- Key insight: Because open banking runs entirely through usernames and passwords, the 40 million Americans that don't bank online are locked out of benefiting from this innovation.
- What's at stake: Section 1033 of the Dodd-Frank Act enshrines a right for all Americans to be able to access and share their financial data — not just those that bank online.
- Forward look: Who gets to benefit from new open banking tools deserves its own conversation, much like the bigger conversation a few years ago about the underbanked getting left behind by the rise of a cashless society.
Section 1033 of the
There's a lingering issue, however, which the financial industry has never been able to address. Roughly 40 million Americans don't bank online. These Americans might have accessibility issues, have other people managing their accounts, have never signed up for online banking, or they might just prefer banking in-person. Section 1033 enshrines a right for all Americans to be able to access and share their financial data. Not just those that bank online. But because open banking runs entirely through usernames and passwords, 40 million people are locked out of benefiting from this innovation.
These 40 million Americans might not look like the younger, textbook fintech consumer. But they're still deserving and in-need of these tools. An elderly American might not bank online, but could still benefit from fraud protection, help with financial management and retirement planning.
And what's more, it's well within our powers as an industry to easily fix this.
At its most elemental, open banking incorporates any use case where one financial tool you're using needs to access information held at another institution. This could look like a lender checking your cash flow in your primary bank account, a HELOC-provider looking at your current credit card balances, or a mortgage provider verifying your income.
All of this plumbing across the industry is connected by one credential. Passwords became the default in a roundabout way. In the rules implementing Section 1033, the only specific instruction the
To settle the matter, banks said that if consumers gave them their username and password, they'd access the information and hand it over. Usernames and passwords became the first way to authenticate an account online, and the standard-setting body of the CFPB (made up of banks and fintechs) accepted them as the default. The CFPB initially responded effectively in understanding how usernames and passwords were used by early data aggregators. But by being open ended and tech neutral, they inadvertently created a system that closed the door to a lot of people.
Read more:
Fed & FDIC cite 'significant uncertainty' in Amex living will Fed finalizes stress test reforms, takes comment on scenarios Check fraud ring stole $7M from nine banks, credit unions OCC approves first CEBA credit card bank in 20 years
A username and password aren't even the most secure or efficient way to verify who someone is. If you call your bank, go into a branch, open a new account or reset your password, there's a standard menu of information you have to provide: name, social security, account number (which is then confirmed through two-factor identification). It has created a circular trap, when providing the personally identifiable information that helps you get a password in the first place cannot serve as a proxy for the password and let you share financial data between banks.
The CFPB is lining up to offer new guidance on its open banking rules. This is an unenviable and monumental task to bring thousands of banks, credit unions, financial institutions and tech providers together, and create a system that helps all of them work together. A more inclusive approach would be to direct banks and financial institutions to support multiple paths for authenticating accounts, such that other options (like providing account numbers, or passkeys) are just as reliable as passwords, hopefully leaving the door open for whatever other technology comes along in the future.
There are a lot of possible solutions that could make this more equitable. Apple is clearly angling for the iPhone to be a centralized wallet where a consumer stores all of their banking information, and then is able to share account details with their biometric information. Passkeys tied to individual devices are gaining traction too. But both still require some level of digital participation. The only universal solution is still an identity confirmed against an account number, either through a phone number, or email, or verified in person.
We're at a point, where who gets to benefit from new open banking tools deserves its own conversation, much like the bigger conversation a few years ago about the underbanked getting left behind by the rise of a cashless society. The exciting thing is that if you allow for more modes of authentication and make it easier to verify someone's identity, much like open banking itself, a wave of new innovation will follow behind it. If banks get more comfortable trusting other institutions' authentication processes, and we can use verified identities to connect all of our accounts in a single flow, we can move from sharing our whole financial fingerprint in one handshake, rather than one account at a time.
If we make it easier to securely serve more people with open banking, we're making an investment in seamlessness. And if we're making things more seamless, history has proven that innovation will follow.








