Consent and Statement-Sharing Tooling for Zambian Lenders Ahead of Open Finance
Zambian lenders and fintechs still depend on bilateral data-sharing agreements or on customers forwarding their own statements, while new law and regulator plans point toward consented data sharing whose technical manner is not yet set.
Evidence
The Bank of Zambia’s Position Paper on Open Finance (uploaded June 2026) says consumers must request bank or mobile-money statements from their current provider and pass them to new providers “mainly through insecure digital or physical means”, with no built-in check on authenticity, and that data sharing between institutions relies on bilateral agreements. It plans a phased path: governance and draft standards in 2025-2027, a mandatory-sharing test with a small group of major providers in 2027-2028, and all banks and payment service providers in 2028-2030, following standards such as FAPI and ISO 20022. Section 58(1) of the National Payment System Act, 2026 (No. 5 of 2026) says a payment service provider “shall facilitate” consented sharing of customer data with another regulated entity or a third party authorised by the Bank, and section 58(2) leaves the manner to the Bank. The Act takes effect on a date the Minister appoints by statutory instrument; whether that date has been set was not checked. A consent and statement-ingestion layer is an AfriAI build hypothesis. These sources do not show lender demand or willingness to pay.
First customer
Digital lenders and microfinance institutions in Zambia that underwrite from customer-supplied bank or mobile-money statements.
Build path
- 1. With one lender, capture express consent and ingest customer-supplied statements in one or two formats, with authenticity and consistency checks.
- 2. Generate consent receipts and an audit log that map to the consent requirements in the National Payment System Act and the Data Protection Act, 2021, hosted in-country.
- 3. Keep the consent and data model API-ready so it can move to Bank of Zambia standards when they are issued.
Risks
- The manner of sharing is still for the Bank to determine (section 58(2)), and the Act may not yet be in force.
- Extraction errors or forged statements create false confidence; extraction must be validated, not trusted.
- Consent, data-protection, and localisation rules need legal review. This is a technical hypothesis, not legal advice.
Next action
Interview 8-10 Zambian lenders on how they obtain and verify statements today and how many applications stall on missing or unverifiable data; ask the Bank of Zambia Payment Systems Department for its consultation timetable.
Last reviewed 2026-09-29 · Monthly review cadence
Get the next Field Desk brief by email
Sourced African tech signals — one email, every Monday.
More FinTech teardowns
AI Credit Scoring for Informal Economy Workers
Map three lenders with default data and one mobile-money partner with consented transaction access.
AI Governance Workbench for Small Regulated Lenders
Interview 10 risk and compliance officers at microfinance banks and digital lenders: what would they need to answer a regulator’s AI questionnaire this quarter?
Read the weekly radar
Signals that mature into teardowns like this one — delivered every week.
Subscribe on the blogOpportunity teardowns are editorial analysis, not investment, financial, or business advice. Market sizes and projections are estimates — do your own diligence. Read the full disclaimer.