Skip to main content
Sector Guide

Accessibility compliance for Banking & Fintech

Accessibility compliance for banking and financial services

Regulatory context

Banking and financial services are explicitly covered by the EAA under Article 2. This includes consumer banking services, payment services, and financial products offered through digital channels. The requirements extend to online banking platforms, mobile banking apps, ATMs, payment terminals, and any digital interface used to access financial services. EN 301 549 is the applicable standard, incorporating WCAG 2.1 Level AA for web and mobile interfaces.

Common issues Lumi finds in banking & fintech websites

Complex form accessibility

Banking applications have some of the most complex forms on the web - account opening, loan applications, KYC verification, and transaction forms. These frequently have missing labels, poor error messages, and confusing field groupings that make them unusable for screen reader users.

Two-factor authentication barriers

2FA flows involving SMS codes, authenticator apps, or biometric verification are frequently inaccessible. Time limits on code entry, inaccessible modal dialogs for code input, and lack of alternative authentication methods create barriers.

Data tables and financial statements

Account statements, transaction histories, and financial data tables often lack proper table markup (headers, scope attributes) making it impossible for screen readers to understand the relationship between data cells.

PDF statements and documents

Bank statements, loan agreements, and regulatory documents are frequently published as scanned or inaccessible PDFs. Under the EAA, these documents must be accessible - meaning proper text, structure, reading order, and alt text for any visual elements.

Dashboard and data visualisation

Account dashboards with charts, graphs, and spending breakdowns are often built with canvas or SVG elements that convey no information to screen readers. All visual data representations need text alternatives.

Session timeout handling

Banking applications use session timeouts for security, but users with disabilities may need more time. WCAG requires warnings before timeout and the ability to extend sessions - many banking apps fail both requirements.

Banking & Fintech-specific challenges

Banking faces unique accessibility challenges due to the intersection of security requirements and usability. Strong customer authentication (SCA) under PSD2 must be accessible. Real-time transaction processing needs to announce status changes. Multi-step financial processes (loan applications, account opening) require maintaining accessibility across complex workflows. Legacy core banking systems may limit what's possible in the front-end. Regulatory compliance documentation needs to be accessible alongside the digital service itself.

Compliance timeline

The EAA is enforceable from 28 June 2025 for new banking services. Existing services have until 28 June 2030. However, banks are already subject to sector-specific accessibility requirements in many jurisdictions, and the European Banking Authority (EBA) has issued guidance on digital accessibility in financial services.

Check your banking & fintech site now

Lumi scans against WCAG 2.2 and EN 301 549 using five scanning engines - free, no signup required.

Frequently asked questions

Does the EAA apply to banking?

Yes. Consumer banking services are explicitly listed in the EAA. This covers online banking, mobile banking apps, ATMs, payment terminals, and any digital channel used to access financial services.

Are mobile banking apps covered?

Yes. The EAA covers all digital interfaces used to access banking services, including native mobile apps. EN 301 549 includes specific requirements for mobile applications beyond web content.

Do ATMs need to be accessible under the EAA?

Yes. Self-service terminals including ATMs are explicitly listed in the EAA. They must meet accessibility requirements for physical interaction, visual display, audio output, and input methods.

How does PSD2 authentication interact with the EAA?

Strong customer authentication (SCA) required by PSD2 must be implemented in an accessible way. This means authentication flows must be keyboard navigable, screen reader compatible, and provide sufficient time for users who need it. Alternative accessible authentication methods should be available.

Related resources

Last reviewed: April 2026. Content is reviewed quarterly for accuracy.

Get accessibility insights in your inbox

WCAG guides, scanner updates, and industry news. No spam.