Non-bank payment aggregators require RBI authorisation under the applicable framework. The guidelines cover merchant onboarding, escrow and settlement, customer grievance handling, technology and security, audits and reporting. A payment gateway that only supplies technology is not necessarily performing the same fund-handling role.
Merchant onboarding should examine business model, prohibited activity, website terms, refund policy and beneficial ownership. A weak onboarding process can turn payment infrastructure into a channel for fraud.
Settlement timing, reserves, chargebacks and refunds should be contractually clear. Gross payment value is not the aggregator’s accounting revenue.
Card and payment credentials require security controls such as PCI-DSS where applicable. The merchant should never ask the customer to disclose OTP, PIN or full credentials.
| Issue | Current position | Why it matters |
|---|---|---|
| Aggregator role | Receives and settles customer funds under the model | RBI authorisation for non-banks |
| Gateway role | Technology routing without necessarily handling funds | Legal role depends on actual activity |
| Core control | Escrow, merchant due diligence and settlement reconciliation | Customer and merchant money must be traceable |
A customer pays ₹20,000 to an online merchant that does not deliver. The aggregator may have processed and settled the payment, but it is not automatically the seller or guarantor of performance. The customer should preserve the order, payment reference and refund request; the merchant, aggregator and issuing bank have different roles in resolution.
Consumers should first complain to the merchant and payment participant with the transaction reference, then to the issuing bank where appropriate. Regulated-entity complaints may be escalated through RBI CMS. Fraud should be reported immediately to the bank and cybercrime authorities.
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.
The prior page did not embed a page-specific external source. The category authority above is the minimum verification starting point; a specific instrument should be added during the next substantive editorial review.