viaBanking

Reference · Directive explainer

PSD2 open banking, explained

PSD2 is the European Union's second Payment Services Directive, and the law that turned open banking into a regulated activity. It obliges banks to open access to payment accounts, and it created two new licensed services that let an authorised third party read account information or initiate a payment on a customer's instruction. This page sets out the directive, the roles it defines and the open banking vocabulary that comes with them.

This is a description of the directive and the market around it. It is general information rather than legal advice, and it is not a statement about the regulatory status of any company.

Definition

What PSD2 is

A payment services directive, not a technology standard. What banks had to build as a result is covered on the open banking for banks page.

  • The instrument

    A European directive

    PSD2 is Directive (EU) 2015/2366 on payment services in the internal European market. It replaced the first payment services directive and has applied across the European Economic Area since January 2018. Each member state transposes it into national law, so the detail varies by market while the substance stays the same. It is the part of European financial law that open banking rests on.

  • The intent

    Why it was introduced

    Two goals sit behind the text: more competition in payment services, and stronger protection for the customer. New entrants were already building new financial services on top of bank accounts, often by asking people for the credentials they use for online banking. The directive brought that inside a licensing regime and gave it a supervised interface to use instead.

  • The scope

    What it regulates

    Payment services and the financial institutions that provide them. It defines who may offer each new financial service, what a bank must make available to an authorised third party, and how a customer's identity is verified before a payment or an access request is allowed to proceed. That last part is where open banking gets its security model.

Mechanism

How PSD2 created open banking

Open banking is the practical consequence of one part of the text. A bank that services a payment account has to give an authorised third party access to that account when its customer asks for it. The customer's explicit consent is the trigger, and the bank cannot insist on a commercial agreement with the third party as a precondition.

That single rule turned account access into an open, licensed market. Banks publish dedicated interfaces and any authorised provider can use them on the same terms, which is what makes the access open rather than negotiated. The phrase open banking describes that arrangement rather than a product, API or brand, which is part of why it gets used so loosely. New services grew on top of it.

Vocabulary

Key roles and services under PSD2

Four abbreviations carry most of the meaning. They turn up on every open banking page and in every new open banking contract, so they are worth getting straight once.

  • ASPSP

    Account servicing payment service provider

    The bank, building society or electronic money institution that holds the customer's payment account and services it. Under the directive the ASPSP is the party obliged to make open access available, and it stays responsible for checking its own customer's identity.

  • TPP

    Third party provider

    An authorised firm that uses that open access. A TPP is licensed by a national competent authority for the specific service it offers, and an authorisation obtained in one member state can be passported across the European Economic Area. Most new open banking entrants use this route.

  • AISP

    Account information service provider

    A TPP authorised to provide account information services: reading account data on the customer's explicit consent, within the scope that consent defines, and without moving any money. Many new financial products in the open banking market use this service.

  • PISP

    Payment initiation service provider

    A TPP authorised to provide the payment initiation service: placing a payment order at the customer's request from an account the customer holds elsewhere, without ever taking possession of the funds. It is the new open banking service behind pay-by-bank, and the one most merchants use.

Service one

AIS: account information service

The first of the two new services the directive created, and the one most open banking products use.

An account information service provides consolidated information about one or more payment accounts a customer holds. Under PSD2 this is a regulated financial activity: the firm needs authorisation as an account information service provider, and it may act only inside the scope of the consent that customer gave it.

In practice AIS sits behind new products that use open banking access to read balances and transactions for budgeting, affordability checks or accounting. The provider does not move money. Access is read-only by definition, and the customer can withdraw that consent at the bank at any point without asking the provider first.

Scope of the service

  • Reading the account data a consent covers
  • Consolidating accounts a customer holds at different banks
  • Moving money or placing a payment order
  • Acting beyond what the customer consented to

Service two

PIS: payment initiation service

The second new service, and the open banking service behind pay-by-bank checkouts. The role is described in more detail on the PIS provider page.

A payment initiation service places a payment order at the customer's request, from an account the customer holds at another financial provider. The firm needs authorisation as a payment initiation service provider. It initiates the payment and never takes possession of the funds at any part of the process.

The money still moves between the customer's bank and the payee's account on ordinary payment rails, the same ones every other transfer uses. The provider passes the instruction and reports what the bank returned, which is why an initiation confirmation and an actual credit are two separate events rather than one.

Scope of the service

  • Placing a payment order on the customer's instruction
  • Reporting the status information the bank returns
  • Holding or handling the customer's funds
  • Guaranteeing that a payment will complete

Protection

SCA and identity

The directive's main consumer protection mechanism, and the part of open banking where identity enters the picture.

  • The test

    What strong customer authentication requires

    SCA means verifying the customer's identity using at least two independent elements drawn from three categories: something only the customer knows, something only the customer has, and something the customer is. The elements must be independent, so compromising one part of the identity check does not compromise the rest.

  • The place

    Where the identity check happens

    At the bank. The customer authenticates with the financial institution that holds the account, using the identity credentials that institution issued and the app they already use. A third party never sees those identity credentials, and that separation is the point of the open banking design rather than a side effect of it.

  • The reach

    When it applies

    SCA applies to electronic payments and to online access to a payment account, with exemptions set out in the regulatory technical standards for certain low-value and low-risk cases. Those exemptions are the part practitioners argue about most. The SCA requirements have applied since September 2019.

Identity here is a regulatory concept rather than a product category. The directive cares whether the bank can satisfy itself that the person authorising an access request or a payment is the customer it knows, and leaves the mechanics of that identity check to the institution and the technical standards. Identity verification therefore looks different from one bank to the next while the legal test stays the same.

Effect

What PSD2 changed

Since the directive took effect, four new patterns show up consistently across the open banking market.

  • New services on top of accounts

    Budgeting tools, lending decisions, accounting integrations and pay-by-bank checkouts became a new class of regulated financial service with a defined interface to use, rather than workarounds built on shared credentials. New financial products now assume open banking exists.

  • New entrants

    Authorisation created a new route into financial services for firms that would never have been granted the bank relationship the old model required. New competition arrived from outside the incumbent set, and a large part of it now uses open banking.

  • A different customer experience

    The customer stays with their own bank for identity and consent. What moved is where a payment starts, not who holds the account and not who checks the customer's identity. For the customer the new part is the checkout, not the bank.

  • New obligations for banks

    Banks became infrastructure providers as well as financial service providers, with a new standing duty to keep an open access interface working for parties they neither chose nor control.

Disclosure

Where viaBanking fits

One section about the operator of this site, for completeness, in the same third person as the rest of the page.

viaBanking is a software company. It is not a financial institution, it holds no authorisation under the directive, and it does not perform account information or payment initiation services. Each of those services is performed by the licensed providers a business chooses to use.

What the platform does is orchestration. It connects a business to the licensed AIS and PIS providers it wants to use through one integration, routes each request to a provider that reaches the relevant bank, and normalises what comes back into a single shape. On top of that it confirms, read-only, that a payment reached the business's own account. Adding a new provider is a configuration change rather than a new integration. The same model is set out on the open banking aggregator page.

  • Licensed AIS and PIS providers Perform the regulated services the directive defines, for the businesses that use them
  • The customer's bank Verifies identity, applies SCA and moves the funds the customer sends
  • The account issuer Holds the business account that receives a payment
  • viaBanking Software the business chooses to use: routing, normalisation, a read-only credit check

Status

A note on what comes next

The European Commission has published proposals for a third payment services directive and an accompanying payment services regulation, often referred to as PSD3 and PSR. Those proposals have been moving through the European legislative process and their final content and timing are not settled. Nothing here should be read as a description of law already in force, no provision of the proposals is described on this page, and anyone planning around them should follow the official process and their own advisers rather than a vendor page. What the package covers is walked through on the PSD3 open banking page.

FAQ

Common questions

  • Does PSD2 require a licence to offer AIS or PIS?

    Yes. Both are regulated payment services under the directive. A firm that wants to offer either service needs authorisation from a national competent authority, and the authorisation is specific to the service it covers. Supervision, capital and conduct requirements are part of the package.

  • Is viaBanking a PSD2-licensed provider?

    No. viaBanking is a software layer and holds no PSD2 authorisation of any kind. It does not perform account information or payment initiation services. Those are performed by the licensed providers the platform routes to.

  • Is open banking the same thing as PSD2?

    Not quite. PSD2 is the law; open banking is the market and the set of practices that grew out of it. Other jurisdictions run their own new frameworks with different rules and names, so the term travels further than the directive does. Part of the confusion comes from that.

  • Does the customer consent once, or every time?

    Consent is given to the provider and authenticated at the bank. How long an access consent lasts and when it has to be renewed are set by the directive and the technical standards rather than by whichever service the customer chose to use. A customer can withdraw consent with their bank.

See how the platform works

This page covered the directive and the open banking market it created. If you would rather see the software side, the connectivity a business would use is described on the bank connectivity page.

This page is general information about EU payment services regulation and is not legal advice. viaBanking is a software and technology provider: it holds no PSD2 authorisation, does not perform account information or payment initiation services, does not execute bank payments and does not hold or move funds. Regulated services are performed by licensed partner institutions, and licence and authorisation details vary by market and by provider.