Before you sign a payment contract, you are really asking one question: can this provider legally collect customer payments and settle them to my business for the payment flow I need?
An RBI-authorised payment aggregator is a non-bank entity that holds a Certificate of Authorisation to aggregate customer payments and settle the collected funds to merchants in one or more approved categories. That status is verifiable from public records.
“RBI-compliant” is broader. The public record lets you verify the legal entity and its permitted payment aggregator categories. It does not certify every continuing obligation the provider owes on merchant due diligence, escrow, security, or disputes.
Three verification failures are common:
- Searching only for a consumer-facing brand and missing the legal entity behind it.
- Assuming online authorisation also covers physical or cross-border payment aggregation.
- Treating a pending application, an old press release or a provider claim as current evidence.
With UPI alone processing 24,162 crore transactions worth about Rs 314 lakh crore in FY 2025-26, the money moving through these providers is not trivial. This article gives you a ten-minute public-record check, then a pre-contract checklist covering KYC, escrow, settlements, security, and grievance redressal.
Key Takeaways
- Verify the provider’s legal entity in the current RBI list, not only its brand name.
- Confirm that the listed category matches your payment flow: PA-O, PA-P or PA-CB.
- Ask for the Certificate of Authorisation reference and reconcile it with your contract.
- Review merchant KYC, settlement, refund, chargeback, and grievance terms before onboarding.
- For cross-border payments, verify inward, outward or both PA-CB permissions.
- Treat authorisation as the starting point for due diligence, not proof of every control.
What Does “RBI-Compliant Payment Aggregator” Actually Mean?
In practical merchant due diligence, “RBI-compliant” should mean two separate things: the provider has the required RBI authorisation for the activity it performs, and it can show how it meets continuing obligations for merchant due diligence, escrow, settlement, security, fraud controls, disputes and regulatory reporting. The RBI list publicly verifies the first part, not every element of the second.
The RBI Payment Aggregator Directions, 2025 apply to both bank and non-bank entities undertaking payment aggregator business. Non-bank entities must seek authorisation from the RBI. A bank does not require a separate payment aggregator authorisation to carry out the activity.
The 2025 Directions consolidate the online, physical and cross-border framework into a single instrument. Entry requirements are prudential as well as procedural: a non-bank applicant needs a minimum net worth of Rs 15 crore at application, rising to Rs 25 crore by the end of the third financial year from authorisation.
Why care as a merchant? A mismatch between the contracted entity, your actual payment flow, and the provider’s authorisation category creates real exposure: onboarding delays, settlement interruptions, continuity risk, and missing documentation for cross-border transactions.
DID YOU KNOW: The current framework distinguishes PA-O for online aggregation, PA-P for physical aggregation and PA-CB for eligible cross-border aggregation. The category must match the service you are buying.
How Can You Verify an RBI-Authorised Payment Aggregator?
Verify the provider in seven steps: identify the contracting legal entity, find that entity in RBI’s current authorised-operator list, cross-check the application-status page, confirm the authorisation date and PA category, reconcile the entry with the contract, and then review its merchant KYC, escrow, settlement, security and grievance evidence.
- Identify the legal entity. Find the company name and corporate identity number in the contract, terms of service, invoice or public notice. Do not start with the brand name alone. The brand on your checkout page and the entity on your settlement advice are frequently different.
- Open the current RBI list. Use the RBI list of authorised Payment System Operators. Note the page’s visible update date before you rely on it, and record that date in your file.
- Search for the exact legal entity, then check the second page. Confirm the entry sits in the authorised section, not a section covering returned, withdrawn, refused, revoked or ceased operations. Then open RBI’s status of applications received from payment aggregators page, where in-principle approvals and returned applications appear. RBI’s own page notes that new payment aggregators cannot commence operations until granted authorisation under Section 7 of the PSS Act, 2007.
- Check the permitted PA category. Match PA-O to online payments, PA-P to physical payments, and PA-CB inward, PA-CB outward or both to the cross-border direction you need.
- Record the authorisation date and reference. Ask the provider to identify the relevant Certificate of Authorisation and confirm the same entity appears in your agreement. If the provider added a category recently, ask to see the revised certificate, since a payment aggregator must intimate the RBI at least 30 days before commencing business in another category.
- Review continuing control evidence. Ask how merchant due diligence, settlement timing, escrow handling, refunds, disputes, security, and grievance escalation operate for your specific account.
- Recheck before signing and at contract review. Do not diary a renewal date. Under RBI’s 2026 authorisation framework, new authorisations are perpetually valid and existing operators may receive perpetual validity on renewal, with one-year renewals where deficiencies exist. Recheck on entity changes, category changes and commercial reviews instead.
| Check | Acceptable Evidence | Warning Sign |
|---|---|---|
| Legal identity | Contracting entity matches the current RBI entry | Only a brand name is supplied |
| Authorisation | Entity appears in RBI’s authorised-operator list | Only an application, partnership or press claim is shown |
| PA category | Category matches the actual payment flow | Online authorisation is used to imply every category |
| Merchant KYC | Clear document, consent and verification process | No explanation for additional checks or delays |
| Escrow and settlement | Written settlement timing, account flow and exception terms | Vague “best effort” settlement language |
| Security and disputes | Current security evidence plus refund and escalation process | Unsupported “100% secure” or “fully compliant” claims |
| Contract continuity | Regulatory status and termination obligations are addressed | No provision for authorisation or service changes |
PRO-TIP: Save a dated PDF or screenshot of the relevant RBI entry and the provider’s legal terms when you sign. This creates an audit trail for procurement and renewal.
Payment Aggregator, Payment Gateway and PA Category: What Should You Check?
Under the 2025 Directions, a payment aggregator handles aggregated customer funds and settles them to merchants. A payment gateway provides technology infrastructure that routes or facilitates a transaction without handling funds, and in that role it sits outside the payment aggregator authorisation requirement.
| Term or Category | What It Covers | Merchant Verification Question |
|---|---|---|
| Payment Aggregator | Collects and settles customer funds for merchants | Is the contracting entity authorised for this activity? |
| Payment Gateway | Routes or facilitates the transaction without handling funds | Which authorised entity handles and settles the money? |
| PA-O | Online transactions where the instrument and acceptance device are not physically together | Does the RBI entry show PA-O? |
| PA-P | Physical transactions where the instrument and acceptance device are in proximity | Does the RBI entry show PA-P? |
| PA-CB inward | Eligible inward cross-border aggregation | Is inward PA-CB authorisation shown? |
| PA-CB outward | Eligible outward cross-border aggregation | Is outward PA-CB authorisation shown? |
You may buy a combined payment platform, and that is normal. The legal roles still have to be separated in your file. One entity may supply the technology while another holds the funds.
Terminology needs care. Current wording refers to PA-CB inward and PA-CB outward. Older material may still use export and import labels drawn from the repealed 2023 cross-border circular, so do not match labels across documents of different vintages.
One further point for platforms and resellers: where a payment aggregator contracts with another payment aggregator that onboards the merchant, the latter carries the merchant due diligence responsibility. Ask which entity actually onboarded you.
PRO-TIP: Ask one direct question during procurement: “Which legal entity handles my customer funds, and where is that exact activity shown in the RBI list?”
What Merchant KYC and AML Controls Should an Authorised PA Follow?
An authorised payment aggregator must conduct customer due diligence on merchants, retrieve the merchant’s KYC record from the Central KYC Records Registry with consent where applicable, check the merchant’s background, and monitor whether later transactions remain consistent with the merchant’s declared business profile.
The current Directions set out the following expectations:
- Retrieval of the merchant’s record from the Central KYC Records Registry, with the merchant’s consent, during onboarding.
- Alternative due-diligence mechanisms under the KYC Master Direction where a record is unavailable or cannot be accessed.
- PAN or Form 60 verification, Contact Point Verification, which is physical verification of the merchant’s address or place of business, and a certified officially valid document under the simplified path.
- Background and antecedent checks on the merchant.
- Correct Merchant Category Code and merchant name capture.
- Ongoing monitoring of transactions against the declared business profile.
- Registration with the Financial Intelligence Unit-India and associated reporting obligations for a non-bank payment aggregator.
Marketplace operators should note an additional requirement: a payment aggregator must ensure the marketplace it onboards does not accept payments for sellers who are not separately onboarded on that platform.
What does this mean for you? Additional document requests are not automatically a red flag. Existing merchants were brought into the refreshed due-diligence regime during 2026, and aggregators asked the RBI for more time to complete the merchant re-KYC exercise. Insist on a clear explanation of the request, the consent being taken, how your data is handled and the expected review timeline. For background on the role itself, start with what a payment aggregator does.
DID YOU KNOW: The 2025 Directions describe an alternative due-diligence process for merchants whose annual turnover does not exceed Rs 40 lakh, or whose annual export turnover does not exceed Rs 5 lakh. This is a different documentation route, not automatic approval, and background checks still apply.
How Should an RBI-Authorised PA Handle Escrow and Merchant Settlements?
A non-bank payment aggregator must keep funds collected for merchants in a separate escrow account with a Scheduled Commercial Bank in India. The merchant agreement should state settlement timelines transparently, and the escrow account should be used only for authorised payment aggregator business and permitted credits and debits.
In plain terms:
- The escrow account separates collected merchant funds from the provider’s ordinary operating money.
- Your contract, not a generic marketing page, should state the settlement timeline for your account.
- The day-end balance should not be less than realised funds payable to merchants but not yet settled.
- Refunds, reversals and permitted merchant payouts must follow the regulated account flow.
- Settlement holds, reserves, failed transactions and chargeback handling should be explained before you sign.
Be sceptical of any claim that the RBI mandates one universal T+1 or T+2 cycle for every merchant. Under the 2025 Directions, settlement timelines are determined contractually between the payment aggregator and the merchant, with the regulatory requirement being that the agreement is fair, equitable and transparently states those timelines. Negotiate and document the timeline rather than assuming it.
There is a genuine fund-safety consequence to using an unauthorised provider: funds held with payment aggregators that have not received authorisation no longer enjoy bankruptcy-remote status. If you run a marketplace and need funds split across sellers, check how that architecture sits alongside the escrow flow, as with Route for split and routed marketplace payments.
PRO-TIP: Ask for a sample settlement report and the exact contract clauses covering settlement timing, holds, refunds, chargebacks, reconciliation and final settlement after termination.
What Should Exporters and Importers Verify About PA-CB Authorisation?
A domestic online payment aggregator authorisation does not automatically prove that a provider may facilitate your cross-border flow. Verify whether the RBI entry shows PA-CB for inward transactions, outward transactions, or both, then confirm that your contract covers your exact import or export use case.
Current requirements worth checking before you contract:
- Funds relating to inward and outward transactions must be kept separate, with no commingling or netting off permitted.
- Foreign currency may be purchased from or sold only to an Authorised Dealer.
- The maximum value per PA-CB inward or outward transaction is Rs 25 lakh under the current Directions.
- Inward Collection Accounts and Outward Collection Accounts serve distinct purposes and are maintained separately.
- The provider should supply the documents you need for closure of the corresponding EDPMS or IDPMS entry with your AD bank, where applicable. This is a frequent operational gap, so raise it early.
- Non-INR settlement is permitted only for directly onboarded Indian exporters, under the conditions stated in the Directions.
Treat PA-CB authorisation as one input, not a complete answer. It does not resolve your own FEMA, tax, customs or documentation obligations. If you are scoping cross-border collections, review how eligible cross-border payments are structured against these checks.
DID YOU KNOW: RBI’s current authorised-operator list labels PA-CB inward and outward permissions separately, so you can check whether the category matches the direction of your payment flow.
What Should Subscription Businesses Verify Beyond PA Authorisation?
Recurring billing carries a second compliance layer. Payment aggregator authorisation does not cover mandate handling. Recurring card, UPI and prepaid instrument transactions fall under the separate Digital Payments E-mandate Framework, 2026, covering one-time mandate registration with additional factor authentication and pre-transaction notification. Ask the provider how mandate registration, customer notification, failed debits and exception handling work on your account.
Which Security, Fraud and Grievance Controls Should You Review?
Authorisation is not a substitute for technical due diligence. Review current security evidence, fraud controls, incident handling, refund and dispute processes, and the published grievance escalation path before you allow a provider to handle live customer payments.
Work through this list during evaluation:
- Applicable PCI DSS or PCI Software Security Framework evidence.
- Board-approved information security and risk-management governance.
- Fraud detection and prevention controls appropriate to your risk profile.
- Annual system and cybersecurity audit requirements, which under the RBI framework are conducted through CERT-In empanelled auditors with reports submitted to the RBI.
- Payment-data storage requirements, including storage of payment system data in India.
- Refund, failed-transaction and chargeback procedures, with reason codes.
- A named merchant support or grievance officer and a published escalation matrix.
- Contracted incident notification and business-continuity expectations.
A provider will not share confidential audit reports. Ask instead for current attestations, certificates, audit summaries, contractual commitments and named escalation contacts. For technical background, review payment gateway security and encryption controls and wider secure payment gateway considerations. Then test the published grievance escalation path rather than assuming it works.
How Razorpay Supports Regulated Payment Aggregation in India
Apply the same checklist to Razorpay that you would apply to any provider. Here is where the public evidence sits.
| Verification item | Evidence you can check |
|---|---|
| Legal entity and categories | The RBI authorised-operator list updated September 30, 2026 lists Razorpay Payments Private Limited, formerly Razorpay Software Private Limited, for PA-O, PA-P and PA-CB inward and outward activities |
| Entity transition | The Razorpay public notice states that payment aggregation services have been operated by Razorpay Payments Private Limited from January 1, 2026, following an RBI-approved transfer |
| Online collections | Razorpay Payment Gateway for online payment acceptance |
| Cross-border flows | International Payments for eligible cross-border collections |
| Marketplace money movement | Route for supported marketplace split and routing flows |
| Grievance escalation | A published customer grievance redressal policy with escalation information |
How to verify this yourself, using the seven steps above:
- Search the exact legal entity name, Razorpay Payments Private Limited, in the current RBI list rather than the brand name.
- Confirm the categories shown against that entry match your flow: online, physical, cross-border inward, cross-border outward, or a combination.
- Reconcile the entity named in the RBI entry with the entity named in your agreement, invoices and settlement descriptor.
- Read the public notice to understand the entity change, then archive both records with the list’s visible update date.
Authorisation does not mean every merchant or business model will be approved. Onboarding still depends on due diligence, your business category and contract terms.
Verify the current RBI entry, identify the category required for your payment flow, and speak with Razorpay about onboarding and contract requirements for your business model.
Final Pre-Contract Verification Checklist
- [ ] Contracting legal entity matches the current RBI list.
- [ ] RBI authorisation date and PA category are recorded, with the list’s visible update date.
- [ ] The provider’s status has also been checked on RBI’s application-status page.
- [ ] Online, physical and cross-border needs are mapped separately.
- [ ] Merchant KYC documents, consent and expected review time are clear.
- [ ] Settlement timeline, escrow flow and reconciliation format are written into the agreement.
- [ ] Refund, failed-transaction, reserve and chargeback terms are documented.
- [ ] Current security attestations and incident-escalation commitments have been reviewed.
- [ ] Merchant support and grievance contacts have been tested, not just noted.
- [ ] Regulatory-status change, termination and final-settlement clauses are included.
- [ ] Recurring mandate handling has been verified separately if you run subscriptions.
- [ ] Evidence has been archived for procurement and renewal review.
Choosing an authorised payment aggregator is not a one-time logo check. It is an evidence trail connecting the legal entity, the permitted activity, the merchant agreement and the operating controls behind your settlements.
This checklist supports commercial due diligence and is not a substitute for legal advice on a business’s specific regulatory obligations.
Frequently Asked Questions
How do I check whether a payment aggregator is RBI-authorised?
Search the exact contracting legal entity in RBI’s current list of authorised Payment System Operators. Confirm that it appears in the authorised section, and record its PA category and authorisation date. Do not rely only on a brand logo, an old announcement or a pending application.
Does RBI authorise payment gateways and payment aggregators in the same way?
No. The 2025 Directions define a payment aggregator as an entity that handles aggregated funds and settles them to merchants. A payment gateway provides transaction-routing technology without handling funds and, in that role, is outside the payment aggregator authorisation requirement.
Is in-principle approval the same as final RBI authorisation?
No. For merchant verification, look for the legal entity in RBI’s current authorised-operator list and ask for the Certificate of Authorisation reference. A pending application or preliminary approval should not be presented as equivalent to current final authorisation.
Does PA-O authorisation cover international payments?
Not automatically. PA-O covers online payment aggregation. Cross-border aggregation requires the relevant PA-CB category. Check whether the RBI entry shows inward, outward or both permissions for the legal entity handling your cross-border flow.
What if the provider’s brand name differs from the RBI-listed company name?
Reconcile the brand with the legal entity in the contract, terms, settlement descriptor and current RBI entry. Ask the provider to explain any name change, merger or transfer, and to provide the related public notice before you sign.
Why should I check both RBI payment aggregator pages?
The authorised-operator list confirms final authorisation and permitted categories. The application-status page helps you distinguish authorised entities from those with pending, in-principle, or returned applications. Checking only one page can leave you treating an applicant as an authorised provider.