The short answer
An Account Information Service Provider (AISP) is a legal entity licensed under PSD2 (Payment Services Directive 2) to read account data directly from your bank via official Open Banking APIs. Before allowing a budgeting app, net-worth tracker, or loan provider to access your bank, you must verify that the operating entity holds an active AISP license on a national financial regulator’s public register.
If an app does not hold an AISP license or operate via a licensed Open Banking aggregator (such as Tink, Plaid, or Nordigen/GoCardless), it may be using unregulated screen-scraping techniques that harvest your banking credentials.
Step-by-Step Verification Guide
Follow this 4-step check before connecting your bank account to any financial application:
Step 1: Identify the Legal Entity
Marketing names often differ from the regulated corporate entity. Scroll to the footer of the app’s website or privacy policy to locate the full legal name and registration/company number (e.g., “Finance App Ltd, company number 123456”).
Step 2: Check National Regulator Registers
Depending on where the fintech is incorporated, search the official public register of the national competent authority (NCA):
- Finland (FIN-FSA / Finanssivalvonta): Search the FIN-FSA Financial Sector Register for authorized payment institutions and AISPs.
- United Kingdom (FCA): Search the Financial Conduct Authority (FCA) Financial Services Register under “Account Information Service Provider”.
- Germany (BaFin): Check the BaFin database of authorized payment institutions.
- Sweden (FI / Finansinspektionen): Search the FI company register for AISP authorizations.
Step 3: Check the EBA Payment Institutions Register
The European Banking Authority (EBA) maintains a centralized register of all licensed Payment Institutions and AISPs across the EU/EEA. You can query the EBA register by company name or country of origin to verify passporting rights across European borders.
Step 4: Verify Aggregator Partnerships (If Applicable)
Many fintech apps do not hold their own direct AISP license; instead, they partner with a licensed Open Banking aggregator. If an app uses an aggregator:
- The consent flow must explicitly name the licensed aggregator (e.g., “Data access powered by Tink AB, authorized AISP by Finansinspektionen”).
- You can verify the aggregator’s license on the EBA or national regulator register.
AISP vs PISP: Knowing the Difference
| License Type | Full Name | Capabilities | Access Level |
|---|---|---|---|
| AISP | Account Information Service Provider | Read-only access to balances and transaction history | Cannot initiate payments or transfer funds |
| PISP | Payment Initiation Service Provider | Authorized to initiate transfers directly from your bank | Can execute payments with your explicit SCA consent |
Reading the register entry properly
Finding the name is the beginning, not the end. A register entry contains four fields worth actually reading, and people routinely stop at the first.
Status. Look for authorised. Other values appear and mean different things: registered is a lighter category in some jurisdictions, and applied for, cancelled, expired or in wind-down all mean the firm is not currently licensed to do this. Cancelled entries stay visible on most registers, which is why “I found them on the FCA register” is not by itself an answer.
Permissions. Account information and payment initiation are listed separately. An entity may hold one, both, or a broader payment institution authorisation. If an app is asking to move money and holds only AISP permission, something is wrong with your understanding of the product or with the product.
Effective dates. Authorisation granted three weeks ago is not disqualifying, but it is context. So is a date that ended.
Regulated address and country. The jurisdiction determines which regulator supervises the firm and where you complain. It is frequently not the country the app appears to be from.
The three complications that trip people up
The app is an agent, not the licence holder. Agents and distributors act on behalf of an authorised firm and appear on registers as agents, not as authorised institutions in their own right. This is entirely legitimate — but your regulatory protection runs through the principal, and the principal is the entity you should be checking. Register entries for agents name their principal.
The app is passported into your country. A firm authorised in one EEA state may provide services across the union under passporting rights without a separate local licence. So a Lithuanian or Irish entity operating in Finland will not appear on the Finnish register as an authorised institution — it appears in the inbound-passporting list, and its home regulator is the one supervising it. Not finding a firm on your own national register is therefore weak evidence of anything. Check the EBA register, which spans the union.
The app uses an aggregator and never names itself. Covered in Step 4 above, and the practical tell is on your bank’s consent screen: the entity named there is the one holding the token. If that name is unfamiliar, it is probably the aggregator, and that is the licence to verify.
When you cannot find the entity at all
Work through this before concluding anything.
Check the terms and conditions rather than the website footer — the contracting entity is named there and it is often a different company from the brand, in a different country. Search the register by company number rather than name, since trading names and legal names diverge constantly. Try the EBA register if the national one is empty, to catch passporting. Look at your bank’s consent screen, which names the actual token holder.
If all four come back empty, the reasonable conclusion is that the app is not operating under a PSD2 licence. That does not automatically mean it is a scam — it may be using screen scraping, which was widespread before PSD2 and has not disappeared — but it does mean you would be handing over banking credentials rather than granting a scoped, revocable token, with no regulator supervising the arrangement.
Red flags that should stop you regardless
- The app asks you to type your online banking username and password into its own screen rather than redirecting you to your bank. This is the single clearest signal, and it is decisive.
- The consent flow never leaves the app to your bank’s own interface.
- The website names no legal entity, no company number and no registered address.
- The named entity exists on the register with status cancelled or in wind-down.
- The app claims to be “regulated” without naming a regulator or a licence category — see “bank-level security” and other claims that mean nothing.
- The terms name a contracting entity outside the EEA while the marketing implies European regulation.
Why License Verification Matters
Connecting your bank to an unlicensed entity exposes your financial data to three severe risks:
- Credential Exposure: Unlicensed apps often rely on screen scraping, requiring you to enter your actual bank login credentials. Read our guide on screen scraping vs Open Banking API.
- Lack of Regulatory Oversight: Licensed AISPs are subject to mandatory security audits, GDPR compliance, and statutory breach notifications overseen by financial regulators.
- Revocation Deficits: Unlicensed apps make revoking access difficult. With a licensed AISP, you can revoke access directly from your bank’s portal. Read our guide on what you actually agree to when an app connects to your bank.
What the licence does not tell you
A licence is a floor, not a recommendation. It means the firm met authorisation requirements — capital, governance, security controls, complaints handling — and is supervised. It says nothing about whether the app is well built, whether its retention policy is reasonable, whether it shares data widely with partners, or whether it will still exist in two years.
Those are separate questions with separate answers, found in the privacy policy and the terms rather than the register. How to read a privacy policy in fifteen minutes covers the retention and sharing side, and AISP or PISP: what the difference means for you covers what each permission actually allows once granted.
Verification takes about five minutes and it rules out the worst outcome. It is worth doing every time, and it is not the whole assessment.