Shiv Patel · Chartered Accountant (ICAS)
Tax year 2026/27Published Last reviewed Checked for 2026/27 rates
Is open banking safe? What an app is allowed to do
Open banking in the UK is regulated, and the honest answer turns on a detail most articles skip: the permission the app holds. Account information services read your accounts. Payment initiation services move money. They are separate regulated activities[1], and an app can be allowed to do one and not the other.
How do people normally decide an app is safe?
Most of us judge a finance app the way we judge a restaurant - by signals. A four-and-a-half-star rating on the App Store. A privacy policy that mentions encryption. The fact that someone at work already uses it. The more careful users go further and skim the terms, or look up the company underneath on Companies House.
None of that is foolish. Those signals do correlate with a firm that takes care. But none of it addresses the fear underneath the search, which is usually narrower than “is my data safe”. It is: if I connect this to my current account, can it take money out. That one has a precise answer in UK regulation, and the answer does not depend on believing anybody’s marketing page.
What does the FCA actually regulate?
The Payment Services Regulations 2017 brought two activities under regulation for the first time - account information services and payment initiation services[1]. The two sound alike. They are not.
An account information service is an online service that provides consolidated information on one or more payment accounts held with other payment service providers[1]. In consumer language, the FCA describes an account information service provider (AISP) as one that lets you “see information from all your selected accounts in one place” and can analyse your spending[2]. Reading and presenting. That is the whole activity.
A payment initiation service is an online service that initiates a payment order at the request of the user, from an account held at another payment service provider[1]. The FCA’s consumer wording is that a payment initiation service provider (PISP) lets you “pay companies directly from your bank account” rather than going through a debit or credit card[2]. Moving money. A different activity, regulated separately.
The FCA is responsible for ensuring AISPs and PISPs are registered or authorised[1], and the bar is deliberately not the same for each. A business providing payment initiation services must be authorised and hold minimum initial capital of €50,000[1]. A business that carries on only account information services has a lighter route - it can become a registered account information service provider, with no capital requirement and fewer conditions than an authorised firm[1]. The regime treats the ability to move money as the riskier thing and prices the permission accordingly.
Can a budgeting app move my money?
Not where the firm behind the connection holds an account information permission only. This is the part that goes missing in the usual reassurance, so it is worth saying flatly: a firm “must be authorised or registered and have permission for the right activities”[2], and payment initiation is its own activity with its own authorisation and its own capital requirement. A firm registered to read accounts has not been permitted to initiate payments. That is not a policy it has generously adopted - it is the limit of what it is allowed to do.
Consent points the same way. Firms can only provide account information services or payment initiation services where you have given explicit consent[2], and the consent you give when you link an account to a budgeting app is a consent to share information. There is no payment instruction folded inside it.
How do I check an app on the FCA register?
The FCA’s instruction to consumers is direct: “You can check our Financial Services Register to find out if a firm is authorised or registered by us”[2]. It takes about two minutes.
A worked example: two minutes on the register
- Find the regulated entity, not the brand. Plenty of apps do not hold the permission themselves - they connect through a regulated provider and operate as that provider’s agent. The app’s terms, privacy policy or website footer normally names the entity, with wording like “authorised and regulated by the Financial Conduct Authority” and a firm reference number (FRN).
- Search that name or FRN on the Financial Services Register at register.fca.org.uk. The FRN is the quicker search, because trading names repeat and rarely match the legal entity exactly.
- Read the record, not the headline. A directly authorised firm lists account information and payment initiation separately - this is where the “permission for the right activities” test[2] becomes something you can see for yourself, and where payment initiation is absent the firm has no permission to move money. An agent’s record looks different: it shows “PSD agent” and the principal it acts for, not a permissions list.
- Check the status is current and that the contact details on the register match the ones the app gave you. The FCA warns that a clone firm is “a copy of a genuine, authorised firm” whose operators pretend to work for the real one[3] - the details on the register are the ones worth trusting.
- If the app is an agent, open the principal’s entry. Agency is normal in open banking. The permission sits with the principal, so the principal’s record is the one that answers the question.
The same five steps work on any app that asks for a bank connection - Surplus included. A firm that makes step 1 hard is telling you something.
What protects me if something goes wrong?
Complaints come first. An AISP or PISP must respond to your complaint within 15 days, unless there are exceptional circumstances[2]. That deadline exists because the firm is inside the regime - and if a firm is not authorised or registered, you will not have access to the Financial Services Compensation Scheme or the Financial Ombudsman Service[2]. The two-minute register check is how you confirm those routes apply before you connect.
The money route runs through your own bank. For a payment from your account that you did not authorise, the FCA tells consumers to contact their bank as soon as possible and claim a refund[2] - not the app, not the app’s support inbox. Your bank is the counterparty for the payment, so it is the counterparty for the refund.
Access also has a shelf life. Third-party providers are required to obtain explicit consent from customers at least every 90 days[4], so a connection that nobody renews simply stops.
How this looks in Surplus
Run this check on Surplus and you’ll see “PSD agent”. That label appears because Yapily Connect, the principal, holds payment-initiation permission as a firm - it offers that service to other clients. It is not the service Surplus has been appointed for. The consent you grant when connecting is account information only - no payment instruction exists inside it.
Surplus connects to UK current accounts and cards through read-only Open Banking provided by Yapily. The appointment behind the connection is account information only, so Surplus cannot move your money. Your bank login is never shared with or stored by Surplus, because the authentication happens with your bank, and access can be revoked from the app or from your bank whenever you want.
Every figure above is cited to its source where it appears and re-verified against the source whenever UK rates move.
Sources
Every figure above is checked against these primary sources - and re-checked whenever the rates move.
| Source | Accessed |
|---|---|
| Account information and payment initiation services - FCA www.fca.org.uk/consumers/account-information-payment-initiation-services | |
| Account information services and payment initiation services - FCA www.fca.org.uk/firms/account-information-services-payment-initiation-services | |
| Strong customer authentication - FCA www.fca.org.uk/firms/strong-customer-authentication | |
| Using the Financial Services Register - FCA www.fca.org.uk/consumers/using-financial-services-register |
Common questions
How do I revoke an app's access to my bank accounts? +
Access runs on explicit consent, so it ends when the consent does. Most apps carry a disconnect option in their own settings, and UK banks list connected third parties inside their app or online banking - often under open banking, data sharing or connected apps - where access can be withdrawn directly with the bank.
What can an account information provider actually see? +
Consolidated information from the accounts you selected - balances, transactions and the details your bank returns with them. Nothing from accounts you did not include. Before you sign up, the firm has to make clear what the service covers, how it will use your data and whether it shares that data with anyone else.
What is the 90-day rule in open banking? +
Third-party providers have to obtain explicit consent from customers at least every 90 days, so an open banking connection expires unless it is renewed. Since the SCA-RTS Article 10A exemption took effect in March 2022, banks that adopt it no longer make you reauthenticate every time an app reads your account information.
What protection do I have if an open banking app gets something wrong? +
Complain to the provider first - an AISP or PISP has to respond within 15 days, unless there are exceptional circumstances. Where the firm is authorised or registered, the Financial Ombudsman Service is the escalation route. For a payment you did not authorise, the FCA points you to your own bank to claim a refund.
Researched and written by Shiv Patel, chartered accountant (ICAS), with AI drafting assistance. Every figure is checked against the cited source. Guidance, not personal advice.