PSD2 lowers entry barriers for payment providers, which increases competitive pressure on incumbent banks. At the same time, it creates a route to new revenue through platform partnerships, data services, and third-party access models. The strategic question is whether a bank remains a narrow processor or uses open access to extend its role in the ecosystem.
How PSD2 Changes the Economics of Banking
PSD2 is not just a compliance change, it changes the economics of who can sit between the customer and the payment rail. By opening access to payment accounts and standardising parts of that access, it reduces the natural moat of the incumbent bank and makes customer switching and third-party competition easier.
For a bank, the strategic effect is that payments become easier to unbundle from the account relationship. That forces the bank to compete on experience, pricing, and ecosystem role rather than on pure access to the rails.
Why the Risk Side Is Real for Incumbents
The risk is loss of margin and loss of customer primacy. If a bank is reduced to a utility behind third-party interfaces, it can still hold the account, but it may no longer own the customer journey, transaction data, or the commercial relationship that creates cross-sell value.
That shift also creates operational pressure. Open access increases the number of external actors, APIs, consent flows, and exception paths that must be governed, monitored, and supported consistently, which raises the cost of controlling service quality and data exposure.
Where the Opportunity Comes From
PSD2 can also be an expansion lever. Banks that expose capabilities cleanly can become platform partners, provide premium data or verification services, and participate in account aggregation, initiation services, or embedded finance models without owning every front-end interaction.
The opportunity is strongest when the bank treats PSD2 as a distribution and partnership layer, not just a regulatory burden. In that model, open access becomes a way to extend reach into adjacent customer journeys and retain relevance even when the original payment flow is intermediated.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | PSD2 changes bank ecosystem position and business model context. |
| GV.SC-01 — Supply Chain Risk Management | PSD2 expands reliance on third-party providers and API partners. | |
| PR.AA-01 — Identity Management, Authentication and Access Control | Open banking depends on controlled access to accounts and APIs. | |
| Recommendation — Define the bank's role in the open-banking ecosystem and align controls to that operating context. Assess third-party payment and data-access relationships as part of the security and resilience model. Enforce strong authentication and access controls for account-access and initiation flows. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | PSD2 increases dependence on external fintech and platform partners. |
| A.5.15 — Access control | PSD2 relies on governed access to customer payment data and initiation rights. | |
| Recommendation — Set security requirements and oversight for third-party payment and data-sharing partners. Restrict access paths and permissions for open-banking interfaces and partner integrations. | ||
Practitioner Guidance
What to prioritise: Separate the economics of transaction access from the economics of customer ownership. If the bank cannot measure where margin is being lost or gained across third-party journeys, it cannot tell whether PSD2 is eroding the franchise or expanding it.
What to verify: Check which APIs, consent paths, and third-party relationships actually create value and which ones only add exposure. A bank should know whether each exposed capability supports retention, fee income, data monetisation, or only regulatory compliance.
Decision rule: If PSD2 exposure is being treated as a defensive compliance project, the bank will likely absorb cost without capturing upside. If it is treated as a product and platform design problem, the bank can still use open access to strengthen distribution and ecosystem position.
Practitioner takeaway: The winners under PSD2 are usually the banks that decide deliberately where they want to be commoditised and where they want to remain indispensable.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org