Consent Architecture is the core distinguishing element of the RBI AA Framework - all financial data sharing between FIPs and FIUs requires explicit + revocable + auditable customer consent mediated through the Account Aggregator. (1) Consent Artefact: digitally signed structured consent record per Sahamati specifications including Consent ID + Consent Handle + Customer ID (VUA Virtual User Address) + FI Types (Accounts + Deposits + Loans + GST + Insurance + Investments + ITR + EPF + NPS + Property) + FI Categories (DEPOSIT + TERM_DEPOSIT + CREDIT_CARD + RECURRING_DEPOSIT + ETF + IDR + CIS + GOVT_SECURITIES + EQUITIES + BONDS + DEBENTURES + MUTUAL_FUND_UNITS + INSURANCE_POLICIES + NPS + LIFE_INSURANCE + GENERAL_INSURANCE + INVOICE + GST) + Purpose Codes per Sahamati taxonomy (Wealth Management + Loan/Credit + Personal Finance Management + Income/Expense Insights + Customer Identification + Investment Advisory) + Frequency of Data Pull (One-Time + Recurring) + Data Range (Start Date + End Date) + Data Life (storage duration at FIU) + FI Fetch Type (ON-DEMAND + PERIODIC) + Consent Start + Expiry Date + FIP Identifier + FIU Identifier + Consent Mode (DIRECT + STORE + VIEW). (2) Explicit Consent: customer must actively grant consent through AA UI + cannot be pre-checked + supports multilingual UX + accessibility + low-bandwidth/2G/3G optimised + Aadhaar OTP/UIDAI eSign integration where applicable + PIN + biometric. (3) Purpose Limitation: data shared with FIU strictly limited to declared purpose + cannot be re-used or shared with third parties + purpose codes binding. (4) Customer Consent Dashboard: AA portal showing all granted/active/expired/revoked consents + allows on-demand revocation (Online Revocation Service ORS) + change of consent parameters where applicable + audit log access. (5) Revocation: customer can revoke at any time + immediate effect + FIU informed + further data pulls cease. (6) Consent Lifecycle: granted -> active -> paused -> revoked -> expired -> deleted. (7) Time-Bound: maximum consent duration limited per RBI guidance + typical 1-2 years + must be re-confirmed. Coordinates with Sahamati Consent Artefact Schema v1.1.2 + ReBIT FI API specifications + DEPA Data Empowerment and Protection Architecture + DPDP Act 2023 Section 5 (Notice) + Section 6 (Consent) + Section 7 (Lawful Use without Consent) + IT Act 2000 Section 43A. RBI AA Consent Architecture applies.
This control maps to 33 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 33 it maps to, and the evidence behind each claim, over MCP and REST.