Fintech Takes

The Biggest Unsolved Problems in Open Banking

Alex Johnson · OCT 29

Happy Wednesday, Fintech Listeners! 

My Money20/20 is officially over, and wow, was that a lot of fun.

I, like everyone, complain about Las Vegas and the Venetian, but the truth is that this conference is one of the most productive and educational times of the year for me. And yes, it’s hard, but as my dad always reminds me, it’s better than digging ditches.

Thank you to everyone who made Monery20/20 2025 so memorable. I’ll share a more in-depth recap of the event in Friday’s newsletter.

— Alex 


3 BIG IDEAS FROM THE PODCAST

Everyone talking about open banking right now is laser-focused on the fight over fees and cost recovery.

However, there’s another fight that is getting less attention, but is (perhaps) more important — the fight over liability and third-party risk management.

We’ve made tremendous progress over the last decade in moving the open banking ecosystem away from screen scraping and towards APIs, with much of the heavy lifting being done by the technical standard-setting organization FDX. APIs reduce credential sharing, but a larger and thornier problem remains: when a consumer grants access to a third party, who’s actually responsible when something breaks?


In today’s podcast, I am joined by Steve Smith (Co-founder & CEO of Invela; former Co-founder of Finicity and of FDX), Todd Taylor (Co-head of Intellectual Property, Commercial & Technology Transactions at Moore & Van Allen), and Dan Murphy (Founder of Sunset Park Advisors; former CFPB Open Banking Program Manager).

Tune in for the full conversation here

And read below for my three big ideas... 

#1: Data Rights for Consumers, Risk and Liability for BanksCopy anchor linkCopied

There's a contradiction at the heart of Section 1033.

Consumers have the right to share their financial data wherever they want, yet when something goes wrong, it’s still the bank that is on the hook for it. That leaves banks in the strange position of having their customers bring them third-party “vendors” they’ve never heard of and insisting they work together.

Under Reg E (the implementing regulation for the Electronic Fund Transfer Act), banks must reimburse customers for unauthorized transactions even if the transactions are facilitated by a fintech company or data aggregator.

And the rulebook they’re told to use — OCC Bulletin 2013-29 and the later Interagency Guidance on Third-Party Risk Management (June 2023) — was written for a different world, when a “third-party vendor” meant FIS or Jack Henry (versus a fintech app connecting to a bank’s systems through APIs because a customer granted it access).

The prudential regulators’ FAQs explicitly clarified that data-sharing relationships in open banking count as third-party relationships, pulling banks under the full third-party risk management framework even when the consumer (not the bank) selects the third party.

So, banks are told to enable open access, but they are judged by risk management standards that were designed for fundamentally different types of relationships.

#2: The Infrastructure of TrustCopy anchor linkCopied

Under Section 1033 of Dodd-Frank, the CFPB’s rulemaking aims to cement consumers’ right to access and share their financial data. This is consistent with the agency’s mandate to spur competition that benefits consumers.

However, it’s important to note that the CFPB is not responsible for ensuring that open banking doesn’t jeopardize the safety and soundness of the U.S. financial system. That responsibility falls on the prudential bank regulators (the OCC, Federal Reserve, and FDIC), which haven’t historically been interested in harmonizing their efforts with the CFPB (there’s a big brother-little brother dynamic at work here). 

Given that, it may make more sense to place some of the responsibility for integrating banks’ open banking and risk management requirements on the banks themselves.

We wouldn’t want this to be done on a bank-by-bank basis. Rather, we would want to facilitate this through the development of new, industry-wide standards and accreditation processes.

There is plenty of precedent to guide us here.

When card-data breaches surged in the early 2000s, the card networks didn’t make every bank and merchant invent its own rules. 

Instead, they created a shared standard (PCI DSS) that applied to anyone handling card data. Independent Qualified Security Assessors (QSAs) verify compliance, and those uniform controls have become the connective tissue that lets millions of merchants plug in securely.

The big question: could the open banking ecosystem do the same?  

Steve and the team at Invela think so.

They are trying to create a single, transparent accreditation process for data recipients, a public registry of approved participants, and a dynamic risk score updated in real time. That means if and when a fintech company’s risk profile changes, a bank can throw a breaker and pause access (all while staying within a prudentially acceptable safe-harbor framework).

It worked for payments; it could work for open banking. The question is whether the U.S. ecosystem will align on a standard approach before a major breach or breakdown forces it to.

🎬 DIRECTOR'S COMMENTARY

A tension that hovers behind our discussion: who should set the standards, and can that process ever really be neutral?

Dan said the CFPB intentionally left the space open for industry standard-setting when it drafted the current rule. The bureau defined what a legitimate standards body should look like (balanced representation, openness, transparent process), but it stopped short of actually prescribing the technical, legal, or operational standards itself.

That approach has worked, to a degree, with the technical standards designed by FDX, but there’s a real question as to whether it is replicable in other, more controversial areas like liability and risk management.

#3: Sharing the RiskCopy anchor linkCopied

Under Reg E and Reg Z, banks have to make the customer whole even when a failure by a third party (chosen by the customer) is what triggers the loss. To put it mildly, banks don’t love this. 

One solution that Invela is pursuing: what if accredited third parties could back their data access with a warranty-based risk-sharing product, essentially an insurance-style mechanism that covers losses their systems create?

That coverage would give banks some assurance when things go wrong.

The question, of course, is would the third parties (or the aggregators they use to access the data) be willing to pay for this?

As we have seen with the debate over fees, the fintech side of the market is very accustomed to getting customers’ data for free, and getting them onboard with paying for insurance (in addition to paying for access to the data itself) may be a tough sell.


WHAT I'M LISTENING TO

#1: The Game of Bank Bargains (2025 Edition) (Fintech Business Weekly) 🎧Copy anchor linkCopied

If you want to understand the structure of the U.S. banking market and the political and regulatory forces that have shaped it, read the book Fragile by Design.

If that sounds a little intimidating, listen to this podcast (featuring the book’s authors) first. It’ll make you want to dive in even deeper.

#2: Reexamining Vullo v. OCC (Bank Nerd Corner) 🎧Copy anchor linkCopied

I really enjoyed this Bank Nerd Corner podcast, featuring a discussion and debate on a very influential (and somewhat unsettled) legal case: Vullo v. OCC.


WHERE I'LL BE

💻 What’s the Best Way to Protect Consumers (and Lenders)?| 11/6 | ZoomCopy anchor linkCopied

Most lenders are running a 2019 playbook in a 2025 economy. Let’s dissect what’s actually working with stressed consumers — without blowing up portfolio risk.

Join me on Nov 6 with Chris Guild (TruStage) and Taylor Nelms (Financial Health Network) for a fast, tactical session on how to spot payment stress earlier, talk to customers more effectively, and deploy flexibility + protection tools that serve people and safeguard portfolios.

Here’s what we’ll cover:

  • The early warning signals lenders should be tracking
  • Messaging that resonates with financially stressed consumers
  • Tools that reduce risk
  • Practical playbook changes for the next 12 months

RSVP here by Nov 5 for a chance to win a Fintech Takes hoodie. Because if we’re all stressed out, we may as well be cozy.


Thanks for the read! Let me know what you thought by replying back to this email. 

— Alex  

By Alex Johnson

Fintech Takes

The weekly read for the people who build fintech and the banks that carry it.