ČNB opinion RS2025-28 (27 November 2025) requires banks to fix their PSD2 APIs. It was issued on the basis of our analysis and in January 2026 its conclusions were adopted by the National Bank of Slovakia. Mo.one is currently the only Czech entity actively involved in this discussion at national and European level at the same time.
You can verify our licence at any time in the public list of regulated entities of the Czech National Bank.
The ČNB list of regulated entitiesWe initiate payments from the payer's account directly to the merchant. No card, no paper authorisation · the user confirms in their banking app and we deliver the transaction.
With the user's consent we aggregate information about their accounts across banks. It powers the multi-account overview, expense categorisation and checking the available balance before a payment.
The state of PSD2 API remediation under ČNB opinion RS2025-28. Updated continuously.
Remedy completed
App2App redirection works for connecting an account and for payment, on Android and on iOS. A reference implementation for the other banks.
Partial remedy
Connecting an account fixed with App2App on Android and iOS. Payment according to the schedule agreed with the ČNB: July 2026 single authentication, September 2026 standard mode.
Analysis and architecture done, development completed in June. Testing follows and a pilot with Mo.one is being prepared.
Shortening the consent screen promised by 31 May 2026, App2App redirection is part of a larger delivery package.
Q4 2026
Payment with a single authentication has been in production since 22 February 2026. The full remedy including App2App redirection is in development, with the scope agreed with the ČNB.
22 November 2026
App2App redirection is being implemented by an external supplier. The bank gave the date only after repeated requests. An action for protection against unfair competition has been filed.
Early 2027
The bank is adjusting the payment flow in coordination with the ČNB. For connecting an account it has not given a date yet, and consent still requires the name to be entered by hand.
In court
The bank refuses substantive communication outside the data box and has not declared a remedy date. A settlement proposal with a remedy by 31 October 2026 has been filed and we are waiting for a response.
In court
Approached in February 2026, no remedy declared so far. A hearing at the Municipal Court in Prague on 13 October 2026, with a submission also made to the Polish regulator.
The interfaces of Partners Banka and Banka CREDITAS are also in development, both with a date in the second half of 2026. We will connect them as soon as the remedy is done.
With banks that refuse to communicate or fail to meet their obligations, we proceed through the courts · civil actions for unfair competition. It is not a question of „whether", but „when".
The European directive requires banks to open APIs to third parties. Banks met it formally, but the implementation was practically unusable · repeated sign-ins, redirection that did not work on phones.
The ČNB granted Mo.one a.s. a payment institution licence for AIS + PIS services. Decision 2021/110092/CNB/570.
On the basis of the passportable EU licence, notification for providing services on the Slovak market was completed.
The eurozone gets mandatory instant bank transfers. A window opens for a European A2A model.
Issued on the basis of our analysis. The ČNB requires banks to fix their PSD2 APIs so that the payment experience is comparable to a payment card. Most major banks have a specific schedule for 2026.
The opinion on the ČNB websiteLive operation starts. 8 banks connected through CERTIS, the first App2App integration with Fio banka on Android.
The National Bank of Slovakia issued its own opinion, taking the ČNB's conclusions as its direct model. Two national regulators, two markets, one precedent · initiated by Mo.one.
We approached the European Commission, the EBA and the ECB calling for uniform enforcement of PSD2 rules across the EU. After a meeting in person with Commissioner Albuquerque, DG FISMA took the matter over for further handling.
By law we hold liability insurance for damage arising from the provision of payment services.
We hold the required capital above the statutory minimum and document its level continuously.
We report to the Czech National Bank at prescribed intervals as a matter of duty. Alongside that, an internal audit of processes and IT security runs all year.
The client confirms every payment with two factors directly in their own bank under PSD2. No shared secret, no working around it by SMS.