Any serious conversation about subscription management in banking should start with a cancellation route that shows up in none of your product analytics. When a subscription becomes hard to escape, customers stop trying to reach the merchant. They come to you, and they block the payment or ask for a new card.
Half of Gen Z consumers say they block payments to cancel a subscription. It works, it takes a minute, and for most customers it is the only cancellation mechanism their bank has ever offered them.
It also does considerably more damage than the customer intends, and almost all of that damage lands on the cards and loyalty P&L while the fix sits on a digital roadmap somewhere else.
Three arguments follow. The cost of not offering subscription management is already being paid, and it hides inside other budget lines. The capability can also be understood through the lens of ongoing consent and control , which changes who in the bank should own it. And across South East Asia and the Gulf, the frameworks being built right now are quietly deciding where the customer’s consent view is going to live.
Taken together, that makes subscription management more than a financial wellbeing feature. It touches card retention, servicing cost, customer control and the bank’s ability to remain the place customers go to understand and manage their financial lives.
The cancellation route that breaks everything else
A blocked card does not end one subscription. It ends every card-on-file arrangement that card was funding.
The streaming services, the utility payments, the wallet top-ups, the recurring transport pass, the cloud storage nobody remembers signing up for. All of it fails at the next billing attempt. The customer re-registers whatever they still want, and while they are doing that, they reach for whichever card is closest to hand. Sometimes it belongs to a competitor.
A customer trying to escape a nine dollar monthly charge can therefore cost an issuer its top-of-wallet position across a dozen merchant relationships. What the bank records is a card replacement request. What it loses is recurring volume that simply stops arriving, with nothing in the system to connect the two events.
This is the number worth calculating, and very few institutions have: take card replacement volume, estimate the share driven by subscription cancellation instead of loss or fraud, and multiply by the card-on-file arrangements a typical active card carries. Most banks cannot produce that figure, because nobody has ever asked for it in that shape. The ones who do produce it stop filing this under customer experience.
That is the first reframe. If subscription management is evaluated only as a PFM or customer experience feature, it competes for budget against every other item on the digital roadmap. If its absence is contributing to card replacement, lost recurring payment volume, disputes and servicing demand, the economics sit somewhere else.
A cheaper intervention exists, and it does not depend on survey data to make sense. Any exit route that preserves the card beats one that destroys it, because the card is what every other recurring arrangement is hanging from. Mastercard puts a number on the appetite, reporting that 34% of consumers would stay subscribed if they could pause instead of cancelling, though it publishes no sample or geography behind that figure. A pause option keeps the card alive, keeps the merchant relationship intact, and keeps the issuer in the payment flow. Three parties benefit from the same button, which is rare enough to be worth noticing.
The product point is not that every bank needs to become the cancellation interface for every merchant. It is that customers are already using the bank as a last-resort subscription management tool, and the instrument they are using is unnecessarily destructive.
Why this cost is invisible on every dashboard
The cost of not having subscription management never appears as a line item, because it is spread across three cost centres that each record it under a different name.
A dispute raised because a customer could not recognise a merchant is logged as a fraud dispute. A card blocked to stop a recurring charge is logged as a card replacement. A call about an unrecognised payment is logged as general servicing. Nothing ever aggregates into a category that reads “we do not offer subscription management”, which is precisely why the business case for offering it never gets written.
The volumes are substantial. 29% of consumers have disputed a recurring payment they believed was fraudulent. 67% say they would dispute fewer charges if the information had been available in their banking app. Every one of those is an operational cost the institution already absorbs and gets nothing back for.
A note on those figures. Mastercard publishes them without a stated sample size, fieldwork window or geography. They are the best available numbers on this behaviour and they align with the independent research cited below, but they are one provider’s figures and not survey data you can interrogate.
The reframe: a subscription is a standing consent
There is a more useful way to think about this category, and it changes who inside the bank should own it.
A subscription is a standing consent to be charged. A marketing permission is a standing consent to be contacted. An open finance authorisation is a standing consent to be read. Most banks have all three, owned by different teams: payments or cards holds the first, compliance and marketing hold the second, and the open finance programme holds the third.
Customers experience no distinction between them whatsoever. What they want to know is one thing: what have I agreed to, and how do I stop it?
That does not mean the three forms of consent are legally or technically the same. Each has its own regulatory requirements, revocation process, and supporting infrastructure. But from the customer’s perspective, they share an important feature. Each is an ongoing permission or commitment that stays active until something changes. This makes consent a useful lens for thinking about the customer experience, without suggesting that the bank should treat three distinct regulatory systems as one.
Customers cannot answer it either
The evidence here is unusually blunt, and the most useful of it comes from the markets that matter most to banks in this region.
Research published in 2023 across India, Indonesia, Malaysia, the Philippines, Thailand and Vietnam, covering more than 6,000 consumers, found 44% had forgotten about active subscriptions and carried on paying for them, while 32% pay for services they never use. A 17-market study fielded in February 2024 found that only 38% of subscribers had used all of their subscriptions in the previous six months, and that in Indonesia 14% could not say how many of their services they had used at all. Not that they had too many. That they could not say.
The picture on consent given is worse than the picture on money spent. Polling of 3,000 UK adults in early 2024 found 26% had accidentally taken out a subscription in the previous 12 months, and among those, 24% believed they were making a one-off purchase. A quarter of accidental subscribers were not confused about the terms. They thought they had bought a thing once.
So the average customer carries an unknown number of standing commitments, some of which they may not remember agreeing to or did not realise were recurring , spread across three categories they cannot see. Regulators have noticed, which is why all three are now moving at once.
Regulation is tightening on all three fronts, separately
Each consent category has acquired its own rulebook, and none of them join up.
Recurring charges. In the EU, the Consumer Rights Directive now requires a labelled, continuously available “withdraw from contract here” function on online interfaces, and since June 2026 that obligation extends to consumer financial services contracts concluded at a distance. It applies through national transposition, so timing varies by member state. In the UAE, the CBUAE Consumer Protection Standards require 30 calendar days’ written notice before an automatic annual renewal, including how and when it can be cancelled. In the UK, the FCA states that card issuers must stop a recurring card payment on request and cannot insist the customer approach the merchant first.
Marketing permissions. The CBUAE standards set marketing to default off: without express opt-in, a consumer is treated as having opted out of promotional communication of any kind. Consumers may withdraw consent at any time, and unless specified otherwise the withdrawal must take effect within 30 calendar days. The CBUAE Telemarketing Regulation, binding on licensed financial institutions and effective 31 March 2026, requires that consent itself specify the customer’s preferred language, chosen channels, preferred contact methods including AI agents and robocalls, and the product types they wish to hear about. SAMA’s advertising rules require institutions to let customers permanently refuse marketing “easily and in clear and specific ways”.
Data sharing. The CBUAE Open Finance Regulation requires licensed institutions to expose account and product data through consent-based sharing. The scope runs across deposits, payment accounts and services, savings and term deposits, credit, debit and charge cards, standing orders, direct debits, stored value and prepaid accounts, foreign exchange products, credit and personal finance, mortgages and asset-secured loans, virtual accounts and insurance. The regulation states that withdrawing consent “should not require undue effort” and “should be at least as simple, quick and easy as the process of giving consent”, and caps consent for recurring access at twelve months.
Bank Negara Malaysia has gone furthest. Its open finance exposure draft would require financial service providers to maintain a customer-accessible digital dashboard showing all active and past consent granted, with revocation “as straightforward as it was to obtain the consent” and recurring consent capped at six months. It remains a proposal, consulted on until March 2026 with a proposed effective date of 1 January 2027 and no final policy document published, but it is the clearest published statement of where this is heading.
Two points get misstated often enough to be worth correcting. The EU’s Financial Data Access Regulation would place a permission dashboard obligation on data holders, but that text is the 2023 Commission proposal, trilogues stalled in 2025, and the Commission spent 2026 circulating options to make the regime less burdensome. It has not become law and the dashboard article may not survive in its present form. In the UK, meanwhile, the FCA considered mandating consent dashboards in 2021 and declined to mandate them on anyone, making account information providers responsible for periodically reconfirming consent instead.
That second point carries more weight than it first appears. In most markets today, a bank that builds a unified consent view has made a competitive decision, and the compliance department did not ask for it.
In this region, the frameworks are already deciding this
Here is the part worth sitting with, and it is specific to South East Asia and the Gulf.
In several of these markets, the consent layer has been designed to sit at scheme or national level. The UAE’s open finance framework routes consent through a central layer, and the accompanying consumer app presents an overview of all active and inactive consents granted under the framework, across different financial institutions, with revocation available at any time. In Singapore, SGFinDex is built on the national digital identity with a centrally managed consent system. In India, consent management has become a separately licensed business: seventeen operational account aggregators, more than 1,100 live institutions on the network, and over 490 million consent requests fulfilled.
Note what the UAE regulation asks of licensees. Every institution in scope has to establish and maintain an interface exposing account and product information through the central hub, whether or not it intends to offer open finance services of its own. The obligation produces a compliant pipe. Turning that pipe into something a customer opens is a separate decision, and nothing in the rulebook prompts anyone to make it.
Where dashboards have existed longest, the design has fragmented on purpose. The UK standards specify one dashboard on the bank side for third-party access and a separate one on the third-party side for consents, split again across account information, variable recurring payments and card-based instruments. The standards themselves warn firms that a customer may revoke one permission and never realise another is still running.
Meanwhile the definition of a primary bank has been shifting underneath the industry for years. US research published in 2020 found the most-used current account fell from 81% to 54% as the identifier consumers chose between 2015 and 2020; trade coverage of the same study reported that most-used mobile app was selected by 24%, having drawn no mentions at all in 2015. That data is American and several years old, which probably makes it a conservative read. Primary status is drifting towards whichever app gets opened, and away from whichever account holds the salary.
In the subscription category specifically, somebody else has already claimed the expectation. In that same 2023 APAC research, 93% of consumers said they wanted a single hub to manage all their subscriptions and 95% said they would show greater loyalty to a provider offering one. Asked who they trusted to build it, 81% chose telcos. Banks were not the answer. That was three years ago, and no major bank in the region has moved to change it.
What the bank can see that nobody else can
The bank’s real advantage has nothing to do with building a better consent screen. It is that no other party can see all three categories of consent at the same time.
A national consent app can show a customer every data-sharing permission they have granted across every institution. It cannot show them the streaming subscription charged to their card, because that charge was never registered as a consent anywhere. It arrived as a transaction.
A specialist subscription tool can show a customer their recurring charges, and nothing about which third parties are reading their account data or what their bank is allowed to contact them about.
A marketing preference centre covers the third category and neither of the others.
The bank sits on all three at once. It is a data holder under open finance, it sends the marketing, and it holds the transaction stream where unregistered commitments actually live. A single register of everything a customer has agreed to is a proposition available only to banks.
One condition decides whether any of it is possible.
The register depends on merchant identification
The recurring-commitment half of that register needs the institution to name a merchant, and most cannot do it reliably.
Direct debits and standing orders are the easy part, because they are formal instructions the bank already holds. The commercially significant commitments are card-on-file charges, and in a raw transaction stream those look exactly like ordinary card spending. Descriptors arrive truncated or abbreviated. They change between months. They frequently resolve to a payment facilitator instead of the service the customer would recognise. Amounts drift as prices rise and tiers change. The merchant universe changes daily.
Build a consent register on raw transaction data and the customer gets their data-sharing consents, their marketing permissions, and a partial, unreliable list of the commitments actually costing them money. A register that misses a third of a customer’s commitments does more harm than no register at all, because it implies a completeness it cannot deliver.
Transaction enrichment is usually sold as a personalisation input. Here it becomes a trust dependency. Merchant identification is what separates telling a customer what they have agreed to from guessing at it.
Frequently Asked Questions
It generally protects it. Customers who cannot cancel easily block the payment or replace the card, which terminates every card-on-file arrangement that card was funding, not only the one they wanted to end. A pause option keeps the card active, and 34% of consumers say they would stay subscribed if they could pause instead of cancelling.
No. Traditional personal financial management reports what has already happened, and most banks treat it as a cost centre. Subscription management works earlier in the sequence, intervening before the next payment leaves the account, so it changes the outcome. Its effects show up in disputes, servicing volume and card retention.
Not widely, and the position is often overstated. Bank Negara Malaysia has proposed one in its open finance exposure draft, which would require a customer-accessible dashboard showing active and past consent, with a proposed effective date of 1 January 2027. No final policy document has been published. The EU’s Financial Data Access Regulation would place a permission dashboard obligation on data holders, but that is the 2023 proposal text and the regime is still being renegotiated. The FCA considered mandating dashboards in the UK in 2021 and declined to mandate them on anyone. In most markets, building one is a competitive decision.
No. There is no regulation in the GCC or most other markets requiring banks to surface third-party subscriptions. Consumer protection rules cover a bank’s own recurring fees, automatic renewals and marketing consent. What drives a subscription and consent register is customer demand, competitive pressure, and the efficiency of meeting three consent obligations with one layer.
Because in raw form most recurring card charges look identical to ordinary card spending. Descriptors are truncated, inconsistent between months, and frequently resolve to a payment facilitator instead of the recognisable service. Amounts and dates drift. Without merchant identification and periodicity detection, any subscription list will be materially incomplete, and an incomplete register does more harm than none because it implies a completeness it cannot deliver.
That question is usually the reason nothing ships. Recurring commitments sit with payments or cards, marketing permissions with compliance and marketing, and data-sharing consents with the open finance programme. Treating all three as one register with one owner is what turns three compliance projects into a single product.
