18,000+ Happy Customers

Get Your Payment Gateway / Aggregator Authorisation with eFileSeva | We Help You Do It Right!

Aggregating online payments for merchants is a regulated activity under the Payment and Settlement Systems Act, 2007 — a non-bank that collects and settles customer money must obtain Payment Aggregator (PA) authorisation from the Reserve Bank of India under RBI's PA-PG Master Directions (March 2020, as updated). A valid authorisation requires a company incorporated in India with a minimum net worth of ₹15 crore at application, rising to ₹25 crore by the end of the third financial year, a board-approved policy set, a full merchant KYC framework, an escrow account with a scheduled commercial bank, and PCI-DSS certification with an annual system audit by a CERT-In empanelled auditor. Cross-border aggregators additionally need a separate PA-CB authorisation (with the ₹25 lakh per-transaction cap and enhanced due diligence above ₹2.5 lakh). eFileSeva helps fintechs get authorised legally and compliantly — from eligibility, net-worth structuring and company setup, to the application dossier, the RBI's review, and the post-authorisation compliance engine.

Google Rating 4.9 / 5.0
Trustpilot Rating 4.8 / 5.0

Request a Call Back

100% Secure • No Spam

Key Details for a Payment Aggregator Authorisation

eFileSeva provides complete assistance for PA authorisation — choosing the right category (PA-O, PA-P, PA-CB), structuring the net worth, building the technology and policy framework, preparing and filing the application, and running the post-authorisation compliance engine — across all RBI categories and payment network integrations.

# Topic Details
1 Choose the Right Category Selecting the correct authorisation category is the first step — PA-O (online / e-commerce merchants), PA-P (physical point-of-sale operations), or PA-CB (cross-border import/export collections, separate authorisation under the October 2023 framework). A pure technology payment gateway that never touches funds needs no separate licence but must still meet security and data standards. eFileSeva helps you choose based on your business model.
2 Authorisation Timeline
  • Application preparation & filing: 4–6 weeks
  • RBI (DPSS) review: typically 4–6 months
  • Gap remediation & proof-of-compliance submissions: 2–8 weeks
  • Authorisation issued on RBI's satisfaction — generally 6–12 months overall
3 Authorisation Cost RBI charges no application fee. The cost comprises professional fees and, primarily, the capital requirement — a minimum net worth of ₹15 crore at application, rising to ₹25 crore (typically ₹16–18 crore of total investment), plus PCI-DSS certification, system-audit, and compliance setup costs. eFileSeva provides transparent pricing with no hidden charges.
4 Net Worth Requirements Net worth = paid-up equity capital + free reserves − accumulated losses − deferred revenue expenditure − intangible assets. A new applicant must show ₹15 crore at application and reach ₹25 crore by the end of the third financial year of authorisation; existing PAs were phased to ₹25 crore by March 2023 / March 2025, and the ₹25 crore level must be maintained at all times thereafter.
5 Funds, Escrow & Settlement Every PA must maintain an escrow account with a scheduled commercial bank for aggregated merchant funds, settle to merchants within T+1 (one working day), restrict merchant payout frequency per the guidelines, and never mix its own funds with customer money — with daily nodal reconciliation and 5-year record retention.
6 Key Law & Guidelines Section 4(1) of the Payment and Settlement Systems Act, 2007 (authorisation of payment system operators), RBI's PA-PG Master Directions (March 2020, as updated), the PA-CB circular of 31 October 2023 (cross-border framework), the tokenisation & data-localisation circulars (2018 onwards, CoFT from 1 October 2022), and the RB-IOS 2021 for grievance redressal.
7 Technology & Security Standards PCI-DSS certification (with annual QSA audits) is mandatory for PAs; all payment data must be stored only in India; card data must be tokenised (no raw storage, CoFT mandated); and an annual system audit by a CERT-In empanelled auditor plus the prescribed periodic reporting are required to keep the authorisation live.
8 Post-Authorisation Services After the authorisation, eFileSeva assists with:
  • Escrow, Settlement & Nodal Reconciliation Setup
  • Merchant KYC/AML & Onboarding Framework
  • PCI-DSS & CERT-In System Audit Coordination
  • Tokenisation (CoFT) & Data-Localisation Compliance
  • Network Integration — UPI, Cards, Netbanking, Wallets
  • Periodic RBI Reporting & Grievance (RB-IOS) Setup

*Timelines may vary depending on application completeness, RBI's review cycle, and the readiness of your technology and audit stack.

Payment Aggregator Authorisation in India: Everything You Need to Know

September 1, 2026 Edited by eFileSeva Team

Get Authorised Legally & Compliantly

A Payment Aggregator (PA) is a non-bank entity that collects customer payments on behalf of online merchants, pools them, and settles them to the merchant — holding funds in the process. A Payment Gateway (PG) is the technology layer that encrypts and routes transaction data without ever touching money. Because a PA holds customer funds, it is a payment system operator requiring RBI authorisation under Section 4(1) of the Payment and Settlement Systems Act, 2007 — while a pure PG carries no separate licence but remains bound by RBI's security, tokenisation, and data-localisation requirements.

RBI's PA-PG Master Directions (March 2020, as updated) set the conditions: a company incorporated in India, a minimum net worth of ₹15 crore at the time of application rising to ₹25 crore by the end of the third financial year of authorisation, a fit-and-proper promoter and management, a board-approved policy set (KYC, risk, cyber-security, settlement, grievance), a merchant KYC and AML framework, and one or more escrow accounts with scheduled commercial banks. The application is filed online with RBI's Department of Payment and Settlement Systems (DPSS); RBI reviews the business plan, technology architecture, certification, and controls, raises clarifications, and may require remedial action before granting authorisation.

Ongoing obligations are equally demanding: settlement to merchants within T+1, daily nodal reconciliation with 5-year record retention, PCI-DSS certification with annual audits, an annual system audit by a CERT-In empanelled auditor, tokenisation of card data (no raw storage; CoFT mandated), and storage of all payment data only in India. Cross-border aggregators need a separate PA-CB authorisation under the 31 October 2023 framework — which withdrawn the earlier OPGSP regime, capped per-transaction value at ₹25 lakh, required enhanced due diligence above ₹2.5 lakh, and demanded a net worth of ₹15 crore at application and ₹25 crore by 31 March 2026 for existing players.

eFileSeva helps you assess eligibility, structure the net worth, build the policy and KYC framework, prepare the application and audit trail, navigate the RBI review, and run the post-authorisation compliance engine — making your PA authorisation simple, fast, and fully compliant.

Client
Satisfied Founder

Payment Aggregator Authorisation Client

★★★★★

"eFileSeva made our PA authorisation journey quick, transparent, and stress-free. Their experts built the application, KYC framework and compliance engine professionally and kept us informed throughout."

100% Client Satisfaction
Disclaimer

eFileSeva is a professional corporate compliance consultancy and service provider. We are not the Reserve Bank of India, the Ministry of Corporate Affairs, or the Registrar of Companies and do not grant authorisations or issue payment system certifications. All authorisations, approvals, and acknowledgements are issued solely by the RBI, MCA, ROC, NPCI, and the respective government authorities. Our role is to assist clients with consultation, documentation, application filing, and end-to-end process support.

Routes to a Payments Aggregation Business

Each route into the payments business serves a different model and carries distinct rules. The correct route depends on whether your platform touches funds, whether the flow is domestic or cross-border, and the capital you can commit. eFileSeva helps you identify the correct route and complete the process with expert guidance.

PA-O — Online Aggregator

The e-commerce standard — aggregating online payments (UPI, cards, netbanking) for web and app merchants under the PA-PG Master Directions. The classic route for fintechs and payment companies with ₹15 crore (→ ₹25 crore) net worth.

Learn More

PA-P — Physical Point-of-Sale

The in-store route — aggregating card and UPI payments at physical POS terminals and QR deployments for offline merchants, under the same net-worth and escrow framework with an additional physical-acquiring build-out.

Learn More

PA-CB — Cross-Border Aggregator

The import/export route under the 31 October 2023 framework (which replaced OPGSP) — separate authorisation, ₹15 crore at application (₹25 crore by 31 March 2026 for existing players), a ₹25 lakh per-transaction cap, and enhanced due diligence above ₹2.5 lakh.

Learn More

Pure Technology Gateway (PG)

The technology-only route — routing and encrypting transaction data without touching funds. No separate RBI authorisation, but full compliance with tokenisation (CoFT), data localisation, PCI-DSS, and the annual CERT-In system audit still applies.

Learn More

PPI / Wallet Authorisation

The prepaid route — issuing wallets and prepaid instruments under the PSS Act with a minimum capital of ₹25 crore (₹5 crore for small PPIs). Often combined with a PA business by the same group, but a distinct authorisation with its own KYC and RBI requirements.

Learn More

Bank / Sponsored Partnership

Where a full authorisation is not viable, sponsor-bank partnerships, aggregator-of-aggregators models, or white-labelling an authorised PA let a fintech offer payments — subject to the partner's authorisation, RBI's outsourcing guidance, and the sponsor's ultimate responsibility for the flow.

Learn More

Not Sure Which Authorisation Applies to Your Payments Business?

eFileSeva's experts will help you choose the most suitable route based on your model, fund flow, and net-worth capacity.

Get Free Consultation

Eligibility / Minimum Requirements

Before applying for PA authorisation, you must meet a few basic eligibility and procedural requirements. eFileSeva helps you verify these requirements and complete the authorisation process without delays.

Company Incorporated in India

The applicant must be a company incorporated in India under the Companies Act, 2013 (or 1956) with payment aggregation as part of its objects, and a board and management meeting RBI's fit-and-proper criteria — a clean record with demonstrated payments or financial-sector experience.

Net Worth of ₹15 Crore → ₹25 Crore

A minimum net worth of ₹15 crore must be demonstrated at application (audited/CA-certified), rising to ₹25 crore by the end of the third financial year of authorisation and maintained thereafter. Net worth = paid-up equity capital + free reserves − accumulated losses − deferred revenue expenditure − intangible assets.

Board-Approved Policy & Control Framework

The board must adopt the full policy set — merchant KYC/AML, risk management, cyber-security & IT, settlement, grievance redressal, and business continuity — with a compliance officer, an audit function, and controls that pass RBI's scrutiny of the application.

Merchant KYC & Onboarding Framework

A full merchant KYC and onboarding process — verified identity, business checks, categorisation of merchants, ongoing monitoring, and refusal/wind-down for high-risk categories (per the prohibited-merchant list) — with periodic KYC refresh and record retention.

Escrow Account & T+1 Settlement

One or more escrow accounts with scheduled commercial banks must be opened before onboarding merchants, with settlement to merchants within T+1 (one working day), no mixing of the PA's own funds, and a daily nodal reconciliation with 5-year record retention.

Security, Tokenisation & Data Localisation

PCI-DSS certification (with annual QSA audits) is mandatory; all payment data must be stored only in India; card data must be tokenised with no raw storage (CoFT), and the estate must be ready for the annual system audit by a CERT-In empanelled auditor.

RBI Application & Verification

The application is filed online with RBI's DPSS with the business plan, financials, certifications, and policy set; RBI reviews, raises clarifications, may conduct an on-site review, and may impose conditions in the authorisation — which the applicant must comply with continuously.

Ready to Apply for Your PA Authorisation?

eFileSeva's experts will help you structure the net worth, build the framework, and complete your authorisation quickly and compliantly.

Get Started Today

Documents Required for PA Authorisation

The required documents may vary depending on the category (PA-O, PA-P, PA-CB) and your network integrations. eFileSeva helps you verify and prepare all the necessary documents for a smooth application.

Corporate & Financial Documents
  • Certificate of Incorporation, MOA & AOA (Indian company)
  • Audited financials for the last 3 years & 5-year projections
  • CA-certified net-worth certificate (₹15 crore minimum)
  • Capital structure & funding-source details
  • KYC & fit-and-proper declarations of promoters/directors
Technology & Security Certifications
  • PCI-DSS certification (with the applicable SAQ/AOC)
  • Annual system audit report (CERT-In empanelled auditor)
  • System architecture, UPI/card/network integration details
  • Tokenisation (CoFT) & data-localisation compliance evidence
  • Third-party / outsourced service provider list & agreements
Policies, KYC & Operations
  • Board-approved policy set (KYC/AML, risk, IT security, settlement, grievance)
  • Merchant onboarding & risk-categorisation framework
  • Escrow account details & bank confirmation(s)
  • Business plan & merchant-acquisition strategy
  • Grievance-redressal mechanism & nodal officer details
Application & Post-Authorisation
  • RBI application (online, DPSS) with the prescribed formats
  • Clarifications & gap-remediation submissions to RBI
  • Authorisation letter & conditions-compliance register
  • NPCI membership / network letters & RB-IOS registration
Pro Tip

Decide PA-O / PA-P / PA-CB before drafting — the categories differ in net-worth path and rules, and changing category later needs RBI's prior approval. Build the merchant KYC and prohibited-category screening before the application, not after, and open the escrow account early. Get PCI-DSS and a CERT-In system audit in place with evidence, since RBI's review is decided on the control paper trail. Keep the ₹25 crore net-worth trajectory documented (3-year plan) and settlement at T+1 working in test — RBI checks the operations, not just the documents. For cross-border, remember the ₹25 lakh per-unit cap and the enhanced due diligence above ₹2.5 lakh, and that the PA-CB framework replaced OPGSP in October 2023.

Timeline for PA Authorisation

eFileSeva simplifies the authorisation journey with expert guidance at every stage. While timelines may vary depending on review cycles and stack readiness, the following is a typical path.

Step 1
Eligibility & Net-Worth Structuring

We confirm the category (PA-O / PA-P / PA-CB), validate the founder and board profile, and structure the ₹15 crore (→ ₹25 crore) net worth and funding plan against RBI's Master Directions.

Step 2
Framework, Escrow & Application Filing

We build the policy set, merchant KYC and audit trail, confirm the escrow account and T+1 settlement design, lock PCI-DSS and the CERT-In audit, and file the complete application with RBI's DPSS.

Step 3
RBI Review & Remediation

We manage RBI's review — clarifications, evidence requests, and any gap remediation — and demonstrate the control environment with the data room and docs prepared for the site review.

Step 4
Authorisation & Going Live

RBI issues the authorisation. We then complete the post-conditions, set up periodic reporting, grievance (RB-IOS) registration and the quarterly audit cycle to go live and stay live.

Estimated Authorisation Time

PA authorisation generally takes 6–12 months from a complete application — 4–6 weeks of preparation, typically 4–6 months of RBI review, and 2–8 weeks of remediation depending on queries. Timelines vary with application completeness and the readiness of your certifications and audit stack.

Process to Get PA Authorisation in India

Getting authorised involves more than filing an application. From category selection and net-worth structuring to the policy framework, the RBI review, and the post-authorisation compliance engine, eFileSeva provides complete support at every stage.

01

Category Selection & Eligibility Review

We map your model to PA-O, PA-P, PA-CB or the pure-PG route, review the founder/board fit-and-proper profile, and prepare a net-worth and funding plan that satisfies the ₹15 crore → ₹25 crore trajectory.

Turnaround: 1–2 Weeks
02

Corporate Setup, Escrow & Capital

We ensure the company is incorporated with the right objects, open the escrow account with a scheduled bank, confirm the net worth with a CA certificate, and establish the board, committees and compliance-officer structure.

Turnaround: 3–4 Weeks
03

Policy Framework & Certifications

We draft the board-approved policy set (KYC/AML, risk, IT security, settlement, grievance), implement the merchant KYC and high-risk screening, and coordinate PCI-DSS and the CERT-In system audit with evidence ready for RBI.

Turnaround: 3–5 Weeks
04

Application, Review & Remediation

We file the application with RBI's DPSS, manage clarifications and evidence requests, prepare for any on-site review, and submit the gap-remediation pack — closing every condition RBI raises.

Turnaround: 4–6 Months (RBI review)
05

Authorisation & Ongoing Compliance

On authorisation we complete the post-conditions, register for RB-IOS, integrate with NPCI / card networks, and run the compliance engine — periodic reporting, quarterly audits, tokenisation and data-localisation checks, and the net-worth roadmap.

Turnaround: Ongoing Compliance

Why businesses trust us

18K+

Clients Served

100+

On-time Filing

20+ Yrs

of Expertise

4.8

Google Rating

Chat on WhatsApp +91 000000xxxx

Filings & Registrations Related to a Payment Aggregator

Depending on your category and network integrations, you may need other approvals alongside the authorisation. eFileSeva helps you identify and complete the actions applicable to your company.

Filing / Authorisation When It May Apply Applicable Law / Authority
PA Authorisation (PA-O / PA-P)
Certificate of Authorisation — DPSS
Mandatory before a non-bank commences aggregating online or physical payments, with a minimum net worth of ₹15 crore at application (₹25 crore by the end of the third financial year), an escrow account, and the full policy, KYC and security framework in place. Reserve Bank of India Section 4(1), PSS Act, 2007 & PA-PG Master Directions
PA-CB Authorisation (Cross-Border)
Cross-Border Aggregator Authorisation
Required separately for aggregating import/export online payments, under the framework that replaced OPGSP (October 2023). ₹15 crore net worth at application (₹25 crore by 31 March 2026 / third FY), a ₹25 lakh per-transaction cap, and enhanced due diligence above ₹2.5 lakh. Reserve Bank of India PA-CB Circular, 31 October 2023
Escrow Account & Settlement Framework
Fund Handling & T+1 Settlement
Escrow account(s) with scheduled commercial banks before onboarding merchants, settlement to merchants within T+1, no mixing of the PA's own funds, daily nodal reconciliation with 5-year record retention, and merchant-payout frequency per the guidelines. RBI / Scheduled Banks PA-PG Master Directions
PCI-DSS & Annual System Audit
Security Certification Regime
PCI-DSS certification with annual QSA audits, an annual system audit by a CERT-In empanelled auditor, and tokenisation (CoFT) with no raw card storage — the evidence of security that RBI reviews in the application and at any time thereafter. PCI SSC / CERT-In / RBI RBI Security & Tokenisation Circulars
NPCI / Card Network Integration
UPI & Card Acquiring Membership
Membership and certification for UPI (via NPCI), card acquiring and netbanking with the respective networks, required to route live transactions — each network imposes its own onboarding, certification and fee requirements. NPCI / Card Networks UPI & Card Schemes
RB-IOS Registration & Tax Filings
Grievance Redressal & GST
Registration under the RBI Integrated Ombudsman Scheme (2021) with a nodal grievance officer, plus GST registration — PA/PG fees are taxable at 18% (SAC 998433) — and the standard income-tax and MCA cycle. RBI / CBIC / MCA RB-IOS 2021 & CGST Act, 2017

Payment Aggregator vs Payment Gateway: What's the Difference?

A Payment Aggregator and a Payment Gateway are often confused. The dividing line is who touches the money. Compare the key differences below to identify your correct regulatory status.

Feature Payment Aggregator Payment Gateway
1. Core Function Collects, pools and settles merchant funds collected from customers. Routes and encrypts transaction data between merchant, bank and network.
2. Fund Handling Handles customer and merchant funds in an escrow account. Does not touch funds at any stage.
3. RBI Authorisation Mandatory — PA authorisation from RBI. No separate RBI authorisation, but bound by security, tokenisation and data-localisation requirements.
4. Net Worth ₹15 crore at application; ₹25 crore within three years, maintained thereafter. No statutory net-worth mandate.
5. Escrow Account Must maintain an escrow account with a scheduled commercial bank. Not applicable — no fund flows through the gateway.
6. Settlement Responsible for settlement to merchants within T+1. No settlement responsibility.
7. Merchant KYC Full merchant KYC, risk categorisation and ongoing monitoring. Not directly responsible for merchant KYC.
8. Certification PCI-DSS mandatory with annual QSA audit and CERT-In system audit. PCI-DSS recommended; annual CERT-In audit and data-localisation compliance apply.

Not Sure Whether You're a PA or a PG — or Both?

Get professional guidance from eFileSeva before applying — the classification determines the entire authorisation.

Talk to an Expert

Frequently Asked Questions

Find answers to common questions about PA authorisation and ongoing compliance with eFileSeva.

It depends on whether you touch funds. A pure payment gateway that only routes transaction data does not require a separate RBI authorisation. A payment aggregator that collects, pools and settles merchant money does — under Section 4(1) of the PSS Act, 2007. Most Indian companies offering both find the PA route applies, and the PA authorisation covers the whole operation.

A minimum net worth of ₹15 crore is required at the time of application, rising to ₹25 crore by the end of the third financial year of authorisation and maintained at all times thereafter. Net worth is calculated as paid-up equity capital plus free reserves minus accumulated losses, deferred revenue expenditure and intangible assets.

Yes — mandatory. The escrow account is a designated account with a scheduled commercial bank where aggregated customer funds are pooled before settlement to merchants. The PA's own funds must never be mixed with the escrow, and there must be daily nodal reconciliation with 5-year record retention.

Typically 6–12 months from a complete application: 4–6 weeks of preparation, about 4–6 months of RBI review in the DPSS, and 2–8 weeks of clarification/remediation. Applications with a ready policy set, certifications and audit evidence move significantly faster.

Merchants must be settled within T+1 — one working day of the transaction's authorisation. The PA must also comply with the prescribed merchant payout frequency limits and the blacklist of high-risk merchants, and maintain the daily reconciliation records for five years.

Yes for a payment aggregator — PCI-DSS certification with an annual audit by a QSA is required, and the annual system audit by a CERT-In empanelled auditor is a separate obligation. Tokenisation (CoFT) with no raw card storage and storage of all payment data only in India complete the security stack.

PA-O covers online/e-commerce aggregations, PA-P covers physical point-of-sale acquiring, and PA-CB covers cross-border import/export collections — the last requiring a separate authorisation under the October 2023 framework that replaced OPGSP, with a ₹25 lakh per-transaction cap and enhanced due diligence above ₹2.5 lakh.

Yes — any company incorporated in India with the net worth, governance and technology capabilities can apply, including NBFCs, fintechs and groups with existing financial services. Banks already have payment system status and do not need a separate PA authorisation, but an NBFC aggregating payments does.

Operating a payment system without authorisation is an offence under Section 26 of the PSS Act, 2007 — with monetary penalties and potential imprisonment — and RBI can order the cessation of operations and the refund/wind-down of merchant floats. Authorised PAs that breach conditions face RBI penalties or cancellation of authorisation.

Yes. eFileSeva can assist with category selection, net-worth structuring, corporate and escrow setup, the policy and KYC framework, PCI-DSS and audit coordination, application filing and RBI review management, and the post-authorisation compliance engine — covering your entire authorisation journey.

Still Have Questions?

Talk to the eFileSeva team for guidance on getting your payments business authorised the right way.

Talk to an Expert

Trusted By Fintech Founders, Payment Companies & Investors Across India

From fintech startups and payment companies to NBFCs and banks, business owners trust eFileSeva for PA authorisation and ongoing payments compliance.

10K+

Businesses Assisted

50+

Business Services

25+

States Served

4.8/5

Customer Rating