Back to All Blogs

What Is the Account Aggregator Consent Framework? How Borrowers Share Financial Data with Lenders

Chailsee Yadav's avatar
Chailsee Yadav
Lending Technology

For most of India’s lending history, a borrower who wanted to share their bank statement with a lender had one option: walk to the bank branch, request a printed statement, and physically hand it over or scan it and upload a PDF. The Account Aggregator framework changes this completely. The borrower taps a few buttons in their bank’s app, and structured, tamper-proof financial data flows directly to the lender in seconds.

The Account Aggregator (AA) consent framework is India’s RBI-regulated data-sharing infrastructure that allows individuals to securely and digitally share their financial data bank statements, GST returns, tax data, and insurance information with regulated entities (lenders, wealth managers, other financial institutions) through a consent-based, privacy-preserving mechanism. The framework is built on the principle that the individual owns their financial data and controls who accesses it.

What the Account Aggregator Framework Is and Why It Was Built

The AA framework was conceptualised by the RBI in 2016 and operationalised between 2020 and 2023. It is India’s implementation of the broader concept of “data empowerment,” the principle that individuals, not institutions, should control their financial data.

Before AA, financial data sharing between institutions happened either manually (physical documents) or through informal, often non-consensual data aggregation by credit bureaus and data brokers. The individual had limited visibility into what data was being shared about them and almost no ability to selectively share specific data with specific entities for specific purposes.

AA changes this by creating a regulated intermediary, the Account Aggregator, that facilitates data sharing based on explicit, informed, time-bound, purpose-specific consent from the data owner (the individual).

How the AA Consent Process Works: Step by Step

  1. Borrower applies for a loan: the borrower begins a loan application with an NBFC. The NBFC requests bank statement data through the AA framework.
  2. AA redirect: the borrower is redirected to the Account Aggregator’s interface (through the NBFC’s app or website) or to their own bank’s AA-enabled interface.
  3. Consent screen presented: the AA presents a detailed consent screen to the borrower showing: who is requesting the data (the NBFC), what specific data is being requested (savings account statements, duration, account numbers), the purpose of the request (credit assessment), how long the consent is valid, and the frequency of data access.
  4. Borrower reviews and approves: the borrower explicitly approves the consent. If the borrower declines, no data is shared, and the lender cannot access the account.
  5. Bank approves data sharing: the borrower’s bank (as the Financial Information Provider, FIP) receives the consented request, authenticates the consent, and packages the data.
  6. Data flows to the lender: the bank (FIP) sends the structured financial data to the AA, which routes it to the NBFC (Financial Information Us,   FIU). The AA never decrypts or stores the data; it is an encrypted pass-through.
  7. NBFC receives structured data: The NBFC receives machine-readable bank statement data directly from the bank, verified, tamper-proof, and formatted for automated analysis.

Who the Participants Are in the AA Ecosystem

AA ecosystem participants:

  • Account Aggregator (AA): the regulated intermediary that facilitates consent-based data flow. Licensed by the RBI. Current licensed AAs include Finvu, OneMoney, Perfios Account Aggregation Services (PAAS), PhonePe AA, and others.
  • Financial Information Provider (FIP): the entity that holds the individual’s data, primarily banks. FIPs include all banks that have implemented the FIP interface (most major public sector and private sector banks as of 2025; cooperative banks and some RRBs still implementing).
  • Financial Information User (FIU): the entity requesting data in lending, the NBFC or bank that wants the borrower’s bank statement for credit assessment. FIUs must be RBI-regulated entities.
  • Borrower/Customer: the data owner who consents. The borrower’s consent is the trigger for every data request. Without explicit consent, no data flows.

What Data Types Are Available Through AA

The AA framework covers multiple categories of financial data, phased in over time:

  • Bank account data: transaction history, account balance, and account information from savings, current, and term deposit accounts. This is the most commonly used data type for lending today, effectively a digital, tamper-proof bank statement.
  • Tax data: ITR (Income Tax Return) data, Form 26AS, and Annual Information Statement (AIS) shared through CBDT as the FIP. Available for income verification in lending.
  • GST data: GSTR-1 and GSTR-3B through the GSTN as FIP. Available for MSME income verification and turnover assessment. Being actively integrated with AA as of 2025–26.
  • SEBI-regulated investment data: mutual fund portfolio data, demat account data available for wealth management and loan against securities use cases.
  • Pension data: NPS (National Pension System) data available for income and retirement asset assessment.

How AA Changes Bank Statement Collection in NBFC Lending

Before AA, the bank statement collection process for NBFC loan applications was:

  • Borrower requests printed statements at bank branches (1–3 days).
  • Borrower delivers physical statements to NBFC (additional time).
  • NBFC scans orreceives, FS, potentially fabricated or altered.
  • NBFC manually reviews or sends to a bank statement analysis tool.

With AA, the process becomes:

  • NBFC sends an AA consent request (instant).
  • Borrower approves on mobile (30–60 seconds).
  • Bank sends structured data to the lender (30–60 seconds after consent).
  • Lender’s bank statement analysis tool processes machine-readable data (seconds).

Total time from “share your bank statement” to analysed income data: under 5 minutes in a well-implemented AA flow versus 2–5 days in the traditional process. Beyond speed, AA data eliminates tampering risk because the data comes directly from the bank’s systems, not through the borrower as a PDF intermediary.

AA Consent Attributes: Duration, Frequency, and Purpose

Every AA consent has specific attributes that define its scope:

  • Purpose: the declared reason for the data request. In lending: “Credit Underwriting” or “Loan Processing.” The borrower sees the specific purpose before approving.
  • Duration: how long the consent is valid. A one-time consent is used for a single data fetch (current application only). A recurring consent allows the lender to pull fresh data periodically (monthly bank statements for active loan monitoring).
  • Frequency: how often data can be fetched during the consent duration. “Monthly” allows one fetch per month; “on demand” allows a fetch whenever the FIU requests it within the duration.
  • Data life: how long the FIU can store the fetched data. After this period, the data must be deleted from the FIU’s systems.

Recurring consent is particularly powerful for active loan monitoring: the NBFC can pull fresh bank statement data monthly from an active borrower with a single one-time consent approval, enabling Early Warning System monitoring without requiring new borrower action each month.

AA Limitations: What 38% AA Adoption Means for Lenders

As of December 2025, approximately 38% of borrowers have accounts at AA-enabled banks. This means 62% of loan applications still require PDF-based bank statement collection.

The 62% gap comes from:

  • Cooperative banks and RRBs: most have not yet implemented FIP interfaces. Borrowers banking primarily with cooperative banks cannot share bank data through AA.
  • Older bank account holders: some customers have accounts at major banks but have not used the mobile banking app that enables AA or have not linked their AA ID.
  • Technical failures: AA consent flows have technical failure rates from bank timeouts, mobile number mismatches, and app compatibility issues that prevent consent completion even for technically eligible borrowers.

For NBFCs: an AA-only bank statement collection strategy reaches 38% of the market. A dual-channel strategy (AA + PDF) is necessary to serve the full borrower population, with AA as the preferred path and PDF with fraud detection as the fallback.

Key Takeaways

  • The Account Aggregator consent framework enables borrowers to share structured, tamper-proof financial data directly from their banks to regulated lenders through explicit, time-bound, purpose-specific digital consent.
  • AA ecosystem: Account Aggregator (regulated intermediary), Financial Information Provider (the bank holding the data), Financial Information User (the NBFC requesting data), and the Borrower (data owner and consent giver).
  • AA eliminates PDF tampering risk; data comes directly from the bank’s systems, not through the borrower as a document intermediary. It also reduces bank statement collection time from days to minutes.
  • 38% AA adoption (December 2025) means 62% of borrowers still require PDF collection. Dual-channel strategy (AA + PDF fallback) is necessary for full market coverage.

Frequently Asked Questions

What is the Account Aggregator framework and how does it work in lending?

The Account Aggregator (AA) framework is India’s RBI-regulated infrastructure for consent-based financial data sharing. In lending, the borrower approves a digital consent request specifying what data is shared (bank statements), with whom (the NBFC), for what purpose (credit assessment), and for how long. The bank then sends structured, tamper-proof financial data directly to the NBFC through the AA infrastructure, eliminating the need for the borrower to submit PDF bank statements.

Who are the participants in the Account Aggregator ecosystem?

The AA ecosystem has four main participants: the Account Aggregator (the RBI-licensed intermediary that facilitates data flow licensed AAs include Finvu, OneMoney, and Perfios Account Aggregation Services), the Financial Information Provider (the borrower’s bank, which holds and sends the data), the Financial Information User (the NBFC or lender requesting data), and the Borrower (the data owner who provides explicit consent).

What data types can be shared through the Account Aggregator framework?

Currently available data types: bank account transaction data (the primary lending use case), Income Tax Return data and Form 26AS (through CBDT as FIP), GST return data (through GSTN being actively integrated as of 2025–26), SEBI-regulated investment data (mutual funds, demat accounts), and NPS pension data. The framework is designed to expand data type coverage progressively.

Why do NBFCs still need PDF bank statements if Account Aggregator exists?

As of December 2025, approximately 38% of borrowers have accounts at AA-enabled banks. The remaining 62% bank primarily with cooperative banks, rural banks, or have accounts not yet integrated with the AA ecosystem. NBFCs that rely solely on AA data collection cannot serve this 62% of the market. A dual-channel approach AA as the preferred path, PDF with fraud detection as the fallback is necessary to reach the full borrower population.

What is a recurring consent in the Account Aggregator framework?

A recurring consent allows the NBFC (FIU) to fetch fresh data from the borrower’s bank periodically during the consent duration, for example, monthly bank statements for 12 months without requiring the borrower to approve each fetch individually. The borrower approves the recurring consent once; data flows monthly. This enables active loan monitoring through the Early Warning System without creating borrower fatigue from repeated consent requests.

Conclusion

The Account Aggregator consent framework is infrastructure, not just a feature. It is the digital plumbing that enables real-time, tamper-proof, consent-based financial data sharing at scale, making bank statement collection faster, safer, and more borrower-friendly than any previous mechanism.

For NBFCs building digital lending infrastructure: AA integration is not optional for competitive digital lending. Build it, test it across the major bank FIPs, and design your borrower journey around the AA consent flow as the primary path. But also build the PDF fallback rigorously because 62% of your addressable market still cannot use AA, and that fraction is not zero in the near future.

Make smarter lending decisions with FinEye.

Home » Account Aggregator Consent Framework
Chailsee Yadav's avatar

Chailsee Yadav

Discover more from FinEye

Subscribe now to keep reading and get access to the full archive.

Continue reading