ZHENESJAKOTHVIRUFRAR

Open Banking

One-Line Definition

Open Banking is a regulatory and technical framework that lets licensed third parties access your bank account data — and, with your explicit consent, initiate payments from it — through standardized APIs rather than screen-scraping or manual bank transfers.

The Real-Life Analogy

Think of your bank account as a house with a single, old-fashioned front door. For decades, only you (with your key) and the bank (with a master key) could get in. If you wanted a mortgage broker to see your statements, you printed them out. If you wanted to pay a friend, you logged into your bank's app and typed in their details.

Open Banking installs a standardized, permissioned side entrance. You can hand a vetted third party a temporary key that opens only specific rooms — say, your transaction history for the last 12 months — and nothing else. You can revoke that key at any time. The third party never gets your actual login credentials, and the bank can't pretend the door doesn't exist, because regulation requires it to be there.

The Core Formula

Open Banking = Consent + Licensed TPP + Standardized API + Bank Account

Broken down:

- Consent: You, the account holder, explicitly authorize access. Consent is granular (which data, which account, how long) and revocable.

- Licensed TPP (Third-Party Provider): The company accessing your data must be authorized by a regulator — in the UK by the FCA, in the EU under PSD2. There are two main flavors: AISPs (Account Information Service Providers, which read data) and PISPs (Payment Initiation Service Providers, which move money).

- Standardized API: The bank exposes a machine-readable interface. In Europe this is often built on Berlin Group's NextGenPSD2 standard; in the UK it's the Open Banking Implementation Entity (OBIE) standard.

- Bank Account: The data source and/or funding source. The bank remains the custodian of the money; Open Banking does not move custody.

Remove any one element and it isn't Open Banking. A fintech that asks for your bank password is doing screen-scraping, not Open Banking. A crypto wallet that holds your funds is custodial, not Open Banking.

Comparison with Related Terms

TermWhat it doesWho holds the moneyRegulatory basisTypical example
**Open Banking**Reads account data and/or initiates payments via bank APIs with consentThe bankPSD2 (EU), CMA Order (UK), similar regimes elsewhereA budgeting app pulling transactions from 5 banks
**Open Finance**Extends the same API-and-consent model beyond payments to investments, pensions, insuranceThe underlying institutionEmerging frameworks (e.g., UK Smart Data, EU FIDA proposal)An app showing your pension, ISA, and mortgage in one view
**Screen-scraping**Third party logs in as you and reads the pageThe bankOften unregulated or toleratedOlder budgeting tools asking for your online banking password
**Card networks**Move money via card rails (Visa, Mastercard)Issuer/acquirerCard scheme rulesPaying online with a saved card
**Custodial wallets / neobanks**Hold your funds on their own balance sheetThe fintechVaries (e-money, banking license)Revolut, Wise balances
**Bank APIs (proprietary)**Bank's own developer interface, not necessarily consent-based or regulatedThe bankContractA corporate treasury tool using a bank's direct API

The key distinction: Open Banking is permissioned, regulated, and non-custodial. The bank keeps the money; the third party gets scoped access.

Use Cases

1. Account aggregation and personal finance management. Apps like Yolt (now closed), Money Dashboard, and Emma pull balances and transactions from multiple banks into one dashboard. This was the original headline use case.

2. Credit underwriting and affordability checks. Lenders use AISP access to verify income and spending in real time instead of asking for PDF statements. In the UK, this has become standard for buy-now-pay-later and SME lending. Faster, less fraud-prone, and more inclusive for thin-file borrowers.

3. Payment initiation (pay-by-bank). A PISP initiates a credit transfer directly from your account to a merchant, bypassing card networks. This is cheaper for merchants (often a flat fee vs. ~1.5–2.5% card interchange) and settles faster. Common in the EU for e-commerce, utility bills, and iGaming.

4. Sweeping and cash-flow management for SMEs. Accounting platforms like Xero and QuickBooks use Open Banking feeds to reconcile transactions automatically, and treasury tools sweep idle balances into higher-yield accounts.

5. Identity and KYC. Account ownership checks — "does this person really control this bank account?" — are used for onboarding, payroll verification, and fraud prevention.

6. Variable recurring payments (VRP). A UK-specific evolution: instead of a one-off payment, you authorize a merchant to pull up to a capped amount on a recurring basis — a card-subscription replacement with better control.

Misconceptions

"Open Banking means my data is public." No. Access requires your explicit, granular consent, and you can revoke it. The data flows only to the specific licensed party you authorize.

"Open Banking is the same as Open Finance." Open Banking covers payment accounts. Open Finance extends the model to investments, pensions, insurance, and mortgages. The UK and EU are both moving toward it, but coverage is still partial.

"It's a European thing only." Europe and the UK are the most mature because PSD2 and the CMA Order mandated it, but similar regimes exist or are emerging in Australia (Consumer Data Right), Brazil (Banco Central's Open Finance), India (Account Aggregator framework), Singapore (SGFinDex), and the US (Section 1033 of the Dodd-Frank Act).

"It's free for everyone." Banks bear significant API and compliance costs, and some markets are debating premium APIs and commercial model. For merchants, pay-by-bank is usually cheaper than cards, but not free.

"It replaces cards." Not yet. Pay-by-bank has lower conversion at checkout in many markets because it adds friction (redirect to bank, authenticate). It's growing fast in specific verticals but cards remain dominant for consumer e-commerce.

"Any app can do it." Only regulated TPPs with the right permissions can. Unlicensed apps asking for your bank login are not Open Banking.

Related Terms

- PSD2 — EU Payment Services Directive 2, the legal basis for Open Banking in Europe.

- AISP — Account Information Service Provider, licensed to read account data.

- PISP — Payment Initiation Service Provider, licensed to initiate payments.

- TPP — Third-Party Provider, umbrella term for AISPs and PISPs.

- SCA (Strong Customer Authentication) — The authentication requirement (two of three factors) that applies to Open Banking access and payments.

- VRP (Variable Recurring Payments) — UK framework for consented, capped recurring payments.

- Open Finance — Extension of Open Banking to non-payment financial products.

- Berlin Group NextGenPSD2 — A common European API standard.

- OBIE — Open Banking Implementation Entity, the UK standard-setting body.

- Section 1033 — US rulemaking to give consumers control over their financial data.

- Account Aggregator — India's consent-based data-sharing framework.

- Consumer Data Right (CDR) — Australia's cross-sector data portability regime.