Open Banking in Australia. The Definitive Guide
Open banking gives Australian businesses and consumers the right to share their bank transaction data with accredited third parties via secure APIs that are regulated under the Consumer Data Right (CDR).This guide brings clarity on how access works, and where SISS Data Services fits in.
CDR Accredited Data Recipient | ISO 27001 Certified
Data holder brands sharing via open banking
CDR Representatives and accredited data recipients
Active CDR authorisations live
Historical transaction data available via CDR
Table of Contents
Trusted by banks, software platforms and their customers for 15+ years.















What is Open Banking
Open Banking is a federal government initiative that gives Australian consumers and businesses the right to share their bank account data - transactions, balances, account details with any accredited third party they choose. The data is shared via secure and standardised APIs only after explicit consent, which can be revoked at any time.
Before Open Banking arrived, your customers' financial data was locked locked inside their bank. If you wanted to assess a customer's cash flow for a lending decision, or wanted your accounting software to automatically reconcile their transactions, someone had to manually download a CSV, email a statement, or hand over login credentials. Open Banking eliminates all of that.
In Australia, Open Banking is governed by the Consumer Data Right (CDR), a federal legislation administered by the ACCC.It mandates that every Australian bank, credit union and mutual make customer data available via standardised APIs to accredited recipients.
Note that banks require your customer's authorisation before they can share their data with accredited organisations specifically identified by them, with purpose and duration also clearly stated. Nothing is disclosed without their consent.
How it works
How open banking data flows
Four steps, from consent to clean data in your platform. No passwords change hands at any point.
Consumer or business gives digital consent
No paper forms, no passwords shared. The consent specifies purpose, data type, and duration.
Bank verifies identity before authorising
The consumer authenticates through their bank’s interface. The bank confirms exactly what data will be shared.
Data is retrieved via CDR API
The Accredited Data Recipient (ADR) retrieves transactions, balance, and account data using standardised APIs.
Data is delivered to your platform
Your software receives clean, structured data that is ready for reconciliation, credit assessment, or financial analysis.
Technical overview
How open banking APIs work
Open banking uses RESTful APIs that conform to the Data Standards Body (DSB) within Treasury, which is a uniform technical specification for how data is formatted, requested, and secured across all participating banks. This standardisation makes it practical for platforms to integrate just once and access data from any ADI.
What data is available via open banking
Customer & Account data
- Account names and numbers
- Contact name and details (email, phone, address)
- Business details, including ABN
- Account type and status
- BSB details
- Credit limits
- Loan details
- Product fees, rates and features
- Scheduled payments
- Saved payees / list of payees
Transaction data
- Transaction description
- Merchant name and merchant code
- Amount and currency
- Date and reference
- Transaction type
- Fees and interest charged, where recorded as individual account transactions
- Transaction history going back to a maximum of two years
Account types covered
Unlike direct bank feeds, which are limited to transaction accounts at select banks, open banking via CDR covers:
Transaction and savings accounts
Credit and charge cards
Home loans and personal loans
Business finance accounts
Term deposits and investment accounts
Open banking versus screen scraping
As CDR coverage expands, banks are gradually shutting the door on screen scraping and the government is moving towards a formal ban. Open Banking is the long-term financial data infrastructure of choice.
| Feature | Open banking (CDR) | Screen scraping |
|---|---|---|
| Password shared | Never | Yes |
| Bank-sanctioned | Yes | No |
| Regulated & auditable | Yes | No |
| Revocable consent | Yes | No |
| Standardised data format | Yes | No |
Regulatory framework
Consumer Data Right & what it means for your business
The CDR is an Australian federal legislation that mandates open banking. It is regulated by ACCC & OAIC. The technical standards are set by Data Standards Australia. Understanding the CDR is essential for any business using or planning to use open banking data.
Data holders
Banks and other Authorised Deposit-taking Institutions (ADIs). They must make customer data available via CDR APIs whenever a customer gives consent. All four major banks plus 90+ other institutions participate.
Data recipients
Businesses accredited by the ACCC to receive open banking data. ADRs like ACSISS hold full accreditation and can receive raw CDR data. They may be principal recipients or sponsors for other organisations.
CDR consumers
Consumers and businesses -the individuals and entities whose data is being shared. They control who accesses their data, for what purpose, and for how long, and can revoke consent at any time.
Key CDR obligations to know
Consent must be explicit and current
Consumers must actively grant consent, and this consent lasts for a maximum of 12 months, after which consent has to be renewed.
Data can only be used for the stated purpose
Open banking data retrieved for credit assessment cannot be repurposed for marketing or other uses. Purpose is bound to consent.
Deletion on request is mandatory
When a consumer revokes consent, the ADR must delete all CDR data collected under that consent on request. SISS manages this on behalf of platform customers.
Security standards are mandatory
ADRs must maintain security standards like ISO 27001 certification, and they must comply with FAPI security profiles.
SISS Data Services is ISO 27001 certified and all data is hosted on Microsoft Azure in Australia.
CDR expansion
What is changing for non-bank lenders
CDR’s rollout isn’t limited to the banks anymore. From 13 July 2026, non-bank lenders – including BNPL and business card providers – are required to start publishing product data under the CDR. Verified consumer data sharing follows: from 9 November 2026 for the largest providers and 10 May 2027 for the rest.
This matters because non-bank credit has become a genuine share of how small businesses fund cash flow. RBA data shows non-banks’ share of smaller business lending reached 26.4% in August 2025: more than double what it was a few years earlier. Separately, a 2025 American Express-commissioned survey of 510 Australian small business owners found 11% rely on the flexible payment features built into their cards.
None of that activity is currently visible through CDR. Today, lenders assessing this exposure are stuck with uploaded PDF statements which are easy to alter, or screen scraping, which is increasingly unreliable and discouraged by banks.
As the non-bank lender rollout lands, that gap closes. With a customer’s consent, lenders will be able to pull verified income, spending, and existing liabilities from sources that sit entirely outside the original CDR data, closing a blind spot that’s grown alongside the non-bank lending market itself.
Full visibility into a borrower’s non-bank credit footprint arrives progressively over the next 12 months. For lending platforms, it’s worth getting data pipelines ready ahead of that timeline rather than reacting once it lands.
Getting access
CDR access models. Choose the right one for you
The government has created multiple access models so that organisations of different sizes and risk profiles can participate in open banking without having to obtain full ADR accreditation. Most software platforms and fintechs work through an ADR like ACSISS rather than getting themselves accredited.
Unrestricted ADR
Full, direct access to CDR data. An unrestricted ADR can receive raw data, act as a principal and sponsor affiliates. This requires ACCC registration, and significant compliance overhead.
SISS Data Services is an unrestricted ADR.
Business Consumer Disclosure Consent (BCDC)
No formal accreditation needed and shielded from compliance burdens. Available where the underlying customer is a CDR business consumer. Suited to B2B software platforms.
CDR Representative
No formal accreditation needed. Using an ADR as your CDR representative principal, you access CDR data under their accreditation – the fastest path to market. The ADR holds data responsibility. This does not necessarily remove compliance obligations or risk for your business.
Use Consent
A data sharing method that enables both individual and business customers to share their bank data with third-party fintechs, without those fintechs needing to be Accredited Data Recipients (ADRs) and without requiring Representative or Sponsorship arrangements with an ADR. In the case of a business, no ABN is required. The key distinction: the customer collects their own data via an ADR like SISS and then elects to share it with a fintech of their choosing.
Sponsored Affiliate
A formal arrangement with an ADR sponsor, requiring your own sponsored-level accreditation through a lighter, self-assessed process. Data access is more limited than an unrestricted ADR – you can’t collect directly from data holders – but the evidentiary burden and cost are lower. Suited to larger organisations wanting some regulatory standing.
CDR Insights Model
Non-accredited parties receive derived insights (income, expenses, account balances) rather than raw data. No formal accreditation is required. Suited for verification workflows where raw transaction data isn’t needed.
Outsourced service provider (OSP)
No accreditation needed, but you operate under a formal CDR outsourcing arrangement with an unrestricted ADR. This pathway covers two distinct functions. In the first, the OSP performs a specific task on the ADR’s behalf, such as data enrichment, using CDR data the ADR discloses to it. In the second, the OSP acts as the technology partner or “rails” for a larger unrestricted ADR, while that ADR retains ownership of its own accreditation, customers and data. In both cases, the ADR carries the obligations and remains fully liable for how the data is handled downstream. Suited to platforms wanting deeper, white-labelled data handling without taking on accreditation risk themselves.
For most software platforms and fintechs it won’t be necessary to pursue a full ADR accreditation — a partner model will likely be a better fit. SISS’s preference is for the Business Consumer Disclosure Consent (BCDC) and/or the Use Consent model, which insulates businesses from compliance restrictions and CDR-related risk. CDR Representative or sponsorship models might seem appealing at first glance, however there is an associated compliance risk that might not be obvious at first sight.
Get to know the difference
Bank Feed Type Comparison
Understand the difference between CDR Bank Feeds and Direct Bank feeds
Open Banking (CDR) feeds
Direct Feeds
Open Banking (CDR) feeds
Direct Feeds
Why ACSISS combines both
No single connection method covers every scenario. Open Banking misses long-running integration where consent renewal creates friction; direct feeds miss smaller banks and broader account types. ACSISS offers both. This gives your platform the most complete, gap-free bank data in Australia with redundancy built in, if you so choose.
Applications
Who uses open banking, and for what
Open banking data has commercial value wherever real-time and accurate financial data reduces decision-making time, improves the quality of the decision and reduces friction. In Australia, the most active use cases are in lending, accounting, and ERP – all areas SISS serves.
Lending platforms
Lenders use open banking transaction data for income verification, expense categorisation, and ongoing portfolio monitoring. Real-time data access replaces slow manual document collection. ACSISS Data Enrich and ACSISS Credit Monitor are built specifically for this workflow.
Accounting platforms
Accounting software uses open banking APIs to automatically pull transaction data into the ledger. It thus eliminates manual CSV uploads, reduces errors, and accelerates month-end close. Partners including Intuit QuickBooks, Reckon, and Wiise use ACSISS for this.
ERP systems
Enterprise platforms use open banking feeds to automate bank reconciliation, to streamline accounts payable and receivable, and to eliminate manual data handling. ACSISS Connect provides ready-to-use integrations for Microsoft Business Central, SAP Business One, SYSPRO, and Jiwa 7.
SISS and open banking
Australia's most complete open banking infrastructure
SISS Data Services (ACSISS product range) is a CDR accredited Data Recipient with upwards of 15 years of bank data experience. Unlike providers that launched when the CDR was introduced, SISS had built bank data infrastructure even before open banking existed. This brought together the reliability and data quality of a mature operator and the regulatory access of a CDR accreditor.
ACSISS Platform
Bank data feeds via open banking and direct connections for accounting, lending, and B2B platforms. REST APIs with free 90-day sandbox access.
ACSISS Connect
Native open banking feeds for Business Central, SAP Business One, SYSPRO, and Jiwa 7. No custom development required.
ACSISS Lending Analytics
Transaction enrichment, categorisation, and periodic SME risk scoring for credit decisioning, onboarding, and portfolio monitoring.
Secure & compliant financial data access
Security and compliance
Is open banking safe?
Open Banking in Australia is one of the most regulated data-sharing frameworks in the world. Because it is legislated – not just industry-agreed – the security, consent, and liability requirements are mandatory for every participant.
No password sharing
Consumers authenticate directly with their bank. Credentials are never shared with or stored by the ADR.
Revocable at any time
Consumers can revoke consent and request data deletion at any time through their bank or directly via the ADR’s consent dashboard.
ACCC-registered participants only
Only ACCC-accredited organisations can receive CDR data. Accreditation requires security audits, privacy assessments, and ongoing compliance reporting.
Hosted in Australia on Microsoft Azure
SISS processes and stores all data on Microsoft Azure infrastructure domiciled in Australia. This data never leaves Australian jurisdiction.
SISS compliance credentials
CDR Accredited Data Recipient
Accredited by the ACCC under the Consumer Data Right. Holds the highest level of CDR accreditation – unrestricted ADR status.
ISO 27001 Certified
International information security management standard. Independently audited and certified, covering data handling, access controls, and incident response.
Microsoft Azure - Australia region
All data processed and stored in Australian Azure data centres. Meets Australian data sovereignty requirements for financial data.
Over 15 years of bank data operations
Operating since before Open Banking existed. Trusted by Commonwealth Bank, ANZ, Westpac, and Macquarie as a data infrastructure partner.
Frequently asked questions
What is open banking in Australia?
Open Banking in Australia is a government-legislated framework under the Consumer Data Right (CDR) that allows consumers and businesses to securely share their bank transaction data with accredited third parties via standardised APIs. It's regulated jointly by the ACCC (accreditation and compliance) and the OAIC (privacy safeguards), and it gives the CDR consumer full control over who accesses their data and for how long.
What is the difference between Open Banking and the Consumer Data Right?
The Consumer Data Right (CDR) is the legislation, while Open Banking is its application in the banking sector. CDR is an economy-wide reform. It was first applied to banking, then to energy, and then to telecommunications. When people say ‘Open Banking in Australia’, they mean the CDR as it applies to banks and financial data.
Which banks support Open Banking in Australia?
All Authorised Deposit-taking Institutions (ADIs) in Australia are required to participate in the CDR framework. This includes the four major banks (ANZ, Commonwealth Bank, NAB, Westpac) and over 100 other brands including credit unions, building societies, and regional banks. The full list is maintained by the ACCC on the CDR website.
What is a CDR Accredited Data Recipient? Why does it matter?
A CDR Accredited Data Recipient (ADR) is an organisation formally accredited by the ACCC to receive consumer data under the Consumer Data Right. Only ADRs can directly access open banking data from banks. SISS Data Services (SISS) holds full ADR accreditation. This is why our platform customers can access Open Banking data through us without needing their own ACCC registration. For most platforms, working with an ADR through a partner model is significantly faster and cheaper than self-accreditation.
How does Open Banking differ from screen scraping?
Screen scraping requires consumers to share their bank login credentials with a third party, which then logs in and scrapes data from the banking interface. It is not sanctioned by banks, it is unregulated, and carries security risks. Open Banking via the CDR uses bank-sanctioned APIs. Therefore, no passwords are shared, consent is explicit and revocable, and the data is standardised across all institutions.
For how long does Open Banking consent last?
Under the CDR rules, Open Banking consent can last for a maximum of 12 months before renewal of consent is required. After 12 months, the consumer must actively reauthorise data sharing. This differs from direct bank feeds, which can operate on ongoing consent without an annual re-authorisation requirement.
Can businesses use Open Banking, or is it just for consumers?
It’s for both. The CDR introduced ‘CDR Business Consumer’ provisions for entities holding an active ABN operating a B2B business. Business customers can give consent to share their transaction data with accredited third parties — including accountants, lenders, and software platforms — under what is called a ‘Business Consumer Disclosure Consent’. SISS supports both consumer and business consent journeys.
How quickly can my platform go live with Open Banking via SISS?
SISS offers a 90-day free sandbox access so you can build and test integrations before going live. Our ACSISS Platform product is typically is live in weeks rather than months. You simply integrate the SISS API once and have immediate access to all participating banks. ACSISS Connect is up and running almost instantly after installation.
Is Open Banking data stored in Australia?
Yes - for SISS customers. All data processed and stored by SISS Data Services is hosted on Microsoft Azure infrastructure in Australian data centres. It does not leave Australian jurisdiction and thus meets both CDR requirements and Australian data sovereignty expectations for financial data.
Does Open Banking cover non-bank lenders and BNPL providers?
Not fully yet, but that's changing. From 13 July 2026, non-bank lenders, including BNPL and business card providers, are required to start publishing product data under the CDR. Verified consumer data sharing follows on a phased timeline: from 9 November 2026 for the largest providers and 10 May 2027 for the rest, with full rollout completing by September 2027. Until then, non-bank credit activity remains largely invisible to CDR data.
Related guides and resources
What does "accounting-grade" bank data mean?
Why data quality matters, and what separates accounting-grade from standard transaction data.
CDR reforms that could unlock $1.2 billion a year
The policy changes that could dramatically expand the scope of open banking for Australian businesses.
ACSISS Platform - open banking API
Bank data feeds via open banking and direct connections, in a single REST API. 90-day free sandbox.
Open banking for lenders
How ACSISS Data Enrich and ACSISS Credit Monitor use open banking data for credit decisioning and portfolio monitoring.
Open banking bank feeds for ERP
Pre-built integrations for Business Central, SAP Business One, SYSPRO, and Jiwa 7.
Developer documentation
API reference, getting-started guides, and sandbox access for ACSISS open banking APIs.
Now that you are ready to build on Open Banking
Talk to our team about the right access model for your platform.