Practical Guide

Open Banking for financial
planners: a practical guide.

By earmarkIQ August 2026 8 min read

Open Banking underpins every serious attempt to replace guesstimated client expenditure with real data — but the terminology (AIS, PIS, SCA, TPPs) puts advisers off before the useful part starts. This guide explains the machinery in plain terms: what it is, how consent works, what the security chain looks like, and what it means for a planning firm.

Quick Answer

Open Banking is the UK's regulated framework for letting authorised apps read bank account data with the customer's consent. Expenditure collection uses Account Information Services (AIS) — read-only, no ability to touch money. The client authorises access with their own bank, no credentials are shared, and consent is revocable at any time. For planning firms, it replaces the expenditure questionnaire with continuously accumulating, categorised reality. earmarkIQ uses AIS via Finexer, an FCA-authorised provider — the adviser platform, including the web dashboard, is live.

What Open Banking actually is

Open Banking came out of a 2016 Competition and Markets Authority ruling requiring the UK's largest banks to let customers share their account data with authorised third parties. It's now a mature piece of national infrastructure: standardised, secure APIs that every major UK bank operates, overseen by the FCA under the Payment Services Regulations 2017, with millions of active UK users.

The key word is authorised. Not any company can call these APIs. Access is restricted to firms the FCA has authorised for the purpose — or firms operating as Appointed Representatives of an authorised principal. When a client connects a bank account to an app, there is a regulated entity accountable for that connection, which is precisely what makes the framework different from the screen-scraping era it replaced, when tools asked users to hand over their actual banking passwords.

AIS and PIS: the two permissions that matter

Open Banking splits into two entirely separate services, and the distinction matters for how you explain it to clients.

Account Information Services (AIS) — read-only access. An AIS connection can see balances, transactions, direct debits and standing orders. It cannot move money, cannot make payments, cannot change anything on the account. This is the permission all of earmarkIQ's data access runs on today: the app reads and categorises, and that is the full extent of what it does with your clients' accounts. (earmarkIQ also holds Payment Initiation permissions for planned allocation features, but these are switched off and unavailable to users.)

Payment Initiation Services (PIS) — a separate permission that allows an authorised app to initiate a payment, with the customer explicitly approving each transaction. PIS powers things like account-to-account payments at checkout. It requires its own authorisation and its own consent, and an AIS-only app has no route to it. When a client asks "can this app take my money?", the accurate answer for an AIS-only tool is no — structurally, not just contractually.

ℹ️ The client-friendly version

"The app can look, through a regulated connection you approve with your own bank. It cannot touch. And you can switch off its access whenever you like."

1

The client picks their bank in the app

The app hands over to the bank — usually by opening the bank's own app on the client's phone.

2

The bank authenticates the client directly

Face ID, fingerprint or passcode — the bank's own Strong Customer Authentication (SCA). At no point does the client type banking credentials into the connecting app, and the app never sees them.

3

The bank shows exactly what will be shared

Accounts, balances, transactions — itemised on the bank's own consent screen. The client approves, and read-only access begins.

4

Consent expires and is revocable

AIS consent typically lasts up to 90 days before the client must reconfirm it — a deliberate regulatory feature, not an app limitation. The client can also revoke access at any time, either in the app or from their bank's own connected-services settings.

The 90-day reconfirmation is worth knowing about operationally: a client who ignores the renewal prompt goes dark until they reconfirm. Any adviser process built on Open Banking data should treat connection upkeep as part of the annual service rhythm — a ten-second task for the client when prompted.

What data comes through — and what doesn't

Through AIS, an app receives balances and transaction history — amounts, dates, merchant references — from the point of connection, plus a window of back-history that varies by bank (commonly 90 days to 12 months). It does not receive the client's credentials, card PINs, or the ability to see or alter anything beyond the accounts consented. Raw transaction feeds are messy — "CRV*COSTA 0384" rather than "coffee" — which is where categorisation technology earns its keep: earmarkIQ classifies transactions automatically with AI classification, turning the raw feed into the category-level expenditure picture a planner actually wants. Why that matters for the advice process is the subject of our article on how firms collect expenditure data.

The security and regulatory chain, end to end

For a firm's data-governance file, the chain looks like this: the client's bank (FCA-regulated) exposes data through Open Banking APIs → an FCA-authorised AIS provider operates the connection — in earmarkIQ's case, Finexer Ltd (FRN 925695) → earmarkIQ operates as an FCA Appointed Representative of Finexer, with data encrypted in transit and at rest to 256-bit standard and ICO registration (CSN2001882) for UK GDPR. Every link is regulated, auditable, and — unlike a PDF bank statement forwarded over email — access can be terminated by the client instantly.

What this means for a planning firm

Open Banking consent is between the client, their bank and the authorised app — an adviser can't sit inside that triangle directly. The workable model is a consented sharing layer: the client connects their own accounts to the app, then separately and explicitly grants their adviser access to the categorised output. The adviser sees expenditure summaries with drill-down where needed; the client keeps control and can revoke; the firm gets an evidence-based expenditure line for the cashflow model.

That sharing layer is live in earmarkIQ for UK planning firms — client consent grants at category or transaction level, adviser recategorisation, and expenditure exports that work with any cashflow modelling tool. The adviser web dashboard is live, with pilot places limited. Firms displaced by the Moneyhub shutdown have the most immediate reason to look: our guide to replacing the Moneyhub Voyant integration covers that migration specifically.


FAQ

What is the difference between AIS and PIS?
Account Information Services (AIS) provide read-only access: an authorised app can view balances and transactions but cannot touch the money. Payment Initiation Services (PIS) are a separate permission allowing an authorised app to initiate a payment with the customer's explicit approval each time. Expenditure data collection for planning uses AIS only — earmarkIQ operates read-only and cannot move client money. It holds Payment Initiation permissions for planned features, but these are currently disabled.
How does Open Banking consent work for clients?
The client authorises access directly with their own bank, using the bank's app and its usual security (biometrics or passcode). No banking credentials are ever shared with the connecting app. Consent is granted per bank connection, typically lasts up to 90 days before it must be reconfirmed, and the client can revoke it at any time through their bank or the app.
Is Open Banking data collection safe enough for advice firms?
Open Banking runs on the same regulated rails UK banks use, overseen by the FCA under the Payment Services Regulations 2017. Only authorised firms — or their Appointed Representatives — can access the APIs, data is encrypted in transit and at rest, and access is read-only under AIS. For most firms this is a stronger security posture than clients emailing bank statements as PDF attachments.
Can an adviser get direct access to a client's Open Banking data?
Not directly — Open Banking consent is between the client, their bank and the authorised app. The workable adviser model is a consented sharing layer inside the app: the client connects their own accounts, then explicitly grants their adviser access to categorised summaries. earmarkIQ has built exactly this consent-first adviser layer — consent grants, expenditure exports and the adviser web dashboard are all live.

Put the rails to work

Register pilot interest and we'll contact your firm as the consented adviser layer opens — real expenditure data on regulated Open Banking rails.

Register pilot interest →

Pilot places offered in registration order · Pricing available on request