Data Protection / Open Finance

Open Finance Consent and Data Sharing Readiness

BNM has proposed an open finance framework built on customer consent to share data across the financial sector. We help institutions get the consent, governance and data protection side ready while the technical teams build the pipes.

Built on BNM's November 2025 exposure draft Consent journeys and records designed PDPA and customer information rules aligned
Overview

Open Finance Readiness

What it is

A readiness engagement covering customer consent design, data sharing governance, third-party onboarding and data protection alignment for institutions preparing for open finance. It is a compliance and governance service, not API development.

Why organisations need it

BNM issued its Exposure Draft on Open Finance on 18 November 2025, with feedback closing on 1 March 2026, and industry reports point to a first batch of implementation proposed for 1 January 2027. The final framework has not been issued, so this is preparation, not compliance with final rules. The consent and governance decisions take longest and are hardest to change later.

Key features

What the engagement covers

Framework tracking

What the exposure draft proposes and what changes in the final version.

Consent design

Consent capture, scope, duration, revocation and records.

Data sharing governance

Which data, to whom, on what basis, with what oversight.

Third-party onboarding

Due diligence and contracts for data recipients.

PDPA and MCIPD alignment

Notices, permitted disclosures and breach handling.

Customer communication

Explaining data sharing to customers plainly.

Business value

What the business gets out of it

Ahead of the rules

Decisions made early rather than rushed.

Consent that holds up

Records that prove what the customer agreed.

Fewer rework cycles

Governance settled before build.

Aligned with existing law

PDPA and BNM customer information rules respected.

Board clarity

Directors see the risk and the plan.

How it works

How the engagement runs

01

Briefing

Current proposals and implications.

02

Assessment

Current consent and data sharing practices.

03

Design

Consent and governance model.

04

Documentation

Policies, notices and contracts.

05

Update

Revisions when the final framework is issued.

Deliverables

What you receive

Readiness assessment

Current position against the proposals.

Consent model

Journeys, records and revocation.

Governance framework

Roles, approvals and oversight.

Third-party due diligence pack

Checklists and contract clauses.

Board paper

Position and plan.

Who it is for

Who this is built for

Industries

Banks and Islamic banksInsurers and takaful operatorsDevelopment financial institutionsE-money issuersPayment companiesMoney services businessesFintechs

Company sizes

Licensed financial institutionsFintechs seeking participation

Departments

Digital bankingComplianceData protectionLegalProduct
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Is open finance mandatory yet?

Not yet. BNM has issued an exposure draft and the final framework has not been published. We treat this as readiness work.

When does it start?

Industry reporting points to a first batch proposed for 1 January 2027. The final date will be set by BNM.

Do you build APIs?

No. We handle consent, governance and data protection. Your technology team or vendor builds the integration.

How does the PDPA apply?

Customer consent, notices, disclosure and breach duties under the PDPA and BNM's customer information policy all apply to data sharing.

Will the work be wasted if the rules change?

Consent and governance foundations carry over. We update the documents when the final framework is issued.

Get started

Get consent and governance ready early

Tell us your institution type and open finance plans. We will scope readiness support and quote.