Breaking Down the Silos: What Uruguay’s New Open Finance Decree Means for the Market
Uruguay’s financial sector is standing at the edge of its biggest structural shift in a generation. The Banco Central del Uruguay (BCU) recently published its draft bill (anteproyecto de ley), formalised as resolution P_2_2026, establishing a nationwide Open Finance System (Sistema de Finanzas Abiertas). It sits inside the BCU’s broader Hoja de Ruta del Sistema de Pagos, and it isn’t just a policy update. It’s an architectural rewrite of how financial data, payments, and customer relationships work in Uruguay.
We’ve seen this sequence before: first in the UK, then Brazil, then Australia. A regulator publishes a data-ownership mandate, incumbent banks resist the up-front capex, and eighteen to twenty-four months later the market looks unrecognisable.
If you’ve been following Brazil’s rollout, you already have a rough sense of where this goes. Brazil’s foundational regulation was published in May 2020, and by June 2026 , the Banco Central do Brasil was reporting 220+ million active data-sharing authorizations from 130+ millions unique users , with Pix payments initiated via Open Finance growing from 546,000 transactions in July 2024 to 50+ million in Q2 2026, (all figures from the Banco Central do Brasil). That’s the trajectory a market steps onto once the plumbing is in place. We covered a near-identical structural shift in our breakdown of Colombia’s Decree 0368 earlier this year, and the pattern in Uruguay’s text is familiar down to the clause level.
Here’s what the BCU decree actually requires, how it stacks up against what we’ve watched happen in the UK, Brazil, Mexico, and Australia and is happening in Chile, Colombia and Peru, and what that comparison means for banks, FinTechs, and regulators working through the Uruguayan market today. For broader regional context, see our state of Open Finance in Latin America report.
For decades, financial institutions treated user transactional data as proprietary property. The BCU’s framework flips that premise entirely: data belongs to the end user, and financial institutions are custodians, not owners. Under the draft bill, users can share their data with registered third parties, or revoke that access, whenever they choose.
This isn’t a Uruguayan invention. It’s the same founding principle behind open banking everywhere it has been tried, from the UK’s 2016 mandate through Brazil’s 2020 regulation. What changes market to market is how tightly the consent mechanics are specified. Uruguay’s draft is unusually explicit:
Key rules of consent:
Every market we’ve watched run this playbook has treated consent granularity as the detail that separates a working system from a lawsuit-generating one. Uruguay writing it into the primary legislation, rather than leaving it to secondary rulemaking, is a good early sign.
The BCU draft doesn’t invent a new market structure so much as import a proven one. The same three-role taxonomy underpins open banking in the UK, the EU, and across Latin America: a regulated data holder, a regulated data user, and the consumer who authorises the connection between them.
Information Access Providers (PAIs) are the incumbents: banks, credit unions, and regulated payment entities that hold user accounts and financial history. Under the decree, PAIs must build, maintain, and expose standardised APIs to transfer that data on request.
Third-Party Service Providers (TPSs) are the financial entities, FinTechs, personal finance platforms, and software providers registered with the BCU. They consume the data PAIs expose to build products, from consolidated dashboards to instant credit scoring. They can also qualify as Payment and Service Initiation Providers.
For full definitions of PAI, TPS, PISP, and how they map to equivalent terms like AISP and TPP in the UK and EU frameworks, see our glossary.
The BCU draft includes a number of technical mandates we have seen written into existing infrastructure in other markets, which indicates the regulators have been learning from the struggles and successes of other regions.
The death of screen scraping. FinTechs in many emerging markets have historically relied on screen scraping, asking users to share their online banking log in credentials so that the third party can log in and access the data. The BCU decree bans that outright. All data transfers must run through encrypted, standardised APIs managed by the PAIs. The UK faced the identical problem before its own API mandate took hold: FDATA estimated that roughly 2 million UK customers were relying on screen-scraping to connect their accounts to third-party apps, a method its chair Gavin Littlejohn called “never what we would have chosen” (Open Banking Limited, 19 December 2017). Banning the practice in law, as Uruguay has done, tends to move faster than waiting for the market to phase it out on its own.
Direct payment initiation. By permitting payment initiation, the BCU opens the door to Account-to-Account (A2A) payments. E-commerce merchants will eventually be able to offer “Pay with Bank Account” at checkout, at a fraction of card processing fees. This is where the commercial case stops being theoretical: UK open banking payments hit 31 million in March 2025 alone, up 70% year over year, against 13.3 million active users and 145 live-to-market TPPs (Open Banking Limited, Impact Report 7, 16 May 2025). Brazil’s Pix-via-Open-Finance volume, cited above, grew nearly 100x in the 24 months to June 2026 . Payment initiation is the feature that turns a compliance mandate into a revenue line.
Infrastructure costs fall on incumbents. The regulation puts the cost of building and maintaining API infrastructure on the PAIs. That means near-term capex for incumbent banks, but it also sets a reliable, secure baseline for the whole system. It’s worth being honest about how that plays out under time pressure: in the UK’s CMA9 rollout, 6 of the 9 mandated banks missed their original 13 January 2018 API deadline. Barclays delayed to 7 February 2018, HSBC’s payment functionality slipped to 28 February 2018, and some of Santander’s functionality didn’t land until January 2019 (New Statesman, 31 January 2018, citing the CMA’s published compliance directions). Regulatory deadlines and engineering timelines rarely match on the first attempt.
Building all of this in house is costly and complex. Plus it is an ongoing challenge as in most markets there are multiple phases with the regulatory frameworks and standards continuing to evolve.
How long does this actually take? Leveraging a specialist platform to deliver compliant open banking APIs that keep up to date with future changes to the regulations and standards (like Ozone API) is a much faster and lower cost route to comply.
Publishing a decree and running a live ecosystem are two different projects, and the gap between them varies enormously by market:

Uruguay’s draft is closer in structure to Brazil’s than to Mexico’s: it pairs the data-ownership mandate with concrete API and consent requirements rather than leaving them for later. That’s the detail worth watching as secondary regulation is drafted.
| Industry Actor | The Big Opportunity |
| FinTechs & Startups | Rapid onboarding, instant credit analysis from historical bank data, lower customer acquisition cost. |
| SMEs & Merchants | Cheaper payment acceptance through A2A payments, faster access to working capital based on verified cash flow. |
| Incumbent Banks | Partnerships with agile tech firms, modernised internal API architecture, embedded financial products beyond their own apps. |
| Consumers | Single-app views across accounts, faster loan approvals, personalised financial planning. |
For incumbent banks specifically, the opportunity is bigger than defense. Once the API layer exists, it can be turned into a product line rather than just a compliance cost, through premium APIs and embedded finance APIs. We go deeper on that shift in Commercialising Open Banking: A Practical Guide.
For Tech Teams: The reality is that open banking requires a set of capabilities that you are unlikely to have in your existing technology stack. That means delivering APIs that meet the specific market standards. Supporting the specific security requirements such as FAPI 2.0. Handling the fine grained consent management to ensure only the right customer authorised access to trusted TSPs and PISPs. Building this in house has been a complex and costly process for many banks that have tried it.
For Product Leaders: Open Finance is more than a compliance project, at least it should be. This is a moment that has the potential to transform the banking business model. How and where your customers engage with their accounts with you and how you partner with other technology platforms you use. Whether you embrace it strategically or not things will change. Product Managers should develop clear strategies to determine how the open banking APIs can enable deeper partnerships with platforms their customers use. They should consider how the APIs can become a channel, not just to serve but to grow customers relationships (by embedding what you do, where your customers are). They also need to think how the payment landscape will change. Brazil’s Pix-via-Open-Finance volume went from 500k to 50 million million transactions in two years. That’s the kind of adoption curve that rewards whoever is ready to move first, not only whoever moves best.
For Compliance & Risk Officers: For Compliance and Risk officers the big consideration is ensuring your organisation complies and meets the regulatory obligations within the timescales. Whilst we have seen regulators show understanding in different markets, we have also seen them apply corrective measures and actions where banks miss their obligations. But also this is not a one off implementation. In all markets we have seen multiple phases of open finance bringing extensions to scope and functionality as well as new versions of standards. In fact conformance testing and certification has been mandated in a number of markets. Fundamentally though, open finance changes the business model for banking, enabling customers to provide consent to trusted third parties to access their data or make payments on their behalf, creating new considerations. It is a complex and ever changing area and requires expertise.
Uruguay is moving from isolated financial islands to a connected, API-first ecosystem, and the institutions that treat data as a customer asset rather than a proprietary fortress will lead the next wave of Latin American financial innovation. Uruguay is a mature market, with high levels of financial inclusion – top of class in Latin America – and the ideal environment for financial innovation to be created, tested, and readied for export and scaling to other markets.
We’ve watched this exact rollout happen in the UK, Brazil, Colombia, and now Uruguay, because we’ve helped build the standards-compliant API infrastructure behind several of them. That’s the work Ozone API does for PAIs and TPS operators navigating exactly this kind of mandate, across the standards we support globally. If your team is starting to map what BCU compliance means for your architecture, that’s a conversation worth having early.
Fundamentally, this is complex and requires a set of technical capabilities and expertise that typically do not exist in banks pre open finance.
Talking to experts early can really help you shape your plan, understand what is required and shape budgets. We’ve done this for banks around the world. Get in touch to find out how we can help.
Sources (BCU): a. BCU press release (Spanish) b. Resolution P_2_2026 (Spanish, PDF)
Embedded finance is the implementation of financial services within non-financial contexts via standardised API connections to regulated bank infrastructure. Most coverage of embedded finance addresses the opportunity from the non-financial platform perspective: what it means for the retailer, the SaaS company, the marketplace. This piece takes the other angle, addressing what embedded finance means for...
The first half of 2026 has been busy; Colombia made open finance mandatory, Saudi Arabia issued its first commercial open banking licences, the UAE completed one of the most ambitious cross-border open finance experiments in the world, UKPI launched what it calls the first new UK payment scheme since 2008, and in Brussels, a decade-long...
The UAE built a fully operational national Open Finance API Hub in 12 months. The UK took nearly five years. Brazil took almost three. This guide examines the six building blocks, coalition model, and realistic delivery timeline that made that speed possible, and what regulators and central banks need to get right to do the same.