Open Banking is the UK's regulated framework for letting authorised apps read bank account data with the customer's consent. Expenditure collection uses Account Information Services (AIS) — read-only, no ability to touch money. The client authorises access with their own bank, no credentials are shared, and consent is revocable at any time. For planning firms, it replaces the expenditure questionnaire with continuously accumulating, categorised reality. earmarkIQ uses AIS via Finexer, an FCA-authorised provider — the adviser platform, including the web dashboard, is live.
What Open Banking actually is
Open Banking came out of a 2016 Competition and Markets Authority ruling requiring the UK's largest banks to let customers share their account data with authorised third parties. It's now a mature piece of national infrastructure: standardised, secure APIs that every major UK bank operates, overseen by the FCA under the Payment Services Regulations 2017, with millions of active UK users.
The key word is authorised. Not any company can call these APIs. Access is restricted to firms the FCA has authorised for the purpose — or firms operating as Appointed Representatives of an authorised principal. When a client connects a bank account to an app, there is a regulated entity accountable for that connection, which is precisely what makes the framework different from the screen-scraping era it replaced, when tools asked users to hand over their actual banking passwords.
AIS and PIS: the two permissions that matter
Open Banking splits into two entirely separate services, and the distinction matters for how you explain it to clients.
Account Information Services (AIS) — read-only access. An AIS connection can see balances, transactions, direct debits and standing orders. It cannot move money, cannot make payments, cannot change anything on the account. This is the permission all of earmarkIQ's data access runs on today: the app reads and categorises, and that is the full extent of what it does with your clients' accounts. (earmarkIQ also holds Payment Initiation permissions for planned allocation features, but these are switched off and unavailable to users.)
Payment Initiation Services (PIS) — a separate permission that allows an authorised app to initiate a payment, with the customer explicitly approving each transaction. PIS powers things like account-to-account payments at checkout. It requires its own authorisation and its own consent, and an AIS-only app has no route to it. When a client asks "can this app take my money?", the accurate answer for an AIS-only tool is no — structurally, not just contractually.
"The app can look, through a regulated connection you approve with your own bank. It cannot touch. And you can switch off its access whenever you like."
How consent actually works
The client picks their bank in the app
The app hands over to the bank — usually by opening the bank's own app on the client's phone.
The bank authenticates the client directly
Face ID, fingerprint or passcode — the bank's own Strong Customer Authentication (SCA). At no point does the client type banking credentials into the connecting app, and the app never sees them.
The bank shows exactly what will be shared
Accounts, balances, transactions — itemised on the bank's own consent screen. The client approves, and read-only access begins.
Consent expires and is revocable
AIS consent typically lasts up to 90 days before the client must reconfirm it — a deliberate regulatory feature, not an app limitation. The client can also revoke access at any time, either in the app or from their bank's own connected-services settings.
The 90-day reconfirmation is worth knowing about operationally: a client who ignores the renewal prompt goes dark until they reconfirm. Any adviser process built on Open Banking data should treat connection upkeep as part of the annual service rhythm — a ten-second task for the client when prompted.
What data comes through — and what doesn't
Through AIS, an app receives balances and transaction history — amounts, dates, merchant references — from the point of connection, plus a window of back-history that varies by bank (commonly 90 days to 12 months). It does not receive the client's credentials, card PINs, or the ability to see or alter anything beyond the accounts consented. Raw transaction feeds are messy — "CRV*COSTA 0384" rather than "coffee" — which is where categorisation technology earns its keep: earmarkIQ classifies transactions automatically with AI classification, turning the raw feed into the category-level expenditure picture a planner actually wants. Why that matters for the advice process is the subject of our article on how firms collect expenditure data.
The security and regulatory chain, end to end
For a firm's data-governance file, the chain looks like this: the client's bank (FCA-regulated) exposes data through Open Banking APIs → an FCA-authorised AIS provider operates the connection — in earmarkIQ's case, Finexer Ltd (FRN 925695) → earmarkIQ operates as an FCA Appointed Representative of Finexer, with data encrypted in transit and at rest to 256-bit standard and ICO registration (CSN2001882) for UK GDPR. Every link is regulated, auditable, and — unlike a PDF bank statement forwarded over email — access can be terminated by the client instantly.
What this means for a planning firm
Open Banking consent is between the client, their bank and the authorised app — an adviser can't sit inside that triangle directly. The workable model is a consented sharing layer: the client connects their own accounts to the app, then separately and explicitly grants their adviser access to the categorised output. The adviser sees expenditure summaries with drill-down where needed; the client keeps control and can revoke; the firm gets an evidence-based expenditure line for the cashflow model.
That sharing layer is live in earmarkIQ for UK planning firms — client consent grants at category or transaction level, adviser recategorisation, and expenditure exports that work with any cashflow modelling tool. The adviser web dashboard is live, with pilot places limited. Firms displaced by the Moneyhub shutdown have the most immediate reason to look: our guide to replacing the Moneyhub Voyant integration covers that migration specifically.
FAQ
Put the rails to work
Register pilot interest and we'll contact your firm as the consented adviser layer opens — real expenditure data on regulated Open Banking rails.
Register pilot interest →Pilot places offered in registration order · Pricing available on request