Anshu Thakur
Payment System Authorisation and PRAVAAH: A Compliance Roadmap under RBI’s 2025-26 Master Directions
Summary: The Reserve Bank of India has substantially consolidated the licensing framework for Payment Aggregators (PAs) and Payment System Operators (PSOs). The Master Direction on Regulation of Payment Aggregators, 2025, issued on September 15, 2025, replaced earlier fragmented PA-PG guidelines, while the June 2026 Master Direction on Authorisation to Operate a Payment System introduced perpetual validity for new PSO authorisations, subject to continued compliance and absence of supervisory concerns. PA applicants must meet eligibility requirements, including incorporation under the Companies Act, 2013, appropriate MoA provisions, ₹15 crore minimum net worth at filing rising to ₹25 crore within three years, and prescribed governance, information-security and escrow requirements. Applications are routed through PRAVAAH. Existing authorised entities face continuing annual, quarterly and cybersecurity compliance obligations. The 2026 framework also permits a one-year renewal where compliance conditions for perpetual authorisation are not met. Voluntary surrender requires settlement of outstanding liabilities and auditor certification, while the RBI may impose a one-year cooling-off period following revocation, non-renewal, voluntary surrender or rejection of authorisation. The supplied material highlights ambiguity concerning the interaction between the PA-specific and general PSO Directions and the discretionary cooling-off provision.
- Why PRAVAAH Exists
- Eligibility and the Net Worth Threshold
- Net Worth Requirement
- Filing Through PRAVAAH: Practical Compliance Sequence
- 1. Entity Readiness
- 2. Regulatory Clearance, If Applicable
- 3. Portal Registration
- 4. Application Submission
- 5. Technical and Security Documentation
- 6. Escrow Arrangement
- 7. Post-Filing Scrutiny
- Staying Authorised: Ongoing Compliance Requirements
- Perpetual Authorisation Under the June 2026 PSO Framework
- FATF-Linked Investment Restrictions
- Surrender and the Cooling-Off Period
- Voluntary Surrender of Authorisation
- One-Year Cooling-Off Provision
- Where the Framework Leaves Gaps
- Perpetual Authorisation and Conditional Renewal
- Voluntary Surrender and Cooling-Off Risk
- Interaction Between PA and PSO Master Directions
- Worked Example: Voluntary Exit by a Payment Aggregator
- Practical Implications for Payment Aggregators and PSOs
- For Entities Preparing a PRAVAAH Filing
- For Existing Certificate of Authorisation Holders
- For Entities Considering Exit
- Conclusion
- References
Why PRAVAAH Exists
The Reserve Bank of India has, over the past year, rebuilt the licensing architecture for payment system operators (PSOs) and payment aggregators (PAs) almost entirely. The Master Direction on Regulation of Payment Aggregators, 2025, issued on September 15, 2025, replaced the fragmented PA-PG guidelines of 2020, 2021 and 2023. In June 2026, the RBI went further and issued a consolidated Master Direction on Authorisation to Operate a Payment System, covering PSOs generally and introducing perpetual validity for new authorisations.
Both frameworks route their applications through PRAVAAH (Platform for Regulatory Application, Validation And AutHorisation), the RBI’s online licensing portal. For any non-bank entity planning to operate as a PA or PSO, or already holding a Certificate of Authorisation (CoA), the practical question is no longer whether authorisation is required but how to navigate the thresholds, filings, and exit mechanics the RBI has now codified in far greater detail than before.
This roadmap covers net worth and structural eligibility, the PRAVAAH filing sequence, ongoing compliance obligations associated with holding a CoA, and surrender and cooling-off provisions governing an exit from the business. It also flags areas where the framework leaves ambiguity for applicants to resolve.
Before 2024, applications for RBI authorisation, including PA licences, moved through physical filings and correspondence, which meant unpredictable timelines and no standard tracking mechanism. The RBI introduced PRAVAAH to consolidate this into a single online system. The portal now handles a wide range of application types across the RBI’s regulatory, supervisory and foreign exchange departments, and PA/PSO authorisation is one of the categories that must be filed through it rather than by any offline route.
PRAVAAH is a filing mechanism, not a separate set of substantive rules. The eligibility conditions, capital thresholds and conduct requirements come from the underlying Master Directions; PRAVAAH is simply the channel through which an applicant demonstrates compliance with them. That distinction matters because a well-prepared PRAVAAH submission is really a demonstration that the applicant has already put the underlying governance, capital and security infrastructure in place, not a form-filling exercise that can be completed before that infrastructure exists.
Eligibility and the Net Worth Threshold
A non-bank entity seeking PA authorisation must be incorporated under the Companies Act, 2013, and its Memorandum of Association must expressly cover payment aggregation as a stated activity. Banks are exempt from separate PA authorisation, since they already operate under RBI’s banking regulation.
If the applicant is already regulated by another financial sector regulator, such as SEBI or IRDAI, it must obtain a No Objection Certificate (NOC) from that regulator and file its PRAVAAH application within 45 days of receiving it.
Net Worth Requirement
The capital threshold is where most applicants underestimate the lead time involved. The Master Direction requires a minimum net worth of ₹15 crore at the time of filing, certified by the applicant’s statutory auditor in the prescribed annexure format, rising to ₹25 crore within three years of authorisation being granted.
Net worth for this purpose is computed under the Companies Act and applicable accounting standards; compulsorily convertible preference shares count towards it, but deferred tax assets are specifically excluded. Entities that have historically padded their net worth position with deferred tax assets on the balance sheet will find that capital unavailable for the RBI’s calculation, and raising the shortfall in fresh equity or CCPS takes considerably longer than preparing the rest of the application.
A newly incorporated entity without audited financials can still apply, using a net worth certificate based on a provisional balance sheet, but this is a narrow accommodation and does not relax the substantive threshold itself.
Filing Through PRAVAAH: Practical Compliance Sequence
The application sequence, in the order most applicants actually work through it, runs as follows.
1. Entity Readiness
Confirm incorporation under the Companies Act, 2013, with the MoA amended if necessary to cover PA activity, and obtain the auditor’s net worth certificate.
2. Regulatory Clearance, If Applicable
If another financial regulator already governs the entity, secure the NOC before the 45-day filing clock starts running.
3. Portal Registration
Create an account on PRAVAAH in the applicant company’s name, with a working corporate email ID, since most subsequent correspondence and status updates route through the portal itself rather than by separate letter.
4. Application Submission
File the prescribed PA authorisation application with the net worth certificate, promoter and director fit-and-proper declarations, board resolutions authorising the application, and the entity’s governance and information security policies.
5. Technical and Security Documentation
Submit the information security policy approved by the board, along with evidence of PCI-DSS and PA-DSS readiness for the systems that will process card data, since RBI increasingly expects this infrastructure to be demonstrable at the application stage rather than promised for later.
6. Escrow Arrangement
Where the business model involves holding merchant funds, the escrow account agreement with a scheduled commercial bank needs to be in place, structured to meet the Master Direction’s restrictions, including the bar on using escrow accounts for cash-on-delivery collections.
7. Post-Filing Scrutiny
Once accepted for processing, the application is examined against the fit-and-proper criteria for promoters and directors, covering integrity, financial soundness and the absence of criminal or regulatory disqualification, before a CoA is issued.
Two documentation points are easy to underestimate. Firstly, the fit-and-proper declaration is not a one-time filing; any subsequent change in promoters, directors or key managerial personnel has to be reported to the RBI with a fresh declaration.
Secondly, the PCI-DSS/PA-DSS compliance obligation extends past the applicant’s own systems to the merchants it onboards, which means an authorised PA has to build merchant-side compliance verification into its onboarding process, not just its own.
Staying Authorised: Ongoing Compliance Requirements
Authorisation is the beginning of the compliance obligation, not its conclusion.
A PA has to maintain a board-approved information security policy reviewed at least annually, undergo an annual information systems and cybersecurity audit conducted by a CERT-In empanelled auditor, and report cybersecurity incidents to the RBI within the prescribed timeframe, with monthly incident summaries including root cause analysis.
Quarterly, the auditor and the escrow-maintaining bank must each certify compliance with escrow account operating norms. Annually, the entity submits its net worth certificate, IS and cyber audit report, and confirmation of governance compliance.
Perpetual Authorisation Under the June 2026 PSO Framework
The June 2026 Master Direction on Authorisation to Operate a Payment System adds a structural change that applies across PSOs generally, not just PAs: authorisation granted to new PSOs is now perpetually valid, rather than subject to periodic renewal, provided regulatory requirements continue to be met and there is no supervisory concern.
Existing operators can migrate to perpetual validity when their CoA comes up for renewal, on the same condition. Where an operator falls short of that condition, the RBI issues a one-year renewal instead, effectively placing the entity on a shorter compliance leash until the deficiency is resolved.
FATF-Linked Investment Restrictions
The same Master Direction retains restrictions on investment from FATF non-compliant jurisdictions, capping the voting rights of new investors from such jurisdictions below 20 per cent in a PSO.
Surrender and the Cooling-Off Period
Voluntary Surrender of Authorisation
An entity that wants to exit the business voluntarily cannot simply stop operating. It must settle outstanding liabilities to customers, merchants, agents and banks, and obtain an auditor-certified confirmation of that settlement before the RBI will process the surrender of its CoA.
One-Year Cooling-Off Provision
The cooling-off provision is the sharper edge of the framework. Under the 2026 Master Direction, the RBI may impose a one-year cooling-off period on any entity whose authorisation has been revoked, not renewed, voluntarily surrendered, or whose application for authorisation was rejected.
During that period, the entity is barred from applying for permission to operate any payment system.
The provision is written broadly enough to cover a voluntary, orderly surrender in exactly the same terms as a revocation for misconduct: both can trigger the one-year bar, and the RBI’s discretion—the text uses “may,” not “shall”—means an applicant cannot assume in advance which category its own exit will fall into, or that an amicable surrender will automatically be treated more leniently than a forced one.
Where the Framework Leaves Gaps
Perpetual Authorisation and Conditional Renewal
The RBI’s move to perpetual authorisation is, on balance, a sensible correction to the older model of periodic renewal, which imposed a recurring compliance and filing burden on operators with no history of supervisory concern.
Tying perpetual status to continued compliance rather than granting it unconditionally also avoids the opposite problem, where a perpetual licence becomes effectively unsupervisable once granted. The structure of a conditional one-year renewal for entities that fall short is a reasonable middle path.
Voluntary Surrender and Cooling-Off Risk
The difficulty lies in how the cooling-off provision interacts with voluntary surrender. Treating voluntary surrender and involuntary revocation as triggering the same discretionary one-year bar removes any incentive for an entity to wind down its payment business in an orderly, RBI-notified manner rather than simply lapsing into non-compliance and inviting revocation instead.
If both paths carry the same downside risk, entities with a legitimate commercial reason to exit—a merger, a change in business focus, or a decision to route payments through a different licensed group entity—have little to gain from the cleaner exit route.
A more calibrated approach would tie the cooling-off period to the entity’s compliance history at the time of surrender: a PA that surrenders with a clean supervisory record and settled liabilities presents a materially different risk profile from one whose authorisation is being revoked for cause, and the current drafting does not distinguish between them on the face of the text as reported.
Interaction Between PA and PSO Master Directions
There is also a coordination question between the two Master Directions. The PA-specific Master Direction of September 2025 and the general PSO Master Direction of June 2026 were issued nine months apart, and PAs sit within the broader PSO category the later Direction governs.
Applicants and existing licence holders need clarity on which provisions of the general PSO framework, such as the perpetual authorisation mechanism and the FATF-linked investment cap, layer on top of the PA-specific net worth and security requirements, and which, if any, are superseded or narrowed by the PA-specific text.
Where the two instruments are silent on their own interaction, the safer compliance posture is to treat both as cumulatively applicable rather than assume the more recent general Direction implicitly relaxes anything in the sector-specific one.
Worked Example: Voluntary Exit by a Payment Aggregator
Take a hypothetical entity, A Fintech Private Limited, that has operated as an unauthorised PA-P business processing point-of-sale transactions for three years. It filed its PRAVAAH application for authorisation before the December 31, 2025 deadline, as the transition provisions required, and received its CoA in mid-2026.
Two years later, A Fintech’s board decides to exit the PA business entirely and route all payment processing through an affiliate that already holds its own authorisation.
Under the framework as it stands, A Fintech settles its outstanding merchant and agent liabilities, obtains the auditor’s confirmation, and files for voluntary surrender through PRAVAAH. Nothing in its compliance history suggests any supervisory concern.
Even so, the RBI retains discretion to impose the one-year cooling-off bar on A Fintech, exactly as it could on an entity whose CoA was revoked for KYC failures.
If A Fintech’s affiliate later needs A Fintech itself, rather than the affiliate, to hold a payment authorisation for an unrelated reason, perhaps a change in group structure, that possibility is foreclosed for a year regardless of A Fintech’s clean record.
The example is not a technical edge case; group restructurings of exactly this kind are common in the fintech sector, and the current drafting does not appear to account for them.
Practical Implications for Payment Aggregators and PSOs
For Entities Preparing a PRAVAAH Filing
For entities currently preparing a PRAVAAH filing, the immediate priorities are:
- Getting the net worth position audited and certified well before the filing date.
- Recognising that deferred tax assets will not count towards the relevant net worth calculation.
- Building out PCI-DSS/PA-DSS readiness in demonstrable form rather than as a roadmap.
- Locking in the escrow banking arrangement early, since escrow documentation tends to take longer than applicants expect once a bank’s own compliance review is factored in.
For Existing Certificate of Authorisation Holders
For entities already holding a CoA, the practical takeaway is to treat the transition to perpetual authorisation as conditional rather than automatic.
The annual audit, net worth and governance filings still have to be maintained without gaps, since any lapse converts what would otherwise be perpetual validity into a one-year renewal cycle.
For Entities Considering Exit
For entities considering an exit, voluntary surrender should be planned with the cooling-off risk priced in from the outset, and ideally raised directly with the RBI during the surrender process rather than assumed away, given that the Directions leave the point to the regulator’s discretion.
Conclusion
The central question this framework raises is not whether the RBI’s tightening of PA and PSO authorisation is justified—the capital thresholds and security requirements are a reasonable response to a sector handling substantial customer and merchant funds—but whether the exit mechanics have kept pace with the entry mechanics.
Perpetual authorisation and the FATF-linked investment cap show a regulator thinking carefully about who gets into the business and how long they stay in without renewed scrutiny.
The cooling-off provision, by treating voluntary and involuntary exits alike, has not yet had the same degree of calibration applied to it. Until the RBI clarifies how supervisory history at the point of surrender factors into the cooling-off decision, applicants planning a group restructuring or a considered exit from the PA business should build the one-year bar into their timeline as a default assumption rather than an exception.
References
- Reserve Bank of India, Master Direction on Regulation of Payment Aggregators, 2025 (RBI/DPSS/2025-26/141, CO.DPSS.POLC.No.S-633/02-14-008/2025-26), dated September 15, 2025.
- Reserve Bank of India, Master Directions on Authorisation to Operate a Payment System, issued June 15, 2026 (as reported).
- “An Analysis of the Reserve Bank of India’s Master Direction on Regulation of Payment Aggregators, 2025,” Lexology, October 2025.
- “Resetting the Rules: Overhaul of the Regulatory Framework for Payment Aggregators,” Lexology, October 2025.
- “RBI Master Direction 2025: Compliance Mandate For Payment Aggregators And PA-P Deadline,” Mondaq, November 2025.
- “RBI Master Directions 2025, Compliance And Operational Challenges For Payment Aggregators,” Mondaq, January 2026.
- “RBI issues consolidated Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025,” AZB & Partners, September 2025.
- “RBI issues payment system authorisation norms under new master directions,” Business Standard, June 15, 2026.
- “RBI’s Updated Guidelines For Payment Aggregators 2025: Key Details,” AuthBridge, March 2026.
- “Explained – RBI’s Master Direction For Payment Aggregators,” Medianama, September 2025.
- “RBI Master Direction on Digital Payment Aggregators: Understanding Compliance Requirements and Industry Implications,” AK & Partners, February 2026.
- RBI (Regulation of Payment Aggregators) Directions, 2025, full text as reproduced by TaxGuru and FIDC India.
- “Payment Aggregator License in India: Eligibility & RBI Rules,” Corpzo.
- “RBI Introduces The Pravaah Portal, FinTech Repository And RBI Retail Direct Mobile Application,” Mondaq, June 2024.






