Browse all writing

The last mile of open banking is a policy choice

Experimenting with Kitty, a community-owned payments app in Leeds, and the one permission we're missing at the shop counter.


What we're experimenting with

We're experimenting with Kitty, a payment network for independent shops, owned by the community that uses it. When you pay a local shop, the money goes straight from your bank account to theirs over Faster Payments. The roughly 1.5% that would normally go to the card schemes (and out of the local economy with it) goes into a ring-fenced community fund instead, and the people paying help decide how it's spent. The idea is for the organisation behind it to be a Community Benefit Society: owned by its members, asset-locked, one member one vote. So the fee isn't a margin for shareholders. It stays in the place where it was earned.

The idea is simple enough. Every time you tap a card, the shop pays a toll, and on a huge share of UK retail spending that toll is collected by two overseas networks. Account-to-account (A2A) payments let you avoid almost all of it. Technically, the money can already stay local. What we don't yet have is permission for the last bit, the bit where a customer is standing at a counter, to work the way people expect it to. That's what this post is about.

Why A2A

Open banking has become real infrastructure without much fanfare. A2A payments are authenticated by your bank, the shop never sees your card details (there aren't any), and fraud is much lower than with cards, in person or online. For shops the cost difference is enormous. Card fees are a percentage of every sale; A2A costs are closer to a flat fee per transaction. On anything bigger than a small basket that's a real saving, and in our model that saving is the whole point, because it's what pays into the community fund rather than into the network.

And a single open banking payment already works at a physical till. You tap an NFC tag or scan a code, a payment page opens, and you approve the payment to the shop in your banking app. No card, no card scheme, no acquirer. It works in our prototype now, with nothing exotic underneath.

So what's the problem?

The approval step

It's the approval step. Under Strong Customer Authentication (SCA), you have to actively authenticate every one of those payments: open your banking app, approve, every single time. As fraud policy that's sensible. At a busy counter, though, it's the difference between something that feels like contactless and fifteen seconds of someone prodding at their phone while the queue behind them sighs. For quick, frequent purchases, that friction is enough to kill adoption.

There's already a mechanism built to remove that step: Variable Recurring Payments (VRPs). A VRP is a standing mandate, authenticated by your bank. You consent once, within limits you set, and later payments go through without asking you again. Commercial VRP (cVRP), run under the UK Payments Initiative scheme that went live on 2 June 2026, extends this from moving money between your own accounts to paying businesses. It's the first new UK payment scheme since Faster Payments in 2008, and it's exactly the tool we need.

The catch is that cVRP is being rolled out in waves, by type of use, and the order runs away from us:

  • Wave 1 (live now): regulated utilities, regulated financial services, central and local government, and charities.
  • Wave 2 (expected in the second half of 2026): general online shopping.
  • In-person retail: not scheduled. The industry describes it as a useful extra "over the next 12 to 24 months", with physical shops last in line.

So the one thing that would let a community network offer a genuine single tap at the counter, a standing mandate with a shop as an allowed payee, is precisely the case that hasn't been switched on. The technology exists, it's live, and it's working as designed for your energy supplier. It just isn't allowed for the corner shop yet.

What we're doing in the meantime

We made two choices.

For the experiment, we're using single A2A payments, approved in the app every time. We use what works now. A customer taps a distinctive tag on the counter, lands on our page, and approves a payment straight to the shop. We think of the tag as a civic object: a deliberate "I'm choosing to keep this local" gesture rather than something designed to disappear. There's no cVRP, no stored value, no e-money licence, and we don't even need to incorporate to test the core idea. The money goes from customer to shop and we take nothing yet. The experiment only has to answer one question, as cheaply as possible: will people keep doing it? The approval step is a real cost, but for slower, values-driven, bigger purchases (market stalls, bookshops, taprooms, veg boxes) it's bearable, and it arguably suits the idea of making a deliberate choice anyway.

For the single-tap version, there's a workaround we'd rather not need. Because in-person cVRP isn't available, the only compliant route to a tap without approval is stored value. Wave 1 does allow cVRP to top up an e-money wallet, since that counts as a regulated financial services payee. So your mandate tops up a balance and each tap spends from it, like an Oyster card. It works, and it's compliant. But it means bringing in an Electronic Money Institution partner, safeguarding customer money, and all the machinery that comes with holding other people's funds. That's a big fixed cost and the slowest dependency in the whole project, taken on purely to fake something the payment rails could do directly.

This is the heart of the policy argument. The e-money layer does nothing for anyone. It doesn't protect consumers any better than the direct route would. It doesn't reduce fraud. It doesn't help the customer or the shop. It exists only to get around a restriction on who's allowed to be paid. It's regulatory dead weight: cost and complexity spent simulating something the infrastructure already does, because we're not permitted to use it directly.

The trade-off underneath

There's a second problem that the rollout order makes worse, and we'd rather be upfront about it, because it shapes what good policy would look like.

If you want one mandate that works across a whole network of shops (activate once, tap anywhere, the way a card works), the money has to pass through a central party, the network, which then pays the shops. That makes the network a holder of customer money, and that's where the heavy regulation starts: e-money, or something very like it. If you want to stay light, with money going directly from customer to shop and the network never touching it, then each mandate has to be with a particular shop, and you lose the activate-once convenience.

Network-wide activation, staying out of the flow of money, not holding funds: pick any two. Direct in-person cVRP, with shops as allowed payees, is what would let a light network that holds no money still offer a good experience, because the bank pays each shop directly under the mandate and the network never handles a penny. Without it, organisations that deliberately don't want to extract anything get pushed towards exactly the fund-holding, licensed structures that raise their costs and blunt their purpose. The current order doesn't just slow us down. It tilts the eventual market towards well-capitalised intermediaries, and away from direct, community-scale models.

What we'd like to see

None of this needs new technology. It needs the scheme and regulators to switch on uses the system already supports, on a sensible timeline and with proportionate safeguards. Specifically:

  1. Put in-person retail on the cVRP roadmap, explicitly and with a date. At the moment it's implied and unscheduled. Even a firm signal about a "Wave 3" would let people plan and invest, instead of building throwaway e-money workarounds.
  2. Let shops, including small ones, be cVRP payees for in-person payments. The consumer protections are already built into the mandate model: caps, per-transaction and per-period limits, and instant cancellation.
  3. Give small and community operators a proportionate way in. The Wave 1 sectors are large, regulated institutions. A community payment network shouldn't need an EMI partner and a safeguarding regime just to offer a tap. A light agent model, working under an authorised provider's payment initiation (PISP) licence with clear rules for in-person cVRP, would let small operators take part without ever holding funds.
  4. Treat money staying in the local economy as something the rails should serve, not a happy accident. The National Payments Vision and community wealth building policy already point this way. The cVRP roadmap should be read in that light, and in-person retail, where card fees hit the smallest shops hardest, should come sooner rather than last.

Why this is bigger than us

We're one small community experiment in one city. But the wall we've hit isn't ours alone. Anyone who wants to use A2A payments to cut card fees at a physical till runs into the same thing, whether they're a co-op, a market, a business improvement district, a local currency, a high-street regeneration project, or just a cheaper commercial pay-by-bank provider. And they all get pushed towards the same unnecessary e-money scaffolding. As things stand, in-person A2A arrives last, and when it does arrive it favours whoever can afford to hold funds and carry licences.

The infrastructure is built. It went live in June, and it works. What's stopping money staying in local economies at the till isn't technical. It's a permission nobody has granted yet. That's a policy choice, and policy choices can change.


Bernie is experimenting with Kitty, a community-owned A2A payments app in Leeds, as a hobby project.

Written August 2026. cVRP status current as of the UKPI Wave 1 rollout; roadmap references reflect industry and HM Treasury Payments Forward Plan guidance at the time of writing. Check current status before citing.