EU / EEA
PSD3 & PSR
The Payment Services Directive 3 and Payment Services Regulation replace PSD2 with stronger open banking obligations, enhanced SCA rules, and a new liability framework for payment service providers. Phased implementation runs 2026–2027 across all EU member states.
Phased · 2026–2027
United Kingdom
UK OBL / CMA9
The UK's Open Banking Implementation Entity has mandated all CMA9 banks to deliver standardised APIs covering accounts, transactions, payments, and standing orders. The OBIE v3.1.10 standard is live and in enforcement. Variable Recurring Payments (VRP) is in commercial rollout.
Live · CMA9 Enforced
United States
CFPB Section 1033
The Consumer Financial Protection Bureau's Personal Financial Data Rights rule requires covered data providers to make consumer financial data available to authorised third parties via standardised APIs. FDX is the dominant technical standard. Phased compliance deadlines run 2026–2030 by institution size.
Phased · 2026–2030
Global · SWIFT
ISO 20022 CBPR+
SWIFT's Cross-Border Payments and Reporting Plus programme completed its migration November 2025. All SWIFT MT message types for payments and cash reporting are deprecated. Every correspondent bank on the network now sends and receives MX (ISO 20022 XML) messages exclusively.
Live · Migration Complete
United States · Federal Reserve
Fedwire ISO 20022
The Federal Reserve completed its Fedwire Funds Service migration to ISO 20022 in 2025, aligning the US large-value payment system with global RTGS standards. All Fedwire participants must now originate and receive pacs.008, pacs.009, and camt.054 messages.
Live · 2025 Migration
Global · OpenID Foundation
FAPI 1.0 & 2.0
The Financial-grade API security profile defines the OAuth 2.0 and OpenID Connect requirements for open banking APIs. FAPI 1.0 Advanced is mandated by UK OBIE and referenced by PSD3 RTS. FAPI 2.0 (Security Profile + Message Signing) is in adoption across AU CDR and UK's next-generation framework.
Active Adoption
⚙️
Payments Engineer
Building open banking integrations
Validate ISO 20022 messages before they hit production, debug raw API responses in the JSON Visualizer, generate FAPI-compliant PKCE payloads, and test rate limit handling with the retry code generator — all without standing up a test environment.
⚖️
Compliance Officer
Managing PSD3, CFPB 1033, or UK OB obligations
Use the Consent Dashboard Builder to prototype customer-facing permission UIs and generate per-jurisdiction compliance checklists. Generate portable consent receipts for audit trails. Map SCA exemption eligibility against EBA RTS 2023 thresholds.
🗺️
Product Manager
Scoping open banking features
Use the Consent Scope Mapper to understand what permissions your product needs across jurisdictions, model VRP mandate structures for subscription and sweep use cases, and compare payment rail options for your target corridors — all without developer support.