Summary
- RBI's PA-CB (Payment Aggregator – Cross Border) framework, introduced on October 31, 2023, requires all non-bank entities aggregating cross-border payments in India to hold a direct RBI authorization, replacing the older, lightly regulated OPGSP model.
- Three PA-CB categories exist: PA-CB-E (export only), PA-CB-I (import only), and PA-CB-E&I (export and import). Non-bank entities must maintain a minimum net worth of ₹15 crore at application, rising to ₹25 crore by the end of the third financial year.
- FEMA governs all foreign exchange transactions in India. Following the RBI's November 2025 amendment, Indian exporters now have 15 months (18 months for INR-settled exports) to repatriate export proceeds, extended from the earlier 9-month limit.
- All merchants receiving international payments must complete full KYC under CKYCR from January 2026, with September 15, 2026, as the deadline for existing merchant KYC completion.
- Every international payment must be tagged with the correct RBI purpose code. Wrong or missing codes delay settlement, trigger bank queries, and complicate FEMA audits and GST export claims.
- FIRA (Foreign Inward Remittance Advice) is the current standard proof of foreign payment receipt, required for FEMA compliance, income tax filing, GST reconciliation, and eBRC generation for goods exporters.
- Pay10 holds RBI authorization as a PA-CB (Export & Import) and Online Payment Aggregator, with automatic FIRA generation, correct purpose code tagging, and FEMA-aligned merchant onboarding built into every settlement.
Introduction
Receiving an international payment looks simple from the outside: a customer pays, the money arrives, and the business continues. Behind that transaction, however, is a regulatory framework that governs how the money moves, what documents prove it arrived correctly, how long the merchant has to bring it into India, and what happens if any of these steps are handled incorrectly.
For Indian merchants, whether exporters of goods, SaaS companies billing overseas clients, D2C brands selling internationally, or freelancers receiving foreign income, understanding RBI's cross-border payment rules is not optional. It is the foundation on which compliant, predictable international revenue is built.
This guide covers the complete regulatory framework in plain language: the PA-CB framework that changed the industry in 2023, FEMA's role, KYC requirements, purpose codes, and the compliance documents every merchant needs to maintain.
The PA-CB Framework - The Most Important RBI Rule for Cross-Border Payments
The most significant change to cross-border payment regulation in India in recent years came on October 31, 2023, when the Reserve Bank of India issued its circular on the regulation of Payment Aggregators – Cross Border (PA-CB). This framework replaced the older Online Payment Gateway Service Provider (OPGSP) model, under which non-bank entities facilitated cross-border payments without holding a direct RBI license, with a mandatory authorization requirement.
Under the PA-CB framework, every non-bank entity that aggregates online cross-border payments for Indian merchants must hold a valid RBI PA-CB authorization. Operating without one is not a grey area - it is a regulatory violation. For merchants, this matters directly: the payment provider handling your international transactions must itself be PA-CB licensed, or the compliance trail behind your settlements is incomplete.
The three PA-CB categories:
- PA-CB-E (Export only): Authorizes inward cross-border collections - money coming into India from foreign customers for goods or services exported. Entities must maintain a dedicated Inward Collection Account (InCA) with an AD Category-I bank.
- PA-CB-I (Import only): Authorizes outward cross-border payments, money going out of India to pay foreign vendors or suppliers. Entities must maintain a dedicated Outward Collection Account (OCA).
- PA-CB-E&I (Export and Import): Full authorization for both inward and outward cross-border transactions with strict requirements that InCA and OCA funds are never commingled.
Key compliance requirements under PA-CB:
- Minimum net worth of ₹15 crore at the time of application, rising to ₹25 crore by the end of the third financial year from authorization
- Mandatory FIU-IND registration as a pre-requisite to the RBI authorization application, making all PA-CBs reporting entities under PMLA
- Maximum transaction value of ₹25 lakh per unit of goods or services, applying to both inward and outward flows
- All FX conversion must happen through AD Category-I banks - PA-CBs cannot buy or sell foreign currency directly
- From January 2026, merchant KYC must be conducted via the Central KYC Registry (CKYCR) as the mandatory first step
Power everyday transactions with secure digital payment infrastructure built to support scale, speed, and convenience.
FEMA - The Foundation of Cross-Border Payment Compliance
The Foreign Exchange Management Act (FEMA) is the primary legislation governing all foreign exchange transactions in India, and it applies to every international payment an Indian merchant sends or receives. FEMA does not operate in isolation from the PA-CB framework; the two work together. PA-CB governs who can aggregate cross-border payments; FEMA governs how those payments must be handled once they arrive.
For Indian exporters and service providers, FEMA's most operationally important rule is the export proceeds realization period, the deadline by which foreign payment must arrive in India after export. Following the RBI's amendment effective November 2025, this period is now
Key compliance requirements under PA-CB:
- 15 months from the date of shipment (goods) or invoice date (services) - extended from the earlier 9-month limit
- 18 months where the export is invoiced or settled in Indian Rupees - a deliberate RBI incentive to encourage more bilateral trade to settle in INR
Missing this deadline without a valid extension from an AD bank can result in the export entry being flagged as overdue in EDPMS, repeated delays leading to caution listing, and in serious cases, FEMA penalties and Enforcement Directorate scrutiny. Exporters whose payment is genuinely delayed should apply to their AD bank for an extension before the deadline, not after.
FEMA also defines what cross-border payments are prohibited entirely: inward remittances for online gambling, lottery winnings, and illegal trading activities are not permitted under any circumstances, regardless of the payment provider used.
KYC Requirements for Merchants Under RBI's PA-CB Rules
Full KYC is mandatory for all merchants receiving international payments through a PA-CB-authorized platform, with two limited exemptions: merchants with annual domestic turnover below ₹40 lakh or annual export turnover below ₹5 lakh. All other merchants must complete full KYC, regardless of transaction volume or business size.
From January 1, 2026, CKYCR (Central KYC Registry) is the mandatory first point of verification for merchant KYC under the RBI's PA Directions 2025. This means the PA-CB provider must check CKYCR before completing onboarding — not just collect documents independently. For existing merchants on PA-CB platforms, the deadline to complete full CKYCR-aligned KYC is September 15, 2026.
Standard KYC documents for merchant onboarding:
- PAN card
- Business registration certificate (or partnership deed, LLP agreement, or memorandum of association as applicable)
- Proof of business address
- Bank account details with a cancelled cheque or bank statement
- Identity proof of the authorized signatory
- Beneficial ownership declaration for entities above specified thresholds
Name consistency across all KYC documents- the exact legal business name, PAN, GSTIN, and bank account holder name- is the single most common cause of merchant onboarding delays. A discrepancy between the business name on the KYC document and the bank account triggers verification holds that can delay the first international settlement by days or weeks.
Pay10 helps businesses manage global payment flows with trusted cross-border infrastructure and enterprise-ready payment capabilities.
RBI Purpose Codes - Why Every Cross-Border Payment Must Be Tagged
Every international payment received in India must be tagged with an RBI purpose code, a classification system that tells the bank and regulator what the foreign currency receipt is for. Purpose codes are not optional. They are a mandatory part of the inward remittance process under FEMA, and they determine how the transaction is categorized in the banking system, EDPMS, and regulatory reporting.
Using the wrong purpose code, or submitting a transaction without one, can delay settlement while the bank investigates, trigger a query from the forex desk, complicate GST zero-rating claims on export of services, and create inconsistencies in EDPMS records that affect eBRC generation.
Commonly used purpose codes for Indian merchants:
| Type of Receipt | Purpose Code |
|---|---|
| Software development, IT services, SaaS | P0802 |
| Business consulting, management advisory | P1006 |
| Graphic design, content, creative services | P0806 |
| Marketing, SEO, digital advertising | P1007 |
| Goods export (non-software) | Varies by HS category |
Cash flow is everything for a growing D2C brand. International payments come with uncertainty about when money will actually arrive, how much will remain after FX conversion, and what documentation proves the receipt. These are not abstract concerns, and they affect inventory planning, supplier payments, and the brand's ability to reinvest in growth between sales cycles.
The right purpose code depends on what was actually delivered, not the platform used to receive the payment, not the invoice description, but the nature of the underlying goods or service. Confirming the correct code with a CA or your payment provider during onboarding, rather than after a payment is already in review, is the most practical way to avoid purpose code problems.
FIRA, FIRC, and eBRC - The Compliance Documents Every Merchant Needs
Three documents form the compliance paper trail for international payments received in India. Understanding what each one is, who issues it, and when it is needed keeps merchants audit-ready and eligible for export incentives.
FIRA (Foreign Inward Remittance Advice)
It is the current standard proof of foreign inward remittance for all export and service-related payments in India, replacing FIRC for these transactions since 2016 under RBI's EDPMS framework. FIRA is issued by the merchant's AD bank or payment platform, and contains the transaction reference, sender details, foreign currency amount, INR equivalent, exchange rate, and RBI purpose code. It is required for FEMA compliance, income tax filing, GST reconciliation, and as the prerequisite document the AD bank needs to generate an eBRC.
FIRC (Foreign Inward Remittance Certificate)
It is now issued only for capital account transactions, primarily Foreign Direct Investment (FDI) and Foreign Institutional Investment (FII). For export and service payments, FIRC has been replaced by FIRA. Merchants asking their bank for a FIRC for an export receipt are asking for the wrong document, it simply will not be issued for these transactions.
eBRC (Electronic Bank Realisation Certificate)
Links the received payment to a specific export shipment or invoice and is mandatory for GST refunds on export inputs and for DGFT export incentive claims, including RoDTEP and duty drawback. It is issued by the AD bank after matching the payment to the relevant shipping bill or SOFTEX form and is uploaded to the DGFT portal. Service exporters, SaaS, IT, consulting, and freelancers generally do not need an eBRC; FIRA is sufficient for their compliance purposes.
FEMA requires all inward remittance documentation to be maintained for a minimum of five years. Merchants who do not collect and archive FIRA for every international payment discover the gap only when a tax assessment or FEMA audit requires documentation they no longer have.
What RBI's Rules Mean for Choosing a Cross-Border Payment Provider
The practical consequence of the PA-CB framework for Indian merchants is straightforward: the payment provider handling your international collections must hold a valid RBI PA-CB authorization. Using a non-PA-CB-licensed provider does not shield the merchant from compliance exposure; the settlement trail is still incomplete, FIRA may not be generated correctly, purpose codes may not be tagged, and the AD bank routing may not meet FEMA requirements.
When evaluating a cross-border payment provider, the compliance checklist matters as much as the pricing:
- Does the provider hold a valid RBI PA-CB authorization - E, I, or E&I?
- Are funds routed through an InCA or OCA at an AD Category-I bank?
- Is FIRA generated automatically for every eligible inward remittance?
- Are RBI purpose codes tagged correctly as part of the settlement workflow?
- Is merchant KYC handled through CKYCR as required from January 2026?
- Does the platform hold PCI-DSS and ISO 27001 certifications?
A provider that meets all of these criteria handles the regulatory compliance layer automatically; the merchant receives settlements that are already documented, correctly classified, and audit-ready. A provider that does not meet these criteria leaves the merchant responsible for filling the compliance gaps manually, often after the fact.
How Pay10 Keeps Indian Merchants Cross-Border Compliant
Pay10 holds RBI authorization as a PA-CB (Export & Import) and as an Online Payment Aggregator, covering both inward collections from global customers and outward payments to foreign vendors under a single, direct RBI license. Every element of the cross-border compliance framework described in this guide is built into Pay10's platform by design.
Merchant onboarding follows FEMA-aligned KYC workflows with CKYCR integration. Every inward remittance is automatically tagged with the correct RBI purpose code, reducing the risk of EDPMS mapping errors or bank queries. FIRA is generated for every eligible settlement and is available directly from the merchant dashboard, without requiring a separate bank request. Funds are settled to the merchant's verified Indian bank account via AD 1 bank routing within T+2/T+3 business days, in accordance with FEMA's export realization framework.
Pay10 supports 100+ currencies with real-time FX conversion through AD bank partnerships at transparent rates, with no hidden markup embedded in the conversion spread. PCI-DSS Level 1 and ISO 27001:2022 certifications apply across the platform.
For Indian merchants ready to build a compliant, predictable international payment setup, explore Pay10's international payment gateway or get in touch with the Pay10 team.
Conclusion
RBI's cross-border payment regulations are not designed to slow down international business; they are designed to make it more secure, more traceable, and more predictable for every party involved. The PA-CB framework, FEMA's realization timelines, purpose code requirements, KYC obligations, and documentation standards together create a compliance environment that protects Indian merchants as much as it regulates them.
For merchants, the practical takeaway is simple: choose a payment provider that meets the full compliance checklist, and the regulatory complexity resolves itself in the background. The settlements arrive documented, the FEMA trail is clean, and the compliance position is audit-ready without requiring a dedicated legal or finance function to maintain it.
The risk is concentrated entirely on the other side: merchants who use non-PA-CB-licensed providers, skip purpose code tagging, or fail to collect FIRA consistently are building compliance gaps that surface at the worst possible moment.
Why Businesses Trust Pay10 | RBI Authorized Payment Aggregator | PCI-DSS Compliant | ISO 27001 Certified | 100+ Payment Options | Advanced Fraud Prevention & Risk Monitoring | Trusted by Enterprises & Growing Businesses | Scalable Infrastructure for India & Cross-border | Enterprise-grade Payment Technology | Secure UPI & Digital Payment Solutions




