Open Banking: Guide to APIs, Regulations and FinTech | Kong Inc.

\## The dawn of the open banking revolution

In January 2024, consumers in the United Kingdom made a record-breaking 14.5 million open banking payments. This milestone shows how dramatically the financial services industry has changed. It's the result of years of regulatory work that kicked off back in 2017, when the UK's Competition and Markets Authority (CMA) first required banks to adopt open banking.

Let's start by defining some key terms:

By November 2023, there were 8 million active open banking users in the UK. By July 2024, **the UK hit 10 million active users****the UK hit 10 million active users**, which works out to about 15% of the UK's population. Open banking in the UK continues to evolveOpen banking in the UK continues to evolve. But this isn't just a UK trend — growth has been picking up in a big way across multiple regions around the world.

Open banking gives everyday consumers and businesses more control over their finances through regulated data sharing. Users can safely share their financial information with approved outside companies through standardized APIs. This does away with the old, insecure practice of screen scraping and puts consumers in the driver's seat when it comes to who gets access to their data.

The market opportunity here is huge. According to Grand View Research, **the global open banking market was ** **valued****valued** ** at $31.61 billion in 2024**. Industry projections indicate it could climb all the way to $135.17 billion by 2030, growing at a compound annual growth rate (CAGR) of 27.6% between 2025 and 2030.

Why does this matter? Three key reasons.

Open banking brings together traditional banks, innovative fintechs, and enterprises, ushering in unprecedented opportunities for collaboration. Organizations leverage open banking APIs to access previously siloed financial data, building new services that address real consumer needs:

For businesses, ensuring proper management of open banking APIsmanagement of open banking APIs is necessary to comply with regulatory standards while moving fast to leverage new opportunities.

\## Understanding open banking: Technical foundations

**Core concepts and value proposition**

Open banking replaces password sharing with secure, token-based access. In the past, screen scraping forced customers to hand over their banking credentials to third-party apps, inviting serious security risks. Today, open banking removes that exposure by using OAuth 2.0 and standardized APIs to enable safe, permission-based data sharing.

The value of open banking looks different depending on who you ask.

**For consumers, it means:**

**For fintechs, it delivers:**

**For banks, it unlocks:**

\### The three technical pillars

**1. Secure authorization flows**

Open banking relies on OAuth 2.0 and OpenID ConnectOpenID Connect (OIDC), reinforced by Financial-Grade API (FAPI) standards, that add an extra layer of protection for financial transactions. Customers can grant explicit consent to share their data without ever exposing their passwords.

**The key security features include:**

**2. Standardized data schemas and APIs**

Interoperability depends on consistent data formats across all participants. A fintech should be able to connect to any bank using the same endpoints and get the same structured response every time. For example, the /accounts/{accountId}/balance endpoint returns a standardized payload regardless of the provider.

**Standardization typically covers:**

**3. Governance and accreditation**

Trust frameworks ensure that only vetted participants can access sensitive financial data. According to a recent reportreport in the UK, adoption continues to soar, reaching about 18% among small businesses and 13% among consumers as of January 2024. Every participant must pass rigorous security audits and certification before joining the ecosystem.

**Core governance components include:**

\### The API stack components

Open banking delivers its capabilities through several specialized API layers.

**Identity and authentication layer**

Strong Customer Authentication (SCA) requires multi-factor verification to confirm a user’s identity. This typically includes:

**Account information services (AIS)**

AIS APIs provide secure, read-only access to key financial data, including:

**Payment initiation services (PIS)**

PIS APIs support a range of payment scenarios, such as:

\### Security evolution: From FAPI 1.0 to 2.0

The Financial-Grade API (FAPI) standard continues to evolve, tightening security while making implementations easier to manage. FAPI 1.0 introduced critical safeguards but often came with added complexity. In contrast, FAPI 2.0 builds on that foundation by simplifying requirements without compromising protection.

**The key FAPI 2.0 improvements:**

One of the most important updates is **Pushed Authorization Requests (PAR)**. Instead of sending authorization parameters through the browser, they’re delivered directly to the authorization server. This approach shrinks the attack surface and helps prevent request tampering, resulting in a more secure authorization flow.

\## Real-world example: SEB's open banking journey

Open banking's potential may best be illustrated through real-world success stories, such as that of SEB, a leading Nordic corporate bank. SEB's transformation into an API-first organization exemplifies the profound impact of strategic API management on financial services.

\### **SEB's API transformation**

Faced with the need to modernize its API platform, the team at SEB began work to enhance its open banking capabilitiesenhance its open banking capabilities. Daniel Franzén, Head of Open Banking at SEB, shared insights into their transition. Initially, SEB struggled with a cumbersome API platform that hindered agility and innovation. After evaluating multiple solutions, SEB chose Kong for its robust API management capabilities.

Franzén emphasized the importance of APIs as both a technological and business asset within SEB. Kong's solution was pivotal in simplifying their architecture, reducing complexity, and enabling faster time-to-market for new services.

"We need all products represented by APIs on a centralized platform and portal. And that’s where we’re heading," Franzén said. "Customers want to consume a service or product directly, so time to market is critical."

\####

**Business impact and innovation**

SEB's adoption of Kong led to a streamlined API management process, allowing for approximately 200 APIs across external and internal products. This transformation not only reduced development costs but also attracted new business opportunities by showcasing SEB's API offerings to prospective clients.

"When people in our different product areas see us getting customers due to our API offerings, everyone wants to be there," Franzén said. This shift in mindset has fueled a forward movement in product thinking across SEB.

SEB's story is a testament to the transformative power of effective API management in Open Banking. By aligning technology with business objectives, SEB has positioned itself to thrive in the evolving financial landscape. Their experience underscores the critical role of API platforms like Kong in driving innovation, enhancing customer experiences, and maintaining competitive advantage.

For more insights into how Kong is empowering financial institutions to harness the potential of Open Banking, explore our customer storiescustomer stories and solutions for open bankingsolutions for open banking.

\## Banking as a Service (BaaS) vs Open Banking

Banking as a service (BaaS) is making a financial institution’s digital banking services available through a third party’s products. These third parties can then offer customers things like payment services and loans without having to acquire a banking license and meet the regulatory requirements that banks must. BaaS allows these third parties to pick and choose the digital banking services they wish to use and embed these banking services into their products.

The rise of *Banking as a Service* (BaaS) allows non-financial companies to seamlessly integrate banking services into their platforms. For instance, consumers can split ride costs with friends in a single tap, or arrange installment payments during online checkout without leaving the merchant's website. These embedded financial experiences dramatically expand consumer choice and convenience, representing a paradigm shift in how consumers access and use financial services.

The communications needed to handle BaaS are done securely via APIs. The third party using the bank's services never directly has access to a customer’s finances — they only act as an intermediary. Banking as a service is sometimes also called white-label banking or private-label financial services.

Like Open Banking, BaaS can create new sources of revenue and deliver a better customer experience. And the connections that make this possible are done via financial APIs. But banking as a service is NOT the same as Open Banking. Open banking is about access to a bank’s data while banking as a service is about third parties using complete banking services in their own products.

\### **The value of strategic partnerships**

The fintech landscape is evolving from competition between banks and startups to collaboration. Rather than competing directly, many traditional banks and fintech companies have discovered the power of collaboration. Banks contribute established infrastructure, trusted reputations, and regulatory expertise, while fintechs bring agility, innovation, and new technologies. Successful partnerships, such as Goldman Sachs with Apple Card and BBVA's Open Platform, highlight how these complementary strengths create superior customer experiences.

\## Global regulatory landscape: A market-by-market analysis

**United States: Section 1033 and market evolution**

The U.S. open banking market blends voluntary adoption with a growing push toward regulation. On October 22, 2024, the Consumer Financial Protection Bureau (CFPB) released its Final Rule on Personal Financial Data RightsFinal Rule on Personal Financial Data Rights, but the broader regulatory picture has been evolving ever since.

Current dynamics include:

The framework is still evolving, with active debates around:

**European Union: From PSD2 to PSD3/PSR evolution**

Europe leads global open banking adoption through regulatory frameworks. The European Commission proposed updates to modernize PSD2 into PSD3 and introduce a Payment Services Regulation (PSR)Payment Services Regulation (PSR) to continue supporting competition while strengthening consumer protections.

**PSD3/PSR enhancements:**

Proposed PSD3/PSR enhancements focus on strengthening security, improving consumer protections, and promoting fair competition across the payments ecosystem.

**Enhanced fraud prevention**

**Consumer protection**

**Market competition**

**United Kingdom: A global open banking success story**

The UK is now a classic model for regulatory-led open banking. A combination of clear mandates, strong governance, and practical standards has helped drive meaningful adoption across both consumers and businesses.

**Adoption metrics**:

**The key success factors:**

**Leadership in variable recurring payments (VRP):**

**Emerging markets: A quick tour**

Several markets are rapidly advancing open banking, each with its own regulatory approach, infrastructure, and innovation priorities.

**India**

**Brazil**

**Australia**

**Singapore**

**Canada**

\## Adoption metrics: What success looks like

**Growth trajectory at a glance**

Open banking adoption is accelerating worldwide, with strong momentum across market size, usage, and innovation.

**Market growth projections:**

**Regional leadership:**

**Use case distribution**

Adoption patterns vary by region, with different markets leaning into different applications.

**United Kingdom:**

**Consumers vs. businesses:**

**API call volume and performance**

As adoption scales, global performance benchmarks are starting to take shape:

\## Security, fraud, and consumer protection

**End of screen scraping**

Sunsetting screen scraping marks a major milestone for financial security. Customers no longer need to share their banking credentials with third parties. Instead, APIs provide controlled, permission-based access that is fully traceable and auditable.

**The key security improvements include:**

Regulators around the world are reinforcing this shift. The CFPB’s Section 1033 rule (targeted for October 2024 implementation) and the EU’s proposed PSD3 framework both move to prohibit credential sharing.

**Mandatory verification requirements**

The Council’s negotiating mandatemandate strengthens fraud prevention by expanding the scope to include electronic communications service providers.

**Verification of Payee (VoP) systems enable:**

**Enhanced authentication may also include:**

**Liability and reimbursement**

Regulatory frameworks are reshaping how liability is handled when some fraudulent activities occur, with a stronger emphasis on consumer protection.

**Proposed European approach**

**UK model:**

\## The future: From open banking to open finance

**Where the industry is headed**

Many countries are moving beyond open banking toward broader open finance frameworks. This next phase applies the same data-sharing principles across the entire financial ecosystem, not just bank accounts.

The scope is expanding to cover insurance policies and claims, investment portfolios and performance, pension accounts and projections, mortgage and loan data, and even cryptocurrency holdings. In the EU, the proposed **Financial Data Access (FIDA)** regulation aims to extend these principles across all financial services.

This broader access opens the door to more advanced use cases, including truly holistic financial management platforms, AI advisors to operate on complete financial pictures, seamless product switching across providers, and more comprehensive risk assessment models.

**The rise of the premium API economy**

As fintech business models mature, the focus is shifting from basic data access to higher-value services built on top of open finance APIs. Many premium offerings are emerging that go well beyond raw connectivity.

These services include advanced data analytics, predictive financial modeling, real-time fraud scoring, digital identity verification, and forward-looking cash-flow forecasting. At the same time, monetization models are evolving. Providers are experimenting with usage-based pricing per API call, subscription tiers for enhanced data access, value-based pricing tied to insights delivered, and revenue sharing on completed transactions.

**Cross-border interoperability: the next frontier**

International data sharing is becoming one of the biggest opportunities and challenges for open finance. Expanding across borders introduces real complexity, from aligning data standards globally to navigating regulatory differences between jurisdictions. The most prominent practical hurdles –  currency conversion, time zone handling, and language localization – also come into play.

To address these challenges, the industry has started coalescing around emerging solutions. These include greater cooperation on global standards, bilateral data-sharing agreements between regions, technical “bridges” that connect otherwise incompatible systems, and shared security frameworks that establish a common baseline for trust across markets.

\## Practical implementation guide

Let's explore what implementation might look like for financial institutions, fintechs, and enterprises.

\### For financial institutions

Successfully preparing for open banking and the broader shift to open finance, requires a phased, practical approach. Those organizations that move deliberately tend to reduce risk while accelerating time to value.

**Core technology capabilities**

A resilient open banking strategy depends on several foundational components. An API gateway enables centralized traffic management and secure, scalable integrations. Strong identity management — typically built on OAuth and OIDC with support for FAPI — helps protect sensitive financial data. Data transformation tools are often necessary to connect legacy systems with modern APIs, while real-time monitoring ensures reliability and performance. Finally, a well-designed developer portal provides the self-service documentation and tooling partners need to integrate quickly and securely.

\### For fintechs

Entering the open banking ecosystem requires more than technical readiness; it calls for a thought-through strategy that balances compliance, partnerships, and innovation. API security and management in the fintech industryAPI security and management in the fintech industry are crucial.

\### For enterprises

As open banking adoption skyrockets, enterprises have an opportunity to streamline financial operations, improve decision-making, and unlock new revenue streams. Prioritizing use cases that balance complexity with measurable business impact helps achieve success faster.

**Enterprise open banking use case prioritization**

**Implementation best practices**

Start small and scale thoughtfully. Pilot programs help validate assumptions before broader rollout, while focusing on high-value, straightforward use cases builds early momentum. Over time, organizations should develop internal expertise, establish clear data governance policies, and create feedback loops that support continuous improvement.

**Building a risk management foundation**

A structured risk framework is essential for sustainable adoption. This typically includes strong data security controls, thorough vendor risk assessments, business continuity planning, ongoing regulatory compliance monitoring, and clearly defined performance standards.

**A practical 12-month readiness checklist**

By the end of the first year, many organizations aim to have a modern security posture in place—such as implementing the FAPI 2.0 profile and operationalizing a Pushed Authorization Requests (PAR) endpoint. Payment verification measures, such as VoP or CoP checks, should be integrated, fraud reimbursement processes should be documented, and a developer portal with a live sandbox should be available for partners.

Operational maturity should also include active SLA monitoring, completed security audits, streamlined partner onboarding, validated performance benchmarks, and any required compliance certifications.

\## Conclusion: Navigating the open banking revolution

Open banking has evolved from a regulatory experiment into critical financial infrastructure. With roughly 10 million users in the UK alone, which is about 15% of the population, the scale now speaks for itself.

The data tells a clear story of transformation. Billions of API calls are driving billions in economic value. FAPI 2.0 is helping standardize security across markets, PSD3 and PSR proposals are reinforcing fraud protections, and Section 1033 is fueling U.S. momentum despite ongoing legal challenges.

**What stakeholders should do next?**

**The path forward (from 2024 to 2030)**

Open banking ultimately represents a philosophical shift in financial services. Data is becoming the foundation for innovation, enabling infrastructure that turns information into tangible value for consumers and businesses alike.

This transformation is already measurable in API traffic, market growth, and changing customer expectations. The real question is no longer whether organizations should participate, but how quickly they can position themselves to compete.

The winners won’t necessarily be the biggest or the oldest. They’ll be the ones that stay open, move fast, and remain relentlessly focused on customer needs.

Welcome to the future of finance — now more open than ever.

*Ready to build your open banking infrastructure? Discover how * *Kong Gateway**Kong Gateway* * powers secure, scalable financial services.*

\## Open Banking FAQs

**What is Open Banking?**

Open Banking is a financial framework that allows banks and third-party providers to securely share banking data through APIs, giving consumers more control over their financial information. This open access fosters innovation, as fintech companies can develop new products and services built on real-time financial data.

**How do Open Banking APIs work?**

Open Banking APIs provide standard interfaces for securely sharing financial data, such as bank account transactions, balances, and payment information. With customer authorization, these APIs enable third-party services to access and process financial data, fueling innovative solutions like budgeting apps, payment solutions, and investment platforms.

**Why is PSD2 significant for Open Banking?**

PSD2 (the Second Payment Services Directive) is a major European regulation mandating that banks safely share customer data with authorized third-party providers via standardized APIs. This directive accelerated Open Banking across Europe, sparking a wave of fintech innovation and expanding consumer choice by creating a more level playing field for financial institutions.

**What are the main benefits of Open Banking for consumers?**

Open Banking helps consumers quickly compare banking services, access personalized financial products and manage their finances more effectively. Streamlined account-switching, faster payment processes, and personalized budgeting tools are frequent advantages, making it easier for customers to find better interest rates, reduce fees, and receive tailored financial advice.

**How does Banking as a Service (BaaS) differ from Open Banking?**

Although both rely on APIs, BaaS focuses on banks providing their core banking services (like payment processing or loan issuance) to third parties, letting them embed those services into their own products. Open Banking, on the other hand, centers on sharing financial data with authorized third parties. Essentially, BaaS offers banking functions, while Open Banking offers data access.

**What security measures protect customer data in Open Banking?**

Open Banking relies heavily on secure protocols such as OAuth 2.0, TLS encryption, and strong customer authentication. Banks and fintech providers use multi-factor authentication, tokenization, and real-time fraud detection systems, ensuring financial data is encrypted before and during transfer, and access is granted only with explicit user permission.

**Are there Open Banking regulations in the United States?**

Yes. While the U.S. lacks a single, centralized Open Banking mandate like PSD2 in Europe, regulations proposed by the Consumer Financial Protection Bureau (CFPB) emphasize data portability and give consumers more control over their financial data. Voluntary guidelines and interagency collaboration help shape how Open Banking evolves across the country.

**How do Payment APIs help businesses under Open Banking?**

Payment APIs facilitate direct account-to-account transfers, often saving on processing fees charged by traditional methods like credit cards. By integrating real-time, secure payment capabilities, businesses can boost conversion rates, lower fraud risk, reduce chargebacks, and often receive instant settlement of funds.

**What is the role of fintech startups in Open Banking?**

Fintech startups leverage secure Open Banking APIs to build consumer-facing apps and services that deliver personalized budgeting, faster payments, and advanced financial insights. By accessing real-time banking data, these companies can rapidly develop and iterate new solutions that challenge traditional banking norms and enrich the financial ecosystem.

**How do global regulations impact Open Banking implementation?**

Different regions adopt various regulatory models—Europe uses PSD2, Australia has the Consumer Data Right (CDR), and the U.S. follows a more decentralized approach. Each framework addresses security, data privacy, and customer empowerment in its own way, influencing how quickly new banking solutions can be launched and integrated.

**Which standards support security and interoperability in Open Banking?**

Standards such as the Financial-grade API (FAPI) from the OpenID Foundation(FAPI) from the OpenID Foundation and the Berlin Group's NextGenPSD2 framework define secure authentication, authorization, and data exchange processes. These standards help ensure consistency and reliability for banks, fintechs, and consumers, promoting widespread adoption of Open Banking solutions.

**What does the future hold for Open Banking?**

Open Banking is expanding into broader "Open Finance," integrating services like insurance, investments, and lending under a unified digital infrastructure. Emerging technologies, including AI and blockchain, will enable more personalized products and reduce friction in accessing financial services. As consumer trust and regulatory frameworks mature, collaboration between traditional banks and fintechs will continue driving new business models and enhanced user experiences.

References

  1. Statista. (2024). Number of open banking users in the United Kingdom (UK) from November 2019 to November 2023. Retrieved from https://www.statista.com/statistics/1314421/uk-open-banking-users/https://www.statista.com/statistics/1314421/uk-open-banking-users/
  2. Mastercard. (2024). The acceleration of open banking in the UK. Retrieved from https://www.mastercard.com/europe/en/news-and-trends/Insights/2024/the-acceleration-of-open-banking-in-the-uk.htmlhttps://www.mastercard.com/europe/en/news-and-trends/Insights/2024/the-acceleration-of-open-banking-in-the-uk.html
  3. Open Banking Limited. (2024). Latest Impact Report shows strong growth and the power of payments. Retrieved from https://www.openbanking.org.uk/insights/latest-impact-report-shows-strong-growth-and-the-power-of-payments/https://www.openbanking.org.uk/insights/latest-impact-report-shows-strong-growth-and-the-power-of-payments/
  4. PYMNTS. (2024). UK's Open Banking Milestone: What 10 Million Users Mean for UK's Financial Services Future. Retrieved from https://www.pymnts.com/news/banking/2024/uks-open-banking-milestone-what-10-million-users-mean-for-uks-financial-services-future/https://www.pymnts.com/news/banking/2024/uks-open-banking-milestone-what-10-million-users-mean-for-uks-financial-services-future/
  5. Open Banking Limited. (2024). Adoption Analysis - The open banking Impact Report 2024 (March). Retrieved from https://openbanking.foleon.com/live-publications/the-open-banking-impact-report-2024-march/adoption-analysishttps://openbanking.foleon.com/live-publications/the-open-banking-impact-report-2024-march/adoption-analysis
  6. Grand View Research. (2024). Open Banking Market Size & Share | Industry Report, 2030. Retrieved from https://www.grandviewresearch.com/industry-analysis/open-banking-systems-markethttps://www.grandviewresearch.com/industry-analysis/open-banking-systems-market
  7. Market.us. (2024). Open Banking Market Size, Share | CAGR of 23.3%. Retrieved from https://market.us/report/open-banking-market/https://market.us/report/open-banking-market/
  8. ACI Worldwide. (2024). Your Guide To PSD3, PSR & Changes From PSD2. Retrieved from https://www.aciworldwide.com/psd3https://www.aciworldwide.com/psd3
  9. European Parliament. (2024). Revision of EU rules on payment services | Legislative Train Schedule. Retrieved from https://www.europarl.europa.eu/legislative-train/theme-an-economy-that-works-for-people/file-revision-of-eu-rules-on-payment-serviceshttps://www.europarl.europa.eu/legislative-train/theme-an-economy-that-works-for-people/file-revision-of-eu-rules-on-payment-services
  10. Consumer Financial Protection Bureau. (2024). Required Rulemaking on Personal Financial Data Rights. Retrieved from https://www.consumerfinance.gov/personal-financial-data-rights/https://www.consumerfinance.gov/personal-financial-data-rights/
  11. Freshfields Bruckhaus Deringer. (2024). From PSD2 to PSD3 and PSR – European Parliament sets out its vision on the future of payments. Retrieved from https://riskandcompliance.freshfields.com/post/102j643/from-psd2-to-psd3-and-psr-european-parliament-sets-out-its-vision-on-the-futurehttps://riskandcompliance.freshfields.com/post/102j643/from-psd2-to-psd3-and-psr-european-parliament-sets-out-its-vision-on-the-future
  12. Congress.gov. (2024). Access to Consumer Financial Data: Open Banking and the CFPB's Section 1033 Rule. Retrieved from https://www.congress.gov/crs-product/IF13117https://www.congress.gov/crs-product/IF13117

Learn MoreLearn More Get a DemoGet a Demo

**Topics**

- Open BankingOpen Banking- API GatewayAPI Gateway

Share on Social

Kong