Direct Tax
Consulting
ESG Advisory
Indirect Tax
Growth Advisory
Internal Audit
BFSI Audit
Industry Audit
Valuation
RBI Services
SEBI Services
IRDA Registration
AML Advisory
IBC Services
Recovery of Shares
NBFC Compliance
IRDA Compliance
Finance & Accounts
Payroll Compliance Services
HR Outsourcing
LPO
Fractional CFO
General Legal
Corporate Law
Debt Recovery
Select Your Location
India’s digital payment system is growing rapidly. Now, many businesses are getting involved in online payments, from small startups to large fintech companies. However, collecting payments on behalf of others or settling money with merchants requires more than just good technology. You also need to understand the applicable rules and compliance.
Payment Aggregator (PA) compliance is not just a matter of getting regulatory approval. It involves company structure, financial capacity, merchant due diligence, escrow system, technical security, customer protection, and ongoing compliance.
It is important to clarify that working as a payment aggregator and taking payments for your business using an authorized PA are not the same thing. Not all online businesses require their own PA authorization.
This article will highlight the important compliance issues for new brands before entering the PA ecosystem.
A Payment Aggregator or PA is a system or organization that simplifies the digital payment process between customers and merchants. A merchant can accept various types of digital payments without creating separate integrations with each payment system.
So, a customer makes a payment online. The payment aggregator facilitates that payment process and arranges settlement with the merchant through the applicable mechanism.
Payment Aggregator and Payment Gateway are not the same thing. A payment gateway provides the technical infrastructure to complete the payment. On the other hand, the role of a PA may be related to payment collection and settlement.
So, the first task of any new business should be to understand its business model well. It is important to verify whether the business falls within the regulatory scope of the payment aggregator.
PA compliance is not just about getting regulatory approval. When a payment aggregator is involved in the payment flow of customers and merchants, the security and proper management of funds become very important. A good compliance system also helps in detecting fraud and suspicious transactions.
It strengthens internal governance, reduces operational risk, and makes the business more prepared during an audit or due diligence. In addition, a compliant business can be more trustworthy to both customers and merchants.
It is a good idea to plan PA compliance before starting a payment operation. Having a strong compliance structure from the beginning can reduce regulatory gaps, operational risk, and various future problems. The following checklist highlights the important things for new brands simply.
It is important to have the right legal structure for the business to work as a non-bank payment aggregator. The company should be properly incorporated in India, and the applicable rules of the Companies Act, 2013 should be reviewed.
It is also necessary to see whether the proposed payment activity of the company is properly mentioned in its constitutional documents, especially the Memorandum of Association (MoA). There should also be a clear arrangement regarding ownership, management, and governance structure.
Net worth is an important factor in PA compliance. New businesses should do capital planning from the beginning. It is better to make the necessary financial preparations in advance rather than planning to meet the financial requirement at the time of application.
Minimum net worth at the time of application is ₹15 crore, and required net worth by the end of the third financial year after authorization is ₹25 crore.
Certification by a CA or statutory auditor and relevant financial statements may be required, where applicable. So, it is important to prepare financial documents properly before application. The applicable net-worth requirement may also have to be maintained on an ongoing basis.
Customer payments and the company’s own operational funds should not be managed together or uncontrollably. The applicable RBI escrow requirements and banking arrangements for payment flow should be understood well.
The necessary arrangements should be made with a qualified banking partner. The entire process of fund movement and merchant settlement should be clearly documented. In addition, having a regular reconciliation system helps to identify errors or discrepancies in transactions.
Merchant onboarding is not just about filling out a registration form. The Payment Aggregator should create a systematic process to verify the necessary information about the merchant.
This may include verifying the merchant’s identity, the legitimacy of the business, and relevant ownership and control information. It is also important to understand the merchant providing goods or services. Risk-based due diligence and a system for identifying suspicious or prohibited activity are important parts of compliance.
A good onboarding process can help reduce many potential risks from the start.
Technology and cybersecurity are very important in the payment business. Having a good-looking payment platform is not enough. The backend system also needs to be secure.
The business should look at secure technology architecture, access control, encryption, and secure data transmission. Multi-factor authentication and secure API systems can also be important as needed. Transaction monitoring and vulnerability management systems help to identify potential problems in advance.
A payment platform’s user interface may be very good, but a weak security control can cause financial and reputational damage.
When running a payment business, it is important to know where payment data is stored and processed. It is necessary to review the applicable RBI data storage or localization requirements carefully.
Especially if you use a third-party cloud provider or technology vendor, you should understand the data handling arrangements. It is also important to maintain appropriate access control and security measures. Applicable card security and tokenization standards may need to be followed.
However, it is not right to make a general statement that all types of business data must always be stored only in India.
A key objective of compliance is to prevent misuse of the payment system. So, the new PA needs to have a transaction monitoring and fraud detection system.
There needs to be a clear process for how unusual activity will be detected, how merchant risk will be monitored, and who will take action in the event of a fraud alert.
A new PA should know:
Customer protection is a critical part of a PA’s operating model. There should be a clear system for customer complaints, refunds, disputes, or chargebacks.
Whether the complaint channel is easily accessible, who the responsible person or team is, and what the escalation process is? All these need to be clearly defined. It is also important to keep a record of each complaint and its resolution.
A clear grievance system is not only convenient for the customer but also increases the accountability of the business.
PA compliance is not a one-time filing process. Internal reviews, security assessments, and applicable audits may be required even after business operations have commenced.
Information security assessments, system audits, Vulnerability Assessment and Penetration Testing or VAPT, and other independent reviews may be important in appropriate situations. It is best to keep all compliance-related documents in an organized repository.
A Compliance Repository may contain:
Proper documentation helps ensure that necessary information is available quickly during audits and regulatory reviews.
Incomplete or disorganized documentation can complicate the regulatory process. So, all necessary corporate, financial, governance, and operational documents should be prepared well before the application.
Each document and policy should be reviewed before submitting an application. It is very important that the information and documentation provided to the regulator match the way the company actually operates.
Some common mistakes when starting a new Payment Aggregator business can create compliance and operational problems in the future. For example:
The strongest compliance framework is one that actually works in day-to-day business operations, not just written in a policy document.
Planning a PA business’s compliance journey step by step makes the entire process much easier and more organized. New brands can follow the following roadmap:
Step 1: Assess the Business Model
First, you need to understand whether the business model falls within the PA framework.
Step 2: Establish the Correct Corporate Structure
You need to create an applicable corporate structure and governance system.
Step 3: Plan Capital and Net Worth
You need to plan in advance for the necessary capital and net worth requirements.
Step 4: Build Escrow and Operational Systems
You need to create the right system for fund flow, settlement, and reconciliation.
Step 5: Implement KYC, Security, and Risk Controls
Merchant verification, cybersecurity, and fraud control need to be strengthened.
Step 6: Prepare Documentation and Application
You need to prepare the necessary documents, policies, and application-related information.
Step 7: Maintain Ongoing Compliance
Regular compliance reviews and monitoring should continue even after authorization or operational readiness.
Working with payment regulations requires considering legal, financial, operational, and technology-related issues together. Understanding these requirements can be complex for new businesses. Enterslice can help businesses understand the applicable compliance framework and develop a structured regulatory readiness plan.
Our Services:
The right professional guidance can help new brands understand the various aspects of PA compliance more clearly and take an organized approach.
Payment aggregation is a regulated activity, so proper planning is required from the start. New brands need to first understand whether their business model falls within the PA framework. Then, they need to consider issues such as capital, corporate structure, escrow arrangement, merchant due diligence, technology security, and customer protection together. Compliance doesn’t end with authorization. It’s an ongoing responsibility.
Planning to enter the digital payments ecosystem? Enterslice can help you understand the applicable Payment Aggregator compliance requirements and create a structured roadmap for regulatory readiness. Businesses can build sustainable payment operations while managing regulatory responsibilities more effectively with the right preparation and compliance support. So, contact us today for hassle-free compliance.
Payment Aggregator or PA facilitates the process of collecting payments from the customer and settling money to the merchant. Through this, the merchant can accept various digital payment methods through an integrated arrangement. However, the regulatory treatment of an organization depends on its actual business model and role in the payment flow. So, it is important to first verify whether the business activities fall under the Payment Aggregator framework of RBI.
Yes, a startup or a newly registered company can apply for Payment Aggregator authorization if it meets the applicable conditions. However, it is important to meet the proper corporate structure of the entity and other eligibility requirements of RBI. One of the most important things for a new business is to meet the net worth requirement. So, capital planning, corporate readiness, and necessary compliance measures should be prepared well before the application.
As per RBI's Payment Aggregator framework, a minimum net worth of ₹15 crore may be required at the time of application for authorization for PA business. There is a requirement to increase the net worth to ₹25 crore within a specified period after getting authorization. However, the matter should be verified as per the applicable regulatory conditions. Financial statements, net worth calculation, and necessary certification are also an important part of the application process.
Foreign investment, or FDI, can be used in fintech and payment-related businesses as per applicable laws and policies. However, just getting foreign funding is not enough. The investment should be in line with India's prevailing FDI policy, FEMA provisions, and applicable reporting requirements. In order to meet the net worth requirement, it is important to properly verify the capital structure and regulatory treatment. So, taking professional regulatory advice can be helpful.
In the case of a payment business, data storage and processing is very important. The business needs to review its technology architecture as per the applicable payment data storage requirements of RBI. In some cases, there may be localization requirements for specific payment data. So, if the cloud server is located abroad, it is important to verify whether the entire setup complies with the regulatory requirements. It is not right to assume that the same rules apply to all data.
In the case of PA, the requirements for information security and system audit are determined as per the applicable regulatory framework. In general, it is important to review system security regularly. A security assessment such as a vulnerability assessment and penetration testing, or VAPT, may also be required. Additional security reviews may be required after major infrastructure changes or the launch of a new system. The business should prepare an audit schedule as per the applicable RBI requirements and maintain the necessary documentation.
In the case of merchant fraud or illegal activity, the payment aggregator's responsibility may be determined according to the situation and applicable law. However, effective merchant due diligence and monitoring is very important for PAs. A weak KYC or onboarding process can increase the risk of fraud. So, it is necessary to properly verify the identity, business activity, and risk profile of the merchant. It is also important to have appropriate action and escalation processes in place if suspicious activity is detected.
The timeline for merchant settlement may depend on the payment flow, transaction type, and applicable RBI framework. The payment aggregator should clearly define the settlement process and follow applicable escrow requirements. Customer payments should not be held unnecessarily. Proper reconciliation and fund-flow controls help reduce settlement delays. So, a PA should regularly review applicable settlement timelines and manage its operational system accordingly.
No, funds held through an escrow arrangement generally cannot be used as the PA’s own operational money. The fund flow from this account should be managed in accordance with applicable regulatory requirements. Using payment-related funds for investment, business expenses, or other purposes can create serious compliance risks. A PA should maintain proper separation between operational funds and transaction-related funds and conduct regular reconciliations.
Enterslice can help new businesses understand the regulatory implications of their payment model and assess applicable compliance requirements. We can help with compliance assessment, documentation review, corporate readiness, and policy frameworks. Our expert team also provides assistance with merchant onboarding and risk-management documentation. Professional guidance in developing structured internal controls and compliance practices can help new brands understand complex requirements.
India's digital payment system is growing rapidly. Now, many businesses are getting involved in...
AI is becoming an important part of banking, payments, securities markets, and financial servic...
The RBI has brought a change in the concentration of risk norms for NBFCs involved in infrastru...
The Securities and Exchange Board of India (SEBI) has recently proposed some important changes...
FIU-IND, or Financial Intelligence Unit – India, is an important financial intelligence agenc...
Are you human?: 4 + 3 =
Easy Payment Options Available No Spam. No Sharing. 100% Confidentiality
A Collective Scheme is provided under Section 11AA (2) of the SEBI (The Securities and Exchange Board of India) Act...
16 Jan, 2021
Semi-Closed Wallet Registration with RBI Semi-Closed Wallet Registration - All non-banking entities looking to issu...
05 Jun, 2019