Getting Prepared with Banking Open API Phase III & IV with beNovelty
What are Open APIs?
Over recent years, Open APIs have been applied by companies in different industry sectors to expand their core businesses and develop ecosystems that enable relevant, interconnected and intelligent customer experiences. For example, travel agency websites have leveraged Open APIs to access data from hotels and airlines in order to provide real-time booking and ticketing services.
* Contents on this page are extracted from “The Next Phase of the Banking Open API Journey” by HKMA, 2021
The four-phased approach of the Open API Framework in Hong Kong
I. Product and service information
“Read-only” information offered by banks, providing details of their products and services.
II. Subscriptions and new applications for products/services
Customer acquisition processes, such as online submissions/applications for credit cards, loans, or other bank products.
III. Account information
Retrieval and alteration (where applicable) of the account information of authenticated customers, e.g. account balances, transactions (balances, transaction history, etc.), for stand-alone or aggregated viewing.
IV. Transactions
Banking transactions and payments or scheduled payments/transfers initiated by authenticated customers.
Implementation Status of Banking Open APIs in Hong Kong
Since the issuance of the Open API Framework in July 2018, retail banks in Hong Kong have made encouraging progress in building capabilities to adopt banking Open APIs in the areas of strategy, organisation structure and API infrastructure.
of surveyed banks have already defined, or are planning to define, a banking Open API strategy
of surveyed banks have set up, or plan to set up a central team to develop a bank-wide strategy for banking Open API development
of surveyed banks have developed a banking Open API infrastructure
of the surveyed banks have allocated a budget for banking Open API development or have already invested in various Open API initiatives
Benefits of implementing Banking Open APIs
Banking Open APIs give TSPs the opportunity to innovate and design solutions to meet customers’ digital needs, while banks can leverage TSPs’ capabilities to improve customer experiences.
New revenue streams from new products and services
Customer satisfaction and retention
New collaboration opportunities with TSPs
Innovation facilitation
Acceleration of digital technology adoption
Personalisation of existing products/services
Cost saving and efficiency
Essential practices for Phase III and IV implementation
Monitoring and reviews of risk management frameworks need to be regularly conducted to protect against risks associated with cybersecurity, system resilience, data privacy, liability, and fraud and money laundering.
To mitigate risks, protection measures need to be in place to address key areas of data protection and retention, customer consent, disclosure and transparency, liability, complaint and redress handling.
Designing customer-centric propositions, fostering trust towards TSPs, and educating customers are essential both for satisfying market needs and driving adoption of banking Open APIs.
A federated operating model, a robust core system and technical enablers (e.g. API portals) are key capabilities to facilitate implementation.
Depending on the nature of their business, TSPs will need to have a well-defined operating model, strong data management, and information security capabilities.
Banks and TSPs should develop a suitable monetisation strategy, which includes a range of direct and indirect monetisation models, according to the use cases to be implemented.
Monitoring mechanisms for fraud monitoring, API availability and performance monitoring are crucial to building trust and transparency among ecosystem participants and ensuring reliable banking Open API operations.