Introduction
Open banking refers to a regulatory and technological framework that enables consumers to share their financial data with authorised third-party providers through standardised application programming interfaces, subject to explicit user consent. The model replaces an earlier practice known as screen scraping — in which third-party applications required users to share banking login credentials directly — with secure, token-based API connections in which the user’s credentials are never transmitted to external parties.
The framework has material implications for how financial data flows across the banking system. By mandating that institutions expose structured data interfaces to authorised parties, open banking regulation has created the technical conditions for a new class of financial products spanning personal finance management, alternative credit underwriting, account-to-account payment initiation, and automated accounting integration.
Two regulatory regimes have defined the open banking landscape to date. The European Union’s revised Payment Services Directive, known as PSD2, came into force in January 2018 and established mandatory API access requirements across EU member states. The United Kingdom implemented its Open Banking Standard simultaneously, initially covering the nine largest retail banks. Together, these frameworks have produced ecosystems of thousands of API-connected applications, while exposing structural gaps in consumer adoption, regulatory consistency, and cross-border interoperability that analysts say remain unresolved.
What Open Banking APIs Are and How They Function
An application programming interface, or API, is a defined technical protocol through which two software systems exchange data in a structured format. In the context of open banking, APIs serve as the channel through which a regulated financial institution transmits customer account data — or executes payment instructions — to an authorised third-party provider at the account holder’s direction.
Prior to the introduction of mandatory open banking frameworks, third-party financial applications commonly accessed bank account data through screen scraping: a process in which the application used the customer’s banking credentials to log into the bank’s consumer interface and extract data by reading the screen output. This approach was insecure, unreliable, and provided no audit trail visible to the bank. Open banking APIs replace this model with a formally authenticated, tokenised connection that does not involve credential sharing.
Under PSD2, open banking APIs are structured around two primary service categories. Account Information Services, or AIS, provide authorised third parties with read access to a customer’s account data, including transaction history, balances, and account details. Payment Initiation Services, or PIS, enable authorised third parties to instruct the bank to execute a payment directly from the customer’s account without routing the transaction through a card network.
Third-party providers seeking to operate within these frameworks must be registered and authorised by their relevant national competent authority — the Financial Conduct Authority in the United Kingdom, or the equivalent regulator in each EU member state. Banks are required to implement Strong Customer Authentication protocols for all API connections, and consumers must provide explicit consent for each third-party connection, with the ability to revoke access at any time through their bank’s application.
Regulatory Frameworks: PSD2, the UK Open Banking Standard, and Global Equivalents
The EU’s PSD2 Framework
PSD2 represents the most structurally comprehensive open banking mandate implemented globally. Enacted by the European Parliament and effective from January 2018, it requires all banks and payment service providers operating in EU member states to provide API access to authorised third parties for both account information and payment initiation purposes. The directive applies uniformly across the EU, though implementation was carried out by national regulators, producing variation in technical standards and enforcement intensity across member states.
Industry participants have identified the absence of a single harmonised technical standard as a persistent limitation of the EU framework. Adnan Chowdhury, UK policy lead at cross-border payments firm Wise, noted in published commentary that without a single standard, the majority of firms in the EU struggled to gain traction without relying on third-party intermediaries — a structural friction that the UK’s more harmonised approach was intended to avoid.
The UK Open Banking Standard
The UK framework predates PSD2 by approximately one year. In 2017, the Competition and Markets Authority concluded a market investigation into retail banking that identified the concentration of market power among the largest institutions as a barrier to competition. The CMA subsequently mandated that the nine largest UK banks — collectively referred to as the CMA9 — implement a standardised open banking framework enabling secure data sharing with authorised third parties.
The UK standard has produced a measurably larger installed base of open banking connections than its EU counterpart, in part due to its greater technical standardisation. However, industry analysis indicates that open banking remains used by approximately 10% of the UK adult population, with use cases concentrated in a relatively narrow range of applications rather than embedded in daily financial behaviour.
Global Frameworks
Open banking regulatory frameworks have been implemented or are under development in multiple jurisdictions beyond the EU and UK, including Australia, Brazil, Singapore, and Nigeria, among others. Adoption rates and compliance levels vary substantially. Wise’s Chowdhury noted that in Australia, where an open banking equivalent exists under the Consumer Data Right framework, limited adoption and compliance has constrained the value the system currently delivers. Analysts at the Banking Industry Architecture Network have pointed to Singapore as a jurisdiction demonstrating relative success in driving adoption, citing its approach to consumer education and industry coordination.
Key Applications and Use Cases
Personal Finance Management
Open banking AIS connections enable consumer-facing applications to aggregate account data from multiple institutions into a single interface. This allows users to view consolidated balances, categorise transactions, and monitor cash flow across bank accounts, credit facilities, and savings products held at different institutions — functionality that was previously unavailable without credential sharing.
Alternative Credit Underwriting
Lending platforms use open banking transaction data to assess creditworthiness on the basis of observed income, expenditure patterns, and financial behaviour over periods ranging from 90 days to two years or more. This model provides a data-based supplement or alternative to traditional credit scoring, which relies primarily on historical credit product usage and may not accurately reflect the financial position of individuals with limited credit histories.
Account-to-Account Payments
PIS-enabled open banking connections allow payment initiation directly from a consumer’s bank account, bypassing card networks entirely. Industry data indicates that card payment transaction costs typically range from 1.5% to 3% of transaction value, while account-to-account payments facilitated via open banking APIs carry materially lower per-transaction costs. GoCardless, a payment processing firm active in the open banking payments segment, has indicated that account-to-account payment initiation is positioned to become a primary alternative to card payments, contingent on broader infrastructure development.
Variable Recurring Payments
Variable Recurring Payments, or VRPs, represent a more advanced payment use case enabled under the UK Open Banking Standard. VRPs allow authorised third parties to initiate recurring payments of variable amounts from a consumer’s bank account within pre-agreed parameters, without requiring separate authorisation for each individual transaction. The Joint Regulatory Oversight Committee announced a commercial VRP pilot programme in 2024. Industry participants note that mass adoption of VRPs remains a multi-year objective.
Fraud Detection and Accounting Automation
Open banking transaction data supports real-time fraud detection systems by enabling continuous analysis of account activity against established behavioural baselines. In business contexts, API-based bank feed integrations allow accounting and bookkeeping platforms to automate transaction reconciliation, reducing manual data entry and improving the accuracy of financial reporting.
Costs, Competitive Implications, and Industry Structure
The introduction of mandatory API access requirements has altered the competitive dynamics of retail banking by reducing the data asymmetry that previously favoured incumbent institutions. Prior to open banking regulation, transaction history and behavioural data resided exclusively within the originating bank’s systems, limiting the ability of third-party providers to offer competing products based on that data.
By requiring institutions to make this data accessible — with consumer consent — open banking frameworks have lowered the informational barriers to entry for fintech providers operating in lending, payments, and financial management categories. Industry observers note, however, that the practical competitive impact has been constrained by low consumer awareness, limited use case development, and the continuation of data access on terms set primarily by incumbent institutions.
For businesses adopting A2A payment infrastructure, the cost differential relative to card-based acceptance is material. The reduction in per-transaction fees can represent a meaningful reduction in payment processing costs at scale, though the business case depends on the availability of open banking payment options across the customer base and the maturity of dispute resolution infrastructure.
Risks, Limitations, and Regulatory Gaps
Consumer Protection and Liability
Regulatory frameworks governing liability for open banking transactions have not kept pace with the growth of the technology. The UK’s Future of Payments Review, published in recent years, identified a need for greater clarity regarding consumer protection and liability allocation in open banking payment scenarios — particularly in cases of fraud or disputed transactions. James Hickman, Chief Commercial Officer of Ecospend, noted that some of the regulatory framework surrounding open banking technology still lags behind its actual deployment, most notably in terms of consumer protection provisions.
Adoption Gap
Open banking in the UK is used by approximately 10% of the adult population, according to figures cited by NatWest. Hans Tesselaar, executive director at the Banking Industry Architecture Network, has noted that open banking has been primarily initiated and supported by regulators rather than consumer demand, resulting in incremental rather than transformational progress. He has identified increased consumer education on the benefits and security implications of open banking as a prerequisite for broader adoption.
Interoperability
The proliferation of different open banking standards across jurisdictions creates friction for cross-border financial service providers. The absence of interoperability between open banking frameworks means that a provider operating in multiple markets must maintain separate technical integrations for each jurisdiction. Wise has identified interoperability across different open banking setups as a foundational challenge for the long-term global utility of the technology.
Future Outlook
The trajectory of open banking development is shaped by three concurrent processes: regulatory evolution, infrastructure maturation, and consumer adoption.
On the regulatory side, the European Commission is developing PSD3 and an open finance framework intended to address limitations identified in the PSD2 implementation, including the absence of a uniform technical standard and gaps in consumer protection provisions. The UK is separately progressing toward an open finance regime that would extend data portability principles beyond payment accounts to include investment, insurance, and pension products.
Infrastructure development — including the expansion of VRP capabilities, integration of open banking payments into digital wallets, and improvements to dispute resolution mechanisms — is expected to progress over a multi-year timeline. Industry participants including GoCardless have indicated that achieving the infrastructure conditions necessary for open banking payments to operate as a primary card alternative will require years rather than months.
Consumer adoption remains the most structurally uncertain variable. The gap between the availability of open banking-enabled services and their use by the broad population reflects a combination of limited awareness, constrained use case breadth, and residual concerns about data security. Regulatory and industry stakeholders have identified consumer education as a necessary condition for closing this gap, with Singapore cited as a reference jurisdiction for effective adoption strategy.
Conclusion
Open banking APIs have established the technical and regulatory foundation for a materially more competitive and data-portable financial services market. PSD2 in the EU and the Open Banking Standard in the UK have created frameworks that enable account information access and payment initiation for authorised third parties, generating a significant ecosystem of API-connected applications across lending, payments, personal finance management, and business accounting.
Progress to date has been uneven. Consumer adoption remains limited relative to the installed base of available services, regulatory frameworks in areas including consumer protection and liability continue to lag deployment, and cross-border interoperability remains unresolved. The development of open finance — extending data portability principles to a broader range of financial products — represents the next regulatory frontier, with implementation timelines measured in years. The foundational infrastructure is in place; the conditions for its full utilisation are still being constructed.

