Reference🔭 Ecosystems & horizonsIntermediate⏱ 17 min read

🔗 Open banking and pay-by-bank

AISPs, PISPs, PSD2 APIs, instant payments, and payee verification: how account-to-account payments are becoming a credible alternative to cards.

From PSD2 to open banking

Open banking is the opening of payment accounts to licensed third parties, as mandated by EU regulation. Banks must expose APIs through which a third party, with the customer's consent, can view the customer's accounts or initiate payments. This access right comes from PSD2 (Directive 2015/2366, applicable since January 2018, with APIs mandatory since September 2019). Before PSD2, aggregators “screen-scraped” online banking sites using their customers' login credentials, in a legal gray area. The directive replaced that practice with regulated access. The third party identifies itself to the bank, and customers share their credentials only with their own bank.

2015
PSD2 adopted
The European Parliament enshrines “access to account” (XS2A) for licensed third parties.
Jan. 2018
Amendments take effect
Account information and payment initiation become payment services in their own right (services 7 and 8).
Sept. 2019
SCA RTS + APIs
Strong customer authentication becomes mandatory, and banks must provide dedicated interfaces (APIs).
Apr. 2024
Instant Payments Regulation (IPR)
SCT Inst becomes mandatory and can cost no more than a standard credit transfer.
Oct. 9, 2025
Instant sending + VoP
All euro-area banks must send instant payments and verify the payee's name.
2026
PSD3/PSR near adoption, FIDA still in talks
The June 2023 package moves ahead: PSD3 and the PSR were politically agreed in late November 2025 and are going through formal adoption, while FIDA is still under negotiation. Application of PSD3 and the PSR is expected in the second half of 2028 at the earliest, and FIDA later.
👁️
AISP: account aggregation
The Account Information Service Provider (PSD2 service 8) has read-only access to the customer's accounts to aggregate balances and transactions. Use cases: account aggregators, credit scoring, income verification, SME cash management.
🚀
PISP: payment initiation
The Payment Initiation Service Provider (PSD2 service 7) initiates a credit transfer from the customer's account after strong authentication with the customer's bank. This service powers pay-by-bank, where the customer pays a merchant by bank transfer without entering an IBAN.
✅
CBPII: confirmation of funds
A rarer license (PSD2 Article 65). The issuer of a payment instrument linked to an account held at another bank can request a yes/no confirmation that funds are available before authorizing a transaction.
> 350
licensed third-party providers (TPPs) in the EEA
EBA and ACPR registers
> 11M
active open banking users in the UK, the most mature market
Open Banking Ltd, 2024
10 s
maximum execution time for a SEPA instant credit transfer, 24/7/365
SCT Inst scheme, EPC

PSD2 APIs under the hood

PSD2 account access runs through an interface that each bank designs itself, within the framework set by the RTS (Delegated Regulation 2018/389), because the directive imposed no single technical standard. Two industry initiatives have limited the resulting fragmentation: the Berlin Group (NextGenPSD2), dominant in Europe, and STET in France. TPPs identify themselves with eIDAS certificates (QWAC/QSEAL), and every call is logged. The uneven quality of bank APIs remains the industry's main pain point, with patchy availability, variable documentation, and authentication flows that differ from bank to bank. The PSD3/PSR package makes it one of its priorities.

  • AIS consent: valid for 180 days, renewable (extended from 90 to 180 days in 2023 by the RTS revision, to reduce friction).
  • SCA every time for payment initiation: the customer authenticates with their own bank (app-to-app or web redirect), never with the TPP.
  • Possible SCA exemption for account access: after the first authentication, the bank can let the AISP refresh data up to 4 times a day without SCA.
  • Fallback interface: required unless the supervisor grants an exemption because the API meets the required quality level.
  • No mandatory contract between bank and TPP: access is a free regulatory right, limited to data from payment accounts accessible online.
Initiating a credit transfer, Berlin Group style (NextGenPSD2)
POST /v1/payments/sepa-credit-transfers
X-Request-ID: 5e3d02b1-9c4a-4f7e-b0aa-1d2f6a9c1e77
TPP-Redirect-URI: https://checkout.shop.example.com/psu-return
Content-Type: application/json

{
  "instructedAmount": { "currency": "EUR", "amount": "128.40" },
  "debtorAccount": null,
  "creditorName": "Example Shop SAS",
  "creditorAccount": { "iban": "FR7630001007941234567890185" },
  "remittanceInformationUnstructured": "Order CMD-84512"
}

HTTP/1.1 201 Created
{
  "transactionStatus": "RCVD",
  "paymentId": "pmt-7f21c",
  "_links": {
    "scaRedirect": { "href": "https://customer-bank.example.com/sca/pmt-7f21c" },
    "status": { "href": "/v1/payments/sepa-credit-transfers/pmt-7f21c/status" }
  }
}
⚠️
The API is not the product
PSD2 APIs provide the raw plumbing: inconsistent payment statuses, bank outages, SCA flows that vary from bank to bank. Pay-by-bank providers add the product layer on top: bank selection, error handling and retries, status normalization, reconciliation, and sometimes a contractual payment guarantee. This work determines what share of the payments started at checkout actually end in an executed transfer.

How a pay-by-bank payment works

Paying €128.40 by initiated credit transfer (PIS)
Customer
Selects “pay by bank transfer” at checkout
Then picks their bank from the list
PISP
Prepares the transfer order and redirects to the bank
Amount, payee, and reference are prefilled and locked
Customer’s bank
Strong authentication (mobile app, biometrics)
The customer approves in their usual banking environment
Customer’s bank
Executes the transfer, instantly within the euro area
SCT Inst: funds reach the payee in under 10 seconds, 24/7
PISP
Notifies the merchant of the execution status
The merchant can ship right away if the status is final
Customermerchant checkoutPISPlicensed initiator (PSD2)Payer's bankPSD2 API + SCAMerchantwaits for the final statusBeneficiary's bankfinal credit1 · pay by bank transfer2 · payment initiation3 · SCA in the banking app4 · SCT Inst · ≤ 10 s5 · funds credited, final6 · status sent back to the merchantVoP: match · close · no matchdynamic linking: amount + IBANISO 20022 statuses: only ACSC means settledRCVDreceived, nothing sent yetACCPaccepted, not yet paidACSCsettled, funds transferredship only on ACSCNo issuer guarantee, no chargebackthe browser redirect proves nothingAPI access: a PSD2 rightFunds: the only proofNo card-style guarantee

Two points set this flow apart from a card payment. The first is status: PSD2 guarantees the PISP information on the initiation of the payment, but not always on its final settlement. With standard SCT, there was a lag between “accepted” and “credited,” during which the merchant did not know whether the funds had arrived. The switch to instant payments solves this, since the final status comes back within seconds. The second is irrevocability: an executed transfer cannot be charged back. The merchant has no chargebacks to provision for, but the consumer has no scheme recourse in a commercial dispute.

🔑
The IPR changes the economics and the technology
The EU Instant Payments Regulation (2024/886) has required all euro-area banks to receive SCT Inst since January 2025 and to send it since October 9, 2025. It also requires pricing aligned with standard credit transfers (often €0). Pay-by-bank becomes real-time and nearly free by default, the two features whose absence had kept it from competing with cards in e-commerce.

Verification of Payee (VoP), mandatory for euro credit transfers since October 9, 2025, adds an anti-fraud check. Before the payer approves the transfer, the payer's bank checks whether the payee's name matches the IBAN and shows the result: match, close match, or no match. In merchant pay-by-bank, where the PISP prefills the IBAN, VoP alerts the payer to any mismatch between that IBAN and the stated merchant name. That curbs fake bank-detail fraud, which is common in B2B payments.

Pay-by-bank vs. cards, head to head

CriterionCardPay-by-bank (PIS + SCT Inst)
Merchant costMSC from ~0.3% to 2%+ (interchange + scheme + acquirer)flat fee or low % (often 0.1–0.4%), no interchange
Disputes / chargebackschargebacks governed by scheme rules (strong cardholder protection)irrevocable transfer: no chargeback, refunds at the merchant's discretion
Checkout UXPAN entry or one-click wallet, 3-D Secure if requiredredirect to the banking app plus biometrics; excellent on mobile, clunkier on desktop
Speed of fundssettlement at D+1/D+2 after clearingfunds in the account in under 10 s (SCT Inst)
Limitsthe cardholder's card limits (often a constraint above €1,500)transfer limits, much higher, ideal for large orders
Payment guaranteeauthorization = near guarantee (barring fraud or disputes)payment received = final; but customers may drop off during SCA
Recurring billingcredentials on file, mature subscriptionsless mature: SDD mandates or recurring transfers, Request-to-Pay coming
Cards vs. pay-by-bank: a structural comparison
Payerbanking app or ERPPayer’s PSPchecks, debits, forwardsorder + SCAVoP: payee name vs IBANmandatory since Oct. 9, 2025pacs.008 in batchesBatch CSMSTEP2 · CORE(FR): cut-offsPayee’s PSPcredit on D+1 (business day)net settlement, in cyclesfunds on D+1single pacs.008Real-time CSMTIPS · RT1: 24/7/365Payee’s PSPcredit in ≤ 10 sgross settlement in central bank moneyreusable immediatelyaccepted or rejected in ≤ 10 sSCT Inst cap removed Oct. 5, 2025SCT: recall up to 13 months, no guaranteeSCT Inst: irrevocable once creditedStandard SCT: batchesSCT Inst: one by one, 24/7confirmationEach PSP sets its own limits, but under the EU Instant Payments Regulation (IPR) they cannot be lower than for standard SCT.
⚠️
The Achilles' heel: consumer protection
Without chargebacks, a consumer who pays a failing merchant by bank transfer has no scheme recourse and no regulatory guarantee comparable to the one for unauthorized debits. Some pay-by-bank providers respond with contractual refund policies and by vetting the merchants they take on. The upcoming PSR will strengthen reimbursement for impersonation fraud (spoofing). For high-value goods, this protection gap remains the main argument for cards.
  • Where pay-by-bank already wins: large amounts (travel, furniture, cars), account top-ups (trading, iGaming), bills and taxes, B2B, and sectors with high MSCs.
  • Where cards still rule: small baskets with high conversion rates, subscriptions, travel with deposits, and situations where cardholder protection is decisive.
  • The cultural factor: the Netherlands (iDEAL, now part of Wero/EPI) and Poland (BLIK) show that a well-integrated A2A method can dominate a national e-commerce market.
≈ 60-70 %
of Dutch e-commerce paid with iDEAL, Europe's most advanced A2A scheme
Currence / iDEAL
0 €
maximum extra charge for an instant transfer vs. a standard transfer since 2025
Regulation (EU) 2024/886
-30% to -70%
typical savings on acceptance fees vs. cards for large baskets
Pay-by-bank industry studies

Players and markets

Open banking specialistsTITinkTRTrueLayerPLPlaidGOGoCardlessTRTrustlyFIFintecturePOPowens
CompanyRequestPositioningMilestone
TinkSwedenfull AIS + PIS platform, widely used by banksacquired by Visa (~€1.8B, closed 2022)
TrueLayerUnited Kingdome-commerce pay-by-bank, the sector's unicornvery strong in trading and iGaming
PlaidUnited Statesthe leader in US aggregation, with a presence in EuropeVisa's $5.3B acquisition abandoned in 2021 after a US antitrust challenge
GoCardlessUnited Kingdomrecurring direct debits + open bankingacquired Latvian aggregator Nordigen (2022)
TrustlySwedenconsumer A2A, payment guaranteepioneer of Nordic pay-by-bank
FintectureFranceinstant and deferred bank transfers for e-commerce and B2BFrench specialist in bank transfer payments
Powens (formerly Budget Insight)Francewhite-label aggregation and initiationthe open banking backbone of many French fintechs
BridgeFranceaggregation + pay-by-banka long-standing French open banking player
Market landscape

Visa's acquisition of Tink and Mastercard's acquisition of Aiia reflect the same strategy at both networks. Rather than suffer the rise of A2A, each bought account-access infrastructure and sells that service whichever rail wins. Wero (EPI), which started as an interbank wallet, has been expanding into e-commerce since late 2025, offering pan-European account-to-account payments built on instant transfers that are now universal. EPI's absorption of iDEAL and its migration to Wero illustrate the ongoing consolidation of European A2A.

ℹ️
The French market
Cartes Bancaires (CB), France's domestic card scheme, and cards in general dominate the French market. Pay-by-bank is nonetheless gaining ground in three niches: B2B (large amounts, with VoP fighting fraud based on fake RIBs, the French bank account details), bills (energy, telecom, public sector), and account top-ups. Wero's move into e-commerce, which began in France in 2026, could extend this use to mainstream consumer payments.

FIDA and PSD3/PSR: what comes next

In June 2023, the European Commission proposed a three-part package. PSD3 is a directive covering licensing and supervision, so each member state will have to transpose it. The PSR is a regulation on payment services with directly applicable rules, including those on open banking. FIDA (Financial Data Access) extends data access beyond payment accounts to savings, credit, insurance, and investments, known as “open finance.” Parliament and the Council reached a political agreement on PSD3 and the PSR on November 27, 2025, and formal adoption is under way in 2026. FIDA is still under negotiation. PSD3 and the PSR are not expected to apply before the second half of 2028, and FIDA later still.

  • Merged licenses: e-money institutions are folded into the payment institution license, and licensing rules are cleaned up.
  • Stronger open banking: mandatory dedicated interfaces with performance requirements, consent management dashboards (“permission dashboards”) at banks, and an end to unjustified obstacles.
  • Fraud prevention: payee verification extended across the board, fraud data sharing between PSPs, and reimbursement extended to victims of impersonation fraud (spoofing).
  • Access to bank accounts: payment institutions and EMIs get the right to open an account with a bank (banks' “de-risking” of fintechs becomes regulated).
  • FIDA: financial data sharing schemes, with possible compensation for banks where PSD2 required free access, a major change in the business model.
June 2023
PSD3 + PSR + FIDA proposals
The European Commission publishes the package.
Apr. 2024
Parliament position
First-reading vote before the European elections.
2025
Council positions, trilogues
FIDA, once at risk of being dropped from the Commission's work program, survives and goes to negotiation.
2026
Adoption expected
PSD3/PSR trilogues concluded with the political agreement of November 27, 2025; formal adoption under way. The FIDA timeline is less certain.
≈ 2028-2029
In force
Transposition (PSD3) and application (PSR/FIDA) periods after publication.
🔑
The strategic takeaway
PSD2 opened up technical access to accounts, the IPR made it real-time in the euro area at no extra cost over a standard transfer, and VoP added a payee check before the payer approves the order. PSD3 and the PSR focus on the quality and performance of these interfaces, and FIDA on extending them to all financial data. Each text narrows the structural gap between A2A and cards. Over the next five years, the difference between the two rails will shift away from the pipes toward the experience offered to the payer, which A2A wallets like Wero aim to unify, and toward trust: the level of protection the payer has in a dispute.

Elsewhere in the world. The same mechanism, elsewhere.

The legal basis for third-party access to bank accounts

Brazil

In Brazil, Open Finance rests on Joint Resolution No. 1 (Resolução Conjunta nº 1) of May 4, 2020, issued jointly by the Banco Central do Brasil and the National Monetary Council (CMN). Since January 1, 2025, data sharing has been mandatory for institutions in segments S1 and S2 and for any institution or conglomerate with more than five million customers. Sharing through the payment initiation service is mandatory for all mandatory Pix participants and for licensed payment initiators.

Banco Central do Brasil / CMN, Resolução Conjunta nº 1 of May 4, 2020, art. 6 — https://normativos.bcb.gov.br/Lists/Normativos/Attachments/51028/Res_Conj_0001_v7_L.pdf

Australia

In Australia, account access comes not from payments law but from competition law. The Consumer Data Right, set out in Part IVD of the Competition and Consumer Act 2010, is administered by the Australian Competition and Consumer Commission (ACCC), which accredits data recipients and keeps the register of participants. Bank data sharing has been live since July 1, 2020, and the regime is designed to expand beyond banking, sector by sector.

Australian Competition and Consumer Commission — https://www.accc.gov.au/by-industry/banking-and-finance/the-consumer-data-right

In the US, the access right dates only from the CFPB's final rule of October 22, 2024 (12 CFR Part 1033), issued under Section 1033 of the Dodd-Frank Act and effective January 17, 2025. Compliance is phased in from April 1, 2026, for the largest institutions to April 1, 2030, for the smallest. On August 22, 2025, the CFPB opened a reconsideration of the rule and said it intends to push back those deadlines. Since October 29, 2025, a federal court in Kentucky has barred it from enforcing the rule until that review is complete, so the April 1, 2026, deadline passed with no effect.

Consumer Financial Protection Bureau — https://www.consumerfinance.gov/rules-policy/rules-under-development/personal-financial-data-rights-reconsideration/

India

In India, the equivalent is the Reserve Bank of India's Account Aggregator framework (Master Direction DNBR.PD.009/03.10.119/2016-17 of September 2, 2016). With the customer's consent, an intermediary licensed as an NBFC-Account Aggregator collects, consolidates, and presents the financial information held by financial information providers, for the benefit of financial information users. Its business is restricted to this data-sharing activity.

Reserve Bank of India, Master Direction — Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions, 2016 — https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=10598

Key parameters of a domestic instant payment: speed, limit, availability

Brazil

In Brazil, the Banco Central's Pix timing manual (Manual de Tempos do Pix) sets a maximum of 40 seconds between the participant's receipt of the order and settlement in the Instant Payment System (SPI). Past that limit, the SPI itself rejects the transaction and notifies the participants. Orders routed to the SPI's secondary channel get 45 minutes.

Banco Central do Brasil, Manual de Tempos do Pix, version 7.0, §1.1 and §1.2 — https://www.bcb.gov.br/content/estabilidadefinanceira/pix/Regulamento_Pix/IX_ManualdeTemposdoPix.pdf

In the US, the Federal Reserve's FedNow Service runs 24/7, all year round, but bank participation is voluntary. Its network limit per customer transfer, set at $500,000 at launch, rose to $10 million on November 12, 2025. Each institution keeps a default limit of $100,000, which it can raise or lower.

Federal Reserve Financial Services — https://www.frbservices.org/news/fed360/issues/091625/fednow-service-10-million-transaction-limit

India

In India, the standard UPI limit is ₹1 lakh (₹100,000) per transaction. NPCI has raised it to ₹2 lakh for certain categories (capital markets, collections, insurance, inbound remittances) and to ₹5 lakh for IPOs and the Retail Direct Scheme.

National Payments Corporation of India, UPI — Frequently Asked Questions — https://www.npci.org.in/what-we-do/upi/faqs

Reimbursing victims of authorized push payment (APP) fraud

In the UK, the Payment Systems Regulator has required reimbursement of APP fraud victims on Faster Payments and CHAPS transfers since October 7, 2024. Reimbursement is capped at £85,000 per claim, a level that covers more than 99% of cases, and each firm is free to reimburse more. The protection covers consumers, micro-enterprises, and charities, who have 13 months to claim, and it applies to all payment service providers, including e-money institutions.

Payment Systems Regulator, PS24/7 — https://www.psr.org.uk/information-for-consumers/app-fraud-reimbursement-protections/

Singapore

In Singapore, MAS and the Infocomm Media Development Authority (IMDA) implemented a Shared Responsibility Framework for phishing scams on December 16, 2024. Losses are covered in a waterfall: the financial institution bears the loss first if it breached any of its prescribed duties, then the telecom operator. If every party met its duties, the consumer receives no payout. The framework also excludes malware scams.

Monetary Authority of Singapore — https://www.mas.gov.sg/news/media-releases/2024/mas-and-imda-announce-implementation-of-shared-responsibility-framework-from-16-december-2024

In the US, Regulation E caps a consumer's liability at $50 if they report within two business days of discovery, and at $500 after that (12 CFR 1005.6). But the regime covers only an “unauthorized electronic fund transfer,” defined in 12 CFR 1005.2(m) as a transfer initiated by someone other than the consumer, without actual authority, and from which the consumer receives no benefit. A transfer the victim initiated, even under manipulation, falls outside it.

Electronic Code of Federal Regulations, 12 CFR 1005.2(m) and 1005.6 — https://www.ecfr.gov/current/title-12/chapter-X/part-1005