Call For Business Enquiries : +91 9819 000 511 / +91 9821 83 26 83 / +91 9819 000 445

NBFC Account Aggregator Compliance in India – CA for RBI AA Consent Framework, Audits & Reporting – N D Savla & Associates
NBFC Compliance

NBFC Account Aggregator Compliance in India
CA for RBI AA Consent Framework, Audits & Reporting

An NBFC Account Aggregator holds one of the most trust-sensitive licences the RBI grants — it sits on the consent layer of India's financial data ecosystem, and its compliance has to match that responsibility. NBFC Account Aggregator compliance is not ordinary NBFC compliance: alongside the usual RBI returns and audits, an AA must prove, on an ongoing basis, that its consent architecture, data security, and governance meet the RBI's standards. At N D Savla & Associates, we act as the Chartered Accountant for NBFC Account Aggregator compliance — handling the consent-framework controls, the Net Owned Fund, the returns and the IS audits as one connected system.

What Is an NBFC Account Aggregator (AA)?

An NBFC Account Aggregator is a specialised non-banking financial company licensed by the RBI under the Master Direction – Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions, 2016. Its single permitted business is consent-based financial data sharing: it retrieves a customer's financial information from Financial Information Providers (FIPs) — such as banks, NBFCs, insurers, and depositories — and shares it with Financial Information Users (FIUs), typically lenders and wealth platforms, strictly on the customer's explicit and revocable consent. The AA is the consent layer of the Data Empowerment and Protection Architecture (DEPA).

What makes the AA model distinctive is what it cannot do. An Account Aggregator is 'data-blind' — it transfers the financial information in encrypted form and cannot read, store, use, or monetise it. It cannot lend, cannot give advice, and cannot carry on any business other than account aggregation. To hold the licence, a company must be incorporated in India and maintain a minimum Net Owned Fund of ₹2 crore, and the RBI grants it a Certificate of Registration as an NBFC-AA. Those design restrictions are exactly what AA compliance has to evidence, year after year.

Key Compliance Requirements for an NBFC Account Aggregator

Account Aggregator compliance spans four fronts — consent and data, capital, technology, and corporate governance. The core obligations are:

Consent architecture

implement and maintain a consent framework aligned with the RBI/ReBIT technical specifications, ensure every data pull is backed by a valid consent artefact, and store those artefacts securely for audit and dispute resolution.

Data-blind operations

keep the AA strictly limited to consent-based data sharing, with no reading, storage, use, or sale of customer financial data, and no business activity beyond account aggregation.

Net Owned Fund

maintain NOF at or above the ₹2 crore minimum on an ongoing basis, monitored and certified, not just at the time of licensing.

IT and cybersecurity

meet the RBI's IT and cybersecurity requirements with secure data-transfer infrastructure and periodic Information Systems (IS) / system audits by CISA-qualified auditors.

RBI returns and Statutory Auditor Certificate

file the applicable RBI/DNBS returns and the annual Statutory Auditor Certificate, in line with our wider NBFC annual compliance framework.

Governance and grievance redressal

maintain fit-and-proper directors, board oversight, a Citizen's Charter and customer grievance redressal mechanism, and audited financial statements.

ROC and event-based filings

complete corporate filings such as AOC-4 and MGT-7, and intimate the RBI of changes in directors or control, where applicable through NBFC takeover approvals.

How NBFC Account Aggregator Compliance Works – Step by Step

01

Review the Compliance and Control Position

Assess the NBFC-AA against the RBI AA Directions — consent architecture, IT and cybersecurity controls, NOF, governance, and any pending returns or gaps.
02

Build the Compliance and Audit Calendar

Map every RBI return, the Statutory Auditor Certificate, IS/system audit, ROC filing, and event-based intimation to its due date.
03

Validate the Consent Framework and Data Controls

Check that the consent architecture follows the RBI/ReBIT specifications, that the AA remains data-blind, and that consent artefacts are stored for audit and dispute resolution.
04

Monitor Net Owned Fund and Finalise the Accounts

Track Net Owned Fund against the ₹2 crore minimum on an ongoing basis and finalise the audited financial statements.
05

File RBI Returns and Complete the Audits

File the applicable RBI returns and the annual Statutory Auditor Certificate, and complete the Information Systems and cybersecurity audits through CISA-qualified auditors.
06

Maintain Governance and Grievance Redressal

Keep fit-and-proper governance, board processes, policies, and the customer grievance redressal mechanism current, and intimate the RBI of changes in directors or control.

Why Hire a Chartered Accountant for NBFC Account Aggregator Compliance?

AA compliance lives at the intersection of finance, regulation, and technology — and that is precisely where a Chartered Accountant adds value. A Chartered Accountant for NBFC Account Aggregator compliance monitors and certifies the Net Owned Fund, prepares and files the RBI returns and the Statutory Auditor Certificate, coordinates the Information Systems and cybersecurity audits with the technology team, and keeps the consent-framework controls, governance, and reporting consistent with the RBI's AA Directions. The numbers, the audits, and the regulatory narrative all stay aligned.

Just as importantly, a CA firm for Account Aggregator compliance runs the whole thing on a calendar. The RBI evaluates an AA on a continuing record — NOF maintained, returns filed, IS audits completed, consent controls demonstrable — and a lapse on any one front is a supervisory risk. When you hire a Chartered Accountant for NBFC Account Aggregator compliance, you get a single accountable team keeping the licence in good standing, so your business can focus on the data network rather than the regulator's checklist.

Account Aggregator Compliance vs General NBFC Compliance – What Is Different?

Every NBFC-AA carries the standard NBFC compliance load — RBI returns, the Statutory Auditor Certificate, NOF discipline, ROC filings, and governance. What sets AA compliance apart is the layer on top, and it is a heavy one. A lending NBFC is judged largely on its financials, asset quality, and prudential norms; an Account Aggregator is judged additionally on its consent architecture, its data security, its data-blind design, and its IT systems. The Information Systems audit and the consent-artefact trail are central to AA compliance in a way they simply are not for a conventional NBFC.

That difference changes how the compliance function must be built. An AA cannot be serviced by a generalist who treats it as just another NBFC — it needs a team that understands the RBI's AA Directions, the ReBIT consent specifications, and the technology controls, and can still deliver the standard RBI and ROC compliance underneath. We bring both layers together, with internal audit and IS-audit coordination where the technology side demands deeper assurance.

Our NBFC Account Aggregator Compliance Services

At N D Savla & Associates, we provide end-to-end support for NBFC Account Aggregator compliance and the wider NBFC obligations that sit beneath it. Our AA compliance services cover:

  • Consent framework compliance — review and upkeep of the consent architecture against RBI/ReBIT specifications, consent-artefact management, and audit-and-dispute readiness.
  • Net Owned Fund monitoring and certification — ongoing tracking of NOF against the ₹2 crore minimum, with the supporting computations and certificates.
  • RBI returns and Statutory Auditor Certificate — preparation and filing of the applicable RBI/DNBS returns and the annual SAC, with audited financial statements.
  • IS and cybersecurity audit coordination — managing the Information Systems / system audits and the RBI cybersecurity framework requirements through CISA-qualified auditors, supported by our internal audit team.
  • Governance and data compliance — fit-and-proper support, board and policy upkeep, grievance redressal, and alignment with related data and AML obligations such as CKYC and FIU-IND reporting where applicable.
  • ROC, event-based and regulatory support — corporate filings, intimations of changes in directors or control, and NBFC legal support where regulatory questions arise.

Why Choose N D Savla & Associates as Your CA for NBFC Account Aggregator Compliance

Account Aggregator compliance rewards a team that genuinely understands both the regulation and the technology controls behind it. As a Chartered Accountant firm with strong RBI-facing experience across the NBFC space, we run the AA's financial, regulatory, and audit-coordination obligations as one system — the same team that certifies your Net Owned Fund files your returns and coordinates your IS audit, so nothing falls between functions.

Clients choose us because AA compliance stops being a scramble. You get a defined calendar with continuous NOF and control monitoring, returns and audits prepared ahead of deadlines, clear flags when the RBI's AA expectations evolve, and a compliance record that holds up in supervision, funding rounds, and partner due diligence. From the consent framework to the Statutory Auditor Certificate, we keep your NBFC-Account Aggregator licence secure and in good standing.

Related Services & Compliance Support

Common Questions

What is an NBFC Account Aggregator (AA)?
An NBFC Account Aggregator is a specialised class of non-banking financial company licensed by the RBI under the Master Direction – Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions, 2016. Its sole business is consent-based financial data sharing: it retrieves a customer's financial information from Financial Information Providers (FIPs) and shares it with Financial Information Users (FIUs) only on the customer's explicit, revocable consent. The AA is the consent layer of India's Account Aggregator ecosystem under the Data Empowerment and Protection Architecture (DEPA).
Can an Account Aggregator see, store, or use customer financial data?
No. An NBFC-AA is 'data-blind' by design — it moves the financial information in encrypted form and cannot read, store, use, or sell it. The RBI also restricts an AA to a single line of business: it cannot lend, cannot give financial advice, and cannot undertake any activity other than account aggregation, and it may deploy its funds only in instruments the RBI permits. These restrictions are core compliance obligations, not just product features, and they must be evidenced in the AA's systems and policies.
What are the key compliance requirements for an NBFC-AA?
The main obligations are: maintaining a consent architecture aligned with the RBI/ReBIT technical specifications and storing consent artefacts for audit and dispute resolution; keeping Net Owned Fund at or above the ₹2 crore minimum on an ongoing basis; meeting RBI cybersecurity and IT requirements with periodic Information Systems (IS) audits by CISA-qualified auditors; filing the applicable RBI returns and the annual Statutory Auditor Certificate; submitting audited financial statements; maintaining fit-and-proper governance and a grievance redressal mechanism; and intimating the RBI of changes in directors or control.
Why hire a Chartered Accountant for NBFC Account Aggregator compliance?
AA compliance sits where finance, regulation, and technology meet, and a Chartered Accountant for NBFC Account Aggregator compliance ties those threads together. A CA monitors and certifies the Net Owned Fund, prepares and files the RBI returns and the Statutory Auditor Certificate, coordinates the IS and cybersecurity audits, and keeps the consent-framework controls, governance, and reporting consistent with the RBI's AA Directions. A specialist CA firm runs this as one connected compliance calendar so the licence stays in good standing rather than being managed form by form.
What returns and audits must an NBFC-AA file with the RBI?
An NBFC-AA files the applicable RBI/DNBS returns online, the annual Statutory Auditor Certificate confirming it continues to meet its registration conditions, and its audited financial statements. On the technology side, it must undergo periodic Information Systems (IS) / system audits covering the consent architecture, data security, and the RBI cybersecurity framework. Corporate filings with the ROC — such as AOC-4 and MGT-7 — and event-based intimations to the RBI for changes in directors or control apply on top of the RBI-AA-specific reporting.

Get a CA for NBFC Account Aggregator Compliance in India

An Account Aggregator licence is a statement of trust, and that trust is maintained one compliance cycle at a time.

Get in Touch