FinHub Lending Desk
Credit & underwriting · 21 April 2026 · 9 min read
Last updated 16 August 2026
The Account Aggregator (AA) framework is one of the most consequential pieces of India's digital financial infrastructure, and for lenders it changes something fundamental: how you get a borrower's financial data. Instead of chasing PDF bank statements over email, you can receive verified, consent-driven, tamper-proof data straight from the source. Here's how the framework works and why it matters for credit.
The three roles
The AA ecosystem has three types of participant. A Financial Information Provider (FIP) holds the customer's data — banks, NBFCs, mutual funds, insurers, and, since the framework expanded, tax and GST data providers. A Financial Information User (FIU) consumes that data to provide a service — a lender underwriting a loan is a classic FIU. And in the middle sits the Account Aggregator itself, an RBI-regulated NBFC-AA that moves data from FIP to FIU strictly on the customer's instruction.
The AA is deliberately 'data-blind'
The crucial design choice is that the Account Aggregator cannot see the data it moves. It's data-blind: information passes through it encrypted, and it acts purely as a consent-and-transport layer, not a data store. The AA can't read, use or retain the financial data — it only ensures that the right data flows from the right FIP to the right FIU under a valid consent. That separation is what makes the framework trustworthy for handling sensitive financial information.
Consent as a structured, revocable artefact
Consent in the AA framework isn't a vague checkbox — it's a structured, machine-readable consent artefact built on an open standard. Every consent specifies exactly what data is being shared, for what purpose, for how long, and how often it can be fetched. The customer can see these parameters and can revoke consent at any time. For a lender, this is a step-change from paper mandates: you get granular, auditable, revocable permission that maps directly to the data you actually need — no more, no less.
Why tamper-proof-at-source matters for credit
Data delivered through AA comes signed from the FIP, which means it's authentic and tamper-proof at source. Compare that to an uploaded PDF bank statement, which a borrower could have edited and which you then have to run through forensic tamper-detection. With AA, the anti-tampering guarantee is structural rather than investigative. That reliability is what makes AA data strong enough to underwrite on directly — and it underpins cash-flow-based lending, where you assess a borrower's actual transaction history and repayment capacity rather than relying solely on a bureau score or collateral. For thin-file and new-to-credit customers, that's often the only way to lend responsibly.
Scale and the role of Sahamati
The ecosystem has moved from pilot to production scale, with tens of millions of accounts linked and a rapidly growing volume of loans disbursed on AA-shared data — growth that's been strong year over year as more FIPs come online. Coordinating this multi-party ecosystem is Sahamati, the industry alliance that supports AA participants with standards, tooling and governance (it's the collective body for the ecosystem, not a regulator). For a lender, the practical takeaway is that AA is no longer experimental — it's a mainstream rail worth integrating into your origination flow.
FinHub helps lenders plug into AA-driven data and combine it with bank statement analysis, so consented, source-verified financial data flows straight into your underwriting — with the borrower in control of what's shared.