Mifos X is the open-source core banking stack built on Apache Fineract, covering loans, savings, client management, accounting, mobile banking and reporting for financial institutions. It serves more than 400 institutions and 20 million customers worldwide, providing the account-keeping layer that financial inclusion and digital payments depend on.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
4 partially met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
As an open-source core banking platform it sits in the Digital Payments domain. The same financial infrastructure serves microfinance institutions, banks and cooperatives across every sector touched by financial inclusion, with 400-plus institutions and over 20 million customers served globally.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
A full REST API is documented with a live demo and predictable, resource-oriented URLs, exchanging JSON over standard HTTP verbs and response codes. Core banking operations are well implemented, though ISO 20022 compliance is not prominently documented.
Is it a modular building block that does one thing well, rather than a monolithic platform?
The Spring Boot platform is organised into modular services that can be extended independently, with Fineract as the backend platform and Mifos X supplying reference applications such as the web client, mobile apps and reporting. Multi-tenancy is built in, giving each institution an isolated database configurable to its own context.
Can other public and private actors build on top of it?
The REST API allows any client application to be built against the platform, and community apps and integrations exist alongside 400-plus institutions running it independently. Apache Software Foundation governance under an Apache 2.0 licence keeps the project community-driven.
Can it run in distributed or federated deployments suited to national infrastructure?
Multi-tenancy with a separate database per institution supports independent deployments worldwide, self-hosted so data stays with the institution. High availability relies on standard infrastructure such as load balancers and database replication rather than built-in federation, on a single application server design.
Does it meet the security and privacy bar for population-scale infrastructure?
HTTPS, HTTP authentication, tenant isolation and role-based access control are in place. Vulnerability handling runs through the Apache Foundation security process rather than a Mifos-specific published policy, and cross-jurisdictional privacy and regulatory adaptability are not prominently documented.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA