Open banking obliges account providers to share data and initiate payments at a customer's instruction, through defined technical interfaces. The change is structural rather than cosmetic.

Screen scraping was the previous method

Before formal interfaces existed, aggregators obtained data by asking customers for their online banking credentials and logging in on their behalf.

The approach worked but required customers to hand over full access, broke whenever a bank changed its website, and left responsibility for any loss unclear.

Banks generally regarded it as a breach of their terms, which created a persistent conflict between them and the services their customers were using.

Permissioned interfaces changed the relationship

Under open banking rules, a customer authorises a regulated third party to access specific data for a defined period, without sharing credentials.

Access is granted through the bank's own authentication process, and the customer can review and revoke permissions directly.

The third party must be authorised and supervised, which places accountability on a regulated entity rather than on an informal arrangement.

Payment initiation is the larger shift

The same framework allows an authorised provider to initiate a payment from the customer's account with their consent, bypassing card networks entirely.

For merchants this offers substantially lower costs than card acceptance, since the fee structure that funds interchange and rewards is absent.

Adoption has been slower than data sharing, partly because the payment is generally irrevocable and lacks the dispute protections cards provide.

Merchants also lose the ability to hold an authorisation and charge later, which matters for hotels, car hire and any business that adjusts the amount after the customer has committed.

Underwriting gained a new input

Lenders with permission to view transaction history can assess income stability and existing commitments directly, rather than inferring them from credit bureau records.

This is particularly useful for applicants with limited credit history, whose bureau file contains little but whose account activity is informative.

It also raises questions about what inferences are appropriate, since transaction data reveals a great deal beyond the borrower's capacity to repay.

Implementation quality determines the outcome

The rules specify what must be shared, but the reliability, completeness and speed of each bank's interface vary considerably.

Inconsistent implementation limits what can be built on top, since a service must work across all of a customer's accounts to be useful.

Regimes differ by jurisdiction, with some mandating standards and others leaving them to industry, which is the main reason progress has been uneven between markets.

Where no single standard applies, every third party must build and maintain a separate connection to each institution, and that cost falls hardest on smaller entrants.