"Account Aggregator is what India built instead of asking banks to play nice. It's the most consumer-friendly piece of digital infrastructure RBI has put out - and most users don't even know it exists."
Quick answer
- AA (Account Aggregator) is an RBI-regulated, consent-based framework for sharing financial data between institutions.
- Three roles: FIP (data source), FIU (data recipient), AA (consent broker - the pipe).
- AAs in 2026: OneMoney, CAMS Finserv, Finvu, NESL, Yodlee, Perfios AA, Anumati, PhonePe AA. Setu is a Technology Service Provider, not an AA.
- Data covered: bank, deposits, mutual funds, insurance, NPS, equity, GST, EPF (pilot). Tax returns and credit card statements not yet, but coming.
- Architecture is data-blind: the AA doesn't see your data, only the consent artifact and the routing.
- DPDP overlap: AA is the sector-specific consent regime under RBI; DPDP is the umbrella personal data law. AA is DPDP-aligned by design.
Who this guide is for
- Consumers who saw "Connect via Account Aggregator" on a lending or wealth app and want to know what they're agreeing to.
- Young earners setting up consolidated net-worth and portfolio aggregation.
- Founders or PMs building fintech features on AA rails (lending, PFM, advisory).
- Anyone concerned about data privacy who wants to understand the architecture before opting in.
What problem AA solves
Before AA, sharing financial data meant one of three painful options:
- Manually downloading PDFs and emailing them.
- Sharing net banking credentials with a third party (insecure, against bank T&Cs).
- Letting a screen-scraper read your statements (slow, fragile, also against bank T&Cs).
For a lender to underwrite a personal loan, they needed your bank statements. For a wealth platform to aggregate your net worth, they needed access to bank + MF + insurance + NPS. There was no clean, regulated rail to do this consensually.
AA fixed that. Conceptually, it works like UPI but for data, not money. Instead of routing rupees between bank accounts under user consent, AA routes data between regulated financial entities under user consent.
The three roles, in detail
``` FIP (data source) → AA (consent broker) → FIU (data recipient)
Your bank Your AA dashboard Lender / wealth app / insurance / PFM ```
FIP - Financial Information Provider
The institution that holds your data. RBI's FIP list in 2026 covers:
- Banks (all scheduled commercial banks + most cooperative banks + payment banks)
- Mutual fund RTAs (CAMS, KFintech) and AMCs via depositories
- Depositories (NSDL, CDSL) for equity holdings
- Insurance companies (life, general, health)
- NPS via PFRDA
- GSTN for business data
- EPFO in pilot
FIPs are mandated by RBI to respond to consent-backed data requests within a defined SLA. Refusal or delay invites supervisory action.
FIU - Financial Information User
The institution that wants to consume the data. Common FIU categories:
- Lenders (banks, NBFCs) for credit underwriting
- Wealth managers and PFM apps for portfolio aggregation
- Insurance companies for underwriting and KYC
- Brokers for margin calculation and exposure tracking
- Tax advisors (in pilot via specific data classes)
FIUs must be regulated entities under SEBI, RBI, IRDAI, or PFRDA. A random unregulated app cannot become an FIU directly - though there's a path via a regulated parent.
AA - Account Aggregator
The licensed consent broker. As of 2026, eight live AAs:
| AA | Owner / parent | Notable use cases |
|---|---|---|
| OneMoney | Fintech Products and Solutions India | First AA live, broad FIP coverage |
| CAMS Finserv | Computer Age Management Services | Strong MF coverage via CAMS RTA |
| Finvu (FinSec AA Solutions) | Cookiejar Technologies | Wealth and lending platforms |
| NESL Asset Data | National e-Governance Services | Bank-led use cases |
| Yodlee Finsoft | Envestnet Yodlee | Cross-border-relevant aggregators |
| Perfios AA | Perfios | Embedded in many lender apps |
| Anumati | Cookiejar Technologies | Newer, growing FIP coverage |
| PhonePe AA | PhonePe | Bundled with PhonePe app flow |
The AA only sees the consent metadata (which user, which FIP, which FIU, which data, which duration), not the actual data - which flows encrypted directly between FIP and FIU.
What's a consent artifact
A consent in the AA framework is a signed digital artifact that contains:
- Customer (you, identified by Aadhaar VID or mobile number on the AA)
- FIP the data is being pulled from
- FIU the data is going to
- Data types (e.g., savings account transactions, MF holdings)
- Purpose code (e.g., wealth management, loan underwriting, account aggregation)
- Duration (one-time fetch or recurring with end date)
- Frequency (for recurring - daily, weekly, monthly)
- Date range of data (e.g., last 12 months of transactions)
The artifact is digitally signed (PKCS#7 over JWS) and stored on the AA. Both the FIP and FIU verify the signature before honouring the data request. The consent ID is auditable end-to-end.
How a consent flow actually works, step by step
- User opens an FIU app (say, a wealth manager like Qubera, or a lender like Lentra).
- FIU app says "connect your bank account via Account Aggregator" and lists supported AAs.
- User picks an AA they already have or signs up (Aadhaar OTP + mobile-based KYC).
- AA app opens, shows the requested consent: which FIP, which data, what duration, what purpose.
- User reviews, accepts, OTP-verifies.
- AA writes the signed consent artifact and notifies the FIP.
- FIP fetches the data for the date range, encrypts it for the FIU's public key, and sends it to AA.
- AA forwards the encrypted payload to FIU. AA cannot decrypt it.
- FIU decrypts with its private key and processes the data.
- User sees the consent (and can revoke it) in their AA dashboard at any time.
End-to-end, this typically takes 30-90 seconds for the first connection.
What you can and can't yet share over AA
Available (2026):
- Bank - savings, current, FD, RD, term deposits
- Mutual funds - units, NAV, transactions (via CAMS/KFintech)
- Equities - holdings via NSDL/CDSL (transactions in pilot)
- Insurance - life, general, health policies
- NPS - corpus, contributions
- GST - returns and filings (for businesses)
- EPF - pilot, expected GA in 2026
Not yet on AA:
- Income tax returns (use DigiLocker for ITR-V)
- Credit card statements (still email-extraction or direct issuer API)
- PPF (paper-rail; some banks integrating)
- ESOPs and unlisted shares
- Real estate, gold, alternative assets
For full portfolio aggregation today, you need AA + email extraction + manual entry stacked together. No single rail covers everything yet.
AA + DPDP: how the two regimes interact
The DPDP (Digital Personal Data Protection) Act 2023 came into force in 2024-25 with phased rules. Its key requirements:
- Explicit, informed consent for collection and processing.
- Right to access, correct, and erase personal data.
- Data fiduciary obligations on processors.
- Penalties up to ₹250 crore for serious breaches.
AA was already designed with most of these in mind - granular consent, revocability, data-minimum purpose codes, audit trail. Where AA goes further than DPDP: it's sector-specific to financial data, with RBI as the regulator, and it mandates technical interoperability between regulated entities.
In practice:
- If you grant consent via AA, you're DPDP-compliant on that data flow by construction.
- DPDP applies to all other personal data (name, email, browsing, etc.) regardless of AA.
- The two regimes don't conflict; they layer.
What can go wrong (and how to avoid it)
- Granting too long a consent duration. Most lending use cases need a one-time pull. If the FIU asks for 1-year recurring access, ask why. A "lifetime" duration is virtually never necessary.
- Granting too many data types. Underwriting a personal loan doesn't need your insurance data. Each consent should match the stated purpose.
- Picking the wrong AA. Some AAs have weaker FIP coverage than others. If your bank isn't supported by the AA the FIU is offering, you'll fail mid-flow. Most apps now let you choose.
- Phishing apps mimicking AAs. There have been scattered reports of fake AA apps. Verify the AA license at RBI's NBFC-AA registry: search "rbi.org.in NBFC-AA list".
- Ignoring the consent dashboard. Most AA users never revisit their consent history. Quarterly review and revoke unused consents.
How AA shows up in real Indian fintech in 2026
| Use case | Typical FIU | What's pulled |
|---|---|---|
| Personal loan underwriting | Bank / NBFC | 12 months of bank transactions |
| Credit card pre-approval | Card issuer | 6 months of bank transactions |
| Wealth aggregation / PFM | Portfolio app | Bank + MF + insurance + NPS holdings |
| Mutual fund execution | Broker / advisor | MF holdings, transactions |
| Insurance underwriting | Insurer | Bank + investment summary |
| MSME lending | Business lender | Bank + GST + ITR (via DigiLocker) |
| Robo-advisory | Wealth advisor | MF + bank + insurance holdings |
| Tax advisory | CA / advisor | MF + bank + ITR (DigiLocker) |
The wealth aggregation + PFM use case is what most consumer apps now build on. Personal loans were the first big use case in 2022-23; wealth and insurance are the 2025-26 growth phase.
The Qubera AA stack
Qubera connects via AA through Setu, the leading TSP, which gives us coverage across all eight licensed AAs without dedicated integrations into each. The user picks the AA they prefer (OneMoney is our default recommendation for young earners due to FIP coverage), grants consent for the data classes Qubera needs - bank transactions, MF holdings, insurance, NPS - and Qubera builds a live net-worth and spending view in seconds.
What we don't do:
- Ask for sweeping multi-year consents. Each consent is tightly purpose-scoped.
- Pull data we don't display back to you. The principle is data minimum, not data maximum.
- Store data we don't need for the user-facing computation.
For the broader "tools that read everything for you" picture, see best AI personal finance app India 2026.