The regulator creates the obligation. The lender carries the risk. The bank controls the access.

In a recent chat with a client — an online lender — we got talking about bank APIs, screen scraping, and what happened when Capitec withdrew access to consumer transaction data.

For years, most of their applicants shared transaction data straight from the bank. Verified at source, nothing to manipulate — fraud on that channel was never the worry. Normal course of business.

Then the access was withdrawn.

For most lenders, Capitec is 50–60% of consumer applications. So more than half of their applications fell back to the old way: an uploaded bank statement. And a document can be edited. The fraud that verified access had been filtering out arrived all at once, at a scale they hadn’t seen before.

Another lender has put a number on it: fraud running at 3% of the book. On a book writing R50 million a month, that’s R1.5 million a month walking out the door — on fraud that verified data would have caught at the front door.

Here’s the part that matters. There are only two ways to collect that data safely, straight from the bank: screen scraping with the consumer’s consent, or a bank API. Capitec has restricted access to both. Which leaves lenders — who are required by regulation to collect this data for affordability — with the one channel where the fraud lives: uploaded documents.

Consumers are willing to share their data. The technology exists. The access doesn’t.

He was blunt about where that leaves him:

“I’m forced to collect this data. And given that I’m forced to do it, and that’s a government regulation, it then follows that government should force institutions to make that data available — in the easiest possible way that mitigates document manipulation.”

That’s the whole argument, and it’s hard to fault.

So a note to the NCR: you require this data. That gives you a stake in how it can be collected — and an interest in the one channel that can’t be manipulated. This isn’t the market’s problem to negotiate, bank by bank. We’re ready to help whenever you are.

And to all lenders reading this — should access to data you’re required by law to collect be your problem to solve?

Because right now, this is how it works:

The regulator creates the obligation. The lender carries the risk. The bank controls the access.

Leave a Reply

Your email address will not be published. Required fields are marked *