# Open banking

Source: https://ordergroup.co/glossary/open-banking/
Last updated: 2026-10-10

> Open banking (AIS) for lenders: how account data access works under PSD2 and what it changes in onboarding, income checks and the loan app.

[Fintech](https://ordergroup.co/glossary/fintech/)
5 min read

# Open banking

Also known as: AIS, account information service, account information services, PSD2, income verification, bank account verification

Definition

Open banking is regulated third-party access to a customer's payment account, with the customer's consent. In the EU it rests on PSD2, which defines account information services (AIS) and payment initiation services (PIS).

Cite this entry

Text
"Open banking". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/open-banking/
HTML
`<a href="https://ordergroup.co/glossary/open-banking/">Open banking</a> - Order Group`

Reviewed by [Mateusz Widenka](https://ordergroup.co/authors/mateusz-widenka/), Head of Delivery
Last reviewed 10 October 2026

## How open banking works

PSD2 (Directive (EU) 2015/2366) gave customers the right to let a licensed third party into their payment account. Article 4 defines two services. An account information service (AIS) is "an online service to provide consolidated information on one or more payment accounts" held with other providers. A payment initiation service (PIS) initiates a payment order from an account held at another provider. In lending, AIS is the one that matters: the borrower logs in to their own bank, approves access, and the lender receives the balance and the transaction history.

Three parties take part. The bank that keeps the account is the account servicing payment service provider. The AIS provider connects to the bank's interface and passes the data on. The lender is usually a client of the AIS provider. Under Article 33 of PSD2 a company that provides only AIS needs a registration rather than a full payment institution license, but it still has to follow several of the directive's rules, including Articles 67 and 95 to 98.

Article 67 sets the access rules. The AIS provider may act only on the customer's explicit consent, may read only the accounts the customer designated, may not request sensitive payment data, and may not use or store the data for anything other than the service the customer asked for. The bank has to treat requests from AIS providers like any other request unless it has an objective reason not to.

## What open banking means for your software

AIS replaces the bank statement PDF and the paper income certificate with structured data that arrives in seconds. The flow has few steps, but each step can fail, and an unhandled failure ends in a lost application.

The customer authenticates at their bank. Article 97 of PSD2 requires strong customer authentication (SCA) when a customer accesses a payment account online. Since July 25, 2023 the amended RTS (Delegated Regulation 2022/2360, Article 10a) tells banks to skip it for AIS access limited to the balance or to the transactions of the last 90 days, except on first access and when more than 180 days have passed since the last authentication. A loan app that checks income again for a repeat loan has to expect the customer to log in to the bank again once that window has passed.

The exemption covers only 90 days of history. If your scoring looks at three or six months of income, the request goes beyond what Article 10a exempts, and the customer goes through SCA at the bank for that access. Decide how much history the credit policy really needs before you design the flow, because it decides how often the customer sees the bank's login screen.

Background refreshes are capped. Article 36(5) of Delegated Regulation 2018/389 allows an AIS provider to fetch data without the customer actively requesting it no more than four times in 24 hours, unless the provider and the bank agree on more with the customer's consent. Monitoring an account after payout therefore needs a schedule and a record of consent, and real-time polling is off the table.

Article 33 of the RTS requires banks to keep contingency measures for their dedicated interface and presumes it unavailable when five consecutive requests get no reply within 30 seconds. That is the bank's obligation. Your app talks to the AIS provider, not the bank: handle its error and timeout statuses, keep the application open while the status is pending, and offer a second route, such as a verification transfer, so the customer can still finish.

The data is personal, and the law narrows what it may be used for. Article 67 limits use to the purpose the customer approved, so the consent screen, the stored consent, and the data retention rules have to match what the scoring actually uses.

Writing the specification?

Add Open banking to your requirements checklist

Collect the terms your project touches and get their system requirements in one e-mail, ready for an RFP.

PSD2 and RTS rules that shape a lending app's AIS flow
RuleSourceWhat the system needs

Access only with the customer's explicit consentPSD2 Art. 67(2)(a)Consent screen, stored consent with timestamp and scope, withdrawal pathOnly designated accounts, no sensitive payment dataPSD2 Art. 67(2)(d)-(e)Account picker; scoring that works on balance and transactions onlyData used only for the requested servicePSD2 Art. 67(2)(f)Retention rules tied to the purpose; no reuse for marketingBank applies SCA on first access and after 180 daysRTS 2018/389 Art. 10a, as amended by 2022/2360Repeat-loan flow that expects a bank login againSCA exemption limited to the balance or the last 90 days of transactionsRTS 2018/389 Art. 10a(1)Credit policy that states how much history it needs; SCA step when it needs more than 90 daysNo more than 4 unattended fetches in 24 hoursRTS 2018/389 Art. 36(5)Scheduler with per-customer limits for post-payout monitoringBank keeps contingency measures for its dedicated interfaceRTS 2018/389 Art. 33Handling of the AIS provider's error and timeout statuses and a fallback verification route

## Rules and regulation

Member States had to apply PSD2 from January 13, 2018. The technical detail sits in Commission Delegated Regulation (EU) 2018/389, the regulatory technical standards on strong customer authentication and secure communication, which apply from September 14, 2019. The European Banking Authority drafted the 2022 amendment that moved the renewal period for AIS access from 90 to 180 days and made the exemption mandatory for banks, to reduce friction for customers of AIS providers. In November 2025 the European Parliament and the Council reached a provisional agreement on PSD3 and a Payment Services Regulation (PSR) that will replace PSD2 and move most of its rules into a directly applicable regulation. As of October 2026 the new rules do not yet apply: they start after formal adoption, publication in the Official Journal and a transition period, so PSD2 and the RTS remain the rules to build against today.

In Poland, account data can also support the creditworthiness assessment that a [loan institution](https://ordergroup.co/glossary/loan-institution/) must carry out and document under Article 9a of the Consumer Credit Act.

## From our projects

In Aasa24, the lending app we have built and developed for Aasa Polska since May 2023, a customer confirms income with a verification transfer or by logging in to their bank, instead of sending a paper certificate. Bank login went into the app as a new verification method in November 2024. The app also carries Aasa's Visa credit card with a credit limit, and in 2025 we extended the card application flow so that a positive account verification moves the card application on to the KYC step.

In the app we have built for AvaFin Poland since January 2026, the customer chooses between two routes: logging in to their bank to share the account history, or a verification transfer. The bank login appears during registration, in the loan application and when the customer changes their bank account in the profile. The app follows the verification status and handles failures and timeouts so the application stays open. Testing in September 2026 confirmed that the bank step needs explicit success, failure and timeout transitions, otherwise the app can stop on the wrong screen.

## Related terms

- [APR](https://ordergroup.co/glossary/apr/)

Annual percentage rate of charge
In EU consumer credit law, the APR (annual percentage rate of charge) is the total cost of credit to the consumer expressed as an annual percentage of the total amount of credit. One EU formula is used to calculate it, so offers can be compared.
- [Early repayment](https://ordergroup.co/glossary/early-repayment/)

Early repayment is a consumer's right to repay all or part of a credit before the agreed date. EU law gives a matching reduction in the total cost of credit and caps the lender's compensation at 1% or 0.5% of the amount repaid early.
- [Loan institution](https://ordergroup.co/glossary/loan-institution/)

A loan institution is a Polish non-bank lender that grants consumer credit. It must be a joint-stock company or a limited company with a supervisory board, hold PLN 1 million in share capital and be entered in the KNF register.

## Sources

1. [Directive (EU) 2015/2366 on payment services in the internal market (PSD2)](https://eur-lex.europa.eu/eli/dir/2015/2366/oj) - EUR-Lex
2. [Commission Delegated Regulation (EU) 2022/2360 amending the RTS on strong customer authentication and common and secure communication](https://eur-lex.europa.eu/eli/reg_del/2022/2360/oj) - EUR-Lex
3. [EBA publishes final Report on the amendment of its technical standards on the exemption to strong customer authentication for account access](https://www.eba.europa.eu/publications-and-media/press-releases/eba-publishes-final-report-amendment-its-technical-standards) - European Banking Authority
4. [Payment services deal: more protection from online fraud and hidden fees (PSD3 and PSR provisional agreement)](https://www.europarl.europa.eu/news/en/press-room/20251121IPR31540/payment-services-deal-more-protection-from-online-fraud-and-hidden-fees) - European Parliament
5. [Ustawa z dnia 12 maja 2011 r. o kredycie konsumenckim (tekst jednolity Dz.U. 2025 poz. 1362)](https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20250001362) - ISAP

Mateusz Widenka reviewed this entry. Ask how it applies to your project.

[Ask an engineer](https://ordergroup.co/contact-us/)

## FAQ

![Mateusz Widenka](https://ordergroup.co/media/images/T02DHCC1Z-U039G6G3JS1-8e7d2cd80ccb-512.format-webp.webp)

Mateusz Widenka

Head of Delivery

[Talk to an engineer](https://ordergroup.co/contact-us/)

### Does a lender need its own PSD2 license to use open banking data?

Usually the AIS provider holds the registration under Article 33 of PSD2 and the lender is its client. Whether your own flow counts as providing an account information service is a question for your lawyer.

### How often can a loan app refresh a customer's bank data?

Without the customer actively requesting it, an AIS provider may fetch data up to four times in 24 hours. Banks must also ask for strong customer authentication again on first access and once 180 days have passed since the last one.

### Does the customer have to log in to the bank every time?

Not for the balance or the last 90 days of transactions within the 180-day window. If the credit policy needs a longer income history, expect the bank's authentication for that access.

### Can open banking replace an income certificate?

In the Aasa24 app customers confirm income by logging in to their bank instead of sending a certificate. What a Polish lender must keep and prove about the credit decision is described under [loan institution](https://ordergroup.co/glossary/loan-institution/).

### What happens when the customer's bank is not responding?

Your app sees it as an error or timeout status from the AIS provider. Keep the application open and offer a second route, such as a verification transfer, so the application does not end there.

Building a system that depends on Open banking?

See how we build software for this domain, with case studies and the stack we use.

[See Fintech Software Development Services](https://ordergroup.co/fintech-software-development/)

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.
Your checklist is empty. Use the plus next to a term to add it.
