Giving a Lender Access to Your Business Bank Account: What Can They See?
Business Owners Hub
Equipment finance · Bank feed link · What lenders see
You applied for equipment finance and the lender sent a link asking you to connect your business bank account. Before you click it, the real questions are who receives the data, whether the connection uses CDR Open Banking or screen scraping, which accounts will be visible, what happens if you refuse, and how to shut the access down later. This page follows that journey from the first link to payout.
Quick Answer
Giving a lender access to your business bank account means the lender or its data provider receives account and transaction data for the connected accounts. Open Banking authorises sharing through your bank without handing over a password; screen scraping uses your credentials. Ongoing facilities can keep receiving new activity after settlement.
Also called: a lender bank feed, a live bank feed, an ongoing bank account connection.
What can a lender see when you connect your business bank account?
A lender can receive account and transaction data through the connection, but the boundary depends on how the connection works. With CDR Open Banking, you choose the eligible accounts and data categories you authorise. With screen scraping, a third-party service uses the banking credentials you provide, so you should not assume the technical scope is limited in exactly the same way.
The data used for a finance assessment commonly includes account details, balances, transaction dates, amounts, transaction descriptions, credits and debits. Depending on the authorised CDR data set, information can also include direct debits, scheduled payments and other account information. The important question is not just can the lender see my bank account? It is which accounts, which data fields, who receives them and for how long.
With CDR Open Banking, the sharing request is specific and consent based. With screen scraping, the provider may say its service is contractually limited to retrieving the information needed for the application, but the underlying internet-banking login is a different access mechanism. The OAIC notes that screen scraping can give a third party broader account capability in some circumstances, so ask what the provider retrieves rather than relying on the label "read only". Source: OAIC, screen scraping policy submission, read 28 August 2026.
The finance data request is also separate from the authority used to collect your loan repayments. A lender may receive banking data for assessment and, separately, hold a direct-debit or payment authority under the facility. Treat those as two different permissions.
Is this the same bank feed as Xero, MYOB or other accounting software?
No. An accounting-software bank feed sends transaction data into your bookkeeping platform so transactions can be reconciled and coded. A lender connection sends data to a lender, assessment platform or data provider for a finance purpose. Disconnecting one does not automatically disconnect the other.
Where are you in the process, and what matters next?
The useful question changes depending on whether the link has just arrived, you are choosing accounts, the facility is already live, or you are trying to shut the access down.
| Where you are | What matters most right now | Where it is answered |
|---|---|---|
| The link has arrived and you have not clicked it | Verify the request, identify the data provider and find out whether the route is CDR Open Banking or screen scraping | Password and connection route |
| You are choosing accounts | Know which accounts and data fields will be shared, especially if business trading runs through a personal account | Mixed personal and business accounts |
| You would rather not connect | Ask what evidence or product is available instead, and what changes to the facility if you refuse | Refusing or withdrawing consent |
| The facility is live and an unusual transaction appears | The transaction can become part of the data set; what it means depends on the lender, the surrounding pattern and your explanation | Ongoing monitoring and explanations |
| The connection stopped or the facility is paid out | Separate a technical failure from consent withdrawal, then separately deal with new access and data already held | Connection failures and revoking at payout |
Does giving a lender access mean sharing your banking password?
Only one of the two common routes asks you to hand banking credentials to a third-party service. CDR Open Banking does not require you to give the lender or data recipient your online-banking password. Screen scraping does.
With CDR Open Banking, you move through your bank's authorisation flow and approve specific data sharing. Current CDR guidance requires the data recipient to tell you what data it wants, why it wants it, how long the consent will run, and how to withdraw it. The current maximum consent period is 12 months. Source: Consumer Data Right, legal obligations for data recipients, read 28 August 2026.
Why is my business bank account not showing in Open Banking?
A missing business account does not automatically mean the account cannot be shared. For a company, trust or partnership, the problem can be the customer or account eligibility, the way authority is set up, a missing nominated representative, or a known implementation gap at the bank.
Current CDR rules generally require a non-individual or partnership to have at least one nominated representative who can authorise sharing. As at August 2026, the official CDR rectification schedule also records implementation gaps affecting some business and trust account types. If the account you actually trade through is missing, stop and ask your bank whether the account is CDR eligible, whether a nominated representative must be appointed and whether there is a current implementation issue. Do not connect a different account just to get through the finance application. Sources: CDR, nominated representatives fact sheet and CDR rectification schedule, read 28 August 2026.
With screen scraping, you enter internet-banking credentials into a third-party service so it can log in and retrieve data. Treasury describes credential sharing for screen scraping as inconsistent with cyber-security advice and says it may pose consumer-protection risks. Whether credentials are stored, how often the service logs in and exactly what it retrieves depends on the provider. Source: Australian Treasury, screen scraping policy and regulatory implications, read 28 August 2026.
| What you are asking | CDR Open Banking | Screen scraping |
|---|---|---|
| Do you give a third party your banking password? | No. You authorise sharing through your bank's CDR flow | Yes. You provide banking credentials to a third-party service |
| How is account scope chosen? | You choose from eligible accounts and authorise specified data | Provider-specific. Do not assume the technical scope is identical to CDR account selection |
| How long can it run? | For the consent period you choose, up to the current 12-month maximum | Provider-specific. It may be one-off or recurring |
| Does the data consent authorise payments? | No. CDR banking data sharing is currently a data-access permission, not a payment authority | Do not assume the same technical boundary. The service may be contracted only to retrieve data, but it is using banking credentials |
| Where do you manage or stop it? | Through the relevant consumer dashboards or another permitted withdrawal method | Through the provider's process and, if needed, the lender; changing the password may break access but does not prove stored data was deleted |
| What legal framework governs the sharing route? | The Consumer Data Right rules and privacy safeguards apply to the CDR arrangement | It is not the same CDR consent framework; check the provider's privacy terms, security terms and your bank's credential-sharing rules |
What will the connection screen actually ask you?
The exact screen varies, but the important signals are who is asking, what route you are on, which accounts are shown and how long the permission will run. Treat the screen as a consent decision, not a form to click through quickly.
| What you may see | What it means | What to check before you continue |
|---|---|---|
| A provider brand you do not recognise | A data service may be handling the connection for the lender | Verify the provider through the broker or lender using contact details you already trust |
| A redirect into your bank's data-sharing flow | This is consistent with a CDR Open Banking authorisation journey | Check the recipient, data categories, accounts, purpose and consent duration before approving |
| A field asking for your internet-banking login | The service is using screen scraping rather than CDR Open Banking | Who receives the credentials, whether they are stored, what is retrieved and what your bank terms say about credential sharing |
| A list of accounts with tick boxes | The accounts available for the connection | Select only what the lender requires and understand the consequences if a personal account is also the business trading account |
| The business account you expected is missing | The account may be ineligible, not enabled for CDR sharing or missing a nominated-representative setup | Stop and ask your bank. Do not substitute a different account merely to finish the flow |
| A consent duration or expiry date | How long the authorised CDR sharing can continue | Record the date and ask whether the facility expects renewal before expiry |
| A one-time code or authentication prompt | Your bank is authenticating you | Never read a one-time code out to a caller or send it by message |
The sequence above is indicative of the screens applicants may encounter as at August 2026. It is not a published universal sequence and providers differ. Use it as a checklist of what to identify, not as a guarantee of how your screen will look.
How do you check the request is genuine before you enter anything?
Verify the request through a channel you started yourself. A real finance application can generate an email asking you to follow a data-sharing link, but a phishing attempt can look almost identical.
- Call the broker or lender on a number you already had, not a number inside the new email or text
- Ask them to confirm the data provider name and the web address or bank-authorisation flow you should expect
- If the service wants banking credentials, check your own bank's current terms on sharing login details
- Never read out a one-time code, authentication response or security code to anyone
- If the request is being rushed or the domain looks wrong, stop and verify it before entering anything
If you think the request is not genuine, or you already entered details and are unsure, contact your bank first and then report it through Scamwatch, phishing scams, read 28 August 2026.
What should you ask before you connect your business bank account?
Get the answers to these questions before you click approve or enter credentials. They cover nearly every problem that becomes harder to unwind later.
- Which route is this? CDR Open Banking or screen scraping?
- Who receives the data? The lender, an accredited data recipient, another provider, or more than one party?
- Exactly what is shared? Which accounts, transaction history and other data fields?
- Is it one-off or ongoing? How long will new data continue to be collected?
- Is ongoing access a facility condition? What happens to approval, drawdowns or the product if you refuse or later withdraw it?
- Where is the off switch? What exact step ends new collection?
- What happens to data already collected? Who keeps it, for how long, and what deletion or retention rules apply?
What if your business uses a personal bank account?
If you connect an account that mixes business trading with personal spending, the transactions inside that account can be part of the data the lender receives. The connection does not know that one debit was groceries and another was a supplier payment unless the transaction data and surrounding context make that distinction clear.
This is common for sole traders and small businesses that have never fully separated personal and business banking. If the personal account is where the business revenue lands and the business bills are paid, it may be the trading account the lender needs to assess. The privacy question therefore becomes practical: do you want to connect that account, and is there another evidence route if you do not?
Can the lender see personal purchases, transfers or gambling transactions?
Yes, if those transactions sit inside an account and data range reached by the connection. A lender can see the transaction record it receives, including the date, amount and description available in the banking data. The connection does not provide the story behind the transaction, and the effect of any particular entry depends on the lender's policy, the rest of the account history and the explanation.
If you are worried about a particular entry, do not move money around in an attempt to erase the history. The original transaction has already been recorded and extra transfers simply create more entries. The useful move is to understand what is visible and prepare a truthful explanation if the item is material. For the separate question of how assessors read transaction patterns, see what equipment-finance lenders flag in bank statements.
Should you open a separate business account before applying?
A separate business trading account can make future applications easier to read, but opening one today does not rewrite the history a lender is assessing now. A new account also has little or no trading history. If your current application needs evidence of the last several months, ask the lender which existing account history is required and start separating the flows for the next review or application.
What does a live bank connection show that PDF statements do not?
The main difference is continuation, not a completely different category of financial information. A PDF statement is fixed at the date you download it. An ongoing connection can keep supplying authorised account data after that date.
| What the lender gets | PDF bank statements | Ongoing bank connection |
|---|---|---|
| How current the data is | Fixed at the statement or export date | Can continue to refresh while the authorised connection remains active |
| What happens after settlement | No new transactions arrive unless you send another statement | New account data can continue to be supplied if the facility uses ongoing access |
| Which accounts are covered | The accounts contained in the files you provide | The accounts and data reached by the connection, subject to the route and authorisation |
| Who supplies the data | You upload or send the file | The data-sharing or aggregation service retrieves it after you authorise or provide access |
| What a later review or draw can use | The lender may need a fresh statement pack | Current data may already be available if the connection is still active |
The history itself is familiar: dates, transaction descriptions, credits, debits and balances. The connection changes how current the evidence can be and how it arrives. It does not turn a weak transaction pattern into a strong one.
On equipment-finance applications of this shape we commonly see the bank data sitting alongside other application evidence rather than replacing every document. What is required varies by lender, structure and amount. Where an assessment runs on trading statements rather than full financials, current bank data can carry more weight because it is doing more of the income-verification work.
What happens after you connect the account?
The provider can retrieve the data covered by the permission or access you gave, and that data can then be used in the finance assessment. If the product only needs a one-off verification, the role of the connection may end there. If the facility is built around ongoing access, later account activity can continue to be available for drawdowns, reviews or facility management. Ask which of those two situations you are agreeing to before you connect.
Does connecting your bank account affect your credit file?
The bank-data connection and the credit enquiry are separate things. Connecting an account does not itself turn into a bank-feed entry on your credit report. A lender may separately make a credit enquiry as part of the finance application, depending on the product and applicant. Keep those two permissions separate when you are deciding what you have agreed to.
What do lenders look for in your business bank transactions after you connect?
Lenders are usually looking for patterns that show whether the business is trading as expected and whether its cash flow can carry existing and proposed debt. Common signals visible in bank transaction data include the rhythm of revenue deposits, low or negative balances, overdraft use, dishonours or returned payments, existing loan repayments, payroll and supplier outgoings, ATO payments where visible, cash-flow volatility and large or unexplained transfers.
An ongoing connection keeps those signals current after the original statement pack was produced. It does not mean one transaction automatically decides the application or that a person is sitting in front of a live screen watching every purchase. An ATO payment in the bank account also shows that a payment occurred, not the full balance of any ATO debt. The lender would need separate evidence to know the exact tax position.
For the wider equipment-finance underwriting sequence, see what a lender checks on a manufacturer's equipment file. For transaction-description issues specifically, see how transaction narration is read.
Is a person watching the feed, or is it automated?
The retrieval and categorisation can be automated, while the way the data is reviewed depends on the lender and provider. Do not assume either extreme: that somebody is watching every transaction in real time, or that no automated flags or categories exist. A human review can occur at application, a later draw, a limit change, a facility review or when an issue needs explanation.
What happens if an unusual transaction appears after you connect?
The transaction can become visible in the same way it would appear on a later bank statement. There is no universal rule that one unusual entry automatically cancels a facility or causes a decline. The outcome depends on what the transaction is, whether it is isolated or part of a pattern, the lender's policy and the terms of the facility.
If a material item has an innocent explanation, give that context before the next drawdown or review rather than hoping the entry is never noticed. A one-off transfer between your own accounts, a large tax payment, an asset purchase or a temporary cash-flow event can read very differently once the assessor knows what it is.
Can you refuse to connect your bank account, and what changes if you do?
Yes, you can choose not to give CDR consent, and CDR consent must be voluntary. That does not mean a lender has to offer the same product without the data it uses to assess or manage that product. The commercial question is therefore not just "can I refuse?" but what evidence or facility is available if I do? Source: OAIC, how the Consumer Data Right opt-in process works, read 28 August 2026.
Before you decline, ask the lender or broker to answer four things in writing: whether PDF statements are an alternative, whether the product or limit changes, whether later drawdowns will need fresh evidence, and whether ongoing access is an actual facility condition or only an application step. That turns a vague privacy concern into a decision you can price and understand.
If you connect, does it have to stay connected for the whole facility?
Only if the arrangement and facility terms require ongoing access. On a revolving equipment facility built around current trading data, the ongoing connection can be part of what lets the lender make later draws available without repeating the same evidence process every time. If that is the product you are being offered, read the condition that deals with ongoing data access before you sign.
On a revolving equipment facility, the commercial value of current data is that the lender may be able to assess the trading position without asking you to export another statement pack for each purchase. The exact consequence of withdrawing access is facility-specific, so do not assume a held draw, a review or a product change unless the terms actually allow it.
From our broking, indicative
On revolving equipment facilities of this shape, as at August 2026, we have placed or seen:
- Limits written to $500k where the facility is asset backed and the bank connection is in place
- A cap of $100k on deals we have placed where the facility is not asset backed
- Applications considered to $2m, which is a consideration ceiling and not an approval
- Five-year terms per transaction with repayments monthly in advance on deals we have placed
Indicative only, based on deals we have placed, not a quote, published market standard or offer. Actual limits, evidence, terms and access conditions depend on lender policy and your circumstances at the time of application. General information only, not financial advice.
What happens if the lender bank connection stops working?
First work out whether the problem is technical, an expired consent, a provider-access change or a deliberate withdrawal. Those events can look the same from the outside because new data stops arriving, but they do not mean the same thing and should not be treated the same way.
If current bank data is required for a later draw or review, the lender may ask you to restore the connection or provide replacement evidence before it proceeds. The exact consequence depends on the facility terms and lender policy.
| What happened | Likely cause | How to treat it | What to do next |
|---|---|---|---|
| A screen-scraping login stopped authenticating | You changed a password, the bank changed authentication, or the credentials were locked | Technical until you know otherwise | Contact the provider and ask whether it can reconnect or use a different data-sharing route |
| A CDR consent reached its end date | The authorised consent period expired | Expected expiry, not a hidden decision by the lender | Ask whether the facility needs a new consent and review the new scope before renewing |
| The bank or provider changed access controls | A screen-scraping route may no longer work after security or platform changes | Provider/access issue | Ask for CDR Open Banking, a direct data feed or another evidence method rather than repeatedly entering credentials |
| You deliberately withdrew or disconnected it | You chose to stop the arrangement | A consent and facility question, not a technical fault | Check the facility consequence and arrange replacement evidence if required |
For CDR Open Banking, current published guidance says consent is time limited and the maximum consent period is 12 months. You can also stop sharing earlier. That 12-month rule does not tell you how long a screen-scraping arrangement lasts. Sources: Consumer Data Right, legal obligations for data recipients and OAIC, CDR opt-in process, read 28 August 2026.
How do you revoke lender bank account access after payout?
Stop new access where the sharing or connection was created, then separately deal with the data already collected. Paying out the finance does not tell you, by itself, whether every data-sharing permission, stored credential or retained data copy has been closed.
| The step | CDR Open Banking | Screen scraping |
|---|---|---|
| Stop new data collection | Withdraw the consent or authorisation through the relevant consumer dashboard or another permitted withdrawal method | Use the provider's disconnection process and confirm with the lender that the scraping arrangement is closed |
| What happens to banking credentials | Your online-banking password was not given to the data recipient as part of the CDR authorisation | Ask whether credentials were stored and when they are deleted. Do not assume disconnection answers that question |
| What happens to data already collected | Stopping collection and deleting retained data are separate. CDR gives rights relating to deletion of redundant data, subject to the rules and exceptions | Provider- and lender-specific. Ask what is retained, why and for how long |
| Does changing your password solve it? | No need for that to withdraw a CDR consent because the sharing does not rely on your password | It may break future logins, but it does not prove stored credentials or previously retrieved data have been deleted |
| What should you keep | The withdrawal confirmation or dashboard record plus the payout letter | Written provider/lender confirmation that access is closed, plus the payout letter |
Under CDR, accredited data recipients must provide a consumer dashboard that lets you manage and withdraw consents. The rules also distinguish withdrawing consent from the separate handling of redundant data. Sources: OAIC, consumer consent, authorisation and dashboards and Consumer Data Right, data recipient obligations, read 28 August 2026.
What happens to the data the lender already holds?
Stopping the connection answers the future-collection question. It does not automatically answer the retention question. Under CDR, data that becomes redundant is subject to the CDR deletion or de-identification rules and any applicable exceptions. Outside that route, the answer depends on the provider's privacy terms, the lender's retention obligations and any legal requirement to keep records.
Ask two questions separately: is new data still being collected? and what happens to the data already collected? If the answer matters to you, get both responses in writing. The same applies if the loan book is later sold, transferred, or the lender is acquired: do not assume a universal answer across every provider and facility.
What should you keep after the finance is paid out?
Keep the payout or discharge confirmation, a screenshot or receipt showing any CDR withdrawal, and written confirmation from the lender or data provider that the ongoing connection is closed. If you asked for deletion or clarification of retained data, keep that response with the facility records as well.
The CDR paragraphs above describe current published rules in general terms only. They are not legal advice and do not determine the terms of a particular lender, data provider or account. If data retention or credential security matters to a decision you are making, confirm the position with the provider and your bank in writing.
If a lender asks you to connect your business bank account, settle five things before you click: which route is being used, because CDR Open Banking and screen scraping handle credentials differently; who receives the data; which accounts and data are in scope; whether access is one-off or ongoing and what happens if you refuse; and how new access and retained data are dealt with at payout. If your trading runs through a personal account, assume the mixed transactions in that account can be visible once the account is connected. If something unusual appears later, explain the material item rather than trying to rearrange the history. And if you are assembling an equipment application now, the machinery and equipment loan pack sets out what a lender may ask for alongside the bank data.
Key takeaway: do not ask only "is this read only?" Ask which route, which data, which accounts, how long, what happens if you stop it, and what happens to the data already collected.Frequently Asked Questions
Only data from accounts reached by the connection is available, but the boundary depends on the route. With CDR Open Banking you select eligible accounts and data to share. With screen scraping, a third-party service uses the banking credentials you provide, so do not assume the technical scope is identical. If a personal account is also your business trading account and you connect it, the personal transactions inside that account can be visible.
Not if the connection uses CDR Open Banking. That route sends you through your bank to authorise data sharing without giving the lender or data recipient your online-banking password. A request to enter your banking credentials into a third-party service indicates screen scraping, which is a different method and should be checked against the provider terms and your own bank terms before you continue.
A CDR Open Banking data-sharing consent does not authorise the lender to make payments. Loan repayments are normally taken under a separate direct-debit or payment authority. Screen scraping is different because it uses banking credentials, so do not assume it has the same technical access limits as CDR. Ask the provider exactly what it can do and what it is contractually authorised to do before you enter credentials.
Connect the trading accounts the lender actually requires and disclose the accounts that are relevant to the assessment. If you use several accounts, ask which ones must be connected rather than assuming one account is enough or that every account is required. If a company, trust or partnership account does not appear in a CDR flow, check nominated-representative and account-eligibility requirements with your bank before choosing another route.
Stop the sharing arrangement where it was created, then get written confirmation that no new data is being collected. For CDR Open Banking you can withdraw consent through the relevant consumer dashboard or other permitted withdrawal method. For screen scraping, the process is provider-specific. Changing your banking password may break a scraping connection, but it is not the same thing as confirming that stored credentials or previously collected data have been deleted.