Insights

The Necessary Foundations for Consumer-Directed Finance in Canada — Lessons from Global Markets

The Necessary Foundations for Consumer-Directed Finance in Canada — Lessons from Global Markets image
Structure

Canada does not need to guess how consumer-directed finance plays out. It can watch.

That is the country’s genuine advantage as it builds its Consumer-Driven Banking framework: every other major open banking market has already run the experiment, and each has left a different lesson Canada can improve on. The UK took over six years to finish what it launched in 2018. Australia’s banking industry spent an estimated AU$1.5 billion on the Consumer Data Right and ended 2023 with just 0.31% of bank customers actually using it. Brazil moved fast: by August 2025 its open finance ecosystem connected 65 million accounts, yet a 2024 survey found 55% of Brazilians have never even heard of open finance. And Mexico shows what happens when high ambitions aren’t followed through: its 2018 Fintech Law promised open APIs across three tiers of data, but the transactional-data tier, the one that would actually have been commercially transformative, has never had its secondary regulation published, more than six years past the statutory deadline.

Canada, by contrast, is not trying to be first, but does want to get things right. The Consumer-Driven Banking Act initially received Royal Assent in June 2024 via Bill C-69, before being substantially expanded and re-enacted through Bill C-15 in March 2026 to complete the legislative framework. With draft regulations open to public comment through August 2026, Canada now stands at a crucial juncture where legislative momentum meets global learnings.

This article sets out what those foundations are, the lessons learned from how markets build them, and how Canada can sequence its own build from here.

Why Foundations Matter More Than Speed

It is tempting to treat open banking as a race. Governments like to announce timelines; banks like to know when compliance is due. But speed and durability are different things, and conflating them is exactly the mistake several markets have already made.

A rushed ecosystem tends to produce a narrow, compliance-only build: the minimum API surface required by law, bolted onto existing infrastructure, with commercial incentives and consumer trust treated as someone else’s problem to solve later. Australia’s own numbers show where that leads. The ABA/Accenture Consumer Data Right Strategic Review, found that 97% of the AU$1.5 billion the industry spent on CDR since 2018 went on compliance, with only 3.5% (major banks) and 0.5% (mid-tier banks) spent on innovation. More than half of all data-sharing arrangements were discontinued or allowed to lapse during 2023 alone. ABA chief executive Anna Bligh put it plainly: “It’s time to go back to the drawing board.”

A well-founded ecosystem does the opposite. It gets the regulatory mandate, the technical standard, the accreditation and liability model, the commercial incentives, and consumer trust design right from the outset, so each layer reinforces the others instead of undermining them. That takes longer to specify. It does not take longer to deliver, and it avoids the multi-year course-correction that Mexico’s Ley Fintech is still waiting on and that Australia is now openly discussing.

Canada’s later start means it does not have to choose between speed and rigour. It can build once, properly, using the mistakes of five other markets as a specification document, getting these foundations right from the start. 

Foundation 1: A Clear and Stable Regulatory Mandate

Banks do not typically invest ahead of legislative certainty. The UK only moved once the CMA’s Retail Banking Market Investigation issued its final report in August 2016 and the resulting 2017 Order gave the CMA9 a binding mandate. Australia’s rollout followed the same pattern: the Consumer Data Right legislation passed in 2019, with major banks live by July 2020 and the rest of the sector by July 2021.

Canada has now cleared that bar. Oversight of the new CDBA sits with the Bank of Canada rather than the FCAC, a deliberate move to “align with existing oversight for the Retail Payment Activities Act”. That consolidation matters: it puts consumer-directed finance under the same regulator already supervising payments infrastructure, rather than splitting oversight across agencies.

The harder question is how prescriptive the mandate should be. Too rigid, and it cannot adapt as the ecosystem matures; too principles-based, and banks will interpret their obligations as narrowly as possible, which is precisely the behaviour that produced Australia’s compliance-only build. Canada’s federal structure adds a further layer: the new CDBA allows the Minister of Finance to designate a provincial regulator for security, privacy, liability and complaints handling in that province, while accreditation and enforcement remain federal. That is a workable division of labour, but only if the handoffs between federal and provincial oversight are specified precisely. Quebec’s Law 25 already grants a broader, self-executing data-portability right, and the new CDBA borrows Quebec’s “gross fault” standard alongside the common-law “gross negligence” test for liability. Getting that alignment wrong, through scope creep, unclear liability allocation, or enforcement that lacks teeth, is how mandates lose credibility with the institutions meant to build against them.

Foundation 2: A Fit-For-Purpose Technical Standard

Canada faces a genuine open question here, and it is the first of the two that will determine whether this framework succeeds: no technical standard has yet been formally designated. Budget 2024 and Budget 2025 both describe only a process for the Minister of Finance to designate a standards body, not a decision.

FDX is the industry-favoured candidate. The FDX Canada Working Group, launched in July 2020 with 31 founding members including Ozone API and originally co-chaired by Interac and TD Bank. The CFPB stayed and reopened parts of the Section 1033 rule in 2025–2026, making US compliance timelines fluid. FDX remains the leading contender in Canada, though formal designation by the Canadian Minister of Finance remains pending. But as Fintech Futures reported in March 2026, quoting FDATA’s Steve Boms: “the starting gun really goes off once the technical standard for the APIs is known.” Until formal designation happens, adoption of FDX in Canada should be treated as likely, not settled.

The comparative picture across markets shows there is no single right answer, only trade-offs. Berlin Group’s NextGenPSD2 is voluntary and industry-driven, yet adopted by more than 75% of European banks. The UK Open Banking Standard was mandatory, but only for the CMA9; everyone else adopted it voluntarily. Australia’s CDR Standard is legally mandated and, uniquely, was designed to span banking, energy and telecoms, not just financial services, by design, though the telecoms sector’s rollout has been paused and has not gone live. What all four have in common is that they are API-based and reject screen-scraping outright, which matters directly for Canada: an estimated 9 million Canadians currently rely on screen-scraping, and the new CDBA introduces a statutory ban on the practice.

The practical lesson is that Canada does not need to build a bespoke standard from scratch, and probably should not. What it needs is to build on an existing standard and ensure it supports the specific Canadian sovereign requirements. If FDX is the chosen route then there will need to be a clear plan to build on it in a way that is right for Canada. That includes the addition of payment initiation in future phases as well as ensuring clear and concrete decisions about the security profile. . . FAPI (Financial-grade API) has become the de facto security profile across many markets including the UK, Brazil, Australia, Saudi Arabia and the UAE. The FDX standard currently leaves a wide range of optionality when it comes to the security profile. Making a clear choice is the best route to avoid  the fragmentation that happens when each bank makes their own choices and the systemic risk of different approaches to security. A standard without a firm security baseline is an invitation for exactly the kind of incident that erodes public trust before the ecosystem has had a chance to earn it.

Foundation 3: A Trusted Accreditation and Liability Framework

The new CDBA introduces an accredited third-party provider regime, with consumer liability capped except in cases of gross negligence, or “gross fault” in Quebec. That is a solid starting principle. The design choice still ahead is how accreditation itself is structured, and here the global models differ.

The UK’s approach is effectively single-tier: any AISP or PISP must first gain FCA authorisation, to be able to operate as third parties within the ecosystem. It is simple, but it offers only one door in. Australia built a more graduated model: six distinct accreditation pathways, from Unrestricted through Streamlined for ADIs, CDR Representative arrangements from October 2021, Sponsored accreditation from February 2022, Trusted Adviser, and insights-disclosure models. That ladder lets smaller players participate without clearing the same bar as a major bank, though it has not, on its own, solved Australia’s adoption problem. Brazil sits at the other extreme: accreditation is effectively single-gate, a BCB operating licence plus registration in the Diretório de Participantes, with governance now sitting under a private-sector body, the Associação Open Finance, since January 2025.

Canada’s new penalty structure signals real enforcement intent, with criminal fines up to CAD 5 million and administrative monetary penalties up to CAD 10 million for entities and CAD 1 million for individuals. The design question is whether the accreditation model needs Australia’s full tiered complexity from day one, or whether a minimum viable framework, a single clear gate with defined liability allocation between banks, third-party providers and consumers, is sufficient to launch, with graduated tiers added once real usage patterns emerge. Given the multi-year timelines every other market has needed just to get its first accreditation model working, a minimum viable framework that can be adapted is the more realistic starting point.

Foundation 4: Commercial Incentives for Banks

This is the foundation most markets have left unresolved, and it is the second open question that will shape whether Canada’s framework actually gets used.

A mandate creates obligation, rather than enthusiasm. The UK’s own experience shows the gap between the two: a NatWest-commissioned report from July 2023 found only 10% of UK adults had used open banking, against more than 60% for mobile banking, with NatWest’s Stephen Wright noting that “unless the regulator says to do something, nothing happens.” Lack of commercial incentive was cited as a core obstacle. Since then usage figures have continued to increase with 2026 figures citing that it is now closer to 30% to 35% of UK adults using open banking, whilst 75% of UK adults have adopted mobile banking. 

The UK has since tried to design an answer. The Joint Regulatory Oversight Committee, the FCA and PSR’s joint open banking body, set out principles for commercial frameworks for premium APIs in June 2023, allowing banks to charge for functionality that goes beyond the CMA-mandated scope, and UK Finance published Commercial VRP Model Clauses in April 2024. This is a regulatory permission structure, not yet a documented commercial rollout. This laid the foundations for an industry led scheme for Commercial Variable Recurring Payments. It is still at the early stages of launch but this should create the path to deliver a commercially sustainable account to account payment model. It has been many years in the making however. The UAE took an alternative path: it designed the liability framework and a centralised API hub, run by a central operator, into its regulation from the outset, then published its Commercial and Pricing Model within its first year of implementation, a markedly faster sequence than the years of industry dialogue the UK’s premium-API framework has taken. JPMorgan Chase’s move in 2025 shows what “settled later” can look like in an unstructured market. In July 2025, after revealing its systems handled 1.89 billion monthly API calls, with only 13% stemming from direct consumer actions, JPMorgan announced plans to charge fintech data aggregators for API access. The pushback from industry groups was immediate: FDATA North America’s Steve Boms called the fees “a cynical attempt to take advantage of regulatory uncertainty,” while the Financial Technology Association’s Penny Lee argued they were “designed to crush competition”.

By September 2025, JPMorgan signed a landmark bilateral agreement with Plaid, establishing paid data access terms that set a precedent for the US open banking ecosystem. By November 2025, the bank had finalized revised, lower-priced contracts covering more than 95% of its system data pulls across aggregators like Plaid, Yodlee, Morningstar, and Akoya. However, this resolution only came after months of public dispute and unilateral leverage.

That is not just a US corporate spat. It is a signal that where no commercial framework exists, the largest incumbent will eventually set the terms unilaterally, and the resulting fight becomes public, adversarial and slow to resolve. Canada has the chance to design the commercial model from the start, as part of the same framework that sets liability and accreditation, rather than leaving banks and fintechs to negotiate it after the fact. This is precisely the kind of design problem Ozone API’s own work sits inside: building infrastructure that lets institutions turn compliance obligations into monetisable, premium API products from day one, rather than treating commercial value as an afterthought bolted on years later.

Foundation 5: Consumer Trust and Inclusion by Design

None of the foregoing matters if consumers do not use the system, or do not understand what they are consenting to.

Neither the UK nor Australia solved this by accident, and neither has fully solved it at all. Both markets built formal consumer representation into governance from early on: OBIE’s Independent Consumer and SME Representatives published “Consumer Priorities for Open Banking” in June 2019, and the UK’s 2021 Future Entity Board proposal specified one dedicated consumer seat. Australia’s Consumer Policy Research Centre made a formal submission to Treasury in October 2021 specifically on consumer vulnerability in CDR design.

A lot of work remains even with that input. Adoption figures early into the journey showed that the UK’s 10% usage figure and Australia’s 0.31% figure both pointed to the same conclusion: legal permission to share data does not translate into consumer confidence, and consent screens that are technically compliant are not automatically ones people understand. 

Canada should treat consumer education and genuinely informed consent UX as a foundation to design deliberately, not a feature to assume will emerge from adoption. That means building consumer and financial-inclusion advocacy into governance structures from the start, standardising consent language and flows across institutions rather than leaving each bank to interpret “informed consent” independently, and paying particular attention to underserved communities who are least likely to benefit from data portability if the interface assumes a level of financial or digital literacy they do not have.

A Recommended Sequencing for Canada

Given where Canada already stands, with the CDBA enacted, oversight consolidated under the Bank of Canada, and draft regulations interpreted after public consultation, the sequencing question is less about starting from zero and more about closing the two open loops before implementation locks in.

Over the next twelve months, Canada should focus on finalising the technical standard designation for clarity when building; publishing the accreditation and liability framework; and laying the foundations for sustainable commercial incentive models, launching with a legitimate, pre-agreed monetisation structure from launch. Consumer trust and inclusion design should be forefront when finalising the regulatory standards.

This is where infrastructure choices matter as much as policy choices. A proven platform that can support FDX, or any other global standard allowing it to adapt if the final designation differs, and that treats commercial monetisation as a first-class feature rather than an add-on, gives Canadian institutions room to move as fast as the regulatory timeline allows without betting their technical architecture on a designation that has not yet happened.

How Ozone API Can Help

Ozone API was founded by the original architects of the UK Open Banking standard. We have watched, and helped central banks, regulators and financial institutions to build, open finance infrastructure through exactly the questions Canada is now working through: which standard to build to, how to structure accreditation and liability, and how to turn a compliance mandate into a genuine commercial channel rather than a cost centre.

The bottom line: Canada does not need to choose between moving fast and building it right. Every other market’s foundations are already visible, mistakes included. To talk about what a well-founded consumer-directed finance framework could look like for the Canadian market, get in touch.

Recommended articles

Surfing bank house. Opportunities in the economy and financial crisis. Challenge to overcome difficulty. Flat vector illustration
Insights

The FCA’s Open Finance Roadmap: What It Means for Banks and Financial Institutions

The FCA has published its Open Finance Roadmap, with key milestones beginning this year and a 2030 horizon. Banks, lenders, and fintechs face a significantly wider scope than open banking, with real commercial opportunity for those who prepare early. Here is what the roadmap says and what it means for your business.

Ozone API
18, May 2026
Route to the goal. Working with plan on paper. Plan on paper. Strategy, marketing, business development. Flat vector illustration.
Insights

The FCA’s Open Finance Roadmap Is Really Promising, but the UK Has Ground to Make Up

The FCA has published its Open Finance Roadmap with specific milestones, credible use cases, and an honest acknowledgement that the UK is catching up, not leading. We break down what the plan gets right, where the real risks are, and what regulators worldwide should take from it.

Ozone API
11, May 2026
Insights

Global Interoperability in Open Finance: 18 Months On

In September 2024, I published Global Interoperability, making the case that open finance would only deliver on its promise if the underlying plumbing was standardised globally, not just market by market. Eighteen months later, the landscape has changed considerably. More markets. More data. More urgency. Three arguments from that piece have aged particularly well, and...

Chris Michael
05, May 2026