UK credit data and open finance solve related but different information problems. Credit-reference agencies receive account-performance data from lenders and other subscribers, combine it with public records and identity data, and supply reports and analytical products. The three main consumer CRAs are Experian, Equifax and TransUnion, but each file can differ because suppliers do not currently have to report identical information to all three. A CRA file is not a universal credit score: each CRA can display its own score and each lender applies its own risk, affordability, fraud and policy models. Consumers can obtain statutory credit-file information free and dispute inaccuracies. The FCA’s 2023 market study found a highly concentrated market, incomplete and inconsistent data, low consumer awareness and slow governance. Its February 2026 consultation proposed mandatory reporting by credit and mortgage firms that already share with at least one future designated CRA, plus accuracy obligations; that consultation closed on 1 May and is not yet a final rule. Open banking is different: it lets a customer authorise a regulated third party to access payment-account data or initiate a payment through standard APIs. The FCA reported approximately 17 million users in April 2026. Open finance would extend permissioned access toward mortgages, savings, investments and pensions. The Data (Use and Access) Act 2025 supplies regulation-making powers and a route to FCA oversight of financial Smart Data interfaces; it does not automatically compel every financial provider to expose every dataset. The FCA’s April 2026 roadmap runs to 2030, prioritising SME credit and mortgages and targeting regulatory-framework options with HM Treasury by the end of 2027. Trust will depend on data quality, authentication, purpose limitation, revocation, security, commercial incentives and clear responsibility when data or decisions fail.
More data does not automatically produce a fairer credit decision. A lender may see a thin credit file, a rich stream of bank transactions, an identity signal and an affordability model—and still need to decide which data are reliable, relevant and lawful. The system’s quality depends on provenance and accountability as much as access.
This guide separates persistent credit-reporting data from customer-permissioned API access. It builds on Kurums’ UK open-banking guide, consumer-credit map and digital-identity and fraud infrastructure analysis.
Is a credit score the number a lender uses?
Not necessarily. CRA consumer scores are educational indicators; lenders combine data with their own risk, affordability, fraud and policy models.
Does open banking replace a credit file?
No. It adds permissioned, current payment-account data. Credit files provide a longer shared history and public-record layer; the sources can complement one another.
Did the 2025 Act switch on open finance?
No. It created powers and oversight foundations. Detailed regulations, rules, standards, interfaces and governance are still needed for a mandatory scheme.
What information problem does credit reporting solve?
A lender cannot directly observe whether every applicant has repaid obligations elsewhere. Credit reporting creates a shared record of accounts, balances, limits, payment performance and arrears, combined with identity and public information. That can reduce adverse selection, support responsible lending, detect fraud and let reliable borrowers demonstrate a history beyond one institution.
Sharing also creates power and error risk. A missed payment can affect access and price across the market; a mismatched identity or stale default can follow the wrong person; sparse history can look like high risk. Governance must therefore cover what is reported, matching, timeliness, disputes and correction. The objective is decision-useful information, not the largest possible dataset.
Who supplies data to UK credit-reference agencies?
Banks, card issuers, mortgage and consumer lenders, telecoms, utilities and other subscribers can report account information under contracts and industry data standards. CRAs also obtain electoral-register data, county court judgments, bankruptcies and insolvency records from public sources. Addresses, aliases and financial associations help match records but can also propagate errors if identity resolution is weak.
The three main consumer CRAs are Experian, Equifax and TransUnion, all requiring FCA authorisation for regulated credit-reference activity. Other authorised firms and specialist data providers operate in the market. The FCA said 22 firms held the Providing Credit References permission in October 2025, but permissions do not mean every firm has equivalent coverage, products or consumer scale.
Why can the three main credit files differ?
A data supplier can choose which CRA or CRAs it reports to, subject to its arrangements. Update cycles, matching, public-record feeds and dispute status can also differ. An account appearing at one CRA may therefore be absent or shown differently at another. A lender may search one, two or three agencies and may contribute to a different combination.
That fragmentation can disadvantage consumers whose positive history is missing and lenders whose view is incomplete. It also means checking one report may not reveal every issue. The ICO advises consumers that they may need reports from all three and can ask lenders which agencies they use. Differences are not automatically errors, but material inaccuracies require investigation.
Credit file, credit score and lending decision are not the same
The credit file contains underlying records. A CRA can transform that information into a score, attribute or risk model. A consumer-facing score helps explain direction but is not a universal UK number. Ranges and methods differ, and the score shown to a consumer may not be the precise product purchased by a lender.
The lender combines CRA information with application data, income and expenditure, existing relationship, fraud indicators, collateral, product economics and its credit policy. Credit risk asks whether repayment is likely; affordability asks whether the customer can repay without undue difficulty; eligibility applies product rules. A high CRA score cannot compel a lender to approve credit or explain every decline.
How can a consumer access and correct a credit file?
An individual can request information about their financial standing from a CRA free of charge. The ICO advises looking for the statutory-report route rather than assuming a paid subscription is required. The CRA normally responds within one month after receiving enough identity information, with limited extension rights for complex cases under data-protection law.
For an inaccurate entry, the consumer can contact the CRA and the organisation that supplied it. The supplier is often responsible for the account record, while the CRA remains responsible for reasonable accuracy measures and its own matching data. Unresolved data-protection concerns can go to the ICO; a financial dispute may belong with the firm and FOS. A notice of correction can add context but is not a substitute for correcting objective error.
What lawful basis allows credit data to be processed?
CRAs and lenders do not necessarily rely on consent to process credit-reference information. UK data-protection law permits processing under an appropriate lawful basis, commonly legitimate interests or legal obligation depending on purpose, with transparency and necessity safeguards. The absence of a consent button therefore does not itself make credit reporting unlawful.
Accuracy, fairness, purpose limitation, data minimisation, security, retention and individual rights still apply. Article 5 accuracy requires reasonable steps to keep personal data correct and erase or rectify inaccurate data without delay. Automated decision-making rules can be relevant to solely automated decisions with legal or similarly significant effects. Governance should document both the input data and the accountable decision process.
What did the FCA’s Credit Information Market Study find?
The FCA’s December 2023 final report followed an interim assessment of competition, data quality, consumer engagement and governance. It found a highly concentrated market with barriers to entry and expansion, poor coverage and inconsistency in shared data, limited consumer awareness and governance that was slow and not sufficiently representative.
The remedy package spans FCA rules and industry work: improve data coverage, quality and consistency; strengthen consumer access and awareness; foster competition and innovation; and reform governance. A new Credit Information Governance Body has been established to progress industry-led elements. The implementation status of each remedy matters—market-study intent is not the same as an enforceable rule.
What did the FCA propose in February 2026?
CP26/7 proposed that credit and mortgage firms already sharing consumer credit information with at least one agency designated by the FCA would have to share the same information with the other designated agencies. Connected proposals address accuracy and quality, including marking a county court judgment or Scottish decree satisfied when the debt has been repaid and the firm has the required information.
The aim is more consistent and comprehensive files without initially forcing non-sharing firms to begin sharing. The consultation closed on 1 May 2026, and the FCA is considering responses at this guide’s July review date. Terms such as Designated Consumer Credit Reference Agency describe the proposed framework; firms should wait for final policy, rules, designation and implementation dates before treating the proposal as live law.
How is open banking different from credit reporting?
Open banking lets a customer authorise a regulated account-information service to access payment-account data or a payment-initiation service to start a transfer through secure interfaces. Access is purpose-specific and revocable rather than a persistent industry credit file built through reciprocal reporting. It began through the CMA Order and payment-services framework.
Open-banking data can show current income, expenditure, cash-flow volatility and commitments, helping a lender assess affordability or an SME automate accounts. It may be especially useful where a conventional credit file is thin. But a few months of transactions can miss long-term defaults, closed accounts or public records. Combining sources can improve insight while increasing privacy, model and explanation obligations.
How large is UK open banking in 2026?
The FCA reported approximately 17 million users in April 2026, close to one in three UK adults. Open Banking Limited reported more than 17 million user connections, over two billion monthly API calls and more than 34 million monthly payments by May. Connection counts can include the same person at multiple bank brands, so definitions should accompany adoption claims.
Scale changes the governance question. Open banking is no longer a small innovation pilot: tax payments, accounting, credit, sweeping and recurring-payment products depend on its availability. Industry is designing a Future Entity to set common API standards, while the FCA expects to consult on a long-term regulatory framework before the end of 2026, subject to the necessary powers and legislation.
What would open finance add?
Open finance would extend customer-permissioned data access beyond payment accounts toward savings, investments, mortgages, pensions and potentially insurance. A household could view assets, liabilities, fees and cash flows in one service; an SME could present richer information for credit. Providers could compare, switch, advise or support using more complete and current data.
The label does not define one API or permission. Each product has different data, legal ownership, valuation frequency, beneficiaries, advisers and harm risks. Pension projections are not the same as bank transactions; investment cost data can require product and platform layers; mortgage data combines property, balance and contractual terms. Standards must preserve meaning, not merely move fields.
What does the Data (Use and Access) Act 2025 do?
Part 1 creates powers for government and HM Treasury to make Smart Data regulations requiring holders to supply customer or business data to the customer or an authorised third party. Regulations can address data, standards, security, accreditation, onward use, fees and enforcement. Section 14 enables a route for the FCA to oversee financial-services interface bodies and participants.
The Act received Royal Assent on 19 June 2025. Its regulation-making powers are an enabling framework, not a complete open-finance mandate. Detailed secondary legislation and FCA rules must define which firms, products, datasets and interfaces enter a scheme. Describing all financial data as already portable under the Act would confuse statutory capacity with implemented obligation.
What is in the FCA’s April 2026 open-finance roadmap?
The roadmap sets a delivery path to 2030. The FCA prioritises SME access to credit and consumer mortgage journeys, using its Smart Data Accelerator and a PRISM taskforce to test and rank use cases. TechSprints between November 2025 and February 2026 brought together 17 firms and generated more than 92,000 synthetic-data calls for mortgage and SME prototypes.
The FCA plans to work with HM Treasury on regulatory-framework options by the end of 2027. Firms can develop services sooner where data access and permissions already exist, but voluntary bilateral access is not the same as a universal scheme. The roadmap must coordinate with the permanent open-banking framework, Future Entity, digital identity, data protection, Consumer Duty and sector-specific product rules.
What permissions and consent controls are needed?
An open-finance service may require permissions for account information, payment initiation, credit information, advice, arranging or other regulated activity depending on what it does. Receiving data does not authorise a firm to make a personal recommendation or execute a transaction. The Financial Services Register should identify the responsible legal entity and relevant permissions.
Customer authorisation should be informed, specific and easy to revoke. Dashboards need to show which provider has which data, for what purpose and duration. A data recipient should not retain a broad dataset merely because an API made it available. Re-authentication, access expiry, delegated business users, bereavement and vulnerable-customer support need consistent journeys across the data holder and recipient.
Where do liability, security and data quality sit?
A poor outcome can originate with the data holder, interface body, API, receiving fintech, analytics vendor or final financial provider. Contracts and scheme rules need to allocate incident response, correction, service levels and economic loss without making the customer diagnose the chain. Regulatory responsibility for the final service remains with the firm performing it, even when inputs are outsourced.
Security covers authentication, encryption, certificate management, consent integrity, monitoring and recovery. Data quality covers definitions, completeness, freshness, matching and provenance. Availability without semantic consistency can create confident errors at scale. Firms should reconcile critical fields, expose timestamps and sources, test model sensitivity and create a human route when the customer disputes the data or inference.
How should lenders combine credit and cash-flow data?
Start with a defined decision purpose. Credit-file performance can evidence longer-term repayment and public events; open-banking transactions can evidence current affordability and cash-flow. Identity and fraud signals help confirm that the applicant and accounts belong together. The lender should measure incremental predictive value and disparate outcomes rather than assume that more variables are inherently fair.
Models need validation, explainability, change control and overrides. Decline reasons should identify material drivers in language the customer can act on where possible. Missing API history should not silently become a negative signal. Consent withdrawal requires an operating policy for data already used in a decision. Data correction must propagate to reconsideration when the error was material.
A trust framework for UK open finance
A credible scheme aligns six layers: legal mandate, common semantics, secure interfaces, third-party accreditation, commercial funding and customer redress. Governance should represent data holders, fintechs, consumers and smaller firms without letting one group control standards. Performance and incident metrics should be public enough to support accountability while protecting security-sensitive details.
Success should be measured in outcomes: faster appropriate SME credit, lower switching friction, better mortgage journeys, corrected data, accessible consent and fewer avoidable harms. Connection and API-call totals show scale, not value. The transition from open banking to open finance will be durable only if customers can understand access, stop it, correct information and obtain a prompt remedy when the multi-firm chain goes wrong.
Frequently Asked Questions
Are Experian, Equifax and TransUnion files identical?
No. Suppliers may report to different agencies, and matching or update timing can differ. A consumer may need to check more than one file, especially when investigating a refusal or error.
Must a consumer pay to see a statutory credit report?
No. The ICO says people can request information about their financial standing free of charge. Subscription products may add monitoring or scores, but they are not required to exercise the access right.
Can open-banking data guarantee a loan approval?
No. It can enrich affordability and cash-flow evidence, but the lender applies its own credit, fraud, eligibility and policy criteria. Consent to data access is not a promise of credit or a particular price.
Is every open-finance dashboard regulated in the same way?
No. Permissions depend on the activities performed—data access, payments, credit information, arranging or advice can have different perimeters. Customers should identify the responsible entity and service.
When will UK open finance be complete?
There is no single completion date. The FCA roadmap runs to 2030 and targets framework options with HM Treasury by the end of 2027, while open-banking reform and specific use cases progress on separate tracks.
Primary Sources and Further Reading
This guide prioritises regulators, payment-system operators and company filings. Figures are the latest available at the July 2026 review date.
- FCA — Credit Information Market Study
- FCA — CP26/7 proposed credit-information remedies
- FCA — Proposed action on gaps in credit files
- ICO — Credit-reference information and consumer rights
- ICO — UK GDPR accuracy principle
- FCA — Credit-reference agency authorisation
- FCA — Open finance roadmap to 2030
- FCA — April 2026 open-finance announcement
- FCA — Smart Data Accelerator
- FCA — Open-finance mortgage and SME TechSprints
- UK Legislation — Data (Use and Access) Act 2025 explanatory notes
- FCA — Future Entity for UK open banking
- Open Banking Limited — Future Entity design and 2026 scale
Discover more from Kurums | Business Intelligence
Subscribe to get the latest posts sent to your email.


