The regulations governing data sharing in open banking in the UK have been changed by the Financial Conduct Authority. The changes will reduce friction for consumers, removing the requirement to re-authenticate with their bank every 90 days.
What are the changes?
How will reconfirmation of consent benefit my users?
Does this mean re-authentication will no longer be required?
- As banks transition one-by-one to the new UX in the second half of 2022, some banks’ connections will support the new UX while others won’t. Your integration will need to be able to handle both.
- There are still exceptional circumstances where a bank can ask a user to go through strong customer authentication (SCA). This occurs in cases where the bank believes fraudulent data access is occurring. This is very rare.
- If your app supports connections to EU banks, re-authentication remains the only way to extend data access with these providers.
How can I implement reconfirmation of consent?
When can I implement the new Connections API?
1. TrueLayer production environment: The re-authentication workflow is now available in beta in production. We expect to make the new reconfirmation of consent workflow available in production from the end of September. We will provide a further update when this is ready.
2. White-labelled implementation: Unregulated customers planning to use the white-labelled option will need to submit their designs for review to ensure they meet . This will be a prerequisite to obtaining production access. You can submit your screens for review by submitting this .
3. Bank readiness timeline: UK banks have until the end of September to complete their integration work and therefore individual banks may be ready at different times. The Connections API has been designed to accommodate this varied readiness timeline so you don’t need to worry about it. Your users will be taken through the relevant flow (re-authentication OR reconfirmation of consent) depending on their bank and its readiness. When each bank is available for the reconfirmation of consent flow this will be updated on the in the following fields:
What if I am not ready to implement the Connections API?
Ready to get started?
- Review our
- Start testing in sandbox
- Start building out your user experience design and submit them for (if you are unregulated for AIS)
- Stay tuned for further updates on the full production launch date for reconfirmation of consent