Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Banking > What the admonishment of Barclays/Lloyds means for Open Banking APIs
    Banking

    What the admonishment of Barclays/Lloyds means for Open Banking APIs

    What the admonishment of Barclays/Lloyds means for Open Banking APIs

    Published by Jessica Weisman-Pitts

    Posted on May 19, 2022

    Featured image for article about Banking

    By Shreyans Mehta, CTO, at Cequence Security

    One of the promises of Open Banking was that it would level the playing field, making it possible for new entrants to compete with the banking behemoths but for that to happen there needs to be transparency. Any inaccurate information can skew the market and potentially disadvantage those that rely on that information to compete. So the news that the Competition and Markets Authority (CMA) recently reprimanded both Barclays and Lloyds for breaching the open banking provisions of the Retail Banking Market Investigation Order was significant.

    Open Banking relies upon APIs (Application Programming Interfaces) to share data between banks, fintechs and trusted third parties (TTPs) to create a thriving digital ecosystem but it’s down to the banks to ensure those APIs are kept up to date. In the case of Barclays, it failed to do this thirteen times between November 2018 and August 2021, by not disclosing correct fees, interest rates and failing to list 47 ATMs, among other infractions. Lloyds similarly provided incorrect information ten times from March 2017 to August 2021, from failing to update credit card interest rates and cash withdrawal charges to broken links within the APIs to the terms and conditions of three of its bank account products.

    Suitably chastened, both banks elected to take steps to try to prevent these issues recurring. Barclays opted to introduce manual controls, staff training and a process to update APIs in line with any changes to its service literature while Lloyds committed to more frequent, periodic checks, training and guidance, and asserted it will be moving towards an automated solution. But does the fact these issues occurred in the first place cast some doubt over the way that Open Banking APIs are managed? Are manual checks sufficient to stop it happening again? And what lessons does this hold for the industry as it becomes more dependent on APIs and moves towards Variable Recurring Payments (VRPs)?

    A work in progress

    Open Banking APIs adhere to regulations laid down in the European Union’s Payment Services Directive 2 (PSD2) which is mirrored in the Open Banking Regulation in the UK but it’s very much an evolving set of regulations. In June 2020, the European Banking Authority (EBA) took steps to ensure that the customer experience via the API was comparable with that the banks gave to their online customers. It gave national regulators the power to impose fines if access was hindered and it’s those fines which Barclays and Lloyds could have been hit with.

    We also saw the EBA Working Group still thrashing out PSD2 just six months ago, with issues ranging from the lack of notification of downtime to TTPs, lack of support for embedded redirection, and the inability to conduct batch processing via APIs, listed among those items for discussion.

    While the regulators are doing their utmost to both encourage and enforce the principles of Open Banking, the banks also have to play their part. What the above examples show us is that these organisations aren’t always aware of or in control of their APIs. Creating an inventory of active APIs is key to tracking and managing them effectively. This will allow the financial provider to assign ownership and determine the business function but it also allows APIs to be assessed for misconfigurations, coding errors or potential vulnerabilities and flagged for remediation. Are the APIs exposing sensitive data, do they have weak or poorly implemented authentication, are they in conformance with an OpenAPI specification? Moving towards a model of automated continuous monitoring is the only way to test APIs effectively to ensure the specifications are being observed and that data is adequately protected.

    Future focus

    Open Banking is the future but it is contingent upon how effectively APIs are managed and protected. The ecosystem which is just starting to become established will see banks able to partner with third parties to expedite loan applications, for example, or to monitor user behaviours and market trends to spot opportunities or even stamp out fraud. A key benefit of APIs is the visibility they confer, allowing the provider to spot anomalous activity, with APIs with push notifications able to alert the account holder and suspend activity.

    APIs will also be crucial in the future rollout of Variable Recurring Payments (VRPs). These are expected to replace direct debits and allow consumers to ‘sweep’ or transfer payments between user accounts and, longer term, between the user and businesses. We can expect banks to commercialise their VRPs with TTPs, by setting up payment arrangements with ecommerce outlets or subscriptions, but for this to happen, banks will need to set up ledgers and have APIs that can be monitored, protected and updated in real-time.

    It’s this real-time responsiveness that will determine the winners and the losers in the era of Open Banking. Being able to align or update services automatically and to protect API data will be crucial in determining which financial institutions are agile enough to thrive. Yet, for that to happen, the sector will need to start thinking about the complete API lifecycle, from establishing an inventory that maps to risk and compliance demands, to attack detection/prevention, to baking in security during API development.

    Related Posts
    CIBC wins two Global Banking and Finance Awards for student banking
    CIBC wins two Global Banking and Finance Awards for student banking
    DeFi and banking are converging. Here’s what banks can do.
    DeFi and banking are converging. Here’s what banks can do.
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Are Neo Banks Offering Better Metal Debit Cards Than Traditional Banks?
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Banking at the Intersection: From Nashville to Cannes, A Strategic Call to Action
    Driving Efficiency and Profit Through Customer-Centric Banking
    Driving Efficiency and Profit Through Customer-Centric Banking
    How Ecosystem Partnerships Are Redefining Deposit Products
    How Ecosystem Partnerships Are Redefining Deposit Products
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    CIBC Private Banking wins four 2025 Global Banking & Finance Awards
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    How Banks Can Put AI to Work Now and Prove ROI in 90 Days
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    Top 5 AI quality assurance framework providers for Banks and Financial Services firms.
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    The Unbanked Paradox: How Banking Access Creates Economic Resilience
    Hyper-Personalised Banking - Shaping the Future of Finance
    Hyper-Personalised Banking - Shaping the Future of Finance
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication
    The End of Voice Trust: How AI Deepfakes Are Forcing Banks to Rethink Authentication

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Banking PostRate of bank loan defaults set to rise across the eurozone, while growth in lending slows from the pandemic peak
    Next Banking PostEgypt’s central bank, citing inflation, hikes interest rates 200 bps

    More from Banking

    Explore more articles in the Banking category

    Predicting and Preventing Customer Churn in Retail Banking

    Predicting and Preventing Customer Churn in Retail Banking

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Growth and Impact: Banreservas Leads Dominican Republic Economic Expansion

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    Turning Insight into Impact: Making AI and Analytics Work in Retail Banking

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    KeyBank Embraces Next-Generation AI Platform to Transform Fraud and Financial Crime Prevention

    Understanding Association Banking: Financial Solutions for Community Success

    Understanding Association Banking: Financial Solutions for Community Success

    Applying Symbiosis for advantage in APAC banking

    Applying Symbiosis for advantage in APAC banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    AmBank Islamic Berhad Earns Triple Recognition for Excellence in Islamic Banking

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    FinTok Strategy: How Banks Are Reaching Gen Z Through Social Media

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    Rethinking Retail Banking Sustainability: Why the ATM is an Asset in the Sustainable Transition

    How private banks can survive the neo-broker revolution

    How private banks can survive the neo-broker revolution

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    Next-Gen Bank Branches: The Evolution from Transaction Hubs to Experience Centers

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    The Banking Talent Crunch: How Financial Institutions Are Competing for Digital-Native Skills

    View All Banking Posts