Open Banking Innovation vs Legacy Systems
Deploy API middleware and microservices architecture to satisfy NIS2 resilience obligations without destabilising regulated core banking systems.
CyberTRIZ analysis · Banking contradiction OB023 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Business Context
Banks continue introducing innovative Open Banking services while many core banking platforms were designed long before API ecosystems existed.
Banking TRIZ Resolution
Integrate modern API services through middleware, event-driven architecture, and microservices rather than replacing core systems immediately.
Recommended Principles
Principle 7 - Nested Doll
Principle 24 - Intermediary
Principle 40 - Composite Materials
Expected Outcome
Faster innovation
Lower modernization risk
Better platform stability
TRIZ principles applied
P7 Nested DollP24 IntermediaryP40 Composite Materials
Controls that address this (22)
EU_NIS2-CTRL-001 - Daily safeguarding reconciliationoperational · critical priority · Daily reconciliation between safeguarded customer balances, core ledger balances and safeguarded bank accounts. Variances above EUR 100 mustEU_NIS2-CTRL-002 - Critical ICT incident reportingoperational · critical priority · All major ICT incidents impacting payment services, customer data or availability must be classified within 4 hours and reported under DORA EU_NIS2-CTRL-003 - GDPR breach notification workflowoperational · critical priority · Personal data breaches must be assessed within 12 hours and reported to the Belgian DPA within 72 hours where risk to data subjects exists.