India Account Aggregator Framework (RBI)
RBI AA Consent Architecture

India Account Aggregator Framework (RBI) RBI-AA-ConsentArchitecture-ConsentArtefact-ExplicitConsent-PurposeLimitation-CustomerDashboard-ORS-CMP: RBI AA Consent Architecture - Consent Artefact + Explicit Customer Consent + Purpose Limitation + Customer Consent Dashboard + Online Revocation Service + Consent Management Provider

Consent Architecture is the core distinguishing element of the RBI AA Framework - all financial data sharing between FIPs and FIUs requires explicit + revocable + auditable customer consent mediated through the Account Aggregator. (1) Consent Artefact: digitally signed structured consent record per Sahamati specifications including Consent ID + Consent Handle + Customer ID (VUA Virtual User Address) + FI Types (Accounts + Deposits + Loans + GST + Insurance + Investments + ITR + EPF + NPS + Property) + FI Categories (DEPOSIT + TERM_DEPOSIT + CREDIT_CARD + RECURRING_DEPOSIT + ETF + IDR + CIS + GOVT_SECURITIES + EQUITIES + BONDS + DEBENTURES + MUTUAL_FUND_UNITS + INSURANCE_POLICIES + NPS + LIFE_INSURANCE + GENERAL_INSURANCE + INVOICE + GST) + Purpose Codes per Sahamati taxonomy (Wealth Management + Loan/Credit + Personal Finance Management + Income/Expense Insights + Customer Identification + Investment Advisory) + Frequency of Data Pull (One-Time + Recurring) + Data Range (Start Date + End Date) + Data Life (storage duration at FIU) + FI Fetch Type (ON-DEMAND + PERIODIC) + Consent Start + Expiry Date + FIP Identifier + FIU Identifier + Consent Mode (DIRECT + STORE + VIEW). (2) Explicit Consent: customer must actively grant consent through AA UI + cannot be pre-checked + supports multilingual UX + accessibility + low-bandwidth/2G/3G optimised + Aadhaar OTP/UIDAI eSign integration where applicable + PIN + biometric. (3) Purpose Limitation: data shared with FIU strictly limited to declared purpose + cannot be re-used or shared with third parties + purpose codes binding. (4) Customer Consent Dashboard: AA portal showing all granted/active/expired/revoked consents + allows on-demand revocation (Online Revocation Service ORS) + change of consent parameters where applicable + audit log access. (5) Revocation: customer can revoke at any time + immediate effect + FIU informed + further data pulls cease. (6) Consent Lifecycle: granted -> active -> paused -> revoked -> expired -> deleted. (7) Time-Bound: maximum consent duration limited per RBI guidance + typical 1-2 years + must be re-confirmed. Coordinates with Sahamati Consent Artefact Schema v1.1.2 + ReBIT FI API specifications + DEPA Data Empowerment and Protection Architecture + DPDP Act 2023 Section 5 (Notice) + Section 6 (Consent) + Section 7 (Lawful Use without Consent) + IT Act 2000 Section 43A. RBI AA Consent Architecture applies.

What else in your programme already covers this

This control maps to 33 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 27014:2020 · 2 controls

ISO/IEC 27400:2022 · 2 controls

  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data

FedRAMP Rev 5 · 1 control

  • FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act)
  • CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

IEEE 7000 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 33 it maps to, and the evidence behind each claim, over MCP and REST.