Framework tracking
What the exposure draft proposes and what changes in the final version.
BNM has proposed an open finance framework built on customer consent to share data across the financial sector. We help institutions get the consent, governance and data protection side ready while the technical teams build the pipes.
A readiness engagement covering customer consent design, data sharing governance, third-party onboarding and data protection alignment for institutions preparing for open finance. It is a compliance and governance service, not API development.
BNM issued its Exposure Draft on Open Finance on 18 November 2025, with feedback closing on 1 March 2026, and industry reports point to a first batch of implementation proposed for 1 January 2027. The final framework has not been issued, so this is preparation, not compliance with final rules. The consent and governance decisions take longest and are hardest to change later.
What the exposure draft proposes and what changes in the final version.
Consent capture, scope, duration, revocation and records.
Which data, to whom, on what basis, with what oversight.
Due diligence and contracts for data recipients.
Notices, permitted disclosures and breach handling.
Explaining data sharing to customers plainly.
Decisions made early rather than rushed.
Records that prove what the customer agreed.
Governance settled before build.
PDPA and BNM customer information rules respected.
Directors see the risk and the plan.
Current proposals and implications.
Current consent and data sharing practices.
Consent and governance model.
Policies, notices and contracts.
Revisions when the final framework is issued.
Current position against the proposals.
Journeys, records and revocation.
Roles, approvals and oversight.
Checklists and contract clauses.
Position and plan.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
Not yet. BNM has issued an exposure draft and the final framework has not been published. We treat this as readiness work.
Industry reporting points to a first batch proposed for 1 January 2027. The final date will be set by BNM.
No. We handle consent, governance and data protection. Your technology team or vendor builds the integration.
Customer consent, notices, disclosure and breach duties under the PDPA and BNM's customer information policy all apply to data sharing.
Consent and governance foundations carry over. We update the documents when the final framework is issued.
Tell us your institution type and open finance plans. We will scope readiness support and quote.