RMiT 2025 Tightens Strong Authentication Requirements in Malaysia and Savyint’s Compliance Solutions for Financial Institutions

In November 2025, Bank Negara Malaysia (BNM) officially issued an updated version of its Risk Management in Technology (RMiT) policy, introducing stricter requirements for enhanced identity verification, device binding, and fraud prevention across Malaysia’s financial sector. 1. About BNM’s RMiT Policy Risk Management in Technology (RMiT) is Bank Negara Malaysia’s central policy framework for managing technology risk and cybersecurity risk in the financial sector. The policy sets out minimum requirements for financial institutions to strengthen governance, cybersecurity, technology operations, digital services, third-party risk management, cloud adoption, fraud detection, and customer protection. Its objective is to ensure that financial institutions can maintain secure, stable, and trusted digital services amid increasingly complex cyber threats. RMiT applies to all financial institutions regulated by BNM, ranging from banks to insurers and reinsurers, electronic money issuers, payment system operators, financial institutions, and money transfer intermediaries. 2. The November 2025 RMiT Update The RMiT policy issued in June 2023 introduced several authentication-related requirements, including multi-factor authentication, access management, and digital service controls. However, these requirements remained largely guidance-based rather than mandatory standards. In November 2025, the updated RMiT policy was issued, marking a significant turning point in strong authentication by introducing clearer mandatory requirements on how organizations must authenticate users and protect digital services. Below are the key changes. a. One Device per User by Default One of the most important changes is the default requirement to use only one device, aimed at preventing SIM-swap fraud and account takeover. Financial institutions must ensure secure device binding and unbinding processes, while limiting digital service transaction authentication by default to one mobile device per account holder. Users may register additional devices, but they must actively request this and accept the associated risks. Financial institutions are not allowed to make multiple devices the default option. The process must include: b. Stronger Verification for Mobile Number Changes Previously, many banking applications allowed users to update their mobile phone numbers by confirming an OTP sent to the existing number. However, this approach is no longer considered secure if the number has already been compromised or affected by SIM swapping. Therefore, under the latest RMiT update, organizations are required to adopt stronger authentication mechanisms, such as: c. Cooling-Off Periods and Transaction Limits for Newly Registered Devices RMiT requires appropriate verification and cooling-off periods in the following cases: Accordingly, newly registered devices should not be granted full transaction privileges immediately. Organizations need to establish time-based limits and transaction frequency controls. Transaction rights should be gradually expanded as the device and user behavior build a trusted history. Combined with fraud detection standards that require behavioral analytics and real-time risk scoring, RMiT requires the authentication layer to understand context, not merely verify login credentials. d. Multi-Factor Authentication and Passwordless Authentication to Reduce Dependence on SMS OTP The most important change in the RMiT update is the requirement to use MFA and passwordless authentication methods. MFA must be resistant to interception or manipulation by third parties throughout the authentication process. Examples of passwordless authentication methods include biometric authentication, device binding, cryptographic key-based authentication, and risk-based step-up authentication. In addition, “transaction linking” requires the authentication code to be bound to specific transaction details, including the recipient and transaction amount, rather than being linked only to the login session. 3. Savyint – A Global Expert in Strong Payment Authentication and Risk Prevention Amid rising security requirements, Savyint provides a comprehensive security ecosystem that helps banks and financial institutions comply with BNM’s RMiT regulations while enhancing their overall security and risk management capabilities. Built on a Zero Trust architecture and centered around four key pillars – Secure Payment, Open Banking, Secure Data, and Digital Trust – Savyint’s RMiT compliance solution enables financial institutions to: This solution is designed in strict compliance with international standards such as FIDO2, PSD2/PSD3 eIDAS, GDPR, PCI DSS,… ensuring rapid deployment, compatibility with existing infrastructure, and the highest level of security. Connect with Savyint experts today to build a secure and compliant payment ecosystem.
Top 6 Benefits of Zero Trust Security Architecture

As cyberattacks become increasingly sophisticated, traditional security models such as firewalls, VPNs, or trusted internal networks are no longer sufficient to protect modern enterprises. Zero Trust Architecture has emerged as a critical approach in today’s cybersecurity landscape, helping organizations strengthen protection across users, devices, applications, data, and digital transactions. What is Zero Trust Architecture? Zero Trust Architecture is a modern security model built on the principle of “never trust, always verify.” It is designed for today’s complex, distributed, and increasingly cloud-based IT environments. Unlike traditional security models, Zero Trust requires every access request to be continuously verified, whether it originates from inside or outside the organization. Zero Trust Architecture typically combines multiple security technologies, including: Key Benefits of Zero Trust Security Architecture Implementing Zero Trust can bring significant benefits to enterprises and organizations, including: 1. Strengthening Comprehensive Security Against Advanced Threats Zero Trust helps organizations defend against threats such as ransomware, phishing, compromised accounts, and insider risks. By enforcing least-privilege access and continuous verification, businesses can significantly reduce the risk of attackers exploiting exposed credentials to access sensitive systems and data. 2. Reducing the Risk of Data Breaches Since every access request must be verified, attackers cannot easily reach sensitive data even if they manage to compromise an account or device. This helps limit unauthorized access, reduce lateral movement within the system, and minimize the potential impact of security incidents. 3. Improving Monitoring and Incident Detection Zero Trust enables organizations to monitor user behavior, devices, applications, and access activities in real time. With stronger visibility across the digital environment, businesses can detect unusual activities earlier, respond to risks more quickly, and improve their overall incident response capability. 4. Supporting Remote Work, Cloud, and Hybrid Infrastructure With Zero Trust, users can securely access enterprise resources from anywhere, as long as their identity, device, and access permissions are properly verified. This is especially valuable for remote and hybrid work models, where employees may access corporate systems from different locations, networks, and personal devices. 5. Enhancing Regulatory Compliance Zero Trust provides a unified governance framework for enforcing security policies, authenticating users, managing access rights, and maintaining activity logs. This allows organizations to better meet data protection and information security requirements in highly regulated sectors such as finance, banking, healthcare, telecommunications, and government. 6. Optimizing Long-Term Security Costs While Zero Trust implementation may require initial investment, it can help optimize security costs in the long run. By consolidating security controls, reducing the likelihood of data breaches, and limiting damage when incidents occur, Zero Trust helps organizations build a more sustainable and cost-effective cybersecurity strategy. A Comprehensive Zero Trust-Based Security and Fraud Prevention Solution for BFSI Organizations With deep experience in the Finance and Banking sector and a proven track record of implementing projects for major banks, SAVYINT introducs e a comprehensive security and fraud prevention solution built on Zero Trust Architecture. Aligned with the core pillars of modern Zero Trust, SAVYINT’ solution enables end-to-end protection across users, devices, applications, data, and digital transactions: + Identity verification and user access control + Establish device trust + Real-time application protection with RASP+ + API security and third-party connectivity + Consent management and personal data protection + AI/ML integration, transaction risk assessment, and real-time fraud prevention + Automated compliance reporting + Support compliance with Vietnamese regulations, including Circular 50, Circular 64, Circular 77 of the State Bank of Vietnam, Decree 356, the Data Protection Law, and the Cybersecurity Law,…; international standards such as eIDAS, GDPR, and PCI-DSS…; and regional regulations such as Malaysia’s PDPA and RMiT, and the Philippines’ AFASA and BSP 1213–1215… Connect with SAVYINT experts today to take the lead in enterprise-wide security and fraud prevention! Read more: Zero Trust – A Next-Gen Security Architecture for Vietnamese Banks Amid Increasingly Stringent Regulations
Savyint Advances Cooperation in Cybersecurity, Artificial Intelligence and High Technology in India

May 6, 2026, Savyint Group participated in the Vietnam – India Innovation Forum in New Delhi, India. The event was jointly organized by Vietnam’s Ministry of Science and Technology and India’s Ministry of Electronics and Information Technology, as part of the State visit to India by H.E. To Lam, The General Secretary, President of the Socialist Republic of Viet Nam. Taking place from May 5 to 7, 2026, the State visit by General Secretary, President To Lam was made at the invitation of Indian Prime Minister Narendra Modi, with the participation of a high-level Vietnamese delegation and a business delegation. The visit also coincided with the 10th anniversary of the elevation of Viet Nam-India relations to a Comprehensive Strategic Partnership, while opening new momentum for cooperation in areas that are fundamental to future growth, including science and technology, innovation, digital transformation, cybersecurity, artificial intelligence, semiconductors, energy and high-quality human resource development. Under the theme “Cooperation in Human Resource Development, Science and Technology, Innovation and Digital Transformation,” the Vietnam-India Innovation Forum brought together senior leaders, ministries, government agencies, research institutes, universities, associations, digital technology corporations, and innovation-driven enterprises from both countries. At the forum, General Secretary and President To Lam emphasized the need for Viet Nam and India to strengthen strategic information sharing and expand cooperation in cybersecurity, digital infrastructure protection, the prevention of high-tech crime, and capacity building to respond to non-traditional security challenges. The forum served as an important platform to promote substantive cooperation between the Vietnamese and Indian technology communities, particularly in fast-growing sectors across the Asia-Pacific region. Amid the rapid growth of the digital economy, data security, digital identity protection, and cyber resilience have become strategic requirements for governments, financial institutions, large enterprises, and critical infrastructure operators. As a Vietnamese technology company focused on digital safety, data protection, digital trust, and risk governance in digital environments, Savyint joined the forum with the aim of expanding international cooperation, connecting Vietnamese technology capabilities with India’s technology ecosystem, and supporting the development of platforms and solutions that meet the increasingly demanding requirements of regional markets. At the event, Savyint Group and Vantageo Pvt. Ltd. exchanged a technology cooperation agreement, opening new directions for collaboration in development, integrated design, joint research and co-production. The partnership aims to combine the strengths of both companies to deliver solutions and products in areas such as cybersecurity, AI Security, Data Safe, Quantum Safe, Zero Trust Network, HPC platforms, AI accelerators, and GPU platforms for Viet Nam, India, the APAC region and SAARC region. The cooperation agreement goes beyond connecting the capabilities of the two companies. It also reflects a shared orientation toward co-developing secure technology platforms that can be localized to meet the requirements of each market, while aligning with international standards for security, compliance, and operational reliability. Mr. Steve Huang, Executive Chairman of Savyint Group, shared: “India is one of the world’s fastest-growing technology hubs. By participating in the Vietnam-India Innovation Forum, Savyint aims to connect with like-minded partners and jointly develop secure, trusted, and widely applicable technology solutions for enterprises and organizations in Viet Nam, India, and the wider region.” As Viet Nam-India relations enter a new phase of deeper and broader cooperation, Savyint’s presence at the forum affirms its commitment to accompanying Viet Nam’s national digital transformation journey, while promoting “Make-in Vietnam” technology solutions to regional and global markets. The event through media coverage:
Common Challenges in Consent Management

Customer data is a valuable asset for organizations and businesses. Without a structured, transparent system, companies may face numerous challenges, or even risk compromising customer trust. Typical Challenges in User Consent Management Most businesses and organizations understand the importance of consent management. However, in practice, the majority still manage it manually, in a fragmented way, with limited oversight. Common challenges in managing user consent management include: Incomplete or invalid consent collection Many organizations collect consent through default checkbox plugins, registration forms, often accompanied by terms of service that span dozens of pages and combine multiple purposes. Unintentionally, these practices can violate fundamental data protection laws, as they may not rely on voluntary consent and often fail to provide full, specific, clear, and detailed information to users. Fragmented consent management Organizations interact with customers through multiple touchpoints: mobile apps, internet banking, service counters, emails, SMS, and more. Each channel often has its own mechanism for collecting consent, which can lead to: These inefficiencies affect user experience and complicate organizational data management. Non-compliance with legal regulations Data protection laws are constantly evolving. What is valid today may no longer be valid tomorrow. Different regions and countries have different requirements. Violating international regulations can result in fines up to €20 million or 4% of annual global revenue under GDPR (EU), or USD 7,500 under CCPA (US). In Vietnam, banks must comply with the Personal Data Protection Law 2025 and Decree 356/2025/ND-CP. User personal data must be collected, stored, processed, and shared transparently, with mechanisms ensuring user rights to access, edit, revoke consent, and delete data when no longer necessary. Ensuring ongoing compliance with both international and local regulations is a significant challenge for organizations. Modern Consent Management Architecture Today, a modern consent management system is more than just a pop-up or a checkbox form. It is a complex technical system with multiple layers, ensuring that consent is collected accurately, stored securely, and remains consistent across the organization’s digital ecosystem. A modern consent management system typically includes the following pillars: About Savyint Consent Management SAVYINT is a global technology company with extensive experience in building secure digital infrastructure and digital trust for financial institutions, governments, and large enterprises. Built on an API-first and Zero Trust architecture, Savyint Consent Management automates the entire consent management process – from collection and storage to verification and revocation – ensuring transparency and control over user data. Integrating advanced technologies such as AI/ML and Post-Quantum Cryptography (PQC), Savyint Consent Management leverages immutable logs and homomorphic encryption to maximize security for sensitive data, enabling organizations to: Savyint Consent Management meets international standards such as GDPR, PDPA, CCPA, ISO 27701, PCI DSS, and local regulatory requirements in countries including Vietnam (Personal Data Protection Law 2025, Decree 356/2025/ND-CP, Circulars 64, 50, 77 from the State Bank of Vietnam), Singapore (PDPA), and more. Upgrade your consent management system and protect customer data today with Savyint, CONNECT NOW.
Zero Trust – A Next-Gen Security Architecture for Vietnamese Banks Amid Increasingly Stringent Regulations

Vietnam’s financial and banking sector is entering a phase of significantly tightened requirements for security, data protection, and fraud prevention. From Circular 50, Circular 77, and Circular 64 issued by the State Bank of Vietnam, to the Personal Data Protection Law, Decree 356, and the Cybersecurity Law 2025, financial institutions are no longer required to simply have security systems – they must prove that these systems are reliable, secure, and capable of real-time risk control. Over the past five years, regulations in Vietnam’s financial and banking sector have clearly shifted – from system-level security requirements to comprehensive control and enhanced protection across the entire digital customer journey. Notably, since 2024, the Vietnamese government has introduced a series of policies to strengthen information security, data protection, and cybersecurity. Online Service Security Circular 50/2024/TT-NHNN establishes a comprehensive foundation for securing online banking services, covering customer authentication, transaction data protection, and responsibilities for guiding users about risks. However, the real tightening comes with Circular 77/2025/TT-NHNN, which amends Circular 50 and takes effect from March 1, 2026. Accordingly, financial institutions must place strong emphasis on endpoint security (Mobile Apps). Mobile banking applications are required to automatically log out or stop functioning if detecting: rooted/jailbroken devices, emulators, debuggers, etc. Server systems must implement version control mechanisms, prevent users from downgrading versions, and ensure software is protected against the top 10 common vulnerabilities (OWASP). Stronger identity verification is required in high-risk scenarios, mandating biometric authentication combined with high-level verification when customers change identity documents or authentication methods. Circular 64/2024/TT-NHNN sets strict technical standards for open system connectivity architecture, requiring data structures using JSON or XML via REST APIs. APIs must be digitally signed (JWS) and encrypted. It also mandates identity and access management between banks, customers, and third parties (TPPs) based on OAuth 2.0 standards. Personal Data Protection The Personal Data Protection Law No. 91/2025/QH15, effective from January 1, 2026, marks a significant milestone in privacy protection in Vietnam. The law requires technical controls embedded directly into system architecture, including mandatory encryption/decryption of sensitive data, implementation of data anonymization processes to prevent re-identification, and compulsory impact assessments for data processing and cross-border data transfers. Systems involving Big Data, AI, Blockchain, and Cloud must integrate appropriate security measures with strict access controls. Additionally, the law requires the establishment of identity governance mechanisms based on user consent, with features allowing customers to monitor, view, modify, or withdraw their consent. Decree 356/2025/NĐ-CP, which guides the implementation of the law and replaces Decree 13/2023, establishes a robust technical and legal “barrier,” requiring organizations to implement dual verification mechanisms in personal data processing. Systems must support verifiable consent logging (e.g., OTP, voice recordings, SMS). Access to sensitive data requires strong authentication methods, at minimum multi-factor authentication (MFA), combining passwords with OTP, digital signature devices, or biometrics. These requirements exceed the capabilities of most existing identity and access management systems. Cybersecurity The Cybersecurity Law 2025, effective July 1, 2026, establishes a framework for protecting information systems based on five risk levels. It clearly defines the responsibility of online service providers to verify user information during digital account registration and secure user account data. This compels financial institutions to treat digital security as a core capability rather than a supporting technical function. Zero Trust Architecture Zero Trust is a modern security architecture based on the principle “Never trust, always verify,” designed for complex and distributed systems. Instead of inherently trusting users or devices within the network, Zero Trust continuously verifies five key pillars: user identity, devices, networks, applications, and data. Every access request must be authenticated, authorized, and continuously monitored. This model enforces strict control over identity, device posture, applications, data, and user behavior in real time. The three core principles of Zero Trust include: By applying these principles, Zero Trust helps organizations reduce cyberattack risks, limit lateral movement within systems, and protect digital assets across cloud, mobile, IoT, and remote working environments. Comprehensive Security and Fraud Prevention Solution for Banks With extensive experience in the financial and banking sector, Savyint introduces a comprehensive security and fraud prevention solution based on Zero Trust architecture. This solution enables financial institutions to comply with stringent legal requirements both domestically and internationally while addressing key challenges including user authentication, device and application protection, API security, consent management, fraud prevention, transaction risk control, and compliance: Beyond compliance with Vietnamese regulations, Savyint’s security and fraud prevention solutions also strictly adhere to international standards such as eIDAS, GDPR, PCI-DSS, as well as regional regulations in countries like Malaysia (PDPA, RMiT) and the Philippines (AFASA, BSP 1213-1215). Connect with Savyint experts today to ensure secure operations and full compliance with both domestic and international regulations.
Savyint Trains Strategic Partner Vietnet: Leveling Up On Digital Trust, Open Banking & Next-gen Security

With data security, digital authentication, and legal compliance getting stricter by the day, Savyint recently held a training session for the strategic partner, Vietnet, to help Vietnet level up their consulting, deployment, and business development skills around next gen security, Digital Trust, and Open Banking – all fully aligned with Vietnam’s State Bank Circulars 50, 77, and 64. The program took place over two days (April 16–17, 2026) in Hanoi. It’s part of our long term strategic partnership to equip Vietnet with deep expertise and real world implementation skills – so they can bring world class security solutions to customers right here in Vietnam and across the ASEAN region. SAM Appliance – All in one data encryption, digital signature & mobile identity On the first training day, Savyint’s experts walked everyone through today’s biggest security challenges: the explosion of connected devices, tough compliance rules (GDPR, PCI DSS, eIDAS…), and the pressure to move toward post quantum cryptography (PQC). That’s where SAM Appliance comes in. It’s a complete package for data encryption, digital signatures, and mobile identity – fully compliant with standards for remote digital signatures, blockchain, cryptography, mobile payments, transaction encryption, time stamping, system security, IoT, Car2X, and more. But SAM Appliance isn’t just about signing invoices, contracts, certificates, or payment files. Built on a Cryptographic Security Platform (CSP), it also includes SCA & MFA, passwordless PKI based authentication, tokenization, end to end transaction signing, advanced mobile cryptography, and support for Post Quantum Cryptography (PQC) algorithms – ready for the next era of security. Plus, it integrates blockchain and cryptocurrency, enables mobile payments and digital wallets, and supports long term digital preservation with timestamps for 5, 10, even 20 years. SAM Appliance proudly meets regional technical standards and international regulations, including FIPS 140 2 Level 3, ISO 9001:2015, ISO 14001:2015, ISO 27001:2022, GDPR, SOC 2 Type II, HIPAA, and PCI DSS. Alongside all the technical details, the Vietnet team also got to explore real life use cases from banking, finance, and government – so they can see exactly how the solution fits each customer’s unique challenges. Digital Trust & Compliance Beyond SAM Appliance, Savyint offers a full Digital Trust solution stack designed to strictly follow local and international legal requirements. It’s built on four pillars: Risk Management & Compliance, Cyber Security & App Protection, SCA/MFA Identity, and FMS AI Fraud. On top of strong authentication (passwordless with FIDO2/Passkey, biometrics, contextual auth, Smart OTP, push notifications…), the solution adds AI and Machine Learning. This helps banks and financial institutions detect, assess, and stop fraud across the entire user journey – from login behavior and device fingerprints to access context and transaction details. Combine that with RASP+ (runtime app protection) and TrustShield – a mobile fraud prevention platform using device fingerprinting, behavior analysis, and AI – and you get a seriously robust defense. These pillars form a complete, end to end architecture that protects devices, behavior, identity, and transactions all at once. This is Savyint’s real strength: building high value, long term solutions that keep customers safe while staying compliant across multiple markets – like Vietnam (SBV Circulars 50, 64, 77), the Philippines (AFASA Act, Circulars 1213–1215), Malaysia (MRiT, PDPA), and beyond. Expanding capabilities with Open Banking Day two of the training focused on the Open Banking Tech Stack – fully compliant with Circular 64/2024/NHNN. It includes: • Savyint Open Banking Portal, Savyint API Management, Savyint Consent Management • Savyint CIAM/SCA (PSD2), eKYC • Savyint TPP Management, Fraud Prevention & Risk Management Savyint is positioned not just as a tech vendor, but as an end to end Digital Trust platform – providing the security and compliance layer for the entire Open Banking ecosystem. Sprinkled throughout the technical sessions were open Q&A discussions where Savis and Savyint could talk through real world scenarios, challenges, and implementation tips. This training is part of Savyint’s long term strategy to build a strong partner ecosystem in Southeast Asia – and to cement our position as a leader in Digital Trust, Open Banking, and next gen data security. Some snapshots from the training program:
SAVYINT Officially Joins the Cloud Signature Consortium (CSC): Advancing the Global Digital Trust Ecosystem

March 2026, SAVYINT has officially become a member of the Cloud Signature Consortium (CSC) – the world’s leading international standardization body in the field of cloud-based digital signatures and digital trust services. As the global digital economy undergoes profound shifts in both regulatory frameworks and technical standards, establishing common benchmarks for cross-border electronic transactions has become an urgent priority. SAVYINT – a pioneer in security and trust services – has officially joined the Cloud Signature Consortium (CSC). This milestone reaffirms SAVYINT’s position and commitment to aligning its digital signature and authentication solutions with the highest international standards. Trust with Cross Border As a CSC member, SAVYINT’s Chairman of the Board, Mr. Steve Huang, made a notable introduction at the CSC online networking session themed “Trust with Cross Border — The EU–Mercosur Free Trade Agreement and Its Impact on the Digital Trust Ecosystem”. During the session, leading experts shared insights on the opportunities and challenges in advancing global interoperability for cross-border digital signatures. For SAVYINT, participating in these international dialogues is not only an opportunity to stay current with the most advanced technical specifications, but also a chance to connect with strategic partners across Europe and Latin America — laying the groundwork for SAVYINT’s international market expansion strategy. SAVYINT – Leading Digital Trust Solutions in the Region SAVYINT Group is a premier IT security company headquartered in Australia, with a Research & Development (R&D) center based in Vietnam. With a strategic focus on building market-adaptive digital trust infrastructure, SAVYINT has developed a comprehensive suite of solutions including: Qualified Remote Signing, VA & Timestamp, PKI in a Box, SAM Appliance, ePaperless, eStamping, and eArchive. All platforms are entirely researched and developed in-house, ensuring high flexibility and customizability to meet the distinct legal frameworks and trust requirements across regional markets including SEA, APAC, and MENA, as well as international standards such as PSD2/PSD3, eIDAS, GDPR, and beyond. Looking further ahead, SAVYINT is also committed to realizing a roadmap toward post-quantum-ready trust services, encompassing PQC-enabled cryptographic infrastructure and PKI. As a member of CSC, SAVYINT commits to long-term contributions to the digital trust community, synchronizing with international standards, sharing real-world implementation experience, and offering practical perspectives from Vietnam and other emerging markets to help make CSC’s standards more comprehensive and reflective of the world’s diverse realities. Digital trust knows no borders, and joining CSC is the foundation upon which SAVYINT will realize that vision on a global scale.
PIONEERING THE NEXT GENERATION OF SECURITY: QUANTUM AND AI HORIZON

On March 26, Savyint welcomed a student delegation from the University of San Agustin, Philippines. During the visit, the students got a first-hand look at leading technology trends such as Post-Quantum Cryptography (PQC), the Digital Trust platform, AI in fraud prevention, and especially Agentic AI – fields that are shaping the future of global digital security and transformation. 1. Post-Quantum Cryptography (PQC) – Ready for the New Era As quantum computing gets closer to a breakthrough, traditional encryption methods are at risk of being broken. PQC (Quantum-Resistant Cryptography) has emerged as a vital solution, designed to protect data infrastructure against the massive computing power of this new era. Savyint is a pioneer in integrating advanced PQC standards (like ML-KEM and ML-DSA) into its core systems to secure devices. Furthermore, Savyint has established the Quantum AI Lab – a leading lab in Vietnam for researching and testing these quantum-resistant algorithms. Here, they simulate real-world attacks from “AI hackers” to test how strong their security layers really are. 2. AI Fraud & Digital Trust – Protecting Finance in the AI Age Beyond the pressure from quantum computers, threats like Deepfakes and automated malware are making financial security more urgent than ever. Savyint shared an overview of the 2025 threat landscape, where fraud not only causes financial loss but also creates legal risks for organizations. To fight this, Savyint introduced its Digital Trust platform. This platform uses AI to analyze user behavior, detect unusual activity, and make decisions in real-time. The system is built on four pillars: device security, advanced authentication, AI-based fraud detection, and risk management. 3. Agentic AI – Toward Self-Operating Security Systems Savyint also introduced Agentic AI – AI systems capable of making decisions and taking action on their own, rather than just creating content or analyzing data. In fraud prevention, Agentic AI is used to simulate complex attack scenarios to “train” defense systems, helping them react and adapt faster over time. Additionally, these AI agents can: This approach marks a shift from “reactive” systems to “autonomous” (self-operating) systems, where AI acts as an active partner in the security ecosystem. The visit gave the University of San Agustin students a practical look at how cutting-edge tech is used in real businesses. It was more than just a learning experience; it was inspiration for the younger generation to join the journey of global innovation. See more photos from the event below:
Consent Management in Open Banking

Open Banking is a new financial ecosystem that allows users to securely share their personal financial data with third-party providers, such as fintech companies or other financial institutions. By sharing this data, these organizations can provide personalized financial services to users. So, how is Open Banking data processed, and for what purposes is it used? Open Banking: Consent Management To provide and develop high-quality products and services, Third-Party Providers (TPPs) require user consent to access their financial data. From there, they filter and process this data for research purposes and to build new financial products and services. Consent management is a sensitive matter that requires caution and expertise in both legal and technical aspects. Contrary to popular belief, consent management is not just a simple click or checking an “I Agree” box; it is a structured process implemented in compliance with regional and national regulations and directives, such as PSD2/PSD3 or GDPR in the EU. The consent management process in banking typically unfolds as follows: While different organizations may present data access agreements differently, this is the most common mechanism, often used in: Understanding how data and information flow during the consent request process is a decisive factor for transparency and the success of organizations in Open Banking. The Process of Managing Consent for Open Banking Data Sharing The consent management process is generally divided into three stages: a. Consent Stage b. Authentication Stage c. Authorization Stage Throughout every process, users always know who they are granting access to, for how long, and for what purpose. Most importantly, users can revoke consent at any time. The information available to users typically includes: Open Banking Data Sharing: How Does It Work? Open Banking allows third-party financial service providers to access information with user permission. Technically, this process is facilitated via Open APIs. Legally, the data-sharing process is overseen and governed by existing government regulations, such as the Payment Services Directive (PSD2) in the EU or the Open Banking Act in the UK. However, as these regulations vary by region, the types of data shared through open banking services also differ. Typically, to ensure transparency and integrity, there are multiple layers of security and verification during the data exchange between financial institutions and TPPs. Data transmission is executed in a “heartbeat” thanks to APIs, ensuring a seamless, secure, and efficient experience. Who Can Access Open Banking Data? Not everyone can access data in Open Banking. To view this data, user consent is mandatory, and the TPP must be licensed. TPPs must also meet specific requirements before being authorized to access a user’s financial information. Dedicated competent authorities are responsible for licensing TPPs to access user data. For example, in Australia, the Australian Competition and Consumer Commission (ACCC) is responsible for Open Banking data licensing. These agencies ensure that personal financial data sharing does not violate the law while having the power to grant, modify, or revoke data collection licenses. What Data is Collected in Open Banking? The data collected by open banking service providers may vary depending on the regulations of each country/region and the type of service provided. Regulators often set strict rules on the type of information that can be collected, limiting the scope to ensure TPPs only access what is strictly necessary. The most commonly collected data includes: How Does Open Banking Protect User Data? Protecting data in Open Banking is a top priority for regulators and financial institutions. Security measures applied include: However, alongside these protections, certain risks remain of concern to developers and users: In summary, while risks cannot be entirely eliminated, current security measures are established to ensure user data is protected within the open banking system. Nevertheless, users should also protect themselves by using strong passwords, updating software regularly, and staying vigilant against phishing attacks. Furthermore, empowering users to manage their open banking data is an excellent way for them to take responsibility for when and how they wish to provide their information. TPPs must clearly communicate the purpose and the data to be collected to ensure transparency and Open Banking data privacy. Savyint and Savyint Consent Management As an global technology company with extensive expertise in PKI, Cryptography, Blockchain, Electronic Identification, Authentication, Savyint proudly introduces Savyint Consent Management, specifically designed for the collection, storage, and transparency of user data rights. As an international technology group with extensive expertise in PKI, Cryptography, Blockchain, Electronic Identification, Authentication, and Open Banking/Finance, Functioning as a central “Trust Engine,” this solution automates 100% of the processes for collecting, storing, and verifying data rights across the entire customer journey. Savyint Consent Management enables enterprises to process sensitive data with total transparency, ensuring full compliance with global and local regulations such as Vietnam’s Personal Data Protection Law (No. 91/2025/QH15), Circular 64/2024/TT-NHNN, GDPR, FAPI 2.0… Advanced Technologies of Savyint Consent Management: Connect with Savyint’s experts today to lead the way in the data security era and build sustainable digital trust!