Open-banking architectures make one party's API another party's product: when the account-information or payment-initiation interface fails, the consumer's outcome — a declined payment, a stale balance, a broken application — lands on the brand that issued it, and the question of who bears the loss is decided by a lattice of regulatory liability rules and contract clauses that most programs only read after their first material outage. In the EU, PSD2's liability architecture has been litigated for a decade; in the US, the CFPB's open-banking rulemaking and its contested transition made interface duties a contract matter again. The engineering is shared infrastructure; the exposure is asymmetric.
3G Times publishes information, not legal advice. Liability allocation is regime- and contract-specific, and this analysis addresses the architecture rather than any party's obligations.
What does the regulatory lattice assign?
Europe's PSD2 stack is the most developed mapping. For account information services, the account-servicing institution owes availability — 99.5 percent annualized, measured excluding scheduled maintenance — and correct data to authorized third parties, with "correct data" meaning consistency with what the institution's own channels show. For payment initiation, the third-party provider steps into a liability frame: unauthorized-payment losses sit with the account-servicing institution where the defect is theirs, and with the PISP where it is the PISP's, while the payer's own institution cannot debit a payment the PISP did not properly initiate. The lesson generalizes beyond the EU: when the law names interface duties, it also names who eats the failure — and where the law does not (the US state of play), the same allocation happens in commercial paper with less supervision and more variance.
What should the API-gateway contract actually say?
The market's mature clauses cluster into four families. Service levels: availability measured at the interface with a defined measurement point, latency bands for read and initiation paths, error-rate thresholds, and maintenance windows negotiated around the consumer product's own promises. Consequences: service credits for misses (the cheap remedy), and — the negotiated line — liability for consequential consumer losses where the failure was prolonged or negligent, with carve-outs for force majeure read narrowly enough that "the cloud had a bad day" is not a defense the drafters assumed. Data warranties: the provider warrants correctness and freshness within stated bounds, because downstream decisions — credit offers built on stale balances — inherit the error silently. Remediation: incident notice timelines, joint post-mortem duties, and data-correction paths that run faster than the billing cycle.
| Failure mode | Consumer-visible harm | Allocation lever |
|---|---|---|
| Interface outage | Declined payments, dead applications | SLA measurement point; loss-sharing above threshold |
| Stale or wrong data | Bad offers, failed underwriting | Data warranties; freshness bounds |
| Initiation defects | Unauthorized or duplicated payments | Regulatory liability rules; error-correction duties |
| Rate limiting | Throttled journeys, partial failures | Quota engineering; degradation playbook |
Why do consumer-outcome duties travel to the brand?
Because every regime on the map holds the consumer-facing institution responsible for the consumer's outcome regardless of whose middleware failed: the Reg E error-resolution clocks run from the consumer's report to their institution, not to an API vendor; unfairness doctrines evaluate the journey the brand shipped; and prudential supervisors read third-party interface dependencies as the institution's operational risk under the resilience frameworks. The contract cannot delegate the duty — only the loss. That asymmetry is the architecture's core fact: institutions operate interfaces they do not control, own outcomes they did not cause, and negotiate the difference into indemnities, SLAs, and exit rights that price the risk transfer honestly or discover its market price in an incident.
How does the US picture differ in practice?
The CFPB's Section 1033 rulemaking, adopted in late 2024 and contested since — including the compliance-timeline revisions that followed — set a federal frame for data access that remains in transition; in the interim, US open-banking runs on network standards, aggregator relationships, and the liability rules of the payment rails themselves (Reg E, card networks, NACHA). Practically, US programs write European-style clauses without European-style supervision: availability and correctness warranties matter more, because no regulator's measurement regime backs them, and the aggregator market's consolidation has made exit rights — data portability, transition assistance — the clause that decides negotiating leverage years later.
What does this mean in practice?
- Define the measurement point before the SLA number. Availability measured at the provider's edge and at the consumer's screen are different products; the contract should promise the one the journey depends on.
- Warrant data, not just uptime. Correctness and freshness bounds convert silent failures into compensable ones.
- Engineer degradation, not just recovery. Rate-limit playbooks, cached-fallback disclosure, and partial-journey design decide whether an outage is an inconvenience or a consumer-harm event.
- Rehearse the joint post-mortem. The incident that names both parties' engineers finds the truth faster and the liability slower — which is usually the right order.
Open banking's legal content is ultimately about made promises around shared pipes: the institution that promises the journey owns its failures, and the paperwork that reallocates the cost is the difference between an outage and a dispute. The best programs are known by their contracts before they are known by their incidents.
The consumer-communication layer belongs in the same file: degraded-journey disclosure — what the app tells the user when the pipe is slow or stale — is both an unfairness question and a liability-mitigation one, because the documented, disclosed limitation reads differently in every forum than the silent failure. The playbook that pre-writes the degradation notice turns an outage's legal character from concealment into candor.
How should smaller fintechs negotiate against asymmetric power?
By buying standards instead of bespoke terms: industry-standard SLA templates, recognized measurement definitions, and portability commitments are cheaper to demand as "market" than as favors. The alternative — accepting the provider's paper whole — prices the risk transfer at zero until the first incident invoices it at full value.
Where does resilience regulation re-enter?
Through the dependency inventory: interface providers are critical or important business services under the operational-resilience regimes, meaning impact tolerances, exit planning, and register entries attach to the same relationship the SLA governs. Programs that align the two files — tolerance statements quoted in contracts, exit plans priced in portability clauses — answer resilience exams and renewal negotiations from one document.
Frequently asked questions
Who pays when a payment-initiation API double-fires?
The payment rails' error-correction rules reach the consumer first — the institution restores per the applicable regime — and the institutions allocate between themselves by the contract's defect-allocation clauses. The consumer never waits for the allocation.
Can SLAs really price a multi-day outage?
Service credits cannot; that is why the negotiated line is consequential-loss sharing above thresholds. The draft question is what the counterparty's own resilience obligations (their regulators, their cloud) already guarantee — buy the gap, not the blanket.
Recovery-time honesty completes the architecture: contracts quote MTTR figures the responders did not write, so the table-top exercise — both parties' engineers, one injected outage, a clock — turns the number into a rehearsed capability. The SLA that survived rehearsal is the only one worth negotiating around.
What is the aggregator-consolidation angle?
Concentration: fewer interface providers mean more institutions on the same failure domain, which regulators' resilience frameworks read as systemic. Exit rights and portability clauses are the competitive discipline that keeps the dependency negotiable.
For more context, read Fed's Payment-Account Proposal Draws Industry Comments: Direct Settlement Access for Fintechs Advances.
For more context, read iso 20022 fedwire migration.
For more context, read app store privacy labels compliance.

