michaela-damm.jpg
blocshop
January 15, 2025
0 min read

UK Open Banking Future Entity Framework: A Comprehensive Overview

roro665_UK_Open_Banking_Future_Entity_Framework_and_open_bank_7916b1ec-0bf6-4c9e-9963-1433c845582e_0.png

Open banking in the United Kingdom is entering a new phase, transitioning from the Open Banking Implementation Entity (OBIE) to what is often referred to as the Future Entity. The transition to a new entity is about moving to a more permanent, sustainable governance model as the OBIE completes its original mandate.

This shift follows a 2016 inquiry by the Competition and Markets Authority (CMA) into the retail banking sector, which found limited competition in the field and the need to give consumers more choice. Initially, the CMA required the nine largest banks (often called the “CMA9,” comprising Barclays, HSBC, Lloyds Banking Group, Nationwide, RBS, Santander, Danske Bank, Bank of Ireland, and Allied Irish Bank) to allow third-party providers (TPPs) regulated access to customer data—subject to user consent—via standardized application programming interfaces (APIs).

Under this mandate, the OBIE was formed to define technical guidelines, set compliance requirements, and coordinate efforts among the CMA9 and TPPs. As open banking matured, however, the CMA recognized the need for a more inclusive structure that extends beyond these nine major institutions and also embraces smaller banks, fintech enterprises, consumer groups, and other stakeholders. A new committee, the Joint Regulatory Oversight Committee (JROC), was established to guide this transition. JROC comprises the CMA, the Financial Conduct Authority (FCA), the Payment Systems Regulator (PSR), and HM Treasury, working together to chart the strategic direction and governance of the upcoming Future Entity.

The Future Entity: Key objectives

A prominent goal of the Future Entity is delivering robust oversight across open banking operations.

By including stakeholders outside the original CMA9, it aims to ensure a balanced governance model that avoids any single party’s dominance. Standardization and interoperability, already central to the existing open banking framework, remain priorities as the Future Entity seeks to refine APIs and data formats so newcomers can enter the market with fewer hurdles.

Strengthening security protocols through consistent guidelines around encryption, incident response, and authentication is another focal point. Lastly, consumer protection underpins these efforts, making sure that users can seamlessly grant or revoke data access while understanding how their information is managed.

Structure and funding model

The Future Entity’s governance frequently mentions a balanced board that includes representatives from banks, TPPs, consumer advocacy organizations, and regulators in an observer role. This structure prevents overconcentration of power among the former CMA9.

Funding is likely to come from a broader range of participants—rather than solely these largest banks—distributing financial obligations more equitably. There is also a discussion of offering paid services or toolkits to generate additional revenue that supports long-term operations. For an in-depth breakdown of these proposals, refer to the JROC's latest Proposals for the Future Entity.

Technical architecture and standards overhaul

The new entity will refine existing API specifications—originally defined by the OBIE—for account data, payment initiation, and other services. This could involve aligning certain technical elements with global best practices, particularly for fintech firms operating in multiple jurisdictions.

Security protocols, including tokenization and advanced fraud-detection measures, will likely be reinforced through frequent audits and self-assessments. Participants must also abide by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act (2018), maintaining clear data usage logs and consent policies. In addition to technical changes, the new entity will also focus on improving user experience and accessibility.

All of the above will require market players in the open banking industry to invest in data architecture transformation and update their infrastructure to be compliant.

Market impact

On the other hand, banks and financial institutions stand to benefit from a unified set of standards as they develop service offerings in conjunction with technology partners. Although this may require increased spending on cybersecurity, system upgrades, data tranformations and staff training, such measures lay a foundation for stable, future-oriented growth.

Fintechs could see lower barriers to entry but must prepare for rigorous security and compliance checks. Meanwhile, consumers and small businesses may gain access to more advanced products and integrated solutions—ranging from real-time cash flow monitoring to data-driven financing options.

Below is an outline of practical steps that fintech and open banking companies need to prepare to take to align with the Joint Regulatory Oversight Committee (JROC) April 2023 recommendations, drawn from the JROC Report – Recommendations and Actions, April 2023:

  • Update APIs and infrastructure
    Ensure compatibility with new API standards, refine authentication flows, and document changes for future audits.

  • Strengthen security and resilience
    Adopt stronger encryption, run regular penetration tests, and set clear response protocols for incidents or disruptions.

  • Implement performance reporting
    Automate metrics collection (e.g., uptime, error rates) and share data in standardized formats to enhance transparency.

  • Support Variable Recurring Payments (VRPs)
    Adapt payment systems to accommodate VRPs, clearly define user consent processes, and align technical requirements with partner banks.

  • Enhance consumer protection
    Maintain straightforward consent controls, respond quickly to privacy or fraud complaints, and offer user education on data usage.

  • Participate in governance discussions
    Engage with industry groups, regulators, and working committees to stay informed about funding, timeline adjustments, and evolving guidelines.

  • Plan phased rollouts
    Coordinate internal and partner roadmaps with JROC’s recommended milestones, anticipating interim updates and changes in deadlines.

Looking Ahead: Operational and strategic considerations

Adhering to the Future Entity’s guidelines demands diligent data governance. Financial institutions should maintain thorough inventories of the data they collect and process, ensuring robust encryption and consent management. Collaboration among industry associations—like Innovate Finance or UK Finance—as well as with regulators and technology consortia, remains crucial. The Bank of England and the FCA also emphasize operational resilience, defining clear protocols for incident response, uptime, and continuity planning to mitigate service disruptions.

The shift to a broader, more inclusive system under the UK Open Banking Future Entity Framework represents an evolution beyond the initial OBIE model. With well-defined governance, refined technical standards, and stakeholder collaboration, this next phase of open banking promises both challenges and opportunities. Institutions that adapt promptly can deliver secure, transparent, and flexible services, strengthening user trust and supporting long-term market confidence.

Data transformation and IT consultancy firms, such as Blocshop, can facilitate this transition by applying AI-driven data integration tools and tailoring API infrastructures to meet specific operational and regulatory needs. Blocshop can create and revise APIs for seamless data sharing, identify gaps in existing architectures, and implement best practices that align with open banking guidelines. Through dedicated consultations, unique in-house tools, and hands-on expertise, we help organizations manage the complexities of evolving regulatory requirements, and maintain robust security standards.

LET'S TALK


Learn more from our insights

roro665_UK_Open_Banking_Future_Entity_Framework_and_open_bank_7916b1ec-0bf6-4c9e-9963-1433c845582e_0.png
January 15, 2025

UK Open Banking Future Entity Framework: A Comprehensive Overview

Open banking in the United Kingdom is entering a new phase, transitioning from the Open Banking Implementation Entity (OBIE) to what is often referred to as the Future Entity.

roro665_Navigating_major_open_banking_regulations_in_2025_PSD_280ffc61-b7d4-400c-885b-302452398dcf_0.png
January 09, 2025

Navigating major open banking regulations in 2025: PSD3, Retail Payment Activities Act, Dodd-Frank, and more

See four major regulatory initiatives shaping global open banking’s ecosystem in 2025.

roro665_Best_Practices_for_Integrating_AI_in_Fintech_Projects_937218e6-8df0-49aa-9a1a-061228aba978_3.png
December 03, 2024

AI-Driven ETL Tools Market: A Comprehensive Overview

Explore AI-driven ETL tools like Databricks, AWS Glue, and Roboshift, tailored for automation, data quality, and compliance in regulated sectors.

roro665_Best_Practices_for_Integrating_AI_in_Fintech_Projects_76570294-b2df-4e1d-a775-bdc646351d08_2 (1).png
November 19, 2024

Introducing Roboshift: AI-Powered ETL and Data Processing for Compliance in Regulatory Industries

Discover Roboshift, the AI-driven ETL solution by Blocshop, designed for secure, efficient data processing in fintech, banking, and other regulatory industries.

roro665_Best_Practices_for_Integrating_AI_in_Fintech_Projects_76570294-b2df-4e1d-a775-bdc646351d08_1 (1).png
October 16, 2024

Best practices for integrating AI in fintech projects

Discover 8 key steps for AI implementation in fintech and open banking with a focus on compliance, data quality, bias, and ethics.

roro665_Extract_Transform_Load_process_for_data_that_is_power_8734b36d-5737-4fdb-904e-ea6bca40c51b_3.png
October 09, 2024

Real-life examples of generative AI products and applications

See real-life examples of generative AI products and applications developed by Blocshop that impact industries from retail to fintech.

roro665_data_transformation_from_one_format_to_another_with_g_91332f66-93b0-48d8-9d5e-a8609529cbb7_3.png
September 25, 2024

Generative AI-powered ETL: A Fresh Approach to Data Integration and Analytics

ETL meets generative AI. See how AI-powered ETL redefines data integration and brings more flexible data processing and analytics across industries.

roro665_uk_pensions_dashboard_reform_magazine_cover_collage_-_1888e056-80f6-4aac-958c-bf02b128a7d3_1.png
September 03, 2024

UK Pensions Dashboard Compliance: Deadlines, Transition Steps, and the Use of AI-driven Data Mapping

How AI-driven data mapping can support UK Pensions Dashboard compliance. Understand key deadlines and steps for efficient data conversion and transition to the UK Pensions Dashboard.

roro665_a_cover_image_depicting_data_conversions_and_compliance_c8ddf35a-cc0f-447a-abb7-0f4b1f14bb64 (1).png
August 23, 2024

Using AI for data conversion and compliance in the banking sector

Discover how AI transforms data conversion and compliance in the banking industry, optimizing processes while managing risks.

ai_applications_in_banking_and_banking_technology_blocshop.png
August 14, 2024

AI Applications in Banking: Real-World Examples

Explore how major banks are using AI to enhance customer service, detect fraud, and optimize operations, with insights into technical implementations.

20221116_153941.jpg
July 31, 2024

From Concept to MVP in Just 12 Weeks with Blocshop

Blocshop delivers your MVP in 12 weeks, solving real pain points with agile sprints, daily scrum meetings, and fortnightly reviews. Here's the process explained.

chatgpt4_ai_integration_blocshop-transformed.png
July 19, 2024

ChatGPT-4: An Overview, Capabilities, and Limitations

The technical aspects, usage scenarios, and limitations of ChatGPT-4, including a comparison with ChatGPT-4o.

roro665_depict_a_data_sample_thta_completely_changes_its_form_725a4f20-ea40-4dd1-a68d-5c4327c9bf24_1.png
June 20, 2024

Generative AI used for data conversions and reformatting

How to use generative AI for data conversion, addressing integrity, hallucinations, privacy, and compliance issues with effective validation and monitoring strategies.

DALL·E 2024-05-30 09.37.01 - An illustration suitable for an article about ISO 20022. The scene should feature a modern, sleek representation of the ISO 20022 logo in the center. .webp
May 28, 2024

ISO 20022 Explained: A Comprehensive Guide for Financial Institution Managers

What is ISO 20022? How does it affect companies and institutions in the fintech and banking industry and how to prepare for its adoption? All explained in this article.

DALL·E 2024-05-22 20.55.08 - A detailed and high-quality DSLR photo of a person using a laptop to shop online, showing personalized product recommendations on the screen. The back.webp
May 16, 2024

Key AI Trends in E-commerce and Overview of AI integrations for E-commerce Platforms in 2024

Transform your e-commerce platform with AI tools for personalization, analytics, chatbots, search, and fraud detection. Boost sales and improve customer experiences.

eIDAS mark.png
May 09, 2024

Digital Identity and Payment Services in the EU in 2024: Key Updates

eIDAS 2.0 and PSD3 are set to enhance how digital identities and payment services are managed across the European Union in 2024. Here’s an overview of how each framework contributes to the digital landscape of the EU, what to expect, and how to prepare.

eIDAS 2 in fintech and open banking EU market.png
May 06, 2024

What is eIDAS 2.0 and EU Digital Identity Wallet and how will it change the EU digital market

Learn how eIDAS 2.0 and the EU Digital Identity Wallet will transform digital transactions and identity management across the European Union.

best large language models for ERP systems.png
March 31, 2024

Language Models Best Suited for Integration into ERPs

Four prominent large language models stand out for their compatibility and effectiveness in ERP system processes and automation. See what they are.

PSD3 in open banking Blocshop.png
April 23, 2024

PSD2 vs. PSD3: The Evolution of Payment Services Regulation

What is PSD3 in open banking? See how PSD3 compares to PSD2 and what should banks and fintech businesses do to ensure regulatory compliance in the EU market.

roro665_hands_working_with_a_laptop_in_a_modern_office_there_is_20dca307-c993-4539-99d7-fd5ca264248c.png
April 14, 2024

Enhancing ERP Systems with AI Chatbots

Explore how AI chatbots can transform ERP systems, enhancing efficiency, decision-making, and user interaction.