The Reserve Bank of India (RBI) has released a detailed framework to regulate Payment Aggregators (PAs), reinforcing governance, financial strength, and consumer protection in the digital payments industry. The new guidelines, effective immediately, require non-bank aggregators to maintain a minimum net worth of Rs. 15 crore at the time of application, rising to Rs. 25 crore within three years. The directives cover online, offline, and cross-border aggregators, mandating strict escrow norms, merchant due diligence, and enhanced cybersecurity measures. By setting clear compliance standards, the RBI aims to curb risks, boost trust, and ensure long-term resilience in India’s fast-growing digital payments sector.
Classification and Scope
The guidelines distinguish between three types of aggregators—PA-Online, PA-Physical, and PA-Cross-Border—each subject to category-specific regulations. Non-bank entities providing aggregator services must seek RBI authorisation, while banks remain exempt since they already operate under existing prudential norms. The move is intended to provide regulatory clarity and align aggregator operations with India’s broader payment infrastructure goals.
Net Worth Requirements
One of the most significant changes lies in capital adequacy norms. Non-bank PAs must demonstrate a net worth of Rs. 15 crore at the time of application and achieve Rs. 25 crore by the end of the third financial year after authorisation. Thereafter, the Rs. 25 crore threshold must be maintained consistently. These requirements are expected to push smaller players toward either capital infusion or consolidation, ensuring that only financially sound firms remain in operation.
Escrow and Fund Management
To safeguard consumer funds, the RBI has mandated that all amounts collected by aggregators on behalf of merchants must be routed through escrow accounts with scheduled commercial banks. Any delays or discrepancies in settlement must be immediately reported. This measure not only improves transparency but also reduces the risk of misappropriation or operational lapses that could harm end-users.
Governance and Compliance Norms
The directives also emphasise stronger corporate governance. Promoters and directors of PAs must meet the RBI’s “fit and proper” criteria, and any change in control requires prompt regulatory notification. In addition, aggregators must establish robust systems for merchant due diligence, verifying credentials at the onboarding stage and monitoring transactions thereafter to detect fraudulent or suspicious activity.
Consumer Protection and Dispute Resolution
To enhance customer confidence, the RBI has required aggregators to develop clear refund and grievance redressal policies approved by their boards. Refunds are to be processed via the original payment method unless the consumer consents otherwise. Disputes must be resolved within a defined timeline, reducing consumer uncertainty in the event of failed or disputed transactions.
Cybersecurity and Data Safeguards
Given rising cyber threats, the rules place heavy emphasis on IT infrastructure and data security. Aggregators must undergo annual audits by CERT-In empanelled cybersecurity auditors, maintain resilient systems to prevent fraud, and ensure that no card details are stored. This focus aligns with India’s broader digital security roadmap as transaction volumes continue to surge.
Implications and Industry Outlook
The new framework is expected to reshape India’s payments ecosystem. Larger, well-capitalised firms may find opportunities to expand market share, while smaller startups could face pressure to merge or seek investment. Merchants and consumers, on the other hand, stand to benefit from greater reliability, quicker settlements, and safer transactions. Over time, the guidelines may also pave the way for tighter cross-border payment oversight, harmonising India’s rules with international standards.
Conclusion
The RBI’s new Master Directions for Payment Aggregators mark a decisive step toward strengthening India’s digital payment infrastructure. By addressing governance, financial soundness, escrow protection, and cybersecurity, the central bank is signalling its commitment to safeguarding consumer interests while supporting innovation. For the industry, compliance will be challenging in the near term, but in the long run, these measures could enhance trust, scale, and stability in one of the world’s fastest-growing digital payment markets.
Comments