Consent Is the New Revenue Line in Open Finance
Banks are losing measurable revenue to weak permission capture — while consumers signal they'll walk over how their data is handled. The consent screen just became a P&L item.
The Brief
For years, consent in financial data sharing was treated as a legal checkbox. New industry research — Mastercard and FT Longitude's State of Open Finance 2026, a survey of 8,000 consumers and 300 businesses — puts a number on that mistake: firms estimate they've forgone roughly 4.6% of annual revenue through gaps in customer data permissions. With US open-banking regulation stalled in court and consumers openly willing to switch providers, consent capture has quietly become a competitive weapon rather than a compliance chore.
Somewhere between the terms-of-service page and the product roadmap, a strange thing happened to the consent screen: it started earning money. Or, more precisely, institutions started noticing how much money it was quietly losing them. The permission a customer grants — or declines to grant — over their financial data now determines whether a lender can verify income in seconds, whether a new account actually gets funded, and whether a bank's AI ambitions have anything trustworthy to run on.
That reframing is the most interesting thread running through the current wave of open-finance research and practice. The headline numbers are about growth. The mechanism underneath them is about permission.
The 4.6% problem
The clearest evidence that consent has become a commercial variable comes from Mastercard's research with FT Longitude, which surveyed businesses across the US, Europe and Australia. Executives in that study estimate they have missed out on around 4.6% of annual revenue because of shortcomings in how customer data permissions were captured.
Read that carefully: this isn't fines, and it isn't churn in the abstract. It's revenue that institutions believe they could have earned — from faster lending decisions, funded accounts, personalised offers, smoother payments — but couldn't, because the customer never granted (or was never persuasively asked for) access to the data those services depend on. A clunky consent flow, a vague explanation of data use, a permission that silently expires: each one is a small leak, and the leaks compound.
The same research finds the upside is equally concrete. Three in four executives report a direct revenue uplift from their open-finance initiatives. The gap between the winners and the leakers isn't primarily technology — API connectivity is increasingly table stakes — it's the quality of the permission layer sitting on top of it.
Loyalty is now conditional
The other half of the equation is the customer, and the data says the customer is restless. In the same study, 76% of consumers say they're ready to switch financial providers for better digital money-management features — a striking figure in an industry that has historically relied on inertia as its most reliable retention strategy.
Crucially, willingness to share data isn't the bottleneck. When the value exchange is obvious, consumers lean in: 82% say they would share their data if it simplified a loan or mortgage journey. Nobody enjoys assembling payslips and PDF statements; linking an account and letting income verification happen in real time is a trade most people will happily make. The resistance appears when the ask is vague — when a customer can't see what the data is for, who touches it, or what they get in return.
That points to a subtle strategic shift. The old question was "how do we get customers to consent?" The better question is "what are we offering that makes consent the obviously rational choice?" Consent, framed this way, is a measure of whether the product's value proposition actually landed.
Consent isn't the paperwork around the product. In open finance, it is the product's front door — and the conversion rate on that door is a revenue metric. — Fintech360hub analysis
Regulation stalled; the market didn't
All of this is playing out against a US regulatory backdrop that is, to put it politely, unresolved. The CFPB's Section 1033 rule — the American attempt to formalise open banking, finalised in October 2024 with first compliance dates of April 2026 — has been enjoined by a federal court and is being rewritten by the agency itself, which now argues the original version overstepped its authority.
Among the questions reopened in that rulemaking is whether banks may charge third parties for data access at all — a fight given real-world stakes when large institutions began signalling they would levy fees on data aggregators. The original rule prohibited such fees; its successor may not. For anyone building open-finance products in the US, the binding constraint right now is not the rulebook but the live legal state of it.
Here's the paradox: the regulatory vacuum has made the commercial logic stronger, not weaker. In Europe and Australia, data-sharing rights are mandated, so participation is a floor. In the US, participation is a choice — which means the institutions investing in consent-first data experiences are doing it because the numbers work, not because a regulator told them to. When 76% of your customers say they'd move for a better digital experience, waiting for legal certainty is its own kind of risk.
What good consent design actually looks like
The institutions getting this right share a pattern: they attach the permission ask to a moment of obvious, immediate value, rather than front-loading it as an abstract data grab at onboarding.
Income and account verification in lending is the canonical example — replace document uploads with a linked account, and the customer experiences the consent as a shortcut, not a concession. Deposit and payment switching is another: the genuinely painful part of changing banks has never been opening the account, it's rewiring the direct deposits, subscriptions and billers attached to the old one. Banks such as Citizens have built open-finance tooling around exactly that moment, using permissioned connectivity to automate the migration — turning the industry's biggest switching barrier into an acquisition feature.
Three design principles fall out of the successful cases. First, specificity: ask for the narrowest permission that unlocks the value, and say plainly what it's for. Second, reciprocity: the benefit should arrive within the same session as the consent, not in some future personalisation roadmap. Third, revocability: customers who know they can see and withdraw permissions grant them more readily — control, counterintuitively, increases sharing.
The AI stakes make this compound
If consent were only about today's use cases, it would be a meaningful optimisation. What makes it strategic is what's coming next: every serious AI ambition in banking — hyper-personalisation, real-time financial guidance, agentic tools that act on a customer's behalf — runs on continuously accessible, customer-permissioned data.
An AI copilot that can see one account is a gimmick; one that can see a customer's whole financial life is a product. The difference between those two outcomes is not model quality. It is the accumulated stock of trust and granted permissions an institution has built — which means every consent flow shipped today is also infrastructure for the AI products of the next five years.
That is the real argument for treating consent as a revenue line. The 4.6% figure prices what weak permission capture costs now. It says nothing about what it will cost an institution to arrive in the agentic era with customers who never learned to trust it with their data. That number is likely to be much larger — and much harder to win back.
Key takeaways
- Consent is a commercial lever, not a compliance chore. Firms estimate ~4.6% of annual revenue lost to gaps in data permissions, per Mastercard and FT Longitude's 2026 research.
- Customers will share — for visible value. 82% would share data to simplify loan and mortgage journeys; resistance comes from vague asks, not data sharing itself.
- Inertia is no longer a retention strategy. With 76% of consumers ready to switch for better digital money management, the consent experience is part of the competitive product.
- Don't wait for the rulebook. With the CFPB's Section 1033 rule enjoined and being rewritten, US open finance is market-led — the economics, not the mandate, justify investment.
- Every permission granted today funds tomorrow's AI. Agentic and personalised finance run on permissioned data; consent infrastructure built now compounds into future product capability.
