Finance Operations

Open Banking in India: Consent, APIs and Operations

Understand open banking concepts and India’s Account Aggregator framework through consent steps, data roles, operations controls, and a fictional case.

Centaur CareersFinance education editorial team
Illustration of customer-authorized data sharing between financial institutions and an operations review team

Open banking describes ways customers can authorize financial data or services to work across providers through defined digital connections. The exact model, legal roles, and safeguards depend on the country and framework. In India, the RBI-regulated Account Aggregator (AA) framework is one consent-based financial-data-sharing arrangement; it should not be treated as a label for every API, fintech connection, or open-banking model.

The Account Aggregator roles in India

The RBI’s Account Aggregator Directions establish a framework for registered NBFC Account Aggregators. In a typical data-sharing request, a Financial Information User (FIU) seeks specified information for a stated purpose, a customer provides consent through an AA, and a Financial Information Provider (FIP) supplies the information through the framework. A customer chooses whether to participate and what consent to provide. The parties’ exact permissions and responsibilities depend on the current directions and their regulated status.

  1. A customer begins a service journey with a participating FIU.
  2. The FIU requests defined financial information, a purpose, and a time period.
  3. The customer reviews the consent request and chooses whether to approve it through an Account Aggregator.
  4. The FIP responds to the authorized request through the framework; the FIU uses the information for the stated purpose.
  5. The operations teams monitor status, exceptions, consent records, customer questions, and required retention or deletion controls under applicable rules.

What operations teams need to control

  • Purpose and scope: confirm that requested information matches the customer journey and approved use.
  • Consent state: track request, approval, expiry, and withdrawal events accurately.
  • Data integrity: match customer, account, time range, and response identifiers without exposing unnecessary information.
  • Security and access: apply authorized access, transmission safeguards, and audit logging under the relevant framework.
  • Exceptions and complaints: record missing, delayed, incomplete, or disputed responses and route them to the responsible party.
  • Partner handoffs: make ownership and escalation clear across FIU, FIP, and AA participants.

Fictional operations case

A fictional FIU requests six months of account data for a customer who has approved the request. One account responds, while a second has a pending status. The analyst checks the consent record, requested account list, timestamps, and response status; avoids treating the partial response as complete; records the missing item; and routes the exception to the defined team. The analyst does not expand the purpose or ask the customer to approve a different request without the required process.

What this means for analyst careers

Depending on the employer, operations, onboarding, customer support, compliance, and product-operations teams may monitor request status, investigate exceptions, verify consent records, answer process questions, and maintain evidence. Job titles vary. Analysts follow their employer’s current procedures and do not make independent legal interpretations or promise that a data transfer is risk-free.

Explore FinTech and neo-banking operations

Explore digital payment operations roles

Read RBI’s Account Aggregator Directions

Read the Government of India Account Aggregator framework overview

Rules and ecosystem participation can change. Review the current RBI Directions and official government guidance before relying on a regulatory or participation detail. This article is educational and does not provide legal, compliance, investment, or financial advice.

Does open banking mean every bank shares customer data automatically?

No. Data sharing depends on the framework, participating institutions, the customer’s authorization, the requested information, and applicable rules.

Is the Account Aggregator framework the same as every open-banking API?

No. India’s Account Aggregator framework has defined roles and RBI Directions. Other API connections and international open-banking arrangements may follow different models.

Can an operations analyst approve customer consent?

An analyst follows the employer’s approved workflow and authority. The customer’s authorization and the regulated parties’ responsibilities must be handled through the applicable process.

Open BankingAccount AggregatorFinTech OperationsConsentBanking APIs

Continue your finance career journey

Explore the learning tracks and placement support available through Centaur Careers.