Overview
ISO/TR 21941:2017 is a Technical Report from ISO that documents research into the interface between third‑party payment service providers (TPPs) and account servicing payment service providers (ASPSPs). It summarizes the global TPP landscape (Europe, Asia, Americas, Oceania, Africa), defines key terms (for example PISP and AISP), and reports findings on secure interfaces, reference models and potential future developments. The report uses the revised PSD2 framework as a primary reference point for terminology and regulatory context.
Key topics and requirements
- TPP types and roles: Distinguishes payment initiation service providers (PISPs) and account information service providers (AISPs) and their interaction with ASPSPs.
- Security principles: Emphasis on strong customer authentication (SCA), protection of personalized security credentials, end‑to‑end encryption, segregation of duties, and least‑privilege access controls.
- Authentication & authorization:
- Entity authentication - ASPSPs must verify that an accessing TPP is approved (contractually or via whitelist).
- Strong customer authentication - PSU (payment service user) must be authenticated before granting access or executing transactions.
- Authorization workflows - ASPSP authorizes transaction requests prior to execution.
- Data protection: Confidentiality, integrity and availability expectations for account data handled by TPPs; handling of sensitive payment data and privacy compliance.
- Interfaces & APIs: The report discusses the move to external APIs for secure connectivity between TPPs, merchants and banks and the need to avoid storing user credentials - recommending standards like OAuth or SAML for delegated access.
- Operational models: Bilateral contractual models, multilateral schemes, and the concept of a gatekeeper to manage TPP participation and compliance.
Applications and who uses it
ISO/TR 21941:2017 is practical for:
- Banks and ASPSPs designing secure interfaces and API governance to allow TPP access.
- Fintechs and TPPs (PISPs/AISPs) building compliant payment initiation and account aggregation services.
- Security architects and developers implementing SCA, token‑based access and secure API patterns.
- Regulators and scheme operators assessing multilateral access models, whitelisting and gatekeeper functions.
Use cases include API design reviews, risk assessments for third‑party access, and aligning operations with PSD2‑style requirements.
Related standards and references
- PSD2 (EU Payment Services Directive 2) - used as a key reference for terms and regulatory expectations.
- Protocols referenced in the report: OAuth, SAML (for secure delegated access).
- Prepared by ISO/TC 68 (Financial services) - useful context for standards alignment.
ISO/TR 21941:2017 is a practical research‑based resource for organizations implementing secure, standards‑aware third‑party payment access and API ecosystems.