Open Banking
Open banking is regulated access to bank account data and to payment initiation through APIs, with the account holder’s consent. In the European Union and the United Kingdom it is a licensed activity under payment services law, not a private arrangement between a fintech and a bank.
Also called: account access · PSD2 APIs
Two distinct services sit under the label. Account information lets an authorized provider read a customer’s account data — balances and transactions — with that customer’s consent. Payment initiation lets a provider instruct a payment out of the customer’s own bank account, again on consent, so money moves by bank transfer rather than by card. Both are set out in the European Union under PSD2, and in the United Kingdom under the equivalent domestic regime supervised by the Financial Conduct Authority.
Where it applies
Open banking is not one global system. In the EU and the UK it rests on a statutory obligation on banks, with an authorization regime around the firms that use it. Some markets run it as a central-bank scheme. In others, including much of the United States, comparable access has grown out of commercial data aggregation and bilateral agreements rather than a single statutory framework. The word travels further than the regulation does, so check which regime a provider is actually operating under.
For a merchant, the attraction of payment initiation is that funds arrive as a bank transfer with no card chargeback right attached — which also means a dissatisfied customer has a different route to redress, not no route.
In practice
Open banking gives consented access to accounts and the ability to initiate payments from them. It does not give the accessing firm any right to hold customer funds — a firm that also wants to receive or hold the money is carrying on a separate regulated activity that its open banking permission does not cover.
Example
A UK accounting app reads a client’s bank feed under an account information permission. When it adds a “pay this bill” button, the payment is initiated from the client’s own account straight to the supplier. The app never receives the money. To collect it first and pay the supplier later, it would need different permissions and a way to safeguard the funds in between.
Commonly confused with
| Term | How it differs |
|---|---|
| PSD2 | PSD2 is the EU law that created the obligation on banks; open banking is the practice that grew out of it and out of equivalents elsewhere. |
| Screen scraping | Screen scraping reads an account using the customer’s own login credentials; regulated open banking uses authorized access through the bank’s API. |
See also
- PSD2PSD2, the Second Payment Services Directive, is the EU law governing payment services. It sets the authorization categories for payment firms, opened bank account access to licensed third parties, and required strong customer authentication for electronic payments.
- Financial Conduct AuthorityThe Financial Conduct Authority is the United Kingdom’s conduct regulator for financial services. It decides whether a payments or e-money firm may operate in the UK, authorizes or registers it, and supervises how it behaves afterwards.
- Payment InstitutionA payment institution is a firm authorized in the United Kingdom or a European Union member state to provide payment services — transfers, acquiring, remittance, payment initiation — but not to issue electronic money. It may hold customer funds in payment accounts used only for payment transactions; those funds are neither deposits nor e-money.
- Electronic Money InstitutionA firm authorized in the United Kingdom or in an EU member state to issue electronic money and to provide payment services. The e-money it issues is a claim its holders have against the institution, redeemable at par and expressly not a deposit, which is why the funds behind it must be safeguarded.
