Someone on your payments team has pitched open banking as the fix for a problem cards cannot solve — a crypto exchange tired of card-scheme rolling reserves, an iGaming operator watching card deposits get declined at the issuer level, a forex broker looking for a cheaper settlement rail. The pitch sounds clean: connect straight to the customer's bank account, skip the card network, skip the chargeback exposure.
It is worth understanding what you are actually being sold before you build a roadmap around it, because open banking is not one product. It is two distinct license categories with different capabilities, sitting inside a regulatory framework the EU is still finishing and the UK is rebuilding on an entirely separate timeline.
This guide sets out what an AISP and a PISP can each actually do, where PSD3 and the PSR stand as of mid-2026, what the UK's Future Entity and Open Finance Roadmap change, and why the gap between what open banking promises and what it currently delivers matters more for high-risk operators than for anyone else.
Direct Answer
Open banking covers two separate license categories: an AISP reads account data with no minimum capital requirement, a PISP initiates payments directly from a customer's account and needs 50,000 EUR in initial capital. Both operate under PSD2 today. PSD3 and the PSR reached political agreement in November 2025 but are not yet in force, and the UK runs an entirely separate reform track.
What Is Open Banking, and What Do AISP and PISP Actually Do?
Open banking is the regulatory requirement, introduced under the EU's second Payment Services Directive (PSD2), that banks must give licensed third parties access to a customer's account data and payment rails, with the customer's explicit consent. It created two license categories, and confusing them is where most operators go wrong.
An AISP (Account Information Service Provider) can only read data: transaction history, balances, account holder details. It cannot move a single unit of currency. A PISP (Payment Initiation Service Provider) does the opposite job — it initiates a payment directly out of the customer's bank account, with consent, which is the rail underlying what the market calls "pay by bank" or A2A (account-to-account) payments.
The two categories are licensed, supervised, and capitalized differently, and a provider can hold either one alone or both together as a combined authorization.
What to Consider:
- Read access only: an AISP integration gives you account data for verification, affordability, or underwriting — it is not a payment mechanism and cannot replace your existing rail.
- Payment initiation: a PISP moves funds directly between the customer's bank and yours, without a card network sitting in between.
- Combined licenses exist: some providers hold both AISP and PISP authorization, but confirm which specific capability your contract actually covers.
- Passporting: a license issued in one EU/EEA member state can passport across the bloc, so the provider's home regulator matters less than its actual authorization scope.
Example
A licensed forex broker integrated an AISP-only connection to pull 12 months of a prospective client's transaction history for source-of-funds and affordability checks. Manual bank-statement review that used to take a three-business-day queue dropped to same-day, without the broker ever touching a payment rail through the integration.
Final Takeaway: Confirm which of the two capabilities actually solves the problem in front of you before you evaluate a provider — verification and payment initiation are different jobs, licensed and priced differently.
| Feature | AISP | PISP |
|---|---|---|
| Function | Reads account data only | Initiates payments from the account |
| Minimum initial capital | None — professional indemnity insurance only | 50,000 EUR |
| Moves funds | No | Yes, with customer consent |
| EU/EEA passporting | Yes | Yes |
| Typical high-risk use | KYC / source-of-funds verification | Alternative to card-based deposits |
Where Do PSD3 and the PSR Actually Stand in Mid-2026?
The European Commission published its proposals for a third Payment Services Directive (PSD3) and a new Payment Services Regulation (PSR) in June 2023, intended to replace PSD2 and close gaps the Commission itself identified in how the current open banking framework functions. The European Parliament and the Council of the EU reached a provisional political agreement on both texts on 27 November 2025.
Political agreement is not the same thing as law. The Parliament's ECON committee approved the agreed text on 5 May 2026, but as of mid-2026 neither instrument has been formally adopted by the full Parliament and Council or published in the Official Journal. Realistic application is not likely before late 2027, and could slip into 2028 depending on how quickly the formal adoption and transposition steps move — track the Legislative Train Schedule for the current stage rather than any single article's headline date.
Reality Check
Open banking is frequently pitched to high-risk operators as an already-arrived alternative to card rails. It is not, at least not in its next form. PSD3 and the PSR reached political agreement in November 2025, but as of mid-2026 neither has been formally adopted or published in the Official Journal, and realistic application is not before late 2027, possibly slipping into 2028. Build your compliance roadmap on the framework actually in force today, not on the one still being negotiated.
What to Consider:
- Political agreement is not law: formal adoption and Official Journal publication are separate, later steps, each with their own timeline.
- Official Journal date starts the clock: application dates are typically set relative to publication, not to the agreement date reported in the press.
- PSD2 remains operative: every AISP and PISP obligation described in this guide is enforced under the current directive until PSD3/PSR formally replace it.
- Expect phased transposition: member states will need time to transpose a directive (PSD3) into national law even after adoption; a regulation (PSR) applies more directly but still on a delayed schedule.
Example
A Lithuania-licensed EMI planning its 2027 product roadmap assumed the PSR would already govern account-access rules by Q1 2027 and began building its integration around the new provisions. When Official Journal publication still had not happened by mid-2026, the EMI had to fall back to building against the existing PSD2 technical standards instead, absorbing a rework cycle it had not budgeted for.
Final Takeaway: Track the Official Journal publication date, not the political-agreement date, before committing engineering time to PSD3- or PSR-specific provisions.
What's the UK Doing Separately: the FCA's Future Entity and Open Finance Roadmap?
The UK is not bound by PSD3 or the PSR — post-Brexit, it runs its own reform track through the Financial Conduct Authority (FCA). Following recommendations from the Joint Regulatory Oversight Committee, the FCA published Feedback Statement FS25/4 in August 2025, setting out the design of a "Future Entity" — a not-for-profit standard-setting body expected to run open banking API standards, directory, and certification services, without enforcement powers of its own.
The FCA followed with its Open Finance Roadmap on 14 April 2026, extending open banking's principles across a wider range of financial products through 2030. The roadmap is explicitly phased: 2026 prioritization work (SME lending and mortgage access come first), a 2027 regulatory framework, and scheme delivery running 2028 through 2030. The statutory instrument that would actually give the FCA rulemaking power over open banking is still pending, expected by the end of 2026.
What to Consider:
- Two separate tracks: do not assume EU PSD3/PSR provisions map onto UK requirements — build compliance plans for each market independently.
- Statutory instrument gates enforcement: the Future Entity has no legal teeth until the pending legislation granting FCA rulemaking power is in force.
- Priority use cases come first: SME lending and mortgage access sit at the front of the roadmap; other use cases, including payments-focused ones, follow later.
- Full delivery runs to 2030: plan for a multi-year rollout, not a single go-live date.
Example
A UK-facing payments operator assumed 'open banking' meant identical rules on both sides of the Channel and mapped its onboarding flow to EU PSD3 provisions. Once the FCA's Open Finance Roadmap set SME lending and mortgage access as the earliest scheme priorities for 2027, the operator had to build a second, UK-specific compliance track from scratch.
Final Takeaway: Treat EU and UK open banking as two separate regulatory programs requiring two separate compliance builds, not one shared roadmap.
Why Does Open Banking Matter Specifically for High-Risk Operators?
Card-scheme rails carry structural costs that fall hardest on high-risk verticals: rolling reserves that lock up cash for 90-180 days, chargeback ratio thresholds that trigger acquirer review, and the risk of landing on the MATCH list after a termination. A payment initiated through a PISP moves directly between bank accounts and carries none of that card-network apparatus, which is exactly why crypto, iGaming, forex, and adult operators keep asking about it.
The underwriting value is arguably the bigger win. An AISP connection gives a compliance team direct, consented access to a customer's real transaction history, which strengthens source-of-funds and affordability evidence far beyond a submitted bank statement PDF. That matters more for a high-risk applicant's file than for a low-risk retail customer's, because high-risk underwriting lives or dies on document quality.
None of this makes open banking a frictionless replacement for the rails you already run. Adoption is uneven, and the friction is vertical-specific — our companion guide on pay by bank versus cards for high-risk merchants walks through the fee-versus-adoption tradeoff in detail, and the piece on open banking payments for iGaming covers a genuinely contrarian pattern: some UK banks now actively block gambling-related use of open-banking rails, and many PISPs decline to onboard iGaming merchants at all.
What to Consider:
- Underwriting value first: treat AISP data as a way to strengthen your compliance file before you treat PISP rails as a way to cut processing costs.
- Vertical-specific friction is real: gambling and adult operators face onboarding friction that crypto and forex operators may not, and it is provider-dependent, not universal.
- Not a guaranteed acceptance rail: plenty of PISPs still decline high-risk merchants outright, for the same compliance-burden reasons a bank would.
- Complement, not replacement: the realistic near-term use is alongside your existing card and EMI rails, not instead of them.
Example
A crypto exchange combined AISP-sourced bank-statement data with its existing KYC stack and cut manual source-of-funds review from an average of three business days to under four hours for verified customers, while keeping its card and EMI rails as the primary settlement channel.
Final Takeaway: Evaluate open banking as an underwriting and verification tool first for a high-risk business, and as a payment rail second — the fee savings only materialize if a provider will actually onboard your vertical.
How Does Open Banking Compare to the Payment Rails You Already Use?
Cards, EMI-issued IBAN transfers, and open banking / A2A payments solve overlapping but not identical problems, and the honest comparison has to include what each rail costs you when something goes wrong, not just the headline processing fee.
Bank-transfer and A2A fees typically run 1.0-2.0%, against roughly 2.5-3.5%+ for cards (average card swipe fee sits around 2.36%) — a real advantage, though vendor claims of "up to 50% lower" fees are a marketing hedge on a range, not a guaranteed outcome. The bigger structural difference is dispute rights: card transactions carry a chargeback right enforced by the card scheme, while A2A payments have no equivalent — disputes route through the payment provider's own resolution process instead, which is a genuinely weaker consumer-protection model in most cases, not a footnote.
What to Consider:
- Fee ranges are ranges, not guarantees: model savings on realistic 1.0-2.0% versus 2.5-3.5%+ bands, not on a vendor's best-case marketing figure.
- No chargeback right under A2A: disputes go through the provider's own process, which shifts risk allocation in a way your terms of service need to reflect.
- Adoption still lags awareness: in the UK, open banking payment volume grew 53% year-on-year through 2025, yet consumer awareness of the term "Pay by Bank" fell from 55% to 38% over the same period — a real gap between rail growth and customer recognition.
- US adoption remains marginal: roughly 1.5% of US consumer transactions used pay-by-bank in the twelve months to mid-2025, so treat any claim of imminent mainstream displacement of cards with skepticism.
Example
An operator processing 250,000 EUR a month at a 2.8% blended card cost modeled a switch to a 1.3% bank-transfer channel, a theoretical saving of roughly 3,750 EUR a month. The saving only exists for the share of customers who actually choose the option and complete it — in this operator's pilot, that was under a fifth of transaction volume in the first quarter.
Final Takeaway: Model open banking savings against realistic adoption rates for your customer base, not against 100% of card volume switching overnight.
| Feature | Cards | EMI / bank transfer | Open banking (PISP / A2A) |
|---|---|---|---|
| Typical fee range | 2.5-3.5%+ | 0.1-1.0% flat or fixed fee | 1.0-2.0% |
| Dispute mechanism | Chargeback right via card scheme | None — provider-specific | None — provider-specific |
| Settlement speed | T+1 to T+3 typical | Same-day to T+1 (SEPA/SWIFT) | Near-instant to same-day |
| High-risk vertical acceptance | Uneven, MCC-dependent | Established route via licensed EMIs | Provider-dependent, still maturing |
| Provider capital to hold the license | N/A (card scheme membership) | 350,000 EUR (EMI) | 50,000 EUR (PISP) / none (AISP) |
Getting the Open Banking Decision Right
The discipline that actually matters here is separating three questions that get collapsed into one: what can this specific provider's license do (AISP, PISP, or both), what regulatory framework governs that license today rather than the one under negotiation, and does this provider actually onboard businesses in your vertical.
Get those three answers before you evaluate cost. A PISP rail that is 1.5 percentage points cheaper than your card processing is not a win if the provider declines to onboard an iGaming or adult merchant, and a roadmap built around PSD3 provisions that have not reached the Official Journal is a roadmap built on a date nobody can actually confirm.
The operators getting real value out of open banking today are using AISP access to strengthen underwriting files and treating PISP rails as a genuine but partial complement to existing processing, not a wholesale replacement — exactly the sequencing this guide has walked through.
How BankMyCapital Helps
Structuring a payment stack that actually includes open banking rails means matching the right license category to the right use case, verifying a provider's real appetite for your vertical before you integrate, and keeping a card or EMI rail live as the fallback while adoption catches up to the fee advantage. BankMyCapital works through exactly that sequencing rather than presenting A2A as a drop-in card replacement.
See our payment processing services for how this structuring works in practice across card, EMI, and open banking rails together.
Frequently Asked Questions
What is the difference between an AISP and a PISP?
An AISP can only read account data — transaction history, balances, account details — with no minimum capital requirement beyond professional indemnity insurance. A PISP initiates payments directly from a customer's bank account and needs 50,000 EUR in initial capital. Some providers hold both authorizations.
Is PSD3 already in force in the EU?
No. The European Parliament and Council reached political agreement on PSD3 and the PSR on 27 November 2025, and the ECON committee approved the text on 5 May 2026, but neither instrument had been formally adopted or published in the Official Journal as of mid-2026. Realistic application is not before late 2027, and could slip into 2028.
Does the UK follow the same open banking rules as the EU?
No. The UK runs a separate, post-Brexit track through the FCA. Feedback Statement FS25/4 (August 2025) set out the design of a Future Entity to standardize open banking APIs, and the Open Finance Roadmap (April 2026) phases delivery through 2030, starting with SME lending and mortgage access rather than payments.
Does open banking actually work for high-risk verticals like crypto and iGaming?
Partially, and unevenly. AISP-based verification works well for source-of-funds and KYC evidence across every high-risk vertical. PISP-based payment rails are more provider-dependent — many decline high-risk merchants outright, and gambling specifically faces additional friction covered in our guide to open banking for iGaming.
What does BankMyCapital charge to help structure open banking or A2A payment rails?
Engagements are scoped individually because the mix of card, EMI, and open banking rails a business needs changes the workload, but structured payment support starts from a fixed floor rather than a percentage of turnover. Ask for a scoped quote once you can describe your business model and current rail mix.