Most of your users’ financial accounts are already connected to third-party apps, without your institution’s visibility or control. Here’s how open banking capabilities help you lead that experience before regulators require it.
By Brian Abele, VP of Product Management
Brian Abele has been a product management leader in the fintech market for over 20 years. He has a key leadership role in the expansion of Lumin’s digital banking solution into new markets while helping transform the product team’s operational model in line with company growth.
What are your users sharing, and with whom?
The apps they use every day, like Venmo, TurboTax, Rocket Money, and QuickBooks, are actively pulling data from their financial accounts. They set it up once, often years ago, and have not thought about it since. Or perhaps they set up an app and used it, but got little value from it. Most could not tell you which apps have access, what data those apps can see, or how to revoke that access if they wanted to.
Financial institutions are never really part of that conversation. Open banking consent capabilities are built specifically to change that, giving credit unions and community/regional banks the tools to show members what’s connected, and the controls to help them manage it.
How does open banking data sharing actually work?
Data aggregation is not new. For two decades, the way it worked was straightforward and quietly alarming: when a user linked their bank account to an outside app, they handed that app their online banking username and password. The app logged in on their behalf, scraped the data it needed, and stored those credentials indefinitely. The bank had no visibility. The user had no control. And the exposure, should anything go wrong, sat entirely with the user.
The industry has spent years building a better path. The Financial Data Exchange standard, FDX, replaces credential sharing with a secure, permissioned API. Instead of handing over a password, a user authorizes a specific app to access specific data, through their institution’s own authentication flow, for a defined period of time, meaning no more stored passwords, invisible access, or guessing what was shared.
That shift is underway now. And it changes what is possible for the institutions that choose to lead it.
Why would members trust their institution with data access it doesn’t actively manage?
When a user connects an app to their account today, the financial institution is largely absent from that experience. The consent moment, the decision about what gets shared and with whom, happens somewhere else, in an app the FI did not build, through a flow the FI did not design, without any visibility into what was agreed to.
The result is a trust gap. Users assume their bank or credit union is watching out for them. In most cases, when it comes to third-party data access, no one is. They do not know which apps are connected. They do not know that, for example, their mortgage company has been pulling their transaction history since 2021. They do not know that the app they stopped using two years ago still has access.
Why is open banking an opportunity for credit unions and community/regional banks?
Large banks and fintechs are moving toward permissioned data sharing because they have to. Regulatory pressure, competitive dynamics, and the demands of a more sophisticated user base are all pointing in the same direction.
But for community banks, regional banks, and credit unions, this moment is different. These institutions were not built to extract value from user relationships. They were built to protect them. The consent experience, the moment where a user decides who gets access to their financial life, is a natural extension of that founding promise.
A large bank adding a connected apps dashboard is adding a feature. A community institution doing the same thing is expressing a value. That distinction will not be lost on the users who notice.
Section 1033, the federal rule pushing the industry toward standardized data sharing, is still being finalized. But the direction is clear: regulators want consumers to be able to see who has access to their financial data and revoke that access on demand. The institutions that build this experience before the rule lands will not just be compliant. They will already have the habit of trust.
Every month you run ungoverned AI is another month of audit exposure, breach surface, and user trust eroding in ways that won’t show up in engagement metrics until it’s already costly. The question to now ask is how far behind is your institution today, and how do you stop it?
What does leading the open banking consent experience look like?
Leading the consent experience does not require reinventing the digital banking relationship. It requires showing up in a moment where most institutions are currently absent. There are three capabilities every institution needs to own this experience.
1
Visibility
Users can see, at a glance, every app that has access to their account data, when that access was granted, and what the app can actually see. Not buried in a settings menu three screens deep; present, clear, and easy to find.
2
Control
Revoking or pausing access is a single action, not a process. The connected app has a more reliable, trusted route. The user does not have to change their password and inadvertently disconnect from every app at once; they have granular options. Users who value those external apps can share their information in a safe, unbreakable way.
3
Framing
The institution positions itself as the steward of that experience, not a passive participant in it. The language, the design, and the placement of these controls all communicate something: we are watching out for you. That message, delivered consistently at the right moment, compounds over time.
When should your institution act on open banking consent management?
For decades, the branch was where trust was built: face-to-face, in a physical space the institution owned and designed. Digital banking moved that relationship to an app. The consent experience is where it moves next.
The institutions that recognize this moment for what it is, not a compliance requirement, not a technology project, but a relationship opportunity, will earn something that cannot be mandated by regulation or replicated by a fintech: the genuine trust of users who feel seen, protected, and in control of their own financial lives.
That is the open banking opportunity that matters most. And it is available right now to the institutions willing to take it.
Frequently Asked Questions
What is open banking consent management?
Open banking consent management is the process by which a financial institution gives members visibility into which third-party applications have access to their account data, and the controls to grant, pause, or revoke that access. Under the FDX standard and emerging Section 1033 regulations, consent management is shifting from invisible credential sharing to explicit, permissioned API authorization that the institution actively manages.
What is FDX and why does it matter for credit unions and community/regional banks?
FDX (Financial Data Exchange) is the industry standard that replaces username/password credential sharing with a secure, permissioned API framework. For credit unions and community banks, FDX matters because it gives the institution visibility and control over which apps are accessing member data, and it positions the institution as an active participant in the consent experience rather than a passive bystander.
What is Section 1033 and what does it require?
Section 1033 of the Dodd-Frank Act is the federal rule directing financial institutions to provide consumers with access to their own financial data and to enable them to share that data with authorized third parties. The rule is still being finalized, but it is expected to require institutions to support permissioned data sharing and give consumers the ability to see and revoke third-party access on demand.
How can members see which apps are connected to their financial accounts?
With Lumin Digital’s open banking consent capabilities, members can access a connected apps dashboard directly within their digital banking experience. The dashboard shows every authorized third-party app, the date access was granted, the specific data types each app can access, and a one-tap option to revoke or pause access.
What is the difference between credential sharing and permissioned API access in open banking?
Credential sharing (the legacy approach) requires users to give third-party apps their banking username and password, which the app stores and uses to log in on the user’s behalf. The institution has no visibility and the user has no way to revoke access other than changing their password. Permissioned API access (the FDX approach) replaces this with a secure token: the user explicitly authorizes a specific app to access specific data types for a defined period, through the institution’s own authentication flow. No stored passwords, no invisible access, and full control for both the member and the institution.

Brian Abele
VP of Product Management
About Brian Abele
Brian Abele leads the product management team at Lumin Digital. He has been a product management leader in the fintech market for over 20 years, leading domestic and global teams on the build out and delivery of digital banking and origination platforms at industry leaders such as Q2, Fiserv and Temenos. He has played a key leadership role in the expansion of the Lumin digital banking solution into new markets while helping transform the product team’s operational model in line with company growth. His team plays an instrumental role in meeting both client needs and market demands with best in class solutions delivered at scale.

