Blog Content Overview
- 1 What counts as a payment aggregator under the 2025 Master Direction?
- 2 Who needs a payment aggregator license in India?
- 3 What are the eligibility criteria for PA and PA-CB authorisation?
- 4 How is PA-CB different from PA-Online and PA-Physical?
- 5 How does the PRAVAAH application process work step by step?
- 6 What escrow, InCA and OCA structure does RBI require?
- 7 What KYC and merchant due diligence obligations apply after authorisation?
- 8 What technology, cyber security and data localisation standards apply to payment aggregators?
- 9 How many entities currently hold PA-CB authorisation?
- 10 Common mistakes that cost payments and cross-border fintechs time and money
- 11 Treelife’s practitioner note
- 12 FAQ’s on RBI Payment Aggregator & PA-CB Authorisation: Eligibility, Application
A payment aggregator license in India is the RBI authorisation that lets a non-bank entity collect, pool and settle customer payments to merchants without a bank in the middle of every transaction. Since 15 September 2025, this runs under a single Master Direction that folds the earlier PA-Online, PA-Physical and PA-Cross Border frameworks into one rulebook. A second Master Direction, issued 15 June 2026, layers general PSO rules on top, covering perpetual validity, cooling-off periods and investment restrictions. Getting this wrong means a returned application, a launch delayed by months, or a business built on an unauthorised payment flow. This article works through eligibility, the PRAVAAH application sequence, net worth thresholds, and the escrow and KYC obligations that follow authorisation.
What is the RBI payment aggregator license and who needs it
A payment aggregator (PA) license is RBI authorisation under Section 4 read with Section 7 of the Payment and Settlement Systems Act, 2007, required by any non-bank entity that collects customer payments and later settles them to merchants, whether for domestic online sales (PA-O), physical point-of-sale acceptance (PA-P), or cross-border import-export transactions (PA-CB) (Master Direction on Regulation of Payment Aggregator, RBI/DPSS/2025-26/141, 15 September 2025).
What counts as a payment aggregator under the 2025 Master Direction?
A payment aggregator is defined as an entity that aggregates payments from customers to merchants through one or more payment channels, and subsequently settles the collected funds to those merchants (Master Direction, 2025, paragraph 4(i)). The definition turns on two facts: does the entity ever hold customer funds before they reach the merchant, and does it have a direct contractual relationship with that merchant.
The Master Direction splits PA business into three categories:
- PA-Online (PA-O): aggregates transactions where the payment instrument and acceptance device are not physically together, essentially e-commerce and app-based collections
- PA-Physical (PA-P): aggregates transactions at physical points of sale, such as POS machines at a retail counter
- PA-Cross Border (PA-CB): aggregates cross-border payments for current account transactions permitted under FEMA, routed through e-commerce, split further into inward and outward sub-categories
A payment gateway (PG), which only provides the technology to route a transaction without ever handling funds, sits outside this Master Direction entirely (paragraph 10(g)). This distinction matters commercially: a lot of “payment infrastructure” pitches from technology vendors are PG arrangements, not PA arrangements, and confusing the two is one of the fastest ways to build a product that later needs an unplanned license.
Cross-border payments moved through three regulatory phases. Before 2010, banks alone processed export-import receipts. Between 2010 and 2023, non-bank Online Payment Gateway Service Providers (OPGSPs) handled these flows through bank-partnered arrangements, with no direct RBI licensing of the OPGSP itself. The October 2023 circular ended that indirect model and brought these entities under direct authorisation as PA-CB, a shift the September 2025 Master Direction carried forward, formally repealing the old OPGSP circulars (Annexure-3, Master Direction, 2025).
Common mistake to flag early: an entity authorised as an AD Category-II facilitating current account transactions that are not purchase or sale of goods or services does not fall within PA-CB (paragraph 4(i)(ii), Note 1). Founders building remittance or forex-only products sometimes assume they need a PA-CB license when the correct authorisation is an AD Category-II license under FEMA.
Who needs a payment aggregator license in India?
Any non-bank entity that holds merchant funds, even momentarily, before settlement needs authorisation. Banks are exempt from separate PA authorisation (paragraph 5(a)), but every non-bank aggregator, marketplace-linked collection entity, and cross-border checkout provider that pools customer money before passing it to a seller needs a Certificate of Authorisation (CoA).
The practical triggers Treelife sees in client conversations:
- A SaaS or content platform that collects subscription payments in INR and pays out to a network of creators or sellers is running PA activity, not merely “payment processing”
- A cross-border e-commerce checkout that lets an Indian buyer pay a US or EU seller in INR, converting and remitting the balance, needs PA-CB authorisation for the outward leg
- An Indian exporter-facing platform that collects export proceeds on behalf of onboarded exporters and remits foreign currency inward needs PA-CB for the inward leg
- A marketplace that only lists the technology and routes payments straight from buyer to seller’s own bank account, with the marketplace never touching the funds, is closer to a PG and should get this structuring reviewed before assuming PA status
A PA business is barred from also running marketplace business (paragraph 10(b)), so a founder running both a marketplace and a collection flow under one entity needs to separate the two structurally before applying.
The core eligibility test has four parts: corporate form, capital, governance fitness, and (for regulated applicants) a no-objection from the sectoral regulator. Two layers of RBI direction now apply together: the PA-specific Master Direction of 15 September 2025 sets eligibility, capital and conduct rules unique to payment aggregators, while the general Master Direction on Authorisation to Operate a Payment System, dated 15 June 2026, applies validity, cooling-off and cross-jurisdiction investment rules common to every RBI-authorised payment system.
Corporate and constitutional requirements:
- The applicant must be a company incorporated in India under the Companies Act, 2013 (Master Direction, paragraph 5(c))
- The Memorandum of Association must expressly cover the proposed PA activity
- An entity already regulated by another financial sector regulator (for instance a NBFC or an intermediary under SEBI) must apply along with a No Objection Certificate from that regulator, within 45 days of obtaining it (paragraph 5(b))
Net worth requirements:
| Requirement | At the time of application | By end of 3rd financial year of authorisation | Ongoing |
|---|---|---|---|
| Minimum net worth | ₹15 crore | ₹25 crore | Must be maintained continuously thereafter |
| Certification | Statutory auditor certificate in the prescribed Annexure 2.1 format | Same certificate, submitted annually by 30 September | Auditor certificate submitted as part of annual reporting |
| Computation basis | Set out in the Master Direction on Authorisation to Operate a Payment System, dated 15 June 2026 (paragraph 4.3), which consolidates and replaces the earlier standalone circular on Computation of Net-worth | Compulsorily convertible preference shares count toward net worth; deferred tax assets, intangible assets and deferred revenue expenditure are deducted | Applies uniformly to PA-O, PA-P and PA-CB |
A newly incorporated entity that has no audited financial statements yet can still apply, but must submit an auditor certificate on current net worth together with a provisional balance sheet as of a recent date (paragraph 6(e)). An application from an entity that does not meet the minimum net worth, or that is incomplete or not in the prescribed form, is simply returned, not queued or held pending (paragraph 5(e)).
Fit and proper criteria for promoters and directors: RBI checks for financial integrity, reputation and honesty, and disqualifies anyone convicted of an economic offence or an offence under RBI-administered law, anyone insolvent and undischarged, anyone restrained by a financial regulator, anyone of unsound mind, or anyone not financially sound (paragraph 7(a)). Directors submit a declaration in the prescribed format, and RBI’s decision on fit-and-proper status is final, with no appeal mechanism in the Direction itself.
Any takeover, acquisition of control, or change in management of a non-bank PA, including one whose application is still pending, needs prior RBI approval under the existing takeover circular (dated 4 July 2022). Founders negotiating a fundraise or secondary sale involving a PA applicant should build this approval into the closing timeline, not treat it as a post-closing formality.
Validity and exit under the June 2026 general framework: a new PA is granted authorisation on a perpetual basis from the date of the CoA, replacing the earlier position where authorisation needed periodic renewal (paragraph 6.1). An existing PA gets perpetual validity at renewal provided it stayed fully compliant with no unresolved regulatory concern; one that does not meet this bar gets one-year renewals until deficiencies clear (paragraphs 6.2 to 6.3). If a PA’s application is refused, or its CoA revoked, not renewed, or voluntarily surrendered, RBI can impose a one-year cooling-off period barring any fresh application, extending even to a new entity set up by the same promoters (paragraph 8.1), though RBI can waive or shorten this on representation (paragraph 8.3).
FEMA and cross-border implication for PA-CB applicants specifically
PA-CB applicants carry an additional layer: the Master Direction is issued jointly under the PSS Act, 2007 and Sections 10(4) and 11(1) of FEMA, 1999, because PA-CB business necessarily involves foreign exchange. This means a PA-CB applicant’s compliance function has to satisfy both RBI’s payment systems supervision and FEMA’s current account transaction rules simultaneously, not sequentially.
How is PA-CB different from PA-Online and PA-Physical?
PA-CB is structurally the most demanding of the three categories because it sits at the intersection of payment systems regulation and foreign exchange control. Three features are unique to it.
Sub-categorisation: PA-CB is split into PA-CB facilitating inward transactions (foreign exchange coming into India, typically export proceeds) and PA-CB facilitating outward transactions (foreign exchange leaving India, typically import payments) (Master Direction, paragraph 4(i)). An applicant can seek authorisation for inward only (PA-CB-I), outward only (PA-CB-E), or both (PA-CB-E&I), and the choice should map to the actual merchant base, not to what looks more impressive on an application.
Transaction value cap: the maximum value per inward or outward transaction processed by a PA-CB is ₹25 lakh (Master Direction, paragraph 11(d)). Platforms with average order values approaching this figure, such as high-ticket B2B export invoicing tools, need to plan for transaction splitting or an alternate settlement route above this threshold.
Foreign currency dealing: a PA-CB cannot purchase or sell foreign currency to or from anyone other than an Authorised Dealer bank (paragraph 11(d)), and settlement in non-INR currencies is permitted only for exporters directly onboarded by the PA-CB handling inward transactions, not for exporters onboarded through an intermediary (paragraph 11(i)).
| Feature | PA-Online | PA-Physical | PA-Cross Border |
|---|---|---|---|
| Transaction type | Card-not-present, e-commerce | Card-present, POS | Cross-border current account transactions via e-commerce |
| Foreign exchange involved | No | No | Yes, inward and/or outward |
| Escrow account type | Domestic escrow account | Same domestic escrow account as PA-O | Separate InCA (inward) and OCA (outward) |
| Per-transaction cap | None prescribed under the Master Direction | None prescribed under the Master Direction | ₹25 lakh |
| Governing law overlap | PSS Act, 2007 | PSS Act, 2007 | PSS Act, 2007 and FEMA, 1999 |
An entity operating both PA-O and PA-P business can use the same escrow account for both (Master Direction, Note (a) to Table 1), but a PA-CB must keep its inward and outward accounts, and its domestic PA escrow account if it runs one, entirely separate, with no co-mingling or netting off permitted under any circumstance (paragraph 11(a) and paragraph 18(d)).
A second route worth knowing before committing to PA-CB: the International Financial Services Centres Authority (IFSCA) issues its own Payment Service Provider (PSP) authorisation at GIFT City under the IFSCA (Payment Services) Regulations, 2024 (Notification No. IFSCA/GN/2024/001, dated 29 January 2024, amended by Notification No. IFSCA/GN/2024/002 dated 2 April 2024), outside RBI’s PA-CB framework, its ₹25 lakh cap, trade-only mandate, and INR-anchored escrow rails. A PSP here can offer account issuance, e-money issuance, escrow and cross-border money transfer services, and must commence operations within 6 months of authorisation. This suits a cross-border fintech whose flows exceed import-export current account transactions or whose ticket sizes regularly exceed the PA-CB cap, though it carries its own IFSCA-specific capital, governance and substance requirements at GIFT City. Treelife’s guide to GIFT City business opportunities covers this route in more detail for teams weighing it against a mainland PA-CB application.
How does the PRAVAAH application process work step by step?
All PA and PA-CB applications, whether fresh or for expanding into an additional PA category, are filed through RBI’s PRAVAAH portal (Platform for Regulatory Application, Validation and AutHorisation), mandatory for all regulatory applications to RBI with effect from 1 May 2025.
The sequence Treelife walks clients through:
- Pre-application readiness check. Confirm corporate structure, MoA object clause, net worth against ₹15 crore, and whether an NOC is needed
- Form A submission. File Form A under Regulation 3(2) of the PSS Regulations, 2008, through PRAVAAH, with the auditor’s net worth certificate, business plan, Board-approved Information Security Policy, dispute management policy, merchant KYC/CDD framework, escrow structuring note, and director declarations
- Application fee. Pay ₹10,000 plus 18% GST electronically to RBI’s DPSS account, and attach proof of payment
- In-principle review. RBI reviews eligibility, net worth and fit-and-proper status, and may issue in-principle approval, not itself authorisation to commence business
- System Audit Report (SAR). A CERT-In empanelled auditor conducts a system audit, including cyber security audit, and submits the SAR to RBI
- Grant of Certificate of Authorisation (CoA). RBI issues the CoA after receiving the SAR, within a citizen’s charter timeline of 30 days (60 if there are subsequent changes in promoters, directors, or fresh investment)
- Escrow account opening. The entity must open the required escrow account, or InCA/OCA for PA-CB, within two months of authorisation
An entity regulated by another financial sector regulator must file its NOC-linked application within 45 days of obtaining that NOC (paragraph 5(b)). Note that the December 2025 and February 2026 deadlines that applied to existing PA-P-only entities transitioning into the new framework have now closed. A founder incorporating and applying today applies fresh under the same eligibility and process, with no transition relief available.
If RBI returns or rejects an application: an aggrieved applicant can appeal the RBI order under Section 9 of the Payment and Settlement Systems Act, 2007, to the Central Government, through the Department of Financial Services, Ministry of Finance. This route sits outside the Master Direction itself and is the applicant’s recourse where the application was not merely returned for a curable defect (paragraph 5(e)) but formally rejected on merits.
What escrow, InCA and OCA structure does RBI require?
Every non-bank PA must hold merchant funds in a separate escrow account with a Scheduled Commercial Bank in India, never mixed with the entity’s own operating funds (Master Direction, paragraph 16(a)). For PA-CB, this escrow structure splits further into an Inward Collection Account (InCA) for inward transactions and an Outward Collection Account (OCA) for outward transactions, each maintained with an Authorised Dealer Category-I bank.
| Feature | Domestic escrow (PA-O/PA-P) | InCA (PA-CB inward) | OCA (PA-CB outward) |
|---|---|---|---|
| Bank | Any Scheduled Commercial Bank | AD Category-I bank | AD Category-I bank |
| Currency | INR | INR and/or each non-INR currency separately | INR |
| Pre-funding | Allowed | Not permitted | Not applicable |
| Additional account | One additional account permitted in a different bank | One additional account per currency permitted | One additional account permitted |
| Timeline to open | Within 2 months of authorisation | Within 2 months of authorisation | Within 2 months of authorisation |
A “core portion” of the domestic escrow account, computed as the average of the lowest fortnightly balances over 26 fortnights, can earn interest once the entity has been in business for 26 fortnights with a fully audited accounting year (paragraph 17). No loan can be raised against this core portion, and banks cannot issue any receipt implying a lien on it. InCA and OCA balances earn no interest at all.
Auditor certificates on escrow, InCA and OCA balances must be submitted quarterly, separately for domestic PA activity and cross-border PA-CB activity, by the 15th of the month following each quarter (Annexures 2.2 and 2.3, Master Direction).
Once authorised, a PA has an ongoing due diligence obligation on every merchant it onboards, run in accordance with RBI’s Master Direction on Know Your Customer (KYC), 2016. The Master Direction adds a specific concession for small merchants: where a merchant’s annual turnover does not exceed ₹40 lakh, or its annual export turnover does not exceed ₹5 lakh, a lighter documentation route (PAN or Form 60 verification, contact point verification, and one officially valid document of the proprietor or authorised signatory) can substitute for full CDD (Master Direction, paragraph 13(b)).
Additional obligations that founders building compliance programmes tend to underweight:
- Retrieve merchant KYC records from the Central KYC Records Registry (CKYCR) with merchant consent during onboarding, before falling back to other verification routes
- Register the non-bank PA itself with the Financial Intelligence Unit-India (FIU-IND) and meet its reporting requirements
- Where a PA contracts with another PA that has already onboarded the merchant, due diligence responsibility sits with the PA that actually onboarded the merchant, not the one settling downstream
- Ensure a marketplace onboarded by the PA does not accept payments on behalf of any seller not itself onboarded on that marketplace
- Merchants onboarded before 31 December 2025 must comply with the new due diligence requirements by 15 September 2026, one year from the Master Direction, a deadline now imminent; merchants onboarded from 1 January 2026 onward must meet the new requirements from day one
For PA-CB specifically, the entity must also provide documents the exporter’s or importer’s AD bank needs to close the corresponding entry in EDPMS or IDPMS (paragraph 11(h)). Missing this is a common operational gap, since it sits outside the PA’s own payment flow and depends on a bank the PA does not control.
What technology, cyber security and data localisation standards apply to payment aggregators?
RBI treats PA authorisation as a technology-intensive licence, not merely a financial one. Annexure 1 sets out baseline technology recommendations, mandatory for PAs, and this is the layer of the application founders most often under-resource, since it reads like an IT checklist rather than a regulatory obligation.
Requirements a PA-CB applicant needs to build into its technology stack before filing:
- Information security governance: a risk assessment of people, IT systems and business processes, with findings presented to the Board via internal audit or a CERT-In empanelled auditor
- Data security standards: PCI-DSS and PCI-SSF, current encryption standards, and transport channel security, reviewed at merchant onboarding, not left to a later audit cycle
- Data sovereignty: data stored outside external jurisdictions with controls against unauthorised access, ruling out an offshore-only cloud region for the core payments database
- IT governance structure: a Board-approved Information Security Policy reviewed annually, an IT Steering Committee, and a Cyber Crisis Management Plan covering detection, containment, response and recovery
- Vendor and outsourcing risk: SLAs must permit regulatory access to vendor set-ups, and outsourcing agreements need a right-to-audit clause or an annual independent security audit report
- Incident reporting: security incidents and data breaches reported to RBI within stipulated timeframes, with monthly cyber incident reports
- Audit cadence: quarterly internal and annual external cyber audits, bi-annual VAPT reports, and PCI-DSS Attestation and Report of Compliance, all before the IT Committee
This sits alongside the annual System Audit Report a CERT-In empanelled auditor submits for CoA issuance, and the broader obligations under RBI’s Master Direction on Cyber Resilience and Digital Payment Security Controls for non-bank PSOs, dated 30 July 2024, expressly incorporated by the 2025 Master Direction (paragraph 9(e)). Treating this as a post-authorisation clean-up item, rather than building it into the application file, is one of the more common reasons a straightforward application stretches past a year.
Reported counts range from 19 (RBI’s own data as of January 2026) to approximately 25 (industry estimates), reflecting the pace of in-principle-to-final conversions rather than any inconsistency in the framework. RBI has no single, continuously updated public page for PA-CB CoAs the way it does for domestic PA-O entities; the authoritative source is RBI’s periodically published status list under the PSS Act, 2007, which a founder should check directly rather than relying on any third-party roster. For a new applicant, the count matters less than the signal: approvals have come in visible waves since 2024, and net worth, fit-and-proper and technology readiness, not queue position, separate an application that clears in one cycle from one stuck in repeated queries.
Common mistakes that cost payments and cross-border fintechs time and money
Treating a payment gateway arrangement as sufficient when the business model is actually PA. The moment an entity’s bank account, even transiently, holds funds destined for a merchant, PG status is no longer available. Operating without authorisation is an offence under Section 26(1) of the PSS Act, 2007, and RBI can impose monetary penalties or compound the contravention under Sections 30 and 31, separately from the practical damage of a bank de-risking the entity once discovered.
Underestimating the net worth glide path. ₹15 crore at application looks manageable for a funded fintech, but ₹25 crore by the end of the third financial year needs to be planned into the cap table and fundraise timeline from day one, not addressed reactively in year three.
Applying for PA-CB-E&I when the actual flow is one-directional. Seeking both inward and outward authorisation when the merchant base only needs one direction adds unnecessary escrow, banking and compliance overhead, since InCA and OCA must be maintained and reported entirely separately regardless of volume.
Missing the takeover approval requirement during a fundraise. A Series A or Series B round that changes control of a PA applicant, without RBI’s prior approval under the 2022 takeover circular, can jeopardise the authorisation itself, and this approval routinely takes longer than commercial teams budget for.
Assuming DPIIT recognition or startup status earns any relaxation. The Master Direction draws no distinction for DPIIT-recognised startups on net worth, fit-and-proper criteria, or application fee. Every applicant clears the same bar.
Founders scoping a payments or cross-border collections product before incorporation should read Treelife’s guide on structuring wealth-tech and fintech entities in India alongside this one, since entity structure decisions taken at incorporation directly affect PA-CB eligibility later.
Treelife’s practitioner note
In the PA and PA-CB engagements Treelife has run, the single most recurring gap is not net worth or documentation, it is founders discovering midway through building their product that their fund flow does not match any single PA category cleanly. A checkout that lets an Indian buyer pay in INR for a subscription billed by an overseas SaaS company usually needs an outward PA-CB structure, but if the same platform also lets Indian creators receive payouts from international brands, that is a second, inward flow requiring separate InCA structuring under paragraph 11(a)’s no-comingling rule. Building the escrow and banking architecture around this distinction before filing, rather than restructuring after RBI queries it, is the difference between a 3 to 4 month timeline and one that stretches well past a year. We flag early to every PA-CB client that the ₹25 lakh cap under paragraph 11(d) is a hard ceiling, not a soft guideline, since we have seen AD Category-I banks reject settlement instructions outright once it is breached.
If your team is deciding whether to route international collections through a licensed PA-CB partner instead of applying independently, Treelife’s note on payment aggregator cross-border considerations for platform incorporation works through that trade-off in more commercial detail.
FAQ’s on RBI Payment Aggregator & PA-CB Authorisation: Eligibility, Application
Q: What is the fastest way to check whether my business needs a payment aggregator license?
A: Ask one question: does your entity ever hold customer funds before they reach the merchant? If yes, you need PA or PA-CB authorisation. If funds move directly from payer to merchant with your entity only routing the instruction, you likely operate as a payment gateway, outside this Master Direction.
Q: How much does it cost to apply for a payment aggregator license in India?
A: The RBI application fee is ₹10,000 plus 18% GST. The larger cost is advisory, legal documentation, information security policy drafting, and the CERT-In empanelled System Audit, together typically several lakhs, separate from the ₹15 crore net worth required.
Q: How long does the entire PA-CB authorisation process take end to end?
A: RBI’s citizen’s charter commits to 30 days from receipt of the System Audit Report for CoA issuance, extending to 60 if there are changes in promoters, directors, or fresh investment. In practice, the full cycle from Form A to CoA runs 4 to 8 months depending on documentation readiness.
Q: What documents does a PA-CB application need?
A: Form A under the PSS Regulations, 2008, the auditor’s net worth certificate, a business plan, Board-approved Information Security Policy, dispute management framework, merchant KYC/CDD policy, director declarations, and, where applicable, an NOC from any other financial sector regulator.
Q: Does a PA-CB license cover FEMA compliance automatically, or is separate FEMA approval needed?
A: The Master Direction is issued under both the PSS Act, 2007 and FEMA, 1999, so a PA-CB CoA is the operative authorisation for cross-border payment activity. It does not replace the AD bank’s own FEMA checks, EDPMS/IDPMS closure, or current account transaction restrictions.
Q: Can two co-founders’ separate entities jointly hold or share one PA-CB license?
A: No. RBI discourages the same payment system being operated across multiple companies within a corporate group, and a PA-CB CoA is issued to one incorporated entity. Groups running related payment flows across sister entities must consolidate the activity in one entity or apply separately.
Q: Is there any relaxation for DPIIT-recognised startups on net worth or fees?
A: No. The Master Direction applies the same ₹15 crore at application, ₹25 crore by year three, fit-and-proper criteria, and fee regardless of DPIIT recognition or funding stage.
Q: What happens if a PA-CB application is rejected or returned?
A: An application short of the minimum net worth, or incomplete, is returned outright under paragraph 5(e) and can be refiled once cured. Where RBI rejects an application on merits, the applicant can appeal to the Central Government under Section 9 of the PSS Act, 2007, and separately faces a possible one-year cooling-off period barring any fresh payment system application, including by a new entity set up by the same promoters (paragraph 8.1, June 2026 Master Direction).
Q: What happens to a PA’s authorisation if the company is acquired or its promoters change?
A: Any takeover, acquisition of control, or management change requires prior RBI approval under the July 2022 takeover circular, applicable even while a CoA application is pending. Proceeding without approval risks the authorisation itself.
Q: Can a foreign-owned entity apply for a PA-CB license in India?
A: Yes, subject to the Consolidated FDI Policy and applicable FEMA regulations (paragraph 6(d)). One added restriction now applies across all payment system authorisations: fresh investment from a FATF non-compliant jurisdiction cannot, in aggregate, cross 20 per cent of voting power in the applicant, though pre-existing investors from such a jurisdiction can continue or add to their stake (paragraphs 5.1 to 5.3, June 2026 Master Direction).
Q: How is net worth actually computed for the ₹15 crore and ₹25 crore thresholds?
A: Net worth consists of paid-up equity capital, compulsorily convertible preference shares, free reserves, share premium, and capital reserves from asset sales (excluding revaluation reserves), reduced by accumulated losses, intangible assets, deferred revenue expenditure and deferred tax assets (paragraph 4.3, June 2026 Master Direction, which repealed the earlier 2015 net-worth circular while carrying its substance forward).
Q: Does a payment aggregator license need to be renewed periodically?
A: A CoA granted to a new PA is now perpetually valid from the date of grant. An existing PA’s CoA becomes perpetually valid at its next renewal provided it has stayed fully compliant; one that has not stays on one-year renewals until the deficiency clears (paragraphs 6.1 to 6.3).
Q: Does GST apply on payment aggregator commission or merchant discount rate income?
A: Yes, PA commission and MDR-linked income is a taxable supply of services under GST, and the applicable rate and place-of-supply treatment should be confirmed against the entity’s fee structure, since cross-border PA-CB flows can raise export-of-service classification questions needing a case-specific review.
Q: What happens to merchants an existing payment aggregator has already onboarded once the new due diligence rules apply?
A: Merchants onboarded up to 31 December 2025 need to comply with the new due diligence standard by 15 September 2026, a deadline now days away. Merchants onboarded from 1 January 2026 onward must meet the full standard from onboarding, with no grace period.
Regulatory references
- Payment and Settlement Systems Act, 2007, Sections 4, 7, 9, 10(2), 18, 23A, 26 and 30
- Foreign Exchange Management Act (FEMA), 1999, Sections 10(4) and 11(1)
- Master Direction on Regulation of Payment Aggregator (PA), RBI/DPSS/2025-26/141, dated 15 September 2025
- Master Direction on Authorisation to Operate a Payment System, RBI/DPSS/2026-27/401, dated 15 June 2026
- Payment and Settlement Systems Regulations, 2008, Regulation 3(2) (Form A)
External sources
We Are Problem Solvers. And Take Accountability.
Related Posts
NBFC Registration with RBI: Process, NOF & Certificate of Registration
A Non Banking Financial Company cannot lend, invest or carry on any non-banking financial business in India without first obtaining...
Learn More
Second Advisor Engagement alongside First – The Founder’s Perspective
Founders searching for how to switch a startup compliance advisor are usually not trying to fire anyone. They have a...
Learn More
Hardware R&D Startup Fundraising – Choosing instrument for multi year
A hardware R&D startup does not raise capital the way a SaaS company does. A software founder can go from...
Learn More© 2026 Treelife Ventures Services Private Limited. All Rights Reserved.