Site icon CTIN

Online Trust: Most Excellent User Experience

abstract global map with IT images - user experience

The FDX User Experience Guidelines are designed to help technical teams deliver user-permissioned data sharing flows that are intuitive, transparent, and compliant with regulatory expectations. Developed by the FDX working group, these guidelines directly reflect requirements from the CFPB’s Section 1033 rule, ensuring that user interface (UI) and user experience (UX) in open finance is not just functional, but also meets the letter and spirit of consumer data rights.


Regulatory Foundations for the 1033 UX

The Consumer Financial Protection Bureau’s Section 1033 rule, finalized in October 2024, mandates that financial institutions provide consumers and authorized third parties with access to their financial data in a secure, reliable, and user-friendly manner. FDX’s UX Guidelines are explicitly mapped to these regulatory requirements, providing actionable recommendations for technical implementers.

Key CFPB 1033 requirements that guided FDX’s UX Guidelines include:

Trust, transparency, and clear communication are foundational to guiding the user journey in website design and development. These principles help users understand how their data is used, who has access to it, and for what purpose—building confidence in the system and empowering users to make informed decisions.

By providing clear, conspicuous disclosures, intuitive consent management, and accessible revocation options, designers ensure that users remain in control of their experiences and data. This approach not only streamlines interactions but also fosters lasting trust and satisfaction throughout the user journey.

hand holding sun - indicating good user experience

Technical Implementation Highlights

1. Consent Journeys and Processes

The guidelines break down the user experience into “Journeys” (e.g., granting, managing, or revoking consent) and “Processes” (e.g., authentication, account selection). Each journey is mapped to CFPB 1033 requirements, ensuring that every user touchpoint is compliant and user-centric.

2. Authorization Disclosure

3. Data Clusters and Scope

4. Consent Duration and Reauthorization

5. Consent Management Dashboards

6. Revocation and Reauthorization Flows


FDX UX Guideline AreaCFPB 1033 ReferenceImplementation Example
Authorization Disclosure1033.411(a), (b)(1)-(4)Clear, segregated consent screen with all required details
Data Clusters & Scope1033.211, 1033.411(b)(4)Standardized data cluster selection in UI
Consent Duration1033.411(b)(6), 1033.421Display of expiration date, annual reauthorization process
Revocation Rights1033.411(b)(7)“Revoke access” button in consent dashboard
Consent Dashboards1033.411(b)(7), 1033.431Dashboard showing all active and past authorizations

Conclusion

The FDX User Experience Guidelines are a practical, technical blueprint for building user data-sharing flows that are both best-in-class and CFPB 1033-compliant. By mapping every step of the user journey to specific regulatory requirements, FDX ensures that open finance implementations are not only secure and interoperable, but also empower consumers with real control and transparency over their financial data.

For technical teams, aligning with these guidelines is not just about compliance—it’s about building trust and usability into the core of open finance.


References:

  1. https://financialdataexchange.org/FDX/News/Announcements/FDX_Announces_Spring_2025_API_Release_6_4.aspx
  2. https://financialdataexchange.org
  3. https://financialdataexchange.org/common/Uploaded%20files/Intoduction%20To%20APIs%203212024_1120.pdf
  4. https://www.businesswire.com/news/home/20210519005031/en/Financial-Data-Exchange-Releases-FDX-API-4.6
MastodonLinkedInRedditBloggerSlashdotEvernoteDiggPinterestTumblrTelegramSnapchatWhatsAppMessengerXFacebookCopy LinkEmailPrintShare
author avatar
Jane Ginn CTIN President & Co-Founder
Jane Ginn ~ As the co-founder of the US-based Cyber Threat Intelligence Network (CTIN), a consultancy with partners in Europe, Ms. Ginn has been pivotal in the development of the STIX international standard for modeling and sharing threat intelligence. She also served as the Secretary of the OASIS Threat Actor Context Technical Committee, contributing to the creation of a semantic technology ontology for cyber threat actor analysis. Her efforts in this area and her earlier work with the Cyber Threat Intelligence (CTI) TC earned her the 2020 Distinguished Contributor award from OASIS. She is currently supporting the analysis services of Datos Insights, an advisory firm focusing on the financial services sector. In public service, she advised five Secretaries of the US Department of Commerce on international trade issues from 1994 to 2001 and served on the Washington District Export Council for five years. In the EU, she was an appointed member of the European Union's ENISA Threat Landscape Stakeholders' Group for four years. A world traveler and amateur photojournalist, she has visited over 50 countries, further enriching her global outlook and professional insights.
Exit mobile version