Open Banking
Preparing CIBC for Canada’s emerging Open Banking framework, through consent and funding experiences.
Here’s how it came together
Overview
Challenge
Opportunity
Date of Project
Role
Responsibilities
- Use-case research and prioritization
- Product and technology roadmap
- Consent and data-sharing journeys
- Account-funding requirements
- Rollout and frontline education
Tools
- BRDs and PRDs
- FDX-aligned API requirements
- Knowledge Central
- Workplace
- Use cases assessed
- 150+
- Prioritized for FY25 and FY26
- 33
- Business teams engaged
- 8+
- Integrations and partnerships supported
- 15+
What is Open Banking?
Open Banking, called consumer-driven banking in Canada, lets a client authorize their bank to share selected financial data with an approved app, or bring data from another institution into their bank, through secure APIs instead of shared passwords.
In 2024 the framework was still being written. The federal budget set the direction, consultations were under way and FCAC was expected to oversee it. Oversight has since moved to the Bank of Canada, under Bill C-15 in 2026, and the regulated framework wasn’t live during this project.
Compliance first, opportunity second
Data Out is the obligation: CIBC as the data holder, sharing a client’s data with an approved third party once the client consents. Data In is the opportunity: with permission, bringing a client’s outside accounts into CIBC’s own experiences.
Since the bank had to build the sharing foundation anyway, the real question wasn’t how to comply. It was what becomes possible once those capabilities exist.
Data Out · the obligation
An approved app asks for access
The client signs in with CIBC and consents
CIBC shares only the data they chose
Data In · the opportunity
A CIBC experience offers something useful
The client connects an outside account and consents
CIBC uses that data to fund, advise or decide
Reciprocity: a bank has to offer Data Out before it can benefit from Data In.
From 150 ideas to a portfolio a bank could fund
I researched 150+ use cases from markets further along, including the UK, Australia, Brazil and India, into a use-case master: account verification, account funding, aggregation, credit decisions, personalization and payments.
Through roadshows with 8+ business teams, scored on client value, strategic fit, feasibility, regulatory and data constraints and business value, we landed on 33 priorities for FY25 and FY26, with money-in and lending as the main themes.
150+
use cases assessed from the UK, Australia, Brazil, India and others
33
use cases prioritized for FY25 and FY26
Narrowed in prioritization roadshows across 8+ business teams.
- Account funding
- Lending
- Verification
- Personalization
- Payments, later
Sequence by what each idea depends on
An idea can be attractive and still be wrong to build first if it needs consent, API, partner or data foundations that don’t exist yet. So the roadmap ran along a maturity curve, starting with one-time reads. Then recurring reads, then payments, then a wider open-finance ecosystem.
The priorities moved into BRDs, requirements and early cost estimates for the technology build.
Stage 1
One-time read
Account verification, account funding
Stage 2
Recurring read
Insights, personalization, lending decisions
Stage 3
Write and payments
Payment initiation, request-to-pay
Stage 4
Open data ecosystem
Investments, insurance and beyond
Foundations first, one use case at a time
Option A
One all-encompassing business case
A single big approval.
Too abstract to fund while the rules were still moving.
Option B
Start with the flashiest use cases
Exciting demos.
They depended on foundations that didn’t exist yet.
Option C
Use case by use case, foundations first
ChosenNear-term value in account funding that also builds the consent, API and partner groundwork later use cases need.
Slower to show the whole vision.
Consent is a product, not a checkbox
Online banking normally asks one question: are you the account holder? Open Banking adds another: what are you letting another app see, from which accounts, and for how long?
I worked on the Data Out consent and client journey: a CIBC-controlled sign-in, plain-language scopes, account-by-account choice and a place to review or revoke connections later.
1 · Context
2 · Who and why
3 · Sign in with CIBC
4 · Choose
5 · Confirm
6 · Stay in control
Account funding: value now, foundations for later
Account funding was the strongest near-term case. Interac Request Money launched for FastApp, CIBC’s digital account opening, so new clients could pull money in on rails they already used. I worked on the product side: prioritizing the use case and coordinating the journey, requirements and rollout.
For EFT through Flinks, I worked on the product definition: UX research, requirements and the PRD, vendor and dependency coordination, the business case and AML requirements. It was built as a shared service for Investor’s Edge and Simplii, and used screen scraping as a stepping stone toward regulated Data In, not as Open Banking itself.
FastApp completed
A new digital account
Choose a funding method
Client consent
Pick their other bank
Account verified
EFT started
Built as a shared service, with Investor’s Edge and Simplii as consumers.
A concept for newcomers with thin credit files
I contributed to a credit-decisioning proof of concept for newcomers. With consent, external transaction data could complement, not replace, CIBC’s usual credit process, so someone with a short Canadian credit history but strong cash flow could see which cards might fit. The plan included client testing of a prototype.
Sees a better-fit card offer
Links outside accounts, with consent
Transactions categorized
Pre-qualification
Normal CIBC application and checks
Clients and staff had to understand it first
In 2024 most people had never heard of Open Banking. I ran rollout communications: 12 newsletters, with newsletter readership up 48% from January to November 2024; 45 internal posts with 3,900+ impressions; and 6 communication intakes for the Contact Centre, Banking Centres, Fraud Management, the Open Banking microsite and Knowledge Central.
Rollout and education materials reached 2,000+ employees and customers.
What it changed
- 150+ use cases assessed and 33 prioritized across 8+ business teams
- A product and technology roadmap, with priorities moved into BRDs, requirements and estimates
- Interac Request Money launched for FastApp; EFT through Flinks taken through UX research, requirements, the PRD and AML review
- 15+ fintech and ecosystem integrations and partnerships supported
- Rollout and education reaching 2,000+ employees and customers
What did I learn?
Key takeaways
- Standards define the rails. Product decides how they become something clients use.
- Sequence by dependency, not by how exciting an idea sounds.
- Consent works when clients see the value first, then the permissions.
Next time
- Define the scoring and dependency logic earlier, to shorten the debate.
- Bring frontline teams in sooner; they field the first questions.
Next project
Investor’s Edge
CIBC · 2024–25