

A business that wants to issue regulated prepaid payment instruments such as wallets or prepaid cards in India must operate within the RBI's PPI framework. Eligible non-bank entities require a Certificate of Authorisation under the Payment and Settlement Systems Act, 2007, while banks require RBI approval.
For non-bank applicants, the process involves eligibility checks, minimum net worth, fit-and-proper assessment, RBI scrutiny, in-principle approval, system audit and final authorisation. This guide explains the current requirements and application process.
This requires RBI regulatory approval. For non-bank PPI issuers, the formal regulatory instrument is a Certificate of Authorisation (CoA) under the Payment and Settlement Systems Act, 2007. The term ‘PPI licence’ is commonly used to describe this authorisation.
The simplest way to understand a PPI licence is to separate company formation from payment authorization. Registering a company lets the entity exist. It does not automatically let that entity issue wallets or prepaid cards.
PPI licence is the commonly used term for the RBI permission required to issue regulated prepaid payment instruments in India. For an eligible non-bank entity, the formal permission is a Certificate of Authorisation issued under the Payment and Settlement Systems Act, 2007. Eligible banks require RBI approval under the applicable PPI framework.
With that authorization in place, the company can issue and operate the prepaid payment system covered by the approval. The instrument itself holds value loaded in advance for later spending. Banks can participate in the PPI framework as well, subject to the required approval.
The need for authorization depends on the role a company plans to take in the payment flow. Using prepaid technology, building an app, or distributing another company's product does not automatically place a business in the position of a regulated PPI issuer.
Authorization becomes relevant when the company plans to:
A closed-system balance that can be used only to buy goods or services from the issuing entity is not treated as a payment system requiring RBI approval or authorisation under the PPI framework, as it cannot be used for third-party payments. A company working with an existing authorized issuer may also have a different structure.
Obtaining PPI authorisation involves more than submitting paperwork. RBI looks at the applicant as a regulated payment-system operator. The company has to be legally eligible, properly governed, and capable of running the proposed system with suitable controls.
The following areas need attention before filing:
A non-bank applicant must be a company incorporated in India. If the applicant is regulated by another financial-sector regulator, it must obtain the required No Objection Certificate from that regulator and submit it with the RBI application in accordance with the prescribed timeline.
The company's Memorandum of Association should include the proposed activity of PPI issuance. The stated business objects need to match the regulated activity being proposed.
Foreign investment has to comply with the applicable Indian investment rules. Foreign investment must comply with applicable Indian investment rules. Additional restrictions apply to certain investments from jurisdictions identified by the Financial Action Task Force as non-compliant.
RBI can assess the applicant, its directors, promoters, and management for fit-and-proper status. Governance quality forms part of the wider regulatory review.
The proposed system needs secure transaction processing, customer access, monitoring, recordkeeping, and system controls. Technology and security are examined before approval.
Policies and internal responsibilities should cover KYC, anti-money laundering controls, customer protection, risk management, information security, audits, and regulatory reporting.
The financial threshold changes over the life of the authorization. A non-bank applicant does not need ₹15 crore on the day it applies. The starting requirement is lower, with a higher level becoming mandatory after final authorization.
The main thresholds are:
| Stage | Required Positive Net Worth |
|---|---|
| At the time of application | ₹5 crore |
| Until the higher threshold applies | ₹5 crore maintained |
| By the end of the third financial year from the date of final authorisation | ₹15 crore |
| After that point | ₹15 crore maintained |
The ₹5 crore requirement is measured against the latest audited balance sheet at application. A Chartered Accountant certificate is also required.
A newly incorporated company without audited financial statements can submit a CA certificate on current net worth with a provisional balance sheet. After authorization, a non-bank PPI issuer has to provide annual net-worth certification based on audited financial statements.
The application process is designed to test both the company and the system it wants to operate. RBI does not treat the filing itself as authority to issue PPIs. The business has to clear several gates before it reaches final approval.
Those gates are:
Prepare the corporate papers, financial information, management records, and other documents needed for the application.
Submit the prescribed authorisation application through RBI's designated portal, together with the required documents and application fee. Under the PSS Regulations, the prescribed application is Form A, and the application fee is ₹10,000 excluding applicable GST.
RBI first checks whether the applicant appears eligible and whether the filing is complete enough to proceed.
The review can cover how customers will be served, how the system will be secured, whether the technology is adequate, who will manage the business, and how the proposed payment system will operate.
If the applicant satisfies the eligibility and regulatory assessment, RBI may grant in-principle approval valid for six months. The applicant must submit the required System Audit Report within this period. A one-time extension of up to six months may be requested with valid reasons, but RBI may decline the request.
The applicant then completes its procedures, controls, technology, and implementation work.
A satisfactory system audit and the prescribed net-worth evidence must be submitted within the approval period, subject to any extension available.
After receiving the final Certificate of Authorisation, the entity must commence the authorised business within six months. A one-time extension of up to six months may be sought in advance with valid reasons, subject to RBI approval.
Authorization gives an issuer a defined payment-system role. The service range depends on the approved product structure, the PPI category, and the conditions that apply to the issuer.
The approved setup may cover areas such as:
| Service Area | What It Can Cover |
|---|---|
| Prepaid wallets | Wallet-based prepaid value under the applicable PPI framework |
| Prepaid cards | Physical or virtual card-based PPIs |
| Merchant payments | Payments for eligible goods and services |
| Fund transfers | Transfers where the relevant PPI category permits them |
| Cash withdrawal | Cash access for eligible Full-KYC PPIs under applicable conditions |
| Special-purpose PPIs | PPIs with specific regulatory provisions |
Small PPIs and Full-KYC PPIs do not carry the same transaction functions. Full-KYC instruments can support purchases, transfers, and eligible cash withdrawals, while Small PPIs have narrower use.
The authorization has a defined scope. Banking, accepting deposits, lending, unrestricted foreign-exchange activity, and other separately regulated payment businesses require their own legal and regulatory basis.
An issuer's authorization status can change, and the brand customers see may differ from the legal entity holding the approval. Checking the official records is the safer way to verify whether a bank or non-bank entity is permitted to issue PPIs in India.
The RBI maintains separate records for bank and non-bank PPI issuers. You can check the current lists here:
When checking an issuer, use the legal entity name shown in the RBI record instead of relying only on the consumer-facing brand. Review the latest available authorization status before using it for a commercial or compliance decision.
The authorization allows the payment system to begin operating. From that point onward, the issuer has to keep the approved setup in working order. A lapse in finance, customer checks, records, technology, or complaint handling can become a compliance issue long after launch.
Ongoing compliance broadly covers six areas:
The required positive net-worth level has to be maintained, not achieved only at the application stage. Annual certification also forms part of the ongoing requirement.
Once transactions start flowing, the technology stack needs regular scrutiny. Non-bank issuers carry continuing cyber-security and system-audit obligations. Proposed major changes to product features, processes, structure or operation of the payment system must also be communicated to RBI in accordance with the applicable requirements.
Customer verification is only the first layer. The issuer must continue applying the relevant KYC and anti-money laundering requirements and keep transaction monitoring active.
Funds collected through the PPI structure have to be handled according to the applicable safeguarding and settlement rules.
The issuer needs a grievance process that works in practice. Customers must have a way to raise transaction problems, unauthorized activity, and other account concerns.
The business also needs a dependable paper trail. Transaction data, customer information, audit evidence, and regulatory submissions must remain available when required.
RBI’s June 15, 2026 Master Directions reset the reference point for payment-system authorization. The directions consolidate rules that affect how an entity gets authorized, maintains financial eligibility, handles certain investments, exits voluntarily, and deals with cooling-period requirements.
PPI issuers must apply those general authorization rules alongside the requirements specific to prepaid instruments. The Certificate of Authorization remains valid on a perpetual basis while its conditions are met. Older guidance that assumes a normal five-year validity period no longer matches the current framework.
A company considering its own PPI license needs to decide first if it will act as the regulated issuer. From there, the work spans corporate eligibility, financial readiness, technology, governance, RBI authorization, and continuing compliance. The approval creates an ongoing regulated role, with responsibilities that continue after launch.
They cover different regulated activities. PPI authorization concerns issuing and operating prepaid payment instruments. Payment aggregator authorization covers merchant-payment aggregation under a separate regulatory framework. RBI maintains separate Master Directions for these activities.
Yes. RBI may return an application that is incomplete, not in the prescribed form or does not meet prima facie eligibility requirements. It may also reject an application after regulatory assessment. The consequences of a returned application and a rejected application can differ, including in relation to cooling-period rules.
Yes. An authorized payment-system operator can seek voluntary surrender of its Certificate of Authorization. The current authorization framework includes a process for surrender and the handling of outstanding obligations.
The issuer has to address customer balances, liabilities, records, and other regulatory obligations before the payment-system activity closes. The steps depend on the circumstances and the conditions that apply to the closure or surrender.
A one-year cooling period can apply in specified circumstances, including where an authorisation is revoked or voluntarily surrendered, or an application is refused. It can also apply to certain new entities promoted by persons connected with such cases. The exact treatment depends on the circumstances and the applicable RBI provisions. The treatment depends on what happened to the earlier application or authorization, including refusal, surrender, or revocation.