Join our Newsletter — 33% off our NHI Course

What do lenders get wrong about consumer consent and data use in digital underwriting?

A common mistake is treating customer data as if the platform owns it. In digital underwriting, the consumer remains the data owner and material lending decisions require explicit consent for use of that data. If consent is unclear or implied, firms weaken trust, create privacy risk, and expose themselves to compliance challenges across e-commerce and lending journeys.

The core error is treating consent as a formality instead of a boundary on how consumer data may be used. In digital underwriting, the borrower is not surrendering ownership of the data by submitting it, and lenders should not assume the right to reuse it across products, journeys, or channels without clear permission and purpose alignment.

That matters because underwriting usually blends identity, transaction, and behavioural data. If the customer does not understand what is being collected, why it is needed, and whether it will influence a decision, the lender may have a process that is technically efficient but commercially and legally fragile.

Practitioners should also distinguish between consent for one decision and consent for broader data reuse. A consumer may agree to data use for affordability assessment, but that does not automatically justify secondary use for marketing, model training, or onward sharing unless the consent basis and notice support it.

Implied consent breaks down quickly in journeys where applicants move across web, app, call centre, broker, and partner environments. If disclosures are buried, copied from a generic privacy notice, or detached from the actual decision point, the lender may have collection permission in theory but not a defensible basis for material use. The EU General Data Protection Regulation (GDPR) is a useful reference point here because it forces discipline around lawful processing, data minimisation, and privacy by design.

That weakness shows up operationally as trust erosion, complaint handling, consent disputes, and model or workflow redesign after legal review. It can also create downstream risk when underwriting data is copied into decisioning platforms, shared with third parties, or retained longer than the customer reasonably expected.

Lenders also misread “consent” as a catch-all solution. For some processing, the real control is not a generic tick box but the combination of notice, legal basis, minimisation, retention limits, and a documented reason why the data is necessary for the lending decision.

Good practice starts with purpose specificity. The lender should be able to state, in plain language, which data fields are needed, which decision they support, who receives them, and whether they influence automation, human review, or both. That description should match the actual workflow rather than a broad enterprise privacy policy.

It also requires consent and permissions to be traceable across the full decision chain. Where the underwriting journey includes consent capture, sharing with service providers, or enrichment through third-party data, the control point should be visible enough that a reviewer can prove what the customer agreed to and when. NHIMG’s Identity Data Privacy and Consent Guide is directly relevant because it treats consent, minimisation, and retention as part of governed identity data use.

For practitioners, the practical standard is simple: if a data item can affect creditworthiness, affordability, fraud screening, or adverse action, its lawful basis and consent path should be auditable end to end. If that path cannot be shown, the process should be treated as a control gap, not a documentation issue.

Risk and Threat Considerations

Unclear consent does more than weaken privacy posture. It creates a vulnerable decisioning chain where consumers may later challenge the fairness, scope, or legitimacy of the underwriting process, especially when data is reused beyond the original context or shared with multiple parties.

Failure mechanism: The lender collects or repurposes consumer data on the assumption that application submission implies permission, then uses that data across underwriting, enrichment, retention, or downstream sharing without a defensible, purpose-specific basis.

Impact: The result can be regulatory exposure, complaint escalation, disputed decisions, forced rework of underwriting journeys, and loss of trust in both the product and the lender’s data handling.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
GDPR Art.5 — Principles Relating to Processing of Personal Data Digital underwriting data use must be purpose-limited and minimized.
Art.25 — Data Protection by Design and by Default Underwriting journeys need privacy controls built into the flow.
Art.35 — Data Protection Impact Assessment Broad consumer data use in underwriting can create high privacy risk.
Recommendation — Apply Art.5 to limit underwriting data use to the stated purpose and minimal necessary fields. Embed privacy-by-design controls into the underwriting workflow from the start. Perform a DPIA when underwriting data use may create high privacy risk.
ISO/IEC 27001:2022 A.5.34 — Privacy and protection of PII Consumer underwriting data handling is a privacy and PII governance issue.
A.5.31 — Legal, statutory, regulatory and contractual requirements Consent and data use in lending must meet applicable legal obligations.
Recommendation — Define and enforce controls for lawful collection, use, retention, and disclosure of PII. Track and satisfy legal and contractual requirements that govern lending data use.
NIST SP 800-53 Rev 5 AU-2 — Event Logging Underwriting consent and use decisions should be auditable.
Recommendation — Log consent capture, data access, and decision events so the chain is reviewable.

Practitioner Guidance

What to verify: Confirm that the consent language matches the exact underwriting use case, not just the broader platform or app journey. Check that the data categories, decision purpose, retention period, and third-party sharing terms are all visible to the borrower before collection.

Decision rule: If the data can influence a lending decision, treat consent and notice as production controls, not UX text. If you cannot explain the permission chain to a customer in one pass, the underwriting flow is probably over-collecting or over-reusing data.

Common mistake: Teams often optimise for conversion and then try to “fix” consent later in legal review. By then, the workflow, model inputs, and partner dependencies are already embedded, which makes remediation slower and more disruptive.

Practitioner takeaway: In digital underwriting, the control objective is not just collecting data lawfully, it is proving that every material use of consumer data was expected, necessary, and explicitly bounded at the point of decision.