
Open Banking and Variable Recurring Payments
Payment initiation, open banking compliance and commercial VRP frameworks for fintechs and banks
A firm that initiates a payment from a customer’s bank account provides a payment initiation service, and may provide it only as one of the payment service providers listed in regulation 138 of the Payment Services Regulations 2017. In practice that means an authorised payment institution under regulation 6, an authorised electronic money institution, or a credit institution. A firm that only reads the data in that account provides an account information service, and must be registered by the FCA under regulation 18 unless it already holds one of those other permissions. Either firm falls outside the payment services regime where an activity exclusion in Schedule 1, Part 2 applies, or where another exemption in the Regulations does, such as the exemption in regulation 3 for credit unions, municipal banks and the National Savings Bank. What it must then do is set out in the Payment Services Regulations 2017, in the technical standards on strong customer authentication and common and secure open standards of communication, and, for a commercial variable recurring payment, in the rules of the scheme it joins. Bratby Law advises payment institutions, fintechs and scheme participants on where that perimeter falls and on what a firm must do once it is inside it.
When open banking regulation applies to a firm
A firm that builds account information services or payment initiation services into its product crosses the FCA perimeter and must hold the right permission before it goes live: for payment initiation, authorisation as a payment institution, or provision of the service as an authorised electronic money institution or credit institution; for account information services, registration under regulation 18; and neither where an exclusion in Schedule 1, Part 2 of the PSRs 2017 or another exemption in those Regulations applies. A bank or building society that opens customer accounts to third parties through an application programming interface carries its own obligations as the account provider. A third-party provider applying for authorisation must satisfy the FCA’s authorisation conditions and then meet the conduct-of-business obligations in the PSRs 2017. A firm launching a commercial variable recurring payment product, which lets a customer consent in advance to payments of varying amounts, must meet the requirements of the PSRs 2017 and of the technical standards on strong customer authentication and common and secure open standards of communication, which the FCA maintains under regulation 106A of the PSRs 2017 and which supplement rather than amend those Regulations. A firm that wants to use open banking data for credit decisions, cross-selling or aggregation cannot do so under an account information service permission, because regulation 70(3)(f) of the PSRs 2017 stops an account information service provider using, accessing or storing information for any purpose except the account information service the customer has explicitly requested. Any wider use needs its own analysis of the regulatory perimeter and of data protection, and a lawful route to the data that does not rest on that permission. Whether an artificial intelligence agent can give valid consent under regulation 67 of the PSRs 2017 is examined in Agentic AI and Payments: Can an AI Agent Consent to a Payment?
Why open banking matters now
The CMA9 banks must offer sweeping variable recurring payments free of charge under the Retail Banking Market Investigation Order 2017. A commercial variable recurring payment is provided under a scheme’s participation and pricing arrangements rather than free of charge, and a firm that offers one joins that scheme and takes on its rulebook. The first such scheme, run by the UK Payments Initiative, launched on 2 June 2026. Under its Phase 1 arrangements a payment initiation service provider pays an access fee to the account servicing payment service provider on each transaction, at a level set centrally by the scheme, and the FCA and the Payment Systems Regulator have published a prioritisation statement saying that they will not at this time prioritise a Chapter I Competition Act 1998 investigation into those pricing arrangements, subject to conditions and safeguards on how the fee is set and until the Data (Use and Access) Act 2025 framework is implemented or July 2027, whichever is earlier. HM Treasury has published a sequence for the Long-Term Regulatory Framework: a consultation in the second quarter of 2026 carrying proposals for its delivery, an FCA consultation paper on interface rules in the third quarter, and a statutory instrument under the Data (Use and Access) Act 2025 to be laid in Parliament in the fourth quarter which, with the wider payments reforms, would give the FCA the powers it needs to oversee open banking in the long term. Those dates are indicative and depend on the legislation and the consultations still to come. The FCA and the Payment Systems Regulator will assess how far commercial variable recurring payments have been adopted before deciding whether that framework delivers for consumers and for the market. A firm choosing a first use case will find Phase 1, which the FCA and the PSR treat as the lower-risk use cases, confined to regulated financial services, regulated utilities, and local and central government. A scheme sets its own eligibility criteria in its rulebook and may draw them differently, so the rulebook is the document to read rather than the policy scope.
Requirements a firm must meet before launch
Account information services and payment initiation services are payment services under Schedule 1, Part 1 of the PSRs 2017. A payment initiation service provider must hold authorisation as a payment institution under regulation 6, or provide the service as an authorised electronic money institution or credit institution. An account information service provider must hold registration under regulation 18, its business must include no payment service other than account information services, and it must hold professional indemnity insurance or a comparable guarantee. Both must meet the strong customer authentication and secure communication requirements. Consent works differently for each of them. An account information service provider must not provide the service without the customer’s explicit consent, under regulation 70(3)(a). A payment transaction is authorised only where the payer has consented in the form and by the procedure agreed with its payment service provider, under regulation 67(2), and where the payment is executed through a payment initiation service provider the payer’s explicit consent engages the access duties in regulation 69. The perimeter question therefore comes before the build, because the answer changes the product design. Sweeping and commercial variable recurring payments are distinct. A sweeping payment is mandated by the CMA Order 2017, free to the consumer and a regulated payment service; a commercial payment is voluntary, provided under the scheme’s participation and pricing arrangements, and governed by its rules. A firm offering a commercial variable recurring payment must also settle its dispute design before launch, because the scheme rulebook fixes refund rights, the burden of proof and merchant indemnities. The present framework is interim, and the statutory Long-Term Regulatory Framework would replace it once the legislation is made, so a firm building only for the interim regime pays for the transition twice.
Designing an open banking product to meet the requirements
A firm should complete the perimeter analysis before product design begins, and settle whether its product involves account information services, payment initiation services or both. It should design the customer journey so that strong customer authentication is applied where the technical standards require it, and so that consent is taken in the form the Regulations require for the service in question: explicit consent before an account information service is provided, and consent in the agreed form for each payment or series of payments. A firm joining a commercial variable recurring payment scheme should read the rulebook, the dispute mechanism and the commercial terms of participation before it signs. It should build for a statutory framework rather than for the interim regime, so that the transition is a configuration change rather than a rebuild. Obligations on authorisation, consumer protection and dispute resolution interact across the PSRs 2017, the UK GDPR, the smart data powers in Part 1 of the DUAA 2025 and the Long-Term Regulatory Framework as it is made, and a decision taken on one affects the others.
When to instruct an open banking specialist
The perimeter analysis belongs in the product design phase, before engineering time is committed, because it decides whether the firm needs FCA authorisation and which conduct-of-business obligations in the PSRs 2017 apply to it. A firm applying for registration as an account information service provider, or for authorisation as a payment institution to provide payment initiation services, has to settle its application strategy, its regulatory reporting arrangements and the conduct requirements in Parts 6 and 7 of the PSRs 2017 and the Consumer Duty before it applies. A firm joining a commercial variable recurring payment scheme has to agree its participation terms, its governance and its dispute design. A firm already live under the interim framework has to plan its transition to the statutory Long-Term Regulatory Framework. Each of those is a decision that is expensive to revisit after launch.
Bratby Law’s open banking work
Bratby Law advises on the regulatory perimeter for open banking products: whether a service is an account information service, a payment initiation service or another regulated activity, and whether an exemption applies. The firm advises on FCA registration for account information service providers and on FCA authorisation for payment institutions providing payment initiation services, covering application strategy, regulatory reporting and the conduct-of-business obligations in the PSRs 2017 that govern how a firm deals with its customers and handles disputes. For a firm joining a commercial variable recurring payment scheme, that work covers participation, governance and merchant dispute design, including refund rights, the burden of proof and settlement timescales. It also covers interface compliance, strong customer authentication design, consent mechanisms and data handling under the PSRs 2017 and the UK GDPR, and the smart data regulations to be made under Part 1 of the DUAA 2025, planning for the move to the statutory Long-Term Regulatory Framework, and the points at which open banking obligations meet the FCA Handbook rules on consumer credit and insurance distribution.
Advice on open banking and variable recurring payments
Frequently asked questions about open banking regulation
Do I need FCA authorisation to offer open banking services?
It depends on the service you are offering. The route differs by service. A payment initiation service provider must be authorised as a payment institution under regulation 6 of the PSRs 2017, or provide the service as an authorised e-money institution or credit institution. An account information service provider must be registered under regulation 18, a lighter route which carries a professional indemnity insurance condition and is open only where the business includes no other payment service. Schedule 1, Part 2 excludes a closed list of activities from the definition of a payment service, including payments through a commercial agent, limited network instruments, electronic communications billing within the £40 single transaction and £240 monthly limits, technical service provision where the provider never holds the funds, intra-group payments and certain ATM cash withdrawal services. Schedule 1, Part 2 is not the only route out: regulation 3 exempts credit unions, municipal banks and the National Savings Bank from the Regulations altogether. If you are providing data aggregation services, or using open banking data for credit decisions or cross-selling, that use cannot sit under an account information service permission because of regulation 70(3)(f), and it may in any event fall within other regulated activities requiring authorisation. Conduct a regulatory perimeter analysis to determine whether authorisation is required.
What is the difference between sweeping VRPs and commercial VRPs?
Sweeping VRPs are mandated by the CMA Retail Banking Market Investigation Order 2017, implemented through the Open Banking Roadmap, item A10 of which the CMA approved on 26 July 2021 as the mechanism for delivering sweeping by variable recurring payment; they are a free service that CMA9 banks must offer to customers who consent to variable recurring payments. Commercial VRPs are voluntary, and are provided under the participation and pricing arrangements of the scheme rather than free of charge. The payment itself remains a regulated payment service, because it is executed by payment initiation under Schedule 1, Part 1, paragraph 1(g) of the PSRs 2017, so the authorisation, strong customer authentication and conduct duties in those Regulations apply. What sits outside statutory regulation is the scheme’s commercial model and its dispute framework, which the rulebook governs. The key difference is that sweeping VRPs are a regulatory obligation offering consumer protection, whilst commercial VRPs are commercially negotiated services with scheme-specific protections.
How does the cVRP dispute resolution mechanism work?
Commercial VRP schemes establish a centralised contractual dispute process under the scheme rulebook. That process operates alongside the statutory rights and duties in the PSRs 2017, to which the underlying payment initiation remains subject, and it cannot exclude them. The scheme rules define refund rights, the burden of proof, settlement timescales and the indemnity arrangements between consumers, merchants and payment service providers, and those terms differ from scheme to scheme. Chargeback is a card scheme mechanism rather than a statutory process under the PSRs 2017, so the two are not alternatives to one another. Whether a scheme’s process resolves a dispute more quickly than the route a customer would otherwise take depends on what the rulebook provides. Scheme participants must implement dispute resolution procedures that comply with the rulebook, and must still meet their statutory duties on unauthorised and incorrectly executed transactions.
What is a commercial VRP scheme?
A commercial VRP scheme is a scheme body that develops the rulebook, operates a centralised dispute resolution process and sets access terms for firms participating in commercial VRP payments outside the sweeping mandate in the CMA Retail Banking Market Investigation Order 2017. The first such scheme, run by the UK Payments Initiative, launched on 2 June 2026, and the FCA and the Payment Systems Regulator have published a prioritisation statement on its Phase 1 pricing arrangements. The Long-Term Regulatory Framework would bring commercial VRP schemes within statutory regulation. The dates for it are indicative and turn on the statutory instrument under the Data (Use and Access) Act 2025 and on the FCA consultations that follow.
When will the long-term regulatory framework for open banking be in place?
HM Treasury’s Payments Forward Plan sets out that it would consult in the second quarter of 2026 with proposals for delivering a Long-Term Regulatory Framework for open banking, and that a statutory instrument under the Data (Use and Access) Act 2025 would be laid in Parliament in the fourth quarter of 2026 to give the FCA the powers it needs, paving the way for revocation of the CMA Order. The FCA has said that, subject to that legislation, it will consult on the long-term regulatory framework by the end of 2026, with a policy statement in the first quarter of 2027. Firms should plan for transition well ahead of implementation.
What are the strong customer authentication requirements for open banking?
Strong customer authentication requires two or more independent elements drawn from two or more of three categories: something known only by the payment service user, something held only by that user, and something inherent to that user. Regulation 100 of the PSRs 2017 requires a payment service provider to apply strong customer authentication where the user accesses a payment account online, whether directly or through an account information service provider, initiates an electronic payment transaction, or carries out any remote action implying a risk of fraud or abuse; a remote transaction must also be dynamically linked to a specific amount and payee. The technical standards set the exemptions, including trusted beneficiaries, low value transactions and transaction risk analysis, and regulation 100(5) makes the duties subject to them. Exemptions are narrow, and firms must ensure that SCA is properly embedded in the customer journey.
Can I use open banking data for purposes other than the service the customer consented to?
No. Regulation 70(3)(f) of the PSRs 2017 requires an account information service provider not to use, access or store any information for any purpose except the provision of the account information service the payment service user has explicitly requested, and regulation 70(3)(a) requires that explicit consent before the service is provided at all. Using the data for marketing, credit decisions or any other purpose therefore breaches that regulation, and the UK GDPR applies in parallel to the personal data involved. Part 1 of the Data (Use and Access) Act 2025 confers powers on the Secretary of State and the Treasury to make smart data regulations; it imposes no direct consent duty on a provider until those regulations are made.
How does open banking regulation differ from PSD2?
Open banking is the broader market infrastructure of interfaces allowing access to account data, and the CMA Retail Banking Market Investigation Order 2017 is the instrument that mandates sweeping VRPs, while PSD2, as transposed into UK law by the Payment Services Regulations 2017, is the origin of the strong customer authentication and conduct rules. PSD2 binds EU and EEA states as to the result to be achieved and applies through each state’s own transposing law rather than of its own force. UK open banking regulation is set out in the PSRs 2017 as amended, read with the technical standards the FCA maintains under regulation 106A. The Long-Term Regulatory Framework is proposed to introduce rules tailored to the UK market rather than to mirror the EU rules.
Related payments regulation pages
Payments regulation covers more than open banking, and each of these pages deals with one part of it.
Payments Regulation
Payment Institution Authorisation and Licensing
PSR and Scheme Governance
Operational Resilience and DORA
Safeguarding and Consumer Duty
EMI Authorisation and E-Money Regulation
FCA Investigations and Enforcement
Digital Money and Central Bank Digital Currencies
The PSRs 2017 Explained: Payment Authorisation, Liability and Execution Times
The PSRs 2017 Explained: Information Requirements and Framework Contracts. A firm building an open banking or variable recurring payments proposition that is unsure whether its activity falls within the regulated perimeter at all should read The PSRs 2017 Explained: the Payment Services Perimeter and the Exclusions first.
Related insight
The hidden architecture of UK open banking sets out why the directory, the dispute management system and the governed interface standards are the enduring asset for firms building on open banking rails.
Credentials
Rob Bratby is Managing Partner of Bratby Law and Fractional General Counsel to UK Payments Initiative Limited, the industry body developing the UK’s commercial account-to-account payments scheme. He also holds Fractional General Counsel appointments at The One Touch Switching Company, TelXL and Core. He is ranked Band 2 for Telecommunications in Chambers UK 2026, listed by The Legal 500 as a Leading Partner for IT and telecoms in London, and recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media and a Thought Leader for data privacy and protection.
