Reference🧭 Global overviewsIntermediate⏱ 26 min read

🔓 Open banking around the world

PSD2, UK Open Banking and VRP, Brazil's Open Finance, India's Account Aggregator, Australia's CDR, and US Section 1033: the account access regimes, what they let a merchant collect, and the pay-by-bank products built on them

Three services behind one word

“Open banking” is an account holder's right to give a third party of their choice access to that account's data, and sometimes to let that party initiate a payment from it. Depending on the country, the right comes from an obligation imposed on banks or from commercial agreements with them. Two very different businesses share the label. The first sells data: credit scoring, aggregation, income verification, and transaction categorization. The second sells a payment method. An announcement that “country X has launched open banking” doesn't say which of the two was opened up, yet the answer determines whether you can use it to collect payments.

ServiceEU acronymWhat the third party getsWho makes money from it
Account informationAIS, account information serviceBalance, transaction history, account holder identity; read-onlyLenders, aggregators, money management apps, KYC, and income verification
Payment initiationPIS, payment initiation serviceThe right to trigger a credit transfer from the payer's account, with the payer's consentPay-by-bank, account top-ups, bill payment, platforms
Confirmation of fundsCAF, confirmation of availability of fundsA yes/no answer: the funds are there, or they aren'tThird-party card issuers, installment payment providers
The three regulated services and what they actually enable

The three services are independent of one another. A regime can open just one of them, or all three. India built a data sharing regime with no payment initiation at all: payments run over UPI, a separate infrastructure governed by a different framework. Australia opened up data in 2020 and still hasn't taken initiation live, while Brazil delivered both, under the same framework, in 18 months. The resulting markets differ in what they are for, not just in how far along they are.

🔑
Open banking and pay-by-bank are not the same thing
Pay-by-bank is a commercial product: a customer pays a merchant by credit transfer from their bank account, with no card. Open banking is a regime for accessing accounts. The regime can serve as the technical backbone for pay-by-bank, but neither requires the other. Pay-by-bank can exist without open banking: iDEAL in the Netherlands launched in 2005, 13 years before PSD2, on private agreements among banks. And open banking exists without producing pay-by-bank in most EU countries, where access is open but no mass-market payment method has come out of it.
  • EU and UK: the third party is a TPP holding an AISP or PISP license; the bank is an ASPSP.
  • Brazil: the initiating third party is an iniciador de transação de pagamento (ITP), a category of institution authorized by the Banco Central do Brasil.
  • India: data flows from a financial information provider (FIP) to a financial information user (FIU) through a licensed NBFC-Account Aggregator.
  • Australia: the account provider is a data holder, and the third party is an accredited data recipient (ADR), accredited by the ACCC.
  • New Zealand: the third party is an accredited requestor, approved by MBIE.
  • US: the CFPB rule refers to a data provider and an authorized third party, and never uses the term “open banking.”

Two drivers: regulatory mandate or market demand

Banks open their accounts to third parties under one of two models, depending on whether an authority imposes it or the market negotiates it. In the regulatory model, a public authority mandates access, sets the API standard, licenses third parties, and penalizes banks that miss the deadlines. In the market model, banks have no obligation, and intermediaries collect data by whatever means they have. For a long time the main one was screen scraping: logging into the bank's website with the customer's credentials. The law comes later and regulates practices that are already in place. Europe, Brazil, and Australia follow the first model; the US lived under the second for 15 years.

JurisdictionLegal basisAuthorityPayment initiationMarket opens
European UnionDirective (EU) 2015/2366 (PSD2)National supervisors, EBAYes (PISP); banks must provide access free of chargeJanuary 13, 2018
United KingdomRetail Banking Market Investigation Order 2017 (CMA)CMA, FCA, Payment Systems RegulatorYes, and the only market where it carries real weightJanuary 13, 2018
BrazilResolução Conjunta nº 1 of May 4, 2020Banco Central do BrasilYes: the ITP triggers a Pix paymentIn phases, from 2021
IndiaMaster Direction NBFC-AA of September 2, 2016Reserve Bank of IndiaNo, out of scope; payments run over UPIFramework in 2016, mass adoption since 2022
AustraliaCompetition and Consumer Act 2010, Part IVD (CDR)Treasury, ACCC, OAICPlanned (action initiation), not liveJuly 1, 2020 (banking)
New ZealandCustomer and Product Data Act 2025MBIEYes, for designated banksDecember 1, 2025
CanadaConsumer-Driven Banking ActBank of CanadaLater phase, not yet openRegulations proposed June 27, 2026
United StatesDodd-Frank Act, Section 1033; 2024 CFPB ruleCFPBOutside the rule's scopeRule blocked by a court; rewrite underway
South KoreaOpen Banking, driven by the Financial Services CommissionFSC / KFTCYes, from the start, at regulated access fees2019
Saudi ArabiaOpen Banking Framework (Saudi Central Bank)SAMAYes, in the framework's second releaseData since 2022; licenses since March 2026
Nigeria2021 regulatory framework + 2023 operational guidelinesCentral Bank of NigeriaYesPhased rollout announced for 2026
Account access regimes by jurisdiction

Whether payment initiation actually gets used depends less on the quality of the law than on a variable the table doesn't show: whether a cheap instant credit transfer rail sits behind the API. The UK has had Faster Payments since 2008, Brazil launched Pix in 2020, and Korea has used KFTC transfers since the 1980s. All three markets have real pay-by-bank. The rail drives both sides of the merchant's trade-off: how long it takes to get the funds, and what each transaction costs. Where initiation ends in a transfer that is slow, expensive, or capped, the API stays available, but nobody uses it to collect payments.

40.16M
open banking payments in the UK in June 2026 alone
Open Banking Limited, monthly statistics, 2026
R$15.3B
value of payments initiated by ITPs in Brazil's Open Finance in 2025, vs. R$3.2 billion in 2024
Open Finance Brasil / Banco Central do Brasil, dashboard, 2026
≈ 450M
cumulative consents served by India's Account Aggregator network
Sahamati, FY26 report
1.3M
Australians using the Consumer Data Right, up 135% year over year
ACCC, statement of July 13, 2026
🇰🇷
South Korea: access priced at cost
Korea's Open Banking system, launched in 2019 at the urging of the Financial Services Commission and run by the KFTC, exposes balance inquiries and transfer initiation across all banks, at very low regulated access fees. That is what let Toss, Kakao Pay, and Naver Pay disintermediate the banks' own apps.
🇧🇭
Bahrain: the Middle East's first framework
The Central Bank of Bahrain published the Bahrain Open Banking Framework v1.0.0 in October 2020, the region's first formal regime. Bahrain is a small market, but several of its neighbors used the framework as a template.
🇸🇦
Saudi Arabia: data first, payments second
SAMA (the Saudi Central Bank) published its framework in two stages: account information services in 2022, then payment initiation. Since March 26, 2026, AIS, PIS, and confirmation of funds have operated under a formal license rather than a sandbox.
🇳🇬
Nigeria: Africa's first framework, long stuck before go-live
The Central Bank of Nigeria published Africa's first regulatory framework in February 2021, followed by operational guidelines in March 2023. The commercial launch, expected in 2025, slipped, and a phased rollout is now announced for 2026. A timetable is not a working rail.

Europe: a free-of-charge mandate that never built a market

PSD2, Directive (EU) 2015/2366, created two licenses for third-party providers, the AISP and the PISP, and required banks to open access to their accounts free of charge. That zero price shapes the directive's economics. A bank forced to provide an interface it can't charge for has no reason to improve it beyond the regulatory minimum, and the quality of European APIs shows it. Eight years after the directive took effect, data flows at scale; initiated payments, much less so.

November 25, 2015
PSD2 adopted
Directive (EU) 2015/2366. AISP and PISP licenses enter EU law.
January 13, 2018
Amendments take effect
Same day as the UK launch. The APIs don't exist yet, and screen scraping remains the norm.
September 14, 2019
Regulatory technical standards
Delegated Regulation (EU) 2018/389: mandatory strong customer authentication and dedicated interfaces, with a fallback to the customer-facing interface.
June 28, 2023
Commission package
Proposals for a PSD3 directive, a Payment Services Regulation (PSR), and a FIDA regulation on access to financial data.
November 27, 2025
PSD3/PSR political agreement
Trilogue negotiations between Parliament and Council conclude.
April 23, 2026
Final texts adopted
Final texts of PSD3 and the PSR, after COREPER approval on April 22. Publication in the Official Journal is expected in 2026, with application after a 21-month transition period.

The PSR is the regulation that accompanies PSD3 and carries the obligations that apply directly to providers. It changes account access in three ways. Screen scraping goes away, and the dedicated interface becomes the only access route, with no fallback of the kind PSD2 tolerated. Banks must offer a permissions dashboard where customers can see and revoke the access they have granted. And the grounds on which a bank can deny access to a licensed third party are defined more narrowly. Realistically, the measures will apply in 2027 or 2028, depending on the provision, given the 21-month transition period after publication.

Merchant needUnder PSD2After PSD3/PSR
A guarantee that the payment will arriveNone: the PISP passes on an order; the bank decidesUnchanged; any guarantee remains a commercial service from the provider, not a legal obligation
A short payment flowRedirect to the banking app, with strong authentication every timeMarginally better; redirection remains the dominant pattern
Recurring mandate (subscriptions)Out of scopeStill outside the law's scope; that's what the SPAA scheme and UK VRPs address
Consistent API quality and availabilityHighly uneven from one bank to the nextStronger performance requirements; fallback no longer tolerated
A business model for the bankMandatory free accessUnchanged for the baseline; paid services fall under the SPAA scheme
What PSD2 never gave merchants, and what does or doesn't change
⚠️
An initiated payment is not a collected payment
A PISP passes a payment order to the payer's bank, then relays that bank's response to the merchant. The confirmation it returns shows that an order was accepted, not that the funds have reached the payee's account. Between acceptance and credit come the payer's bank's fraud checks, the account's limits, and the transfer rail's queue. A merchant that ships goods on the initiation confirmation takes on a credit risk that no EU law covers. Some providers respond by offering a payment guarantee: an insurance product, sold for a fee and subject to contractual exclusions.

PSD2 did not mandate a single technical specification, so three API families coexist in Europe, and a provider operating in several countries has to integrate several message formats. The Berlin Group's NextGenPSD2 is the most widespread; the STET standard covers part of the French-speaking market; the Polish API serves Poland. In Italy, the shared CBI Globe hub, run by CBI S.c.p.a., aggregates connections to all Italian banks, and local connectivity goes through it. The SEPA Payment Account Access (SPAA) scheme, launched by the European Payments Council in 2023, puts a price on “premium” access services beyond the free baseline. It introduces the compensation that PSD2 never provided for banks that open their accounts.

Initiators and aggregators merchants encounter in EuropeTITinkTRTrueLayerGOGoCardlessTRTrustlyKlarnaPLPlaid

UK: the only market where initiation became a payment method

UK open banking rests on competition law, not payment services regulation. At the end of its retail banking market investigation, the Competition and Markets Authority required the nine largest banks, the CMA9, to publish common APIs in 2017. It also made them fund a dedicated body, which became Open Banking Limited. The setup combined a narrow mandate, a small number of institutions in scope, and a governance body with its own budget. Those three features explain the gap with continental Europe.

40.16M
open banking payments in June 2026, including 32.43M single payments and 7.73M *sweeping* VRPs
Open Banking Limited, monthly statistics, June 2026
351M
payments in 2025, up 57%; sweeping VRP volumes nearly doubled (+98%)
Open Banking Limited, annual review published January 29, 2026
2.81B
API calls in June 2026, a monthly record; 24 billion in 2025 (+27%)
Open Banking Limited, 2026
> 1B
cumulative payments, plus 100 billion API calls since 2018, across the CMA9
Open Banking Limited, July 2026

The UK's monthly volume combines two distinct uses. Of the 40 million payments in June 2026, nearly 8 million were sweeping VRPs: automatic transfers between accounts held by the same person, with no purchase involved. Single payments mainly go to taxes, energy bills, and funding brokerage and gambling accounts. As of that date, online retail makes up a small share of the total.

Sweeping VRPCommercial VRP (cVRP)
Who gets paidAnother account belonging to the same holderA third party: merchant, biller, government agency
License typeMandatory for the CMA9 since 2022; free accessCommercial scheme; access is charged for
Typical use casesAutomated savings, overdraft avoidance, loan repaymentSubscriptions, recurring bills, account top-ups
Mandate parametersMaximum amount, per-period limit, and frequency, set by the payerSame parameters, plus an industry-wide contractual framework
Volume, June 20267.73M in the monthLaunched June 2, 2026; ramping up
The two faces of variable recurring payments

cVRP is a variable recurring payment to a third party, as opposed to sweeping, which stays between the holder's own accounts. Its use cases overlap with stored cards and Bacs direct debits, which carry subscriptions and recurring bills today. A bank mandate replaces the card number the merchant keeps on file. A dedicated industry body, the UK Payments Initiative (UKPI), was set up by 31 funders, including Nationwide, NatWest Group, Mastercard Open Banking Services, GoCardless, TrueLayer, Yapily, Token.io, Moneyhub, and Plaid. cVRP went live on June 2, 2026, the first new UK payment scheme since Faster Payments in 2008.

  • Wave 1, launched June 2, 2026: utilities, telecoms and rail, regulated financial services, e-money institutions, government payments, and registered charities.
  • Wave 2, expected in the second half of 2026: general e-commerce.
  • Pricing: a flat per-transaction fee in pence, paid by the payment provider and set to stay unchanged for about five years.
  • Coverage targeted at launch: about 75% of UK current accounts.
🔑
What the UK did that Europe didn't
The difference comes down to the price of access. PSD2 mandates free access, so the bank providing it earns nothing from it and builds the bare minimum. UK cVRP charges the payment provider and pays the account-holding bank, which then has a financial incentive to make its interface good. That difference in model explains why a recurring A2A mandate exists in the UK but not yet in the EU. The SPAA scheme aims to bring the same compensation mechanism into the European framework.

Brazil: open finance plugged into a universal instant rail

Brazil's Open Finance is the account access regime created by Resolução Conjunta nº 1 of May 4, 2020, issued jointly by the Banco Central do Brasil and the National Monetary Council. It opens access in phases, with mandatory participation for large institutions. Six months later, the same central bank launched Pix. From day one, the initiation API therefore led to an instant credit transfer that was free for consumers and accepted everywhere. Launching the access regime and the instant rail at the same time sets Brazil apart from most other markets.

How a payment is initiated in Brazil's Open Finance
Customer
Chooses “Pay with Open Finance” at checkout
Selects their bank from the list of participating institutions
Initiator (ITP)
Creates the payment consent
An institution authorized by the Banco Central do Brasil; the consent specifies the amount, payee, and payment date
Payer’s bank
Authenticates the customer and obtains consent
Redirect or embedded flow, depending on the bank; this is where conversions are lost
SPI
Executes a Pix payment
Settlement in central bank money, 24/7; the payment is irrevocable once executed
Merchant
Receives confirmation of execution
Funds available within seconds; no card-style chargeback mechanism
>100M
customers and accounts connected to Brazil's Open Finance
Open Finance Brasil, dashboard, February 2026
154M
active consents; consents up 149% from 2024 to 2025
Open Finance Brasil, dashboard, February 2026
64.5M
payment transactions initiated by ITPs in 2025, vs. 7.4M in 2024
Open Finance Brasil / Banco Central do Brasil, 2026
R$15.3B
value initiated by ITPs in 2025, vs. R$3.2 billion in 2024
Open Finance Brasil / Banco Central do Brasil, 2026

These figures need to be read against Brazil's total payment volume. Next to the 79.8 billion Pix transactions in 2025 (Banco Central do Brasil), the 64.5 million ITP-initiated transactions are a tiny fraction. Open finance in Brazil does not replace Pix: it lets a Pix payment be triggered from a third-party app rather than from the bank's own. Initiation moves the payment's entry point without changing the rail. The customer starts in a licensed initiator's app instead of their bank's. The competition is therefore over the banking app as the entry point, not over the card.

ℹ️
The 2022 renaming, and what it signals
The program was called Open Banking; it became Open Finance in spring 2022. The new name reflects a scope that extends beyond deposit accounts to credit, investments, insurance, and foreign exchange. The EU is heading down the same path with the FIDA regulation, still in trilogue in 2026. The most contested issue in that text is the compensation that data users owe to data holders.
  • Mandatory participation for institutions in the largest segments, optional for the rest: the reverse of a voluntary regime.
  • A dedicated industry governance body, separate from the central bank, that publishes the API standards and each institution's availability rates.
  • Banco Central's stated priorities for 2026: credit portability, participant performance, and a simpler initiation flow, with a single consent covering both balance sharing and payment.
  • The flow is still the friction point: redirecting to the bank costs conversions, just as in Europe.

India: the Account Aggregator, consent without payments

India's data sharing regime is built around a licensed intermediary, the NBFC-Account Aggregator, whose status is governed by Reserve Bank of India Master Direction DNBR.PD.009/03.10.119/2016-17 of September 2, 2016. Banks have no obligation to open up, and access runs through this intermediary rather than through a direct link between the bank and the requesting third party. The aggregator carries data with the customer's consent. It may not store the data or use it for its own purposes, a restriction summed up by the established term data blind.

The system is part of the DEPA architecture (Data Empowerment and Protection Architecture), itself one layer of the India Stack alongside Aadhaar, DigiLocker, and UPI. Its core building block is the consent artefact: a signed digital object that specifies the data in scope, the purpose, and the duration and frequency of access. The customer can revoke it. This signed object is an enforceable document, not just a box ticked on a form.

≈ 450M
cumulative consents served, and more than 5 billion (500 crore) data fetches
Sahamati, FY26 report
> 700,000
consents processed per day by the network
Sahamati, FY26 report
≈ 38M
financial products and services enabled in FY26
Sahamati, FY26 report
70-80 %
of income verifications at large brokerages run through the AA network
Sahamati, FY26 report
⚠️
Don't confuse the Account Aggregator with UPI
The Account Aggregator and UPI are two separate infrastructures, under two separate regulations, run by two separate operators. UPI, operated by the National Payments Corporation of India under an RBI mandate, moves money: it carried 241.62 billion transactions in fiscal 2025–26. The Account Aggregator network moves data and moves no funds. The NBFC-AA framework includes no payment initiation function. A business collecting payments in India therefore relies on UPI, not on the AA.
  • The FIU role is something you buy; AA status is not: a lender or broker connects as a financial information user through a licensed aggregator. An NBFC-AA license requires minimum net owned funds and a corporate purpose limited to that single activity.
  • The scope goes beyond banking: deposit accounts, securities, mutual funds, insurance, and pensions, depending on which sector regulators have joined.
  • Credit is still the dominant use case: verifying income and inflows instead of relying on PDF statements and screen scraping.
  • Sahamati is the industry's recognized self-regulatory organization. It maintains the participant directory and the usage statistics.

Australia, New Zealand, Canada: data rights before payments

Australia's Consumer Data Right is a cross-sector data portability right, set out in *Part IVD of the Competition and Consumer Act 2010* and switched on sector by sector through Treasury designation. It reaches beyond banking, which is just one sector among several. Banking was designated in 2019, data sharing actually began on July 1, 2020**, and energy followed. The ACCC accredits data recipients and maintains the register; the OAIC oversees privacy. The regime therefore sits in competition and data protection law, not in payments regulation.

Adoption six years after launch shows the limits of the Australian model. The CDR has 1.3 million users, up 135% year over year (ACCC, July 13, 2026), nowhere near UK or Brazilian volumes. The government has announced a reset, citing compliance costs that are too high and too few use cases. The planned fixes narrow the scope by dropping niche products and shorten the transaction history that must be provided.

AustraliaNew ZealandCanada
Legal basisCompetition and Consumer Act 2010, Part IVDCustomer and Product Data Act 2025Consumer-Driven Banking Act
AuthorityTreasury (designation), ACCC (accreditation), OAIC (privacy)MBIEBank of Canada
Data sharingBanking since July 1, 2020; non-bank lenders from November 9, 2026Standards in force since December 1, 2025Proposed regulations published June 27, 2026
Payment initiationAction initiation provided for in law, not livePlanned for designated banksLater phase
ReachMulti-sector by designMulti-sector, with banking designated firstBanking
Three regimes, one model, three different stages

New Zealand built its regime in the opposite order to Australia: market first, law second. For years the framework rested on Payments NZ's industry-run API Centre, which published the payment initiation and account information standards. The Customer and Product Data Act 2025 put it on a statutory footing, with standards in force from December 1, 2025. ANZ, ASB, BNZ, and Westpac were designated on that date, and Kiwibank from June 1, 2026. The country has no retail instant payment rail, so API-based initiation fills that role.

ℹ️
Canada: the law was rewritten before it took effect
Canada's first Consumer-Driven Banking Act became law in June 2024, with supervision assigned to the Financial Consumer Agency of Canada. Budget 2025 repealed and replaced it and moved oversight to the Bank of Canada, which already supervises retail payment service providers. The implementing regulations were published for consultation in the Canada Gazette, Part I, on June 27, 2026. As of that date, no interface is open. Canada's timeline is measured in legislative steps, not in API availability.
  • Accreditation is costly under these regimes: a competition or markets authority grants it, with insurance, security, and governance requirements that often exceed those of a European AISP license.
  • *In Australia, screen scraping is still legal*, and a formal ban is under consideration, which leaves the legal status of this kind of data collection uncertain.
  • The CDR covers energy as well as banking: a rare case of data portability outside finance, and useful to know for scoring models.
  • Phase-in timetables depend on the data holder's size in all three countries: a small institution may become reachable only one or two years after the big banks.

US: market first, rule second, and the rule on hold

In the US, access to bank accounts was organized through private contracts, well before any federal implementing rule. Plaid, founded in 2013, built its account connectivity network first on screen scraping, then on APIs negotiated one by one with the large banks. Trustly took the same route on the payments side through its acquisition of PayWithMyBank. This market worked, with two limits: customers' credentials passed through third parties, and access depended on each bank's agreement.

Section 1033 of the Dodd-Frank Act, passed in 2010, gave consumers a right to access their financial data. No implementing rule was adopted for 14 years, so the right had no practical effect. The Consumer Financial Protection Bureau finalized its rule on October 22, 2024; it was published in the Federal Register on November 18, 2024 and took effect on January 17, 2025. On January 8, 2025, the CFPB recognized Financial Data Exchange (FDX) as a standard-setting body authorized to issue API standards under the rule.

October 22, 2024
CFPB final rule
Personal Financial Data Rights Rule. Data providers must make data available to consumers and to the third parties they authorize.
October 22, 2024
Lawsuit
Forcht Bank, the Kentucky Bankers Association, and the Bank Policy Institute challenge the rule in the US District Court for the Eastern District of Kentucky.
January 17, 2025
Entry into force
The rule takes effect, with compliance deadlines phased in by institution size.
May 30, 2025
CFPB asks the court to vacate its own rule
It concludes that the rule exceeds its statutory authority and is arbitrary.
July 29, 2025
About-face
The CFPB withdraws its request to vacate the rule and says it will reopen the rulemaking.
August 22, 2025
Advance notice of the rewrite
The CFPB publishes an advance notice of proposed rulemaking, seeking comments and data for the rewrite.
November 2025
Preliminary injunction
The Eastern District of Kentucky court bars the CFPB from enforcing the current rule, finding that the plaintiffs are likely to succeed.
⚠️
Don't build a US integration on Section 1033
As of 2026, the rule exists, it is blocked by a court injunction, and the agency that wrote it is rewriting it. What the final text will say is unknown. Whether access stays free, whether banks may charge third parties, and whether the rule survives at all are all still open questions. A merchant or lender operating in the US therefore depends on commercial agreements with Plaid, MX, Finicity, or the large banks, not on an enforceable right of access. A US integration rests on contracts that can be renegotiated, not on a settled legal framework.

Two features define the US situation regardless of Section 1033. First, US pay-by-bank already exists without any access regulation. Trustly, Plaid, and major billers run ACH debits initiated at checkout, with real-time balance checks. Big billers, online gambling operators, and brokerages have adopted it to avoid credit card interchange, which no federal law caps. Second, the issue is shifting to the states, several of which are passing laws on financial data sharing. The applicable regime varies from state to state and has to be checked law by law.

Pay-by-bank: what merchants gain and what they give up

For a merchant, accepting pay-by-bank means receiving a credit transfer that the customer triggers from their bank account, instead of a card payment. The decision depends on three variables: whether the country has an instant payment rail; how the cost of a transfer compares with the cost of a card at the merchant's average order value; and how much the merchant values what cards provide at no extra cost, namely refunds, recurring billing, tokenization, and the payment guarantee.

CriterionCardPay-by-bank (A2A)
CostProportional to the amount: interchange + scheme fees + acquirer marginOften a flat fee per transaction, so the savings grow with order size
Funds receivedAuthorization, then clearing; funds credited at D+1 or D+2Instant where a rail exists (Faster Payments, Pix, NPP), 24/7
ChargebacksChargeback process run by the scheme, at the merchant's expenseNo scheme process: an executed transfer is irrevocable
RefundsStandardized reverse transaction, tracked by the networkHandled by the merchant through an outbound transfer; often reconciled manually
Recurring billingMITs and stored cards, mature and proven, with automatic card updatesOnly where a mandate exists: UK cVRP, Australia's PayTo, Pix Automático
ConversionA form, or one click with a walletRedirect to the banking app and strong authentication: the weak point
International reachOne contract, near-global acceptanceOne regime per country, one rail per country, one contract per provider
Cards and pay-by-bank compared, from the merchant's side
🧾
Billers and utilities
Large amounts, repeat customers, no cart abandonment to worry about. The flat cost of a transfer beats card fees by a wide margin. This is exactly the scope of wave 1 of UK cVRP: utilities, telecoms, rail, and charities.
🎰
Account top-ups
Brokerage, online gambling, crypto. Cards are expensive in these sectors, often declined by issuers, and exposed to fraudulent chargebacks. An irrevocable instant transfer solves all three problems at once. This is the segment that made Trustly take off.
🏢
B2B and large orders
Above a few hundred euros, the cost gap becomes decisive, and no European interchange regime caps commercial cards.
🛒
Online retail
The hardest case: small orders, extreme sensitivity to conversion, and high expectations of buyer protection. Cards stay ahead, except in markets where pay-by-bank is already the norm. In the Netherlands, iDEAL accounted for about 62% of online spending in 2023 (EPI Company, 2026).
⚠️
Irrevocability cuts both ways
With no chargebacks, merchants face fewer disputes. By the same token, customers have no recourse if goods never arrive, a gap that will sooner or later call for regulatory action. An instant transfer sent to the wrong payee also can't be recalled once executed. Payee verification services (PayID in Australia, Verification of Payee in Europe, Confirmation of Payee in the UK) respond to fraud moving to that step of the flow. Accepting A2A payments at scale therefore requires dedicated fraud controls, separate from those used for cards.
  • Actual bank coverage has to be measured country by country and bank by bank: coverage of 75% of accounts leaves one customer in four with no way to pay.
  • Success rates must be tracked per bank, not as an average: the differences between banks are large, and they drive the merchant's conversion.
  • Initiation confirmation and receipt of funds are two separate events in an order management system: without an explicit contractual guarantee, only the second one justifies releasing the goods.
  • Refunds are part of service design: an outbound transfer, a reconciliation, a receipt. The rail provides none of them.
  • Recurring payments don't carry over from one country to the next: an A2A mandate exists in only a handful of countries, and its framework differs in each.
  • Keep cards running in parallel for at least one full cycle: pay-by-bank takes over specific segments, but it replaces cards nowhere.

Comparing the regimes reveals a pattern. Where the regulator mandated access and a cheap instant rail already existed, payment initiation took hold: in the UK, Brazil, and South Korea. Where either piece was missing, it remained a niche tool, whatever the law said. Assessing a market therefore comes down to three separate questions: is there an instant rail, is there a recurring mandate, and is access priced? The mere existence of an open banking regime answers none of them.