Resources Insights News

The Essential Guide to OBL Version 4.0

Essential guide to UK Open banking standard v4.0
Structure

Download the UK open banking version 4.0 essential guide

In this essential guide to the Open Banking Read-Write API Profile version 4.0, we cover the key changes and enhancements being made to the UK open banking standard, key deadlines for compliance and implementation, technical specifications you need to be aware of, and how it’ll impact stakeholders. We also cover what support is available.

This guide was first published in July 2024, when v4.0 was still a future deadline. It’s now August 2026, the dust has settled, and the standard has moved on to v4.0.1. This guide has been updated to reflect that.

Once you’ve read this guide, you’ll understand where the UK stands on v4.0 today. When you feel ready to start implementing OBL 4.0, head to our Commercial VRP page.

_

Why is the UK Open Banking Standards being Updated?

The changes within v4.0 have been triggered by several critical events:

  • The OpenID Foundation (OIDF) has confirmed that the FAPI 1 Implementers Draft 2 will be retired, and after 31 March 2025, no further certifications will be available for this version of the security profile. This means that continued use of this deprecated standard would lead to non-compliance with international security protocols.
  • The Bank of England has published mandatory changes to CHAPS payments that mandate the use of ISO 20022 message standards and the inclusion of enhanced and enriched data. These changes are crucial for ensuring that the UK banking ecosystem remains compliant with FCA regulations.

To elaborate on the regulatory requirements:

  • FCA SCA-RTS article 30(3): Account servicing payment service providers (ASPSPs) must ensure that their interfaces follow standards of communication issued by international standardisation organisations.
  • FCA SCA-RTS guidance paragraph 21: To ensure the interoperability of different technological communication solutions, the interface should use standards of communication developed by international standardisation organisations.

These updates are essential to maintain interoperability and compliance with international standards, thereby fostering a secure, efficient, and competitive banking environment in the UK.

_

Who are OBL?

Open Banking Limited (OBL), also known as the Open Banking Implementation Entity (OBIE), was set up by the UK’s Competition and Markets Authority (CMA) to implement the CMA Order—a remedy to drive competition, innovation, and transparency in UK retail banking.

What do OBL do?

  • Champions the Open Banking Ecosystem; Aims to deliver open banking-powered products and services to the UK.
  • Provides critical services and infrastructure; Manages the UK’s open banking ecosystem of banks, financial institutions, fintechs and technical service providers.
  • Supervisory activities; Involved in the ongoing development of UK standards and future regulations.

The Joint Regulatory Oversight Committee (JROC), the body that drove the reform recommendations behind v4.0, has been wound down, and its function absorbed into the FCA, which is now the lead regulator for open banking under the National Payments Vision. OBL itself continues operating, but its role has changed too: it is now facilitating, not becoming, an industry-led “Future Entity” expected to eventually succeed it. Future Entity has not yet been legally established (as of August 2026).

_

Key changes and Enhancements to the UK Open Banking Standard

Overview of version 4.0

The Open Banking Read-Write API Profile version 4.0 is the first major release of the UK standards since September 2018. This major release, requiring mandatory updates by the CMA9, has been published to ensure the UK Standards continue to align with international best practices in terms of electronic messaging standards, security, and reliability of APIs used in the financial industry.

Key features:

  • Migration to FAPI 1.0 Advanced: The uplift to FAPI 1.0 Advanced is necessary as FAPI 1 Implementers Draft 2 is being deprecated by the OpenID Foundation and will no longer be supported.
  • Alignment to ISO 20022 Code Values: This replaces the previously modified non-standard code names so that providers can meet the Bank of England deadlines for CHAPS payments while providing the required codes for all ISO 20022 payments like International SEPA and Swift payments.
  • Inclusion of Additional ISO 20022 Data Elements: Required for CHAPS payments to meet the Bank of England’s mandatory requirements.

Enhancements:

  • Enhanced data sharing protocols: Despite the TDA voting against implementing certain elements like Pushed Authorisation Requests (PAR) and Proof of Key Code Exchange (PKCE), the adoption of FAPI 1.0 Advanced will still bring significant benefits to the UK Open Banking ecosystem.
  • Security and privacy enhancements: The adoption of ISO 20022 code values and messaging rather than continuing to use non-standard code names for open banking initiated payments will provide harmonisation with payment systems worldwide. The enriched data provided by PISPs can also lead to fewer delays for the end customer and reduce manual interventions due to fraud ‘false positives’.

Technical specifications and API updates:

The v4.0 ISO 20022 changes impact all payment types as it is not possible to separate CHAPS and faster payments within the API specifications. The additional ISO 20022 data elements include:

  • Category purpose: Can be used to specify the high-level purpose of the transaction.
  • LEI: Ensures a unique and clear identification of all parties involved in the transaction, improving traceability and compliance.
  • Ultimate creditor and ultimate debtor: Provide clarity and transparency on the final recipient and origin of funds, enhancing auditing and compliance.
  • Proxy: Allows PISPs to provide an identifier that can be used as a substitute for a primary account number.

In addition to the above data elements, the v4.0 Payment APIs have been enhanced to enable PISPs to provide information for regulatory reporting and remittance information, aiding faster and more accurate reconciliation processes.

Additional ISO 20022 data elements introduced:

  • Category purpose: Specifies the high-level purpose of the transaction.
  • LEI (Legal Entity Identifier): Ensures unique, clear identification of all parties involved in a transaction, improving traceability and compliance.
  • Ultimate creditor and ultimate debtor: Provide clarity and transparency on the final recipient and origin of funds, enhancing auditing and compliance.
  • Proxy: Allows PISPs to provide an identifier that can be used as a substitute for a primary account number.

Beyond these data elements, the v4.0 Payment APIs were enhanced to let PISPs supply information for regulatory reporting and remittance purposes, aiding faster, more accurate reconciliation.

The current standard is v4.0.1, a maintenance release published by OBL on 1 April 2026. OBL describes it as “focused on assurance rather than transformation” — no v4.1 or v5.0 exists yet.

_

The Implementation of Version 4.0

The original deadlines to implement OBL 4.0 set an ambitious pace. Here’s what happened:

FAPI 1.0 Advanced migration — deadline 31 December 2024. This was mostly achieved, but two of the nine CMA9 groups missed it. NatWest Group was around four weeks late, implementing on 28 January 2025 and Bank of Ireland UK was around six months late, implementing around 9 July 2025.

Read-Write v4.0 Standards — deadline end of Q1 2025, which was missed broadly. Only HSBC hit the original date, going live on 13 December 2024. The rest of the CMA9 rolled out between April and October 2025 — Nationwide in June 2025, Barclays in September 2025, Santander in October 2025. Bank of Ireland UK is still not fully implemented as of August 2026: PIS went live on 2 June 2026, AIS/CBPII is planned for August 2026, and VRP isn’t scheduled until December 2026.

CHAPS ISO 20022 compliance — deadline 1 May 2025. The base ISO 20022 messaging migration for CHAPS was completed ahead of schedule in June 2023. The 1 May 2025 date applied to a narrower enhanced-data mandate: Purpose Codes and LEI for FI-to-FI and property payments. That mandate was met on schedule.

Pending Upgrades

Since then, the picture has moved again:

  • Purpose Codes will expand to all CHAPS payments, and LEI will be mandated for more payment types, from November 2027.
  • In July 2026, the Bank of England confirmed it will not mandate structured remittance data from November 2027 as originally proposed. No revised date has been set.
  • CHAPS won’t reject payments solely for missing or incorrect enhanced data before end-2028 at the earliest.

For non-CMA9 firms: the case to migrate for CHAPS and international payments still stands. The FCA may yet extend PSR 2017/SCA-RTS Article 30(3) direction to all ASPSPs.

_

Impact on Stakeholders

For the CMA9 Banks, there was a period of transition as the new standard was adopted. The rollout stretched through most of 2025 rather than concluding by Q1 as originally planned, with Bank of Ireland UK’s implementation still incomplete as of August 2026. Until Bank of Ireland UK completes its outstanding AIS/CBPII rollout and VRP capability (scheduled for December 2026), the CMA9 as a group won’t have fully closed out the v4.0 mandate.

Many Tier 1 and 2 Banks outside CMA9 have opted to adopt v4.0 due to the enhanced security, future-proofed operations, and competitive advantage — VRP and the new revenue streams it enables chief among them. These banks will also need to plan for the next wave of CHAPS enhanced-data requirements, with Purpose Codes expanding to all CHAPS payments and LEI mandated for more payment types from November 2027.

TPPs had to support both FAPI 1 Implementers Draft 2 and FAPI 1.0 Advanced concurrently for longer than originally expected, given the staggered CMA9 rollout through 2025. Looking ahead, TPPs should expect further changes as the Future Entity transition progresses and as the standard continues to evolve, as it did with the v4.0.1 maintenance release in April 2026.

_

The Next Steps

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, giving the FCA formal long-term powers to run cross-sector “Smart Data” schemes built on the open banking model, the legislative underpinning for open banking’s expansion into open finance. This was a change in legal foundation from the original v4.0 implementation.

On 14 April 2026, the FCA released its “Open Finance Roadmap: our vision for a smart data future“. The plan is phased:

  • 2026: TechSprints and PolicySprints on SME lending and mortgages, with a discussion paper on the first open finance scheme due in Q4 2026.
  • 2027: framework design work with HM Treasury.
  • 2028–2030: scaled delivery of open finance schemes.

The UK Payments Initiative (UKPI), an industry-owned company funded by 31 firms, formed in 2025 to deliver commercial VRP (cVRP) for consumer-to-business use cases, which replaced the previous JROC consumer-to-business VRP pilot. First live UKPI cVRP transactions went live in June 2026, and we will continue to monitor the developments.

The numbers are moving in open banking’s favour. VRP now accounts for around 16% of all open banking transactions, and open banking payments were up 53% year-on-year.

_

Support with OBL 4.0

Whatever stage of the v4.0/v4.0.1 journey you’re at, Ozone API can help. We provide Tier 1 and 2 banks with tools to secure operations, align with future regulations and tap into new revenue streams.

  • Proven technology and deep subject matter expertise – We have helped banks around the world, from Tier 1 banks to digital banks to wallets and everything in between.
  • Compliance with any global standard  – We support all global standards and a single integration can allow you to deliver open banking APIs in any market you operate.
  • Hassle-free updates – We always stay up to date with the latest global versions, enabling a smooth transition to v4.0 as well as always keeping your API up to date with future versions.
  • Advanced features – Enhance your open banking offerings with our platform’s advanced features and rich API catalogue to stay competitive.
  • Cost efficiency: Utilise our streamlined API integration to reduce operational costs and complexity.
  • Tapping into new revenue streams – We help you quickly deliver premium APIs like Variable Recurring Payments to create new avenues for commercial growth.

Want to know how we can help you navigate the UK Open Banking Standard? Book a call with Claire Seydoux (General Manager, UK).

Download the UK open banking version 4.0 essential guide

Recommended articles

Progress or journey to success or achieve goal, business step or career path, mission or challenge to succeed, improvement concept, ambitious businessman run on progress bar to achieve success flag.
Resources

Three Routes to One Destination: Comparing Open Finance in Chile, Colombia and Peru

An Ozone API & Finerio Connect Article Ask three regulators to build the same thing, in the same region, in the same decade, and you get three different roads. Chile, Colombia, and Peru are all building toward Open Finance. None of them are doing it the same way, and none of them are on the...

Ozone API and Finerio Connect
02, Sep 2026
Business milestones or achievement to reach goal or success, progress development, vision to see target destination, step to success, businessman look on telescope to see success trophy milestone.
Resources

Colombia’s Open Finance Roadmap: Moving from Mandate to Operational

An Ozone API & Finerio Connect Article The shift in Colombia’s regulatory framework from an optional model to a mandatory requirement was paramount in setting clear, unified expectations across the entire financial ecosystem. With Open Finance officially backed by law since April 2026, the market’s focus has now turned to the critical transition from legal...

Ozone API and Finerio Connect
25, Aug 2026
Milestone to reach goal or success target, strategy to progress achievement, leadership planning or advancement, improvement step to mission objective, businessman on mountain looking for next target.
Resources

Chile’s Open Finance System: Your Guide to Get Started

An Ozone API & Finerio Connect Article Most Open Finance debates in Latin America still centre on what the rules will say, but not Chile. The Sistema de Finanzas Abiertas (SFA) is defined in law, its technical annex is published, and every deadline that matters is already counting down. What’s left isn’t interpretation, it’s execution....

Ozone API and Finerio Connect
25, Aug 2026