Open Finance

Samit Deb

Director of Enterprise Sales | Jul 13, 2026

Open Finance Is Coming to Malaysia. Is the Customer Experience Ready?

In Brief

Bank Negara Malaysia is rolling out a national Open Finance framework. Industry feedback on the exposure draft closed in March 2026, and the central bank’s most recent public remarks now frame implementation as phased, starting from 2027, as part of a new Financial Sector Blueprint running through 2030. It is part of a wider Southeast Asian pattern already visible in Singapore’s SGFinDex and Indonesia’s SNAP standard. For banks, this means customer financial data will soon move between institutions with consent, not just within them. The regulatory and technical questions are being actively worked through. The customer experience question, whether people will actually understand and trust what they are opting into, is being worked through far less. Banks that treat open finance as a trust-building moment, not just a compliance deadline, are the ones likely to keep the customer relationship once data becomes portable.

Open Finance Is Not a Malaysia Story. It Is a Regional One.

Southeast Asia has been building toward this for several years, market by market. Singapore’s Financial Data Exchange (SGFinDex), a joint initiative between the Monetary Authority of Singapore and GovTech, lets individuals pull financial data from participating banks, insurers, and government agencies into one consolidated view using Singpass authentication. Indonesia has taken a phased route through Bank Indonesia’s SNAP standard, moving from payment API standardisation toward a broader open finance roadmap that is expected to extend into lending, insurance, and investment data.

Malaysia is now formalising its own version. Bank Negara Malaysia released an exposure draft on Open Finance in November 2025, describing a consent-based framework for sharing customer information between data providers and data consumers in a secure, interoperable, and timely manner. Industry feedback on the draft closed on 1 March 2026. Technical development is being led by PayNet with seven banks and the Employees Provident Fund, and an early pilot had originally been targeted for mid-2026. More recently, BNM’s own leadership has framed the rollout differently: at a July 2026 industry address, the central bank governor described Open Finance as a foundation of a new Financial Sector Blueprint covering 2027 to 2030, with implementation now positioned as phased and starting from 2027. The finalised framework had not yet been published at the time of writing, so the exact phasing and start date should be treated as directional and worth reconfirming closer to publication.

The pattern across all three markets is the same: data moves with consent, in standard formats, through infrastructure built by regulators and industry together rather than bank by bank. In Malaysia’s case, the exposure draft also proposed that larger banks would onboard first, before the requirement extends to a wider set of financial service providers, a sequencing likely to carry through regardless of the exact start date. That is the shift banks need to plan for now, regardless of exactly when their market’s rollout date lands.

What Open Finance Actually Changes

Open banking, the first wave of this shift globally, was mostly about payment initiation and account information, driven by regulation like the UK’s Open Banking standard, which the Competition and Markets Authority mandated in 2017 for the country’s nine largest banks and building societies, known as the CMA9, and the EU’s PSD2. Open finance goes further. It extends the same consent-based sharing model to savings, credit, insurance, and investment data, giving a fuller picture of a customer’s financial life, not just their transactions.

For banks, that is a meaningful change in what “knowing your customer” means. A financial institution requesting a customer’s data could, for example, pull months of history from another institution to speed up a loan application, or let a customer view several credit card statements in one place instead of switching between banking apps. The upside is real: faster approvals, better-informed lending, and products built on a fuller financial picture. The complication is that the same visibility works both ways. If a bank can see more of a customer’s financial life elsewhere, other institutions can see more of that customer’s life at this bank too.

What Banks Are Actually Worried About

Conversations with banks across the region tend to circle back to a consistent set of concerns, and they are reasonable ones:

  • Data control and residency. Where is the data stored, can it leave the country, and who is accountable if something goes wrong downstream, after the data has already been shared.
  • Regulatory exposure. Consent frameworks, audit requirements, and jurisdictional data rules differ by market, and getting ahead of them takes real compliance investment.
  • Commoditisation risk. If a customer’s financial data becomes portable, the customer becomes more portable too. A bank that has spent years building a relationship on convenience or inertia may find that no longer holds once switching is a few consent taps away.
  • Integration complexity. Most banks are working with core systems that were never designed to expose structured, real-time data externally, which makes compliance a genuine engineering project, not a policy memo.

These are not hypothetical concerns. Legal analysts covering the exposure draft point out that today’s data-sharing practices, largely PDF statements sent by email or documents couriered between institutions, leave customers with little visibility or control over where their information goes, which is exactly the gap Open Finance is designed to close, and precisely the operational shift banks now have to absorb.

What Customers Are Actually Worried About

Less discussed, but just as important, is the other side of the consent screen. Customers are not automatically enthusiastic about sharing more financial data, even when the framework is designed to protect them. The concerns tend to be simpler than the regulatory ones, but no less real:

  • “What am I actually agreeing to?” Most consent flows are written for compliance, not comprehension. A legal disclosure is not the same as an explanation.
  • “What’s in it for me?” Without a visible, immediate benefit, sharing data feels like a one-sided request, even when the long-term upside (faster approvals, better rates, less paperwork) is genuine. That gap is exactly where a well-designed loyalty or rewards layer earns its keep, giving the customer something they can feel the moment they say yes, rather than a promise they have to trust will show up later.
  • “Will this be used against me?” A reasonable fear is that more visibility means more scrutiny, sharper risk pricing, or unwanted product pushing, rather than something that works in the customer’s favour.
  • “What happens if I say no?” Today, that usually means nothing. No follow-up, no explanation of what they are missing, no path back in later if their situation changes.

Any bank rolling out open finance well has to answer both sets of concerns at once, the regulator’s and the customer’s, and they are not the same conversation.

Where the Experience Breaks Today

Across most current data-sharing and consent flows, regardless of market, the pattern looks the same. A customer is handed a legal consent screen with limited context, asked to accept or decline, and then nothing happens with that decision either way. If they accept, they rarely understand what they have shared or why. If they decline, the bank rarely finds out why, and almost never follows up. The interaction closes the moment the toggle is set, either way. That is not a technology failure. It is a design failure, and it exists independently of any particular platform or vendor. It happens because consent has been built as a legal checkpoint, not a customer conversation.

What a Well-Designed Open Finance Experience Looks Like

Open finance done well flips that design failure into an engagement opportunity. A few principles worth building around:

Education before consent, not instead of it. A short, plain-language explanation of what is being shared, why, and what the customer gets in return does more for trust than any length of legal text. This does not replace the compliance disclosure, it comes before it.

Understanding “no,” not just recording it. When a customer declines to share data, that is useful information, not a dead end. Understanding whether the hesitation is about a specific data type, a trust issue, or simple inattention lets a bank address it directly, potentially through a relationship manager follow-up rather than a repeated pop-up.

Recognising that one reward model does not fit everyone. A younger, digitally native customer and a long-standing older customer are not motivated the same way. Probability-based, game-like mechanics can work well for one segment and feel patronising or confusing to another, who may respond better to a straightforward, immediate reward for completing a step.

Turning visibility into relevance, not just retention tactics. Once a bank has a fuller picture of a customer’s financial life, the useful move is a genuinely relevant offer at the right moment, not a generic upsell campaign that ignores the context the bank just gained permission to see.

Three Open Finance Customer Journeys That Get This Right

To make this concrete, here are three anonymised journey concepts that show what a thoughtfully designed open finance experience can look like in practice. These are illustrative patterns, not descriptions of any specific bank’s live programme.

The onboarding journey that explains itself. 

Instead of a bare consent toggle, a customer arriving at the open finance opt-in sees a short explainer, in plain language, on what data sharing means and what they stand to gain, such as faster approvals or a consolidated view of their finances. A brief follow-up question then checks understanding and willingness, rather than assuming silence means comprehension. If the customer is not ready to share, the flow captures why, so the bank can address the specific concern rather than simply representing the same request later.

Onboarding Journey

The engagement journey that treats segments differently. 

Two customers complete the same onboarding step, but the reward experience differs by what motivates them. One is offered a game-like, probability-based reward that adds a moment of anticipation. The other receives an immediate, guaranteed reward with no extra steps. Neither approach is “better,” they are matched to what actually drives each group to engage, rather than a single mechanic applied uniformly across the customer base.

Engagement Journey

The retention journey that rewards good financial behaviour. Rather than only reacting when a customer withdraws funds or shows signs of disengagement, a milestone-based journey rewards the absence of a negative behaviour, for instance recognising a customer for each consecutive period they maintain a balance rather than draw it down, with a meaningful reward at a specific milestone. It is a small shift, from campaigns that chase customers after they’ve already started leaving, to ones that recognise and reinforce the behaviour a bank actually wants to see more of.

Retention Journey
None of these require exotic technology. They require treating open finance as a customer relationship to design, not only a data pipe to build.

Where Open Finance and Loyalty Are Heading Next

The open finance rollout will happen whether or not any individual bank gets the experience right. What is less certain is which banks will use it to deepen customer relationships and which will simply treat it as a compliance milestone to clear.

This is also where the next phase of what Perx is building becomes relevant. Alongside the loyalty and engagement journeys banks run today, we are working on giving banks a much fuller, real-time understanding of a customer’s overall financial health, not just their activity with a single product, so that the offers and journeys built on top of open finance data are genuinely useful rather than generic. More on that soon.

If you are working through what your own open finance rollout should look like, from consent design to the engagement layer sitting on top of it, we would be glad to talk it through.

FAQs

Common questions.

What is the difference between open banking and open finance?

Open banking generally refers to sharing payment and account information, often driven by regulation such as the UK’s Open Banking standard or the EU’s PSD2. Open finance extends the same consent-based data-sharing model to a broader set of financial products, including savings, credit, insurance, and investments.

When is open finance launching in Malaysia?

Bank Negara Malaysia released an exposure draft on Open Finance in November 2025, with industry feedback closing in March 2026. An early pilot had originally been targeted for mid-2026, but as of a July 2026 industry address, BNM’s governor has framed the rollout as a phased implementation starting from 2027, as part of a new Financial Sector Blueprint covering 2027 to 2030. Larger banks are expected to onboard first.

Which other Southeast Asian markets have open finance frameworks?

Singapore’s SGFinDex, run jointly by the Monetary Authority of Singapore and GovTech, has been live for several years and covers banks, insurers, and government agencies. Indonesia’s Bank Indonesia has developed the SNAP standard for open API payments, with a broader open finance roadmap expected to extend into lending, insurance, and investment data.

Why do customers hesitate to share financial data, even with regulatory protection?

Most hesitation comes down to unclear communication rather than distrust of the regulation itself. Customers commonly want to know what exactly is being shared, what they get in return, and whether visibility could be used against them, such as through sharper pricing or unwanted product offers.

How can banks make open finance consent flows more effective?

Plain-language education before the consent screen, understanding the specific reason behind a decline rather than just recording it, and following up appropriately all help. Consent works better as an ongoing conversation than a one-time legal gate.

Samit Deb

Samit Deb is Director of Enterprise Sales at Perx Technologies in Singapore. ACA and CISA qualified, with a background at PwC and KPMG, he writes on open finance, BFSI, and AI-enabled customer engagement. Connect on LinkedIn.

Recommended for you

Loyalty Engagement Platform Built for the Mobile-first Economy
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.