An Account Aggregator (AA) is a special type of RBI-licensed NBFC that transfers your financial data from one institution to another only after you give explicit, time-bound, revocable consent. It replaces the old routine of emailing bank statement PDFs or handing over net banking passwords. The AA itself cannot read, store, or sell your data - it is a consent-managed pipe, not a data warehouse. Launched in September 2021, the network had 17 operational AAs, 179 data providers, and 955 data users as of 2026, and had fulfilled over 45 crore consent requests by the time Sahamati published its FY 2025-26 report in June 2026.

Chapter 1

What is the Account Aggregator framework?

The AA framework is India's regulated system for sharing financial data with the customer's consent, built on RBI's Master Direction on NBFC-Account Aggregators dated 2 September 2016. The ecosystem went live on 2 September 2021, which the industry now marks as AA Foundation Day.

The framework sits inside India's larger digital public infrastructure story, alongside Aadhaar and UPI. It implements the Data Empowerment and Protection Architecture (DEPA), a design principle that says your data belongs to you and should move only on your instruction. In June 2026, RBI recognised Sahamati, the industry alliance that coordinates the ecosystem, as a self-regulatory organisation (SRO) for the AA network.

🇮🇳 In India, four financial regulators - RBI, SEBI, IRDAI, and PFRDA - jointly back the AA framework. That is why data from banks, mutual funds, insurers, and pension accounts can all flow through the same consent system.
Chapter 2

How does an Account Aggregator actually work?

You link your financial accounts once inside an AA app, and after that any regulated institution that wants your data must send a consent request through the AA, which you approve or reject on your phone. The flow has four steps:

  1. You download an AA app (examples live in 2026 include Finvu, OneMoney, CAMS Finserv, and Saafe) and link your accounts using your mobile number and an OTP.
  2. A lender, broker, or insurer you are dealing with raises a consent request. The request states what data it wants, for what purpose, for how long, and how often it can fetch it.
  3. You approve the request in the AA app. The data then moves from your bank (the provider) to the requesting institution (the user) in encrypted form.
  4. You can view every active consent in the app and revoke any of them at any time. Once revoked, future fetches stop.

The consent record itself is a machine-readable "consent artefact" that logs the purpose, duration, and frequency, so there is an audit trail of exactly what you agreed to.

Chapter 3

Who are the participants in the AA network?

The network has four roles, all of them regulated entities. Financial Information Providers (FIPs) hold your data: banks, NBFCs, asset management companies, depositories, insurers, insurance repositories, and pension funds. Financial Information Users (FIUs) request your data to offer you a service, and every FIU must be regulated by RBI, SEBI, IRDAI, or PFRDA. Account Aggregators sit in the middle and move the data on consent. Technology Service Providers (TSPs) build the software plumbing for the others.

As of 2026, per Sahamati's public dashboard, the network counted 179 FIPs, 955 FIUs, 17 operational AAs, and 75 TSPs, with over 999 financial entities live in total.

Chapter 4

What data can be shared through an AA?

RBI's master direction defines the categories of "financial information" that can move through the network - commonly cited as 19 categories - covering bank deposit accounts, term and recurring deposits, mutual fund units, insurance policies, and balances under the National Pension System, among others. In practice, bank statement data for lending has been the workhorse use case, with securities and insurance data scaling up behind it.

What the AA cannot do matters just as much. The AA cannot see the contents of the data it transmits (the framework calls this being "data blind"), cannot store it beyond the transfer, and cannot sell it. Your data moves encrypted end to end between the provider and the user.

Chapter 5

Is the Account Aggregator system safe?

The design is safer than the alternatives it replaces, because consent is explicit, purpose-limited, time-bound, and revocable, and because the middleman is licensed by RBI and barred from reading or storing your data. Sharing a bank statement PDF over email or WhatsApp, by contrast, gives the recipient a permanent, uncontrolled copy, and sharing a net banking password gives them everything.

⚠ The consent screen is the control point - read it before tapping approve. Check the duration (a one-time fetch for a loan application is different from daily fetches for a year) and the purpose. Also, no genuine AA flow ever asks for your net banking password or UPI PIN; a request for either is a fraud signal.
Chapter 6

How big is the AA network in 2026?

Adoption has compounded fast. As of February 2026, Sahamati's dashboard reported over 27.2 crore linked accounts, over 40.8 crore consent requests fulfilled, and more than 26.5 crore data shares per month. By the FY 2025-26 annual report released in June 2026, cumulative consents had crossed 45 crore, with over 500 crore data fetches and more than 7 lakh consents processed daily.

Usage has also spread beyond lending. In FY 2025-26 the ecosystem facilitated nearly 3.8 crore financial products and services, verified income for about 67.65 lakh futures and options trading accounts, and supported the issuance of roughly 1.51 lakh life insurance policies. Around 5.96 crore people used AA-powered personal finance management tools, a user base Sahamati says has grown at a 164 percent compound annual rate since FY 2022-23. On the credit side, NPCI Bharat BillPay reported in September 2025 that AA had enabled loans worth about Rs 1.6 lakh crore across more than 1.8 crore loan accounts.

Chapter 7

For the individual, using an AA is typically free - the institution requesting your data pays the AA, not you. Consent is revocable at any time from the AA app, and each consent expires on its own end date even if you do nothing. Linking your accounts to an AA also does not, by itself, share anything; data moves only when you approve a specific request.

Chapter 8

How is AA different from emailing statements or screen scraping?

The old methods gave away control; AA keeps it with you. A PDF sent by email can be stored forever, forwarded, or leaked, and there is no record of what you agreed to. Screen-scraping apps that asked for net banking credentials could see your entire account, not just what was needed. Under AA, the data user gets only the data categories you approved, for the period you approved, with a logged consent artefact, and tampering is harder because data arrives digitally signed from the source institution. That is also why lenders trust AA data more than uploaded PDFs, which can shorten loan processing from days to minutes.

For context on what lenders do with this data, see the guide on credit scores at https://norafi.ai/artha/guides/cibil-score-explained and the digital payments primer at https://norafi.ai/artha/guides/neft-rtgs-imps-upi.

How Nora helps

Nora can explain any consent request in plain language before you approve it - what data is being asked for, by whom, for how long, and how often. If you are comparing loan offers or wondering why a lender wants a year of bank statements, Nora walks you through what the data reveals and what a purpose-limited consent looks like, so the approve button is an informed choice rather than a reflex.

App · coming soon
Chapter 9

What this means for you

The AA framework changes the default from "hand over everything and hope" to "share exactly this, for exactly this long, and see a record of it." Understanding the four-step flow, the role of consent artefacts, and the red flags (anyone asking for passwords) is enough to use the system confidently. The figures above are as of mid-2026 and the network is growing quickly, so the live numbers on Sahamati's public dashboard will be higher by the time you read this.