
Open finance is moving from a policy idea towards a practical programme for UK lending. The FCA's roadmap puts SME credit among the first use cases to explore in 2026, while its latest credit-market speech says data, open finance and open banking will be central to how consumers and businesses navigate credit.
For credit brokers, this is not a new rulebook and it is not a licence to collect every available data point. It is an early warning that the customer journey may soon depend more heavily on data shared between banks, accounting platforms, lenders, brokers and technology providers.
The firms that prepare well will not begin with an API. They will begin with responsibility: what data is needed, what the customer understands, how the information affects a decision, who can challenge it and what happens when the data is wrong or unavailable.
The FCA published its open finance roadmap in April 2026. It describes a path from collaboration and experiments in 2026, through framework design in 2027, to wider delivery between 2028 and 2030.
The first priorities include lending to small and medium-sized enterprises and improving access to mortgages. The FCA says open finance could give consumers and SMEs more control over their financial data, support more personalised services and strengthen competition. It also says the system should develop in a secure, trusted and proportionate way.
In a later speech on the future of the credit market, the FCA connected that programme with faster digital journeys, better data and more targeted supervision. The message was not that more data is automatically better. It was that the right data, connected to outcomes, can show how people use credit and where risks are emerging.
That distinction matters. A data-rich journey can still produce a poor decision, confuse a customer or exclude somebody unfairly.
The roadmap does not replace the FCA Handbook, the Consumer Duty, data-protection law or a firm's existing permissions. It also does not settle the detailed rules for a future open-finance scheme.
The Data (Use and Access) Act 2025 provides powers that can support Smart Data schemes and changes parts of the UK's data-protection framework. Government guidance is equally clear that the Act does not replace the UK GDPR or the Data Protection Act 2018.
A broker considering a new data service should therefore separate three questions:
Calling a service "open finance" does not answer perimeter, privacy, Consumer Duty or contractual questions. Those depend on the activity, the data, the parties and how the output is used.
Open finance could change more than underwriting. A broker might use consented account or business data to pre-populate an application, match an SME with a suitable lender panel, verify income or cash flow, identify affordability pressure, reduce repeated form filling or refer a declined applicant to a more appropriate provider.
Each use case can improve speed and access. Each can also create a new control point.
If a customer grants access but does not understand the purpose, the consent journey may be technically complete and practically weak. If a matching tool relies on incomplete data, a fast result may still be the wrong result. If a supplier changes its model, the broker's customer outcome can change without the broker changing a line of its own code.
That is why readiness is an operating-model exercise, not simply a technology project.
Write down the customer problem and the decision the data will support. A request for transaction history, accounting information or credit data should be traceable to a specific purpose. "It may be useful later" is not a strong control.
For each field or dataset, identify its source, age, coverage, limitations and owner. The same discipline that makes CCR009 reporting reproducible is useful here: the business should be able to explain where a number came from and how it was transformed.
A customer should be able to tell what information is being accessed, why it is needed, who will receive it and what may happen as a result. That explanation belongs in the journey, not only in a privacy notice few people will read at the decision point.
Test the language with real users, including people under financial pressure or with accessibility needs. A short journey is not automatically a clear one.
Credit journeys already involve multiple parties. Open finance may add account-information providers, data aggregators, analytics vendors and automated matching tools.
Create a responsibility map covering data collection, validation, matching, customer communication, complaints, incident response and outcome monitoring. Contracts should support the information flow needed to perform those responsibilities. A supplier agreement cannot remove the broker's responsibility for the parts of the journey it controls or influences.
More current data can improve a decision, but it can also amplify errors or create false confidence. Firms should test how the journey treats missing accounts, irregular income, cash businesses, new businesses, shared finances and customers whose data does not fit the expected pattern.
Record when data is rejected, corrected or overridden. Compare outcomes across relevant customer groups and channels. The objective is not to promise that every applicant will receive credit; it is to understand whether the method produces explainable, consistent and supportable outcomes.
Government guidance on changes to automated decision-making under the Data (Use and Access) Act highlights safeguards such as information, representations, challenge and human intervention for significant solely automated decisions. The exact legal analysis will depend on the use case, but the operational lesson is wider.
A customer journey should not become a locked door when the data connection fails or the result looks wrong. Define when manual review is available, who can perform it, what evidence they receive and how the customer is told about the next step.
Technical measures matter, but system availability does not show whether customers received good outcomes. Monitor drop-off at the consent stage, failed data connections, unmatched applications, complaints, overrides, repeat attempts, referral outcomes and differences between suppliers or lead sources.
Link those measures to action. A dashboard that records failure without changing the journey is an archive, not a control.
The answers should be tested against the actual journey, not accepted as a sales-deck assurance.
Open finance has real potential to make credit applications faster, reduce repeated data entry and help lenders and brokers understand customers and SMEs more accurately. The FCA is also still gathering evidence and designing the future framework.
The sensible response is neither to wait for every rule nor to build as though the rules already exist. Credit brokers can prepare now by mapping data flows, clarifying responsibilities, testing explanations, creating fallback routes and connecting monitoring to customer outcomes.
Authorised Compliance helps credit brokers review new customer journeys, supplier arrangements, permissions and Consumer Duty controls before technology becomes embedded in the business model.
This article provides general compliance information and is not legal advice. The FCA's open finance roadmap is a policy programme, and detailed future requirements may change as the framework develops.
Sources:

I’m Will Hurst, and I bring 20+ years of hands-on experience across credit broking, AR/IAR oversight, lender relationships and regulated finance operations.
Learn more about my practical, FCA-focused approach