TPP Assurance

TPP Continuity Assurance

Prove that existing TPP registrations continue to operate correctly across the Directory migration.

TPP continuity
94%assured

162 of 172 assessed registrations fully validated against the Bank's configured continuity controls.

The Accelerator provides technical assurance and evidence against the Bank's configured controls. It does not authorise TPPs or make regulatory trust decisions.

Existing registered TPPs184
TPPs assessed172
Fully validated162
Not yet assessed12
Evidence coverage91%

Existing TPP Continuity

3 TPPs at risk of migration disruption

Existing TPP registration and Directory migration are separate concerns. A failed continuity control does not mean the TPP must repeat dynamic client registration — the underlying cause and its owner are shown for each affected TPP.

Common Migration Issues

Failures aggregated by root cause — fix one underlying issue rather than many TPP symptoms

Population view
  • CriticalKeyfactor trust chain missing from Bank trust storeFND-1045
    BLAST RADIUS: 17 TPPsSystems: Open Banking API Gateway, NGINX Reverse ProxyOwner: Bank PKI TeamAction: BANK
  • CriticalLegacy Directory lookup in TPP Registration ServiceFND-1042
    BLAST RADIUS: 184 TPPsSystems: TPP Registration ServiceOwner: API EngineeringAction: BANK
  • CriticalOAuth audience references legacy token endpointFND-1043
    BLAST RADIUS: 184 TPPsSystems: Jans IAM, Open Banking API Gateway, TPP Registration ServiceOwner: IAM EngineeringAction: BANK
  • HighRole difference between Bank registration and Directory recordFND-1046
    BLAST RADIUS: 4 TPPsSystems: TPP Registration ServiceOwner: Open Banking ArchitectureAction: INVESTIGATION REQUIRED
  • MediumCRL distribution point intermittently unavailableFND-1055
    BLAST RADIUS: 172 TPPsSystems: Certificate Validation ServiceOwner: Network EngineeringAction: BANK

Cutover sub-gates

Feeds the Existing TPP Continuity gate in the Cutover Control Centre

Cutover
  • PASSExisting registrations preserved
  • FAILDirectory identity resolution
  • PASSEntrust certificate continuity
  • FAILKeyfactor certificate readiness
  • WARNINGDual trust
  • PASSSSA validation
  • WARNINGRole / permission validation
  • WARNINGRepresentative end-to-end testing
  • FAILCritical TPP exceptions
  • WARNINGEvidence completeness

TPP continuity control library

20 controls across registration, Directory, roles, certificates, SSA and end-to-end

TPP-REG-001Existing client registration preservedPASS
TPP-REG-002Existing Client ID recognisedPASS
TPP-REG-003Existing registration correlates to Directory organisationPASS
TPP-REG-004Client metadata remains validPASS
TPP-DIR-001TPP organisation resolves in new DirectoryFAIL
TPP-DIR-002Organisation identity matches Bank registrationPASS
TPP-DIR-003Software identity matchesWARNING
TPP-ROLE-001TPP roles successfully retrievedPASS
TPP-ROLE-002Bank authorisation aligns with Directory role informationWARNING
TPP-CERT-001TPP certificate validatesFAIL
TPP-CERT-002Entrust certificate trust validated where applicablePASS
TPP-CERT-003Keyfactor certificate trust validated where applicableFAIL
TPP-CERT-004Dual-trust capability validatedWARNING
TPP-REV-001Certificate revocation checking validatedWARNING
TPP-SSA-001SSA signature validation succeedsPASS
TPP-JWKS-001Signing key successfully resolvedWARNING
TPP-E2E-001Existing TPP completes mTLSPASS
TPP-E2E-002Existing client recognised by IAMPASS
TPP-E2E-003TPP identity and permissions resolvedWARNING
TPP-E2E-004Open Banking API access succeedsPASS