Bank website development, and web design for banks generally, is a compliance project with a design phase

A bank's website is a regulated surface. Deposit and lending pages carry disclosure obligations, accessibility is an enforcement area for financial institutions, vendors are examined as part of the institution's own risk management, and security expectations apply to everything customer facing. Treated as a design project, it produces a site that has to be rebuilt.

Disclosure rules apply to the pages themselves

Advertising deposit accounts and consumer credit brings specific requirements about what must be stated and how prominently, including the terms that must accompany a rate or a payment figure. These are content rules with layout consequences, so the templates have to accommodate them properly rather than treating disclosure as small print added at the end.

Accessibility is examined, not optional

Financial institutions are a focus for accessibility enforcement and complaints, so the site should be built to a recognised standard and tested with assistive technology rather than only with an automated checker. Retrofitting is expensive, and an overlay does not make an inaccessible site compliant.

The supplier is part of the risk assessment

Bank regulators expect institutions to manage third party relationships, which means the web supplier's security, continuity and subcontracting are examined alongside the bank's own. That lengthens procurement and it is not negotiable, so build the due diligence into the timetable rather than discovering it midway.

Authentication and the boundary to online banking

The marketing site and the banking application are usually separate systems, and the join between them is where security and clarity problems appear. Make the transition obvious to the customer, keep the marketing site free of anything that collects credentials, and be explicit about which pages are which.

Questions people ask about bank website development

Can a bank use a common content management system?

Many do, with hardening, controlled plugins and a managed update process. The platform matters less than the controls around it and the ability to evidence them during an examination.

Who approves page content?

Compliance, and the workflow should be built into the publishing system with a record of approvals. A process that lives in email becomes the reason pages go live unapproved.

How should rates be published?

Through a controlled source with an effective date and the required accompanying terms, rather than typed into pages by hand. Hand edited rates across many pages are the most common disclosure failure on bank sites.

Does the marketing site need the same security as banking?

It needs to be secure and monitored, because a compromised marketing site can be used against customers. It should not be handling credentials at all, which is exactly why the boundary must be clear.

Sources

Related answers

Get your agency shortlistDescribe your project