Today, every bank, building society, credit union and intermediary manages open finance risk on its own, using approaches which are not fit for purpose:
In practice, most banks don’t negotiate directly with each fintech – that relationship usually sits with the intermediary, and only the largest banks or directly-connected entities take the extra step of a bespoke data access agreement. But whichever layer does the vetting, the work doesn’t transfer: an aggregator that has fully vetted a fintech gets no credit for that when the next aggregator – or the next bank with its own data access agreement – vets the same fintech from scratch. The effort multiplies with every new connection, but none of it compounds.
These were built for suppliers the institution chose – an IT outsourcer, a payment processor. Open finance inverts that: the consumer chooses the third party, not the bank, but the bank still carries the regulatory accountability for what happens next. A framework built for chosen vendors doesn’t fit relationships the institution didn’t initiate and can’t control.
Due diligence happens at onboarding, then again on some fixed cycle – annually, perhaps. Between those checkpoints, a third party’s risk profile can change completely: new ownership, new sub-processors, a security lapse. The check confirms what was true months ago, not what’s true today.
Intermediaries, fintechs and technology service providers in the chain are deploying AI at the same pace as everyone else, often with governance lagging behind adoption. None of the three approaches above were built to assess that risk, let alone monitor it as it changes – so an institution can pass every existing check and still have no idea whether the third party it’s connected to is running ungoverned AI experiments.
None of these approaches were designed for the structure of open finance, where data and payments move horizontally through chains of intermediaries, fintechs, and their own sub-processors – while regulation governs vertically, within sectors and within borders. That mismatch is the gap. It isn’t a failure of any single institution’s diligence; it’s a structural feature of how the ecosystem is built.
Regulatory pressure on this gap is real but fragmented: PSD2 in the EU/UK governs access rights, Section 1033 of the Dodd-Frank Act is drafted to do something similar in the US, and Canada’s Consumer-Driven Banking Act is standing up its own regime. None of them, on their own, solve the cross-chain monitoring problem – that gap is structural, not a single jurisdiction’s rulebook falling short.
The result: fragmented visibility (no institution sees the full open finance chain), duplicated effort (the same fintech gets vetted independently by every aggregator or directly-connected bank it works with), and liability that, in reality, lands on whoever holds the customer relationship – regardless of where in the chain something actually went wrong. If that institution then tries to recover the cost from the party actually responsible, the practical picture often falls short in either direction: when the liable party is a small fintech or aggregator, its balance sheet often can’t absorb the exposure. When the liable party is instead a large, well-resourced third-party provider, recovery can mean years of litigation rather than a straightforward claim. Either way, the institution is left holding the cost more often than not – and the wider ecosystem carries the uncertainty of not knowing, in advance, how liability will actually land.
A network solves this because it changes what gets repeated and what gets shared. That’s different from bolting another point-in-time governance, risk, and compliance tool or industry consortium scheme onto the same fragmented status quo – a network only works if verification and monitoring are shared and continuous, not layered on top of processes that stay siloed.
The effect compounds: the more participants join the network, the more complete the visibility becomes for everyone already in it – the opposite of the bilateral model, where every new connection adds complexity and cost without adding shared insight.
A third party verified by Invela carries that verification into every relationship it has across the network, instead of being re-assessed from zero by each counterparty. This converts duplicated bilateral effort into a single shared baseline. Each accreditation is assessed against defined financial, operational, security and AI governance criteria – and because it is reassessed on a regular cycle, portability reflects your most recently verified status, not a one-time onboarding snapshot.
The Invela Risk Indicator activates immediately on every participant and updates as that participant’s behavior and exposure evolve, replacing a static, point-in-time snapshot with something that stays current. It draws on behavioral telemetry to produce a scored, evidence-backed profile an institution can defend to an examiner. Extending that same monitoring into sub-processor relationships and emerging risks like AI deployment is on our roadmap.
Warranty, anchored to the risk score, is being designed to give institutions a funded path to resolution when something goes wrong – rather than a costly argument about whose balance sheet absorbs the loss. Primary regulatory accountability itself will still stay with the institution with the customer relationship; what the warranty is intended to change is who ultimately funds the recovery, once it’s built.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place. Open finance, covered.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.