From PSD2 to open banking
Open banking is the opening of payment accounts to licensed third parties, as mandated by EU regulation. Banks must expose APIs through which a third party, with the customer's consent, can view the customer's accounts or initiate payments. This access right comes from PSD2 (Directive 2015/2366, applicable since January 2018, with APIs mandatory since September 2019). Before PSD2, aggregators “screen-scraped” online banking sites using their customers' login credentials, in a legal gray area. The directive replaced that practice with regulated access. The third party identifies itself to the bank, and customers share their credentials only with their own bank.
PSD2 APIs under the hood
PSD2 account access runs through an interface that each bank designs itself, within the framework set by the RTS (Delegated Regulation 2018/389), because the directive imposed no single technical standard. Two industry initiatives have limited the resulting fragmentation: the Berlin Group (NextGenPSD2), dominant in Europe, and STET in France. TPPs identify themselves with eIDAS certificates (QWAC/QSEAL), and every call is logged. The uneven quality of bank APIs remains the industry's main pain point, with patchy availability, variable documentation, and authentication flows that differ from bank to bank. The PSD3/PSR package makes it one of its priorities.
- AIS consent: valid for 180 days, renewable (extended from 90 to 180 days in 2023 by the RTS revision, to reduce friction).
- SCA every time for payment initiation: the customer authenticates with their own bank (app-to-app or web redirect), never with the TPP.
- Possible SCA exemption for account access: after the first authentication, the bank can let the AISP refresh data up to 4 times a day without SCA.
- Fallback interface: required unless the supervisor grants an exemption because the API meets the required quality level.
- No mandatory contract between bank and TPP: access is a free regulatory right, limited to data from payment accounts accessible online.
POST /v1/payments/sepa-credit-transfers
X-Request-ID: 5e3d02b1-9c4a-4f7e-b0aa-1d2f6a9c1e77
TPP-Redirect-URI: https://checkout.shop.example.com/psu-return
Content-Type: application/json
{
"instructedAmount": { "currency": "EUR", "amount": "128.40" },
"debtorAccount": null,
"creditorName": "Example Shop SAS",
"creditorAccount": { "iban": "FR7630001007941234567890185" },
"remittanceInformationUnstructured": "Order CMD-84512"
}
HTTP/1.1 201 Created
{
"transactionStatus": "RCVD",
"paymentId": "pmt-7f21c",
"_links": {
"scaRedirect": { "href": "https://customer-bank.example.com/sca/pmt-7f21c" },
"status": { "href": "/v1/payments/sepa-credit-transfers/pmt-7f21c/status" }
}
}How a pay-by-bank payment works
Two points set this flow apart from a card payment. The first is status: PSD2 guarantees the PISP information on the initiation of the payment, but not always on its final settlement. With standard SCT, there was a lag between “accepted” and “credited,” during which the merchant did not know whether the funds had arrived. The switch to instant payments solves this, since the final status comes back within seconds. The second is irrevocability: an executed transfer cannot be charged back. The merchant has no chargebacks to provision for, but the consumer has no scheme recourse in a commercial dispute.
Verification of Payee (VoP), mandatory for euro credit transfers since October 9, 2025, adds an anti-fraud check. Before the payer approves the transfer, the payer's bank checks whether the payee's name matches the IBAN and shows the result: match, close match, or no match. In merchant pay-by-bank, where the PISP prefills the IBAN, VoP alerts the payer to any mismatch between that IBAN and the stated merchant name. That curbs fake bank-detail fraud, which is common in B2B payments.
Pay-by-bank vs. cards, head to head
| Criterion | Card | Pay-by-bank (PIS + SCT Inst) |
|---|---|---|
| Merchant cost | MSC from ~0.3% to 2%+ (interchange + scheme + acquirer) | flat fee or low % (often 0.1–0.4%), no interchange |
| Disputes / chargebacks | chargebacks governed by scheme rules (strong cardholder protection) | irrevocable transfer: no chargeback, refunds at the merchant's discretion |
| Checkout UX | PAN entry or one-click wallet, 3-D Secure if required | redirect to the banking app plus biometrics; excellent on mobile, clunkier on desktop |
| Speed of funds | settlement at D+1/D+2 after clearing | funds in the account in under 10 s (SCT Inst) |
| Limits | the cardholder's card limits (often a constraint above €1,500) | transfer limits, much higher, ideal for large orders |
| Payment guarantee | authorization = near guarantee (barring fraud or disputes) | payment received = final; but customers may drop off during SCA |
| Recurring billing | credentials on file, mature subscriptions | less mature: SDD mandates or recurring transfers, Request-to-Pay coming |
- Where pay-by-bank already wins: large amounts (travel, furniture, cars), account top-ups (trading, iGaming), bills and taxes, B2B, and sectors with high MSCs.
- Where cards still rule: small baskets with high conversion rates, subscriptions, travel with deposits, and situations where cardholder protection is decisive.
- The cultural factor: the Netherlands (iDEAL, now part of Wero/EPI) and Poland (BLIK) show that a well-integrated A2A method can dominate a national e-commerce market.
Players and markets
| Company | Request | Positioning | Milestone |
|---|---|---|---|
| Tink | Sweden | full AIS + PIS platform, widely used by banks | acquired by Visa (~€1.8B, closed 2022) |
| TrueLayer | United Kingdom | e-commerce pay-by-bank, the sector's unicorn | very strong in trading and iGaming |
| Plaid | United States | the leader in US aggregation, with a presence in Europe | Visa's $5.3B acquisition abandoned in 2021 after a US antitrust challenge |
| GoCardless | United Kingdom | recurring direct debits + open banking | acquired Latvian aggregator Nordigen (2022) |
| Trustly | Sweden | consumer A2A, payment guarantee | pioneer of Nordic pay-by-bank |
| Fintecture | France | instant and deferred bank transfers for e-commerce and B2B | French specialist in bank transfer payments |
| Powens (formerly Budget Insight) | France | white-label aggregation and initiation | the open banking backbone of many French fintechs |
| Bridge | France | aggregation + pay-by-bank | a long-standing French open banking player |
Visa's acquisition of Tink and Mastercard's acquisition of Aiia reflect the same strategy at both networks. Rather than suffer the rise of A2A, each bought account-access infrastructure and sells that service whichever rail wins. Wero (EPI), which started as an interbank wallet, has been expanding into e-commerce since late 2025, offering pan-European account-to-account payments built on instant transfers that are now universal. EPI's absorption of iDEAL and its migration to Wero illustrate the ongoing consolidation of European A2A.
FIDA and PSD3/PSR: what comes next
In June 2023, the European Commission proposed a three-part package. PSD3 is a directive covering licensing and supervision, so each member state will have to transpose it. The PSR is a regulation on payment services with directly applicable rules, including those on open banking. FIDA (Financial Data Access) extends data access beyond payment accounts to savings, credit, insurance, and investments, known as “open finance.” Parliament and the Council reached a political agreement on PSD3 and the PSR on November 27, 2025, and formal adoption is under way in 2026. FIDA is still under negotiation. PSD3 and the PSR are not expected to apply before the second half of 2028, and FIDA later still.
- Merged licenses: e-money institutions are folded into the payment institution license, and licensing rules are cleaned up.
- Stronger open banking: mandatory dedicated interfaces with performance requirements, consent management dashboards (“permission dashboards”) at banks, and an end to unjustified obstacles.
- Fraud prevention: payee verification extended across the board, fraud data sharing between PSPs, and reimbursement extended to victims of impersonation fraud (spoofing).
- Access to bank accounts: payment institutions and EMIs get the right to open an account with a bank (banks' “de-risking” of fintechs becomes regulated).
- FIDA: financial data sharing schemes, with possible compensation for banks where PSD2 required free access, a major change in the business model.
Elsewhere in the world. The same mechanism, elsewhere.
The legal basis for third-party access to bank accounts
In Brazil, Open Finance rests on Joint Resolution No. 1 (Resolução Conjunta nº 1) of May 4, 2020, issued jointly by the Banco Central do Brasil and the National Monetary Council (CMN). Since January 1, 2025, data sharing has been mandatory for institutions in segments S1 and S2 and for any institution or conglomerate with more than five million customers. Sharing through the payment initiation service is mandatory for all mandatory Pix participants and for licensed payment initiators.
Banco Central do Brasil / CMN, Resolução Conjunta nº 1 of May 4, 2020, art. 6 — https://normativos.bcb.gov.br/Lists/Normativos/Attachments/51028/Res_Conj_0001_v7_L.pdf
In Australia, account access comes not from payments law but from competition law. The Consumer Data Right, set out in Part IVD of the Competition and Consumer Act 2010, is administered by the Australian Competition and Consumer Commission (ACCC), which accredits data recipients and keeps the register of participants. Bank data sharing has been live since July 1, 2020, and the regime is designed to expand beyond banking, sector by sector.
Australian Competition and Consumer Commission — https://www.accc.gov.au/by-industry/banking-and-finance/the-consumer-data-right
In the US, the access right dates only from the CFPB's final rule of October 22, 2024 (12 CFR Part 1033), issued under Section 1033 of the Dodd-Frank Act and effective January 17, 2025. Compliance is phased in from April 1, 2026, for the largest institutions to April 1, 2030, for the smallest. On August 22, 2025, the CFPB opened a reconsideration of the rule and said it intends to push back those deadlines. Since October 29, 2025, a federal court in Kentucky has barred it from enforcing the rule until that review is complete, so the April 1, 2026, deadline passed with no effect.
Consumer Financial Protection Bureau — https://www.consumerfinance.gov/rules-policy/rules-under-development/personal-financial-data-rights-reconsideration/
In India, the equivalent is the Reserve Bank of India's Account Aggregator framework (Master Direction DNBR.PD.009/03.10.119/2016-17 of September 2, 2016). With the customer's consent, an intermediary licensed as an NBFC-Account Aggregator collects, consolidates, and presents the financial information held by financial information providers, for the benefit of financial information users. Its business is restricted to this data-sharing activity.
Reserve Bank of India, Master Direction — Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions, 2016 — https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=10598
Key parameters of a domestic instant payment: speed, limit, availability
In Brazil, the Banco Central's Pix timing manual (Manual de Tempos do Pix) sets a maximum of 40 seconds between the participant's receipt of the order and settlement in the Instant Payment System (SPI). Past that limit, the SPI itself rejects the transaction and notifies the participants. Orders routed to the SPI's secondary channel get 45 minutes.
Banco Central do Brasil, Manual de Tempos do Pix, version 7.0, §1.1 and §1.2 — https://www.bcb.gov.br/content/estabilidadefinanceira/pix/Regulamento_Pix/IX_ManualdeTemposdoPix.pdf
In the US, the Federal Reserve's FedNow Service runs 24/7, all year round, but bank participation is voluntary. Its network limit per customer transfer, set at $500,000 at launch, rose to $10 million on November 12, 2025. Each institution keeps a default limit of $100,000, which it can raise or lower.
Federal Reserve Financial Services — https://www.frbservices.org/news/fed360/issues/091625/fednow-service-10-million-transaction-limit
In India, the standard UPI limit is ₹1 lakh (₹100,000) per transaction. NPCI has raised it to ₹2 lakh for certain categories (capital markets, collections, insurance, inbound remittances) and to ₹5 lakh for IPOs and the Retail Direct Scheme.
National Payments Corporation of India, UPI — Frequently Asked Questions — https://www.npci.org.in/what-we-do/upi/faqs
Reimbursing victims of authorized push payment (APP) fraud
In the UK, the Payment Systems Regulator has required reimbursement of APP fraud victims on Faster Payments and CHAPS transfers since October 7, 2024. Reimbursement is capped at £85,000 per claim, a level that covers more than 99% of cases, and each firm is free to reimburse more. The protection covers consumers, micro-enterprises, and charities, who have 13 months to claim, and it applies to all payment service providers, including e-money institutions.
Payment Systems Regulator, PS24/7 — https://www.psr.org.uk/information-for-consumers/app-fraud-reimbursement-protections/
In Singapore, MAS and the Infocomm Media Development Authority (IMDA) implemented a Shared Responsibility Framework for phishing scams on December 16, 2024. Losses are covered in a waterfall: the financial institution bears the loss first if it breached any of its prescribed duties, then the telecom operator. If every party met its duties, the consumer receives no payout. The framework also excludes malware scams.
Monetary Authority of Singapore — https://www.mas.gov.sg/news/media-releases/2024/mas-and-imda-announce-implementation-of-shared-responsibility-framework-from-16-december-2024
In the US, Regulation E caps a consumer's liability at $50 if they report within two business days of discovery, and at $500 after that (12 CFR 1005.6). But the regime covers only an “unauthorized electronic fund transfer,” defined in 12 CFR 1005.2(m) as a transfer initiated by someone other than the consumer, without actual authority, and from which the consumer receives no benefit. A transfer the victim initiated, even under manipulation, falls outside it.
Electronic Code of Federal Regulations, 12 CFR 1005.2(m) and 1005.6 — https://www.ecfr.gov/current/title-12/chapter-X/part-1005