As open banking continues to mature across Europe, questions regularly arise regarding the Anti-Money Laundering (AML) obligations that should apply to Account Information Service Providers (AISPs). Given that AISPs have access to significant volumes of customer’s financial data, some commentators have questioned whether they should be subject to the same AML requirements comparable to those applicable to banks, payment institutions and other regulated firms involved in the receipt, transfer or movement of funds.
Both the existing PSD2 framework and the proposed PSD3 package recognise a fundamental distinction between account information services and transactional payment services. Put simply, AISPs provide access to information, not access to money.
This distinction raises an important regulatory question: how should an AML framework traditionally focused on institutions that hold, receive or transfer funds apply to a provider whose role is limited to accessing and presenting financial information?
What is an Account Information Service Provider (AISP)?
Introduced by PSD2, an account information service is an online service that provides consolidated information relating to one or more payment accounts held by a payment service user with one or more Account Servicing Payment Service Providers (ASPSPs), typically banks. The AISP, with the payment service user’s explicit consent, accesses data from the user’s designated payment accounts and provides consolidated information relating to those accounts. An AISP does not hold the payment service user’s funds or operate the user’s payment accounts, nor does it initiate or execute payment transactions on the user’s behalf.
This business model differs fundamentally from that of a bank, Electronic Money Institution or Payment Institution that receives funds, safeguards client money or executes payment transactions. An AISP acts as a data access provider, accessing and consolidating information from payment accounts held with ASPSPs, rather than holding client funds, operating payment accounts or initiating and executing payment transactions.
That distinction is particularly important from a financial crime perspective. Certain money laundering risks are heightened where financial institutions are capable of receiving or transferring funds, initiating payment transactions, converting funds into different forms of value or facilitating withdrawals. An AISP does not itself hold client funds, initiate or execute payment transactions, or facilitate the movement of funds between accounts. Instead, it provides visibility over information that already exists within regulated financial institutions. Accordingly, AISP’s direct exposure to transaction-based money laundering risks is materially different from that of institutions that handle or transfer client funds.
What Are the AML Risks for AISPs?
This does not mean that AISPs are entirely irrelevant from an AML perspective. The AISP remains subject to applicable AML/CFT obligations and must maintain appropriate controls to address risks arising from its customers, access to account information and use of its services.
Indeed, one of the interesting characteristics of the open banking model is that AISPs may have access to information from multiple accounts and multiple financial institutions simultaneously. In some circumstances, this aggregated view could potentially reveal patterns that may not be visible to any single institution in isolation.
The European Banking Authority (EBA) has recognised this possibility through its sector-specific guidance on money laundering and terrorist financing risk factors for both AISPs and Payment Initiation Service Providers (PISPs). The existence of that guidance demonstrates that regulators do not regard AISPs as entirely devoid of financial crime risk. Rather, they recognise that those risks are materially lower and structurally different from those associated with institutions that hold funds or process transactions. Again, proportionality at work.
Similarly, some national regulators have considered whether AISPs should undertake elements of transaction monitoring. The Dutch Central Bank, for example, has taken the view that AISPs may have certain monitoring obligations under local AML legislation. However, it has simultaneously emphasised the low inherent money laundering risk presented by AISPs because they neither conduct transactions nor hold customer funds. It also recognises that any controls should be proportionate (that word again) to the nature of the service being provided.
The broader regulatory theme is therefore one of proportionality rather than exemption.
Are AISPs Currently Subject to AML Requirements?
Notwithstanding the particular characteristics and comparatively limited inherent ML/TF risk of the AISP business model, under the current EU AML/CFT framework AISPs fall within the scope of obliged entities and are therefore required to comply with the applicable AML/CFT requirements.
AISPs do not benefit from a general exemption from the requirements of the AMLD. However, as with other obliged entities, they may apply their AML/CFT systems and controls on a risk-sensitive and proportionate basis, taking into account the nature and level of ML/TF risk associated with their activities.
The EBA Guidelines on ML/TF risk factors (EBA/GL/2021/02) provide further guidance on how AISPs may apply this risk-based approach. In particular, the EBA recognises that the inherent ML/TF risk associated with AISPs is generally limited, given that they are not involved in the payment chain and do not hold payment service users’ funds. For this reason, the Guidelines indicate that simplified customer due diligence measures may be appropriate in most circumstances.
The regulatory position will, however, change once the EU Anti-Money Laundering Regulation (“AMLR”) becomes applicable. Under Article 2(6)(a) of the AMLR, the definition of a “financial institution” expressly excludes undertakings carrying out the activity referred to in point (8) of Annex I to PSD2, namely account information services.
Accordingly, the table below summarises how the treatment of AISPs will change from 10 July 2027 under the AMLR
| Current EU AML/CFT Framework | From 10 July 2027 under AMLR | |
|---|---|---|
| AISP status | AISPs fall within the scope of obliged entities. | Account information services are expressly excluded from the relevant definition of a financial institution. |
| AML/CFT requirements | AISPs are required to comply with applicable AML/CFT requirements, on a risk-sensitive and proportionate basis. | An undertaking carrying out only account information services will no longer qualify as an obliged entity on that basis. |
How Will PSD3 and the PSR Affect AISPs?
The parallel reform of the EU payments framework reinforces the importance of distinguishing between access to account information and control over payments.
The European Commission’s PSD3 proposal, published in June 2023 alongside the proposed Payment Services Regulation (PSR), seeks to strengthen the payments framework by improving fraud prevention, enhancing consumer protection, creating greater supervisory consistency and addressing practical shortcomings identified during the operation of PSD2.
Importantly, however, the proposal does not fundamentally alter the nature of Account Information Services (AIS). AIS remains a service centred on accessing, retrieving and consolidating information relating to payment accounts held with the ASPSPs, rather than holding or transferring funds. AISPs do not thereby become payment account providers, deposit takers or payment execution providers, merely by providing AIS under the proposed framework. Indeed, one could argue that there is no ‘payment service’ per se but, absent a better fit, PSD2/PSD3 was the best fit for AIS.
As a result, the underlying logic supporting the differentiated AML treatment of AISPs remains intact.
The Commission’s review of PSD2 identified challenges relating to open banking performance, fraud prevention, supervisory convergence and the competitive position of non-bank payment providers. However, it did not conclude that AISPs represent a significant money laundering vulnerability requiring a wholesale reassignment of AML responsibilities.
Consequently, PSD3 proposal broadly preserves the existing allocation of responsibility. The institution maintaining the payment account remains the primary party responsible for customer due diligence and monitoring of transactions taking place through that account.
The two legislative developments therefore point in a broadly consistent direction: account information services remain regulated financial services, but their regulatory treatment increasingly reflects the fact that access to financial data is not equivalent to control over financial flows.
What Do the AMLR and PSD3 Changes Mean for AISPs?
The AML/CFT treatment of AISPs illustrates the importance of distinguishing regulatory status from underlying financial-crime risk.
A pure AISP does not hold customer funds, maintain the underlying payment account or execute the transactions that appear within the account information it accesses. Its role is informational rather than transactional. This does not eliminate financial-crime considerations, particularly given the potentially valuable insights generated through aggregated account data, but it produces a materially different risk profile from that of institutions directly involved in the movement or safeguarding of funds.
The current EU framework nevertheless brings AISPs within the AML/CFT perimeter, while allowing the characteristics and lower inherent risk of their business model to be taken into account through the application of the risk-based and proportionality principles.
The AMLR introduces an important change to this position. From 10 July 2027, account information services will be expressly excluded from the relevant definition of a financial institution. As a result, the provision of pure account information services will no longer, in itself, bring an undertaking within that category of obliged entity.
This does not amount to a conclusion that account information services are entirely free from financial-crime risk. Rather, it reflects a more fundamental regulatory distinction between visibility over money and control over money.
The developing PSD3/PSR framework maintains this distinction. Taken together, these developments indicate a more differentiated EU regulatory approach, under which AML/CFT obligations are increasingly aligned with the nature of the services actually provided and the financial-crime risks associated with those activities.
How Complyport EU Can Support AISPs and Payment Services Providers
Complyport EU supports payment services providers across the EU in meeting evolving regulatory requirements and maintaining effective compliance frameworks. Our services include:
- Authorisation support for Payment Institutions, Electronic Money Institutions, AISPs and PISPs.
- Regulatory compliance advice on AML, PSD2, PSD3 and the PSR.
- AML/CFT frameworks, policies and risk assessments.
- Governance and compliance reviews and ongoing regulatory support.
- Regulatory change management to help firms prepare for new EU payment services requirements.
Contact Complyport EU today to book a meeting with one of our Subject Matter Experts and discuss how we can support your business.
Table of Contents
Watch Our Recent Webinar
EU’s Latest AML/CTF Package
The Changes Financial Firms Need to Prepare for Now
Presented by Alexandros Constantinou, Senior Managing Director, Complyport EU.

Subscribe for Exclusive Regulatory News and Updates
Receive the latest regulatory developments, expert insights, practical compliance guidance and invitations to Complyport webinars and events.
Share this Article
Found this article useful? Share it with your colleagues and network.






