Published: July 08, 2026
Open finance is reshaping the way people and businesses connect with their financial data to get more personalized financial services — and that transformation is unfolding within a fast-evolving regulatory landscape. From the European Union’s Payment Services Directive 2 to Brazil’s comprehensive open finance framework, regulations differ by jurisdiction, but the goal is the same: empower consumers to access more personalized financial services by giving them control of their own financial data in a safe and secure way. Whether you’re a compliance officer managing multi-market exposure or a fintech founder planning your next move, understanding these regulations isn’t just a box to check — it’s a competitive advantage.
So, what exactly is open finance, and how is it different from open banking? Open banking focuses on payment account data — think transaction history and balances — and requires banks to share that information with authorized third parties. Open banking enables use cases like budgeting apps, account verification and account-to-account payments.
Open finance extends data-sharing principles across a much broader landscape: investments, insurance, pensions, mortgages, lending, wealth management and more. The goal is to give people (and businesses) a complete picture of their financial lives, not just their banking activity. Open finance offers users smarter advice, better products and more personalized experiences across their financial activity.
The distinction matters. If you're building products across multiple financial verticals, it shapes everything from your licensing strategy to your technical architecture. Understanding where each market sits on that spectrum is essential to getting it right.
Let’s dive in.
The European Union's PSD2 directive changed the game for open banking. It requires banks to provide licensed third-party providers access to customer payment account data through secure application programming interfaces (APIs) — fundamentally opening the door to more innovative and personalized financial services across the European Economic Area.
PSD2 introduced two categories of regulated providers:
Account Information Service Providers (AISPs): Enable consumers to securely share their bank account data with third parties — allowing aggregation, insights and financial management tools across multiple accounts in one place.
Payment Initiation Service Providers (PISPs): Allow third parties to send payment instructions to financial institutions to initiate payments directly from a customer’s bank account on their behalf, with their explicit consent — bypassing the need for traditional card rails or manual bank transfers.
The core mechanism behind this is XS2A — Access to Account. Under XS2A, banks must provide dedicated APIs that let regulated third-party providers retrieve account information and initiate payments on behalf of consumers who’ve given explicit consent. It was a fundamental shift: before PSD2, banks controlled all access to customer financial data. Now the customer is in charge of who can “plug in” to their financial data and payments.
Security is built into the foundation of open finance. SCA requires electronic payments to use at least two of three authentication factors:
Banks and payment service providers must implement SCA for online transactions and access to bank accounts, with specific exemptions for low-value payments, trusted beneficiaries and ongoing access to bank accounts. The Regulatory Technical Standards (RTS) on SCA and secure communication also mandate that bank APIs match the availability and performance of their customer-facing interfaces — and that all communication is encrypted. SCA is critical to the security of open finance because it:
Want to see how compliance looks in practice? Explore Mastercard's PSD2 compliance approach as a benchmark for implementation standards.
Europe’s open banking rulebook is set for a major upgrade. The Payment Services Regulation (PSR) and Third Payment Services Directive (PSD3), which were proposed in 2023 and have reached provisional agreement, are intended to replace the current PSD2 framework.
Why the change? After several years under PSD2, the landscape is very different. Fraud tactics have evolved, open banking adoption has been uneven, and inconsistently applied rules from one country to the next have made cross-border innovation harder than it needs to be. PSR and PSD3 are designed to strengthen and streamline the EU’s open banking and payments framework. The priorities are clear:
At the heart of the EU’s open finance debate is the proposed Financial Data Access regulation (FiDA), a legislative proposal introduced in 2023. If adopted, FiDA would create a framework for secure, permission-based access to financial data that reaches far beyond the payment accounts covered by traditional open banking. At this stage, however, there is still uncertainty around whether, when and in what form the proposal will be adopted.
The principle behind the proposal is straightforward: customers — whether individuals or businesses — control their own financial data. FiDA would give them the right to decide who can access it, for what purpose and for how long, while requiring financial institutions to share that data with authorized third parties in a standardized, secure way.
If adopted, FiDA could significantly broaden the scope of data sharing in Europe by encompassing data from loans, savings, investments, insurance, pensions and even crypto-assets — generating a far more complete financial picture that could support smarter, more personalized services.
If enacted, FiDA could help create a more open, competitive ecosystem where fintechs, banks and new entrants alike can innovate. For now, though, it is best understood as the EU’s legislative proposal for open finance rather than an established or upcoming framework.
No two markets are alike. Each jurisdiction takes its own approach to data-sharing mandates, licensing requirements and technical standards. Here's how the major regulatory frameworks compare:
| Region | Framework | Scope | Data Sharing Model | Key Requirements |
| European Union | PSD2/PSD3 | Payment accounts | Mandatory | SCA, API access, third-party provider licensing |
| United Kingdom | Open Banking Standard | Payment accounts | Mandatory | CMA9 API standards, Financial Conduct Authority authorization |
| Australia | Consumer Data Right (CDR) | Banking, energy, telecom | Mandatory | Accreditation, consent rules, data standards |
| Brazil | Open Banking/Open Finance | All financial products | Mandatory | Central bank licensing, phased rollout |
| United States | Consumer Financial Protection Bureau Section 1033 | Consumer financial data | Evolving | Currently lacks a unified federal mandate |
European Union: The EU's PSD2 sets the template. Banks must provide APIs to licensed AISPs and PISPs, implement Strong Customer Authentication and maintain service levels comparable to their own digital channels. As the framework matures, new business opportunities with open banking regulation in Europe continue to emerge.
United Kingdom: The UK, post-Brexit, maintains its Open Banking Limited (OBL) standards while evolving its own regulatory model. The Competition and Markets Authority originally mandated the nine largest UK banks to adopt open banking APIs, with the FCA responsible for third‑party provider authorization and ongoing supervision.
Australia: Australia’s Consumer Data Right takes a multi-sector approach. It is currently operational in banking and energy and is intended to extend to sectors such as telecommunications, with stringent security and privacy requirements for accredited data recipients.
Brazil: Brazil has built one of the most comprehensive open finance frameworks in the world. The central bank mandates participation from regulated institutions and has established detailed technical standards covering payment accounts, credit, insurance, investments and foreign exchange.
United States: The U.S. currently lacks a unified federal mandate. Implementation of the Section 1033 rule has been stayed by a U.S. federal court, and the CFPB is currently reconsidering the framework. Today, data sharing relies largely on bilateral agreements and screen scraping — creating complexity for organizations operating across state lines.
Latin America: For organizations expanding into emerging markets, open banking in Latin America offers additional considerations as regulatory frameworks develop alongside growing fintech ecosystems.
Before accessing customer financial data, third-party providers must obtain regulatory authorization in most jurisdictions. The licensing process varies by region and service type.
In the EU, AISPs and PISPs register with their home country's national competent authority. Understanding AISPs and PISPs is essential for determining which license applies to your business model. AISPs face lighter capital requirements than PISPs, reflecting the lower risk profile of read-only access compared with payment initiation.
API compliance standards define the technical specifications both financial institutions and third-party providers must implement. Key standards include:
The Mastercard Open Finance glossary provides detailed definitions of technical terms and standards relevant to API compliance.
Under PSD2's XS2A requirements, banks must expose specific endpoints for account information and payment initiation. Each must implement appropriate authentication and consent verification before returning data.
At the heart of every open finance regulation is a simple principle: people should control their own financial data. Regulations mandate that consumers provide explicit, informed consent before any data sharing occurs — and they retain the right to revoke that consent at any time.
Under PSD2, consumers authenticate directly with their bank when granting access, using Strong Customer Authentication (SCA). The bank issues an access token to the third-party provider, typically valid for 90 days before re-authentication is required.
Getting consent right is critical. Organizations must:
If you operate across multiple jurisdictions — or plan to — you need a compliance framework that's flexible enough to accommodate regional differences while keeping operations efficient.
Identify which open finance regulations apply in each market. Understand licensing requirements. Document the technical standards governing API implementation. This exercise reveals where requirements overlap — and where you'll need jurisdiction-specific adaptations.
A single consent management platform can implement jurisdiction-specific rules while delivering consistent user experiences and audit capabilities. This approach reduces the risk of violations that could trigger enforcement actions across multiple regulators.
Technical choices have a direct impact on cross-border compliance costs. Organizations that adopt widely recognized standards — such as NextGenPSD2 or FAPI security profiles — can meet requirements across multiple jurisdictions with minimal customization. Proprietary implementations may require significant rework when entering new markets.
The landscape is evolving. PSD3 and PSR are advancing in Europe’s open banking framework. FiDA remains a legislative proposal for open finance, and its adoption is uncertain. The future of the Section 1033 rule remains uncertain in the United States. Frameworks are maturing across Asia and Latin America. Compliance teams need dedicated resources to track these developments and assess their impact on existing operations and product roadmaps.
Enforcement approaches vary by market. Understanding these differences helps organizations prioritize compliance investments where they matter most.
You don't have to build everything from scratch. Partnering with established players in the open finance ecosystem can accelerate market entry and reduce compliance risk — giving you access to regulatory relationships and proven infrastructure without the heavy lift.
Mastercard brings global regulatory expertise and proven infrastructure to organizations navigating open finance compliance across jurisdictions. With deep experience implementing PSD2-compliant solutions and strong relationships with regulators worldwide, we serve as a trusted partner for financial institutions and fintechs building compliant open finance products.
The Mastercard Open Finance platform provides the technical infrastructure you need to meet regulatory requirements while delivering seamless customer experiences — including API connectivity to financial institutions, consent management capabilities and security controls aligned with regulatory standards across multiple markets.
For compliance officers managing complex, multi-jurisdictional exposure, Mastercard simplifies the landscape. For fintech founders building products that span borders, we provide the infrastructure and partnerships to accelerate time to market — without compromising on compliance.
Explore how Mastercard can support your open finance compliance strategy and help you unlock new opportunities in the evolving regulatory landscape.
Open banking focuses on the sharing of payment account data — such as transaction history and account balances — between banks and authorized third-party providers. Open finance expands this to a broader range of financial products, including investments, insurance, pensions, mortgages and lending. Regulatory frameworks differ accordingly: open banking regulations like PSD2 center on payment accounts, while open finance initiatives such as the EU’s proposed FiDA would extend data-sharing principles across a wider range of financial services if adopted.
The European Union enforces PSD2 and is advancing PSD3 and PSR for open banking and payments. Separately, FiDA is the EU’s legislative proposal for open finance, but its adoption remains uncertain. The United Kingdom maintains its Open Banking Limited (OBL) standards, with the FCA responsible for third-party provider authorization and ongoing supervision. Australia implements the Consumer Data Right (CDR), which is operational in banking and energy and is intended to extend to sectors such as telecommunications. Brazil mandates comprehensive open finance participation through central bank regulations.
PSD2 applies directly within the European Economic Area (EEA), including EU member states plus Iceland, Liechtenstein and Norway. It does not apply in the United States. However, organizations serving EU consumers or processing EU payment data must comply regardless of where they're headquartered. The UK maintains similar requirements through its own regulatory framework following Brexit.
It depends on who you are. Banks must share customer data when a licensed third-party provider requests access and the consumer has consented. For consumers, data sharing is entirely voluntary — they choose whether to grant access. Third-party providers must obtain proper regulatory licensing before requesting data, making their participation subject to regulatory approval.
Consumer consent requires explicit authorization before any data sharing occurs. Consumers authenticate directly with their bank using Strong Customer Authentication. Consent must specify the data types being shared, the third-party provider receiving access and the duration of access. Consumers can view active consents and revoke them at any time. Under PSD2, consent typically requires re-authentication every 90 days.
Key risks include data breaches, unauthorized access, fraud and privacy violations. Regulations address these through mandatory licensing, Strong Customer Authentication, API security standards, consent requirements that give consumers control, and liability frameworks that establish clear accountability. Regulators maintain enforcement authority to penalize non-compliance and mandate remediation.