top of page

How to Apply for a Payment Aggregator Licence from the RBI Under the PSS Act

  • Writer: Kaustav Chowdhury
    Kaustav Chowdhury
  • 4 hours ago
  • 6 min read

Introduction

Payment Aggregators (PAs) play a central role in India's digital payments ecosystem by enabling merchants to accept online, physical, and cross-border payments without establishing direct relationships with banks and payment networks. Under the Payment and Settlement Systems Act 2007 (PSS Act), no entity other than the Reserve Bank of India may operate a payment system without authorisation. The RBI first issued comprehensive PA guidelines in March 2020, followed by revisions in June 2022, and most recently consolidated them into the Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025, issued on 15 September 2025.

This guide is for fintech companies, e-commerce platforms, and non-bank entities seeking to apply for a PA licence. It covers eligibility criteria, the application process, net worth thresholds, escrow compliance, KYC obligations, and ongoing regulatory requirements.



Step 1: Confirm Eligibility and Choose Your PA Category

A non-bank entity applying for PA authorisation must be a company incorporated in India under the Companies Act 2013. The Memorandum of Association (MoA) of the applicant must expressly include the proposed activity of operating as a Payment Aggregator.

Under the 2025 Directions, PAs are classified into three sub-categories:

  • PA-Online (PA-O): Facilitates transactions where the acceptance device and payment instrument are not present in proximity at the time of payment (for example, e-commerce checkout).

  • PA-Physical (PA-P): Facilitates proximity-based transactions where both the acceptance device and the payment instrument are physically present.

  • PA-Cross Border (PA-CB): Facilitates aggregation of cross-border payments for current account transactions permissible under FEMA through the e-commerce route.

Entities engaged in cross-border payment aggregation should also be familiar with the FEMA regulatory framework governing authorised persons and the applicable forex dealing requirements.


Step 2: Meet the Net Worth Requirements

Net worth thresholds are a critical eligibility criterion. Under the RBI's PA Directions:

  • At the time of application, the entity must maintain a minimum net worth of Rs 15 crore.

  • Within three years of receiving authorisation, the entity must achieve a net worth of Rs 25 crore.

  • Once the Rs 25 crore threshold is achieved, it must be maintained at all times.

The application must be accompanied by a Net Worth Certificate issued by the statutory auditor confirming compliance. For newly incorporated companies that do not yet have audited financial statements, a Net Worth Certificate along with a provisional balance sheet as on a recent date is acceptable.


Step 3: Submit the Application Through the PRAVAAH Portal

The application for PA authorisation must be submitted through the RBI's online PRAVAAH portal, addressed to the Department of Payment and Settlement Systems (DPSS). The key components include:

  • Completed application form (Form PA) with all stipulated documents

  • Proof of payment of the application fee of Rs 10,000 (plus applicable GST) via electronic transfer

  • Net Worth Certificate from the statutory auditor

  • Certificate of Incorporation and Memorandum of Association (with PA activity expressly stated)

  • Details of directors, promoters, and beneficial owners

  • No Objection Certificate (NOC) from any other financial sector regulator, if the applicant is already regulated

  • Information security and cybersecurity policies

Under Section 7 of the PSS Act 2007, the RBI evaluates the application by considering factors such as the need for the payment system, technical standards and security measures, the applicant's financial status and integrity, and consumer protection mechanisms. The RBI may call upon the applicant to furnish additional documents, provide a security deposit, or pay an authorisation fee.


Step 4: Set Up the Escrow Account

PAs are required to maintain an escrow account with a scheduled commercial bank to hold the funds collected from customers. The escrow framework is central to the RBI's consumer protection objectives:

  • Merchant funds and the PA's own funds must be kept strictly separate.

  • Settlement to merchants must occur no later than T+1 (one banking day after the transaction date).

  • The escrow account cannot be used for Cash-on-Delivery (CoD) transactions.

  • Permitted debits: payments to merchants and service providers, commissions to intermediaries, and payments for promotional activities.

  • Permitted credits: payments from customers, pre-funding by merchants, refunds for failed or cancelled transactions.

  • Daily reconciliation of the escrow balance against collected but unsettled funds is mandatory.


Step 5: Establish KYC and Merchant Onboarding Processes

PAs must perform rigorous Customer Due Diligence (CDD) for every merchant onboarded. This includes:

  • Verification of PAN, CKYCR records, Officially Valid Documents (OVD), and Contact Point Verification

  • Retrieval of the merchant's KYC record from CKYCR with merchant consent

  • Simplified due diligence for small merchants with annual turnover not exceeding Rs 40 lakh (or annual export turnover not exceeding Rs 5 lakh)

  • Ongoing transaction monitoring to ensure consistency with the merchant's declared business profile

Non-bank PAs must also register with the Financial Intelligence Unit India (FIU-IND) and comply with reporting obligations under the Prevention of Money Laundering Act 2002 (PMLA). The RBI has granted PAs an extended timeline until 15 September 2026 to ensure that merchants onboarded up to 31 December 2025 comply with updated due diligence requirements, while merchants onboarded after 1 January 2026 must comply immediately.


Step 6: Implement Cybersecurity and Data Localisation Compliance

The RBI mandates robust information security and technology risk management frameworks for all PAs:

  • Board-approved information security policy is required.

  • PCI-DSS and PA-DSS compliance is mandatory for entities handling card payment data.

  • Annual cybersecurity audits must be conducted by a CERT-In empanelled auditor, with reports submitted to the RBI by 31 May each year.

  • 100% data localisation is required: all payment data must be stored and processed within India. Foreign copies of data must be purged within 24 hours of transaction processing.

  • Security incidents must be reported to the RBI promptly.

These requirements are particularly relevant for entities managing sensitive user data across jurisdictions. Companies should also consider the broader implications of India's data protection enforcement architecture under the DPDP Act 2023 when designing their data handling processes.


Step 7: Comply With Transition Deadlines

The 2025 Directions imposed specific transition timelines that entities must be aware of:

  • Entities carrying on PA-P (physical) business must apply for RBI authorisation by 31 December 2025. Failure to do so requires winding up PA-P operations by 28 February 2026.

  • Entities already authorised as PAs and carrying on PA-P activity must intimate the RBI, which will then issue a revised Certificate of Authorisation (CoA).

  • All non-bank PAs (including those with pending applications) must register with FIU-IND and comply with PMLA reporting obligations without delay.



Common Pitfalls and Mistakes to Avoid

  • Insufficient MoA coverage: If the Memorandum of Association does not expressly mention payment aggregation as a business object, the RBI will reject the application. Ensure the MoA is amended before applying.

  • Underestimating net worth requirements: Many applicants focus only on the Rs 15 crore threshold at application but fail to plan for the Rs 25 crore requirement within three years. Build capital adequacy into your business plan from the outset.

  • Neglecting FIU-IND registration: Operating without FIU-IND registration exposes the PA to penalties under the PMLA. This registration must be completed before or alongside the RBI application.

  • Escrow account mismanagement: Using the escrow account for CoD transactions, co-mingling PA funds with merchant funds, or failing to conduct daily reconciliation can result in regulatory action and potential revocation of the licence.

  • Data localisation non-compliance: Storing payment data outside India or failing to purge foreign data copies within 24 hours is a serious violation. Ensure your technology infrastructure supports full data residency in India before applying.

  • Missing the NOC requirement: If your entity is regulated by SEBI, IRDAI, or another financial sector regulator, you must obtain a No Objection Certificate before applying to the RBI. Overlooking this requirement will delay the application.



Key Takeaways

  • Only companies incorporated in India under the Companies Act 2013 with expressly stated PA activity in their MoA are eligible for authorisation.

  • Minimum net worth is Rs 15 crore at application and Rs 25 crore within three years, maintained at all times thereafter.

  • The 2025 Directions classify PAs into three categories: PA-O (online), PA-P (physical), and PA-CB (cross-border), each with specific compliance requirements.

  • Applications must be filed through the RBI's PRAVAAH portal with supporting documents including the Net Worth Certificate, MoA, and board-approved security policies.

  • Escrow accounts are mandatory, with daily reconciliation and T+1 settlement timelines for merchant payouts.

  • PCI-DSS compliance, annual cyber audits by CERT-In empanelled auditors, and 100% data localisation within India are non-negotiable requirements.

  • FIU-IND registration and PMLA compliance are mandatory for all non-bank PAs.



Conclusion

Obtaining a Payment Aggregator licence from the RBI is a rigorous but navigable process for well-prepared applicants. The consolidated 2025 Directions have streamlined the regulatory framework by unifying previous guidelines into a single reference document, while also introducing the three-tier classification system for PA-O, PA-P, and PA-CB operations. The emphasis on capital adequacy, escrow discipline, cybersecurity, and data localisation reflects the RBI's commitment to ensuring that payment aggregators operate with the same level of prudential rigour expected of financial institutions.

For fintech companies and e-commerce platforms planning to enter or expand in India's payments space, early and thorough preparation is essential. Entities should begin by ensuring corporate structural readiness (MoA amendments, net worth build-up), then move to technology and compliance infrastructure (escrow accounts, PCI-DSS certification, data localisation), and finally submit a well-documented application through PRAVAAH. Companies also exploring branch or liaison office structures in India under FEMA should coordinate their PA licence application with their broader India market entry strategy. Engaging experienced legal and compliance advisors throughout the process is strongly recommended.

Comments


bottom of page