Exterior view of a classic bank building facade with warm interior lighting and a backlit sign above the entrance.

Headless CIAM architecture for a leading CEE retail bank

Replacing an over-customised, brittle legacy customer identity and access management platform with a lean, standards-based CIAM built on FAPI 2.0.

Project Impact & Velocity

Key outcomes delivered.

99

%

Uptime promise upheld — by removing complexity, not insuring against it.

99

%

Uptime promise upheld — by removing complexity, not insuring against it.

10

CIAM platforms scored on real flows and standards conformance, not datasheets.

10

CIAM platforms scored on real flows and standards conformance, not datasheets.

9

End-to-end flows specified down to claim and token lifetime.

9

End-to-end flows specified down to claim and token lifetime.

The challenge

Two decades of customisation had pushed the bank's customer identity platform far beyond its supportable limits. Availability — not features — had become the board-level problem: every change carried outage risk, and the incoming regulatory horizon (PSD3/PSR, eIDAS 2.0) guaranteed more change, not less.

To keep the 99.95% uptime promise to their customers, we supported the bank in removing complexity, rather than insuring against it.

Glowing green biometric fingerprint icon isolated on a dark background.
Glowing green biometric fingerprint icon isolated on a dark background.

What we did

From a brittle, over-customised platform to a lean, standards-based CIAM.

Architecture

Standards over custom protocols, vanilla IdP, and zero bank-app favoritism. Two candidate architectures modelled.

Architecture

Standards over custom protocols, vanilla IdP, and zero bank-app favoritism. Two candidate architectures modelled.

Vendor selection

Ten CIAM platforms scored on FAPI 2.0 standards compliance.

Vendor selection

Ten CIAM platforms scored on FAPI 2.0 standards compliance.

The outcome

A headless CIAM powering nine end-to-end flows. Custom logic lives beside the provider, never inside.

The outcome

A headless CIAM powering nine end-to-end flows. Custom logic lives beside the provider, never inside.

The Outcome

A platform smaller than the one it replaced — and defensible to any regulator.

11 RFCs

published standards the flows are built to, not bespoke protocols

2 apps → 1

the separate authenticator app retired; customers approve payments in the banking app itself

Why it worked

Key drivers behind our success.

Root cause, not symptom

Lift-and-shift would have raised uptime without touching the over-customisation causing the outages. We tackled the harder brief because it closed the problem.

7 projects

Root cause, not symptom

Lift-and-shift would have raised uptime without touching the over-customisation causing the outages. We tackled the harder brief because it closed the problem.

Secure core

Data sync

Root cause, not symptom

Lift-and-shift would have raised uptime without touching the over-customisation causing the outages. We tackled the harder brief because it closed the problem.

Standards address risks

Every flow maps to a published RFC and a peer-reviewed threat model. We weigh residual risk, UX cost, and effort across options before selection.

4 projects

Standards address risks

Every flow maps to a published RFC and a peer-reviewed threat model. We weigh residual risk, UX cost, and effort across options before selection.

Data safety

Integrations

Standards address risks

Every flow maps to a published RFC and a peer-reviewed threat model. We weigh residual risk, UX cost, and effort across options before selection.

Designed for the day after

Custom code sits beside the identity provider, not inside it. The platform upgrades cleanly, treating future compliance shifts as configuration rather than retrofits.

5 projects

Designed for the day after

Custom code sits beside the identity provider, not inside it. The platform upgrades cleanly, treating future compliance shifts as configuration rather than retrofits.

Automation

Supply tech

Designed for the day after

Custom code sits beside the identity provider, not inside it. The platform upgrades cleanly, treating future compliance shifts as configuration rather than retrofits.

Technologies & standards

FAPI 2.0

Financial-grade API security profile — the baseline the entire identity platform is built to.

Passkey-pattern auth

Phishing-resistant, passwordless sign-in built on the passkey / WebAuthn pattern.

3-D Secure 2.x

Strong customer authentication for card payments, aligned to SCA / PSD2.

CIBA

Client-Initiated Backchannel Authentication for decoupled, out-of-band approval across devices.

Fine-grained authorization (FGA)

Policy-based, relationship-aware access decisions that go beyond coarse role checks.

Cedar

Open-source policy language that expresses fine-grained access rules as verifiable policies, decoupled from application code.

Afraid to touch your identity platform?

Afraid to touch your identity platform?

Afraid to touch your identity platform?

Expect more from your consultants.

Warsaw, Poland

office@exerizon.com

© 2026 Exerizon P.S.A.

All rights reserved

NIP: 5223288319

REGON: 52778057600000