Industry report

UK Open Banking API Performance 2022–2023

Approximately 8.4 million real FAPI consent calls to 29 UK Open Banking brands, measured every five minutes from 22 European cloud locations between July 1, 2022 and June 30, 2023.

Published
Length
25 min read
Author
Dr. Paul M. Cray, Head of Machine Learning and Artificial Intelligence, APImetrics

Executive Summary

In a follow-up to the 2020–21 and 2021–22 reports, APImetrics made more than 8 million API test calls to 29 banks in 2022–23 to determine the quality of Open Banking APIs implemented in conformance with the standards published by each bank.

API performance in banking is critical to the user experience for payment processing, transfers, and other digital use cases. It is also regulated by the Financial Conduct Authority (FCA), which considers Open Banking a strategic priority for the UK financial sector.

Performance improved overall, but remains sub-optimal. Compared with 2021–22, the CMA9 and traditional banks improved while neobanks declined. The CMA9 were nearly as performant as challenger neobanks, while smaller traditional banks showed the weakest performance. Infrastructure choice mattered more than ever: Azure performed dramatically slower than other cloud providers and substantially slower than its own performance in the preceding period.

At a glanceThe 2022–23 benchmark
~8.4m
API calls

FAPI consent endpoint calls

29
bank brands

CMA9, traditional, and neobank groups

22
cloud locations

APImetrics agents across Europe

99.98%
neobank availability

Highest group average

APImetrics, UK Open Banking API Performance 2022–2023.

Introduction

The UK continues to be at the forefront of the global Open Banking revolution thanks to the proactive attitude of its regulators. The resulting ecosystem encourages smaller banks, fintechs, and neobanks to participate alongside the largest banks. As the most advanced Open Banking market in the world, the UK provides an example of best practice that other jurisdictions can use as a model.

This follow-up study covers the large CMA9 UK banks, traditional High Street banks, credit card providers and building societies, and new entrant banks (neobanks). The endpoints were provided by the banks and measured using the APImetrics active API monitoring service, including its patented Cloud API Service Consistency (CASC) quality scoring system.

The data was generated from real API calls made using the FAPI-compliant consent process with the support of third-party provider (TPP) partner tomato pay. All calls were made between July 1, 2022 and June 30, 2023.

Key Findings

  • Performance varies significantly between banks: Most banks experienced good overall performance, but a small number need attention for underperformance.
  • Poor performance has a measurable cost: An underperforming endpoint needs an estimated 2.5 times the resources of a good performer. At a standard rate of $75 USD per hour, this can cost as much as $50,000 USD per endpoint per year.
  • Latency differs by more than six times: There is over 1,100 milliseconds of total latency between the fastest and slowest banks, with large differences in DNS lookup, TCP connect, and processing time.
  • Cloud choice matters: Azure's median DNS lookup time is above 70 ms, compared with below 10 ms for AWS and IBM and above 20 ms for Google.
  • Location matters: UK-hosted applications generally perform best. The report does not recommend Nordic data centers for UK Open Banking applications.

Financial-grade API consent endpoints are not reliant on historical technical debt in the same way as many legacy applications. The differences therefore point to implementation resources, consent solution choices, caching and validation, and the infrastructure serving the journey.

Scope of Report

We made approximately 8.4 million API calls to Open Banking consent endpoints and measured availability and latency components including DNS name lookup, TCP connect, SSL handshake, and backend processing time.

The UK Open Banking landscape was categorized into three groups: CMA9 banks, the largest incumbent banks; traditional banks, established smaller banks and building societies; and neobanks, innovative entrants to UK banking services.

APImetrics monitored FAPI-compliant journey endpoints for 29 Open Banking brands, up from 28 in 2021–22.

Table 1. The 29 UK Open Banking brands monitored, by group
GroupBrands
CMA9Allied Irish Bank (GB); Bank of Ireland; Bank of Scotland; Barclays Business; Barclays Personal; Danske Bank; Halifax; HSBC Bank (Business); HSBC Bank (Personal); Lloyds Bank; Nationwide Building Society; NatWest; RBS; Santander; Ulster Bank NI
TraditionalCater Allen Private Bank; Creation Cards; Cumberland Building Society; Sainsbury's Bank; Tesco Bank; TSB; Virgin Money; Yorkshire Building Society
NeobanksMonzo Bank; NewDay – Amazon Mastercard; Tide; Vanquis Bank

Brands monitored from July 1, 2022 to June 30, 2023.

Methodology

APImetrics used its active API performance and quality monitoring system with a Software Statement Assertion from partner tomato pay to make standardized end-to-end consent calls for the FAPI journey at 29 bank brands, approximately every five minutes from software agents hosted at all 22 European cloud locations.

Raw metrics were combined using patented Cloud API Service Consistency (CASC) technology to generate a quality score every month for each brand.

Figure 1The measured path of an Open Banking API call
  1. AgentSynthetic user call
  2. DNS lookupFind the target
  3. TCP connectOpen the connection
  4. SSL handshakeSecure the session
  5. Backend processingHandle the request
  • Unexpected responseAvailability or quality issue

Each call consists of steps before data is exchanged: Name Lookup (DNS), TCP Connect, and SSL Handshake. As a rule of thumb, the SSL handshake is double the TCP connect time, and can be longer when the server analyzes the incoming connection. Once the connection is established, the request is uploaded, processed, and returned; the total elapsed time is logged.

Detailed Results

Endpoints

Traditional banks have been the lowest-quality bank type since early 2021. In 2022–23, both traditional banks and neobanks performed consistently in the CASC Green Zone, although neobanks typically outperformed the CMA9 and traditional banks. Including the Irish CMA9 banks, there were several months when CMA9 banks led the neobanks.

Figure 2Average CASC score by bank type
Neobanks
8.82
CMA9 banks
8.72
Traditional banks
8.08

APImetrics CASC scores, July 2022–June 2023.

Figure 3Quality score of bank brand APIs over time
  • CMA9 banks
  • Neobanks
  • Traditional banks
  • All brands

APImetrics CASC score chart; values reproduced at rounded chart resolution.

Figure 4Quality score over time excluding Irish CMA9 banks
  • English and Scottish CMA9
  • Neobanks
  • Traditional banks
  • All brands

APImetrics CASC score chart excluding Irish CMA9 banks; values reproduced at rounded chart resolution.

In 2021–22, traditional banks averaged in the Yellow Zone. In 2022–23, they improved into the Green Zone, indicating high-quality APIs with no major issues. APImetrics estimates that improving an endpoint from the Yellow Zone to the Green Zone saves approximately 720 support engineer hours per year. For the three Open Banking authentication endpoints considered here, the 12-month savings were more than GBP 125,000.

Figure 3Average availability by bank type

Neobanks

Three Nines availability

CMA9 banks

Three Nines availability

All brands

All monitored brands

Traditional banks

Lowest group average

Average availability, July 2022–June 2023.

Unlike in 2020–21 and 2021–22, no traditional bank suffered a major outage. Average availability was still lowest for traditional banks, while neobanks and CMA9 banks achieved Three Nines availability.

Figure 6Total latency by bank type
  • CMA9 banks
  • Traditional banks
  • Neobanks

APImetrics total latency chart; values reproduced at rounded chart resolution.

Figure 7Availability by bank type
  • Neobanks
  • CMA9 banks
  • Traditional banks

APImetrics availability chart; values reproduced at rounded chart resolution.

Cloud data center performance

Most applications that call Open Banking APIs are hosted in a cloud data center from AWS, Azure, Google, or IBM. APImetrics made the same calls using the same infrastructure and configuration from the same cloud data centers. Latency becomes perceptible to end users at roughly 400–450 ms, and Azure was the slowest cloud overall throughout the period, with latency above 450 ms.

Figure 4Median DNS lookup time by cloud provider
<10 ms
AWS
<10 ms
IBM
>20 ms
Google
>70 ms
Azure

APImetrics analysis, July 2022–June 2023. Values are rounded report ranges.

AWS and IBM were comparable for the first part of the period, while Azure was slowest in 2023. Google sat between the two faster clouds and Azure. Cloud choice can add 100 ms or more of latency when every millisecond counts.

Figure 8Median total call time by cloud data center
330 ms
AWS UK
350 ms
IBM UK
370 ms
Google UK
380 ms
AWS Ireland
395 ms
AWS France
405 ms
IBM France
420 ms
AWS Germany
440 ms
Azure UK
450 ms
Google Netherlands
465 ms
IBM Germany
480 ms
Google Belgium
495 ms
Google Germany
505 ms
AWS Italy
520 ms
Azure Ireland
535 ms
AWS Sweden
550 ms
Azure Netherlands
565 ms
IBM Italy
585 ms
Google Switzerland
600 ms
Azure Germany
630 ms
Google Finland
650 ms
Azure Norway

APImetrics median total call duration by data center; values reproduced at rounded chart resolution.

Figure 9p99 total time by cloud data center
AWS UK
1,050 ms
Google UK
1,080 ms
Azure Ireland
1,120 ms
IBM UK
1,140 ms
IBM France
1,160 ms
Azure UK
1,180 ms
AWS Germany
1,210 ms
Azure Netherlands
1,240 ms
AWS France
1,260 ms
Google Belgium
1,280 ms
Google Germany
1,300 ms
Google Netherlands
1,320 ms
IBM Germany
1,340 ms
Google Switzerland
1,360 ms
AWS Sweden
1,380 ms
AWS Italy
1,400 ms
Azure Germany
1,420 ms
Azure Norway
1,450 ms
IBM Italy
1,470 ms
Google Finland
1,500 ms

APImetrics p99 total time by data center; values reproduced at rounded chart resolution.

Table 2. Relative performance observations by location
Location patternReport finding
Fastest locationsThe three fastest locations were in the UK, followed by AWS Ireland.
Slowest locationsGoogle Finland and Azure Norway were the slowest locations; calls from these locations added more than 200 ms compared with UK or Ireland.
AzureThe five Azure locations were the slowest cloud locations overall, driven by slow DNS lookup and high variance.
TCP connectTCP Connect Time was largely determined by geography, with the fastest locations in the UK and Ireland and the slowest in Eastern and Southern Europe.

APImetrics cloud location analysis, July 2022–June 2023.

AWS, Google, and IBM improved their DNS performance compared with 2021–22, with lookup time decreasing by 40% or more. Azure increased by 80%. The report attributes the whole of Azure's increase in total time to the increase in DNS time.

Figure 10Average DNS name lookup time by cloud provider
AWS
8 ms
IBM
9 ms
Google
23 ms
Azure
72 ms

APImetrics DNS lookup time by cloud provider; values reproduced at rounded chart resolution.

Figure 11DNS time change period on period

Median DNS lookup time

AWS

IBM

Google

Azure

  • 2021–22
  • 2022–23

APImetrics comparison of median DNS time by cloud; values reproduced at rounded chart resolution.

Figure 12Percentage change in DNS time between periods
IBM
-40%
Google
-40%
AWS
-40%
Azure
+80%

APImetrics period-on-period DNS comparison; direction is shown in the display values.

Figure 13Median DNS lookup time by cloud location
AWS UK
6 ms
Google UK
8 ms
IBM UK
9 ms
AWS Ireland
10 ms
AWS France
11 ms
IBM France
12 ms
AWS Germany
13 ms
IBM Germany
14 ms
AWS Italy
15 ms
AWS Sweden
18 ms
IBM Italy
18 ms
Google Netherlands
22 ms
Google Belgium
24 ms
Google Germany
26 ms
Google Switzerland
30 ms
Google Finland
45 ms
Azure Netherlands
58 ms
Azure Ireland
62 ms
Azure Germany
64 ms
Azure UK
70 ms
Azure Norway
75 ms

APImetrics median DNS lookup time by cloud location; values reproduced at rounded chart resolution.

Figure 14Median TCP Connect Time by cloud data center
AWS UK
12 ms
Google UK
14 ms
IBM UK
16 ms
AWS Ireland
20 ms
AWS France
28 ms
IBM France
30 ms
AWS Germany
34 ms
Azure UK
38 ms
Google Netherlands
42 ms
IBM Germany
45 ms
Google Belgium
48 ms
Google Germany
50 ms
AWS Italy
54 ms
Azure Ireland
58 ms
AWS Sweden
62 ms
Azure Netherlands
66 ms
IBM Italy
70 ms
Google Switzerland
74 ms
Azure Germany
80 ms
Google Finland
88 ms
Azure Norway
105 ms

APImetrics median TCP Connect Time by cloud location; values reproduced at rounded chart resolution.

Performance by cloud and bank type

Removing the impact of Nordic data centers showed that the performance differences between bank types were consistent across clouds. For median total time, the speed order was AWS, IBM, Google, then Azure for all three bank types. Traditional banks had p99 times around 1,400 ms regardless of cloud, while neobanks had p99 times below 700 ms.

Figure 5Relative latency of the same calls by cloud and bank type

Median total time

AWS

IBM

Google

Azure

  • CMA9 banks
  • Traditional banks
  • Neobanks

APImetrics comparative chart, July 2022–June 2023; values shown at rounded chart resolution.

Figure 15p99 time for bank types by cloud

p99 total time

AWS

IBM

Google

Azure

  • CMA9 banks
  • Traditional banks
  • Neobanks

APImetrics p99 comparison by bank type and cloud; values reproduced at rounded chart resolution.

Slow calls affect user experience. Neobanks can provide faster and more reliable endpoints than traditional banks, with fewer outliers, indicating a difference in infrastructure quality. Banks with greater p99 total times will likely encounter more API issues and higher support costs: high latency comes at a price.

Recommendations

Only by monitoring API quality from the end-user perspective can an organization understand how its APIs behave. Internal monitoring will not expose every issue that requires rapid escalation and resolution.

  • Monitor API quality actively from the locations where end users and TPPs make calls.
  • Choose cloud and data center locations carefully; UK and Ireland generally provide the best performance for UK Open Banking.
  • Design for the additional processing overhead of traditional banks when building services for their users and APIs.
  • Prefer AWS or IBM for performance-critical applications based on the 2022–23 data.
  • Investigate Azure DNS lookup performance before building a performance-critical UK Open Banking application on Azure.

About tomato pay

tomato pay is a QR-code-based payments and invoice app for businesses and sole traders who want to receive payments in a safe, streamlined, and cost-effective way. It offers low-cost QR-code payments with no hidden fees and near-immediate cash settlement.

The app provides access to bank accounts and transactions in one place. Users can create invoices, automate discounts and late penalties, send payment reminders, and connect their bank account so digital payments are embedded in the invoice.

Glossary

The measurement, API, and Open Banking terms used throughout this report, defined for teams comparing performance across banks, clouds, and locations.

4xx HTTP status code
A client-side response generated when a request is made to an endpoint that does not exist or for which the user lacks authorization. These warnings generally should not be included when determining endpoint performance and quality.
5xx server error
An actual error reported by the application server hosting the API.
Agent
The APImetrics software agent running at cloud locations around the world to generate synthetic calls as if they were made by an end user or partner.
API
An Application Programming Interface; in this report, a web API that receives an HTTP request and returns data or changes the state of a remote resource.
API call
A single HTTP request made to a particular endpoint. Request and response details are stored for analysis of performance and quality.
Authentication and authorization
The processes used to validate the identity of a requesting party and confirm that it has been granted access to an API endpoint, often using OAuth 2.0 and FAPI.
Availability
A measure closely linked to pass rate. An endpoint can be available even when a call does not pass because of authentication, authorization, or malformed-request issues.
Cloud provider
An organization that provides a commercial service hosting applications on servers, such as AWS, Google Cloud, Microsoft Azure, or IBM Cloud.
Configuration
Internal and external network configuration, including load balancers and routing tables, that can materially affect API performance and quality.
CASC score
Cloud API Service Consistency, an APImetrics metric combining availability, latency, reliability, response consistency, and outliers into a benchmarked quality score. Green is 8.00 or greater, Yellow is 6.00–7.99, and Red is below 6.00.
CMA9 banks
The nine large UK banks mandated by the Competition and Markets Authority to expose Open Banking APIs and regularly report performance.
DNS latency
The time taken by the service making the API call to identify the target server and route the request using the Domain Name System.
Endpoint
The web address called by an API request, together with the parameters and security needed to make the call.
FAPI
Financial-grade API, a technical specification based on OAuth 2.0 and OpenID Connect that defines additional security requirements for financial and other high-security industries.
Handshake time
The time required to establish the secure HTTP connection between services.
Latency
The time between making a request and receiving the response, including DNS, connection, handshake, upload, processing, and download components.
Metric
A measure of an aspect of endpoint performance, such as availability or the median length of a latency component.
Non-conformance
An endpoint that does not respond according to its published specification, for example by returning missing fields or unexpected errors.
OBIE
Open Banking Implementation Entity, the UK entity managing Open Banking standards in the United Kingdom.
Open Banking
A paradigm for banking, financial, and payment services that enables new products and experiences through data exchange using APIs.
p99 time
The value below which 99% of measured latency values fall; the remaining 1% are slower. p99 is useful for understanding performance at the extremes.
Processing time
The time the server takes to process a received request before sending a response to the end user.
PSD2
Payment Services Directive 2, a pan-European agreement covering access to payment and banking services for financial services providers in the EU and United Kingdom.
Reliability
The tendency of an endpoint to respond within a narrow range of times. A reliable endpoint may not be fast, but its latency variance is relatively small.
Software Statement Assertion
A signed JSON Web Token containing metadata about a third-party provider's client software, issued through the Open Banking Directory and used to prove the identity of the regulated entity.
Total time
The time between a request being made to an endpoint and the complete response being received, including DNS, TCP connection, and handshake time.

About APIContext

APIContext eliminates blind spots for enterprises across the digital delivery chain with proactive synthetic monitoring, performance analytics, and automated conformance validation. Our platform delivers actionable insights so connected systems perform and conform—ensuring every interaction is trusted, secure, and compliant.

What are your APIs saying to AI? Contact us to find out.

PDF

Download the PDF

The complete report is also available as a PDF. Complete this form and we will send it to you.

  • How availability and latency differed across 29 UK Open Banking brands
  • Why neobanks and CMA9 banks outperformed traditional banks
  • How AWS, IBM, Google, and Azure compared on DNS and total call time
  • Why UK and Irish cloud locations were generally fastest
  • What API teams can do to reduce latency, outliers, and support cost
Agent View