Skip to content

Open Banking

Open banking is the framework under which a bank must hand a customer's own account data to that customer, or to a company the customer authorizes, through an interface built for the purpose. In the United States it is the Consumer Financial Protection Bureau's word for what its personal financial data rights rule, 12 CFR part 1033, is meant to build.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • Open banking describes a design rather than a product. The account data sits with the institution, and the framework decides on what terms it leaves.
  • The statute is section 1033 of the Consumer Financial Protection Act, 12 U.S.C. 5533, enacted in 2010 and expressly conditioned on rules the Bureau had not yet written. The rule arrived in November 2024.
  • Most of the rule's weight falls on the bank, not on the app. It must build and maintain interfaces, meet a stated reliability floor, and charge nothing for either.
  • Coverage is narrower than most readers expect. It reaches checking, prepaid and other Regulation E accounts and credit cards, not mortgages, auto loans, student loans or brokerage accounts.
  • Duties phase in by institution size on a schedule beginning April 1, 2026 and running to 2030, and the smallest depository institutions sit outside them, so what any one bank owes today is a question about that bank.

Definition

Open banking is the framework under which a consumer can direct the institution holding their financial accounts to release the data in those accounts, either to the consumer or to a third party the consumer has authorized, through a standardized interface rather than by screen-scraping or a mailed statement. In the United States the name is the regulator's own: the Consumer Financial Protection Bureau's rule appendix on standard setters describes section 1033 of the Consumer Financial Protection Act as the provision that "describes the CFPB's role in implementing open banking." The idea and the rule are not the same thing. Open banking names a design that several countries have approached differently; 12 CFR part 1033, titled Personal Financial Data Rights, is the American implementation of it.

Advanced Explanation

The statute came first by fourteen years, and the delay is the reason the subject reads as new. Section 1033 of the Consumer Financial Protection Act, codified at 12 U.S.C. 5533 and headed "Consumer rights to access information", was enacted with the rest of the Dodd-Frank Act in 2010. It says that a covered person "shall make available to a consumer, upon request, information in the control or possession of the covered person concerning the consumer financial product or service that the consumer obtained", in an electronic form usable by consumers. But it opens with the words "Subject to rules prescribed by the Bureau", and for fourteen years no such rules existed. The Bureau published its final rule on November 18, 2024, and it is codified at 12 CFR part 1033.

What the rule covers is narrower than the phrase suggests, and this is the single most useful thing to know before expecting anything of it. Section 1033.111(b) defines a covered consumer financial product or service as three things: a Regulation E account, which is a consumer asset account as defined in 12 CFR 1005.2(b) and takes in checking, savings and prepaid accounts; a Regulation Z credit card; and the facilitation of payments from either, with first-party payments such as loan servicing carved out. A mortgage, an auto loan, a student loan, an insurance policy and a brokerage or retirement account are all outside it. So a consumer who expects a legal right to pull every account they own into one place will find the right stops at the transaction accounts and the cards.

The obligations run at the institution, and that is what separates open banking from the practice of aggregation. Section 1033.301(a) requires a covered data provider to maintain two interfaces: a consumer interface, which is ordinary online banking, and a developer interface for authorized third parties. Section 1033.301(c) prohibits any fee for building or maintaining them or for responding to requests. Section 1033.311(b) requires the developer interface to deliver data in a standardized, machine-readable format. Section 1033.311(c)(1) sets a floor most consumer rules do not attempt: proper responses divided by total requests must be at least 99.5 percent in each calendar month, with properly noticed scheduled downtime excluded from both sides of the fraction. Section 1033.311(d) bars unreasonable caps on how often an authorized third party may ask. And section 1033.201(a)(2) forbids a data provider from acting with the intent of evading the rule, or in a way it knows or should know is likely to make the data unusable or to materially discourage access.

One provision in subpart C decides how the plumbing has to work. Section 1033.311(e)(1) says a data provider "must not allow a third party to access the data provider's developer interface by using any credentials that a consumer uses to access the consumer interface." Where the rule binds, in other words, the bank may not satisfy it by letting an outside company log in as the customer. The consumer-facing consequences of that choice, and the older credential-based method it displaces, belong to the account aggregation page.

A bank may refuse access, but the refusal has to be defensible. Section 1033.321 lets a data provider deny a third party without breaching its general obligation, if granting access would be inconsistent with policies reasonably designed to meet prudential safety and soundness standards, the information security standards under section 501 of the Gramm-Leach-Bliley Act, or other risk-management law, and if the denial is reasonable. Reasonable is defined: directly related to a specific risk the provider is aware of, such as a third party's failure to maintain adequate data security, and applied consistently and without discrimination. Section 1033.221 separately lists what need not be released at all, including confidential commercial information such as a scoring algorithm, information collected solely to prevent fraud or money laundering, information another law requires to be kept confidential, and information the provider cannot retrieve in the ordinary course of business. The first exception carries its own limit: a figure does not become confidential merely because an algorithm produced it, and the rule names annual percentage rate and other pricing terms as examples that stay disclosable.

The American design leans on private standard bodies rather than a government-built interface, and section 1033.141 is where that choice lives. A standard-setting body may ask the CFPB to recognize it, recognition lasts up to five years absent revocation, and the body must demonstrate five attributes: openness, meaning its processes are open to consumer and public-interest groups as well as to banks and aggregators; balance, meaning no single interest dominates decision-making; due process and appeals; consensus, defined as general agreement though not necessarily unanimity; and transparency. Appendix A to the part is the application instruction. Conformance to a recognized standard is then used throughout subpart C as evidence that a provider's format, downtime and response times are acceptable. The regulator sets the outcome and delegates the specification.

A reader also gets something to check. Section 1033.341 requires a covered data provider to publish, at least as visibly as it would on a public website and in both human-readable and machine-readable form, its legal name and any assumed name, a link to its website, its Legal Entity Identifier, contact information for questions about data access, documentation for its developer interface, and, by the last day of each month, the response rate its developer interface achieved the previous month, as a percentage to four decimal places, with a rolling thirteen months shown. Section 1033.351 requires written policies and procedures behind all of it.

Both the timing and the future of the rule are live questions, and neither should be stated flatly. Compliance is staged by size under section 1033.121(b), beginning April 1, 2026 for the largest institutions and stepping down each April through 2030, and section 1033.111(d) leaves depository institutions at or below the applicable Small Business Administration size standard outside subparts B and C altogether. Separately, the Bureau published an advance notice of proposed rulemaking headed "Personal Financial Data Rights Reconsideration" on August 22, 2025, so the content of the rule is under reconsideration even though the rule is codified. One of the four questions that notice puts up for comment is the approach to fees a covered person may charge for responding to a consumer-driven request, which is the same no-fee rule described above. Anyone relying on a specific duty should check both the institution's size and the current state of the rule.

Used in a Sentence

“The bank's product team spent most of 2026 on open banking work, because the developer interface, its documentation and the monthly performance figure all had to exist before the compliance date rather than after it.”

How It Works

In outline, the framework has four moving parts. A data provider, meaning the institution holding a covered account, builds and maintains a developer interface alongside its ordinary online banking. A third party the consumer has authorized asks that interface for covered data. The provider answers, without charge, in a standardized machine-readable format, unless one of the narrow exceptions applies or it has a defensible risk-based reason to refuse. And the provider publishes enough about itself, its documentation and its own reliability that the arrangement can be inspected from outside.

A hypothetical showing how the reliability floor is actually measured. Suppose a covered bank's developer interface receives 2,000,000 requests for covered data in a calendar month, all outside any properly noticed scheduled downtime. Of those, 12,000 draw no proper response, because the reply neither fulfilled the request nor explained why it was not fulfilled, which is the first of the three things section 1033.311(c)(1)(iv) requires of a proper response. The proper responses are 2,000,000 minus 12,000, or 1,988,000. Dividing that by 2,000,000 gives 0.994, which is 99.4 percent. That sits below the 99.5 percent minimum in 12 CFR 1033.311(c)(1), so the interface's performance is not commercially reasonable for that month on the specification's own terms, and the figure the bank must publish under 1033.341(d) would show it. Had 8,000 requests failed instead, the rate would be 1,992,000 divided by 2,000,000, or 99.6 percent, and the specification would be met.

Pros and Cons

Pros

  • It replaces an informal arrangement with a written one. Before the rule, a consumer's ability to move their own account data depended on what each bank chose to allow.
  • The duties sit on the institution, including a prohibition on charging for access, so the cost of the framework does not land on the customer.
  • The reliability floor and the monthly performance disclosure are unusually concrete, which makes a provider's compliance checkable rather than a matter of assertion.
  • Barring third-party access through consumer credentials pushes the market toward connections that do not require handing over a banking password.
  • Recognized standard setters must admit consumer and public-interest groups and keep decision-making balanced, so the specification is not written by the largest participants alone.

Cons

  • Coverage stops at Regulation E accounts and credit cards, so mortgages, auto and student loans, insurance and investment accounts are outside it.
  • The duties phase in by institution size through 2030, and the smallest depository institutions never acquire them, so a reader's own bank may owe nothing today.
  • The exceptions are real. A provider may withhold confidential commercial information and anything it cannot retrieve in the ordinary course, and may refuse a specific third party on documented risk grounds.
  • Delegating the specification to recognized standard setters means the working detail lives in private documents rather than in the regulation.
  • The Bureau opened a reconsideration of the rule in August 2025, so the framework's content is a policy question rather than a settled one.

People Also Asked

Answers to the most frequently asked questions.

Is open banking the same thing as account aggregation?
No, though they meet in the middle. Account aggregation is the practice of pulling a person's balances and transactions from several institutions into one place, and it existed for years before any rule required it. Open banking is the policy framework that decides on what terms an institution must release that data, and most of its obligations are duties of the bank rather than of the app or the aggregator. Aggregation can happen without open banking, by signing in as the customer, and open banking reaches institutions whether or not any aggregator is involved.
Which of my accounts does the US rule actually cover?
Under 12 CFR 1033.111(b) the rule reaches Regulation E accounts, which include checking, savings and prepaid accounts, Regulation Z credit cards, and the facilitation of payments from either. It does not reach mortgages, auto loans, student loans, insurance policies, or brokerage and retirement accounts. A service may still connect to those accounts by other means, but it is doing so outside this framework.
Can my bank charge me for releasing my data?
Not where the rule binds it. Section 1033.301(c) prohibits a covered data provider from imposing any fee or charge on a consumer or an authorized third party for establishing or maintaining the required interfaces, or for receiving requests and making covered data available in response. Whether a particular institution is bound depends on its size and on the compliance date that applies to it under 1033.121(b). The Bureau's August 2025 advance notice of proposed rulemaking put the fee question itself up for comment, so this is one of the parts of the rule under reconsideration.
Why did it take from 2010 to 2024 for anything to happen?
Because the statute made itself conditional. 12 U.S.C. 5533 opens with "Subject to rules prescribed by the Bureau", so the access right it describes had no operative content until the Consumer Financial Protection Bureau wrote the rules. Those arrived as the final rule published on November 18, 2024 and codified at 12 CFR part 1033, with compliance staged from April 1, 2026 onward.
Who writes the technical standards?
Private standard-setting bodies that the CFPB has recognized, rather than the regulator itself. Under 12 CFR 1033.141 a body may apply for recognition, which lasts up to five years, and must show openness, balance across interests, due process and appeals, consensus and transparency. Conformance to a recognized standard is then treated throughout the rule as evidence that a provider's data format, downtime and response times are acceptable.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Consumer Financial Protection Bureau. "12 CFR Part 1033 — Personal Financial Data Rights."
  2. U.S. Code. "12 U.S.C. § 5533 — Consumer rights to access information."
  3. Consumer Financial Protection Bureau. "Required Rulemaking on Personal Financial Data Rights" (final rule, 89 FR 90838).
  4. Consumer Financial Protection Bureau. "Personal Financial Data Rights Reconsideration" (advance notice of proposed rulemaking).

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor