{
  "data_version": "seed-0.1 · 2026-08-28",
  "source": "https://banking.foundation",
  "license": "CC BY 4.0",
  "disclaimer": "Approximate reference data; not real-time; not legal or investment advice.",
  "collection": "standards",
  "count": 15,
  "data": [
    {
      "id": "iso-20022",
      "name": "ISO 20022",
      "category": "Messaging",
      "organization": "ISO",
      "scope": "Universal financial industry messaging (payments, securities, cards, trade)",
      "status": "Active",
      "machine_readable": true,
      "website": "https://www.iso20022.org",
      "description": "International standard for electronic financial messaging, defining a shared data dictionary and message schemas (XML/ASN.1) for payments, securities, cards and trade. Adopted by SWIFT cross-border payments and major payment and RTGS systems worldwide."
    },
    {
      "id": "iso-8583",
      "name": "ISO 8583",
      "category": "Cards",
      "organization": "ISO",
      "scope": "Card-originated financial transaction messages",
      "status": "Active",
      "machine_readable": false,
      "website": "https://www.iso.org",
      "description": "ISO standard for financial transaction card originated messages, defining the bitmap-based message format used to authorize, clear and settle card payments. It underpins most ATM and card-network authorization traffic worldwide."
    },
    {
      "id": "swift-mt",
      "name": "SWIFT MT",
      "category": "Messaging",
      "organization": "SWIFT",
      "scope": "Tag-based interbank messages on the SWIFT network",
      "status": "Being phased out in favor of ISO 20022",
      "machine_readable": false,
      "website": "https://www.swift.com",
      "description": "Legacy tag-based message format used on the SWIFT network for interbank communication, such as the MT103 customer credit transfer. Cross-border payment message categories have been migrated to ISO 20022 under the CBPR+ programme, while MT remains in use for other business areas such as securities."
    },
    {
      "id": "iban-iso-13616",
      "name": "IBAN (ISO 13616)",
      "category": "Payments",
      "organization": "ISO",
      "scope": "International bank account number format",
      "status": "Active",
      "machine_readable": false,
      "website": "https://www.iso.org",
      "description": "Defines the International Bank Account Number, a standardized account identifier of up to 34 alphanumeric characters including a country code and check digits. SWIFT acts as the registration authority and publishes the per-country IBAN formats."
    },
    {
      "id": "bic-iso-9362",
      "name": "BIC (ISO 9362)",
      "category": "Reference data",
      "organization": "ISO",
      "scope": "Business Identifier Codes for institutions",
      "status": "Active",
      "machine_readable": false,
      "website": "https://www.iso.org",
      "description": "Defines the Business Identifier Code (commonly called the SWIFT code), an 8- or 11-character identifier for financial and non-financial institutions used to route financial messages. SWIFT is the ISO-designated registration authority and issues BICs."
    },
    {
      "id": "lei-iso-17442",
      "name": "LEI (ISO 17442)",
      "category": "Identity",
      "organization": "GLEIF / ISO",
      "scope": "Legal entity identification for financial transactions",
      "status": "Active",
      "machine_readable": true,
      "website": "https://www.gleif.org",
      "description": "Defines the 20-character Legal Entity Identifier used to identify parties to financial transactions. The Global Legal Entity Identifier Foundation (GLEIF) oversees the system and publishes the full LEI registry as open, machine-readable data with a public API."
    },
    {
      "id": "iso-4217",
      "name": "ISO 4217",
      "category": "Reference data",
      "organization": "ISO",
      "scope": "Currency codes and minor units",
      "status": "Active",
      "machine_readable": true,
      "website": "https://www.iso.org",
      "description": "Defines three-letter alphabetic and three-digit numeric codes for currencies (for example USD/840, EUR/978) together with their minor units. The maintained code lists are published in machine-readable form by the ISO 4217 maintenance agency."
    },
    {
      "id": "emv",
      "name": "EMV",
      "category": "Cards",
      "organization": "EMVCo",
      "scope": "Chip, contactless and tokenized card payment technology",
      "status": "Active",
      "machine_readable": false,
      "website": "https://www.emvco.com",
      "description": "Family of specifications for chip-based payment cards and acceptance devices, covering contact and contactless transactions, payment tokenisation and QR code payments. Managed by EMVCo, which is jointly owned by American Express, Discover, JCB, Mastercard, UnionPay and Visa."
    },
    {
      "id": "3-d-secure",
      "name": "3-D Secure",
      "category": "Authentication",
      "organization": "EMVCo",
      "scope": "Cardholder authentication for e-commerce transactions",
      "status": "Active (EMV 3-D Secure; original 3DS 1.0 retired)",
      "machine_readable": false,
      "website": "https://www.emvco.com",
      "description": "Protocol for authenticating cardholders in online card transactions by involving the card issuer, deployed under brands such as Visa Secure and Mastercard Identity Check. The current EMV 3-D Secure specifications add risk-based authentication and mobile support, replacing the retired 3DS 1.0 protocol."
    },
    {
      "id": "pci-dss",
      "name": "PCI DSS",
      "category": "Security",
      "organization": "PCI Security Standards Council",
      "scope": "Security requirements for handling payment card data",
      "status": "Active (v4.x)",
      "machine_readable": false,
      "website": "https://www.pcisecuritystandards.org",
      "description": "The Payment Card Industry Data Security Standard sets security requirements for any organization that stores, processes or transmits payment card data. It is maintained by the PCI Security Standards Council, founded by the major card brands, with version 4.x as the current generation."
    },
    {
      "id": "psd2",
      "name": "PSD2",
      "category": "Open banking",
      "organization": "European Union",
      "scope": "EU regulatory framework for payment services and account access",
      "status": "Active (successor package PSD3/PSR proposed)",
      "machine_readable": false,
      "website": "https://eur-lex.europa.eu",
      "description": "Directive (EU) 2015/2366 on payment services in the EU internal market, mandating strong customer authentication and giving licensed third-party providers access to payment accounts. It is the regulatory foundation of open banking in the EU/EEA; a successor package (PSD3 and the Payment Services Regulation) has been proposed."
    },
    {
      "id": "uk-open-banking-standard",
      "name": "UK Open Banking Standard",
      "category": "Open banking",
      "organization": "Open Banking Limited (UK)",
      "scope": "UK APIs for account information and payment initiation",
      "status": "Active",
      "machine_readable": true,
      "website": "https://www.openbanking.org.uk",
      "description": "API, security and customer-experience standards that the largest UK banks (the CMA9) are required to implement for account information and payment initiation, built on OAuth 2.0, OpenID Connect and FAPI. Developed by Open Banking Limited under the UK Competition and Markets Authority's Retail Banking Market Investigation Order."
    },
    {
      "id": "berlin-group-nextgenpsd2",
      "name": "Berlin Group NextGenPSD2",
      "category": "Open banking",
      "organization": "Berlin Group",
      "scope": "Pan-European PSD2 access-to-account (XS2A) API framework",
      "status": "Active",
      "machine_readable": true,
      "website": "https://www.berlin-group.org",
      "description": "Pan-European API framework for PSD2-compliant access to accounts (XS2A), published with OpenAPI specifications for account information and payment initiation. It is widely implemented by banks across continental Europe as their PSD2 API."
    },
    {
      "id": "fdx-api",
      "name": "FDX API",
      "category": "Open banking",
      "organization": "Financial Data Exchange",
      "scope": "North American consumer-permissioned financial data sharing API",
      "status": "Active",
      "machine_readable": true,
      "website": "https://financialdataexchange.org",
      "description": "Standard API for consumer-permissioned sharing of financial account data in North America, maintained by the non-profit Financial Data Exchange. It is widely adopted by US and Canadian financial institutions and data aggregators as the common alternative to screen scraping."
    },
    {
      "id": "fapi",
      "name": "FAPI (Financial-grade API)",
      "category": "Authentication",
      "organization": "OpenID Foundation",
      "scope": "High-security OAuth 2.0 / OpenID Connect profile for financial APIs",
      "status": "Active",
      "machine_readable": false,
      "website": "https://openid.net",
      "description": "Security profile of OAuth 2.0 and OpenID Connect that hardens authorization and token flows for high-value API access. Developed by the OpenID Foundation's FAPI working group and adopted by open banking ecosystems including the UK, Brazil and Australia."
    }
  ]
}