Introduction:
The CDR opportunity
The Consumer Data Right (CDR) is reshaping how Australians control, access, and share their data. For product managers, this is a significant opportunity to build innovative services, enhance customer experiences, and gain a competitive edge. But moving from the concept of open banking to a successful implementation requires a clear, strategic plan.
“The business case has shifted from ‘why change’ to ‘how soon’,” Jack Morgan, Director of Policy at FinTech Australia, stated at the recent CDR Symposium hosted by SISS Data Services.
CDR adoption is accelerating
- Over 530,000 Australians were actively using Open Banking products as of late 2024 (source: Fintech Australia)
- Screen scraping is becoming increasingly unreliable as banks implement multi-factor authentication and consumers grow more concerned about sharing their credentials
Why a 90-day plan?
This guide is designed for product managers and leaders in fintech, accounting software, and financial services considering their move to CDR. The structured 90-day action plan will help you navigate the complexities of compliance, technology, and strategy. The timeframe allows for thorough investigation and decision-making without losing momentum. Before you begin, ensure clarity on your business objectives and how customer data fits into your current product strategy.
The First 30 Days: Discovery and Strategy
The initial month is all about foundational work. Your goal is to define the “why” and “how” of your CDR journey, ensuring every subsequent step is aligned with a clear purpose.
Understand the customer problem
Your CDR strategy must start and end with the customer. What problem are you trying to solve? Is it streamlining loan applications, providing smarter budgeting tools, or simplifying bookkeeping for small businesses? Don’t just focus on current issues; consider future and adjacent problems your customers might face. A successful CDR implementation isn’t just about accessing data; it’s about using that data to deliver real, tangible value.
Evaluate CDR access models
There isn’t a one-size-fits-all approach to CDR. You need to choose the model that best fits your business reality, considering compliance burden, user experience and cost. At the recent CDR Symposium, Daniel Knight, partner at K&L Gates, outlined several key models and their pros and cons:
- Accredited Data Recipient (ADR): This model offers the most control over the user experience and data flow, but it also carries the highest compliance and security overhead. ADRs may choose to use the CDR technology of another ADR as their Outsourced Service Provider (OSP), to save on time and infrastructure investment.
- CDR Representative: You can partner with an existing ADR, who takes on the compliance burden. This is a faster route to market but offers less control over the branding and user journey than being an ADR.
- Sponsorship Model: Similar to the CDR representative model, this involves being sponsored into the ecosystem by an ADR.
- Business Consumer Disclosure (BCDC): A more flexible model for B2B use cases, allowing data to be shared outside the strict CDR regime, subject to general privacy laws and only applicable for ABN holders.
Your choice will impact everything from budget to the customer’s consent journey. Analyse the trade-offs between control, speed to market, and resource allocation.
Consult legal and technical experts
During this first month, engage your legal and technical advisors. Legal counsel is essential to understand your rights, responsibilities and liabilities under the various CDR models. On the technical side, start assessing what is required to integrate with CDR APIs. Focus on data quality, completeness and the support you’ll need.
Day 31-60: Evaluation and due diligence
With a strategic foundation in place, the second month is for deep-dive evaluation and selecting the right partners to bring your product roadmap to life.
Select and investigate partners
If you decide against becoming a full ADR, or you’ve chosen the ADR path and want to partner with an outsourced service provider (OSP), choosing the right technology partner is the most critical decision you’ll make. A good partner does more than provide an API; they provide the technology, monitoring, data validation and domain expertise to make your transformation possible.
When vetting potential partners, consider their:
- Track record: Who are their existing clients? How long have they been operating in the open banking space?
- Security and compliance: Are they an ADR? Are they ISO 27001 certified? A strong security posture is non-negotiable.
- User journey: How seamless is their consent flow? A clunky or confusing process can lead to high customer drop-off rates.
- Data quality: Do they validate and filter data, or just pass through what’s received from the bank or data holder?
Test the consent journey
The consent process is a cornerstone of the CDR. As outlined at the CDR Symposium by Kate Brown, Product Manager at SISS Data Services, consent must be “voluntary, expressed, informed, specific, time-limited and easily withdrawn.” The user experience during this journey is paramount.
Work with friendly partners to test their consent flow in a sandbox environment. Experience it from your customer’s perspective. Is it clear who they are sharing data with and why? Is it easy to manage and revoke consent? A poor consent journey undermines trust and can cripple your adoption rates.
Conduct a technical deep dive
Your technical team should use this period for hands-on evaluation. Get sandbox access and start testing the APIs. Assess the data quality, the structure of the data feeds and the completeness of the information available. Evaluate the partner’s support model and their service level agreements (SLAs). Understand who is responsible for what if an issue arises.
Day 61-90: Proposal and finalisation
The final 30 days are about synthesising your findings into a comprehensive plan and securing the internal buy-in to move forward.
Prepare a Comprehensive Proposal
You now have the information needed to build a robust business case. Your proposal to leadership should be well-researched and compelling, covering:
- The “Why”: Reiterate the customer problem you are solving and the business opportunity.
- The “How”: Detail the recommended CDR model and partner, justifying your choice.
- Customer impact: Explain how this will improve your product and the overall customer experience.
- Costs and ROI: Present a clear breakdown of implementation costs, ongoing fees and the expected return on investment.
- Compliance and risk: Outline how you will manage compliance and mitigate potential risks.
- Rollout plan: Provide a high-level timeline for implementation, from development to market launch.
Address potential challenges
Be prepared to address potential roadblocks. Your internal capability and priorities can cause you to stumble. Acknowledge that the CDR is not static; it’s an evolving framework. There will be iterative change, and you will need a team that is resourced to manage these ongoing updates. Plan for this by allocating resources for continuous compliance and development.
Finalise partnerships
Once you have leadership approval, move to finalise contracts with your chosen legal and technology partners. Ensure all terms, responsibilities and service levels are clearly documented.
Day 91 and beyond: implementation and innovation
Congratulations, you have a plan. Day 91 is where the work of implementation begins. You’ve moved from strategy to action. You have a clear path forward, chosen partners and organisational alignment.
This is not the end of the journey, but the beginning of a new chapter in your product roadmap. Your 90-day plan has equipped you to build with customer experience at the centre, transforming your product and your relationship with customers.
How SISS Data Services can help
Navigating the CDR landscape can be complex, but you don’t have to do it alone.
At SISS Data Services, Australia’s leading independent open banking platform, we help you understand evolving customer needs, select the right CDR model for your business and build solutions with a positive customer experience. For over a decade, we have earned the trust of Australia’s major banks and leading software platforms to securely
Enquire here to find out how SISS can support you on your CDR journey.


