Also: PSD2, account information service, payment initiation service, AISP, PISP, third party provider
An arrangement, grounded in law and shared technical standards, under which customers can let an authorised third party read their bank account data or start payments from their account through secure interfaces, without ever handing over their banking login details.
Our take. Open banking is a consent and permissions model before it is a technology. The interfaces are the easy part; the hard parts are liability when a payment goes wrong, the quality of each bank's implementation, and whether customers understand what they agreed to share. It does not make bank data public, and it does not let a provider move money without the customer's authorisation.
Account information service: defined in the EU's revised Payment Services Directive, PSD2 (Directive 2015/2366), it gives the user one online view of payment accounts held with one or more providers, the basis of budgeting apps and affordability checks.
Payment initiation service: also a PSD2 service, it places a payment order at the user's request from an account held with another provider, so a merchant can be paid straight from a bank account and told at once that the payment is on its way.
Authorisation and access: providers of either service must be authorised, and the banks that hold the accounts must let them connect.
The British route
The UK went beyond the directive's minimum, and in doing so gave the term its common name. After its retail banking market investigation reported in 2016, the Competition and Markets Authority ordered the nine largest current account providers in Great Britain and Northern Ireland to fund an implementation entity and adopt common API standards for sharing data and initiating payments. The CMA judged that roadmap substantially complete in January 2023 and fully complete for all nine providers in September 2024. Common standards were the point: one specification for third parties to build against instead of one per bank. Every journey still ends at the customer's own bank, where the customer passes the bank's authentication and approves the access, and the connections run over web APIs with delegated permissions rather than shared passwords. Providers are regulated payment firms with their own anti-money laundering duties, and the concept anchors banking, fintech and payments.
A rotating selection from the course directory, drawn from the subcategories where this concept is taught rather than picked for it. Details, price and the provider link are on the course page.