On this page
- Two categories: Sweeping and Commercial
- Sweeping VRP (live since 2022)
- Commercial VRP (cVRP — live June 2026)
- UKPI — the commercial VRP scheme
- Wave 1 and Wave 2 rollout (UK)
- Wave 1 — live June 2026
- Wave 2 — expected H2 2026 / early 2027 (volatile)
- How VRP works technically
- VRP vs Direct Debit
- Merchant proposition
- Adoption and scale (UK)
- First ecommerce deployment (historical)
- Regulatory landscape
- UK
- EU / PSD3
- Known blockers to scale
- PSP ecosystem
- Key terms
- Next frontier concepts
Variable Recurring Payments (VRP)
Variable Recurring Payments (VRP)
A Variable Recurring Payment (VRP) is an open banking payment instruction that lets a licensed third-party payment provider (PISP/TPP) initiate multiple payments from a customer's bank account over a set period within pre-agreed, customer-defined parameters — without requiring re-authentication for each transaction. The customer defines a maximum payment amount, a frequency limit, a time window, and a destination account; every subsequent payment must fit inside those boundaries. Consent is held at the customer's bank, not by the merchant, and can be revoked unilaterally through the customer's banking app at any time. In the UK, VRP payments settle over Faster Payments in real time.
Two categories: Sweeping and Commercial
Sweeping VRP (live since 2022)
Sweeping VRP moves money between two accounts owned by the same person (me-to-me), using open banking APIs. It has been live in the UK since 2022 under a Competition and Markets Authority (CMA) mandate on the nine largest UK banks (CMA9). Use cases include automated savings pots, overdraft sweep protection, and mortgage offset funding. (Modulr Finance, 2026-05-01)
[!note] Sweeping VRPs are proposed to remain free of charge to customers under the HM Treasury July 2026 consultation on the long-term regulatory framework. (HMT Consultation, 2026-07-14)
Commercial VRP (cVRP — live June 2026)
Commercial VRP extends the same mechanics to payments from customers to third parties — billers, merchants, charities, government — enabling a business to collect variable amounts from a customer's bank account under a single standing consent. Funds availability is checked before each payment executes, reducing failures from insufficient funds. (Modulr Finance, 2026-05-01)
cVRP launched in the UK on 2 June 2026 via the UK Payments Initiative (UKPI) — described as the UK's first new payment scheme since Faster Payments in 2008. (as-of 2026-06-08) (Open Banking Tracker, 2026-06-08)
UKPI — the commercial VRP scheme
UKPI (UK Payments Initiative Ltd) is an independent, industry-owned company established in late 2025 by 31 firms to own and run the commercial VRP scheme. Members include all major UK retail banks, Mastercard Open Banking Services, GoCardless, TrueLayer, Yapily, Token.io, Moneyhub, Plaid, and others. (Open Banking Tracker, 2026-06-08)
UKPI's defining feature is a Multilateral Agreement (MLA) that sets a common, centrally managed price for initiating a cVRP — a fixed pence-per-transaction fee, charged to the payment provider, not the consumer — so providers do not have to negotiate bank-by-bank. (as-of 2026-06-08) (Open Banking Tracker, 2026-06-08)
The initial industry proposal (UK Finance, January 2026) put the Wave 2 price range at 3p–11p per transaction (recommended 6p–8p), with a separate proposal for an ad valorem (percentage-of-value) model to compete with card-like fee structures. (as-of 2026-01-08) (UK Finance, 2026-01-08)
[!note] The specific published headline fee at Wave 1 launch was not public as of June 2026. The £0.02 bank-cost figure is from pre-launch Frontier Economics modelling, not a confirmed live price. (as-of 2026-06-08) (Open Banking Tracker, 2026-06-08)
In January 2026, the FCA and PSR stated they would not prioritise a Competition Act investigation into UKPI's centralised pricing model, giving the scheme interim regulatory comfort. (Open Banking Tracker, 2026-06-08)
Wave 1 and Wave 2 rollout (UK)
Wave 1 — live June 2026
Wave 1 cVRP covers five sector categories: (as-of 2026-06-08)
| Sector | Examples |
|---|---|
| Utilities, telecoms, rail | Energy bills, broadband, train season tickets |
| Regulated financial services | FCA-authorised firms; mortgage servicers, pension administrators |
| E-money institutions | Wallet and prepaid account top-ups |
| Local and central government | Tax payments, council fees, benefit repayments |
| Registered charities | Variable gift amounts |
Wave 1 explicitly excludes: general ecommerce, BNPL, unsecured loan repayments outside sweeping, travel supplier payments, and general commercial trade. (Open Banking Tracker, 2026-06-08)
The first ever live cVRP transaction was made in November 2025, powered by Tink in partnership with Visa, Kroo Bank, and Utilita (energy). (The Payments Association, 2026-02-16)
Wave 2 — expected H2 2026 / early 2027 (volatile)
Wave 2 is intended to extend cVRP scope to general ecommerce, including SaaS Subscription Commerce, streaming, and regular-purchase recurring payments. (as-of 2026-06-08) (Open Banking Tracker, 2026-06-08; Yapily, 2026-05-12)
Wave 2 timing: Open Banking Tracker (June 2026) states Wave 2 is "expected in the second half of 2026." Yapily (May 2026) says "late 2026 or early 2027." The FCA (December 2025) does not commit to a Wave 2 date — it commits to evaluating Wave 1 adoption by end of 2026 and then building a long-term framework. The H2 2026 date is an industry expectation, not a regulatory commitment. (PSR, 2025-12-01)
How VRP works technically
- Customer authenticates once with their bank and grants a standing consent with defined parameters (max amount, frequency, destination, time window).
- Consent is stored at the customer's bank, not by the merchant.
- The merchant's licensed PISP (e.g. TrueLayer, GoCardless, Yapily) initiates each payment via open banking APIs.
- Before execution, funds availability is checked — reducing insufficient-funds failures structurally.
- Payment settles over Faster Payments in real time.
- The customer can view, amend, or cancel the mandate at any time through their banking app.
Cancellation of a VRP mandate is unilateral and immediate — unlike a Direct Debit mandate, which requires action from the payee or a bank dispute. Unlike Direct Debit, the merchant knows immediately when a VRP mandate is cancelled rather than finding out when a payment fails. (Stripe, 2026-04-19; TrueLayer, 2026-01-07)
VRP vs Direct Debit
| Dimension | VRP (cVRP) | Direct Debit (BACS) |
|---|---|---|
| Settlement | Real-time (Faster Payments) | 3-day BACS cycle |
| Funds check | Before execution (pre-flight) | Not verified in advance |
| Failure rate | Low (structural pre-check) | 2.29%–3% (as-of 2026-05-12) |
| Cancellation visibility | Instant — merchant notified immediately | Found out on failed payment |
| Failed-payment charges | Not yet standardised | Can reach £50/transaction (BACS) |
| Consumer revocation | Unilateral, via banking app | Requires payee action or bank dispute |
| Consumer protection | No Direct Debit Guarantee equivalent (as-of 2026) | UK Direct Debit Guarantee |
| Cost model | Flat pence-per-transaction (proposed) | BACS service fees + bank charges |
(Yapily, undated; Modulr Finance, 2026-05-01)
cVRP as complement vs replacement for Direct Debit: Modulr Finance (May 2026) explicitly frames cVRP as a complement to Direct Debit — not a replacement — due to incomplete bank coverage at launch, recommending a hybrid approach. TrueLayer's "Bank on file" framing implies eventual replacement of card-on-file and Direct Debit. Yapily's framing is more disruptive ("primed to disrupt Direct Debit"). The near-term operational reality aligns with Modulr's hybrid framing; long-term aspiration aligns with TrueLayer/Yapily. (Modulr Finance, 2026-05-01; TrueLayer, 2026-01-07)
Merchant proposition
TrueLayer brands cVRP as "Bank on file" — a deliberate analogue to Card-on-File / "card on file" — arguing the naming is intuitive because it mirrors familiar behaviour. (TrueLayer, 2026-01-07)
Merchant benefits cited by TrueLayer (January 2026):
- Lower cost per transaction — avoids card scheme fees and interchange; flat pence fee model
- Higher retention — fewer failed payments mean fewer involuntary churn events; 20%–40% of subscription churn is driven by payment failure, not customer intent (as-of 2026-05-12) (Yapily, 2026-05-12)
- Elimination of card fraud at source — bank-authenticated payments eliminate card-not-present fraud vector
- Faster settlement — real-time vs. card settlement lag (Visa/Mastercard: 1–3 days)
- Card expiry problem eliminated — ~30% of stored cards become obsolete per year through expiry, reissue, or account closure (as-of 2026-05-12); VRP mandates persist regardless of card changes (Yapily, 2026-05-12)
- Privacy — merchants store consent parameters, not sensitive card data
Amazon UK's Head of Payment Acceptance, Rajni Tiwari, said at Open Banking Expo (October 2025) that large merchants are "actively searching for payment method innovations that provide more choice competition" — and that a commercial bank-on-file scheme "represent[s] a massive opportunity." Amazon UK subsequently rolled out Pay by Bank (powered by TrueLayer), seen as a potential inflexion point for merchant adoption. (TrueLayer, 2026-01-07; The Payments Association, 2026-02-16)
Adoption and scale (UK)
VRP payments in the UK (as-of early 2026):
- 5.5 million VRP payments per month (as-of 2026-01-07) (TrueLayer, 2026-01-07)
- ~16% of all open banking payments — note: this is a share of open banking payments, not a share of all UK payments; the vast majority are sweeping VRP (as-of October 2024) (Open Banking Limited, 2025-12-16)
- VRP volume more than doubled year-on-year to Q1 2026 (Worldpay Global Payments Report 2026, 2026-04-01)
- Open banking total: 16.5 million active user connections by December 2025; 31 million payments/month (March 2025), equivalent to 7.9% of all Faster Payments (as-of March 2025) (OBL Impact Report 7, 2025-05-16)
VRP volume percentage denominator confusion: The widely-cited "16% of open banking payments" figure refers to VRP's share of open banking payments only — not all UK payments. Industry trade coverage frequently strips the denominator, creating a misleading impression of VRP's overall scale in the UK payments landscape. (Open Banking Tracker, 2026-06-08)
The problem VRP addresses — Direct Debit failure rates:
- UK Direct Debit failure rates averaged 2.29% in May 2025 and are trending up year-on-year (as-of 2026-05-12) (Yapily, 2026-05-12)
- Energy Direct Debit failures rose 39% year-on-year in early 2024; UK domestic energy debt reached £4.43 billion by June 2025, with nearly 75% held by customers in arrears (as-of 2026-05-12) (Yapily, 2026-05-12)
First ecommerce deployment (historical)
In February 2024, Yapily and Ant Financial (via its Antom payment platform) launched what was described as a European "first" for commercial VRP in ecommerce: a "One Click Payment" powered by cVRP on HungryPanda, an Asian food delivery platform operating in over 80 cities in 10 countries. (Open Banking Expo, 2024-02-07)
Regulatory landscape
UK
| Instrument | Status (as-of 2026-07-26) |
|---|---|
| CMA Order on CMA9 | In force — mandates sweeping VRP APIs on nine largest banks |
| Data (Use and Access) Act 2025 | In force — statutory foundation for UK open banking redesign |
| UKPI cVRP scheme | Live since 2 June 2026 (Wave 1) |
| HM Treasury Consultation | Published 14 July 2026; proposes statutory VRP access right; closes 6 October 2026 |
| FCA Long-Term Regulatory Framework | Under development; FCA consultation expected before end of 2026 |
| FCA Open Finance Roadmap | Published 14 April 2026; VRP monitoring a 2026 deliverable; open finance 2030 horizon |
The HM Treasury consultation (14 July 2026) proposes replacing the CMA Order with a statutory FCA-led open banking framework and creating a formal access right for VRPs, with sweeping VRPs proposed to remain free of charge and commercial VRP access potentially chargeable under FCA rules. (Skadden analysis, 2026-07-22)
(The Payments Association, 2026-02-16; FCA Open Finance Roadmap, 2026-04-14)
EU / PSD3
PSD2 enabled Payment Initiation Services (PIS) and established the open banking API framework, but VRP as a product type emerged from the UK's specific CMA intervention and is not defined in PSD2 text. The EU does not yet have a scheme comparable to UKPI. (Stripe, 2026-04-19)
The UK is not bound by PSD3 or the EU Payment Services Regulation (PSR). The EU provisional agreement was reached 27 November 2025; agreed texts published 23 April 2026. The PSR applies approximately 21 months after Official Journal publication (expected mid-2026), so approximately Q1 2028. PSD3 requires national transposition within 18 months. (as-of 2026) (Brite Payments, 2026)
PSD3/PSR clarifies Strong Customer Authentication (SCA - PSD2) exemptions for recurring and low-risk transactions, which has bearing on how VRP-style recurring payment mandates will be treated in the EU — though VRP as a distinct category remains a UK construct with no direct EU equivalent yet. (GR4VY, 2026)
Known blockers to scale
Stripe (April 2026) identifies the following structural blockers:
- Inconsistent bank API quality beyond the CMA9 mandate — smaller banks have less reliable APIs
- No mandated bank commercial incentive to invest in VRP infrastructure beyond the CMA9
- Incomplete consumer liability / chargeback framework — VRPs currently lack a "Direct Debit Guarantee" equivalent
- TPP fragmentation — unresolved payment-failure resolution paths across provider ecosystems
- Incomplete bank coverage at cVRP launch (UKPI targeted ~75% current-account coverage as a launch threshold) (as-of 2025-12-01) (PSR, 2025-12-01)
Additionally, 26% of merchants surveyed by The Payments Association cited the absence of a standardised dispute/chargeback mechanism as a barrier to open banking adoption. (as-of 2026-02-16) (The Payments Association, 2026-02-16)
PSP ecosystem
Major providers in the UK cVRP stack:
| Provider | Role |
|---|---|
| TrueLayer | PISP / aggregator; UKPI founding member; powers Amazon UK Pay by Bank |
| GoCardless | PISP; first to process VRP transactions (2019); UKPI member; >£50B annually on platform |
| Yapily | PISP; UKPI founding member and shareholder; Wave 1 launch partner |
| Tink (Visa) | PISP; first live cVRP transaction (Nov 2025, with Utilita) |
| Token.io | PISP; UKPI member |
| Plaid | PISP; UKPI member |
| Adyen | PSP with open banking gateway (routes to Tink, Yapily, Plaid); supports VRP-based recurring |
| Modulr | Payment infrastructure; Wave 1 enablement provider |
(Open Banking Tracker, 2026-06-08; Adyen Knowledge Hub, 2026-06-02; GoCardless, 2026-05)
Key terms
| Term | Meaning |
|---|---|
| VRP | Variable Recurring Payment — umbrella term for sweeping + commercial |
| cVRP | Commercial VRP — customer to third party; the ecommerce-relevant variant |
| Sweeping VRP | Me-to-me VRP (same person, different accounts); live since 2022 |
| UKPI | UK Payments Initiative Ltd — the industry-owned company running the cVRP scheme |
| PISP | Payment Initiation Service Provider — licensed TPP that initiates VRP payments |
| TPP | Third-Party Provider — generic term for licensed open banking participants |
| MLA | Multilateral Agreement — UKPI's centralised pricing mechanism |
| Bank on file | TrueLayer's term for cVRP as a bank-account equivalent of card on file |
| Wave 1 | First cVRP rollout cohort (utilities, financial services, government, charities) |
| Wave 2 | Planned ecommerce extension (general retail, subscriptions) |
| CMA9 | Nine largest UK retail banks mandated by the CMA to provide open banking APIs |
Next frontier concepts
- Direct Debit — the incumbent recurring rail VRP is designed to improve upon; no standalone concept page
- Payment Initiation Service (PIS) — the PSD2 framework underlying VRP; no standalone page
- Open Banking — the regulatory and technical infrastructure enabling VRP; no standalone page
- Faster Payments — the settlement rail VRP runs on; no standalone page
- Agentic Commerce — AI agents initiating VRP payments on behalf of users; emerging intersection surfaced in HMT consultation
- Card-on-File — the merchant payment credential VRP ("Bank on file") aims to complement/replace; no standalone page