One engineered asset, twenty-one institutions
Twenty-one Australian customer-owned banks, mutuals and credit unions — including Hume Bank, Bank of Us and BankVic — faced the same regulatory conformance obligation, individually and non-delegably, on a deadline they had already missed once. Innovo converted 21 duplicate compliance problems into one engineered asset executed 21 times.
Banks cleared to go live
From engagement to compliance
Mandatory scenarios automated
Client and industry context
Australia's Consumer Data Right — Open Banking — obliged banks to expose customer data through standardised, secure APIs on a mandated timetable. Regulatory and media attention focused on the Big Four and other Tier 1 institutions. Behind them sat roughly 130 smaller banks, mutuals and credit unions, which were advised by the ACCC to find their own path to conformance.
These are small organisations: Hume Bank, a regional bank headquartered in Albury, ran a technology team of twelve; Tasmania's Bank of Us had an IT group of five; BankVic had eighteen. None was large enough to build a conformance capability alone. And the bind was structural — these institutions share technology by design, but each Open Banking participant had to provide its own evidence, validated against ACCC-defined scope, and attestation could not be assigned to a third-party provider. So the sector faced one shared problem and 21 separate, non-delegable regulatory obligations.
The challenge
- The deadline had already been missed once — these banks did not meet the Phase 1 deadline of 1 July 2021, leaving roughly four months to reach compliance by the Phase 2 deadline of 1 November, covering both phases of scope.
- The software platform provided for building their CDR capabilities lacked a robust testing system capable of demonstrating regulatory conformance — the banks could build the capability but not evidence it.
- For each institution to develop its own testing solution meant 21 duplicate builds of the same thing, with added risk and no time to do it in.
- CDR conformance spans security-profile validation, dynamic client registration, consent flows, API-contract compliance and negative-path recovery — materially harder than conventional API testing — and had to be repeatable, because a point-in-time pass was worthless as standards evolved.
Innovo's role
The banks convened themselves, led by Hume Bank and others, and pooled their resources. Innovo came to the work with directly relevant standing: from 2019 it had been engaged in the creation of Australia's industry CDR test strategies, protocols and scenarios (the Test Director work in the ACCC story). Rather than invent a test corpus, Innovo took the test cases the ACCC had published and engineered them into an automated solution the banks could execute in a short window.
Innovo built the conformance engine, funded the build up front and shared it across the group at a fraction of the per-institution cost, provided the specialist CDR knowledge the institutions did not hold, ran conformance testing per participant, and produced the documentation and evidence each needed for its own submission. The accountability boundary was drawn deliberately: Innovo built the engine, ran the testing and produced the evidence; attestation stayed with each bank, where the regulator required it to stay.
The solution delivered
A shared CDR conformance platform, executed per bank. It took the ACCC's CDR definitions — API endpoints, parameters, schema, properties and status codes — as configurable input, and drove validation against each bank's own environment and test data, connecting through the Open Banking Industry Sandbox as the mock CDR registry. Because the definitions were held as configuration rather than hard-coded logic, the same engine could be re-pointed at each institution and updated centrally as standards changed — the architectural decision that made a one-to-many model viable across 21 separately regulated entities.
The hard part was not the first bank; it was the twentieth. The code proved stable across institutions, but each bank carried its own environmental customisations, and resolving that variation — bank by bank, without forking the codebase — was the real engineering problem of the programme. Scope covered 270 mandatory ACCC scenarios (189 in Phase 1, 81 in Phase 2), with per-participant readiness packs delivered in registry-required formats.
Capabilities involved
- Regulation-as-configuration architecture — ACCC CDR definitions held as configuration, not code, so the platform tracked regulatory change centrally instead of requiring 21 parallel rebuilds.
- Multi-tenant isolation on AWS — AWS Control Tower keeping 21 competing institutions' environments and evidence properly separated on shared infrastructure.
- Automation of the ACCC's own published regulatory test cases into an executable suite.
- Security and consent-flow validation, dynamic client registration testing, and negative-path recovery testing — the most technically demanding parts of the standard.
- Configuration-variance handling across a single shared codebase, and evidence generation as a first-class output in registry-required formats.
- A repeatable regression capability, so each bank retained an owned asset for ongoing compliance rather than a one-time certification.
Client perspective
Bank of Us's applications and projects manager, Karla Day, noted that the group's existing providers had offered no sandboxing capability, and that pooling resources let the banks share cost, experience and perspective — an outcome she described as a repeatable service the banks own and can reuse for regression testing to stay compliant.
Delivery at a glance
Capabilities, platforms and engagement
- Sector
- Financial services — mutual and customer-owned banking
- Pillars
- AutomateAssure
- Platforms used
- Amazon Web Services (EC2, Control Tower)
- Java
- REST-assured
- TestNG
- Spring
- Bitbucket
- Microsoft Excel
- Open Banking Industry Sandbox
- Engagement model
- Outcome-Based Delivery (shared platform)
Measurable outcomes
What changed for the client
- All 21
- Banks passed conformance testing and were cleared to go live
- 4 months
- From engagement to compliance, after a missed deadline
- 270
- Mandatory scenarios automated across Phase 1 and Phase 2
- 1 engine
- A single shared asset serving 21 separately regulated institutions
- Owned
- A repeatable regression capability retained by each bank
a scalable, volume-driven solution that we couldn't replicate with just the people we had
a very clear-cut project plan, and they've certainly delivered
Explore the capability behind this work
See how Innovo delivers this kind of outcome — or tell us the result you need and we'll talk through how we would approach yours.
