Back to Blogs

ReBIT’s AA Client Standards: Raising the Bar for Customer Protection in India’s Account Aggregator Ecosystem

July 31, 2026 3 min. Read

On 30 April 2026, ReBIT published the Standards to Enhance Customer Protection and User Experience within the Account Aggregator (AA) Framework (Version 1.0). These standards represent an important milestone in the evolution of the Account Aggregator ecosystem by establishing a common baseline for how customers interact with Account Aggregator services, irrespective of which Financial Information User (FIU) they use or which Account Aggregator (AA) they choose. (api.rebit.org.in)

Purpose of the AA Client Standards

The Account Aggregator ecosystem serves customers across diverse digital journeys. Users may interact with an AA through a mobile app, web interface or embedded SDK, and their level of digital familiarity can vary widely, from self-service tech-aware users to new-to-digital customers assisted by branch staff or relationship managers. While the underlying framework is standardised, the customer experience can differ across implementations. The ReBIT AA Client Standards establish a common baseline for customer protection, security and user experience, ensuring consistency and trust across the ecosystem. 

The AA Client Standards seek to address this by creating a consistent, secure and transparent customer experience across the ecosystem. The objective is to ensure that every consent provided by a customer is informed, secure and trustworthy, while reducing the risk of impersonation, fraud and poor user experience. (api.rebit.org.in)

Applicability of the Standards

The standards are binding on both Account Aggregators (AAs) and Financial Information Users (FIUs) that integrate with an AA Client. They apply to AA client implementations irrespective of whether the customer interacts through:

  • an AA mobile application,
  • an AA web application,
  • an embedded SDK, or
  • another authorised AA Client implementation.

Since many customer journeys originate within an FIU application before redirecting users to the AA Client for consent management, both AAs and FIUs have implementation responsibilities under these standards. 

Key Areas Covered in the AA Client Standards:

  • Standardised consent presentation – The consent screen must display the prescribed consent artefacts and mandatory information to enable customers to make an informed decision.
  • Customer consent interaction – Consent requests must not use pre-selected options or pre-ticked checkboxes, and must provide clear Accept and Reject actions for the customer.
  • Customer journey and redirection – Informing users before redirecting them from an FIU application to the AA Client.
  • AA Client branding and identity – Prominent display of the Account Aggregator’s name, logo and the tagline “RBI Regulated NBFC-AA”.
  • Customer authentication and device security – Implementation of Two-Factor Authentication (2FA), SIM and device binding for mobile applications, and browser fingerprinting for web applications.
  • Customer profile management – Collection of minimum customer information, including name, verified mobile number and email address, with appropriate masking of sensitive data when displayed in self-use consent.
  • Secure handling of downloaded information – Password protection, masking and watermarking of downloaded financial information from AA App.

The Account Aggregator ecosystem is built on customer trust. Every consent, every authentication step and every interaction contributes to that trust. By introducing uniform client-side standards, ReBIT has created a common benchmark that promotes:

  • consistent customer experience across the ecosystem,
  • stronger security against fraud and impersonation,
  • greater transparency during consent journeys,
  • improved privacy protections, and
  • increased confidence in digital financial data sharing.

As adoption of the AA ecosystem continues to expand across sectors, these standards will play a critical role in ensuring that innovation is accompanied by robust customer protection and a predictable, high-quality user experience.

For participants across the ecosystem, the AA Client Standards are not merely a compliance exercise; they represent an important step towards building a more secure, trusted and customer-centric digital financial infrastructure. 

Reference

The complete ReBIT AA Client Standards can be accessed here:

ReBIT – Standards to Enhance Customer Protection and User Experience within the AA Framework (Version 1.0)

FAQs for FIUs adoption and submission on reports to ReBIT can be accessed here.

Share this post