Payment Aggregator (PA-PG)

Payment aggregator fund flow and RBI licensing perimeter

A payment aggregator is a licensed entity that collects money from customers on behalf of merchants and settles it to them, and in India that licence now carries a full security and audit regime.

  • Glossary
  • India

The short answer

A payment aggregator (PA) pools funds from customers and settles them to merchants. Because it touches money, a non-bank payment aggregator needs authorisation from the Reserve Bank of India under the Payment and Settlement Systems Act, 2007. A payment gateway (PG) only routes transaction data and never holds funds, so it sits outside the licence. The pairing “PA-PG” comes from the 2020 guidelines, which the RBI replaced on 15 September 2025 with the Master Direction on Regulation of Payment Aggregators.

The distinction matters commercially. One of these two businesses is regulated financial infrastructure with net worth floors, escrow rules and a mandatory annual security audit. The other is software.

What a payment aggregator is

A payment aggregator sits between the customer and the merchant. It accepts the payment through whatever channel the customer chose, holds the money briefly, and settles it to the merchant on an agreed cycle. Merchants get to accept cards, UPI, netbanking and wallets without each one negotiating its own arrangement with every bank and network.

That pooling step is the whole regulatory trigger. Customer money sits with the aggregator before it reaches the merchant, so the RBI treats the activity as a payment system rather than a technology service.

MONEY Customer Pays by card, UPI, netbanking or wallet Payment aggregator Pools funds in an escrow account, then settles Merchant Receives settlement on an agreed cycle DATA ONLY Payment gateway Routes the transaction, holds nothing No licence required Baseline technology standards apply
Swipe to see the full diagram. Holding customer funds is what pulls an entity inside the licensing perimeter.

Payment aggregator and payment gateway

The two terms get used interchangeably in the market and are treated very differently by the regulator.

Payment aggregatorPayment gateway
Handles fundsYes, pooled before settlementNo, data routing only
RBI authorisationRequired for non-bank entitiesOutside the licensing perimeter
Net worth floorYesNone
Escrow accountMandatoryNot applicable
Security standardsBinding, with an annual auditRecommended baseline

The three categories under the 2025 rules

PA-Online

PA-O

Remote transactions where the customer and the acceptance point are not in proximity. E-commerce, apps, subscription billing.

PA-Physical

PA-P

Proximity transactions where the instrument and the acceptance device are physically together. Point of sale and offline acceptance.

PA-Cross Border

PA-CB

Inward and outward aggregation of cross-border payments, with the added weight of foreign exchange rules on top.

Offline acceptance was brought inside the perimeter for the first time. Entities running a physical aggregation business had to apply by 31 December 2025 or wind that business down by 28 February 2026.

What the licence requires

RequirementWhat it means in practice
AuthorisationNon-bank entities apply to the RBI through the Pravaah portal. Banks run the activity under existing powers and need no separate approval.
Net worthFifteen crore rupees at application, rising to twenty-five crore by the end of the third financial year and maintained after that.
EscrowCustomer funds sit in an escrow account with a scheduled commercial bank. Permitted credits and debits are defined, and cash on delivery is excluded.
Merchant onboardingCustomer due diligence on every merchant, ongoing monitoring, merchant identifiers, and a board-approved merchant policy.
GovernanceFit and proper criteria for promoters and directors, and prior intimation to the RBI on changes in control or key personnel.
ReportingMonthly transaction statistics, quarterly escrow certificates from the auditor and the bank, and an annual net worth certificate.

The security obligations

This is the part that lands on the engineering team rather than the finance team, and it is where most applications stall.

ObligationStatusWhat it takes
Board-approved information security policyRequiredA documented policy owned at board level, not a template in a shared drive
Payment card industry data security standard complianceRequiredAssessment against the card industry standard, with quarterly scanning
Annual system and cyber security auditRequiredPerformed by a CERT-In empanelled auditor and filed with the RBI
No storage of customer card credentialsRequiredTokenisation, and the same prohibition passed down to merchants
Incident reportingRequiredReporting to the RBI and to CERT-In, which means detection has to be working first
Baseline technology controlsRequiredAccess control, encryption, logging, network segmentation, secure development
Data storage in IndiaRequiredPayment data localisation, which also intersects with the DPDP Act

The annual audit is the recurring cost

A payment aggregator does not clear the security bar once. Every year an empanelled auditor reviews merchant onboarding, escrow controls, payment data handling and the technology baseline, and the report goes to the regulator. Findings left open between cycles become findings the regulator sees.

If you sell software to a payment aggregator

Most companies meeting these rules are not applying for a licence. They are selling into someone who holds one, and the aggregator’s obligations arrive as a vendor security review.

What the aggregator asks you forBecause
Evidence of a recent penetration testTheir auditor will look at material third parties in the payment flow
Confirmation that you never touch card dataThe storage prohibition follows the data, not the entity
Where your data sits, physicallyLocalisation obligations do not stop at their perimeter
Your incident notification timelineThey have a clock to meet with the RBI and CERT-In and cannot start it late
Access control and logging evidenceThe baseline controls are audited, including how vendors reach their systems

How Osto gets you audit-ready

Osto covers the technical side of the payment aggregator regime by default rather than as an add-on. Expert-led VAPT and continuous scanning surface what an empanelled auditor would find, cloud posture management and API discovery close the configuration and endpoint gaps that dominate audit findings, and correlated logging gives you the detection you need before any six-hour reporting clock can start. A web application firewall and multi-factor authentication handle the perimeter and access baseline.

The evidence layer is purpose-built for exactly this problem. The same control set that answers an RBI auditor also maps to SOC 2 and ISO 27001, so one programme serves the regulator and the enterprise buyer. Osto prepares your evidence and gets you through the review. The mandated audit is performed by the empanelled auditor.

Free security assessment

Clear the payment audit before it starts

Osto finds and fixes what an empanelled auditor would flag, then holds the evidence. VAPT, cloud posture, code security, logging and compliance in one platform.

Get a free security assessment Book a platform walkthrough

Audit-ready in days · RBI, SEBI and DPDP mapped · One platform, everything

Frequently asked questions

What is a payment aggregator?

An entity that collects payments from customers on behalf of merchants, pools those funds, and settles them to the merchants on an agreed cycle. Because it holds customer money, a non-bank payment aggregator in India needs authorisation from the Reserve Bank of India under the Payment and Settlement Systems Act, 2007.

What is the difference between a payment aggregator and a payment gateway?

A payment aggregator handles the money. A payment gateway provides the technology that routes the transaction and never holds funds. Only the aggregator needs an RBI licence. Gateways sit outside the licensing perimeter and are encouraged, not required, to follow the baseline technology standards.

What replaced the 2020 payment aggregator and payment gateway guidelines?

The Master Direction on Regulation of Payment Aggregators, issued on 15 September 2025. It consolidates and repeals the March 2020 guidelines, the later amendments, and the 2023 cross-border directions into one framework covering online, physical and cross-border aggregation.

What net worth does a payment aggregator need?

Fifteen crore rupees at the point of application, rising to twenty-five crore rupees by the end of the third financial year from authorisation, and maintained at that level afterwards. A statutory auditor certificate confirming net worth goes with the application.

Who performs the annual payment aggregator security audit?

A CERT-In empanelled auditing organisation. The audit covers merchant onboarding, escrow controls, payment data handling and the technology baseline, and the report is submitted to the Reserve Bank of India each year.