Official Anthropic PartnerNVIDIA Inception Program- MemberIoT Global Awards 2023 Winner- Cloud Big Data Analytics
Arrochar Labs
ARROCHAR
LABS

Family A · Serving customers

MeshFin Share

Open banking, consent and data sharing

Consent granted, shown, enforced and expired exactly as the customer gave it; data served to accredited recipients only within that consent through the standard APIs; every access logged and the regulator's reports produced from the log.

ScopedUniversal ● · Mutual ● · Non-bank ◐BIAN Sales and Service

MeshFin Share (MF-06), the service for open banking, consent and data sharing, is one of the twenty-four MeshFin services, in the "Serving customers" family, which follows the BIAN Sales and Service business area. It covers the BIAN service domains Customer Consent, Customer Access Entitlement, Party Authentication, Customer Agreement and Payee Management in whole or in part. Consent granted, shown, enforced and expired exactly as the customer gave it; data served to accredited recipients only within that consent through the standard APIs; every access logged and the regulator's reports produced from the log. It replaces open banking gateway product, consent dashboard, manual data-holder reports and conformance testing by hand. AI agents carry the work end to end; a named person takes every decision with legal or financial effect on a customer, the balance sheet or a regulatory obligation. It is core for a universal and retail bank, core for a mutual and community bank, common for a non-bank lender and fintech.

The BIAN baseline

BIAN service domains this service covers

In the BIAN Sales and Service business area of the Service Landscape 14.0, in whole or in part. Lay this over your own BIAN map to see what MeshFin Share covers and what stays. BIAN has not reviewed or endorsed MeshFin.

  • Customer Consent
  • Customer Access Entitlement
  • Party Authentication
  • Customer Agreement
  • Payee Management

What it replaces

  • Open banking gateway product
  • Consent dashboard
  • Manual data-holder reports
  • Conformance testing by hand

What it reacts to

  • Consent granted, amended or withdrawn
  • Accredited recipient requests data
  • Consent nears expiry
  • Data quality complaint
  • Standards or rules change

The agents that carry it

  • Consent agent

    Records and displays each consent exactly as granted, including joint-account authorisations, enforces it on every request and expires it on time.

  • Sharing agent

    Serves only the data clusters consented, through the published standards, and logs every access with the consent it relied on.

  • Assurance agent

    Reconciles every disclosure to a consent, produces the performance and dispute reports the regulator requires, and runs the conformance tests on each release.

The MeshFin rule

Where a person decides

No decision with legal or financial effect on a customer, the balance sheet or a regulatory obligation is taken by an agent alone. In MeshFin Share, these decisions are held for a named person, with the agent's evidence and recommendation attached.

DecisionWho decidesWhy a person
Any disclosure outside a valid consentPrivacy officerUnlawful without one; the agent refuses and a person reviews
Refusal of a data request on security groundsDelegated officerMust be justified to the regulator

Records it writes

Consent record · Access log · Conformance test results · Data-holder report

Before MeshFin: the baseline this service is measured against

Illustrative figures for a mid-sized institution on the systems the service replaces. Sample data, not a customer's. A live service reports what its agents are doing instead.

Consents active

92,000

across accredited recipients

Reconciled to a consent

sampled

today, not every access

Conformance tested

quarterly

by hand, after release

Regulator report

3 days

to assemble each period

Institutions: core for a universal and retail bank, core for a mutual and community bank, common for a non-bank lender and fintech. Universal and retail bank ● · Mutual and community bank ● · Non-bank lender and fintech ◐.

Questions banks ask about MeshFin Share

What does MeshFin Share do?
MeshFin Share is the MeshFin service for open banking, consent and data sharing. Consent granted, shown, enforced and expired exactly as the customer gave it; data served to accredited recipients only within that consent through the standard APIs; every access logged and the regulator's reports produced from the log. It reacts to events such as consent granted, amended or withdrawn, accredited recipient requests data and consent nears expiry, and writes consent record, access log, conformance test results and data-holder report as records.
Which BIAN service domains does MeshFin Share cover?
Customer Consent, Customer Access Entitlement, Party Authentication, Customer Agreement and Payee Management, in the BIAN Sales and Service business area, in whole or in part. The mapping is to the published BIAN Service Landscape; BIAN has not reviewed or endorsed MeshFin.
What systems does MeshFin Share replace?
Open banking gateway product, Consent dashboard, Manual data-holder reports and Conformance testing by hand. Because the service runs on the MeshFin platform, the licence, integration and upgrade costs of those systems retire with them.
What do the AI agents do in open banking, consent and data sharing?
The consent agent records and displays each consent exactly as granted, including joint-account authorisations, enforces it on every request and expires it on time. The sharing agent serves only the data clusters consented, through the published standards, and logs every access with the consent it relied on. The assurance agent reconciles every disclosure to a consent, produces the performance and dispute reports the regulator requires, and runs the conformance tests on each release.
Which decisions does a person still take?
Agents never take a decision with legal or financial effect on a customer, the balance sheet or a regulatory obligation. In MeshFin Share, a person decides any disclosure outside a valid consent (privacy officer) and refusal of a data request on security grounds (delegated officer). The record shows who decided, why, on what evidence and under which delegation.