Fintechs A Big Problem With Open Banking?

By Ray Birch

WASHINGTON—Is the fact that most fintechs are not supervised to the same level as banks and credit unions the Achilles’ heel of open banking?

The Independent Community Bankers Association (ICBA) is asserting that lack of strong oversight of fintechs—which are permitted to access financial institution account holder data via the CFPB’s new Personal Financial Data Rights Rule—is a serious concern.

As CUToday.info reported, ICBA President and CEO Rebeca Romero Rainey shared the trade association’s worries about fintechs accessing bank data.

“ICBA continues calling on the CFPB to focus its implementation of Section 1033 on promoting data security at these third-party entities,” Romero Rainey said. “Otherwise, community banks will be faced with the impossible task of vetting the security protocols of potentially thousands of fintech companies seeking to access their customers’ data.” 

fintech 2

No Federal Agency Supervising

ICBA Assistant Vice President and Regulatory Counsel Mickey Marshall expanded on the trade group’s issues with the new open banking rule.

"ICBA's concern is that fintechs may not adequately protect customer data because they are not subject to the same oversight and supervision that banks are,” Marshall told CUToday.info. “Whereas banks and credit unions are regularly examined for their compliance with the Gramm-Leach-Bliley Act’s Privacy and Safeguards Rules by their prudential regulators, fintechs are not. Therefore, while fintechs that receive customer data pursuant to the 1033 rule are technically subject to the data security requirements of the GLBA, no federal agency is actually supervising them to ensure that they are in compliance.”

Marshall said that leaves the burden of vetting the data security protocols of all third-party recipients of customer data with the community banks that are required to provide the data.

“The rule allows banks to deny requests for customer data only if they are aware of a specific risk, such as a failure of a third party to maintain adequate data security,” Marshall said. “But how can banks be aware of all the potential risks when the universe of potential third-party data recipients includes thousands of unregulated fintech companies?”

Many Will Be Secure

Screenshot 2024-10-23 150917

Mickey Marshall

Many fintech companies will likely have adequate data security, acknowledged Marshall.

“But some will not. Unless the CFPB takes a more active role in supervising third-party companies for data security, banks will have no practical way to differentiate legitimate fintech companies from the bad actors and those with deficient data security practices,” he said.

In order to protect themselves and their customers, banks will need to spend considerable time doing due diligence to vet third parties that request customer data, asserted Marshall.

“This will be time consuming and costly,” he said. “Unfortunately, because deficient data security practices typically only become evident after a breach, by the time banks have a specific reason to deny requests for data their customers may already be victims.”

 Marshall said the time and cost of vetting third parties is made worse by the fact that the Section 1033 rule prohibits banks from charging any fee associated with the provision of data to third parties.

“That results in a situation where third parties reap all the benefit of accessing customer data, but banks bear the entire cost of providing the data and ensuring that it is handled responsibly,” he said.

Reputation Loss

There is also concern about reputation loss from a third-party breach of bank data, Marshall added.

"There is absolutely a concern that banks will be blamed if a third-party company mishandles data,” he said. “First of all, banks have an interest in preserving relationships with their customers, so they are going to feel the pressure to make customers who have been victims of fraud whole—even if the fraud was the result of a data breach at a third-party.

"Secondly, customers may not have a full understanding of the ramifications of sharing their data or where to place blame,” continued Marshall. “For example, if a customer shares their account and routing number with a third party, and that third party is compromised by a data breach, the criminals will use that information to transfer money out of the customer's bank account. With those facts, the customer is most likely to notice the breach when they look at their bank statement. So, naturally, they will first blame the bank, even though that is not where the breach that compromised their information occurred."

Section: Standard
Word Count: 984
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Fintechs-A-Big-Problem-With-Open-Banking