MyBankAnswers — Clear answers. Brighter banking. MyBankAnswers CLEAR ANSWERS. BRIGHTER BANKING.
Your trusted
banking companion
DIGITAL BANKING

Is Open Banking safe in the UK? What customers should check

Open Banking can let regulated services access account data or initiate payments with your permission. The security model is designed so you authenticate with your own bank rather than handing passwords to the third-party app.

Quick answer

Open Banking is designed around regulated access, explicit consent and secure APIs. Before connecting a service, check who provides it and whether the firm is appropriately regulated. You should normally authenticate with your own bank or building society and should not give your online-banking password or PIN directly to an unrelated third party.

Open Banking is not the same as sharing your password

In a normal Open Banking journey, a third-party provider redirects you to your bank or uses the bank’s secure authentication flow. You approve what data or payment access you are granting, and the service receives permission through an API. Open Banking Limited states that customers should not have to give their bank login details, PIN or password to anyone other than their own bank or building society.

Advertisement

That distinction is an important scam test. If a budgeting app, lender or payment service asks you to email a full banking password or read out a PIN, stop. A polished interface does not make an unsafe request legitimate. Re-enter the journey from the provider’s official site and verify the firm before connecting anything.

Check that the provider is regulated and identifiable

Open Banking services are provided by regulated firms or by businesses using a regulated technical provider. Check the provider name shown in the consent journey and use the FCA register or the Open Banking directory where appropriate. Be cautious when the trading name in an advert is different from the legal firm requesting access; the connection screen should make clear who is involved.

Regulation does not mean every product is suitable or every commercial decision is good. It tells you something about authorisation and oversight, not whether a budgeting subscription, lending offer or data-analysis service is worth paying for. Security and value are separate questions.

Consent should be specific and controllable

A good Open Banking flow tells you what information will be shared, for what purpose and for how long. Data access can include balances, transactions or account details depending on the service. Payment initiation is different again because you are authorising a payment action. Read the consent screen instead of tapping through because the scope matters.

You can normally withdraw permission, but ending data access does not necessarily cancel a separate subscription contract with the app. If you stop using a service, revoke the banking connection and deal with the commercial account as well. Review connected apps periodically so old permissions do not remain simply because you forgot about them.

Advertisement

Protect the phone and email that sit around Open Banking

API security cannot protect you from every problem if the phone itself is compromised. Keep the operating system and banking apps updated, use a strong device lock and enable two-step verification on important email accounts. Do not approve an Open Banking connection while screen-sharing with an unsolicited caller who claims to be helping with fraud.

If a scammer persuades you to authorise a payment yourself, the technical connection may work exactly as designed while the underlying instruction is fraudulent. Read the payee and amount on the bank’s confirmation screen and treat urgency as a warning sign.

What to do if a connected service looks wrong

Revoke the connection through the bank or service where possible and contact the bank if you see an unauthorised transaction or unfamiliar consent. Change passwords if you disclosed credentials outside the proper banking flow. If you believe a regulated provider mishandled data or payments, use its complaint process and keep screenshots of the consent you thought you were giving.

Do not reconnect repeatedly just to test whether the problem disappears. First establish which firm is requesting access and why. The strength of Open Banking is that permissions can be narrow and explicit; use that transparency to decide whether a connection still belongs in your financial setup.

Review permissions after the reason for sharing ends

Open Banking access should have a purpose. If you connected an app to compare bills, complete a loan application or test a budgeting tool and no longer use it, remove the connection through the bank or provider. Old permissions can create unnecessary data exposure even when the service itself is legitimate.

Keep in mind that revoking data access is not necessarily the same as cancelling a paid subscription or deleting an account with the third party. Close each relationship deliberately: stop access, deal with any subscription and retain confirmation where the service held sensitive financial information.

When a service uses Open Banking to make a payment, pause at the final bank-authentication screen and verify payee, amount and purpose. A regulated connection cannot tell whether a fraudster persuaded you to make a bad purchase. Technical security protects the channel; customer judgement still protects the reason for the payment.

Advertisement
RELATED GUIDES

Continue with these related banking guides

DIGITAL BANKINGMobile banking on a new phone: what UK customers should doRead guide →DIGITAL BANKINGUsing virtual cards inside a banking app: what UK customers should knowRead guide →DIGITAL BANKINGHow to check whether a banking app is really down: practical guidance for UK bank customersRead guide →

Sources and verification

MYBANKANSWERS EXPERT VIEW

Daniel Foster — Digital Banking Editor

I am comfortable using Open Banking when I can answer three questions: who is the regulated provider, what exact permission am I granting, and how can I revoke it? The security architecture is much better than the old habit of giving a third-party service your banking password. Authentication should stay with your bank. But secure technology does not remove social-engineering risk. A criminal can still persuade someone to authorise a real payment or connect a service for the wrong reason. I therefore read the consent screen and the bank confirmation screen as two separate security checkpoints. I also review old connections every few months, because a service I stopped using last year does not need current transaction data today. If an app asks for a full PIN, password or one-time code outside the bank’s own authentication flow, I would stop immediately. Open Banking is safest when the customer uses the control it was designed to provide, rather than treating every connection request as routine. The healthiest Open Banking habit is periodic permission hygiene. I want every connected service to have a current reason for seeing current data; if I cannot explain the reason, I remove the connection.

MyBankAnswers uses official provider and UK regulatory sources wherever practical. Information is general and does not constitute financial advice.