Open Banking: Secure, Customer-Permissioned Data Sharing

Regulation & securityBy: Farzad Didehbaz2 min readSource: BIS, 2019
Open Banking: Secure, Customer-Permissioned Data Sharing

1Introduction

In its 2019 report, the Basel Committee on Banking Supervision describes open banking as the sharing and use of customer-permissioned bank data by third-party developers and firms to build more efficient and transparent banking services. APIs are the main tool for this sharing.

2Discussion

According to the World Bank, the UK was one of the first to formalise it: open banking went live there in January 2018 with the first account-information API. In the EU, PSD2 recognised payment-initiation and account-information services by third parties and required strong customer authentication for online payments.

Approaches differ. In Europe, industry bodies such as the Berlin Group defined a voluntary common standard, while in Brazil the central bank plays a central role and mandates its own standardised APIs for payment initiation.

3Conclusion

Alongside the benefits, the Basel Committee flags challenges: risks to banks’ business models and reputation, data privacy, cyber security and third-party risk management. Success therefore depends on clear API standards, strong authentication and informed, revocable customer consent.

Share:TelegramWhatsAppLinkedIn

Sources

  1. Basel Committee (BIS) — Report on open banking and application programming interfaces, 2019 ↗
  2. World Bank — Open Banking in the Context of Fast Payments, 2023 ↗
  3. World Bank — Technical Note on Open Banking: Comparative Study on Regulatory Approaches ↗
همفکران فناوری شریفThis article summarises the official sources cited, prepared by the Hamfekran Fanavari Sharif team for finance leaders.
Want to see these solutions in your organisation?Book a free demo

Related articles

Regulation & securityDigital customer onboarding (eKYC): opening accounts without visiting a branchRemote identity verification is the gateway to digital banking; the challenge is balancing convenience with fraud resistance.Regulation & securityPCI DSS v4: card data security in the digital payments eraAny organisation storing, processing or transmitting card data faces PCI DSS; v4 introduces a more flexible, risk-based approach.Regulation & securityInformation security risk management: from assets to management decisionsAbsolute security does not exist; informed risk management targets security spending.Regulation & securityRespected cybersecurity certifications: from CISSP to OSCPProfessional certifications are the global job market’s common language; knowing each one’s role helps choose well.