India Stack and Digital Public Infrastructure: Layers and Banking Use (Digital Banking)
India Stack and digital public infrastructure form the backbone of modern Indian banking. Every JAIIB and CAIIB candidate must understand how these building blocks fit together. India Stack is not one single application. It is a layered set of open APIs spanning identity, payments and data. Each layer solves one specific problem for banks and customers. This article maps how a bank actually plugs into each layer. We keep the focus on architecture, not on any one product. UPI, the account aggregator framework and CBDC each already have dedicated articles on this site. Here we look at the full stack together, layer by layer, the way exam questions usually frame it.
🏗️ What Is India Stack and Digital Public Infrastructure
Digital public infrastructure means population-scale, interoperable systems built on open APIs. Government bodies and private players both build on top of them. Instead of one closed system, you get shared rails that any licensed bank can use. India Stack is the umbrella name for this approach in India.
Three layers sit inside India Stack. The identity layer proves who a customer is, using Aadhaar-based eKYC and e-Sign. The payments layer moves money, mainly through UPI and related rails. The data layer moves information, under explicit customer consent, through the DEPA architecture.
Each layer is designed to work without the others. A bank can use only the identity layer for onboarding. It can use only the data layer for a loan appraisal. This separation is exactly what makes the design flexible for banks of every size.
For a broader view of everyday retail operations, see this Overview of Digital Banking chapter. Then return here for the layer-by-layer detail.
| Layer | Core Building Blocks | Where a Bank Plugs In | Consent-Based? |
|---|---|---|---|
| Identity | Aadhaar eKYC, e-Sign, Video KYC | Customer onboarding and re-KYC APIs | ❌ No |
| Payments | UPI, RuPay, IMPS, NPCI switch | Payment initiation, acquiring and issuing | ❌ No |
| Data | DEPA, Account Aggregator, DigiLocker | Consent-based data-sharing APIs | ✅ Yes |

🆔 The Identity Layer: Aadhaar eKYC and e-Sign
Aadhaar eKYC lets a bank verify a customer's identity electronically. The customer authenticates using an OTP or a biometric match through UIDAI's systems. The bank receives a verified demographic record within seconds, instead of manual document checks.
e-Sign works alongside eKYC. It lets a customer digitally sign an account-opening form or a loan agreement using Aadhaar-based authentication. This signature carries legal validity because it is recognised as an electronic signature service.
Banks are not allowed to make Aadhaar-based authentication the only onboarding path. Video KYC and physical KYC remain valid alternatives. This matters for financial inclusion, since not every customer has an Aadhaar-linked mobile number handy.
💡 Exam Tip: Aadhaar eKYC and e-Sign sit in the identity layer, not the data layer. Do not confuse this with DEPA-based consent sharing, which is a separate layer entirely.
The identity layer also feeds directly into Financial Inclusion efforts, since faster onboarding brings more first-time customers into formal banking. It also underpins app-based onboarding covered in the Mobile Banking chapter.

💳 The Payments Layer: How Banks Plug In
The payments layer is the most visible part of India Stack for ordinary customers. UPI sits at its centre, connecting bank accounts through the NPCI switch for near-instant transfers. Banks connect either as issuing banks, acquiring banks, or through a payment service provider app.
RuPay and IMPS run alongside UPI as older or parallel rails inside the same layer. A bank's core banking system talks to these rails through standard APIs, not through separate closed networks for each product.
CBDC, the e-Rupee, is emerging as an additional instrument inside this same payments layer. Since it already has a dedicated article on this site, we mention it here only as context, not as a deep dive. The same applies to CBDC e-Rupee digital currency and to UPI Lite and offline payments, both of which sit inside this layer.
Physical acceptance points such as POS terminals and ATMs also connect into the payments layer at the last mile, turning a digital rail into a cash-in or cash-out point for the customer.

🔐 The Data Layer: DEPA Consent Architecture and DigiLocker
DEPA stands for Data Empowerment and Protection Architecture. It is the design principle behind consent-based data sharing in India. A neutral Consent Manager sits between a data-sending institution and a data-receiving institution.
Every data flow needs a consent artefact. This artefact records the purpose, the specific data items, and the duration for which access is granted. Nothing moves without this explicit, revocable consent record.
⚠️ Common Mistake: Candidates often treat DEPA and the Account Aggregator ecosystem as two different things. DEPA is the architecture; the Account Aggregator framework is its working, regulated implementation for financial data.
DigiLocker is a related but distinct utility. It stores government-issued documents such as PAN cards, driving licences and marksheets. A bank can pull a verified copy of a document from DigiLocker with the customer's consent, cutting down paper submissions during onboarding or loan processing. For the full mechanics of consent-based sharing, read the account aggregator framework in India article.
🏦 Governance, Privacy and Risk Questions for Banks
Layered infrastructure raises layered governance questions. The Digital Personal Data Protection Act, 2023 sets out consent, purpose-limitation and data fiduciary duties. These duties apply on top of, not instead of, RBI's existing outsourcing and data-security guidelines.
Banks must map exactly which layer holds which risk. Identity-layer risk centres on authentication failure and impersonation. Payments-layer risk centres on settlement and fraud. Data-layer risk centres on consent misuse or data leakage by a downstream party.
Newer tools are entering this governance picture too. Banks increasingly use analytics and automated monitoring across these layers, a theme covered in depth in generative AI in banking, including its own governance risks.
📌 Remember: Digital Banking Units already operate as physical touchpoints built on this same layered stack. Treat that as a delivery channel, not a fourth architectural layer.
Board-level oversight, API security audits and periodic consent-log reviews are now standard expectations for any bank using these layers at scale. Examiners expect candidates to connect the layer to its specific control, not to describe controls in general terms.
🎯 Conclusion: Study the Layers, Not Just the Products
India Stack and digital public infrastructure reward candidates who think in layers. Identity, payments and data each have their own building blocks, their own risks and their own governing rules. Map every product you study back to one of these three layers.
Browse more explainers on the digital banking tag hub, and revise the full CAIIB elective syllabus on the CAIIB course page. Ready to test yourself? Attempt the practice set below, then move to full-length mocks.
🧠 Practice MCQs: India Stack and Digital Public Infrastructure
Q1. Which three layers make up the India Stack architecture? (a) Identity, Payments, Data (b) Core Banking, Payments, Lending (c) KYC, AML, Fraud (d) Aadhaar, UPI, RuPay only
Answer: (a) — The three layers are identity (Aadhaar eKYC/e-Sign), payments (UPI and related rails) and data (consent-based sharing via DEPA).
Q2. What legal framework gives Aadhaar-based e-Sign its validity as a signature? (a) Information Technology Act, 2000 (b) Banking Regulation Act, 1949 (c) Companies Act, 2013 (d) Negotiable Instruments Act, 1881
Answer: (a) — e-Sign is an electronic signature service recognised under the Information Technology Act, 2000.
Q3. In the DEPA consent architecture, which entity sits between a bank and a customer's data source? (a) Consent Manager / Account Aggregator (b) Payment Aggregator (c) Credit Information Company (d) Business Correspondent
Answer: (a) — A Consent Manager, operating as an Account Aggregator, moves data only against a specific, revocable consent artefact.
Q4. What is the primary function of DigiLocker in this architecture? (a) Storing and sharing verified documents with consent (b) Processing UPI payment settlements (c) Issuing Aadhaar numbers (d) Recording credit bureau scores
Answer: (a) — DigiLocker stores government-issued documents and shares verified copies with banks for onboarding, with the customer's consent.
Q5. Which layer of India Stack does UPI primarily belong to? (a) Payments layer (b) Identity layer (c) Data layer (d) Governance layer
Answer: (a) — UPI belongs to the payments layer, distinct from the identity layer and the data layer.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
What does the term India Stack mean in digital banking?
It refers to a set of open, interoperable APIs across identity, payments and data layers that banks and other players use to build digital financial services.
How is DEPA different from the Account Aggregator framework?
DEPA is the underlying consent architecture and set of design principles. The Account Aggregator framework is its live, regulated implementation for financial data sharing in India.
Is Aadhaar eKYC mandatory for opening a bank account?
No. Banks must offer alternate onboarding paths such as physical KYC or Video KYC alongside Aadhaar-based eKYC, since Aadhaar authentication remains voluntary.
Which law governs how banks handle personal data collected through these layers?
The Digital Personal Data Protection Act, 2023 sets consent, purpose-limitation and data fiduciary obligations, applied on top of RBI's data and outsourcing guidelines. See the RBI website for current circulars.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading