September 14, 2026
10 min read
What Is the Account Aggregator Consent Framework? How Borrowers Share Financial Data with Lenders
September 14, 2026
10 min read
For most of India’s lending history, a borrower who wanted to share their bank statement with a lender had one option: walk to the bank branch, request a printed statement, and physically hand it over or scan it and upload a PDF. The Account Aggregator framework changes this completely. The borrower taps a few buttons in their bank’s app, and structured, tamper-proof financial data flows directly to the lender in seconds.
The Account Aggregator (AA) consent framework is India’s RBI-regulated data-sharing infrastructure that allows individuals to securely and digitally share their financial data bank statements, GST returns, tax data, and insurance information with regulated entities (lenders, wealth managers, other financial institutions) through a consent-based, privacy-preserving mechanism. The framework is built on the principle that the individual owns their financial data and controls who accesses it.
The AA framework was conceptualised by the RBI in 2016 and operationalised between 2020 and 2023. It is India’s implementation of the broader concept of “data empowerment,” the principle that individuals, not institutions, should control their financial data.
Before AA, financial data sharing between institutions happened either manually (physical documents) or through informal, often non-consensual data aggregation by credit bureaus and data brokers. The individual had limited visibility into what data was being shared about them and almost no ability to selectively share specific data with specific entities for specific purposes.
AA changes this by creating a regulated intermediary, the Account Aggregator, that facilitates data sharing based on explicit, informed, time-bound, purpose-specific consent from the data owner (the individual).
AA ecosystem participants:
The AA framework covers multiple categories of financial data, phased in over time:
Before AA, the bank statement collection process for NBFC loan applications was:
With AA, the process becomes:
Total time from “share your bank statement” to analysed income data: under 5 minutes in a well-implemented AA flow versus 2–5 days in the traditional process. Beyond speed, AA data eliminates tampering risk because the data comes directly from the bank’s systems, not through the borrower as a PDF intermediary.
Every AA consent has specific attributes that define its scope:
Recurring consent is particularly powerful for active loan monitoring: the NBFC can pull fresh bank statement data monthly from an active borrower with a single one-time consent approval, enabling Early Warning System monitoring without requiring new borrower action each month.
As of December 2025, approximately 38% of borrowers have accounts at AA-enabled banks. This means 62% of loan applications still require PDF-based bank statement collection.
The 62% gap comes from:
For NBFCs: an AA-only bank statement collection strategy reaches 38% of the market. A dual-channel strategy (AA + PDF) is necessary to serve the full borrower population, with AA as the preferred path and PDF with fraud detection as the fallback.
The Account Aggregator (AA) framework is India’s RBI-regulated infrastructure for consent-based financial data sharing. In lending, the borrower approves a digital consent request specifying what data is shared (bank statements), with whom (the NBFC), for what purpose (credit assessment), and for how long. The bank then sends structured, tamper-proof financial data directly to the NBFC through the AA infrastructure, eliminating the need for the borrower to submit PDF bank statements.
The AA ecosystem has four main participants: the Account Aggregator (the RBI-licensed intermediary that facilitates data flow licensed AAs include Finvu, OneMoney, and Perfios Account Aggregation Services), the Financial Information Provider (the borrower’s bank, which holds and sends the data), the Financial Information User (the NBFC or lender requesting data), and the Borrower (the data owner who provides explicit consent).
Currently available data types: bank account transaction data (the primary lending use case), Income Tax Return data and Form 26AS (through CBDT as FIP), GST return data (through GSTN being actively integrated as of 2025–26), SEBI-regulated investment data (mutual funds, demat accounts), and NPS pension data. The framework is designed to expand data type coverage progressively.
As of December 2025, approximately 38% of borrowers have accounts at AA-enabled banks. The remaining 62% bank primarily with cooperative banks, rural banks, or have accounts not yet integrated with the AA ecosystem. NBFCs that rely solely on AA data collection cannot serve this 62% of the market. A dual-channel approach AA as the preferred path, PDF with fraud detection as the fallback is necessary to reach the full borrower population.
A recurring consent allows the NBFC (FIU) to fetch fresh data from the borrower’s bank periodically during the consent duration, for example, monthly bank statements for 12 months without requiring the borrower to approve each fetch individually. The borrower approves the recurring consent once; data flows monthly. This enables active loan monitoring through the Early Warning System without creating borrower fatigue from repeated consent requests.
The Account Aggregator consent framework is infrastructure, not just a feature. It is the digital plumbing that enables real-time, tamper-proof, consent-based financial data sharing at scale, making bank statement collection faster, safer, and more borrower-friendly than any previous mechanism.
For NBFCs building digital lending infrastructure: AA integration is not optional for competitive digital lending. Build it, test it across the major bank FIPs, and design your borrower journey around the AA consent flow as the primary path. But also build the PDF fallback rigorously because 62% of your addressable market still cannot use AA, and that fraction is not zero in the near future.