LOUISE: Open banking allows consumers and businesses to share the data in their bank and building society accounts. Open finance extends that same principle across the full spectrum of your financial life - mortgages, investments, pensions, insurance – allowing consumers and business to access rather more powerful and personalised services.
So, the first mistake - over-engineering - is what I'd call building a Rolex when you need a Swatch. You spend five years perfecting the mechanism, and by the time you're done, the world has changed. You can see this in markets that have produced extraordinarily detailed technical rules and technical standards that nobody has actually implemented at scale, because the commercial model didn’t work and the risk infrastructure never got built. Australia comes to mind….
The second mistake, under-engineering, is what I'd call the empty pipe problem. You build the infrastructure - the rails, the APIs, the consent mechanisms - and then you stand back and wait for the market to fill it. And, then as usage starts to build and incidents start to pile up, the market looks at the pipe and says: but where's the risk management? Where's the liability framework? Who's accountable if something goes wrong? And in the absence of answers, adoption falters.
The UK is - and I say this with enormous affection because I've spent fifteen years in this ecosystem - the UK is making the second mistake right now. We have genuinely world-class infrastructure. The open banking pipes are real, they work, and the numbers are growing. But we've built the pipe without building the safety net underneath it. The liability framework hasn't kept up. And the result is that banks and fintechs are looking at each other across a liability gap that nobody has bridged.
The EU is making a version of the first mistake but in slow motion. FiDA is architecturally ambitious and in many respects correct - but it's being designed by committee across twenty seven jurisdictions and the implementation timeline keeps stretching. By the time it's fully in force, the market it was designed to govern will look wildly different.
Are either recoverable? Yes - but the clock is running. And the investment required to deliver the open finance benefits case is looking for one thing and one thing only – where’s the best place to make a return? The UK and the EU need to make sure that the market sees them as attractive.
LOUISE: I think the open finance industry has spent a decade solving the wrong problem.
We've been obsessed with transparency tech. Consent journeys, data dashboards, disclosure notices - we've got very good at telling consumers and businesses what's happening to their data. And transparency matters. But there's a crucial gap between a consumer or business knowing that their data is being shared and being genuinely protected when something goes wrong.
I use this analogy: imagine the electricity grid. You don't need to understand how the grid works in order to plug in your kettle. You don't read a disclosure notice and tick a consent box every time you flip a switch. You trust it because the infrastructure underneath it is safe - because there are standards, monitoring, and accountability baked into the system at a level you never see. The safety is structural, not disclosed.
Open finance is still at the stage where we're handing consumers a very detailed disclosure notice and calling it protection. We're not yet at the stage where the infrastructure underneath is safe enough that the disclosure notice becomes irrelevant.
And here's the uncomfortable truth about who closes that gap. Regulators can mandate disclosure and, to an extent, legal liability. They can set up standards bodies to set standards. They can define who's responsible in a relationship between regulated parties – but, let’s face facts: legal liability is largely theoretical if the liable player has no balance sheet. What regulators cannot do - because no regulator has jurisdiction across the entire open finance chain from regulated to unregulated - is monitor every participant continuously, detect when a third-party provider's risk profile changes, and ensure that when something goes wrong, the liability lands with the party that caused the harm rather than defaulting to whoever is closest to the consumer or business. That requires infrastructure. And infrastructure is a market problem, not a regulatory problem.
The firms that understand this - that safety is structural, not disclosed - are the ones that are going to win consumers’ and business’ trust. The firms that are still treating risk management as a compliance checkbox are building on sand.
LOUISE: Most firms get it wrong in the same way. They treat compliance as a cost centre - something you minimise, something you outsource to the legal team, something you do once at onboarding and then file away. And then they wonder why their bank partners are slow to connect with them, why deals take eighteen months to close, why the people from Risk and InfoSec keeps appearing in commercial conversations uninvited.
The firms that get it right treat compliance as market infrastructure. They don't do the minimum - they build a risk score that is genuinely defensible, continuously maintained, and visible to their counterparties. And the effect is immediate and commercial. Bank relationships open faster. Procurement cycles shorten. The conversations that used to get stuck at the TPRM questionnaire - the ones that take six months and produce a seventy page document that nobody reads - those conversations become a formality rather than a roadblock.
I'll give you a concrete version of what this looks like in three years. Imagine two fintechs. They launched at the same time, roughly the same product, roughly the same market. One of them treated risk management as a tax on innovation - something to be minimised. The other built it into the foundation. Three years from now, the first firm is still spending six months closing every bank partnership. They're still answering the same onboarding questionnaire again and again and again. The second firm has a dynamic risk indicator score. Their bank partners can see their risk profile in real time. They don't fill in questionnaires anymore - they just share their risk score.
The open finance market is going to bifurcate. There will be participants who are genuinely inside a trusted network - accredited, monitored, covered - and participants who are outside it. The ones outside it will find that the ones inside it simply won't connect with them. Not because of regulation. Because of commercial logic. Banks and fintechs will choose their counterparties based on verified risk profiles, not self-reported questionnaires.
Watch the full podcast interview: https://www.youtube.com/@fintechgarden
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.