Three services behind one word
“Open banking” is an account holder's right to give a third party of their choice access to that account's data, and sometimes to let that party initiate a payment from it. Depending on the country, the right comes from an obligation imposed on banks or from commercial agreements with them. Two very different businesses share the label. The first sells data: credit scoring, aggregation, income verification, and transaction categorization. The second sells a payment method. An announcement that “country X has launched open banking” doesn't say which of the two was opened up, yet the answer determines whether you can use it to collect payments.
| Service | EU acronym | What the third party gets | Who makes money from it |
|---|---|---|---|
| Account information | AIS, account information service | Balance, transaction history, account holder identity; read-only | Lenders, aggregators, money management apps, KYC, and income verification |
| Payment initiation | PIS, payment initiation service | The right to trigger a credit transfer from the payer's account, with the payer's consent | Pay-by-bank, account top-ups, bill payment, platforms |
| Confirmation of funds | CAF, confirmation of availability of funds | A yes/no answer: the funds are there, or they aren't | Third-party card issuers, installment payment providers |
The three services are independent of one another. A regime can open just one of them, or all three. India built a data sharing regime with no payment initiation at all: payments run over UPI, a separate infrastructure governed by a different framework. Australia opened up data in 2020 and still hasn't taken initiation live, while Brazil delivered both, under the same framework, in 18 months. The resulting markets differ in what they are for, not just in how far along they are.
- EU and UK: the third party is a TPP holding an AISP or PISP license; the bank is an ASPSP.
- Brazil: the initiating third party is an iniciador de transação de pagamento (ITP), a category of institution authorized by the Banco Central do Brasil.
- India: data flows from a financial information provider (FIP) to a financial information user (FIU) through a licensed NBFC-Account Aggregator.
- Australia: the account provider is a data holder, and the third party is an accredited data recipient (ADR), accredited by the ACCC.
- New Zealand: the third party is an accredited requestor, approved by MBIE.
- US: the CFPB rule refers to a data provider and an authorized third party, and never uses the term “open banking.”
Two drivers: regulatory mandate or market demand
Banks open their accounts to third parties under one of two models, depending on whether an authority imposes it or the market negotiates it. In the regulatory model, a public authority mandates access, sets the API standard, licenses third parties, and penalizes banks that miss the deadlines. In the market model, banks have no obligation, and intermediaries collect data by whatever means they have. For a long time the main one was screen scraping: logging into the bank's website with the customer's credentials. The law comes later and regulates practices that are already in place. Europe, Brazil, and Australia follow the first model; the US lived under the second for 15 years.
| Jurisdiction | Legal basis | Authority | Payment initiation | Market opens |
|---|---|---|---|---|
| European Union | Directive (EU) 2015/2366 (PSD2) | National supervisors, EBA | Yes (PISP); banks must provide access free of charge | January 13, 2018 |
| United Kingdom | Retail Banking Market Investigation Order 2017 (CMA) | CMA, FCA, Payment Systems Regulator | Yes, and the only market where it carries real weight | January 13, 2018 |
| Brazil | Resolução Conjunta nº 1 of May 4, 2020 | Banco Central do Brasil | Yes: the ITP triggers a Pix payment | In phases, from 2021 |
| India | Master Direction NBFC-AA of September 2, 2016 | Reserve Bank of India | No, out of scope; payments run over UPI | Framework in 2016, mass adoption since 2022 |
| Australia | Competition and Consumer Act 2010, Part IVD (CDR) | Treasury, ACCC, OAIC | Planned (action initiation), not live | July 1, 2020 (banking) |
| New Zealand | Customer and Product Data Act 2025 | MBIE | Yes, for designated banks | December 1, 2025 |
| Canada | Consumer-Driven Banking Act | Bank of Canada | Later phase, not yet open | Regulations proposed June 27, 2026 |
| United States | Dodd-Frank Act, Section 1033; 2024 CFPB rule | CFPB | Outside the rule's scope | Rule blocked by a court; rewrite underway |
| South Korea | Open Banking, driven by the Financial Services Commission | FSC / KFTC | Yes, from the start, at regulated access fees | 2019 |
| Saudi Arabia | Open Banking Framework (Saudi Central Bank) | SAMA | Yes, in the framework's second release | Data since 2022; licenses since March 2026 |
| Nigeria | 2021 regulatory framework + 2023 operational guidelines | Central Bank of Nigeria | Yes | Phased rollout announced for 2026 |
Whether payment initiation actually gets used depends less on the quality of the law than on a variable the table doesn't show: whether a cheap instant credit transfer rail sits behind the API. The UK has had Faster Payments since 2008, Brazil launched Pix in 2020, and Korea has used KFTC transfers since the 1980s. All three markets have real pay-by-bank. The rail drives both sides of the merchant's trade-off: how long it takes to get the funds, and what each transaction costs. Where initiation ends in a transfer that is slow, expensive, or capped, the API stays available, but nobody uses it to collect payments.
Europe: a free-of-charge mandate that never built a market
PSD2, Directive (EU) 2015/2366, created two licenses for third-party providers, the AISP and the PISP, and required banks to open access to their accounts free of charge. That zero price shapes the directive's economics. A bank forced to provide an interface it can't charge for has no reason to improve it beyond the regulatory minimum, and the quality of European APIs shows it. Eight years after the directive took effect, data flows at scale; initiated payments, much less so.
The PSR is the regulation that accompanies PSD3 and carries the obligations that apply directly to providers. It changes account access in three ways. Screen scraping goes away, and the dedicated interface becomes the only access route, with no fallback of the kind PSD2 tolerated. Banks must offer a permissions dashboard where customers can see and revoke the access they have granted. And the grounds on which a bank can deny access to a licensed third party are defined more narrowly. Realistically, the measures will apply in 2027 or 2028, depending on the provision, given the 21-month transition period after publication.
| Merchant need | Under PSD2 | After PSD3/PSR |
|---|---|---|
| A guarantee that the payment will arrive | None: the PISP passes on an order; the bank decides | Unchanged; any guarantee remains a commercial service from the provider, not a legal obligation |
| A short payment flow | Redirect to the banking app, with strong authentication every time | Marginally better; redirection remains the dominant pattern |
| Recurring mandate (subscriptions) | Out of scope | Still outside the law's scope; that's what the SPAA scheme and UK VRPs address |
| Consistent API quality and availability | Highly uneven from one bank to the next | Stronger performance requirements; fallback no longer tolerated |
| A business model for the bank | Mandatory free access | Unchanged for the baseline; paid services fall under the SPAA scheme |
PSD2 did not mandate a single technical specification, so three API families coexist in Europe, and a provider operating in several countries has to integrate several message formats. The Berlin Group's NextGenPSD2 is the most widespread; the STET standard covers part of the French-speaking market; the Polish API serves Poland. In Italy, the shared CBI Globe hub, run by CBI S.c.p.a., aggregates connections to all Italian banks, and local connectivity goes through it. The SEPA Payment Account Access (SPAA) scheme, launched by the European Payments Council in 2023, puts a price on “premium” access services beyond the free baseline. It introduces the compensation that PSD2 never provided for banks that open their accounts.
UK: the only market where initiation became a payment method
UK open banking rests on competition law, not payment services regulation. At the end of its retail banking market investigation, the Competition and Markets Authority required the nine largest banks, the CMA9, to publish common APIs in 2017. It also made them fund a dedicated body, which became Open Banking Limited. The setup combined a narrow mandate, a small number of institutions in scope, and a governance body with its own budget. Those three features explain the gap with continental Europe.
The UK's monthly volume combines two distinct uses. Of the 40 million payments in June 2026, nearly 8 million were sweeping VRPs: automatic transfers between accounts held by the same person, with no purchase involved. Single payments mainly go to taxes, energy bills, and funding brokerage and gambling accounts. As of that date, online retail makes up a small share of the total.
| Sweeping VRP | Commercial VRP (cVRP) | |
|---|---|---|
| Who gets paid | Another account belonging to the same holder | A third party: merchant, biller, government agency |
| License type | Mandatory for the CMA9 since 2022; free access | Commercial scheme; access is charged for |
| Typical use cases | Automated savings, overdraft avoidance, loan repayment | Subscriptions, recurring bills, account top-ups |
| Mandate parameters | Maximum amount, per-period limit, and frequency, set by the payer | Same parameters, plus an industry-wide contractual framework |
| Volume, June 2026 | 7.73M in the month | Launched June 2, 2026; ramping up |
cVRP is a variable recurring payment to a third party, as opposed to sweeping, which stays between the holder's own accounts. Its use cases overlap with stored cards and Bacs direct debits, which carry subscriptions and recurring bills today. A bank mandate replaces the card number the merchant keeps on file. A dedicated industry body, the UK Payments Initiative (UKPI), was set up by 31 funders, including Nationwide, NatWest Group, Mastercard Open Banking Services, GoCardless, TrueLayer, Yapily, Token.io, Moneyhub, and Plaid. cVRP went live on June 2, 2026, the first new UK payment scheme since Faster Payments in 2008.
- Wave 1, launched June 2, 2026: utilities, telecoms and rail, regulated financial services, e-money institutions, government payments, and registered charities.
- Wave 2, expected in the second half of 2026: general e-commerce.
- Pricing: a flat per-transaction fee in pence, paid by the payment provider and set to stay unchanged for about five years.
- Coverage targeted at launch: about 75% of UK current accounts.
Brazil: open finance plugged into a universal instant rail
Brazil's Open Finance is the account access regime created by Resolução Conjunta nº 1 of May 4, 2020, issued jointly by the Banco Central do Brasil and the National Monetary Council. It opens access in phases, with mandatory participation for large institutions. Six months later, the same central bank launched Pix. From day one, the initiation API therefore led to an instant credit transfer that was free for consumers and accepted everywhere. Launching the access regime and the instant rail at the same time sets Brazil apart from most other markets.
These figures need to be read against Brazil's total payment volume. Next to the 79.8 billion Pix transactions in 2025 (Banco Central do Brasil), the 64.5 million ITP-initiated transactions are a tiny fraction. Open finance in Brazil does not replace Pix: it lets a Pix payment be triggered from a third-party app rather than from the bank's own. Initiation moves the payment's entry point without changing the rail. The customer starts in a licensed initiator's app instead of their bank's. The competition is therefore over the banking app as the entry point, not over the card.
- Mandatory participation for institutions in the largest segments, optional for the rest: the reverse of a voluntary regime.
- A dedicated industry governance body, separate from the central bank, that publishes the API standards and each institution's availability rates.
- Banco Central's stated priorities for 2026: credit portability, participant performance, and a simpler initiation flow, with a single consent covering both balance sharing and payment.
- The flow is still the friction point: redirecting to the bank costs conversions, just as in Europe.
India: the Account Aggregator, consent without payments
India's data sharing regime is built around a licensed intermediary, the NBFC-Account Aggregator, whose status is governed by Reserve Bank of India Master Direction DNBR.PD.009/03.10.119/2016-17 of September 2, 2016. Banks have no obligation to open up, and access runs through this intermediary rather than through a direct link between the bank and the requesting third party. The aggregator carries data with the customer's consent. It may not store the data or use it for its own purposes, a restriction summed up by the established term data blind.
The system is part of the DEPA architecture (Data Empowerment and Protection Architecture), itself one layer of the India Stack alongside Aadhaar, DigiLocker, and UPI. Its core building block is the consent artefact: a signed digital object that specifies the data in scope, the purpose, and the duration and frequency of access. The customer can revoke it. This signed object is an enforceable document, not just a box ticked on a form.
- The FIU role is something you buy; AA status is not: a lender or broker connects as a financial information user through a licensed aggregator. An NBFC-AA license requires minimum net owned funds and a corporate purpose limited to that single activity.
- The scope goes beyond banking: deposit accounts, securities, mutual funds, insurance, and pensions, depending on which sector regulators have joined.
- Credit is still the dominant use case: verifying income and inflows instead of relying on PDF statements and screen scraping.
- Sahamati is the industry's recognized self-regulatory organization. It maintains the participant directory and the usage statistics.
Australia, New Zealand, Canada: data rights before payments
Australia's Consumer Data Right is a cross-sector data portability right, set out in *Part IVD of the Competition and Consumer Act 2010* and switched on sector by sector through Treasury designation. It reaches beyond banking, which is just one sector among several. Banking was designated in 2019, data sharing actually began on July 1, 2020**, and energy followed. The ACCC accredits data recipients and maintains the register; the OAIC oversees privacy. The regime therefore sits in competition and data protection law, not in payments regulation.
Adoption six years after launch shows the limits of the Australian model. The CDR has 1.3 million users, up 135% year over year (ACCC, July 13, 2026), nowhere near UK or Brazilian volumes. The government has announced a reset, citing compliance costs that are too high and too few use cases. The planned fixes narrow the scope by dropping niche products and shorten the transaction history that must be provided.
| Australia | New Zealand | Canada | |
|---|---|---|---|
| Legal basis | Competition and Consumer Act 2010, Part IVD | Customer and Product Data Act 2025 | Consumer-Driven Banking Act |
| Authority | Treasury (designation), ACCC (accreditation), OAIC (privacy) | MBIE | Bank of Canada |
| Data sharing | Banking since July 1, 2020; non-bank lenders from November 9, 2026 | Standards in force since December 1, 2025 | Proposed regulations published June 27, 2026 |
| Payment initiation | Action initiation provided for in law, not live | Planned for designated banks | Later phase |
| Reach | Multi-sector by design | Multi-sector, with banking designated first | Banking |
New Zealand built its regime in the opposite order to Australia: market first, law second. For years the framework rested on Payments NZ's industry-run API Centre, which published the payment initiation and account information standards. The Customer and Product Data Act 2025 put it on a statutory footing, with standards in force from December 1, 2025. ANZ, ASB, BNZ, and Westpac were designated on that date, and Kiwibank from June 1, 2026. The country has no retail instant payment rail, so API-based initiation fills that role.
- Accreditation is costly under these regimes: a competition or markets authority grants it, with insurance, security, and governance requirements that often exceed those of a European AISP license.
- *In Australia, screen scraping is still legal*, and a formal ban is under consideration, which leaves the legal status of this kind of data collection uncertain.
- The CDR covers energy as well as banking: a rare case of data portability outside finance, and useful to know for scoring models.
- Phase-in timetables depend on the data holder's size in all three countries: a small institution may become reachable only one or two years after the big banks.
US: market first, rule second, and the rule on hold
In the US, access to bank accounts was organized through private contracts, well before any federal implementing rule. Plaid, founded in 2013, built its account connectivity network first on screen scraping, then on APIs negotiated one by one with the large banks. Trustly took the same route on the payments side through its acquisition of PayWithMyBank. This market worked, with two limits: customers' credentials passed through third parties, and access depended on each bank's agreement.
Section 1033 of the Dodd-Frank Act, passed in 2010, gave consumers a right to access their financial data. No implementing rule was adopted for 14 years, so the right had no practical effect. The Consumer Financial Protection Bureau finalized its rule on October 22, 2024; it was published in the Federal Register on November 18, 2024 and took effect on January 17, 2025. On January 8, 2025, the CFPB recognized Financial Data Exchange (FDX) as a standard-setting body authorized to issue API standards under the rule.
Two features define the US situation regardless of Section 1033. First, US pay-by-bank already exists without any access regulation. Trustly, Plaid, and major billers run ACH debits initiated at checkout, with real-time balance checks. Big billers, online gambling operators, and brokerages have adopted it to avoid credit card interchange, which no federal law caps. Second, the issue is shifting to the states, several of which are passing laws on financial data sharing. The applicable regime varies from state to state and has to be checked law by law.
Pay-by-bank: what merchants gain and what they give up
For a merchant, accepting pay-by-bank means receiving a credit transfer that the customer triggers from their bank account, instead of a card payment. The decision depends on three variables: whether the country has an instant payment rail; how the cost of a transfer compares with the cost of a card at the merchant's average order value; and how much the merchant values what cards provide at no extra cost, namely refunds, recurring billing, tokenization, and the payment guarantee.
| Criterion | Card | Pay-by-bank (A2A) |
|---|---|---|
| Cost | Proportional to the amount: interchange + scheme fees + acquirer margin | Often a flat fee per transaction, so the savings grow with order size |
| Funds received | Authorization, then clearing; funds credited at D+1 or D+2 | Instant where a rail exists (Faster Payments, Pix, NPP), 24/7 |
| Chargebacks | Chargeback process run by the scheme, at the merchant's expense | No scheme process: an executed transfer is irrevocable |
| Refunds | Standardized reverse transaction, tracked by the network | Handled by the merchant through an outbound transfer; often reconciled manually |
| Recurring billing | MITs and stored cards, mature and proven, with automatic card updates | Only where a mandate exists: UK cVRP, Australia's PayTo, Pix Automático |
| Conversion | A form, or one click with a wallet | Redirect to the banking app and strong authentication: the weak point |
| International reach | One contract, near-global acceptance | One regime per country, one rail per country, one contract per provider |
- Actual bank coverage has to be measured country by country and bank by bank: coverage of 75% of accounts leaves one customer in four with no way to pay.
- Success rates must be tracked per bank, not as an average: the differences between banks are large, and they drive the merchant's conversion.
- Initiation confirmation and receipt of funds are two separate events in an order management system: without an explicit contractual guarantee, only the second one justifies releasing the goods.
- Refunds are part of service design: an outbound transfer, a reconciliation, a receipt. The rail provides none of them.
- Recurring payments don't carry over from one country to the next: an A2A mandate exists in only a handful of countries, and its framework differs in each.
- Keep cards running in parallel for at least one full cycle: pay-by-bank takes over specific segments, but it replaces cards nowhere.
Comparing the regimes reveals a pattern. Where the regulator mandated access and a cheap instant rail already existed, payment initiation took hold: in the UK, Brazil, and South Korea. Where either piece was missing, it remained a niche tool, whatever the law said. Assessing a market therefore comes down to three separate questions: is there an instant rail, is there a recurring mandate, and is access priced? The mere existence of an open banking regime answers none of them.