From Open Banking to Banking-as-a-Service: What Comes Next?

Over the past decade, financial innovation has evolved from open banking, which focuses on consumer-authorized data sharing, to banking-as-a-service (BaaS), which uses application programming interfaces (APIs) to make core banking functions more modular and accessible. Open banking & Open Finance The term “Open Banking” emerged around 2016 as a policy initiative aimed at increasing competition in the retail payments sector. The United Kingdom was the first country to explore this approach as a regulatory tool for promoting greater competition in digital payments through the Open Banking Implementation Entity. The idea behind these initiatives was straightforward: by making it easier for third-party providers (TPPs) to access data, regulators could lower barriers to entry, encourage competition, and create more opportunities for innovation in digital payments. A similar approach was taken by the European Union through the Second Payment Services Directive (PSD2), which came into effect in 2018. PSD2 required banks to provide registered third-party providers with access to customer account data through standardized application programming interfaces (APIs). Open Finance takes this concept a step further. While Open Banking mainly focuses on banking and payment data, Open Finance covers a much broader range of financial products and services, including credit, investments, pensions, and insurance. Under an Open Finance model, consumers can give third parties access to a broader set of financial data, potentially providing a more complete picture of their financial lives. While the potential benefits of Open Finance have not yet been fully demonstrated in practice and evidence of its impact remains limited, the concept could give consumers and businesses greater control over their financial data. By making more financial data available, Open Finance could help reduce information gaps, encourage competition, and create opportunities for more personalized financial products. These products could better reflect an individual’s financial profile, spending habits, and long-term goals. Open Finance can also make it easier for consumers to bring together and compare information from multiple providers, helping reduce complexity and make financial decisions easier. Concept of Everything-as-a-Service (XaaS) Against this backdrop, Open Banking is often seen as one of the starting points for the rise of Banking-as-a-Service (BaaS) – a new approach to financial services that brings data-driven capabilities into the way banking services are delivered. BaaS is built around the broader concept of Everything-as-a-Service (XaaS), also known as Anything-as-a-Service. XaaS refers to a wide range of cloud-based and remotely delivered services that companies can access through the Web or similar networks. The idea started with Software-as-a-Service (SaaS), where cloud providers made individual software applications available to customers. Over time, the model expanded into other services such as Infrastructure-as-a-Service (IaaS) and Communications-as-a-Service (CaaS). Eventually, the concept developed into the broader XaaS model, where businesses can access the specific services they need and pay for them on demand. In simple terms, instead of buying a software license and installing the application on individual computers, a business can subscribe to a cloud-hosted application provided by the software company. This approach gives businesses greater flexibility to switch providers while also making software maintenance easier. APIs play a key role in making this possible. They allow different applications and software systems to communicate and work with each other. As XaaS continues to grow, opportunities are also expanding for developers to build third-party applications that connect with existing platforms. The growth of SaaS, for example, has created entire businesses around developers and companies using SaaS platforms. However, APIs and SaaS are not the same thing. APIs do not require SaaS, and they have existed long before the Internet. They can also be used in offline environments. LinkedIn is an example of the SaaS model because it delivers its platform through cloud computing and generates revenue through recurring subscription fees. Facebook, on the other hand, does not operate as a SaaS company. Although it provides data through APIs, its primary source of revenue is advertising, much like Google’s core business model. Unlike SaaS providers, these platforms do not rely on subscription fees for their core services. Bank as a Service What banks can now build with APIs follows a similar XaaS approach. Banking-as-a-Service enables banks to deliver digital banking capabilities through APIs. In other words, banking services can move beyond traditional branches and become part of mobile and web-based experiences. Banks can make their data, functions, and infrastructure available through APIs, allowing other digital platforms and businesses to integrate banking capabilities into their own services. From the customer’s perspective, this can lead to very different types of digital experiences. A bank may continue to interact directly with customers, or it may operate behind the scenes as a white-label service provider. In either case, customers no longer have to interact with their bank in the traditional way. Instead, APIs allow consumers to interact with companies that may not be banks themselves, while still being seamlessly connected to regulated financial institutions through digital interfaces. While Open Banking has opened the door to greater data sharing, its role as a data-sharing mechanism can still have limitations. BaaS, meanwhile, can act as a catalyst for creating more seamless and integrated financial services in the digital economy. This model allows banks to move toward more customer-centric, platform-based business models. For traditional banks, this may also mean rethinking and restructuring how they operate. In many ways, the future of financial institutions could increasingly resemble the broader XaaS model. Making this transition possible requires a connected and collaborative ecosystem, where integration is at the core and APIs become a key enabler. Savyint provides a comprehensive Open Banking and BaaS ecosystem, backed by more than 20 years of experience in the Banking and Financial Services sector, with successful deployments for leading banks and major organizations across Vietnam and Southeast Asia (SEA). Contact us to start your banking digital transformation journey today HERE! Source: From open banking to banking-as-a-service – Nydia Remolin
Global Financial Fraud in Recent Years: Alarming Figures

Financial fraud targeting financial activities is becoming increasingly complex and sophisticated. The use of artificial intelligence (AI) by criminals, together with the widespread standardization and replication of malware and other technologies, is acting as a major driver of fraudulent activities. Financial Fraud Is Increasing Globally In INTERPOL’s March 2026 Global Financial Fraud Threat Assessment, financial fraud ranks among the top five global crime threats, with a 54% rise in fraud-related Notices and Diffusions from 2024 to 2025. Global fraud losses climb to $442 billion. The number of INTERPOL Notices and Diffusions related to fraud increased by 54% between 2024 and 2025. The sharp increase in INTERPOL alerts reflects the growing complexity and scale of cross-border fraud. Payment fraud is increasingly taking place across multiple jurisdictions, making purely domestic control measures no longer sufficient. Payment card fraud losses worldwide dipped 1.2% to $33.41 billion in 2024, according to the Nilson Report, the leading trade publication covering the global payment card industry. This fraud was tied to global card volume of $51.920 trillion. The 2026 AFP Payments Fraud and Control Survey Report provides that payments fraud remains widespread, with 76% of organizations reporting that they experienced attempted or actual fraud in 2025. Checks remain the payment method most frequently impacted by fraud. In 2025, 58% of organizations reported check fraud, outpacing ACH fraud and wire fraud. Despite long-standing awareness of check-related risks, checks continue to present persistent vulnerabilities for many organizations managing payments fraud risk. Business Email Compromise (BEC) remains one of the most common forms of payment fraud, as criminals increasingly exploit impersonation techniques to manipulate organizational processes. A 2025 study by global technology research and consulting firm Juniper Research found that e-commerce fraud is expected to increase from $56 billion in 2025 to $131 billion by 2030, representing a 133% increase over the period. This growth is driven by the rising incidence of friendly fraud, in which legitimate transactions are fraudulently disputed. Key Financial Fraud Trends AI-powered deception AI-powered manipulation is rapidly changing people’s perception of what can be considered trustworthy. Advanced AI tools can generate “deepfakes” — including realistic voices, synthetic videos, and highly personalized text — making it easier to stage scenarios that appear completely authentic, even to generations highly familiar with digital environments. As technology advances and the digital world becomes increasingly visual, victims find it more difficult to question what they see or hear. The boundary between reality and fabrication is becoming increasingly blurred. This creates an increasingly complex and unpredictable fraud landscape. According to Koren, once again, understanding human behavior has become critically important. Fraud Is Becoming More Personalized and Persistent Between 2024 and 2025, the number of fraud incidents involving social engineering increased by 33%. This method is not only growing in scale but is also undergoing a fundamental shift in its approach. To address future forms of fraud, technological expertise alone is no longer sufficient; understanding human behavior is equally essential. One clear trend is that social engineering is no longer simply a technical attack, but has evolved into a prolonged process of influencing individuals. Whereas fraud previously often consisted of a single message, we are now seeing multi-step schemes in which trust is gradually built over days or even weeks. Criminals are increasingly using psychological tactics: they spend time learning about their victims, mimicking their language and behavior, and then gradually influencing them to make decisions that ultimately harm themselves. The Professionalization of Fraud Tools One clear emerging trend is the professionalization of fraudulent online storefronts. Scam websites have evolved significantly: they are no longer crude and poorly designed sites, but professionally built platforms with convincing e-commerce interfaces and close integration with digital marketing channels such as Facebook. Fraudsters can quickly create new stores with a trustworthy appearance within just a few hours, while flexibly adapting their visuals and messaging with remarkable sophistication. One alarming trend that Recorded Future called out is the increasing industrialization of support services and technology that allows fraudsters to maximize their effectiveness. One such popular tool allows scam operators to rewrite the code on an online retailer’s payments page and then steal, or “skim,” payment information as transactions happen in attacks called Magecart. The report points out that there were 10,500 such hacks active in 2025, leading to the compromise of over 23 million online transactions. These highly professional fraudulent commercial environments play a critical role in the constantly evolving fraud economy, targeting online shoppers through highly convincing storefront interfaces. Cross-Border and Distributed Fraud Operations We are also seeing a significant increase in cross-border fraud activities, particularly in the movement of illicit funds. Transactions are distributed across multiple countries, with participants — including both willing participants and individuals who are manipulated or unaware of the scheme — being used to break transaction flows into smaller segments, making them more difficult to trace. The recruitment of “money mules” often relies on psychological tactics involving financial pressure, social influence, and emotional manipulation. The “fraud economy” is becoming increasingly professionalized and global, while also becoming far more adaptable and resilient. Savyint Fraud Detection and Prevention Solutions With more than 20 years of experience in cybersecurity, information security, and cyber safety, particularly in the financial and banking sectors, Savyint has developed a comprehensive ecosystem of solutions for fraud detection, payment security, identity, authentication, and system access control. We leverage AI, AI agents, and the latest security standards to detect and respond to fraud, ensuring that every transaction conducted in our customers’ digital environments is protected in real time and capable of withstanding evolving and increasingly sophisticated forms of fraud over the long term. Our solution ecosystem includes: Contact us today for expert consultation HERE! Reference: https://www.helpnetsecurity.com/2026/03/18/online-fraud-victims-losses-interpol-report https://www.tietoevry.com/en/blog/2026/04/five-payment-fraud-trends-to-monitor https://www.mastercard.com/global/en/news-and-trends/stories/2026/recorded-future-annual-payment-fraud-report.html https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud The Nilson Report
Ensuring Information Security in Electronic Transactions in Selected Countries

In the era of digital transformation, electronic transactions are becoming increasingly prevalent and have become an important foundation for commercial activities, public services, and social governance. Therefore, many countries have enacted legal regulations to protect parties involved in electronic transactions and ensure information security. 1. European Union 2. United States 3. Canada 4. Australia 5. Vietnam The laws governing electronic transactions in many countries, particularly developed economies, have become relatively comprehensive, covering legal frameworks, electronic signature/trust service regulations, personal data protection, enforcement of violations, international recognition, and clear technical standards. However, challenges remain regarding data security, personal data protection, and legal compliance, which need to be further strengthened and more rigorously developed. Reference:
Detecting and Preventing Real-Time Deepfake Impersonation

If you are concerned about the growing threat of deepfakes, you are not alone. The spread of deepfakes is closely tied to the question of what is real and what is fake, as well as the growing erosion of digital trust. So, what exactly are deepfakes, and how can we detect and prevent them? Let’s explore these questions in today’s article. 1. What Are Deepfakes? Deepfakes are highly realistic forms of synthetic media, typically in the form of video or audio, created using AI to manipulate or fabricate content, making viewers believe that someone said or did something they never actually said or did. As a result, deepfakes are increasingly being used to facilitate financial fraud, undermine user trust, and create risks for legal systems. However, like many other AI technologies, deepfakes also have positive applications, including online education, digital content creation, and enhanced film production. Nevertheless, the risks associated with deepfakes are increasingly beginning to outweigh their potential benefits. 2. How to Detect Deepfakes Deepfakes affect users in three primary ways: by manipulating personal data or images; deceiving viewers into believing that fake content is real; and causing genuine content to be mistakenly identified as fake. So, how can we determine whether content is a deepfake? Below are four key techniques that can help. 2.1 Manual Inspection Using the Naked Eye 2.2 Contextual Checks 2.3 Technical Detection Tools The rapid development of AI technology is making the detection and prevention of deepfakes increasingly challenging. To mitigate and prevent these threats, technology providers, users, and regulators must work together. From a technology perspective, capabilities such as Blockchain-based content provenance and verification need to be strengthened to help establish the origin and integrity of digital content. Users need to develop stronger media literacy, verify content before sharing it or carrying out requested transactions, and report suspicious content. Finally, regulators need to strengthen platform policies and enforcement mechanisms, establish proactive content moderation systems, clearly label deepfake and AI-generated content, introduce effective deterrents against the malicious use of deepfakes, mandate greater transparency for AI-generated content, and work toward global standards for digital integrity. By bringing these efforts together, we have a real opportunity to restore digital trust and give users greater confidence and security in the online environment. Contact SAVYINT’s experts today for consultation on digital fraud detection solutions HERE.
Singapore’s Singpass Introduces Passkeys to Strengthen National Digital Identity

The Government Technology Agency of Singapore (GovTech Singapore) announced the rollout passkey on Jun 30, 2026 as a new login method for Singpass, Singapore’s national digital identity platform. Singpass is every Singapore resident’s trusted digital identity to prove who we are when performing everyday transactions like checking our CPF balance, booking medical appointments, renewing insurance and more. Access over 2,700 services across 800 government agencies and businesses, simply by authenticating with your biometrics or SMS Two-Factor Authentication (2FA). Created by GovTech as a key enabler of Singapore’s digital economy, Singpass facilitates over 41 million transactions every month. Out of 5 million Singpass users, more than 4.2 million people use the Singpass app to easily log in to services, prove their identity over counters, digitally sign documents and do more on the go. Passkeys add to existing authentication methods such as QR login, Face Verification, and SMS One-Time Passwords (OTPs). Passkeys are a secure, password-free way to log in to services with Singpass. They are phishing resistant and use device-based authentication such as facial recognition, fingerprint, or app passcode to verify your identity. If a device is lost or stolen, the Singpass app and passkey on it will be automatically deactivated when the user sets up Singpass on another device. What is a Passkey? A passkey is a cryptographic key designed to replace passwords. As old passwords could easily be stolen, hacked, or even guessed, passkeys would work on a completely different level, with public-private key pairs authentication. Unlike a password, passkeys cannot be shared, remembered, or written down. This makes it far less vulnerable to the types of attacks that commonly target password-based systems. While early biometric authentication technologies laid the foundation for identity verification, the journey toward passkeys began in 2012 with the establishment of the FIDO Alliance, with the mission of eliminating passwords. The passkey revolution began in 2021, when major technology companies adopted the FIDO2 and WebAuthn standards, enabling passwordless authentication. Today, passkeys have become an authentication method accessible to billions of users worldwide. A significant milestone in the evolution of passkeys was the National Institute of Standards and Technology (NIST) formally recognizing synced passkeys in its supplement to the SP 800-63B guidelines. NIST SP 800-63B Supplement This recognition highlights the phishing-resistant nature of passkeys, while demonstrating their potential to replace traditional passwords with a more secure, convenient, and user-friendly authentication method. With NIST’s recognition, passkeys are well positioned for widespread adoption, particularly in highly regulated industries such as banking and healthcare. This is expected to drive the next phase of secure digital identity verification. The Difference Between Passkeys and Passwords Types of Passkeys There are two main types of passkeys, designed for different use cases and, more importantly, different security requirements. Within the digital security ecosystem, the two primary categories are Multi-Device Passkeys and Device-Bound Passkeys. Let’s explore the differences between them. Multi-Device Passkeys Multi-Device Passkeys, also known as Synced Passkeys, are well suited for personal use. They can be seamlessly synchronized across multiple devices, such as smartphones, tablets, and laptops, provided those devices are linked to an Apple, Google, or Microsoft account. This flexibility allows users to access their accounts from any trusted device without having to remember or enter a password. Device-Bound Passkeys In contrast, Device-Bound Passkeys can be viewed as a “security shield” for enterprise environments. Because they are bound to a single device and cannot be copied, this type of passkey provides an additional layer of security that is particularly valuable for organizations with strict data protection and access control requirements. In other words, Multi-Device Passkeys prioritize convenience and flexibility, while Device-Bound Passkeys prioritize stronger control and security. Benefits of Passkeys Benefits for Users Benefits for Developers As these technologies continue to evolve, more people are asking: What is a passkey, and how does it work? Growing interest in passkeys is encouraging technology innovators to invest significant resources in researching, developing, and advancing this technology. Passkeys are set to bring profound changes to security and digital identity while shaping how future generations interact with the digital world. Reference source: https://www.passkeys.com/ Contact us HERE to explore Savyint’s most advanced and secure solutions for authentication and digital identity.
eIDAS 2.0 – Reshaping a Safer and More Trusted Digital Future for Europe

Building on the foundation of eIDAS – the European framework for “Electronic Identification, Authentication and Trust Services” in the European Single Market – eIDAS 2.0 was introduced to strengthen the region’s digital infrastructure, promising greater efficiency and higher levels of trust in the digital economy. eIDAS – The Regulation on Electronic Identification, Authentication and Trust Services Approved in September 2014, the Regulation on “Electronic Identification, Authentication and Trust Services” for the European Single Market, known as eIDAS, became fully applicable in September 2018. Under eIDAS, European citizens and businesses can use nationally issued electronic identification systems to verify their identities when accessing public services or carrying out cross-border electronic transactions. eIDAS focuses on two key areas: Importantly, eIDAS applies not only to public authorities but also to private-sector organizations that use electronic identification or trust services, including those in the financial services, insurance, healthcare, and e-commerce sectors. As such, eIDAS serves as a unified digital trust infrastructure for cross-border electronic transactions across Europe. Why is eIDAS 2.0 Needed? Although eIDAS significantly improved Europe’s electronic identification and trust services infrastructure, several limitations remained. The emergence of new electronic identification services and models has resulted in a fragmented market. The scope of the existing legal framework no longer fully reflects the way electronic identification and trust services are being used in practice. Today, private companies also provide eID solutions, but these solutions do not necessarily follow a unified standard offering the same high levels of security, assurance, and transparency as eID schemes recognized under eIDAS. While eIDAS-compliant eID solutions are secure, their adoption and usability in the private sector have remained relatively limited. Challenges also exist in areas such as identity verification, data management, and user control. Today’s users expect a seamless and secure online experience. They want to access both public and private services such as healthcare and banking through a single, convenient digital identity or Single Sign-On (SSO) experience. However, the original eIDAS framework focused primarily on cross-border access to public services, while giving less attention to the needs of the private sector. Even for public services, barriers remain that prevent many citizens from accessing trusted electronic identification solutions. Social media platforms and private technology companies already offer login options based on existing accounts, such as Facebook, Microsoft, or Google. However, these solutions raise concerns regarding data control and security. They often lack robust real-world identity verification processes, potentially making systems more vulnerable. In addition, using these platforms across multiple services may result in non-transparent data sharing and privacy concerns. What is eIDAS 2.0? eIDAS 2.0 – officially known as the European Digital Identity Framework under Regulation (EU) 2024/1183 – is the updated version of the European Union’s framework for electronic identification, authentication, and trust services. The updated framework is designed to improve the efficiency of cross-border services while supporting secure electronic identification solutions for both the public and private sectors. eIDAS 2.0 represents a structural evolution of Europe’s digital identity and trust services framework. It addresses limitations in the original framework, expands the range of regulated trust services, strengthens security and governance requirements, and, most notably, introduces the European Digital Identity Wallet (EUDI Wallet) as a core component of Member States’ digital identity ecosystems. Key Changes Introduced by eIDAS 2.0 The transition from eIDAS to eIDAS 2.0 introduces two major developments aimed at strengthening Europe’s legal and regulatory framework for electronic identification and trust services. Expanded Trust Services eIDAS 2.0 further develops the regulatory framework for Qualified Trust Service Providers (QTSPs), with particular emphasis on identity verification processes for individuals and legal entities when qualified certificates are issued. The objective is to ensure greater consistency and harmonization across Europe. In addition, new qualified trust services – including electronic archiving, electronic ledgers, and the management of remote electronic signature devices – have been introduced under eIDAS 2.0. European Digital Identity Wallet (EUDI Wallet) One of the most significant innovations introduced by eIDAS 2.0 is the European Digital Identity Wallet (EUDI Wallet). The EUDI Wallet is a secure, user-controlled digital wallet that enables individuals to store, manage, and selectively share their identity data, credentials, and other personal information, as well as verified legal documents such as driving licences, educational qualifications, professional certificates, or bank account information. The Wallet can be used for both online and offline services, allowing users to conveniently share verified credentials with relying parties including government authorities and private-sector organizations for purposes such as identity verification or electronic signing. Under the original eIDAS framework, EU Member States had the discretion to decide whether to develop or notify official national electronic identification schemes. This resulted in significant differences in adoption rates among Member States and inconsistencies in cross-border interoperability. eIDAS 2.0 replaces this approach with a more unified and mandatory framework. By the end of 2026, each EU Member State is required to make at least one European Digital Identity Wallet (EUDI Wallet) available to its citizens and residents. Conclusion The adoption of eIDAS 2.0 marks a significant step toward a secure, interoperable, and trusted ecosystem for electronic identification and trust services across the European Union. By emphasizing user-friendly experiences, strong security mechanisms, and streamlined processes, eIDAS 2.0 is expected to deliver tangible benefits for citizens, businesses, and government institutions alike. While the detailed implementation roadmap is still being developed, the foundations have now been established for a safer, more inclusive, and more trusted digital future for people across Europe.
Strengthening Authentication, Fraud Prevention and Risk Governance Become Top Priorities for Philippine Banks

To strengthen fraud prevention, the Bangko Sentral ng Pilipinas (BSP), under Circular No. 1213, requires institutions to adopt enhanced authentication methods in place of SMS and email OTPs, while also strengthening automated fraud management systems. According to BSP Circular No. 1213, issued in May 2025, the central bank requires BSP-supervised financial institutions to replace SMS- and email-based OTPs with stronger authentication methods such as biometrics, behavioural authentication, adaptive authentication, or passwordless authentication by 25 June 2026. In addition, the circular sets out specific requirements for strengthening automated fraud monitoring. This directive applies to banks and e-wallet operators with average online transaction revenues of more than PHP 75 million per month, including most commercial banks, digital banks, cooperative banks, and rural banks. Banks that fail to comply must reimburse customers for funds lost due to fraud. 1. Authentication and Compliance Requirements Circular 1213 requires institutions to move away from authentication mechanisms that can be shared with or intercepted by third parties. SMS and email OTPs fall under this definition. By 30 June 2026, high-risk transactions and critical account changes must use phishing-resistant, device-bound alternatives, such as server-side biometrics authenticated against templates stored by the bank, or FIDO2/WebAuthn passkeys with device authentication. OTPs may only be used to confirm ownership of a registered mobile phone number. Biometrics BSP requires financial institutions to adopt server-side biometric authentication, where customer identity is verified within the bank’s secure backend system based on biometric templates stored on the bank’s server. The use of biometrics is expected to reduce the risks of account takeover, device compromise, spoofing, and unauthorized changes to authentication credentials. FIDO2 Passkey FIDO2/WebAuthn is a passwordless authentication standard designated by BSP as a mandatory solution for high-risk transactions and critical account changes, which must use phishing-resistant and device-bound alternatives. Smart OTP As mentioned above, Smart OTP is used for one purpose only: confirming ownership of a registered mobile phone number. It must not be used for transaction authentication. This is an important distinction that banks should note to avoid confusion with traditional OTPs. 2. Fraud Prevention and Management Requirements In addition to strong authentication methods, Circular 1213 also requires financial and banking institutions to strengthen their proactive fraud monitoring and detection capabilities by identifying suspicious transactions, unfamiliar devices, and abnormal customer behaviour before financial losses occur. Accordingly, fraud management systems must operate in real time and be capable of: BSP emphasizes that batch processing or end-of-day reconciliation does not meet this standard. 3. AI-Powered Strong Authentication and Fraud Prevention Solutions from Savyint With extensive experience working with and supporting financial institutions, SAVYINT provides a security and fraud prevention solution suite that supports compliance with AFASA and BSP Circulars 1213, 1214, and 1215. The solution suite is built around four pillars: strong and passwordless authentication; AI-powered fraud management; security, data encryption, and application protection; and risk management and compliance with local and international regulatory requirements. It ensures end-to-end protection across the entire customer journey, from registration, login, and transaction authentication to post-transaction monitoring. Key differentiators of the SAVYINT solution suite include: In particular, Savyint’s solution suite supports compliance with regulatory requirements in multiple countries, including the Philippines, such as AFASA and BSP Circulars 1213-1215; Vietnam, such as Circulars 50, 64, and 77 of the State Bank of Vietnam; and Singapore, such as MAS requirements. It also aligns with international security standards including FIDO2, PSD2/PSD3, eIDAS, GDPR, PCI DSS,… Connect with our experts today to quickly achieve compliance with AFASA and BSP Circulars 1213-1215.
Savyint wins two Sao Khue 2026 Awards, with Savyint Digital Trust rated 5 stars

In its second year participating in the Sao Khue Awards, Savyint continues to stay committed to its mission of strengthening cybersecurity and digital trust, with two technology solutions honored at the Sao Khue Awards 2026: Savyint Digital Trust and SAM Appliance. Notably, Savyint Digital Trust received a 5-star rating in the Application and Data Security category. On May 28, the Sao Khue Awards 2026 Ceremony was solemnly held in Hanoi by the Vietnam Software and IT Services Association (VINASA), under the patronage of the Ministry of Science and Technology. Entering its 23rd year, Sao Khue 2026 marks an important transformation as it is redesigned under the “new-generation Sao Khue” model—not only as an event honoring outstanding digital technology products and services, but also as a system for evaluating, validating and positioning the digital technology capabilities of Vietnamese enterprises. After rigorous assessment rounds, the Final Jury of the Sao Khue Awards 2026 selected 123 outstanding digital platforms, services and solutions. These recognized solutions clearly reflect the strong shift in technology trends toward platforms capable of solving practical problems, optimizing operations, protecting data, enhancing transaction security and building trust in the digital environment. This year, Savyint’s award-winning solutions at Sao Khue demonstrate the company’s research, development and mastery of core technologies in cybersecurity, cryptography, electronic identification, digital signatures and online fraud prevention through Savyint Digital Trust and SAM Appliance. In particular, Savyint Digital Trust received a 5-star rating for its relevance and ability to keep pace with global fraud prevention trends. Savyint Digital Trust – A comprehensive security and fraud prevention platform In response to the growing need for proactive fraud prevention and increasingly stringent international regulatory requirements, Savyint Digital Trust is a unified security platform designed to protect the entire digital journey of users and transactions. Built on a Zero Trust security architecture powered by cryptography, Savyint Digital Trust helps organizations strengthen security, enhance user experience and build sustainable digital trust. The solution integrates key capabilities, including: With high scalability and flexible integration with internal enterprise systems, Savyint Digital Trust is suitable for various sectors, including digital banking, fintech, e-wallets, payments, e-commerce, enterprises, government, public services and systems that process sensitive data. SAM Appliance – An all-in-one solution for data encryption, digital signature authentication and mobile identification Alongside Savyint Digital Trust, SAM Appliance is also one of SAVYINT’s two solutions honored at Sao Khue 2026. It is an all-in-one solution for data encryption, digital signature authentication and mobile identity, built on a Cloud HSM platform. The solution ensures compliance with standards for remote signing, blockchain, crypto assets, mobile payment, data encryption, transaction encryption, timestamping, security, system authentication, IoT, Car2X and more. SAM Appliance includes: SAM Appliance confidently complies with regional technical standards as well as international legal and regulatory requirements such as FIPS 140-2 Level 3, ISO 9001:2015, ISO 14001:2015, ISO 27001:2022, GDPR, SOC 2 Type II, HIPAA and PCI DSS. Notably, SAM Appliance supports Post-Quantum algorithms such as ML-KEM, ML-DSA and SLH-DSA, helping shape organizations’ security strategies in the quantum era. The Sao Khue Awards 2026 are not only a recognition of SAVYINT’s innovation efforts, but also a motivation for the company to continue researching, improving and bringing to market more comprehensive solutions for security, identity and digital trust, contributing to the development of a safe, reliable and sustainable digital infrastructure for Vietnam and international markets. Two consecutive years of participation and two consecutive awards at Sao Khue stand as proof of the steadfast journey the company has pursued from the very beginning: strengthening security and building digital trust. Savyint will continue contributing to the development of a secure, trusted and sustainable digital infrastructure for Vietnam and the global market. Some snapshots from the event:
From PSD3 and eIDAS 2.0 to Zero Trust: A New Security Strategy for the Finance and Banking Sector

The financial sector is entering a period of profound transformation. Amid the rapid increase in both the frequency and financial impact of scams and payment fraud – alongside emerging risks from quantum computing and tighter regulatory requirements under PSD3 and eIDAS 2.0, financial institutions need a well-structured, proactive, flexible, and future-ready security strategy. From PSD1, PSD2 to PSD3: A new standard for digital payments and fraud prevention In 2007, the European Union’s first Payment Services Directive, PSD1, established a unified payments market, improved transparency, and enabled cross-border e-commerce. A decade later, PSD2 was introduced, driving competition through open banking, requiring Strong Customer Authentication (SCA), and creating a legal foundation for third-party access to payment accounts. By November 2025, the European Parliament and the Council of the European Union reached a provisional political agreement on PSD3, addressing emerging challenges in digital payments, open banking, and fraud prevention. One of the most notable aspects of PSD3 is the strengthened requirement for Strong Customer Authentication. SCA is no longer limited to payment authentication, but is also extended to a wider range of customer actions, such as changing transaction limits, updating contact information, restoring devices, setting up authorization, or changing authentication methods. Strong authentication is becoming an integral layer across the entire customer journey. Under the latest directive, PSD3 also reinforces the responsibility of payment service providers in fraud prevention. When incidents occur involving authentication failures or suspicious transactions, legal liability must be clearly defined. This is a key driver for financial institutions to invest more heavily in multi-layered authentication, risk analytics, transaction monitoring, and digital identity protection. In addition, PSD3 continues to promote API standardization in open banking, compliance with FAPI, and greater consistency, interoperability, and service quality among banks, fintech companies, and third-party providers. If PSD3 raises the question of how to strengthen customer authentication, reduce fraud, and ensure accountability in digital payments, then eIDAS 2.0 provides part of the answer – by positioning digital identity and electronic identity wallets as a trusted, standardized, and cross-border foundation for user verification. eIDAS 2.0: Digital identity as the foundation of digital trust While PSD3 focuses heavily on payments and financial services, eIDAS 2.0 places electronic identity and trust services at its core. One of the most prominent elements of eIDAS 2.0 is the European Digital Identity Wallet, or EUDI Wallet. The EU DI Wallet enables individuals and businesses to store, manage, and use their digital identity across a wide range of services. When integrated into the financial sector, digital identity wallets can become a powerful authentication method, helping customers access banking services, verify their identity, and conduct transactions more securely. Beyond promoting the EUDI Wallet, eIDAS 2.0 also introduces stricter requirements for Trust Service Providers, or TSPs, in areas such as governance, risk management, and auditability. In particular, crypto-agility and readiness for Post Quantum Cryptography, or PQC, are identified as critical factors to ensure the long-term resilience of trust services. The requirements under PSD3 and eIDAS 2.0 reflect a clear trend: financial security is becoming inseparable from digital identity. A secure transaction requires not only a protected payment system, but also a trusted and verifiable identity authentication foundation. For banks and fintech companies, this creates an urgent need to prepare modern authentication infrastructure that can integrate with digital identity wallets, support passwordless authentication, manage the identity lifecycle, and provide compliance evidence when required. Zero Trust Security Architecture: Never trust by default, always verify Zero Trust is one of the most widely discussed security architectures today, thanks to its strong security posture and core principles: Instead of assuming that users, devices, or applications inside the system are secure, the Zero Trust model starts from the principle that no user, device, or application should be trusted by default. As a result, every access request must be continuously verified, rather than checked only once at login. For the Finance and Banking sector – where sensitive data, high-value transactions, and multiple third-party connection points are involved – a well-implemented Zero Trust security architecture can help organizations reduce the risk of unauthorized access, minimize potential damage when incidents occur, and strengthen control over activities across the entire system. Further reading on Zero Trust: Savyint Group: A trusted partner in building digital trust Bringing together leading experts in open banking, data encryption, and payment security, Savyint is ready to accompany enterprises and global partner ecosystems throughout the journey – from assessment and roadmap consulting to testing and implementation of Zero Trust-aligned security solutions. These solutions are designed to meet stringent international standards such as PSD3, eIDAS 2.0, PCI DSS,… and to prepare organizations for the Post Quantum era. Savyint’s comprehensive security and fraud prevention solution suite, built on a Zero Trust architecture, addresses multiple critical challenges at once: Notably, Savyint is also the first organization to announce a PQC Lab in Vietnam. The lab enables organizations to explore NIST-approved PQC algorithms, address real-world challenges in the Finance sector, and assess compatibility, performance, and impact – without disrupting existing infrastructure or operational systems. Through this testing environment, organizations can reduce migration risks, select suitable technologies, and systematically build internal capabilities. In addition to its deep expertise, Savyint is also a global technology partner of major industry leaders such as Entrust, Keyfactor, Crypto4A, Kryptus, Futurex, Thales,… Connect with Savyint’s experts today to stay ahead of the next wave of security innovation.