Get Your Payment Gateway / Aggregator Authorisation with eFileSeva | We Help You Do It Right!
Aggregating online payments for merchants is a regulated activity under the Payment and Settlement Systems Act, 2007 — a non-bank that collects and settles customer money must obtain Payment Aggregator (PA) authorisation from the Reserve Bank of India under RBI's PA-PG Master Directions (March 2020, as updated). A valid authorisation requires a company incorporated in India with a minimum net worth of ₹15 crore at application, rising to ₹25 crore by the end of the third financial year, a board-approved policy set, a full merchant KYC framework, an escrow account with a scheduled commercial bank, and PCI-DSS certification with an annual system audit by a CERT-In empanelled auditor. Cross-border aggregators additionally need a separate PA-CB authorisation (with the ₹25 lakh per-transaction cap and enhanced due diligence above ₹2.5 lakh). eFileSeva helps fintechs get authorised legally and compliantly — from eligibility, net-worth structuring and company setup, to the application dossier, the RBI's review, and the post-authorisation compliance engine.
Request a Call Back
Key Details for a Payment Aggregator Authorisation
eFileSeva provides complete assistance for PA authorisation — choosing the right category (PA-O, PA-P, PA-CB), structuring the net worth, building the technology and policy framework, preparing and filing the application, and running the post-authorisation compliance engine — across all RBI categories and payment network integrations.
| # | Topic | Details |
|---|---|---|
| 1 | Choose the Right Category | Selecting the correct authorisation category is the first step — PA-O (online / e-commerce merchants), PA-P (physical point-of-sale operations), or PA-CB (cross-border import/export collections, separate authorisation under the October 2023 framework). A pure technology payment gateway that never touches funds needs no separate licence but must still meet security and data standards. eFileSeva helps you choose based on your business model. |
| 2 | Authorisation Timeline |
|
| 3 | Authorisation Cost | RBI charges no application fee. The cost comprises professional fees and, primarily, the capital requirement — a minimum net worth of ₹15 crore at application, rising to ₹25 crore (typically ₹16–18 crore of total investment), plus PCI-DSS certification, system-audit, and compliance setup costs. eFileSeva provides transparent pricing with no hidden charges. |
| 4 | Net Worth Requirements | Net worth = paid-up equity capital + free reserves − accumulated losses − deferred revenue expenditure − intangible assets. A new applicant must show ₹15 crore at application and reach ₹25 crore by the end of the third financial year of authorisation; existing PAs were phased to ₹25 crore by March 2023 / March 2025, and the ₹25 crore level must be maintained at all times thereafter. |
| 5 | Funds, Escrow & Settlement | Every PA must maintain an escrow account with a scheduled commercial bank for aggregated merchant funds, settle to merchants within T+1 (one working day), restrict merchant payout frequency per the guidelines, and never mix its own funds with customer money — with daily nodal reconciliation and 5-year record retention. |
| 6 | Key Law & Guidelines | Section 4(1) of the Payment and Settlement Systems Act, 2007 (authorisation of payment system operators), RBI's PA-PG Master Directions (March 2020, as updated), the PA-CB circular of 31 October 2023 (cross-border framework), the tokenisation & data-localisation circulars (2018 onwards, CoFT from 1 October 2022), and the RB-IOS 2021 for grievance redressal. |
| 7 | Technology & Security Standards | PCI-DSS certification (with annual QSA audits) is mandatory for PAs; all payment data must be stored only in India; card data must be tokenised (no raw storage, CoFT mandated); and an annual system audit by a CERT-In empanelled auditor plus the prescribed periodic reporting are required to keep the authorisation live. |
| 8 | Post-Authorisation Services |
After the authorisation, eFileSeva assists with:
|
*Timelines may vary depending on application completeness, RBI's review cycle, and the readiness of your technology and audit stack.
Payment Aggregator Authorisation in India: Everything You Need to Know
Get Authorised Legally & Compliantly
A Payment Aggregator (PA) is a non-bank entity that collects customer payments on behalf of online merchants, pools them, and settles them to the merchant — holding funds in the process. A Payment Gateway (PG) is the technology layer that encrypts and routes transaction data without ever touching money. Because a PA holds customer funds, it is a payment system operator requiring RBI authorisation under Section 4(1) of the Payment and Settlement Systems Act, 2007 — while a pure PG carries no separate licence but remains bound by RBI's security, tokenisation, and data-localisation requirements.
RBI's PA-PG Master Directions (March 2020, as updated) set the conditions: a company incorporated in India, a minimum net worth of ₹15 crore at the time of application rising to ₹25 crore by the end of the third financial year of authorisation, a fit-and-proper promoter and management, a board-approved policy set (KYC, risk, cyber-security, settlement, grievance), a merchant KYC and AML framework, and one or more escrow accounts with scheduled commercial banks. The application is filed online with RBI's Department of Payment and Settlement Systems (DPSS); RBI reviews the business plan, technology architecture, certification, and controls, raises clarifications, and may require remedial action before granting authorisation.
Ongoing obligations are equally demanding: settlement to merchants within T+1, daily nodal reconciliation with 5-year record retention, PCI-DSS certification with annual audits, an annual system audit by a CERT-In empanelled auditor, tokenisation of card data (no raw storage; CoFT mandated), and storage of all payment data only in India. Cross-border aggregators need a separate PA-CB authorisation under the 31 October 2023 framework — which withdrawn the earlier OPGSP regime, capped per-transaction value at ₹25 lakh, required enhanced due diligence above ₹2.5 lakh, and demanded a net worth of ₹15 crore at application and ₹25 crore by 31 March 2026 for existing players.
eFileSeva helps you assess eligibility, structure the net worth, build the policy and KYC framework, prepare the application and audit trail, navigate the RBI review, and run the post-authorisation compliance engine — making your PA authorisation simple, fast, and fully compliant.
Satisfied Founder
Payment Aggregator Authorisation Client
"eFileSeva made our PA authorisation journey quick, transparent, and stress-free. Their experts built the application, KYC framework and compliance engine professionally and kept us informed throughout."
100% Client Satisfaction
Disclaimer
eFileSeva is a professional corporate compliance consultancy and service provider. We are not the Reserve Bank of India, the Ministry of Corporate Affairs, or the Registrar of Companies and do not grant authorisations or issue payment system certifications. All authorisations, approvals, and acknowledgements are issued solely by the RBI, MCA, ROC, NPCI, and the respective government authorities. Our role is to assist clients with consultation, documentation, application filing, and end-to-end process support.
Eligibility / Minimum Requirements
Before applying for PA authorisation, you must meet a few basic eligibility and procedural requirements. eFileSeva helps you verify these requirements and complete the authorisation process without delays.
Company Incorporated in India
The applicant must be a company incorporated in India under the Companies Act, 2013 (or 1956) with payment aggregation as part of its objects, and a board and management meeting RBI's fit-and-proper criteria — a clean record with demonstrated payments or financial-sector experience.
Net Worth of ₹15 Crore → ₹25 Crore
A minimum net worth of ₹15 crore must be demonstrated at application (audited/CA-certified), rising to ₹25 crore by the end of the third financial year of authorisation and maintained thereafter. Net worth = paid-up equity capital + free reserves − accumulated losses − deferred revenue expenditure − intangible assets.
Board-Approved Policy & Control Framework
The board must adopt the full policy set — merchant KYC/AML, risk management, cyber-security & IT, settlement, grievance redressal, and business continuity — with a compliance officer, an audit function, and controls that pass RBI's scrutiny of the application.
Merchant KYC & Onboarding Framework
A full merchant KYC and onboarding process — verified identity, business checks, categorisation of merchants, ongoing monitoring, and refusal/wind-down for high-risk categories (per the prohibited-merchant list) — with periodic KYC refresh and record retention.
Escrow Account & T+1 Settlement
One or more escrow accounts with scheduled commercial banks must be opened before onboarding merchants, with settlement to merchants within T+1 (one working day), no mixing of the PA's own funds, and a daily nodal reconciliation with 5-year record retention.
Security, Tokenisation & Data Localisation
PCI-DSS certification (with annual QSA audits) is mandatory; all payment data must be stored only in India; card data must be tokenised with no raw storage (CoFT), and the estate must be ready for the annual system audit by a CERT-In empanelled auditor.
RBI Application & Verification
The application is filed online with RBI's DPSS with the business plan, financials, certifications, and policy set; RBI reviews, raises clarifications, may conduct an on-site review, and may impose conditions in the authorisation — which the applicant must comply with continuously.
Ready to Apply for Your PA Authorisation?
eFileSeva's experts will help you structure the net worth, build the framework, and complete your authorisation quickly and compliantly.
Get Started TodayDocuments Required for PA Authorisation
The required documents may vary depending on the category (PA-O, PA-P, PA-CB) and your network integrations. eFileSeva helps you verify and prepare all the necessary documents for a smooth application.
Corporate & Financial Documents
- Certificate of Incorporation, MOA & AOA (Indian company)
- Audited financials for the last 3 years & 5-year projections
- CA-certified net-worth certificate (₹15 crore minimum)
- Capital structure & funding-source details
- KYC & fit-and-proper declarations of promoters/directors
Technology & Security Certifications
- PCI-DSS certification (with the applicable SAQ/AOC)
- Annual system audit report (CERT-In empanelled auditor)
- System architecture, UPI/card/network integration details
- Tokenisation (CoFT) & data-localisation compliance evidence
- Third-party / outsourced service provider list & agreements
Policies, KYC & Operations
- Board-approved policy set (KYC/AML, risk, IT security, settlement, grievance)
- Merchant onboarding & risk-categorisation framework
- Escrow account details & bank confirmation(s)
- Business plan & merchant-acquisition strategy
- Grievance-redressal mechanism & nodal officer details
Application & Post-Authorisation
- RBI application (online, DPSS) with the prescribed formats
- Clarifications & gap-remediation submissions to RBI
- Authorisation letter & conditions-compliance register
- NPCI membership / network letters & RB-IOS registration
Pro Tip
Decide PA-O / PA-P / PA-CB before drafting — the categories differ in net-worth path and rules, and changing category later needs RBI's prior approval. Build the merchant KYC and prohibited-category screening before the application, not after, and open the escrow account early. Get PCI-DSS and a CERT-In system audit in place with evidence, since RBI's review is decided on the control paper trail. Keep the ₹25 crore net-worth trajectory documented (3-year plan) and settlement at T+1 working in test — RBI checks the operations, not just the documents. For cross-border, remember the ₹25 lakh per-unit cap and the enhanced due diligence above ₹2.5 lakh, and that the PA-CB framework replaced OPGSP in October 2023.
Timeline for PA Authorisation
eFileSeva simplifies the authorisation journey with expert guidance at every stage. While timelines may vary depending on review cycles and stack readiness, the following is a typical path.
Eligibility & Net-Worth Structuring
We confirm the category (PA-O / PA-P / PA-CB), validate the founder and board profile, and structure the ₹15 crore (→ ₹25 crore) net worth and funding plan against RBI's Master Directions.
Framework, Escrow & Application Filing
We build the policy set, merchant KYC and audit trail, confirm the escrow account and T+1 settlement design, lock PCI-DSS and the CERT-In audit, and file the complete application with RBI's DPSS.
RBI Review & Remediation
We manage RBI's review — clarifications, evidence requests, and any gap remediation — and demonstrate the control environment with the data room and docs prepared for the site review.
Authorisation & Going Live
RBI issues the authorisation. We then complete the post-conditions, set up periodic reporting, grievance (RB-IOS) registration and the quarterly audit cycle to go live and stay live.
Estimated Authorisation Time
PA authorisation generally takes 6–12 months from a complete application — 4–6 weeks of preparation, typically 4–6 months of RBI review, and 2–8 weeks of remediation depending on queries. Timelines vary with application completeness and the readiness of your certifications and audit stack.
Process to Get PA Authorisation in India
Getting authorised involves more than filing an application. From category selection and net-worth structuring to the policy framework, the RBI review, and the post-authorisation compliance engine, eFileSeva provides complete support at every stage.
Category Selection & Eligibility Review
We map your model to PA-O, PA-P, PA-CB or the pure-PG route, review the founder/board fit-and-proper profile, and prepare a net-worth and funding plan that satisfies the ₹15 crore → ₹25 crore trajectory.
Corporate Setup, Escrow & Capital
We ensure the company is incorporated with the right objects, open the escrow account with a scheduled bank, confirm the net worth with a CA certificate, and establish the board, committees and compliance-officer structure.
Policy Framework & Certifications
We draft the board-approved policy set (KYC/AML, risk, IT security, settlement, grievance), implement the merchant KYC and high-risk screening, and coordinate PCI-DSS and the CERT-In system audit with evidence ready for RBI.
Application, Review & Remediation
We file the application with RBI's DPSS, manage clarifications and evidence requests, prepare for any on-site review, and submit the gap-remediation pack — closing every condition RBI raises.
Authorisation & Ongoing Compliance
On authorisation we complete the post-conditions, register for RB-IOS, integrate with NPCI / card networks, and run the compliance engine — periodic reporting, quarterly audits, tokenisation and data-localisation checks, and the net-worth roadmap.
Why businesses trust us
18K+
Clients Served
100+
On-time Filing
20+ Yrs
of Expertise
4.8
Google Rating
Filings & Registrations Related to a Payment Aggregator
Depending on your category and network integrations, you may need other approvals alongside the authorisation. eFileSeva helps you identify and complete the actions applicable to your company.
| Filing / Authorisation | When It May Apply | Applicable Law / Authority |
|---|---|---|
PA Authorisation (PA-O / PA-P)Certificate of Authorisation — DPSS |
Mandatory before a non-bank commences aggregating online or physical payments, with a minimum net worth of ₹15 crore at application (₹25 crore by the end of the third financial year), an escrow account, and the full policy, KYC and security framework in place. | Reserve Bank of India Section 4(1), PSS Act, 2007 & PA-PG Master Directions |
PA-CB Authorisation (Cross-Border)Cross-Border Aggregator Authorisation |
Required separately for aggregating import/export online payments, under the framework that replaced OPGSP (October 2023). ₹15 crore net worth at application (₹25 crore by 31 March 2026 / third FY), a ₹25 lakh per-transaction cap, and enhanced due diligence above ₹2.5 lakh. | Reserve Bank of India PA-CB Circular, 31 October 2023 |
Escrow Account & Settlement FrameworkFund Handling & T+1 Settlement |
Escrow account(s) with scheduled commercial banks before onboarding merchants, settlement to merchants within T+1, no mixing of the PA's own funds, daily nodal reconciliation with 5-year record retention, and merchant-payout frequency per the guidelines. | RBI / Scheduled Banks PA-PG Master Directions |
PCI-DSS & Annual System AuditSecurity Certification Regime |
PCI-DSS certification with annual QSA audits, an annual system audit by a CERT-In empanelled auditor, and tokenisation (CoFT) with no raw card storage — the evidence of security that RBI reviews in the application and at any time thereafter. | PCI SSC / CERT-In / RBI RBI Security & Tokenisation Circulars |
NPCI / Card Network IntegrationUPI & Card Acquiring Membership |
Membership and certification for UPI (via NPCI), card acquiring and netbanking with the respective networks, required to route live transactions — each network imposes its own onboarding, certification and fee requirements. | NPCI / Card Networks UPI & Card Schemes |
RB-IOS Registration & Tax FilingsGrievance Redressal & GST |
Registration under the RBI Integrated Ombudsman Scheme (2021) with a nodal grievance officer, plus GST registration — PA/PG fees are taxable at 18% (SAC 998433) — and the standard income-tax and MCA cycle. | RBI / CBIC / MCA RB-IOS 2021 & CGST Act, 2017 |
Payment Aggregator vs Payment Gateway: What's the Difference?
A Payment Aggregator and a Payment Gateway are often confused. The dividing line is who touches the money. Compare the key differences below to identify your correct regulatory status.
| Feature | Payment Aggregator | Payment Gateway |
|---|---|---|
| 1. Core Function | Collects, pools and settles merchant funds collected from customers. | Routes and encrypts transaction data between merchant, bank and network. |
| 2. Fund Handling | Handles customer and merchant funds in an escrow account. | Does not touch funds at any stage. |
| 3. RBI Authorisation | Mandatory — PA authorisation from RBI. | No separate RBI authorisation, but bound by security, tokenisation and data-localisation requirements. |
| 4. Net Worth | ₹15 crore at application; ₹25 crore within three years, maintained thereafter. | No statutory net-worth mandate. |
| 5. Escrow Account | Must maintain an escrow account with a scheduled commercial bank. | Not applicable — no fund flows through the gateway. |
| 6. Settlement | Responsible for settlement to merchants within T+1. | No settlement responsibility. |
| 7. Merchant KYC | Full merchant KYC, risk categorisation and ongoing monitoring. | Not directly responsible for merchant KYC. |
| 8. Certification | PCI-DSS mandatory with annual QSA audit and CERT-In system audit. | PCI-DSS recommended; annual CERT-In audit and data-localisation compliance apply. |
Not Sure Whether You're a PA or a PG — or Both?
Get professional guidance from eFileSeva before applying — the classification determines the entire authorisation.
Talk to an ExpertFrequently Asked Questions
Find answers to common questions about PA authorisation and ongoing compliance with eFileSeva.
Still Have Questions?
Talk to the eFileSeva team for guidance on getting your payments business authorised the right way.
Talk to an ExpertTrusted By Fintech Founders, Payment Companies & Investors Across India
From fintech startups and payment companies to NBFCs and banks, business owners trust eFileSeva for PA authorisation and ongoing payments compliance.
10K+
Businesses Assisted
50+
Business Services
25+
States Served
4.8/5
Customer Rating