Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚡ TL;DR
UK open banking lets authorised providers access account data or initiate payments through standardised bank APIs when a customer gives explicit consent. It began with a competition order imposed on nine large banks, then grew into infrastructure supporting more than 19 million active user connections and over 40 million monthly payments by mid-2026. The next phase is commercial variable recurring payments, a permanent standards body and open finance extending permissioned data sharing beyond current accounts.

Open banking is often described as “sharing financial data,” but that phrase understates the system. It is a coordinated set of technical standards, authorisation rules, customer-consent journeys, bank interfaces, directory services and operating obligations. Its purpose is to let a customer use an authorised third party without handing over online-banking credentials or becoming locked into the account provider’s own app.

The UK became an early global reference because open banking was mandatory for the largest retail banks rather than a collection of voluntary bilateral integrations. This guide explains the architecture, economics and unresolved governance questions behind the open-banking layer of the United Kingdom Finance & Fintech Hub.

Editorial scope: This is business education, not personal financial, legal or investment advice. Rules, permissions and protection depend on the specific regulated entity and product.
Key Takeaways

Why did UK open banking begin?
The Competition and Markets Authority required major banks to open standardised access after finding weak competition in retail banking.

What can authorised providers do?
Account-information providers can retrieve permissioned data; payment-initiation providers can ask a bank to execute a customer-approved payment.

What comes after open banking?
Commercial recurring bank payments, a durable standards and governance body, and open finance covering products such as savings, investments and pensions.

A UK Open-Banking TransactionCustomerGives consentFintechAISP or PISPBank APIData or paymentOutcomeInsight or transferThe bank authenticates its customer; the authorised provider receives only the consented access needed for the service.
The bank authenticates its customer; the authorised provider receives only the consented access needed for the service.

Why was open banking created as a competition remedy?

The Competition and Markets Authority concluded that established UK banks were not competing hard enough for personal and small-business current-account customers. Incumbents held transaction histories and customer relationships inside closed systems, making it difficult for new services to compare accounts, automate decisions or initiate payments. Switching alone could not solve that data advantage.

The 2017 Retail Banking Market Investigation Order required the CMA9 banks and building society to implement common API standards. The design turned account access from a private bilateral privilege into a governed capability available to authorised providers. Regulation created the initial market because no single bank had an incentive to make its data advantage interoperable on equal terms.

Who are the CMA9 and what did Open Banking Limited build?

The CMA9 are the major account providers named by the order: Allied Irish Bank, Bank of Ireland, Barclays, Danske, HSBC, Lloyds Banking Group, Nationwide, NatWest Group and Santander. They funded the implementation entity that became Open Banking Limited. OBL developed the API standard, security profile, customer-experience guidance and directory supporting trusted participants.

That implementation structure was effective for delivering a remedy, but it was never an ideal permanent governance model for an expanding national ecosystem. By 2026 work was under way on a future entity and long-term regulatory framework. The next body must preserve neutral standards while accommodating firms beyond the CMA9, commercial schemes and products that were not contemplated when the order began.

What is an AISP and what is a PISP?

An account information service provider, or AISP, retrieves account and transaction data with the customer’s consent. Use cases include account aggregation, affordability assessment, cash-flow forecasting, accounting automation and personalised financial management. The service may be visible to the user or embedded inside another regulated journey such as a credit application.

A payment initiation service provider, or PISP, sends a payment request to the customer’s bank after consent and authentication. It does not pull money from the account like a card merchant or hold the customer’s bank credentials. The underlying transfer normally travels over an account-to-account rail such as Faster Payments, explained in the UK payment-systems guide.

How do consent and strong customer authentication work?

The customer chooses a provider and purpose, selects a bank, reviews the requested data or payment and is redirected or deep-linked to the bank for authentication. The bank confirms identity using its own strong customer-authentication controls and returns an authorised result. The third party receives tokens and scoped access rather than reusable online-banking credentials.

Consent must be informed, specific and revocable. Good design says which accounts, data categories, purpose and duration apply and provides a usable way to withdraw. A technically valid consent can still be poor if language is vague, the benefit is unclear or revocation is hidden. Firms must manage token expiry, reconfirmation, changed permissions and data deletion as product states, not exception cases.

💡 Pro Tip: Treat consent as a product lifecycle: grant, use, refresh, change, revoke and delete. A polished authorisation screen is only the first state.

How large was UK open banking by mid-2026?

Open Banking Limited reported 24 billion successful API calls during 2025, up 27% from 2024, and 351 million payments, up 57%. User connections reached 16.5 million by December 2025. By June 2026 the ecosystem supported more than 19 million active user connections and more than 40 million open-banking payments each month.

Connections are not identical to unique individuals because one person or business can connect several accounts or services. Even with that qualification, the trajectory shows that open banking moved beyond a pilot population. The infrastructure now has to meet mainstream expectations for uptime, fraud prevention, customer support and governance while preserving space for smaller providers.

What business problems does account information solve?

For consumers, aggregated data can produce budgeting, subscription management, savings prompts and a consolidated financial view. For lenders, permissioned transaction data can complement traditional credit files and verify income or expenditure. For SMEs, bank feeds can automate bookkeeping, cash positioning, forecasting and covenant monitoring across several institutions.

The value is not the raw transaction list; it is the decision or workflow built from it. Providers must categorise data accurately, explain uncertainty and avoid inferring more than consent supports. A lending model that uses transaction data creates fairness, model-risk and adverse-action questions. An accounting product creates reconciliation and audit-trail obligations. Open access removes one barrier but not the professional duty around the outcome.

How does pay-by-bank compete with cards?

A pay-by-bank checkout initiates an account transfer from the customer’s bank rather than sending card credentials through a scheme. Merchants can receive faster confirmation, reduce card-related fees and match payments using structured references. High-value ecommerce, account funding, tax, debt repayment and business invoices are natural use cases because card cost or limits are material.

The comparison is not fee versus fee alone. Cards provide broad acceptance, familiar checkout, recurring credentials, credit and mature chargeback rules. Open-banking payments need clear refund and dispute arrangements and may convert differently by customer segment. A merchant should test total acceptance cost, fraud, failure, support and repeat usage, then offer the method where its strengths are real.

What are Variable Recurring Payments?

Variable Recurring Payments allow a customer to create consent for a series of bank payments whose amount or timing can vary within agreed parameters. Sweeping VRP, used to move money between accounts owned by the same person, came first. Commercial VRP aims to support merchant and service-provider payments that currently rely on cards or Direct Debit.

VRP combines flexibility with explicit controls such as maximum amount, frequency, beneficiary and consent duration. That makes it powerful but governance-heavy: pricing, dispute allocation, liability, fraud controls and service levels must be agreed across participants. In June 2026 the FCA welcomed the launch of the UK Payments Initiative, a commercial scheme intended to advance cVRP.

Capability Customer permission Typical use Underlying movement
AIS Read specified account data Aggregation, affordability, accounting Data only; no payment
Single payment initiation Approve one payment Pay-by-bank checkout or account funding Usually Faster Payments for domestic GBP
Sweeping VRP Recurring transfers within parameters Move money between a customer’s own accounts Account-to-account rail
Commercial VRP Recurring merchant payments within parameters Subscriptions and variable bills Commercial scheme above bank rails
ℹ️ Context: Open banking initiates many payments but does not replace the underlying sterling rail. API success and payment settlement are separate dependencies.

What is the Future Entity and why does governance matter?

A standard used by banks, fintechs and millions of customers needs a permanent body that can maintain specifications, certify conformance, coordinate change and represent participants without being captured by incumbents. The government’s 2026 Payments Forward Plan expected industry to establish a standards body capable of becoming the Future Entity during the second half of 2026.

The governance problem is economic as well as constitutional. Core standards create public value, but maintenance costs money. Banks, third parties, merchants and customers benefit differently. Funding rules must not let the largest contributors dictate technical direction or price smaller innovators out. The Future Entity also needs clear accountability to the FCA’s long-term open-banking framework.

How is open finance different from open banking?

Open banking focuses mainly on payment accounts and payment initiation. Open finance extends permissioned data access to a wider financial life: savings, investments, pensions, insurance, mortgages and potentially other credit products. A broader view can improve advice, switching, underwriting and financial planning because decisions no longer depend on one current account.

Breadth also raises the stakes. Investment holdings and pension data are long-term and sensitive, product definitions differ and erroneous advice can cause substantial harm. The FCA’s April 2026 roadmap sets a path to 2030 and links open finance to the Data (Use and Access) Act 2025. Sequencing, liability, identity and data-quality standards will determine whether breadth creates value or simply more exposure.

What are the main fraud and consumer-protection risks?

Open-banking APIs reduce credential sharing, but they do not eliminate social engineering, malicious providers, account takeover or authorised push-payment fraud. A genuine consent can be obtained from a manipulated customer. Payment initiation can also give victims less recovery time than a card dispute. Firms must monitor device, session, beneficiary and behavioural signals without turning every transaction into an obstacle.

Data services create different risks: excessive retention, secondary use, opaque scoring and breaches. Providers need data minimisation, purpose controls, encryption, supplier governance and a clear deletion path. Customers need to know who is responsible when the bank, third party or downstream service fails. A sustainable ecosystem cannot rely on technical consent as a substitute for understandable accountability.

⚠️ Risk: Customer authentication proves control of an account, not freedom from manipulation. Social-engineering controls remain essential for pay-by-bank.

Why do API performance and standardisation matter commercially?

A provider cannot build a reliable product on APIs that behave differently by bank, fail unpredictably or return inconsistent data. Standardisation lowers integration cost and lets product teams focus on customer value. OBL publishes availability, response-time and failure metrics; in May 2026 weighted average availability was 99.98% and failed calls represented a small share of overall volume.

Averages can still hide bank-specific or journey-specific problems. Fintechs need bank-level observability, retry rules that do not create duplicate actions, graceful degradation and honest status messaging. Merchants using pay-by-bank should route or offer alternatives when an institution is unavailable. Shared infrastructure becomes commercially valuable only when exceptions are engineered as carefully as the happy path.

How should a company implement open banking responsibly?

Begin with one measurable customer problem. Define the minimum data or payment permission needed, expected benefit, retention period and fallback. Choose an authorised partner or permission strategy, verify directory status and allocate responsibility for authentication, support, fraud, refunds and complaints. Build consent records that can be explained to both customers and auditors.

Then measure end-to-end outcomes: connection success by bank, payment conversion, API latency, consent renewal, fraud, complaints, refund time and customer savings. Do not celebrate API calls as the outcome. The winning implementation is one in which customers understand the exchange, receive a better service and can leave cleanly. Infrastructure scale should make trust more visible, not less.

What does the UK model teach other countries?

The UK shows that common standards and mandatory participation can break a coordination failure that voluntary integrations struggle to solve. A neutral directory, strong authentication and regulated third parties can create a competitive application layer above bank accounts. Adoption then compounds as accounting platforms, lenders, merchants and consumers reuse the same infrastructure.

It also shows that launching APIs is only the first phase. Governance, funding, liability, commercial incentives and consumer protection become harder as the ecosystem succeeds. Other countries should copy the principles—interoperability, permission, neutral standards and measurable outcomes—rather than freeze one version of the UK’s institutions. Open banking is an operating system that must keep being governed.

Continue the country series: Explore the United Kingdom Finance & Fintech Hub, or compare the underlying concepts in the Fintech & Transfers Hub.

Frequently Asked Questions

Is UK open banking safe?

It uses authorised providers, bank authentication and scoped API access rather than credential sharing. Risk remains from fraud, poor consent, data misuse and operational failure, so provider and journey quality matter.

Does open banking let a fintech see every account?

No. Access is limited to the accounts, data and duration the customer consents to and the provider is authorised to use.

How many people use UK open banking?

OBL reported more than 19 million active user connections by mid-2026. Connections are not exactly the same as unique people because a user can connect several services or accounts.

What is a Variable Recurring Payment?

VRP is a consent that permits a series of bank payments whose amount or timing can vary within customer-agreed limits, rather than authorising each payment separately.

What is open finance?

Open finance extends permissioned data sharing beyond payment accounts to products such as savings, investments, pensions, insurance and mortgages.

Primary Sources and Further Reading

This guide prioritises regulators, payment-system operators and company filings. Figures are the latest available at the July 2026 review date.

Last Updated: July 2026 · Reviewed by the Kurums Finance editorial team.

Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading