Any provider accessing UK banking data or initiating payments must be authorised. That is the starting point of open banking UK regulation, and it is the first thing a compliance lead or product manager should verify. Most platforms do not hold their own authorisation.
They rely on a licensed provider sitting underneath them. Understanding what that provider must hold, and what your platform retains responsibility for, is the practical purpose of this guide.
The legal basis is PSD2 and open banking: the Payment Services Regulations 2017 (the UK’s domestic implementation of PSD2) established the framework that requires banks to open their APIs to authorised third parties. In 2026, that framework is evolving, with the FCA receiving new powers and a long-term regulatory consultation expected.
This guide is informational. Firms should take their own regulatory advice for their specific situation.
Key Takeaways
- Open banking UK regulation sits with the FCA for authorisation, and Open Banking Limited for technical standards; most competitor content conflates these two
- PSD2 and open banking are inseparable in the UK: the Payment Services Regulations 2017 is the legal basis that obligates banks to open their APIs to authorised third parties
- Platforms relying on a provider’s permissions still hold independent obligations on consent presentation, purpose clarity, and complaints handling
- The Data (Use and Access) Act 2025 and new FCA powers mark a clear direction of travel, without replacing the existing framework
Who Regulates Open Banking UK and How Does the Framework Work?

Open banking UK regulation involves two distinct bodies with different roles. Most published content on this topic conflates them, which creates compliance confusion.
The FCA authorises providers. The Open Banking Limited (OBL) maintains the technical standard that those providers must conform to. Understanding this split is foundational.
The FCA: Authorisation and Supervision
The Financial Conduct Authority (FCA) is the regulatory authority for open banking UK regulation under the Payment Services Regulations 2017. Any third party seeking to access banking data or initiate payments must apply to the FCA for authorisation as either an AISP, a PISP, or both.
The FCA supervises authorised firms, enforces compliance, and maintains the Financial Services Register where authorisation can be independently verified. The open banking directory maintained by Open Banking Limited lists registered technical service providers, but the FCA Register is the definitive source for regulatory authorisation status.
Open Banking Limited: The Technical Standard
Open Banking Limited maintains the open banking API UK standard that governs how authorised providers connect to bank APIs, manage consent flows, and maintain availability. Compliance with this standard is a condition of participating in the UK open banking ecosystem, but OBL is not a regulator. Authorisation status must be verified with the FCA, not OBL.
The scale of the open banking API UK infrastructure reflects how far the ecosystem has grown. As of July 2026, more than one billion Open Banking payments and 100 billion API calls have been recorded since launch. Monthly API traffic reached 2.81 billion calls in June 2026, a new record. Open banking statistics like these underline that this is now core financial infrastructure, not an emerging technology experiment.
What Does PSD2 and Open Banking Mean for UK Platforms in 2026?
PSD2 and open banking operate together as the legal and technical foundation of the UK framework. The Payment Services Regulations 2017 implement PSD2 in UK law. It imposes three core obligations relevant to platforms:
- Banks must provide open access to authorised third parties through open banking API UK connections
- Third parties must hold FCA authorisation before accessing bank accounts on behalf of customers
- Customers must provide explicit, revocable consent before any access begins
The Payment Services Regulations 2017 also established the liability framework. Where an authorised provider causes an unauthorised transaction, the provider bears primary liability. Where a platform facilitates access outside the scope of the customer’s consent, the liability question becomes less clear.
For a full deep dive into PSD2 obligations, see psd2.
Instant Payments Regulation under the UK Framework
Instant payments regulation in the UK sits within the broader open banking UK regulation framework. Faster Payments handles the settlement rail. The FCA-authorised PISP initiates the payment instruction. The Payment Systems Regulator (PSR) oversees Faster Payments as the payment system. These three bodies have distinct but complementary roles.
Instant payments regulation has become more pressing as instant payments volumes grow. Open banking payments UK reached 40.16 million transactions in June 2026, with VRPs growing 6.7% month on month (Open Banking Limited, July 2026). As open banking payments UK scale, the regulatory expectation on providers to maintain availability and incident reporting is rising accordingly.
What Are the Authorisation Types Under Open Banking UK Regulation?
Open banking UK regulation creates two authorised roles for third parties. A platform relying on a provider needs to understand which authorisation the provider holds, because the permissions are different.
| Authorisation Type | Permission | What It Covers |
|---|---|---|
| AISP | Read-only | Account data, transaction history, balances |
| PISP | Write | Payment initiation from a customer’s bank account |
| AISP + PISP | Both | Data access and payment initiation under one authorisation |
Most platforms need both. A provider holding only an AISP licence cannot initiate payments. A provider holding only a PISP licence cannot retrieve transaction data. Platforms should verify which permissions their provider holds on the FCA Register before integration.
For a full explanation of the difference, see aisp vs pisp.
What a platform relies on when it uses a provider
When a platform builds on an FCA-authorised provider, it is relying on that provider’s permissions to access banking data or initiate payments. This is legally permitted, but the platform retains its own obligations.
Open banking providers in the UK that hold dual AISP and PISP authorisation cover both functions. Platforms using such providers do not need to seek their own permissions for those functions. However, they remain responsible for:
- Presenting consent accurately and completely to the end customer
- Limiting data use to the stated purpose
- Maintaining consent records for audit purposes
- Operating a complaints process that meets regulatory standards
Consent records are not a provider responsibility. They are a platform responsibility, regardless of who holds the underlying authorisation. For how this connects to open banking security and data handling, see open banking security.
The open banking directory maintained by OBL lists registered technical participants but is not a substitute for checking the FCA Register. Always verify open banking providers’ UK status at the FCA Register directly.
What Is Changing in Open Banking UK Regulation in 2026?
Open banking UK regulation is entering a new phase in 2026. The framework established by PSD2 and open banking remains the legal basis, but three developments are reshaping the direction.
The Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 created a statutory basis for smart data schemes, placing open banking within a broader legal framework. This gives the FCA authority to set open banking data standards through a new legislative mechanism, separate from the CMA Order that originally mandated open banking.
New FCA powers
HM Treasury has published a consultation proposing that the FCA receive expanded powers. The FCA has stated it intends to consult on a long-term regulatory framework before the end of 2026. No final framework has been published at the time of writing.
Instant Payments Regulation Development
The instant payments regulation environment is also developing. The Payment Systems Regulator has been active in reviewing Faster Payments access and pricing, with relevance to how open banking API UK payment initiation interacts with the broader payment infrastructure.
For platforms, the practical implication of these changes is to verify provider authorisation regularly, not just at onboarding, and to stay current with FCA consultations as they emerge.
The open banking ecosystem, as it exists today, is described in detail in our open banking ecosystem guide.
How Does Finexer Align With Open Banking UK Regulation?

Finexer is FCA-authorised under the Payment Services Regulations 2017, holding both AISP and PISP permissions under FRN 925695. This means platforms building on Finexer’s infrastructure can rely on Finexer’s regulatory permissions for both banking data access and payment initiation, without seeking their own separate FCA authorisation for those functions.
What this means in practice for compliance leads:
- FCA authorisation independently verifiable on the FCA Register under FRN 925695
- Dual AISP and PISP status under a single authorisation
- PSD2 and open banking compliant under the Payment Services Regulations 2017
- PCI DSS-compliant infrastructure for data security obligations
- Consent lifecycle managed end-to-end across the platform layer
- Almost all UK bank coverage via the open banking API UK standard, including challenger and business accounts
- Open Banking Limited registered technical participant
Finexer’s 3-5 weeks refers to onboarding support for platforms. FCA authorisation is held by Finexer. Platforms should take their own legal advice on the scope of reliance for their specific use case.
See Finexer Data for the data access product details.
Bottom Line
Open banking UK regulation in 2026 rests on PSD2 and open banking as the legal foundation, with the FCA as authorisation authority and Open Banking Limited as technical standards body. Platforms relying on a provider’s permissions benefit from that provider’s authorisation but retain their own consent and complaints obligations.
The Data (Use and Access) Act 2025 and new FCA powers confirm that open banking UK regulation is maturing, not being replaced. Verify your provider on the FCA Register. Maintain consent records. Take your own regulatory advice for your specific situation. This content is informational only.
Who regulates Open Banking UK?
Open Banking UK regulation is the FCA’s responsibility. The FCA authorises providers under the Payment Services Regulations 2017 and supervises compliance. Open Banking Limited maintains the technical standard, but authorisation status must be verified on the FCA Register. The two bodies have distinct roles that should not be confused.
What is PSD2 FCA and how does it apply to UK platforms?
PSD2 FCA refers to the FCA’s role as the UK’s competent authority for enforcing PSD2 obligations under the Payment Services Regulations 2017. For UK platforms, PSD2 FCA supervision applies to the authorised provider. Platforms retain independent obligations on consent, purpose limitation, and complaints handling. Firms should seek their own regulatory advice on their specific position.
How do I find open banking providers in the UK on the FCA Register?
The FCA Financial Services Register lists authorised payment institutions and registered account information service providers. Search by firm name or FRN. The open banking directory maintained by Open Banking Limited lists technical participants but is not the authoritative source for regulatory status.
What is the open banking directory and how is it used?
The open banking directory is maintained by Open Banking Limited and lists firms registered to participate in the open banking API UK ecosystem. It is used by banks to verify that a third party connecting to their API has legitimate registration. It is a technical registry, not a regulatory register. Authorisation must be verified separately on the FCA Register.
What does instant payments regulation mean for platforms using Open Banking?
Instant payments regulation in the UK covers the Faster Payments rail (overseen by the PSR) and the payment initiation layer (authorised by the FCA). Platforms using an FCA-authorised PISP provider comply with instant payments regulation through that provider’s permissions. The PSR’s review of Faster Payments access and the FCA’s evolving open banking powers mean this area is changing. Monitor FCA consultations as they are published.
Finexer is FCA-authorised as both an AISP and PISP (FRN 925695), allowing platforms to access banking data and payments through its regulatory framework without needing separate FCA authorisation for these functions.
Verify Finexer’s Regulatory Status and Explore the API
Explore with AI

