Open Banking is the development of a new financial ecosystem based on connections between financial institutions and businesses, supported by APIs. Financial institutions are enabling third parties to integrate services, provide access to banking data, and deliver entire banking services through APIs. So how can APIs, data, and user consent be managed and protected?
Key Characteristics of Open Banking
Open Banking focuses on serving consumers, with API or SDK technology as its core foundation and operates within the financial ecosystem. Open Banking has three key characteristics: data portability, customer autonomy, and recipient accountability.
- Data Portability
The International Organization for Standardization (ISO) defines data portability as “the ability to easily transfer data from one system to another without having to re-enter the data.” Based on this definition, in Open Banking, consumers can share their relevant banking data with third-party providers (TPPs), in line with “data portability.” Data portability in Open Banking is supported by standardized and interoperable data technologies, primarily APIs.
- Customer Autonomy
This is a fundamental principle of liberal democracy, in which marketers are permitted to influence customers but must respect their autonomy. Open Banking empowers customers to control the sharing of their banking data, and this right is supported by customers’ legal rights to share data through Open Banking.
- Recipient Accountability
Open Banking requires recipients of customers’ banking data (TPPs) to be accountable to customers. Therefore, Fintech companies receiving banking data must be responsible for protecting this data from leakage, theft,… This is why strict management of TPPs through a regulatory system is very important.
In summary, these three characteristics of Open Banking all reflect the goal of improving competitiveness, promoting innovation, and strengthening consumer protection.
Solutions for Managing APIs, Data, and User Consent
With many years of experience in developing security solutions as well as specialized solutions for the Financial – Banking sector, Savyint has developed an Open Banking Tech Stack solution that enables banks to comply with the current legal regulations of each country (such as EU PSD2/3, Philippines AFASA, BSP Circular No. 1213 – 1215, Vietnam Circular No. 64, Circular No. 50, Circular No. 77…), ensuring end-to-end security across API protection, payment, data sharing, and consent management operations.
- For API security: integrate HSM with API Gateways supporting OAuth/JWS/TLS, limit the number of API requests, conduct inspection and tracing to protect credentials and access rights. All critical APIs are ensured for integrity and centrally managed in a single location, reducing the risk of exposing security information in individual applications.
- Use hardware security modules HSM – Root of Trust in protecting APIs, payments, data sharing, and consent management.
- For data sharing, Savyint combines Consent Management based on Microservices architecture – breaking data down into small, independent components – to control data shared according to the TPP, account, scope, and duration approved by the customer.
- Integrate a consent lifecycle management system (grant, revoke, expire), record consent evidence; support control over data query periods in accordance with regulations; combine a signing key management system – KMS based on HSM to protect the cryptographic layer and the integrity of evidence.
- Integrate with third-party service provider management modules, digital certificate lifecycle management, and Monitoring/SIEM, helping banks centrally manage partners, digital certificates, monitoring, and activity tracing.
In particular, the solution is flexibly designed by Savyint according to scale, prioritizing the use of existing security infrastructure: small banks can deploy it in a simple and lightweight manner; large banks can scale up to a highly redundant model, ensuring continuous and stable operations even in the event of incidents.
Contact us now for consultation HERE!






