A payment aggregator is a licensed entity that collects money from customers on behalf of merchants and settles it to them, and in India that licence now carries a full security and audit regime.
The short answer
A payment aggregator (PA) pools funds from customers and settles them to merchants. Because it touches money, a non-bank payment aggregator needs authorisation from the Reserve Bank of India under the Payment and Settlement Systems Act, 2007. A payment gateway (PG) only routes transaction data and never holds funds, so it sits outside the licence. The pairing “PA-PG” comes from the 2020 guidelines, which the RBI replaced on 15 September 2025 with the Master Direction on Regulation of Payment Aggregators.
The distinction matters commercially. One of these two businesses is regulated financial infrastructure with net worth floors, escrow rules and a mandatory annual security audit. The other is software.
On this page
What a payment aggregator is
A payment aggregator sits between the customer and the merchant. It accepts the payment through whatever channel the customer chose, holds the money briefly, and settles it to the merchant on an agreed cycle. Merchants get to accept cards, UPI, netbanking and wallets without each one negotiating its own arrangement with every bank and network.
That pooling step is the whole regulatory trigger. Customer money sits with the aggregator before it reaches the merchant, so the RBI treats the activity as a payment system rather than a technology service.
Payment aggregator and payment gateway
The two terms get used interchangeably in the market and are treated very differently by the regulator.
| Payment aggregator | Payment gateway | |
|---|---|---|
| Handles funds | Yes, pooled before settlement | No, data routing only |
| RBI authorisation | Required for non-bank entities | Outside the licensing perimeter |
| Net worth floor | Yes | None |
| Escrow account | Mandatory | Not applicable |
| Security standards | Binding, with an annual audit | Recommended baseline |
The three categories under the 2025 rules
PA-Online
PA-O
Remote transactions where the customer and the acceptance point are not in proximity. E-commerce, apps, subscription billing.
PA-Physical
PA-P
Proximity transactions where the instrument and the acceptance device are physically together. Point of sale and offline acceptance.
PA-Cross Border
PA-CB
Inward and outward aggregation of cross-border payments, with the added weight of foreign exchange rules on top.
Offline acceptance was brought inside the perimeter for the first time. Entities running a physical aggregation business had to apply by 31 December 2025 or wind that business down by 28 February 2026.
What the licence requires
| Requirement | What it means in practice |
|---|---|
| Authorisation | Non-bank entities apply to the RBI through the Pravaah portal. Banks run the activity under existing powers and need no separate approval. |
| Net worth | Fifteen crore rupees at application, rising to twenty-five crore by the end of the third financial year and maintained after that. |
| Escrow | Customer funds sit in an escrow account with a scheduled commercial bank. Permitted credits and debits are defined, and cash on delivery is excluded. |
| Merchant onboarding | Customer due diligence on every merchant, ongoing monitoring, merchant identifiers, and a board-approved merchant policy. |
| Governance | Fit and proper criteria for promoters and directors, and prior intimation to the RBI on changes in control or key personnel. |
| Reporting | Monthly transaction statistics, quarterly escrow certificates from the auditor and the bank, and an annual net worth certificate. |
The security obligations
This is the part that lands on the engineering team rather than the finance team, and it is where most applications stall.
| Obligation | Status | What it takes |
|---|---|---|
| Board-approved information security policy | Required | A documented policy owned at board level, not a template in a shared drive |
| Payment card industry data security standard compliance | Required | Assessment against the card industry standard, with quarterly scanning |
| Annual system and cyber security audit | Required | Performed by a CERT-In empanelled auditor and filed with the RBI |
| No storage of customer card credentials | Required | Tokenisation, and the same prohibition passed down to merchants |
| Incident reporting | Required | Reporting to the RBI and to CERT-In, which means detection has to be working first |
| Baseline technology controls | Required | Access control, encryption, logging, network segmentation, secure development |
| Data storage in India | Required | Payment data localisation, which also intersects with the DPDP Act |
The annual audit is the recurring cost
A payment aggregator does not clear the security bar once. Every year an empanelled auditor reviews merchant onboarding, escrow controls, payment data handling and the technology baseline, and the report goes to the regulator. Findings left open between cycles become findings the regulator sees.
If you sell software to a payment aggregator
Most companies meeting these rules are not applying for a licence. They are selling into someone who holds one, and the aggregator’s obligations arrive as a vendor security review.
| What the aggregator asks you for | Because |
|---|---|
| Evidence of a recent penetration test | Their auditor will look at material third parties in the payment flow |
| Confirmation that you never touch card data | The storage prohibition follows the data, not the entity |
| Where your data sits, physically | Localisation obligations do not stop at their perimeter |
| Your incident notification timeline | They have a clock to meet with the RBI and CERT-In and cannot start it late |
| Access control and logging evidence | The baseline controls are audited, including how vendors reach their systems |
How Osto gets you audit-ready
Osto covers the technical side of the payment aggregator regime by default rather than as an add-on. Expert-led VAPT and continuous scanning surface what an empanelled auditor would find, cloud posture management and API discovery close the configuration and endpoint gaps that dominate audit findings, and correlated logging gives you the detection you need before any six-hour reporting clock can start. A web application firewall and multi-factor authentication handle the perimeter and access baseline.
The evidence layer is purpose-built for exactly this problem. The same control set that answers an RBI auditor also maps to SOC 2 and ISO 27001, so one programme serves the regulator and the enterprise buyer. Osto prepares your evidence and gets you through the review. The mandated audit is performed by the empanelled auditor.
Free security assessment
Clear the payment audit before it starts
Osto finds and fixes what an empanelled auditor would flag, then holds the evidence. VAPT, cloud posture, code security, logging and compliance in one platform.
Get a free security assessment Book a platform walkthroughAudit-ready in days · RBI, SEBI and DPDP mapped · One platform, everything
Frequently asked questions
What is a payment aggregator?
An entity that collects payments from customers on behalf of merchants, pools those funds, and settles them to the merchants on an agreed cycle. Because it holds customer money, a non-bank payment aggregator in India needs authorisation from the Reserve Bank of India under the Payment and Settlement Systems Act, 2007.
What is the difference between a payment aggregator and a payment gateway?
A payment aggregator handles the money. A payment gateway provides the technology that routes the transaction and never holds funds. Only the aggregator needs an RBI licence. Gateways sit outside the licensing perimeter and are encouraged, not required, to follow the baseline technology standards.
What replaced the 2020 payment aggregator and payment gateway guidelines?
The Master Direction on Regulation of Payment Aggregators, issued on 15 September 2025. It consolidates and repeals the March 2020 guidelines, the later amendments, and the 2023 cross-border directions into one framework covering online, physical and cross-border aggregation.
What net worth does a payment aggregator need?
Fifteen crore rupees at the point of application, rising to twenty-five crore rupees by the end of the third financial year from authorisation, and maintained at that level afterwards. A statutory auditor certificate confirming net worth goes with the application.
Who performs the annual payment aggregator security audit?
A CERT-In empanelled auditing organisation. The audit covers merchant onboarding, escrow controls, payment data handling and the technology baseline, and the report is submitted to the Reserve Bank of India each year.

