Payment Aggregators: The Regulated Layer Behind an Online Checkout
Reviewed by CA Nikhil Gupta · Last reviewed 24 June 2026
Current position
Non-bank payment aggregators require RBI authorisation under the applicable framework. The guidelines cover merchant onboarding, escrow and settlement, customer grievance handling, technology and security, audits and reporting. A payment gateway that only supplies technology is not necessarily performing the same fund-handling role.
How it works
Merchant onboarding should examine business model, prohibited activity, website terms, refund policy and beneficial ownership. A weak onboarding process can turn payment infrastructure into a channel for fraud.
Settlement timing, reserves, chargebacks and refunds should be contractually clear. Gross payment value is not the aggregator’s accounting revenue.
Card and payment credentials require security controls such as PCI-DSS where applicable. The merchant should never ask the customer to disclose OTP, PIN or full credentials.
| Issue | Current position | Why it matters |
|---|---|---|
| Aggregator role | Receives and settles customer funds under the model | RBI authorisation for non-banks |
| Gateway role | Technology routing without necessarily handling funds | Legal role depends on actual activity |
| Core control | Escrow, merchant due diligence and settlement reconciliation | Customer and merchant money must be traceable |
Practical example
A customer pays ₹20,000 to an online merchant that does not deliver. The aggregator may have processed and settled the payment, but it is not automatically the seller or guarantor of performance. The customer should preserve the order, payment reference and refund request; the merchant, aggregator and issuing bank have different roles in resolution.
Action checklist
- Verify the aggregator’s current RBI authorisation status.
- Document merchant due diligence and prohibited categories.
- Reconcile gateway data, escrow, bank settlement and merchant ledger daily.
- Publish clear cancellation, refund and grievance terms.
- Test incident response, access controls and credential security.
Evidence and document checklist
- RBI authorisation and policy framework.
- Merchant KYC and beneficial-ownership records.
- Escrow statements and settlement reconciliation.
- Chargeback/refund logs and customer tickets.
- Security audit and incident reports.
Common mistakes
- Calling payment value revenue.
- Assuming a gateway and aggregator are interchangeable.
- Settling to a bank account that differs from onboarded records.
- Treating aggregator involvement as a guarantee of delivery.
Red flags
- Sudden merchant-volume spike without business evidence.
- Refunds routed outside the original payment path.
- Large unexplained settlement holds.
- Merchant website lacks legal identity and grievance details.
Escalation and complaint route
Consumers should first complain to the merchant and payment participant with the transaction reference, then to the issuing bank where appropriate. Regulated-entity complaints may be escalated through RBI CMS. Fraud should be reported immediately to the bank and cybercrime authorities.
Frequently Asked Questions
Source and review trail
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.
- Primary category
- GST & Indirect Tax
- Official starting point
- www.gstcouncil.gov.in
Page source links
The prior page did not embed a page-specific external source. The category authority above is the minimum verification starting point; a specific instrument should be added when available.