Payment Initiation Service Provider
What Is a Payment Initiation Service Provider (PISP)? Definition and How It Works
Definition
A Payment Initiation Service Provider (PISP) is a regulated third party, licensed under PSD2 and successor frameworks, that initiates payment transactions from a payer's bank account on their behalf via open banking APIs, without the payer needing to access their bank's own interface. PISPs are a foundational participant in the account-to-account payments ecosystem, enabling Pay by Bank, instant bank transfers, and Variable Recurring Payment services.
How it works
PISPs operate under an open banking licence granted by a competent authority, the FCA in the UK, national regulators in EU member states under PSD2 authorisation. Holding a PISP licence grants access to the open banking APIs that banks are required to expose under PSD2 (and PSD3 when implemented): specifically, the payment initiation API, which allows the PISP to submit a payment instruction directly into the payer's bank account infrastructure.
At checkout, the PISP sits between the merchant and the consumer's bank. The merchant's payment provider (often operating as or partnering with a PISP) redirects the consumer to their bank for SCA, the consumer authenticates in their banking app and approves the specific payment. The bank returns an authorisation confirmation to the PISP, and the PISP submits the payment instruction over the bank's API. The bank executes the transfer over its connected domestic real-time rail.
PISPs are distinct from Account Information Service Providers (AISPs), which have read-only access to account data for aggregation and analytics purposes, and cannot initiate payments. A single firm may hold both PISP and AISP licences.
Under PSD2, banks are prohibited from blocking or discriminating against licensed PISPs. They must provide equivalent API access to PISPs as they provide to their own digital banking channels. PSD3/PSR is expected to further strengthen PISP API access rights and reduce technical barriers that have impeded adoption in some markets.
Why it matters
PISPs are the regulated intermediaries that make Pay by Bank and A2A e-commerce payments commercially available to merchants. Without PISP infrastructure, each merchant would need to build and maintain direct API integrations with every bank, an impractical proposition given thousands of banks across even a single market. PISPs aggregate those bank connections and provide merchants a single integration point.
The PISP licence also provides the regulatory framework that gives consumers protection: PISPs are regulated for conduct of business, data handling, and security standards, and are subject to supervisory oversight. This regulation is what allows banks to trust PISP payment instructions and consumers to trust the PISP-powered checkout experience.
Market consolidation is occurring: specialist open banking providers (such as Token, TrueLayer, and Yapily, with Plaid primarily an account information provider that also offers payment initiation in some markets) operate as PISPs and provide API aggregation services to payment providers, fintechs, and merchants, abstracting the complexity of multi-bank connectivity into a single integration.
With PXP
PXP enables Pay by Bank acceptance by integrating with licensed payment initiation service providers, so merchants can offer account-to-account payments alongside cards. Talk to our team about how PXP can support your account-to-account acceptance.
Frequently asked questions
Does a merchant need to be a PISP to offer Pay by Bank?
No. Merchants typically access PISP capabilities through their payment provider, which either holds a PISP licence itself or aggregates access through a licensed open banking provider. The merchant integrates Pay by Bank as a payment method through its payment provider's API without independently obtaining or managing a PISP licence.
What is the difference between a PISP and an AISP?
A Payment Initiation Service Provider (PISP) initiates payment transactions from consumer bank accounts via open banking APIs. An Account Information Service Provider (AISP) has read-only access to bank account data for aggregation, balance checks, and financial management purposes but cannot initiate payments. Both are regulated under PSD2. Some firms hold both licences and combine account data access with payment initiation capabilities.
How does PSD3 change PISP access rights?
PSD3 and the accompanying Payment Services Regulation (PSR) aim to reduce technical barriers that have limited PISP API adoption under PSD2. Key improvements include enhanced API performance requirements, stronger provisions against banks discriminating against PISP payment flows, improved SCA exemption frameworks for low-risk PISP transactions, and clearer liability rules for payment initiation failures.
Revolutionize your business with PXP
Take complete control of your commerce and payments with one platform.
Get Started