India Stack and Digital Public Infrastructure: Layers and Banking Use (Digital Banking)

DIGIBANK By Ashish Jain · IIBF STORE Editorial · 06 August 2026 · Updated 22 Sep 2026 · 8 min read · 37 views
India Stack and Digital Public Infrastructure: Layers and Banking Use (Digital Banking)

India Stack and digital public infrastructure form the backbone of modern Indian banking. Every JAIIB and CAIIB candidate must understand how these building blocks fit together. India Stack is not one single application. It is a layered set of open APIs spanning identity, payments and data. Each layer solves one specific problem for banks and customers. This article maps how a bank actually plugs into each layer. We keep the focus on architecture, not on any one product. UPI, the account aggregator framework and CBDC each already have dedicated articles on this site. Here we look at the full stack together, layer by layer, the way exam questions usually frame it.

🏗️ What Is India Stack and Digital Public Infrastructure

Digital public infrastructure means population-scale, interoperable systems built on open APIs. Government bodies and private players both build on top of them. Instead of one closed system, you get shared rails that any licensed bank can use. India Stack is the umbrella name for this approach in India.

Three layers sit inside India Stack. The identity layer proves who a customer is, using Aadhaar-based eKYC and e-Sign. The payments layer moves money, mainly through UPI and related rails. The data layer moves information, under explicit customer consent, through the DEPA architecture.

Each layer is designed to work without the others. A bank can use only the identity layer for onboarding. It can use only the data layer for a loan appraisal. This separation is exactly what makes the design flexible for banks of every size.

For a broader view of everyday retail operations, see this Overview of Digital Banking chapter. Then return here for the layer-by-layer detail.

LayerCore Building BlocksWhere a Bank Plugs InConsent-Based?
IdentityAadhaar eKYC, e-Sign, Video KYCCustomer onboarding and re-KYC APIs❌ No
PaymentsUPI, RuPay, IMPS, NPCI switchPayment initiation, acquiring and issuing❌ No
DataDEPA, Account Aggregator, DigiLockerConsent-based data-sharing APIs✅ Yes
The three layers of India Stack: identity, payments and data
The three layers of India Stack: identity, payments and data

🆔 The Identity Layer: Aadhaar eKYC and e-Sign

Aadhaar eKYC lets a bank verify a customer's identity electronically. The customer authenticates using an OTP or a biometric match through UIDAI's systems. The bank receives a verified demographic record within seconds, instead of manual document checks.

e-Sign works alongside eKYC. It lets a customer digitally sign an account-opening form or a loan agreement using Aadhaar-based authentication. This signature carries legal validity because it is recognised as an electronic signature service.

Banks are not allowed to make Aadhaar-based authentication the only onboarding path. Video KYC and physical KYC remain valid alternatives. This matters for financial inclusion, since not every customer has an Aadhaar-linked mobile number handy.

💡 Exam Tip: Aadhaar eKYC and e-Sign sit in the identity layer, not the data layer. Do not confuse this with DEPA-based consent sharing, which is a separate layer entirely.

The identity layer also feeds directly into Financial Inclusion efforts, since faster onboarding brings more first-time customers into formal banking. It also underpins app-based onboarding covered in the Mobile Banking chapter.

How Aadhaar eKYC and e-Sign speed up digital account opening
How Aadhaar eKYC and e-Sign speed up digital account opening

💳 The Payments Layer: How Banks Plug In

The payments layer is the most visible part of India Stack for ordinary customers. UPI sits at its centre, connecting bank accounts through the NPCI switch for near-instant transfers. Banks connect either as issuing banks, acquiring banks, or through a payment service provider app.

RuPay and IMPS run alongside UPI as older or parallel rails inside the same layer. A bank's core banking system talks to these rails through standard APIs, not through separate closed networks for each product.

CBDC, the e-Rupee, is emerging as an additional instrument inside this same payments layer. Since it already has a dedicated article on this site, we mention it here only as context, not as a deep dive. The same applies to CBDC e-Rupee digital currency and to UPI Lite and offline payments, both of which sit inside this layer.

Physical acceptance points such as POS terminals and ATMs also connect into the payments layer at the last mile, turning a digital rail into a cash-in or cash-out point for the customer.

DEPA consent architecture: how a Consent Manager links banks and data sources
DEPA consent architecture: how a Consent Manager links banks and data sources

🔐 The Data Layer: DEPA Consent Architecture and DigiLocker

DEPA stands for Data Empowerment and Protection Architecture. It is the design principle behind consent-based data sharing in India. A neutral Consent Manager sits between a data-sending institution and a data-receiving institution.

Every data flow needs a consent artefact. This artefact records the purpose, the specific data items, and the duration for which access is granted. Nothing moves without this explicit, revocable consent record.

⚠️ Common Mistake: Candidates often treat DEPA and the Account Aggregator ecosystem as two different things. DEPA is the architecture; the Account Aggregator framework is its working, regulated implementation for financial data.

DigiLocker is a related but distinct utility. It stores government-issued documents such as PAN cards, driving licences and marksheets. A bank can pull a verified copy of a document from DigiLocker with the customer's consent, cutting down paper submissions during onboarding or loan processing. For the full mechanics of consent-based sharing, read the account aggregator framework in India article.

🏦 Governance, Privacy and Risk Questions for Banks

Layered infrastructure raises layered governance questions. The Digital Personal Data Protection Act, 2023 sets out consent, purpose-limitation and data fiduciary duties. These duties apply on top of, not instead of, RBI's existing outsourcing and data-security guidelines.

Banks must map exactly which layer holds which risk. Identity-layer risk centres on authentication failure and impersonation. Payments-layer risk centres on settlement and fraud. Data-layer risk centres on consent misuse or data leakage by a downstream party.

Newer tools are entering this governance picture too. Banks increasingly use analytics and automated monitoring across these layers, a theme covered in depth in generative AI in banking, including its own governance risks.

📌 Remember: Digital Banking Units already operate as physical touchpoints built on this same layered stack. Treat that as a delivery channel, not a fourth architectural layer.

Board-level oversight, API security audits and periodic consent-log reviews are now standard expectations for any bank using these layers at scale. Examiners expect candidates to connect the layer to its specific control, not to describe controls in general terms.

🎯 Conclusion: Study the Layers, Not Just the Products

India Stack and digital public infrastructure reward candidates who think in layers. Identity, payments and data each have their own building blocks, their own risks and their own governing rules. Map every product you study back to one of these three layers.

Browse more explainers on the digital banking tag hub, and revise the full CAIIB elective syllabus on the CAIIB course page. Ready to test yourself? Attempt the practice set below, then move to full-length mocks.

🧠 Practice MCQs: India Stack and Digital Public Infrastructure

Q1. Which three layers make up the India Stack architecture? (a) Identity, Payments, Data (b) Core Banking, Payments, Lending (c) KYC, AML, Fraud (d) Aadhaar, UPI, RuPay only

Answer: (a) — The three layers are identity (Aadhaar eKYC/e-Sign), payments (UPI and related rails) and data (consent-based sharing via DEPA).

Q2. What legal framework gives Aadhaar-based e-Sign its validity as a signature? (a) Information Technology Act, 2000 (b) Banking Regulation Act, 1949 (c) Companies Act, 2013 (d) Negotiable Instruments Act, 1881

Answer: (a) — e-Sign is an electronic signature service recognised under the Information Technology Act, 2000.

Q3. In the DEPA consent architecture, which entity sits between a bank and a customer's data source? (a) Consent Manager / Account Aggregator (b) Payment Aggregator (c) Credit Information Company (d) Business Correspondent

Answer: (a) — A Consent Manager, operating as an Account Aggregator, moves data only against a specific, revocable consent artefact.

Q4. What is the primary function of DigiLocker in this architecture? (a) Storing and sharing verified documents with consent (b) Processing UPI payment settlements (c) Issuing Aadhaar numbers (d) Recording credit bureau scores

Answer: (a) — DigiLocker stores government-issued documents and shares verified copies with banks for onboarding, with the customer's consent.

Q5. Which layer of India Stack does UPI primarily belong to? (a) Payments layer (b) Identity layer (c) Data layer (d) Governance layer

Answer: (a) — UPI belongs to the payments layer, distinct from the identity layer and the data layer.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

What does the term India Stack mean in digital banking?

It refers to a set of open, interoperable APIs across identity, payments and data layers that banks and other players use to build digital financial services.

How is DEPA different from the Account Aggregator framework?

DEPA is the underlying consent architecture and set of design principles. The Account Aggregator framework is its live, regulated implementation for financial data sharing in India.

Is Aadhaar eKYC mandatory for opening a bank account?

No. Banks must offer alternate onboarding paths such as physical KYC or Video KYC alongside Aadhaar-based eKYC, since Aadhaar authentication remains voluntary.

Which law governs how banks handle personal data collected through these layers?

The Digital Personal Data Protection Act, 2023 sets consent, purpose-limitation and data fiduciary obligations, applied on top of RBI's data and outsourcing guidelines. See the RBI website for current circulars.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

Digital Banking · 5 questions · instant result
Q1. A merchant acquirer pays its large merchants on Day 1, certain banked merchants on Day 2, and the remaining merchants on Day 3, even before the card scheme operator has fully settled funds to it. Which set of source facts together best explains this practice?
Q2. A small merchant with a turnover of Rs 15 lakh in the previous financial year processes a Rs 50,000 debit-card sale on a physical POS. Under the RBI MDR mandate effective 01.01.2018, what is the applicable MDR ceiling?
Q3. An m-POS solution is being marketed to small retailers. Which statement MOST accurately captures its defining advantage over a traditional merchant POS terminal as described in the chapter?
Q4. Assertion (A): A merchant must verify the cardholder's signature against the one on the card for all signature-based cards. Reason (R): Signature verification is also mandatory for chip-and-PIN cards before completing the transaction.
Q5. Consider the following statements about PSTN and GPRS POS terminals: 1. A PSTN POS terminal needs telephone lines to interact with the Data Centre. 2. A GPRS POS terminal uses a SIM card and can be moved anywhere as it has a built-in battery. Which of the statements is/are correct?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading