Bank Feed Streaming via Account Aggregator: RBI Guide (2026)
Bank Feed Streaming via Account Aggregator: RBI Guide (2026)
Learn how the RBI Account Aggregator (AA) framework enables real-time bank feed streaming. Consent-based sharing and Tally BRS automation. Overview guide.
Who is this for: Bank Reconciliation
Reconciling bank accounts is a routine task for corporate finance departments. Download bank statements, normalise formats, and match transactions against general ledger entries. With multiple current accounts, managing this manually slows down monthly closures.
The **RBI Account Aggregator (AA)** framework solves this by enabling secure, real-time bank feed streaming directly to your ERP systems, eliminating manual downloads.
1. What is the Account Aggregator Framework?
The Account Aggregator framework is a financial data-sharing system regulated by the Reserve Bank of India (RBI). It allows individuals and businesses to securely share their financial information from one institution (like a bank) to another (like an accounting package or lender) using digitally signed consents.
The architecture divides participants into three distinct roles:
- Financial Information Provider (FIP): The institutions holding the financial records (such as current accounts at HDFC or SBI).
- Financial Information User (FIU): The authorized recipient of the data (such as accounting systems or GST analysis portals).
- Account Aggregator (AA): The RBI-licensed intermediary that manages consent logs and routes data.
2. Technical API Handshake & Payload Security
Data transmission through the AA network utilizes high-security protocols to protect business financial details. The API handshake follows a structured sequence:
- Consent Request: The FIU sends a structured digital consent request payload containing parameters like data scope, fetch frequency, and consent duration to the AA.
- User Approval: The customer approves the consent request via their AA app. The AA generates a digitally signed Consent Artifact.
- Data Fetch & Key Exchange: The FIP verifies the Consent Artifact. Using **Diffie-Hellman Key Exchange (ECDH)**, the FIP and FIU establish ephemeral encryption keys. The FIP encrypts the financial statement payload and transmits it through the AA intermediary to the FIU.
3. Risks of Traditional Screen-Scraping Bank Feeds
Before the AA network, automated accounting tools relied on screen-scraping or credential harvesting. This requires corporate users to share their net banking passwords and answers to security questions with third-party apps.
Sharing login credentials violates the terms of service of major banks, leaving corporate accounts vulnerable to security risks. In contrast, the AA network uses tokenized consent APIs with zero credential sharing, ensuring security.
4. ReBIT Data Schema Standards (XML & JSON)
To ensure data compatibility across different banks, the IT subsidiary of the RBI (ReBIT) has developed unified data schemas. Whether pulling current account statements from HDFC, ICICI, or SBI, transaction details are returned in a standard ReBIT format.
This standardization maps complex payment strings (such as `NEFT/HDFCH2619028901/X-CORP`) into clean parameters (Transaction Type: NEFT, Reference: HDFCH2619028901, Counterparty: X-CORP), simplifying automated reconciliation rule engines.
5. The Consent Architecture
Unlike traditional bank feeds that rely on screen-scraping or sharing credentials, the AA framework is based on direct consent:
| Consent Parameter | Control Mechanism | Security / Audit Benefit |
|---|---|---|
| Granular Consent | Users select which bank accounts and dates to share | Prevents broad access to unrelated accounts |
| Revocable Access | Users can cancel consent permissions at any time | Ensures complete control over data sharing |
| Data Encryption | Data is encrypted from bank to recipient | Conduits cannot access or read details in transit |
6. Security and Compliance u/s RBI Guidelines
The AA network complies with strict data localization and security rules:
- No Data Caching: AA intermediaries cannot store or cache the transactions passing through their systems.
- End-to-End Encryption: Financial data is encrypted using public-key cryptography from the FIP bank to the FIU ERP, preventing leaks.
- Digitally Signed Logs: Every consent grant is logged with digital signatures, providing clear audit trails.
7. Automating Tally Prime BRS with Bank Feeds
To manage BRS with automated bank feeds:
Tally Bank Reconciliation:
Go to **Gateway of Tally > Banking > Bank Reconciliation**. Select your bank ledger and choose the automated statement import option.
The system matches transactions based on values, dates, and reference numbers, auto-populating matching entries. You only need to manually reconcile exception transactions, reducing BRS times by up to 90%.
Chartered Accountant & Accounting Automation Specialist