Ten years in the making, the Consumer Financial Protection Bureau’s recently finalized open banking rule is making waves.
The rule, Section 1033, was finalized Oct. 22 and states that consumers can transfer their financial data to another financial institution (FI) provider at no cost, using the framework for secure payments and comparing financial services at different organizations.
The rule will foster innovation, competition and protect consumer rights, CFPB Director Rohit Chopra told Bank Automation News.
But it may never be enacted. A lawsuit filed by the Bank Policy Institute on Oct. 22 could delay its implementation. BPI is a banking trade organization whose members include JPMorgan, Bank of America and Citi.
Now banks find themselves in a precarious position, in which “they have to comply but also have to compete in order to stay relevant,” Natalie Talpas, executive vice president and senior group manager of digital banking and payments at $599 billion PNC, said during a panel at the Money20/20 event last month in Las Vegas.
Banks need to look at Section 1033 with both “a defensive and offensive mindset,” she added.
Goran Barnes, head of API at the $82 billion Memphis-based First Horizon Bank, highlighted this uncertainty, speaking at the recent Banking Transformation Summit 2024 in North Carolina.
“The downside of the regulation is that it was just big enough to leave more questions than it solved,” Barnes said. But “the good thing about that is CFPB did provide a framework,” a net positive for the industry after initial hiccups.
The Defensive
Lack of clarity on liability
Banks argue that the CFPB did not address a glaring pain point: “Who is liable if a data breach occurs beyond the walls of the bank?” Nicole Elam, president and chief executive of the National Bankers Association, said at Money20/20. The association’s mission is to advocate for minority depository institutions in the U.S.
Under the rule, banks must share consumer data with fintechs, Elam said. However, banks are concerned that fintechs are not as heavily regulated as banks are and can suffer data breaches due to a lack of security infrastructure, she added.
The CFPB says banks “are responsible for what happens to the consumer” even in the case of a data leak from a vendor’s end, Elam said. Small FIs cannot bear the burden of over-regulation, she added.
PNC’s Talpas agreed. The CFPB is “forcing [banks and fintechs] to work together for the good of the consumer, but there are still many gaps” that are not addressed by the rule, she said, especially as data breaches remain a concern within the industry.
In fact, in 2024, data breaches at these institutions caused major disruptions:
- Bank of America, reported a data breach in February when its IT service provide Infosys Macintosh was compromised;
- Santander Bank, reported in May that its employee data was stolen during a breach earlier this year;
- American Express, in March, the payments company suffered a data breach which resulted in 50,000 customer’s information getting compromised; and more recently
- Fintech Finastra, reported suspicious activity in its internally hosted Secure File Transfer Platform in November.
Risky data-sharing channels
Section 1033 does not ban screen scraping, but it does promote the use of APIs for data sharing, Chopra said.
“My sense is that it would be difficult for the government to maintain some sort of white list” of good data-sharing companies, Chopra said. “It would really need to be done outside and maintained by the industry or some other organization.”
The CFPB asked industry leaders to apply to become part of a standard-setting body for data sharing in a release on June 5, but only data sharing infrastructure company FDX has applied, according to the agency’s website. JPMorgan, Bank of America and Citi are members of the organization, according to the company.
Many FIs are not comfortable sharing data via screen scraping, Trent Sorbe, chief payments officer at $5.3 billion First International Bank and Trust (FIBT) and former FDIC bank examiner, told BAN.
FIs prefer to share data via APIs due to a lack of clarity over data liability and adverse events that make customers wary, Sorbe said. FIBT is working with vendors and its core provider to develop APIs to prevent potential data leaks, he noted.
Cost of compliance
Nearly 90% of financial institutions in the U.S. have less than $2 billion in assets, National Bankers Association’s Elam said. The cost of compliance regarding APIs and data security will weigh heavily on many of those FIs.
“The ability to comply with this rule is going to be significantly impacted by the capability of the bank and the asset size of the bank,” Elam said.
According to a recent survey conducted by the National Bankers Association, 84% of FIs with less than $5 billion in assets said that “high implementation cost is why they are struggling to get on board with APIs and why they’re struggling with open banking,” Elam said.
Big banks have already moved toward “buy, build and partner” for data sharing infrastructure and aim to outsource a big chunk of infrastructure development and have the resources to afford the transition, she said.
And implementation costs are not the only expenses associated with Section 1033, Elam said. Another concern among small FIs is maintaining oversight over what third-party vendors are trustworthy and can be shared data with, which can create hurdles to open banking adoption.
The Offensive
Expanded consumer reach, revenue
Improved access to financial data will lower the “barriers of entry to acquire customers,” the CFPB’s Chopra said.
Adoption of the rule will “just facilitate easier switching” between FIs, promoting competition among them, he added.
PayPal, for example, accesses a consumer’s transaction history — rather than their most recent credit report — for a full understanding of their credit history, Ratinder Bedi, senior vice president and global credit chief at PayPal, said at Money20/20.
Access to this consumer data “allows us to do a deep dive into a consumer’s finances and provide them with a friction-free experience, which increases conversion rates,” Bedi said.
The payments provider can then estimate the consumer’s needs and provide them with the right product at the right time to pull them deeper into their ecosystem.
Fintech Chime, similarly, can easily onboard a customer via open banking and easily learn where they stand in their financial journey in order to provide them with products that speak to them, Chime Vice President of Business Development Jay Parekh said at Money20/20.
Better access to consumer data can allow better messaging to customers, making them feel that their FI cares about them, he said.
AI strategy
Many banks are welcoming Section 1033 with open arms and exploring opportunities to capitalize on it, Chopra said.
“They realize that actually they want the ability to be able to use data in different ways, to be able to underwrite products using disparate types of data” to boost revenue, Chopra said. “They want to actually think about how this aligns with their AI strategy.”
Banks can use AI not only for better underwriting solutions with additional data points, but to interpret newly available data and structure it, Colin Walsh, CEO at $427 million Varo Bank, told BAN.
FIBT is also working on AI solutions that can help make the most of open banking, Sorbe said. Features like AI-driven know-your-customer solutions, consumer data analytics and underwriting can provide small FIs an edge by building stronger customer relationships.
Through AI and access to vast amounts of consumer data, FIs can predict the departure of a customer and then offer better services to retain them, Viral Parikh, vice president of engineering at Varo Bank, told BAN.
Legalities of implementation
While it took the CFPB nearly a decade to finalize the open banking ruling, its future remains uncertain, Peter Dugas, executive director at technology management and consulting firm Capco, told BAN.
The aforementioned Bank Policy Institute lawsuit makes the path to implementation uncertain, Chopra said.
“I don’t think they read the ruling,” Chopra said of the institute. “And I haven’t read the lawsuit.”
The Trump administration can also change the ruling or disregard it, Dugas said, adding that implementation is a long way out.
Different FIs are given different timelines for getting their organizations ready for open banking, Dugas said, adding that as the ruling stands major banks over $250 billion will have to implement Section 1033 by 2026 and FIs under $2 billion have until the end of 2030.
Debra Geister, head of regulatory compliance business lines at digital identity verification and fraud solution provider Socure, agreed.
“It could happen that 1033 gets squashed, but you can’t count on that,” she said. “You have to make sure that your operational systems in this day and age are sound and up to speed with where you need to be today.”
Many industry experts also expect a revision after Donald Trump is inaugurated, Barnes said.
Despite uncertainty hanging over the regulation, many banks “are not going to sit around and wait for regulation to tell us how to do open banking,” First Horizon’s Barnes said. “We will let the framework guide us” to build customer-centric solutions, he said.
Register here for early-bird pricing for Bank Automation Summit 2025, taking place March 3-4 in Nashville, Tenn. View the full event agenda here.






