NBFC Account Aggregator Framework: What You Must Know

NBFC By Ashish Jain · IIBF STORE Editorial · 21 August 2026 · Updated 03 Oct 2026 · 9 min read · 37 views
NBFC Account Aggregator Framework: What You Must Know

When most bankers think of a Non-Banking Financial Company, they picture an asset financier or a microfinance lender. But the NBFC Account Aggregator framework created a very different animal — an NBFC that never lends money, never accepts a deposit, and by regulatory design is not even allowed to look at the financial data it moves between institutions. For JAIIB and CAIIB candidates, NBFC-AA questions now come up regularly because the Account Aggregator ecosystem quietly sits behind loan underwriting, wealth advisory and insurance distribution across the industry. This article sets out what an NBFC-AA actually does, how its consent architecture works, and the exact regulatory boundaries examiners expect you to know.

🏦 What Is an NBFC Account Aggregator?

An NBFC-Account Aggregator (NBFC-AA) is a category of Non-Banking Financial Company registered with the Reserve Bank of India whose sole permitted business is to enable the consent-based flow of a customer's financial information between two regulated entities. It does not extend credit, does not invest, and does not accept public deposits — its business is purely technological and consent-management in nature.

This makes NBFC-AA registration structurally different from the lending-focused NBFC categories covered under the broader study of types and roles of NBFCs. A candidate who only revises asset finance companies, ICCs and MFIs will miss this entire non-lending category, which the RBI created specifically to formalise India's open finance data-sharing layer.

Every institution in the ecosystem plays one of three roles: the Financial Information Provider (FIP) — a bank, mutual fund, insurer, pension fund or NBFC that holds the customer's data; the Financial Information User (FIU) — typically a lender or wealth platform that wants to use that data, with the customer's consent, to make a decision; and the Account Aggregator itself, which sits in the middle purely as a consent-driven pipe.

🔐 The Consent Architecture: FIP, FIU and the Consent Artifact

Nothing moves in the AA ecosystem without a Consent Artifact — a digital, machine-readable record that specifies exactly what data is being requested, by whom, for what purpose, for how long, and with what expiry. The customer approves this artifact on the AA's app or web interface before a single byte of financial data is released by the FIP to the FIU.

The consent artifact must carry defined parameters: the identity of the requesting FIU, the specific FIP(s) involved, the data categories (bank statements, mutual fund holdings, insurance policies, tax data, and so on), the purpose code, the frequency of access, and the validity period. A customer can revoke consent at any time, and once revoked, the FIU's access to fresh data stops immediately.

This is one of the outcomes of the RBI's broader digital-finance push, part of the same wave of reforms you will see referenced under recent RBI initiatives in your NBFC syllabus. The same regulatory instinct — standardised, auditable consent — also shapes the corporate governance norms for NBFCs that apply to every regulated entity handling customer data at scale, AA included.

💡 Exam Tip: Remember the three roles as a straight line — FIP holds the data, AA moves the data, FIU uses the data. The AA never appears at either end of that line.
How data flows between the FIP, the Account Aggregator and the FIU
How data flows between the FIP, the Account Aggregator and the FIU

🚫 Data Blindness: Why the AA Never Sees Your Data

The single most tested concept in this topic is data blindness. An NBFC-AA is technically and legally barred from storing, parsing, or using the financial information that passes through it. The data travels encrypted from the FIP to the FIU, and the AA's role is limited to authenticating the consent and routing the transfer — it cannot retain a readable copy, monetise it, or use it for any purpose of its own, including its own credit models.

This design choice is what separates the AA model from a typical data broker or a credit bureau. A candidate should also connect this back to the general customer-data handling standards taught under KYC and AML/CFT norms, since AAs must still identify and verify their customers even though they never touch the substance of the financial records being shared.

Because the AA cannot see the data, it also cannot be held liable for its accuracy — that responsibility sits with the FIP that generated it. Exam questions frequently test this liability split, so keep the roles distinct: FIP is accountable for data accuracy, FIU is accountable for how it uses the data, and the AA is accountable only for consent integrity and secure transmission.

⚠️ Common Mistake: Do not confuse an Account Aggregator with a credit information company. A credit bureau stores and scores data; an AA is contractually and technically barred from doing either.
Key parameters captured inside a consent artifact
Key parameters captured inside a consent artifact

📋 Registration, Net Owned Fund and Permitted Scope

An NBFC-AA is registered under Section 45-IA of the RBI Act, 1934, like other NBFC categories, but its minimum Net Owned Fund requirement is set lower than a typical lending NBFC — reflecting that it carries no credit or market risk on its own books. Because it neither lends nor invests, its capital requirement is calibrated to operational and technology risk rather than balance-sheet risk.

An AA cannot diversify into any other financial activity — lending, investment, or deposit-taking — without the prior written approval of the RBI. This is a stricter version of the same principle that governs the principal business criteria for NBFCs: an AA's principal business is not just dominant, it is effectively its only permitted business.

The framework is technically overseen by the RBI, but the day-to-day interoperability standards — API specifications, consent artifact formats, and onboarding protocols — are maintained by Sahamati, a voluntary, not-for-profit industry alliance. Sahamati is not a regulator; it does not issue licences or enforce compliance. That authority rests solely with the RBI.

NBFC-AA compared with other NBFC categories by function
NBFC-AA compared with other NBFC categories by function

🌐 NBFC-AA in Practice: Lending, Wealth and Insurance Use Cases

In lending, banks and NBFCs use AA-routed bank statements and GST data to underwrite cash-flow-based loans for thin-file borrowers far faster than manual document collection allows. In wealth management, AAs pull consolidated mutual fund and pension data for advisory dashboards. Insurers use the same rails to verify existing coverage before underwriting a new policy.

It helps to think of the AA's role the way a trade finance officer thinks about a shipment's protection: just as marine cargo insurance covers a specific risk in a transaction without becoming a party to the underlying trade contract, an AA covers the data-movement risk in a financial transaction without becoming a party to the loan or investment decision itself.

The AA model is a purely domestic-consent framework and should not be confused with lending-side NBFC categories you may already have revised, such as the peer-matching structure under p2p lending platform norms, where the NBFC-P2P actually facilitates the loan itself rather than just the data behind it.

📌 Remember: AA = consent and data movement only. It never appears on either side of a loan, investment or deposit transaction.
FeatureNBFC-AANBFC-P2PNBFC-ICC
Core functionConsent-based data transferPeer-to-peer loan matchingDirect lending / investment
Can extend credit❌ No✅ Yes (matches lenders)✅ Yes
Stores/uses customer financial dataNo (data blind)Loan-specific data onlyYes
Regulatory anchorSection 45-IA + AA Master DirectionSection 45-IA + P2P Master DirectionSection 45-IA, Scale Based Regulation

For the full regulatory text on registration, permitted activities and Net Owned Fund norms, refer to the RBI Master Directions on NBFCs, and revisit the wider NBFC regulations archive on this site to connect this topic with the rest of the NBFC syllabus.

🧠 Practice MCQs: NBFC Account Aggregator Framework

Q1. What is the minimum Net Owned Fund required for an NBFC-Account Aggregator to be registered with the RBI? (a) Rs 2 crore (b) Rs 10 crore (c) Rs 25 crore (d) Rs 5 crore

Answer: (a) — The NOF requirement for an NBFC-AA is set lower than typical lending NBFCs since it carries no credit or market risk on its own books.

Q2. In the Account Aggregator framework, which entity requests a customer's financial data after obtaining valid consent? (a) Financial Information Provider (b) Financial Information User (c) Consent Manager (d) Credit Information Company

Answer: (b) — The Financial Information User (FIU) requests the data; the Financial Information Provider (FIP) holds it, and the AA only routes it.

Q3. Which statement best describes "data blindness" in the NBFC-AA model? (a) The AA cannot see or store the financial data it transmits (b) The AA is exempt from RBI registration (c) The AA is exempt from KYC requirements (d) The AA cannot operate a mobile app

Answer: (a) — The AA is technically and legally barred from storing, reading, or using the underlying financial data it moves.

Q4. Under which section of the RBI Act, 1934 is an NBFC-Account Aggregator registered? (a) Section 45-IA (b) Section 45-IC (c) Section 8 (d) Section 138

Answer: (a) — Like all NBFC categories, an NBFC-AA obtains its certificate of registration under Section 45-IA of the RBI Act, 1934.

Q5. Can an NBFC-AA take up lending or investment activity in addition to its data-aggregation business? (a) Yes, freely (b) No, not without the prior written approval of the RBI (c) Yes, up to 10% of its Net Owned Fund (d) Only after five years of operation

Answer: (b) — An NBFC-AA's principal business is effectively its only permitted business; diversification requires prior written RBI approval.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

What does NBFC-AA stand for?

NBFC-Account Aggregator — a category of Non-Banking Financial Company registered by the RBI solely to enable consent-based sharing of a customer's financial information between regulated entities.

Does an NBFC-AA charge the customer for sharing data?

The AA's commercial arrangement is typically with the Financial Information User or Provider rather than the customer directly, though this can vary by app; the customer's consent is always required regardless of the fee structure.

Is Sahamati an RBI-regulated body?

No. Sahamati is a voluntary, not-for-profit industry alliance that maintains technical specifications for the Account Aggregator ecosystem. Licensing and regulatory oversight of every NBFC-AA rests solely with the RBI.

Can a bank operate as an Account Aggregator?

A bank cannot function as an Account Aggregator under its banking licence. Only a company separately registered with the RBI as an NBFC-AA may carry on the Account Aggregator business.

The NBFC-Account Aggregator framework is a small but increasingly exam-relevant corner of the NBFC syllabus, and it rewards candidates who keep the FIP-FIU-AA roles and the data-blindness principle crystal clear. Test yourself on this and the rest of the NBFC module with IIBF CAIIB practice tests before exam day.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading