Skip to main content

Article

Open finance regulations explained: Navigating open finance regulations across global markets

Published: July 08, 2026

Coworkers brainstorming on a tablet

Open finance is reshaping the way people and businesses connect with their financial data to get more personalized financial services — and that transformation is unfolding within a fast-evolving regulatory landscape. From the European Union’s Payment Services Directive 2 to Brazil’s comprehensive open finance framework, regulations differ by jurisdiction, but the goal is the same: empower consumers to access more personalized financial services by giving them control of their own financial data in a safe and secure way. Whether you’re a compliance officer managing multi-market exposure or a fintech founder planning your next move, understanding these regulations isn’t just a box to check — it’s a competitive advantage.

 

What is open finance — and how is it different from open banking?

So, what exactly is open finance, and how is it different from open banking? Open banking focuses on payment account data — think transaction history and balances — and requires banks to share that information with authorized third parties. Open banking enables use cases like budgeting apps, account verification and account-to-account payments.

Open finance extends data-sharing principles across a much broader landscape: investments, insurance, pensions, mortgages, lending, wealth management and more. The goal is to give people (and businesses) a complete picture of their financial lives, not just their banking activity. Open finance offers users smarter advice, better products and more personalized experiences across their financial activity.

The distinction matters. If you're building products across multiple financial verticals, it shapes everything from your licensing strategy to your technical architecture. Understanding where each market sits on that spectrum is essential to getting it right. 

Let’s dive in.

PSD2

The European Union's PSD2 directive changed the game for open banking. It requires banks to provide licensed third-party providers access to customer payment account data through secure application programming interfaces (APIs) — fundamentally opening the door to more innovative and personalized financial services across the European Economic Area.

PSD2 introduced two categories of regulated providers:

Account Information Service Providers (AISPs): Enable consumers to securely share their bank account data with third parties — allowing aggregation, insights and financial management tools across multiple accounts in one place.

Payment Initiation Service Providers (PISPs): Allow third parties to send payment instructions to financial institutions to initiate payments directly from a customer’s bank account on their behalf, with their explicit consent — bypassing the need for traditional card rails or manual bank transfers.

The core mechanism behind this is XS2A — Access to Account. Under XS2A, banks must provide dedicated APIs that let regulated third-party providers retrieve account information and initiate payments on behalf of consumers who’ve given explicit consent. It was a fundamental shift: before PSD2, banks controlled all access to customer financial data. Now the customer is in charge of who can “plug in” to their financial data and payments.

Strong Customer Authentication (SCA)

Security is built into the foundation of open finance. SCA requires electronic payments to use at least two of three authentication factors:

  • Something the customer knows (password or PIN)
  • Something the customer possesses (mobile device or card)
  • Something the customer is (biometric verification)

Banks and payment service providers must implement SCA for online transactions and access to bank accounts, with specific exemptions for low-value payments, trusted beneficiaries and ongoing access to bank accounts. The Regulatory Technical Standards (RTS) on SCA and secure communication also mandate that bank APIs match the availability and performance of their customer-facing interfaces — and that all communication is encrypted. SCA is critical to the security of open finance because it:

  • Reduces fraud in digital payments
  • Protects consumers from unauthorized transactions
  • Builds trust in open banking and API-based ecosystems

Want to see how compliance looks in practice? Explore Mastercard's PSD2 compliance approach as a benchmark for implementation standards.

 

What’s next for open banking: PSD3 and PSR

Europe’s open banking rulebook is set for a major upgrade. The Payment Services Regulation (PSR) and Third Payment Services Directive (PSD3), which were proposed in 2023 and have reached provisional agreement, are intended to replace the current PSD2 framework.

Why the change? After several years under PSD2, the landscape is very different. Fraud tactics have evolved, open banking adoption has been uneven, and inconsistently applied rules from one country to the next have made cross-border innovation harder than it needs to be. PSR and PSD3 are designed to strengthen and streamline the EU’s open banking and payments framework. The priorities are clear:

  • Stronger fraud protections, including expanded liability for impersonation scams
  • Better open banking, with enforceable API standards that make data sharing more reliable
  • Greater transparency around fees for both consumers and merchants

Want to learn more about PSD3, PSR and what’s next for open banking regulation in Europe? Watch our webinar on demand.

FiDA

At the heart of the EU’s open finance debate is the proposed Financial Data Access regulation (FiDA), a legislative proposal introduced in 2023. If adopted, FiDA would create a framework for secure, permission-based access to financial data that reaches far beyond the payment accounts covered by traditional open banking. At this stage, however, there is still uncertainty around whether, when and in what form the proposal will be adopted. 

The principle behind the proposal is straightforward: customers — whether individuals or businesses — control their own financial data. FiDA would give them the right to decide who can access it, for what purpose and for how long, while requiring financial institutions to share that data with authorized third parties in a standardized, secure way. 

If adopted, FiDA could significantly broaden the scope of data sharing in Europe by encompassing data from loans, savings, investments, insurance, pensions and even crypto-assets — generating a far more complete financial picture that could support smarter, more personalized services. 

If enacted, FiDA could help create a more open, competitive ecosystem where fintechs, banks and new entrants alike can innovate. For now, though, it is best understood as the EU’s legislative proposal for open finance rather than an established or upcoming framework.

 

What regulations govern open finance globally?

No two markets are alike. Each jurisdiction takes its own approach to data-sharing mandates, licensing requirements and technical standards. Here's how the major regulatory frameworks compare:

 

RegionFrameworkScopeData Sharing ModelKey Requirements
European UnionPSD2/PSD3Payment accountsMandatorySCA, API access, third-party provider licensing
United KingdomOpen Banking StandardPayment accountsMandatoryCMA9 API standards, Financial Conduct Authority authorization
AustraliaConsumer Data Right (CDR)Banking, energy, telecomMandatoryAccreditation, consent rules, data standards
BrazilOpen Banking/Open FinanceAll financial productsMandatoryCentral bank licensing, phased rollout
United StatesConsumer Financial Protection Bureau Section 1033Consumer financial dataEvolvingCurrently lacks a unified federal mandate

 

European Union: The EU's PSD2 sets the template. Banks must provide APIs to licensed AISPs and PISPs, implement Strong Customer Authentication and maintain service levels comparable to their own digital channels. As the framework matures, new business opportunities with open banking regulation in Europe continue to emerge.

United Kingdom: The UK, post-Brexit, maintains its Open Banking Limited (OBL) standards while evolving its own regulatory model. The Competition and Markets Authority originally mandated the nine largest UK banks to adopt open banking APIs, with the FCA responsible for third‑party provider authorization and ongoing supervision.

Australia: Australia’s Consumer Data Right takes a multi-sector approach. It is currently operational in banking and energy and is intended to extend to sectors such as telecommunications, with stringent security and privacy requirements for accredited data recipients.

Brazil: Brazil has built one of the most comprehensive open finance frameworks in the world. The central bank mandates participation from regulated institutions and has established detailed technical standards covering payment accounts, credit, insurance, investments and foreign exchange.

United States: The U.S. currently lacks a unified federal mandate. Implementation of the Section 1033 rule has been stayed by a U.S. federal court, and the CFPB is currently reconsidering the framework. Today, data sharing relies largely on bilateral agreements and screen scraping — creating complexity for organizations operating across state lines.

Latin America: For organizations expanding into emerging markets, open banking in Latin America offers additional considerations as regulatory frameworks develop alongside growing fintech ecosystems.

 

Licensing and API compliance: What you need to know

Before accessing customer financial data, third-party providers must obtain regulatory authorization in most jurisdictions. The licensing process varies by region and service type. 

In the EU, AISPs and PISPs register with their home country's national competent authority. Understanding AISPs and PISPs is essential for determining which license applies to your business model. AISPs face lighter capital requirements than PISPs, reflecting the lower risk profile of read-only access compared with payment initiation. 

API standards that matter

API compliance standards define the technical specifications both financial institutions and third-party providers must implement. Key standards include:

  • The Berlin Group's NextGenPSD2 framework — widely adopted across Europe
  • The UK's Open Banking Implementation Entity API standards
  • OAuth 2.0 and OpenID Connect for authorization and identity verification
  • FAPI (Financial-grade API) security profiles for enhanced protection
  • Qualified certificates (eIDAS) for TPP identification
  • API gateways with rate limiting and monitoring capabilities
  • Developer sandboxes for testing and certification

The Mastercard Open Finance glossary provides detailed definitions of technical terms and standards relevant to API compliance.

Under PSD2's XS2A requirements, banks must expose specific endpoints for account information and payment initiation. Each must implement appropriate authentication and consent verification before returning data.

 

Data sharing and consumer consent: Putting consumers in control

At the heart of every open finance regulation is a simple principle: people should control their own financial data. Regulations mandate that consumers provide explicit, informed consent before any data sharing occurs — and they retain the right to revoke that consent at any time. 

Under PSD2, consumers authenticate directly with their bank when granting access, using Strong Customer Authentication (SCA). The bank issues an access token to the third-party provider, typically valid for 90 days before re-authentication is required. 

Consent lifecycle management

Getting consent right is critical. Organizations must:

  • Capture explicit customer consent before accessing data
  • Maintain records of consent scope and duration
  • Provide mechanisms for consumers to view and revoke consent
  • Honor consent expiration without requiring customer action

 

What infrastructure is required for open banking compliance?

  • Dedicated, standardized APIs – Secure interfaces that allow third-party providers to access account data and initiate payments with customer consent
  • Strong Customer Authentication – Multifactor authentication — something you know, have or are — to secure data access and payments
  • Consent management infrastructure – Systems to capture, store, manage and revoke customer consent for data sharing
  • Identity, authorization and security protocols – Frameworks like OAuth 2.0, OpenID Connect and FAPI enable secure, token-based access control
  • Licensing and registration systems – Regulatory authorization processes for third parties, such as AISPs and PISPs, to access financial data
  • Data governance and privacy controls – Policies and systems ensuring compliant data usage, privacy protection and adherence to regulations
  • Aggregator and vendor infrastructure layer – Intermediary platforms that enable connectivity, data normalization and API orchestration across institutions

 

Building a compliance strategy that scales across borders

If you operate across multiple jurisdictions — or plan to — you need a compliance framework that's flexible enough to accommodate regional differences while keeping operations efficient. 

Start with a regulatory map

Identify which open finance regulations apply in each market. Understand licensing requirements. Document the technical standards governing API implementation. This exercise reveals where requirements overlap — and where you'll need jurisdiction-specific adaptations. 

Centralize consent management

A single consent management platform can implement jurisdiction-specific rules while delivering consistent user experiences and audit capabilities. This approach reduces the risk of violations that could trigger enforcement actions across multiple regulators. 

Make smart architecture decisions

Technical choices have a direct impact on cross-border compliance costs. Organizations that adopt widely recognized standards — such as NextGenPSD2 or FAPI security profiles — can meet requirements across multiple jurisdictions with minimal customization. Proprietary implementations may require significant rework when entering new markets. 

Stay ahead of regulatory change

The landscape is evolving. PSD3 and PSR are advancing in Europe’s open banking framework. FiDA remains a legislative proposal for open finance, and its adoption is uncertain. The future of the Section 1033 rule remains uncertain in the United States. Frameworks are maturing across Asia and Latin America. Compliance teams need dedicated resources to track these developments and assess their impact on existing operations and product roadmaps. 

Calibrate your risk approach

Enforcement approaches vary by market. Understanding these differences helps organizations prioritize compliance investments where they matter most. 

Partner strategically

You don't have to build everything from scratch. Partnering with established players in the open finance ecosystem can accelerate market entry and reduce compliance risk — giving you access to regulatory relationships and proven infrastructure without the heavy lift.

 

Partner with Mastercard for open finance compliance

Mastercard brings global regulatory expertise and proven infrastructure to organizations navigating open finance compliance across jurisdictions. With deep experience implementing PSD2-compliant solutions and strong relationships with regulators worldwide, we serve as a trusted partner for financial institutions and fintechs building compliant open finance products. 

The Mastercard Open Finance platform provides the technical infrastructure you need to meet regulatory requirements while delivering seamless customer experiences — including API connectivity to financial institutions, consent management capabilities and security controls aligned with regulatory standards across multiple markets. 

For compliance officers managing complex, multi-jurisdictional exposure, Mastercard simplifies the landscape. For fintech founders building products that span borders, we provide the infrastructure and partnerships to accelerate time to market — without compromising on compliance. 

Explore how Mastercard can support your open finance compliance strategy and help you unlock new opportunities in the evolving regulatory landscape.

 

Frequently asked questions

What is the difference between open banking and open finance?

Open banking focuses on the sharing of payment account data — such as transaction history and account balances — between banks and authorized third-party providers. Open finance expands this to a broader range of financial products, including investments, insurance, pensions, mortgages and lending. Regulatory frameworks differ accordingly: open banking regulations like PSD2 center on payment accounts, while open finance initiatives such as the EU’s proposed FiDA would extend data-sharing principles across a wider range of financial services if adopted. 

What are the key open finance regulations by country?

The European Union enforces PSD2 and is advancing PSD3 and PSR for open banking and payments. Separately, FiDA is the EU’s legislative proposal for open finance, but its adoption remains uncertain. The United Kingdom maintains its Open Banking Limited (OBL) standards, with the FCA responsible for third-party provider authorization and ongoing supervision. Australia implements the Consumer Data Right (CDR), which is operational in banking and energy and is intended to extend to sectors such as telecommunications. Brazil mandates comprehensive open finance participation through central bank regulations. 

What is PSD2 and how does it enable open banking?

The Revised Payment Services Directive (PSD2) is legislation effective in the European Economic Area (EEA). PSD2 aims at driving market efficiency and integration, increasing consumer protection, creating competition, and improving security.

The European Union's PSD2 directive changed the game for open banking. It requires banks to provide licensed third-party providers access to customer payment account data through secure application programming interfaces (APIs) — fundamentally opening the door to more innovative and personalized financial services across the European Economic Area.

PSD2 introduced two categories of regulated providers:

Account Information Service Providers (AISPs): Enable consumers to securely share their bank account data with third parties — allowing aggregation, insights and financial management tools across multiple accounts in one place.

Payment Initiation Service Providers (PISPs): Allow third parties to send payment instructions to financial institutions to initiate payments directly from a customer’s bank account on their behalf, with their explicit consent — bypassing the need for traditional card rails or manual bank transfers.

The core mechanism behind this is XS2A — Access to Account. Under XS2A, banks must provide dedicated APIs that let regulated third-party providers retrieve account information and initiate payments on behalf of consumers who’ve given explicit consent. It was a fundamental shift: before PSD2, banks controlled all access to customer financial data. Now the customer is in charge of who can “plug in” to their financial data and payments.

Does PSD2 apply outside the EU, including the U.S.?

PSD2 applies directly within the European Economic Area (EEA), including EU member states plus Iceland, Liechtenstein and Norway. It does not apply in the United States. However, organizations serving EU consumers or processing EU payment data must comply regardless of where they're headquartered. The UK maintains similar requirements through its own regulatory framework following Brexit. 

Is data sharing mandatory or voluntary under open finance regulations?

It depends on who you are. Banks must share customer data when a licensed third-party provider requests access and the consumer has consented. For consumers, data sharing is entirely voluntary — they choose whether to grant access. Third-party providers must obtain proper regulatory licensing before requesting data, making their participation subject to regulatory approval. 

How is consumer consent managed under open finance frameworks?

Consumer consent requires explicit authorization before any data sharing occurs. Consumers authenticate directly with their bank using Strong Customer Authentication. Consent must specify the data types being shared, the third-party provider receiving access and the duration of access. Consumers can view active consents and revoke them at any time. Under PSD2, consent typically requires re-authentication every 90 days. 

What are the main risks of open finance and how are they regulated?

Key risks include data breaches, unauthorized access, fraud and privacy violations. Regulations address these through mandatory licensing, Strong Customer Authentication, API security standards, consent requirements that give consumers control, and liability frameworks that establish clear accountability. Regulators maintain enforcement authority to penalize non-compliance and mandate remediation. 

Contact sales

Talk to an expert to learn how Mastercard can enhance your business through our products and services.

Mastercard