The Account Aggregator (AA) framework came from the NITI Aayog’s Data Empowerment and Protection Architecture to empower every Indian to have seamless and secure access to their data and to enable portability of trusted data between service providers. And as the Unified Payments Interface (UPI) did to payments, the AA framework can revolutionise financial services by simplifying data sharing. There are four main stakeholders within the framework — consumers, financial information providers (FIP), financial information users (FIUs), and AAs, which provide the digital infrastructure to enable data flows and manage consent for financial data sharing.
Lenders rely on credit scores and digital or physical copies of financial information from consumers. By sharing information digitally and securely through the AA framework, lenders get a host of data points like bill payments and investments to assess creditworthiness. It isn’t hard to imagine a world where running from one bank branch to another with signed copies of this and attested copies of that, is the exception rather than the norm. The reduced cost of loan application procedures combined with the capability to give instant approvals will lead to increased competition, implying lower interest rates for consumers.
The framework enables security companies to better detect fraud against consumers and businesses by enabling the monitoring of data from across accounts in real-time. We’ve all submitted our Aadhaar and PAN cards countless times for “Know Your Customer” (KYC) verification. But with financial institutions sharing data within the framework, after the first time, KYC details can be derived with additional risk checks in place. This may still take a while since the Reserve Bank of India (RBI) would have to amend its regulations to enable “derived KYC”.
A lot of effort has been put in by the RBI, Sahamati and the AA ecosystem to ensure data security and privacy measures are built into the framework. Unified consent management and multi-factor authentication by AAs ensure that FIUs can only access your data if you give an FIP permission to share it. The AA ecosystem enables users to specify the duration of data sharing and retention and provides easy access to revoke consent at any time and request for data deletion, which are integral parts of consumer protection.