Open Banking Security
Open Banking Implementation Entity security profile
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (9)
Data Minimisation and Localisation
| Code | Title |
|---|---|
| OPENBANK-5 | Data Minimisation, Scope Enforcement, Localisation, Cross-Border Transfers |
FAPI 2.0 Conformance
| Code | Title |
|---|---|
| OPENBANK-1 | FAPI 2.0 Security Profile and OpenID Foundation Conformance |
Fraud + TRA + Rate Limiting + Sandbox
| Code | Title |
|---|---|
| OPENBANK-6 | Fraud Detection, Transaction Risk Analysis, Rate Limiting, Sandbox |
Incident + BCM
| Code | Title |
|---|---|
| OPENBANK-8 | Incident Detection, Response, Customer Notification, Post-Incident Review, BCM |
Logging + Reporting + SLA
| Code | Title |
|---|---|
| OPENBANK-7 | Logging, Monitoring, Regulatory Reporting, SLA, Availability |
Open Banking Security: Information Security Governance
IT governance for financial institutions (Open Banking Security)
SCA + Consent + UX
| Code | Title |
|---|---|
| OPENBANK-2 | Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX |
TPP Onboarding
| Code | Title |
|---|---|
| OPENBANK-4 | Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence |
mTLS + Signing + Keys
| Code | Title |
|---|---|
| OPENBANK-3 | Mutual TLS, Token Binding, Request Signing (JWS), Key Management |
Your Compliance Coverage
If you comply with Open Banking Security, you already cover:
NIST Cybersecurity Framework 2.0
63%
5 controls mapped
Compare →APRA CPS 234
63%
5 controls mapped
Compare →FFIEC IT Examination Handbook
63%
5 controls mapped
Compare →+ 155 more: NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (63%), Annex 11 to EU GMP - Computerised Systems (63%)
See all 158 mapped frameworks ↓Maps to 158 other frameworks
Frequently Asked Questions
What is Open Banking Security?
Open Banking Security is a compliance framework from United Kingdom with 9 domains and 8 controls. Open Banking Implementation Entity security profile It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Open Banking Security have?
Open Banking Security has 8 controls organised across 9 domains. The largest domains are Data Minimisation and Localisation (1 controls), FAPI 2.0 Conformance (1 controls), Fraud + TRA + Rate Limiting + Sandbox (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Open Banking Security map to?
Open Banking Security maps to 158 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (63% coverage), APRA CPS 234 (63% coverage), FFIEC IT Examination Handbook (63% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Open Banking Security compliance?
Start your Open Banking Security compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Open Banking Security requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required