SlideShare a Scribd company logo
1© 2018 Rogue Wave Software, Inc. All Rights Reserved.
PSD2 & Open Banking:
How to go from standards to
implementation and compliance
Olaf van Gorp
2© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Presenter
Olaf van Gorp
Technical Sales Europe - Akana
olaf.van.gorp@roguewave.com
3© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Agenda
• PSD2 and APIs
• Implementation standards
• Added value of API management
• Q & A
4© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Watch the on-demand webinar
5© 2018 Rogue Wave Software, Inc. All Rights Reserved.
PSD2 and APIs
6© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Third
party
provider
account
information
Third
party
provider
account
information
payment
initiation
Third
party
provider
payment initiation
Third
party
provider
account
information
Third
party
provider
payment
initiation
Third
party
provider
account
information
Third
party
provider
confirmation of
funds Third
party
provider
7© 2018 Rogue Wave Software, Inc. All Rights Reserved.
APIs!
(really..?)
8© 2018 Rogue Wave Software, Inc. All Rights Reserved.
PSD2? APIs?
9© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Understand PSD2…
…technical compliance.
10© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Verify request integrity
Strong customer authentication
Mutual authentication
Dynamic linking
Consumer authorization
11© 2018 Rogue Wave Software, Inc. All Rights Reserved.
PSD
2
APIs
!
PSD
2
APIs
!
12© 2018 Rogue Wave Software, Inc. All Rights Reserved.
A sample PSD2 component architecture
IAM: Identity and access management
APIM: API management
PSD2
APIM
IAM
Fraud
detection
Banking
system
13© 2018 Rogue Wave Software, Inc. All Rights Reserved.
What are APIs and API management?
APIs
Expose a business
capability to
designated
consumers in a
secure and controlled
manner.
API
management
Gives you control
over the API across
it’s entire lifecycle,
from design to
deployment to
operational health.
API management
solutions
Provide the
capabilities to
address and
automate your API
management
requirements.
14© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Sample API architecture
15© 2018 Rogue Wave Software, Inc. All Rights Reserved.
In addition, take care of ‘implicit’ API requirements
Summary: Benefits of an APIM solution for
PSD2
Delegate PSD2 API requirements
Decouple published API from downstream landscape
Offer flexibility re. published API
• In particular: API security, authorization
• Rate limiting, consumer management, API lifecycle management, etc.
• Interoperability, different target consumers, etc.
16© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Watch the on-demand webinar
17© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Implementation standards
18© 2018 Rogue Wave Software, Inc. All Rights Reserved.
PSD2 / OB standards
• Regulatory Technical Standards (RTS)
on strong customer authentication
and secure communication
• UK Open Banking (with PSD2 additions)
• Berlin Group
• STET
• Polish API (and others)
19© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Standards comparison
• UK Open Banking (≠ PSD2):
– Fully open standards-based
(OAuth2.0, OIDC, PKI, JWT, etc.)
– Swagger docs published
• Berlin Group:
– Standards like OAuth2.0 optional rather than preferred
– Deviation and divergence
• E.g. OAuth scopes, signing HTTP messages, ..
20© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Standards divergence
• Deviations force customization
• Interoperability consequences?
– …across ‘standards’?
21© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Multiple initiatives (that may not be compatible)
Summary: Standards
Indispensable for effective technical implementation, yet..
Not yet complete
‘Exotic’ elements may force customization
Interoperability concerns
22© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Added value of
API management
23© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Sample PSD2 portal
24© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Import PSD2 specified API
25© 2018 Rogue Wave Software, Inc. All Rights Reserved.
PSD2 requirements: API security
• Certificate-based client authentication
• OAuth2.0 (as one way to deal with authorization)
Policies
- configurable
- reusable
- versioned
26© 2018 Rogue Wave Software, Inc. All Rights Reserved.
API best practice: rate limiting
• Limit the number of requests
• Protect your downstream systems (request overload)
27© 2018 Rogue Wave Software, Inc. All Rights Reserved.
API best practice: API lifecycle management
• API development lifecycle
– E.g. dev, test, QA, prod
• API consumption lifecycle
– Accepted, rejected, suspended, revoked
• API versioning
– Notification, parallel versions
28© 2018 Rogue Wave Software, Inc. All Rights Reserved.
API best practice: API analytics
• Does my API provide the
expected business value?
• What consumption trends do
I see?
• Do my APIs function as
expected?
29© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Non-mandatory APIs
• Open banking as a business opportunity…
• …offering a much wider range of services…
• …that will make your bank stand out.
30© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Allow for effective consumer on-boarding and management
Summary
Help you with the technical implementation of your
PSD2 API-based interface
Provide you with a flexible/adaptable solution
Ensure effective management of your APIs
Offer great possibilities to offer additional functionality (opening up further
business opportunities)
An APIM solution is indispensable for an effective implementation of the
PSD2 interface. It will:
31© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Q & A
32© 2018 Rogue Wave Software, Inc. All Rights Reserved.
Next steps:
Learn more in our blog series on PSD2 &
Open Banking at:
blog.akana.com
Watch the full webinar
on-demand.
33© 2018 Rogue Wave Software, Inc. All Rights Reserved.

More Related Content

PPTX
PSD2: Open Banking with APIs
PDF
PSD2 - An Open Banking Revolution
PPTX
APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...
PDF
PSD2 & Open Banking
PPTX
Psd2 challenges
PPTX
PSD2: Implementing APIs that interoperate with ISO 20022
PPTX
APIdays Singapore 2019 - Introduction to essential elements of Open Banking F...
PDF
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...
PSD2: Open Banking with APIs
PSD2 - An Open Banking Revolution
APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...
PSD2 & Open Banking
Psd2 challenges
PSD2: Implementing APIs that interoperate with ISO 20022
APIdays Singapore 2019 - Introduction to essential elements of Open Banking F...
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...

What's hot (19)

PDF
Psd2 in a nutshell
PDF
APIdays Singapore 2019 - Open Banking is Here to Stay: How Will You Benefit f...
PPTX
Webinar: Technology Insights - PSD2
PDF
[Workshop] Business Benefits and Digital Transformation through Open Banking
PPTX
APIdays Singapore 2019 - Promoting Financial Inclusion with an Open Banking M...
PDF
Holos psd2 open-api
PPTX
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
PPTX
Open Banking APIs with case studies for senior stakeholders
PPTX
Open banking-Future of Banking
PPTX
APIdays Singapore 2019 - Securing Value in API Ecosystems, Ajay Biyani, Head ...
PDF
WSO2 Open Banking: Digital Transformation Through PSD2
PDF
PSD2: Making it actionable
PDF
Open Banking: Lessons from the UK #fapisum - Japan/UK Open Banking and APIs S...
PPTX
2017 Feb 3rd Malta - NPF2017 - APIs in context of PSD2
PPTX
Open Banking - Opening the door to Digital Transformation
PDF
What’s new in WSO2 Open Banking
PDF
Banking is Now More Open: Open Banking Update
PDF
OpenID Foundation/Open Banking Workshop - Open Banking Update
PPTX
Idc finansal 2017 open banking
Psd2 in a nutshell
APIdays Singapore 2019 - Open Banking is Here to Stay: How Will You Benefit f...
Webinar: Technology Insights - PSD2
[Workshop] Business Benefits and Digital Transformation through Open Banking
APIdays Singapore 2019 - Promoting Financial Inclusion with an Open Banking M...
Holos psd2 open-api
Webinar materials | PSD2: Ensuring a seamless payments journey - connecting A...
Open Banking APIs with case studies for senior stakeholders
Open banking-Future of Banking
APIdays Singapore 2019 - Securing Value in API Ecosystems, Ajay Biyani, Head ...
WSO2 Open Banking: Digital Transformation Through PSD2
PSD2: Making it actionable
Open Banking: Lessons from the UK #fapisum - Japan/UK Open Banking and APIs S...
2017 Feb 3rd Malta - NPF2017 - APIs in context of PSD2
Open Banking - Opening the door to Digital Transformation
What’s new in WSO2 Open Banking
Banking is Now More Open: Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking Update
Idc finansal 2017 open banking
Ad

Similar to PSD2 & Open Banking: How to go from standards to implementation and compliance (20)

PPTX
Getting the most from your API management platform: A case study
PPTX
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
PDF
Disrupt or be disrupted – Using secure APIs to drive digital transformation
PDF
91APP API Gateway 導入之旅
PDF
[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...
PDF
ForgeRock Open banking - Meetup 28/06/2018
PDF
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
PDF
[Workshop] Managing the API lifecycle with Open Source Technologies
PDF
apidays LIVE New York 2021 - 5 Pragmatic steps to unlock Open Finance with AP...
PDF
INTERFACE by apidays - API Success: Running a Successful API Program by Nelso...
PDF
API Gateway How-To: The Many Ways to Apply the Gateway Pattern
PDF
Monitor and Measure Your Way to Successful Digital Transformation
PDF
WSO2 User Group Bangalore Meetup
PDF
Fintech Primitives - Wealth Management - MF Pro - Distributor
PPTX
API Management - Practical Enterprise Implementation Experience
PDF
BATBern46_Syncier Marketplace.pdf
PDF
INTERFACE, by apidays - From Monolith to Open Finance with APIs by Marcilio ...
PDF
apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat, Lombar...
PDF
API Management within a Microservice Architecture
PPTX
API Management Within a Microservices Architecture
Getting the most from your API management platform: A case study
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
Disrupt or be disrupted – Using secure APIs to drive digital transformation
91APP API Gateway 導入之旅
[WSO2 Summit Sydney 2019] Building a Successful API Strategy from Scratch and...
ForgeRock Open banking - Meetup 28/06/2018
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
[Workshop] Managing the API lifecycle with Open Source Technologies
apidays LIVE New York 2021 - 5 Pragmatic steps to unlock Open Finance with AP...
INTERFACE by apidays - API Success: Running a Successful API Program by Nelso...
API Gateway How-To: The Many Ways to Apply the Gateway Pattern
Monitor and Measure Your Way to Successful Digital Transformation
WSO2 User Group Bangalore Meetup
Fintech Primitives - Wealth Management - MF Pro - Distributor
API Management - Practical Enterprise Implementation Experience
BATBern46_Syncier Marketplace.pdf
INTERFACE, by apidays - From Monolith to Open Finance with APIs by Marcilio ...
apidays London 2023 - API Metrics matters in APIOps, Ludovic Pourrat, Lombar...
API Management within a Microservice Architecture
API Management Within a Microservices Architecture
Ad

More from Rogue Wave Software (20)

PPTX
The Global Influence of Open Banking, API Security, and an Open Data Perspective
PPTX
No liftoff, touchdown, or heartbeat shall miss because of a software failure
PPTX
Leveraging open banking specifications for rigorous API security – What’s in...
PPTX
Adding layers of security to an API in real-time
PPTX
Advanced technologies and techniques for debugging HPC applications
PPTX
The forgotten route: Making Apache Camel work for you
PPTX
Are open source and embedded software development on a collision course?
PDF
Three big mistakes with APIs and microservices
PPTX
5 strategies for enterprise cloud infrastructure success
PPTX
Java 10 and beyond: Keeping up with the language and planning for the future
PPTX
How to keep developers happy and lawyers calm (Presented at ESC Boston)
PPTX
Open source applied - Real world use cases (Presented at Open Source 101)
PPTX
How to migrate SourcePro apps from Solaris to Linux
PPTX
Approaches to debugging mixed-language HPC apps
PPTX
Enterprise Linux: Justify your migration from Red Hat to CentOS
PPTX
Walk through an enterprise Linux migration
PPTX
How to keep developers happy and lawyers calm
PPTX
Open source and embedded software development
PDF
Open source software: The infrastructure impact
PPTX
Plan a successful enterprise Linux migration
The Global Influence of Open Banking, API Security, and an Open Data Perspective
No liftoff, touchdown, or heartbeat shall miss because of a software failure
Leveraging open banking specifications for rigorous API security – What’s in...
Adding layers of security to an API in real-time
Advanced technologies and techniques for debugging HPC applications
The forgotten route: Making Apache Camel work for you
Are open source and embedded software development on a collision course?
Three big mistakes with APIs and microservices
5 strategies for enterprise cloud infrastructure success
Java 10 and beyond: Keeping up with the language and planning for the future
How to keep developers happy and lawyers calm (Presented at ESC Boston)
Open source applied - Real world use cases (Presented at Open Source 101)
How to migrate SourcePro apps from Solaris to Linux
Approaches to debugging mixed-language HPC apps
Enterprise Linux: Justify your migration from Red Hat to CentOS
Walk through an enterprise Linux migration
How to keep developers happy and lawyers calm
Open source and embedded software development
Open source software: The infrastructure impact
Plan a successful enterprise Linux migration

Recently uploaded (20)

PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PPTX
ai tools demonstartion for schools and inter college
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Nekopoi APK 2025 free lastest update
PPTX
history of c programming in notes for students .pptx
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PPTX
Operating system designcfffgfgggggggvggggggggg
PDF
AI in Product Development-omnex systems
PPTX
Reimagine Home Health with the Power of Agentic AI​
PPTX
Essential Infomation Tech presentation.pptx
PDF
Understanding Forklifts - TECH EHS Solution
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PPTX
L1 - Introduction to python Backend.pptx
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
ai tools demonstartion for schools and inter college
Wondershare Filmora 15 Crack With Activation Key [2025
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Nekopoi APK 2025 free lastest update
history of c programming in notes for students .pptx
Odoo Companies in India – Driving Business Transformation.pdf
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
2025 Textile ERP Trends: SAP, Odoo & Oracle
VVF-Customer-Presentation2025-Ver1.9.pptx
Design an Analysis of Algorithms II-SECS-1021-03
Operating system designcfffgfgggggggvggggggggg
AI in Product Development-omnex systems
Reimagine Home Health with the Power of Agentic AI​
Essential Infomation Tech presentation.pptx
Understanding Forklifts - TECH EHS Solution
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
L1 - Introduction to python Backend.pptx

PSD2 & Open Banking: How to go from standards to implementation and compliance

  • 1. 1© 2018 Rogue Wave Software, Inc. All Rights Reserved. PSD2 & Open Banking: How to go from standards to implementation and compliance Olaf van Gorp
  • 2. 2© 2018 Rogue Wave Software, Inc. All Rights Reserved. Presenter Olaf van Gorp Technical Sales Europe - Akana olaf.van.gorp@roguewave.com
  • 3. 3© 2018 Rogue Wave Software, Inc. All Rights Reserved. Agenda • PSD2 and APIs • Implementation standards • Added value of API management • Q & A
  • 4. 4© 2018 Rogue Wave Software, Inc. All Rights Reserved. Watch the on-demand webinar
  • 5. 5© 2018 Rogue Wave Software, Inc. All Rights Reserved. PSD2 and APIs
  • 6. 6© 2018 Rogue Wave Software, Inc. All Rights Reserved. Third party provider account information Third party provider account information payment initiation Third party provider payment initiation Third party provider account information Third party provider payment initiation Third party provider account information Third party provider confirmation of funds Third party provider
  • 7. 7© 2018 Rogue Wave Software, Inc. All Rights Reserved. APIs! (really..?)
  • 8. 8© 2018 Rogue Wave Software, Inc. All Rights Reserved. PSD2? APIs?
  • 9. 9© 2018 Rogue Wave Software, Inc. All Rights Reserved. Understand PSD2… …technical compliance.
  • 10. 10© 2018 Rogue Wave Software, Inc. All Rights Reserved. Verify request integrity Strong customer authentication Mutual authentication Dynamic linking Consumer authorization
  • 11. 11© 2018 Rogue Wave Software, Inc. All Rights Reserved. PSD 2 APIs ! PSD 2 APIs !
  • 12. 12© 2018 Rogue Wave Software, Inc. All Rights Reserved. A sample PSD2 component architecture IAM: Identity and access management APIM: API management PSD2 APIM IAM Fraud detection Banking system
  • 13. 13© 2018 Rogue Wave Software, Inc. All Rights Reserved. What are APIs and API management? APIs Expose a business capability to designated consumers in a secure and controlled manner. API management Gives you control over the API across it’s entire lifecycle, from design to deployment to operational health. API management solutions Provide the capabilities to address and automate your API management requirements.
  • 14. 14© 2018 Rogue Wave Software, Inc. All Rights Reserved. Sample API architecture
  • 15. 15© 2018 Rogue Wave Software, Inc. All Rights Reserved. In addition, take care of ‘implicit’ API requirements Summary: Benefits of an APIM solution for PSD2 Delegate PSD2 API requirements Decouple published API from downstream landscape Offer flexibility re. published API • In particular: API security, authorization • Rate limiting, consumer management, API lifecycle management, etc. • Interoperability, different target consumers, etc.
  • 16. 16© 2018 Rogue Wave Software, Inc. All Rights Reserved. Watch the on-demand webinar
  • 17. 17© 2018 Rogue Wave Software, Inc. All Rights Reserved. Implementation standards
  • 18. 18© 2018 Rogue Wave Software, Inc. All Rights Reserved. PSD2 / OB standards • Regulatory Technical Standards (RTS) on strong customer authentication and secure communication • UK Open Banking (with PSD2 additions) • Berlin Group • STET • Polish API (and others)
  • 19. 19© 2018 Rogue Wave Software, Inc. All Rights Reserved. Standards comparison • UK Open Banking (≠ PSD2): – Fully open standards-based (OAuth2.0, OIDC, PKI, JWT, etc.) – Swagger docs published • Berlin Group: – Standards like OAuth2.0 optional rather than preferred – Deviation and divergence • E.g. OAuth scopes, signing HTTP messages, ..
  • 20. 20© 2018 Rogue Wave Software, Inc. All Rights Reserved. Standards divergence • Deviations force customization • Interoperability consequences? – …across ‘standards’?
  • 21. 21© 2018 Rogue Wave Software, Inc. All Rights Reserved. Multiple initiatives (that may not be compatible) Summary: Standards Indispensable for effective technical implementation, yet.. Not yet complete ‘Exotic’ elements may force customization Interoperability concerns
  • 22. 22© 2018 Rogue Wave Software, Inc. All Rights Reserved. Added value of API management
  • 23. 23© 2018 Rogue Wave Software, Inc. All Rights Reserved. Sample PSD2 portal
  • 24. 24© 2018 Rogue Wave Software, Inc. All Rights Reserved. Import PSD2 specified API
  • 25. 25© 2018 Rogue Wave Software, Inc. All Rights Reserved. PSD2 requirements: API security • Certificate-based client authentication • OAuth2.0 (as one way to deal with authorization) Policies - configurable - reusable - versioned
  • 26. 26© 2018 Rogue Wave Software, Inc. All Rights Reserved. API best practice: rate limiting • Limit the number of requests • Protect your downstream systems (request overload)
  • 27. 27© 2018 Rogue Wave Software, Inc. All Rights Reserved. API best practice: API lifecycle management • API development lifecycle – E.g. dev, test, QA, prod • API consumption lifecycle – Accepted, rejected, suspended, revoked • API versioning – Notification, parallel versions
  • 28. 28© 2018 Rogue Wave Software, Inc. All Rights Reserved. API best practice: API analytics • Does my API provide the expected business value? • What consumption trends do I see? • Do my APIs function as expected?
  • 29. 29© 2018 Rogue Wave Software, Inc. All Rights Reserved. Non-mandatory APIs • Open banking as a business opportunity… • …offering a much wider range of services… • …that will make your bank stand out.
  • 30. 30© 2018 Rogue Wave Software, Inc. All Rights Reserved. Allow for effective consumer on-boarding and management Summary Help you with the technical implementation of your PSD2 API-based interface Provide you with a flexible/adaptable solution Ensure effective management of your APIs Offer great possibilities to offer additional functionality (opening up further business opportunities) An APIM solution is indispensable for an effective implementation of the PSD2 interface. It will:
  • 31. 31© 2018 Rogue Wave Software, Inc. All Rights Reserved. Q & A
  • 32. 32© 2018 Rogue Wave Software, Inc. All Rights Reserved. Next steps: Learn more in our blog series on PSD2 & Open Banking at: blog.akana.com Watch the full webinar on-demand.
  • 33. 33© 2018 Rogue Wave Software, Inc. All Rights Reserved.