Skip to content

Build vs buy: Open Banking connectivity for licensed PISPs

Updated · MVP Payments

A PISP licence grants the right to initiate payments at every bank in the market. Turning that right into working connections is a separate project, and the way a PISP chooses to do it shapes its costs, its margins and its regulatory position for years.

There are three realistic options.

Option 1: build the connections yourself

Building means integrating each bank’s PSD2 interface directly. On paper this is attractive — no dependency, no per-payment fee — and for a PISP serving one country with a handful of dominant banks it can be the right call.

The cost is routinely underestimated, because most of it is not in the first integration.

  • Every bank is its own project. Even within one API standard, banks differ in which authentication approaches they offer, which optional fields they insist on, how they expect requests to be signed and how far they report payment status. The specification tells you the shape; only the bank tells you the behaviour.
  • Onboarding is slow and manual. Developer portal registrations, sandbox access, test certificates and production enrolment each run on the bank’s timetable, not yours.
  • Sandboxes mislead. Bank sandboxes frequently behave differently from production, so a connection that passes every test can still fail on its first live payment.
  • The work never finishes. Banks rotate certificates, upgrade API versions, redesign authentication journeys and retire old endpoints. Connections break without a line of your code changing, and someone has to be watching.

The honest way to cost a build is as a permanent team — engineers who know the banks, and monitoring they can trust — rather than as a one-off project. And none of that spend sets you apart: your competitors’ bank connections do the same job yours do.

Option 2: use an aggregator’s licence

The opposite approach is to buy payments from an Open Banking aggregator. The aggregator holds its own PISP licence, maintains its own connections and sells initiated payments through an API.

For an unlicensed merchant or platform this is exactly the right product. For a firm that holds its own licence, it has three drawbacks.

  • Your licence goes unused. The aggregator is the regulated PISP in the payment flow. The authorisation you worked to obtain adds nothing.
  • You pay for a permission you already hold. Aggregator pricing includes the value of the regulatory cover it provides. A licensed firm is paying for cover it does not need.
  • You are one step further from the bank. The bank sees the aggregator’s certificates. Incidents are diagnosed in someone else’s support queue, and the aggregator’s roadmap decides which banks and features you get.

Option 3: run your own licence on infrastructure

The third option separates the two things the other options bundle together. The PISP keeps the regulated role — its own authorisation, its own eIDAS certificates, its own merchant contracts — and a technical service provider supplies and operates the connectivity underneath.

This is the bring-your-own-licence model. The bank sees the PISP’s certificates and authorisation number. The provider never holds funds and has no relationship with the PISP’s merchants. It is paid for infrastructure rather than for regulatory cover.

The trade-off is that it is an outsourcing arrangement, and the PISP must treat it as one: due diligence, contractual audit and exit rights, and an entry in the outsourcing register. Our guide to outsourcing to a technical service provider covers what regulators expect.

The options side by side

BuildAggregator’s licenceYour licence on infrastructure
Regulated PISP in the flowYouThe aggregatorYou
Whose certificates the bank seesYoursThe aggregator’sYours
Time to first live paymentLongestShortShort
Ongoing engineeringA permanent teamMinimalMinimal
What you pay forSalaries and toolingConnectivity plus regulatory coverConnectivity
Merchant relationshipYoursOften sharedYours
PortabilityFullLow — coverage leaves with the providerHigh — licence, certificates and merchants are yours

How to choose

Build if you serve one concentrated market, connectivity is genuinely part of what you sell, and you can fund a team that will maintain it for good.

Use an aggregator’s licence if you are not licensed and do not intend to be, or if you need a market quickly while your own authorisation is pending.

Run your own licence on infrastructure if you hold — or are obtaining — a PISP authorisation and want its full commercial value without taking on a connectivity engineering function.

That third option is what MVP Payments provides: direct bank connections, AI-driven connectivity monitoring, one API and a white-label hosted payment page, with every payment initiated under your own licence.