Account Aggregator Framework: NBFC-AA, FIP, FIU & DEPA Explained for IIBF
The Account Aggregator framework is one of the most transformative regulatory innovations in India's financial sector, enabling secure, consent-driven sharing of financial data between institutions under a robust and interoperable architecture. For aspirants preparing for the IIBF Digital Banking certification and allied examinations such as JAIIB and CAIIB, a clear understanding of how this ecosystem functions — from NBFC-AA licensing to the Data Empowerment and Protection Architecture (DEPA) — is essential for both the examination and professional practice.
What Is the Account Aggregator Framework?
The Account Aggregator (AA) framework is a consent-based financial data-sharing architecture introduced by the Reserve Bank of India (RBI). It allows individuals and businesses to consolidate. Share.
And control their financial information — such as bank statements. Insurance policies. Mutual fund holdings.
And tax records — across participating institutions in a standardised. Encrypted, and auditable manner.
At its core, the framework is built around three principal roles:
- Account Aggregator (NBFC-AA): A non-banking financial company licensed by RBI solely to aggregate. Transmit financial data. The AA acts as a consent manager — it does not store. View. Or analyse the data itself. It only passes encrypted data packages between parties after obtaining the customer's explicit consent.
- Financial Information Provider (FIP): An entity that holds a customer's financial data. Such as banks. NBFCs, insurance companies, mutual fund registrars, pension funds, and tax authorities. FIPs expose data through standardised APIs to the AA ecosystem once a user grants consent.
- Financial Information User (FIU): An entity that seeks access to a customer's financial data to deliver a service. Such as a lender assessing creditworthiness or a financial planning app analysing spending patterns. FIUs must be registered participants in the ecosystem. Can only receive data through the AA channel. Never directly from the FIP.
This tripartite structure ensures that the data principal. The customer — remains in control at every step. No data moves without an active. Time-bound, purpose-specific consent granted by the user.

The Consent Artefact and DEPA Stack
The technical backbone of the Account Aggregator system is the consent artefact. A machine-readable. Digitally signed document that encapsulates the precise terms under. Financial data may be shared. Every data transaction in the AA ecosystem is governed by a consent artefact that specifies:
- The identity of the data principal (customer) and the FIU requesting data
- The type and range of financial information to be shared
- The purpose of use (lending, personal finance management, insurance underwriting, etc.)
- The data fetch frequency — one-time, periodic, or recurring
- The validity period and expiry of consent
- Whether the FIU may store, process, or further share the received data
The consent artefact is cryptographically signed by the AA. Which generates a unique consent handle. The FIP validates this handle before releasing any data. This architecture ensures non-repudiation: neither the FIP nor the FIU can claim they received or shared data without a valid. Auditable consent trail.
The broader technology layer underpinning this system is known as the Data Empowerment. Protection Architecture (DEPA). DEPA is a policy-plus-technology framework developed collaboratively by government agencies.
Regulators. And civil society to enable data sharing across sectors — finance. Health, telecom — in a manner that is citizen-centric and interoperable.
In the financial domain. The AA framework is the most mature implementation of DEPA principles. DEPA distinguishes between the role of a data fiduciary (an entity that determines the purpose of data processing.
Bears accountability. Such as a bank or NBFC). A data processor (an entity processing data on behalf of the fiduciary).
This distinction is aligned with. And increasingly harmonised alongside. The Digital Personal Data Protection (DPDP) Act.
2023. Which places obligations on data fiduciaries to ensure lawful. Purpose-limited, and secure processing of personal data.
Sahamati, a non-profit industry alliance, serves as the operational backbone of the AA ecosystem. It maintains the Central Registry of all AA-licensed entities, FIPs, and FIUs; sets technology standards; monitors ecosystem health; and facilitates dispute resolution. Banking professionals should be familiar with Sahamati's role as the ecosystem steward, separate from RBI's regulatory role. More information is available at the Sahamati official website.
Licensing and Regulatory Framework for NBFC-AAs
An entity wishing to operate as an Account Aggregator must obtain a Certificate of Registration from the RBI as a Non-Banking Financial Company. Account Aggregator (NBFC-AA). The Master Direction for NBFC-AAs.
Issued by RBI in 2016 and subsequently updated. Lays down the eligibility. Capital requirements, governance norms, and operational restrictions for these entities.
Key regulatory characteristics of an NBFC-AA include:
- Single-purpose restriction: The NBFC-AA cannot undertake any other financial activity. It cannot lend, invest, or provide financial advice. Its sole function is consent management and data routing.
- Net Owned Fund (NOF) requirement: A minimum NOF of ₹2 crore is prescribed at the time of registration.
- Data blindness principle: The AA must not store. Process, or view the financial data it transmits. All data flows through the AA in encrypted form. Using end-to-end encryption technologies specified in the AA Technical Standards.
- Consent revocability: Users must be able to pause. Revoke, or modify consent at any time through the AA interface. The AA is responsible for propagating such revocations to the FIP. FIU within the prescribed timelines.
- Grievance redressal: Each NBFC-AA must maintain a grievance officer. Report periodically to RBI on consent logs. Data disputes, and consumer complaints.
Several entities have received NBFC-AA licences. And the ecosystem has seen rapid expansion with major public sector. Private sector banks joining as FIPs.
The RBI has also been progressively expanding the scope of FIPs to include entities regulated by SEBI. IRDAI. PFRDA.
And the Income Tax Department. Making the AA ecosystem a truly cross-regulatory data highway.
Candidates preparing for the Digital Banking module of the IIBF certification should also stay updated through the IIBF News section for regulatory circulars and examination updates.

Use Cases: Lending, PFM, and Beyond
The practical impact of the Account Aggregator framework is best understood through its use cases. Across retail banking. MSME finance.
And personal financial management (PFM). The AA architecture eliminates paper-based data submission. Reduces processing times, and enables more accurate risk assessment.
Retail. MSME Lending: A borrower seeking a personal loan or business loan can consent. Via an AA app — to share bank statements.
GST returns (via the GSTN as FIP). And ITR data (via CBDT/tax authority as FIP) directly with the lender (FIU). This eliminates the need for physical bank statement submission and manual verification.
Reducing the loan processing cycle from days to minutes. Credit underwriting models become more accurate because lenders access cash flow data. Not just credit bureau scores.
Personal Finance Management: A PFM application (FIU) can aggregate a user's bank account balances. Credit card statements. Mutual fund NAVs.
And insurance premiums into a single dashboard. All through the AA channel — enabling holistic financial planning. Unlike screen-scraping methods used by legacy fintech apps (which required users to share passwords).
The AA framework delivers data without exposing credentials.
Insurance Underwriting: Insurers (FIUs) can access income. Banking transaction data with user consent to offer personalised. Risk-adjusted insurance products. Particularly for health. Term plans targeting self-employed individuals or gig workers who lack traditional salary slips.
Wealth Management. Investment Advisory: Portfolio management service providers. SEBI-registered investment advisers can pull consolidated account. Holding data to provide tailored advice. Reducing the information asymmetry that has traditionally limited wealth services to high-net-worth individuals.
For examination practice, candidates should explore the IIBF mock test platform and the banking concept matching game to test and reinforce knowledge of these use cases in an engaging format. Regular practice through topic-specific tests helps consolidate conceptual understanding for the Digital Banking paper.
Security Architecture and the DPDP Act Interplay
Security is foundational to the credibility of the Account Aggregator ecosystem. The AA Technical Standards mandate end-to-end encryption of financial data using public-key cryptography: the FIU generates an encryption key pair. Shares the public key with the FIP (via the AA).
And the FIP encrypts the data payload such that only the FIU can decrypt it. The AA handles the encrypted blob but cannot read it. This architecture.
Sometimes described as "data blind". Is central to the trust model of the framework.
Additional security measures in the AA framework include:
- Digital signatures on consent artefacts. Data packages to ensure authenticity and integrity
- Mutual TLS (mTLS) for all API communications between AA. FIP, and FIU to prevent man-in-the-middle attacks
- Token-based access — FIPs validate consent tokens before releasing data. And expired or revoked tokens result in data request rejection
- Audit logs maintained at each node (AA. FIP, FIU) for regulatory inspection and consumer grievance resolution
The interplay with the Digital Personal Data Protection (DPDP) Act. 2023 is a key area for banking professionals to understand. The DPDP Act establishes the concept of a "Consent Manager".
A registered entity through which data principals grant. Manage, and revoke consent for personal data processing. NBFC-AAs.
Operating in the financial data domain. Are well positioned to function as consent managers under the DPDP framework. However.
Certain obligations are sector-specific: for instance. The AA framework's data blindness requirement. The RBI's sector-specific rules may govern over general DPDP provisions in case of conflict.
In line with the DPDP Act's provisions for sector-specific regulations.
The concept of data fiduciary under the DPDP Act maps to the responsibilities of FIPs and FIUs in the AA framework — both bear accountability for lawful data collection and use. Understanding this interplay is increasingly relevant for IIBF Digital Banking candidates, as examination questions draw on the intersection of technology regulation, data privacy law, and financial services compliance. Candidates seeking additional regulatory context can also refer to the RBI regulatory rates and updates resource, or browse the IIBF exam blog for topic-wise coverage across all modules.
For a deeper dive into RBI's regulatory framework for AAs, refer to the Reserve Bank of India's official website, which hosts the Master Directions and circulars governing NBFC-AAs.
What is the difference between an Account Aggregator, a FIP, and a FIU?
An Account Aggregator (NBFC-AA) is a licensed consent manager that routes encrypted financial data between parties without accessing it. A Financial Information Provider (FIP) is the institution that holds a customer's financial data. Such as a bank or mutual fund registrar.
And releases it upon valid consent. A Financial Information User (FIU) is the entity requesting the data. Such as a lender or a personal finance app.
To deliver a specific financial service. The AA mediates between FIP and FIU. Ensuring all data flows are consent-backed and auditable.
What does the consent artefact contain in the Account Aggregator framework?
The consent artefact is a digitally signed. Machine-readable document that specifies the identity of the parties. The type of financial data to be shared.
The purpose of use. The frequency of data fetch (one-time or recurring). The validity period of the consent.
And any restrictions on data storage or onward sharing by the FIU. It is generated. Signed by the AA.
Validated by the FIP before any data is released. The customer can revoke or pause consent at any time. And this revocation is propagated across the ecosystem.
How does DEPA relate to the Account Aggregator framework?
DEPA. Or the Data Empowerment and Protection Architecture. Is a broader policy-plus-technology framework that governs consent-based data sharing across sectors in India.
Including finance. Health, and telecom. The Account Aggregator framework is the financial sector's implementation of DEPA principles.
Operationalised through RBI's NBFC-AA licensing regime and Sahamati's ecosystem governance. DEPA distinguishes between data fiduciaries (accountable for purpose. Use) and data processors.
Concepts also reflected in the Digital Personal Data Protection Act, 2023.
Is the Account Aggregator framework relevant for JAIIB, CAIIB, and IIBF Digital Banking examinations?
Yes. The Account Aggregator framework is explicitly part of the IIBF Digital Banking certification syllabus. Is increasingly covered in CAIIB's Banking Technology and Risk Management modules.
JAIIB candidates benefit from understanding the AA framework under the banking regulation. Technology components. Examination questions test knowledge of NBFC-AA licensing.
The FIP-FIU-AA tripartite model. Consent artefact mechanics. DEPA, Sahamati's role, and the intersection with the DPDP Act.
Regular practice on topic-specific tests helps candidates master this rapidly evolving area.
The Account Aggregator framework represents a foundational shift in how financial data is managed in India — from institution-centric silos to customer-controlled flows built on interoperability and trust. For IIBF Digital Banking aspirants, mastering this framework is both an examination necessity and a professional imperative. Reinforce your understanding with targeted practice at iibf.store/tests — where subject-wise mock tests are designed to match the current examination pattern for Digital Banking and allied IIBF certifications.
Quick summary in plain words
In short: keep it simple.
Read each point slow.
Take notes as you go.
Use the free tests to check what you know.
Watch the video if a part feels hard.
Do a bit each day.
Ask us on WhatsApp if you get stuck.
You can pass this exam.
Stay calm and trust your prep.
Come back to this guide often.
Small steps add up fast.
Skim the box below first.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.