What is open banking, and why Morocco is not there yet
Open banking Morocco explained: how it works, how the EU, UK and Brazil did it, and why Bank Al-Maghrib expects a reference framework only by Q1 2027.
The Sahl Team · · 17 min read
Updated
In short
Open banking lets a customer allow a licensed third party to read their bank data or start a payment through a standard API.
The EU has had it since 2018, the UK has 18.81 million user connections, and Brazil and Saudi Arabia have built their own versions. Morocco has not: Bank Al-Maghrib says the framework is still being drafted.
The central bank's 2025 supervision report expects the reference framework to be defined by the first quarter of 2027. That is a framework, not a launch date.
What is open banking?
Open banking is a rule, not a product. It says that your bank must let a third party use your account data, when you give permission, through a secure interface called an API. No password is shared and no screen is scraped.
There are two uses.
- Reading data. The third party sees balances and transactions. In EU law this is an account information service.
- Starting a payment. The third party sends a transfer from your account without a card. In EU law this is a payment initiation service.
The key word is consent. The customer decides who sees what and for how long, and can withdraw it.
How a connection works, step by step
- The customer picks a service, for example a lender, and chooses their bank.
- The service sends the customer to the bank's own login page or app. The service never sees the password.
- The bank asks the customer to approve a specific scope: which accounts, which data, how long.
- The bank gives the service a token, which is a key limited to that scope and that period.
- The service calls the bank's API with the token and receives the data or sends the payment instruction.
- The customer can see the active permissions in the bank app and cancel one at any time.
83%
How did the EU and the UK do it?
They wrote it into law and gave banks a deadline.
The EU's second Payment Services Directive (PSD2) entered into force on 12 January 2016. Member states had to apply it by 13 January 2018, and the technical security standards applied from 14 September 2019, according to the European Central Bank. The directive itself, Directive (EU) 2015/2366, creates two licensed roles: account information service providers and payment initiation service providers.
A revised directive (PSD3) and a new payment services regulation (PSR) have been proposed.
The UK result is measurable. Open Banking Limited reported on 30 July 2026 more than 1 billion open banking payments and more than 100 billion API calls across the nine largest banks since launch. For June 2026 it shows 40.16 million payments and 18.81 million user connections. A connection is a link between a user and a service, not a unique person, so the number of people is lower.
1 in 5

What does PSD2 require of banks and third parties?
The rules sit in a few articles of Directive (EU) 2015/2366. I read each in the EUR-Lex text.
- Access. Articles 66 and 67 give a payer the right to use a payment initiation provider, and a user the right to use an account information provider, where the account is accessible online. The bank must treat their requests without discrimination other than for objective reasons, and access cannot depend on a contract between the third party and the bank (articles 66(5) and 67(4)).
- Consent and data use. An account information provider may act only on the user's explicit consent, may access only designated accounts, and may not use the data for any other purpose than the requested service (article 67(2)). A payment initiation provider may not hold the payer's funds or change the amount or payee (article 66(3)).
Article 98 asked the European Banking Authority (EBA), working with the ECB, to draft the technical standards. They became Commission Delegated Regulation (EU) 2018/389. Its article 32 requires a dedicated interface to offer the same availability and performance as the customer's own interface, and article 33 says unplanned unavailability may be presumed when five consecutive requests get no reply within 30 seconds. A later amendment, Regulation (EU) 2022/2360, sets 180 days as the interval after which strong customer authentication applies again to account information access through a third party.
What do the UK monthly open banking figures count?
Open Banking Limited was set up as the implementation entity under the competition authority's order, according to its own description. Its figures cover the CMA9, which the July 2026 release defines as the nine largest banks and building societies in Great Britain and Northern Ireland by volume of personal and business current accounts.
Its API performance page defines the metrics. Successful API calls are third-party requests to the banks' APIs that succeeded. User connections are total and new connections using account information or payment initiation in the month, and the page says they count connections, not individual users. Unweighted availability uses, for each bank and each day, the endpoint with the highest downtime, whatever its call volume. Weighted availability weights each endpoint by its share of the day's calls.
The July 2026 release gives June 2026: 2.81 billion API calls (up 4.4% on May, a record), 40.16 million payments, of which 32.43 million single domestic payments (down 1.2%) and 7.73 million sweeping variable recurring payments (up 6.7%), and 18.81 million user connections (down 4.2%). Weighted availability was 99.80%, unweighted 99.35%, and the average response time 349 milliseconds.
How do other countries compare?
The models differ. The EU and the UK used law and regulator orders. Brazil used a central bank rule and tied it to its instant payment system. Saudi Arabia ran a sandbox first.
| Legal basis and regulator | Status (7 October 2026) | Scale | |
|---|---|---|---|
| European Union | PSD2, Directive (EU) 2015/2366; PSD3 and PSR proposed | In force since 13 January 2018; security standards from 14 September 2019 | Not stated in the sources used |
| United Kingdom | Open Banking Limited, set up under the competition authority's order | Live; the 30 July 2026 release shows 18.81 million user connections (June 2026) | Over 1 billion payments, over 100 billion API calls since launch |
| Brazil | Joint Resolution No. 1 of 4 May 2020, Central Bank of Brazil and the National Monetary Council | Open Finance in phases: own data, customer data, payment initiation through Pix, then other products | Pix: 148 million individual users in 2025, about 86% of adults |
| Saudi Arabia | SAMA Open Banking Framework | On 26 March 2026 SAMA said it began licensing fintechs for open banking after the sandbox phase | Not published in the source I read |
| Morocco | No framework in force; Bank Al-Maghrib with the banking association GPBM and the World Bank | Reference framework expected by Q1 2027 | No public usage data |
Sources: ECB, EUR-Lex, Open Banking Limited, Banco Central do Brasil (joint resolution and Pix management report 2023-2025), SAMA, Bank Al-Maghrib. Links in the list at the end.
India shows what consented data sharing looks like at scale. Its Account Aggregator framework is a data-sharing network, not a payments scheme, and it is run under rules of the Reserve Bank of India.
252M+
What has Brazil published about Open Finance?
Brazil's rule is Joint Resolution No. 1 of 4 May 2020, as amended. I read the consolidated text. Article 6 makes participation compulsory for institutions in segments 1 and 2 of the central bank's prudential classification and voluntary for the others.
The central bank's Pix management report 2023-2025 gives one result. Pix payments started through the Open Finance APIs rose from 7.4 million in 2024 to 64.5 million in 2025, and their value from R$3.17 billion to R$15.3 billion.

~80bn
What does an open banking regulation have to define?
The two texts show the topics a rule has to settle. Each cell cites the article I read.
| Topic | European Union | Brazil |
|---|---|---|
| Consent | Explicit consent (articles 66 and 67) | Clear language, stated purposes, validity matched to the purpose; no consent through an adhesion contract, a pre-ticked box or by presumption (article 10) |
| Who can access | Payment initiation providers need EUR 50,000 of capital and indemnity insurance; account information providers are registered and insured (articles 5, 7 and 33) | Compulsory for segment 1 and 2 institutions, voluntary for others (article 6) |
| Security standard | Strong customer authentication, which for remote payments links the transaction to a specific amount and payee (article 97); dedicated interface as available as the customer's (Regulation 2018/389, article 32) | Consent, authentication and confirmation done electronically in the institution's dedicated interface (article 8) |
| Liability | Refund of an unauthorised payment by the end of the next business day; payer loss capped at EUR 50 in stated cases (articles 73 and 74) | Each participant answers for the reliability, integrity, availability, security and confidentiality of the sharing it takes part in (article 31) |
| Fees | Third-party payment orders treated without discrimination in timing, priority or charges (article 66(4)) | Fees between institutions allowed; banned for payment initiation calls and for at least 2 monthly calls per client on registration data and 120 on transaction data (articles 42 and 43) |
| Sandbox | The directive text has no sandbox provision | The resolution text has no sandbox provision; participants agree operating rules in a convention (article 44) |
Saudi Arabia chose a sandbox. SAMA announced on 26 March 2026 that it had begun licensing fintech companies for open banking after the sandbox phase. I could not open its framework document, so I do not compare its terms.
Bank Al-Maghrib's 2025 report states none of these points for Morocco. It describes work on a contractual framework and API standards, not their content.
What is the status of open banking in Morocco?
Morocco has no open banking framework in force today. The regulator says so itself.
In its banking supervision report for 2025, section 2.3 on open banking (printed page 174), Bank Al-Maghrib describes two parallel workstreams:
- A contractual framework agreed with the Moroccan banking association (GPBM). The report says it should govern open banking while strengthening interoperability, control of the risks of data sharing and consumer protection.
- Technical work, with World Bank technical assistance, on API standards and technical prerequisites, and on a governance model.
The report says the work should lead, "à l'horizon du premier trimestre de l'année 2027", to the definition of the reference framework and of the conditions for its progressive rollout nationally. The governor's foreword (page 4) describes the same project as a secure framework for data sharing between banks and fintech providers.
The report speaks of defining a reference framework, not of a launch date. It cites Europe, the United States and Brazil as references, and lists open banking among the new business models appearing in Moroccan fintech.
I found no public consultation by Bank Al-Maghrib on open banking and no statement from the data protection commission (CNDP) on it.
What has Bank Al-Maghrib said about fintech and payments?
The 2025 supervision report covers fintech support on pages 168 to 170. Over three years, Bank Al-Maghrib received requests for regulatory opinions or licences from 48 fintech firms, 13 of them met at the Morocco Fintech Center's regulatory sprint in October 2025. Eight are based abroad. The models presented were mainly payments, crowdfunding and buy now pay later, with digital tontines, open banking and escrow as new ones.
In December 2025 the bank published a guide to the fintech route. A firm asks the Banking Supervision Directorate to clarify the rules, then can ask for a formal opinion, which in principle comes two weeks after a presentation meeting. If a licence is needed, the Credit Institutions Committee gives its opinion before the decision.
At the end of 2025 the supervised institutions included 20 payment institutions out of 95 (page 84).
What do the account figures show?
Bank Al-Maghrib counts 39.8 million bank accounts at the end of 2025, a holding rate of 62% of the adult population, up from 58% a year earlier. It also counts 16.35 million payment accounts, up 18% in a year, held at 14 payment institutions and opened largely for beneficiaries of government aid programmes.
The World Bank's survey gives a more cautious picture, because it asks adults whether they have an account. Its Global Findex 2025 puts account ownership among adults at 44.39% in 2024 and 44.37% in 2021, while the world figure rose from 73.8% to 78.7% (World Bank data API). In Morocco, 34.68% of women had an account in 2024, against 54.63% of men. Only 5.88% of adults had a mobile money account (data), and 31.99% made or received a digital payment in the previous year (data). The women and men figures come from the women and men series.
The two sources measure different things: one counts accounts from supervised institutions and the other counts people in a survey. I do not try to reconcile them.

For the groups with little account data, see thin-file borrowers.
What does Moroccan law already say about sharing data?
Three texts matter today. None of them is an open banking law.
Banking secrecy, Law 103-12. Article 180 of Law 103-12 on credit institutions binds people who handle information about institutions to professional secrecy. It lists who the secret information can go to, including rating agencies, counterparties in credit and other operations, and contractors under an outsourcing agreement. It also allows disclosure "chaque fois que les personnes sur lesquelles portent ces informations les y auront autorisées", that is, whenever the customer has authorised it. So the customer's authorisation is a legal route today.
Personal data, Law 09-08. The law is enforced by the CNDP. Article 4 makes the person's unequivocal consent the main basis for processing, with exceptions such as a legal obligation or performance of a contract. Financial data is not in the list of sensitive data in article 1, which covers origin, opinions, beliefs, union membership and health. Article 43 limits transfers abroad to countries with a sufficient level of protection.
Credit bureaus, Law 01-22. Law 01-22 (Dahir 1-24-12 of 20 February 2024) is about credit information bureaus, not open banking. Its consent rule is useful as a reference: article 30 makes any collection, use, sharing or dissemination of information subject to the consumer's prior consent, and article 1 defines consent as a specific, free and explicit agreement. But article 29 forbids bureaus from being supplied the balances and transactions of savings and current accounts, apart from unpaid cheques. So a bureau cannot become the route for account-level data. Under article 47 the law takes effect when its implementing texts are published, and I found no sign that Bank Al-Maghrib has published them. I come back to this in the thin-file article.
This is a summary, not legal advice. Check with your compliance team before building a product that moves customer data.
About Sahl
At Sahl, we build bank connectivity and verification for lenders. See the platform page, the developers page and the security page.
For business customers as well as your consumers. The KYB document checklist for a Moroccan SARL covers that side.
What to do next
- Lenders and banks: map where you use paper today, and rank each document by how often it delays a decision.
- Fintechs: read section 2.3 of the 2025 supervision report and write down which of your products depend on a bank API that does not exist yet.
- Everyone: check the Bank Al-Maghrib site for the reference framework in the first quarter of 2027.
Glossary
- API: a set of rules that lets one program ask another for data or an action.
- AISP: account information service provider, a licensed firm that reads account data with consent.
- PISP: payment initiation service provider, a licensed firm that starts a payment from the customer's account.
- Consent: the customer's agreement, given for a stated scope and period, and withdrawable.
- CNDP: Commission Nationale de contrôle de la protection des Données à caractère Personnel, the Moroccan data protection authority.
- GPBM: Groupement Professionnel des Banques du Maroc, the banking association.
- PSD2: the EU's second Payment Services Directive.
- Screen scraping: logging in as the customer and reading the bank pages automatically.
- Token: a limited key a bank gives to a service for one scope and one period.
- User connection: the UK's unit of measure, a link between a user and a service.
FAQ
What is open banking in simple terms?
It is a way for a customer to let a licensed third party read their bank data or start a payment, through a secure API, with the customer's permission. The customer stays in control and can withdraw consent.
Does open banking exist in Morocco?
Not as a framework in force. Bank Al-Maghrib's 2025 supervision report says a framework is under preparation, with the banking association (GPBM) on the contractual rules and World Bank technical assistance on API standards and governance. It expects the reference framework to be defined by the first quarter of 2027.
Is my data shared with third parties without my consent?
Under Law 09-08, processing personal data generally needs the person's consent, and the CNDP oversees the law. Under article 180 of Law 103-12, banks can disclose secret customer information when the customer has authorised it, among a few other cases. Ask any provider which consent it collected and why.
How is open banking different from screen scraping?
Open banking uses an interface the bank provides for this purpose, with the customer's explicit permission and no password sharing. Screen scraping logs in as the customer and reads the pages, which is fragile and exposes credentials.
Will open banking replace credit bureaus?
No. A bureau holds repayment history reported by data providers. Open banking gives a lender the customer's own account data, with consent. Law 01-22 bars bureaus from receiving current account transactions.
What does PSD2 require from a bank that offers online accounts?
It must let licensed third parties use the account with the customer's explicit consent, without discrimination and without a contract with them. Regulation 2018/389 requires an interface with the same availability and performance as the customer's own. See articles 66, 67 and 97 of Directive (EU) 2015/2366 and article 32 of Regulation 2018/389.
Can banks charge third parties for data in Brazil's Open Finance?
Fees between institutions are allowed, but articles 42 and 43 of Joint Resolution No. 1 ban them for payment initiation calls and for at least 2 monthly calls per client on registration data and 120 on transaction data.
How does Morocco compare with the UK and Brazil?
The UK reports 18.81 million user connections in June 2026. Brazil built phased rules and a fast payment system, and the central bank reports 148 million individual Pix users in 2025. Morocco is at the drafting stage, with the reference framework expected by Q1 2027.
Sources
All links were opened on 7 October 2026 unless noted. Statistics keep their own reference dates.
Morocco, primary
- Bank Al-Maghrib, Rapport sur la supervision bancaire 2025: open banking section 2.3 (page 174), foreword (page 4), bank and payment accounts, fintech support and the fintech guide (pages 168 to 170), institution counts (page 84).
- Law 103-12 on credit institutions, Dahir 1-14-193, article 180.
- Law 09-08, articles 1, 4 and 43.
- Law 01-22 on credit bureaus, Dahir 1-24-12, articles 1, 29, 30 and 47.
International, primary
- ECB on PSD2 and Directive (EU) 2015/2366 on EUR-Lex.
- Open Banking Limited, milestones release of 30 July 2026.
- Banco Central do Brasil, Joint Resolution No. 1 of 4 May 2020 and the Pix management report 2023-2025.
- SAMA news release of 26 March 2026.
- Directive (EU) 2015/2366, articles 5, 7, 33, 66, 67, 73, 74, 97 and 98; Delegated Regulation (EU) 2018/389, articles 30, 32 and 33 and Delegated Regulation (EU) 2022/2360, opened 7 Oct 2026.
- Open Banking Limited, API performance statistics (August 2026 view) and about page, opened 7 Oct 2026.
- Banco Central do Brasil, Joint Resolution No. 1, consolidated text, articles 3, 6, 8, 10, 31, 42, 43 and 44 and Pix management report 2023-2025, page 17 of the PDF, opened 7 Oct 2026.
- World Bank Global Findex 2025 and the World Bank data API for account ownership.
- open banking
- Morocco
- Bank Al-Maghrib
- PSD2
- open finance