# Open Banking: AISP and PISP Licences, Access to Bank APIs and Open Finance

> AISP and PISP authorisation under PSD2: registration or licence, €50,000 capital, PII, bank API access and what PSD3, the PSR and FIDA would change.

Author: Gordey Bolotko — Partner, Corporate & Commercial (https://wiki.private.law/en/authors/bolotko)
Last modified: 2026-09-25T08:10:00.000Z
Canonical: https://wiki.private.law/en/open-banking-aisp-pisp
Publisher: wiki.private.law (https://wiki.private.law)
Version: 91a14ac041e850e0c62a663c813bbb0a6d4e55f84a5e8883f1fd8ae66c7f7b2e
Cite as: Open Banking: AISP and PISP Licences, Access to Bank APIs and Open Finance. wiki.private.law. https://wiki.private.law/en/open-banking-aisp-pisp. Version 91a14ac041e850e0c62a663c813bbb0a6d4e55f84a5e8883f1fd8ae66c7f7b2e.
Topics: banking
Jurisdictions: eu, uk, bulgaria
Functional tags: license
Product tags: license-emi-eu, compliance, banking
Semantic tags: license, license-emi-eu, compliance, banking

---

Open banking, one of the core [fintech models](https://wiki.private.law/en/fintech-hub), rests in the EU on two payment services that never touch the customer's money. A payment initiation service (PIS) sends a payment order to the customer's bank on the customer's instruction. An account information service (AIS) gathers balances and transactions from accounts held elsewhere and shows them in one place. [PSD2 lists them as points 7 and 8 of Annex I](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117), and the firms that provide them are the payment initiation service provider (PISP) and the account information service provider (AISP).

What the law gives them is a right of access: the customer may use them on any payment account that is accessible online, and the bank holding that account cannot make the access depend on a contract with the provider.

## How open banking works under PSD2

### Two services built on someone else's account

PSD2 defines payment initiation as a service [to initiate a payment order at the request of the payment service user with respect to a payment account held at another payment service provider](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) (Art. 4(15)). Account information is [an online service providing consolidated information on one or more payment accounts](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) that the user holds with another provider, or with several (Art. 4(16)). Both services sit on top of an account that the provider does not keep. The provider that keeps it, usually a bank, is the account servicing payment service provider (ASPSP); the AISP or PISP is the third party.

That structure is the point of the regime. PSD2 turns access to someone else's account into a regulated service and gives it a matching obligation on the account-holding bank, so that aggregation and pay-by-bank can be built by firms that are not banks and have no commercial agreement with the banks they connect to.

### The legal result: access without a contract

A payer has [the right to use a PISP, and a user the right to use an AISP](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117), unless the payment account is not accessible online (Arts 66(1) and 67(1)). Neither service may be made [dependent on a contractual relationship](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) between the provider and the bank (Arts 66(5) and 67(4)).

The bank's side of the bargain is set out in [Arts 66(4) and 67(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117). It must communicate securely with the PISP, give it all information on the initiation and execution of the payment immediately after receiving the order, and treat orders sent through a PISP without discrimination other than for objective reasons, in particular as to timing, priority or charges. Data requests from an AISP get the same non-discrimination rule.

The provider's side carries matching limits. A PISP [may not hold the payer's funds](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) at any time in connection with the service, may not store sensitive payment data or request more data than the service needs, and may not change the amount, the payee or any other feature of the transaction (Art. 66(3)). An AISP acts only on the user's explicit consent, reaches only the accounts the user designates and uses the data only for the service requested ([Art. 67(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117)). The account owner's name and the account number are [not sensitive payment data](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) for these services (Art. 4(32)).

### How access works in practice

The mechanics sit in [Delegated Regulation (EU) 2018/389](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912), the regulatory technical standards on strong customer authentication and secure communication (the RTS). Every bank offering an online payment account must keep [at least one access interface](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912) for third parties: a dedicated interface, in practice an API, or an adapted version of the interface its own customers use (RTS Arts 30(1) and 31). The provider identifies itself with an eIDAS qualified certificate, and the customer authenticates with the bank's own credentials, because PSD2 requires the bank to [let AISPs and PISPs rely on its authentication procedures](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) (Art. 97(5)).

A pay-by-bank payment runs along this chain:

```mermaid
flowchart LR
    C["Customer"] -->|instruction| P["PISP"]
    P -->|payment order via interface| B["Customer's bank"]
    C -->|authenticates with bank credentials| B
    B -->|credit transfer| M["Payee"]
```

The customer instructs the PISP, the PISP transmits the order through the bank's interface, the customer authenticates with the bank, and the bank executes the transfer from the customer's own account. The money never passes through the PISP, which is why the prudential rules for these firms look so different from those for other payment institutions.

### What makes the model distinctive

Three features follow from that design.

**Registration for data, authorisation for payments**

An AIS-only firm is registered rather than authorised and needs no initial capital. Payment initiation requires full authorisation as a payment institution, with €50,000 of initial capital.

**Insurance instead of balance sheet**

Neither service triggers safeguarding or the ongoing own-funds formula. The prudential cushion is professional indemnity insurance (PII), sized to the losses the provider could cause.

**Dependence on the bank's interface**

The product is only as good as the bank's interface. The law answers with parity rules, a list of obstacles, a fallback and supervision by the national authority.

A fourth feature is the allocation of loss. In a failed or unauthorised pay-by-bank payment the customer claims from the bank, which refunds first; the PISP then compensates the bank if the fault lies with it. When a platform embeds pay-by-bank or aggregation in its own product, whose authorisation stands behind the service is the question addressed in [embedded finance](https://wiki.private.law/en/embedded-finance) and, for bank partnerships, in [BaaS and sponsor banks](https://wiki.private.law/en/baas-sponsor-bank).

> 🍓 The regulatory weight of an open-banking provider follows what it can do to the money, not the size of the firm. Reading data needs a registration and insurance. Moving money needs authorisation, €50,000 of capital and insurance. Holding money would bring safeguarding and own funds, which AIS and PIS avoid by design.

The regime as it stands in September 2026:

- Legal basis · PSD2 Annex I points 7–8, Arts 33, 66–68; RTS 2018/389
- AIS only · registration; no initial capital; PII
- PIS · payment-institution authorisation; €50,000 initial capital; PII
- Client funds · none held; no safeguarding; no own-funds formula
- Bank access · statutory right, no contract; at least one interface per bank
- Market · 87 active AISP registrations in the EBA register (24 September 2026)
- Reform · PSR and PSD3 provisionally agreed, not adopted; FIDA a proposal

## Registration or licence: the two statuses

### Account information: registration

A provider offering only account information is [exempt from the PSD2 authorisation procedure and conditions](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) and is registered instead (Art. 33(1)). Only part of the authorisation regime applies to it: a subset of the application information in Art. 5(1), the insurance requirement of Art. 5(3), the registers of Arts 14 and 15 and the common provisions of Section 3, which include passporting, except Art. 23(3). The initial-capital rule of Art. 7 is not on that list.

Registered AISPs are [treated as payment institutions](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117), but Titles III and IV of PSD2 do not apply to them, except Arts 41, 45 and 52 where applicable and Arts 67, 69 and 95–98 (Art. 33(2)).

The insurance must cover the territories where the AISP offers services and its [liability to the bank or the user for unauthorised or fraudulent access to or use of payment account information](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) (Art. 5(3)). A comparable guarantee may replace the policy.

### Payment initiation: authorisation

A PISP needs [authorisation as a payment institution](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) (Art. 11), and the competent authority decides within three months of receiving a complete application (Art. 12). Its [initial capital is at least €50,000](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) under Art. 7(b), between the €20,000 set for money remittance and the €125,000 set for services 1 to 5. It must also hold [PII covering its liabilities under Arts 73, 90 and 92](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) (Art. 5(2), as corrected in 2018). How that €50,000 sits beside the other payment and e-money capital levels is set out in [regulatory capital](https://wiki.private.law/en/regulatory-capital), and how the two routes compare with other EU payment and e-money licences in the [fintech licence map](https://wiki.private.law/en/fintech-license-map).

The two tracks compared:

| Point | AIS only | PIS, alone or with AIS |
| --- | --- | --- |
| Status | registration (Art. 33) | authorisation as a payment institution (Art. 11) |
| Initial capital | none | €50,000 (Art. 7(b)) |
| Ongoing own funds | none | none if only PIS and AIS (Art. 9(1)) |
| Insurance | PII for unauthorised or fraudulent access to or use of account data | PII for liabilities under Arts 73, 90 and 92 |
| Safeguarding | none | none; the PISP may never hold the payer's funds |
| Decision period | none set by PSD2 | three months from a complete application (Art. 12) |
| Passport | notification; forwarded to the host authority within one month | the same (Art. 28(2)) |

The ongoing burden is therefore light on both tracks: payment institutions offering only PIS, AIS or both are [exempt from the own-funds calculation of Art. 9(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117), and [safeguarding under Art. 10(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) reaches only services 1 to 6. What separates the two tracks is the entry: capital and a full authorisation file for PIS, a registration for AIS.

Both statuses appear in the home state's [public register](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117), which must identify the services and list authorised institutions separately from registered persons, and the European Banking Authority (EBA) keeps a central register fed by the national authorities (Arts 14 and 15). Because the passporting section applies to AISPs too, a registered AISP can serve other member states: the home authority [forwards the notification to the host authority within one month](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) of receiving complete information (Art. 28(2)). The notification procedure itself is covered in [EU passporting](https://wiki.private.law/en/eu-passporting), and the use of agents in [payment agents and passporting](https://wiki.private.law/en/payment-agents-eu).

### How the PII minimum is calculated: 3 criteria

PSD2 leaves the amount of cover to the national authority, which applies the [EBA Guidelines EBA/GL/2017/08](https://www.eba.europa.eu/sites/default/files/documents/10180/1901998/6411f24d-e430-4e05-ab03-1393a3f865cb/Final%20Guidelines%20on%20PII%20under%20PSD2%20%28EBA-GL-2017-08%29.pdf), applicable since 13 January 2018. The minimum is the sum of three amounts: one for the risk profile, one for the type of activity and one for the size of activity, stated as a figure per year. Where a firm has not provided services in the previous 12 months and gives no forecasts, or its forecasts produce less than €50,000 for an indicator, the authority sets that indicator to €50,000.

For a new firm with no business other than payment services, the arithmetic gives the same total on both tracks:

| Indicator | AIS only | PIS only |
| --- | --- | --- |
| Requests for refunds | €50,000 | €50,000 |
| Accounts accessed or transactions initiated | €50,000 | €50,000 |
| Type of activity | €0 | €0 |
| Clients or value of transactions initiated | €50,000 | €50,000 |
| Minimum per year | €150,000 | €150,000 |

Three adjustments change that figure. A firm also engaged in business other than payment services adds €50,000, unless it shows that the other business does not affect PIS or AIS. An applicant for both services has the two amounts calculated separately and added, which gives €300,000. And the floors are a start-up rule only: the [EBA confirmed in Q&A 2025\_7317](https://www.eba.europa.eu/single-rule-book-qa/qna/view/publicId/2025_7317) that once a firm has provided services in the previous 12 months they no longer apply, and the amount is recalculated from actual data at the periodic review.

### Bulgaria under the BNB: 4 parameters

Bulgaria transposes the regime in the [Payment Services and Payment Systems Act (ZPUPS)](https://www.bnb.bg/bnbweb/groups/public/documents/bnb_law/laws_payment_services_bg.pdf). A company that wants to provide account information applies to the Bulgarian National Bank (BNB) for entry in the public register under Art. 19 (Art. 18). The conditions include PII covering each state where it will operate, a three-year business plan, governance consistent with DORA and fit-and-proper managers, and the BNB decides within the time limits of Art. 11.

The main parameters of the Bulgarian regime, as they stand in September 2026:

| Point | Bulgarian rule |
| --- | --- |
| PIS initial capital | €50,000, stated in euro since 1 January 2026 (ZPUPS Art. 8 item 2) |
| PIS insurance | PII covering ZPUPS Arts 79, 94 and 95, the counterparts of PSD2 Arts 73, 90 and 92 (Art. 10(6)) |
| Insurance amount | EBA method, indicators under Guidelines 5–7, per year, reviewed annually (Ordinance No. 16, Arts 13–14) |
| BNB review fee | €2,500 for AISP registration; €4,000 PI licence; €5,000 EMI licence (Ordinance No. 16, Art. 70) |

The [ZPUPS](https://www.bnb.bg/bnbweb/groups/public/documents/bnb_law/laws_payment_services_bg.pdf) sets the capital and insurance rules, and [BNB Ordinance No. 16](https://www.bnb.bg/bnbweb/groups/public/documents/bnb_law/au_lf_ordinance_16_bg.pdf) adopts the EBA formula for the insurance amount without setting a separate Bulgarian figure; the annual review is notified to the BNB within one month.

On 24 September 2026 the [EBA register](https://euclid.eba.europa.eu/register/pip/search) showed no AISP registered by the BNB. The Bulgarian open-banking permissions sit with payment institutions: Iris Solutions AD (licensed in 2019) and Octis Pay OOD (licensed on 24 February 2026), which hold only PIS and AIS, and BORICA AD, which holds them alongside acquiring. Five e-money institutions also list PIS or AIS: Easy Payment Services OOD, MyFin EAD, EasyPay AD, Tenen Payments AD and Paynetics AD. The rest of the BNB regime is described in [EMI and payment institution licences in Bulgaria](https://wiki.private.law/en/bulgaria-emi-license) and, across supervisors, in [Bulgaria's financial licences](https://wiki.private.law/en/bulgaria-financial-licenses).

## What the bank must provide

The RTS turn the right of access into engineering duties on both sides of the connection.

**The bank (ASPSP)**

Keeps at least one interface. A dedicated interface must match the customer interface in availability and performance, with published quarterly statistics. Documentation is free, a testing facility is provided, and specification changes are announced at least three months ahead.

**The provider (AISP or PISP)**

Identifies itself with a qualified certificate carrying its authorisation number and relies on the bank's authentication. A PISP does not store sensitive payment data, and an AISP does not request it. An AISP refreshing data in the background stays within four accesses in 24 hours unless more are agreed.

Parity is measured rather than asserted. The dedicated interface must offer [at all times the same level of availability and performance, including support](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912), as the customer interface, against transparent key performance indicators and service-level targets (RTS Art. 32(1), (2) and (4)).

The technical documentation is [available free of charge](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912) to authorised providers and to applicants for authorisation, and a summary is published on the bank's website. The three months' notice of changes can be shortened only in an emergency (Art. 30(3)–(5)).

The certificates are [eIDAS qualified certificates for electronic seals or for website authentication](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912) (Art. 34). The registration number in the certificate is the authorisation number in the home state's PSD2 register or, for a credit institution offering these services, the number that results from its banking authorisation.

The four-access limit applies only to access without the user: an AISP may access data [whenever the user actively requests it, and otherwise no more than four times in 24 hours](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912), and a higher background frequency needs an agreement with the bank and the user's consent (Art. 36(5)).

### Strong customer authentication and the 180-day cycle

Strong customer authentication applies whenever a user [accesses the account online, including through an AISP, and whenever a payment is initiated through a PISP](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) (PSD2 Art. 97). The access-security measures of PSD2 [applied from 14 September 2019](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912), the date from which the RTS apply.

For aggregation, the burden was eased in 2023. Since 25 July 2023, under [Art. 10a inserted by Delegated Regulation (EU) 2022/2360](https://eur-lex.europa.eu/eli/reg_del/2022/2360/oj), a bank must not apply strong customer authentication when a user accesses through an AISP only the balance or the transactions of the last 90 days, without disclosure of sensitive payment data.

It must apply it at the first access through that AISP and when more than 180 days have passed since it was last applied for that access. The bank may still require it for objectively justified and duly evidenced reasons relating to unauthorised or fraudulent access. As a result, the customer authenticates with the bank again at least every 180 days for the AISP's access to continue.

### The fallback and the exemption from it

A dedicated interface must come with a contingency plan for the case where it fails.

> ⚙️ Unplanned unavailability or a systems breakdown [may be presumed](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912) when five consecutive access requests go unanswered within 30 seconds (RTS Art. 33(1)). As a contingency, providers may then use the interface the bank offers its own customers, provided they identify themselves and log the data they access (Art. 33(4)–(5)).

The national authority, after consulting the EBA, [exempts a bank from the fallback](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912) if its dedicated interface complies with Art. 32, was designed and tested to the providers' satisfaction, has been widely used for at least three months and has its problems resolved without undue delay. The exemption is revoked if the first or the last of those conditions is not met for more than two consecutive calendar weeks, and the bank must then set up the fallback within two months (Art. 33(6)–(7)).

## Obstacles, refusals and supervision

Parity would mean little if the bank could design the interface to discourage its use. The RTS therefore require that a dedicated interface [create no obstacles to AIS and PIS](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02018R0389-20230912) and give examples: preventing the use of bank-issued credentials, imposing redirection to the bank's own authentication, requiring authorisations or registrations beyond those of PSD2, and requiring additional checks of the consent the user gave the provider (Art. 32(3)).

The EBA has given the notion of an obstacle a broad reading. In [Opinion EBA/OP/2020/10 of 4 June 2020](https://www.eba.europa.eu/sites/default/files/document_library/Publications/Opinions/2020/884569/EBA%20Opinion%20on%20obstacles%20under%20Art.%2032%283%29%20RTS%20on%20SCA&CSC.pdf) it stated that redirection is not in itself an obstacle but becomes one if it adds unnecessary friction, and that mandatory redirection is an obstacle where it is the only authentication method supported. The Opinion also addresses multiple authentications, 90-day re-authentication, account selection, additional consent checks and additional registrations.

In [Opinion EBA/Op/2021/02 of 18 February 2021](https://www.eba.europa.eu/sites/default/files/document_library/Publications/Opinions/2021/963372/Opinion%20on%20supervisory%20actions%20for%20removal%20of%20obstacles%20to%20account%20access%20under%20PSD2.pdf) it asked national authorities to take supervisory action by 30 April 2021 against banks that had not removed obstacles, including revocation of fallback exemptions and fines where deadlines are missed.

A bank may deny a provider access only for [objectively justified and duly evidenced reasons relating to unauthorised or fraudulent access](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117). It must inform the payer, unless security reasons or law prevent it, and immediately report the incident to the competent authority (Art. 68(5)–(6)).

> ⚠️ Because there is no contract with the bank, a provider's leverage is regulatory. Disputes over redirection-only journeys, extra authentication steps or blocked access are a matter for the national competent authority, which receives the bank's report on every denial and supervises the interface and its fallback exemption.

## Liability when a payment goes wrong

Pay-by-bank separates the party the customer claims from and the party that bears the loss. For an [unauthorised transaction initiated through a PISP](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117), the bank refunds the payer no later than the end of the following business day. If the PISP is liable, it must immediately compensate the bank, and the burden of proving that the transaction was authenticated, accurately recorded and not affected by a technical failure within its sphere lies on the PISP (Art. 73(2)).

The same pattern applies to [non-execution or defective or late execution](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02015L2366-20250117) of an order initiated through a PISP: the bank refunds the payer, and the PISP must prove that it received the order and handled it correctly within its sphere, compensating the bank if it is liable (Art. 90).

> ⚠️ The customer's refund does not wait for the PISP, but the loss can end up with it. A PISP carries a recourse exposure towards every bank it connects to and must prove its own correct handling. Its insurance exists to cover that exposure, which is why PSD2 requires it even though the firm never holds client money.

Who bears the loss in authorised push-payment fraud, and how refund rights compare across payment types, is the subject of [payment fraud liability](https://wiki.private.law/en/payment-fraud-liability); how card schemes allocate disputes, the usual point of comparison for pay-by-bank at checkout, is covered in [card scheme rules](https://wiki.private.law/en/card-scheme-rules).

## Operating perimeter: ICT and sanctions

### Digital operational resilience

[DORA (Regulation (EU) 2022/2554)](https://eur-lex.europa.eu/eli/reg/2022/2554/oj) applies expressly to account information service providers as well as to payment institutions (Art. 2(1)(b)–(c)), from 17 January 2025. An AISP is therefore within DORA despite its light prudential status; what that entails is set out in [DORA](https://wiki.private.law/en/dora-eu). Where a provider relies on a technical vendor to run its bank connections, the limits are those of [outsourcing by licensed firms](https://wiki.private.law/en/outsourcing-licensed-firms).

### EU sanctions perimeter (Regulation 833/2014)

Sanctions split the two services. Since 24 October 2025, [Art. 5b(2)(b) of Regulation 833/2014](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02014R0833-20260724) has prohibited providing payment initiation services to Russian nationals, natural persons residing in Russia and legal persons, entities or bodies established in Russia. Nationals of a member state, the EEA or Switzerland, and holders of a residence permit there, are exempt under Art. 5b(3). Account information services are not listed, so the ban reaches pay-by-bank but not aggregation.

## The market in numbers

The EBA central register shows how the two statuses are used. Counts in the [EBA register as of 24 September 2026](https://euclid.eba.europa.eu/register/pip/search):

| Measure | Count |
| --- | --- |
| Active AISP registrations (of 129 ever registered) | 87 |
| Active payment institutions offering PIS | 168 |
| Active EMIs offering PIS | 77 |
| Active payment institutions with no services beyond PIS and AIS | 62 |

The registered AISPs come from 20 national authorities, led by Finland with 15, France with 10 and Sweden with 9. Payment initiation, by contrast, is mostly an add-on to a broader payment or e-money licence: only 62 of the 168 payment institutions offering it hold no other payment permission. Banks are payment service providers in their own right and can offer both services, but they do not appear in this register. The EBA states that its register, [unlike the national registers under PSD2, has no legal significance](https://euclid.eba.europa.eu/register/pip/search).

## What changes next: PSD3, the PSR and FIDA

Two EU reforms would change open banking, the PSD3/PSR payments package and FIDA, and neither is law. [PSD3](https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2023%2F0209\(COD\)) and the [Payment Services Regulation (PSR)](https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2023%2F0210\(COD\)) were provisionally agreed by the Council and Parliament, as announced on 27 November 2025, and the ECON committee approved the agreed text on 5 May 2026; both await the Council's first-reading position, with a plenary vote forecast, as of September 2026, for 14 December 2026, and neither is adopted, published or in force.

The Financial Data Access Regulation (FIDA), proposed by the Commission on 28 June 2023, is further behind. The Council adopted its negotiating position on 4 December 2024, and Parliament's committee decision to negotiate was confirmed in plenary on 18 December 2024. [Trilogue negotiations began in 2025](https://data.consilium.europa.eu/doc/document/WK-5041-2026-INIT/en/pdf), but no provisional agreement has been recorded, and the [legislative file](https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2023%2F0205\(COD\)) still shows Parliament's first-reading position as pending.

### Licensing in the agreed PSD3 text

The [final compromise text of PSD3](https://data.consilium.europa.eu/doc/document/ST-8222-2026-INIT/en/pdf) (Council document 8222/26 of 17 April 2026) would keep both statuses. Account information would remain a registration backed by PII (Art. 36(1) and (4)). Payment initiation, renumbered as point 6 of Annex I, would still require €50,000 of initial capital (Art. 5(b)) and would stay outside the own-funds calculation when offered alone or only with AIS (Art. 7(1)). Where a payment institution also provides any of services 1 to 5 or issues e-money, the capital minimums would be added together (Art. 5).

### Access rules in the agreed PSR text

The Commission's [PSR proposal](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52023PC0367) put forward four access elements: a mandatory dedicated interface, a permission dashboard for users, a list of prohibited obstacles and AIS access whether or not the user is actively requesting data. The [final compromise text](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf) (Council document 8221/26 of 17 April 2026) keeps all four and also covers exemptions from the dedicated interface, interface failure and strong customer authentication for account information. Article numbers may still change in legal-linguistic revision. Under that text:

- a bank offering an online payment account would have to maintain at least one dedicated interface, in place within three months of its authorisation (Art. 35);
- unavailability would be presumed ("shall be presumed") after five consecutive failed requests within 30 seconds, where the RTS now say "may be presumed" (Art. 38(1));
- the competent authority could exempt a bank from the dedicated interface, allowing the customer interface with equivalent functionality or, where justified, no interface at all (Art. 39);
- background access by an AISP would be written into the regulation itself, with no numeric limit in the article, provided the AISP makes the user aware of it beforehand (Art. 41(2)–(2a));
- banks would have to give users a permission dashboard to monitor and withdraw consents (Art. 43);
- a list of prohibited obstacles would become part of the regulation (Art. 44);
- the bank would apply strong customer authentication only at an AISP's first access, unless it has reasonable grounds to suspect fraud (Art. 86(3));
- the AISP would then apply it at least every 180 days, using its own or the bank's (Art. 86(4)).
Most of the agreed text would apply 21 months after the regulation enters into force (Art. 112).

### FIDA: data beyond payment accounts

The [FIDA proposal](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52023PC0360) would open other categories of financial data: mortgages, loans and accounts other than payment accounts, savings and investments, crypto-assets, pension rights, non-life insurance and data used to assess the creditworthiness of firms (Art. 2(1)). Payment-account data would stay under the payments framework.

Data holders and users would have to join financial data sharing schemes within 18 months of entry into force (Art. 9(1)). A data holder could claim compensation only for data made available under scheme rules or under the fallback act of Art. 11 (Art. 5(2)). A new financial information service provider would need PII or, as an alternative, €50,000 of initial capital that can be replaced by insurance once it starts operating (Art. 12(3)).

The Council's [negotiating position of 4 December 2024](https://www.consilium.europa.eu/en/press/press-releases/2024/12/04/capital-markets-union-council-agrees-to-make-consumers-financial-data-more-accessible/) supports step-by-step implementation and excludes occupational pension data, with an opt-in for member states.

The three instruments side by side:

| Instrument | Status (September 2026) | Data covered | Access model |
| --- | --- | --- | --- |
| PSD2 and RTS 2018/389 | in force | payment accounts | statutory access without contract; at least one interface; fallback unless exempted |
| PSR (agreed text) | provisionally agreed, not adopted | payment accounts | dedicated interface unless exempted, permission dashboard, prohibited obstacles |
| FIDA (proposal) | in trilogue, no agreement | other financial data, excluding payment accounts | data sharing schemes; compensation under scheme rules |

The table shows that the two reforms do not overlap: a product built on current-account data stays in the payments regime whatever happens to FIDA.

> 🧭 PSD2 and the RTS govern payment-account data today, and the PSR would replace them for the same data once adopted and applicable. FIDA would reach loans, savings, investments, pensions and insurance data instead. The wider reform, including the merger of payment and e-money institutions, is followed in [PSD3 and the PSR](https://wiki.private.law/en/psd3-psr).

## United Kingdom in brief

Under [Schedule 3 to the Payment Services Regulations 2017](https://www.legislation.gov.uk/uksi/2017/752/schedule/3), payment initiation requires €50,000 of initial capital and account information none, and AIS-only firms apply to the FCA for registration as account information service providers (regs 17–18).

The [Data (Use and Access) Act 2025](https://www.legislation.gov.uk/ukpga/2025/18/contents), which received Royal Assent on 19 June 2025, gives powers in Part 1 to make customer-data ("smart data") regulations, with sections 14 to 17 on the FCA and financial services interfaces. As of 24 September 2026 no smart-data regulations for open banking have been made under it; the instruments made so far are commencement and consequential regulations. UK registration mechanics are covered in the [UK FCA licence map](https://wiki.private.law/en/uk-fca-license-map).

## Q/A

### Status and cost

### **Do I need a licence to build account aggregation in the EU?**

Not a full licence. A firm offering only account information registers with its national authority under PSD2 Art. 33, needs no initial capital and must hold professional indemnity insurance. Once registered, it can passport its service to other member states by notification.

### **What does a pay-by-bank provider need?**

Payment initiation requires authorisation as a payment institution under PSD2 Art. 11, initial capital of at least €50,000 and professional indemnity insurance covering its liabilities to payers and banks. The authority decides within three months of a complete application. There is no safeguarding and no ongoing own-funds formula, because a PISP never holds the payer's funds.

### **How much professional indemnity insurance is required?**

The national authority sets it under EBA/GL/2017/08. For a new AIS-only or PIS-only firm with no other business and no forecasts, the floors give €150,000 a year; a firm providing both services adds the two amounts, giving €300,000. After 12 months of activity the floors no longer apply and the amount is recalculated from actual data.

### Access to banks

### **Do I need a contract with each bank?**

No. PSD2 Arts 66(5) and 67(4) forbid making AIS or PIS dependent on a contract with the account-holding bank. The provider identifies itself with an eIDAS qualified certificate and connects through the interface the bank must provide.

### **Can a bank refuse or block my access?**

Only for objectively justified and duly evidenced reasons relating to unauthorised or fraudulent access. The bank must inform the payer, unless security reasons or law prevent it, and immediately report the incident to its competent authority. An interface that obstructs AIS or PIS breaches the RTS, and the EBA has asked authorities to act against such obstacles.

### **How often can an aggregator refresh account data?**

Whenever the user actively requests it, and otherwise up to four times in 24 hours unless a higher frequency is agreed with the bank with the user's consent. Since 25 July 2023 the bank must not require strong customer authentication for balance and 90-day transaction access through an AISP except at first access and every 180 days, or where it has evidenced fraud-related reasons.

### Sanctions and reform

### **Can an EU PISP serve Russian nationals or residents?**

Since 24 October 2025 Art. 5b(2)(b) of Regulation 833/2014 prohibits payment initiation services for Russian nationals, residents of Russia and entities established in Russia, with an exemption for EU, EEA and Swiss nationals and residence-permit holders. Account information services are not covered by that prohibition.

### **Does FIDA apply now?**

No. FIDA is a Commission proposal of 28 June 2023 that is still in trilogue negotiations, with no provisional agreement. Even as proposed, it would not cover payment accounts, which remain under PSD2.

### **Will the PSR change the rules for my interface access?**

The agreed text would require dedicated interfaces, subject to exemptions granted by the competent authority, a permission dashboard and a statutory list of prohibited obstacles. It would put background AIS access into the regulation itself and move the 180-day renewal of strong customer authentication from the bank to the AISP. It is provisionally agreed but not adopted or in force, so PSD2 and the RTS continue to govern access.

---

## Factual claims

- What the law gives them is a right of access: the customer may use them on any payment account that is accessible online, and the bank holding that account cannot make the access depend on a contract with the provider.
- PSD2 defines payment initiation as a service to initiate a payment order at the request of the payment service user with respect to a payment account held at another payment service provider (Art. 4(15)).
- A payer has the right to use a PISP, and a user the right to use an AISP, unless the payment account is not accessible online (Arts 66(1) and 67(1)).
- The bank's side of the bargain is set out in Arts 66(4) and 67(3).
- The mechanics sit in Delegated Regulation (EU) 2018/389, the regulatory technical standards on strong customer authentication and secure communication (the RTS).
- The regime as it stands in September 2026:
- A provider offering only account information is exempt from the PSD2 authorisation procedure and conditions and is registered instead (Art. 33(1)).
- Registered AISPs are treated as payment institutions, but Titles III and IV of PSD2 do not apply to them, except Arts 41, 45 and 52 where applicable and Arts 67, 69 and 95–98 (Art. 33(2)).

---

Source: wiki.private.law — the private.law legal knowledge base. When quoting, cite the canonical page URL.
Consultation with a lawyer: https://t.me/private_law_bot
