{"id":18544,"date":"2024-04-10T17:33:33","date_gmt":"2024-04-10T16:33:33","guid":{"rendered":"https:\/\/staging2022.42crunch.com\/?p=18544"},"modified":"2024-04-10T21:49:18","modified_gmt":"2024-04-10T20:49:18","slug":"addressing-api-security-regulations-in-financial-services","status":"publish","type":"post","link":"https:\/\/staging2022.42crunch.com\/addressing-api-security-regulations-in-financial-services\/","title":{"rendered":"Addressing API Security Regulations in Financial Services"},"content":{"rendered":"

Introduction<\/span><\/h2>\n

APIs are disrupting almost every industry vertical, and nowhere is their impact more profound than in the financial services industry. Whether helping modernize legacy systems or creating entirely new business opportunities through innovations such as OpenBanking, APIs are the lifeblood of the financial services industry. At the same time, there is increasing scrutiny on the security of these very APIs to ensure that they both meet the requirements of strict regulatory standards (such as PSD2 and PCI-DSS) and instil confidence within their customers.\u00a0<\/span><\/p>\n

OpenBanking depends on APIs to connect banking systems, customer devices, and third-party providers (TPPs). OpenBanking allows TTPs to provide innovative services, access account information, and initiate payments on the account holder\u2019s behalf. It is becoming widely adopted, with one in nine people in the U.K. using associated services in 2023 and a doubling in the volume of payments in that period. Due to the sensitive nature of the data and operations processed by OpenBanking APIs, providers must ensure they are implemented securely to meet regulatory requirements and customer demands.\u00a0<\/span><\/p>\n

The overarching regulatory standard to ensure secure APIs is the European Union (EU) Payment Services Directive (PSD2), which has specific requirements for the following:<\/span><\/p>\n