Bank integration · Nordea

How to connect your ERP or system to Nordea.

Nordea offers two corporate connectivity paths: Corporate Access Webservice for quick, automatic integration in Scandinavia, and E-Gateway for global enterprises on PGP-encrypted SFTP. BankConnector supports both, handles the certificates, the keys, the message formats and the test scripts, so your product just calls one JSON API.

Nordea connectivity profile

Channels, formats, markets.

Bank
Nordea Bank Abp
Markets
Scandinavia (FI, SE, NO, DK) · UK (CAW) · Global (E-Gateway)
Connectivity channels
Nordea Corporate Access Webservice (CAW) · Nordea E-Gateway (PGP-encrypted SFTP)
Outgoing payments
pain.001.001.03 · pain.001.001.09 · pain.001 standard (E-Gateway)
Status reports
pain.002.001.03 acknowledgements and rejections (fast on E-Gateway)
Statements
camt.053 end-of-day · camt.052 intraday · camt.054 debit/credit notifications
Special features
CAMT.055 payment cancellation requests (CAW) · Automated test-script validation (E-Gateway)
Security
Nordea-issued client certificate (CAW) · PGP encryption with SSH authentication (E-Gateway)
Typical onboarding
A few minutes (CAW) · 2 to 4 weeks (E-Gateway)

Channel 1

Corporate Access Webservice.

The quick and automatic option for Scandinavian accounts (and partly UK). Setup is as easy as it gets: you provide a Signer ID, Sender ID, Username and an SMS activation that Nordea sends to your Bank Administrator (valid for 7 days). Your Corporate Access Agreement number is handled automatically in the files.

Message formats

Supports pain.001.001.03 and the newer pain.001.001.09, which is Nordea's new scheme for all payments. BankConnector follows their migration closely.

Payment cancellations

Nordea CAW is one of the few banks that have adopted the CAMT.055 scheme, allowing clients to send payment cancellation requests. BankConnector supports this fully.

Stability

A very stable and reliable service we have had great success with across hundreds of integrations.

Channel 2

E-Gateway.

Nordea E-Gateway is targeted at global enterprises. We usually see it when working with clients in the US and Canada, but it is truly a global gateway. Integration is built on a PGP-encrypted SFTP connection with SSH authentication.

Key exchange

You exchange encryption keys with the bank through their secure messaging. BankConnector makes these steps easy and describes the exact process end to end.

Test scripts

When signing an E-Gateway agreement, Nordea hands you their test scripts: a long list of test payments they require before production. BankConnector automates all of it, so you can satisfy their requirements with a few clicks.

Enterprise grade

E-Gateway is heavier than CAW and takes longer to set up, but it is a fantastically stable and reliable service. Supports pain.001, camt.053, camt.054 and returns pain.002 acknowledgements faster than average.

Why integration quality matters

Anyone can POST a file to Nordea. Doing it properly is the hard part.

There are a lot of shortcuts vendors take to get a green checkmark in a demo. Skip the signature check. Fire-and-forget the upload. Call it integrated. It works right up until the day it quietly does not, and with payments, quietly does not means real money in the wrong place.

We do not build it that way. If you care about security and usability the way we do, you do the unglamorous work:

Verify bank signatures

Every response and statement file from Nordea is cryptographically verified before we trust a single byte of it. If a file is not signed by Nordea, it does not enter your reconciliation.

Sign our own requests properly

Outbound payment files are signed per the Corporate Access spec, with keys that are encrypted at rest and never logged. Your signing material is treated like the crown jewels, because it is.

Handle duplicates, every time

Network blips, retries, and double-clicks happen. We use end-to-end identifiers and idempotency checks so a payment is submitted once. A resend never becomes a second debit.

Reconcile status, do not assume it

We do not mark a payment done because the upload returned 200. We read Nordea's pain.002 acknowledgements and camt statements back, match them to what we sent, and tell you the real state: accepted, rejected, or pending, with the reason.

Fail loudly and recover gracefully

Rejections surface with the bank's actual reason code, not a generic error. Retries are deliberate and bounded. Nothing important fails in silence.

Encrypt the sensitive bits end to end

Credentials, signing keys, and personal data are encrypted in transit and at rest. Not as a checkbox, but as the default everything else is built on.

The lazy version of this integration is faster to ship. Ours is the one you actually want sitting between your ERP and your bank account.

How a Nordea integration goes live

From signed agreement to first reconciled payment.

Corporate Access Webservice

  1. 1. Signed agreement. You sign the CAW agreement with Nordea, listing the accounts and services.
  2. 2. Enter information in BankConnector. Provide your Signer ID, Sender ID, Username and SMS activation. BankConnector handles the rest. There is no sandbox and no test environment.
  3. 3. Production. You are live. Onboarding takes a few minutes from the moment the agreement is signed!Wait?? Legacy Bank Integrators really charges thousands for this process?

E-Gateway

  1. 1. Signed agreement. You sign the E-Gateway agreement with Nordea.
  2. 2. Exchange keys. You exchange PGP encryption keys with Nordea through their secure messaging.
  3. 3. Send test payments. Nordea requires their test-script payments to be sent before production. BankConnector automates this.
  4. 4. Move to production. After successful test-script validation, you switch to production. Typical onboarding is 2 to 4 weeks.

Things teams ask about Nordea

Common questions.

Which Nordea channel should I use?

For Scandinavian accounts (and partly UK), use Corporate Access Webservice. It is quick and automatic. For global enterprises, especially US and Canada, use E-Gateway on PGP-encrypted SFTP.

What do I need to set up CAW?

A Signer ID, Sender ID, Username and an SMS activation sent to your Bank Administrator (valid for 7 days). Your Corporate Access Agreement number is handled automatically.

How do E-Gateway test scripts work?

Nordea requires a long list of test payments before production. BankConnector automates the entire script, so you satisfy their requirements with a few clicks or run the full end-to-end suite.

Does Nordea support payment cancellations?

Yes, on Corporate Access Webservice. Nordea is one of the few banks that have adopted the CAMT.055 scheme, and BankConnector supports it fully.

How long does onboarding take?

CAW is typically 1 to 2 weeks. E-Gateway is 4 to 8 weeks because of key exchange, setup and test-script validation.

Can we run sandbox payments first?

E-Gateway has a test environment where we run the automated test-script suite before production. Corporate Access Webservice has no sandbox: once the agreement is signed, you enter your credentials in BankConnector and go straight to production.

Ready to connect your Nordea accounts?

Talk to us about your accounts, your country footprint and the channel you want to use. We will tell you exactly what Nordea needs you to sign and how soon you can be live.