How to Become a Financial Information User (FIU)
A Financial Information User (FIU) is any regulated entity that consumes user-consented financial information through the Account Aggregator (AA) framework for purposes such as credit underwriting, risk assessment, personal finance management, etc.
Becoming an FIU involves regulatory validation, technology implementation, and compliance with the AA ecosystem’s operational standards. Below are the detailed steps:
1. Regulatory Eligibility
To participate as an FIU, the applicant must be regulated by one of India’s financial sector regulators, such as:
- RBI – Banks, NBFCs
- SEBI – Investment advisors, stockbrokers
- IRDAI – Insurance companies
- PFRDA – Pension fund managers
The entity must hold an active license or registration from the appropriate regulator and must operate within the permissible scope that justifies the use of financial data. Entities not governed by these regulators are currently not permitted to become FIUs.
2. FIU Module Development
The next step is to develop an FIU module, either in-house or with the support of a Technology Service Provider (TSP). This module:
- Sends consent requests to AAs on behalf of the user
- Fetches encrypted financial information once the user consents
- Handles consent lifecycle (creation, revocation, expiry)
- Ensures data is decrypted and processed securely
The module must adhere to the technical specifications defined by ReBIT, which include data formats (JSON/XML), encryption standards, error handling, and more.
3. Integration with Account Aggregators (AAs)
Once the FIU module is developed, the next step is to integrate with one or more licensed Account Aggregators. This includes:
- Setting up secure API integrations to exchange consent artefacts and financial data
- Establishing mutual authentication (digital certificates)
- Configuring the routing of requests and responses
- Ensuring endpoint whitelisting and IP filtering, if applicable
AAs act as consent managers and data pipelines, hence a successful integration ensures compliance with the user’s consent and secure data transmission.
4. Sandbox Testing
After integration, FIUs must test their module in a sandbox environment provided by AAs. The sandbox is a controlled space where:
- End-to-end consent flows are simulated
- Error cases (invalid consent, expired tokens, etc.) are tested
- Security, latency, and response formats are validated
- Compliance with functional and technical standards is verified
This phase is mandatory and helps ensure smooth operations before moving to the live (production) environment.
5. Certification
Following sandbox validation, the FIU must obtain certification from a Sahamati-empaneled certifier. Certification involves:
- Source code and infrastructure audit
- Conformance to AA APIs and consent architecture
- Verification of encryption/decryption mechanisms
- Security testing (e.g., API authentication, consent integrity)
Only after passing certification can the FIU be approved to enter the production ecosystem.
6. Go Live and Onboarding
Once certified:
- The FIU is whitelisted by participating AAs
- The production endpoints are activated
- Live consent flows and data fetching begin
- The FIU registers with Sahamati, gaining access to governance updates, technical advisory groups, and visibility within the ecosystem
Although Sahamati registration is optional, it is strongly recommended for operational transparency and collaboration.
Learn More
For official documentation, technical specifications, and registration links, please visit: