Open banking & trust

Open banking, explained — and why it is safe

Open banking is the regulated system that lets you securely share your transaction data with an app you choose — without ever handing over your online banking password.

What open banking replaced

Before open banking, an app that wanted to see your transactions had one option: ask for your internet banking username and password and log in as you. That pattern is called screen scraping, and it worked, but it asked you to hand over the keys to everything in order to share one thing. It also gave you no way to see what the app was doing, and no way to switch it off except by changing your password.

Open banking replaces that with a regulated handshake. You authorise the connection inside your own bank’s official login flow, the bank issues the app a limited, revocable permission, and no credential ever passes through the app at all. The improvement is not only technical — it is that the arrangement becomes visible and reversible, listed in your banking app alongside every other permission you have granted.

The result is the same useful outcome with a much smaller surface: an app that can read what you agreed to share, for as long as you agreed to share it, and nothing else. That is why the connection is worth understanding before you make one — not because it is risky, but because knowing what it can and cannot do is what makes the choice an easy one.

How the connection actually works, step by step

Start the connection in the app and pick your bank. The app does not ask for your details; it redirects you to your bank’s own authorisation page or app, where the address bar shows your bank’s domain. That redirect is the whole security model in one step — you type your credentials only where you always type them.

Your bank then shows you exactly what is being requested: which accounts, which kinds of data, and for how long. You approve or decline, account by account. If you approve, your bank sends the app a token — a limited permission slip that names the app, the accounts and the scope, and expires on a date. The app stores the token and never sees the password that produced it.

From then on the app uses that token to request transactions on a schedule, and the ongoing sync is simply that request repeating. If you change your banking password, the token keeps working, because it was never derived from your password in the first place.

Fin sits outside these accreditation regimes, and is upfront about it. Bank data reaches Fin through a read-only feed you connect yourself with a key you own — BankSync or SimpleFIN, or Akahu, Up Bank, Monzo or Starling in the desktop app — or through a CSV or XLSX statement or a Google Sheet feed. The connection flow and the ongoing sync describe how that works in practice; either way, your banking password is never handed to Fin.

What "read-only" means in practice

A read-only connection can see transaction history and balances on the accounts you named. It cannot move money, set up a payment, add a payee, change your details, or open or close anything. It is the same category of access as looking at a statement, and the payment side of open banking is a separate permission with its own, much louder authorisation step that a data connection never touches.

It is also narrower than "your bank". You approve specific accounts, so an everyday account can be shared while a mortgage offset or a joint account stays out of scope entirely. Adding another account later is a new approval rather than an extension of the old one, which is worth knowing if you expect a second account to appear on its own and it does not.

What the app receives is descriptive rather than complete: dates, amounts, balances and the descriptor text the bank puts on each line. That descriptor is often abbreviated and occasionally cryptic, which is a genuine limitation rather than a security one — what a tool can read from a transaction is bounded by what the bank chose to send.

Who is allowed to ask

Access is not open to anyone who wants to build it. In every jurisdiction with a live regime, the app on the other end has to be authorised, and the authorisation carries obligations about security, data handling, complaints and breach reporting. That gate is what turns "an app can read your bank data" from a worrying sentence into an ordinary one.

The shape varies by country. Australia runs the Consumer Data Right, with data recipients accredited by the competition regulator and privacy obligations overseen alongside it. The United Kingdom built its regime under a competition order, with the firms involved authorised by the financial regulator. The European Union set the rules through payment services legislation that obliges banks to offer regulated third parties access. India uses a licensed Account Aggregator sitting between you and your institutions, and Brazil runs a central-bank-led Open Finance programme.

Others are still arriving. Canada has been legislating a consumer-driven banking framework, New Zealand has been building its own regime, and the United States has been developing rules for personal financial data rights under its consumer protection law. Where a regime is not yet live, connections in that market usually still run through an established data provider under contract with the banks, which is a different legal basis with a similar practical effect.

When open banking is not available

Coverage is real but not universal. Smaller institutions, some business accounts, most payment platforms and nearly every credit product outside the major banks sit outside the regimes today, and a regime that covers personal accounts does not always cover business ones. That gap is normal and worth planning around rather than waiting out.

The fallback is your own statements. Every bank in the world will give you an export — CSV, Excel, OFX or a PDF — and a good tool should read those as first-class input rather than as a degraded mode. Importing a long stretch of statements gets an account that no feed reaches to exactly the same place as one that a feed does reach, which matters when the account outside the regime is the one your business actually runs on.

Whichever route the data takes, the value only appears once it is sorted, and that is where the habit side begins: bookkeeping for freelancers covers what to do with a feed once you have one. A connection is a starting point rather than an outcome — the point of removing the typing is that the deciding gets your attention instead.

Common questions

Can an app move my money through an open banking connection?

No — a read-only connection can only view transaction data. Moving money requires a separate, explicit payment authorisation that a read-only feed does not grant.

Does the app ever see my banking password?

No. Authorisation happens directly on your bank’s own login page or app — the connecting service never receives or stores your credentials.

Can I disconnect at any time?

Yes. You can revoke access whenever you like, and the connection stops immediately — see the security & trust page for exactly how that works.

What is the difference between open banking and screen scraping?

Screen scraping means giving an app your internet banking username and password so it can log in as you, which grants everything your login grants and can only be withdrawn by changing the password. Open banking issues the app a limited token through your bank’s own authorisation flow, scoped to named accounts and a fixed period, revocable from your banking app, with no credential ever leaving your bank.

How long does a bank data-sharing consent last?

It is set when you grant it and it expires by itself — commonly up to a year, sometimes shorter, depending on the regime and what you chose. When it lapses the requests simply stop until you renew, which is why a connection you set up long ago may quietly go quiet rather than run forever. Your banking app lists every arrangement you have granted along with its expiry.

Which of my accounts does an open banking connection cover?

Only the ones you tick during authorisation. You approve account by account, so an everyday account can be shared while a savings, offset or joint account stays out of scope entirely. Adding another account later is a fresh approval rather than an automatic extension, which is the usual reason an account you expected to appear has not.

What happens to my data if I disconnect the bank?

Requests stop immediately, because the token stops being honoured. Under most regimes the provider is then obliged to delete or de-identify the data collected under that consent, and a well-built product will tell you which it does. Revoking from inside your banking app is the stronger route, since it stops access at the bank rather than relying on the app to stand down.

Sources

  1. Consumer Data Right (Australia) — The Australian regime: accreditation of data recipients, consent, and how to withdraw it
  2. Open Banking (United Kingdom) — How UK open banking authorisation, consent and revocation work
  3. CFPB (US) — Consumer tools — US Consumer Financial Protection Bureau material on personal financial data rights and account access

General information computed from published government guidance, not personal tax advice.

Let Fin handle it automatically

Connect your bank and Fin keeps this sorted for you all year — free to start, no card needed.

Get 2Fin free →

Back to all guides, or explore the glossary.