PSD2 is positioned as a transformative shift in EU banking comparable to the impact ATMs had on customer self-service, aiming to strengthen the single EU payments market by making transactions cheaper, safer, faster, and more transparent. A central mechanism is regulated, consent-based data sharing: once customers approve, Third Party Providers (TPPs) can access account data and initiate payments through secure bank APIs. Technically, PSD2 drives two major capability areas: opening and securing new financial services APIs, and implementing Strong Customer Authentication (SCA) alongside transactional risk analysis and malware mitigation.
PSD2 introduces new roles and market structure: banks become Account Servicing Payment Service Providers (ASPSPs), while TPPs include Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs). Functions historically handled by banks are explicitly opened to competition, potentially from non-traditional businesses, raising both innovation potential and security exposure. Many EU banks are described as underprepared for secure, programmatic, high-volume third-party access, especially given legacy core systems protected by layered internal defenses that were not designed for external API exposure. Consequently, banks must build new TPP-facing interface layers and defense-in-depth infrastructure, including API gateways, web application firewalls, traffic analysis, certificate-based trust, authorization services, and national/international trust frameworks (including eIDAS certificates).
Standardization efforts such as UK Open Banking and Berlin Group NextGenPSD2 aim to reduce fragmentation by defining API and security approaches; UK Open Banking specifies OAuth 2.0 more directly, while PSD2 is technology-agnostic. ForgeRock is presented as an identity and API security platform supporting consent, OAuth2/OIDC/UMA, SAML, policy enforcement, monitoring, and conformance tooling (Test Directory and Model Bank) to help banks and TPPs meet PSD2 and related standards under tight implementation deadlines.
See All Locations
See All Locations