahamati ecosystem onboarding, and operational tie-ups completed within the window RBI allows.
Final Certificate of Registration issued, with ongoing compliance monitoring set up from day one.
Registration is the starting point — the leverage, governance, and technical obligations continue for as long as you operate.
Ongoing Net Owned Fund and leverage ratio (≤7:1) maintenance.
Prior RBI approval required for major ownership or board changes.
Continued Sahamati ecosystem compliance as technical specifications and Financial Information Provider integrations evolve.
Continued Sahamati ecosystem compliance as technical specifications and Financial Information Provider integrations evolve.
CS Chetna Shoor’s team replies within 4 hours on WhatsApp.
An Account Aggregator (NBFC-AA) is an RBI-licensed intermediary that retrieves a customer’s financial information from institutions like banks, insurers, and depositories, and shares it with other institutions the customer authorizes — entirely based on explicit, revocable consent. The AA itself never reads or stores the underlying financial data; it acts purely as a secure, consent-governed pipe between institutions.
An NBFC-AA needs a minimum Net Owned Fund of ₹2 crore at the time of final registration, one of the lowest thresholds across NBFC categories. Companies that don’t yet meet this at the time of applying can bring in the required capital during the validity period of RBI’s in-principle approval.
“Data-blind” means the Account Aggregator’s technical architecture is designed so it cannot itself read or store the financial data it passes between institutions — data flows encrypted from the Financial Information Provider to the Financial Information User, with the AA only managing consent and routing. RBI reviews the underlying technical architecture during the application process, not just a policy statement claiming this design.
No. RBI’s framework restricts an NBFC-AA’s business solely to account aggregation activities, with no lending, investment, or other financial services permitted within the same entity. Groups wanting to combine account aggregation with lending or other NBFC activity typically need to house the AA function in a separate, dedicated company.
RBI’s review of the initial application can take up to a year before granting in-principle approval, and the applicant then has 12 months from that approval to complete the technical integration, capital requirements, and operational tie-ups needed for final registration. The overall timeline from application to final Certificate of Registration can therefore extend well beyond a year for a first-time applicant.
Qualified Company Secretary · ICSI Member · Founder, Expertvuw Management Pvt Ltd
Chetna has guided NBFC promoters through RBI’s COR process end to end, with particular focus on structuring the Net Owned Fund and business plan so the application survives first-round RBI scrutiny rather than coming back with a query.