All posts
4 min readOpenKYC Team

Open Banking and KYC: Why Account Access Didn't Solve Identity

open-bankingkyc

Open banking promised that connecting a bank account would unlock everything: payments, data, and (many assumed) identity. After all, the bank already verified you, so shouldn't a bank connection count as KYC? It's a reasonable intuition, and it's wrong in instructive ways. Account access and identity verification solve different problems, and conflating them has left fintechs running full KYC on customers who just proved they have a fully KYC'd bank account.

What open banking actually does

Open banking, as a regulatory construct, came out of the EU's PSD2 and parallel regimes like the UK's Open Banking mandate. It forces banks to expose two capabilities through APIs, with the customer's consent:

  • Account information: licensed third parties can read balances, transactions, and account details.
  • Payment initiation: licensed third parties can trigger payments directly from the account.

That's it. Open banking is a data-access and payments framework, not an identity framework. PSD2 says a great deal about strong customer authentication (proving the account holder consents to this session) and almost nothing about porting the bank's original identity verification to anyone else. The bank verified you for its own books; the API hands out your transaction data, not your identity file.

The open banking KYC misconception

The misconception goes: the bank did rigorous KYC at account opening, I can prove control of that account via open banking, therefore the recipient can inherit the bank's KYC. Each premise is true. The conclusion doesn't follow, for three reasons.

First, what travels across the API is data, not attestation. A fintech reading your account sees a name string on an account record. It does not receive a signed statement from the bank saying "we verified this person's passport on this date under this standard." There is no liability transfer and no audit trail a regulator would accept.

Second, account control is not the same as being the verified person. Logging into a bank account proves you hold the credentials, which could be a money mule, a coerced account holder, or a partner with shared access. The name on the account matching the name you typed into a form is a useful fraud signal; it is not identity proofing.

Third, regulation doesn't recognize it. AML rules require regulated entities to perform customer due diligence themselves or formally rely on a third party under strict conditions, with the reliant party still holding liability. A bank API connection meets none of the reliance criteria. No supervisor has blessed "they have a bank account" as a substitute for document-grade verification.

What bank data is genuinely good for in KYC

None of this makes open banking useless for identity. It makes it a signal source rather than a verification method. Used honestly, account data strengthens a KYC process:

  • Account ownership checks: confirming the name on a connected account matches the applicant cuts off a whole class of payout fraud.
  • Corroboration: address and name data from a bank can support, though not replace, document checks.
  • Affordability and source-of-funds context: transaction history answers questions documents can't, useful for lending and for AML risk scoring.
  • Counter-fraud signals: account age, salary inflows, and behavioral patterns help separate real customers from synthetic identities.

The pattern: open banking is excellent at proving facts about an account and weak at proving facts about a person. Document-grade identity proofing, verifying a government credential and binding it to a live human, stays outside its scope. So regulated entities run full KYC anyway, and the open banking connection becomes one more step in onboarding rather than a shortcut through it.

Bank-based ID schemes: the partial answer

Some countries did build identity on top of banking, just not through open banking APIs. The Nordic BankID systems, and similar bank-anchored schemes elsewhere in Europe, let banks act as identity providers: because the bank verified you thoroughly once, you can authenticate to government services, sign documents, and onboard with other companies using your bank-issued identity.

These schemes prove the core thesis: bank KYC can be made reusable, and where it has been, onboarding friction collapses. Their limitation is structural: each scheme is national. A Swedish BankID means nothing to a German fintech; every market that wants this has to rebuild it with its own banks, its own scheme operator, and its own legal framework. Decades in, coverage remains a patchwork, and cross-border interoperability efforts move slowly. Bank-based ID solved reusability inside one market and stopped at the border.

Reusable credentials complete the picture

This is where W3C Verifiable Credentials change the architecture. Instead of identity living inside a bank's login system or a national scheme, the verification result becomes a portable, cryptographically signed credential held by the user: verify once with a certified provider, store the credential in your own wallet, present it to any verifier that trusts the issuer, in any market. The full model is laid out in What Is Reusable KYC?.

Crucially, this complements open banking rather than competing with it. Picture a fintech onboarding flow: the user presents a reusable KYC credential (document-grade identity, verified seconds ago by signature check) then connects their bank account via open banking for payments and an ownership match against the verified name. Identity proofing and account access each do the job they're actually good at, and the duplicated cost of re-verifying every applicant disappears. It's a cost worth taking seriously, as we showed in The True Cost of KYC.

The honest summary of "open banking KYC": open banking moved money and data, bank-based ID schemes proved reusable identity works nationally, and portable verifiable credentials are the missing layer that makes it work everywhere.

Where OpenKYC fits

OpenKYC is building a reusable KYC marketplace on open standards (W3C Verifiable Credentials, OpenID4VC): verify once, hold the credential in your own wallet, reuse it everywhere, including with fintechs onboarding you through open banking, and earn every time it's used. Join the waitlist at openkyc.org.

Verify once. Use everywhere. Earn every time.

OpenKYC is building the reusable KYC marketplace on open identity standards. Be first in line.

Join the waitlist