🏦 Open Banking

Open Banking in the UK: What Apps Can and Cannot Do With Your Data

By Caolan Preston August 2026 8 min read

Most anxiety about money apps comes from not knowing where the boundary sits. UK Open Banking draws it precisely, in law: one permission lets an app read, a separate permission lets it start a payment you authorise. Knowing which one an app holds tells you almost everything about what it could do to you.

The short version

UK Open Banking gives regulated firms two separate permissions. Account Information Services (AIS) lets an app read your accounts. Payment Initiation Services (PIS) lets it start a payment that you then authorise at your own bank. They are granted separately, and an app holding one does not hold the other. In both cases you authenticate at your bank rather than handing over a password, your consent has to be reconfirmed at least every 90 days, and you can withdraw it at any time from your bank’s own app.

What Open Banking actually is

Open Banking is a UK framework, live since 2018, that lets you instruct your bank to share your account data — or to accept a payment instruction — through an authorised third party. It came out of a Competition and Markets Authority order and the second Payment Services Directive, and it is supervised by the Financial Conduct Authority.

The problem it was built to solve is worth remembering, because it explains the design. Before Open Banking, an app that wanted to see your transactions had to log in as you, using credentials you had handed over. That practice, screen scraping, gave the app everything your account could do and left you outside your bank’s fraud protections. Open Banking replaced it with something narrower: you authenticate at your own bank, on your bank’s own screen, and the bank releases a limited, time-bound, revocable feed to a firm the FCA has authorised.

The practical rule that follows is short. No legitimate UK app will ever ask you to type your online banking password into its own interface. If one does, close it.

AIS and PIS: the two permissions

Almost every misunderstanding about what money apps can do comes from not knowing these are separate.

 Account Information (AIS)Payment Initiation (PIS)
What it permitsReading balances and transactionsStarting a payment you then authorise
Direction of travelData out of the bankAn instruction into the bank
Can money move?NeverYes, with your authentication each time
Who authenticates youYour bankYour bank, per payment
Typical useBudgeting, categorisation, net worth, subscription trackingPaying a bill, topping up savings, checkout at a merchant
Firm must beAn authorised or registered AISPAn authorised PISP

A budgeting app operating under AIS cannot move a penny. Not because it has promised not to, and not because a setting is switched off, but because the permission it holds is a reading permission. There is no payment instruction it is able to construct. This is the most reassuring fact about UK money apps and the least widely known.

PIS is not a sinister capability either — it is what sits behind “pay by bank” at an online checkout. The important feature is that it is not a standing power. Each payment is a separate instruction that you authorise with your bank, seeing the amount and the payee, exactly as you would a manual transfer. A PISP cannot help itself to your account later.

What an AIS app can and cannot do

CanCannot
Read balances across your connected accountsMove money between your accounts
Read transaction history and categorise itMake a payment to anyone
Spot recurring payments and price risesCancel a direct debit or standing order
Work out net worth from what it can seeChange your overdraft, limits or account settings
Show you trends, forecasts and suggestionsApply for credit in your name
Export or share data where you ask it toAccess accounts you have not connected

The right-hand column trips people up in a specific way: because an app can see a subscription, users often assume it can cancel one. It cannot. Cancelling a recurring card payment or a direct debit is something you do with your bank or the provider. A good app will find it, tell you what it costs, and tell you where to go — and that is the boundary of what AIS allows.

Consent under Open Banking is narrower than most people assume, and it expires.

Scope is set when you connect. You choose which accounts to share, and the permission covers those accounts and the data types the app requested — not everything you hold at that bank, and not accounts you add later unless you connect them too.

Duration is finite. Access is time-bound rather than perpetual. Under the FCA’s rules, introduced in PS21/19 and in force since 26 March 2022, a firm relying on the Article 10A exemption must obtain your explicit consent again at least every 90 days. Where a bank has not adopted that exemption, you may instead be asked to reauthenticate with the bank itself on a similar cycle. Either way, an Open Banking connection you set up and forget about does not quietly run forever — something will ask you to confirm it is still wanted.

Data minimisation applies throughout: a firm should request only what it needs for the service it provides, and should not be hoovering up categories it has no use for.

Two consents, often confused

Consenting to share data with an app is not the same as agreeing to the app’s terms, and neither is the same as authorising a payment. Under AIS there is no payment to authorise at all. If you are ever shown a payment authorisation screen by a budgeting app that told you it was read-only, stop.

How to revoke, and what happens next

You have two independent routes, and you do not need the app’s cooperation for either.

01

Through your bank

Every UK bank offering Open Banking must let you see connected third parties and withdraw access, usually under a heading such as “connected apps”, “data sharing” or “third party access” in the app or online banking. Revoking there stops the data feed at source.

02

Through the app

The app should also let you disconnect an account or close your account entirely, and deal with data held under its privacy policy and your UK GDPR rights.

Revoking stops future access. It does not, by itself, delete data the app has already collected — that is governed by the app’s retention policy and your right to erasure, which is a separate request. If deletion is what you want, ask for it explicitly rather than assuming disconnection achieved it. Nothing about revocation affects your bank account, your payments, or your credit file.

What FCA regulation gets you in practice

“FCA regulated” is used loosely enough to be worth unpacking. A firm is either directly authorised, or an Appointed Representative operating under a principal firm that is and which carries regulatory responsibility for its conduct. Both appear on the FCA register, which is public, free and not controlled by the firm. Checking takes a minute and is the single most useful thing you can do.

What regulation actually gets you:

What it does not get you, and this matters just as much:

Where earmarkIQ sits

earmarkIQ operates under AIS only. Bank connections run through Finexer Ltd (FRN 925695), an FCA-authorised provider, with earmarkIQ as an Appointed Representative — verifiable on the register. The connection is read-only: earmarkIQ reads balances and transactions, categorises them, and builds things like a payday allocation and a net worth figure on top. It cannot move money, because AIS does not permit it to.

On payment initiation, the accurate position is this: PIS sits within the permissions earmarkIQ operates under and is on the roadmap, but it is not enabled today. earmarkIQ does not initiate payments. If it is ever switched on, it will work the way PIS works everywhere — a payment you start, with an amount and a payee you see and confirm, authenticated by you at your own bank, one at a time. It would not be a standing power, and nothing automated, including any assistant connected through earmarkIQ Context, would be able to trigger it.

We have written the longer argument about that boundary in the difference between an app that shows you your money and one that moves it. It is the distinction we think people should be asking every provider about, including us.


Frequently asked questions

What is the difference between AIS and PIS?
Account Information Services (AIS) is a read permission: it lets an authorised firm see your balances and transactions. Payment Initiation Services (PIS) is an instruction permission: it lets an authorised firm start a payment which you then authorise with your own bank. They are granted separately and a firm holding one does not automatically hold the other. An app operating under AIS alone cannot move money under any circumstances, because it has no ability to construct a payment instruction.
Can a budgeting app take money from my account?
Not if it operates under Account Information Services, which almost all UK budgeting apps do. AIS is a reading permission and there is no payment instruction available to it. Even a firm that also holds Payment Initiation permissions cannot move money without you authorising each payment at your own bank, seeing the amount and the payee. No Open Banking permission of any kind creates a standing ability to help itself to your account.
How often does Open Banking access need renewing?
At least every 90 days. Under FCA rules introduced in PS21/19 and in force since 26 March 2022, a firm relying on the Article 10A exemption must obtain your explicit consent again at least every 90 days; where a bank has not adopted that exemption you may be asked to reauthenticate with the bank itself on a similar cycle. Either way, access is time-bound rather than perpetual, so a connection you set up and forget will prompt you rather than run indefinitely.
How do I stop an app accessing my bank data?
You have two routes and need neither the app's permission nor its help. Withdraw access in your own bank's app or online banking, usually under connected apps, data sharing or third party access — that stops the feed at source. Or disconnect from within the app itself. Revoking stops future access but does not by itself delete data already collected; if you want that removed, make a separate erasure request under UK GDPR. Nothing about revoking affects your account, your payments or your credit file.
Can an Open Banking app cancel my subscriptions for me?
No, not under Account Information Services. The app can identify recurring payments, tell you what each costs annually and flag when a price has risen, but cancelling a direct debit or a recurring card payment is something you do with your bank or with the provider. Any app claiming it will cancel subscriptions on your behalf is either doing something outside Open Banking or describing a guided process where you do the cancelling.
Is my money protected by the FSCS if I use a budgeting app?
The question does not quite apply, and that is reassuring rather than worrying. FSCS protection covers deposits held with an authorised deposit-taker, up to £85,000 per person per institution. A budgeting app operating under AIS is not holding your money at all — your money stays in your bank accounts, where FSCS protection already applies. If the app went out of business tomorrow, your accounts would be entirely unaffected, because they were never with the app in the first place.

About earmarkIQ

earmarkIQ is a UK personal finance app for iOS and the web. It is an FCA Appointed Representative of Finexer Ltd (FRN 925695) and ICO registered (CSN2001882). It connects to UK bank accounts through read-only Open Banking, categorises spending automatically, builds a payday allocation plan, and tracks subscriptions, property equity and net worth. Website: earmarkiq.app

What read-only access is actually for

The point of a reading permission is not the reading. It is what you can build on top of it: spending categorised without you sorting it, subscriptions surfaced before the price rise lands, and a payday allocation that updates itself. earmarkIQ does that from AIS data alone.