Data & Technology
How to Choose a Customer Data Platform for Financial Services
Choosing a customer data platform for financial services: RealCDP criteria, DORA/EBA must-haves, and red flags for your RFP.
•
acceleraid Redaktion
5 min read
01
Acquire
Signale erkennen
02
Onboard
Aktivierung steuern
03
Grow
Next Best Action
04
Retain
Churn reduzieren
05
Reactivate
Potenziale zurückholen

Part two of our new series on customer data platforms in financial services. Part one covered definition, architecture, and regulatory foundations. This part turns that into a concrete selection process.
Choosing a customer data platform for financial services rarely fails for lack of vendors — the market alone counts 217 CDP vendors with $10.5 billion in cumulative funding (CDP Institute / Customer Data Alliance). It more often fails because criteria stay vague and regulatory must-haves only surface after the contract is signed. Selecting a customer data platform for financial services systematically requires a criteria catalog that covers both functional RealCDP requirements and the supervisory obligations under DORA and the EBA guidelines.
Functional criteria: the seven RealCDP requirements as an evaluation grid
The most solid, vendor-neutral starting point for a criteria catalog is the CDP Institute's seven RealCDP core requirements: ingest from any source, full data depth, persistent storage, unified profiles of identified individuals, data sharing with any connected system, real-time response, and governance in line with local privacy and security law (CDP Institute, RealCDP). These requirements translate directly into an RFP evaluation grid — no need to invent softer, home-grown criteria.
A hard, testable definition of "real time" matters especially here: RealCDP requires "under one second" for both ingesting new data and answering a profile query (CDP Institute, RealCDP). Vendors that only offer a vague "real-time" promise should be held to a concrete millisecond figure in the RFP.
Equally important: proof, not self-reporting. RealCDP audits are evidence-based, require three reference customers with contact details, and specifically test change data capture, real-time identity graphs, and data clean rooms (CDP Institute, RealCDP). The same standard of proof can be demanded in your own RFP process, even without formal vendor certification.
Probing agentic AI features deliberately
Many CDP vendors now market agentic AI capabilities. This deserves a more pointed line of questioning: for such implementations, RealCDP requires documenting autonomy levels — assistive, supervised (human-in-the-loop), or fully autonomous — with the explicit rule that "autonomy is not permitted to bypass governance" (CDP Institute, RealCDP). An RFP should ask which autonomy level a vendor actually supports for which function — not merely whether "AI" appears in the product description.
Another frequently overlooked point: a CDP does not automatically replace a consent management platform. The CDP Institute Vendor Privacy Survey Report investigates exactly this question across "40+ vendors" (CDP Institute Library) — the RFP should treat consent management as a separate, explicit requirement block.
Regulatory RFP must-haves

For financial services, functional criteria come with mandatory contractual minimums on top. Article 30(2) DORA requires, for ALL ICT services: a clear and complete description of functions including conditions for sub-outsourcing, the locations where services and data processing are performed including the data storage location with an obligation to notify in advance of any change, provisions on data access and return upon termination, and termination rights with minimum notice periods (DORA, Art. 30(2)).
If the CDP supports critical or important functions, the requirements under Article 30(3) DORA tighten considerably: full SLAs with precise quantitative performance targets, participation in threat-led penetration testing (TLPT), unrestricted rights of access, inspection, and audit, and mandatory exit strategies with an appropriate transition period (DORA, Art. 30(3)). Germany's BaFin spells this out explicitly: exit strategies must be developed, and a binding, appropriate transition period must be contractually agreed (BaFin, cloud supervisory notice).
The EBA guidelines also provide concrete contract clauses worth including in an RFP: the contract must set out the locations of service delivery and data processing, including the possible storage location, with an obligation to notify if the provider plans to change locations (para. 75(f)), and must include provisions on accessibility, availability, integrity, confidentiality, and safety of the relevant data (para. 75(g)) (EBA/GL/2019/02).
RFP checklist at a glance
Category | Must-ask question | Source |
|---|---|---|
Real time | Response time for ingest and profile query, in milliseconds? (benchmark: under 1 second) | |
Proof | Three reference customers with contact details; evidence of CDC, identity graph, data clean rooms? | |
AI autonomy | Which autonomy level (assistive/supervised/fully autonomous) per feature? | |
Data location | Concrete data center location; notification on change? | |
Exit strategy | Binding transition period; platform-independent export formats? | |
Audit rights | Unrestricted access, inspection, and audit rights contractually fixed? |
Source: compiled by the editors based on the primary sources cited above.
Red flags in vendor evaluation
Four warning signs are evidence-based and should stop — or at least slow down — any CDP evaluation:
"Choosing the right vendor solves our data problem": the 2025 CDP Institute member survey names governance, integration, skills, and value realization as the actual barriers — not vendor choice (CDP Institute, 2025 Member Survey).
No AI governance framework before project start: only 14% of banks have a specific AI governance framework (McKinsey, Getting personal) — a CDP project without that framework is built on sand.
Models without an activation path: only about 8% of banks are actually able to apply predictive insights from their ML models to campaign execution and decision making (McKinsey, Getting personal) — scoring without orchestration creates no value. For a concrete look at orchestration logic, see our article on how a next-best-action engine decides.
Opaque pricing model: under usage-based billing models, even anonymous website visitors sometimes count as billable profiles — a point part three of this series covers in detail on cost and TCO (Twilio Segment Docs, MTUs, Throughput and Billing).
Organizational checkpoints alongside vendor selection
Technical and regulatory criteria are necessary but not sufficient. Alongside vendor selection, every bank should assess its own operational readiness: is a siloed operating model or a limited tech stack a central pain point — as 59% of surveyed brands confirm (BCG, Personalization Consulting)? Is there a lack of centralized customer data, as reported by 41% (BCG, Personalization Consulting)? Is the organization even able to work across silos, or does a siloed operating model with numerous handoffs dominate, as 71% of respondents report (BCG, Personalization Consulting)?
These organizational questions ultimately matter just as much for project success as the technical vendor selection. Acceleraid's CDP & Data Governance module is specifically built around these regulatory must-haves: real-time connectivity to core banking, CRM, and card processing, consent management, lineage documentation, PII protection, and German hosting under a GDPR-by-design approach (Acceleraid Platform).
Applying this criteria catalog consistently significantly reduces the risk of a failed or delayed CDP project — and shifts the real conversation to where it belongs: cost and business case, the subject of part three of this series.
In practice, it helps to structure the RFP process in two phases: a first elimination round checks only the hard regulatory must-haves — data location, exit strategy, audit rights — before any discussion of functional nuances or pricing even begins. Vendors that cannot or will not meet these must-haves are eliminated regardless of their technical maturity. Only in the second round does the detailed evaluation of the seven RealCDP capabilities follow, based on concrete vendor demos and reference calls. This sequencing prevents institutions from spending time on vendors that are disqualified on regulatory grounds anyway.
Illustration: AI-generated. AI-assisted content: We use AI technologies and automated agents in the creation of our articles, including from Microsoft, Google, OpenAI, Anthropic and other providers. Topics, editorial direction and final approval remain with our team.
Weitere Insights
Regulation & Compliance
EU Banking Competitiveness 2026: What the Reform Agenda Means for Technology and Customer Processes
CLM & CVM
Customer Journey Analytics in Banking: From Mature Analytics to Lifecycle Decisioning
Data & Technology
Dynamic Banking Engagement Platforms: The Missing Layer Between Core and Customer Dialogue
We use Cookies 🍪
Strictly necessary cookies (e.g. Pipedrive forms) remain active. With your consent we also use Google Analytics (analytics) and Leadfeeder (visitor identification). More in our Privacy Policy.