Contributor · Core Banking & Financial Services

The fragmentation of lending: regulatory responses, lessons from India, and the changing role of banks

By Anubha Sharma Mishra · Contributor · Core Banking & Financial Services

Lending is no longer a bank-centric business — origination, assessment and funding are splitting across platforms, fintechs and private credit. Anubha Sharma Mishra on the regulatory response, what India's Account Aggregator ecosystem shows the world, and how banks stay central by staying relevant.

Traditional lending has largely been a bank-centric business. A customer approaches a bank, provides financial information, undergoes a credit assessment, and receives the approved loan. The process is relatively linear, and the bank largely controls the customer relationship, the data used for underwriting, and credit delivery.

This model is now being disrupted. One can now originate credit through a merchant or digital platform that uses transactional and alternative data for assessment, and finally fund it through a bank, fintech, NBFC, or a private-credit provider. The result is not simply the digitization of lending, but a fragmentation of the lending value chain itself.

Digital acceleration leading to fragmentation in lending

The global financial crisis fundamentally changed the regulatory and risk-management landscape for banks, while the COVID-19 pandemic accelerated an already emerging trend toward digital payments and digital finance services. As customers gradually became more comfortable accessing financial services digitally, products like embedded finance and Buy Now Pay Later (BNPL) paved the way for a new wave of digital loans. This not only created more data but also transformed how credit is discovered, assessed, originated, and serviced.

Regulatory response

Over time, several regulatory developments have improved credit quality and brought data portability and agility to the lending ecosystem.

Basel III aimed to strengthen the quality and quantity of capital requirements and introduced non-risk-based leverage ratios to absorb market volatility better.

IFRS 9 regulations focused on a forward-looking, pre-emptive approach to recognizing expected credit losses, rather than waiting for losses to materialize.

The Open Banking framework developed under PSD2 added another dimension. It allowed authorized third-party providers, with customer consent, to access payment-account information. In lending, this data can supplement traditional credit information, provide more visibility into income, expenditure and cash flow patterns, and help make more informed underwriting decisions. While PSD2 itself is a European framework, several other economies, including India, have developed their own approaches to consent-based financial data sharing and digital lending infrastructure.

However, two main problems arise.

First, while regulations govern credit risk for a lender at the individual product or institution level, timely aggregation of total exposure across all lending channels remains a challenge. This means that lenders, at large, still struggle to get a complete and timely consolidated view of a borrower’s financial obligations across banks, fintechs and other lenders — amplifying the risk of over-indebtedness, non-payment and default.

Second, lending fragmentation is also creating an architectural challenge for incumbent banks. While many banks still run on mainframes, more are under increasing pressure to harness new technologies to innovate alongside their existing mainframe environments to provide competitive products and services. Pressure is increasing around investment in modernization, data security, cloud connectivity, and experimentation with AI use cases, while still retaining significant legacy infrastructure.

Both these issues are interlinked.

The potential of PSD2/Open Banking norms

What developing economies like India have showcased in the last decade in building a robust network of “FIPs & FIUs” is commendable.

India has gone beyond payments to build a broader digital public infrastructure, combining UPI for payments, Account Aggregators for consent-based financial data sharing, and ULI for standardized, API-driven lending connectivity.

What this has enabled is secure data sharing with customer consent with Financial Information Users (such as merchants, third-party vendors or even other FIs). The customer initiates a purchase on an online portal of vendor (FIU), provides consent, and authorizes the Account Aggregator to securely connect with and retrieve financial information from their financial institution (FIP) and share it with the FIU. This could be to make an online purchase, secure a loan, or even make an account balance retrieval using a third-party app.

As of 31 July 2026, the Account Aggregator ecosystem, comprising FIPs & FIUs, has expanded into a vibrant network of 1200+ regulated entities spanning banks, NBFCs, insurers, wealth managers, depositories, and more, all under the oversight of four financial sector regulators & the Ministry of Finance, and the number continues to grow (per Sahamati’s list of certified entities in the Account Aggregator ecosystem, retrieved 4 September 2026; the published list has since been restructured).

While these developments have significantly reduced manual intervention and the time required to complete a payment or secure a loan, they have also introduced important considerations around credit risk for financial institutions. In addition to stricter underwriting and provisioning requirements, the Reserve Bank of India (RBI) has mandated fortnightly reporting of credit information to credit bureaus. This provides lenders with more timely and comprehensive visibility into a borrower’s outstanding obligations, enabling better credit-risk assessment and helping mitigate the risk of over-leveraging. While there is still room for tightening these norms further, this is heading in the right direction.

The maturity and regulatory approach to Open Banking varies significantly across jurisdictions. Despite the sophistication and scale of the North American financial system, its financial-data infrastructure remains relatively fragmented, with the U.S. relying heavily on data aggregators, screen scraping, and bilateral arrangements between banks and fintechs rather than a universally standardized, API-based framework for consumer-permissioned data access. The third-party fintechs often rely on data aggregators that act as intermediaries, connecting to customers’ bank accounts and accessing their financial data on the customer’s behalf. This remains a step behind the Account Aggregator model of India.

Canada, on the other hand, is still in the process of laying the foundations for the architecture of consumer-driven data sharing, although implementation remains at an early stage.

Brazil, by contrast, is a clear example of a mature, regulator-led Open Finance model in the Americas enabling financial and credit data sharing and digital payments.

What does it mean for the future of lending?

While the world is moving towards greater standardization in data sharing and improving its infrastructure, the future of lending is unlikely to be defined by banks versus fintechs. It will be defined by how effectively participants across the ecosystem combine distribution, data, technology and capital while maintaining appropriate risk and regulatory controls.

The real questions remain:

How can banks leverage more data points for a bigger outreach, while operating within the boundaries of data privacy and governance? Banks are often sitting on a mine of customer data, from expenditure patterns to investment behaviors, that can be harnessed to provide better tools for financial management, while remaining within the boundaries of regulatory governance.

How to continuously monitor risk covenants in a global transactions set-up. This calls for measures to strengthen and evolve regulatory compliance frameworks around data sharing and privacy.

How to partner rather than compete with non-traditional players, leveraging better technology while maintaining sovereignty in lending. A clear demarcation of operational boundaries needs to be established while fostering partnerships that complement each other by providing value-added products and services, rather than competing directly for market share.

Banks therefore no longer need to own every step of the customer journey to remain central to lending; they need to remain relevant. Their competitive advantage may increasingly lie in capital, risk, trust, financial control, and regulatory accountability. They can delegate customer access and API repository development to fintechs, merchants, and other third-party lenders that are more technologically advanced.

After all, the customer wants speed, agility, convenience, as well as assurance of regulatory data privacy, without getting stuck in monolithic processes and layers of documentation.


Anubha Sharma Mishra is a Senior Consultant at SAP Fioneer. She writes here in a personal capacity; views are her own. Articles are vendor- and firm-neutral.

Next: the platform’s latest insights.