Author
Listed:
- Cristiano Wilson
(NOVA Information Management School (NOVA IMS), Universidade Nova de Lisboa, 1070-312 Lisbon, Portugal)
- Carlos Tam
(NOVA Information Management School (NOVA IMS), Universidade Nova de Lisboa, 1070-312 Lisbon, Portugal)
Abstract
Background: Open banking (OB) is rapidly transforming financial ecosystems by enabling controlled data sharing among multiple actors through application programming interfaces (APIs). While this transformation promises innovation and competition, it also introduces complex security challenges that extend beyond purely technical considerations. Despite growing attention in academic and professional domains, existing reviews provide limited integration of security concerns with global adoption patterns and cross regional variation. Methods : This systematic review analyses empirical and conceptual research on security in OB published between 1999 and 2025, capturing early digital banking studies that later informed the development of OB. The literature is structured into three distinct phases: foundational digital banking developments, regulatory formalisation of OB frameworks, and post-implementation expansion of OB ecosystems. A comprehensive search was conducted across major academic databases and scholarly portals, complemented by relevant regulatory and policy sources. Following duplicate removal, title and abstract screening, full-text eligibility assessment, and methodological quality appraisal, 117 studies were retained for qualitative synthesis. Results: The findings reveal recurring security challenges arising from the interaction between technological infrastructures, regulatory frameworks, and user behaviour within OB ecosystems. Technical safeguards such as APIs, strong customer authentication, and encryption are necessary but insufficient when they are misaligned with regulatory implementation and user behaviour. Behavioural factors, including trust, consent understanding, and security-related decision making, play a central role in shaping ecosystem resilience. Based on this synthesis, the study develops a tri-dimensional security framework integrating technological, regulatory, and behavioural dimensions. The bibliometric analysis of 117 studies reveals that technological security dominates the literature (58%), followed by regulatory governance (44%) and behavioural dimensions (42%). However, only 17.9% of studies integrate all three dimensions simultaneously. APIs and authentication mechanisms represent the most frequent technological terms, while PSD2 and GDPR dominate regulatory discourse. Trust and decision-making are the most recurrent behavioural constructs. The relatively low proportion of fully integrated studies confirms a structural fragmentation within OB security research, thereby empirically justifying the proposed tri-dimensional framework. Chronologically, early studies (1999–2015) predominantly focused on technical security mechanisms and regulatory compliance, whereas more recent research (2020–2025) increasingly highlights the interplay between regulatory frameworks and user behaviour, suggesting a shift towards a more holistic understanding of security within OB adoption. Conclusions : This systematic review concludes that integrating technological, regulatory, and behavioural perspectives advances a more comprehensive understanding of security in OB ecosystems. The proposed tri-dimensional security framework provides a structured foundation for future research and supports policy-relevant and practice-oriented security design.
Suggested Citation
Cristiano Wilson & Carlos Tam, 2026.
"Security Challenges in Open Banking: A Systematic Review and Conceptualisation of a Tri-Dimensional Security Framework,"
FinTech, MDPI, vol. 5(2), pages 1-28, May.
Handle:
RePEc:gam:jfinte:v:5:y:2026:i:2:p:38-:d:1934725
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jfinte:v:5:y:2026:i:2:p:38-:d:1934725. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.