
Open Banking in iGaming: Pay-by-Bank Deposits and Payouts
Open banking is moving iGaming money: pay-by-bank deposits, instant payouts, SCA exemptions, and where account-to-account rails beat cards on cost, speed and chargebacks.
- Open banking payments are account-to-account (A2A) credit transfers initiated through bank APIs. The player pushes money; nothing gets pulled. That single design choice removes chargebacks entirely.
- The EU rails are regulated and dated: PSD2 created the API access right in 2018; the Instant Payments Regulation forced eurozone banks to receive instant euro transfers by 9 January 2025 and send them by 9 October 2025. The PSD3/PSR package got political agreement in November 2025 and is expected to apply from around 2027-2028.
- The UK is the maturity benchmark: 351 million open banking payments in 2025, up 57% year on year, running over Faster Payments rails that settle in seconds.
- For iGaming specifically, A2A wins on cost (no interchange or scheme fees), acceptance (no MCC 7995 discrimination), settlement speed, and built-in strong customer authentication.
- Cards still win on universality, one-click familiarity, and offline/fallback coverage. A2A refund flows are also clumsier than card refunds. You need both rails, orchestrated.
- The payout side may matter more than deposits: instant bank withdrawals are one of the strongest retention levers in regulated markets — players who get paid in minutes come back.
The Cheapest Rail in Your Cashier Is the One Banks Built
For twenty years, the online gambling cashier has been a story about cards. Acquirers who'd take MCC 7995, declines that killed a third of first deposits, chargebacks that ate margin and triggered scheme fines. The whole payments conversation in iGaming was really a conversation about managing card pain.
Open banking quietly changed the terms of that conversation. A player taps "pay by bank", authenticates in their own banking app with Face ID, and money moves directly from their account to the operator's — no card number, no scheme, no interchange, no chargeback right. In the UK, open banking passed one billion cumulative payments in July 2026, and gambling has been one of the heaviest commercial users of the payment side from the start.
The interesting question in 2026 isn't whether pay-by-bank works. It's where account-to-account rails genuinely beat cards, where they still lose, and what an operator has to build to capture the difference. That's what this guide covers — with the regulatory dates checked, and the vendor marketing hedged.
What Open Banking and A2A Payments Actually Are
Strip the jargon and open banking is one idea: your bank must let licensed third parties access your account — with your consent — through standardised APIs. Two access types matter. Account information (AIS) reads balances and transactions. Payment initiation (PIS) tells the bank to push a credit transfer out of the account.
Payment initiation is what powers pay-by-bank. The player picks their bank in the cashier, gets bounced to their banking app, approves the payment with their everyday biometric login, and the bank fires a credit transfer to the operator. That's an account-to-account payment: money moves bank to bank, no card network in between.
The direction of the push is the load-bearing detail. Card payments are pull payments — the merchant, holding the card credentials, pulls funds, and the player keeps a dispute right for months. A2A payments are credit-push: the player's own bank executes an instruction authorised inside the bank's security perimeter. No credential for the merchant to store, no pull to dispute, no chargeback mechanism at all.
iGaming found this rail early, for unglamorous reasons. Nordic operators adopted bank-transfer deposits in the 2010s because local card acceptance for gambling was patchy, and companies like Trustly built their books on gaming volume. Open banking regulation turned that regional workaround into a standardised, pan-European access right.
The Regulatory Rails, Fact-Checked
Payment strategy in Europe is downstream of three regulatory tracks. Get the dates right before you plan around them.
PSD2 built the door
The second Payment Services Directive, applied from January 2018 with SCA rules biting from September 2019, did two things that matter here: it forced banks to open account access to licensed third-party providers for free, and it made two-factor strong customer authentication (SCA) mandatory for electronic payments. Every pay-by-bank transaction is SCA-compliant by construction, because the authentication happens inside the bank's own app.
PSD3 and the PSR are nearly done
The review package — a third directive (PSD3) covering licensing, plus a directly applicable Payment Services Regulation (PSR) covering conduct and open banking rules — reached provisional political agreement between the European Parliament and Council on 27 November 2025. The Council published final compromise texts in April 2026, and Parliament signalled it would adopt the package without amendment by September 2026; you can track the file on the European Parliament's legislative train. Entry into force is expected in 2027, with most obligations applying after a transition period — realistically 2028 for operators.
For iGaming the PSR direction is favourable: better-performing, more standardised bank APIs, consumer permission dashboards, tighter fraud liability rules. Nothing in the package winds back payment initiation. The rail is getting stronger, not weaker.
Instant payments are now mandatory in the eurozone
The blocker for euro-zone pay-by-bank was never the API — it was settlement. A standard SEPA credit transfer can take a business day, useless for a casino deposit. The Instant Payments Regulation fixed that with hard deadlines: eurozone PSPs had to receive instant euro transfers by 9 January 2025 and send them — at prices no higher than standard transfers, with mandatory payee-name verification — by 9 October 2025. Non-eurozone EU states follow in 2027; PaymentExpert's guide to the SEPA instant rules lays out the full timeline. Ten-second settlement is now the regulated baseline for euro A2A, not a premium feature.
The UK is the proof of scale
The UK mandated open banking APIs for its nine largest banks in 2018 and runs A2A over Faster Payments, which has settled in near real time since 2008. The result is the most mature pay-by-bank market anywhere: 351 million open banking payments in 2025, up 57% year on year, monthly volumes above 40 million by mid-2026, and 16.5 million active user connections. Gambling was pushed onto this rail partly by regulation — the Gambling Commission banned credit card gambling in April 2020 — and partly because debit-card declines and fees made the alternative attractive on pure economics.
Why A2A Fits the Gambling Cashier
Most industries adopted pay-by-bank for modest cost savings. iGaming's fit is structural, because the industry's card problems are structural.
- No chargebacks, by design. Credit-push transfers carry no dispute mechanism. Friendly fraud — deposit, lose, dispute the charge — simply cannot happen on this rail. For an industry where chargeback ratios threaten acquiring relationships and trigger scheme monitoring programmes, that's not an optimisation, it's an exit from the whole problem class.
- No card economics. No interchange, no scheme fees, no high-risk acquiring markup. A2A providers charge their own fees, but the stack they replace is the expensive one described in our guide to high-risk acquiring in iGaming — gambling merchants routinely pay several times mainstream retail's card rates.
- No MCC 7995 discrimination. Card issuers decline gambling-coded transactions wholesale; some US and UK banks block the MCC outright. A bank transfer has no merchant category code for an issuer's risk engine to veto, so the acceptance rate conversation changes completely. Trustly has reported deposit conversion around 98% — company-reported, but directionally consistent with what operators see.
- Settlement in seconds. Faster Payments in the UK, SCT Inst in the eurozone. Funds arrive near-instantly, which shrinks the float, simplifies reconciliation, and weakens the case acquirers make for a rolling reserve.
- SCA without conversion pain. Card SCA bolted 3DS friction onto a flow that wasn't designed for it. Pay-by-bank is the authentication — the bank app approval satisfies SCA natively.
- Verified identity in the flow. The deposit arrives from a named, KYC'd bank account, and payee verification is now mandatory on SEPA instant transfers. Account-name matching for free, before your own KYC even starts.
Cards vs A2A vs E-Wallets: The Honest Comparison
| Dimension | Cards (debit) | Open banking A2A | E-wallets |
|---|---|---|---|
| Merchant cost | High: interchange + scheme + high-risk markup | Low-mid: provider fee, no interchange | High: often 3-5% for gambling merchants |
| Settlement to operator | T+1 to T+3 | Seconds to minutes | Fast, but funds sit inside wallet system |
| Chargebacks | Yes — plus scheme fine exposure | None (credit-push) | Rare; wallet-level disputes possible |
| Acceptance / declines | MCC 7995 declines, issuer blocks | High approval; limited by bank coverage | High where wallet is adopted |
| Player familiarity | Universal | Growing; strong in UK/Nordics, weak elsewhere | Strong with existing wallet users |
| SCA / fraud posture | 3DS friction, stolen-card fraud | Native bank-app SCA, very low fraud | Wallet login; account-takeover risk |
| Payout support | Slow (card refund rails, days) | Instant credit transfer | Instant within wallet |
| Refund ergonomics | Mature, built-in | Manual: separate outbound transfer | Built-in |
Read that table with cold eyes: A2A dominates the cost, risk and settlement columns, and loses familiarity and coverage. Which is exactly why it's a cashier component, not a cashier replacement.
Where Pay-by-Bank Still Loses
Anyone selling you A2A as the only rail you'll ever need is selling. The gaps are real:
- Consumer habit. Outside the UK, Nordics and Netherlands, most players still reach for a card or wallet on instinct. A payment method converts only if players trust it, and trust follows exposure.
- Coverage gaps. Open banking quality varies bank by bank. A mid-tier bank with a flaky API or clunky app-redirect turns your cashier into an error page. Aggregating providers smooth this, but no one covers everything equally well.
- No credential-on-file model. Cards have decades of tooling for stored credentials and one-click repeat payments. A2A repeat deposits still mean re-authenticating in the bank app each time — variable recurring payments (VRP) are fixing this in the UK, where sweeping VRP volumes nearly doubled in 2025, but commercial VRP for gambling is early.
- Refunds are manual. There's no native "reverse this transfer" primitive. Refunding a deposit means a fresh outbound payment, with its own ops and reconciliation overhead.
- Mobile redirect friction. The app-to-app hop usually works. When it breaks — webview issues, missing bank app, timeout — you lose the deposit at the worst moment. Fallback design isn't optional.
Payouts: Where the Rail Earns Its Keep
Deposits get the attention, but withdrawals are where instant A2A changes player behaviour. The evidence keeps stacking up that fast withdrawals beat bonuses as a retention lever: a player who requests £200 and sees it land in ninety seconds has a different relationship with your brand than one who waits three days wondering if you'll pay. Instant payouts over Faster Payments or SCT Inst make that the default rather than a VIP perk. Trustly reports over 95% of its payouts settling instantly — company-reported, again, but the rail supports the claim.
There's a compliance dividend too. Closed-loop payments — paying winnings back to the same verified account the deposit came from — give AML teams source-of-funds and destination-of-funds visibility that card rails never offered. That's a cleaner audit trail for regulators, a natural control against money-mule patterns, and a quieter life for your compliance function. Brazil's Pix — a central-bank instant rail that became the near-universal deposit method for licensed operators, covered in our Pix payments analysis — is the extreme version of the same lesson: when instant bank rails are ubiquitous, they don't share the cashier. They own it.
How to Add Pay-by-Bank to an iGaming Cashier
iGamingHub's platform reviews keep finding the same pattern: operators rarely integrate A2A providers directly anymore. The method arrives through the platform's cashier or a payment orchestration layer. Platform vendors such as SoftSwiss and EveryMatrix ship cashier modules with pre-built connections to A2A and open banking providers alongside cards and wallets, so adding pay-by-bank is increasingly a configuration and routing exercise rather than an integration project. Here's the sequence that works:
- Map coverage against your player geography — Open banking is not one product. UK Faster Payments, SEPA Instant and Nordic domestic rails all behave differently. List your licensed markets, check which banks your players actually use, and score candidate providers on real bank coverage there — not on the logo wall on their website.
- Route through orchestration, not a single contract — Put A2A behind a payment orchestration layer so you can route by market, bank and success rate, and swap providers without re-integrating. Our guide to payment orchestration in iGaming covers the architecture; the short version is that single-provider dependency leaves you hostage to one API's bad week.
- Build the payout leg first-class — Wire instant withdrawals to the same rail, enforce closed-loop back to the depositing account, and surface the speed in the UI ("arrives in seconds"). The retention value lives here; a deposits-only integration captures half the benefit.
- Design the fallback path — When the bank redirect fails, the cashier should degrade gracefully to card or wallet in one tap, and monitoring should alert on per-bank success rates so you can pull a misbehaving bank out of the default flow before it burns a day of deposits.
- Position the method deliberately — In high-familiarity markets, put pay-by-bank first and label it with the local vocabulary players know. In low-familiarity markets, don't force it — offer it, watch adoption, and let card volume migrate at the player's pace.
What the Numbers Say — and How Much to Trust Them
A caution on market data. UK volumes come from regulated CMA9 reporting and are close to ground truth. Gambling's share of that volume is murkier — Trustly has described iGaming as a substantial share of its UK book, but that's a company statement, not an audited split. The same hedge applies to performance claims: TrueLayer reporting monthly volumes past $10 billion in 2025, Trustly's 98% conversion and 0.008% fraud figures — plausible, company-reported, not independently verified. Treat them as directional evidence that the rail performs; the only conversion numbers that matter are your own, measured against your card baseline.
The direction, though, isn't in dispute. Regulated instant rails on both sides of the Channel, a legislative package that strengthens API quality rather than restricting it, UK volumes compounding at 57% a year, and a gambling industry with uniquely painful card economics. Every structural force points the same way.