Select Page

Built to the Highest Security Standard: What Qwist’s ISO 27001:2022 Certification Means for Your Business

Discover how our zero-finding audit eliminates procurement friction, fast-tracks your third-party risk management, and delivers the audit-ready evidence your regulators demand.

Financial institutions handle arguably the most sensitive user data in existence: personal identifications, bank account numbers, credit histories, and detailed spending records. It is, rightfully, one of the most regulated industries in the world. Information security has long been a priority for financial institutions, who are acutely aware of the reputational damage a mismanaged breach can cause. But recent regulations, like DORA, have forced a more fundamental shift. The financial ecosystem is now expected to approach risk and cybersecurity holistically, moving beyond the protection of its own assets and the interfaces to its providers. Financial institutions are now accountable for the security of their entire supply chains. That changes the underlying contract between financial institutions and their providers: open finance providers have become an integrated part of the critical infrastructure that financial institutions must secure.

For vendors, claims of security robustness are no longer sufficient. Partners now expect tangible, documented evidence that cyber threats are being effectively mitigated. ISO 27001:2022 is the global information security standard that provides this independent verification. It requires a rigorous examination of a business’s Information Security Management System (ISMS) to confirm that it effectively addresses security threats and has continuous monitoring and improvement processes in place.

Zero corrective actions

ISO 27001:2022 has become a baseline expectation for open banking providers. Starting from asset inventory, the certification demonstrates that cyber risk is understood and mitigated with appropriate controls, across all channels. Where Qwist stands out is in the result: the 2025 certification audit carried out by TÜV Nord found Qwist’s entire product range to be fully compliant, with zero corrective actions required. Zero non-conformities places Qwist in a small minority of fintechs. That outcome reflects the maturity of Qwist’s security posture:

  • The certification covers the entire product portfolio and all data processed, not a subset of products or operations
  • Achieving zero non-conformities during certification demonstrates that Qwist’s controls are not just designed correctly, but are operating with sustained, continuous effectiveness
  • A strong security culture and active management commitment were decisive factors in this rare result. 

Behind the certificate

ISO 27001:2022 certification is a point-in-time verification, but it is designed to ensure that ISMS processes endure and that improvement cycles remain active. At Qwist, this is embedded in how we operate:

  • Security performance is assessed through audit findings and automated scanning fully integrated in CI/CD pipelines
  • The control set is continuously monitored and improved to ensure information security and regulatory requirements continue to be met as the business evolves
  • Beyond ISO 27001:2022, Qwist undergoes both internal and external DORA audits annually, ensuring security posture is validated against the EU’s most demanding regulatory standards

What it means for financial institutions

Under DORA, EU financial institutions are responsible for the security of their entire supply chains, including providing regulators with evidence that all vendors meet DORA standards. Working with an ISO 27001:2022-certified vendor materially reduces that third-party vetting burden:

  • Independent auditor verification means financial institutions can fast-track security questionnaires, replacing months of manual back-and-forth with documented, audit-ready evidence and building genuine trust from the outset
  • Under DORA Article 28, financial entities must maintain a Register of Information covering all ICT third-party arrangements, supported by pre-contractual due diligence and ongoing monitoring. Independently audited evidence is exactly the documentation that feeds into that register and due diligence process
  • ISO 27001:2022 directly maps with DORA’s ICT risk management requirements.  Annex A controls, including Information Security for Use of Cloud Services (A.5.23) and Configuration Management (A.8.9), address the technical pillars mandated in DORA. Articles 6 through 16, covering ICT risk management frameworks, business continuity, and testing requirements.

Qwist’s ISO 27001:2022 certification reduces procurement friction, accelerates onboarding, and standardises security expectations across markets. Qwist’s ISO 27001:2022 certification is designed to do the compliance heavy lifting on your behalf, minimising your third-party risk management (TPRM) workload and transforming exhaustive, manual security questionnaires into an accelerated, audit-ready verification process. 

“Trust is the currency of Open Finance. Our clients are sharing sensitive data through our infrastructure, and they deserve more than an assurance that their data is protected — they deserve evidence. The 2025 ISO 27001:2022 certification audit with zero corrective actions, carried out by TÜV Nord across our entire product portfolio, is that evidence. The result reflects the security mindset that our teams have built into their workflows, and our ongoing commitment to meet that rigorous standard, audit after audit.” — Glenn Mac Donald, CEO

Request Qwist’s ISO 27001:2022 audit report

As cyber threats continue to evolve, financial institutions need evidence their entire supply chain is continuously adapting to new threats. The ISO 27001:2022 certification is not the finish line; it’s a milestone. Continued investment in people, processes, and controls keeps zero corrective actions the expectation, not the exception. For clients building on Qwist infrastructure, that means verified, ongoing assurance that rigorous compliance is native to every product and API they use.

Contact us to request a copy of the TÜV Nord audit report.

Person multitasking with a laptop and smartphone, reading online content.

Newsletter subscription

Stay up to date with all Open Finance news
Subscribe to the free newsletter now

Person multitasking with a laptop and smartphone, reading online content.

Newsletter-Anmeldung

Bleiben Sie up-to-date bei allen News rund um Open Finance
Jetzt zum kostenlosen Newsletter anmelden

Person multitasking with a laptop and smartphone, reading online content.

Inscripción al boletín

Manténgase al día con todas las noticias sobre Open Finance
Regístrese ahora al boletín gratuito

Latest from Qwist