Open Banking in Ukraine for FinTech Companies
Open Banking became operational in Ukraine on 1 August 2025. Account-servicing payment service providers (ASPSPs) are banks and non-bank payment service providers (PSPs) that hold payment accounts. Each must give authorised third parties programmatic access to those accounts through dedicated interfaces. The ASPSP implementation deadline was 1 January 2026, and the National Bank of Ukraine (NBU) enforcement grace period expired on 1 August 2026. Both deadlines have passed.
For a FinTech company planning to provide AIS or PIS in Ukraine, client consent alone is not sufficient. A Ukrainian legal entity must obtain NBU authorisation as a non-financial payment service provider; a branch of a foreign payment institution is subject to a separate accreditation procedure. Before connecting to bank APIs, the provider must also obtain a qualified Open Banking certificate for technical authentication.
This article is intended for foreign and Ukrainian FinTech companies, banks, payment institutions, investors, product teams and compliance teams planning to launch AIS or PIS in Ukraine.
Account information services (AIS) and payment initiation services (PIS) are classified as non-financial payment services under the Law of Ukraine on Payment Services No. 1591-IX. A Ukrainian legal entity may provide them without a payment institution licence, but only after NBU authorisation and entry in the Register of Payment Infrastructure. PSD2 authorisation does not apply automatically in Ukraine. A bilateral agreement with the ASPSP is not required for access to the base interface; separate requirements apply to the qualified Open Banking certificate, liability insurance, strong customer authentication and personal data protection.
1. The Ukrainian Open Banking framework
2. AIS and PIS Services for FinTech Companies
3. NBU Authorisation of AISP and PISP
4. NBU Authorisation Procedure and Timeline
5. Market Entry for Foreign FinTech Companies
6. Liability insurance and qualified Open Banking certificates
7. Access to Bank APIs
8. User consent and strong customer authentication
9. Data scope and restrictions for AISP
10. Personal data protection
11. AML, Cybersecurity and Internal Documentation
12. Liability allocation and contracts
13. Open Banking Pre-Launch Checklist
Frequently asked questions
How DLF can help
1. The Ukrainian Open Banking framework
The statutory foundation is the Law of Ukraine on Payment Services No. 1591-IX. The operational rules are set out in NBU Resolution No. 80/2025 on Open Banking, NBU Resolution No. 81/2025 on authorisation of non-financial payment service providers, and accompanying NBU acts.
The Open Banking framework uses the following core designations: ASPSP for an account-servicing payment service provider; AISP for an account information service provider; PISP for a payment initiation service provider; and TPP as the collective term for AISP and PISP.
| Date | Event |
|---|---|
| 1 August 2025 | Open Banking launched: ASPSPs required to provide interface access; AISP/PISP authorisation open |
| 1 January 2026 | Five-month ASPSP implementation transition period expired |
| 3 April 2026 | NBU Resolution No. 32/2026 enters into force: PISP no longer fills in the recipient PSP name field |
| 1 August 2026 | NBU enforcement grace period expired |
| 1 August 2026 — present | NBU may impose supervisory measures; both transition periods exhausted |
| 1 January 2027 | Full volume-linked insurance calculation formula takes effect |
The NBU maintains the public Register of Payment Infrastructure. On 27 September 2026, the NBU Open Banking page listed four third-party providers.
2. AIS and PIS Services for FinTech Companies
The Law distinguishes two non-financial payment services that form the core Open Banking offering for FinTech providers.
Account information service (AIS) means providing consolidated, real-time information about one or more payment accounts that a client holds at one or more payment service providers. An AISP accesses account data but does not move funds.
Payment initiation service (PIS) means initiating a payment instruction, at the payer’s request, from an account held at another PSP. A PISP triggers the payment but does not hold the client’s account.
A provider offering both AIS and PIS must satisfy the requirements for each service separately, in particular for insurance and certificates.
A payment technology operator is a separate regulated role for an entity performing operational, information and other technological functions. That status alone does not make the operator an AISP or PISP.
AIS and PIS are distinct non-financial payment services, so the applicable capital, insurance and strong customer authentication requirements differ.
3. NBU Authorisation of AISP and PISP
AISP
For a Ukrainian legal entity, AIS is classified as a non-financial payment service, so providing it does not require a payment institution licence. NBU authorisation is required instead, resulting in entry in the Register of Payment Infrastructure.
AIS does not appear in the capital table of the Law on Payment Services, so no statutory minimum capital applies to a provider offering AIS exclusively.
PISP
For a Ukrainian legal entity, PIS is likewise a non-financial payment service. A provider offering PIS only requires NBU authorisation and entry in the Register, rather than a payment institution licence.
The minimum statutory capital for a PISP is UAH 1,000,000 (approximately USD 22,000). Where PIS is combined with money remittance without account opening, the minimum rises to UAH 3,000,000 (approximately USD 67,000).
Comparison of Key Parameters for a Ukrainian Legal Entity
| Parameter | AISP only | PISP only | AISP + PISP | Payment institution (financial services) |
|---|---|---|---|---|
| Payment institution licence | Not required | Not required | Not required | Required |
| NBU authorisation + Register entry | Mandatory | Mandatory | Mandatory | Separate procedure |
| Minimum capital | Not set by statute | UAH 1,000,000 (approximately USD 22,000) |
UAH 1,000,000 (approximately USD 22,000) |
UAH 1–10m (approximately USD 22,000–223,000) |
| Insurance (July–Dec 2026) | €110,000 | €110,000 | €180,000 | Separate regime |
| Certificate role attribute | PSP_AI | PSP_PI | PSP_AI + PSP_PI | — |
4. NBU Authorisation Procedure and Timeline
Documents required for a Ukrainian entity
| # | Document |
|---|---|
| 1 | Application and questionnaire |
| 2 | Information notice |
| 3 | Business plan |
| 4 | Liability insurance contract (per NBU Resolution No. 71/2025) |
| 5 | Articles of association and corporate documents |
| 6 | Ownership structure and ultimate beneficial owner (UBO) information |
| 7 | Financial statements with auditor’s report |
| 8 | CVs, criminal record certificates, and credit reports for key persons |
| 9 | Organisational structure |
| 10 | Documents confirming the source of funds |
| 11 | Certificate of no tax arrears |
| 12 | Trade mark documentation |
| 13 | State fee payment confirmation |
Timing and outcome
The NBU reviews the application within 60 business days and may extend the review by a further 30 business days. Legislation does not prescribe an expiry period for the authorisation or require mandatory renewal.
Internal policies and procedures must be adopted within three months of the authorisation date or before the first non-financial payment service is provided, whichever comes first.
5. Market Entry for Foreign FinTech Companies
A foreign FinTech company planning to provide AIS or PIS in Ukraine must select an appropriate form of presence. The principal options are a Ukrainian legal entity or a branch of a foreign payment institution. Direct cross-border provision of AIS or PIS without Ukrainian registration is not provided for under the current legal framework.
Ukrainian Legal Entity
Any foreign company may incorporate a limited liability company (LLC) or joint-stock company (JSC) in Ukraine and undergo the full NBU authorisation procedure.
Branch of a Foreign Payment Institution
The Law permits foreign payment institutions to establish branches in Ukraine. Accreditation of such a branch is a separate procedure. It is not a simplified version of AISP/PISP authorisation.
This route is available to a foreign payment institution, meaning a non-resident legal entity that is entitled under the law of its home jurisdiction to provide payment services. For a company planning to provide only AIS or PIS, the availability of this model should be assessed separately in light of the payment services the parent institution is entitled to provide and the licensing regime applicable to the branch.
Cross-Border Provision of Services
Ukrainian law does not provide a separate mechanism for direct cross-border provision of AIS or PIS from abroad without Ukrainian registration. Market entry therefore requires a form of presence recognised by Ukrainian law and completion of the applicable NBU authorisation or accreditation procedure.
EU PSD2 authorisation
An authorisation obtained under EU law, including under PSD2, does not by itself confer a right to operate in Ukraine. The company must select the appropriate form of presence and complete the relevant Ukrainian procedure: authorisation of a Ukrainian legal entity or, where applicable, accreditation of a branch of a foreign payment institution.
6. Liability insurance and qualified Open Banking certificates
Liability insurance
NBU Resolution No. 71/2025 establishes mandatory minimum indemnity levels for non-financial payment service providers. During the final stage of the transitional period (1 July – 31 December 2026), the minimums are:
| Provider type | Minimum indemnity | Maximum deductible |
|---|---|---|
| AISP-only or PISP-only | €110,000 | 10% |
| AISP + PISP (combined model) | €180,000 | 10% |
The insurance contract must be concluded for one year and remain continuous: each new policy must begin the day after the preceding one ends. Bank guarantees and other financial instruments cannot replace the required insurance contract, which must be issued under Class 13 (other liability insurance).
These figures are transitional. From 1 January 2027, the full volume-linked calculation methodology will apply.
Qualified Open Banking certificates
Requirements for qualified Open Banking certificates are set out in NBU Resolution No. 82/2025.
Before connecting to the dedicated interfaces, every AISP and PISP must obtain a qualified Open Banking certificate after completing the applicable NBU procedure. The certificate identifies the provider and enables the ASPSP to authenticate it technically.
Two certificate types are permitted: a qualified electronic seal certificate or a qualified website authentication certificate, either carrying Open Banking attributes.
Qualified Open Banking certificates are issued by Ukrainian QTSPs included in the Trust List at czo.gov.ua. Certificates issued in the EU under eIDAS standards are not accepted as substitutes for a Ukrainian qualified Open Banking certificate.
7. Access to Bank APIs
Ukrainian legislation provides for a two-tier access model through dedicated interfaces.
| Parameter | Base interface | Commercial interface |
|---|---|---|
| Mandatory for ASPSP | Yes | No (ASPSP’s right, not obligation) |
| Agreement with the bank | Not required | Bilateral contract required |
| Cost to TPP | Free of charge | ASPSP’s commercial terms |
| Data scope | Account balance + transactions for the last 31 calendar days | Extended — defined by contract |
| Access conditions | NBU authorisation + qualified Open Banking certificate | NBU authorisation + certificate + contract |
The base interface is mandatory: any ASPSP must grant free access to any authorised AISP or PISP. Refusal of access without a statutory ground is not permitted.
A bilateral agreement between the AISP/PISP and the ASPSP is not required for access to the base interface. A bilateral contract is required for the commercial interface with its extended data scope.
8. User consent and strong customer authentication
AIS Consent and SCA
To access a client’s account, an AISP must obtain the client’s explicit consent. A single consent may remain valid for a maximum of 180 calendar days, after which a new consent is required.
Two separate time limits apply within the 180-day consent period:
- Consent validity: up to 180 calendar days, the period during which the client’s consent to account access remains effective.
- Strong customer authentication (SCA) cycle: the ASPSP may continue providing access without repeating SCA for up to 90 days from the last SCA event. Once 90 days have elapsed, the ASPSP must re-authenticate the client, but no new consent is required while the 180-day period is running.
SCA is performed by the ASPSP when consent is first established and again after the applicable 90-day period expires. The AISP initiates the request but does not authenticate the user itself.
PIS Consent and SCA
For each payment, the PISP obtains a separate explicit consent from the payer. There is no standing consent mechanism for individual payment transactions.
The PISP requests the ASPSP to carry out SCA; the ASPSP performs it. Dynamic linking (binding the authentication code to the specific payment amount and payee) is also the ASPSP’s responsibility.
The ASPSP also authenticates the TPP itself (AISP or PISP) as a technical participant via the qualified Open Banking certificate.
9. Data scope and restrictions for AISP
Through the base interface, an AISP accesses only:
- the account balance;
- the list of transactions for the last 31 calendar days from the date of the request.
Access to an extended data set (longer history, additional attributes) is available only through the commercial interface under a contract with the ASPSP.
An AISP is prohibited from:
- storing sensitive payment data (authentication credentials, full payment card numbers, CVV/CVC codes);
- sharing account data for purposes unrelated to the AIS provision;
- using data for purposes other than those for which the client gave consent.
Open Banking in Ukraine covers payment accounts only. Credit products, investment accounts and other financial products fall outside the current regime, and Ukraine does not yet have a formal Open Finance legal framework.
10. Personal data protection
The Law of Ukraine on Personal Data Protection No. 2297-VI governs the processing of clients’ personal data. Access to an account under Open Banking is based on the user’s consent under payment legislation. The legal basis for any further processing of personal data must be assessed separately in light of the processing purpose and applicable legislation.
Using account data for marketing or profiling outside the purpose for which the user gave consent requires a separate lawful basis. The user may withdraw consent at any time. After withdrawal, the AISP must cease account access; data already obtained may be retained only where another lawful basis exists and the purpose and retention period justify continued processing.
Cross-border transfers of personal data are carried out in accordance with the procedure established by law. EU/EEA member states and states party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data are treated as providing an adequate level of personal data protection.
11. AML, Cybersecurity and Internal Documentation
AML and financial monitoring
The Law of Ukraine “On Prevention and Counteraction to Legalisation (Laundering) of the Proceeds of Crime, Terrorism Financing and Financing the Proliferation of Weapons of Mass Destruction” No. 361-IX does not expressly list AISPs or PISPs as a separate category of primary financial monitoring subjects. At the same time, the law refers to other legal entities that are not financial institutions but provide certain financial services, whereas AIS and PIS are non-financial payment services. The AML status of a particular AISP or PISP should therefore be assessed separately, taking into account any other activities and the provider’s actual service model.
Branches of foreign payment institutions require a separate analysis.
Cybersecurity
NBU Resolution No. 43/2021 sets baseline information security and cybersecurity requirements for payment service providers, including AISPs and PISPs. They cover information risk management, system and data protection, incident management with NBU notification where required, access controls and business continuity.
Internal documentation
An authorised non-financial payment service provider must adopt the required internal policies and procedures within three months of the authorisation date or before providing the first service, whichever comes first.
12. Liability allocation and contracts
A bilateral agreement between the AISP/PISP and the bank (ASPSP) is not required for base interface access. The ASPSP grants access on the basis of the NBU authorisation and the qualified certificate. For the commercial interface, a bilateral contract is required and governs data scope, fees and liability terms.
A client agreement (terms of service) is required for any AISP or PISP. It must cover the type of service (AIS or PIS), the scope of account access, the duration of consent and the procedure for withdrawing it, and the FinTech company’s liability to the client.
Liability for unauthorised or incorrectly executed transactions depends on whether the failure occurred on the ASPSP or PISP side, and each case requires individual legal analysis. Liability insurance covers defined risks: for a PISP, incorrect initiation of payment transactions; for an AISP, unauthorised access to data or its improper use.
13. Open Banking Pre-Launch Checklist
- Service classification. Determine whether AIS, PIS, or both will be provided; this drives capital, insurance, and certificate requirements.
- Legal structure. Choose between a Ukrainian legal entity (LLC or JSC) and a branch of a foreign payment institution where the parent institution meets the statutory definition and the branch accreditation requirements.
- Capital. For a Ukrainian legal entity applying for PIS authorisation, confirm minimum statutory capital of UAH 1,000,000 (approximately USD 22,000); for an AIS-only provider, note that the statute does not set a separate minimum capital amount. A branch of a foreign payment institution is subject to a separate regime.
- Insurance. For a provider undergoing authorisation, conclude a liability insurance contract; for a branch, verify the requirements of the applicable branch regime separately.
- Authorisation documents.
- Qualified Open Banking certificate. After completing the applicable NBU procedure and before connecting to the dedicated interfaces, obtain a qualified Open Banking certificate from a Ukrainian QTSP.
- Internal documentation. Adopt it before providing services or within three months of authorisation, whichever comes first.
- Client consent process. Design explicit consent forms and the technical flow for collecting and managing client consent.
- SCA coordination with ASPSP. Agree the technical integration for ASPSP-performed strong customer authentication.
- Interface access model. Determine whether base interface access is sufficient or a commercial interface contract with the ASPSP is needed.
- Personal data. Prepare data processing documentation.
- AML status. Determine the applicable financial-monitoring obligations separately, taking into account the provider’s status and any other activities.
- Cybersecurity and business continuity. Implement protective measures in accordance with applicable legislation.
- Client and ASPSP contracts. Prepare client terms of service and, if required, a commercial interface contract with the ASPSP.
- Register confirmation. Verify Register of Payment Infrastructure entry before commencing commercial operations.
Frequently asked questions
Is Open Banking currently operational in Ukraine?
The framework entered into force on 1 August 2025. Both implementation deadlines have since passed: the ASPSP deadline on 1 January 2026 and the NBU enforcement grace period on 1 August 2026. The regime is now fully in effect.
Does an AISP require a payment institution licence?
For a Ukrainian legal entity providing AIS only, no payment institution licence is required. NBU authorisation and entry in the Register of Payment Infrastructure are required instead. A branch of a foreign payment institution is subject to a separate accreditation and licensing regime.
What is the minimum capital for a PISP?
For a Ukrainian legal entity applying for PIS authorisation, the minimum statutory capital is UAH 1,000,000 (approximately USD 22,000). Where PIS is combined with money remittance without account opening, the minimum is UAH 3,000,000 (approximately USD 67,000). No separate statutory minimum is set for an AIS-only provider. A branch of a foreign payment institution is subject to a separate regime.
Does an EU PSD2 authorisation cover Ukraine?
No. PSD2 authorisation does not apply automatically in Ukraine. Depending on the chosen form of presence, the company must complete the Ukrainian authorisation procedure or, where applicable, the branch accreditation procedure.
Can a foreign company provide AIS or PIS without establishing a Ukrainian entity?
Yes, through a form of presence recognised by Ukrainian law. A foreign payment institution may establish a branch in Ukraine if it meets the requirements of the law and completes NBU accreditation. Other foreign companies may incorporate a Ukrainian legal entity and obtain authorisation under the relevant NBU resolution. Direct cross-border provision of AIS or PIS without Ukrainian registration is not provided for.
Is a contract with the bank needed to access the base interface?
No bilateral agreement with the ASPSP is required for base interface access. Any authorised AISP or PISP is entitled to free access without a prior agreement. A bilateral contract is required for the commercial interface with extended data.
How long does AIS consent remain valid?
One AIS consent may remain valid for up to 180 calendar days. After expiry, new consent is required. Within the 180-day window, the ASPSP repeats strong customer authentication at intervals of no more than 90 days from the previous authentication event.
Who performs strong customer authentication?
The ASPSP — the bank or other account-holding PSP — performs user SCA. The AISP or PISP initiates the relevant request, but neither authenticates the user independently.
What are the insurance requirements for AISP/PISP in 2026?
From 1 July through 31 December 2026, the minimum indemnity is €110,000 for a single-service provider (AIS-only or PIS-only) and €180,000 for a combined AISP + PISP model. These are transitional figures. From 1 January 2027, the full volume-linked methodology under Resolution No. 71/2025 will apply.
How DLF can help
DLF supports FinTech companies and financial institutions at every stage of entering the Ukrainian market: from choosing the corporate structure and preparing documents to NBU authorisation, capital structuring and insurance, agreements with ASPSPs and clients, personal data protection, AML analysis and cybersecurity. For such projects, DLF’s Corporate Law / M&A and Contract Law practices are particularly relevant.
Iurii Dynys, Counsel, Attorney-at-law, DLF attorneys-at-law.
Contacts: +380 44 384 24 54, info@dlf.ua.
This material is intended for general information. The application of the approaches described depends on the circumstances of the specific situation and requires a separate legal assessment.
