What Can Lenders See With Open Banking? A Guide for ABN Holders

What Lenders Can See With Open Banking | Switchboard Finance
Switchboard Finance Self-Employed Evidence

Open banking · Consumer Data Right · ABN holders

What Can Lenders See With Open Banking? A Guide for ABN Holders

Just been sent a link to connect your bank? Through open banking the lender sees only the accounts you pick, for as long as you agree, and never your login. This guide covers what it sees, how to check the link is genuine, and what happens after you share.

Published 25 September 2026 / Reviewed 25 September 2026 / Nick Lim, FBAA Accredited Finance Broker / General information only

Quick Answer

Through open banking under the Consumer Data Right, a lender sees only the accounts you choose to share: account details, balances and transactions, including direct debits and who you paid or were paid by. It comes from your bank, not your login, for the period you consent to.

Also called: Consumer Data Right sharing, CDR data sharing or bank data sharing. Lenders and brokers may call it a bank connection, bank feed or statement retrieval, and those names can mean open banking or screen scraping, which is why the difference matters.

What can a lender see when you share bank data through open banking?

A lender sees only the accounts you select and only the data it asked for and you approved: typically your account names, types and balances, your transactions with their descriptions and available merchant, payer or payee details, your direct debits and scheduled payments, and your saved payees. Nothing you leave unselected is automatically shared, although the lender can still ask you to provide another account if the application or transfers show that it is relevant.

Under the Consumer Data Right that data falls into information about you, about how you use the account and about the account itself, and anything worked out from it, such as a categorisation of your transactions, counts as Consumer Data Right data too. For self-employed borrowers weighing one doc home loans, that consent is often where the bank data comes from, and it sits alongside what a lender sees once your application is submitted.

What can a lender see when you share bank data through open banking? (September 2026)
What the consent screen asks to share What it includes What a lender reads from it
Your name and contact details Name and contact details held by your bank Matching the data to your application
Account name, type and balance Name of account, type of account, account balance Which accounts you hold and what is in them
Account balance and details The above plus account number, interest rates, fees, discounts, account terms and mail address Confirming the account and its terms
Transaction details Incoming and outgoing transactions, amounts, dates, descriptions, and who you paid or were paid by Income, spending, commitments and account conduct
Direct debits and scheduled payments Direct debits and scheduled payments set up on the account Regular commitments, such as other loan repayments
Saved payees Names and details of accounts you have saved, for example BSB and account number, BPAY biller or PayID Who you pay regularly

Sources: Data Standards Body, Consumer Data Standards, Consumer Experience, Banking and Non-Bank Lending Language; Office of the Australian Information Commissioner, Consumer data right data, modified 22 August 2024. Both read 25 September 2026. A lender receives only the items it asks for and you approve.

Can a lender see what you spend money on?

Yes, on the accounts you share. Transaction details carry each transaction’s amount, date and description and who you paid or were paid by, so merchant names, buy now pay later repayments, gambling transactions, payments to the ATO and repayments to other lenders all show. For a business owner the items that draw questions are usually transfers between your own accounts, ATO instalments and repayments on a facility that is not on the application. How lenders weigh each of these is covered in how lenders read business bank statements.

Can you leave a bank account out when a lender asks for open banking?

Yes. Open banking only shares the accounts you select, but leaving an account out does not force the lender to assess the loan without it. If the missing account receives business income, pays a loan or tax commitment, or appears in transfers from an account you did share, the lender may ask for that account separately before making a decision.

What transaction details can a lender actually see?

On a shared account, transaction data can include the amount, date, description, reference and available merchant, payer or payee information. That can make payments to buy now pay later providers, gambling merchants, the ATO, other lenders, payment platforms and crypto exchanges visible when those names or references are present in the bank data.

Can a lender see why you spent the money?

Usually not from the transaction alone. The lender can see the transaction information your bank supplies, such as the amount, date, description and available merchant or counterparty details, but that does not necessarily explain the purpose or context. A cash withdrawal shows that cash left the account, for example, not what the cash was ultimately used for. If the transaction matters to the assessment, the lender can ask you to explain it or provide supporting evidence.

How far back can a lender see your transactions?

Your bank only has to share the last two years of transactions. Older data, back to seven years, and data from closed accounts is voluntary, so some banks share it and some do not. Before 4 March 2025 seven years was required, which is why older guides still say seven years.

Sources: Consumer Data Right Rules, Schedule 3, clause 3.2, Compilation No. 10 of 4 March 2025; Consumer Data Right, Compliance guide for data holders, banking and non-bank lenders sectors, July 2025. Both read 25 September 2026.

Can your broker see the data too?

Only if you give a separate consent for the data to be disclosed to them. The rules list mortgage brokers within the meaning of the National Consumer Credit Protection Act 2009 as one class of trusted adviser, and disclosure to a trusted adviser needs its own consent. That is the consumer credit definition, so whether a particular broker falls within it depends on the kind of lending involved. Source: Office of the Australian Information Commissioner, Trusted advisers in the CDR system, modified 22 August 2024, read 25 September 2026.

Is the bank connection link safe, and is it open banking or screen scraping?

A genuine open banking link sends you to your own bank to approve the sharing, and it never needs your password. The Consumer Data Standards require services using the Consumer Data Right to tell you they do not need your password, and on the web version of the flow your bank asks for a customer identifier and a one-time password it sends you, or opens its own app. From 10 May 2027 banks and data recipients must also support approval inside the bank’s own app, a change made over security concerns with one-time passwords. A page that asks you to type your banking username and password into someone else’s site is screen scraping.

Treasury has said sharing login details “is inconsistent with cyber security advice and may pose consumer protection risks”. On 9 August 2024 the then Assistant Treasurer called screen scraping “fundamentally unsafe” and asked Treasury to advise on a way forward for a full and formal ban. That was a request for advice, not a ban. No ban had been legislated when this guide was reviewed, and Treasury’s September 2025 Regulatory Initiatives Grid, its list of planned financial sector reforms, did not include one. Both methods still turn up on self-employed files, including equipment finance applications, where a lender may ask for a bank connection before it assesses the deal.

Open banking or screen scraping: what is the difference when a lender asks for your bank data? (September 2026)
Point Open banking (Consumer Data Right) Screen scraping
What you hand over A consent to the lender and an authorisation at your own bank, using a one-time password or your bank’s app Your online banking username and password, typed into a third party’s screen
What the lender can see Only the accounts and data you select Whatever your login can see
How long access lasts Until the consent end date you agree to, or earlier if you withdraw Set by the service, not by a Consumer Data Right consent
How you stop it Withdraw on the recipient’s consent dashboard or at your bank No Consumer Data Right dashboard to withdraw from
How it is regulated Consumer Data Right rules; the recipient must be accredited or operate under the rules No specific regulation; Treasury says sharing logins is inconsistent with cyber security advice

Sources: Data Standards Body, Consumer Data Standards, Authentication Standards; The Treasury, Screen scraping, policy and regulatory implications, consultation 30 August to 25 October 2023; the then Assistant Treasurer, address to the Committee for Economic Development of Australia, 9 August 2024; The Treasury, Regulatory Initiatives Grid, Edition 2, September 2025. All read 25 September 2026.

Why does the consent screen name a company you have never heard of?

Because many lenders use a specialist data company to collect bank data for them, the consent screen can name that company rather than your lender. That is normal, and you can check the name on the government’s Consumer Data Right provider list, which covers accredited data recipients and representative arrangements. The screen must show the accredited company’s name and accreditation number, and where a representative runs it, the representative’s name as well as the accredited company behind it (Consumer Data Standards guideline, modified 5 March 2025, read 25 September 2026). If the link arrived out of the blue rather than from a lender or broker you applied with, do not use it; contact them on a number you already have, and never share a one-time password with anyone who contacts you (Scamwatch, phishing scams, read 25 September 2026).

How can you tell which one you are being asked for?

  1. Check who sent it. Did the link come from the lender or broker you applied with, in reply to your application?
  2. Check where you log in. Are you sent to your own bank’s site or app, or asked to type your banking password into someone else’s page?
  3. Check the consent screen. Does it name the data, the accounts, the purpose and how long the consent runs?
  4. Check the recipient. Is the company named on the consent screen on the Consumer Data Right provider list? If you are unsure, ask the lender or your broker which method it uses and whether statements are accepted instead.

What can’t a lender see or do through open banking?

A lender cannot see accounts or data you did not share, and the consent you give it is not a line to the ATO or to your credit report. The table below puts the common questions in one place, with where each answer actually comes from.

What does open banking do, and not do, on a loan application? (September 2026)
Question Under the Consumer Data Right Where the answer actually comes from
Can the lender see accounts I did not select? No; only the accounts and data you consent to share Your consent, which names the accounts and data
Does the lender get my banking login? No; you approve the sharing at your own bank Screen scraping is the method that uses your login
Can the lender move money from my account? Not through a data-sharing consent A separate direct debit authority you sign with the loan
Does it put an enquiry on my credit report? No; sharing data is not an application for credit Applying for the loan is what lets a lender access your credit report
Does the ATO get the data? No; it goes to the business you consented to The ATO’s own data-matching programs with financial institutions, separate from open banking
What happens when consent ends? Collection stops; the data must be destroyed or de-identified unless an exception applies Your consent dashboard and your deletion election

Sources: Office of the Australian Information Commissioner, How the Consumer Data Right opt-in process works (modified 22 August 2024) and Credit reporting (modified 4 April 2025); Australian Government, Consumer Data Right, your rights (no date shown); ATO, Residential investment property loan data-matching program protocol (updated 6 April 2023). All read 25 September 2026. General information. The credit report row reflects consumer credit reporting; business credit is handled under the Australian Privacy Principles.

Does open banking send your bank data to the ATO?

No: open banking data goes to the business you consented to, not to the tax office. The half most answers leave out is that the ATO runs its own data-matching programs with financial institutions, for example its residential investment property loan program covering 2021-22 to 2025-26. Those programs are separate from open banking and exist whether or not you ever share data. For the registers and records a lender does check, see what else a lender checks on a self-employed borrower.

What happens after you share your bank data with a lender?

Your bank sends the data you approved to the lender or its data company, software sorts the transactions into categories, and a credit assessor reads the result against your application and comes back with any questions or conditions. Sharing the data is one step of the assessment, not the decision.

  1. Choose the accounts and data. The consent screen lists what is asked for, the purpose and how long the consent runs, and you pick the accounts.
  2. Authorise at your bank. You are sent to your bank’s site or app to confirm, using a one-time password or the app itself.
  3. The data is collected. The lender or its data company receives the approved data, and the consent appears on its dashboard and on your bank’s.
  4. Software categorises it. Transactions are sorted into groups such as income, living costs and loan repayments, and that categorisation is derived Consumer Data Right data.
  5. An assessor reads it. A person compares the categorised data with your application and whatever else the lender’s policy asks for, such as BAS, an accountant’s letter or tax returns.
  6. Questions or conditions come back. Most queries are about transactions the software labelled one way and your business uses another.

What should a self-employed borrower line up before sharing?

Know which accounts the lender needs, make sure every loan and ATO arrangement on the application matches what the data will show, and have a one-line explanation ready for anything software may misread. Whether shared data stands in for BAS, an accountant’s letter or tax returns is each lender’s rule; the mix each takes, from BAS, an accountant’s letter or bank statements, is set out separately.

Why does a lender ask questions after reading your open banking data?

A lender usually asks questions when the bank data does not match the application, when software cannot confidently categorise a transaction, or when the feed reveals another account, liability, expense or source of income that needs explaining. For a self-employed borrower, the fastest way to reduce back-and-forth is to identify those items before assessment and explain them in plain language.

What commonly triggers questions after a lender reads open banking data? (September 2026)
What the lender sees Why it may matter What usually resolves it
Transfers to another account in your name The software may count the transfer as income or spending, or the lender may need to see the other account. Identify the matching account and explain that the money is moving between your own accounts.
Repayments to another lender The payment may reveal a liability or commitment that is not on the application. Confirm the facility, balance and repayment and make sure it is disclosed on the application.
ATO payments or payment-plan instalments The assessor may need to know whether the payment is normal tax, a current arrangement or overdue tax. Explain what the payment relates to and provide the relevant ATO or accountant evidence if the lender asks.
Large or irregular credits The lender may need to determine whether the money is trading income, an internal transfer, a loan, an asset sale or a one-off receipt. Identify the source and provide supporting evidence if it is material to income or serviceability.
Business income paid into a personal account The lender may need both accounts to understand turnover and avoid counting the same money twice. Show how the accounts connect and which credits are genuine business receipts.
BNPL or finance repayments They may represent an ongoing commitment that needs to be included in the assessment. Confirm whether the facility is still open and what the current repayment obligation is.
Regular cash withdrawals The feed proves the withdrawal but not what the cash was ultimately used for. Explain the purpose if it is relevant to the assessment; the transaction alone does not provide that context.

Sources: Office of the Australian Information Commissioner, Consumer data right data (derived data includes categorisation), modified 22 August 2024, read 25 September 2026. Rows are Switchboard practice, not a regulator list. Illustrative. Each lender’s software and policy differ.

What if open banking software categorises a transaction incorrectly?

Transaction categorisation is an interpretation of the bank data, not a new bank record. If software treats an internal transfer as income, labels a business payment as personal spending or otherwise misreads a transaction, the assessor can ask you to identify it and may request supporting evidence. A categorisation error does not change the underlying bank transaction, so the useful response is to explain what the transaction actually was rather than trying to make the feed disappear.

What we see in practice (indicative, general information, not a quote or an offer). As of September 2026.

From the self-employed files we work on, the questions a lender raises about shared data tend to fall in the same few places.

  • The most common query on shared data is money moving between the owner’s own accounts, which software often reads as income or spending.
  • A single account used for business and personal money takes longest to explain.
  • Sharing only one of several business accounts usually leads to a request for the rest.
  • A repayment to another lender that shows in the data but not on the application causes more delay than almost anything else.

Every lender’s software and policy differ and change. Nothing here is an approval indication, a timeframe or a rate.

If you would rather have the odd transactions explained before a lender reads them, talk the file through with us first. How lenders judge turnover, cash deposits, gambling and failed payments is covered in what lenders look for in business bank statements.

Illustrative scenario: sole trader, equipment finance A sole trader applying for equipment finance receives a Consumer Data Right consent link from the lender, naming a data company he does not recognise. He checks it on the provider list, approves the sharing at his bank with a one-time password, and shares only his business account for the period asked. The categorisation labels his transfers to his personal account as spending, so his broker explains them before assessment, naming the matching account.

How does open banking work for a company, trust or partnership account?

A business account can be shared, but someone the business has nominated has to authorise it, and not every lender or account type is covered yet. Under the rules you are treated as a Consumer Data Right business consumer if you are not an individual, or if you have an active ABN, once the business receiving the data has taken reasonable steps to confirm it. That status is what unlocks the longer business consent covered in the next section.

In the banking sector, non-individuals and partnerships can participate through a nominated representative; being a director, trustee or partner does not automatically make someone the nominated representative. In the non-bank lender sector, consumer data sharing starts on 9 November 2026 for initial providers and 10 May 2027 for large providers that were already large by 13 July 2025. The non-bank lender rules do not require those providers to handle complex requests made by a secondary user or nominated representative, or requests involving joint or partnership accounts. That matters when you are gathering evidence for a business loan across several entities.

  • Sole trader with an active ABN: you authorise your own accounts.
  • Company or trust: a nominated representative authorises the entity’s accounts.
  • Partnership: sharing runs through the partnership’s arrangements with its bank.
  • Joint or partnership account held with a non-bank lender: that lender does not have to respond to the request.

Why isn’t your business bank account showing when you connect?

Work through the problem in this order rather than repeatedly retrying the connection.

  1. Check who owns the account. Confirm whether it is your personal sole-trader account, a company account, a trust account, a partnership account or a joint account.
  2. Check who has authority. A director, trustee or partner is not automatically the Consumer Data Right nominated representative for the entity. At some banks the business’s online banking administrator must first switch data sharing on and nominate you before the entity’s accounts appear.
  3. Check the bank profile. Make sure the account sits under the internet-banking profile or business login you are using for the connection.
  4. Check the request type. Joint, partnership, nominated-representative and other complex requests are treated differently, and non-bank lenders are not required to support them at all.
  5. Ask the bank before retrying again. If a nomination or authority is missing, the bank is the party that usually has to fix that first.
  6. Ask the lender what it accepts instead. If the account cannot be shared through that flow, ask whether PDF statements or another evidence route is acceptable for that product.

Sources: Consumer Data Right Rules, rule 1.10A(9), Compilation No. 10 of 4 March 2025; Consumer Data Right, Nominated representatives of non-individuals and partnerships fact sheet, October 2025; Consumer Data Right, CDR in the non-bank lenders sector (no date shown). All read 25 September 2026. The complex-request carve-out applies to the non-bank lender sector only.

There are three different clocks: how far back the transaction history goes, how long your bank can keep sending new data, and how long the recipient may use or hold data it has already collected. Do not treat those as the same thing.

  • Transaction history: this is the historical data available from the account, covered earlier in this guide.
  • Ongoing collection from your bank: the bank authorisation is time-limited and can be withdrawn. A collection consent covers either a single occasion or a set period of up to 12 months, and a business consumer statement cannot be given for a collection consent, so it never extends how long new data is collected.
  • Use or disclosure of data already collected: some consents given by a CDR business consumer with a business consumer statement can run for up to seven years. The seven-year rule is a ceiling for certain business use or disclosure consents, not a statement that a lender can continuously pull fresh bank transactions for seven years without renewal.

When consent ends or you withdraw it, collection stops. Redundant CDR data must generally be destroyed or de-identified unless an exception applies, and the recipient dashboard must let you manage consent and make a deletion election.

What if the loan is declined or you go elsewhere?

Withdraw the consent, because it does not end on its own when a loan is declined or you choose another lender.

  1. Open the dashboard. Go to the consent dashboard of the business you shared with.
  2. Withdraw the consent. Collection stops from that point.
  3. Withdraw at your bank too. You can also withdraw the authorisation at your own bank.
  4. Ask for deletion. Ask for redundant data to be deleted if you have not already elected it.

Does a lender keep watching your account after settlement?

Not automatically. Whether new data can keep flowing depends on the consent and bank authorisation you approved. A one-off disclosure ends after the data is shared; an ongoing arrangement has a stated period and can be withdrawn. If a lender asks you to keep a connection active after settlement, for example on an equipment facility, check exactly what data it will collect, why it is needed and when the authorisation ends before agreeing. How that works in practice is covered in what a lender sees in a live bank feed.

Sources: Consumer Data Right Rules, rules 4.11(1)(b), 4.12(1), 4.12(1A) and 4.14(2), Compilation No. 10 of 4 March 2025; Office of the Australian Information Commissioner, Consumer consent, authorisation and dashboards, modified 22 August 2024; Data Standards Body, Collection and use consents, read 25 September 2026; Australian Government, Consumer Data Right, your rights. All read 25 September 2026.

Can you say no to open banking and send statements instead?

Yes, you can refuse the Consumer Data Right consent because the system is opt-in. That does not mean the lender is required to offer the same loan using PDF statements. Whether it accepts statements, downloaded transaction files or another evidence route is a separate lender and product-policy question.

Ask before you apply: is the bank connection mandatory for this product, what alternatives are accepted, how recent must the statements be, and will refusing the connection change the product, limit, turnaround time or documents required? The alternatives vary by lender and product, and are summarised in what non-bank lenders accept as evidence.

What changes when non-bank lenders join open banking?

Status as at September 2026: non-bank lenders began sharing product data from 13 July 2026, and consumer data sharing starts on 9 November 2026 for initial providers and 10 May 2027 for large providers. In this sector the rules do not apply to complex requests, a carve-out with no later start date. These are rules about non-bank lenders sharing the data they hold, for example about a loan you already have with one; they are not rules about what a lender receiving your bank data may do. For how this plays out on commercial deals, see open banking and non-bank commercial property lenders.

Sources: Consumer Data Right, CDR in the non-bank lenders sector; ACCC, Non-bank lenders join Consumer Data Right as next stage commences, 13 July 2026; Australian Government, Consumer Data Right, your rights. All read 25 September 2026. Dates are data-holder obligations and may change.

Illustrative scenario: company director asked for a login A company director is asked to type the company’s online banking login into a lender’s portal. That is screen scraping. He asks whether a Consumer Data Right connection or PDF statements are accepted instead, and the lender’s process decides which.
Illustrative scenario: trust and partnership accounts A family trust account and a partnership account form part of one application. The trust account does not appear when the trustee director connects, because no nominated representative has been set up at the bank, so the director arranges the nomination. The partnership’s facility is held with a non-bank lender that does not have to share a partnership account’s data, so that part of the file goes down the statement route.

Open banking gives a lender the accounts and data you choose to share, directly from your bank, without handing over your normal banking password. It can expose balances, transaction descriptions, available merchant or counterparty information, direct debits and regular commitments on those accounts. It does not automatically reveal unshared accounts, explain why every payment was made, move money, send data to the ATO or create a credit enquiry. The practical risk for a self-employed borrower is usually not the connection itself; it is what the data causes the assessor to ask next, such as another account, an undisclosed liability, an ATO arrangement, irregular income or a transaction the software has categorised incorrectly.

Key takeaway: check who is asking, know exactly what you are sharing, explain anything the data is likely to misread, and review or withdraw the consent when it is no longer needed.

Frequently Asked Questions

No. Through the Consumer Data Right you approve the sharing at your own bank, and the Consumer Data Standards say services using it do not need your password. Screen scraping is the method that asks for your login, and Treasury has said sharing login details is inconsistent with cyber security advice.

Many lenders use a specialist data company to collect bank data, so the consent screen can name that company rather than the lender. You can check it on the government’s Consumer Data Right provider list, which covers accredited recipients and representative arrangements.

No. A data-sharing consent only lets a lender read the data you agreed to share; taking repayments needs a separate direct debit authority that you sign with the loan.

Yes, to the extent the transaction data identifies it. On accounts you share, the lender can receive transaction amounts, dates, descriptions and available merchant or counterparty details, so gambling, buy now pay later repayments and ATO payments can be visible. The transaction does not necessarily explain why you made the payment, and the lender may ask for context if it matters to the assessment. How lenders assess those patterns is covered in what lenders look for in business bank statements.

No: open banking data goes only to the business you consented to, but the ATO has its own data-matching programs with financial institutions that do not depend on open banking. Those programs exist whether or not you share data with a lender.

No. Sharing bank data is not an application for credit, so it does not put an enquiry on your credit report; applying for the loan is what lets a lender check it. For the business side, see what a business credit report shows.

No, only the accounts you choose to share, although a lender may ask to see the others before it decides. Sharing one account and leaving out others you use for the business usually prompts that request.

Not automatically. A lender can collect new data only on a single occasion or for the period you agreed, which is at most 12 months, and you can withdraw it at any time. A business consumer statement can extend how long some collected data may be used, up to seven years, but it cannot extend collection.

Yes, you can withdraw consent at any time through the consent dashboard, and the data must then be destroyed or de-identified unless an exception applies. A consent does not end on its own when a loan is declined, so withdraw it; you can also withdraw the authorisation at your own bank.

Usually because the bank data does not line up neatly with the application, software has misclassified a transfer or payment, or the feed shows an account or commitment the lender did not know about. Transaction categorisation is an interpretation of the underlying bank data, so an internal transfer or business payment can be queried and corrected with an explanation or supporting evidence.

Yes, but a company, trust or partnership usually needs a nominated representative set up at its bank for CDR sharing, and a director or partner is not automatically that representative. In the non-bank lender sector, initial providers start consumer data sharing on 9 November 2026 and relevant large providers follow from 10 May 2027; those providers are not required to handle complex requests such as nominated-representative, joint or partnership requests.

You can refuse a Consumer Data Right consent because the system is opt-in, but the lender is not automatically required to offer the same product using PDF statements. Whether statements or another evidence route are accepted, and whether refusing changes the product, limits, turnaround time or documents required, is a lender and product-policy question.

Nick Lim

Nick Lim

Broker, Switchboard Finance

0483 980 567 / hello@switchboardfinance.com.au

FBAA FBAA Accredited
Previous
Previous

Declined for a Business Loan With a New ABN? What Works Instead

Next
Next

How to Buy a Petrol Station: How the Finance Works