open-banking · 20 July 2026
Your banking password never leaves your bank, and that's the whole safety case
Is open banking safe? Yes, when the provider is regulated. Here's exactly how the connection works and what is and isn't shared.
By Moxim Team
This is the question we hear most, and it deserves a straight answer instead of spin: yes, open banking is safe, provided the provider is registered and regulated, and here is exactly why.
How it actually works
You click connect, get redirected to your own bank's login page, not a third-party page, and log in there. Your bank issues a time-limited, read-only token; the requesting app receives your transaction data, and no password is ever transferred. Nobody can move money, make a payment or change your account details through that connection; it is read-only, full stop.
Who regulates it
UK open banking is not a grey-area product. It is overseen by the Financial Conduct Authority and the Open Banking Implementation Entity, which sets the technical standards every provider has to meet.
What's shared, and what isn't
A typical mortgage affordability check shares transaction history, usually three to twelve months, income credits and their frequency, regular outgoings and direct debits and account balance history.
It does not share your banking password or PIN, access to accounts you haven't specifically connected, the ability to move money or personal data your bank doesn't already hold.
Can you revoke access?
Yes, and it's usually straightforward; you can revoke a provider's access at any time, either through your bank's app or by contacting the provider directly and asking them to delete your data under GDPR.
The honest caveat
Open banking is safe when the provider is registered and compliant. It is not automatically safe just because an app claims to use it; there are services operating in a grey area, unregistered or poorly secured, and the real question isn't whether open banking itself is safe, it's whether you can trust the specific provider asking for access.
Every company that accesses your data through open banking must be registered with the Financial Conduct Authority (FCA) as an Account Information Service Provider (AISP). You can check any provider's status on the FCA Register at fca.org.uk — in under 30 seconds.
Open banking, used through a registered provider, is a genuinely secure way to share financial data; the regulation is real, the technology is read-only and you stay in control throughout.
What a fake or unregistered app looks like
The clearest warning sign is being asked to enter your online banking password directly into a lender's website or a broker's portal, rather than being redirected to your own bank's login page. A genuine open banking connection never asks for your password anywhere except on your bank's own site; if a form on any other page asks for it, stop and check the provider's FCA registration before continuing.
Other signs worth checking: no mention of the Financial Conduct Authority or the Open Banking Implementation Entity anywhere in the provider's terms, no visible privacy policy explaining how long data is held, and pressure to connect an account before you have had time to read what you are agreeing to. None of these appear with a properly regulated provider, and any one of them is worth pausing over.
A worked example: two customers, two different experiences
One customer connects her account through a registered open banking provider linked to her mortgage broker's platform. She is redirected to her own bank's app, confirms a read-only consent for ninety days, and never enters her password anywhere but her bank's own login screen. Her broker receives categorised transaction data within a minute and nothing else changes about how her account works.
Another customer is asked, on a page that looks similar, to type his online banking username and password directly into a form. There is no FCA registration number visible and no redirect to his bank. This is not open banking; it is exactly the kind of screen scraping or credential harvesting that regulation was designed to replace.
Checking a provider's status on the FCA Register, covered in more detail in the step-by-step consent guide, takes under thirty seconds and would have caught the difference immediately.
What actually happens behind the screen when you connect
The mechanics are more mundane than the word open banking suggests. You are redirected away from the lender or broker's site entirely, to a login page hosted by your own bank, using the exact same login you would use to check your balance on a normal day. Your bank then asks you to confirm, in plain language, what is being requested and for how long.
Once you approve that screen, your bank sends a read-only data feed to the provider through a secure, regulated interface called an API; this is the same kind of technology your banking app itself relies on, not something bolted on for the occasion. Your password stays on your bank's own servers throughout and is never transmitted to, or stored by, the lender, broker or provider at any stage.
Why this is different from linking a budgeting app
Consumers who already use a budgeting app or a savings tracker have effectively been using open banking for years without necessarily calling it that; the underlying connection works the same way. What changes for a mortgage application is simply what the data is used for, not how securely it moves.
The same regulatory protections covered in the mortgage readiness guide apply whether the provider is checking your affordability for a mortgage or simply categorising your spending for a budgeting dashboard. That familiarity is worth remembering when a mortgage-specific request feels new or unfamiliar; the technology behind it almost certainly is not.
What lenders and brokers do to protect this data on their end
Security is not a one-sided obligation that starts and ends with the connection itself. Any lender or broker using open banking data is required to hold it under the same UK data protection law that covers a payslip or a passport copy, with defined retention limits and a lawful basis for processing it in the first place.
In practice this means the data is not kept indefinitely once a decision is made, is not sold on or shared with unrelated third parties, and is stored using the same standard of encryption expected of any regulated financial business. A customer is entitled to ask any lender or broker exactly how long their data will be retained and to request its deletion once it is no longer needed for the application.
Before you connect
Before connecting your bank account to any service:
- Check the provider is registered on the FCA Register at fca.org.uk.
- Read (or at least scan) their privacy policy for how long they hold data.
- Look for the OBIE logo or regulated provider badge.
If you can't find this information easily, that's a red flag.
Moxim uses FCA-regulated open banking infrastructure. We're built on the principle that your data is yours. We're here to help you make a better mortgage decision, not to harvest your financial history.
Find out where you stand — before you apply. Check my readiness →
Frequently asked questions
Can someone move money out of my account through open banking?
No. The connection is read-only by design; a provider can view categorised transaction data but has no technical ability to move money, make a payment or change your account details.
What if I regret connecting my account later?
You can revoke access at any time, either through your bank's app in a couple of taps or by asking the provider directly to delete your data under GDPR; they are required to comply.
How do I know a provider is genuinely FCA-registered?
Check the FCA Register at fca.org.uk directly, rather than trusting a badge or logo shown on the provider's own site, since a badge alone proves nothing.
Does open banking ever ask for my card details?
No. A genuine open banking connection only ever requires your bank login on your bank's own site; it never asks for a card number, CVV or PIN.
Is it safe to use open banking on a mobile app rather than a computer?
Yes; the same regulated standards and read-only access apply regardless of the device you use to complete the connection.
What happens if my bank itself has a data breach?
That risk exists independently of open banking and is covered by your bank's own security obligations; open banking does not add a new point of failure to your bank account beyond what already exists.
Does open banking work the same way for a joint mortgage application?
Yes; each applicant connects their own account separately, and each sees exactly the same read-only consent screen and the same protections, regardless of whose income makes up the larger share of the application.
Can a broker see my banking password if I connect through their platform?
No, and this is worth repeating because it is the most common misunderstanding: a broker's platform only ever receives the categorised data your bank sends after you authenticate directly with your bank, never your login details themselves.
Is open banking regulated differently in the UK than elsewhere?
The underlying principle, that customers can securely share their own data with authorised third parties, is shared across many regulated markets, though the specific rules and registration bodies vary by country; UK open banking sits under the FCA and the Open Banking Implementation Entity specifically.
Does deleting my data affect an application already in progress?
Not if the lender or broker has already recorded the relevant affordability outcome; deletion removes the underlying transaction data itself, not the decision already made from it, though it is worth timing a deletion request around any active application to avoid delays.
What should I do if I'm unsure whether a request is genuine?
Stop before entering any details, check the provider's name against the FCA Register directly, and if in doubt, contact your bank or broker through a number you already know and trust rather than one shown on the page in question.
Can I see exactly what data has been shared before I agree?
Yes; the consent screen shown by your bank sets out exactly what is being requested and for how long, before you confirm anything.