A payment aggregator can offer a polished checkout, dozens of payment methods and fast APIs.
But before a business integrates one, there is a more important question:
Is the provider authorised for the payment flow you need, and how will it handle your customers, funds and settlement obligations?
That is the real purpose of India's payment-aggregator regulation.
In September 2025, RBI issued the Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025, consolidating rules for online, physical and cross-border payment aggregators into one framework.
But before a business integrates one, there is a more important question:
Is the provider authorised for the payment flow you need, and how will it handle your customers, funds and settlement obligations?
That is the real purpose of India's payment-aggregator regulation.
In September 2025, RBI issued the Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025, consolidating rules for online, physical and cross-border payment aggregators into one framework.
TL;DR
- RBI's 2025 framework recognises PA-Online (PA-O), PA-Physical (PA-P) and PA-Cross Border (PA-CB).
- Non-bank PAs need RBI authorisation and must meet prescribed capital, merchant-due-diligence, risk and escrow requirements.
- Merchant funds collected by a non-bank PA must be maintained in the applicable escrow/collection account, separate from the PA's general business funds.
- Before choosing a PA, check its authorisation category, settlement terms, merchant KYC process, security controls and whether it is authorised for cross-border flows.
Check 1: Is it actually a payment aggregator?
A payment aggregator does more than provide checkout technology.
Its regulated role involves aggregating customer payments on behalf of merchants and subsequently settling those funds to merchants.
That is different from a pure payment gateway, which primarily provides the technology used to route or facilitate payment information.
One company can provide both functions, but merchants should understand which regulated entity is actually handling the collection and settlement.
Check 2: Which PA authorisation applies?
RBI's 2025 Directions classify payment aggregators by the type of transaction they facilitate.
PA-Online
PA-O covers online or remote payment aggregation, such as ecommerce and app-based transactions.
PA-Physical
PA-P covers proximity or face-to-face payment aggregation where the customer and payment instrument are physically present at the payment point.
PA-Cross Border
PA-CB covers eligible cross-border aggregation under the applicable FEMA framework.
A provider authorised for domestic online aggregation should not automatically be assumed to have permission to process international merchant payments.
Check 3: Does the PA meet RBI's capital requirements?
For non-bank PAs, authorisation comes with financial requirements.
Under the 2025 framework, a non-bank entity seeking PA authorisation must generally have:
- ā¹15 crore minimum net worth when applying
- ā¹25 crore minimum net worth by the end of the third financial year after authorisation
The applicable minimum must then be maintained on an ongoing basis.
These requirements are designed to ensure that an entity handling merchant payment flows has sufficient financial capacity to operate the business.
Check 4: Why does merchant onboarding involve KYC?
A PA cannot simply issue every applicant an API key and begin collecting funds.
The 2025 Directions require merchant due diligence under RBI's KYC framework.
That can include:
- retrieving or verifying merchant KYC records
- business and identity verification
- beneficial-owner or authorised-signatory checks
- background and antecedent checks
- understanding the merchant's business profile
- ongoing transaction monitoring
The PA is expected to make sure the payment activity remains consistent with the merchant's stated business.
For merchants, this means onboarding friction is not always a sign of poor product design. Some checks exist because the aggregator is performing a regulated function.
Check 5: Where does customer money sit before settlement?
This is one of the most important differences between a regulated PA and a simple software provider.
A non-bank PA must maintain funds collected for merchants in the prescribed escrow account with a Scheduled Commercial Bank.
For PA-CB transactions, the framework uses:
- Inward Collection Account (InCA) for inward cross-border flows
- Outward Collection Account (OCA) for outward flows
These accounts are intended for authorised PA activity rather than the aggregator's unrelated operating expenses.
The framework also requires the day-end balance to cover amounts realised but not yet settled to merchants.
Check 6: How and when will you receive settlement?
There is no universal settlement timeline that applies identically to every PA product.
RBI requires the PA-merchant agreement to clearly and fairly state the settlement arrangement.
Before signing, check:
- settlement frequency
- cut-off rules
- refund and dispute treatment
- fee deductions
- reserve/hold conditions where applicable
- transaction and settlement reporting
A promise such as "fast settlement" is less useful than knowing the exact settlement terms in your merchant agreement.
Check 7: What security and fraud controls exist?
Payment aggregation creates operational and fraud risk because the provider connects merchants, customers and payment systems.
RBI's framework therefore covers security, fraud prevention and risk management.
Merchants should also assess:
- PCI DSS obligations for card acceptance
- tokenisation/stored-credential handling
- authentication support
- fraud screening
- chargeback and dispute processes
- incident response
- payment-status visibility
A PA does not remove every compliance responsibility from the merchant. The responsibilities depend on the integration, payment method and merchant environment.
What changes for cross-border payment aggregators?
International payment aggregation adds FEMA, foreign-exchange and collection-account requirements on top of the normal PA framework.
A PA-CB may be authorised for:
- inward transactions
- outward transactions
- both
The relevant InCA and OCA arrangements must remain separate as prescribed.
For an Indian exporter, this regulatory status matters because collecting a foreign customer's payment is not the same as processing a domestic ecommerce transaction.
Where PayGlocal fits
PayGlocal currently holds RBI authorisation for:
- Payment Aggregator ā Online (PA-O)
- Payment Aggregator ā Cross Border ā Inward & Outward (PA-CB-I&O)
Its certificate of authorisation is No. 250/2025.
That allows PayGlocal to support domestic online aggregation as well as eligible inward and outward cross-border payment flows under the applicable regulatory frameworks.
Its international stack includes cards, alternate payment methods, recurring payments and Multi-Currency Accounts for local collections.



