Open banking gets described as letting apps see your bank account, which undersells what the regulation actually did to the structure of retail banking.

The core requirement

Banks were required to provide, through standardised interfaces, access to account data and payment initiation, on the customer's instruction, to authorised third parties.

Two distinct things sit in that sentence.

Data access lets a third party read transaction history with permission.

Payment initiation lets a third party instruct a payment directly from the account, without a card network in between.

The second is the more consequential and receives less attention.

Why regulators did it

The stated reasoning was that banks held customer transaction data exclusively, and that exclusivity was a barrier to competition.

A new entrant could not assess a customer's finances without the incumbent's cooperation, which the incumbent had no reason to provide.

Mandating access was intended to lower that barrier.

Whether it has worked is contested, and the honest answer varies considerably by market.

The screen scraping it replaced

Before the standardised interfaces, aggregation services obtained data by asking customers for their banking credentials and logging in as them.

Which worked, broke constantly when interfaces changed, and required customers to hand over credentials in a way that violated every security instruction their bank had given them.

The regulated interfaces removed that, replacing shared credentials with scoped, revocable, time-limited authorisation.

That is a genuine security improvement and it is the clearest benefit of the whole exercise.

What got built on it

Account aggregation, which shows balances across institutions in one place.

Affordability assessment using actual transaction data rather than declared income, which has changed lending decisions particularly for people with irregular income.

Accounting integration that pulls bank transactions directly rather than through file imports.

And account-to-account payments, which bypass card networks and the interchange fees attached to them.

The payment initiation question

This is where the commercial stakes are largest.

Card payments carry fees paid by the merchant, split between the issuing bank, the acquiring bank and the network.

A direct bank transfer initiated by a third party avoids most of that structure.

Which is attractive to merchants and unattractive to the parties currently receiving those fees.

Adoption has been strongest where the payment experience is genuinely comparable, and card habits have proven durable where it is not.

The uneven implementation

Markets that mandated standardised interfaces with performance requirements saw faster adoption than those that left implementation to industry.

Where banks were required to meet availability and response time standards, and to report on them, the interfaces worked.

Where they were not, quality varied enough to limit what could be built.

Which is a reasonably clear natural experiment about whether mandating an outcome or mandating a capability produces results.

Consent and its limits

Authorisation is granted for a defined scope and period and can be withdrawn.

In practice, consent is granted at the moment of enthusiasm about a new application and reviewed rarely afterwards.

Which means live authorisations accumulate, and most people could not list them.

Banks provide a view of active authorisations, generally buried in settings. Checking it periodically is a five-minute exercise worth doing.

Where it goes next

Several jurisdictions have extended or proposed extending the model beyond banking, into pensions, insurance, utilities and investments, generally under the label of open finance.

The argument is that the same reasoning applies wherever an incumbent's exclusive hold on customer data limits competition.

The counterargument concerns the security and liability implications of extending data sharing across more sensitive categories.

Both positions have substance and the direction of travel appears settled even where the pace is not.

What it means practically

Mostly that services asking to connect to your bank are now doing so through a supervised channel rather than by holding your credentials, which is worth knowing.

And that the authorisation you granted is revocable at any time from your bank, without needing to contact the third party.

That control is the part of the regulation that most directly benefits an individual, and it is the part least advertised.

Liability when something goes wrong

The question that determines whether any of it is safe to use.

Where a payment is initiated by a third party and goes wrong, the regulations generally place the initial obligation to refund on the account-holding bank, which then recovers from the third party if the fault lay there.

Which matters because it means the customer deals with their own bank rather than pursuing an unfamiliar company.

Authorised push payment fraud sits differently — where the customer was deceived into instructing a legitimate payment — and reimbursement rules for it have been introduced separately in some markets after sustained pressure.

The commercial reality for banks

Banks bore the cost of building the interfaces and received no direct revenue from them, which explains the pace and quality of some implementations.

Some have since built premium interfaces offering richer data on commercial terms, beyond the regulatory minimum.

Which is where the market is heading — a mandated floor with commercial arrangements above it — and it was probably always the likely outcome.