National Australia Bank’s September outage did not merely inconvenience app users—it exposed a policy fiction we have tolerated too long: that open banking can compensate when core banking stops. For hours, customers could not reliably move money, see cleared balances, or complete card payments, even as accredited data recipients still pulled read-only feeds from APIs that sat atop the same fragile stack. We should say plainly what that means for the Consumer Data Right: portability and transparency are not substitutes for ledger uptime, and regulators who grade banks on consent screens while tolerating repeated incident notices are grading the wrong exam.

Our argument is that Canberra’s competition story—more fintech switches, sharper comparison tools, richer transaction exports—cannot mask the fact that Australians still experience major bank digital failures as household emergencies. Rent transfers stall, payroll files bounce, and small businesses miss supplier cut-offs. Open banking did not cause this outage, but it is being marketed as progress while the underlying batch and real-time payment paths remain brittle.

What failed versus what still “worked”

NAB’s service status page acknowledged degraded internet banking, mobile login loops, and intermittent BPAY processing during the peak window—exactly the rails people use for mortgages and school fees. Meanwhile, accredited data holders could still satisfy read requests for some accounts, creating a surreal split screen: your budgeting app might show yesterday’s transactions while the bank’s own transfer screen spun. That is not consumer empowerment; it is two faces of one dependency.

The Australian Competition and Consumer Commission’s first spoofed SMS sender-ID block this week—triggered in part by phishing that mimicked NAB during outage anxiety—shows the reputational tail risk. Scammers do not need core systems down to profit, but uncertainty about whether a text is genuine rises when the bank itself cannot confirm payments in real time.

The objection—and its limit

Banks and Treasury officials will reply that the Consumer Data Right was never promised as redundancy, that APRA’s operational resilience program is tightening, and that outages are measured in hours not days compared with a decade ago. There is partial truth: incident disclosure improved, and major banks invest billions in cloud migration. But partial truth is cold comfort to a café owner who could not settle suppliers on a Friday afternoon.

Fintech cheerleaders add that outages accelerate switching—a competitive discipline incumbents fear. In practice, switching a mortgage or business account takes weeks, and many households keep NAB because branch networks and employer payroll files are sticky. Competition policy that assumes instant portability overstates how fast ordinary customers can vote with their feet.

What should change

First, APRA and the ACCC should publish a joint uptime scorecard for materially important digital services—payments, balances, card authorisations—distinct from open-banking API availability. If read APIs stay green while write paths fail, that gap belongs in the headline number, not a footnote.

Second, Treasury should require outage compensation frameworks with automatic micro-credits for retail customers after defined thresholds, rather than case-by-case goodwill gestures. Third, phishing enforcement must stay coupled to infrastructure incidents: when sender-ID blocks land the same week as a major bank failure, regulators should coordinate customer communications through a single government channel, not a patchwork of bank tweets.

Until core uptime is treated as a utility obligation, open banking will remain a useful but secondary reform—exposing account data while the account itself cannot transact. Australians deserve both: the right to share data safely and the right to expect that when they tap pay, the bank’s ledger is alive. We cannot keep praising API innovation while apologising for the same missed cut-offs every quarter.