Eight years after the Competition and Markets Authority mandated the nine largest UK current account providers — collectively known as the CMA9 — to open their infrastructure to third-party developers, the country's open banking ecosystem has reached two milestones that redefine its strategic weight: cumulative account-to-account (A2A) payments have crossed one billion transactions, and cumulative API calls have surpassed 100 billion. These are not incremental statistics. They are the benchmarks of a payments network that has decisively outgrown its regulatory origins and become load-bearing infrastructure for British financial services.

Data published by Open Banking Limited confirms that growth is accelerating rather than plateauing. In June 2026 alone, the network processed 2.81 billion API calls — a 4.4 percent increase month-on-month — and recorded 40.16 million successful open banking payments. Average API latency has improved to 349 milliseconds, a 50-millisecond reduction compared to the prior period, while weighted network availability held at 99.80 percent, with unweighted uptime at 99.35 percent. For a system processing nearly three billion calls per month, these are operationally demanding benchmarks to sustain, and the fact that they are improving simultaneously speaks to material investment in core infrastructure by the CMA9 institutions.

The composition of payment volumes is revealing. Single Domestic Payments — the dominant transaction type — posted a modest 1.2 percent decline in June, settling at 32.43 million transactions. That slight softness was more than offset by explosive growth in Sweeping Variable Recurring Payments (sVRPs), which expanded 6.7 percent month-on-month to reach 7.73 million transactions. Variable Recurring Payments allow users to grant standing, consent-based authority for automated A2A transfers within predefined parameters, eliminating the friction of per-transaction approval. Enterprise treasury desks, fintech platforms, and subscription businesses are adopting sVRPs at an accelerating pace precisely because they offer the automation of direct debit with the speed of instant settlement — and without the interchange economics of card networks.

The VRP segment's trajectory deserves particular attention from corporate finance professionals and payments strategists. As sVRPs gain traction in liquidity management, savings automation, and subscription processing, they represent a structural threat to the revenue streams that card schemes and legacy direct debit operators have long taken for granted. The absence of card scheme fees is not a minor detail; for high-volume merchants and treasury operations executing tens of millions of transactions annually, the cost differential between VRP-based A2A rails and traditional card infrastructure is commercially transformative.

The technical architecture sustaining these volumes introduces a distinct and growing security surface. Running a gateway that handles 349-millisecond average response times at 2.81 billion monthly calls requires aggressive rate-limiting, edge caching, and automated load balancing to prevent distributed denial-of-service vulnerabilities during peak periods. The rise of VRPs further complicates the security posture: long-lived, multi-use consent tokens operating under OAuth 2.0 and Financial-grade API (FAPI) standards must be hardened against credential stuffing, token hijacking, and unauthorised consent manipulation. Meanwhile, the instant settlement character of open banking payments — routed over the UK's Faster Payments network — removes the chargeback backstop that card rails provide, making the system acutely vulnerable to Authorised Push Payment (APP) fraud, where bad actors exploit the human layer rather than technical API weaknesses. DevSecOps teams operating in this environment face an architectural imperative: inline, machine-learning-driven threat detection at the gateway layer is no longer optional when sub-350ms response benchmarks make out-of-band fraud checks operationally untenable.

The UK's trajectory also carries direct implications for policy debates unfolding on the other side of the Atlantic. The UK's model was built on top-down CMA enforcement, which created a single technical baseline that accelerated institutional adoption across all nine major providers simultaneously. The United States pursued a different path — bilateral market agreements and screen scraping — but the Consumer Financial Protection Bureau (CFPB) is now driving convergence through its Personal Financial Data Rights rulemaking, pushing US banks and fintechs toward standardised API frameworks modelled closely on the architecture the UK established. The 100-billion API call milestone is, in effect, a live proof-of-concept for US regulators: standardised, mandated API infrastructure can achieve network-grade scale without sacrificing performance or availability.

What This Means for the Industry

The crossing of both cumulative thresholds in the same reporting cycle is more than symbolic. It signals that open banking has completed its transition from a compliance exercise — imposed reluctantly on incumbent banks by a competition regulator — into genuine enterprise infrastructure that financial institutions, corporate treasuries, and technology platforms are actively building upon. The 6.7 percent monthly growth in sVRPs suggests that the next phase of volume expansion will be led by commercial use cases rather than consumer-facing payments, deepening the structural integration of A2A rails into business-critical workflows. For regulators, engineers, and payments strategists alike, the operational benchmarks now on the table — 2.81 billion monthly API calls, 40.16 million monthly payments, 99.80 percent availability — define the performance floor that any serious open finance architecture must be engineered to meet and exceed.

Written by the editorial team — independent journalism powered by Codego Press.