+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

Building on the Account Aggregator framework

Security By Mits Engineering Team 2 min read
Building on the Account Aggregator framework

India's Account Aggregator framework moves financial data between institutions with the customer's explicit consent, and it has quietly become usable infrastructure rather than a pilot. As of early 2026 there were seventeen licensed Account Aggregators, thirteen of them with live integrations, and more than 135 financial information providers on the network: 72 banks spanning private, public, small finance, regional rural, foreign and cooperative institutions, 57 insurers, both depositories, the two major registrars, three NPS record keepers, six NBFCs, forty asset management companies via the RTAs, GSTN and CCIL.

The model has three parties and it is worth getting the vocabulary right because every integration document assumes it. The financial information provider holds the data. The Account Aggregator acts purely as a consent manager and pipe — it does not store or read the data. The financial information user is the entity requesting it, which is what your product will be. Consent is granular: specific data categories, named source institutions, a duration and a stated purpose, all reviewable and revocable by the customer at any time from their AA application.

Becoming a financial information user is a gate, not a formality. The entity must be regulated by the RBI, SEBI, IRDAI or PFRDA. If it is regulated, it must also function as a provider, giving data back to the network rather than only consuming it. Sahamati certification is required, and information security audits run on a two-yearly cycle. A software company building for a client sits outside this — the licence belongs to the client, which changes the shape of the engagement and needs establishing before scoping.

Coverage is uneven in ways that matter enormously to a product plan. Savings accounts, equities, mutual funds, ETFs, AIFs, InvITs, REITs, mutual fund folios, GSTR-1 and 3B filings and NPS balances are fully operational. Fixed and recurring deposits are available from roughly forty per cent of banks. Current accounts work with about sixty-five of the seventy-two. Insurance depends on the specific insurer and AA pairing. Bonds, debentures, government securities, commercial paper, certificates of deposit, EPF and PPF are proposed rather than live.

The exclusions are sharper still, and they are where lending products break. Joint accounts are excluded. NRE and NRO accounts are excluded. Accounts held by anything other than a sole proprietor are excluded. Depository history beyond two years is not available. A product designed around household income or a partnership firm's banking will not work as specified, and discovering that during integration rather than during design is an expensive way to learn it.

The regulatory ground has moved repeatedly — the RBI Master Direction has been updated nine times since its original issue in September 2016, with substantial revisions in October 2021, November 2022, November 2023, February 2024 and September 2024. That cadence is the argument for building the integration behind an internal abstraction rather than against a specific AA's SDK, and for treating coverage as a data table you refresh rather than an assumption baked into the code.

Need help with this? Explore our Cybersecurity & Compliance services. Learn more Back to all news

Keep reading

More on Security