Articles

Summaries of official reports on fintech, open banking, payments and AI.

HFS Podcast | S. Mohsen Shahmoradi on open banking and the future of fintech in IranThe first episode of the Hamfekran Fanavari Sharif podcast. Listen to the full conversation right here.Office automation: from paper correspondence to intelligent digital workflowsOffice automation redesigns how work flows so decisions are faster, more transparent and traceable.Observability: logs, metrics and tracing for critical systemsMonitoring says something is broken; observability says what, where and why — minutes versus hours of downtime.Event-driven architecture and message queues in payment systemsAt thousands of transactions per second, direct synchronous calls become brittle; event-driven design decouples services.Fintech revenue models: how financial technology companies make moneyGrowth without a sustainable revenue model fails; understanding common models matters for investors, partner banks and founders.Digital customer onboarding (eKYC): opening accounts without visiting a branchRemote identity verification is the gateway to digital banking; the challenge is balancing convenience with fraud resistance.Key financial KPIs: the dashboard every finance manager needsFinance leaders need a few accurate, timely indicators that show financial health at a glance.Integrating petty cash with accounting software: from receipt photo to journal entryManual transfer of petty-cash expenses causes errors and delays; integration automates and traces the path.PCI DSS v4: card data security in the digital payments eraAny organisation storing, processing or transmitting card data faces PCI DSS; v4 introduces a more flexible, risk-based approach.Cryptography in financial systems: from TLS to key management and HSMsStrong encryption only helps if keys are managed well; most failures stem from key handling, not algorithms.Identity and access management (IAM): least privilege in financial institutionsMost serious incidents begin with excessive access. IAM decides who can access what, for how long and at what level.Information security risk management: from assets to management decisionsAbsolute security does not exist; informed risk management targets security spending.Red, blue and purple teams: testing defence through the attacker’s eyesDefences never tested against realistic attacks give no assurance; red–blue collaboration closes the gap.Defence in depth: a layered strategy for financial systemsNo single control is perfect; independent layers stop one failure becoming a full breach.Respected cybersecurity certifications: from CISSP to OSCPProfessional certifications are the global job market’s common language; knowing each one’s role helps choose well.Ransomware in finance: from encryption to double extortionRansomware has become an organised industry; preparation before an attack is the only way to limit damage.Insider threats in financial institutionsSome of the most serious incidents come from people with legitimate access.Account takeover: the silent threat to digital bankingAccount takeover uses leaked passwords and deception and often goes unnoticed until funds move.Cyber attacks on banks: from messaging-network heists to stealthy intrusionsBanks are prime targets for organised attackers; known incidents reveal recurring patterns and lessons.Types of cyber attacks: a complete threat mapKnowing attack categories is the first step to effective defence.Protecting customer personal data: privacy principles in financeFinancial data is among the most sensitive; privacy by design builds trust and lowers legal risk.Petty-cash policy and approval workflowsPetty cash without clear rules breeds discrepancies; written policy and system approvals create transparency.AI receipt reading: the end of manual expense entryOCR and machine learning extract receipt data in seconds, removing manual-entry errors.Payment orchestration: smart multi-gateway managementOnline businesses use several gateways; orchestration makes this multiplicity smart and unified.Core banking modernisation: a bank’s biggest technology decisionCore banking is the heart of operations; modernising is risky but unavoidable, and gradual approaches improve success.DDoS attacks: layered defence for financial servicesDDoS floods services offline; effective defence is layered and planned in advance.SMS fraud and banking phishing: protecting usersFake summons, subsidy and gateway SMS are the most common card-theft methods in Iran.Secure coding with the OWASP Top 10The OWASP Top 10 is the global reference for the most common web-application risks.Git and branching strategy: orderly team collaborationGit underpins developer collaboration; a clear branching strategy reduces conflicts and release errors.Database optimisation: indexes, queries and performanceMuch slowness comes from inefficient queries, not servers; a few principles multiply speed.API design: REST or GraphQL? Choose by needREST and GraphQL each excel in different situations; the right choice depends on consumers.Containers and Docker for small teams: no more “it worked on my machine”Containers standardise runtime environments and turn deployment into a repeatable process.Automated testing and CI/CD: fast releases without fearTeams with automated tests and CI/CD release many times a day with fewer failures.Clean code and code review: software quality from the first lineQuality is shaped when code is written; clean-code principles and regular review sharply cut maintenance cost.Data engineering and ETL pipelines: the backbone of analyticsBefore any analysis or AI model, data must be extracted, cleaned and integrated — the job of data engineering.UX design in financial products: simplicity, trust and accessibilityIn finance, UX reduces user error, builds trust and ensures access for all.Python for data analysis: practical tools for financial analystsPython’s rich libraries make it the main language of data analysis, from cleaning to predictive modelling.Database design for financial systems: integrity, performance and auditabilityIn finance the database guarantees correct figures and traceability of every change.REST API design: principles, versioning and documentationA good API is a clear, stable contract between systems; careful design lowers integration cost for everyone.Secure coding: ten common mistakes that make web systems vulnerableMost software vulnerabilities stem from repeated, preventable coding errors; the OWASP Top 10 maps them.Automated software testing: from unit tests to continuous integrationAutomated tests are the team’s safety net, enabling bold changes without fear of breaking things.Clean Architecture: software that does not decay over timeSeparating business logic from technical details keeps software testable, maintainable and independent of passing technologies.Digital financial inclusion: bringing finance to everyoneTechnology can reach remote and underserved groups — if designed inclusively.RegTech: technology for regulatory complianceFinancial regulation keeps growing; compliance technology cuts cost and error.Regulatory sandboxes: bridging fintech innovation and regulationSandboxes let innovators test products at limited scale under supervision before full rules exist.Smart contracts: uses, limits and legal considerationsSmart contracts automate obligations, but code bugs and legal ambiguity can be costly.Neobanks: branchless, user-centred bankingNeobanks redefine banking through apps without branches, pushing incumbents to transform.Crowdfunding: a new tool for investing in startupsCrowdfunding platforms let the public invest small sums in businesses under capital-market supervision.Cross-border payments: challenges and new approachesInternational transfers remain slow and costly; new technology and regional cooperation aim to reduce friction.E-wallets: role, regulation and opportunities in the payment systemE-wallets simplify micro-payments, but operate within central-bank rules.Operational budgeting and cost control: from plan to real-time monitoringA budget matters only if execution is tracked continuously; technology exposes the gap between plan and reality.Corporate liquidity management: cash-flow forecasting and lower funding costsCash shortages can sink even profitable firms; accurate forecasting is the main defence.Responsible AI: transparency, fairness and accountability in automated decisionsAs more decisions move to algorithms, fairness and transparency matter more.Fraud detection with machine learning: uncovering hidden transaction patternsFraud keeps evolving; ML offers a dynamic defence by spotting anomalous behaviour.Big-data analytics in banking: from storage to valueBanks generate vast data daily; the right architecture turns it into competitive advantage.Third-party payment initiation: the next phase of open bankingAdvanced open banking lets licensed third parties initiate payments directly from customer accounts with consent.API gateways and management: the hidden infrastructure of digital bankingEvery digital bank service is exposed via APIs; central management ensures security, stability and scale.Incident response planning: the golden hours after an attackResponse quality in the first hours determines total damage; a prepared plan makes the difference.Software supply-chain security: when threats come from librariesModern software relies on hundreds of open-source packages; one poisoned dependency can compromise everything.Mobile banking app security: threats and countermeasuresMobile apps are now the main banking channel — and an attractive target.Vulnerability and patch management: a race against timeThe window between disclosure and exploitation keeps shrinking; a disciplined patch process keeps you ahead.Multi-factor authentication: the simplest, most effective defence layerMany breaches start with a stolen password. MFA blocks most of that path.Microservice architecture in banking systems: agility, scalability and resilienceMoving from legacy monoliths to microservices lets banks ship services faster and scale components independently.Asset tokenisation: the future of digital ownership and capital marketsTokenisation turns real assets into tradable digital units and widens access to investment.Persian natural language processing: opportunities and challenges for AILanguage models now understand and generate Persian text, but Persian’s particular features demand a localised approach.ISO 27001-based ISMS: an implementation roadmapISO 27001 provides a systematic framework for identifying risks, selecting controls and continually improving information security.Credit-risk management with machine learning: more accuracy, faster decisionsML models estimate default probability more accurately by capturing complex patterns — provided they are transparent and continuously monitored.Iran’s card payment network: the architecture of Shetab and ShaparakShetab and Shaparak form the backbone of Iran’s electronic payments; understanding them is essential for any payments business.Internal control and continuous auditing: technology’s role in preventing financial fraudInstead of periodic sampling, continuous auditing evaluates every transaction automatically and in real time.Business intelligence in financial organisations: from traditional reporting to predictive analyticsBI turns raw data into strategic insight and shifts decision-making from hindsight to foresight.Consent management in open banking: trust, transparency and data controlIn open banking, data belongs to the customer. A transparent, revocable consent mechanism is the foundation of trust.Security Operations Center (SOC): from event monitoring to intelligent threat responseThe SOC is the heart of cyber defence, where scattered data becomes meaningful alerts and alerts become rapid action.Banks and fintechs: competition or synergy?Banks bring trust, licences and capital; fintechs bring speed and UX. Done right, partnership wins for all.Digital BNPL: a sales opportunity and a debt riskBuy now, pay later lifts online sales, but without proper scoring it can lead to accumulated debt.Supply chain finance: funding small suppliers with a large buyer’s creditSmall suppliers wait months to be paid. Supply chain finance bridges the gap using the buyer’s credit.Process automation with RPA and AI: what to automate first?Not everything is worth automating. Repetitive, rule-based, error-prone tasks are the best start.What is penetration testing and how often do financial firms need it?A pen test is a controlled attack that finds weaknesses before a real attacker does.E-invoicing and the taxpayer system: are businesses ready?With mandatory e-invoices, financial software must connect to the taxpayer system. Early preparation avoids penalties.Banking as a Service: when non-banks offer financial servicesWith BaaS, a retailer or app can offer wallets and payments while the bank provides the infrastructure.Data quality: the prerequisite for any AI projectEven the best model fails on messy data. Much of the work is data preparation.Retail payments, PAYA and SATNA: how settlement worksBehind every interbank transfer are systems that set settlement time and cost. Understanding them is essential for financial product design.Zero Trust: security architecture for the borderless organisationWith remote work and cloud services, “inside the network” no longer means “trusted”. Zero Trust evaluates every request.Digital transformation in banks: why big projects failDigital transformation is about process and culture more than technology. Small, measurable steps raise the odds of success.Digital rial: goals and open questionsA central bank digital currency could make payments more efficient, but privacy and the role of banks remain open questions.AI assistants in the enterprise: from customer replies to document summariesLanguage models speed up repetitive text work — provided confidential data is controlled.Backup and recovery: business continuity against ransomwareRansomware can lock all data in hours. Organisations with tested backups recover instead of paying.Alternative-data credit scoring: lending to the credit-invisibleMany people have no formal credit history. Alternative data can better reflect repayment capacity.QR payments: an opportunity for small merchantsQR payments lower acceptance costs for small businesses, but security and UX must be taken seriously.Controlling running costs under inflation with smart petty cashUnder high inflation, small frequent expenses spiral. Real-time capture and limits stop budget leakage.Management dashboards: from scattered data to fast decisionsManagers spend hours collecting reports. A good dashboard turns that time into analysis.Social engineering: people are the weakest link in securityMost successful breaches start by deceiving an employee, not by breaking encryption. Training and process are the strongest defence.Standard banking APIs: why interface consistency is key to open bankingWhen every bank has its own API, integration costs multiply for fintechs. Standardisation shortens the path.Crypto and regulation: the Iranian policy approachFrom licensed mining to limits on domestic payments—an overview and what it means for businesses.E-wallets and central bank oversightE-wallets speed up micro-payments; the regulator sets rules on KYC tiers, balance limits and settlement.Digital transformation in Iranian organisations: barriers in researchManagement research points to culture and resistance to change as the main barriers, more than technology.AI in credit scoring: a review of Iranian researchDomestic studies find machine-learning models outperform traditional scoring—given good data.Paya, Satna and Pol: which transfer rail for which job?Iran's interbank transfer systems are designed for different amounts and speeds.Buy now, pay later in Iran: fast growth and regulatory questionsBNPL services are spreading quickly; what they offer merchants and which risks need managing.Open banking in Iran: bank APIs and the need for a common standardSeveral Iranian banks offer API platforms, but a common standard and consent framework are still missing.Sayad cheques: transparency for commercial instrumentsIran's Sayad system requires cheques to be registered and confirmed, reducing fraud and bounced-cheque risk.Shaparak and payment facilitators: how card payments flow in IranShetab, Shaparak, PSPs and payment facilitators each play a role from card swipe to merchant settlement.Digital rial: national money in digital formThe Central Bank of Iran has piloted a centrally issued digital rial. How does it differ from crypto and bank wallets?Swift gpi: Tracking Cross-Border Payments Like a ParcelSince 2017 Swift gpi has let banks track international payments end to end, improving transparency of fees and timing.The FATF Travel Rule: Transparency for Crypto-Asset TransfersSince 2019 FATF has required virtual asset service providers to pass originator and beneficiary information with transfers.Zero Trust Architecture: NIST SP 800-207In zero trust, no user or device is trusted merely for being on the internal network; every access is authenticated and authorised.ISO/IEC 27001:2022: The Information Security Standard with 93 ControlsThe 2022 edition regrouped controls into organisational, people, physical and technological themes and added new controls for cloud and threat intelligence.Open Finance in Brazil: From Open Banking to Insurance and InvestmentsBrazil’s central bank rolled out open banking in phases from 2021 and expanded it into open finance covering insurance, investments and payments.India’s Account Aggregator Framework: Consent-Based Data Sharing Without Seeing the DataIndia’s Account Aggregators enable sharing of financial data across banking, insurance and markets based on digital customer consent.Explaining Loan Denials Even with Complex Algorithms: CFPB GuidanceIn 2022 the US CFPB said complex AI models do not exempt lenders from giving specific reasons for credit denials.The CJEU SCHUFA Ruling: An Automated Credit Score Is a “Decision”In December 2023 the EU Court of Justice ruled that automated credit scoring that plays a determining role in lending falls under GDPR Article 22.The EU AI Act: Credit Scoring as a “High-Risk” SystemRegulation 2024/1689, the world’s first comprehensive AI law, classifies creditworthiness assessment of individuals as high-risk with strict obligations.NIST Cybersecurity Framework 2.0: Governance at the Heart of SecurityPublished in February 2024, CSF 2.0 adds “Govern” as a sixth core function and broadens the framework to all organisations.ISO/IEC 42001: Artificial Intelligence Management SystemsThe first international AI management system standard gives organisations a certifiable framework for responsible AI.The OECD AI Principles: The First Intergovernmental AI StandardAdopted in 2019 and updated in 2024, the OECD AI Principles set five values for trustworthy AI.IOSCO Recommendations for Crypto Markets: Same Risk, Same RulesIn 2023 IOSCO published 18 recommendations for regulating crypto-asset markets, from conflicts of interest to custody of client assets.Principles for Financial Market Infrastructures (PFMI)The CPMI-IOSCO principles set 24 principles for safe, efficient payment, clearing and settlement systems and 5 responsibilities for authorities.BCBS 239: Data Quality as a Precondition for Sound Risk ManagementThe Basel Committee’s principles require banks to aggregate and report risk data quickly, accurately and completely, a lesson from 2008.Basel Committee Principles for Operational ResilienceIn 2021 the Basel Committee published seven principles for bank operational resilience, from governance and mapping dependencies to resilient ICT.Singapore’s Project Guardian: Testing Asset Tokenisation with IndustrySince 2022 the Monetary Authority of Singapore has worked with major institutions to pilot tokenised bonds, funds and payments.UK Open Banking: A Model Born from a Competition OrderUK open banking began in January 2018 when nine large banks were required to offer standard APIs, and has since grown into recurring payments and new services.EU Instant Payments Regulation: Euro Transfers in 10 SecondsRegulation 2024/886 requires euro instant transfers at no higher cost than standard ones, with payee verification before payment.PCI DSS v4: Securing Payment Card DataThe PCI Security Standards Council’s version 4 emphasises multi-factor authentication, e-commerce page security and a more flexible approach.Cyber Risk: A Growing Threat to Financial Stability, Says the IMFThe IMF devoted a full chapter of its April 2024 Global Financial Stability Report to cyber risk.FedNow: The US Federal Reserve’s Instant Payment ServiceThe Federal Reserve launched FedNow in July 2023 so banks of all sizes can offer instant payments.The Digital Euro: Where Does the ECB Stand?The ECB has been designing a digital euro, a digital form of cash for everyday payments.Project Agorá: Tokenised Bank and Central Bank Money on One PlatformThe BIS, seven central banks and dozens of private firms are testing whether tokenisation can improve cross-border payments.Project Nexus: Connecting Countries’ Instant Payment SystemsThe BIS Innovation Hub designed Nexus as a standard way to link national instant payment systems.Third-Party Risk and Cloud Services: The FSB ToolkitIn December 2023 the FSB published a toolkit for managing financial institutions’ reliance on third-party providers.New Technologies Against Money Laundering: The FATF ViewFATF examines how machine learning and data analytics can make AML more effective and less costly.E-Invoicing and “VAT in the Digital Age” in EuropeWith the ViDA package the EU makes e-invoicing and digital reporting mandatory for intra-EU trade.Digital Public Infrastructure: Identity, Payments and Data ExchangeThe World Bank sees digital public infrastructure as a foundation for delivering public and private services at national scale.Regulators and Fintech: Sandboxes, Innovation Hubs and Proportionate RulesThe BIS Financial Stability Institute compares how authorities respond to fintech innovation.Credit Decisions by Complex Algorithms: Customers Must Know WhyThe CFPB says complex models do not exempt lenders from explaining why credit was denied.NIST AI Risk Management Framework: Practical Guidance for OrganisationsNIST’s voluntary framework helps organisations identify and manage AI risks.Basel and Cryptoassets: How Much Capital Should Banks Hold?In December 2022 the Basel Committee published the global standard for banks’ cryptoasset exposures.ISO 20022: A Common Language for Payment MessagesISO 20022 makes payment messages richer and more structured; banks’ migration on Swift is nearly complete.Mobile Money: Financial Services for the UnbankedIn many developing economies, mobile money has become the main way people pay and save.Brazil’s Pix: The Instant Payment System Built by a Central BankLaunched by Brazil’s central bank in 2020, Pix made free instant payments an everyday habit.India’s UPI: How Public Payment Infrastructure Changed PaymentsIndia’s Unified Payments Interface enables instant interbank payments with simple identifiers and has become one of the world’s most used payment systems.The FATF Travel Rule: Transparency in Virtual Asset TransfersFATF requires virtual asset service providers to send originator and beneficiary information with each transfer.AI in Financial Services: Findings of Cambridge’s 2026 Global ReportThe latest CCAF survey shows fintechs lead incumbents in advanced AI adoption, with agentic AI emerging as the next frontier.Trust in Money in the Age of Tokenisation: the BIS 2026 Annual ReportThe BIS argues in June 2026 that the path to the next-generation financial system lies in safeguarding trust in money, and current stablecoins still fall short.Big Tech in Finance: The Data–Network–Activities LoopThe BIS explains why big tech firms move quickly into finance and what it means for competition and supervision.Post-Quantum Cryptography: Preparing Finance for Quantum ComputersNIST published the first quantum-resistant cryptography standards, and the BIS has tested migrating financial systems to them.From Open Banking to Open Finance: The EU PackageIn June 2023 the European Commission proposed updating payment rules and extending data sharing across financial services.MiCA: A Unified Crypto-Asset Framework for EuropeWith MiCA, the EU set common rules for issuing and servicing crypto-assets and stablecoins for the first time.The EU AI Act and Credit Scoring: High-Risk SystemsThe EU AI Act classifies creditworthiness assessment as high-risk and sets strict requirements.DORA: Digital Operational Resilience for European FinanceSince January 2025, the EU’s DORA regulation requires financial entities to manage ICT risk in a coherent way.Generative AI in Finance: IMF Risk ConsiderationsThe IMF weighs the opportunities of generative AI for finance against the risks to manage before adoption.The G20 Roadmap for Cheaper, Faster Cross-Border PaymentsThe FSB has set quantitative 2027 targets for cost, speed, access and transparency in international payments.Project mBridge: Testing Cross-Border Payments with CBDCsSeveral central banks, with the BIS, built a shared platform for instant cross-border settlement in central bank digital currency.Buy Now, Pay Later: Rapid Growth and Hidden RisksA CFPB report shows BNPL loans grew roughly tenfold in two years.Stablecoins: Why the BIS Says They Are Not Sound MoneyThe BIS argues stablecoins fail the key tests of sound money and, without regulation, threaten financial stability.AI-Driven Fraud and Deepfakes: A Threat to Financial TrustThe FSB warns AI-driven fraud and disinformation could erode trust and amplify market volatility.SupTech: Technology in the Service of Financial SupervisionThe BIS Financial Stability Institute examines how supervisors use big data and generative AI.Fast Payments: Infrastructure for Economic GrowthThe World Bank explains what defines fast payment systems and how they boost growth and inclusion by freeing up liquidity.Financial Inclusion Worldwide: Findings of Global Findex 2025The latest World Bank database shows 79% of adults have an account and digital payments are the most widely used financial service.Central Bank Digital Currencies: 91% of Central Banks Are ExploringA BIS survey of 93 central banks shows CBDC work remained strong in 2024.AI in Lending and Credit Scoring: Opportunities and RisksThe FSB examines how machine learning sharpens credit assessment and which new vulnerabilities it brings to the financial system.AI and Cybersecurity in the Financial SectorThe IMF warns the main AI risk is not new attacks but the speed and scale at which vulnerabilities are found and exploited.Tokenisation: The BIS Blueprint for the Next-Generation Monetary SystemIn its 2025 Annual Economic Report, the BIS sees a tokenised unified ledger as the foundation of the future financial system.Open Banking: Secure, Customer-Permissioned Data SharingHow the Basel Committee defines open banking, its benefits and risks, and how different countries have implemented it.