From Open Banking to Open Finance: What PSD3 and the PSR Mean for Your Roadmap
Tributary's regulatory and product leads unpack the EU payments package, API performance expectations, and how the US data-rights debate is shaping product plans.
Eight years after PSD2 put open banking into law across the EU, the next generation of rules is taking shape. In this session, Tributary's regulatory and product leads explain what the new framework is likely to change and what it probably will not.
A regulation, not only a directive
The European Commission's 2023 proposals split the payments framework into a revised directive (PSD3), covering licensing and supervision of payment institutions, and a directly applicable Payment Services Regulation covering conduct rules, including open-banking access. The speakers explain why a regulation matters: it reduces room for divergent national implementation, which was a persistent source of friction under PSD2. They caution that final texts and timelines depend on the legislative process and that transition periods will apply after adoption.
API performance and permission dashboards
Among the changes discussed in the negotiations are stronger requirements for banks' dedicated access interfaces, limits on obstacles that make third-party journeys harder than a bank's own, and permission dashboards that let customers see and withdraw access they have granted. For third-party providers, the speakers argue, these could matter more than any headline change because unreliable APIs have been a main cause of failed journeys.
Beyond payment accounts
Open finance extends data sharing to savings, investments, insurance and pensions. The EU has a separate proposal for a financial-data-access framework, the UK is developing smart-data schemes, and in the US the debate over personal financial data rights under Section 1033 of the Dodd-Frank Act has continued through rulemaking, litigation and reconsideration. The speakers encourage product teams to design consent, data minimization and revocation as reusable components that will work under any of these regimes.
The session concludes with a checklist: audit current consent flows, map data fields to likely future categories, and instrument API reliability by bank so that you can evidence problems when the new rules give you a route to raise them.
More from the library
Injection Attacks and the Next Phase of Remote Identity Verification
Presentation attacks put something fake in front of the camera. Injection attacks skip the camera entirely. This paper explains the difference and the layered defenses onboarding teams need.
The Seconds Before Send: Designing Scam Interventions That Work
A conversation on why generic warnings fail, what behavioral signals reveal a coached payment, and how banks are tuning friction as reimbursement rules shift liability.
Keystone Ledgerworks Launches Verification of Payee API for Platforms and Marketplaces
Platforms that initiate SEPA transfers on behalf of users can now run payee name checks and show the four standard outcomes inside their own interfaces.