08/02/2025 15:38

What are groups in the List of basic Open APIs in the banking sector in Vietnam?

What are groups in the List of basic Open APIs in the banking sector in Vietnam?

Recently, the Governor of the State Bank of Vietnam issued a Circular regulating the implementation of Open Application Programming Interfaces (Open API) in the Banking sector.

What are groups in the List of basic Open APIs in the banking sector in Vietnam?

The Governor of the State Bank of Vietnam issued Circular 64/2024/TT-NHNN on December 31, 2024, regulating the implementation of open application programming interfaces (Open API) in the banking sector.

Pursuant to Clause 1, Article 6, of Circular 64/2024/TT-NHNN, the basic Open API list is organized into the following groups:

Article 6. Open API List

1. The basic Open API list is organized into the following groups:

a) Open APIs for querying exchange rate and interest rate information of the bank include: API for Interest Rate Information, API for Exchange Rate Information;

b) Open APIs for querying customer information include: API for Customer Consent and Retrieve, API for Access Token Retrieval, API for Access Token Refresh, API for Access Token Revocation, API for Account List Retrieval, API for Account Information Retrieval, API for Transaction History Retrieval;

c) Open APIs for initiating payments, depositing into e-wallets, and withdrawing from e-wallets include:

(i) Open APIs for payment initiation include: API for Payment Initiation, API for Customer Confirmation Redirect Flow, API for Access Token Retrieval Redirect Flow, API for Updating Customer Payment Confirmation Status Decoupled Flow, API for Payment Confirmation, API for Transaction Status Retrieval, API for Customer Payment Confirmation Status Retrieval Decoupled Flow:

(ii) Open APIs for e-wallet deposits include: API for E-Wallet Deposit, API for OTP Confirmation, API for Updating Customer E-Wallet Deposit Confirmation Status Decoupled Flow, API for Customer E-Wallet Deposit Confirmation Status Retrieval Decoupled Flow, API for E-Wallet Deposit Confirmation, API for Transaction Status Retrieval;

(iii) Open APIs for withdrawing from e-wallets.

...

Thus, the basic Open API list in the banking sector is organized into three main groups:

- Open APIs for querying exchange rate and interest rate information of the bank, including: API for Interest Rate Information, API for Exchange Rate Information;

- Open APIs for querying customer information, including: API for Customer Consent and Retrieve, API for Access Token Retrieval, API for Access Token Refresh, API for Access Token Revocation, API for Account List Retrieval, API for Account Information Retrieval, API for Transaction History Retrieval;

- Open APIs for payment initiation, depositing into e-wallets, and withdrawing from e-wallets.

What are the bank’s responsibilities in implementing Open API in Vietnam?

According to Article 11 of Circular 64/2024/TT-NHNN, the responsibilities of the bank in implementing Open API are specified as follows:

(1) Fully develop the information system infrastructure to support the implementation of Open API to be ready for data connection and processing.

(2) Develop and complete connection and data processing guidance documents.

(3) Ensure data quality during Open API implementation. Promptly notify third parties of data discrepancies and cooperate with them to promptly correct and amend.

(4) Ensure the information system's network safety and security in implementing Open API, meeting at least level 3 according to the Government of Vietnam’s regulations on information system safety by level, and comply with the regulations of the State Bank of Vietnam on information system safety in banking activities.

(5) Provide tools or functionalities allowing customers to:

- Query the data that the customer consents for third-party processing;

- Withdraw customer consent according to legal regulations.

(6) Set limits on the period for querying customer information after customer consent, not exceeding 180 days, unless otherwise agreed between the customer and the bank.

(7) Provide information on Open API implementation to the State Bank of Vietnam (through the Information Technology Department) when requested.

(8) Cooperate with third parties per the agreement and with competent authorities to address issues and disputes in implementing Open API.

(9) Implement technology solutions to limit the number of automatic customer information queries from third parties.

(10) Bear responsibility for selecting, evaluating, supervising, and managing third parties.

(11) Update or revoke third-party data access rights when there are changes according to the contract.

(12) Monitor access activities:

- Have a monitoring system to detect and prevent abnormal or unauthorized access actions from third parties;

- Log all third-party Open API usage for at least 3 months and back it up for a minimum of 1 year to serve inspection needs when necessary.

17


Please Login to be able to download
Login

  • Address: 17 Nguyen Gia Thieu, Vo Thi Sau Ward, District 3, Ho Chi Minh City
    Phone: (028) 7302 2286 (6 lines)
    E-mail: info@lawnet.vn
Parent company: THU VIEN PHAP LUAT Ltd
Editorial Director: Mr. Bui Tuong Vu - Tel. (028) 7302 2286
P.702A , Centre Point, 106 Nguyen Van Troi, Ward 8, Phu Nhuan District, HCM City;