Brankas
Brankas
Open Banking & Regulation

Oman's Open Banking Sandbox: How CBO's Approach Compares Regionally

Brankas Team September 15, 2026
Oman's Open Banking Sandbox: How CBO's Approach Compares Regionally

The Central Bank of Oman has taken a sandbox-led, sequenced route to open banking: a fintech regulatory sandbox in 2020, published API specifications in 2023, and an approved Open Banking regulatory framework in December 2024. That is a more gradual, test-and-learn path than Bahrain’s early mandate or the UAE’s centralized national hub. This piece compares CBO’s approach with its regional peers, and what the differences mean for banks and fintechs.

What is the Central Bank of Oman’s approach to open banking?

CBO has built open banking in stages rather than through a single mandate. It launched a Fintech Regulatory Sandbox in December 2020, opening with payments use cases and requiring a minimum six-month live test under supervision. It then published open banking API specifications in April 2023 as a reference for banks. In December 2024, its board approved a formal Regulatory Framework for Open Banking covering data security, standardized APIs, consent management, and authentication. The through-line is deliberate sequencing: test first, standardize second, regulate third.

The Central Bank of Oman has taken a sandbox-led, sequenced route to open banking: a fintech regulatory sandbox in 2020, published API specifications in 2023, and an approved Open Banking regulatory framework in December 2024. That is a more gradual, test-and-learn path than Bahrain’s early mandate or the UAE’s centralized national hub. This piece compares CBO’s approach with its regional peers, and what the differences mean for banks and fintechs.

What does Oman’s draft open banking framework actually cover?

The framework is more than a set of API standards; it outlines a full licensing regime. Third parties that want to offer open banking services must be licensed by CBO as an Account Information Service Provider (AISP) or a Payment Initiation Service Provider (PISP), the same account-information and payment-initiation split used across the GCC. Banks and other data holders do not need a separate license, but they must share customer data, on the customer’s permission, without undue delay and in real time, and may charge access fees under a model the central bank sets.

Consent sits at the center. The framework requires permission dashboards, re-validation of consent every year, and automatic expiry after 180 days without use, so access stays bounded rather than open-ended. Around that, the regulations span data protection, cybersecurity, governance and AML controls, fair-conduct rules (screen-scraping is explicitly prohibited), customer protection, and a defined exit process for departing participants.

How does Oman classify open banking APIs?

The framework’s most commercially revealing detail is how it treats APIs for monetization. API services are sorted into three tiers. Basic APIs cover read-only information, and CBO recommends they not be charged for. Standard APIs carry restricted transactional data such as account and customer details. Premium APIs expose the full data set and the highest-value functions, with the framework naming credit scores, payment initiation, and bill payments. Only the Basic tier is expected to be free, which makes Standard and Premium the revenue layer of Oman’s open banking market.

CBO goes further than most regional peers in spelling out how that revenue can work, setting out models from freemium and pay-per-call to data-exchange, transaction, and subscription pricing, and requiring each participant to test its monetization model in the sandbox before launch. Notably, the framework’s API specifications are illustrative rather than prescriptive; it states plainly that these are not actual APIs and leaves the design to participants. That is a lighter touch than Bahrain’s or Saudi Arabia’s prescriptive API standards, and it reinforces the participant-driven character of Oman’s approach.

How does Oman’s sandbox-led approach differ from its neighbours?

The GCC has converged on the goal of open banking but split on the method. Three broad models are visible in the region, and Oman sits clearly in the most gradual of them.

Bahrain moved first, mandating open banking in 2018 with a 2019 compliance deadline and setting prescriptive standards for account information and payment initiation. Saudi Arabia paired a formal framework with an Open Banking Lab to certify and test participants at scale. The UAE went furthest on centralization, routing connectivity through a single national platform. Against those, Oman’s path is the most incremental: it is building the components in order rather than compelling the market to connect by a fixed date. The regional prize is large: open banking users across the Middle East are projected to grow around fivefold to more than 130 million within a few years, which raises the cost of moving too slowly.

Why does a sandbox-led approach make sense for Oman?

For a smaller market, sequencing lowers the cost of getting it wrong. A sandbox lets the regulator observe real use cases, refine API standards against live testing, and build supervisory capacity before imposing obligations on every bank. It also gives Oman’s banks, many of which run leaner technology teams than the largest regional players, time to prepare rather than a compliance cliff. The published API specifications give the market a common reference, and the 2024 framework signals that the direction is settled even if the timeline is not.

What are the limits of the sandbox-led model?

A sandbox-led approach tends to produce a slower, thinner ecosystem than a mandate, because participation is opt-in until obligations bite. Without a firm go-live date or a central hub, connectivity can fragment into bilateral integrations that are expensive to build and hard to supervise, the exact problem that Bahrain’s mandate and the UAE’s hub were designed to avoid. Approving a framework is also not the same as operationalizing it: the commercial value only appears when banks expose production APIs and third parties can rely on them. On that measure, Oman still has distance to close against Bahrain and Saudi Arabia, which already have live services and certified participants. The risk is not the direction but the pace.

What does this mean for banks and fintechs in Oman?

For banks, the sandbox window is a chance to treat open banking as product rather than compliance, and to build the API and consent infrastructure before it is mandatory. For fintechs, Oman is an earlier-stage market than Bahrain or Saudi Arabia, which means less competition but also thinner rails to build on, so the near-term opportunity sits in sandbox-tested use cases such as account information and payments. In both cases, the practical lesson from more advanced regional markets is the same: the winners are the institutions that build to a standard early and partner for implementation speed, rather than waiting for the mandate to force the work.

Frequently asked questions

When did Oman approve its open banking framework?

The Central Bank of Oman’s board approved the Regulatory Framework for Open Banking in December 2024, following a fintech regulatory sandbox launched in 2020 and API specifications published in 2023.

Is open banking mandatory in Oman?

Oman’s approach has been sandbox-led and sequenced rather than a hard mandate. CBO has approved a regulatory framework and published API standards, but its path has emphasized supervised testing and staged adoption rather than a fixed compliance deadline like Bahrain’s.

What is the CBO Fintech Regulatory Sandbox?

It is a supervised environment, launched in December 2020, where fintechs can live-test solutions under CBO oversight, starting with payments use cases and requiring a minimum six-month test period.

How does Oman compare to Bahrain and Saudi Arabia?

Bahrain mandated open banking early and is the regional pioneer, and Saudi Arabia built a framework plus an Open Banking Lab with live services. Oman is at an earlier stage, sequencing a sandbox, API specifications, and a 2024 framework rather than compelling connection by a set date.

What services does open banking in Oman cover?

The framework covers standardized APIs, data security, consent management, and authentication, with early sandbox activity centered on account information and payments, consistent with the account information and payment initiation services seen across the GCC.

Brankas builds the Open Finance Suite and helps banks and regulators turn open banking frameworks into working, revenue-ready infrastructure.

Building for open banking in Oman or the wider GCC? Talk to our team.

Circular 64/2024/TT-NHNN: Vietnam's Open API Mandate, From Compliance to Commercialization
Open Banking & Regulation 03/09/2026
Circular 64/2024/TT-NHNN: Vietnam's Open API Mandate, From Compliance to Commercialization

In December 2024, the State Bank of Vietnam issued Circular 64/2024/TT-NHNN, making Open API a legal requirement for banks. It took effect on 1 March 2025 and requires full compliance by 1 March 2027, setting standards for consent-based data sharing and payment initiation with licensed third parties. But the same infrastructure that satisfies the regulator also opens new revenue: embedded lending, account-to-account payments, and data products. This piece explains what Circular 64 requires, and where the commercial upside sits for banks and fintechs.