UK Open Banking gives regulated firms two separate permissions. Account Information Services (AIS) lets an app read your accounts. Payment Initiation Services (PIS) lets it start a payment that you then authorise at your own bank. They are granted separately, and an app holding one does not hold the other. In both cases you authenticate at your bank rather than handing over a password, your consent has to be reconfirmed at least every 90 days, and you can withdraw it at any time from your bank’s own app.
What Open Banking actually is
Open Banking is a UK framework, live since 2018, that lets you instruct your bank to share your account data — or to accept a payment instruction — through an authorised third party. It came out of a Competition and Markets Authority order and the second Payment Services Directive, and it is supervised by the Financial Conduct Authority.
The problem it was built to solve is worth remembering, because it explains the design. Before Open Banking, an app that wanted to see your transactions had to log in as you, using credentials you had handed over. That practice, screen scraping, gave the app everything your account could do and left you outside your bank’s fraud protections. Open Banking replaced it with something narrower: you authenticate at your own bank, on your bank’s own screen, and the bank releases a limited, time-bound, revocable feed to a firm the FCA has authorised.
The practical rule that follows is short. No legitimate UK app will ever ask you to type your online banking password into its own interface. If one does, close it.
AIS and PIS: the two permissions
Almost every misunderstanding about what money apps can do comes from not knowing these are separate.
| Account Information (AIS) | Payment Initiation (PIS) | |
|---|---|---|
| What it permits | Reading balances and transactions | Starting a payment you then authorise |
| Direction of travel | Data out of the bank | An instruction into the bank |
| Can money move? | Never | Yes, with your authentication each time |
| Who authenticates you | Your bank | Your bank, per payment |
| Typical use | Budgeting, categorisation, net worth, subscription tracking | Paying a bill, topping up savings, checkout at a merchant |
| Firm must be | An authorised or registered AISP | An authorised PISP |
A budgeting app operating under AIS cannot move a penny. Not because it has promised not to, and not because a setting is switched off, but because the permission it holds is a reading permission. There is no payment instruction it is able to construct. This is the most reassuring fact about UK money apps and the least widely known.
PIS is not a sinister capability either — it is what sits behind “pay by bank” at an online checkout. The important feature is that it is not a standing power. Each payment is a separate instruction that you authorise with your bank, seeing the amount and the payee, exactly as you would a manual transfer. A PISP cannot help itself to your account later.
What an AIS app can and cannot do
| Can | Cannot |
|---|---|
| Read balances across your connected accounts | Move money between your accounts |
| Read transaction history and categorise it | Make a payment to anyone |
| Spot recurring payments and price rises | Cancel a direct debit or standing order |
| Work out net worth from what it can see | Change your overdraft, limits or account settings |
| Show you trends, forecasts and suggestions | Apply for credit in your name |
| Export or share data where you ask it to | Access accounts you have not connected |
The right-hand column trips people up in a specific way: because an app can see a subscription, users often assume it can cancel one. It cannot. Cancelling a recurring card payment or a direct debit is something you do with your bank or the provider. A good app will find it, tell you what it costs, and tell you where to go — and that is the boundary of what AIS allows.
Consent: scope, duration and reconfirmation
Consent under Open Banking is narrower than most people assume, and it expires.
Scope is set when you connect. You choose which accounts to share, and the permission covers those accounts and the data types the app requested — not everything you hold at that bank, and not accounts you add later unless you connect them too.
Duration is finite. Access is time-bound rather than perpetual. Under the FCA’s rules, introduced in PS21/19 and in force since 26 March 2022, a firm relying on the Article 10A exemption must obtain your explicit consent again at least every 90 days. Where a bank has not adopted that exemption, you may instead be asked to reauthenticate with the bank itself on a similar cycle. Either way, an Open Banking connection you set up and forget about does not quietly run forever — something will ask you to confirm it is still wanted.
Data minimisation applies throughout: a firm should request only what it needs for the service it provides, and should not be hoovering up categories it has no use for.
Consenting to share data with an app is not the same as agreeing to the app’s terms, and neither is the same as authorising a payment. Under AIS there is no payment to authorise at all. If you are ever shown a payment authorisation screen by a budgeting app that told you it was read-only, stop.
How to revoke, and what happens next
You have two independent routes, and you do not need the app’s cooperation for either.
Through your bank
Every UK bank offering Open Banking must let you see connected third parties and withdraw access, usually under a heading such as “connected apps”, “data sharing” or “third party access” in the app or online banking. Revoking there stops the data feed at source.
Through the app
The app should also let you disconnect an account or close your account entirely, and deal with data held under its privacy policy and your UK GDPR rights.
Revoking stops future access. It does not, by itself, delete data the app has already collected — that is governed by the app’s retention policy and your right to erasure, which is a separate request. If deletion is what you want, ask for it explicitly rather than assuming disconnection achieved it. Nothing about revocation affects your bank account, your payments, or your credit file.
What FCA regulation gets you in practice
“FCA regulated” is used loosely enough to be worth unpacking. A firm is either directly authorised, or an Appointed Representative operating under a principal firm that is and which carries regulatory responsibility for its conduct. Both appear on the FCA register, which is public, free and not controlled by the firm. Checking takes a minute and is the single most useful thing you can do.
What regulation actually gets you:
- Rules on handling financial data that sit on top of UK GDPR, specific to payment services.
- Consumer Duty obligations — to act to deliver good outcomes, communicate clearly, avoid foreseeable harm, and make leaving as easy as joining.
- Access to the Financial Ombudsman Service if a complaint cannot be resolved with the firm, with the power to make binding decisions.
- Supervision, meaning someone can take enforcement action rather than merely being disappointed.
What it does not get you, and this matters just as much:
- It is not a guarantee the product is any good. Regulation sets a floor for conduct, not a standard for quality.
- It is not protection against your own decisions. A regulated app showing you accurate data can still be the backdrop to a poor choice.
- It is not FSCS cover for the app. Deposit protection applies to money held at an authorised deposit-taker. A budgeting app is not holding your money, so there is nothing for FSCS to protect — which is a feature, not a gap.
- It does not make the firm solvent. If it closes, your bank accounts are unaffected, because they were never with the app.
Where earmarkIQ sits
earmarkIQ operates under AIS only. Bank connections run through Finexer Ltd (FRN 925695), an FCA-authorised provider, with earmarkIQ as an Appointed Representative — verifiable on the register. The connection is read-only: earmarkIQ reads balances and transactions, categorises them, and builds things like a payday allocation and a net worth figure on top. It cannot move money, because AIS does not permit it to.
On payment initiation, the accurate position is this: PIS sits within the permissions earmarkIQ operates under and is on the roadmap, but it is not enabled today. earmarkIQ does not initiate payments. If it is ever switched on, it will work the way PIS works everywhere — a payment you start, with an amount and a payee you see and confirm, authenticated by you at your own bank, one at a time. It would not be a standing power, and nothing automated, including any assistant connected through earmarkIQ Context, would be able to trigger it.
We have written the longer argument about that boundary in the difference between an app that shows you your money and one that moves it. It is the distinction we think people should be asking every provider about, including us.
Frequently asked questions
About earmarkIQ
earmarkIQ is a UK personal finance app for iOS and the web. It is an FCA Appointed Representative of Finexer Ltd (FRN 925695) and ICO registered (CSN2001882). It connects to UK bank accounts through read-only Open Banking, categorises spending automatically, builds a payday allocation plan, and tracks subscriptions, property equity and net worth. Website: earmarkiq.app