Back to Glossary
Technology & Analytics · Glossary Definition

Account Aggregator (AA)

Account Aggregator (AA): The Account Aggregator framework is an RBI-regulated, consent-based system for sharing financial data. A licensed NBFC-AA moves data from a Financial Information Provider to a Financial Information User only with the customer's explicit, revocable, purpose-bound consent — and never sees the data itself.

Why Account Aggregator (AA) matters in credit and collections

  • Replaces the archaic system of manually uploading bank statement PDFs.
  • Revolutionizes credit underwriting by providing un-tamperable live banking data.
  • In collections, it helps assess if an 'inability to pay' claim is genuinely true.

How consent-based data sharing works

There are three roles. The Financial Information Provider holds the data — typically a bank, and increasingly other regulated entities. The Financial Information User needs it, such as a lender underwriting a loan. The Account Aggregator sits between them purely as a consent and routing layer: it is explicitly data-blind, meaning it cannot read or store the financial data passing through it.

Consent is granular and machine-readable. It specifies the data requested, the purpose, the frequency, and a validity period, and the customer can revoke it at any time. This is what distinguishes AA from the practices it replaces — screen-scraping with shared net-banking credentials, and PDF statements emailed around with no audit trail.

For lenders the practical gains are speed, authenticity and reusability. Data arrives structured and machine-readable rather than as a PDF requiring parsing, it comes from the source so tampering is not a concern, and periodic consent enables ongoing monitoring rather than a single snapshot at underwriting.

Regulatory basis

Account Aggregators are licensed by the Reserve Bank of India under the NBFC-Account Aggregator Directions, which establish the data-blind role, consent architecture and technical standards. The framework operates within India's broader consent-based data-sharing approach.

Source: Reserve Bank of India / Sahamati

How lenders should use the AA framework

  • Request the minimum data and the shortest validity that serves the purpose. Over-broad consent is a compliance and trust liability.
  • Use periodic consent for post-disbursement monitoring, not just a one-time underwriting pull.
  • Design a fallback. AA coverage is not universal, so statement upload paths still need to exist.
  • Honour revocation immediately and provably, and be able to evidence the consent trail for any data you hold.
  • Combine AA banking data with GST and bureau signals — the value is in cross-source contradiction, not any single feed.

Account Aggregator (AA) — frequently asked questions

Can an Account Aggregator see my financial data?

No. The framework requires AAs to be data-blind: they route encrypted data between provider and user based on consent, and are not permitted to read or store the financial information itself.

Can a customer revoke Account Aggregator consent?

Yes, at any time. Consent is revocable by design, and once revoked the Financial Information User cannot receive further data under it. Data already lawfully received remains subject to the purpose limitation under which it was obtained.

Automate your operations

CarmaOne executes Account Aggregator (AA) workflows across digital, field and legal recovery — on one platform, with a full audit trail.