Zurück

Account insights in B2B: how AIS data changes credit checks

02.09.2026
 · 
17 min read
Kontoblick B2B Bonitätsprüfung – Panorama

Account insights have long since arrived in the lending business. Banks and financial service providers use account data to assess an applicant's financial situation in a more current and differentiated way. However, the method is also becoming increasingly relevant for B2B companies: after all, anyone offering business customers payment terms, invoice purchase or instalment payment likewise takes on a financial risk.

Classic credit reports provide important information for this purpose. However, their data is often based on the past and can be incomplete, particularly for young companies or dynamic business models.

An account-based analysis approaches the matter from a different angle. It looks at actual payment flows and can thereby provide a current insight into a company's financial situation.

This article explains how account information services work technically, what data can be evaluated, what B2B use cases arise, and where the limitations of the method lie.

What exactly is account-based insight?

"Account insight" is not a fixed, defined regulatory term. It usually refers to digital access to information from a bank account after the account holder has authorised that access.

The technical and regulatory basis is formed by so-called Account Information Services, or AIS.

These services were anchored in regulation by the second European Payment Services Directive, PSD2. They allow authorised third-party providers, with the payment service user's consent, to access defined information from a payment account. An account information service may only retrieve account data with the user's express consent.

In Germany, providers of account information services are subject to the requirements of the Payment Services Supervision Act (Zahlungsdiensteaufsichtsgesetz). BaFin maintains corresponding registers of licensed and registered payment service providers.

From screen scraping to a regulated interface

Technically, today's open banking differs significantly from earlier methods. In so-called screen scraping, a user's access credentials were in some cases used to technically log in to that user's online banking as if they were that user and read out information there.

PSD2 has instead created a regulated framework for account access by third-party providers. Banks must provide corresponding access options for regulated payment service providers. In practice, the exchange of data today typically takes place via dedicated interfaces.

Modern account-based insight is therefore not based on an analytics provider gaining arbitrary access to a company's online banking. Rather, access takes place in a controlled, purpose-bound manner and via regulated technical processes.

How does account-based insight work technically?

For the user, an account-based analysis often feels like a brief digital process. Technically, several steps take place in the background.

1. Consent from the account holder

The process begins with the account holder's active decision to provide account information for a specific purpose. In a B2B use case, this could, for example, be a company requesting a higher payment term from a supplier or wanting an additional check carried out after an initially negative credit decision.

Under PSD2, access by an Account Information Service requires the express consent of the payment service user.

2. Selecting the bank

The user then selects their bank or credit institution. The account information service then establishes the technical connection to the relevant bank. This uses the account access interfaces provided by banks, often referred to as XS2A — "Access to Account".

3. Strong customer authentication

The account holder authenticates with their bank. In principle, the requirements for strong customer authentication, or SCA, apply here. PSD2 provides for such strong authentication in particular for online access to payment accounts.

The specific authentication required depends on the bank and the respective access scenario. Typically, the process takes place via the familiar banking environment of the relevant credit institution.

4. Retrieval of defined account information

After successful authorisation, the released account information can be retrieved via the relevant interfaces. Access is not unlimited. Which information is available depends, among other things, on the respective bank, the account and the interface.

It is also important to avoid a frequent conceptual confusion: the previously often cited 90-day cycle does not relate generally to the "validity of a consent". The regulatory requirements for renewed strong customer authentication for certain account information accesses have been adjusted to 180 days.

5. Analysis and evaluation

The retrieved raw data alone does not yet amount to a credit decision. Only an analysis logic classifies transactions, identifies recurring payment flows and calculates relevant metrics from them. An account analysis in the B2B context can, for example, examine how stable the available funds are or what ratio regular obligations bear to incoming payments.

This is what turns technical account access into an economically usable basis for decisions.

What data does account-based insight provide?

Which information is actually available depends on the bank, the account and the specific technical integration. In principle, however, various categories of account information can be evaluated.

Account holder and master account data

Depending on the interface, basic account information can be provided. This includes, for example, the account identifier and available details about the account holder. In a B2B context, this information can also help verify the connection between a company and the business account being linked.

Current balance

The current account balance provides a snapshot of available liquidity. On its own, however, this figure is only of limited informative value. A high balance may have arisen briefly from a single incoming payment, while a low balance shortly before regularly expected income likewise says little about fundamental solvency. What matters, therefore, is looking at it in its temporal context.

Transaction history

Depending on the bank and technical availability, account transactions from a past period can be retrieved. In practice, several months are often examined for credit analyses. However, this does not allow for a blanket guarantee that every bank always provides, for example, 90 or 180 days in full via a PSD2 interface.

Regular income

An automated analysis can identify recurring incoming payments. For a business account, these could, for example, be customer payments, recurring revenue or other regular inflows of funds. This makes it possible to examine whether income arises continuously or fluctuates significantly.

Regular expenditure

On the expenditure side, recurring obligations can become visible. These can include, among other things, rent, salary payments, loan instalments, insurance or tax payments, provided these can be identified and reliably categorised based on the available transaction data.

Calculated metrics

The actual added value arises from evaluating the transaction data. Possible metrics include, for example:

  • average available liquidity,
  • level and stability of regular incoming payments,
  • fluctuations in the account balance,
  • ratio of recurring outgoings to income,
  • frequency of critical liquidity situations,
  • development of cash flows within the period under review.

Which metrics are actually suitable for a credit decision depends on the respective business model and risk model.

Account-based insight in B2C vs. B2B — the differences

The technical basis can be similar for private and business accounts. However, the economic context differs significantly.

  • Data source: B2C uses the private payment account, B2B the business payment account.
  • Typical purpose: B2C — creditworthiness check, financing. B2B — payment term, credit limit, invoice purchase, instalment payment.
  • Account holder: consumer vs. company or authorised representative.
  • Assessment focus: income and personal obligations vs. cash flow, liquidity and business payment flows.
  • Typical use: credit application vs. sales, onboarding or credit process.

A key difference lies in the interpretation of the data. For a private individual, for example, regular salary payments can play a central role. For a company, by contrast, seasonal fluctuations, irregular customer invoices and larger individual payments can be entirely normal. An open banking credit assessment in B2B therefore requires different assessment models than an analysis of private current accounts.

A legal distinction must also be made. For a corporation, the company is a legal entity. Nevertheless, transaction data can contain personal data, for example the names of individuals or details of managing directors and employees.

Use cases in B2B

Account-based insight can be used at various points in a B2B process.

1. New-customer checks for invoice purchase in B2B e-commerce

B2B shops frequently face a conflict of objectives: invoice purchase is attractive for many business customers but increases the default risk for the provider. A PSD2-based credit check can provide additional current information where the classic data basis is not sufficient for a decision. This allows the review process to be structured in a more differentiated way, without generally restricting invoice purchase.

2. Setting individual credit limits

In classic B2B sales too, customers are frequently granted individual credit limits. Historical credit information can serve as a basis here. Current liquidity data can provide additional indications, for example when a higher limit is requested. This allows for a decision more strongly oriented towards the specific individual case.

3. Second look after a negative credit report

A particularly relevant use case is a second review stage. If a potential customer initially receives no approval based on classic credit data, they can optionally be offered an additional account-based check. This gives the company the opportunity to present its current economic situation on the basis of real account data. For the provider, this creates an alternative to a binary decision between acceptance and final rejection.

Second look in practice: instead of blanket rejection of borderline cases, the customer is actively offered the account-based second review. For many B2B providers, this is precisely the most effective lever against unnecessary revenue losses caused by strict score cut-offs.

4. Ongoing assessment of existing business customers

In principle, account information services can also be used for recurring analyses, provided the regulatory and contractual requirements are met. The advantage lies in being able to identify changes in the financial situation earlier than through new annual financial statements, however, continuous monitoring requires a suitable consent and authentication process. Under the current PSD2 rules, strong customer authentication must be repeated at the latest after 180 days for certain AIS accesses.

5. Onboarding of young companies

Start-ups and newly founded companies present classic credit models with a structural problem. Lack of history does not automatically mean a lack of solvency. At the same time, fewer external information sources are often available for a well-founded assessment. A current account analysis can provide additional data here and thereby narrow an information gap.

Advantages over classic credit checks

Account-based methods differ from traditional business credit reports in several respects.

Currency

An annual financial statement describes a past reporting period. Account data, by contrast, can reflect the financial situation much closer to the time of a business decision.

Real cash flows

Classic scores derive risks from various characteristics and historical data. An account-based analysis, by contrast, looks at payment flows that actually exist. This makes it possible to take into account, for example, current income, recurring outgoings and liquidity fluctuations.

Additional opportunities for companies without a long history

A young company may not yet have several published annual financial statements or extensive payment experience. Current account data can create an additional basis for assessing the actual situation.

Potential for higher conversion

An advantage arises in particular when the account check is used as a second decision-making stage. Customers with an initially insufficient classic result do not have to be automatically and finally rejected. If the additional check produces a positive picture, the transaction can, if appropriate, be approved under defined conditions. This can reduce erroneous rejections without forgoing a risk check.

Automatability

The entire process can run largely digitally. From bank selection through authentication to data analysis, individual steps can be integrated into existing application, checkout or onboarding processes via interfaces.

Limitations and challenges

An account-based check is not a cure-all. This method too has clear limitations.

Technical coverage is not identical everywhere

PSD2 has created a regulatory framework for account access. Nevertheless, banks and interfaces differ in their practical implementation and in the information actually available. BaFin therefore continues to address requirements for PSD2 account access interfaces.

The customer must actively participate

A company cannot simply retrieve account data without the account holder's involvement. The payment service user must expressly enable the account information service to access it. Not every customer will be willing to do so. The process should therefore convey clear benefit and create as little friction as possible.

Ongoing access requires renewed authentication

For longer-term use cases, companies must take into account the regulatory requirements for recurring access. The 90-day period often still referenced has been extended to 180 days under the relevant SCA rule. Continuous monitoring without renewed user interaction is therefore not possible indefinitely.

Business accounts are more complex

Business payment flows are often harder to interpret than private household accounts. Seasonal turnover, bulk payments, internal transfers or several parallel business accounts can complicate the analysis. Technical coverage can also vary depending on the bank, account type and corporate constellation.

Data requires suitable evaluation logic

More data does not automatically mean better decisions. A single high payment or a temporarily low account balance can easily be misinterpreted without context. What matters, therefore, are traceable rules or models tailored to the respective B2B use case.

Legal framework — PSD2, GDPR, upcoming regulation

The regulatory basis for account information services is currently PSD2. It has embedded account information services as regulated payment services within a European legal framework. In Germany, the corresponding supervisory requirements are implemented in particular via the Payment Services Supervision Act. Among other things, BaFin maintains a register of licensed and registered institutions for this purpose.

In parallel, the European payments framework continues to evolve. The EU is working on PSD3 and the Payment Services Regulation, or PSR, to further develop existing payment services regulation. Following a provisional political agreement at the end of 2025, this was confirmed in April 2026 according to Council documents; the legislative procedure had therefore made significant progress by 2026.

In addition, the planned Financial Data Access framework, or FIDA, is intended to eventually extend regulated data exchange beyond payment account data to further financial data. The proposal expressly covers data of both consumers and businesses and relies on access with the customer's permission.

The GDPR remains a separate matter

The regulatory permissibility of account access under payment services law does not automatically answer all data protection questions. Once personal data is processed, the processing requires a suitable legal basis under the GDPR. Depending on the process, consent or a legitimate interest may, for example, be relevant.

Companies must also take into account, among other things, purpose limitation, transparency and data minimisation. The specific legal assessment depends on the respective process, the parties involved and the data processed. This overview therefore does not replace an individual legal or data protection assessment.

How to integrate account-based insight into your B2B process

A successful integration does not begin with the technical interface but with the decision-making process. For a broader overview of B2B credit checks in general, our guide to credit checks for businesses can help.

1. Define the right point in time

First determine when the account-based check should be used. One option is to check every new business customer. However, a risk-based approach, in which additional account data is only required in certain cases, can often be more efficient.

2. Combine with classic data

Account data and classic business information answer different questions. Register and credit bureau data can provide indications of history and structural risks. Account data supplements this perspective with current payment flows and liquidity. A multi-stage process can combine both types of information in a targeted way.

3. Choose a regulated provider

For technical account access, it should be checked whether the account information service used holds the required regulatory authorisation. The relevant registers of the competent supervisory authorities provide important guidance here.

4. Keep the consent process simple

Every additional step in checkout or onboarding can lead to drop-offs. The user should therefore understand why the account connection is being offered, what data is required and what happens to it afterwards. Particularly in a second-look check, the value proposition is clear: the additional check provides a further opportunity to review an initially negative or unclear decision.

5. Define decision logic

Before integration, it should be established which metrics are actually relevant. Companies must, for example, define which liquidity values, fluctuations or expenditure-to-income ratios lead to approval and when manual review is required. Only a clear evaluation logic turns account data into a robust component of the credit management process.

Conclusion

Account-based insight does not change credit checking because it makes classic business credit reports superfluous. Its added value lies rather in closing an information gap.

Classic methods show how a company is assessed historically. Account-based analyses can add how a company's actual payment flows and liquidity currently look. This combination is particularly interesting for young companies, for outdated or incomplete credit information, and for customers who would initially be rejected based on a classic score.

Instead of deciding exclusively between acceptance and rejection, companies can establish an additional review stage. This makes account-based insight a logical complement to classic credit assessment methods: historical data provides the baseline, while current account data enables an additional view of financial reality at the moment of decision.

Frequently asked questions

Is account-based insight the same as screen scraping?

No. Modern account access via regulated account information services is based on the legal and interface framework created by PSD2. Screen scraping, by contrast, refers to methods in which account information is read out via the user interface of online banking.

How long may account access be used?

The specific duration depends on the process and the consent given. For certain recurring AIS account accesses, a 180-day period currently applies for renewed strong customer authentication; the previously often cited 90-day rule is outdated in this respect.

Does the provider need its own BaFin licence?

Not every company that uses an account-based credit analysis within its process needs to be an account information service provider itself. However, the actual regulated account access must be carried out by an appropriately authorised provider; in Germany, supervisory licensing or registration requirements apply for this purpose.

Does account-based insight also work for business accounts?

In principle, business accounts can also be connected via PSD2-based account information services. However, the specific availability and scope of the retrievable data depend on the bank, account type and interface.

Can account-based insight completely replace classic credit reports?

In most B2B use cases, a complement is more sensible than a complete replacement. Classic reports provide information on history and structural risks, while account data enables a more current insight into cash flows and liquidity.

Frequently asked questions

What is an account information service (AIS) under PSD2?
An AIS is a payment service licensed by BaFin that, with the account holder's consent, is granted read-only access to account data. It is based on PSD2 (EU 2015/2366) and the German Payment Services Supervision Act (ZAG).
What licence does an AIS provider need?
AIS providers require registration as an account information service under sections 34 et seq. of the ZAG with BaFin, together with compliance with the EBA's technical regulatory standards (RTS).
What data may an AIS read — and what may it not?
An AIS may only read the balances and transactions of the accounts released by the user. Initiating payments or passing data to third parties outside the agreed purpose is not permitted.
How does a corporate customer grant access (SCA)?
The authorised signatory identifies themselves via strong customer authentication (SCA) directly with their bank — typically via an app or TAN procedure — and confirms the purpose and scope of the access.
How long is an AIS authorisation valid?
Under the EBA RTS, authorisation is time-limited (currently up to 180 days), must be reconfirmed thereafter, and can be revoked at any time.
What happens if consent is revoked?
If consent is revoked, the AIS's access ends immediately. Further data retrieval is not permitted; any data already collected is handled in line with purpose limitation and the deletion concept.

Sources and further reading

Want to win customers despite a weak classic credit score?

ConversionUp analyses current business account data and gives borderline cases a well-founded second look.

Request a demo

©itsmydata 2026. Alle Rechte vorbehalten

©itsmydata 2026. Alle Rechte vorbehalten