Open Banking API Implementation for Retail Banks Training Course
| Course code | SD-FT-011 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Financial Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Retail banks implementing open banking APIs must expose regulated account and payment capabilities while protecting customer data, maintaining consent integrity, and meeting demanding availability expectations. Product, architecture, security and operations teams need more than an understanding of API terminology: they must make defensible decisions on customer journeys, API contracts, consent models, authentication flows, third-party provider onboarding, monitoring and incident response. This course addresses the practical gap between regulatory obligations and a deployable retail-bank API service.
Participants work through the design and implementation lifecycle for Account Information Services and Payment Initiation Services. They learn to translate PSD2 and UK Open Banking-style requirements into API capabilities; design RESTful resources using OpenAPI; apply OAuth 2.0, OpenID Connect and Financial-grade API principles; model consent, scopes and token lifecycles; and define controls for Strong Customer Authentication, data minimisation and audit evidence. The course also covers sandbox strategy, developer portals, versioning, service-level measures, fraud signals and production support.
Delivery combines instructor-led technical briefings with guided design labs, Postman-based API testing and retail-bank case work. Teams assess a sample bank's current-state architecture, build an API contract and security flow, test representative customer and third-party-provider interactions, and rehearse an operational incident. Each participant leaves with an implementation blueprint containing an API inventory, consent and authorisation design, OpenAPI specification extract, control matrix, test scenarios and a phased rollout plan that can be adapted for their bank.
The course is designed for intermediate banking professionals who contribute to open banking delivery decisions, including technology, product, risk, compliance and operational leaders.
Course objectives
By the end of this course, participants will be able to:
- Map retail banking account and payment journeys to Account Information Service and Payment Initiation Service API capabilities
- Draft an OpenAPI 3.1 contract for account, transaction, consent and payment resources
- Design OAuth 2.0 and OpenID Connect authorisation flows for third-party provider access
- Model consent scopes, token lifecycles, revocation rules and customer permission records
- Apply Strong Customer Authentication and Financial-grade API controls to an open banking threat model
- Build Postman collections that test API validation, consent states, error handling and payment-status flows
- Define API versioning, sandbox, developer-portal and service-level operating requirements
- Produce a phased open banking API implementation blueprint with ownership, controls and acceptance criteria
Benefits of attending
For you
- Gain the ability to challenge API designs using concrete consent, authentication and data-sharing requirements
- Build credible evidence for roles in open banking product delivery, API governance or digital banking transformation
- Learn to translate regulatory obligations into backlog items, acceptance criteria and operational controls
- Create reusable OpenAPI and Postman artefacts that demonstrate practical API delivery capability
- Strengthen cross-functional communication with security, compliance, engineering and third-party provider teams
For your organisation
- Reduce rework by aligning product, architecture, security and compliance teams on a shared API implementation model
- Improve third-party provider onboarding through clearer API contracts, sandbox requirements and support processes
- Lower consent and data-access risk through defined scopes, token controls, revocation rules and audit records
- Increase release confidence with structured API test cases for customer journeys, errors and payment statuses
- Create a prioritised rollout blueprint that identifies dependencies, ownership, controls and measurable service targets
Target competencies
Who should attend
- Open Banking Product Managers — who must turn regulated customer and third-party journeys into an implementable product backlog
- Banking Solution Architects — who design API, identity, integration and data architectures for retail banking platforms
- API Product Owners — who define API contracts, lifecycle policies and developer experience for external consumers
- Information Security Managers — who must assess consent, authentication, token and third-party access controls
- Risk and Compliance Managers — who need traceable evidence that API services meet regulatory and conduct obligations
- Digital Banking Operations Managers — who establish monitoring, incident handling and support processes for API services
Requirements and prerequisites
Participants should understand retail banking products such as current accounts, payment initiation and transaction data, and have working familiarity with REST APIs, JSON and basic HTTP request-response behaviour. Experience reading API documentation or using a tool such as Postman is helpful, as is awareness of PSD2, customer authentication or third-party providers. Participants should be able to discuss their bank's channels, core banking integrations and control environment. Coding experience, prior API development, cryptography expertise and detailed knowledge of a particular national open banking standard are not required; labs focus on design, testing and implementation decisions rather than software engineering.
Training methodology
The instructor uses a retail-bank implementation case throughout the five days, moving from regulatory interpretation to production operating model. Short technical sessions introduce standards and decision frameworks, followed by facilitated workshops in which participants map journeys, draft OpenAPI resources, configure and run Postman requests, and review consent and authentication scenarios. Small groups conduct architecture and control reviews from product, security and operations perspectives. On the final day, participants assemble their artefacts into a practical implementation blueprint and receive structured peer and instructor feedback.
Course outline
Day 1: Open Banking Scope, Regulation and Target Architecture
- Retail open banking ecosystem roles: ASPSPs, TPPs, AISP and PISP models
- PSD2 and UK Open Banking-style obligations for account access and payment initiation
- Customer journeys for account aggregation, consent and payment initiation
- API capability inventory across channels, core banking and payment systems
- Open banking reference architecture and integration boundary patterns
- Data classification, minimisation and purpose limitation for account data
- Implementation readiness assessment and dependency mapping
Workshop: Participants map a retail bank's account-information and payment-initiation journeys and produce a capability-and-dependency heat map.
Day 2: API Contract and Data Design
- REST resource modelling for accounts, balances, transactions, consents and payments
- OpenAPI Specification 3.1 structure, reusable components and schema validation
- JSON payload design and banking data-field mapping
- HTTP methods, idempotency keys and asynchronous payment processing patterns
- Pagination, filtering, date ranges and transaction enrichment parameters
- Error taxonomy, problem details and customer-safe error messages
- API versioning, deprecation and backward-compatibility policies
Workshop: Participants draft an OpenAPI 3.1 extract for account, transaction and payment endpoints, including schemas, errors and versioning rules.
Day 3: Consent, Identity and Secure Access
- OAuth 2.0 roles, grants, scopes and token lifecycle controls
- OpenID Connect identity assertions and customer authentication context
- Financial-grade API security profiles and sender-constrained token concepts
- Consent creation, confirmation, amendment, expiry and withdrawal states
- Strong Customer Authentication step-up and decoupled authentication patterns
- Third-party provider registration, certificate validation and client trust management
- Threat modelling for token theft, redirect attacks, excessive data access and consent fraud
Workshop: Participants design an authorisation sequence diagram and consent-state model for a third-party account-aggregation journey.
Day 4: Testing, Sandboxes and Production Operations
- Postman collections, environments and variable management for API testing
- Positive, negative and boundary test cases for account and payment APIs
- Consent-state, scope and token-expiry test scenarios
- Sandbox design, synthetic data and third-party developer onboarding
- API gateway policies for rate limits, throttling, quotas and request validation
- Observability metrics for latency, availability, errors, consent failures and payment status
- Incident triage, customer communication and regulatory evidence capture
Workshop: Participants execute a Postman test pack against a sample API and produce a defect log with operational severity and remediation recommendations.
Day 5: Governance, Rollout and Implementation Blueprint
- API governance roles, decision rights and architecture review checkpoints
- Control matrix for privacy, authentication, auditability and third-party access
- Service-level objectives, error budgets and operational acceptance criteria
- Vendor, core-banking and payment-rail dependency management
- Pilot selection, phased rollout and migration planning
- Regulatory reporting, audit trails and evidence-retention requirements
- Implementation roadmap, investment case and success measures
Workshop: Participants assemble and present a phased open banking API implementation blueprint with contract artefacts, controls, test evidence, owners and milestones.
Tools & standards covered
OpenAPI Specification 3.1, OAuth 2.0, OpenID Connect, Postman
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Cape Town · USD 4,200 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Nairobi · USD 3,000 -
19 – 23 Oct 2026Book
Nairobi · USD 3,000 -
19 – 23 Oct 2026Book
Mombasa · USD 3,200 -
02 – 06 Nov 2026Book
Dar es Salaam · USD 3,500 -
02 – 06 Nov 2026Book
Mombasa · USD 3,200 -
09 – 13 Nov 2026Book
Live Online · USD 1,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Financial Technology
Financial Technology Applications in Insurance Training Course
Insurance firms are under pressure to shorten quote-to-bind cycles, reduce claims leakage, strengthen fraud controls, and serve policyholder…
NICE Actimize Financial Crime Detection Training Course
Financial-crime teams need more than alert queues: they need investigators who can interpret detection scenarios, distinguish credible risk …
COBIT 2019 Governance of Fintech Systems Training Course
Fintech organisations must govern payment platforms, digital lending engines, customer-data services, cloud-hosted core systems, API ecosyst…
Mambu Core Banking Platform Configuration Training Course
Mambu implementation teams must translate banking propositions into controlled product configurations: loan terms, deposit rules, interest c…