UAE banks and insurers are now required to hand your financial data to licensed third parties when you consent, and to let those parties start payments from your account. Here is what you are actually agreeing to, how long that consent lasts, and who pays when something goes wrong.

Open Finance is the Central Bank’s framework for letting you share your own banking and insurance data with companies other than the institution holding it, and for letting those companies initiate transactions on your accounts. It is not optional for the banks. Participation is mandatory for every licensee within the scope of the regulation, and they must build and maintain the interface that makes it work.

What is optional is your participation. Nothing moves without your explicit consent, that consent is capped at twelve months for a recurring arrangement, and you can withdraw it at any time by a process the provider must make as easy as giving it in the first place.

This guide works from the in-force text of the Open Finance Regulation, Circular C 03/2025, issued on 10 July 2025, which repealed and replaced the original 2023 regulation. It covers exactly which of your products are in scope, the seven things a licensed provider is banned from doing, who is liable for an unauthorized transaction or a data breach, and the specific terms you should look for before you tap Allow.

What Open Finance Actually Is

The framework has three parts, all defined in the regulation: an API Hub established by the Central Bank, which includes a Trust Framework, plus a set of Common Infrastructural Services. Together they give a licensed third party one secure connection into the market rather than a separate deal with each bank.

What Is Open Finance in the UAE?

Open Finance is a Central Bank framework that lets you authorize a licensed third party to read your financial data across banks, finance companies, payment providers, exchange houses and insurers, and to initiate transactions on your accounts. Access runs through a centralized API Hub, requires your explicit consent every time, and is limited to companies holding a Central Bank Open Finance License.

The Central Bank describes it as the first consolidated trust framework and centralized API hub of its kind, giving a single secure connection to the whole banking and insurance market with access granted only on customer consent and only to Central Bank-regulated third parties. Implementation began with open banking, with open insurance following.

Data Sharing and Service Initiation Are Two Different Permissions

The regulation splits the activity in two, and a provider can be licensed for one or both. Data Sharing means an online service that gives you consolidated information about one or more accounts or products held with a data holder. Service Initiation means the provider starts a transaction on your account.

The distinction matters when you approve a permission screen. An app that only reads your balances and transactions is doing something meaningfully different from one that can move money, and the regulation attaches different consent rules and different liability to each.

Which of Your Products Are in Scope

Article 5 of the regulation lists thirteen categories of account and product covered when offered or issued by a licensee. The list runs far wider than a current account.

  • Deposits, savings accounts and term deposits.
  • Payment accounts and payment services.
  • Credit, debit and charge card accounts and products, including card acquiring and processing.
  • Standing orders and direct debits.
  • Stored value facilities, prepaid payment accounts and post-paid payment accounts.
  • Foreign exchange accounts and products.
  • Credit, loans and other personal finance products.
  • Mortgages and other loans secured on property or other assets.
  • Virtual accounts or products providing for any of the above.
  • Insurance products, including life and general insurance.

One significant carve-out sits at Article 5(3): accounts or products regulated by the Securities and Commodities Authority are excluded unless the SCA approves their inclusion. Your brokerage and securities holdings are therefore outside the framework, so a budgeting or wealth app cannot pull them through Open Finance the way it pulls your bank data.

Which Institutions Have to Take Part

Participation is mandatory for banks incorporated in the UAE, branches and representative offices of foreign banks, specialized and restricted license banks, Islamic banks and Islamic windows, finance companies, payment service providers in categories 1 to 4, retail payment systems providers, stored value facility providers, exchange houses, loan-based crowdfunding companies, insurance brokers and insurance companies.

Onboarding runs in phases announced by the Central Bank rather than all at once, so the practical answer to whether your own bank is connected is that it depends on where it sits in the sequence. Article 15 requires those institutions to build a dedicated interface for secure online access through the API Hub and to register under the Trust Framework within 14 days of Central Bank approval.

The Seven Things a Licensed Provider Cannot Do

Article 4 is the most useful part of the regulation for a consumer, because it draws hard lines around what an Open Finance Provider is permitted to do with the access you grant. These limitations apply unless the provider separately holds another Central Bank license for the relevant activity.

Prohibited What it means for you
Receiving, holding or transferring funds on your behalf Your money never sits with the app; it moves between your own accounts
Giving advice on a particular account or product An Open Finance app cannot tell you which mortgage to take
Giving any personal, specific recommendation Generic comparisons are allowed; a tailored recommendation is not
Receiving a fee or commission from a product provider The provider cannot be paid by the bank whose product it shows you
Processing sensitive data, even with your explicit consent You cannot waive this one; consent does not unlock it
Negotiating or entering into any agreement on your behalf It can start a payment you authorized, not sign you up to a product
Any form of insurance intermediation or underwriting Reading your policy data is not the same as broking you a new one

The fourth line is the one worth dwelling on. A commission ban means an Open Finance Provider’s business model cannot be paid referrals from the institutions whose products appear in its comparisons, which removes the incentive that distorts a lot of financial comparison content. If an app is recommending a specific product to you personally, either it holds a separate license for that or it is operating outside Article 4.

Article 4(2) permits providers to show you information and analysis about commercially available but non-specific products, so a screen that says which category of account tends to pay more is fine, while one that says you should switch to a named bank’s account is not. If you want a regulated adviser rather than a data tool, our guide to robo-advisors in the UAE covers a different licensing category.

Article 22 sets the consent standard, and it is stricter than the tick-box most apps train you to accept. Nothing can be processed without your explicit consent, and the regulation prescribes what a valid consent looks like.

How Long Does Open Finance Consent Last?

For a recurring transaction, your consent must specify the period for which it is valid, up to a maximum of twelve months. Any consent can be withdrawn at any time and for any reason on notice to the provider, and the provider must tell you about that right and how to use it at the moment consent is taken.

The regulation adds a detail that is easy to skip and worth insisting on: withdrawing consent should not require undue effort and should be at least as simple, quick and easy as the process of giving it. An app that lets you connect in two taps but requires an email to a support address to disconnect is not meeting that standard.

Valid consent must also be specific to the purpose it is given for, informed, unambiguous and freely given, expressed through a clear and affirmative statement or action. Where the processing covers multiple purposes, consent has to be obtained for each purpose in a clearly distinguishable way, which rules out one blanket approval covering several unrelated uses.

Consent for a Payment Is Per Transaction

Where a provider is initiating a payment rather than reading data, consent is required for each transaction, or, for a recurring transaction, at the point you first set it up along with its parameters. That consent must record the accounts or products involved, the nature of the transaction including whether it recurs, the value, and the beneficiary.

Withdrawing consent does not unwind what was lawfully processed before you withdrew it, and it does not stop the provider retaining data it is required to keep under the regulation’s record-keeping obligations or other applicable law.

Who Pays When It Goes Wrong

Article 21 allocates liability, and it is more favorable to consumers than most people assume. Three separate rules apply depending on what failed.

Who Is Liable for an Unauthorized Open Finance Transaction?

An Open Finance Provider is liable to you for loss or damage where there has been unauthorized access to, or loss of, your data held by that provider. A Service Initiation Provider is liable for the non-execution, late execution or defective execution of a transaction, including a failure to ensure it was properly authorized and authenticated. In a dispute over that, the burden of proof sits with the provider, not with you.

That reversal of the burden is the most practically important sentence in the regulation. Article 21(3) requires the Service Initiation Provider to prove the transaction was correctly processed, with supporting evidence, rather than requiring you to prove it was not. Where the fault lies with the institution holding the account rather than the initiating provider, Article 21(4) makes that institution liable instead.

A security breach leading to illegal, unauthorized or accidental access, alteration, destruction, disclosure or loss of your personal data also exposes the provider to administrative and financial sanctions from the Central Bank, separately from any liability to you. That sits alongside your rights under the UAE Personal Data Protection Law.

What Your Terms and Conditions Must Contain

Article 20 requires a provider to give you written terms and conditions before the relationship starts, in clear, plain and understandable language, available in at least Arabic and English. It also sets a minimum content list, so if any of the following is missing, the terms are non-compliant.

  • A schedule of fees and charges.
  • The provider’s legal name and registered address, and its agent’s address where relevant.
  • The communication channels between you and the provider.
  • The manner and timeline for you to notify an unauthorized, delayed or incorrect service initiation.
  • Your respective liability for unauthorized transactions.
  • The provider’s complaint procedures and how disputes with you are resolved.
  • The procedure for reporting unauthorized transactions.

Where the provider is contractually entitled to change those terms, it must give at least 60 calendar days’ notice, and you are entitled to terminate the relationship at no direct or indirect cost if you do not accept the change. That is a materially better deal than most app terms offer, and it exists because the Central Bank wrote it in. It sits alongside the separate cooling-off period on UAE bank and insurance products.

If a provider will not resolve a complaint, the escalation route is the same as for any regulated financial institution, covered in our guide to taking a bank or insurance complaint to Sanadak. Article 35 confirms that Open Finance Providers and the API Hub are subject to the applicable consumer protection laws and regulations.

Why Screen Scraping Is Now Prohibited

Before Open Finance, some apps got your bank data by asking for your online banking username and password and logging in as you. Article 15(2) shuts that down: no person may engage in data scraping or any similar data extraction activity to undertake activities subject to the regulation, except as permitted under applicable law.

The same provision bans intercepting digital connections between a licensee’s public interfaces and its other systems, including by reverse engineering an online or mobile banking app. The practical rule for you follows directly: a legitimate Open Finance app never needs your banking password, because it authenticates you through your own bank’s login and gets data through the API Hub.

Treat any request for your online banking credentials by a third-party app as a red flag regardless of how the app describes itself. Handing them over also typically breaches your bank’s own terms, which can complicate a later claim if your account is compromised or frozen while the bank investigates.

What Open Finance Is Useful For, and What It Is Not

Open Finance is infrastructure, not a product, so the benefit reaches you through whatever apps are built on it. The realistic near-term uses are aggregation and initiation.

What it enables What it does not do
Seeing accounts at several banks in one app Move your accounts or close any of them
Sharing verified income and transaction history with a lender Change your credit score or what a lender decides
Initiating a payment from within a merchant’s app or site Give you card-style chargeback rights on that payment
Getting quotes for financial products Recommend a specific product to you personally
Pulling policy data from your insurers Broker or underwrite insurance for you
Reading bank, finance company and exchange house data Reach securities accounts regulated by the SCA

Note the third row. A payment initiated through Open Finance is a push payment from your own account, so it does not carry the card network’s dispute machinery described in our guide to the chargeback and Central Bank dispute process. What it does carry is Article 21 liability against the initiating provider, which is a different and narrower remedy.

Open Finance also sits alongside, not on top of, the Central Bank’s other infrastructure. Instant transfers and the national card scheme are separate initiatives under the same Financial Infrastructure Transformation programme, covered in our guide to how Aani and Jaywan work.

Practical Checks Before You Connect an App

The regulation gives you rights, but only if you use them at the point of connection rather than afterwards. Four checks take under a minute.

  • Confirm the provider is licensed. Only Central Bank-licensed Open Finance Providers, and certain licensees deemed licensed under Article 3, may offer these services. Ask the app to name its license.
  • Read what the permission covers. Consent must be specific to a purpose, so a screen that bundles unrelated purposes into one approval is not meeting Article 22(2.3).
  • Check the duration. A recurring consent cannot run past twelve months, so a permission described as permanent or indefinite is wrong.
  • Find the disconnect button before you connect. If withdrawing takes more effort than granting, that is a compliance failure and a reason to walk away.

We could not obtain a published, public register of licensed Open Finance Providers from the Central Bank at the time of writing, so verification currently depends on asking the provider and, where you are unsure, asking your own bank whether it recognizes that provider on the Trust Framework. That is a genuine gap in the consumer-facing side of an otherwise detailed framework.

Frequently Asked Questions

Is Open Finance in the UAE compulsory for me?

No. Participation is mandatory for the institutions, not for you. Banks, finance companies, payment providers, exchange houses, crowdfunding companies, insurance brokers and insurance companies within scope must build the interface and provide access, but nothing about your data moves without your explicit consent, and you can withdraw that consent at any time.

Can an Open Finance app take money out of my account?

Only a provider licensed for Service Initiation can start a transaction, and only with your consent for that specific transaction, or, for a recurring arrangement, the consent you gave when you set it up with its stated value, beneficiary and parameters. Article 4 separately prohibits any Open Finance Provider from receiving, holding or transferring funds on your behalf, so the money moves between your accounts and never sits with the app.

How long does an Open Finance consent last?

For a recurring transaction, the consent must state its validity period and cannot exceed twelve months. Any consent is withdrawable at any time and for any reason on notice to the provider, and the provider has to tell you about that right and explain how to exercise it when it takes the consent. Withdrawal does not affect processing that already lawfully happened.

Does Open Finance cover my investment account?

Not usually. Article 5(3) excludes accounts and products regulated by the Securities and Commodities Authority unless the SCA approves their inclusion, so brokerage and securities holdings sit outside the framework. Bank deposits, cards, loans, mortgages, foreign exchange products, stored value facilities and insurance policies are all in scope.

Is it safe to give an app access to my bank data?

The regulation restricts access to Central Bank-licensed providers, requires strong authentication and secure communication, and makes the provider liable for unauthorized access to or loss of your data. The real risk is granting access to something that is not licensed at all. A legitimate Open Finance app never asks for your online banking password, because credential-based screen scraping is expressly prohibited under Article 15(2).

Can an Open Finance app tell me which bank account to switch to?

No, not as a personal recommendation. Article 4 bars an Open Finance Provider from giving advice on a particular account or product or making any personal, specific recommendation, unless it separately holds the license required for that activity. It may show you information and analysis about commercially available but non-specific products, which is a comparison rather than a recommendation.

Can the app be paid by the bank whose products it shows me?

No. Article 4(1.4) prohibits an Open Finance Provider from receiving any fee, commission, payment or other benefit from the provider of an account or product. That is a structural protection against the referral-commission model that shapes a lot of financial comparison content elsewhere.

What if a payment initiated through an app fails or goes to the wrong place?

A Service Initiation Provider is liable to you for the non-execution, late execution or defective execution of a transaction, including where it failed to ensure the transaction was properly authorized and authenticated. If it disputes that liability, the burden is on the provider to prove the transaction was correctly processed with supporting evidence. Where the fault lies with the institution holding your account instead, that institution is liable.

Which banks are live on Open Finance?

Onboarding is phased and announced by the Central Bank through official channels rather than fixed in the regulation, with the first phase covering all banks including branches of foreign banks, and insurance companies. There is no single published consumer-facing list of which institutions are live at a given moment, so the practical answer is to ask your own bank.

How is Open Finance different from Aani?

Aani is a payments rail that moves money instantly between UAE accounts using a phone number or QR code. Open Finance is a data and initiation framework that lets a third-party app read your financial data across institutions and start transactions on your behalf with your consent. Both come out of the Central Bank’s Financial Infrastructure Transformation programme, but they solve different problems and you can use either without the other.

Official Sources

This article references the following official sources:

This guide is for general information and is not financial or legal advice. Information is current as of August 2026. The Open Finance Regulation comes into effect in phases notified by the Central Bank, so a requirement described here may not yet apply to a particular institution or product on a given date. No public consumer-facing register of licensed Open Finance Providers, and no institution-by-institution list of which banks and insurers are live, was obtainable at the time of writing; confirm a provider’s licensed status with the provider and with your own bank before granting access. Never share online banking credentials with any third-party application.