...
...
...
...
...
...
...
...
...
General
Expand | ||||
---|---|---|---|---|
| Security has
| |||
Open Banking stands to unlock greater value through proliferation of new business models, new market entrants, increased monetization opportunities, scaled up digital banking and most importantly greater value to customer in usage of financial products and services. |
Expand | ||
---|---|---|
| ||
A holistic Open Banking framework that will support the evolution of innovation while continuously addressing issues to protect, maintain and bolster the safety and robustness of Bahrain’s financial system. |
Expand | ||
---|---|---|
| ||
Any participant supplying or accessing data already has obligations under existing legal and regulatory frameworks in Bahrain, such as the Personal Data Protection Law (PDPL) of 2018. Guidelines drafted under Bahrain OBF are complementary to and not a replacement of any existing legal or regulatory requirements in Bahrain. |
Expand | ||
---|---|---|
| ||
No, there is no additional charge for using Open Banking. However, some accredited third party providers may choose to charge you for their products and services. |
Expand | ||
---|---|---|
| ||
No. To use Open Banking you need online or mobile banking services activated for your account. |
Expand | ||
---|---|---|
| ||
PISP offer payment initiation services to users/customers as part of Open Banking. On the other hand, EFTS is a payments network/system that enables payments between two IBAN accounts in Bahrain. Thus both are independent of each other. For example, a user/customer may initiate a payment through a PISP application, and the actual payment will be handled/settled by the EFTS system. |
Security and Privacy
Expand | ||
---|---|---|
| ||
Security has always been the primary focus are for Open Banking.
|
...
Expand | ||
---|---|---|
| ||
You will always be in control. You decide what information you wish to share with which third party. You choose which accredited third party provider you want to use. The ultimate control of your information will always be with you. |
...
Expand | ||
---|---|---|
| ||
Contact the bank or third party provider you believe have misused your data immediately. If you think you have been a victim of identity theft, immediately report it to your bank. |
...
Expand | ||
---|---|---|
Expand | ||
| ||
| ||
Only accredited third party providers and ASPSPs are allowed to offer Open Banking services in Bahrain.
|
Expand | ||
---|---|---|
| ||
Accreditation criteria has been laid down and explained in detail in the Authorization Module of Volume 5 of CBB rulebook. |
Expand | ||
---|---|---|
| ||
Anyone who wishes to know about the accreditation of a third party provider may do so by checking the list of accredited third party providers on the licensing directory available on the CBB website. |
Expand | ||
---|---|---|
| ||
The CBB may amend or revoke a license in any of the following cases:
|
| |
All Open Banking participants to use the existing infrastructure for disputes handling process and dispute resolution. |
Expand | ||
---|---|---|
| ||
When a User/Customer signs up for a service, the AISP/PISPs must request for explicit consent from the User/Customer in order to permit access to data that may be essential only for that specific service. All consent requests should indicate in a clear and specific manner, the details, scope, objectives and implication of providing such consent. Necessary safeguards should be established by the AISP/PISP to ensure that the User/Customer reads the terms and conditions before providing explicit consent. Details on the consent message, structure and language are specified in detail as part of Bahrain OBF. |
Accreditation
Expand | ||
---|---|---|
| ||
Only accredited third party providers and ASPSPs are allowed to offer Open Banking services in Bahrain.
|
Expand | ||
---|---|---|
| ||
Accreditation criteria has been laid down and explained in detail in the Authorization Module of Volume 5 of CBB rulebook. |
Expand | ||
---|---|---|
| ||
The CBB would be licensing third party providers to offer Open Banking service to banks’ customers in Bahrain. All participants that use Open Banking to offer products and services in Bahrain must be accredited and regulated by the CBB. Thus, any person/entity, including banks, that wishes to offer such services would first need to approach CBB for an AISP/PISP license. |
Expand | ||
---|---|---|
| ||
Anyone who wishes to know about the accreditation of a third party provider may do so by checking the list of accredited third party providers on the licensing directory available on the CBB website. In addition to the CBB website, the third party should clearly state their accreditation status. |
Expand | ||
---|---|---|
| ||
The CBB may amend or revoke a license in any of the following cases:
|
API Specification
Expand | ||
---|---|---|
| ||
An idempotency key is used to guard against the creation of duplicate resources when using the POST API endpoints (where indicated). If an idempotency key is required for an API endpoint:
If an idempotency key is not required for an API endpoint:
|
...
Expand | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
The following are the HTTP response codes for the different HTTP methods, across all Read/Write API endpoints.
An ASPSP MAY return other standard HTTP status codes (e.g. from gateways and other edge devices) as described in RFC 7231 - Section 6. ASPSPs must respond with error response in the OAuth/OIDC flow with mandatory alignment of the error codes to those specified in OpenID Connect Core Specification Section 3.1.2.6. ASPSPs must respond with Open Banking Error Response Structure for all errors during API Calls.
|
Expand | ||
---|---|---|
| ||
An ASPSP must provide limited support of filtering on GET operations that return multiple records. The filter parameters, are always specific to particular field(s) of the resource, and follow the rules/formats defined under the resource's data dictionary. In case of DateTime type filter parameters, values must be specified in ISO8601 format. If the DateTime contains a timezone, the ASPSP may ignore the timezone component. The filter values will be assumed to refer to the same timezone as the timezone in which the resource is maintained. |
...
Expand | ||
---|---|---|
| ||
Archiving of resources will be for ASPSPs to define based on their internal Legal and Regulatory ASPSPs should define archiving policies based on existing Bahrain regulations and their internal legal requirements. |
Expand | ||
---|---|---|
| ||
A number of resources in the specification include a section for Supplementary Data. This is intended to allow ASPSPs to accept or provide information in a request or response that is not catered for by other sections of the resource definition. The Supplementary Data section is defined as an empty JSON object in the specification. Wherever used, an ASPSP must define and document (on their developer portal) their own structure, usage and (mandatory/optional) requirements for Supplementary Data. An ASPSP must not use Supplementary Data if an element already exists in the OBF standard that fulfils the requirement. |
Expand | ||
---|---|---|
| ||
This flow assumes that the following steps have been completed successfully:
The AISP attempts to provide an expired or missing access token to the ASPSP in an attempt to Request Data |
Expand | ||
---|---|---|
| ||
This flow assumes that the following steps Steps have been completed successfully:
The AISP attempts to provide an expired or missing access token provides a malformed request to the ASPSP in an attempt to setup an Account Request Data. |
Expand | ||
---|---|---|
| ||
This flow assumes that the following Steps have been completed successfully:
The AISP provides a malformed request to the ASPSP in an attempt to setup an Account Request. (valid) access token which does not have a valid scope (or link to the correct Permissions) to Request Data. |
Expand | ||
---|---|---|
| ||
This flow assumes that the following Steps have been completed successfully:
The AISP provides a (valid) access token which does not have a valid scope (or link to the correct Permissions) to Request Data. is used to generate a burst of multiple requests to retrieve an Accounts resource. The ASPSP may optionally choose to return a 429 Response. |
Expand | ||
---|---|---|
| ||
This flow assumes that the following Steps have been completed successfully:
The AISP provides a (valid) access token which is used to generate a burst of multiple requests to retrieve an Accounts resource. The ASPSP may optionally choose to return a 429 Response. |
Expand | ||
---|---|---|
| ||
This flow assumes that the following Steps have been completed successfully:
|
...
|
Further Information
Expand | ||
---|---|---|
| ||
Feel free to visit our confluence page for more updates. CBB will update this page on a periodic basis. |
Expand | ||
---|---|---|
| ||
Feel free to contact CBB for any enquiry on Open Banking by submitting a general enquiry form available on https://www.cbb.gov.bh/general-enquiry-form/. |
Expand | ||
---|---|---|
| ||
Feel free to visit our confluence page for more updates. CBB will update this page on a periodic basis. | ||
Expand | ||
| ||
| ||
First, discuss your complaint directly with the company, institution or bank. If you believe you are not satisfied with their response, you can contact CBB by submitting a Complaint Form available on https://www.cbb.gov.bh/complaint-form/ |