Consent Management

Grant, use, renewal and withdrawal of customer permissions

Permission as a controlled lifecycle

Consent management records and enforces what a customer has permitted, for which recipient, data or action, and purpose. Consent is not interchangeable with authentication, a token, contractual authority or every privacy-law basis for processing. Determine which permission the applicable framework requires before designing the screen.

The allocation of records and dashboards differs across bank, recipient and consent-manager models. The bank still needs evidence that its own disclosures or actions were authorised. Do not assume every regime requires the customer to grant, renew and withdraw only inside the bank's application.

Grant with the correct authority

Identify the customer or representative, relevant account mandate, recipient, scope, purpose and duration where applicable. Explain the effect of the choice in clear language. Joint accounts, business mandates and representatives may require different checks; a valid login alone does not establish authority to share every connected account.

A grant authorises scoped use; renewal or changes follow applicable rules, and withdrawal must reach enforcement points.

Retain the permission reference, applicable terms or screen version, authority and relevant timestamps. Avoid collecting authentication secrets as evidence. Scope expansion should follow the framework's required confirmation or authorisation process rather than silently inheriting an unrelated earlier permission.

Enforce use and manage tokens

Each relevant request needs sufficient checks on caller, role, account, scope and current authority. A signed token can establish technical claims without proving that an associated permission has not since been withdrawn. Design expiry, token revocation or active permission checks to enforce the actual requirements.

Caching introduces a propagation window. Define and monitor it, and test failure of update events. A consent service outage needs an approved behaviour appropriate to risk and law; it should not silently allow an action requiring authority that cannot be established.

Renewal is not one universal clock

Consent duration, recipient reconfirmation, bank reauthentication and token lifetime are different clocks. They may be linked under a framework but should not be treated as the same number.

As a scoped example, EU Regulation 2022/2360 amended the strong customer authentication exemption for specified account-information access to use a 180-day interval under its conditions. It does not establish a universal 180-day consent lifetime. The UK and other markets have different rules; check the applicable instrument and current implementation requirements.

Withdrawal and retained information

Withdrawal should reach the enforcement points relevant to future sharing or action. Include gateways, adapters, refresh paths and intermediaries, then probe the result. A dashboard marked cancelled is weak evidence if the API still returns data.

Previously collected data may need deletion or restricted use, or may be retained for an applicable obligation. Future access, ongoing use and deletion are separate questions. Explain the actual consequence to the customer and apply the framework's data-handling requirements instead of promising instant erasure everywhere.

Worked example: revocation event is lost

In this fictional example, the bank records a withdrawal, but an adapter misses the update and serves a later request. Operations identifies the permission, recipient, fields and timing, contains further access and assesses the affected population. Legal and compliance owners determine notification and remediation duties under the actual regime.

The repair includes propagation acknowledgements or another effective enforcement design, overdue-update alerts and an end-to-end denial test. Changing only the dashboard would leave the original failure intact.

Assurance and sources

Measure unsupported scope requests, access after expiry or withdrawal, propagation lag, orphaned tokens, failed renewal and customer understanding. Test alternate channels and representative authority. Keep evidence for the applicable retention period with limited access.

The UK Open Banking standards and Australian CDR data-holder guidance illustrate different permission and control arrangements. No single grant-screen design establishes compliance across them.

Takeaway

Consent management joins understandable permission to effective enforcement throughout its lifecycle. Keep consent, authentication, token validity and data retention distinct.

Continue to Third Party Providers.