← All CFP Flashcard Decks

Open Banking & API Integration Flashcards

7 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Open Banking & API Integration flashcards as text
  1. Which regulatory framework mandates that banks open their APIs to third-party providers in the European Union?

    Answer: PSD2 (Payment Services Directive 2)

    PSD2 is the EU regulation that requires banks to provide third-party providers with secure access to customer account data and payment initiation services via APIs.

  2. Which API architecture style is most widely adopted in open banking implementations?

    Answer: RESTful APIs using HTTP methods

    RESTful APIs are the industry standard for open banking due to their simplicity, stateless design, scalability, and broad compatibility with web and mobile applications.

  3. What does 'AISP' stand for in the context of open banking?

    Answer: Account Information Service Provider

    An AISP (Account Information Service Provider) is a third-party entity authorized under PSD2 to access and aggregate customer account information for services like personal finance management.

  4. Which US regulatory provision most closely parallels the EU's open banking mandate by establishing consumer financial data rights?

    Answer: CFPB Section 1033 Personal Financial Data Rights Rule

    CFPB Section 1033 establishes consumers' rights to access their financial data and share it with authorized third parties, serving as the primary US open banking framework.

  5. What is the primary role of a Payment Initiation Service Provider (PISP) in an open banking ecosystem?

    Answer: Initiating payment transactions directly from a customer's bank account with their consent

    A PISP can initiate payment transactions directly from a user's bank account with their explicit consent, enabling direct bank-to-bank payments without card networks.

  6. Which OAuth 2.0 flow is considered most appropriate for securing open banking API authentication for mobile and web applications?

    Answer: Authorization Code Flow with PKCE

    The Authorization Code Flow with PKCE (Proof Key for Code Exchange) is recommended for open banking as it prevents authorization code interception attacks and is suitable for both server-side and public clients.

  7. What is the primary purpose of a 'consent framework' in open banking?

    Answer: To ensure customers explicitly authorize third parties to access their financial data with defined scope and duration

    A consent framework ensures customers provide explicit, granular, and time-bound authorization before any third party can access their financial data, upholding data sovereignty and privacy rights.