
Photo by abuuhurera
Australia's Consumer Data Right (CDR) lets your customers securely share their banking data with you in seconds, giving you verified income, account ownership, and transaction history without a single uploaded payslip or bank statement. For remittance operators, this means faster onboarding, stronger source-of-funds evidence, and richer data for AML risk assessments — all sourced directly from the customer's bank with their explicit consent.
The challenge is that CDR was built for lending and personal finance, not remittance. Accessing the data requires either becoming an Accredited Data Recipient (ADR) or partnering with one, and most MTOs underestimate the compliance overhead. This guide explains how open banking actually works for money transfer businesses, what it can verify, and how to deploy it without taking on regulatory risk you can't manage.
Key Takeaways
- CDR (Consumer Data Right) gives accredited recipients API access to a customer's bank data — account ownership, balances, transactions, and income — with the customer's consent, replacing manual document collection.
- Most MTOs access CDR data through a third-party intermediary or sponsored accreditation rather than building full ADR accreditation, which costs significant time and money.
- Open banking strengthens source-of-funds and source-of-wealth verification under your AML/CTF program by providing tamper-resistant, bank-sourced transaction data.
- CDR is not a substitute for KYC identity verification — it confirms account ownership and financial behaviour, not government-issued identity, so you still need a document or DVS-based identity check.
- The 2026 AML/CTF reforms raise expectations for ongoing customer due diligence, and CDR data feeds directly into more dynamic, evidence-based risk scoring.
What Is the Consumer Data Right and How Does Open Banking Work?
The Consumer Data Right (CDR) is an Australian Government data-sharing framework introduced in 2020 and regulated by the Australian Competition and Consumer Commission (ACCC) and the Office of the Australian Information Commissioner (OAIC). It gives consumers the right to direct businesses that hold their data to share it securely with accredited third parties.
Banking was the first sector brought into the CDR, which is why people often call it "open banking". Every major Australian bank, and most smaller authorised deposit-taking institutions, must expose customer data through standardised APIs when the customer consents.
For a remittance operator, the practical flow looks like this. A new customer begins onboarding, you redirect them to their bank's consent screen, they authenticate and approve the data share, and verified financial data flows back to you through a CDR-compliant API — typically in under a minute.
The data is sourced directly from the bank, not the customer. That distinction matters for AML purposes because it removes the opportunity for a customer to alter a PDF bank statement or fabricate a payslip.
What Banking Data Can MTOs Actually Access Through CDR?
CDR exposes several data categories that are directly relevant to remittance onboarding and ongoing monitoring. Each requires a specific consent scope, and you can only request data that you have a genuine, disclosed purpose to collect.
| Data category | What it contains | Remittance use case |
|---|---|---|
| Account details | Account name, number, type, status | Confirm account ownership and name matching |
| Account balances | Current and available balances | Plausibility check for transfer size |
| Transaction history | Up to 24 months of debits and credits | Source of funds, income verification, behaviour analysis |
| Customer details | Name, address, contact details on file | Cross-check against KYC identity data |
| Direct debits & scheduled payments | Recurring commitments | Affordability and financial profile |
The most valuable category for remitters is transaction history. Twenty-four months of bank-verified transactions lets you establish a customer's income pattern, identify their employer, confirm salary credits, and detect whether their remittance activity aligns with their stated financial circumstances.
This directly supports the source-of-funds and source-of-wealth evidence your AML/CTF program requires, particularly for higher-value or higher-risk customers where enhanced due diligence applies.
How CDR Strengthens AML Risk Assessment and Source-of-Funds Checks
Under the AML/CTF Act 2006 and the rules taking full effect through the 2026 reforms, you must understand the nature and purpose of the customer relationship and, where risk warrants it, verify the source of funds. CDR transforms this from a paper-chasing exercise into a data-driven one.
Consider a customer who wants to send AUD 18,000 to family overseas. Under a manual process you would request bank statements, read them by eye, and rely on the customer providing genuine documents. With CDR, you receive bank-sourced transaction data showing a consistent salary credit of AUD 6,200 per month from a named employer over 18 months.
That evidence does three things at once. It confirms the funds are plausible given the customer's income, it identifies a verifiable source (employment income), and it creates an audit trail you can show AUSTRAC during a review.
Building a richer customer risk profile
CDR data feeds directly into more dynamic risk scoring. Instead of relying solely on self-declared occupation and income, you can score risk using observed financial behaviour.
Useful signals include the regularity and source of income credits, the presence of gambling or high-risk merchant transactions, sudden large deposits inconsistent with income, and rapid in-and-out movement of funds that may indicate layering. These signals let you tier customers into standard and enhanced due diligence pathways with evidence rather than guesswork.
This aligns with AUSTRAC's expectation, reinforced in the 2026 reforms, that customer due diligence is ongoing and proportionate to risk rather than a one-time onboarding tick-box.
CDR Is Not KYC: Understanding the Limits
The single most important point to understand is that CDR does not replace identity verification. Confirming that a customer controls a bank account in a particular name is not the same as verifying that person's government-issued identity.
Your KYC obligations under the AML/CTF Rules still require you to verify the customer's full name and either date of birth or residential address against reliable, independent sources. That typically means a document-based check or an electronic verification through the Document Verification Service (DVS).
Think of CDR and KYC as complementary layers:
- KYC identity verification answers "Is this person who they claim to be?"
- CDR banking data answers "Does this person's financial behaviour match their stated profile, and where do their funds come from?"
Used together, account-name matching from CDR adds a powerful corroborating signal. If the bank account name matches the verified identity name, you have a stronger overall identity confidence score — but the CDR name match alone is not sufficient KYC.
How to Access CDR Data: Accreditation Pathways for MTOs
You cannot simply call a bank's open banking API. Access to CDR data is restricted to Accredited Data Recipients (ADRs) and entities operating under recognised access models. There are several pathways, each with different cost and complexity.
| Access model | What it involves | Best suited to |
|---|---|---|
| Unrestricted (full) ADR | Direct accreditation with the ACCC; full data access; significant compliance build | Large MTOs with technical and compliance resources |
| Sponsored accreditation | A sponsor ADR vouches for you; reduced but real obligations | Mid-sized operators wanting some control |
| CDR Representative | You operate under a principal ADR's accreditation | Operators wanting speed with lower overhead |
| Trusted Adviser / Outsourced provider | Use a third-party data recipient that delivers verified outputs | Most small and mid-sized MTOs |
For the majority of remittance operators, the practical route is to partner with an accredited intermediary — typically an identity-verification or open-banking platform that already holds accreditation and exposes the data through a single onboarding API.
This avoids the substantial cost and ongoing obligations of full accreditation, which include CDR privacy safeguards, an information security control framework, annual attestation, and OAIC oversight.
Questions to ask a CDR data provider
Before integrating, confirm the provider's accreditation status and access model, the data categories they expose, how consent and consent withdrawal are managed, where data is stored and for how long, and how their outputs map to your AML/CTF documentation requirements.
Also confirm pricing structure. Open banking providers typically charge per successful data retrieval or on a monthly platform fee plus per-call basis, which you must factor into your unit economics per onboarded customer.
Consent, Privacy, and CDR Obligations You Must Manage
CDR is built on explicit, informed, and time-limited consent. The customer must understand what data is shared, why, and for how long, and they can withdraw consent at any time.
Even when you use an intermediary, you carry responsibilities. You must clearly disclose your purpose for collecting the data, only use it for the disclosed purpose, and respect the CDR data minimisation principle — you cannot hoard data "just in case".
This intersects with the Privacy Act 1988 and, where you hold CDR data, the additional CDR Privacy Safeguards, which are in some respects stricter than the Australian Privacy Principles. Retention is a particular trap: CDR data should be de-identified or deleted when no longer needed for the consented purpose, while your AML records must be retained for seven years.
Resolve this tension deliberately. The common approach is to retain the verification outcome and supporting evidence record required for AML compliance, rather than the raw CDR data feed, and to document this in your data-handling policy.
A Practical Onboarding Flow Using CDR and KYC Together
Here is how a compliant, CDR-enhanced onboarding sequence works for a remittance customer:
- Collect identity details — full name, date of birth, residential address.
- Verify identity — run a document or DVS-based check to satisfy KYC obligations.
- Initiate CDR consent — redirect the customer to their bank, where they authenticate and approve the data share.
- Retrieve and analyse data — pull account ownership, name match, and transaction history through the accredited provider.
- Score risk — combine identity confidence, source-of-funds evidence, and behavioural signals to assign a risk rating.
- Route to the right pathway — standard customers proceed; higher-risk customers trigger enhanced due diligence.
- Record the outcome — store the verification result and evidence in line with your seven-year AML record-keeping obligation.
This flow turns onboarding into a minutes-long, evidence-backed process and gives your compliance team a defensible audit trail for every customer.
Costs and Trade-offs: Is CDR Worth It for Your MTO?
CDR is not free, and the decision turns on your volume, customer risk profile, and average transaction size. The economics favour operators handling higher-value transfers where source-of-funds verification is a recurring requirement.
| Consideration | Manual document collection | CDR via intermediary |
|---|---|---|
| Onboarding time | Hours to days | Under 2 minutes |
| Document fraud risk | Higher — editable PDFs | Very low — bank-sourced |
| Cost per check | Staff time | Per-retrieval API fee |
| Source-of-funds quality | Variable | Consistent, structured |
| Audit trail | Manual records | Automated, timestamped |
For a small MTO sending mostly low-value transfers, the per-call cost may outweigh the benefit, and a sound document-based source-of-funds process remains compliant. For operators with high-value corridors or a customer base requiring frequent enhanced due diligence, CDR materially reduces friction and fraud exposure.
Many operators adopt a hybrid model: standard low-value customers use lightweight verification, while CDR is triggered only when a transaction or customer crosses a risk threshold. This contains cost while capturing the compliance benefit where it matters most.
Where Open Banking Is Heading for Remittance
The CDR framework continues to expand, and action initiation — the ability to instruct payments, not just read data — is the next frontier. For remittance, this could eventually enable account-to-account funding directly from a customer's bank, reducing reliance on card rails and the costs that come with them.
This matters in light of the RBA ending card surcharging from 1 October 2026, which is pushing operators to reconsider funding methods. Open banking payment initiation, where regulation permits it for your licence type, could become a lower-cost, lower-fraud funding channel.
For now, the immediate, deployable value is in data: faster onboarding, stronger source-of-funds evidence, and richer AML risk assessment. Operators who build CDR into their onboarding architecture today position themselves well for the payment-initiation capabilities arriving over the next few years.
Frequently Asked Questions
Does CDR data replace KYC identity verification for remittance customers?
No. CDR confirms account ownership and financial behaviour but does not verify government-issued identity. You must still complete KYC identity verification through a document-based or DVS check to satisfy your obligations under the AML/CTF Rules. CDR account-name matching is a strong corroborating signal, not a standalone identity check.
Do I need to become an Accredited Data Recipient to use open banking?
Not necessarily. While full ADR accreditation with the ACCC gives direct data access, most remittance operators access CDR data through an accredited intermediary, a CDR Representative arrangement, or sponsored accreditation. Using a third-party accredited provider avoids the significant cost and ongoing obligations of full accreditation.
How long can I keep CDR banking data under privacy rules?
CDR data must be de-identified or deleted once it is no longer needed for the consented purpose, under the CDR Privacy Safeguards. This creates tension with the seven-year AML record-keeping requirement. The common solution is to retain the verification outcome and supporting evidence record needed for AML compliance, rather than the raw CDR data feed, and to document this in your data-handling policy.
How does CDR support source-of-funds verification under the 2026 AML reforms?
CDR provides bank-sourced, tamper-resistant transaction history of up to 24 months, letting you confirm income source and verify that a customer's funds are plausible given their financial profile. This directly supports the source-of-funds and ongoing customer due diligence expectations strengthened under the 2026 AML/CTF reforms, and creates a timestamped audit trail for AUSTRAC reviews.
Is open banking cost-effective for a small MTO?
It depends on your transaction values and risk profile. Providers typically charge per data retrieval or on a platform fee plus per-call basis. For low-value, low-risk customers, document-based verification may remain more economical. Many operators use a hybrid model, triggering CDR only when a customer or transaction crosses a defined risk threshold.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.
Ready to strengthen your onboarding and risk framework? Review your AML/CTF program to ensure your source-of-funds and customer due diligence procedures are reform-ready, and explore our corridor guides to align verification rigour with the risk profile of each market you serve.


