Tech & Fintech · Explainer
Open banking: what sharing your account data actually authorises
A consent screen grants a defined scope for a defined period. Knowing the boundaries is the difference between a tool and an exposure.

The short answer
- Access is granted through regulated interfaces, not by handing over passwords.
- Consent is scoped and time-limited, and can be withdrawn at the bank.
- Payment initiation is a separate permission from data access.
Open banking frameworks require banks to let licensed third parties access account information, or initiate payments, when the customer consents. The mechanism is an authenticated interface, so the third party never holds the customer's banking credentials.
Two different permissions
- Account information: read access to balances and transactions, used for budgeting, accounting and affordability checks.
- Payment initiation: the ability to instruct a payment from your account, used at checkout and for account top-ups.
Scope and duration
Consent specifies which accounts, which data, and for how long. Access expires and must be renewed. Both the provider and the bank must offer a way to revoke it, and revocation at the bank works even when the app does not cooperate.
Where it is heading
Successor frameworks extend the same consent architecture beyond payment accounts into savings, investments, pensions and insurance, with clearer liability rules and compensation for interface access.
Sources
- Payment services and open banking — Financial Conduct Authority
- Payment services (PSD2) — European Commission
Spotted an error? Tell our corrections desk.
