Inside Brazil’s Open Finance Gap: Why Only 3% of Companies Are Connected — And What It Will Take to Close It

Q&A interview with Daniel Ruhman, Co-founder and CEO of Cumbuca

  1. Brazil runs the world’s largest open finance ecosystem, yet only 3% of Brazilian companies are connected to it, compared to 20% in the UK. What has been the single biggest barrier holding that adoption back, and is it a technical problem, a regulatory one, or something else entirely?

The biggest barrier to adoption is the rigorous process of obtaining the necessary licenses to operate, which can take several years and incur high costs. Organizations must obtain authorization from the Banco Central do Brasil (BCB), register in the Participant Directory, obtain Financial-grade API Advanced certification (FAPI 1.0), and pass other steps. This sequence of hurdles significantly impacts companies’ ability to build brand presence and establish profitability when entering the Open Finance ecosystem in Brazil.

Daniel Ruhman
Daniel Ruhman

The lack of standardization in the consent journey also makes it harder for users and companies to provide approval for solutions to access their company account data or to create B2B solutions using open finance. The main problem is that if the company has more than one partner, or more than one person that needs to approve a payment, data consent or transmission, they do not fit in the standardized consent that works for B2C, for users to give consent on their accounts. Adoption is halted in companies with multi-level approval as a result.  For example, only about 20% of user approvals for data sharing result in payments. Customers are unwilling to complete complex consent processes, resulting in low long-term retention. The BCB acknowledged this in its 2025/26 regulatory agenda, committing to reform the consent process and reduce customer friction, which is welcome but long overdue.  

For most companies in Brazil, adoption is slowed by a mix of regulatory complexity and developer resources that are difficult to navigate, making it critical to simplify onboarding and customize consent flows to business needs. 

  • The Open Finance Playground translates hundreds of pages of regulatory documentation into step-by-step developer workflows with live API simulations. What made Cumbuca and the Juspay team decide that this kind of practical, open-source resource was the missing piece and why hadn’t it existed before?

Cumbuca and Juspay created the Playground from real-world experience implementing Open Finance end-to-end in Brazil and the challenges they faced. The official documentation produced by the Banco Central and Open Finance Brazil working groups is comprehensive, but it was written to describe what the system requires rather than to teach developers how to build on it. 

When Cumbuca started working with JusPay, we saw that many teams were struggling with hundreds of pages of specifications, scattered cross-references to external RFCs, and were learning through trial and error. This slows the process down, increases the risk of errors and makes the ecosystem harder to enter. 

The Open Finance Playground did not exist before because the ecosystem was still in a regulation-first phase. The initiative aims to address this and make the process developer-first. For the SMEs, fintechs, and payment initiators who don’t have dedicated regulatory engineering teams, it’s the difference between being inside the ecosystem or watching it from the outside.

  • Consent flows, payment initiation, and data access are the three core areas the Open Finance Playground covers. As open finance matures in Brazil, which of those three do you expect to drive the most transformative new products and services for end users?

All three are important, but I think Payment Initiation will be the most transformative when combined with PIX over the next few years. Payment Initiation API calls grew 194% in 2024, reaching 159 million, up from 54 million the year before. Whilst the consent journey for corporate clients requiring multiple signatures remains a significant obstacle, they are invisible to the end user once they work. Payment initiation layered on top of consent and data enables a financial life that operates proactively on your behalf, allowing users to safely share data, receive better financial services and then act immediately through a payment or transfer. That’s a new category of product, and Brazil’s infrastructure is closer to enabling it than almost any market in the world.

Payment initiation services are scaling rapidly but represent a fraction of total Pix usage. Pix processes over 6 billion transactions per month, with 7 billion in January 2026 alone. The Central Bank’s instant-payment system handles 79.8 billion transactions a year and reaches 170 million users, 91% of Brazilian adults. Cumbuca is working on innovating new types of payment initiation and an optimized journey that offers access to data and payments. It’s a much younger and underutilized market, so it has much more space for innovation and growth.

  • Looking two or three years ahead, what does success look like for open finance in Brazil? And what needs to happen from a policy or industry coordination perspective for this to be achieved?

For open finance adoption to grow, we need more use cases in the market. There are currently a few data use cases, but there’s still many more that can be implemented in the ecosystem, such as Know Your Customer (KYC), anti-fraud, confirming monetary situations for social benefits. There is also strong potential for agentic payments using payment initiation and greater innovation within WhatsApp to enable users to checkout without leaving the app, using linked bank accounts to instantly authorize secure transfers directly from their bank balance, without the need for manual card entry. 

Open finance is also too expensive for many companies looking to innovate and bring new use cases to market. Lower pricing from payment initiators would help accelerate adoption and growth. However, with firms facing a tenfold increase in capital requirements and remaining subject to these rules until the end of 2027, reducing margins is not a realistic option without broader changes to the regulatory environment.

Another important piece of the puzzle is the eventual consolidation of players in the Open Finance as a Service (OFaaS) sector. Pure Open Finance operators face a high-volume, low margin reality, and monetizing raw data aggregation or Payment Initiation Services (PIS) is difficult at a small scale because the technical infrastructure to maintain compliance and API connectivity requires substantial continuous investment. For companies that operate with Credit as a Service (CaaS), they can drastically discount or bundle the service because the profitability of the credit product easily offsets the price. However, the service will not have the same quality, as bundled providers often treat open finance as an internal feature rather than a product with tailored features.

Success for open finance in Brazil will mean it becomes normal infrastructure and developers will not need specialist integration by a large regulatory team to get started. The products enabled by open finance will be so embedded in how Brazilians borrow, pay and manage money that users stop thinking about the infrastructure underneath. From the user’s perspective, this will result in better financial products, easier onboarding, and safer account connectivity with services that work across institutions without friction. OpenAI’s Instant Checkout feature and Mastercard’s agentic tokens demonstrate how rapidly this is evolving and the potential for innovation, but Brazil’s infrastructure is already well-prepared for it.

Achieving progress requires policy and industry alignment on clear standards and enhanced resources for developers. Most importantly, the current one-size-fits-all regulatory and onboarding requirements including FAPI certification, ICP-Brazil certificates, Dynamic Client Registration, and conformance testing should be tailored to reflect each participant’s risk and role. While the BCB recognizes this need, and the 2025/2026 agenda shows intent, the main question is whether changes can be made quickly enough over the next two or three years.

  • Open banking frameworks everywhere tend to produce documentation written for regulators, not developers. How much does that mismatch between regulatory spec and real-world implementation explain the slow pace of adoption?

It explains a lot of it. When a developer sits down to implement an Open Finance consent flow in Brazil for example, they are looking at Joint Resolutions, BCB normatives, FAPI security profiles, Open Finance Brazil technical specifications, and ICP-Brazil certificate requirements that are each maintained by a different body, updated on different cycles, and assuming deep familiarity with financial regulation. That mismatch creates a hidden cost, and for startups this can be a significant hurdle, leaving them to either persevere through months of trial and error or quietly deprioritize the integration entirely. This underscores the need for step-by-step implementation guides that developers can easily understand.

  • There’s a growing argument that the next wave of fintech innovation won’t come from new regulation, but from making existing infrastructure easier to build on. Do you agree, and what does that shift look like in practice?

I agree, in Brazil we already have a lot of the foundational infrastructure across Pix, Open Finance and payment initiation. The next wave of innovation will come from better tooling, documentation for developers that is easily accessible, and platforms that will enable companies to build quickly, safely and at scale. Recent regulations have made compliance more challenging for businesses, especially startups. 

  • For developers picking up Open Banking APIs for the first time, what are the two or three things that official documentation simply won’t tell them and where do most teams get stuck in practice? 

For developers picking up Open Banking Application Programming Interfaces (APIs) for the first time, the biggest obstacle isn’t so much what the documentation leaves out; it’s figuring out where to begin. There’s a whole series of protocols, certifications, and certificates to prioritize implementing. In addition to that, even once you have a working environment, there are still several parallel activities to handle: Platform for Metrics Collection (PCM) reports, Data Quality Motor (MQD) integration, getting access to and using the Service Desk, configuring the software statement, and configuring the authorization servers.

If you look at the Financial-grade Application Programming Interface (FAPI) protocol alone, there’s a set of Request for Comments (RFCs) you have to follow for everything to work correctly. Interoperability becomes a recurring issue when we talk about complexity. The first occurrence is during the security certifications, or the functional certifications, because any detail that slipped through in your implementation can make certification impossible. The second time is once the service is running in production: even when you’re certified and following the standards, there are still unforeseen scenarios in the communication between institutions that end up causing problems.

Two things in particular tend to catch teams off guard. The first is consent for legal entities, or Pessoa Jurídica (PJ), as if it isn’t standardized, that’s exactly the kind of detail that slips past you in the documentation, and you usually only run into it once you’re dealing with real corporate customers. The second is that teams genuinely get stuck on the technical implementation itself. There are a lot of requirements to meet, and grinding through all of them is where most of the effort really goes.

We are close in Brazil, but not fully there globally yet. In 2025, Pix was on track to surpass 8 billion monthly transactionsafter it became the default model for how Brazilians expect money to move. This happened because the volume became undeniable, and because the infrastructure became something businesses and consumers depended on. The industry that has understood the power of Open Finance the most is credit and lending, as their services are used by consumers every day. Other industries do not have a clear vision of how to implement Open Finance in their day-to-day workflows or in their projects.

The Open Finance industry will be seen as core infrastructure with usage. Right now, the users of payment initiation are unaware that they are actually using Open Finance. The market needs to grow and provide better education about where Open Finance is being used and what value it offers on a day-to-day basis.

The shift in how the industry treats open banking will happen when it is no longer discussed as a separate innovation and becomes part of how financial products are built, in the same way that developers can rely on cloud infrastructure or card networks for predictable access and clear standards. Brazil has a real opportunity to lead this transition and the next step will involve making the infrastructure easier for more companies to build on top of it. 

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here


Latest Articles