What does SAMA's Open Banking Framework require of banks?
Exposing customer-permissioned account data, and in later phases payment initiation, to providers permitted by SAMA through standardised secure APIs. That entails a consent journey, a security profile providers can authenticate against, availability and performance obligations, and auditable records of every data-sharing event. Requirements have been released in phases, so confirm current SAMA publications before design.
What is the difference between AIS and PIS?
Account Information Services let a third party read customer data with consent — balances, transactions, account details. Payment Initiation Services let a third party start a payment from the customer's account. AIS is read-only and lower risk; PIS moves money and carries stronger authentication, fraud and liability implications.
What security does an open banking API require?
A financial-grade profile rather than ordinary API security: OAuth 2.0 with PKCE, FAPI conformance, mutual TLS for client authentication, signed and where required encrypted payloads, certificate validation against the approved authority, and full audit logging of access and consent events.
Should we build the platform or buy a vendor product?
Vendor platforms deliver compliance faster and suit banks whose objective is meeting the obligation. Building suits banks intending to compete on developer experience and partner ecosystem. Many buy the compliance layer and build the differentiating layer above it — that hybrid is the most common landing point.
How does consent management actually work?
The customer authenticates with the bank, sees exactly what is being requested and for how long, and approves or declines. That consent is then stored, enforced on every subsequent call, visible in the banking app, revocable at any time and expired automatically. It is the most underestimated part, because it spans the API, the app and the contact centre.
How long does an open banking platform take?
Account information APIs with consent management and a developer sandbox typically take 16 to 24 weeks. Payment initiation adds meaningfully because of stronger authentication, fraud controls and reconciliation. Timelines depend heavily on how reachable the core banking system is.