The UK guide to MCP and Open Banking.
UK banking is different. The CMA9, FCA-regulated AISPs, OBIE standards and the Consumer Duty shape what AI assistants can and cannot do with your money.
What MCP means for UK banking
MCP, the Model Context Protocol, is an open standard that lets AI assistants request data and actions from connected services in a structured, machine-readable way. In UK banking, it sits on top of the Open Banking ecosystem. That means an MCP layer does not replace a bank’s API or the FCA rules that govern it; it is a way for an AI assistant to ask a licensed provider for account information or payment initiation and receive an answer it can act on.
For a fintech product manager or founder, the practical picture is this: your AI product can read balances, categorise transactions or trigger payments only if a regulated Account Information Service Provider (AISP) or Payment Initiation Service Provider (PISP) is somewhere in the chain. The AI assistant itself is usually an agent of that provider, not a standalone regulated entity.
Consent must be explicit, scoped and refreshable. Data must be stored under UK GDPR and FCA rules. The 90-day reconsent rule still applies. And the FCA expects firms to treat customer outcomes, including those of vulnerable customers, as part of the Consumer Duty.
The opportunity is real: lower friction for personal finance tools, automated bookkeeping, and conversational banking. The risk is equally real: an unlicensed MCP wrapper can leak transaction history, over-retain data, or blur who is responsible when something goes wrong. The safest path is to treat MCP as a conversation layer that hands off to a licensed, UK-based provider with clear terms.
UK Open Banking vs EU PSD2 for AI agents
| Topic | UK Open Banking | EU PSD2 |
|---|---|---|
| Regulator | FCA, CMA, Open Banking Ltd | ECB, EBA, national regulators |
| Licensing route | AISP / PISP or agent-of-AISP | AISP / PISP under EU passport |
| Consent model | Explicit, granular, revocable | Explicit, granular, revocable |
| Data standards | Open Banking Standard (UK) | Berlin Group NextGenPSD2 / national APIs |
| 90-day reconsent | Required for ongoing access | Varies by member state |
Who can legally expose UK bank data to an AI assistant
In practice, UK account data reaches an AI assistant through licensed Open Banking providers. Common routes include:
- PlaidFCA-authorised AISP and PISP, widely used by UK fintechs for account connectivity.
- GoCardlessOffers bank data services through its Nordigen entity, available as an agent-of-AISP route.
- TrueLayerFCA-authorised as an AISP and PISP, focused on payments and financial data in the UK and Europe.
- YapilyFCA-authorised AISP/PISP providing account information and payment initiation infrastructure.
Agent-of-AISP means a firm can build the user experience and the technology while the licensed AISP holds the regulatory responsibility and maintains the bank connection. If you are evaluating a bank MCP tool, ask which AISP it is an agent of and confirm that relationship on the FCA register.
Questions to ask any bank MCP tool before connecting it
- ✓Is the provider FCA-authorised as an AISP/PISP, or a documented agent of one?
- ✓Does the connection use read access, or can it also initiate payments?
- ✓How long does the provider retain transaction data?
- ✓Can the user revoke consent fully and quickly?
- ✓Is the entity UK-based, or is data processed outside the UK?
- ✓Is the firm registered with the ICO for data protection?
- ✓Does the provider explain what the AI assistant can and cannot do?
- ✓Does it publish how errors, fraud and complaints are handled?
UK banks and open banking coverage
| Bank or banking group | Open Banking API available |
|---|---|
| Lloyds Banking Group | Yes |
| Barclays | Yes |
| HSBC UK | Yes |
| Nationwide | Yes |
| Santander UK | Yes |
| NatWest Group | Yes |
| Monzo | Yes |
| Starling Bank | Yes |
| Revolut UK | Yes |
| Chase UK | Yes |
Frequently asked questions
What is bank MCP?
It is a conversation layer that lets an AI assistant request UK bank data and actions through licensed Open Banking providers, using the Model Context Protocol to structure those requests.
Do I need to be regulated to build one?
If your service accesses account data or initiates payments, you need FCA authorisation as an AISP or PISP, or you must operate as an agent of one.
Can an MCP tool store my bank transactions?
Only with valid consent and in compliance with UK GDPR and ICO requirements. Retention should be limited, justified and disclosed in the privacy notice.
Is this read access only?
It depends on the permissions granted. AISP connections give read access; PISP connections can also initiate payments.
Is bankmcp.co.uk a bank or an app?
Neither. It is an independent information resource and is not affiliated with any bank, MCP project or open banking provider.