generated: '2026-07-20' method: derived source: >- openapi/westpac-cds-banking-products-openapi.yml + review.yml (confirmed live behaviour) standards: - id: cdr-consumer-data-standards name: Consumer Data Standards (CDS) — Banking, Get Products / Get Product Detail conforms: true evidence: >- Live endpoint returns CDS-shaped ResponseBankingProductList / detail payloads; x-cds-type field annotations throughout; served under the /cds-au/v1/banking/products path mandated by the standard. - id: cdr-version-negotiation name: CDS header-based version negotiation (x-v / x-min-v) conforms: true evidence: >- Confirmed: x-v 5 -> 200, x-v 3 -> 406 UnsupportedVersion. Data holder echoes served version in x-v response header. - id: oauth2 conforms: false evidence: >- No securitySchemes in the spec; the public PRD endpoints are unauthenticated. (Broader CDR consumer-data sharing uses OAuth2/OIDC via the ADR model, but that is outside this public contract.) - id: fapi conforms: false evidence: >- FAPI applies to the authenticated CDR ADR consent channel, not to the unauthenticated PRD surface captured here. - id: rfc9457-problem-details conforms: false evidence: >- Errors use the Consumer Data Standards errors[] envelope, not application/problem+json. - id: pagination conforms: true evidence: >- Standard CDS page-number pagination (page / page-size) with LinksPaginated and MetaPaginated (totalRecords, totalPages) response objects. - id: idempotency conforms: false evidence: Read-only GET surface; no state-changing operations, no idempotency contract. compliance_program: null note: >- This file asserts standards conformance derived from the spec and confirmed behaviour. It does NOT assert a published corporate compliance program (SOC 2 / ISO 27001 / PCI), so no Compliance canonical pointer is emitted from here.