Money Clarity

    What is account aggregator in India, and what can it not see?

    The useful answer to what is account aggregator in India is not the definition. It is that the aggregator is the one party in the chain not allowed to keep what it carries. It moves your bank data to whoever asked for it, on a consent you approved, and the rules say that data may not stay with it, may not be used for anything else, and may not be fetched with your password. So the real decision on a consent screen is not whether the pipe is safe. It is whether the recipient named there should have what you are about to send, for as long as the screen says.

    The definition also leaves out coverage. A consent reaches only institutions that have joined the network as providers, and only the kinds of information the rules list. In the household worked through below, with two bank accounts and three credit cards, a consent covering both banks carried 58 of 101 monthly outflows and ₹70,000 of ₹1,14,000. The cards arrived as three lump bill payments with no merchant in them.

    Below: who does what, what a consent contains and how to pull it back, how it compares with handing over a password, what the network misses, and when an app has no reason to ask for it.

    Last reviewed 2026-09-28

    What is account aggregator in India, in one flow

    The technique

    Three parties, one of them a courier

    People picture the aggregator as a company pooling everyone's bank data. The rules describe the opposite: a licensed courier that verifies the recipient, passes the data on and keeps none of it. Confusing the courier with the recipient is why people worry about the wrong party and read the wrong privacy policy.

    The rules are in the Reserve Bank's Master Direction on NBFC account aggregators, published at https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=10598, issued in 2016 and shown there as updated on 6 September 2024. It names three roles.

    The Financial Information Provider, or FIP, holds your data: a bank, an NBFC, a mutual fund company, a depository or participant, an insurer, the NPS record-keeper, the GST network. The Financial Information User, or FIU, wants it, and the direction defines an FIU as an entity registered with and regulated by a financial sector regulator: the Reserve Bank, SEBI, IRDAI, PFRDA or the Department of Revenue. The Account Aggregator, or AA, is an NBFC holding a Reserve Bank certificate for this business and barred from running any other.

    The flow: the FIU asks through an AA, and the AA shows you a consent request. If you approve, the AA presents the consent to the FIP, which checks its validity, the dates and use it covers, and the AA's credentials. The FIP digitally signs the data and sends it on; the AA verifies the FIU's identity before handing it over. Nobody types your net-banking password.

    • The FIU definition matters more than it looks. An app not itself regulated by one of those five bodies cannot be the named recipient in its own name, so if an app offers linking, read the consent screen for which regulated entity actually receives the data
    • The direction says your financial information shall not be the property of the aggregator, and where the aggregator's copy and the bank's books disagree, the bank's record is treated as correct

    Account aggregator consent: what you are signing

    The technique

    The consent artefact is the contract, so read it like one

    Consent screens get approved like cookie banners: a glance at the logo, a tap. But the artefact is the only thing limiting what the recipient gets, and the fields that decide your exposure, range, frequency and expiry, are the ones people skip.

    Paragraph 6.3 of the direction requires a standardised consent artefact containing your identity, the nature of the information requested, the purpose, the recipients, an address to be notified each time the consent is used, the creation and expiry dates, and the AA's digital signature. The screens you see also spell out the date range and how often data may be fetched, which is where the size of a request lives. An illustrative request for a personal loan might read like this.

    One illustrative consent request, line by line
    Purpose
    Loan underwriting
    Recipient
    The named lender, and no one else
    Accounts
    Bank A and Bank B savings accounts
    Information
    Profile, summary, transactions
    Data range
    Last 12 months
    Fetch frequency
    Once
    Consent expires
    When the purpose is served

    Illustrative. Field names differ between aggregator apps; the direction sets the minimum contents, not the wording.

    • Purpose and frequency should agree. A one-time loan decision does not need a daily fetch for a year; if a narrow purpose comes with a long, repeating fetch, decline and ask why
    • Tick only the accounts the purpose needs. The AA may share only what the consent covers, so an unticked account is one the recipient never sees

    Is account aggregator safe? What the rules close

    The technique

    Separate the pipe from the destination

    Safety questions mix two risks: leakage in transit through the aggregator, and misuse by whoever receives the data. The direction deals with the first directly and the second only through the consent terms and the recipient's regulator. Treating them as one gives false comfort in one place and needless fear in the other.

    What the direction closes off: the aggregator may not request or store the credentials that log you in to your bank, such as passwords, PINs or private keys. None of your financial information may reside with it. It may not support transactions, so it cannot move money, and it may share your information only with you or the recipient your consent names. The provider signs what it sends, and each consent has to be capable of being logged, audited and verified.

    What it leaves to you: once delivered, the data sits under the recipient's policy. A consent that asked for twelve months of every account delivered twelve months of every account; a secure pipe does not make the request smaller. Before any first consent, check the aggregator appears on the Reserve Bank's published list of NBFCs registered as account aggregators, since the direction bars anyone from this business without its certificate.

    Account aggregator vs sharing a bank password

    Before the framework, an app wanting your transactions could ask for your net-banking login and read the pages itself. The gap between that and a consent is not one of degree.

    A password carries everything you can do. Its holder sees every account under that login and, with an OTP, can act on them. It has no purpose, no end date and no log you can inspect, and banks' terms generally put the consequences of sharing it on you. Taking it back means changing it everywhere.

    A consent carries only what it names: chosen accounts, a date range, a recipient and an expiry, revocable in part, with each use logged, and no power to move money. The one thing both share is that whatever was delivered stays delivered. The four ways a tracker can get your transactions, set side by side on secrets held and upkeep, are on the page about tracking expenses without a bank login.

    • A password shared once is a standing grant, because nothing in it tells the holder to stop
    • A one-time consent with a short expiry is closer to a sealed envelope than a key

    What the network does not reach

    The technique

    Coverage is decided per institution and per type

    A consent screen shows the accounts it found, which makes the result look complete. But a provider has to have joined the network, and the information has to be a type the direction lists. Accounts failing either test are simply absent, and absence does not announce itself.

    Take one illustrative household for a month: a salary account at Bank A with 40 UPI debits, an EMI, a SIP, an insurance premium, a cash withdrawal and rent by NEFT; a second account at Bank B with 12 UPI debits and a mandate; and three credit cards with 25, 10 and 8 purchases. That is 101 outflows and ₹1,14,000, of which the cards carry ₹44,000: 38.6 percent of the rupees and 42.6 percent of the lines.

    The direction's list of financial information names bank deposit accounts, NBFC deposits, securities, mutual fund units, insurance policies, NPS balances and GST returns among others. It does not name credit card accounts. So assume, as this household finds, that the consent screen shows both banks and none of the cards.

    RouteOutflows seenRupees seenShare of rupees
    AA consent, both banks live58 of 101₹70,00061.4%
    AA consent, only Bank A live45 of 101₹63,70055.9%
    Email alerts, as set up here81 of 101₹1,00,20087.9%
    SMS alerts on Android101 of 101₹1,14,000All
    Statement PDFs101 of 101₹1,14,000All, up to a month late
    AA for banks, alerts for cards101 of 101₹1,14,000All
    Illustrative household. Email assumption: Bank A emails every debit, Bank B emails its mandate debit but sends UPI debits by SMS only, Cards 1 and 2 email every purchase, Card 3 sends SMS only. SMS assumption: every debit on all five accounts sends an SMS to the registered number. Five statements a month means 60 uploads a year.
    • The consent saw ₹44,000 of card spending only as three bill payments leaving the banks: ₹24,000, ₹11,000 and ₹9,000. Forty-three purchases became three lines and every merchant in them vanished
    • If Bank B has not joined as a provider, the same consent drops to 45 lines and ₹63,700, and nothing on the screen says an account is missing
    • Email alerts alone, the route open to an iPhone, saw 23 more outflows than the full consent, because this household puts 38.6 percent of its rupees on cards
    • Every route saw the ₹4,000 cash withdrawal and none saw what the cash bought

    Consent fatigue, and how to pause or revoke

    The framework's protection lives in reading each consent screen, and that is the part that wears out. The first consent gets read. By the fourth, in a year of loan shopping and insurance quotes, approval happens on recognising the logo. That is not carelessness; it is what any safeguard that asks for attention every time turns into.

    A request is easier to judge in lines than in months. This household's two bank accounts produce 61 debit lines a month, counting the three card bill payments. A 12-month range hands over 732 of them before a single salary credit; a 6-month range hands over 366. The extra 366 lines are history the recipient may not need, set by the range field, not the purpose field.

    Three habits keep fatigue from becoming exposure: decide the accounts before the screen appears, so you are unticking rather than reading; treat any fetch frequency other than once as a question; and set a reminder a week after a loan decision to confirm the one-time consent shows as expired or revoked.

    Revocation is written into the direction, not extended as a courtesy. Paragraph 6.6 requires the aggregator to let you revoke a consent, in whole or in part, and paragraph 10 requires it to show you a record of the consents you have given and who received your information. Most aggregator apps also offer a pause, which stops fetches without ending the consent; that is an app feature rather than a right in the direction.

    Go to the aggregator's app or website, not the app that asked, because the consent lives with the aggregator; uninstalling the requesting app ends nothing. Revoke whatever has served its purpose, then read the fetch history to see whether a one-time consent was used more than once. Revoking stops future fetches. It does not delete what was already delivered, which the recipient's own policy and regulator govern.

    If a complaint goes unresolved, the direction requires the aggregator to dispose of it within 1 month and to tell you that you may then appeal to the Reserve Bank; NBFCs covered by the Integrated Ombudsman Scheme of 2021 must also follow that scheme.

    • A household that applies for two loans, gets one insurance quote and keeps one tracking app approves 4 consents in a year. Only one should be active at year end; if the list shows more, 3 one-time consents outlived their purpose
    • A shorter range is almost always worth asking for. A lender that insists on a longer one is telling you how it underwrites, which is useful to know before applying

    When an app does not need account aggregator

    The technique

    Match the route to the job

    The framework answers one question well: is this exactly what the provider holds? That is a lender's question. Someone tracking their own money asks what each rupee was spent on, and the aggregator's answer to that stops at the accounts and types it covers.

    The framework's real strength is authenticity. Because the provider signs what it sends, a lender knows the data has not been edited, which a PDF emailed by the borrower cannot promise. It also pulls history on day one, as far back as the consent range allows. Loan underwriting, where an edited statement is the risk, is the job it fits.

    Tracking your own spending needs card merchant detail, every account including ones off the network, and debits as they happen. The alerts you already receive cover those: this household got every outflow from SMS on Android and 81 of 101 from email alone, with statements filling gaps at a month's lag and 60 uploads a year. How a parser turns one alert into a transaction is shown on the SMS expense tracker page, and what an app with inbox access can see is the subject of the page on connecting Gmail to a finance app.

    So a consent is the right route when someone needs verified data from the source, and one of several when you want to see where your money goes. For that second job, ask whether an app shows your card purchases merchant by merchant. If it cannot, its route is missing the spending you most need to see.

    • Use a consent when the recipient needs verified data: a loan, a credit decision, an application that would otherwise ask for statements
    • Neither route needs your net-banking password. A tracker that asks for it has picked the one route this page argues against

    How Unyfy helps you see every card and account

    The gap this page kept finding was card spending that reaches a bank-only view as one lump bill payment, and accounts a route does not reach at all. Unyfy works from the channels that already carry every line: it reads bank and card transaction emails and, on Android, transactional SMS, and it parses statement PDFs from Axis, HDFC, ICICI, Kotak and Federal Bank. It never asks for your bank password or UPI PIN, and every payment is one you authorise.

    What you see is each card purchase as its own transaction, read from that card's alert, rather than only the single bill payment on your bank account, and UPI debits with the payee handle turned into a merchant name from a database of about 10,000 entries. A debit that arrives as both an SMS and an email is counted once, so the second channel adds coverage without doubling your spending.

    For an account whose bank sends UPI alerts only by SMS, upload its statement and those debits join the ledger. Install Unyfy on Android, or use the web app at app.unyfy.co.in on an iPhone.

    Common questions

    What is account aggregator in India?

    An NBFC licensed by the Reserve Bank to carry your financial data from the institution holding it, such as your bank, to a regulated institution you choose, only against a consent you approve. The consent names the purpose, recipient, information and expiry. Under the Reserve Bank's direction the aggregator may not keep the data, may not ask for your passwords and may not support transactions.

    Is account aggregator safe?

    In transit, largely yes by design: the provider signs the data, the aggregator may not store it or your credentials, and it cannot move money. The larger risk is at the destination, where the recipient's own policy governs, so read who the recipient is and how much history is asked for. Check the aggregator is on the Reserve Bank's list of registered account aggregators.

    What does an account aggregator consent contain?

    The direction requires your identity, the kind of information requested, the purpose, the recipients, an address notified each time the consent is used, creation and expiry dates, and the aggregator's digital signature. Screens also show the date range and fetch frequency, which set the size: 12 months of this page's two bank accounts is 732 debit lines, 6 months is 366.

    How do I revoke account aggregator consent?

    In the aggregator's app or website, not the app that asked for the data. Open the active consents, revoke those whose purpose is served, and check the fetch history. The direction requires the aggregator to let you revoke in whole or in part and to show a record of consents and recipients. Revoking stops future fetches; it does not delete data already delivered.

    Account aggregator vs sharing bank password: which is safer?

    A consent, on every count. A password grants everything you can do in net banking, has no purpose or end date, and sharing it can weaken your position with your bank if something goes wrong. A consent is limited to named accounts, a date range and a recipient, expires, can be revoked, and cannot move money. For tracking, you often need neither.

    Does account aggregator show my credit card spending?

    Do not assume it does. The information types in the Reserve Bank's direction name bank deposits, investments, insurance, NPS and GST returns, but not credit card accounts. In this page's household, a consent covering both banks saw ₹44,000 of card purchases only as three bill payments with no merchants. Card alerts or card statements show the purchases themselves.

    An account aggregator is a licensed courier that may not keep, reuse or act on what it carries, and a consent is a contract with a purpose, a recipient, a range and an expiry that you can read before approving and revoke afterwards. It beats sharing a password on every count. What it does not do is reach every account: in this household it carried 58 of 101 outflows, and the cards arrived as three lumps with no merchants. Use a consent where someone needs verified data from the source; for seeing your own spending, check what a route actually reaches. Informational page, not financial or legal advice. Consent screens, participating institutions and available information types change over time; the Reserve Bank's direction, your consent screen and the recipient's own policy govern, not this page.

    Our Partners

    Banks and NBFCs we compare

    Unyfy compares offers from these lenders and earns a commission if you take one. The comparison is shown first, and it can tell you not to switch.

    HDFC Bank logo
    ICICI Bank logo
    Axis Bank
    State Bank of India logo
    IDFC First Bank logo
    Kotak Mahindra logo
    IndusInd Bank logo
    Yes Bank logo
    Bajaj Finserv logo
    Tata Capital logo