Open Banking Payments Show Much Lower Fraud Rates Than the UK Payments Average

SSV SmartPay, Banking your success
Payment Security · Open Banking · UK 2026

Open Banking Payments Show Much Lower Fraud Rates Than the UK Payments Average

Official 2025 data shows lower fraud incidence by transaction volume for open banking payments than for the wider UK payments industry. Here is what the comparison means—and what it does not.

Payment fraud Open banking ~5 min read SSV SmartPay
A smartphone approving a secure Pay by Bank payment, protected by a translucent shield
Pay by Bank payments are authorised through the customer’s banking environment without the merchant handling card details.
In one line

Official 2025 data reported by Open Banking Limited showed that open banking had around 58% lower fraud incidence by transaction volume than the wider payments industry in the dataset. The underlying reported rates were approximately 0.017% for open banking and 0.040% across the wider payments industry. Open banking is not risk-free, but the comparison shows a meaningful difference.

The Fraud Rate Gap: What the Data Shows

Open Banking Limited’s June 2026 Fraud Monitor provides the clearest current comparison. Based on data from account providers representing more than 60% of open banking payment volumes, it reported an open banking fraud incidence of approximately 0.017% during 2025, compared with approximately 0.040% across the wider payments industry. Put another way, the recorded rate for open banking was around 58% lower by transaction volume.

Source: Open Banking Limited, Open Banking Payments Fraud Monitor—June 2026 Edition. The comparison is by transaction volume and reflects the providers and period covered by the report. Fraud rates can vary by provider, payment journey, fraud category and reporting method.

The figures show a meaningful difference in observed fraud incidence, but they should not be interpreted as a universal guarantee. The more useful question is why open banking payment journeys may reduce exposure to some common forms of payment fraud.

The difference reflects both payment design and regulatory safeguards. Pay by Bank does not rely on reusable card details, while authentication and bank controls add protection to the payment journey.

Why Card Payments Are More Vulnerable

To understand the difference, it helps to consider what card-not-present (CNP) fraud exploits. These are transactions made online or over the phone without the physical card being checked. Stolen card details may be used to attempt remote purchases, although additional controls such as Strong Customer Authentication can apply.

Card details can be compromised through phishing, malware, skimming or data breaches, and may then be used to attempt purchases without physical access to the card. Tokenisation and authentication controls reduce this risk, but the underlying card credentials still exist within the payment ecosystem.

The structural problem with card payments

Card payments rely on card credentials being presented to the payment ecosystem. Merchants may use tokenisation or a payment processor to avoid storing the raw details themselves, but compromised credentials can sometimes be reused elsewhere.

Strong Customer Authentication adds an important layer of protection to electronic payments. However, the regulatory framework includes exemptions, and card credentials can still be targeted through phishing, data theft and account compromise.

A conceptual comparison between exposed reusable card data and a protected bank-app payment
Pay by Bank removes card details from the transaction, reducing exposure to fraud that depends on stolen card credentials.

Why Open Banking Is Structurally Safer

Open banking payments work differently. When a customer pays using Pay by Bank, they do not enter card details. They select their bank and authorise the payment through their bank’s own environment, using the authentication method required by that bank, such as biometrics, a passcode or another approved method.

For SSV SmartPay, the payment is initiated from the customer’s bank account to the merchant and settled through Faster Payments. No card number, expiry date or CVV is required for the transaction.

1

No card details to steal

There is no card number, expiry date or CVV involved in the Pay by Bank transaction, so those details cannot be taken from this payment journey and reused elsewhere.

2

No card-not-present exposure

Stolen card details cannot be used to initiate a Pay by Bank payment because the payment does not rely on card credentials.

3

Authentication happens at the bank

The customer approves the payment inside their own banking app, with their own bank’s security. The merchant never handles the customer’s banking credentials, and neither does SSV SmartPay.

4

Bank-led authentication

Electronic payments are generally subject to Strong Customer Authentication requirements, using independent authentication elements. Specific regulatory exemptions may apply in some circumstances.

This design reduces exposure to fraud that depends on stolen or reusable card credentials. It does not remove every risk: fraudsters may still target bank accounts, devices or customers through account takeover, malware and social engineering.

What Open Banking Does Not Protect Against

A lower fraud rate is not the same as no fraud risk, and it is important to be clear about what open banking payments do not protect against.

One important remaining risk is authorised push payment (APP) fraud, where a fraudster manipulates or deceives a customer into approving a payment. Because the customer completes the bank’s authentication process, a payment made under social engineering, impersonation or deception can still proceed unless it is identified and stopped. The authentication may be genuine even though the customer’s decision was based on false information.

A customer checking a payment recipient before approving a bank transfer on a smartphone
Bank authentication cannot by itself determine whether a customer has been deceived, so recipient verification remains important.
APP fraud and the protections in place

APP fraud accounted for more than two-thirds of the open banking-related fraud cases reported in Open Banking Limited’s June 2026 monitor. Mandatory reimbursement protections introduced on 7 October 2024 cover eligible APP scam payments made by individuals, microenterprises and charities through Faster Payments or CHAPS, subject to the scheme’s rules and exceptions. Customers and businesses should verify who they are paying before authorising any transfer.

Fraud comparisons should distinguish unauthorised fraud from APP fraud because the risks arise in different ways and may be measured differently. Open banking’s lower overall fraud incidence does not eliminate the need for scam prevention, transaction monitoring and clear customer warnings.

What This Means for UK Businesses

For a UK business accepting payments, lower fraud incidence can help reduce operational risk. Fewer fraudulent transactions may mean fewer disputes to manage, less time spent gathering evidence and a lower risk of financial or reputational damage linked to compromised payment credentials.

There is also a customer-experience benefit. For some customers, authorising a payment through their familiar banking environment may provide reassurance because they do not need to enter card details on the merchant’s website.

No card details means reduced exposure to card-data risk. A merchant accepting Pay by Bank through SSV SmartPay does not handle or store card numbers as part of that payment. This narrows the payment-data attack surface, although businesses still retain their other privacy and security responsibilities.

SSV SmartPay’s Pay by Bank service uses open banking payment initiation, with payments settled through Faster Payments. Customers authorise payments through their bank’s environment, and SSV SmartPay does not require or store card details for these transactions. The industry figures describe the market-level dataset covered by Open Banking Limited’s report; they are not a guarantee of the outcome of any individual payment.

Frequently Asked Questions

Are open banking payments safer than card payments?

Current data from Open Banking Limited indicates that open banking payments recorded lower fraud incidence by transaction volume than the wider payments industry. Open banking is not risk-free, and APP scams and other forms of fraud can still occur.

Why is Pay by Bank safer than paying by card?

Pay by Bank does not require the customer to give the merchant card details that can later be reused. The customer normally authorises the payment through their bank’s own security process, which may use biometrics, a passcode or another approved method.

What is Strong Customer Authentication and why does it matter?

Strong Customer Authentication (SCA) generally requires two independent elements drawn from knowledge, possession and inherence. It is an important safeguard for electronic payments, although the regulatory framework includes specific exemptions.

Does Pay by Bank eliminate all payment fraud?

No payment method eliminates fraud entirely. Open banking payments carry a lower estimated fraud rate than the UK payments average, largely due to their structural design. However, risks such as authorised push payment (APP) fraud, where a customer is socially engineered into making a genuine payment, can still occur.

What types of fraud does open banking avoid?

Pay by Bank does not expose card numbers, expiry dates or CVVs, so stolen card details cannot be reused to initiate this type of payment. Other risks, including account compromise and authorised push payment scams, can still occur.

References

  1. Open Banking Limited. Open Banking Payments Fraud Monitor—June 2026 Edition. Source for the 2025 comparison of around one fraudulent payment in 6,000 open banking payments versus around one in 2,500 payments across the wider payments industry, and for the share of reported cases attributed to APP fraud. Available at: https://www.openbanking.org.uk/insights/open-banking-payments-fraud-monitor-june-2026-edition/
  2. Payment Systems Regulator. APP fraud reimbursement protections. Source for the start date, eligible customer groups and core scope of the reimbursement protections. Available at: https://www.psr.org.uk/information-for-consumers/app-fraud-reimbursement-protections/
  3. Financial Conduct Authority. Strong Customer Authentication. Overview of the UK requirements and their application. Available at: https://www.fca.org.uk/firms/strong-customer-authentication
  4. Financial Conduct Authority Handbook. Chapter 3: Exemptions from Strong Customer Authentication. Source confirming that specific exemptions exist. Available at: https://handbook.fca.org.uk/technical-standards/s140c1226
  5. Open Banking Limited. Why open banking is safe. Consumer guidance on regulated providers, consent and secure bank-led journeys. Available at: https://www.openbanking.org.uk/why-open-banking-is-safe/

Important information

How to interpret the figures. The comparison uses transaction-volume data reported by Open Banking Limited for 2025 and reflects account providers representing more than 60% of open banking payment volumes. It is a market-level comparison, not a guarantee for any provider, merchant or individual transaction. The approximately 58% difference is calculated from the reported rates of one in 6,000 and one in 2,500.

APP fraud risk. Open banking payments are not immune to authorised push payment fraud. Mandatory reimbursement protections apply to eligible individuals, microenterprises and charities for eligible APP scam payments through Faster Payments and CHAPS, subject to the rules and exceptions. Customers and businesses should verify payment recipients before authorising any transfer.

Not financial or legal advice. This article is general information for UK businesses and does not constitute financial, legal, or security advice. For specific guidance on payment security or fraud prevention, speak to your payment provider or a qualified adviser.

SSV SmartPay terms. Full pricing, terms and conditions are available at ssvsmartpay.co/our-pricing. SSV SmartPay Limited is registered in England and Wales (CRN 15424021). SSV SmartPay is not directly FCA-regulated; payment initiation services are provided by FCA-authorised Payment Institution partners.

T&Cs apply

Pay by Bank: safer by design

No card details entered. No card-not-present exposure within the Pay by Bank transaction. Authorisation through the customer’s banking environment. Sign up in minutes, typically approved within 24 hours, with no monthly fees.

Start free trial Book a demo Or get in touch with the team →

Frequently Asked Questions

Do open banking payments have lower fraud rates than other UK payments?

Yes. Open Banking Limited’s 2025 data showed an estimated fraud incidence of approximately 0.017% for open banking payments, compared with approximately 0.040% across the wider UK payments industry. The figures represent transaction volume within the dataset and may vary by provider, fraud category and reporting method.

Are open banking payments safer than card payments?

The available data indicates that open banking payments experienced lower fraud incidence than the wider payments industry. However, this is not a direct comparison with every individual card provider or payment journey, so the results should not be interpreted as proving that every open banking payment is safer than every card payment.

Why can open banking payments have lower fraud rates?

Open banking payments are authorised through the customer’s banking app using the bank’s security process. Customers do not need to enter or share reusable card details during a Pay by Bank transaction, reducing exposure to certain types of credential theft.

Can fraud still happen with an open banking payment?

Yes. Open banking is not fraud-free. Customers can still be manipulated into authorising payments to criminals through authorised push payment scams, impersonation fraud and other forms of social engineering.

What should customers check before approving a Pay by Bank payment?

Customers should carefully review the recipient’s name, payment amount and transaction details inside their banking app. They should never approve an unexpected payment or one requested through suspicious messages, calls or websites.

Related News

Chargebacks: What They Actually Cost UK Businesses

Card Payments · Cost of Business · UK 2026 Chargebacks: … Read more

Open Banking and the Promise of Inclusion

Interview · Open Banking · Financial Inclusion Open Banking and … Read more

Xero Payment Links: How Businesses Can Get Invoices Paid Faster

SSV SmartPayssvsmartpayEdit Profile New Integration · Xero · UK 2026 … Read more

GDPR and Pay by Bank: How Customer Data Is Protected

Data Protection · Open Banking · UK 2026 GDPR and … Read more