SlideShare a Scribd company logo
Date: June 2020
Prepared by: John Phenix
Chief API Architect, HSBC Commercial Bank
Automating API Governance
PUBLIC
1
1
HSBC - The World’s Leading International Bank
39million
customers
3,900 offices
65
countries & territories
Present in
Reported Revenue
$53.8bn 254PB of data
Data Centres in 21
countries
96,600+ Servers
$1.5 Trillion
Daily payments processed
235,000
people around the world
46,000 IT Professionals $2.5bn Run / $3.3bn Change (cash)
PUBLIC
2
Challenge
PUBLIC
How to make API governance an accelerator
instead of a brake?
3
Apple’s iOS Standards and Governance platform produces a consistent, market leading App experience
Why HSBC needs API Standards and Governance – an example from Apple
PUBLIC
4
HSBC’s API Standards and Governance platform will produce a consistent, market leading API developer experience
Why HSBC needs API Standards and Governance
Governance
PUBLIC
Governance
5
Tip 1: What to Govern?
PUBLIC
Security Operations Reputation
As little as possible!The minimum needed to deliver value and
manage risks
Tip 1: Focus governance on real risks rather than personal preferences
6
Comprehensive
Tip 2: What does good look like?
PUBLIC
Scalable Consistent
Evidenced
Tip 2: Good governance scales to meet delivery cadence
7
Visibility
Tip 3: Where to invest effort
PUBLIC
Tools Training
Automation
Tip 3: Shift left – make it easier to fall into success
8
Tip 4a: Pick your style - Centralised
Small team(s) of API SMEs who manually review APIs.
You can duplicate the ARB (API Review Board) in different
geographies.
Scalable
Consistent
Comprehensive
Evidenced
PUBLIC
9
Tip 4b: Pick your style - Federated
API Champions from every region and major project to enforce
standards locally and escalate non-compliance.
Scalable
Consistent
Comprehensive
Evidenced
PUBLIC
10
Tip 4c: Pick your style - Automated
Speed and safety at scale requires an automated approach.
Scalable
Consistent
Comprehensive
Evidenced
PUBLIC
11
Tip 4c: Pick your style -– Hybrid
Focus manual reviews on exceptions and qualitative analysis.
Scalable
Consistent
Comprehensive
Evidenced
PUBLIC
Tip 4: Move from “Are we building APIs right?” to “Are we building the right APIs?”
12
Tip 5: How to automate
Audit Trail
API
Engineers
Governance
Engineers
Batch
Rules Setup
CI/CD Pipeline
CAGE UI
Repository
Rules
Lead
Architects
Certification
Dashboard
CAGE
PUBLIC
13
Peer Reviews
Tip 5: How to automate
PUBLIC
Building APIs Right Building the Right APIs
Training
Tip 5: Automate as much as you can, but you still need people
14
5 Governance Tips
Q1: What to govern
Q2: What does good look like
Q3: Where to invest effort
Q4: How to pick your style
Q5: How to automate
PUBLIC
Tip 1: Focus governance on real risks rather than personal preferences
Tip 2: Good governance scales to meet delivery cadence
Tip 3: Shift left – make it easier to fall into success
Tip 4: Move from “Are we building APIs right?” to “Are we building the right APIs?”
Tip 5: Automate as much as possible, but you still need people
15
Example Rules
Security:
• Sensitive info in query parameters
• Standard headers
• Security policies
Operations:
• Naming standard
• Published to API Repository
• Versioning
• Check for duplicate APIs
• Health endpoint
Style:
• camelCase, PascalCase and snake-case
• Always return 2xx, 4xx and 5xx
• Misuse of HTTP verbs
• Plural nouns for resource collections
• Example request and response schemas
PUBLIC
16 PUBLIC

More Related Content

PPTX
Ex Libris REST API Governance Thresholds
PPTX
API Governance – Modern API solutions in a digitalized world
PPTX
API Governance in the Enterprise
PDF
API Governance
PDF
apidays LIVE Singapore 2021 - What financial services can learn from Marketpl...
PPTX
APIdays London 2019 - Selecting the best API Governance for your organisation...
PPTX
Monetizing on APIs with better API management and monitoring
PPTX
API Management Workshop (at Startupbootcamp Berlin)
Ex Libris REST API Governance Thresholds
API Governance – Modern API solutions in a digitalized world
API Governance in the Enterprise
API Governance
apidays LIVE Singapore 2021 - What financial services can learn from Marketpl...
APIdays London 2019 - Selecting the best API Governance for your organisation...
Monetizing on APIs with better API management and monitoring
API Management Workshop (at Startupbootcamp Berlin)

What's hot (20)

PDF
API Governance and GitOps in Hybrid Integration Platform (MuleSoft)
PDF
apidays LIVE Australia 2021 - SEEK: Establishing a new API integration platfo...
PDF
apidays LIVE Australia 2021 - APIs, open ecosystems, and the emerging future ...
DOCX
API Strategy in Cloud
PDF
apidays LIVE New York 2021 - Design-First: How to champion an API culture shi...
PDF
WSO2Con ASIA 2016: Service Governance Meets API Governance: A Case Study
PDF
Effective API Governance: Lessons Learnt
PPTX
O'Reilly author webinar "APIs: A Strategy guide": Transforming Your Business...
PDF
apidays LIVE Paris 2021 - 5 Learnings Shaping Our View on the Future of APIs ...
PPTX
apidays LIVE New York 2021 - API Automation For DevOps at Scale by Rod Cope, ...
PDF
[apidays Live australia] Building a Sustainable Ecosystem with Open APIs for ...
PPTX
Vizag Virtual Meetup #7: Trending API Topics for 2022
PDF
apidays LIVE Paris 2021 - Beyond API Governance: Run your API org like a lean...
PPTX
apidays LIVE New York 2021 - API narrative: A true story of APIs and I by Div...
PDF
Explaining API Integration: How Does API Integration work?
PDF
apidays LIVE Hong Kong 2021 - Getting API Management adopted: the hearts and ...
PDF
Apigee and Accenture Webcast - Accenture Technology Vision 2013 - An API Cent...
PDF
INTERFACE, by apidays - Aligning teams and strategies behind API investment ...
PPTX
API Management Part 1 - An Introduction to Azure API Management
PDF
INTERFACE by apidays - API Success: Running a Successful API Program by Nelso...
API Governance and GitOps in Hybrid Integration Platform (MuleSoft)
apidays LIVE Australia 2021 - SEEK: Establishing a new API integration platfo...
apidays LIVE Australia 2021 - APIs, open ecosystems, and the emerging future ...
API Strategy in Cloud
apidays LIVE New York 2021 - Design-First: How to champion an API culture shi...
WSO2Con ASIA 2016: Service Governance Meets API Governance: A Case Study
Effective API Governance: Lessons Learnt
O'Reilly author webinar "APIs: A Strategy guide": Transforming Your Business...
apidays LIVE Paris 2021 - 5 Learnings Shaping Our View on the Future of APIs ...
apidays LIVE New York 2021 - API Automation For DevOps at Scale by Rod Cope, ...
[apidays Live australia] Building a Sustainable Ecosystem with Open APIs for ...
Vizag Virtual Meetup #7: Trending API Topics for 2022
apidays LIVE Paris 2021 - Beyond API Governance: Run your API org like a lean...
apidays LIVE New York 2021 - API narrative: A true story of APIs and I by Div...
Explaining API Integration: How Does API Integration work?
apidays LIVE Hong Kong 2021 - Getting API Management adopted: the hearts and ...
Apigee and Accenture Webcast - Accenture Technology Vision 2013 - An API Cent...
INTERFACE, by apidays - Aligning teams and strategies behind API investment ...
API Management Part 1 - An Introduction to Azure API Management
INTERFACE by apidays - API Success: Running a Successful API Program by Nelso...
Ad

Similar to 5 Tips for Scaling API Governance (20)

PPTX
apidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoica
PDF
INTERFACE by apidays 2023 - API Design Governance, Nauman Ali, Stoplight
PDF
apidays Singapore 2025 - From API Intelligence to API Governance by Harsha Ch...
PDF
Approaching APIs
PDF
INTERFACE by apidays 2023 - Governance Doesn't Have to be a Dirty Word, Jason...
PPTX
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
PDF
WSO2's API Vision: Unifying Control, Empowering Developers
PDF
API Governance and Monetization - The evolution of API governance
PDF
apidays New York 2023 - Make API Governance work in your unified API Strategy...
PDF
Build, Test, Deploy: The Ultimate Handbook for Modern API Development
PDF
apidays LIVE Paris 2021 - Low-Code API DevOps approach to API Lifecycle Manag...
PDF
apidays Australia 2022 - API design challenges and making APIs your common la...
PDF
Mastering API Development: A Developer’s Roadmap for Success
PDF
The Future of API Management and the Impact of Platform Engineering - Kenn Hu...
PDF
Practical guide to building public APIs
PDF
apidays LIVE Australia 2020 - Building the right API team for right now by Cl...
PPTX
apidays LIVE Singapore 2021 - Re-imagining the investment workflow using APIs...
PPTX
INTERFACE by apidays_Recommendations for API Governance and an API Economy Ce...
PDF
apidays New York 2023 - Governance Doesn't Have to be a Dirty Word, Jason Har...
PPTX
API_Strategy_Architecture_Development.pptx
apidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoica
INTERFACE by apidays 2023 - API Design Governance, Nauman Ali, Stoplight
apidays Singapore 2025 - From API Intelligence to API Governance by Harsha Ch...
Approaching APIs
INTERFACE by apidays 2023 - Governance Doesn't Have to be a Dirty Word, Jason...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2's API Vision: Unifying Control, Empowering Developers
API Governance and Monetization - The evolution of API governance
apidays New York 2023 - Make API Governance work in your unified API Strategy...
Build, Test, Deploy: The Ultimate Handbook for Modern API Development
apidays LIVE Paris 2021 - Low-Code API DevOps approach to API Lifecycle Manag...
apidays Australia 2022 - API design challenges and making APIs your common la...
Mastering API Development: A Developer’s Roadmap for Success
The Future of API Management and the Impact of Platform Engineering - Kenn Hu...
Practical guide to building public APIs
apidays LIVE Australia 2020 - Building the right API team for right now by Cl...
apidays LIVE Singapore 2021 - Re-imagining the investment workflow using APIs...
INTERFACE by apidays_Recommendations for API Governance and an API Economy Ce...
apidays New York 2023 - Governance Doesn't Have to be a Dirty Word, Jason Har...
API_Strategy_Architecture_Development.pptx
Ad

Recently uploaded (20)

PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
KodekX | Application Modernization Development
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Electronic commerce courselecture one. Pdf
PDF
NewMind AI Monthly Chronicles - July 2025
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
Big Data Technologies - Introduction.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
Cloud computing and distributed systems.
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Encapsulation_ Review paper, used for researhc scholars
Mobile App Security Testing_ A Comprehensive Guide.pdf
Per capita expenditure prediction using model stacking based on satellite ima...
KodekX | Application Modernization Development
Spectral efficient network and resource selection model in 5G networks
20250228 LYD VKU AI Blended-Learning.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Network Security Unit 5.pdf for BCA BBA.
Reach Out and Touch Someone: Haptics and Empathic Computing
Electronic commerce courselecture one. Pdf
NewMind AI Monthly Chronicles - July 2025
Understanding_Digital_Forensics_Presentation.pptx
NewMind AI Weekly Chronicles - August'25 Week I
Big Data Technologies - Introduction.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Cloud computing and distributed systems.

5 Tips for Scaling API Governance

  • 1. Date: June 2020 Prepared by: John Phenix Chief API Architect, HSBC Commercial Bank Automating API Governance PUBLIC
  • 2. 1 1 HSBC - The World’s Leading International Bank 39million customers 3,900 offices 65 countries & territories Present in Reported Revenue $53.8bn 254PB of data Data Centres in 21 countries 96,600+ Servers $1.5 Trillion Daily payments processed 235,000 people around the world 46,000 IT Professionals $2.5bn Run / $3.3bn Change (cash) PUBLIC
  • 3. 2 Challenge PUBLIC How to make API governance an accelerator instead of a brake?
  • 4. 3 Apple’s iOS Standards and Governance platform produces a consistent, market leading App experience Why HSBC needs API Standards and Governance – an example from Apple PUBLIC
  • 5. 4 HSBC’s API Standards and Governance platform will produce a consistent, market leading API developer experience Why HSBC needs API Standards and Governance Governance PUBLIC Governance
  • 6. 5 Tip 1: What to Govern? PUBLIC Security Operations Reputation As little as possible!The minimum needed to deliver value and manage risks Tip 1: Focus governance on real risks rather than personal preferences
  • 7. 6 Comprehensive Tip 2: What does good look like? PUBLIC Scalable Consistent Evidenced Tip 2: Good governance scales to meet delivery cadence
  • 8. 7 Visibility Tip 3: Where to invest effort PUBLIC Tools Training Automation Tip 3: Shift left – make it easier to fall into success
  • 9. 8 Tip 4a: Pick your style - Centralised Small team(s) of API SMEs who manually review APIs. You can duplicate the ARB (API Review Board) in different geographies. Scalable Consistent Comprehensive Evidenced PUBLIC
  • 10. 9 Tip 4b: Pick your style - Federated API Champions from every region and major project to enforce standards locally and escalate non-compliance. Scalable Consistent Comprehensive Evidenced PUBLIC
  • 11. 10 Tip 4c: Pick your style - Automated Speed and safety at scale requires an automated approach. Scalable Consistent Comprehensive Evidenced PUBLIC
  • 12. 11 Tip 4c: Pick your style -– Hybrid Focus manual reviews on exceptions and qualitative analysis. Scalable Consistent Comprehensive Evidenced PUBLIC Tip 4: Move from “Are we building APIs right?” to “Are we building the right APIs?”
  • 13. 12 Tip 5: How to automate Audit Trail API Engineers Governance Engineers Batch Rules Setup CI/CD Pipeline CAGE UI Repository Rules Lead Architects Certification Dashboard CAGE PUBLIC
  • 14. 13 Peer Reviews Tip 5: How to automate PUBLIC Building APIs Right Building the Right APIs Training Tip 5: Automate as much as you can, but you still need people
  • 15. 14 5 Governance Tips Q1: What to govern Q2: What does good look like Q3: Where to invest effort Q4: How to pick your style Q5: How to automate PUBLIC Tip 1: Focus governance on real risks rather than personal preferences Tip 2: Good governance scales to meet delivery cadence Tip 3: Shift left – make it easier to fall into success Tip 4: Move from “Are we building APIs right?” to “Are we building the right APIs?” Tip 5: Automate as much as possible, but you still need people
  • 16. 15 Example Rules Security: • Sensitive info in query parameters • Standard headers • Security policies Operations: • Naming standard • Published to API Repository • Versioning • Check for duplicate APIs • Health endpoint Style: • camelCase, PascalCase and snake-case • Always return 2xx, 4xx and 5xx • Misuse of HTTP verbs • Plural nouns for resource collections • Example request and response schemas PUBLIC