Fintech 5 min read
Open banking
Also known as: AIS, account information service, account information services, PSD2, income verification, bank account verification
Definition
Open banking is regulated third-party access to a customer's payment account, with the customer's consent. In the EU it rests on PSD2, which defines account information services (AIS) and payment initiation services (PIS).
Cite this entry
Text
"Open banking". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/open-banking/
HTML
<a href="https://ordergroup.co/glossary/open-banking/">Open banking</a> - Order Group
How open banking works
PSD2 (Directive (EU) 2015/2366) gave customers the right to let a licensed third party into their payment account. Article 4 defines two services. An account information service (AIS) is "an online service to provide consolidated information on one or more payment accounts" held with other providers. A payment initiation service (PIS) initiates a payment order from an account held at another provider. In lending, AIS is the one that matters: the borrower logs in to their own bank, approves access, and the lender receives the balance and the transaction history.
Three parties take part. The bank that keeps the account is the account servicing payment service provider. The AIS provider connects to the bank's interface and passes the data on. The lender is usually a client of the AIS provider. Under Article 33 of PSD2 a company that provides only AIS needs a registration rather than a full payment institution license, but it still has to follow several of the directive's rules, including Articles 67 and 95 to 98.
Article 67 sets the access rules. The AIS provider may act only on the customer's explicit consent, may read only the accounts the customer designated, may not request sensitive payment data, and may not use or store the data for anything other than the service the customer asked for. The bank has to treat requests from AIS providers like any other request unless it has an objective reason not to.
What open banking means for your software
AIS replaces the bank statement PDF and the paper income certificate with structured data that arrives in seconds. The flow has few steps, but each step can fail, and an unhandled failure ends in a lost application.
The customer authenticates at their bank. Article 97 of PSD2 requires strong customer authentication (SCA) when a customer accesses a payment account online. Since July 25, 2023 the amended RTS (Delegated Regulation 2022/2360, Article 10a) tells banks to skip it for AIS access limited to the balance or to the transactions of the last 90 days, except on first access and when more than 180 days have passed since the last authentication. A loan app that checks income again for a repeat loan has to expect the customer to log in to the bank again once that window has passed.
The exemption covers only 90 days of history. If your scoring looks at three or six months of income, the request goes beyond what Article 10a exempts, and the customer goes through SCA at the bank for that access. Decide how much history the credit policy really needs before you design the flow, because it decides how often the customer sees the bank's login screen.
Background refreshes are capped. Article 36(5) of Delegated Regulation 2018/389 allows an AIS provider to fetch data without the customer actively requesting it no more than four times in 24 hours, unless the provider and the bank agree on more with the customer's consent. Monitoring an account after payout therefore needs a schedule and a record of consent, and real-time polling is off the table.
Article 33 of the RTS requires banks to keep contingency measures for their dedicated interface and presumes it unavailable when five consecutive requests get no reply within 30 seconds. That is the bank's obligation. Your app talks to the AIS provider, not the bank: handle its error and timeout statuses, keep the application open while the status is pending, and offer a second route, such as a verification transfer, so the customer can still finish.
The data is personal, and the law narrows what it may be used for. Article 67 limits use to the purpose the customer approved, so the consent screen, the stored consent, and the data retention rules have to match what the scoring actually uses.
| Rule | Source | What the system needs |
|---|---|---|
| Access only with the customer's explicit consent | PSD2 Art. 67(2)(a) | Consent screen, stored consent with timestamp and scope, withdrawal path |
| Only designated accounts, no sensitive payment data | PSD2 Art. 67(2)(d)-(e) | Account picker; scoring that works on balance and transactions only |
| Data used only for the requested service | PSD2 Art. 67(2)(f) | Retention rules tied to the purpose; no reuse for marketing |
| Bank applies SCA on first access and after 180 days | RTS 2018/389 Art. 10a, as amended by 2022/2360 | Repeat-loan flow that expects a bank login again |
| SCA exemption limited to the balance or the last 90 days of transactions | RTS 2018/389 Art. 10a(1) | Credit policy that states how much history it needs; SCA step when it needs more than 90 days |
| No more than 4 unattended fetches in 24 hours | RTS 2018/389 Art. 36(5) | Scheduler with per-customer limits for post-payout monitoring |
| Bank keeps contingency measures for its dedicated interface | RTS 2018/389 Art. 33 | Handling of the AIS provider's error and timeout statuses and a fallback verification route |
Rules and regulation
Member States had to apply PSD2 from January 13, 2018. The technical detail sits in Commission Delegated Regulation (EU) 2018/389, the regulatory technical standards on strong customer authentication and secure communication, which apply from September 14, 2019. The European Banking Authority drafted the 2022 amendment that moved the renewal period for AIS access from 90 to 180 days and made the exemption mandatory for banks, to reduce friction for customers of AIS providers. In November 2025 the European Parliament and the Council reached a provisional agreement on PSD3 and a Payment Services Regulation (PSR) that will replace PSD2 and move most of its rules into a directly applicable regulation. As of October 2026 the new rules do not yet apply: they start after formal adoption, publication in the Official Journal and a transition period, so PSD2 and the RTS remain the rules to build against today.
In Poland, account data can also support the creditworthiness assessment that a loan institution must carry out and document under Article 9a of the Consumer Credit Act.
From our projects
In Aasa24, the lending app we have built and developed for Aasa Polska since May 2023, a customer confirms income with a verification transfer or by logging in to their bank, instead of sending a paper certificate. Bank login went into the app as a new verification method in November 2024. The app also carries Aasa's Visa credit card with a credit limit, and in 2025 we extended the card application flow so that a positive account verification moves the card application on to the KYC step.
In the app we have built for AvaFin Poland since January 2026, the customer chooses between two routes: logging in to their bank to share the account history, or a verification transfer. The bank login appears during registration, in the loan application and when the customer changes their bank account in the profile. The app follows the verification status and handles failures and timeouts so the application stays open. Testing in September 2026 confirmed that the bank step needs explicit success, failure and timeout transitions, otherwise the app can stop on the wrong screen.
Sources
- Directive (EU) 2015/2366 on payment services in the internal market (PSD2) - EUR-Lex
- Commission Delegated Regulation (EU) 2022/2360 amending the RTS on strong customer authentication and common and secure communication - EUR-Lex
- EBA publishes final Report on the amendment of its technical standards on the exemption to strong customer authentication for account access - European Banking Authority
- Payment services deal: more protection from online fraud and hidden fees (PSD3 and PSR provisional agreement) - European Parliament
- Ustawa z dnia 12 maja 2011 r. o kredycie konsumenckim (tekst jednolity Dz.U. 2025 poz. 1362) - ISAP
FAQ
-
Usually the AIS provider holds the registration under Article 33 of PSD2 and the lender is its client. Whether your own flow counts as providing an account information service is a question for your lawyer.
-
Without the customer actively requesting it, an AIS provider may fetch data up to four times in 24 hours. Banks must also ask for strong customer authentication again on first access and once 180 days have passed since the last one.
-
Not for the balance or the last 90 days of transactions within the 180-day window. If the credit policy needs a longer income history, expect the bank's authentication for that access.
-
In the Aasa24 app customers confirm income by logging in to their bank instead of sending a certificate. What a Polish lender must keep and prove about the credit decision is described under loan institution.
-
Your app sees it as an error or timeout status from the AIS provider. Keep the application open and offer a second route, such as a verification transfer, so the application does not end there.
Building a system that depends on Open banking?
See how we build software for this domain, with case studies and the stack we use.