The deadline has already passed.
Non-bank payment aggregators that did not secure RBI authorisation by the close of 2025 were required to wind down payment aggregation operations. If your entity cleared that bar, the harder part starts now: staying compliant with a framework built around ongoing obligations, not a one-time approval.
Most compliance gaps under the Master Direction on Regulation of Payment Aggregators do not show up as a single missed filing. They show up as small operational habits that were fine under the old circulars and are no longer fine under the consolidated framework.
Here are the twelve mistakes that keep surfacing across PA-O, PA-P, and PA-CB entities adjusting to the new requirements.
Most of these twelve mistakes are not new obligations invented from nothing. They existed in some form under the prior circulars. What changed is that the Master Direction consolidated them into one framework an examiner reviews as a whole.
A gap that used to hide in the space between three separate circulars now has nowhere left to hide. The entities most exposed are not the ones ignoring compliance. They are the ones who complied with the old rules and assumed that compliance carried forward automatically. It did not.
The Direction requires Rs 15 crore at authorisation, rising to Rs 25 crore within three years, maintained continuously. Entities that hit the number once and stop monitoring it are one difficult quarter away from a technical breach.
Cross-border aggregators need separated Inward and Outward Collection Accounts. Entities still running a single commingled account are operating outside the current structure - not in a legacy exception to it.
Merchants not re-verified under updated KYC standards by the applicable compliance deadline were required to be re-onboarded. Skipping this quietly extends risk exposure on merchants nobody has actually re-checked under the current framework.
The Direction requires clear, disclosed refund timelines. A verbal SLA with your support team is not a policy an examiner can review. It needs to be board-approved and documented.
Annual security audits must come from a CERT-In empanelled auditor specifically. An audit from a generic security firm does not satisfy this requirement, however thorough it was.
The Direction sets defined timeframes for reporting incidents and cardholder data breaches to RBI, plus monthly cyber incident reporting with root cause analysis. Silence is not a strategy. It is a separate violation on top of the original incident.
Every PA is required to maintain a functioning fraud prevention and monitoring system - not a policy document describing one. Examiners increasingly ask to see the system operate, not read about it. Continuous merchant monitoring with documented alert histories and review decisions is the operational evidence the framework expects to find.
This is a named, specific requirement - not a shared responsibility folded into a generic support function. The officer must be designated, identified, and reachable.
The Direction is explicit: a PA business cannot also operate as a marketplace. Entities that blurred this line under earlier, looser circulars are now operating a structural violation - not a grey area.
Any change in control or leadership triggers a fresh fit-and-proper review requirement - not just an update at the next audit cycle. This is a common gap in entities that move fast on leadership changes.
The framework expects ongoing monitoring of merchant transactions to catch suspicious activity after onboarding, not a single check at signup. This is the mistake with the highest downstream cost, because it is invisible until a merchant that passed onboarding starts behaving differently months later. Transaction monitoring for payment aggregators needs to cover the full merchant lifecycle - not just the moment of entry.
An examiner does not ask how many alerts fired last quarter. They ask how a specific decision was made and whether the reasoning holds up on paper. Entities without a documented trail have no way to answer convincingly, no matter how sound the underlying decision was. Investigation workflow modernisation - connecting the signal that triggered a review to the documented compliance decision - is no longer optional infrastructure. It is what examiners look for.
Building a compliance programme that satisfies RBI examination is not a documentation exercise. It is an operational one.
Verafye is a network risk intelligence platform built specifically for payment aggregators and PSPs operating under ongoing regulatory scrutiny. It connects your merchant monitoring, transaction surveillance, fraud alerts, and AML workflows into one investigation-ready platform - with documented case trails, audit-ready decision records, and full escalation history for every risk decision your team makes.
What that means practically for RBI compliance: when mistake 12 comes up in an examination - can you show the case trail connecting a fraud flag to a compliance decision - the answer exists, in one place, traceable from the original signal through to the documented outcome.
If you want to understand where your current operational coverage falls short of what the Master Direction now requires, the Verafye Risk Shadowing Review is a practical scoped starting point - no commitment required.
Pick any one of these twelve mistakes and ask whether your entity could produce documentation proving it is handled correctly today - not at the last audit cycle.
If the honest answer involves checking with three different teams, the gap is not the mistake itself. It is not knowing you have it.
The entities that perform well in RBI examinations are not the ones with the most documentation. They are the ones whose operations and their documentation tell the same story.
Abhishek Tuppada
Founder & CEO, Verafye
Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.
See where your monitoring stack has blind spots
The Risk Shadowing Review maps your current coverage against relationship-level gaps.