Data & Technology
Selecting a Customer Data Platform for Financial Services: Criteria and RFP Checklist
Selecting a Customer Data Platform for Financial Services Providers: RealCDP Criteria, DORA/EBA Mandatory Questions, and Red Flags in the RFP.
•
acceleraid Editorial Team
5 min read
01
Acquire
Recognize signals
02
Onboard
Control activation
03
Grow
Next Best Action
04
Retain
Reduce churn
05
Reactivate
Reclaim potential

Part 2 of our new series on Customer Data Platforms in the financial sector. Part 1 covered definition, architecture, and regulatory foundations. This part translates that into a concrete selection process.
Selecting a Customer Data Platform for financial service providers rarely fails due to a lack of vendors — the market alone counts 217 CDP vendors with a cumulative $10.5 billion in funding (CDP Institute / Customer Data Alliance). It more frequently fails because criteria catalogs remain vague and regulatory compliance questions only surface after the contract is signed. Anyone looking to systematically select a Customer Data Platform for financial service providers needs a criteria catalog that covers both functional RealCDP requirements and regulatory obligations of DORA and EBA guidelines.
Functional criteria: the seven RealCDP requirements as an evaluation framework
The most robust, vendor-neutral starting point for a criteria catalog is the seven RealCDP core requirements of the CDP Institute: ingest from any source, full detail, persistent storage, unified profiles of identified individuals, data sharing with any connected system, real-time response, and governance according to local data privacy and security laws (CDP Institute, RealCDP). These requirements can be adopted 1:1 as an evaluation framework in an RFP — instead of inventing custom, softer criteria.
Particularly important is a hard, verifiable definition of "real-time": RealCDP requires "under one second" for both ingesting new data and responding to a profile query (CDP Institute, RealCDP). Vendors making only a vague "real-time" promise should be committed to a specific number in milliseconds in the RFP.
Equally crucial: proof obligation instead of self-declaration. RealCDP audits are evidence-based, requiring three reference customers with contact details and specifically testing Change Data Capture, real-time identity graphs, and data clean rooms (CDP Institute, RealCDP). The same level of proof can be demanded in your own RFP process, even without formal certification from the vendor.
Specifically query agentic AI features
Many CDP vendors now promote agentic AI features. Here, a differentiated inquiry is worthwhile: RealCDP requires documentation of autonomy levels — assistive, supervised (human-in-the-loop), or fully autonomous — for such implementations, with the explicit rule: "Autonomy is not permitted to bypass governance" (CDP Institute, RealCDP). An RFP should ask accordingly which autonomy level a vendor actually supports for which feature — not just whether "AI" is in the product.
Another often overlooked point: a CDP does not automatically replace a consent management platform. The CDP Institute Vendor Privacy Survey Report examines this exact question for "40+ vendors" (CDP Institute Library) — consent management should therefore be treated explicitly as a separate requirements block in the RFP.
Regulatory RFP mandatory questions

For financial service providers, mandatory contractual minimum contents are added to the functional criteria. Art. 30 Para. 2 DORA requires for ALL ICT services, among other things: a clear and complete description of services including the permissibility of subcontracting, the locations of service provision and data processing along with the storage location with a prior notification obligation in case of changes, regulations on data access and return at the end of the contract, as well as termination rights and minimum notice periods (DORA, Art. 30 Para. 2).
If the CDP is used for critical or important functions, the requirements under Art. 30 Para. 3 DORA tighten significantly: full SLAs with precise quantitative performance targets, participation in threat-led penetration testing (TLPT), unrestricted access, inspection, and audit rights, as well as mandatory exit strategies with an appropriate transition period (DORA, Art. 30 Para. 3). BaFin explicitly specifies this obligation: exit strategies must be developed, and a binding, appropriate transition period must be contractually agreed upon (BaFin, Cloud Supervision Announcement).
The EBA guidelines also provide specific contract clauses that should be queried in the RFP: the contract must specify the locations of service provision and data processing including possible storage locations — with a notification obligation if the provider plans to change locations (Para. 75(f)) — and include regulations on accessibility, availability, integrity, confidentiality, and security of relevant data (Para. 75(g)) (EBA/GL/2019/02).
RFP Checklist Overview
Category | Mandatory Question | Source |
|---|---|---|
Real-time | Response time for ingest and profile query in milliseconds? (Benchmark: under 1 second) | |
Proof | Three reference customers with contact details, proof of CDC, identity graph, data clean rooms? | |
AI Autonomy | Which autonomy level (assistive/supervised/fully autonomous) per function? | |
Data Location | Specific data center location, notification of changes? | |
Exit Strategy | Binding transition period, platform-independent export formats? | |
Audit Rights | Unrestricted access, inspection, and audit rights contractually fixed? |
Source: own compilation based on the primary sources cited above.
Red Flags in Vendor Evaluation
Four warning signs are evidence-based and should stop or at least slow down any CDP evaluation:
"Choosing the vendor solves our data problem": The 2025 CDP Institute Member Survey explicitly lists governance, integration, skills, and value realization as actual barriers — not vendor choice (CDP Institute, 2025 Member Survey).
No AI governance framework before project start: Only 14% of banks have a specific AI governance framework (McKinsey, Getting personal) — a CDP project without this framework is built on sand.
Models without an activation path: Only about 8% of banks can actually use predictive insights from their ML models for campaign execution and decisions (McKinsey, Getting personal) — scoring without orchestration creates no value. How orchestration logic actually works is demonstrated in our post on how a Next-Best-Action engine makes decisions.
Intransparent pricing model: In usage-based billing models, anonymous website visitors sometimes count as billable profiles — a point that Part 3 of this series on cost and TCO covers in detail (Twilio Segment Docs, MTUs, Throughput and Billing).
Organizational checkpoints parallel to vendor selection
Technical and regulatory criteria are necessary but not sufficient. Parallel to vendor selection, every bank should check its own operational readiness: Are silos or a limited tech stack a central pain point — as 59% of surveyed brands confirm (BCG, Personalization Consulting)? Is a centralized customer database missing, as is the case for 41% (BCG, Personalization Consulting)? Is the organization even capable of working out of separate silos, or does a silo operating model with numerous handovers dominate, as with 71% of respondents (BCG, Personalization Consulting)?
In the end, these organizational questions determine project success just as much as technical vendor selection. Acceleraid's CDP & Data Governance module is specifically designed for the regulatory requirements mentioned: real-time connection to core banking systems, CRM, and card processing, consent management, lineage documentation, PII protection, and German hosting based on GDPR-by-design principles (Acceleraid Platform).
Anyone who consistently applies this criteria catalog significantly reduces the risk of a failed or delayed CDP project — and shifts the actual discussion to where it belongs: to costs and the business case, the topic of the third part of this series.
In practical implementation, it is recommended to split the RFP process into two phases: a first knock-out round solely checks the hard regulatory criteria — data location, exit strategy, audit rights — before functional details or pricing are even discussed. Vendors who cannot or will not meet these mandatory criteria are eliminated regardless of their technical maturity. The detailed evaluation of the seven RealCDP capabilities follows only in the second round, based on concrete vendor demos and reference calls. This sequence prevents institutions from investing time in vendors who are out of the question for regulatory reasons anyway.
Illustration: AI-generated. AI-supported content: We use AI technologies and automated agents, including those from Microsoft, Google, OpenAI, Anthropic, and other providers, when creating our articles. Topics, professional direction, and final approval rest with our team.
Further Insights
We use cookies 🍪
Strictly necessary cookies (e.g. Pipedrive forms) remain active. With your consent, we also use Google Analytics (analytics) and Leadfeeder (visitor identification). Learn more in our Privacy Policy.