What is open banking (and India's account aggregator)?
For a century your transaction history belonged to your bank. That assumption is being dismantled.
The money stays exactly where it was. Only the story of the money moved, and it moved to you first.
The change underneath
For most of banking history, the complete record of how you earn and spend was visible to exactly one institution, which had no obligation to share it and every commercial reason not to.
Open banking inverts the ownership question. With your explicit permission, a licensed third party can read that data, or start a payment from your account, through a standardised interface the bank is required to provide.
Two distinct superpowers
Reading data unlocks the problem from the credit score article. Someone with no borrowing history still has a financial history: rent paid monthly, salary arriving steadily, bills honoured for years, all previously locked where no lender could see it. Cashflow-based underwriting judges people on how they actually live rather than only on whether they have borrowed before.
Initiating payments creates account-to-account transfers that bypass card rails entirely. No interchange, no scheme rules, no network in the loop. Where this meets instant domestic rails, an alternative road exists beside the toll road.
What India built differently
India's Account Aggregator framework is a genuinely distinctive design and worth understanding on its own terms rather than as a copy of Europe's.
The aggregator sits between the institution holding your data and the one requesting it, and acts purely as a consent manager. Crucially, it is structured so the aggregator itself cannot read the data passing through it. It moves encrypted information and manages permissions; it does not accumulate a view of your finances.
It also extends beyond banks to insurance, investments, and pensions, aiming at a fuller financial picture than banking-only frameworks reach.
For a hundred years the bank held both your money and the story of your money. Open banking splits those two things and hands you the second one.
The parts nobody automated
The framework is regulated, the APIs are mandated, the consent is standardised. What happens after the data arrives is none of those things.
The first gap is meaning. An API returns a date, an amount, and a string of merchant text never designed to be read by a machine. Turning "PYTM*AGGR 4471 MUM" into rent, salary or gambling is a judgement, not a lookup,.
The second gap is reliability. A mandate to expose an API says nothing about whether it answers in 300 milliseconds or 30 seconds, or whether a partial response means missing data or a dropped connection. Consent journeys that abandon halfway are usually a timeout, not a change of heart.
None of this is a design flaw. It is the ordinary shape of infrastructure: the regulated layer sets what is possible, and the unglamorous engineering on top is the actual product.
Where you meet it
Any app that offers to analyse your spending, pre-approve a loan by reading your statements, or pay directly from your bank account rather than by card. Audit your active consents once or twice a year and revoke what you no longer use.
Building this? A second pair of eyes on the architecture is what the advisory is for. →
