Eight years after the Competition and Markets Authority compelled the United Kingdom's nine largest current account providers — collectively known as the CMA9 — to open their data and payment rails to third-party providers, the results are no longer a matter of regulatory speculation. They are a matter of engineering record. Cumulative account-to-account payments processed across the UK's open banking network have surpassed one billion transactions, while total API calls have exceeded 100 billion, according to data published by Open Banking Limited. These are not vanity metrics. They represent the unmistakable graduation of open banking from a compliance exercise into load-bearing financial infrastructure.
A Network That Now Moves Markets
The operational data for June 2026 places the scale of this transformation in sharp relief. The network processed 2.81 billion API calls in that single month alone — a 4.4 percent increase on the prior month — while completing 40.16 million successful open banking payments. Average API latency across the CMA9 infrastructure measured 349 milliseconds, representing a 50-millisecond improvement on the previous period. Weighted system availability held at 99.80 percent, with an unweighted figure of 99.35 percent. For any enterprise-grade financial platform, these are compelling performance benchmarks, and for a network operating at this volume, they are genuinely exceptional.
The headline figures, however, obscure an important compositional shift happening beneath the surface of aggregate payment volumes. Single Domestic Payments — the simplest form of open banking transaction — declined modestly in June, falling 1.2 percent to 32.43 million transactions. That slight dip is not a warning sign; it is a signal of maturation. The growth engine has migrated to more sophisticated payment mechanisms, specifically Sweeping Variable Recurring Payments, known as sVRPs. This category expanded 6.7 percent month-on-month in June to reach 7.73 million transactions, emerging as the primary driver of network growth and, arguably, the most consequential product in the open banking arsenal.
Why sVRPs Change the Commercial Calculus
Variable Recurring Payments allow users and enterprises to grant standing, parameterised consent for automated account-to-account fund transfers — without requiring individual authorisation at the moment of each transaction. For enterprise merchants, fintech platforms, and corporate treasury operations, this removes one of the most significant friction points in modern payment operations. Recurring savings allocations, subscription processing, and liquidity management workflows can all be automated via sVRP rails, entirely bypassing traditional credit card scheme fees. As sVRP adoption accelerates, the commercial case for preserving card-network dependency weakens considerably, and that has meaningful implications not only for UK fintechs but for global payment infrastructure strategy.
Security Challenges Scale With Volume
Processing 2.81 billion API calls per month inside a financial network does not come without a corresponding escalation in attack surface. The security architecture required to sustain this infrastructure is qualitatively different from what governed open banking at its inception. At sub-350-millisecond response benchmarks, traditional out-of-band fraud detection creates unacceptable latency; machine-learning-driven threat inspection must be deployed inline, at the API gateway layer, before payment execution reaches real-time rails like the UK's Faster Payments network.
The rise of sVRPs introduces additional complexity around token security. Third-party providers operating on long-lived, multi-use consent tokens — governed by OAuth 2.0 and Financial-grade API, or FAPI, standards — must defend against credential stuffing, token hijacking, and unauthorised consent modification. Because open banking transfers settle instantly and lack the chargeback mechanisms native to card networks, fraud attempts have increasingly migrated to the human layer, exploiting Authorised Push Payment fraud and social engineering rather than technical API vulnerabilities. For DevSecOps teams, the practical imperative is rigorous auditing of token revocation protocols and consent lifecycle management, ensuring stale permissions are automatically purged before they become exploitable.
The Transatlantic Regulatory Divergence
The UK's trajectory offers an instructive contrast with the United States, where open banking has developed along fundamentally different lines. Washington relied historically on bilateral market agreements and screen-scraping arrangements that introduced significant security and reliability risks. The Consumer Financial Protection Bureau is now actively closing that gap, with Personal Financial Data Rights rulemaking pushing US banks and fintechs toward standardised API frameworks that mirror the technical baseline established in the UK. The distance between the two markets' infrastructure sophistication — measured in cumulative API calls, latency benchmarks, and uptime guarantees — quantifies precisely what eight years of top-down regulatory mandate can produce compared with voluntary, market-led adoption.
What This Means for Financial Services Leaders
The crossing of these twin milestones — one billion payments, 100 billion API calls — reframes the strategic conversation for financial institutions on both sides of the Atlantic. Account-to-account payment capability is no longer an emerging alternative; it is standard enterprise architecture. For technical decision-makers, the priorities are clear: hardening FAPI token infrastructure to support commercial VRP expansion, deploying real-time payload inspection capable of operating inside sub-350-millisecond windows, and building consent lifecycle governance that can scale alongside open finance's expanding perimeter. For regulators and policymakers, the UK's data provides perhaps the most detailed empirical record available of what a mandated, standardised, and rigorously monitored open banking ecosystem actually produces at scale — and the numbers make a powerful argument for their approach.
Written by the editorial team — independent journalism powered by Codego Press.
Top comments (0)