Open Banking
A regulatory framework letting licensed third parties access bank account data, and initiate payments, with the account holder's explicit consent.
Industry & DomainOpen banking splits into two capabilities with very different design weight. Account information (AISP) reads balances and transactions — used for aggregation, affordability checks and accounting tools. Payment initiation (PISP) starts a payment directly from the account, bypassing card rails and their fees. The second is the one that changes checkout economics, and the one where the user experience is least forgiving.
Consent is the interface. The user is granting a third party access to their bank account, and regulation requires that the scope, duration and revocation route are clear. That requirement is also the conversion problem: the screen has to be specific enough to be honest and short enough to be read. Vague consent gets abandoned at the bank redirect, where the user suddenly realises what they are agreeing to.
The redirect is where flows die
Most open banking journeys hand off to the bank's own authentication and come back. That hop is outside your control, varies by institution, and is where most drop-off happens. Design for it explicitly — say what is about to happen, what the user will see, and what to do if they land back with nothing.
In practice
A lending product asked for 12 months of account access with a generic consent screen. 44% abandoned at the bank redirect. Reducing the request to 90 days, naming exactly what would be read, and adding a one-line preview of the next screen took abandonment to 19% — with no change to the underlying permissions the risk team needed.
Where teams get it wrong
- Requesting broader scope or longer duration than the use case needs, which is where consent screens lose people.
- Not preparing the user for the bank redirect, the single largest drop-off point.
- Treating every bank's authentication as equivalent — timings and failure modes differ widely.
- No path when consent expires, so a working integration silently stops.
- Consent text written by legal alone, so it is accurate and unreadable.
Learn more
You may ask
Frequently Asked Questions
What is the difference between AISP and PISP?
An AISP (account information service provider) reads account data such as balances and transactions. A PISP (payment initiation service provider) starts payments directly from the account. Different licences, different consent, very different risk.
Is open banking the same as PSD2?
PSD2 is the EU regulation that made open banking mandatory in Europe. Open banking is the broader practice, and it exists under different regimes elsewhere — the UK's own standard, and market-led equivalents in other regions.
Why do users abandon open banking flows?
Most often at the redirect to their bank, when the scope of what they are agreeing to becomes real. Narrower requests, specific language and a preview of the next screen consistently outperform broad consent.
Related terms
All terms- PSD2The EU payment services directive that mandated strong customer authentication and forced banks to open account access to licensed third parties.
- Strong Customer Authentication (SCA)The EU requirement that electronic payments be authenticated with two independent factors — with a defined set of exemptions.
- Embedded FinanceFinancial products delivered inside a non-financial product, at the moment they are needed, instead of sending the user to a bank.
- Payment GatewayThe service that takes payment details from a checkout, passes them for authorisation, and returns the result.
Defined by Mara Last reviewed .
Let's talk about your product.
Happy to look at what you're building and say where design would move the needle.
Contact Us