The Chartered Accountant • Journal of ICAI December 2021 • Vol. 70 • No. 6 • pp. 89–94 (Journal pp. 733–738)
BANKING & FINANCE • FINTECH & REGULATORY FRAMEWORK

Decoding of Payment Aggregator and Gateway Guidelines of Reserve Bank of India

CA. Subash Thakuri (Member of the Institute of Chartered Accountants of India)

The author is a member of the Institute. He can be reached at thakurisubash2017@gmail.com and eboard@icai.in.

1. Background & Evolution of the Regulatory Architecture

In the early 2000’s, the country witnessed drastic changes in user confidence with internet and mobile banking. With innovation, the orientation of the entire payment industry has substantially enhanced functionality. The development is followed by the setting up of the Board for Regulation and Supervision of Payment and Settlement Systems (BPSS), formulation and implementation of Payment and Settlement System Act, 2007 read with Payment and Settlement System Regulation, 2008 in addition to establishment of Department of Payment and Settlement in the Reserve Bank of India, as a guiding, licensing and regulating unit of the Payment Industry in India.

Subsequently, to leverage the ongoing innovation in terms of financial sector, the Reserve Bank of India issued “Directions for opening and operations of Accounts and settlement of payments for electronic payment transactions involving intermediaries” in late 2009 to guide the market operators involved in payment settlement and facilitation unit.

Further, it took a decade’s time for the Reserve Bank of India for institutionalization of earlier issued directions, to issue full-fledged directions as draft in 2019 for public comments, and finally issued Master Direction for Guidelines on Regulation of Payment Aggregators and Payment Gateways dated 17th March, 2020 as implemented source documents for licensing, guiding and managing the operation module of these entities. It is observed the regulator has taken abundant time to understand, experience the process and develop the regulatory framework for such entities in the market to establish safe, secure, reliable and authentic system participants in the Payment Industry.

“Digitalization of payment realisation process is undoubtedly a welcome step in the finance sector as the process has drastically reduced the effort and time to process payments at a click.”

2. Operational Scheme & Payment Stakeholder Ecosystem

Digitalization of payment realisation process is undoubtedly a welcome step in the finance sector as the process has drastically reduced the effort and time to process payments at a click. Therefore, it is pertinent to understand the involved stakeholders to execute an online payment transaction, precisely:

  • Seller (Merchant)
  • Customer (Buyer)
  • Customer’s Bank / Wallet Account
  • Acquiring Bank
  • The Bank Having the Nodal Account
  • IT and Communication Hardware / Software, Middleware, and Security System
  • Payment Gateways and Payment Aggregators, collectively.

On the other hand we need to understand the means of payment which can be credit card, debit card, bank account, wallet, unified payments interface (UPI) etc. Depending on payment mode used, additional players like card networks, National Payments Corporation of India (NPCI), banks offering net-banking services, banks/non-banks issuing wallet, etc. may be part of the payment chain.

3. Understanding Payment Aggregators (PA) vs. Payment Gateways (PG)

Payment Aggregator (PA)

Payment Aggregators (PA) are companies registered under Companies Act, 2013 with an object to do payment aggregation business which facilitate the e-commerce sites and merchants to accept payment from customer, pool and transfer them on to the merchants after a time period for completion of customers payment obligations. In short, it is an institution which for time being holds money from users against the closure of transaction in between user and merchant and only then settle the payment in respective merchants’ account.

Payment Gateway (PG)

Similarly, Payment Gateway (PG) are companies incorporated under the Companies Act, 2013 with an object to technology developments. These companies provide core technology infrastructure to route and facilitate processing of an online payment transaction in between participant stakeholders without involvement in handling of funds. In fact, Payment Gateway as the name suggests is the path of an encrypted safe and secure communication channel in between stakeholders to materialize the transaction towards closure of event.

Statutory Deadline: Unlike earlier, the issued guidelines mandate existing market players on this activity to obtain the Certificate of Authorization by 30th September, 2021 from the Department of Payment and Settlement, unit of Reserve Bank of India (RBI).

Comparative Analysis: Payment Aggregator vs. Payment Gateway

Basis Payment Aggregator Payment Gateway
Definition Entities that facilitate tripartite money management for consumption of services, goods or both Entities that provide technology infrastructure to route and facilitate processing of an online payment transaction
Industry E-commerce and Merchant to accept various instrument from customers Open for all
Money It holds money It does not hold money
Process It receives payments from customers, pools and transfers them on to the merchants after a time period Collects information on cipher text, transfer between sender, receiver and involves stakeholders to materialize the execution on a secure platform
Technology Baseline Pool Fund Management Company with Baseline Technology of Payment Gateway Core Technology Company

4. Statutory Authorization Requirements

Entities whosoever planning to enter this business should first incorporate the company as per the provision of Companies Act, 2013 with an object to perform such business. The board of directors shall be aware of business modality, vertical and operating guidelines with fit and proper criteria of Reserve Bank of India. Company should possess the required capital adequacy as well as proper business usage case to get the approval from Reserve Bank of India.

Company, being an applicant should file an application to Department of Payment and Settlement in RBI on Form A, prescribed in Payment and Settlement System Act, 2007 (amended 2015) read with its Payment and Settlement System Regulation, 2008 in addition to issued circular and amendment made on it from time to time. Pertinent issues to be acknowledged and addressed upfront before proceeding for application are listed below:

  • Corporate Incorporation: Applicant must be company incorporated under Companies Act, 2013 with an object of doing proposed activity of operating as PAs/PGs business.
  • Regulatory No Objection Certificate: Applicant being company if regulated by any of the financial sector regulators shall apply with a ‘No Objection Certificate’ from their respective regulator, within 45 days of obtaining such clearance.
  • Capital Adequacy & Net-Worth Trajectory: Minimum capital requirement of applicant before application to RBI shall be at least INR 15 Cr as per its latest audited financial statement subject to made this net-worth INR 25 Cr by the end of third financial year of grant of authorization.
  • Data Security Standard Compliance: Applicant shall maintain Payment Card Industry – Data Security Standard (PCI-DSS) and Payment Application – Data Security Standard (PA-DSS) compliance of the Infrastructure.
  • Designated Escrow Account Maintenance: Applicant needs to maintain escrow account with any scheduled commercial bank (maximum two accounts allowed with two different scheduled commercial banks), known as Designated Payment Systems under section 23A of the Payment and Settlement System Act, 2007 (as amended in 2015).

Though its PAs business or PGs business, emphasize precisely more on core technology innovation and involvement. Therefore, base line technology is mandated to be adopted and the business vertical is more centric to technology.

5. Corporate Governance & Grievance Redressal Architecture

Payment Aggregator and Payment Gateway are two different entities, with its own crucial and critical business operation modality and both have been authorised and licensed by the Reserve Bank of India always requiring maintaining governance in the operation of business process. Non-adherence of issued guidelines and set of regulations will trigger the monetary penalty as well as cancellation of license to operate as PAs or PGs, as the case may be.

Key Governance Tenets & Mandates

  • Professional Board & Fit & Proper Criteria: Starting with the Board of Directors (BOD) of entity, it needs to be professionally managed. Promoters of the entity should satisfy the fit and proper criteria prescribed by RBI. Criteria states that such person should have a record of fairness and integrity, including but not limited to financial integrity, good reputation and character and honesty.
  • Website Disclosures & Board Policies: Applicant shall disclose comprehensive information regarding merchant policies, customer grievances, privacy policy and other terms and conditions on the website and/or their mobile applications. Board shall have approved policy for disposal of complaints/dispute resolution mechanism/time-lines for processing refund, turn-around time for resolution of failed transaction as per RBI direction.
  • Multi-Party Commercial Agreements: Agreement between PAs, merchants, acquiring banks, and all other stake holders shall clearly delineate the roles and responsibilities of the involved parties in sorting/handling complaints, refund/failed transaction, return policy, customer grievance redressal (including turnaround time for resolving queries), dispute resolution mechanism, reconciliation, etc.
  • Appointment of Nodal Officer: Applicant shall appoint Nodal Officer responsible for regulatory and customer grievance handling functions. And the details of such Nodal officer shall be disclosed on their website. It is part of governance initiatives as an outcome of Customer Grievance Redressal and Dispute Management Framework in PAs business.
  • Prior Intimation of Management Changes: Besides all these, any takeover or acquisition of control or change in management of entity shall be communicated by way of letter to the CGM, Department of Payment and Settlement Systems, RBI within 15 days with complete details. It is important to note that no threshold limit is prescribed by RBI.
  • Mandatory AML/CFT KYC Norms: The Know Your Customer (KYC) is a crucial aspect of governance for any entity. Hence the RBI has issued direction and guidelines for the adoption of KYC norms and requirements which is applicable to PA/PG to formulate in the course of action as a counter-move to combat with money-laundering, financing of terrorism and so on.

6. Regulatory Reporting Requirements: Periodic & Event-Based Calendar

Reserve Bank of India (RBI) has categorised the reporting requirements on periodic terms say monthly, quarterly, annually and event-based reporting:

Monthly Reporting

By 7th of Next Month

Payment Aggregators (PAs) are required to submit the report of “Statistics of Transaction Handled” as per prescribed RBI format.

Quarterly Reporting

By 15th Following Quarter-End

Auditor shall certify regarding maintenance of balance in Escrow Account, and bankers provide Certificate on Escrow Account Debits and Credits (Internally audited).

Annual Compliance

By 31st May & 30th September

• IS & Cyber Security Audit Reports submitted by 31st May.
• Net worth certificate along with audited annual report submitted by 30th September.

Event-Based Filings

Within 7 to 15 Days

• Cyber Incident Report with root cause & preventive actions by 7th of next month.
• BOD changes / takeover notices within 15 days.

7. Security, Fraud Prevention & CERT-In Audit Architecture

It is a crucial part of the entire gamut of PA/PG business stipulated by RBI. Undoubtedly the applicant should frame a strong risk management system to meet the challenges of fraud and ensure customer protection. Applicant is required to place adequate information and data security infrastructure and systems for prevention and detection of frauds.

CERT-In Empanelled Audit Mandate

Importance of implementation and regular monitoring of security, emphasizes the requirement of Information System Audit Report including cyber security audit conducted by CERT-In empanelled auditors within two months of the close of their financial year to the respective Regional Office of Department of Payment and Settlement System, RBI.

8. Prescribed Baseline Technology Framework (Clauses a to s)

Reserve Bank of India (RBI) places the baseline technology framework for the participating entity in this business vertical either as PAs or PGs, to adopt and implement. The prescribed set of technology framework is bare minimum which is most to adopt and implement in system. However, much more powerful and advanced technology can be inbuilt but not below the set given by RBI. Therefore, it can be understood as a benchmark technology framework of RBI for PAs and PGs business in India:

  • Comprehensive Security Risk Assessment: Applicant at a minimum shall carry out comprehensive security risk assessment of its people, IT, business process environment, etc. to identify risk exposure with remedial measures and residual risks.
  • Data Security & Encryption Standards: Data security standards and best practices like PCI-DSS, PA-DSS, latest encryption standards, transport channel security etc. shall be implemented.
  • Mandatory Data Breach Reporting: Any data breach event in terms of card holder or anything else are serious matter and its threat on security, must be reported to RBI within stipulated timeframe.
  • Merchant Onboarding Security Checks: Applicant shall undertake comprehensive security assessment while onboarding the merchant to ensure these minimal baseline security controls.
  • Internal & External Technical Audits: Company shall carry out and submit to the IT Committee quarterly internal and annual external audit reports; bi-annual vulnerability assessment/penetration test reports, PCI-DSS including attestation of compliance and report of compliance.
  • Board-Approved Information Security Policy: Board approved information security policy in alignment with business objectives, scope, ownership and responsibility for the policy, information security organizational structure, maintenance of asset inventory and registers, data classification, authorization, expectations, knowledge and skill sets required, compliance review etc. shall be incorporated and must be reviewed at least annually.
  • Structured IT Governance Framework: An IT Policy shall be framed for regular management of IT functions and ensure that detailed documentation in terms of procedure and guidelines exist and are implemented. It shall have involvement of Board, IT Steering Committee, Enterprise Information Model, Cyber Crisis Management Plan as Governance Framework for IT Policy.
  • Enterprise Data Dictionary: Applicant shall maintain an ‘enterprise data dictionary’ incorporating the organization’s data syntax rules in order to enable sharing of data across the application and systems.
  • Granular Asset Risk Evaluation: Risk assessment shall, for each asset within its scope, identify the threat/vulnerability combinations and likelihood of impact on confidentiality, availability or integrity of that asset – from a business, compliance and/or contractual perspective.
  • Least Privilege & Need-to-Know Access: Access to application has thumb rule across the Industry, to be facilitated on the principle of least privilege and ‘need to know’ commensurate with the job responsibilities, is requirement of applicant to adopt and implement in its platform.
  • Human Resource IT Skills & Training: Resources are trained with requisite skills set for IT function and periodically assessed for the training requirements for human resources.
  • Vendor Risk Management & BCP-DR: Vendor risk management is required for technology support, including Business Continuity Planning – Disaster Recovery (BCP-DR) and data management.
  • IT Maturity Level Benchmarking: Entities shall consider assessing its IT maturity level, based on well known international standards, design an action plan and implement the plan to reach the target maturity level.
  • Robust Encryption Protocols: Applicant shall adopt and implement strong encryption algorithms.
  • Centralized Security Event Logging & SIEM Analysis: Security events from the entities infrastructure including but not limited to application, servers, middleware, endpoint, network, authentication events, database, web services, cryptographic events and log files shall be collected, investigated and analysed on regular intervals, then either enhanced or made proactive for identification of security alerts.
  • Data Localization & Sovereign Jurisdiction: Entities shall take preventive measure to ensure storing data in infrastructure that do not belong to external jurisdiction.
  • Prohibition on Storing Card Credentials: Customer card credentials shall not be stored within database or the server accessed by merchant.
  • Card-Not-Present Authentication Standards: Option for ATM PIN as factor of authentication for card not present transactions shall not be given.
  • Source-Mode Refund Routing: Refunds in case of failed transition or denied etc. shall be made to source mode of payment unless otherwise agreed by the user to credit amount in any other alternate mode.

These are few among others to be maintained, implemented and monitored on a regular basis as far technology infrastructure and its security and prevention from fraud is concerned related to the business of PAs/PGs as designed and recommended by the Reserve Bank of India.

9. Conclusion & Future Outlook for Market Operators

This is an essential topic in the Fintech industry currently due to requirement of the application for certificate of authorisation and all the existing market player irrespective of performing the activities as PAs or PGs, to Department of Payment and Settlement System, Reserve Bank of India under the Governing Act, Payment and Settlement System Act, 2007 (amended 2015) read with regulation and circular time to time by RBI.

“Gateway performs as communication channel whereas aggregator pool’s the fund from users and as per agreed terms and condition with merchant transfer, the eligible amount to their respective account.”

The PAs and PGs to be same, and the released guidelines take these as separate entities and refer to a totally different nature of activities. Precisely, Gateway performs as communication channel whereas aggregator pool’s the fund from users and as per agreed terms and condition with merchant transfer, the eligible amount to their respective account.

Application for registration needs to be placed to RBI at the earliest to carry on the ongoing business of existing market player else they need to stop the business activities. However, if the existing player has applied for authorization with the Department of Payment and Settlement System as per requirements, then the entity can pursue the ongoing business till the final decision from RBI is not communicated to the applicant entity.