Reserve Bank of India (RBI) Account Aggregator (AA) Framework is established under the RBI Master Direction Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions 2016 dated 2 September 2016 issued under Section 45L of the RBI Act 1934 with subsequent updates including alignment with Digital Personal Data Protection (DPDP) Act 2023. Creates the NBFC-Account Aggregator (NBFC-AA) licensing category for entities providing the service of retrieving + consolidating financial information of a customer from Financial Information Providers (FIPs) and presenting it to the customer or Financial Information Users (FIUs) per customer consent. Registration with RBI through Department of Non-Banking Regulation. Requirements: (1) Net Owned Funds (NOF) of not less than INR 2 crore (revised threshold per Master Direction amendments); (2) Fit and Proper criteria for directors + senior management + promoters + significant shareholders; (3) Information Technology framework + systems for AA operations; (4) demonstrate adequate capital adequacy + risk management framework; (5) compliance with Companies Act 2013 + Banking Regulation Act 1949 (where applicable) + IT Act 2000 + DPDP Act 2023. Application Process: in-principle approval (12 month validity) + Certificate of Registration (CoR) following operational verification + Sahamati onboarding. Live commercial launch 2 September 2021. Initial 4 NBFC-AA licensees: CAMS FinServ + Cookiejar Technologies (Finvu) + NESL Asset Data + Yodlee Finsoft (later 8+ licensees including PhonePe Technology Services + Perfios AA). RBI Regulatory Sandbox + RBI FinTech Department + Innovation Hub coordination. RBI Master Direction Sources: 2 September 2016 original Master Direction + Amendment Notifications 2016-2024 + RBI Guidelines on Outsourcing of IT Services for AA + RBI Guidelines on Information Security/Cyber Security and IT Frameworks for NBFC-AA. Coordinates with India Digital Public Infrastructure (DPI) layer (Aadhaar + UPI + DigiLocker + ONDC + AA + India Stack) + DPDP Act 2023 + IT Act 2000 + Companies Act 2013 + RBI Cyber Security Framework + RBI Cyber Resilience Framework + RBI Master Directions for NBFCs + SEBI Account Aggregator Regulations (for SEBI-regulated FIPs/FIUs) + IRDAI Guidelines (insurance FIPs/FIUs) + PFRDA (pension FIPs/FIUs) + Sahamati Self-Regulatory Organisation (SRO). Public + freely available via rbi.org.in and sahamati.org.in. RBI AA Registration + NBFC-AA + Master Direction 2016 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.