Longer consent in the UK from March 2022

This article might be out of date

Please note we've moved to the new Help Center, hence this article might be outdated. 

Please visit our new Help Center to access the latest articles. 

Changes to SCA-RTS in the UK from March 2022 and what it means for Nordigen customers and users.

Previously, in the UK as in the EU, a user has had to authenticate every 90 days to ensure continuous data flow between their banks and the services they have authorised to use their open banking data.
In November 2021 Financial Conduct Authority (FCA), the UK regulator responsible for the Open Banking rules and standards, has published upcoming changes detailing a simplified process of extending the consent given by users to Account Information Service Providers (AISPs, eg. Nordigen) for accessing their banking data.
Key changes:
  • After authenticating on the bank’s page or app once (the SCA process), the users don’t have to go through the process again. Consent can be reaffirmed on AISP’s (Nordigen’s) page.
  • One customer, one bank connection login, multiple accounts => one consent, not separate consents by account.
  • Such reconfirmation can be done by another party, to which the customer has delegated account access (such as an accountant).
  • When 90 days elapse the AISP must stop accessing the data until the customer reconfirms. Once they do, access can resume. This can also happen at a later time, after a period of inactivity.
  • Banks can choose not to apply these relaxed requirements, but are strongly encouraged to.
  • Banks can require SCA (login) again at any time if they have reasonable suspicions of fraudulent activity
  • These changes come into force 26 March 2022
What this means for Nordigen customers and users:
  • Customers of UK banks can reconfirm their consent using one click on Nordigen page without going through the bank login after they have done it once (we will inform our clients once the change for UK banks has been applied)
  • You can follow the exact same flow to reauthorize accounts at UK banks as before - redirect the user to the url returned under “link” in requisition and Nordigen will redirect them back to the the redirect url you’ve provided when creating the requisition. Except the user will not have to go through the bank login, making this journey so much more smooth.
  • If you create a new requisition, the user will have to go through bank login either way.
  • If a user has multiple banks connected, they will have to go through the flow for each bank (on requisition level)
  • Keep in mind that some UK banks might still require a login every 90 days.
Have any unanswered questions? Read the full story from the horse’s mouth or contact support@nordigen.com.
Did this answer your question? Thanks so much for your feedback! 🙏🏼 There was a problem submitting your feedback. Please try again 🙏🏼

Still need help? Contact Us Contact Us