Accessibility settings

Text size

100%

Fintech 5 min read

Open banking

Also known as: AIS, account information service, account information services, PSD2, income verification, bank account verification

Definition

Open banking is regulated third-party access to a customer's payment account, with the customer's consent. In the EU it rests on PSD2, which defines account information services (AIS) and payment initiation services (PIS).

Cite this entry

Text

"Open banking". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/open-banking/

HTML

<a href="https://ordergroup.co/glossary/open-banking/">Open banking</a> - Order Group

How open banking works

PSD2 (Directive (EU) 2015/2366) gave customers the right to let a licensed third party into their payment account. Article 4 defines two services. An account information service (AIS) is "an online service to provide consolidated information on one or more payment accounts" held with other providers. A payment initiation service (PIS) initiates a payment order from an account held at another provider. In lending, AIS is the one that matters: the borrower logs in to their own bank, approves access, and the lender receives the balance and the transaction history.

Three parties take part. The bank that keeps the account is the account servicing payment service provider. The AIS provider connects to the bank's interface and passes the data on. The lender is usually a client of the AIS provider. Under Article 33 of PSD2 a company that provides only AIS needs a registration rather than a full payment institution license, but it still has to follow several of the directive's rules, including Articles 67 and 95 to 98.

Article 67 sets the access rules. The AIS provider may act only on the customer's explicit consent, may read only the accounts the customer designated, may not request sensitive payment data, and may not use or store the data for anything other than the service the customer asked for. The bank has to treat requests from AIS providers like any other request unless it has an objective reason not to.

What open banking means for your software

AIS replaces the bank statement PDF and the paper income certificate with structured data that arrives in seconds. The flow has few steps, but each step can fail, and an unhandled failure ends in a lost application.

The customer authenticates at their bank. Article 97 of PSD2 requires strong customer authentication (SCA) when a customer accesses a payment account online. Since July 25, 2023 the amended RTS (Delegated Regulation 2022/2360, Article 10a) tells banks to skip it for AIS access limited to the balance or to the transactions of the last 90 days, except on first access and when more than 180 days have passed since the last authentication. A loan app that checks income again for a repeat loan has to expect the customer to log in to the bank again once that window has passed.

The exemption covers only 90 days of history. If your scoring looks at three or six months of income, the request goes beyond what Article 10a exempts, and the customer goes through SCA at the bank for that access. Decide how much history the credit policy really needs before you design the flow, because it decides how often the customer sees the bank's login screen.

Background refreshes are capped. Article 36(5) of Delegated Regulation 2018/389 allows an AIS provider to fetch data without the customer actively requesting it no more than four times in 24 hours, unless the provider and the bank agree on more with the customer's consent. Monitoring an account after payout therefore needs a schedule and a record of consent, and real-time polling is off the table.

Article 33 of the RTS requires banks to keep contingency measures for their dedicated interface and presumes it unavailable when five consecutive requests get no reply within 30 seconds. That is the bank's obligation. Your app talks to the AIS provider, not the bank: handle its error and timeout statuses, keep the application open while the status is pending, and offer a second route, such as a verification transfer, so the customer can still finish.

The data is personal, and the law narrows what it may be used for. Article 67 limits use to the purpose the customer approved, so the consent screen, the stored consent, and the data retention rules have to match what the scoring actually uses.

PSD2 and RTS rules that shape a lending app's AIS flow
RuleSourceWhat the system needs
Access only with the customer's explicit consentPSD2 Art. 67(2)(a)Consent screen, stored consent with timestamp and scope, withdrawal path
Only designated accounts, no sensitive payment dataPSD2 Art. 67(2)(d)-(e)Account picker; scoring that works on balance and transactions only
Data used only for the requested servicePSD2 Art. 67(2)(f)Retention rules tied to the purpose; no reuse for marketing
Bank applies SCA on first access and after 180 daysRTS 2018/389 Art. 10a, as amended by 2022/2360Repeat-loan flow that expects a bank login again
SCA exemption limited to the balance or the last 90 days of transactionsRTS 2018/389 Art. 10a(1)Credit policy that states how much history it needs; SCA step when it needs more than 90 days
No more than 4 unattended fetches in 24 hoursRTS 2018/389 Art. 36(5)Scheduler with per-customer limits for post-payout monitoring
Bank keeps contingency measures for its dedicated interfaceRTS 2018/389 Art. 33Handling of the AIS provider's error and timeout statuses and a fallback verification route

Rules and regulation

Member States had to apply PSD2 from January 13, 2018. The technical detail sits in Commission Delegated Regulation (EU) 2018/389, the regulatory technical standards on strong customer authentication and secure communication, which apply from September 14, 2019. The European Banking Authority drafted the 2022 amendment that moved the renewal period for AIS access from 90 to 180 days and made the exemption mandatory for banks, to reduce friction for customers of AIS providers. In November 2025 the European Parliament and the Council reached a provisional agreement on PSD3 and a Payment Services Regulation (PSR) that will replace PSD2 and move most of its rules into a directly applicable regulation. As of October 2026 the new rules do not yet apply: they start after formal adoption, publication in the Official Journal and a transition period, so PSD2 and the RTS remain the rules to build against today.

In Poland, account data can also support the creditworthiness assessment that a loan institution must carry out and document under Article 9a of the Consumer Credit Act.

From our projects

In Aasa24, the lending app we have built and developed for Aasa Polska since May 2023, a customer confirms income with a verification transfer or by logging in to their bank, instead of sending a paper certificate. Bank login went into the app as a new verification method in November 2024. The app also carries Aasa's Visa credit card with a credit limit, and in 2025 we extended the card application flow so that a positive account verification moves the card application on to the KYC step.

In the app we have built for AvaFin Poland since January 2026, the customer chooses between two routes: logging in to their bank to share the account history, or a verification transfer. The bank login appears during registration, in the loan application and when the customer changes their bank account in the profile. The app follows the verification status and handles failures and timeouts so the application stays open. Testing in September 2026 confirmed that the bank step needs explicit success, failure and timeout transitions, otherwise the app can stop on the wrong screen.

Sources

  1. Directive (EU) 2015/2366 on payment services in the internal market (PSD2) - EUR-Lex
  2. Commission Delegated Regulation (EU) 2022/2360 amending the RTS on strong customer authentication and common and secure communication - EUR-Lex
  3. EBA publishes final Report on the amendment of its technical standards on the exemption to strong customer authentication for account access - European Banking Authority
  4. Payment services deal: more protection from online fraud and hidden fees (PSD3 and PSR provisional agreement) - European Parliament
  5. Ustawa z dnia 12 maja 2011 r. o kredycie konsumenckim (tekst jednolity Dz.U. 2025 poz. 1362) - ISAP

FAQ

Mateusz Widenka
Mateusz Widenka
Head of Delivery
Talk to an engineer
  • Usually the AIS provider holds the registration under Article 33 of PSD2 and the lender is its client. Whether your own flow counts as providing an account information service is a question for your lawyer.

  • Without the customer actively requesting it, an AIS provider may fetch data up to four times in 24 hours. Banks must also ask for strong customer authentication again on first access and once 180 days have passed since the last one.

  • Not for the balance or the last 90 days of transactions within the 180-day window. If the credit policy needs a longer income history, expect the bank's authentication for that access.

  • In the Aasa24 app customers confirm income by logging in to their bank instead of sending a certificate. What a Polish lender must keep and prove about the credit decision is described under loan institution.

  • Your app sees it as an error or timeout status from the AIS provider. Keep the application open and offer a second route, such as a verification transfer, so the application does not end there.

Building a system that depends on Open banking?

See how we build software for this domain, with case studies and the stack we use.

Requirements checklist

For each term we send the definition and what it requires from your software. Free, no sales call needed.

Your checklist is empty. Use the plus next to a term to add it.

    Order Group sp. z o.o. (Warsaw) uses your e-mail to send the checklist (Art. 6(1)(b) GDPR) and keeps a record of the request (Art. 6(1)(f) GDPR). Marketing consent is optional and can be withdrawn at any time. Read the Privacy Policy