Open Banking Shares Data and Starts Payments—Consent Draws the Line

Open banking allows a regulated service to access selected bank-account information or initiate a payment after the account holder gives explicit consent. That principle has not changed: permission is limited to a defined service, rather than granting an app unrestricted access to a person’s finances.
The latest UK evidence shows that this model is now operating at substantial scale. Published after the original June 2026 article, a July Open Banking Limited assessment counted more than 19 million active user connections and over 40 million monthly payments, but also found that authorised push-payment scams represented more than two-thirds of reported open-banking fraud cases.
What open banking actually opens
Open banking creates a controlled connection between a bank and an authorised third-party provider, commonly through an application programming interface, or API. It replaces practices such as manually exporting statements or giving another service broad access to an online-banking session with a structured request for particular data or payment functionality.
There are two main regulated services. An account information service retrieves information from accounts selected by the customer, enabling products such as consolidated balance views, spending analysis and cash-flow tools. A payment initiation service sends a payment order from the customer’s account at the customer’s request.
Those permissions are distinct. Allowing a budgeting app to display transactions does not automatically let it make payments, while approving one transfer does not necessarily authorise future transfers. The provider must request access appropriate to the service, and the customer must complete the required consent and authentication journey.
Open banking therefore does not make bank records public or transfer ownership of an account to an app. The bank continues to maintain the account, while the third party receives only the access required for the agreed function and remains responsible for handling the resulting data lawfully.
Consent defines the boundary
A consent request should identify the service, the accounts or payment authority involved and how the information will be used. The customer decides whether to proceed and will normally be redirected to the account provider to authenticate without handing banking credentials to the third-party service.
FCA guidance for account and payment services explains that both activities require explicit consent, that customers should verify the provider’s regulatory status and that an account-information provider should disclose what its service includes, how it will use data and whether it will share that data.
Consent is consequently a specific boundary, not a general endorsement of everything a provider might do. Access to transaction history can be integral to a budgeting service, for example, but the same request would require a different justification if the advertised feature did not visibly depend on that information.
A provider’s regulatory status also needs to match its activity. Registration or authorisation for account information does not by itself establish permission to initiate payments, so customers and businesses should check the relevant activity rather than relying only on a company name or logo.
What customers can use it for
Open banking is most useful when a product needs either a combined view of selected accounts or a direct route for a bank payment. Typical uses include:
- showing balances and transactions from several accounts in one dashboard;
- categorising spending for budgeting or cash-flow analysis;
- sharing selected account information for an affordability assessment;
- paying a merchant, invoice or tax bill from a bank account;
- moving funds between accounts belonging to the same customer; and
- authorising eligible recurring transfers through a variable recurring payment arrangement.
The practical result depends on the product. A dashboard can reduce manual consolidation, while payment initiation can remove the need to enter card details. Neither benefit guarantees that every bank, account type or requested feature will be supported, and service availability or data quality can still vary.
What changes for businesses
For a business, open banking presents two separate opportunities: receiving financial information and accepting account-to-account payments. Data access can support bookkeeping, reconciliation, affordability checks or cash-flow products; payment initiation can add another checkout or invoice-payment option.
The technology does not make every transaction instant, free or more successful than a card payment. Settlement timing depends on the underlying payment system and participating institutions, while the provider’s commercial agreement determines fees. Claims about reduced costs or higher checkout completion therefore need to be assessed against the actual contract, customer mix and payment journey.
Operational work remains after a transfer succeeds. A merchant still needs reliable payment references, reconciliation, handling for delayed or failed transactions, a refund process and support for disputes about the purchase. Evidence that money moved does not resolve whether the goods or services were delivered as agreed.
Security is not the same as purchase protection
Open banking can reduce the need to disclose account credentials to another company, but it cannot eliminate impersonation, deceptive consent requests or scams in which someone is persuaded to approve a transfer. Successful authentication establishes only that the required approval step was completed; it cannot establish that the recipient is honest or that the underlying transaction is genuine.
An unauthorised transaction is also different from a transfer that the customer approved after being deceived. A customer who does not recognise a payment should contact the bank promptly, including when a payment-initiation service may have been involved. A complaint about the third-party service itself would normally begin with that provider.
Open-banking payment initiation should not be assumed to reproduce every protection associated with a debit or credit card. Liability, purchase protection, refunds and dispute procedures can differ by payment method, provider and circumstances. A secure authentication journey is therefore not a guarantee covering the quality or delivery of a purchase.
The UK system is live, but the framework is still developing
UK open banking is neither a future experiment nor a completed regulatory project. Account-information and payment-initiation services already operate, while government, regulators and industry continue to develop the governance, interface rules and commercial arrangements intended to support a permanent system.
The February 2026 Payments Forward Plan scheduled the first live variable recurring payments under an industry-led scheme for the first quarter of 2026, an FCA consultation on long-term interface rules for the third quarter and secondary legislation for the fourth quarter. These entries form a roadmap: they should not be read as evidence that every scheduled measure had already been completed when the plan appeared.
The result is a market at two stages of maturity. Customers and businesses can already use regulated data-sharing and payment-initiation products, but some recurring-payment models and the institutions intended to govern the future ecosystem remain in development. The important question is therefore not simply whether a product uses open banking, but exactly what permission it requests, what service it provides and which protections apply.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.