Guides

Account Aggregator (AA) in India: the consumer's complete guide for 2026

Updated 2026-05-17 · 16 min read

What the Account Aggregator framework is, how consent flow works, who FIPs and FIUs are, how AA interacts with DPDP, and what consumers should and shouldn't share through AA in 2026.

"Account Aggregator is what India built instead of asking banks to play nice. It's the most consumer-friendly piece of digital infrastructure RBI has put out - and most users don't even know it exists."

Quick answer

  • AA (Account Aggregator) is an RBI-regulated, consent-based framework for sharing financial data between institutions.
  • Three roles: FIP (data source), FIU (data recipient), AA (consent broker - the pipe).
  • AAs in 2026: OneMoney, CAMS Finserv, Finvu, NESL, Yodlee, Perfios AA, Anumati, PhonePe AA. Setu is a Technology Service Provider, not an AA.
  • Data covered: bank, deposits, mutual funds, insurance, NPS, equity, GST, EPF (pilot). Tax returns and credit card statements not yet, but coming.
  • Architecture is data-blind: the AA doesn't see your data, only the consent artifact and the routing.
  • DPDP overlap: AA is the sector-specific consent regime under RBI; DPDP is the umbrella personal data law. AA is DPDP-aligned by design.

Who this guide is for

  • Consumers who saw "Connect via Account Aggregator" on a lending or wealth app and want to know what they're agreeing to.
  • Young earners setting up consolidated net-worth and portfolio aggregation.
  • Founders or PMs building fintech features on AA rails (lending, PFM, advisory).
  • Anyone concerned about data privacy who wants to understand the architecture before opting in.

What problem AA solves

Before AA, sharing financial data meant one of three painful options:

  1. Manually downloading PDFs and emailing them.
  2. Sharing net banking credentials with a third party (insecure, against bank T&Cs).
  3. Letting a screen-scraper read your statements (slow, fragile, also against bank T&Cs).

For a lender to underwrite a personal loan, they needed your bank statements. For a wealth platform to aggregate your net worth, they needed access to bank + MF + insurance + NPS. There was no clean, regulated rail to do this consensually.

AA fixed that. Conceptually, it works like UPI but for data, not money. Instead of routing rupees between bank accounts under user consent, AA routes data between regulated financial entities under user consent.

The three roles, in detail

``` FIP (data source) → AA (consent broker) → FIU (data recipient)

Your bank Your AA dashboard Lender / wealth app / insurance / PFM ```

FIP - Financial Information Provider

The institution that holds your data. RBI's FIP list in 2026 covers:

  • Banks (all scheduled commercial banks + most cooperative banks + payment banks)
  • Mutual fund RTAs (CAMS, KFintech) and AMCs via depositories
  • Depositories (NSDL, CDSL) for equity holdings
  • Insurance companies (life, general, health)
  • NPS via PFRDA
  • GSTN for business data
  • EPFO in pilot

FIPs are mandated by RBI to respond to consent-backed data requests within a defined SLA. Refusal or delay invites supervisory action.

FIU - Financial Information User

The institution that wants to consume the data. Common FIU categories:

  • Lenders (banks, NBFCs) for credit underwriting
  • Wealth managers and PFM apps for portfolio aggregation
  • Insurance companies for underwriting and KYC
  • Brokers for margin calculation and exposure tracking
  • Tax advisors (in pilot via specific data classes)

FIUs must be regulated entities under SEBI, RBI, IRDAI, or PFRDA. A random unregulated app cannot become an FIU directly - though there's a path via a regulated parent.

AA - Account Aggregator

The licensed consent broker. As of 2026, eight live AAs:

AAOwner / parentNotable use cases
OneMoneyFintech Products and Solutions IndiaFirst AA live, broad FIP coverage
CAMS FinservComputer Age Management ServicesStrong MF coverage via CAMS RTA
Finvu (FinSec AA Solutions)Cookiejar TechnologiesWealth and lending platforms
NESL Asset DataNational e-Governance ServicesBank-led use cases
Yodlee FinsoftEnvestnet YodleeCross-border-relevant aggregators
Perfios AAPerfiosEmbedded in many lender apps
AnumatiCookiejar TechnologiesNewer, growing FIP coverage
PhonePe AAPhonePeBundled with PhonePe app flow

The AA only sees the consent metadata (which user, which FIP, which FIU, which data, which duration), not the actual data - which flows encrypted directly between FIP and FIU.

What's a consent artifact

A consent in the AA framework is a signed digital artifact that contains:

  • Customer (you, identified by Aadhaar VID or mobile number on the AA)
  • FIP the data is being pulled from
  • FIU the data is going to
  • Data types (e.g., savings account transactions, MF holdings)
  • Purpose code (e.g., wealth management, loan underwriting, account aggregation)
  • Duration (one-time fetch or recurring with end date)
  • Frequency (for recurring - daily, weekly, monthly)
  • Date range of data (e.g., last 12 months of transactions)

The artifact is digitally signed (PKCS#7 over JWS) and stored on the AA. Both the FIP and FIU verify the signature before honouring the data request. The consent ID is auditable end-to-end.

How a consent flow actually works, step by step

  1. User opens an FIU app (say, a wealth manager like Qubera, or a lender like Lentra).
  2. FIU app says "connect your bank account via Account Aggregator" and lists supported AAs.
  3. User picks an AA they already have or signs up (Aadhaar OTP + mobile-based KYC).
  4. AA app opens, shows the requested consent: which FIP, which data, what duration, what purpose.
  5. User reviews, accepts, OTP-verifies.
  6. AA writes the signed consent artifact and notifies the FIP.
  7. FIP fetches the data for the date range, encrypts it for the FIU's public key, and sends it to AA.
  8. AA forwards the encrypted payload to FIU. AA cannot decrypt it.
  9. FIU decrypts with its private key and processes the data.
  10. User sees the consent (and can revoke it) in their AA dashboard at any time.

End-to-end, this typically takes 30-90 seconds for the first connection.

What you can and can't yet share over AA

Available (2026):

  • Bank - savings, current, FD, RD, term deposits
  • Mutual funds - units, NAV, transactions (via CAMS/KFintech)
  • Equities - holdings via NSDL/CDSL (transactions in pilot)
  • Insurance - life, general, health policies
  • NPS - corpus, contributions
  • GST - returns and filings (for businesses)
  • EPF - pilot, expected GA in 2026

Not yet on AA:

  • Income tax returns (use DigiLocker for ITR-V)
  • Credit card statements (still email-extraction or direct issuer API)
  • PPF (paper-rail; some banks integrating)
  • ESOPs and unlisted shares
  • Real estate, gold, alternative assets

For full portfolio aggregation today, you need AA + email extraction + manual entry stacked together. No single rail covers everything yet.

AA + DPDP: how the two regimes interact

The DPDP (Digital Personal Data Protection) Act 2023 came into force in 2024-25 with phased rules. Its key requirements:

  • Explicit, informed consent for collection and processing.
  • Right to access, correct, and erase personal data.
  • Data fiduciary obligations on processors.
  • Penalties up to ₹250 crore for serious breaches.

AA was already designed with most of these in mind - granular consent, revocability, data-minimum purpose codes, audit trail. Where AA goes further than DPDP: it's sector-specific to financial data, with RBI as the regulator, and it mandates technical interoperability between regulated entities.

In practice:

  • If you grant consent via AA, you're DPDP-compliant on that data flow by construction.
  • DPDP applies to all other personal data (name, email, browsing, etc.) regardless of AA.
  • The two regimes don't conflict; they layer.

What can go wrong (and how to avoid it)

  1. Granting too long a consent duration. Most lending use cases need a one-time pull. If the FIU asks for 1-year recurring access, ask why. A "lifetime" duration is virtually never necessary.
  2. Granting too many data types. Underwriting a personal loan doesn't need your insurance data. Each consent should match the stated purpose.
  3. Picking the wrong AA. Some AAs have weaker FIP coverage than others. If your bank isn't supported by the AA the FIU is offering, you'll fail mid-flow. Most apps now let you choose.
  4. Phishing apps mimicking AAs. There have been scattered reports of fake AA apps. Verify the AA license at RBI's NBFC-AA registry: search "rbi.org.in NBFC-AA list".
  5. Ignoring the consent dashboard. Most AA users never revisit their consent history. Quarterly review and revoke unused consents.

How AA shows up in real Indian fintech in 2026

Use caseTypical FIUWhat's pulled
Personal loan underwritingBank / NBFC12 months of bank transactions
Credit card pre-approvalCard issuer6 months of bank transactions
Wealth aggregation / PFMPortfolio appBank + MF + insurance + NPS holdings
Mutual fund executionBroker / advisorMF holdings, transactions
Insurance underwritingInsurerBank + investment summary
MSME lendingBusiness lenderBank + GST + ITR (via DigiLocker)
Robo-advisoryWealth advisorMF + bank + insurance holdings
Tax advisoryCA / advisorMF + bank + ITR (DigiLocker)

The wealth aggregation + PFM use case is what most consumer apps now build on. Personal loans were the first big use case in 2022-23; wealth and insurance are the 2025-26 growth phase.

The Qubera AA stack

Qubera connects via AA through Setu, the leading TSP, which gives us coverage across all eight licensed AAs without dedicated integrations into each. The user picks the AA they prefer (OneMoney is our default recommendation for young earners due to FIP coverage), grants consent for the data classes Qubera needs - bank transactions, MF holdings, insurance, NPS - and Qubera builds a live net-worth and spending view in seconds.

What we don't do:

  • Ask for sweeping multi-year consents. Each consent is tightly purpose-scoped.
  • Pull data we don't display back to you. The principle is data minimum, not data maximum.
  • Store data we don't need for the user-facing computation.

For the broader "tools that read everything for you" picture, see best AI personal finance app India 2026.

Further reading

Frequently asked questions

What is the Account Aggregator framework in India?

The Account Aggregator (AA) framework is an RBI-regulated, consent-based data sharing system that lets consumers securely share their financial data - bank statements, mutual fund holdings, insurance policies, deposits - between regulated financial institutions. AA entities don't see the data; they just route it from the source (FIP) to the recipient (FIU) under a signed consent artifact.

Who are the licensed Account Aggregators in India in 2026?

As of 2026, RBI has licensed eight Account Aggregators: OneMoney (owner: Fintech Products and Solutions), CAMS Finserv, FinSec AA Solutions (Finvu), NESL Asset Data, Yodlee Finsoft, Perfios AA, Anumati (Cookiejar Technologies), and PhonePe AA. Setu is a TSP (Technology Service Provider) that powers many AA integrations - it's not itself a licensed AA, despite popular usage.

What is the difference between FIP, FIU, and AA?

FIP (Financial Information Provider) is the data source - your bank, mutual fund AMC, insurer, NPS, EPF, or GSTN. FIU (Financial Information User) is the entity that wants the data - a lender for underwriting, a wealth platform for portfolio aggregation, a personal finance app. The AA (Account Aggregator) is the neutral pipe in between, regulated by RBI as a consent broker.

Can the AA see my data?

No. AAs are designed as 'data blind' - they don't see, store, or process the content of the data flowing through them. They handle only the consent artifact, the routing, and the audit trail. The data itself is encrypted end-to-end from FIP to FIU. This is the same architecture as the DigiLocker design, with stricter encryption mandates.

Is the AA framework safe?

AA is one of the most rigorously regulated data-sharing systems in the world - comparable to PSD2 Open Banking in Europe. RBI mandates ISO 27001 compliance, end-to-end encryption, signed consent artifacts that the user can revoke at any time, and a fixed list of data types per consent. The main consumer risk is granting too much data or too long a duration on consent - not the AA framework itself.

What data can be shared via Account Aggregator?

As of 2026, AA supports: savings and current bank accounts, fixed and recurring deposits, mutual fund holdings (via depositories), insurance policies (life, general, health), NPS, equity holdings (via NSDL/CDSL), GSTN data for businesses, and EPF in pilot. Income tax returns, credit card statements, and PPF are not yet on AA but are on the roadmap (some via DigiLocker, some via direct connectors).

How does AA interact with the DPDP Act?

The Digital Personal Data Protection (DPDP) Act 2023 covers personal data broadly; AA is a sector-specific consent regime under RBI for financial data. DPDP and AA both require explicit, granular, revocable consent and define data fiduciary obligations. AA's signed consent artifacts and audit logs were ahead of DPDP requirements - most AA-connected services are DPDP-compliant by design for the financial data they handle.

How do I revoke an AA consent?

Open the app of the Account Aggregator that brokered the consent - OneMoney, Finvu, CAMS Finserv, etc. The consent dashboard lists every active and historical consent with the FIU name, data types shared, and validity window. Tap revoke, confirm with mPIN/OTP, and the FIU's access stops immediately. The audit trail of past data fetched stays with the FIU as a matter of regulatory record.

Related guides

Qubera is the AI personal finance companion for India. Loading the interactive version…