What is Open Banking?
Open Banking is a UK-regulated system that lets you securely share your bank data with trusted third-party apps. It was introduced in 2018, led by the Competition and Markets Authority (CMA) and enforced by the FCA.
The original problem it solved was simple: your financial data was locked inside each bank. If you had accounts across Barclays, Monzo, and a Halifax credit card, there was no way to see everything in one place. You either logged into three apps and added up the numbers yourself, or you handed a third-party app your actual bank password, which is exactly as bad an idea as it sounds. Open Banking replaced that with something better.
How It Works
- . You choose to connect. No app can access your data without your explicit consent.
- . Read-only access. Open Banking provides a read-only view of your accounts. No one can move your money.
- . Bank-level security. Data is transferred using encrypted APIs, the same technology your bank uses.
- . Revoke any time. You can disconnect an app instantly through your bank's app or website.
The key word in all of that is "read-only", and it is worth pausing on what it actually means. Even if a third-party app were breached tomorrow, the attacker would see the same transaction list you see. They could not initiate a payment, transfer money out, or change your account details. The connection simply does not have that capability.
Is It Safe?
Yes, and not in the vague way a marketing page tells you so. Open Banking is:
- Regulated by the FCA. Only authorised firms can access the APIs.
- PSD2 compliant. EU-origin regulation with strong consumer protections.
- Bank-grade encryption. 256-bit TLS encryption on all data transfers.
- Consent-based. Your bank confirms every connection.
- No passwords shared. You never give your bank login to the third-party app.
The FCA authorisation piece matters more than most people realise. Any company that wants to use Open Banking APIs has to pass a formal approval process. They cannot just sign up and start pulling data.
How CoreFi Uses Open Banking
CoreFi connects to your bank accounts via TrueLayer, an FCA-regulated Open Banking provider. We fetch your balances and transactions to give you a single view of your finances. Your bank credentials never touch our servers.
Common Concerns
"Can they spend my money?" No. Open Banking is read-only. It is a window into your account, not a key to it.
"What if the app is hacked?" Even if a breach occurred, attackers cannot move money. They would only see the same data you see in the app.
"Can I stop sharing?" Yes, instantly. Revoke access through your bank app, the third-party app, or the Open Banking directory. Most major UK banks have a dedicated permissions screen where you can see and cancel every active connection.