Compliance

Payment Aggregator Licensing in India: A Practical Overview

In India, a Payment Aggregator (PA) is a non-bank entity that handles merchant funds in transit before settlement, which is why the Reserve Bank of India (RBI) requires such entities to hold direct authorization rather than operate as unregulated intermediaries. This article gives a general, educational overview of why that oversight exists and what becoming an authorized PA typically involves.

This article is for general educational purposes only and is not legal or regulatory advice. Payment Aggregator licensing requirements are defined and periodically updated by the Reserve Bank of India. Always confirm current requirements from official RBI publications or qualified legal counsel.

Why RBI Regulates Payment Aggregators

Payment Aggregators are non-bank entities that collect payments on behalf of many merchants and briefly hold those funds - typically through a nodal or escrow arrangement - before settling the net amount to each merchant. That fund-holding role, even though temporary, is a financial activity: it creates the potential for misused, commingled, or trapped merchant funds if the entity holding them is poorly governed or under-capitalized.

Because of that risk to merchants and to the broader payment system, RBI chose to bring Payment Aggregators under direct regulatory authorization, rather than treating them purely as technology vendors sitting outside the regulatory perimeter.

A Brief History: The 2020 PA/PG Guidelines

RBI first issued formal guidelines for Payment Aggregators and Payment Gateways in March 2020, establishing Payment Aggregators as a distinct, RBI-authorized category, separate from banks and from pure technology-only Payment Gateways. Since that initial framework, RBI has continued to clarify and update its expectations for the sector through subsequent circulars.

Because those specifics change over time, this article deliberately does not restate particular current net-worth thresholds, application deadlines, or fee figures. Always verify those directly against the latest official RBI publications.

What RBI Guidelines Typically Address

Rather than a single fixed checklist, RBI's PA/PG framework is best understood as a set of areas it typically addresses. In general conceptual terms, these commonly include:

  • Escrow arrangements. Maintaining an escrow account with a bank through which merchant funds flow before settlement, rather than commingling them with the PA's own operating funds.
  • Capital and net-worth expectations. RBI sets expectations around the financial strength of an authorized PA, intended to help it operate safely and absorb operational risk.
  • Governance and security policies. Board-approved policies covering information security, fraud monitoring, and risk management.
  • Merchant due diligence. Standards for verifying and monitoring the merchants a PA onboards, to guard against illegitimate or high-risk businesses entering the payment system.
  • Data storage and security requirements. Expectations for how payment data is stored, protected, and handled.

These are areas RBI guidelines typically address in principle, not a list of current numbers - the specific requirements under each heading are for official RBI publications to define.

A Typical Path to Becoming an Authorized PA

Every organization's journey differs, but the high-level path generally followed by a business seeking PA authorization tends to include:

  1. Readiness assessment. Reviewing the business model, governance structure, and existing capabilities against the areas RBI guidelines typically address.
  2. Documentation. Preparing the policies, board approvals, and supporting material an application typically requires.
  3. Escrow bank arrangement. Establishing the escrow relationship through which merchant funds will flow.
  4. Technology and security audit. Having systems and controls independently reviewed against expected security and operational standards.
  5. Application and RBI review. Submitting the application and working through RBI's review and any follow-up queries.

Specific timelines and document requirements are set by RBI and can change, so they are intentionally not detailed here.

How a Partner Like ZentiqOne Typically Supports This Journey

ZentiqOne is a technology and consulting partner, not a bank, Payment Aggregator, or licensed financial entity, and does not itself hold PA/PG authorization. Where a partner like ZentiqOne typically helps is on the technology and documentation side of the journey: supporting the preparation of technical documentation, designing system architecture aligned to the security and governance expectations RBI guidelines typically address, and coordinating with banking partners on matters such as escrow account arrangements. The regulatory decision and the authorization itself rest entirely with RBI and the applicant organization.

Frequently Asked Questions

What is a Payment Aggregator, and why does RBI regulate it?

A Payment Aggregator is a non-bank entity that collects payments on behalf of multiple merchants and briefly holds those funds before settlement. Because that fund-holding role carries systemic and consumer-protection risk, RBI brings Payment Aggregators under direct authorization rather than leaving them unregulated.

What does RBI's PA/PG framework generally cover?

In general terms, RBI's guidelines address areas such as escrow account arrangements, capital and net-worth expectations, governance and security policies, merchant due-diligence standards, and data storage requirements. Specific current thresholds and figures are periodically revised, so they are not restated here - see the disclaimer above and confirm details against current RBI publications.

Is this legal advice?

No — see the disclaimer above; consult RBI publications or legal counsel for current requirements.

Preparing for Payment Aggregator Authorization?

Schedule a consultation and talk to ZentiqOne about the technology and documentation side of your journey.

Schedule a Consultation