Security Challenges in Open Banking: A Systematic Review and Conceptualisation of a Tri-Dimensional Security Framework
Abstract
1. Introduction
2. Open Banking Concept
2.1. APIs and Their Role in Open Banking

2.2. Open Banking Core Security
2.3. Geographic Adoption and Regulatory Frameworks
3. Methodology
- Pre-regulatory foundation phase (1999–2014): Research on online banking security, API development, digital trust, and early FinTech integration.
- Regulatory emergence phase (2015–2018): Formalisation of OB frameworks and introduction of mandatory data sharing under regulatory supervision.
- Post-implementation expansion phase (2019–2025): Ecosystem consolidation, third-party provider integration, platform governance challenges, and advanced security concerns.
3.1. Inclusion and Exclusion Criteria
3.2. Data Sources and Search Strategies
3.3. Regulatory Policy Sources
3.4. Data Collection Process
- Technical security measures (APIs, encryption, authentication protocols)
- Regulatory compliance indicators (PSD2, GDPR, regional guidelines)
- Behavioural outcomes (trust, security decision-making, adoption behaviour)
3.5. Data Synthesis
4. Empirical Literature of the OB Framework
4.1. Studies on API and FinTech Technologies
| Author(s) | Title/Journal | Key Domain | Research Contributions |
|---|---|---|---|
| [27] | An extensive formal security analysis of the openid financial-grade API./IEEE symposium on security and privacy | Security and API protocols | Performs formal security analysis of fAPI, identifies vulnerabilities in authentication flows, and proposes strengthened security mechanisms for open banking APIs. |
| [18] | Security analysis of the open banking account and transaction API protocol./Cyber security and applications | Security and API standards | Analyzes transaction and account API protocols; identifies potential security threats and recommends technical improvements for secure data sharing. |
| [93] | Open banking: emergent roles, risks & opportunities./Ecis 2018 proceedings | Ecosystem and strategic implications | Explores emergent roles in open banking ecosystem; discusses risks (data privacy, security) and opportunities (innovation, competition) for banks and FinTechs. |
| [94] | Predicting the intention to use the investment aggregate functionality in the context of open banking using ann./Procedia computer science | Consumer behaviour and technology | Uses artificial neural networks to predict consumer intention to adopt investment aggregation features; highlights factors driving adoption in open banking apps. |
| [34] | The open banking era: an optimal model for the emergency fund./Expert systems with applications | Financial modelling/open banking applications | Proposes an optimization model for emergency fund management in the open banking era; demonstrates how open banking APIs can improve fund allocation and household financial resilience. |
| [38] | FinTech./Business & information systems engineering | FinTech and open banking foundations | Provides one of the earliest comprehensive analyses of FinTech, highlighting the foundations and evolution of digital finance, including the emergence of open banking ecosystems. |
| [41] | Blockchain-based identity management and access control framework for open banking ecosystem./Future generation computer systems | Security and identity management | Proposes a blockchain-enabled framework for identity management and access control in open banking ecosystems; enhances privacy, authentication, and security. |
4.2. Studies on Regulatory Policy and Market Analysis
| Author(s) | Title/Journal | Key Domain | Research Contributions |
|---|---|---|---|
| [12] | Customer data access and FinTech entry: early evidence from open banking./Journal of financial economics | Regulation and market entry | Provides global evidence from 168 countries on how customer data access regulations affect FinTech entry; shows that open banking policies significantly increase competition, promote innovation, and support consumer choice, but with regional variations. |
| [97] | The many shades of open banking: a comparative analysis of rationales and models./Internet policy review | Comparative regulation and models | Compares open banking rationales across countries; identifies different implementation models (mandatory, voluntary, hybrid) and their policy implications. |
| [19] | Open banking: credit market competition when borrowers own the data./Journal of financial economics | Market competition and data ownership | Investigates the impact of customer data ownership on credit markets; finds that open banking enhances competition and credit allocation efficiency. |
| [96] | Regulatory standards and consequences for industry architecture: the case of UK open banking./Research policy | Regulation and industry structure | Analyses how UK open banking standards reshape banking industry architecture; shows implications for bank–FinTech collaboration and market dynamics. |
| [99] | Open banking: a bibliometric analysis-driven definition./Plos one | Literature mapping and conceptualisation | Provides a bibliometric analysis of open banking literature; proposes a structured definition and identifies emerging research trends and gaps. |
| [98] | Open banking goes to Washington: lessons from the EU on regulatory-driven data sharing regimes./Computer law & security review | Regulation and comparative policy | Explores lessons from EU open banking regulation for US policy; highlights regulatory-driven data sharing benefits and challenges in cross-jurisdiction adoption. |
| [100] | The impact of open banking on traditional lending in the BRICS./Finance research letters | Open banking and credit markets | Analyses how open banking influences lending in BRICS economies; finds that data sharing enhances credit availability and reduces information asymmetry for borrowers. |
| [84] | What drives deregulation? economics and politics of the relaxation of bank branching restrictions./Quarterly journal of economics | Political economy of financial regulation | Uses hazard models to analyse state-level bank deregulation in the USA; finds that private interest group dynamics (large vs. small banks, competing industries) explain deregulation timing better than public interest or political-institutional models. |
4.3. A Tri-Dimensional Framework for Open Banking
- Behavioural dynamics → adoption outcomes → technological control deployment.
- Regulatory policies → platform design constraints → user trust and compliance behaviour.
- Misalignment between behavioural expectations and SecTech/RegTech → increased security vulnerabilities.
| Author(s) | Title/Journal | Key Domain | Research Contributions |
|---|---|---|---|
| [85] | Characterising online gamblers exceeding financial risk thresholds in the UK: A retrospective analysis using open banking data/Public Health | Consumer behaviour, and financial vulnerability | Provides survey evidence that consumers’ willingness to share financial data depends more on trust in institutions than on technical knowledge; identifies generational and education differences in adoption. |
| [75] | Data Trusts as a Service: Providing a platform for multi-party data sharing./International Journal of Information Management Data Insights | Trust, privacy, and data governance in multi-party data sharing | Provides survey evidence that consumers’ willingness to share financial data depends more on trust in institutions than on technical knowledge; identifies generational and education differences in adoption. |
| [112] | M-banking adoption from the developing countries perspective: A mediated model/Digital Business | Consumer behaviour | Examines how usability perceptions rather than security drive mobile banking adoption in developing markets. By positioning trust and satisfaction as behavioural mediators, it demonstrates that user experience is the primary catalyst for technology acceptance. |
| [95] | Mobile payment: Understanding the determinants of customer adoption/Computers in Human Behavior | Behavioural adoption and trust | Finds that mobile payment adoption and recommendation behaviour depend on compatibility, perceived security, innovativeness, and social influence. |
| [113] | Towards an understanding of consumers’ FinTech adoption: the case of open banking./International journal of bank marketing | Consumer adoption and trust | Examines factors influencing consumer adoption of open banking apps; highlights the role of trust, perceived benefits, and institutional guarantees. |
| [83] | The construction of self-sovereign identity: Extending the interpretive flexibility of technology./Government Information Quarterly | Trust, digital identity, and socio-technical interpretation | Demonstrates that stakeholder perceptions and institutional context influence how self-sovereign identity technologies are understood, governed, and implemented. |
5. Results
6. Discussion
6.1. Comparative Implications
6.2. Limitations and Future Research
7. Conclusions
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
Appendix A
| Dimension | Keyword | Studies (N) | Percent of Studies |
|---|---|---|---|
| Technology | Authentication | 27 | 23.1% |
| Technology | Encryption | 19 | 16.2% |
| Technology | Security Protocols | 41 | 35.0% |
| Technology | Middleware | 5 | 4.27% |
| Technology | APIs | 34 | 29.0% |
| Regulation | PSD2 | 21 | 17.9% |
| Regulation | GDPR | 18 | 15.4% |
| Regulation | Compliance | 29 | 24.8% |
| Regulation | Data Sharing | 7 | 5.98% |
| Regulation | Regulation | 33 | 28.2% |
| Behavioural | Trust | 36 | 30.8% |
| Behavioural | Consent | 22 | 18.8% |
| Behavioural | Decision Making | 31 | 26.5% |
| Behavioural | Awareness | 6 | 5.13% |
| Behavioural | Adoption Behaviour | 19 | 16.2% |
| Study Type | Technology | Regulation | Behavioural |
|---|---|---|---|
| Study ID | 1 | 2 | 3 |
| APIs | 1 | 1 | 0 |
| Authentication | 1 | 0 | 1 |
| Encryption | 1 | 1 | 0 |
| Security Protocols | 1 | 1 | 1 |
| Middleware | 1 | 0 | 1 |
| PSD2 | 1 | 1 | 1 |
| GDPR | 0 | 1 | 1 |
| Compliance | 1 | 1 | 0 |
| Data Sharing | 1 | 1 | 0 |
| Regulation | 1 | 1 | 0 |
| Trust | 1 | 1 | 1 |
| Consent | 1 | 1 | 0 |
| Decision Making | 1 | 0 | 1 |
| Awareness | 0 | 1 | 1 |
| Adoption Behaviour | 0 | 0 | 1 |
References
- Banerjee, P. System Integration, From Middleware to APIs. Int. J. Comput. Trends Technol. 2024, 72, 37–45. [Google Scholar] [CrossRef] [Scilit]
- Omarini, A.E. Banks and Fintechs: How to Develop a Digital Open Banking Approach for the Bank’s Future. Int. Bus. Res. 2018, 11, 23. [Google Scholar] [CrossRef] [Scilit]
- Braithwaite, J. Authorized Push Payment’ Bank Fraud: What Does an Effective Regulatory Response Look Like? J. Financ. Regul. 2024, 10, 174–193. [Google Scholar] [CrossRef] [Scilit]
- Ngan, J. “The View from below”: Resistance and Change in Authorised Push Payment Fraud. J. Econ. Criminol. 2025, 9, 100166. [Google Scholar] [CrossRef] [Scilit]
- Laplante, P.; Kshetri, N. Open Banking: Definition and Description. Computer 2021, 54, 122–128. [Google Scholar] [CrossRef] [Scilit]
- Casaló, L.V.; Flavián, C.; Guinalíu, M. The Role of Security, Privacy, Usability and Reputation in the Development of Online Banking. Online Inf. Rev. 2007, 31, 583–603. [Google Scholar] [CrossRef] [Scilit]
- Ege Oruç, Ö.; Tatar, Ç. An Investigation of Factors That Affect Internet Banking Usage Based on Structural Equation Modeling. Comput. Human Behav. 2017, 66, 232–235. [Google Scholar] [CrossRef] [Scilit]
- Wang, S.; Asif, M.; Shahzad, M.F.; Ashfaq, M. Data Privacy and Cybersecurity Challenges in the Digital Transformation of the Banking Sector. Comput. Secur. 2024, 147, 104051. [Google Scholar] [CrossRef] [Scilit]
- Podsakoff, P.; MacKenzie, S.; Lee, J.-Y.; Podsakoff, N. Common Method Biases in Behavioral Research: A Critical Review of the Literature and Recommended Remedies. J. Appl. Psychol. 2003, 88, 879–903. [Google Scholar] [CrossRef] [Scilit]
- Hyon, R.; Kleinbaum, A.M.; Parkinson, C. Social Network Proximity Predicts Similar Trajectories of Psychological States: Evidence from Multi-Voxel Spatiotemporal Dynamics. Neuroimage 2020, 216, 116492. [Google Scholar] [CrossRef] [Scilit]
- Polasik, M.; Butor-Keler, A.; Widawski, P.; Keler, G. Evaluating the Regulatory Approach to Open Banking in Europe: An Empirical Study. Financ. Law Rev. 2024, 34, 59–90. [Google Scholar] [CrossRef] [Scilit]
- Babina, T.; Bahaj, S.; Buchak, G.; De Marco, F.; Foulis, A.; Gornall, W.; Mazzola, F.; Yu, T. Customer Data Access and Fintech Entry: Early Evidence from Open Banking. J. Financ. Econ. 2025, 169, 103950. [Google Scholar] [CrossRef] [Scilit]
- Jafri, J.A.; Mohd Amin, S.I.; Abdul Rahman, A.; Mohd Nor, S. A Systematic Literature Review of the Role of Trust and Security on Fintech Adoption in Banking. Heliyon 2024, 10, e22980. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Arner, D.W.; Barberis, J.; Buckley, R.P.; Arner, D.; Barberis, J. FinTech, RegTech, and the Reconceptualization of Financial Regulation. Northwestern J. Int. Law Bus. 2017, 37, 371. [Google Scholar]
- Frei, C. Open Banking: Opportunities and Risks. SSRN Electron. J. 2023, 4316760. Available online: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4316760 (accessed on 2 December 2025). [CrossRef] [Scilit]
- Tariq, M.; Maryam, S.Z.; Shaheen, W.A. Cognitive Factors and Actual Usage of Fintech Innovation: Exploring the UTAUT Framework for Digital Banking. Heliyon 2024, 10, e35582. [Google Scholar] [CrossRef] [Scilit]
- Nikkhah, H.R.; Grover, V.; Sabherwal, R. Post Hoc Security and Privacy Concerns in Mobile Apps: The Moderating Roles of Mobile Apps’ Features and Providers. Inf. Comput. Secur. 2024, 32, 1–37. [Google Scholar] [CrossRef] [Scilit]
- Modesti, P.; Freitas, L.; Shotomiwa, Q.; Almehrej, A. Security Analysis of the Open Banking Account and Transaction API Protocol. Cyber Secur. Appl. 2025, 3, 100097. [Google Scholar] [CrossRef] [Scilit]
- He, Z.; Huang, J.; Zhou, J. Open Banking: Credit Market Competition When Borrowers Own the Data. J. Financ. Econ. 2023, 147, 449–474. [Google Scholar] [CrossRef] [Scilit]
- Chiew, K.L.; Yong, K.S.C.; Tan, C.L. A Survey of Phishing Attacks: Their Types, Vectors and Technical Approaches. Expert Syst. Appl. 2018, 106, 1–20. [Google Scholar] [CrossRef] [Scilit]
- Torshin, I. Open Banking and API-Driven Financial Innovation: Opportunities and Risks. 2025. Available online: https://www.researchgate.net/publication/390486463_Open_Banking_and_API-Driven_Financial_Innovation_Opportunities_and_Risks (accessed on 4 November 2025).
- Polo, A.; Taburet, A.; Vo, Q.-A. Screening Using a Menu of Contracts: A Structural Model for Lending Markets. J. Financ. Econ. 2025. Available online: https://www.bankofengland.co.uk/-/media/boe/files/working-paper/2024/screening-using-a-menu-of-contracts-a-structural-model-of-lending-markets.pdf (accessed on 2 December 2025).
- Ramdani, B.; Rothwell, B.; Boukrami, E. Open Banking: The Emergence of New Digital Business Models. Int. J. Innov. Technol. Manag. 2020, 17, 2050033. [Google Scholar] [CrossRef] [Scilit]
- Waliullah, M.; George, M.Z.H.; Hasan, M.T.; Alam, M.K.; Munira, M.S.K.; Siddiqui, N.A. Assessing the Influence of Cybersecurity Threats and Risks on the Adoption and Growth of Digital Banking: A Systematic Literature Review. Am. J. Adv. Technol. Eng. Solut. 2025, 1, 226–257. [Google Scholar] [CrossRef] [Scilit]
- Tam, C.; de Matos Conceição, C.; Oliveira, T. What Influences Employees to Follow Security Policies? Saf. Sci. 2022, 147, 105595. [Google Scholar] [CrossRef] [Scilit]
- Beautement, A.; Sasse, A.; Wonham, M. The Compliance Budget: Managing Security Behaviour in Organisations. J. ACM 2008. [Google Scholar] [CrossRef] [Scilit]
- Fett, D.; Hosseyni, P.; Kuesters, R. An Extensive Formal Security Analysis of the OpenID Financial-Grade API. arXiv 2019, arXiv:1901.11520. [Google Scholar] [CrossRef] [Scilit]
- Hanif, Y.; Lallie, H.S. Security Factors on the Intention to Use Mobile Banking Applications in the UK Older Generation (55+). A Mixed-Method Study Using Modified UTAUT and MTAM—With Perceived Cyber Security, Risk, and Trust. Technol. Soc. 2021, 67, 101693. [Google Scholar] [CrossRef] [Scilit]
- European Commission. Directive 2007/64/EC of the European Parliament and of the Council of 13 November 2007 on Payment Services in the Internal Market Amending Directives 97/7/EC, 2002/65/EC, 2005/60/EC and 2006/48/EC and Repealing Directive 97/5/EC (Text with EEA Relevance); European Commission 2007. Available online: https://eur-lex.europa.eu/eli/dir/2007/64/oj/eng (accessed on 14 May 2025).
- European Union. Directive (EU) 2015/ of the European Parliament and of the Council of 25 November 2015 on Payment Services in the Internal Market, Amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and Repealing Directive 2007/64/EC. Off. J. Eur. Union 2015, L337, 35–127. [Google Scholar]
- Gimigliano, G.; Beroš, M.B. The Payments Services Directive II; Edward Elgar Publishing Ltd.: Cheltenham, UK, 2021. [Google Scholar]
- Adiningtyas, H.; Auliani, A.S. Sentiment Analysis for Mobile Banking Service Quality Measurement. Procedia Comput. Sci. 2024, 234, 40–50. Available online: https://www.sciencedirect.com/science/article/pii/S1877050924003363 (accessed on 14 May 2025). [CrossRef] [Scilit]
- Merhi, M.; Hone, K.; Tarhini, A. A Cross-Cultural Study of the Intention to Use Mobile Banking between Lebanese and British Consumers: Extending UTAUT2 with Security, Privacy and Trust. Technol. Soc. 2019, 59, 101151. Available online: https://www.sciencedirect.com/science/article/pii/S0160791X19300132 (accessed on 14 May 2025). [CrossRef] [Scilit]
- Liu, J.; Huang, S.; Fu, Q.; Luo, Y.; Qin, S.; Cao, Y.; Zhai, J.; Yang, S. The Open Banking Era: An Optimal Model for the Emergency Fund. Expert Syst. Appl. 2024, 244, 122915. [Google Scholar] [CrossRef] [Scilit]
- Tam, C.; Oliveira, T. Does Culture Influence M-Banking Use and Individual Performance? Inf. Manag. 2019, 56, 356–363. [Google Scholar] [CrossRef] [Scilit]
- Gill, S.S.; Tuli, S.; Xu, M.; Singh, I.; Singh, K.V.; Lindsay, D.; Tuli, S.; Smirnova, D.; Singh, M.; Jain, U.; et al. Transformative Effects of IoT, Blockchain and Artificial Intelligence on Cloud Computing: Evolution, Vision, Trends and Open Challenges. Internet Things 2019, 8, 100118. [Google Scholar] [CrossRef] [Scilit]
- AWS. Financial Services Industry Lens—AWS Well-Architected Framework. 2024. Available online: https://docs.aws.amazon.com/wellarchitected/latest/financial-services-industry-lens/financial-services-industry-lens.html (accessed on 20 December 2025).
- Puschmann, T. Fintech. Bus. Inf. Syst. Eng. 2017, 59, 69–76. [Google Scholar] [CrossRef] [Scilit]
- Cardoso, S.; Martinez, L.F. Online Payments Strategy: How Third-Party Internet Seals of Approval and Payment Provider Reputation Influence the Millennials’ Online Transactions. Electron. Commer. Res. 2019, 19, 189–209. [Google Scholar] [CrossRef] [Scilit]
- Niranjan, S.K.; Raja, J.; Rajini, A.R. Internet of Things (IoT). In Proceedings of the 4th International Conference on Innovative Computing and Communication (ICICC 2021) SSRN, 23 April 2021; Available online: https://ssrn.com/abstract=3832727 (accessed on 20 December 2025).
- Liao, C.H.; Guan, X.Q.; Cheng, J.H.; Yuan, S.M. Blockchain-Based Identity Management and Access Control Framework for Open Banking Ecosystem. Future Gener. Comput. Syst. 2022, 135, 450–466. [Google Scholar] [CrossRef] [Scilit]
- Takieddine, S.; Sun, J. Internet Banking Diffusion: A Country-Level Analysis. Electron. Commer. Res. Appl. 2015, 14, 361–371. [Google Scholar] [CrossRef] [Scilit]
- Sahoo, B.; Pathak, A.; Deco, G.; Banerjee, A.; Roy, D. Lifespan Associated Global Patterns of Coherent Neural Communication. Neuroimage 2020, 216, 116824. [Google Scholar] [CrossRef] [Scilit]
- Ling, G.M.; Fern, Y.S.; Boon, L.K.; Huat, T.S. Understanding Customer Satisfaction of Internet Banking: A Case Study in Malacca. Procedia Econ. Financ. 2016, 37, 80–85. [Google Scholar] [CrossRef] [Scilit]
- Andrade, R.O.; Yoo, S.G. Cognitive Security: A Comprehensive Study of Cognitive Science in Cybersecurity. J. Inf. Secur. Appl. 2019, 48, 102352. [Google Scholar] [CrossRef] [Scilit]
- The World Bank. World Bank Fast Payments Toolkit Case Study: United Kingdom. 2021. Available online: https://fastpayments.worldbank.org/sites/default/files/2021-09/World_Bank_FPS_UK_FPS_Case_Study.pdf (accessed on 13 November 2025).
- Greene, C.; Rysman, M.; Schuh, S.; Shy, O. Costs and Benefits of Building Faster Payment Systems: The U.K. Experience and Implications for the United States; Federal Reserve Bank of Boston: Boston, MA, USA, 2014; p. 47. [Google Scholar]
- Aboobucker, I.; Bao, Y. What Obstruct Customer Acceptance of Internet Banking? Security and Privacy, Risk, Trust and Website Usability and the Role of Moderators. J. High Technol. Manag. Res. 2018, 29, 109–123. [Google Scholar] [CrossRef] [Scilit]
- Desiraju, K.; Mishra, A.N.; Sengupta, P. Customer Perceptions on Open Banking Apps: Insights Using Structural Topic Modeling. J. Retail. Consum. Serv. 2024, 81, 104029. [Google Scholar] [CrossRef] [Scilit]
- Gounari, M.; Stergiopoulos, G.; Pipyros, K.; Gritzalis, D. Harmonizing Open Banking in the European Union: An Analysis of PSD2 Compliance and Interrelation with Cybersecurity Frameworks and Standards. Int. Cybersecur. Law Rev. 2024, 5, 79–120. [Google Scholar] [CrossRef] [Scilit]
- European Union. Legislative Acts Regulations. Regulation (EU) 2016/679 Of the European Parliament and of The Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA Relevance). Off. J. Eur. Union 2016, L679, 1–88. [Google Scholar]
- ENISA. Data Protection, 2024. European Union Agency for Cybersecurity. Available online: https://www.enisa.europa.eu/about-enisa/data-protection/data-protection (accessed on 9 October 2025).
- Moody, G.D.; Siponen, M. Using the Theory of Interpersonal Behavior to Explain Non-Work-Related Personal Use of the Internet at Work. Inf. Manag. 2013, 50, 322–335. [Google Scholar] [CrossRef] [Scilit]
- Hanafizadeh, P.; Keating, B.W.; Khedmatgozar, H.R. A Systematic Review of Internet Banking Adoption. Telemat. Inform. 2014, 31, 492–510. [Google Scholar] [CrossRef] [Scilit]
- Vanini, P.; Rossi, S.; Zvizdic, E.; Domenig, T. Online Payment Fraud: From Anomaly Detection to Risk Management. Financ. Innov. 2023, 9, 66. [Google Scholar] [CrossRef] [Scilit]
- Souza, C.; Redmiles, D. On The Roles of APIs in the Coordination of Collaborative Software Development. Comput. Support. Coop. Work. 2009, 18, 445–475. [Google Scholar] [CrossRef] [Scilit]
- Li, J.; Chen, C.; Rahimi Azghadi, M.; Ghodosi, H.; Pan, L.; Zhang, J. Security and Privacy Problems in Voice Assistant Applications: A Survey. Comput. Secur. 2023, 134, 103448. [Google Scholar] [CrossRef] [Scilit]
- Hilal, W.; Gadsden, S.A.; Yawney, J. Financial Fraud: A Review of Anomaly Detection Techniques and Recent Advances. Expert Syst. Appl. 2022, 193, 116429. [Google Scholar] [CrossRef] [Scilit]
- Amin, H. Internet Banking Adoption Among Young Intellectuals. J. Internet Bank. Commer. 2007, 12. Available online: https://www.icommercecentral.com/open-access/internet-banking-adoption-among-young-intellectuals.php?aid=38527 (accessed on 26 July 2025).
- Martins, C.; Oliveira, T.; Popovič, A. Understanding the Internet Banking Adoption: A Unified Theory of Acceptance and Use of Technology and Perceived Risk Application. Int. J. Inf. Manag. 2014, 34, 1–13. [Google Scholar] [CrossRef] [Scilit]
- Yang, Z.; Wu, J.; Xu, L.; Deng, Z.; Tang, Y.; Gao, J.; Hu, Y.; Zhang, Y.; Qin, S.; Li, C.; et al. Individualized Psychiatric Imaging Based on Inter-Subject Neural Synchronization in Movie Watching. Neuroimage 2020, 216, 116227. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Xu, Z.; Wang, Q.; Wang, Z.; Liu, D.; Wen, S.; Hanson, R. PPM: A Provenance-Provided Data Sharing Model for Open Banking via Blockchain. In Proceedings of the ACM International Conference Proceeding Series; Association for Computing Machinery: New York, NY, USA, 4 February 2020. [Google Scholar]
- Netherlands PwC. PSD2 in Europe: The Start to a New Future of Banking? 2025. Available online: https://www.pwc.nl/en/industries/banking/finance-and-regulatory-reporting/psd2-in-europe.html (accessed on 27 December 2025).
- ACCC. Targeting Scams: Report of the National Anti-Scam Centre on Scams Data and Activity 2024. Available online: https://www.accc.gov.au/about-us/publications/serial-publications/targeting-scams-reports-on-scams-activity/targeting-scams-report-of-the-national-anti-scam-centre-on-scams-data-and-activity-2024 (accessed on 10 December 2025).
- The National Bank of Angola (BNA). Angola’s Payment System Law. 2020. Available online: https://www.bna.ao/#/pt/legislacao-e-normas/legislacao-financeira/lei-sistema-pagamentos/detalhe/72 (accessed on 20 October 2025).
- Njoroge, P. The Central Bank of Kenya Act. 2022. Available online: https://new.kenyalaw.org/akn/ke/act/1966/15/eng@2025-11-04 (accessed on 16 December 2025).
- GOV.BR. Brazilian Data Protection Law LGPD. 2018. Available online: https://www.gov.br/anpd/pt-br/centrais-de-conteudo/outros-documentos-e-publicacoes-institucionais/lgpd-en-lei-no-13-709-capa.pdf (accessed on 19 May 2025).
- GOV.AE. Federal Decree-Law No. (33) of 2021. 2021. Available online: https://uaelegislation.gov.ae/en/legislations/1541/download (accessed on 22 October 2025).
- Serrado, J.; Pereira, R.F.; Mira da Silva, M.; Scalabrin Bianchi, I. Information Security Frameworks for Assisting GDPR Compliance in Banking Industry. Digit. Policy Regul. Gov. 2020, 22, 227–244. [Google Scholar] [CrossRef] [Scilit]
- BIS.org. Rethinking Regulations in an Interconnected Financial System. 2025. Available online: https://www.bis.org/review/r250901e.pdf (accessed on 15 September 2025).
- Babina, T.; Howell, S.T. Entrepreneurial Spillovers from Corporate R&D. J. Labor Econ. 2024, 42, 469–509. [Google Scholar] [CrossRef] [Scilit]
- Hair, J.F., Jr.; Hult, T.M.; Ringle, C.M.; Sarstedt, M.; Danks, N.P.; Ray, S. Classroom Companion. In Business Partial Least Squares Structural Equation Modeling (PLS-SEM) Using R AAWorkbook; Springer: Cham, Switzerland, 2021. [Google Scholar]
- Anderson, R.E.; Hair, J.F.; Black, W.C.; Babin, B.J. Multivariate Data Analysis; Cengage Learning EMEA: Andover, UK, 2010. [Google Scholar]
- Chen, P.H.A.; Jolly, E.; Cheong, J.H.; Chang, L.J. Intersubject Representational Similarity Analysis Reveals Individual Variations in Affective Experience When Watching Erotic Movies. Neuroimage 2020, 216, 116851. [Google Scholar] [CrossRef] [Scilit]
- Lomotey, R.K.; Kumi, S.; Deters, R. Data Trusts as a Service: Providing a Platform for Multi-party Data Sharing. Int. J. Inf. Manag. Data Insights 2022, 2, 100075. [Google Scholar] [CrossRef] [Scilit]
- Simchon, A.; Zipori, T.; Teitelbaum, L.; Lewandowsky, S.; van der Linden, S. A Signal Detection Theory Meta-Analysis of Psychological Inoculation Against Misinformation. Curr. Opin. Psychol. 2026, 67, 102194. Available online: https://www.sciencedirect.com/science/article/pii/S2352250X25002076?via%3Dihub (accessed on 15 September 2025). [CrossRef] [Scilit]
- Tan, M.; Teo, T. Factors Influencing the Adoption of Internet Banking. J. Assoc. Inf. Syst. 2000, 1, 1–44. [Google Scholar] [CrossRef] [Scilit]
- Iman, N.; Nugroho, S.S.; Junarsin, E.; Pelawi, R.Y. Is Technology Truly Improving the Customer Experience? Analysing the Intention to Use Open Banking in Indonesia. Int. J. Bank Mark. 2023, 41, 1521–1549. [Google Scholar] [CrossRef] [Scilit]
- Scheepers, R.; Mathiassen, L.; Ahmad, A.; Bosua, R.; Baskerville, R. Managing Intellectual Property Leakage in the Digital Era: An Integrated Process Model. Int. J. Inf. Manag. 2026, 87, 103021. [Google Scholar] [CrossRef] [Scilit]
- Hair, J.F.; Hult, G.T.M.; Ringle, C.M.; Sarstedt, M. A Primer on Partial Least Squares Structural Equation Modeling (PLS-SEM); Sage Publishing: Thousand Oaks, CA, USA, 2017; ISBN 9781483377445. [Google Scholar]
- Akyildirim, E.; Corbet, S.; Mukherjee, A.; Ryan, M. Global Perspectives on Open Banking: Regulatory Impacts and Market Response. J. Int. Financ. Mark. Inst. Money 2025, 101, 102159. [Google Scholar] [CrossRef] [Scilit]
- Zhang, W.; Bi, C.; Yang, F.; Wang, D. Mitigating Moral Hazard in Financial Leasing: The Role of Open Banking. Expert Syst. Appl. 2025, 294, 128831. [Google Scholar] [CrossRef] [Scilit]
- Weigl, L.; Barbereau, T.; Fridgen, G. The Construction of Self-Sovereign Identity: Extending the Interpretive Flexibility of Technology towards Institutions. Gov. Inf. Q. 2023, 40, 101873. [Google Scholar] [CrossRef] [Scilit]
- Kroszner, R.S.; Strahan, P.E. What Drives Deregulation? Economics and Politics of the Relaxation of Bank Branching Restrictions. Q. J. Econ. 1999, 114, 1437–1467. Available online: https://academic.oup.com/qje/article-abstract/114/4/1437/1934050?redirectedFrom=fulltext (accessed on 15 September 2025). [CrossRef] [Scilit]
- Ghaharian, K.; Azizsoltani, M.; Cohen, C.; Puranik, P.; Chagas, B. Characterising Online Gamblers Exceeding Financial Risk Thresholds in the UK: A Retrospective Analysis Using Open Banking Data. Public Health 2026, 251, 106080. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- EBA. European Banking Authority, Report 2011. Available online: https://www.eba.europa.eu/sites/default/files/documents/10180/601534/9d498bb4-b875-4b25-b8f0-91ac3173b222/EBA2012_online_final2.pdf (accessed on 14 June 2025).
- Financial Conduct Authority (FCA). The Future of Open Banking and the Joint Regulatory Oversight Committee. 2024. Available online: https://www.fca.org.uk/firms/future-open-banking-joint-regulatory-oversight-committee (accessed on 7 November 2025).
- Financial Conduct Authority (FCA). Open Banking and Open Finance in the UK; 6 October 2025. Available online: https://www.fca.org.uk/publication/research-notes/open-banking-open-finance-uk.pdf (accessed on 7 November 2025).
- The Central Bank of Kenya (CBK). Banking Sector Innovation Survey 2024. 2024. Available online: https://www.centralbank.go.ke/uploads/banking_sector_reports/1736029340_Banking%20Sector%20Innovation%20Survey%202024.pdf (accessed on 17 November 2025).
- The Central Bank of Nigeria (CBN). Operational Guidelines for Open Banking in Nigeria. 2023. Available online: https://nairametrics.com/wp-content/uploads/2023/03/Operational-Guidelines-for-Open-Banking-in-Nigeria.pdf (accessed on 2 November 2025).
- The Central Bank of Nigeria (CBN). Payments System Supervision. 2021. Available online: https://www.cbn.gov.ng/PaymentsSystem/ (accessed on 13 November 2025).
- Tam, C.; Santos, D.; Oliveira, T. Exploring the Influential Factors of Continuance Intention to Use Mobile Apps: Extending the Expectation Confirmation Model. Inf. Syst. Front. 2020, 22, 243–257. [Google Scholar] [CrossRef] [Scilit]
- Pinochet, L.H.C.; Bastos, D.C.M.; Pardim, V.I.; Sun, V.; dos Santos, M. Predicting the Intention to Use the Investment Aggregate Functionality in the Context of Open Banking Using the Artificial Neural Network Approach. Procedia Comput. Sci. 2023, 221, 733–740. [Google Scholar] [CrossRef] [Scilit]
- Gozman, D.; Hedman, J.; Sylvest, K. Open Banking: Emergent Roles, Risks & Opportunities. In Proceedings of the 26th European Conference on Information Systems (ECIS2018), Portsmouth, UK, 23–28 June 2018; Available online: https://research-api.cbs.dk/ws/portalfiles/portal/58899604/Gozman_Hedman_Sylvest.pdf (accessed on 3 November 2025).
- Oliveira, T.; Thomas, M.; Baptista, G.; Campos, F. Mobile Payment: Understanding the Determinants of Customer Adoption and Intention to Recommend the Technology. Comput. Human Behav. 2016, 61, 404–414. [Google Scholar] [CrossRef] [Scilit]
- Dinçkol, D.; Ozcan, P.; Zachariadis, M. Regulatory Standards and Consequences for Industry Architecture: The Case of UK Open Banking. Res. Policy 2023, 52, 104760. [Google Scholar] [CrossRef] [Scilit]
- Colangelo, G.; Khandelwal, P. The Many Shades of Open Banking: A Comparative Analysis of Rationales and Models. Internet Policy Rev. 2025, 14, 1821. [Google Scholar] [CrossRef] [Scilit]
- Colangelo, G. Open Banking Goes to Washington: Lessons from the EU on Regulatory-Driven Data Sharing Regimes. Comput. Law Secur. Rev. 2024, 54, 106018. [Google Scholar] [CrossRef] [Scilit]
- de Araluze, G.K.B.; Cassinello Plaza, N. Open Banking: A Bibliometric Analysis-Driven Definition. PLoS ONE 2022, 17, e0275496. [Google Scholar] [CrossRef] [Scilit]
- Fang, J.; Zhu, J. The Impact of Open Banking on Traditional Lending in the BRICS. Financ. Res. Lett. 2023, 58, 104300. [Google Scholar] [CrossRef] [Scilit]
- Alhelaly, Y.; Dhillon, G.; Oliveira, T. When Expectation Fails and Motivation Prevails: The Mediating Role of Awareness in Bridging the Expectancy-Capability Gap in Mobile Identity Protection. Comput. Secur. 2023, 134, 103470. [Google Scholar] [CrossRef] [Scilit]
- Soyupak, O.; Ipek, H. Exploring User Experience and Usability of Mobile and Open Banking for Digital Natives in Turkiye. Qual. Res. Financ. Mark. 2025, 18, 357–378. [Google Scholar] [CrossRef] [Scilit]
- Pee, L.G.; Woon, I.M.Y.; Kankanhalli, A. Explaining Non-Work-Related Computing in the Workplace: A Comparison of Alternative Models. Inf. Manag. 2008, 45, 120–130. [Google Scholar] [CrossRef] [Scilit]
- Farzin, M.; Sadeghi, M.; Yahyayi Kharkeshi, F.; Ruholahpur, H.; Fattahi, M. Extending UTAUT2 in M-Banking Adoption and Actual Use Behavior: Does WOM Communication Matter? Asian J. Econ. Bank. 2021, 5, 136–157. [Google Scholar] [CrossRef] [Scilit]
- Ng, B.Y.; Kankanhalli, A.; Xu, Y. (Calvin) Studying Users’ Computer Security Behavior: A Health Belief Perspective. Decis. Support Syst. 2009, 46, 815–825. [Google Scholar] [CrossRef] [Scilit]
- Du Plessis, L.; Jordaan, Y.; van der Westhuizen, L.M. Consumer Spending Self-Control, Financial Well-Being and Life Satisfaction: The Moderating Effect of Relative Deprivation from Consumers Holding Debt. Int. J. Bank Mark. 2025, 43, 1779–1803. [Google Scholar] [CrossRef] [Scilit]
- van Esterik-Plasmeijer, P.W.J.; van Raaij, W.F. Banking System Trust, Bank Trust, and Bank Loyalty. Int. J. Bank Mark. 2017, 35, 97–111. [Google Scholar] [CrossRef] [Scilit]
- Besley, J.C.; Benitez Gonzalez, A.; Tiffany, L.A. Differentiating Behavioral Trust and Trustworthiness Beliefs to Improve Science Communication Practice and Research. Curr. Opin. Psychol. 2026, 67, 102192. [Google Scholar] [CrossRef] [Scilit]
- Ikhsan, R.B.; Fernando, Y.; Prabowo, H.; Yuniarty; Gui, A.; Kuncoro, E.A. An Empirical Study on the Use of Artificial Intelligence in the Banking Sector of Indonesia by Extending the TAM Model and the Moderating Effect of Perceived Trust. Digit. Bus. 2025, 5, 100103. [Google Scholar] [CrossRef] [Scilit]
- Han, J.; Kim, H. Do Employees in a “Good” Company Comply Better with Information Security Policy? A Corporate Social Responsibility Perspective. Inf. Technol. People 2018, 32, 858–875. [Google Scholar] [CrossRef] [Scilit]
- Kitkowska, A.; Shulman, Y.; Martucci, L.A.; Wästlund, E. Designing for Privacy: Exploring the Influence of Affect and Individual Characteristics on Users’ Interactions with Privacy Policies. Comput. Secur. 2023, 134, 103468. [Google Scholar] [CrossRef] [Scilit]
- Abdennebi, H. Ben M-Banking Adoption from the Developing Countries Perspective: A Mediated Model. Digit. Bus. 2023, 3, 100065. [Google Scholar] [CrossRef] [Scilit]
- Chan, R.; Troshani, I.; Rao Hill, S.; Hoffmann, A. Towards an Understanding of Consumers’ FinTech Adoption: The Case of Open Banking. Int. J. Bank Mark. 2022, 40, 886–917. [Google Scholar] [CrossRef] [Scilit]
- Alsharida, R.A.; Al-rimy, B.A.S.; Al-Emran, M.; Zainal, A. A Systematic Review of Multi Perspectives on Human Cybersecurity Behavior. Technol. Soc. 2023, 73, 102258. [Google Scholar] [CrossRef] [Scilit]
- Ye, J.; Bai, X.; Li, F.; Browning, M.H.E.M.; Eisenman, T.; Yin, J.; Xu, L. What Really Helps Recovery from Stress: The Leafiness or Representational Style of Trees in a Virtual Nature? J. Environ. Psychol. 2026, 109, 102869. [Google Scholar] [CrossRef] [Scilit]
- Buckley, G.; Caulfield, T.; Becker, I. How Might the GDPR Evolve? A Question of Politics, Pace and Punishment. Comput. Law Secur. Rev. 2024, 54, 106033. [Google Scholar] [CrossRef] [Scilit]
- Casolaro, A.M.B.; Rauber, G.N.; de Lima, U.S.M. Open Banking: A Systematic Literature Review. J. Bank. Regul. 2024, 26, 340–355. [Google Scholar] [CrossRef] [Scilit]
- Esmaeilzadeh, P. The Effect of the Privacy Policy of Health Information Exchange (HIE) on Patients’ Information Disclosure Intention. Comput. Secur. 2020, 95, 101819. [Google Scholar] [CrossRef] [Scilit]
- Blihar, D.; Delgado, E.; Buryak, M.; Gonzalez, M.; Waechter, R. A Systematic Review of the Neuroanatomy of Dissociative Identity Disorder. Eur. J. Trauma Dissoc. 2020, 4, 100148. [Google Scholar] [CrossRef] [Scilit]



| Variable | Worldwide | Africa & Middle East | Europe & Central Asia | LA & the Caribbean | North America | South-East Asia & Pacific |
|---|---|---|---|---|---|---|
| Number of Countries | 193 | 65 | 50 | 25 | 3 | 50 |
| Regulatory Initiatives | 168 | 65 | 50 | 25 | 3 | 25 |
| Promoting competition | 65 | 9 | 39 | 3 | 1 | 13 |
| Fostering innovation | 65 | 9 | 39 | 3 | 1 | 13 |
| Financial inclusion | 66 | 10 | 39 | 3 | 1 | 13 |
| Under discussion | 80 | 16 | 40 | 8 | 2 | 14 |
| Partial implementation | 80 | 16 | 40 | 8 | 2 | 14 |
| Fully implemented | 80 | 16 | 40 | 8 | 2 | 14 |
| Mandatory data sharing | 57 | 6 | 37 | 2 | 1 | 11 |
| Reciprocal data access | 56 | 6 | 36 | 2 | 1 | 11 |
| Regulatory tech standards | 62 | 8 | 39 | 2 | 1 | 12 |
| Extended scope | 56 | 5 | 36 | 3 | 1 | 11 |
| Data access only | 58 | 6 | 38 | 2 | 1 | 11 |
| Payment function | 58 | 6 | 38 | 2 | 1 | 11 |
| Integrated data & payments | 58 | 6 | 38 | 2 | 1 | 11 |
| Variable | Worldwide | Africa & Middle East | Europe & Central Asia | LA & the Caribbean | North America | South-East Asia & Pacific |
|---|---|---|---|---|---|---|
| Number of Countries | 193 | 65 | 50 | 25 | 3 | 50 |
| Regulatory Initiatives | 48% | 25% | 80% | 32% | 67% | 56% |
| Promoting competition | 82% | 67% | 87% | 100% | 0% | 77% |
| Fostering innovation | 97% | 100% | 97% | 100% | 100% | 92% |
| Financial inclusion | 29% | 40% | 10% | 100% | 100% | 54% |
| Under discussion | 38% | 75% | 12% | 75% | 100% | 36% |
| Partial implementation | 18% | 6% | 12% | 25% | 0% | 43% |
| Fully implemented | 44% | 13% | 75% | 0% | 0% | 21% |
| Mandatory data sharing | 88% | 67% | 97% | 100% | 100% | 64% |
| Reciprocal data access | 18% | 33% | 0% | 100% | 100% | 45% |
| Regulatory tech standards | 39% | 63% | 15% | 100% | 100% | 83% |
| Extended scope | 34% | 80% | 3% | 100% | 100% | 91% |
| Data access only | 5% | 0% | 0% | 50% | 100% | 9% |
| Payment function | 0% | 0% | 0% | 0% | 0% | 0% |
| Integrated data & payments | 95% | 100% | 100% | 50% | 0% | 91% |
| Inclusion Criteria | Exclusion Criteria |
|---|---|
| The study should address open banking, security behaviour, regulatory policies, compliance, financial regulation, cybersecurity, FinTech, RegTech or SecTech. It should include a theoretical research model. Articles should be written in a language in which the reviewers are proficient (English, Portuguese, Spanish and Polish). | Studies that did not address open banking, security behaviour, regulatory policies, compliance, financial regulation, cybersecurity, FinTech, RegTech, or SecTech were excluded. Editorials, posters, presentations, position papers. Articles written in languages beyond the reviewers’ proficiency were also excluded. Studies without full-text availability were excluded. |
| Cluster Overlap | Number of Studies | Percentage |
|---|---|---|
| Technology + Regulation | 38 | 32.5% |
| Technology + Behaviour | 29 | 24.8% |
| Regulation + Behaviour | 27 | 23.1% |
| All Three Dimensions | 21 | 17.9% |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Wilson, C.; Tam, C. Security Challenges in Open Banking: A Systematic Review and Conceptualisation of a Tri-Dimensional Security Framework. FinTech 2026, 5, 38. https://doi.org/10.3390/fintech5020038
Wilson C, Tam C. Security Challenges in Open Banking: A Systematic Review and Conceptualisation of a Tri-Dimensional Security Framework. FinTech. 2026; 5(2):38. https://doi.org/10.3390/fintech5020038
Chicago/Turabian StyleWilson, Cristiano, and Carlos Tam. 2026. "Security Challenges in Open Banking: A Systematic Review and Conceptualisation of a Tri-Dimensional Security Framework" FinTech 5, no. 2: 38. https://doi.org/10.3390/fintech5020038
APA StyleWilson, C., & Tam, C. (2026). Security Challenges in Open Banking: A Systematic Review and Conceptualisation of a Tri-Dimensional Security Framework. FinTech, 5(2), 38. https://doi.org/10.3390/fintech5020038

