Frameworks · Americas
OFDSS
The Open Finance Data Security Standard (OFDSS) sets 79 security requirements across 13 control domains. It is written for cloud-native financial technology companies that handle sensitive consumer financial data, such as income, employment and account information. A consortium of open-finance data providers created it. It is maintained at ofdss.org, with implementation guidance and audit steps for each requirement.
Who it applies to
It applies to fintech companies, data aggregators and their partners that access or process consumer financial data. It also applies to any company that an open-finance platform asks to demonstrate OFDSS alignment.
Main requirements
Control domains
The 13 domains cover governance, access, data protection, application and infrastructure security, monitoring and incident response.
Requirements
The standard has 79 requirements, each with implementation guidance and audit steps.
Consumer data
The standard covers how sensitive financial and identity data is handled, from collection to deletion.
Attestation
Organisations self-assess or use a third-party assessment against the standard's audit steps.
How xmodo supports it
- 1
The 79 requirements are set up as controls, and the standard's audit steps become evidence requirements.
- 2
Requirements map to SOC 2 and ISO/IEC 27001, which satisfy most OFDSS requirements, and to PCI DSS where card data is in scope.
Related frameworks
OFDSS shares requirements with the frameworks below. Controls you already run for any of them count towards OFDSS as well.
Frequently asked questions
Is OFDSS a certification?
It is a standard with defined audit steps. Organisations self-assess or engage a third party. xmodo runs either as an engagement and publishes the result in the trust center.