Back to blog

Open banking UK: what it is and how to use it safely

August 27, 2026
Open banking UK: what it is and how to use it safely

Open banking UK: what it is and how to use it safely

Hands holding corporate card near payment terminal

Open banking lets you share your bank account data and initiate payments through regulated third-party apps, instead of only through your bank’s own app. It’s live, regulated, and used by millions across the UK already.

The legal groundwork sits in the Competition and Markets Authority’s 2017 Order and the Payment Services Regulations 2017, though a new smart data framework is due to take over from late 2026. Before connecting any account, do this first:

  • Check the provider is on the FCA Register or listed in the Open Banking Directory
  • Never share your online banking password or PIN with a third-party app
  • Confirm you’re redirected to your own bank’s login screen, not a copy of it

Key Takeaways

Open banking works in the UK because a single regulated API standard, checked against the FCA Register and Open Banking Directory, lets consented data and payments move safely between banks and approved apps.

Point Details
Verify before connecting Check the FCA Register and Open Banking Directory before granting any app access to your accounts.
Scale is already large Open Banking Ltd reports over one billion payments and 100 billion API calls across the CMA9.
Regulation is shifting The Data (Use and Access) Act 2025 moves oversight toward a statutory, FCA-supervised smart data model from late 2026.
SMEs gain the most from automation Bank feeds matched automatically against invoices cut manual reconciliation and speed up month-end closes.
Governance is splitting into a Future Entity JROC recommends OBL’s standard-setting and directory role pass to a new, better-funded Future Entity.

Where to check the facts yourself

Table of Contents

What open banking is and who benefits

Open banking exists because the CMA decided in 2017 that the UK’s nine biggest banks weren’t competing hard enough on current accounts. Customers had no easy way to compare deals or move their financial data between providers, so the regulator ordered those banks to build standardised APIs that let approved third parties access account information and, later, initiate payments, all with the customer’s explicit consent.

Two capabilities sit at the heart of it. Account information sharing lets an app see your balances and transactions once you approve it. Payment initiation lets that same app trigger a transfer straight from your account, bypassing card networks entirely.

The people who gain most from this aren’t abstract. They’re:

  • Consumers comparing mortgage or loan applications without uploading months of PDF statements
  • Small business owners who want their accounting software to see bank transactions the moment they land
  • Fintech firms building budgeting, lending, or payment products without negotiating bank-by-bank data deals

Accounting automation and open banking bank feeds are where SMEs feel the effect most directly, because reconciliation stops being a manual, end-of-month scramble.

Who runs the show: OBL, JROC, the FCA and the CMA9

Four bodies, plus the nine largest banks, keep the system running. Knowing what each one actually does helps you work out who to trust and where to check credentials.

  1. Open Banking Limited (OBL), sometimes still called OBIE, built and maintains the Open Banking Standard, the technical API specification (currently on version 4.0.1) that banks and third parties must follow. It also runs the Open Banking Directory, the enrolment list for regulated providers.
  2. The Joint Regulatory Oversight Committee (JROC) doesn’t regulate directly. It advises government on the next phase of the ecosystem and has recommended replacing OBL with a Future Entity with a broader mandate.
  3. The FCA authorises and supervises the account information and payment firms (AISPs and PISPs) that actually touch your data.
  4. The Payment Systems Regulator (PSR) oversees the payment systems these transactions run through.
  5. The CMA issued the original Order and still monitors the CMA9’s compliance with it.

The CMA Order sets infrastructure requirements for the CMA9. It doesn’t authorise individual firms. That’s the FCA’s job, so always check the FCA Register or Open Banking Directory before trusting an app with your accounts, rather than assuming CMA involvement means every connected firm is vetted.

How open banking actually works behind the screen

Three types of player show up in every transaction. The ASPSP (account servicing payment service provider) is your bank, the one holding your money and exposing the API. The AISP (account information service provider) is a regulated firm that reads your account data, think budgeting apps or accounting software. The PISP (payment initiation service provider) is a regulated firm that triggers payments on your behalf.

Crucially, all of this happens through dedicated APIs, not screen scraping. Screen scraping, where an app logs into your bank using your actual credentials and reads the page, was the old workaround before open banking existed, and it’s far riskier because it requires handing over your real password.

Common patterns you’ll meet in practice:

  • Account aggregation: seeing several bank accounts in one dashboard
  • Payment initiation: paying a supplier or bill directly from your bank balance, skipping card fees
  • Variable Recurring Payments (VRPs): a more flexible, revocable version of a direct debit, useful for things like moving money between your own accounts automatically
  • Accounting integrations: bank transactions flowing straight into bookkeeping software for matching against invoices

Pro Tip: If an app asks you to type your online banking password into its own screen rather than redirecting you to your bank’s login page, stop. That’s a screen-scraping red flag, not proper open banking.

How to check a provider is safe before you connect

Two checks take under two minutes and answer the question that actually matters: is this firm allowed to touch my money data at all?

  • Search the firm’s name on the FCA Register to confirm it holds AISP or PISP permissions
  • Check the Open Banking Directory to see if it’s enrolled against the current API standard
  • Confirm you’re redirected to your own bank’s authentication screen, using your bank’s own app or a code it sends you, never a third-party login form
  • Review exactly what data and permissions you’re granting before you tap “confirm”, not after

Consent under open banking runs through strong customer authentication, which typically means your bank’s app, a one-time code, or biometric approval on your phone, not a password typed into someone else’s website. Barclays’ own explainer walks through exactly how this consent screen looks from the bank’s side, which is worth a glance if you’ve never seen one.

Fraud risk in this space mostly comes from firms pretending to be open banking providers while actually running old-style screen scraping, harvesting login details directly. Consumer guidance from MoneySavingExpert makes the same point: legitimate open banking never asks for your online banking password.

Hand plugging security token into laptop

If something looks wrong, you can revoke access from within your banking app at any time, and you’re entitled to complain to the provider first, then the Financial Ombudsman Service if unresolved.

What this means day to day for consumers and small businesses

For everyday banking, open banking mostly shows up as convenience: seeing every account balance in one screen, switching current accounts faster because your new bank can pull transaction history automatically, or paying for something by bank transfer instead of card.

For small businesses, the payoff is heavier and more financial than convenient. Bank transactions land in accounting software automatically instead of needing manual CSV exports and repeated re-typing. That single change reshapes reconciliation:

  • Bank feeds match against invoices without a bookkeeper manually cross-referencing statements
  • Payment initiation lets you settle supplier invoices directly from a linked account, often cheaper than card processing
  • Real-time balance visibility across multiple accounts means owners stop guessing at cash position between month-end reports

A business running several accounts across different banks used to mean logging into each one separately to check cash position. Open banking collapses that into a single, continuously updated view, which is exactly the kind of manual task that open banking for accounting tools are built to remove entirely.

The numbers behind the growth

Open Banking Limited reports the ecosystem has passed one billion open banking payments and more than 100 billion API calls across the CMA9 since launch. The FCA’s own review of 2025 describes steady, continuing growth in adoption rather than a plateau, with usage climbing across both consumer and business use cases.

Growth chart of UK open banking payments and API calls

Using open banking safely: a step-by-step checklist

Follow this sequence every time you connect a new app to your bank account, not just the first time.

  1. Check authorisation first. Search the app or provider on the FCA Register, or confirm it’s listed in the Open Banking Directory, before entering anything.
  2. Grant only the minimum permissions requested. If an app asks for payment initiation but you only need account viewing, decline the extra scope.
  3. Authenticate through your own bank’s flow, never a form embedded in the third-party app itself.
  4. Record what you’ve approved. Most banking apps list active third-party connections; check this list periodically.
  5. Revoke access the moment you stop using a service, and raise a complaint with the provider, then the Financial Ombudsman Service, if something goes wrong.

Pro Tip: Set a quarterly reminder to review connected apps in your banking app. People forget about a budgeting tool they tried once two years ago, and dormant access is exactly what fraudsters look for.

The next phase: smart data, open finance and a Future Entity

The infrastructure built under the CMA Order was always meant to be temporary scaffolding, not the permanent shape of the market. The Data (Use and Access) Act 2025 creates the legal basis for a broader “smart data” framework, with the specific sector instrument for open banking expected around Q4 2026. That shift moves the whole system from a competition remedy binding nine banks to an FCA-supervised statutory regime that can, in principle, extend well beyond the CMA9.

JROC’s own proposals call for OBL’s functions to pass to a Future Entity, one combining standard-setting, directory maintenance, and consumer protection under FCA supervision, with a more durable funding model than the current arrangement.

Practically, this means:

  • Wider data scope beyond current accounts, feeding into open finance (savings, pensions, insurance)
  • A supervised interface body replacing today’s more informal industry governance
  • Sustainable funding, rather than banks and fintechs negotiating costs ad hoc
  • Continued technical continuity, since the API standard itself isn’t being ripped up, just re-homed

How Zenith-books turns bank feeds into finished books

Open banking’s real value for a small business isn’t the concept, it’s what happens once bank data actually reaches your accounting software without anyone typing it in. Zenith-books connects directly to business bank accounts and consolidates balances across every linked account into one live view, then matches incoming transactions against invoices automatically.

Zenith-books clients including Združenje YES and BAM Chocolate report faster month-end closes and effectively zero manual transaction entry once their cash balances sync automatically.

The point of connecting your bank feed isn’t the connection itself. It’s what stops happening afterwards: no more re-typing statements, no more chasing which invoice matches which payment, no more waiting until month-end to know your real cash position.

  • Automatic bank sync replaces manual statement downloads and CSV imports
  • AI-driven invoice matching reconciles transactions against invoices without manual review
  • Consolidated balances across accounts give a single, current cash position

How the UK’s model compares with open banking elsewhere

The UK was first out of the gate with a mandated, API-based model, and that head start still shows in the numbers. Where the UK pushed nine banks into compliance through the CMA Order, the European Union took a broader but slower route through PSD2, covering all EU banks rather than a targeted nine, but with less standardisation of the API itself, individual banks in the EU implemented PSD2 requirements differently, which fragmented the developer experience compared with the UK’s single standard.

Australia took a different structural approach entirely with its Consumer Data Right, treating open banking as the first sector under a wider “open data” law that later extended to energy and telecoms, a sequencing the UK is now arguably copying with its own move toward smart data.

The United States has no equivalent mandate at all. Data sharing there runs on bilateral agreements between banks and data aggregators, voluntary rather than regulated, which means coverage and reliability vary considerably firm by firm. The Consumer Financial Protection Bureau has moved toward rules requiring banks to share data on request, but the UK’s decade-long head start with a single technical standard and a central directory remains a genuine structural advantage.

Brazil’s open finance framework is arguably the most ambitious now running, extending beyond banking into insurance, investments and pensions faster than the UK has managed. That’s instructive: it shows what the UK’s own open finance ambitions might look like once the smart data transition actually lands, rather than a hypothetical.

Why adoption still lags behind the hype

Awareness remains the biggest barrier. Plenty of consumers use open banking daily through budgeting apps or faster checkout flows without realising that’s what it’s called, while others hear “share my bank data” and assume it’s inherently risky, even when the underlying connection is more tightly regulated than a card payment.

Trust is the second barrier, and it’s not irrational. The API model coexists with older screen-scraping services that still ask for banking passwords directly, and to an average user, both look identical: an app requesting access to a bank account. That confusion is exactly why checking FCA authorisation and Open Banking Directory enrolment matters more than most onboarding flows make clear.

For small businesses specifically, the barrier is often inertia rather than distrust. A bookkeeper who has reconciled statements manually for a decade doesn’t automatically trust a live bank feed to match transactions correctly, even when the software handles it well. Switching also means auditing which existing tools and spreadsheets depend on the old manual process, which takes time businesses don’t always budget for.

Privacy concerns are real but frequently overstated in direction. Open banking connections are permissioned and revocable, generally offering more visibility into what’s shared than a card transaction ever did. The genuine privacy risk sits with non-authorised, screen-scraping services outside the regulated perimeter, not with properly authorised AISPs and PISPs operating under FCA supervision.

Getting started: what consumers and businesses actually need to do

For an individual consumer, onboarding is almost frictionless by design. Download or open the app you want to use, choose “connect your bank” or similar, select your bank from a list, and you’re redirected to your own bank’s login screen to approve the specific permissions requested. No card details, no passwords typed into the third-party app itself. The entire flow usually takes under a minute.

For a small business, the process has one more layer: choosing which accounting or automation platform to connect first, since that decision shapes what data flows where afterwards. The typical sequence looks like this:

  • Pick a platform that lists its open banking integration and Open Banking Directory enrolment clearly
  • Connect your primary business current account through the platform’s bank connection flow
  • Set permission scope, usually read-only account information rather than payment initiation, unless you specifically want to pay invoices through the platform
  • Let the first sync run and check that historical transactions have imported correctly before relying on it for reconciliation
  • Add secondary accounts once the first connection is confirmed stable

Most UK business current account providers, particularly the CMA9, support this without any special enrolment on the account holder’s side. If you run multiple business accounts across different banks, connecting them individually to a single finance automation platform gets you one consolidated view rather than several disconnected bank apps.

Beyond 2026: open finance and embedded finance on the horizon

The smart data legislation lands as a regulatory milestone, not an endpoint. Once the sector-specific instrument for banking is in force, the same legal mechanism can extend to other data-rich sectors, and government has already signalled pensions, savings, and insurance as likely next candidates under the open finance banner.

For SMEs, the more immediately interesting trend is embedded finance, financial services woven directly into non-financial software rather than accessed through a separate banking app. Accounting platforms that can not only see your bank balance but initiate a payment, extend short-term credit, or flag a cash flow gap before it happens are the practical direction open banking’s payment initiation capability is heading.

Variable Recurring Payments deserve particular attention here. Currently used mainly for moving money between your own accounts, VRPs are widely expected to expand into sweeping arrangements and recurring merchant payments, offering a genuine alternative to direct debits with far more granular, revocable control for the payer.

None of this requires consumers or business owners to do anything differently today. The API standard underneath stays broadly consistent even as the legal framework around it shifts. What changes is scope: more data types, more use cases, and eventually a market that looks less like “banking APIs” and more like a general data-sharing layer across UK financial services, with banking as the sector that proved the model works first.

What the hype around open banking gets wrong

Most coverage of open banking treats it as a consumer-app story: budgeting tools, switching current accounts, that sort of thing. That’s the smallest part of what it’s actually done. The bigger, quieter shift is what it’s done for small business finance operations, and that story gets undersold constantly.

The conventional advice tells business owners to “connect your bank for better visibility,” as though visibility were the point. It isn’t. The point is what stops needing to happen once the connection exists: no more manual statement downloads, no more retyping numbers into a spreadsheet, no more waiting until the third of the month to find out what cash actually cleared in February. Visibility is a side effect of automation, not the goal itself.

I’d also push back on the framing that adoption barriers are mainly about consumer trust. The bigger drag, especially for SMEs, is workflow inertia: businesses keep running manual reconciliation because switching feels riskier than it is, not because open banking itself is unproven at this point. Given the scale Open Banking Ltd has already reported, the technology has cleared that bar. What hasn’t caught up is how many finance teams have actually rebuilt their processes around it.

If you take one thing from this, prioritise the FCA Register check over everything else. Everything downstream, safety, reliability, whether an app deserves your bank data, starts there.

— Gašper

Sources

Want to stop doing this by hand?

Zenith automates invoice capture, project cost tracking, approval workflows and bank reconciliation — see it working on your kind of invoices in one short call.