The model becomes asymmetric. Banks are required to open access, while other data holders may remain harder to integrate, which limits the consumer benefit promised by open access. That imbalance can constrain competition, reduce the quality of analytics, and make it harder to build services that reflect a fuller picture of customer behaviour and preference.
Why the imbalance is structural, not just inconvenient
When access is opened on one side of the market but not on the other, the ecosystem stops behaving like a genuine data network and starts behaving like a one-way compliance layer. Banks absorb the cost of connectivity and consent handling, yet the wider set of data holders can still remain fragmented, closed, or difficult to standardise. That makes the consumer promise of open access weaker than the policy language suggests.
The practical effect is that portability does not automatically create symmetry. A customer may be able to move bank-held information, but the fuller context needed for product comparison, affordability assessment, or personalised service can still sit behind separate technical, commercial, or governance barriers.
Where consumer benefit gets constrained
The main loss is not simply slower integration, it is diminished usefulness. If only the regulated core is open, services can compare account data, but they may still miss income volatility, savings behaviour, spending outside the banked core, or other signals held elsewhere. The result is thinner analytics, weaker attribution, and a narrower basis for decision-making than the policy narrative implies.
That asymmetry also affects competition. New entrants may be able to ingest bank data, but they still have to work around uneven participation from the rest of the ecosystem. In practice, that can favour incumbents with broad distribution, established partnerships, or proprietary data access while limiting the upside of open banking for smaller firms and consumers.
Why ecosystem control matters as much as data sharing
Open access works best when the surrounding ecosystem is governed for interoperability, consent, and discoverability, not just when one major data source is compelled to publish interfaces. If the wider environment lacks common rules for data portability, identity matching, permissions, and technical standardisation, the consumer experiences a partial view rather than a connected financial picture.
That is why this question is really about system design. The issue is not whether banks can be made to share data, but whether the rest of the data environment is structured so that shared data can be combined, trusted, and acted on at scale.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | The subject concerns market structure and ecosystem context for data sharing. |
| PR.DS-10 — Data-in-Transit is Protected | Shared bank data depends on protected transfer between participants and aggregators. | |
| Recommendation — Define the ecosystem boundaries and stakeholders before designing open-data participation. Protect transferred financial data with strong transport controls and verified endpoints. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Data sharing depends on controlled access and permission boundaries across participants. |
| Recommendation — Define and enforce access rules for each data-sharing relationship. | ||
| GDPR | Art. 25 — Data protection by design and by default | Interoperable data sharing must embed privacy and portability into the design. |
| Recommendation — Build portability and consent handling into the data-sharing design from the start. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Ecosystem-wide data sharing relies on trustworthy identity and authentication between parties. |
| Recommendation — Use strong federation and authentication assurance for participating services. | ||
Practitioner Guidance
What to prioritise: Treat the gap between bank openness and ecosystem openness as a market-structure problem, not a single integration issue. The right test is whether the consumer can produce a materially better outcome from the combined dataset, not whether one API is available.
What to verify: Check whether the limitation is technical, commercial, or regulatory. If the blocker is upstream data holder participation, interface standardisation, or permission portability, then individual bank connectivity will only deliver partial value.
Practitioner takeaway: Open access creates value only when the surrounding data environment is interoperable enough to turn isolated permission into usable consumer insight.
Related resources from NHI Mgmt Group
- What breaks when customers and third parties can access bank data without robust authentication controls?
- Why is it important to integrate identity and data governance?
- What breaks when adaptive access control is deployed without good identity data?
- What breaks when cost control is built only on invoice data?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org