Bank on technology background showing open banking and fraud risks

What U.S. Companies Can Learn From the European Payment Scene

Could the pitfalls of open banking integration hit traditional U.S. retailers and their customers?

Innovation in the U.S. finance and banking industry is experiencing a quiet struggle between traditional banking entities and new fintech companies. Emerging technologies such as open banking have seen significant growth in the U.K. and abroad, but adoption in the U.S. has been slow in comparison. In the meantime, the most important stakeholders are being left out of the conversation: retailers and consumers.

This struggle has gone mostly unnoticed by the general public, with few able to  explain what open banking can do for them and how it will shape their online shopping experience.

Open banking allows consumers greater autonomy over who has access to their financial information. Whilst great in theory, the system is currently not set up to support newer fintech product integration.

The slow adoption of open banking in the U.S. can be attributed to traditional banks’ outright refusal to cooperate with fintech, this is  partly due to the tangible fraud risks that come with sharing banking information across unsecured networks. As regulators shape the landscape in Europe, U.S. companies should take note of what may impact them soon.

Open banking in the U.S.

U.S. consumers have limited exposure to open banking and most of the technology today relies on “screen scraping,” a technology by which a customer provides its banking app login credentials to a target product profile (TPP).

Screen scraping allows companies, like free credit checking and budgeting apps, to retrieve information from users’ bank accounts, display it on their platforms and build profiles based on the information. The process depends on users sharing their credentials with these third parties to gain access without establishing a formal relationship between the third party and the banking entity.

The process is essentially like providing a stranger with a copy of your house key, which entails all of the security risks associated with trusting a stranger. Sharing credentials across different third parties makes them more susceptible to a data breach, which creates increased fraud potential for consumers and e-commerce businesses.

Fintechs’ solution to the credential problem is the use of application programming interfaces (APIs). APIs are trusted networks that fintech companies can plug into to request data from banks without ever having to exchange passwords or usernames. The only issue is that the current U.S. banking infrastructure does not promote fidelity between banks and third parties. There are only 36 unique APIs used across the U.S. financial system, compared to the U.K.’s 196 and Germany’s 80. This leaves the U.S. to rely on unsafe screen scraping technologies and an uncoordinated API landscape.

Lessons learned from Europe

Recognizing the fighting between banks and nonbank entities, the U.K. parliament and the European Commission passed legislation to satisfy the two and protect online merchants and consumers from fraud. With a series of directives in the U.K. and the Revised Payment Services Directive (PSD2) for the rest of Europe, leadership aimed to force cooperation, standardize data sharing between the two sectors and increase online payment security.

Open banking providers have steadily increased in number since the passing of both legislations and exploded in 2021 as e-commerce accounted for a greater share of retail purchases. Great news for open banking companies, but confusion about the technology and ambiguity written into the security rules caused confusion for consumers and retailers alike.

A survey by the UK-based Nationwide Building Society found that about 21% of consumers experienced problems with completing transactions following the implementation of PSD2 strong customer authentication (SCA) requirements for most online transactions. These requirements were designed to make fraud more difficult to accomplish by requiring additional customer information at checkout but have increased customer friction in the process. Retailers who conduct business in Europe now have to work harder to find the right balance of meeting SCA compliance without compromising on the customer journey.

Realizing the issues, the European Commission requested industry comments last year to inform  a  future planned revision to the Payment Services Directive, dubbed PSD3.

A market built on trust

In the U.S., there is similar legislation aimed at integrating open banking fintech companies and traditional financial institutions with similar authentication measures to stop fraud. The Consumer Financial Protection Bureau has published a notice on proposed rulemaking on the matter and an executive order from the White House is pushing the movement forward as well.

The future is pointing toward open banking integration, but the lack of direction, knowledge, and understanding will put retailers and consumers in a scramble as they try to wrap their heads around the new initiatives. The U.S. could learn a thing or two from its European counterparts as this comes to a head in 2023 and beyond.