Brankas · Open finance · B2B2C
Making open banking safe enough to use.
Context
Brankas is Southeast Asia's leading open-finance infrastructure company, operating across 10+ countries. Brankas Tap is the consumer-facing screen shown when someone picks an open-banking payment method at checkout — a B2B2C product, so consumers meet it without ever knowing the Brankas brand. That invisibility is the whole problem: users see an unfamiliar third-party screen at the exact moment they're handing over access to their bank.
The problem
More than 10% of users were dropping off at the Tap authentication screen — a large, direct conversion loss for Brankas' clients. Analytics showed what was happening (exits, wrong credentials, expired OTPs). It couldn't explain why. The target: get drop-off from over 10% to under 2%.
What I did
I owned the research end to end — analytics review, user interviews and usability testing — and it surfaced four root causes: a trust problem (an unexpected third-party screen felt unsafe, causing deliberate exits), credentials not being to hand, confusion between banks' app and web logins, and OTP delivery failing on high-traffic days through no fault of the user. I ran workshops with the product team to align on the problem and commit to two hypotheses — a quick win and a longer-term bet.
Project Chameleon was the quick win: dynamically theme the Tap screen to match the selected bank — its logo, its colours — so it reads as a natural extension of the bank rather than a foreign screen. The Tap App was the long-term bet: a credential vault enabling one-tap approval that bypassed OTP entirely.
Outcome
Chameleon ran as a controlled experiment against a holdout and produced a statistically significant reduction in the intentional exits driven by trust — validating that trust, not mechanics, was the primary driver for that segment.
The harder call
The Tap App was technically promising and user-validated — but as we moved to build, we hit a wall: most partner banks ran on robotic process automation, not modern APIs, so the reliable connectivity one-tap approval depended on simply didn't exist in the market yet. I made the call to stop — to not pour engineering into a solution the market's infrastructure couldn't support — and documented the concept fully for when API availability caught up. Good product work includes knowing when not to ship.
What it proves
B2B2C trust design — where the end user has no relationship with your brand — breaks the standard playbook. I ran this alongside my de facto Head of Operations mandate at Brankas, pairing rigorous root-cause research with the judgment to de-prioritise a validated idea when business reality wouldn't support it.