Security of account aggregators flawed
Most account aggregators are offering a flawed product while they remain in the middle of the relationship between clients and service providers, according to eWise.com.au chief executive Alex Grinberg.
Grinberg says the placement of third parties in the process, who hold password information and collect the data for the clients, is a security flaw which can be exploited by those outside the relationship.
"If there is unauthorized access to the third party account aggregator from outside there is access to all the data of any clients held by the aggregator," Grinberg says.
eWise.com.au is also an account aggregator but Grinberg says the it does not hold any data on behalf of clients but rather, works as a conduit for information with all details held offsite.
"Anyone breaking into the eWise.com.au system will not find any useful data as there is nothing there in terms of user passwords or financial data. All account information needed to access account data is held on each client's own computer," Grinberg says.
These details are encrypted on the user's computer and are not seen by eWise.com.au at all, nor does it need access to them to provide service according to Grinberg.
Grinberg says account aggregation also breaches the terms of services of many financial institutions which prohibit the handing over of account information to a third party. As a result of this liability issues may arise with some banks actively seeking to bar account aggregation.
Other features of the eWise.com.au service include a bill scheduling, reminder and payment services as well as the ability to perform transactions with the customers' nominated institutions.
The service the only one to provide access to National Australia Bank and St George Bank accounts and is rebadged and in use by a number of third parties. Grinberg says discussions are under way with at least a dozen other financial services groups and online providers to further roll out the service.
Recommended for you
ASIC has released the results of its first adviser exam to be held in 2025, with 241 candidates attempting the test.
Quarterly Wealth Data analysis has uncovered positive improvements in financial adviser numbers compared with losses in the prior corresponding period.
Holding portfolios that are too complex or personalised can be a detractor for acquirers of financial advice firms as they require too much effort to maintain post-acquisition.
As the financial advice profession continues to wait on further DBFO legislation, industry commentators have encouraged advisers to act now in driving practice efficiency.