What is an Account Aggregator?

An Account Aggregator is an RBI licensed NBFC that moves a customer financial data from institutions holding it, called FIPs, to institutions the customer authorises, called FIUs, under a granular, revocable consent. The AA transmits encrypted data it cannot read, store or sell.

Updated 18 August 2026

Key takeaways

  • Consent is purpose bound, time bound and revocable, built on the DEPA consent artefact architecture.
  • Sahamati, recognised by RBI as the ecosystem Self Regulatory Organisation in June 2026, tracks 17 operational AAs and over 2,880 million accounts enabled.
  • Loans worth roughly Rs 1.6 lakh crore across more than 1.8 crore loan accounts had been enabled via AA by mid 2026.
  • NBFCs raised just over 60 percent of all AA consents in FY25, making them the framework heaviest users.

How does the AA data flow work?

The lender, as FIU, raises a consent request. The borrower reviews and approves it, typically with an OTP from their bank. The bank, as FIP, transmits the requested data, encrypted end to end, through the AA to the lender. The AA is data blind by design: it routes ciphertext and keeps an auditable consent trail, nothing more.

For statement analysis, the payload arrives as structured JSON rather than a PDF, which removes the scan quality and format wrangling problems entirely. The consent specifies what data, over what period, for what purpose and until when, and the borrower can revoke it at any time.

How big is the AA ecosystem now?

As of mid 2026, per Sahamati: 17 operational Account Aggregators, 176 FIPs, over a thousand FIUs, more than 2,880 million accounts enabled to share data, and cumulative loans of roughly Rs 1.6 lakh crore across 1.8 crore plus loan accounts enabled through the framework. In FY25, NBFCs accounted for just over 60 percent of consents raised, the largest FIU category. These counters move monthly, so treat any snapshot as dated.

What does AA change for underwriting?

Three things. Authenticity: data arrives from the bank of record, not from a document the borrower could edit, which removes tampering risk for that channel. Freshness: consented pulls can recur through the loan life, enabling monitoring on live data. Friction: no chasing PDFs across eleven accounts. What AA does not change is the analysis problem itself; raw transactions still need categorisation, obligation mapping and conduct reading before they mean anything.

Where this shows up in Fiscus

Fiscus ingests AA delivered JSON natively, applying the same categorisation, fraud checks and analysis as it does to uploaded statements. See bank statement analysis.

Frequently asked questions

Related terms

Read these signals off your own book.

Every term in this glossary is a field in a Fiscus report. Run a parallel evaluation on cases your team has already decided.

Book a demo