Pipelines

Open Banking vs bank statement scraping: what changed for brokers

By Tumai Meroiti · 26 August 2026

Listen instead

Narration not recorded yet

Screen scraping asks a client to hand over internet banking credentials so a third party can log in and pull statements. Open Banking under the Consumer Data Right does the same job through a consented data feed, with no password shared. Both still operate. Government has signalled a ban on scraping but has not set a date.

TL;DR

  • Screen scraping needs the client's banking password. Open Banking under the CDR does not.
  • The 2022 CDR statutory review recommended banning screen scraping where the CDR is a viable alternative. No commencement date has been announced.
  • Mortgage brokers are a named trusted adviser class in the CDR Rules, but CDR protections stop once the data reaches you.
  • Broker use of open banking has grown sharply, while roughly 30 per cent of consent authorisations still fail at the bank.
  • Scraping persists because lenders still want PDF statements and CDR coverage has gaps.
  • CDR expands to non-bank lenders with consumer data sharing from 9 November 2026 and 10 May 2027.

The two methods, plainly

Screen scraping, which Treasury also calls digital data capture, works by the client giving a third party their internet banking username and password. The third party logs in as the client and reads the screens. Treasury's August 2023 discussion paper describes this form of the practice as particularly prevalent in financial services, used by some banks, lenders, mortgage brokers, financial advisers and accounting services, and as inconsistent with best practice cyber security advice.

Open Banking is the banking sector of the Consumer Data Right. The client authorises the transfer at their own bank, using their own bank's login, and the data moves to an accredited data recipient through an interface built for the purpose. No credential changes hands with the broker or the vendor. The consent has a defined scope and an expiry, and the client can see it and withdraw it from a dashboard.

From where a broker sits, the two look similar at the end. You get transaction data and something that functions as a statement. The difference is upstream, in what the client had to surrender, and downstream, in what rules attach to the data afterwards.

What actually changed

The 2022 Statutory Review of the CDR, conducted by Elizabeth Kelly PSM, made the recommendation that set the direction. Recommendation 2.1 stated that screen scraping should be banned in the near future in sectors where the CDR is a viable alternative, and that the Government should clearly signal when and how the implementation of the ban would take effect, to provide certainty and adequate time for businesses to transition.

The Government's response in June 2023 said it would consult on policy options to regulate screen scraping, commencing in the banking sector. Treasury released that discussion paper in August 2023. The consultation ran to 25 October 2023 and drew 44 submissions.

In the CDR reset announced in 2025, the Assistant Treasurer asked Treasury to advise on a way forward for a full and formal ban on screen scraping. A commencement date was not announced. So the accurate position for a broker today is that screen scraping remains lawful, remains in use, and is on notice with no date attached.

The rules moved while everyone was watching the ban

Amending rules that commenced on 12 November 2024 allowed consents to be bundled and simplified the requirements for asking for consent. That is the change brokers noticed, because it shortened the screens a client has to work through.

Rules commencing in early March 2025 extend the CDR to non-bank lenders and narrow the scope of CDR data for the banking and non-bank lending sectors. In the non-bank lending sector, product data sharing obligations apply from 13 July 2026, with consumer data sharing from 9 November 2026 for initial providers and from 10 May 2027 for large providers.

For a broker writing prime bank deals, the non-bank expansion is background. For anyone writing specialist, near prime or asset finance where the client already holds facilities with non-bank lenders, those two 2026 and 2027 dates are the ones that change what you can actually pull through the CDR rather than chase by email.

Where a broker sits in the Consumer Data Right

Almost no individual brokers are accredited data recipients, and there is no need to be. There are three practical routes to CDR data. Your platform provider holds the accreditation and you consume its output. You act as a CDR representative of an accredited person. Or the client nominates you as a trusted adviser and consents to the accredited data recipient disclosing the data to you.

Mortgage brokers are one of the classes of trusted adviser named in the CDR Rules, alongside qualified accountants, lawyers holding practising certificates, tax agents, BAS agents and tax advisers, financial counselling agencies, and financial advisers.

The obligations on that route sit mostly with the accredited data recipient rather than with you. It has to obtain a specific trusted adviser disclosure consent, take reasonable steps to confirm you belong to the class, keep records of the steps it took, show the disclosure on the consumer's dashboard, and it cannot make the disclosure a condition of supplying its service.

The protections stop at your door

This is the part most worth understanding and the part most often skipped in vendor material. The OAIC's guidance is explicit that once CDR data is disclosed to a trusted adviser, the data is no longer subject to the protections and safeguards of the CDR system, unless that adviser is also an accredited person.

That does not mean the data is unprotected. It means the protection changes hands. From the moment it lands with you, it is personal information you hold, governed by the Privacy Act, your own professional obligations and your licensee's requirements, rather than by the CDR privacy safeguards.

The practical error to avoid is treating CDR sourced data as inherently safer to store because it arrived through a regulated pipe. It arrived safely. What happens to it in your inbox, your CRM and your Dropbox folder is entirely on you, and it is now twelve months of a client's transaction history rather than three PDF statements.

How much of the market has actually moved

Frollo's State of Open Banking 2025, reported in August 2025, put broker use of its open banking platform at more than double the previous twelve months, with close to 3,000 brokers onboarded, described as more than 13 per cent of the national broker population, and 32,000 Australians sharing data with their broker. Consent requests for home loans rose sevenfold to more than 6,200 in July 2025.

The same report carries the figure brokers actually feel. Nearly 30 per cent of consent authorisations fail at the bank authentication step, with some major banks recording failure rates above 31 per cent. Of more than 11,000 Frollo users who gave feedback, more than 10,000 identified failed consent as the primary issue, and 88 per cent of failures were attributed to login problems, one time passcode problems or technical errors. These are one provider's figures on its own traffic, not an industry measurement.

Movement on the lender side started earlier. Australian Broker reported in November 2022 that Frollo had disabled screen scraping for the four major banks and then for twenty more institutions, and cited loan completion rates of around 50 per cent with screen scraping against more than 70 per cent with CDR data. The ACCC's Paul Franklin was quoted saying data recipients had reported that consumer take up of the CDR was substantially more successful than screen scraping.

Why scraping has not died

Lenders still want documents. A clean categorised transaction feed does not automatically produce the artefact a credit assessor expects in the file, and some lenders still specify PDF statements or an interim statement in a particular format. Until the lender's own requirement changes, a broker ends up sourcing both.

Coverage is the second reason. The CDR reaches accounts held with data holders inside its scope. Complex business structures, some product types and non-bank facilities have been harder to capture, which is part of what the non-bank lender expansion is designed to close.

The third reason is the consent failure rate above. When close to a third of authorisations fail on the first attempt and the client is on the phone, a broker under deadline reaches for whatever completes. That is not a compliance argument, it is a workflow reality, and it is the thing that will actually determine adoption in your business.

The ePayments Code point that gets overstated

You will hear it said flatly that a client who screen scrapes forfeits their protection against unauthorised transactions. That is stronger than the source supports, and getting it wrong in front of a client is avoidable.

What Treasury's discussion paper says is that consumers who share login details through screen scraping may lose protections available under the ePayments Code. The Code operates so that where a consumer discloses a passcode, and the subscribing entity, usually the bank, can prove on the balance of probability that the consumer contributed to a loss by breaching the passcode security requirements, the bank is not required to indemnify that loss. Treasury's own footnote is careful to add that mere use of a screen scraper and disclosure of a passcode does not necessarily lead to liability, because the bank has to prove the disclosure contributed to the unauthorised transaction. ASIC has said it had not seen evidence to date that use of screen scraping services contributed to loss from unauthorised transactions. Subscription to the Code is also currently voluntary, although the Government has accepted recommendations to mandate it.

The accurate version is narrower and still worth saying out loud. Sharing your internet banking password is contrary to most banks' terms and conditions, it runs against the security advice the client gets from their own bank and from Scamwatch, and it weakens their position if something later goes wrong. That is a complete and defensible reason to prefer the CDR route without overclaiming.

What to check before you change your process

Identify which accredited data recipient actually sits behind your tool, and on what basis the data reaches you. Whether you are consuming an accredited recipient's output, acting as a CDR representative, or receiving a trusted adviser disclosure changes what obligations attach and who is answerable for the consent.

Confirm the output is accepted by the lenders you actually submit to. Ask your business development managers rather than the vendor, and ask about the specific document, not the concept.

Decide what happens to the data after settlement. CDR consents expire and can be withdrawn. The copy sitting in your file does not expire on its own, and your retention policy is now the control that matters.

Have a fallback for a failed consent that is not asking for the password. Given the reported failure rates, you will need one, and deciding it in advance is better than improvising it while a client waits.

Update your privacy collection notice and credit guide language. If you are collecting transaction level data across multiple accounts, the client should be able to read that somewhere other than a consent screen they clicked through in seven minutes.

Finally, check whether your aggregator's platform already includes CDR access before subscribing separately. Finance OS publishes this article and is building a comparison product for broker software. It has not tested any of the tools named here, and nothing above is a recommendation of one over another.

Common questions

Is screen scraping illegal in Australia?
Not currently. Treasury's discussion paper noted there is no specific regulation of screen scraping, while identifying cyber security and consumer protection concerns with it. The 2022 CDR statutory review recommended banning it where the CDR is a viable alternative, and the Government has asked Treasury to advise on a way forward for a full and formal ban. No commencement date has been announced, so it remains lawful and widely used.
Do I need to be accredited to use open banking data with clients?
No. Most brokers access CDR data through a platform whose provider holds the accreditation, as a CDR representative of an accredited person, or as a trusted adviser nominated by the client. Mortgage brokers are one of the trusted adviser classes named in the CDR Rules. The accreditation burden and most of the associated obligations sit with the accredited data recipient.
Does open banking data satisfy a lender's verification requirements?
It depends on the lender, and the answer changes. Major lenders have enabled CDR data through broker lodgement platforms, but some lenders still ask for PDF statements or an interim statement in a specific format for particular scenarios. Check with each lender's business development manager for the deal types you write rather than assuming a general acceptance.
What happens to CDR data once the consent expires or the client withdraws it?
Obligations to delete or de-identify the data sit with the accredited data recipient under the CDR rules. They do not automatically reach a copy that has already been disclosed to you as a trusted adviser, because the OAIC states that CDR protections cease to apply once the data is disclosed to a trusted adviser who is not separately accredited. Your copy is governed by the Privacy Act and your own retention policy.
Will I be able to pull non-bank lender data through the CDR?
Yes, on a staged basis. Rules commencing in March 2025 extend the CDR to non-bank lenders. Product data sharing obligations apply from 13 July 2026, with consumer data sharing from 9 November 2026 for initial providers and from 10 May 2027 for large providers. Until then, non-bank facilities generally still need to be evidenced the old way.

Sources

Everything this article relies on. If a claim above is not traceable to something here, treat it as opinion and tell us.

  1. Treasury discussion paper, Screen scraping: policy and regulatory implications, August 2023
  2. Treasury consultation page for the screen scraping review, including submission count and closing date
  3. OAIC guidance on trusted advisers in the Consumer Data Right system
  4. Consumer Data Right rollout in the non-bank lenders sector
  5. MinterEllison technical update on CDR expansion to non-bank lenders and the amended timelines
  6. The Adviser, broker use of open banking doubles but CDR consent issues persist, August 2025, reporting Frollo's State of Open Banking 2025
  7. Broker Daily, lenders shun screen scraping as open banking takes off, November 2022
  8. The Adviser, how the November 2024 CDR consent changes affect brokers
  9. ASIC, the ePayments Code
  10. Open Banking Expo, Australian government announces CDR reset and asks Treasury to advise on a screen scraping ban