Continuous loan monitoring arrives just as non-bank data opens up
A digital brokerage has rebuilt its loan-comparison tool on permissioned open banking data. Four weeks from now, the first non-bank lenders start sharing consumer data under the CDR.
The CDR timetable for non-bank lenders
-
21 November 2022
Non-bank lending sector designated under the CDR. -
4 March 2025
Amendments to the CDR Rules take effect for the sector. -
13 July 2026
Product data sharing obligations apply in the non-bank lending sector, covering initial providers and large providers that qualified on or before 13 July 2025. -
9 November 2026 — next
Consumer data sharing starts for initial providers, excluding complex requests. Initial providers are lenders with combined resident loans and finance leases above $10 billion on APRA reporting. -
10 May 2027
Consumer data sharing starts for large providers, excluding complex requests.
Source: the Australian Government CDR rollout page for the non-bank lending sector (cdr.gov.au). Lenders qualifying as large providers after 13 July 2025 pick up product data obligations 12 months after qualifying and consumer data obligations 15 months after.
Open banking in the broker channel, by the numbers
Consumers who shared financial data with brokers through the NextGen platform last financial year
Broker-originated home loan applications in which open banking features
Average faster approval for applications supported by open banking data
Improvement reported in refinance approval times
Fall in assessment times reported by some major lenders
These are NextGen’s figures as reported by Broker Daily on 8 October 2026. We could not locate them in a primary NextGen release, so they are presented as that outlet’s reporting rather than independently established market fact.
Three ways CDR data can reach a broker business
Trusted adviser
CDR Rules, subrule 1.10C
- Build cost
- Lowest — mortgage brokers licensed under the NCCP Act are a named class in subrule 1.10C(2).
- Consent
- Consumer gives a TA disclosure consent before any disclosure, per subparagraph 1.10A(1)(c)(iii) and Division 4.3.
- Who carries it
- You do. Your professional and Privacy Act obligations apply instead.
Privacy safeguards: do not follow the data
CDR representative
CDR Rules, rule 1.10AA
- Build cost
- Moderate — you stay unaccredited, under written contract with an unrestricted accredited principal.
- Obligations
- Comply with the contract and the principal’s CDR policy; no outsourced service providers; delete service data on direction.
- Who carries it
- The OAIC states the CDR principal is liable for the representative’s actions when handling service data.
Privacy safeguards 2, 4, 8, 9, 11, 12, 13 apply
Full accreditation
Accredited data recipient
- Build cost
- Highest — a platform strategy rather than a broker workflow.
- Obligations
- The full CDR participant obligations apply to you directly.
- Who carries it
- You do, but inside the regime rather than outside it.
Data stays inside the CDR system
Pathway detail drawn from the OAIC’s guidance on trusted advisers and on the CDR representative model. General information only — confirm your own position with your licensee.
The takeaway for broker businesses
Detection is being automated; placement is not. The question to put to your aggregator in writing is which pathway your business is on — and who carries the liability once client data reaches your office.
UNO Now Monitors Its Clients’ Loans Continuously. Non-Bank Consumer Data Opens 9 November — and the Broker Pathway to It Drops the CDR Safeguards
A digital brokerage has rebuilt its loan-comparison tool on permissioned open banking data, turning a one-off check into continuous monitoring. Four weeks later, the first non-bank lenders start sharing consumer data. Brokers are a named class in the rules that govern who gets that data — and the easiest route in is the one that takes the data outside the regime protecting it.
Two things landed in the same fortnight, and brokers should read them together.
On 8 October, Broker Daily reported that digital brokerage UNO Home Loans had relaunched its LoanScore tool on permissioned open banking data supplied through fintech Fiskil. The practical change is small to describe and large in effect: LoanScore stops being a one-off comparison a borrower runs when they happen to think of it, and becomes a loan that is watched continuously.
Four weeks from now, on 9 November 2026, the first tranche of non-bank lenders begins sharing consumer data under the Consumer Data Right. That date comes from the Australian Government’s own CDR rollout page, not from a vendor’s roadmap.
Put the two beside each other and the question for a broker business is not whether open banking is interesting. It is this: when a client’s actual loan position can be monitored without anyone phoning them, what exactly is your annual review for?
What UNO actually built
According to Broker Daily and a release carried by Australian FinTech on 8 October, LoanScore previously compared a borrower’s existing home loan against the market, and its accuracy depended on what the borrower typed in at the time. With Fiskil’s connection in place, UNO can combine its own pricing and product data with the borrower’s real banking data, drawn with the borrower’s permission.
UNO chief executive Vincent Turner framed the borrower’s problem as a simple one: “I don’t even know if I have a good loan or not.” On the shift the data makes, Broker Daily quotes him saying, “Where it gets really interesting is not the self-reported data, it’s when you add open banking,” and, on the monitoring itself, “That’s the real win because it’s not just a LoanScore now, but it also means we continuously monitor it.”
The reported build timeline is worth noting on its own. Broker Daily says UNO’s engineers reached a working product in their own environment in under two weeks, while the company’s CDR requirements progressed in parallel. The engineering was not the constraint. The permissions were.
Broker Daily also cites figures from NextGen, which owns open banking provider Frollo: almost 120,000 consumers shared financial data with brokers through its platform last financial year; open banking features in close to one in 10 broker-originated home loan applications; applications supported by open banking data were approved an average of 11 per cent faster, with refinance approval times improving by up to 21 per cent and some major lenders reporting assessment times falling by as much as 49 per cent. Those numbers appear in that reporting of NextGen’s data rather than in a primary release we could locate, so treat them as NextGen’s figures as reported, not as independently established market fact.
The date that actually changes your client base: 9 November
Open banking has been an ADI story for years. That is why it has mattered less to brokers than the headlines suggested — a large slice of broker-placed business, and almost all of the harder-to-place business, sits with lenders that were not in the regime.
That is now changing on a published timetable. The Government’s CDR rollout page for the non-bank lending sector sets out the sequence:
- The sector was designated on 21 November 2022, and the amendments to the CDR Rules took effect on 4 March 2025.
- Product data sharing obligations applied in the non-bank lending sector from 13 July 2026.
- Consumer data sharing starts for initial providers on 9 November 2026, excluding complex requests.
- Consumer data sharing starts for large providers on 10 May 2027, excluding complex requests.
“Initial providers” is defined by size: lenders whose combined resident loans and finance leases exceed $10 billion on APRA reporting. Large providers that qualified after 13 July 2025 pick up product data obligations 12 months after qualifying and consumer data obligations 15 months after. Lenders that fall into neither tier can join voluntarily by contacting the ACCC and nominating a start date.
Read that against the composition of a typical broker book. The specialist and near-prime lenders that brokers lean on for self-employed clients, credit-impaired clients and the borrowers that The Broker Times has been tracking as refinance-blocked are mostly non-banks. From 9 November, for the largest of them, the loan your client already holds becomes data your client can direct somewhere.
Brokers are a named class in the rules. That is not the same as being protected.
Here is the part that gets skipped in the vendor conversation, and it is the part a principal broker should actually read.
Under the CDR Rules, a consumer can direct an accredited data recipient to disclose their CDR data to a “trusted adviser”. The OAIC’s guidance on the rules sets out the classes listed in subrule 1.10C(2):
- qualified accountants under the Corporations Act 2001
- legal practitioners holding a current practising certificate
- registered tax agents, BAS agents and tax (financial) advisers under the Tax Agent Services Act 2009
- financial counselling agencies
- financial advisers who are relevant providers, excluding provisional and limited-service time-share advisers
- mortgage brokers under the National Consumer Credit Protection Act 2009
Two things follow, and brokers tend to notice only the first.
The first is that brokers are in. You do not need to build accreditation to be handed CDR data this way.
The second is the catch. The OAIC’s guidance states that trusted advisers are not CDR participants and are not subject to the privacy safeguards, and that unless the adviser is also an accredited person the data “will no longer be subject to the protections and safeguards of the CDR system”. It remains subject to your professional obligations, and APP entities need to consider their Privacy Act position. In other words: the easiest pathway into the data is also the one that takes the data out of the regime that was protecting it, and lands the handling squarely on your licence and your office.
Worth noting separately, because it affects how a group structures this: the same guidance says mortgage aggregators are not a trusted adviser class, and neither are real estate agents. The named class is the broker.
Three pathways, three liability positions
The same client data can reach a broker business three ways, and they are not interchangeable. This is the framework worth taking to your licensee.
1. Trusted adviser (subrule 1.10C). Lowest build cost. The consumer gives a “TA disclosure consent” before anything is disclosed, under subparagraph 1.10A(1)(c)(iii), with the consent request following Division 4.3 of the rules — voluntary, express, informed, specific as to purpose, time limited and easily withdrawn. The data arrives outside the privacy safeguards. Your protection of it is your own.
2. CDR representative (rule 1.10AA). You stay unaccredited, but you operate under a written contract with an unrestricted accredited person — the CDR principal — and that contract must meet the minimum requirements in rule 1.10AA(2). Per the OAIC, a CDR representative must comply with Privacy Safeguards 2, 4, 8, 9, 11, 12 and 13 in relation to service data as if it were the principal; must limit use and disclosure to what the contract allows; must follow the principal’s CDR policy; must not engage outsourced service providers; and must delete service data when the principal directs, with records of deletion. The OAIC also states plainly that “the CDR principal is liable for the actions of the CDR representative when handling service data.” More obligations, more protection, and a counterparty with skin in the game.
3. Full accreditation. Heaviest lift, most control, and the only route on which the data stays inside the regime in your own hands.
The commercial point is that pathway choice is a business decision disguised as a compliance one. Pathway 1 is quick and leaves you holding the risk alone. Pathway 2 costs you process and gives you a principal who is accountable. Pathway 3 is a platform strategy, not a broker workflow.
Your aggregator’s paperwork is about to change, and here is why
Before CDR data reaches a trusted adviser, the accredited recipient has work to do under the rules. The OAIC’s guidance describes it: take reasonable steps to confirm the adviser is and remains a member of the class under subrule 1.10C(3), with re-verification about every 12 months as good practice, and a failure potentially breaching rule 7.6; tell the consumer the data will leave the CDR protections under subrule 8.11(1B); record on the consumer dashboard what was disclosed, when and to whom under subrule 7.9(3); keep records of the disclosure, the adviser’s identity and the verification steps under paragraphs 9.3(2)(eb) and (ec); and report the number of consents and advisers per class to the ACCC and the OAIC under subparagraphs 9.4(2)(f)(vi) and (vii).
There is also a limit that cuts against the obvious commercial temptation. Subrule 1.10C(4) says an accredited person must not make nominating an adviser, or consenting to disclosure, a condition of supplying goods or services, subject to the exception in subrule 1.10C(5).
Translated to a broker’s desk: expect to be asked to prove your credit licence or credit representative status, expect to be asked again roughly annually, and expect the consent screen your client sees to tell them, in terms, that their data is leaving the protected system when it comes to you. That last sentence is a client conversation. Better to have authored it than to be surprised by it.
This is a different mechanism from the credit reporting access seeker route this masthead covered on 8 October. That sits under the Privacy Act and the credit reporting framework. This sits under the CDR Rules. They are not substitutes, and a file note that confuses them is a file note that will not hold up.
The retention problem, stated honestly
Strip out the regulation and a plain commercial fact remains. A business that monitors a client’s loan continuously will know a client should move before the client does. A business that reviews annually will find out when the client calls — or when they don’t.
Brokers have a real advantage here and it is not technology. It is that the hard part of a refinance is placement, not detection: knowing which lender will take this self-employed borrower at this LVR with these last two years of returns. Detection is being automated. Placement is not.
The risk is only that detection gets automated by someone else, who then holds the trigger. The opportunity is that a broker who closes the detection gap keeps both halves.
What to review this week
- Count your non-bank exposure. Pull the share of your book sitting with non-bank lenders, and flag which of those are likely to be “initial providers” on the $10 billion test. Those are the files touched first on 9 November.
- Ask your aggregator one question in writing: which pathway are we on — trusted adviser, CDR representative, or accredited — and who carries the liability for the data once it reaches my office?
- Find out what your clients are being shown. If a consent screen tells your client their data loses CDR protection when it comes to you, read that wording before a client reads it to you.
- Check your verification trail. If an accredited recipient must confirm your class membership annually, decide now who in your business owns that and where the evidence lives.
- Separate your review triggers from your data triggers. List the events you currently review on — fixed expiry, anniversary, rate move. Then list what you would review on if you had live repayment and balance data. The gap between those two lists is your retention exposure.
- Price the pathway. Before buying a monitoring tool, establish which pathway it runs on. The cheapest integration is frequently the one that leaves the data outside the safeguards and the risk inside your licence.
What to watch next
Three dates and one unknown. 9 November 2026 for initial non-bank providers. 10 May 2027 for large providers. Twelve and 15 month tails for lenders qualifying after 13 July 2025. The unknown is whether broker-facing monitoring becomes an aggregator utility, offered as part of the CRM, or a product brokers buy separately and carry the compliance weight for themselves. That decision will be made by aggregators over the next two quarters, and brokers will have more influence on it if they ask the pathway question now than if they ask it after the integration ships.
The strategic takeaway
The open banking conversation has moved past data collection. UNO’s relaunch is not a better fact-find; it is a standing claim on the client relationship, built on the premise that the next refinance belongs to whoever noticed first. From 9 November, the lenders holding a meaningful slice of broker-placed business start supplying the raw material for exactly that.
Brokers get into that data more easily than almost anyone, because the rules name them. The work is in choosing the pathway deliberately rather than inheriting one, and in deciding whether detection is something your business does or something it waits for.
Key takeaways
- UNO Home Loans has relaunched LoanScore on permissioned open banking data supplied via Fiskil, shifting it from a one-off comparison to continuous monitoring of a borrower’s loan.
- On the Government’s published CDR timetable, consumer data sharing in the non-bank lending sector starts for initial providers on 9 November 2026, and for large providers on 10 May 2027, in both cases excluding complex requests.
- Mortgage brokers licensed under the National Consumer Credit Protection Act 2009 are one of the trusted adviser classes listed in subrule 1.10C(2) of the CDR Rules. Mortgage aggregators are not.
- The OAIC’s guidance states that trusted advisers are not CDR participants and are not subject to the privacy safeguards, so data disclosed on that pathway leaves the CDR system’s protections unless the recipient is also accredited.
- The CDR representative model under rule 1.10AA carries more obligations but keeps Privacy Safeguards 2, 4, 8, 9, 11, 12 and 13 in play for service data, and the OAIC states the CDR principal is liable for the representative’s actions in handling it.
- Pathway choice is a commercial decision as much as a compliance one. The question to put to your aggregator in writing is which pathway your business is on and who carries the liability once data reaches your office.
Broker questions answered
Does 9 November mean every non-bank lender on my panel starts sharing client data?
No. The Government’s CDR rollout page for the non-bank lending sector applies the 9 November 2026 date to “initial providers”, which it describes as lenders whose combined resident loans and finance leases exceed $10 billion on APRA reporting, and it excludes complex requests. Large providers follow on 10 May 2027. Lenders that qualified as large providers after 13 July 2025 pick up product data obligations 12 months after qualifying and consumer data obligations 15 months after. Smaller lenders can join voluntarily by contacting the ACCC.
If brokers are a trusted adviser class, can I just ask for a client’s CDR data?
Not unilaterally. On the OAIC’s guidance, the disclosure is made by an accredited data recipient at the consumer’s direction, and the consumer must first give a TA disclosure consent under subparagraph 1.10A(1)(c)(iii), with the consent request following Division 4.3 of the rules. The accredited recipient also has to take reasonable steps to confirm you are, and remain, a member of the class under subrule 1.10C(3). Your own position should be confirmed with your licensee.
What actually changes once the data is in my hands on that pathway?
The OAIC’s guidance is explicit that trusted advisers are not CDR participants and are not subject to the privacy safeguards, and that unless the adviser is also an accredited person the data will no longer be subject to the protections and safeguards of the CDR system. Your professional obligations continue to apply, and APP entities need to consider their Privacy Act position. Practically, the handling obligation sits with your business rather than with the regime.
Is this the same thing as the credit reporting access seeker route?
No. The access seeker mechanism sits under the Privacy Act and the credit reporting framework. The pathways described here sit under the Competition and Consumer (Consumer Data Right) Rules. They are separate regimes with separate consent and record-keeping requirements, and should not be documented interchangeably on a file.
Can a lender or platform require my client to nominate me to get a service?
Subrule 1.10C(4) provides that an accredited person must not make nominating an adviser, or consenting to disclosure to an adviser, a condition of supplying goods or services, subject to the exception in subrule 1.10C(5). If you are shown a flow that appears to do this, it is worth raising with your licensee before it reaches clients.
Should my brokerage become accredited?
For most broker businesses that is a platform-scale decision rather than a workflow one, and this article does not recommend a pathway. The useful first step is establishing which pathway any monitoring tool you are considering actually runs on, and who holds the liability for the data under it. That is a question for your licensee and, where the contracts are material, your own legal adviser.
Breaking news for modern brokers
Lender policy shifts, regulator moves and the market data that changes what you can place — written for brokers, twice a day.
CDR pathway explorer and readiness check
Compare the three ways client data can reach a broker business, then work through what to settle before 9 November. Nothing you tick is recorded or sent anywhere.
Part one
Same data, three liability positions
Trusted adviser
CDR Rules — subrule 1.10C
- Who qualifies
- Mortgage brokers licensed under the National Consumer Credit Protection Act 2009 are a named class in subrule 1.10C(2). On the OAIC’s guidance, mortgage aggregators and real estate agents are not.
- Build cost
- Lowest of the three. No accreditation to obtain and no principal contract to negotiate.
- Consent
- The consumer gives a TA disclosure consent before any disclosure, per subparagraph 1.10A(1)(c)(iii), with the request following Division 4.3 — voluntary, express, informed, specific as to purpose, time limited and easily withdrawn.
- Verification
- The accredited recipient must take reasonable steps to confirm you are and remain in the class under subrule 1.10C(3). The OAIC suggests re-verifying about every 12 months as good practice.
Privacy safeguards do not follow the data. The OAIC’s guidance states trusted advisers are not CDR participants and are not subject to the privacy safeguards, and that unless the adviser is also accredited the data will no longer be subject to the protections and safeguards of the CDR system. Your professional obligations and Privacy Act position apply instead.
“If we receive client data as a trusted adviser, what is our documented handling, storage and deletion standard for it — and who signs off that it meets our Privacy Act obligations?”
CDR representative
CDR Rules — rule 1.10AA
- Who qualifies
- An unaccredited person providing CDR goods or services directly to a consumer under a written contract with an unrestricted accredited person, the CDR principal.
- Build cost
- Moderate. The contract must meet the minimum requirements in rule 1.10AA(2), and you take on operating obligations under it.
- Your obligations
- Limit use and disclosure of service data to what the contract allows; follow the principal’s CDR policy; do not engage outsourced service providers; delete service data when the principal directs and provide records of deletion.
- Liability
- The OAIC states the CDR principal is liable for the actions of the CDR representative when handling service data.
Privacy safeguards partly follow the data. Per the OAIC, a CDR representative must comply with Privacy Safeguards 2, 4, 8, 9, 11, 12 and 13 in relation to service data as if it were the CDR principal. More process than the trusted adviser route, and a counterparty that is accountable alongside you.
“If we operate as a CDR representative, who is the principal, what does the rule 1.10AA(2) contract oblige us to do operationally, and what triggers a deletion direction?”
Full accreditation
Accredited data recipient
- Who qualifies
- A business that obtains accreditation in its own right and becomes a CDR participant.
- Build cost
- Highest of the three. In practice this is a platform or lender-scale decision rather than a broker workflow.
- Your obligations
- The full participant obligations apply to you directly, including the disclosure, dashboard and record-keeping duties that an accredited recipient owes when it passes data to a trusted adviser.
- Liability
- Yours, but exercised inside the regime rather than outside it.
Data stays inside the CDR system. The trade is the heaviest compliance build for the most control over the data and the client relationship built on it.
“Are we building a product other brokers will use, or a workflow our own brokers will use? Only the first makes this arithmetic work.”
Part two
Six things to settle before 9 November
0 of 6
Start with the pathway question. Every other item reads differently depending on the answer.
Detection is being automated. Placement is not.
The hard part of a refinance is still knowing which lender takes this borrower on these numbers. The risk is only that someone else notices the trigger first.
General information only, drawn from the OAIC’s published guidance on the CDR Rules and the Australian Government’s CDR rollout material. It is not legal or compliance advice and does not establish your obligations — confirm your position with your licensee and, where contracts are material, your own legal adviser.
Disclaimer: This article is for general information and professional development purposes only. It does not constitute legal, compliance, or financial advice. Brokers should consult their aggregator’s compliance team and, where required, seek independent legal advice regarding their obligations under the National Consumer Credit Protection Act 2009 and ASIC’s responsible lending guidelines.
