India’s financial system long faced inefficiency: your financial data didn’t truly belong to you in a usable sense. The Account Aggregator framework changes this. Access to earlier required paperwork, calls, or intermediaries meant lenders made decisions on incomplete data while borrowers faced friction at every step.
The Account Aggregator framework, established by the Reserve Bank of India, changes that. It is a consent-based financial data-sharing infrastructure that lets individuals and businesses securely share verified financial data with institutions of their choice, in real time, without surrendering control. To understand this in action, here’s how the account aggregator system actually works step-by-step.
This guide explains what an Account Aggregator is, how it functions architecturally, who the participants are, and what it means for lenders, borrowers, and the broader fintech ecosystem in India.
Before AA, lenders obtained borrower data through three methods. They collected physical bank statements, used screen-scraping tools, or relied on credit bureau scores.
Each approach had serious limitations. PDF bank statements, the dominant standard in Indian lending, can be altered using freely available tools. A 2022 study by a leading digital lender found that fabricated bank statements accounted for a disproportionate share of early-stage delinquencies in their personal loan book.
Screen-scraping, where borrowers share their net banking credentials with a third party for data extraction, creates clear security vulnerabilities and operates in a regulatory grey zone. Reserve Bank of India’s 2022 Digital Lending Guidelines specifically flagged unregulated data collection practices as a compliance concern. A deeper look at the differences between account aggregators and traditional bank statements highlights why this shift is necessary.
The AA framework replaces these workarounds with a regulated, consent-based data pipeline. It transfers data directly between institutions with the individual’s explicit, auditable consent.
The AA ecosystem operates on three distinct roles:
Financial Information Provider (FIP): The institution that holds your data, your bank, insurance company, mutual fund house, or pension fund. FIPs are the data sources. In India, FIPs include all major scheduled commercial banks, NBFCs, insurance companies regulated by the Insurance Regulatory and Development Authority of India, mutual funds regulated by the Securities and Exchange Board of India, and pension funds regulated by the Pension Fund Regulatory and Development Authority.
Financial Information User (FIU): The institution that wants to access your data, typically a lender, wealth manager, or financial advisor. FIUs consume data to make decisions: credit underwriting, portfolio assessment, or financial planning.
Account Aggregator (AA): The licensed intermediary that facilitates the data transfer. The AA never stores or reads the underlying data. It is purely a consent and routing layer; it manages the consent artefact, validates the request, and passes encrypted data from FIP to FIU. For a more detailed explanation of FIP and FIU roles in the ecosystem, refer to this breakdown.
When a borrower initiates an AA data share, they view a consent screen on the AA or FIU interface. The screen specifies the data type, purpose, time range, retention, and whether consent is one-time or recurring. To understand how consent is created, managed, and revoked in account aggregator systems, this detailed breakdown explains the full flow.
The borrower digitally signs the consent, and the AA generates and stores a cryptographic consent artefact. The FIP then prepares and encrypts the data and sends it to the FIU using the consent artefact. No party, including the AA, can access the data; only the FIU decrypts it with its private key.
This architecture differs from screen-scraping, as data stays within a regulated, auditable, consent-based pipeline.
The RBI introduced the Account Aggregator framework through its 2016 Master Directions and has expanded it since. It classifies AA entities as NBFCs and requires them to obtain an RBI licence to operate.
What makes the AA framework unique is its multi-regulator design. Four regulators RBI, SEBI, IRDAI, and PFRDA- have enabled their entities to act as FIPs and FIUs. This is coordinated under the Financial Stability and Development Council, making AA a cross-sector financial data network. For a detailed breakdown of RBI regulations governing the account aggregator framework, refer to this guide.
iSpirt designed the architecture under DEPA, endorsed by NITI Aayog, to enable data sharing with user control. As of 2025, the RBI has licensed eight AA entities, including Onemoney, Finvu, CAMS, Perfios, PhonePe, Anumati, Saafe, and NADL.
The following entities hold active AA licences fthe rom RBI as of early 2025:
Onemoney: One of the earliest operational AAs, widely integrated with major banks and NBFCs. Backed by Perfios.
Finvu (Cookiejar Technologies): Strong developer community and sandbox access. Widely used in fintech lending stacks.
CAMS Finserv: Registry and servicing infrastructure player entering the AA space. Strong SEBI-side data access.
Perfios Account Aggregation Services: Backed by the Perfios analytics group, focused on the lending data supply chain.
Sahamati, the industry body, maintains an updated registry of live FIPs (banks, NBFCs, insurers) and their data-sharing capabilities. As of Q1 2025, over 50 banks are live as FIPs, including all major public sector banks and private sector banks like HDFC, ICICI, Axis, and Kotak.
The AA framework enables a range of applications across the financial services value chain:
Retail lending: Lenders access 12–24 months of bank transaction history in real time to assess income stability, EMI burden, and savings behaviour, without asking borrowers to upload or submit documents.
MSME credit: Small business owners can share GST filing data, current account transactions, and receivables data with lenders, enabling cash-flow-based underwriting for businesses that lack formal audited financials.
Wealth management: Financial advisors can access a client’s complete investment portfolio across AMCs, insurance policies, and bank deposits to provide holistic planning without manual aggregation.
Insurance underwriting: Insurers can use transaction data to assess risk profiles, particularly for health and life insurance products targeting the self-employed segment.
Wealth planning and tax advisory: Accountants and advisors can access income and investment data with client consent, replacing time-consuming data collection exercises. For a deeper look at real-world use cases of account aggregators in lending and finance, explore these practical implementations.
AA replaces manual bank statement collection with a standardised, verified data feed. Consequently, underwriting time drops from days to hours, and fraud from fabricated statements is eliminated. Hence, lenders gain clearer insights into income patterns, cash flows, and actual EMI obligations.
For borrowers, AA means faster loan decisions, less documentation burden, and, critically, data sovereignty. Under the AA framework, borrowers can revoke consent at any time. They can see exactly who has accessed their data and for what purpose. This is a structural shift in the power relationship between financial institutions and their customers.
For fintechs and API-first lenders, AA provides the data infrastructure layer needed to build automated, scalable underwriting without resorting to data practices that may fall foul of the DPDP Act 2023.
The Account Aggregator framework marks a major shift in India’s financial data infrastructure since UPI.
It does not merely digitise an existing process; it changes the power dynamic fundamentally. Financial data moves from being an institutional asset controlled by banks to a personal asset controlled by individuals.
For lenders, integrating AA into underwriting improves speed, accuracy, and fraud resistance. Those who rely on PDF bank statements not only move more slowly but also use data that is no longer reliable.
The ecosystem is maturing rapidly. As FIP coverage expands, AA data will extend beyond bank statements. It will include insurance, mutual funds, GST returns, and eventually tax records. Lenders and fintechs that build on this foundation will position themselves at the centre of India’s next credit expansion.
An Account Aggregator is an RBI-licensed entity that securely transfers your financial data, with your consent, from your bank or insurer to a lender or financial service provider. It acts as a data courier: it never stores or reads your data; it only facilitates the transfer after you approve it.
Yes. The RBI regulates the AA framework, and it secures data transfers with end-to-end encryption. The AA entity cannot read the data, and individuals can revoke consent at any time.
The RBI regulates Account Aggregators under the NBFC-AA licence. RBI, SEBI, IRDAI, and PFRDA oversee data providers and users across banking, securities, insurance, and pensions.
Open banking (as implemented in the UK under PSD2) uses standardised APIs to allow third parties to access bank data. India’s AA framework is broader and more privacy-protective: it covers data across banking, insurance, securities, and pensions, and requires explicit, granular consent for every data share. The AA also never stores underlying data.
As of 2025, all major scheduled commercial banks, including SBI, HDFC, ICICI, Axis, Kotak, PNB, and Bank of Baroda, are live as FIPs. The full updated list is maintained on the Sahamati website (sahamati.org.in).