The Account Aggregator (AA) framework is India’s pioneering consent-based financial data sharing architecture, created by the Reserve Bank of India to give customers clear control over their financial information. An NBFC-AA is a specialized, data-blind intermediary — it does not lend, does not hold customer money, and does not see customer data. Its only role is to securely transport a customer’s consented financial information from a Financial Information Provider (FIP) like a bank or NBFC, to a Financial Information User (FIU) like a lender, insurer, or wealth manager.
NBFC-AAs sit at the heart of the emerging Digital Public Infrastructure (DPI) for finance. Strong AA compliance is not optional — it is a continuous blend of RBI NBFC-AA Directions, ReBIT technical standards, Sahamati ecosystem rules, Digital Personal Data Protection (DPDP) obligations, information security norms, and PMLA / AML discipline, all wrapped around a single core principle: no data flows without a valid, granular, revocable consent.
We offer end-to-end NBFC-AA compliance services — from CoR support and operating model design to consent framework implementation, ReBIT-aligned tech review, DPDP alignment, IS audit, RBI returns, ecosystem integration, and day-to-day compliance — so your AA stays regulator-ready, auditor-ready, and Sahamati-ready at all times.
₹2 Cr
Minimum Net Owned Funds
Consent
Only basis for data flow
Data-Blind
AA cannot read customer data
RBI
NBFC-AA Master Directions
Regulations & Frameworks We Align With
RBI Act, 1934
NBFC-AA Master Directions
ReBIT Technical Specifications
Sahamati Rulebook
DPDP Act, 2023
IT Act & CERT-In
PMLA & FIU-IND
SBR Framework
FAQs on NBFC-AA Compliance
What is an NBFC-AA?
An NBFC-AA is a specialized Non-Banking Financial Company registered with the Reserve Bank of India under the NBFC-AA Master Directions. It acts as a data-blind consent manager that transports a customer’s financial data between a Financial Information Provider (FIP) and a Financial Information User (FIU), strictly on the basis of explicit customer consent.
What are the key compliance pillars for an NBFC-AA?
Key pillars include continuous compliance with the NBFC-AA Master Directions, ReBIT technical specifications, Sahamati rulebook, DPDP Act, CERT-In cyber obligations, PMLA / FIU-IND reporting, corporate and tax compliance, and a strong consent architecture backed by end-to-end audit trails.
Can an NBFC-AA see or store customer data?
No. By design, an NBFC-AA is data-blind. It only transports encrypted data from the FIP to the FIU on the basis of the customer’s consent. It cannot read the content of the data, retain the payload, or use it for any purpose of its own. Any deviation from this design is a fundamental breach of the framework.
Does DPDP Act apply to NBFC-AAs?
Yes. The DPDP Act, 2023 applies to all entities processing personal data, including NBFC-AAs. This includes obligations around notice, consent, purpose limitation, customer rights, grievance redressal, breach reporting, and appointment of a Data Protection Officer where applicable.
What is the role of Sahamati?
Sahamati is the self-regulatory body for the Account Aggregator ecosystem. While it is not a statutory regulator, it plays a critical role in onboarding, certification, interoperability, dispute resolution, and adoption of operational rulebooks for AA participants. Alignment with Sahamati rules is expected in practice by counterparties and supervisory authorities.
Is an IS audit mandatory for NBFC-AAs?
Yes. Given the sensitive nature of AA operations, an IS audit is a core compliance expectation. NBFC-AAs are required to maintain robust information security controls, undergo periodic IS audits, follow CERT-In reporting obligations, and maintain business continuity and disaster recovery arrangements.
Can an NBFC-AA offer lending or investment advice?
No. NBFC-AAs are prohibited from undertaking any financial activity other than account aggregation. They cannot lend, invest, hold customer funds, sell financial products, or provide advice. The only permissible activity is the data-blind transport of customer data between FIPs and FIUs on the basis of consent.
What are the consequences of AA non-compliance?
Non-compliance can lead to monetary penalties under RBI and DPDP Act, restrictions or conditions on the AA CoR, supervisory action, reputational damage, loss of partners, Sahamati-level consequences, and in severe cases, cancellation of the Certificate of Registration itself. Personal liability of directors and key officers can also arise in specific circumstances.
Run a Regulator-Grade, Ecosystem-Ready NBFC-AA
Partner with our specialists for end-to-end NBFC-AA compliance — consent architecture, ReBIT & Sahamati readiness, DPDP alignment, IS audit, and ongoing RBI reporting, all under one roof.
Talk to an Expert