Open Banking and VRPs Cover - Bratby Law Payments Regulation

Open Banking and Variable Recurring Payments

A firm that initiates a payment from a customer’s bank account provides a payment initiation service and must be authorised by the FCA as a payment institution under regulation 6 of the Payment Services Regulations 2017. A firm that only reads the data in that account provides an account information service and must be registered by the FCA under regulation 18. Either firm falls outside the Regulations only where one of the activity exclusions in Schedule 1, Part 2 applies. What it must then do is set out in the Payment Services Regulations 2017, in the technical standards on strong customer authentication and common and secure open standards of communication, and, for a commercial variable recurring payment, in the rules of the scheme it joins. Bratby Law advises payment institutions, fintechs and scheme participants on where that perimeter falls and on what a firm must do once it is inside it.

When open banking regulation applies to a firm

A firm that builds account information services or payment initiation services into its product crosses the FCA perimeter and must hold the right permission before it goes live: authorisation as a payment institution for payment initiation, registration for account information services, and neither only where an exclusion in Schedule 1, Part 2 of the PSRs 2017 applies. A bank or building society that opens customer accounts to third parties through an application programming interface carries its own obligations as the account provider. A third-party provider applying for authorisation must satisfy the FCA’s authorisation conditions and then meet the conduct-of-business obligations in the PSRs 2017. A firm launching a commercial variable recurring payment product, which lets a customer consent in advance to payments of varying amounts, must meet the requirements of the PSRs 2017 and of the technical standards on strong customer authentication and common and secure open standards of communication, which the FCA maintains under regulation 106A of the PSRs 2017 and which supplement rather than amend those Regulations. A firm that uses open banking data for credit decisions, cross-selling or aggregation must establish whether that use is itself a regulated activity, because the answer decides whether it needs authorisation and which consumer protection rules apply to it. Whether an artificial intelligence agent can give valid consent under regulation 67 of the PSRs 2017 is examined in Agentic AI and Payments: Can an AI Agent Consent to a Payment?

Why open banking matters now

The CMA9 banks must offer sweeping variable recurring payments free of charge under the Retail Banking Market Investigation Order 2017. A commercial variable recurring payment is charged, and a firm that offers one joins a scheme and takes on its rulebook. The FCA recorded the launch of the first such scheme, run by the UK Payments Initiative, on 2 June 2026. HM Treasury has published a sequence for the Long-Term Regulatory Framework: a consultation in the second quarter of 2026 carrying proposals for its delivery, an FCA consultation paper on interface rules in the third quarter, and a statutory instrument under the Data (Use and Access) Act 2025 to be laid in Parliament in the fourth quarter which, with the wider payments reforms, would give the FCA the powers it needs to oversee open banking in the long term. The FCA and the Payment Systems Regulator will assess how far commercial variable recurring payments have been adopted before deciding whether that framework delivers for consumers and for the market. A firm choosing a first use case will find phase 1 concentrated on the three categories the PSR has published: utility payments, financial services payments, and payments to local and central government.

Requirements a firm must meet before launch

Account information services and payment initiation services are payment services under Schedule 1, Part 1 of the PSRs 2017. A payment initiation service provider must hold authorisation as a payment institution under regulation 6. An account information service provider must hold registration under regulation 18, and its business must include no payment service other than account information services. It must meet the strong customer authentication and communication requirements, and obtain the customer’s explicit consent at the point of payment. The perimeter question therefore comes before the build, because the answer changes the product design. Sweeping and commercial variable recurring payments are distinct. A sweeping payment is mandated by the CMA Order 2017, free to the consumer and a regulated payment service; a commercial payment is voluntary, charged, and governed by the rules of the scheme. A firm offering a commercial variable recurring payment must also settle its dispute design before launch, because the scheme rulebook fixes refund rights, the burden of proof and merchant indemnities. The present framework is interim and the statutory Long-Term Regulatory Framework is proposed to replace it, so a firm building only for the interim regime pays for the transition twice.

Designing an open banking product to meet the requirements

A firm should complete the perimeter analysis before product design begins, and settle whether its product involves account information services, payment initiation services or both. It should design the customer journey so that strong customer authentication is applied where the Regulatory Technical Standards require it and the customer gives explicit consent at the point of payment. A firm joining a commercial variable recurring payment scheme should read the rulebook, the dispute mechanism and the commercial terms of participation before it signs. It should build for a statutory framework rather than for the interim regime, so that the transition is a configuration change rather than a rebuild. Obligations on authorisation, consumer protection and dispute resolution interact across the PSRs 2017, the UK GDPR, the smart data powers in Part 1 of the DUAA 2025 and the Long-Term Regulatory Framework as it is made, and a decision taken on one affects the others.

When to instruct an open banking specialist

The perimeter analysis belongs in the product design phase, before engineering time is committed, because it decides whether the firm needs FCA authorisation and which conduct-of-business obligations in the PSRs 2017 apply to it. A firm applying for registration as an account information service provider, or for authorisation as a payment institution to provide payment initiation services, has to settle its application strategy, its regulatory reporting arrangements and the conduct requirements in Parts 6 and 7 of the PSRs 2017 and the Consumer Duty before it applies. A firm joining a commercial variable recurring payment scheme has to agree its participation terms, its governance and its dispute design. A firm already live under the interim framework has to plan its transition to the statutory Long-Term Regulatory Framework. Each of those is a decision that is expensive to revisit after launch.

Bratby Law’s open banking work

Bratby Law advises on the regulatory perimeter for open banking products: whether a service is an account information service, a payment initiation service or another regulated activity, and whether an exemption applies. The firm advises on FCA registration for account information service providers and on FCA authorisation for payment institutions providing payment initiation services, covering application strategy, regulatory reporting and the conduct-of-business obligations in the PSRs 2017 that govern how a firm deals with its customers and handles disputes. For a firm joining a commercial variable recurring payment scheme, that work covers participation, governance and merchant dispute design, including refund rights, the burden of proof and settlement timescales. It also covers interface compliance, strong customer authentication design, consent mechanisms and data handling under the PSRs 2017 and the UK GDPR, and the smart data regulations to be made under Part 1 of the DUAA 2025, planning for the move to the statutory Long-Term Regulatory Framework, and the points at which open banking obligations meet the FCA Handbook rules on consumer credit and insurance distribution.

Advice on open banking and variable recurring payments

Frequently asked questions about open banking regulation

Do I need FCA authorisation to offer open banking services?

It depends on the service you are offering. The route differs by service. A payment initiation service provider must be authorised as a payment institution under regulation 6 of the PSRs 2017, or provide the service as an authorised e-money institution or credit institution. An account information service provider must be registered under regulation 18, a lighter route which carries a professional indemnity insurance condition and is open only where the business includes no other payment service. Schedule 1, Part 2 excludes a closed list of activities from the definition of a payment service, including payments through a commercial agent, limited network instruments, electronic communications billing within the £40 single transaction and £240 monthly limits, technical service provision where the provider never holds the funds, intra-group payments and certain ATM cash withdrawal services. If you are providing data aggregation services or using open banking data for credit decisions or cross-selling, you may fall within other regulated activities that require authorisation. Conduct a regulatory perimeter analysis to determine whether authorisation is required.

What is the difference between sweeping VRPs and commercial VRPs?

Sweeping VRPs are mandated by the CMA Retail Banking Market Investigation Order 2017, implemented through the Open Banking Roadmap, item A10 of which the CMA approved on 26 July 2021 as the mechanism for delivering sweeping by variable recurring payment; they are a free service that CMA9 banks must offer to customers who consent to variable recurring payments. Commercial VRPs are voluntary and charged. The payment itself remains a regulated payment service, because it is executed by payment initiation under Schedule 1, Part 1, paragraph 1(g) of the PSRs 2017, so the authorisation, strong customer authentication and conduct duties in those Regulations apply. What sits outside statutory regulation is the scheme’s commercial model and its dispute framework, which the rulebook governs. The key difference is that sweeping VRPs are a regulatory obligation offering consumer protection, whilst commercial VRPs are commercially negotiated services with scheme-specific protections.

How does the cVRP dispute resolution mechanism work?

Commercial VRP schemes typically establish a centralised dispute resolution process that sits outside the statutory framework. Consumers can dispute commercial VRP transactions through the scheme’s dispute process, which is generally faster and simpler than statutory chargeback processes. The scheme rules define refund rights, burden of proof, settlement timescales and indemnity arrangements between consumers, merchants and payment service providers. Scheme participants must implement dispute resolution procedures that comply with the scheme rulebook.

What is a commercial VRP scheme?

A commercial VRP scheme is a scheme body that develops the rulebook, operates a centralised dispute resolution process and sets access terms for firms participating in commercial VRP payments outside the PSD2 mandate. The FCA recorded the launch of the first such scheme, run by the UK Payments Initiative, on 2 June 2026. The Long-Term Regulatory Framework, expected during 2026 or 2027, is intended to bring commercial VRP schemes within statutory regulation.

When will the long-term regulatory framework for open banking be in place?

HM Treasury’s Payments Forward Plan sets out that it would consult in the second quarter of 2026 with proposals for delivering a Long-Term Regulatory Framework for open banking, and that a statutory instrument under the Data (Use and Access) Act 2025 would be laid in Parliament in the fourth quarter of 2026 to give the FCA the powers it needs, paving the way for revocation of the CMA Order. The FCA has said that, subject to that legislation, it will consult on the long-term regulatory framework by the end of 2026, with a policy statement in the first quarter of 2027. Firms should plan for transition well ahead of implementation.

What are the strong customer authentication requirements for open banking?

Strong customer authentication requires two or more independent elements drawn from two or more of three categories: something known only by the payment service user, something held only by that user, and something inherent to that user. Regulation 100 of the PSRs 2017 requires a payment service provider to apply strong customer authentication where the user accesses a payment account online, whether directly or through an account information service provider, initiates an electronic payment transaction, or carries out any remote action implying a risk of fraud or abuse; a remote transaction must also be dynamically linked to a specific amount and payee. The technical standards set the exemptions, including trusted beneficiaries, low value transactions and transaction risk analysis, and regulation 100(5) makes the duties subject to them. Exemptions are narrow, and firms must ensure that SCA is properly embedded in the customer journey.

Can I use open banking data for purposes other than the service the customer consented to?

No. Regulation 70(3)(f) of the PSRs 2017 requires an account information service provider not to use, access or store any information for any purpose except the provision of the account information service the payment service user has explicitly requested, and regulation 70(3)(a) requires that explicit consent before the service is provided at all. Using the data for marketing, credit decisions or any other purpose therefore breaches that regulation, and the UK GDPR applies in parallel to the personal data involved. Part 1 of the Data (Use and Access) Act 2025 confers powers on the Secretary of State and the Treasury to make smart data regulations; it imposes no direct consent duty on a provider until those regulations are made.

How does open banking regulation differ from PSD2?

Open banking is the broader market infrastructure of interfaces allowing access to account data, and the CMA Retail Banking Market Investigation Order 2017 is the instrument that mandates sweeping VRPs, while PSD2, as transposed into UK law by the Payment Services Regulations 2017, is the origin of the strong customer authentication and conduct rules. PSD2 binds EU and EEA states as to the result to be achieved and applies through each state’s own transposing law rather than of its own force. UK open banking regulation is set out in the PSRs 2017 as amended, read with the technical standards the FCA maintains under regulation 106A. The Long-Term Regulatory Framework is proposed to introduce rules tailored to the UK market rather than to mirror the EU rules.

Related payments regulation pages

Payments regulation covers more than open banking, and each of these pages deals with one part of it.

Related insight

The hidden architecture of UK open banking sets out why the directory, the dispute management system and the governed interface standards are the enduring asset for firms building on open banking rails.

Credentials

Rob Bratby is Managing Partner of Bratby Law and Fractional General Counsel to UK Payments Initiative Limited, the industry body developing the UK’s commercial account-to-account payments scheme. He also holds Fractional General Counsel appointments at The One Touch Switching Company, TelXL and Core. He is ranked Band 2 for Telecommunications in Chambers UK 2026, listed by The Legal 500 as a Leading Partner for IT and telecoms in London, and recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media and a Thought Leader for data privacy and protection.

Discuss your matter