Authorisation and scope
Determine whether the model is online PA, physical PA, cross-border PA or technology-only gateway.
Paragraph-wise corpus with Finin2min interpretation, examples, evidence controls and practical Q&A. Source: Master Direction on Regulation of Payment Aggregator, 15 September 2025.
Determine whether the model is online PA, physical PA, cross-border PA or technology-only gateway.
Track initial/continuing net-worth, auditor certificate and shortfall escalation.
Screen promoters/directors, ownership/control changes and conflicts.
Verify business, beneficial ownership, website/app, prohibited goods, settlement account and risk rating.
Monitor abnormal transaction, refund, chargeback and customer-complaint patterns.
Reconcile collections, settlement, refunds, fees and permitted debits daily.
Apply merchant agreement and regulatory outer limits; preserve cut-off and exception evidence.
Show merchant identity, payment status, refund route and complaint contact.
Do not store prohibited authentication data; comply with tokenisation, PCI and RBI security controls.
Use documented responsibility, timeline, evidence and ageing controls.
Map critical vendors, cloud, gateway, fraud, reconciliation and customer support contracts.
Separate import/export collection, FEMA, merchant due diligence and settlement currency controls.
Submit statutory/system audit, cyber incident, escrow and regulator returns and pre-clear material changes.