India Account Aggregator Framework (RBI)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
RBI AA Audit + Logging + Authentication
RBI AA Audit + Logging + Authentication establishes the assurance layer for the AA ecosystem. (1) IT System Audit: per RBI Cyber Security Framework + RBI IT Guidelines for NBFC-AA - bi-annual or annual independent IT system audit by qualified auditors (CISA + CISM + DISA-certified) + scope covering Information Security + IT Operations + Application Security + Network + Database + Cloud + DR/BCP + Outsourcing + Vendor Risk + audit report submitted to RBI + Action Taken Report on findings + Board-level review. (2) Consent Lifecycle Logging: comprehensive logs of all consent events - Consent Granted + Consent Modified + Consent Paused + Consent Revoked + Consent Expired + Data Fetch Initiated + Data Fetch Successful + Data Fetch Failed + FIU Data Access + Customer Login + Customer Dashboard Access + ORS Revocation + with timestamp + IP + device fingerprint + customer ID + AA session ID + FI
- Bi-annual IT system audit + qualified auditor + scope + report + ATR + Board review + records
- Consent lifecycle logs + WORM + 7-year retention + tamper-evident + audit trail + records
- Customer MFA + Aadhaar OTP/eSign + device binding + risk-based + session controls + records
- RBI inspection records + off-site returns + Sahamati compliance reports + bi-annual + KPIs
- CERT-In reporting + 6-hour window + customer audit access + dispute mechanism + records
- IT system audit ad-hoc (not bi-annual or auditor not qualified)
- Consent logs incomplete (failed fetches or revocations not logged)
- Customer authentication single-factor (no Aadhaar OTP + no device binding)
- RBI inspection findings unaddressed (no ATR or repeat findings)
- CERT-In reporting missed window (incident reported beyond 6 hours)
RBI AA Consent Architecture
Consent Architecture is the core distinguishing element of the RBI AA Framework - all financial data sharing between FIPs and FIUs requires explicit + revocable + auditable customer consent mediated through the Account Aggregator. (1) Consent Artefact: digitally signed structured consent record per Sahamati specifications including Consent ID + Consent Handle + Customer ID (VUA Virtual User Address) + FI Types (Accounts + Deposits + Loans + GST + Insurance + Investments + ITR + EPF + NPS + Property) + FI Categories (DEPOSIT + TERM_DEPOSIT + CREDIT_CARD + RECURRING_DEPOSIT + ETF + IDR + CIS + GOVT_SECURITIES + EQUITIES + BONDS + DEBENTURES + MUTUAL_FUND_UNITS + INSURANCE_POLICIES + NPS + LIFE_INSURANCE + GENERAL_INSURANCE + INVOICE + GST) + Purpose Codes per Sahamati taxonomy (Wealth Management + Loan/Credit + Personal Finance Management + Income/Expense Insights + Customer Identification
- Consent artefact per Sahamati schema + JSON validation + records + e-signed
- Customer consent capture UX + multilingual + accessibility + UIDAI/eSign integration + records
- Purpose binding + codes per Sahamati taxonomy + FIU contractual re-use prohibition + audit
- Customer consent dashboard + ORS + active/revoked/expired view + audit log accessible
- Lifecycle states + state transitions + records + time-bound + re-confirmation procedures
- Consent artefact not Sahamati schema compliant (custom JSON breaks ecosystem)
- Consent UX not multilingual or accessible (excludes regional customers)
- Purpose limitation not enforced at FIU (data re-used or shared)
- Customer dashboard absent or hard to find (no easy revocation)
- Lifecycle states not transparent (customer confused about active vs revoked)
RBI AA Customer Protection
Customer Protection sits at the heart of the RBI AA Framework given the asymmetric power between customer and ecosystem participants. (1) Internal Grievance Redressal: appointed Internal Grievance Redressal Officer (IGRO) for AA + 24x7 customer support + multilingual + accessible channels (in-app + portal + email + toll-free + SMS) + standardised intake + acknowledgement within 24 hours + resolution within 30 days per RBI guidance + escalation matrix + senior management oversight + customer protection committee at Board level. (2) Categories of Complaints: consent misuse + data accuracy + revocation not honoured + customer dashboard issues + customer authentication issues + cross-AA portability disputes + FIP issues + FIU misuse of data + technical errors + fee disputes. (3) Fee Transparency: zero-fee customer interaction principle (customer never pays AA directly) + bilateral fee arrang
- Internal Grievance Officer appointed + 24x7 customer support + complaint categories + 30-day SLA
- Fee transparency + zero customer fee + bilateral fee schedule + audited + published on portal
- RBI Integrated Ombudsman escalation procedure + customer awareness materials + Sahamati education
- DPDP customer rights operationalised + access/correction/erasure/grievance/withdraw consent + records
- Vulnerable customer procedures + anti-mis-selling commitment + Sahamati Code of Conduct adherence
- Internal Grievance Officer role unfilled (complaints unaddressed)
- Fee transparency only on website (not in customer dashboard)
- Ombudsman escalation not communicated (customers unaware of right)
- DPDP customer rights not operationalised (no access portal or response SLA)
- Vulnerable customer support absent (only digital-first)
RBI AA Ecosystem
RBI AA Ecosystem orchestrates Financial Information Providers (FIPs) + Financial Information Users (FIUs) through standardised APIs enabling interoperability across regulated entities. (1) Financial Information Providers (FIPs): entities holding customer financial data - Scheduled Commercial Banks (SBI + HDFC + ICICI + Axis + Kotak + etc) + Non-Banking Financial Companies (NBFCs) + Small Finance Banks (SFBs) + Payments Banks + Cooperative Banks + Mutual Fund Asset Management Companies (AMCs) + Depositories (NSDL + CDSL) + Insurance Companies (LIC + general + life insurance) + Pension Funds (NPS through PFRDA) + Goods and Services Tax Network (GSTN) for GSTR-1/2/3B + Employee Provident Fund Organisation (EPFO) + others designated by RBI through Industry Notifications. (2) Financial Information Users (FIUs): entities consuming financial data with customer consent - Banks for digital lendin
- FIP list + sector coverage + bank/NBFC/insurance/pension/GST + onboarded + tested + records
- FIU onboarding + KYC + purpose code + Sahamati Code of Conduct + customer protection commitments
- Interoperability evidence + ReBIT FI API + Sahamati protocol + cross-AA testing + no lock-in
- Sahamati onboarding tracker + technical certification + production rollout + SLA performance
- DPI integration + Aadhaar eKYC + UIDAI eSign + DigiLocker + cross-sector regulator coordination
- FIP coverage limited (only banks, no NBFC/insurance/pension)
- FIU onboarding weak (no purpose code validation or customer protection)
- Interoperability claimed but custom extensions break cross-AA portability
- Sahamati certification skipped (in-house API not validated)
- DPI integration partial (only eKYC, no DigiLocker/UPI/ONDC)
RBI AA IT + Data Protection
RBI AA Framework imposes strict IT and data protection controls reflecting the elevated trust and sensitivity of consolidating financial information. (1) Data Transience (No Storage): AA shall be a data blind pipe - data passes through AA but is never stored at the AA + AA only stores consent artefacts + metadata + audit logs - NOT the actual financial data + AA has no visibility into financial data content (data encrypted end-to-end). (2) End-to-End Encryption (E2EE): data flowing from FIP to FIU passes through AA but is encrypted with FIU public key at the FIP + only the FIU can decrypt + AA cannot see plaintext data + cryptographic key management per Sahamati standards + JWT signing + RSA + ECDSA + AES-256. (3) Data Localisation: per RBI directive (Storage of Payment System Data 2018 extended to AA), all data and the entire ecosystem must operate within geographic boundaries of India
- Data flow architecture + AA blind pipe + storage policy + no actual financial data at AA
- E2EE implementation + FIP public key encryption + FIU decryption + key management + crypto inventory
- Data localisation + servers in India + backup + DR site + geographic boundary attestation
- Information Security Policy board-approved + CISO role + cyber risk + RBI Cyber Framework alignment
- RBI IT framework compliance + outsourcing governance + DPDP Act 2023 SDF obligations + DPO + DPIA
- Data Transience claim + actual storage of financial data (architectural violation)
- E2EE implementation incomplete (AA can decrypt plaintext)
- Data Localisation breached (backup or DR offshore)
- Information Security Policy aspirational + not operationalised + no CISO
- DPDP Act 2023 SDF obligations not assessed (significance threshold ignored)
RBI AA Incident Response + Resilience
Incident Response and Resilience are critical for the trust foundation of the AA ecosystem given the sensitive financial data flowing through it. (1) Incident Reporting: cyber security incidents reported to RBI via prescribed RBI Cyber Security Incident Report template + CERT-In within 6 hours per CERT-In Directions of 28 April 2022 + Department of Telecommunications (DoT) where applicable + Sahamati for ecosystem-wide awareness + DPDP Act 2023 breach notification to Data Protection Board of India (DPBI) within 72 hours for personal data breaches affecting customers + customer breach notification per DPDP Sec 8(6). (2) Incident Categories: data breach + unauthorised data access + ransomware + DDoS + insider threat + supply chain compromise + cryptographic key compromise + consent forgery + AA portal compromise + FIP/FIU API misuse + customer account takeover + payment fraud (if linked to
- Multi-regulator reporting matrix + RBI + CERT-In 6h + DPBI 72h + Sahamati + records
- Incident response plan + phases + IR team + tabletop drills + forensics readiness + chain of custody
- BCP + DR in India + RTO/RPO + drills + active-active + alternate processing + manual procedures
- Resilience + continuous availability target + WAF + DDoS mitigation + capacity + degraded mode
- Customer status page + SLA + RTO/RPO commitments + dispute escalation + customer communication
- Multi-regulator reporting matrix incomplete (CERT-In 6h missed)
- Incident response plan paper-only (no tabletop drills or forensics)
- BCP DR offshore (data localisation violation during recovery)
- Resilience without DDoS or WAF (vulnerable to volumetric attacks)
- Customer communication absent during outage (no status page)
RBI AA Industry Standards + Coordination
Industry standards + coordination position the RBI AA Framework within the broader regulatory and technical ecosystem. (1) Sahamati Self-Regulatory Organisation (SRO): DigiSahamati Foundation acts as the not-for-profit SRO for the AA ecosystem + Sahamati Code of Conduct + Sahamati Technical Standards (Consent Artefact + FI API + APIs for consent management + token-based authentication) + Sahamati Technical Working Group + Sahamati Ecosystem Working Group + AA Onboarding Tracker + Sahamati AA Day events + capacity building + dispute resolution + ecosystem performance KPIs + monthly transaction volume reports. (2) ReBIT Specifications: Reserve Bank Information Technology Pvt Ltd (ReBIT, wholly-owned RBI subsidiary) issues technical specifications - ReBIT FI API v1.1 + token-based authentication + JSON Web Signature (JWS) + JSON Web Encryption (JWE) + protocol versioning + ReBIT-Sahamati al
- Sahamati SRO membership + Code of Conduct adherence + transaction volume reports + records
- ReBIT FI API v1.1 + token auth + JWS/JWE + versioning + Sahamati technical compliance evidence
- DPDP Act 2023 compliance + Consent Manager registration + SDF assessment + DPO + DPIA + breach proc
- DPI India Stack integration + UPI + Aadhaar + DigiLocker + ONDC + OCEN architecture + records
- International AA equivalents awareness + Open Banking/Finance + cross-border coordination + monitoring
- Sahamati SRO membership but no Code of Conduct adherence (compliance gap)
- ReBIT FI API custom extensions break ecosystem interoperability
- DPDP Act 2023 not assessed for Consent Manager registration
- DPI integration partial (only Aadhaar, no UPI/DigiLocker/ONDC)
- International equivalents ignored (RBI-only view + no Open Finance roadmap)
RBI AA Registration + Licensing
Reserve Bank of India (RBI) Account Aggregator (AA) Framework is established under the RBI Master Direction Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions 2016 dated 2 September 2016 issued under Section 45L of the RBI Act 1934 with subsequent updates including alignment with Digital Personal Data Protection (DPDP) Act 2023. Creates the NBFC-Account Aggregator (NBFC-AA) licensing category for entities providing the service of retrieving + consolidating financial information of a customer from Financial Information Providers (FIPs) and presenting it to the customer or Financial Information Users (FIUs) per customer consent. Registration with RBI through Department of Non-Banking Regulation. Requirements: (1) Net Owned Funds (NOF) of not less than INR 2 crore (revised threshold per Master Direction amendments); (2) Fit and Proper criteria for directors + senio
- NBFC-AA Certificate of Registration from RBI + in-principle approval + CoR + records
- Net Owned Funds compliance + audited financial statements + capital adequacy + NOF certification
- Fit and Proper certification + director/promoter background + ongoing monitoring + reports
- IT framework documentation + risk management + capital adequacy + regulatory submissions
- Regulator coordination + RBI + SEBI + IRDAI + PFRDA + Sahamati SRO + records
- NBFC-AA Certificate not held (operating as AA without CoR)
- Net Owned Funds dip below INR 2 crore threshold without RBI notification
- Fit and Proper not refreshed annually for director/promoter changes
- IT framework documentation outdated or missing components
- Cross-sector coordination weak (only RBI engaged for FIPs/FIUs in SEBI/IRDAI domains)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the India Account Aggregator Framework (RBI) framework page.