Open Banking
Open Banking (CDR) for Mortgage Brokers: The Complete 2026 Guide
Chasing bank statements is still one of the slowest parts of writing a loan. Clients forget to send them, PDFs arrive out of date, and you end up cross checking transactions by hand to build a serviceability picture. Open banking changes that. With a client's consent, verified income and expense data flows straight into your CRM in minutes, already categorised and ready to assess.
This guide explains what open banking and the Consumer Data Right actually are, why they matter specifically for Australian mortgage brokers, how client consent keeps everyone protected, and how to start using open banking in your own workflow.
What is open banking and the Consumer Data Right?
Open banking is the banking arm of Australia's Consumer Data Right (CDR), a national framework that gives consumers the right to share their own data securely with businesses they choose. It was legislated in 2019 and rolled out to banking first, which is why "open banking" and "CDR banking" are often used to mean the same thing.
Under the CDR, banks are "data holders". When a customer gives their explicit consent, an accredited business can receive a defined set of that customer's banking data directly from the bank through a secure, regulated channel. No passwords are shared, and the customer controls exactly what is shared, with whom, and for how long.
The framework is overseen by the Australian Government, with the Australian Competition and Consumer Commission and the Office of the Australian Information Commissioner responsible for the register of accredited participants, compliance, and privacy. The point of all that structure is simple: it makes data sharing safe, consented, and auditable.
Open banking versus screen scraping and manual statements
Brokers have historically had two ways to see a client's transactions, and open banking improves on both.
Manual statements. The client downloads PDFs or photographs pages and sends them over. It is slow, error prone, easy to fudge, and gives you a static snapshot that is often weeks out of date by the time you assess it.
Screen scraping. Aggregator tools ask the client to hand over their internet banking username and password, then log in on their behalf to pull the data. It is faster than PDFs, but it asks clients to share their banking credentials, which sits awkwardly against most banks' terms of use and is under increasing regulatory scrutiny.
Open banking. The client authenticates directly with their own bank and consents to share a specific set of data. Nothing about their login is ever exposed to you or your software. The data arrives structured, categorised, and current, straight from the source. It is faster than statements, safer than screen scraping, and it is the direction the whole industry is moving.
Why open banking matters for mortgage brokers
Open banking is not just a nicer way to collect statements. It changes the quality and speed of the work.
Faster serviceability. Verified income and expense data lands in your assessment in minutes. You spend less time chasing documents and more time structuring the deal.
Better data accuracy. Because the data comes straight from the bank, there is no rekeying, no missing pages, and no doctored PDFs. Transactions arrive categorised, so living expenses and income are easier to identify and defend.
Stronger Best Interests Duty evidence. BID requires brokers to make reasonable inquiries into a client's circumstances and to keep records. Consented, bank verified data gives you a clean, timestamped evidence trail of the financial position you relied on, which is far stronger than a folder of PDFs.
A better client experience. Instead of hunting for statements, the client taps through a familiar bank login and it is done. That first impression sets the tone for the whole engagement.
Fewer reworks. Current, complete data up front means fewer surprises at assessment and fewer requests back to the client, which protects your timelines and your conversion rate.
How consent protects your clients
The part clients care about most is security, so it helps to be able to explain it clearly.
Open banking consent is explicit and specific. The client chooses which accounts and which data types to share, and they see exactly what they are agreeing to before anything is shared. Consent is also time limited and can be withdrawn at any moment, either through the business that requested it or directly with their bank.
Critically, the client never gives you or your software their banking password. They authenticate with their own bank, and only the data they approved is passed through the regulated CDR channel. The framework also requires data minimisation, so only the data needed for the stated purpose can be collected.
When a client asks "is this safe?", the honest answer is that open banking is more secure than emailing PDFs and far more secure than handing over a banking password to a scraping tool.
How brokers actually access open banking data
A common question is whether every broker needs to become an accredited CDR participant. In practice, most do not.
Accreditation is demanding, so the CDR includes models that let an accredited provider extend access to other businesses. Through arrangements such as the sponsor and affiliate model and the CDR representative model, an accredited data recipient can enable a broker or a broker's software to use open banking data under the accredited party's umbrella and compliance obligations.
There is also a Trusted Adviser pathway. The CDR recognises certain professionals, including mortgage brokers, as trusted advisers, which means a consumer can consent to share their CDR data with their broker to receive advice.
The practical upshot: you do not need to build accreditation infrastructure yourself. You access open banking through a provider that has already done that work, which is exactly how Lend1 delivers it.
How Lend1 delivers open banking through Fiskil
Lend1 provides open banking through Fiskil, an Australian CDR platform that handles the accreditation, bank connections, and secure data channel so you do not have to.
Inside Lend1, it works like this. From your client's onboarding portal, the client is invited to connect their bank through open banking. They authenticate directly with their institution and consent to share the data you need. That verified data flows back into the client's file in your CRM, categorised and ready for you to assess, alongside the fact find, documents, and everything else in the onboarding flow.
Because it is built into the onboarding portal rather than bolted on as a separate tool, there is no extra login for the client and no manual export and import for you. The bank verified data simply becomes part of the client record.
Getting started with open banking
If you are moving from statements or screen scraping to open banking, a sensible rollout looks like this.
- Decide where it fits. Most brokers introduce open banking at fact find, as the primary way to collect income and expense data during onboarding.
- Prepare a short client explainer. A couple of plain English sentences on what open banking is, that no password is shared, and that consent can be withdrawn, removes almost all hesitation.
- Make it the default, keep a fallback. Lead with open banking, but keep a path for the occasional client whose institution or situation needs a manual statement.
- Fold it into your BID record keeping. Treat the consented data as part of your evidence trail, so your reasonable inquiries are documented as a matter of course.
Frequently asked questions
Is open banking safe for my clients? Yes. Clients authenticate directly with their own bank and never share their banking password with you or your software. They consent to share a specific, limited set of data, and they can withdraw that consent at any time.
Do I need to be CDR accredited to use open banking? Generally no. You access open banking through an accredited provider such as Fiskil, which carries the accreditation and compliance obligations. Models like the CDR representative arrangement and the trusted adviser pathway are designed so brokers can use the data without building accreditation themselves.
Is open banking the same as screen scraping? No. Screen scraping relies on the client handing over their internet banking login. Open banking never exposes those credentials and uses a secure, regulated channel with explicit consent, which makes it both safer and more reliable.
What data can I actually see? With consent, you can access account and transaction data relevant to assessing a loan, such as income, expenses, and account balances. The client controls which accounts and data types they share, and only what they approve is collected.
How long does it take? For the client it is a short, familiar bank login. For you, verified data typically lands in the client file within minutes, rather than the days it can take to chase statements.
The takeaway
Open banking is faster than collecting statements, safer than screen scraping, and it produces a cleaner evidence trail for your Best Interests Duty obligations. The framework and the technology are ready, and the access models mean you do not need to become accredited to benefit.
Lend1 builds open banking directly into client onboarding through Fiskil, so verified bank data becomes part of the client record without extra logins or manual exports. If you want to see how that looks with your own onboarding flow, explore the Fiskil integration or request a demo.
Get Started
Ready to streamline your brokerage?
Automate your back office, onboard clients through a branded portal, and let AI handle the document work. Spend your time on the conversations that win deals.
Easy Onboarding
Cancel Anytime
Australian Built
Setup in Minutes