Payment Aggregators and Gateways: RBI Rules Explained (2026)

DIGIBANK By Ashish Jain · IIBF STORE Editorial · 26 July 2026 · Updated 07 Sep 2026 · 9 min read · 40 views
Payment Aggregators and Gateways: RBI Rules Explained (2026)

Every UPI payment, e-commerce checkout, and utility bill payment in India routes through Payment Aggregators and Gateways working quietly behind the scenes — and for JAIIB and CAIIB Digital Banking candidates, RBI's regulatory framework for these entities has become a recurring exam theme. This article breaks down what payment aggregators and gateways actually do, how RBI's PA-PG guidelines classify, license and supervise them, and the net-worth, escrow and settlement rules every banker preparing for IIBF exams needs to know cold.

💳 What Are Payment Aggregators and Payment Gateways?

A Payment Aggregator (PA) is an intermediary that lets an online merchant accept multiple payment instruments — cards, UPI, net banking, wallets — without the merchant having to build a separate integration with every bank or card network. Critically, a PA receives payments from customers, pools them, and settles the net amount to merchants after a specified period, which means it actually holds and moves money. A Payment Gateway (PG), by contrast, is a pure technology layer: it transmits transaction data securely between the merchant's website, the acquiring bank and the card network, but it never touches or holds funds itself. This single distinction — custody of money versus mere data routing — is exactly why RBI regulates PAs directly while PGs, when they perform no fund-handling role, generally sit outside that direct oversight. In practice, most large Indian fintech players such as Razorpay, Cashfree, PayU and Billdesk operate as combined PA-cum-PG entities, bundling checkout technology with fund settlement in one product. Students should map this concept against the broader payment-systems landscape covered in the Internet / Online Banking chapter, where merchant-facing digital checkout flows are discussed in more detail. Understanding the PA/PG split also helps candidates correctly answer questions that ask "which entity bears settlement risk" — a favourite trap in IIBF digital banking papers, since students often assume the bank alone carries this risk when, structurally, the aggregator is the first point of custody.

📜 RBI's PA-PG Regulatory Framework

RBI first brought non-bank Payment Aggregators under direct, dedicated regulation through its Guidelines on Regulation of Payment Aggregators and Payment Gateways, requiring every non-bank PA to obtain authorisation under the Payment and Settlement Systems Act, 2007 before it can operate. The guidelines mandate board-approved governance policies, baseline technology and cybersecurity standards, PCI-DSS compliance for handling card data, and periodic reporting to the regulator. Existing players already live in the market at the time the guidelines took effect were given a transition window to apply for authorisation, while new entrants must secure approval before commencing operations at all. This licensing model sits alongside — but is distinct from — other RBI oversight regimes candidates study under Developments in Payment Systems in India and Digital Banking, and it should not be confused with lending-focused intermediaries such as non-banking financial companies in India, which are licensed under an entirely separate RBI framework built around credit and asset-liability norms rather than payment settlement. RBI subsequently extended a parallel structure — the Payment Aggregator-Cross Border (PA-CB) framework — to entities facilitating online, small-value export and import related payments, replacing the older OPGSP (Online Payment Gateway Service Provider) arrangement and bringing cross-border collections under the same custody-and-authorisation logic as domestic PAs.

Compliance RequirementPayment Aggregator (PA)Payment Gateway (PG, tech-only)
Holds & settles merchant funds via escrow✅ Yes❌ No — only routes transaction data
Needs RBI authorisation under PSS Act, 2007✅ YesNo, unless separately licensed as a PA
Conducts merchant KYC & risk-based due diligenceYesNo — typically relies on the PA/acquirer
💡 Exam Tip: If a question mentions an entity that "settles funds to merchants" or "maintains an escrow account," it is describing a Payment Aggregator, not a plain Payment Gateway — that single phrase is the fastest way to eliminate wrong options.
Key Concepts — Digital Banking
Key Concepts — Digital Banking

🏦 Net-Worth, Escrow and Settlement Norms

RBI's PA-PG framework prescribes minimum net-worth thresholds that a non-bank Payment Aggregator must meet at the time of application and must scale up to within a defined number of years of receiving authorisation, ensuring aggregators have enough capital cushion to absorb settlement or operational shocks before they can be trusted with large transaction volumes. Alongside capital adequacy, every PA must maintain a dedicated escrow account with a scheduled commercial bank — customer payments collected for merchants must flow into this account and cannot be commingled with the aggregator's own operating funds or used for its working-capital needs. Only specific, clearly defined debits and credits are permitted against the escrow balance: settlement to merchants, refunds to customers, the aggregator's own commission, and applicable taxes such as GST. RBI also caps the permissible settlement cycle, requiring PAs to pay merchants within a specified maximum period rather than holding funds indefinitely, which directly protects small merchants who depend on quick cash flow. These escrow and settlement safeguards mirror the fund-safety logic candidates encounter while studying POS terminals in banking and card-present settlement cycles, reinforcing that RBI applies a consistent principle across digital and physical acceptance infrastructure: whoever holds customer money in transit must ring-fence it and account for every rupee.

⚠️ Common Mistake: Candidates frequently assume the escrow account belongs to the merchant. It does not — the escrow account is opened and controlled by the Payment Aggregator at a scheduled commercial bank, with the merchant only entitled to timely settlement of amounts due, not direct access to the account itself.

🛡️ Merchant Onboarding, KYC and Digital Fraud Controls

Before a Payment Aggregator can plug a merchant into its checkout stack, RBI requires it to complete a background and risk-based due-diligence check on that merchant, verifying the legitimacy of the business, the nature of goods or services sold, and whether the merchant appears on any prohibited-activity or negative list. This merchant-KYC obligation exists precisely because PAs sit at the point of custody for customer funds, making them a natural chokepoint for detecting mule accounts, shell merchants, or entities selling banned products online. On the technology side, PAs must ensure merchants never store raw card credentials on their own servers — a rule that dovetails with RBI's broader card tokenisation mandate — and must run continuous fraud-monitoring systems that flag unusual transaction velocity, mismatched geolocations, or chargeback spikes in near real time. A robust grievance-redressal mechanism is compulsory too, giving customers and merchants a defined escalation path when a disputed transaction or delayed settlement occurs. Many of the fraud-control patterns aggregators deploy — device fingerprinting, two-factor authentication, transaction risk scoring — are the same digital fraud controls candidates see referenced across Bharat Bill Payment System BBPS and lighter-weight rails such as UPI 123Pay, since RBI expects a comparable baseline of customer protection irrespective of which payment rail a transaction ultimately rides on.

📌 Remember: Merchant due diligence is not a one-time onboarding step — RBI expects PAs to periodically re-assess merchant risk and monitor transaction patterns throughout the relationship, not just at sign-up.
Process & Framework — Digital Banking
Process & Framework — Digital Banking

🧠 Practice MCQs: Payment Aggregators and Gateways

Q1. Under RBI's guidelines, what is a Payment Aggregator's primary regulatory distinguishing feature compared to a pure Payment Gateway? (a) It only provides card-network connectivity (b) It holds and settles merchant funds through an escrow arrangement (c) It issues prepaid payment instruments (d) It operates ATMs on behalf of banks

Answer: (b) — A PA takes custody of customer funds and settles them to merchants via escrow, which is why it needs direct RBI authorisation.

Q2. As per RBI's PA-PG framework, non-bank Payment Aggregators must be authorised under which Act? (a) Banking Regulation Act, 1949 (b) Payment and Settlement Systems Act, 2007 (c) Information Technology Act, 2000 (d) Companies Act, 2013

Answer: (b) — Authorisation for non-bank PAs is granted under the Payment and Settlement Systems Act, 2007.

Q3. The escrow account maintained by a Payment Aggregator must be opened with: (a) Any registered NBFC (b) A prepaid wallet provider (c) A scheduled commercial bank (d) A cooperative credit society

Answer: (c) — RBI mandates that PA escrow accounts be maintained only with a scheduled commercial bank.

Q4. Which RBI framework extended payment-aggregator-style regulation to entities handling India's export/import related online payments? (a) PA-CB (Payment Aggregator-Cross Border) framework (b) Account Aggregator framework (c) BBPS framework (d) PPI Master Direction

Answer: (a) — The PA-CB framework brought cross-border online collections under PA-style custody and authorisation norms, replacing the older OPGSP route.

Q5. A key ongoing compliance requirement for Payment Aggregators regarding merchants is: (a) Providing merchants free advertising (b) Conducting background and risk-based due diligence before and during onboarding (c) Issuing merchants a co-branded credit card (d) Setting merchant product prices

Answer: (b) — PAs must vet merchants before onboarding and keep monitoring risk throughout the relationship.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

What is the difference between a Payment Aggregator and a Payment Gateway?

A Payment Aggregator takes custody of customer funds and settles them to merchants through an escrow account, while a Payment Gateway is a technology layer that only routes transaction data between the merchant, acquiring bank and card network without holding money.

Which law governs RBI authorisation of Payment Aggregators?

Non-bank Payment Aggregators must be authorised under the Payment and Settlement Systems Act, 2007, in line with RBI's dedicated PA-PG guidelines.

What is the PA-CB framework?

The Payment Aggregator-Cross Border (PA-CB) framework extends PA-style RBI regulation to entities that facilitate online, small-value export and import related payments, replacing the earlier OPGSP arrangement.

Why must Payment Aggregators maintain an escrow account?

The escrow account, held with a scheduled commercial bank, ring-fences customer and merchant funds from the aggregator's own operating money, ensuring transparent, auditable settlement and protecting merchants if the aggregator faces financial stress.

In Practice — Digital Banking
In Practice — Digital Banking

🚀 Final Word: Master Payment Aggregators and Gateways for Your Next Attempt

Payment Aggregators and Gateways sit at the exact intersection of technology, custody of funds and RBI supervision — which is precisely why examiners keep returning to this topic across JAIIB and CAIIB Digital Banking papers. Revise the PA versus PG distinction, the net-worth and escrow rules, and the PA-CB cross-border extension until you can answer without hesitation, then reinforce the concept against the wider Digital Banking topic cluster and related chapters like Retail Banking - Digital Banking Class 12. For authoritative source reading, RBI's own notifications remain the final word — see rbi.org.in for the latest circulars. When you're ready to test yourself under exam conditions, attempt a full chapter-wise mock test and track exactly where your Digital Banking preparation still needs work.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

Digital Banking · 5 questions · instant result
Q1. In a four-party POS scheme, which party is obliged to actually pay the merchant for the transactions it acquires from that merchant?
Q2. Both OPOS and JavaPOS are hardware-interface standardization initiatives that conform to which overarching standard, led by The National Retail Foundation, Washington, D.C.?
Q3. A POS terminal is best described as an automated version of which traditional retail device, capable of processing card payments, networking with other systems and managing inventory?
Q4. A restaurant wants a card terminal that the waiter can carry to any table inside the premises, but it only works within a limited range of a base unit wired to the outlet's telephone line. Which terminal does this describe?
Q5. Why does the source note that many banks actively pursue POS (acquiring) business even when direct fee income is modest?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading