{"id":955,"date":"2026-08-23T19:57:48","date_gmt":"2026-08-23T19:57:48","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=955"},"modified":"2026-08-23T19:57:48","modified_gmt":"2026-08-23T19:57:48","slug":"payment-aggregator","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/payment-aggregator\/","title":{"rendered":"Payment Aggregator (PA-PG)"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: PAYMENT AGGREGATOR (PA-PG)\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A payment aggregator is a licensed entity that collects money from customers on behalf of merchants and settles it to them, and in India that licence now carries a full security and audit regime.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">India<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A payment aggregator (PA) pools funds from customers and settles them to merchants. Because it touches money, a non-bank payment aggregator needs authorisation from the Reserve Bank of India under the Payment and Settlement Systems Act, 2007. A payment gateway (PG) only routes transaction data and never holds funds, so it sits outside the licence. The pairing &#8220;PA-PG&#8221; comes from the 2020 guidelines, which the RBI replaced on 15 September 2025 with the Master Direction on Regulation of Payment Aggregators.<\/p>\n<\/div>\n\n<p>The distinction matters commercially. One of these two businesses is regulated financial infrastructure with net worth floors, escrow rules and a mandatory annual security audit. The other is software.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">What a payment aggregator is<\/a><\/li>\n    <li><a href=\"#pg\">Payment aggregator and payment gateway<\/a><\/li>\n    <li><a href=\"#cats\">The three categories under the 2025 rules<\/a><\/li>\n    <li><a href=\"#licence\">What the licence requires<\/a><\/li>\n    <li><a href=\"#security\">The security obligations<\/a><\/li>\n    <li><a href=\"#vendor\">If you sell software to a payment aggregator<\/a><\/li>\n    <li><a href=\"#osto\">How Osto gets you audit-ready<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">What a payment aggregator is<\/h2>\n\n<p>A payment aggregator sits between the customer and the merchant. It accepts the payment through whatever channel the customer chose, holds the money briefly, and settles it to the merchant on an agreed cycle. Merchants get to accept cards, UPI, netbanking and wallets without each one negotiating its own arrangement with every bank and network.<\/p>\n\n<p>That pooling step is the whole regulatory trigger. Customer money sits with the aggregator before it reaches the merchant, so the RBI treats the activity as a payment system rather than a technology service.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Money flows from customer to payment aggregator escrow to merchant, while the payment gateway only routes data.\">\n  <defs><marker id=\"paA\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#4a52a8\"\/><\/marker>\n  <marker id=\"paB\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#2f6a89\"\/><\/marker><\/defs>\n\n  <text x=\"14\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#4a52a8\">MONEY<\/text>\n\n  <rect x=\"14\" y=\"40\" width=\"196\" height=\"76\" rx=\"15\" fill=\"#e9ecfa\"\/>\n  <text x=\"112\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#4a52a8\">Customer<\/text>\n  <text x=\"112\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Pays by card, UPI,<\/text>\n  <text x=\"112\" y=\"106\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">netbanking or wallet<\/text>\n\n  <line x1=\"216\" y1=\"78\" x2=\"256\" y2=\"78\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#paA)\"\/>\n\n  <rect x=\"262\" y=\"40\" width=\"216\" height=\"76\" rx=\"15\" fill=\"#1c267a\"\/>\n  <text x=\"370\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">Payment aggregator<\/text>\n  <text x=\"370\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Pools funds in an escrow<\/text>\n  <text x=\"370\" y=\"106\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">account, then settles<\/text>\n\n  <line x1=\"484\" y1=\"78\" x2=\"524\" y2=\"78\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#paA)\"\/>\n\n  <rect x=\"530\" y=\"40\" width=\"216\" height=\"76\" rx=\"15\" fill=\"#e3f0e9\"\/>\n  <text x=\"638\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#3a6f5d\">Merchant<\/text>\n  <text x=\"638\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Receives settlement on<\/text>\n  <text x=\"638\" y=\"106\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">an agreed cycle<\/text>\n\n  <text x=\"14\" y=\"152\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#2f6a89\">DATA ONLY<\/text>\n\n  <rect x=\"262\" y=\"164\" width=\"216\" height=\"60\" rx=\"15\" fill=\"#e2eff7\"\/>\n  <text x=\"370\" y=\"190\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#2f6a89\">Payment gateway<\/text>\n  <text x=\"370\" y=\"209\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Routes the transaction, holds nothing<\/text>\n\n  <line x1=\"484\" y1=\"194\" x2=\"524\" y2=\"194\" stroke=\"#2f6a89\" stroke-width=\"2\" stroke-dasharray=\"5 4\" marker-end=\"url(#paB)\"\/>\n  <text x=\"638\" y=\"190\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"600\" fill=\"#2f6a89\">No licence required<\/text>\n  <text x=\"638\" y=\"208\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Baseline technology standards apply<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Holding customer funds is what pulls an entity inside the licensing perimeter.<\/figcaption>\n<\/figure>\n\n<h2 id=\"pg\" class=\"c-sage\">Payment aggregator and payment gateway<\/h2>\n\n<p>The two terms get used interchangeably in the market and are treated very differently by the regulator.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th><\/th><th>Payment aggregator<\/th><th>Payment gateway<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Handles funds<\/strong><\/td><td>Yes, pooled before settlement<\/td><td>No, data routing only<\/td><\/tr>\n    <tr><td><strong>RBI authorisation<\/strong><\/td><td>Required for non-bank entities<\/td><td>Outside the licensing perimeter<\/td><\/tr>\n    <tr><td><strong>Net worth floor<\/strong><\/td><td>Yes<\/td><td>None<\/td><\/tr>\n    <tr><td><strong>Escrow account<\/strong><\/td><td>Mandatory<\/td><td>Not applicable<\/td><\/tr>\n    <tr><td><strong>Security standards<\/strong><\/td><td>Binding, with an annual audit<\/td><td>Recommended baseline<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"cats\" class=\"c-apri\">The three categories under the 2025 rules<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">PA-Online<\/p>\n    <p class=\"g\">PA-O<\/p>\n    <p>Remote transactions where the customer and the acceptance point are not in proximity. E-commerce, apps, subscription billing.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">PA-Physical<\/p>\n    <p class=\"g\">PA-P<\/p>\n    <p>Proximity transactions where the instrument and the acceptance device are physically together. Point of sale and offline acceptance.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">PA-Cross Border<\/p>\n    <p class=\"g\">PA-CB<\/p>\n    <p>Inward and outward aggregation of cross-border payments, with the added weight of foreign exchange rules on top.<\/p>\n  <\/div>\n<\/div>\n\n<p>Offline acceptance was brought inside the perimeter for the first time. Entities running a physical aggregation business had to apply by 31 December 2025 or wind that business down by 28 February 2026.<\/p>\n\n<h2 id=\"licence\" class=\"c-plum\">What the licence requires<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Requirement<\/th><th>What it means in practice<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Authorisation<\/td><td>Non-bank entities apply to the RBI through the Pravaah portal. Banks run the activity under existing powers and need no separate approval.<\/td><\/tr>\n    <tr><td>Net worth<\/td><td>Fifteen crore rupees at application, rising to twenty-five crore by the end of the third financial year and maintained after that.<\/td><\/tr>\n    <tr><td>Escrow<\/td><td>Customer funds sit in an escrow account with a scheduled commercial bank. Permitted credits and debits are defined, and cash on delivery is excluded.<\/td><\/tr>\n    <tr><td>Merchant onboarding<\/td><td>Customer due diligence on every merchant, ongoing monitoring, merchant identifiers, and a board-approved merchant policy.<\/td><\/tr>\n    <tr><td>Governance<\/td><td>Fit and proper criteria for promoters and directors, and prior intimation to the RBI on changes in control or key personnel.<\/td><\/tr>\n    <tr><td>Reporting<\/td><td>Monthly transaction statistics, quarterly escrow certificates from the auditor and the bank, and an annual net worth certificate.<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"security\" class=\"c-sage\">The security obligations<\/h2>\n\n<p>This is the part that lands on the engineering team rather than the finance team, and it is where most applications stall.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Obligation<\/th><th>Status<\/th><th>What it takes<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Board-approved information security policy<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>A documented policy owned at board level, not a template in a shared drive<\/td><\/tr>\n    <tr><td>Payment card industry data security standard compliance<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Assessment against the card industry standard, with quarterly scanning<\/td><\/tr>\n    <tr><td>Annual system and cyber security audit<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Performed by a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cert-in-empanelment\/\">CERT-In empanelled auditor<\/a> and filed with the RBI<\/td><\/tr>\n    <tr><td>No storage of customer card credentials<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Tokenisation, and the same prohibition passed down to merchants<\/td><\/tr>\n    <tr><td>Incident reporting<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Reporting to the RBI and to CERT-In, which means detection has to be working first<\/td><\/tr>\n    <tr><td>Baseline technology controls<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Access control, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">encryption<\/a>, logging, network segmentation, secure development<\/td><\/tr>\n    <tr><td>Data storage in India<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>Payment data localisation, which also intersects with the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The annual audit is the recurring cost<\/p>\n  <p>A payment aggregator does not clear the security bar once. Every year an empanelled auditor reviews merchant onboarding, escrow controls, payment data handling and the technology baseline, and the report goes to the regulator. Findings left open between cycles become findings the regulator sees.<\/p>\n<\/div>\n\n<h2 id=\"vendor\">If you sell software to a payment aggregator<\/h2>\n\n<p>Most companies meeting these rules are not applying for a licence. They are selling into someone who holds one, and the aggregator&#8217;s obligations arrive as a vendor security review.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>What the aggregator asks you for<\/th><th>Because<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Evidence of a recent penetration test<\/td><td>Their auditor will look at material third parties in the payment flow<\/td><\/tr>\n    <tr><td>Confirmation that you never touch card data<\/td><td>The storage prohibition follows the data, not the entity<\/td><\/tr>\n    <tr><td>Where your data sits, physically<\/td><td>Localisation obligations do not stop at their perimeter<\/td><\/tr>\n    <tr><td>Your incident notification timeline<\/td><td>They have a clock to meet with the RBI and CERT-In and cannot start it late<\/td><\/tr>\n    <tr><td>Access control and logging evidence<\/td><td>The baseline controls are audited, including how vendors reach their systems<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\" class=\"c-plum\">How Osto gets you audit-ready<\/h2>\n\n<p>Osto covers the technical side of the payment aggregator regime by default rather than as an add-on. Expert-led <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> and continuous scanning surface what an empanelled auditor would find, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture management<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API discovery<\/a> close the configuration and endpoint gaps that dominate audit findings, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">correlated logging<\/a> gives you the detection you need before any six-hour reporting clock can start. A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web application firewall<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">multi-factor authentication<\/a> handle the perimeter and access baseline.<\/p>\n\n<p>The evidence layer is purpose-built for exactly this problem. The same control set that answers an RBI auditor also maps to <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-for-startups\/\" target=\"_blank\" rel=\"noopener\">SOC 2<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, so one programme serves the regulator and the enterprise buyer. Osto prepares your evidence and gets you through the review. The mandated audit is performed by the empanelled auditor.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Clear the payment audit before it starts<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto finds and fixes what an empanelled auditor would flag, then holds the evidence. VAPT, cloud posture, code security, logging and compliance in one platform.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Audit-ready in days &middot; RBI, SEBI and DPDP mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is a payment aggregator?<\/summary>\n  <p>An entity that collects payments from customers on behalf of merchants, pools those funds, and settles them to the merchants on an agreed cycle. Because it holds customer money, a non-bank payment aggregator in India needs authorisation from the Reserve Bank of India under the Payment and Settlement Systems Act, 2007.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between a payment aggregator and a payment gateway?<\/summary>\n  <p>A payment aggregator handles the money. A payment gateway provides the technology that routes the transaction and never holds funds. Only the aggregator needs an RBI licence. Gateways sit outside the licensing perimeter and are encouraged, not required, to follow the baseline technology standards.<\/p>\n<\/details>\n\n<details>\n  <summary>What replaced the 2020 payment aggregator and payment gateway guidelines?<\/summary>\n  <p>The Master Direction on Regulation of Payment Aggregators, issued on 15 September 2025. It consolidates and repeals the March 2020 guidelines, the later amendments, and the 2023 cross-border directions into one framework covering online, physical and cross-border aggregation.<\/p>\n<\/details>\n\n<details>\n  <summary>What net worth does a payment aggregator need?<\/summary>\n  <p>Fifteen crore rupees at the point of application, rising to twenty-five crore rupees by the end of the third financial year from authorisation, and maintained at that level afterwards. A statutory auditor certificate confirming net worth goes with the application.<\/p>\n<\/details>\n\n<details>\n  <summary>Who performs the annual payment aggregator security audit?<\/summary>\n  <p>A CERT-In empanelled auditing organisation. The audit covers merchant onboarding, escrow controls, payment data handling and the technology baseline, and the report is submitted to the Reserve Bank of India each year.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> CERT-In Empanelment &middot; VAPT &middot; DPDP Act &middot; Encryption at Rest &middot; SIEM &middot; API Security &middot; ISO 27001<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A payment aggregator is a licensed entity that collects money from customers on behalf of merchants and settles it to\u2026<\/p>\n","protected":false},"author":8,"featured_media":956,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[421,144,422],"class_list":["post-955","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-pa-pg-guidelines","tag-payment-aggregator","tag-payment-aggregator-rbi-licence"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/955","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=955"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/955\/revisions"}],"predecessor-version":[{"id":957,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/955\/revisions\/957"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/956"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=955"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}