generated: '2026-07-23' method: derived source: >- openapi/*, apis.yml description, OBIE Read/Write API Standard v4.0.1, OpenID Foundation FAPI conformance programme standards: - id: oauth2 conforms: true evidence: openapi securitySchemes declare oauth2 (clientCredentials + authorizationCode flows) - id: oidc conforms: true evidence: OpenID Connect used for PSU authentication / SCA (id_token, CIBA) - id: fapi-1.0-advanced conforms: true evidence: >- FAPI 1.0 Advanced profile — x-fapi-* headers, mTLS sender-constrained tokens, detached JWS (x-jws-signature); validated with the OpenID Foundation conformance suite per apis.yml. - id: fapi-ciba conforms: true evidence: PSD2 SCA implemented as a CIBA decoupled (poll-mode) flow - id: mutual-tls conforms: true evidence: mTLS client authentication using OBIE/eIDAS certificates - id: psd2 conforms: true evidence: FCA-authorised ASPSP exposing a PSD2 dedicated interface (AIS/PIS/CBPII) - id: obie-read-write-4.0 conforms: true evidence: OpenAPI documents are the OBIE Read/Write Account, Payment and Funds Confirmation v4.0.1 specs - id: jws-message-signing conforms: true evidence: x-jws-signature detached-signature header on payment operations - id: rfc9457-problem-details conforms: false evidence: errors use the OBIE OBErrorResponse1 envelope (application/json), not application/problem+json - id: fhir-r4 conforms: false - id: scim2 conforms: false compliance_program: published_certifications: [] note: >- Kroo is a PRA/FCA-regulated UK bank with FSCS deposit protection, but no public SOC 2 / ISO 27001 / PCI DSS trust-center page or certification listing was found. Regulatory posture is prudential (banking licence) rather than a published infosec-certification program, so no `Compliance` pointer is emitted.