Banking & Fintech Acronyms in India: PSS, AUA, KUA, NPCI & More
Sit in enough audit rooms and you learn to spot the moment a founder loses the plot. It usually arrives about twenty minutes in, when someone from the RBI regional office asks a straight question: are you a payment aggregator or a payment gateway, and where is your PA authorisation. The room goes quiet. The CTO says the word gateway. The compliance head says aggregator. The lawyer says something about a partnership with a bank. Three answers, one company, and none of them line up with the licence on file.
Acronyms are not trivia in Indian fintech. They are the difference between holding customer funds legally and running an unauthorised payment system that RBI can shut down with a single directive. Half the compliance failures I see do not start with a technical control gap. They start with a founder who genuinely did not know that AUA and KUA are two different UIDAI roles, or that PPI money sitting in an escrow is governed by a completely separate master direction from the one covering their lending book. So let us do the unglamorous thing properly: define the terms that actually decide your audit scope, and say what each one costs you if you get it wrong.
The regulators first, because every acronym hangs off one of them
You cannot read a fintech acronym in isolation. Each one belongs to a regulator, and the regulator decides the rulebook, the audit cadence, and who can revoke your ability to operate. Before you learn a single product acronym, know whose door you are standing at.
| Acronym | Full form | What it governs for you |
|---|---|---|
| RBI | Reserve Bank of India | Banks, NBFCs, payment systems, PPIs, PA/PG, digital lending. The heavyweight for most fintechs. |
| SEBI | Securities and Exchange Board of India | Anything touching securities, broking, wealth, mutual funds, RIAs. |
| IRDAI | Insurance Regulatory and Development Authority of India | Insurance products, insurtech, web aggregators, corporate agents. |
| NPCI | National Payments Corporation of India | The rails: UPI, IMPS, RuPay, NACH, AePS, FASTag. Not a regulator, but its circulars bind you. |
| UIDAI | Unique Identification Authority of India | Aadhaar. Owns the AUA/KUA/Sub-AUA framework and its security requirements. |
| MeitY / CERT-In | Ministry of Electronics and IT / Indian Computer Emergency Response Team | Cyber incident reporting, the 6-hour rule, empanelled audit requirements. |
Notice NPCI is not a regulator in the legal sense. It is a not-for-profit company owned by banks. But if you run on UPI, NPCI procedural guidelines and its audit requirements govern your day-to-day operations as tightly as any RBI direction, and NPCI can suspend your access. Treat its circulars as binding, because in practice they are.
PSS: the Act that decides whether you even need a licence
PSS stands for the Payment and Settlement Systems Act, 2007. This is the single most misunderstood acronym in Indian fintech, and it is the one that quietly determines whether a large chunk of your business is legal. The Act says that no person may operate a payment system in India without authorisation from RBI. That is it. Simple sentence, enormous consequences.
A payment system, under the Act, is any system that enables payment between a payer and a beneficiary, involving clearing, payment or settlement. If your platform sits in the flow of money between a customer and a merchant, and money passes through an account you control, you are very likely operating a payment system. That triggers the need for authorisation, most commonly as a Payment Aggregator. Founders who skip this step are not just non-compliant on a control; they are running an unauthorised payment system, which is an offence under the Act and carries the risk of a wind-down directive.
What actually happens: a D2C brand builds a slick checkout, holds settlement money for two days in its own current account before paying merchants, and calls it a tech feature. Eighteen months later a bank partner runs a review before renewing the nodal account, flags that funds are being pooled without a PA licence, and freezes settlements. The brand now has merchant money it cannot legally move and a customer base it cannot refund on time. That is a PSS Act problem, and no amount of ISO certification fixes it.
PA and PG: the two words people use interchangeably and should not
PA is Payment Aggregator. PG is Payment Gateway. They are governed by the RBI Guidelines on Regulation of Payment Aggregators and Payment Gateways, and the distinction is the whole game.
- A Payment Aggregator (PA) enters the flow of funds. It collects money from customers, holds it, and settles to merchants. Because it touches the money, it needs RBI authorisation and must maintain funds in an escrow account with a scheduled commercial bank.
- A Payment Gateway (PG) provides only the technology to route and process a transaction. It never takes possession of the funds. A pure PG does not need PA authorisation, but RBI expects it to follow the baseline technology and security requirements laid out in the same guidelines.
- The trap: many teams describe themselves as a gateway because it sounds lighter, while their architecture actually pools funds. RBI does not care what you call it. It cares whether money touches your account.
| Question the examiner asks | PA answer | PG answer |
|---|---|---|
| Do you hold customer funds at any point? | Yes, in escrow | No, never |
| Do you need RBI PA authorisation? | Yes | No |
| Escrow with a scheduled commercial bank? | Mandatory | Not applicable |
| Net-worth requirement | Rs 15 crore rising to Rs 25 crore | No prescribed net-worth |
| PCI DSS in scope? | Yes, if handling card data | Yes, if handling card data |
The net-worth numbers are real and they bite. A PA must have a minimum net worth of Rs 15 crore at application and Rs 25 crore by the end of the third financial year. Founders who assumed a gateway-lite path suddenly discover they need a capital plan, an escrow arrangement, a board-approved information security policy, and a System Audit Report from a CERT-In empanelled auditor before RBI will even process the application.
NPCI and the rails: UPI, IMPS, AePS, NACH, RuPay
NPCI runs the plumbing that most Indian fintech products are built on. You will meet these acronyms the moment you integrate, and each one drags its own compliance obligations behind it.
| Acronym | Full form | What it is and why it matters |
|---|---|---|
| UPI | Unified Payments Interface | Real-time account-to-account payments. Governed by NPCI UPI procedural guidelines; PSP and TPAP roles carry distinct audit duties. |
| IMPS | Immediate Payment Service | 24x7 interbank fund transfer. Predates UPI, still used for many payout flows. |
| AePS | Aadhaar-enabled Payment System | Cash-in/cash-out using Aadhaar biometrics. High fraud sensitivity; ties directly into UIDAI security norms. |
| NACH | National Automated Clearing House | Bulk debits and credits: EMIs, salaries, SIPs, mandates. The backbone of recurring collections. |
| RuPay | RuPay card scheme | Domestic card network. Card data handling here pulls you straight into PCI DSS scope. |
On UPI specifically, know your role. A PSP (Payment Service Provider) is the bank-sponsored entity that connects to the UPI switch. A TPAP (Third-Party Application Provider) is the app that offers the UPI interface to users, riding on a PSP bank. If you build a UPI app, you are almost certainly a TPAP, and NPCI has explicit requirements around data localisation, on-soil storage of UPI transaction data, and periodic audits. Getting your role wrong here means you cannot answer the most basic audit question about who is accountable for what.
AUA, KUA and Sub-AUA: the Aadhaar roles nobody reads carefully
If you touch Aadhaar, UIDAI defines exactly what you are allowed to do through a set of roles, and the security obligations differ sharply between them. Confusing them is one of the fastest ways to fail a UIDAI audit.
- AUA, Authentication User Agency. An entity that uses Aadhaar authentication to verify a resident. It sends an authentication request to the CIDR (Central Identities Data Repository) and gets a yes or no back.
- KUA, KYC User Agency. A subset of AUA that is additionally permitted to receive e-KYC data, meaning demographic details and photograph, after successful authentication and consent. Every KUA is an AUA; not every AUA is a KUA.
- ASA, Authentication Service Agency. The entity with a secure leased-line connection to the CIDR that routes requests on behalf of AUAs. You typically connect to the CIDR through an ASA.
- Sub-AUA. An entity that offers Aadhaar services to its customers through a parent AUA, without a direct contract with UIDAI. Common for fintechs that ride on a larger AUA's licence.
The security consequence is concrete. UIDAI requires that Aadhaar numbers be stored only in a reference-key form, tokenised, and that any stored Aadhaar data live in an encrypted Aadhaar Data Vault with strict HSM-backed key management. UIDAI mandates a compliance audit by an empanelled auditor, and its aims and objects around information security are non-negotiable. I have seen a KYC-heavy lender store raw Aadhaar numbers in a logging table because a developer added debug logging that was never removed. That single line of code is a reportable UIDAI breach and a personal-data exposure under the DPDP Act in the same stroke.
NBFC, PPI and the entity types that set your rulebook
Some acronyms are not products; they are what you are. And what you are decides which master direction you live under for the rest of your regulated life.
| Acronym | Full form | Core obligation |
|---|---|---|
| NBFC | Non-Banking Financial Company | RBI registration; capital, KYC/AML, and for digital lending, the Digital Lending Guidelines including the FLDG framework. |
| PPI | Prepaid Payment Instrument | Wallets and prepaid cards. Governed by the RBI Master Directions on PPIs; escrow and KYC tiers apply. |
| LSP | Lending Service Provider | An agent acting for a lender in digital lending. Named explicitly in RBI digital lending norms; you must be disclosed to the borrower. |
| FLDG | First Loss Default Guarantee | The risk-sharing arrangement between an LSP and a regulated lender, now capped and formalised by RBI. |
| RE | Regulated Entity | RBI shorthand for the licensed party, typically the bank or NBFC, that carries ultimate accountability. |
Here is the uncomfortable structural truth of Indian fintech: in most partnership models, the RE, the bank or NBFC, holds the licence and therefore the liability, while the fintech holds the product and the customer. When the audit comes, the RE will push every control obligation it can onto you contractually. If you are an LSP riding on a bank's NBFC, your security posture is not just your problem; it is the audit finding that lands on your partner's desk and threatens the partnership itself.
The security and audit acronyms that decide your evidence pile
Once your entity type and product are settled, a second layer of acronyms defines what you actually have to prove. These are the ones that generate the artefacts an auditor asks for.
- PCI DSS, Payment Card Industry Data Security Standard. If you store, process or transmit card data, you are in scope. The SAQ or ROC and your quarterly ASV scans are non-negotiable evidence.
- SAR, System Audit Report. RBI requires a SAR from a CERT-In empanelled auditor for PA authorisation and for various payment-system entities. This is not a generic pentest; it maps to a defined scope.
- CERT-In, the empanelment and the 6-hour rule. Under the April 2022 directions, specified cyber incidents must be reported to CERT-In within 6 hours of noticing them, and logs must be retained for 180 days on Indian soil.
- DPDP, Digital Personal Data Protection Act 2023. India's data protection law. It layers over everything above: every Aadhaar record, every KYC document, every transaction log is personal data with consent, breach-notification and data-principal-rights obligations.
- VAPT, Vulnerability Assessment and Penetration Testing. The recurring technical test almost every regulator and partner bank now asks for, typically annually and after major changes.
Do not confuse a SAR with a VAPT. A VAPT tells you whether an attacker can break in. A System Audit Report tells RBI whether your entire control environment, governance, escrow reconciliation, data localisation, incident response and merchant onboarding, meets the payment-system requirements. Both are needed, and they are not substitutes for one another.
What the whole alphabet costs you in time and money
Founders always ask for the number. There is no single number, but there are honest ranges. These are indicative Indian-market figures for a mid-sized fintech, and they move with scope and firm.
| Requirement | Typical timeline | Indicative cost (INR) |
|---|---|---|
| PA authorisation prep and SAR | 3 to 6 months | 15 to 40 lakh incl. audit and readiness |
| PCI DSS (Level 1, ROC) | 3 to 5 months | 12 to 30 lakh first year |
| UIDAI compliance audit (AUA/KUA) | 4 to 8 weeks | 4 to 10 lakh |
| Annual VAPT | 3 to 6 weeks | 2 to 8 lakh per cycle |
| DPDP readiness programme | 2 to 4 months | 6 to 20 lakh depending on data estate |
The costs that hurt are never the audit fees. They are the remediation. A PA applicant who discovers, mid-SAR, that reconciliation between the escrow and the settlement ledger is manual and unauditable will spend far more rebuilding that flow than they ever paid the auditor. Budget for the fix, not just the finding.
The fix-it checklist before your next examination
If you do nothing else after reading this, run your product through the list below. Every item maps to a question a real examiner or partner-bank auditor will ask.
- Write down, in one sentence, whether you are a PA or a PG, and confirm your fund flow actually matches that claim. If money touches your account, you are a PA.
- Confirm your legal entity type, NBFC, PPI issuer, LSP, TPAP, PSP, and identify the exact RBI or NPCI master direction that governs it.
- If you touch Aadhaar, confirm your AUA/KUA/Sub-AUA role, that Aadhaar is tokenised in an Aadhaar Data Vault, and that no raw Aadhaar sits in logs, databases or backups.
- Verify escrow reconciliation is automated and produces a daily, auditable trail between customer collections and merchant settlements.
- Confirm card data scope for PCI DSS is minimised, tokenised where possible, and that your last ASV scan and ROC/SAQ are current.
- Check your CERT-In readiness: a documented 6-hour incident-reporting runbook, a named point of contact, and 180 days of logs retained in India.
- Map every category of personal data you hold to a DPDP lawful basis, a consent record, and a retention and deletion rule.
- Ensure your System Audit Report scope and your VAPT scope are both defined, current, and signed off by a CERT-In empanelled auditor.
The point of learning the alphabet
Go back to that quiet audit room. The founder who freezes on PA versus PG is not stupid; they are just discovering, in public, that a word they used loosely on a pitch deck was actually a regulatory declaration. Every acronym in this glossary is a small contract with a regulator. Use the right one and the audit is a formality. Use the wrong one and you find out during an examination, which is the most expensive possible time to learn.
At CyberSigma we sit on the auditor side of that table as CERT-In empanelled assessors and PCI QSAs, and we do this hands-on, mapping your fund flows and data flows to the exact directions that govern them before RBI or a partner bank does it for you. If you want a second pair of eyes on which of these acronyms actually apply to your build, we are happy to have that conversation early, when it is cheap to fix.
FAQs
What is the difference between a Payment Aggregator and a Payment Gateway?
A Payment Aggregator (PA) enters the flow of funds, collecting money from customers and settling to merchants, and therefore needs RBI authorisation and an escrow account with a scheduled commercial bank. A Payment Gateway (PG) provides only the technology to route transactions and never holds funds, so it does not need PA authorisation. The test is simple: if money touches an account you control, you are a PA, whatever you call yourself.
Do I need RBI approval to run a payment system in India?
Yes, if you operate a payment system as defined under the Payment and Settlement Systems Act, 2007, you must be authorised by RBI. Running a payment system without authorisation is an offence under the Act and exposes you to a wind-down directive. For most fintechs handling merchant collections, the relevant authorisation is the Payment Aggregator licence.
What is the difference between AUA and KUA under UIDAI?
An AUA (Authentication User Agency) can send Aadhaar authentication requests to verify a resident and receive a yes or no result. A KUA (KYC User Agency) is a subset of AUA that is additionally permitted to receive e-KYC data, the resident's demographic details and photograph, after successful authentication and consent. Every KUA is an AUA, but not every AUA is a KUA.
Is NPCI a regulator?
No. NPCI is a not-for-profit company owned by banks that operates payment rails such as UPI, IMPS, RuPay, NACH and AePS. It is not a statutory regulator like RBI. However, its procedural guidelines, audit requirements and circulars bind you in practice, and NPCI can suspend your access to the rails, so treat its rules as mandatory.
What is a System Audit Report and how is it different from a VAPT?
A System Audit Report (SAR) is a defined-scope audit, required by RBI for payment-system entities such as Payment Aggregators, that assesses your entire control environment, governance, escrow reconciliation, data localisation and incident response, and must be signed by a CERT-In empanelled auditor. A VAPT (Vulnerability Assessment and Penetration Testing) is a narrower technical test of whether an attacker can break in. You typically need both; they are not substitutes.
How does the DPDP Act affect fintech acronyms like AUA and PPI?
The Digital Personal Data Protection Act, 2023 layers over every other framework. Aadhaar data handled as an AUA or KUA, KYC documents for a PPI or NBFC, and transaction logs are all personal data under DPDP. That means you need a lawful basis, consent records, breach-notification processes and mechanisms to honour data-principal rights, on top of the sector-specific RBI, NPCI and UIDAI obligations.
Liked the post? Share on:




Leave A Comment