Nepal Open Banking Guidelines 2026: What Banks and Fintechs Need to Know

Nepal Rastra Bank’s draft Open Banking Framework sets out API standards, consent rules, licensing requirements, and phased compliance deadlines for banks and fintechs. The guidelines aim to foster competition, protect consumers, and enable new financial services while imposing strict security and reporting obligations.

Aug 27, 2026 - 07:55
 0
C Copyright Protected

Proposed Open Banking Framework

Nepal Rastra Bank has published a draft Open Banking Framework that would let licensed banks and approved fintech firms share customer‑permitted data through secure APIs. The Nepal Open Banking Guidelines 2026 aim to boost competition, encourage new financial products, and give consumers more control over their financial information. Details are available in the regulator’s circular on the NRB website (Nepal Rastra Bank Open Banking Framework).

Technical API Standards and Security

The draft calls for RESTful APIs based on the OpenAPI 3.0 specification. Transport must use TLS 1.2 or higher, and mutual TLS authentication is required for every endpoint. Data payloads are to be encrypted at rest with AES‑256, and audit logs must be retained for a minimum of five years. A sandbox environment is also provided so participants can test compliance before going live.

Customer Consent and Data‑Sharing Scope

Consent sits at the core of the regime. Customers must give explicit, granular permission for each data category — accounts, transactions, credit‑worthiness indicators, and payment initiation. Consent records will be stored in a centralised consent registry operated by the regulator, and users can revoke access at any time through a standardized dashboard. The framework limits sharing to data that is strictly necessary for the requested service, preventing blanket access.

Licensing and Registration for Fintech Participants

Fintech companies that want to consume bank APIs must obtain a "Data Access Licence" from Nepal Rastra Bank. The application requires a business‑model description, proof of capital adequacy, a data‑protection impact assessment, and a commitment to the regulator’s code of conduct. Approved firms receive a unique identifier that must be included in every API call. Existing payment‑service providers can apply for a streamlined amendment to their current licence.

Compliance Timelines, Reporting and Penalties

The rollout is phased. Phase 1, covering core account and transaction APIs, proposes a mandatory deadline of 30 September 2026 for all commercial banks. Phase 2, which adds credit‑scoring and payment‑initiation endpoints, sets a target date of 31 March 2027. Participants must submit quarterly compliance reports detailing API uptime, consent‑revocation rates, and any security incidents. Non‑compliance attracts fines ranging from 0.5 percent to 2 percent of the entity’s annual turnover, and repeated breaches can lead to licence suspension.

Practical Steps for Banks and Fintechs

First, map every data set to the consent categories defined by the regulator. Second, build or upgrade API gateways to support mutual TLS and the required logging format. Third, integrate the centralised consent registry into onboarding flows so that consent capture and revocation are automated. Fourth, run end‑to‑end tests in the official sandbox before the Phase 1 deadline. Finally, appoint a dedicated compliance officer who will own the quarterly reporting cycle.

Expected Impact on Innovation, Competition and Consumer Protection

By standardising data access, the framework lowers the barrier for new entrants such as budgeting apps, alternative‑lending platforms, and personalized insurance services. Banks that embrace the APIs early can monetise data‑as‑a‑service while deepening customer relationships. For consumers, the consent dashboard and revocation rights translate into greater transparency and the ability to switch providers without losing financial history. Overall, the guidelines are positioned to accelerate Nepal’s shift toward a more open, competitive, and consumer‑centric financial ecosystem.

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow