Open Banking Isn't a Tax. It's an Infrastructure Play. — Moroku
Perspective · Open Banking

Open Banking Isn't a Tax.
It's an Infrastructure Play.

Three things collided this July. They point at the same fix — and almost nobody is treating it as one problem.

Moroku July 2026 10 min read
The Setup

Three Collisions

The first is affordability

A 20% deposit now takes around five years to save nationally, and 7.7 years in Sydney. Every capital city sits above the 30%-of-income mortgage stress threshold for entry-priced houses. Meanwhile the large lenders and banks have concentrated on the middle of the risk curve, and if you don't fit, you get a “No”, with nothing attached that tells you how to turn it into a “Yes”.

The people best placed to help are outnumbered. 15.9 million Australians have unmet financial advice needs. There are 15,429 advisers. Only about one in ten Australians received professional advice last year. That maths has never worked, and no amount of adviser recruitment will fix it.

7.7 yrs
To save a 20% deposit in Sydney
15.9M
Australians with unmet advice needs — vs 15,429 advisers
80,000
Firms newly regulated under Tranche 2 from 1 July
$31.3M
Civil penalty per contravention under AML/CTF

The second is Tranche 2

On 1 July, AUSTRAC's reforms brought roughly 80,000 accountants, lawyers, conveyancers and real estate agents into the AML/CTF regime for the first time — alongside the 17,000 banks, credit unions, building societies and other ADIs, non-bank lenders, AFSL holders, investment managers, stockbrokers, superannuation trustees, custodial, depository, remittance and currency providers, casinos and more. Enrolment closed this week. Civil penalties reach $31.3 million per contravention.

Ongoing customer due diligence (CDD) demands continuous monitoring, re-rating customer risk as it moves, with reverification on trigger events — all live since 31 March, with no runway. Failing to comply with your own AML/CTF policies is a civil penalty offence. Write a policy you can't operationalise and you have manufactured your own liability. Many included firms are not ignoring this. They simply have no instrument. Whilst it might work for cheese, wagyu and red wine, you cannot continuously monitor anything with an aged document pack.

The third is open banking itself

Open banking has quietly been sitting there the whole time, treated by most of the market as a tax and a slightly better way to fetch bank statements. It is much more than that. And the reason it matters is not the data. It's the model.

The Reframe

The Opportunity Hiding in Plain Sight

Open banking gets scoped as a feature: replace the statement upload with an API call. Faster, cleaner, nicer UX. Tick. That framing wastes it. The Consumer Data Right didn't just standardise a data format. It forced every ADI in the country to build a consented, versioned, conformance-tested, externally-consumable API surface over their own customer and transaction data, with authentication, authorisation, revocation and audit built in as first-class primitives.

That is not a statement feed. That is national identity, verification and account infrastructure that happens to also carry transactions.

Once you see it that way, one connection solves four problems that most institutions are currently solving four separate times, with four separate vendors, on four separate integration projects.

01

Origination and Onboarding

The most underused part of open banking is not the data. It's the authentication event.

To share data, a customer must log in to their existing bank and authorise the consent. Think about what that single act proves:

  • A real person controls a real account
  • At a real ADI
  • That has already run full, regulated KYC on them
  • And is willing to authenticate them right now

That is an extraordinarily high-signal, near-zero-marginal-cost gate — and it arrives before you have spent a dollar on document verification, biometric liveness, or bureau lookups.

Most origination funnels are built upside down. They apply the expensive checks to 100% of inbound traffic, including the synthetic identities, the mules, the bots and the tyre-kickers. Then they wonder why cost per verified customer is brutal.

Invert it. Put the connect step first. Anyone who can authenticate against an existing regulated institution and show a real transaction history is overwhelmingly likely to be a real customer. Everyone who can't, you handle differently — and you spend your expensive verification budget only on the population that survived the cheap gate.

It also kills a second problem in the same motion. If you are going to debit that customer, you now have their account details from source, rather than from a form they typed. No penny-drop. No micro-deposit dance. No dishonour three days later because a digit was wrong.

This does not mean you can piggyback another institution's KYC to discharge your own obligation. The Act contains reliance provisions with specific conditions attached, and CDR authentication on its own is strong corroborating evidence, not delegated due diligence. Treat it as a gate and a signal that dramatically improves the economics and the accuracy of the checks you still have to do yourself.
02

Compliance, and the Obligation With No Runway

Ongoing CDD demands that regulated entities monitor customers continuously, keep their risk rating current, and reverify when something changes. It is, by definition, a longitudinal obligation. The entire profession is currently holding a point-in-time tool.

A consented data connection changes the shape of what's possible:

  • Source of funds and source of wealth stop being a self-attested declaration and become observable. For higher-risk customers, that is the difference between a file that survives examination and one that doesn't.
  • Monitoring actually monitors. Volume spikes, new counterparties, patterning just under reporting thresholds, undisclosed liabilities appearing, gambling escalation — visible as they happen, not reconstructed afterwards.
  • Risk ratings move when the customer's money moves, rather than sitting frozen at the value someone assigned at file open.
  • Reverification has a channel. The customer reconnects through a flow they have already used once, instead of being chased for documents.
  • The audit trail is a by-product, not a project. What changed, who reviewed it, what was decided, when. That is precisely what an examiner asks for — and the only defence against the policy-breach offence.

The same connection that satisfies the compliance obligation is the one that produces a genuinely useful affordability picture. Real position, real behaviour, real time. That is how a “No” becomes a “Not Yet”, with a pathway to “Yes” attached rather than a shrug.

One consent. Two obligations. One customer interaction.
03

Payments

PayTo has been live since 2022 and reaches roughly 95% of retail accounts. Yet in March 2026 the RBA found it still isn't a proven direct debit replacement, with around 70% of volume remaining on BECS. Fraud liability is unresolved, bank implementations vary, and bulk capability doesn't exist. BECS retires in 2030, so this problem has five more years to run. Consented data fixes the debit on the rail businesses are using, now.

Direct debit in Australia fails two ways. Wrong account details, or no funds on the day. Both surface after the fact, with a fee attached, and usually with a customer relationship slightly worse than it was that morning.

Both are information problems, and consented data solves both:

  • Read the BSB and account number from source, so they are correct before the first debit is ever lodged.
  • See the balance, the pay cycle and what else is queued, and score a debit's probability of failing before submitting it. Then schedule around payday instead of into it.

The economics are neat, because everyone wins in the same direction. Fewer dishonours means a fee the consumer never pays, a collections call the business never makes, and a merchant the payments provider never loses.

That's not a better bank statement. That's a better rail.
04

Core Decoupling

This is the least obvious benefit and, for institutions, probably the largest.

Every bank and lender has the same structural problem. Customer and transaction data is trapped in a core banking system that was never designed to be a system of engagement, and certainly never designed for AI. Every new product, every new experience, every new channel becomes another bespoke core integration that is expensive, slow, and load-bearing in a way nobody is comfortable with.

Meanwhile, regulation has already made every ADI build the thing they needed: a standardised, stable, well-documented read API over exactly that data.

The play is to adopt that contract internally. Build your product surface against the CDR data model rather than against the core. Then:

  • Your experiences read from a stable API contract, not from core-specific structures
  • The core stays as system of record instead of being forced into an extension of purpose it was never built for
  • Replacing or upgrading the core stops being an existential, “CEO killer” project event, because the dependency has been abstracted
  • The same integration that reads your own customers' accounts reads their accounts held everywhere else, because it's the same standard

That last point is the one worth sitting with. Build to the CDR contract once and your front end becomes simultaneously core-agnostic and institution-agnostic. You can show a customer their whole financial life, yours and everyone else's, through a single data model, with consent handled natively.

Most institutions built their CDR compliance as a cost centre: a mandated outbound obligation, ring-fenced, minimally resourced, done. The interesting move is to turn it inward and treat it as the decoupling layer you were going to have to build anyway.

How Moroku Helps

Kanopi One: The Thesis, Shipped

We put this thesis into the Pinch Payments “Pinch Me, I Want $50K” hackathon. Kanopi One brings affordability, identity and AML/CTF into one consented flow for mortgage brokers, advisers and accountants — the channel that reaches underserved Australians, and now writes a record 81% of new residential home lending in this country.

On the payments side, every firm is onboarded as its own Pinch managed merchant, with its own merchant ID and its own settlement, so a brokerage can recover the cost of compliance from day one rather than absorbing it. Cards for instant activation, direct debit for the recurring life of the client, and the open banking connection de-risking the debit before it lodges.

Watch the demo · Kanopi One

Submission is in. Finalists announced 3 August · Demo Night, Sydney, 10 August
The Takeaway

What to Do About It

Regulated Entities

Confirm enrolment, then look at ongoing CDD

Confirm your enrolment, then look hard at ongoing CDD specifically. That is the obligation with no transitional relief, and it is the one that needs tooling you almost certainly don't have. Initial CDD can wait. This can't.

Brokers · Advisers · Accountants

Buy an instrument, not a filing cabinet

The compliance spend is happening either way. The only question is whether it buys you a filing cabinet — or an instrument that also makes you better at the actual job: getting people into homes and toward retirement.

Banks & Lenders

Point your CDR surface inward

You have already built the CDR surface. You paid for it. Right now it is pointed entirely outward, at your competitors' benefit. Point it inward and it becomes an origination gate, a compliance engine, a payment de-risking layer and a core decoupling strategy — using infrastructure that is already live, already conformance-tested, and already sitting on your balance sheet as a sunk cost.

Four Problems. One Connection.

Talk to Moroku about putting the open banking infrastructure you've already paid for to work — for origination, compliance, payments, and core decoupling.