Open Banking in India: IIBF Digital Banking Exam Guide

DIGIBANK By Ashish Jain · IIBF STORE Editorial · 27 August 2026 · Updated 09 Oct 2026 · 11 min read · 44 views
Open Banking in India: IIBF Digital Banking Exam Guide

Open banking in India is a consent-led model in which a customer, not the bank, decides who may see their financial data and for how long. It is built on regulated rails — the RBI-licensed Account Aggregator for data, a common credit-API layer for lending, and the bank's own published APIs for products and servicing.

For IIBF candidates, the paper rarely asks "what is an API". It asks who is accountable when a partner mis-sells, which entity may store data, and what a consent artefact must contain. This guide covers the framework the way the examiner tests it.

🏦 What Open Banking in India Actually Means

Open banking is not a single product or a single regulation. It is an architecture in which a regulated entity exposes data and functionality through secure, standardised interfaces so that a third party can build a service on top of it — always with the customer's permission and always with the bank remaining answerable to the regulator.

Three layers matter. The data layer lets a customer share statements, holdings and repayment history. The transaction layer lets a partner initiate payments or mandates. The product layer lets a partner originate a deposit, a card or a loan that ultimately sits on a licensed balance sheet.

India took a deliberately different route from the United Kingdom or the European Union. There is no single "open banking mandate" forcing every bank to publish a fixed API list. Instead the country built public digital infrastructure — identity, payments and consent — and let market participants plug into it. That is why the exam framing is always regulatory rather than technical.

The practical consequence for a branch banker is simple. A partner application may sit in front of the customer, but the deposit, the loan and the grievance all belong to the bank. Every syllabus treatment of developments in digital technology and business returns to that single point of accountability, and so do most case-style questions.

💡 Exam Tip: When a question names a fintech, a platform or an app, first ask "who holds the licence?" The regulated entity is almost always the correct answer for accountability, grievance redress and data protection.

🔐 The Consent Layer: Account Aggregators and DEPA

The data spine of open banking in India is the Account Aggregator (AA), an NBFC licensed by the Reserve Bank under its 2016 Non-Banking Financial Company – Account Aggregator Directions. The AA is deliberately data-blind: it moves encrypted data from a provider to a user and can neither read nor store the contents.

Three roles must be memorised. A Financial Information Provider (FIP) holds the data — a bank, an NBFC, an insurer, a depository or a pension repository. A Financial Information User (FIU) consumes it for a stated purpose, typically underwriting or advice. The AA sits between them and manages nothing but consent.

That consent is not a tick-box. Under the Data Empowerment and Protection Architecture (DEPA), it is a machine-readable consent artefact that records the identity of the requester, the purpose, the exact data types, the frequency and validity period, and the customer's right to revoke at any moment. Purpose limitation is the examinable idea: data pulled for a loan assessment may not be recycled for cross-selling.

The Digital Personal Data Protection Act, 2023 reinforces the same direction of travel — notice, purpose limitation, and the right to withdraw. Candidates should be able to distinguish the RBI's sectoral consent architecture from the general data-protection statute rather than treat them as one rule.

Revocation is the trap. Once consent is withdrawn, further pulls must stop, but data already lawfully received and used in a sanctioned credit decision does not disappear from the lender's records. Say that precisely in a descriptive answer.

Key Concepts — Digital Banking
Key Concepts — Digital Banking

🔌 Credit Rails, Payment Rails and the Bank's Own APIs

Above the consent layer sits the credit-API layer, usually discussed under the open credit stack. Its purpose is to let a small borrower — a kirana shop, a gig worker, a farmer — receive a small, short-tenor loan through a platform they already use, while the underwriting and the balance sheet stay with a licensed lender. The APIs standardise the loan request, the offer, the disbursal instruction and the collection schedule.

The payment rails are the part every banker already touches daily. Instant retail transfers, mandates and collect requests are all API-driven, and the chapter on developments in payment systems in India is the standard reference for how these systems interlock with settlement. Where a question involves a policy rate or a charge that changes periodically, check the current position on the RBI rates and limits page rather than trusting a printed figure.

The third rail is the bank's own API estate — balance enquiry, account opening, card controls, standing instructions — exposed to partners under contract. This is where banking-as-a-service arrangements live, and where supervisory attention is heaviest, because a thin partner interface can hide a very large book.

Security is not a footnote here. Token-based authentication, mutual TLS, rate limiting and disciplined certificate handling decide whether an open API is an asset or an incident. The IT-security treatment of cryptographic key management in banks is the natural companion reading, because open banking multiplies the number of keys, tokens and endpoints a bank must control.

📊 Comparing the Building Blocks Side by Side

Examiners like a matching question: given a description, name the layer. The table below separates the three core blocks by what actually moves across them, who carries the licence, and whether a formal, revocable consent artefact is required before anything can flow.

Building blockWhat movesWho is accountableConsent artefact needed?
Account Aggregator (data layer)Statements, holdings, repayment historyNBFC-AA licensed by RBI; FIP and FIU regulated by their own regulators✅ Yes — purpose, duration and data types specified
Open credit APIs (lending layer)Loan request, offer, disbursal and repayment instructionsThe lender is the regulated entity; the platform acts as its agent✅ Yes — borrower consent plus a Key Fact Statement
Payment APIs (transaction layer)Payment and mandate instructionsBanks and payment system participants under the settlement framework❌ No — authorisation of a transaction, not a data-sharing consent

Read the last column carefully. A payment instruction authorises one movement of money; a consent artefact authorises a stream of information. Candidates who blur the two lose marks on exactly the questions that look easiest.

The same distinction explains why a lender may not treat an aggregator pull as a marketing list, and why the design of marketing of digital banking products has to respect purpose limitation from the first screen onwards.

Pair the table with the wider syllabus. The class notes on developments in digital technology supply the vocabulary, the currency-side reading on wholesale CBDC in India shows how the same consent-and-accountability logic extends to settlement innovation, and further explainers for this paper sit under the digital banking tag hub.

Process & Framework — Digital Banking
Process & Framework — Digital Banking

⚖️ Regulation, Risk and the Bank's Non-Delegable Duties

Open banking widens the perimeter, so supervisory expectations tighten around four themes: accountability, disclosure, data handling and grievance redress. Every one of them appears in past papers as a short note or a case question.

Accountability. Outsourcing an activity never outsources the responsibility. If a partner application originates a loan, the regulated entity owns the conduct, the recovery practice and the customer complaint.

Disclosure. The borrower must know who the actual lender is before agreeing to anything, and must receive a standardised statement of cost, tenor, penalties and cooling-off terms. The requirements set out in the RBI digital lending guidelines are the reference point, including the principle that loan flows move directly between the borrower and the regulated entity without resting in a partner's pool account.

Data handling. Partner applications should collect only what the service needs, store data in India as required, and avoid harvesting contacts, media or location without a defensible purpose.

Grievance redress. A digitally originated complaint follows the same escalation path as a branch complaint, and an unresolved case can travel to the RBI Ombudsman. Since 1 July 2026 the RB-IOS 2026 scheme applies, with a ninety-day filing window from the bank's reply, an award ceiling of Rs 30 lakh and up to Rs 3 lakh for consequential loss.

For primary text on any of these, go to the source rather than a summary — master directions and circulars are published on the Reserve Bank of India website, and the wording there is what the examiner paraphrases.

⚠️ Common Mistake: Writing that the Account Aggregator "stores" customer data. It does not. It transports encrypted data on consent and is barred from reading or retaining the payload — a one-word error that costs the whole mark.
In Practice — Digital Banking
In Practice — Digital Banking

🧠 Practice MCQs: Open Banking in India

Q1. What best describes the role of an NBFC-Account Aggregator? (a) It underwrites loans using the data it receives (b) It stores customer financial data for a statutory retention period (c) It transfers data only on explicit, revocable consent and can neither read nor store it (d) It licenses digital lending apps on behalf of the regulator

Answer: (c) — the AA is a data-blind consent manager; it moves encrypted data and never reads or retains the payload.

Q2. In the Account Aggregator ecosystem, which entity supplies the customer's financial information? (a) Financial Information Provider (b) Financial Information User (c) Technology service provider (d) The aggregator itself

Answer: (a) — the FIP, such as a bank, insurer or depository, holds and supplies the data; the FIU consumes it for a stated purpose.

Q3. A consent artefact under the data-sharing framework must specify all of the following except: (a) the purpose of the request (b) the data types and frequency of access (c) the validity period and revocation right (d) the interest rate the lender will finally charge

Answer: (d) — pricing is disclosed separately in the loan documentation; the consent artefact governs data, not commercial terms.

Q4. Under the digital lending framework, disbursal and repayment must flow: (a) through the partner platform's pool account (b) directly between the borrower's account and the regulated entity, without a pass-through account (c) through any escrow the platform selects (d) through the account aggregator

Answer: (b) — loan flows move directly between borrower and regulated entity; a lending service provider may not hold the funds in transit.

Q5. Which statement about open banking accountability is correct? (a) Once an activity is outsourced, the partner answers to the regulator (b) A digitally originated complaint follows a separate redress path (c) The regulated entity remains accountable for conduct, data and grievance redress (d) Consent given through an aggregator is irrevocable for the loan tenor

Answer: (c) — outsourcing shifts the work, never the responsibility; consent stays revocable and redress follows the normal escalation path.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Is open banking in India mandatory for every bank?

No. India has no single mandate forcing a fixed API list on every bank. Participation is driven by regulated infrastructure such as the Account Aggregator framework and by commercial partnerships, with the RBI supervising conduct, outsourcing and data handling.

Can an Account Aggregator see or sell my financial data?

No. The aggregator is data-blind by design. It transports encrypted information from the provider to the user strictly under the consent you granted, and it is barred from reading, storing or monetising the contents.

What happens if I withdraw consent midway through a loan application?

Further data pulls stop immediately. Information already lawfully received and used in a credit decision remains on the lender's record for audit and regulatory purposes, but it cannot be refreshed or reused for a new purpose.

Who handles my complaint if a partner app mis-sells a product?

The regulated entity behind the product. Raise it with the bank or NBFC first; if it is not resolved within the prescribed period or the reply is unsatisfactory, escalate to the RBI Ombudsman under the RB-IOS 2026 scheme within ninety days.

🎯 Key Takeaway Before Your Exam

Open banking rewards candidates who think in terms of licence, consent and accountability rather than technology. Learn the three roles, the contents of a consent artefact and the non-delegable duties of the regulated entity, and most questions on this topic answer themselves.

Carry four phrases into the hall — data-blind aggregator, purpose-limited consent, non-delegable accountability, direct borrower flows — and structure every descriptive answer as entity, consent basis, accountable party, redress route.

Test the recall while it is fresh: attempt a free chapter-wise mock test and check whether you can name the accountable party in every scenario without hesitating.

Prefer revising from a printed book?

Chapter-wise books with MCQs after every chapter — minimal pages, complete coverage, delivered anywhere in India. Every book has a free sample to read first.

All books →
DIGIBANK 2026 Edition
Digital Banking

90 pages · 150 MCQs

Learning Sessions · Ashish Sir

Digital Banking 10 chapters · 150 MCQs ₹1,199₹2,39850% off
MSME 2026 Edition
Micro, Small and Medium Enterprises (MSME)

132 pages · 225 MCQs

Learning Sessions · Ashish Sir

Micro, Small and Medium Enterprises (MSME) 15 chapters · 225 MCQs ₹1,199₹2,39850% off
CCP 2026 Edition
Certified Credit Professional (CCP)

188 pages · 435 MCQs

Learning Sessions · Ashish Sir

Certified Credit Professional (CCP) 29 chapters · 435 MCQs ₹1,199₹2,39850% off
KYCAML 2026 Edition
KYC, AML and CFT

117 pages · 236 MCQs

Learning Sessions · Ashish Sir

KYC, AML and CFT 16 chapters · 236 MCQs ₹1,199₹2,39850% off
TIRM 2026 Edition
Treasury, Investment and Risk Management (TIRM)

Learning Sessions · Ashish Sir

Treasury, Investment and Risk Management (TIRM) ₹1,199₹2,39850% off
ITSEC 2026 Edition
IT Security

118 pages · 299 MCQs

Learning Sessions · Ashish Sir

IT Security 20 chapters · 299 MCQs ₹1,199₹2,39850% off
RFS 2026 Edition
Risk in Financial Services

Learning Sessions · Ashish Sir

Risk in Financial Services ₹1,199₹2,39850% off
SFB 2026 Edition
Small Finance Banks

Learning Sessions · Ashish Sir

Small Finance Banks ₹1,199₹2,39850% off
TREASURY 2026 Edition
Treasury Management

Learning Sessions · Ashish Sir

Treasury Management ₹1,199₹2,39850% off
NBFC 2026 Edition
Non-Banking Financial Companies (NBFC)

115 pages · 255 MCQs

Learning Sessions · Ashish Sir

Non-Banking Financial Companies (NBFC) 17 chapters · 255 MCQs ₹1,199₹2,39850% off
ITF 2026 Edition
International Trade Finance

Learning Sessions · Ashish Sir

International Trade Finance ₹1,199₹2,39850% off
CAAP 2026 Edition
Certified Accounting and Audit Professional (CAAP)

334 pages · 936 MCQs

Learning Sessions · Ashish Sir

Certified Accounting and Audit Professional (CAAP) 63 chapters · 936 MCQs ₹1,199₹2,39850% off
RM 2026 Edition
Risk Management

Learning Sessions · Ashish Sir

Risk Management ₹1,199₹2,39850% off
FEFI 2026 Edition
Foreign Exchange Facilities for Individuals (FEFI)

115 pages · 344 MCQs

Learning Sessions · Ashish Sir

Foreign Exchange Facilities for Individuals (FEFI) 24 chapters · 344 MCQs ₹1,199₹2,39850% off
IIBF 2026 Edition
Debt Recovery Agents (DRA)

107 pages · 240 MCQs

Learning Sessions · Ashish Sir

Debt Recovery Agents (DRA) 16 chapters · 240 MCQs ₹1,199₹2,39850% off
BCP 2026 Edition
Banking Compliance Professional

Learning Sessions · Ashish Sir

Banking Compliance Professional ₹1,199₹2,39850% off
Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

Digital Banking · 5 questions · instant result
Q1. A merchant who has not settled the day's POS transactions complains that the day's card sales have not reached the merchant's account. Which statement correctly explains the situation?
Q2. A bank wants to deploy POS terminals to field agents conducting Financial Inclusion enrolment in remote villages that lack any live telecom link during the day, requiring transactions to be stored and uploaded later in a batch. Which POS type is designed for this?
Q3. Arrange the following stages of the POS dispute settlement and arbitration procedure in the correct sequence: 1. Arbitration by the card network's Arbitration Committee 2. Retrieval request 3. Pre-arbitration at the card network end 4. Charge back with reason codes
Q4. A card scheme charges a flat per-transaction fee to recover the cost of authorizing a transaction over its network, and this fee applies even when an authorization is declined for business reasons. Which scheme price point is this?
Q5. A merchant adds a 2% surcharge on card payments and refuses a validly presented credit card from a rival scheme. Judging by the "Dos and Don'ts" for merchants, which assessment is correct?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading