Account Aggregator
Also called: AA · Topic: Payment Systems and Digital Finance · NCERT: Beyond NCERT
Meaning
An Account Aggregator (AA) is an RBI-regulated middleman that moves a person's financial data from one institution to another. It moves the data only when the person gives consent, and it cannot read the data. Legally, it is an NBFC-AA (Non-Banking Financial Company – Account Aggregator) under the RBI Master Direction of 2016 [1].
It matters because it lets a lender see a borrower's real money flows, like bank inflows and sales. So people and small firms with no credit history or collateral can still get loans. It also leaves the person, not the bank, in control of their data.
Explanation
The three players
- Financial Information Provider (FIP): the body that holds your data, such as a bank, insurer or mutual fund.
- Financial Information User (FIU): the body that wants your data, such as a lender or wealth manager.
- Account Aggregator (AA): the pipe in the middle. It carries data only with your explicit consent, for a stated purpose and a stated period.
- One institution can play both roles. A bank can be an FIP (it holds your savings account data) and also an FIU (it wants your data before giving you a loan).
Key design features
- Consent-based
- Every data transfer needs your "yes" on your phone.
-
The consent says why the data is needed (for example, a loan check) and for how long (for example, one-time access).
-
Data-blind
- The data passes through the AA encrypted (locked in a code).
- The AA cannot read or store it. Only the FIU can decrypt it.
-
So the AA is a data pipe, not a data warehouse.
-
Cross-sector
- The AA itself is licensed by RBI.
- FIPs and FIUs can be regulated by RBI, SEBI, IRDAI or PFRDA.
-
So bank, securities, insurance and pension data all move on one network.
-
Part of Digital Public Infrastructure (DPI)
- DPI means open, interoperable systems (systems that work with each other) built as public goods (built once, used by all).
- The AA sits in the data layer of India Stack, along with DigiLocker and DEPA (Data Empowerment and Protection Architecture, the consent-based design idea behind this layer).
How a loan works through an AA
- Step 1: A small shop owner applies to an NBFC (the FIU) for a loan.
- Step 2: The NBFC asks, through an AA, for 12 months of bank statements.
- Step 3: The shop owner approves the consent on their phone. The consent states the purpose (a loan check) and the time limit (one-time access).
- Step 4: The bank (the FIP) sends the encrypted statement through the AA.
- Step 5: The NBFC decrypts it, studies the cash flows and decides on the loan.
Why it changes lending: cash-flow-based lending
- Thin-file borrowers are people or MSMEs (micro, small and medium enterprises) with little credit history and no collateral (property or assets pledged as security for a loan).
- Old method: no credit score and no collateral → no loan.
- New method:
- The lender reads real cash flows (sales, GST data, bank inflows).
- This shows whether the borrower can repay.
- So the lender can give a loan without collateral.
In India
- Regulator and law: RBI, through the NBFC-AA Master Direction, 2016 [1].
- Launch: the AA network went live on 2 September 2021 [1].
- Scale at the four-year mark (September 2025) [1]:
- 2.2 billion financial accounts can share data through AAs.
- 112.34 million (about 11.2 crore) users have linked their accounts.
-
112 institutions are live as both FIP and FIU, 56 as FIP only and 410 as FIU only.
-
Link with the Unified Lending Interface (ULI):
- ULI is RBI's lending platform. It uses open APIs (standard digital "plugs" that let two computer systems talk to each other).
- It pulls in Aadhaar e-KYC, state land records, PAN validation and Account Aggregator data [2][3].
- It was renamed ULI and its national roll-out was announced in August 2024 [4].
-
It had 64 lenders (41 banks + 23 NBFCs) as of 12 December 2025 [2][3].
-
Link with the privacy law:
- Under the DPDP Act 2023, Consent Managers let a person give, manage, review or withdraw consent. They must register with the Data Protection Board [5][6].
- This applies the AA idea to all sectors.
- The DPDP Rules were notified on 13 November 2025 [5].
Don't confuse with
- Credit Information Company (credit bureau): a bureau collects and stores credit histories and gives scores. An AA stores nothing and only carries encrypted data, one consent at a time.
- Open banking (EU PSD2 / UK rules): under open banking, banks share data directly with each third-party provider through APIs. In India's model, a separate regulated consent manager (the AA) sits in between, and the customer manages consent from one place.
- DigiLocker: DigiLocker is a digital locker that stores official documents. The AA moves financial data and does not store it. Both sit in the data layer.
- OCEN / ULI: these are credit rails. OCEN is a common "language" for lenders and loan apps, and ULI is RBI's lending platform. The AA is the data-sharing rail they draw on. None of the three is a payment system.
Prelims Hooks
- The AA is an NBFC-AA regulated by RBI under the Master Direction, 2016. The network went live on 2 September 2021 [1].
- FIP = holds data (for example, a bank). FIU = uses data (for example, a lender). AA = data-blind consent pipe. Trap: the AA does not read or store data.
- The AA is licensed by RBI alone, but FIPs and FIUs can be regulated by RBI, SEBI, IRDAI or PFRDA. Trap: "AAs are regulated by SEBI" is wrong.
- The AA belongs to the data layer of India Stack, with DigiLocker and DEPA. It is not in the payments layer (UPI, AePS) or the identity layer (Aadhaar, eSign).
- As of September 2025: 2.2 billion accounts could share data and 112.34 million users had linked accounts [1].
- PSD2 is the EU's open-banking law, not India's. Under the DPDP Act 2023, Consent Managers register with the Data Protection Board [5][6].
Mains Points
- Data as collateral (GS-III: inclusive growth, MSMEs):
- AA, GST data and ULI allow cash-flow-based lending to thin-file MSMEs and farmers. This can narrow the MSME credit gap.
-
Risks: digital lenders may over-lend, and credit-scoring algorithms can be biased.
-
Consent vs convenience (GS-II: rights and governance):
- The AA's consent design and the DPDP Act's Consent Managers put users in control of their data.
- The AA's data-blind design supports the right to privacy, which Puttaswamy (2017) recognised as a fundamental right.
-
But real consent needs digital literacy, consent notices in local languages and a Data Protection Board that acts firmly.
-
Public rails, private competition:
- The AA is a neutral public rail, and many private lenders and apps compete on top of it.
- So no single firm owns the customer's data, unlike the closed systems of big-tech wallets such as China's Alipay and WeChat Pay.
- This lowers entry barriers for new lenders and strengthens India's DPI model, which it promotes for the Global South.
Related concepts
Read more
Sources
- 1Celebrating four years of launch of the Account Aggregator Ecosystem – India's DPI (PIB)pib.gov.in · tier 1
- 2DFS convenes high-level meeting to scale up Unified Lending Interface (PIB)pib.gov.in · tier 1
- 3AI-Powered Financial Inclusion in India, 13 May 2026 (PIB)static.pib.gov.in · tier 1
- 4Speech, RBI Bulletin September 2024 (ULI)rbidocs.rbi.org.in · tier 1
- 5DPDP Rules, 2025 Notified (PIB)pib.gov.in · tier 1
- 6The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) (MeitY)meity.gov.in · tier 1