Cybersecurity risk governance and fraud management in invoice-tax data sharing for credit scoring: A tripartite framework for Vietnam
Abstract
Purpose - Decree 70/2025 and Decree 94/2025 in Vietnam established a tripartite data pipeline that shares real-time e-invoices from the General Department of Taxation (GDT) to credit institutions for enterprise credit scoring. Prevailing Third-Party Risk Management (TPRM) frameworks, including DORA, NIST CSF 2.0, the FSB TPRM Toolkit, and BIS BCBS d577, address private-sector relationships and do not cover risks specific to government-as-data-provider architectures, such as non-terminability, monopoly provision, and accountability fragmentation. No existing TPRM standard accounts for a government agency serving as the sole, non-terminable data source in private-sector credit scoring, leaving this configuration in a governance vacuum.Method - Using Design Science Research (DSR) methodology, we conducted a comparative regulatory analysis of Decree 94/2025 and constructed a threat taxonomy. Building on this taxonomy, we designed the Tripartite Governance Framework for Vietnam (TGF-VN v1.0) through analogical transfer from HIPAA, Singapore's MyInfo, and the SWIFT Customer Security Controls Framework.Findings - Our analysis identifies 10 regulatory gaps in areas including API security, accountability, and breach notification, and 16 threat vectors across API, transmission, and invoice-fraud layers. TGF-VN v1.0 comprises 12 integrated controls that address these exposures and provide the structural basis for the State Bank of Vietnam's (SBV) implementing circulars.Originality - The framework also yields a replicable governance template for similar government-data-sharing initiatives across ASEAN and emerging markets.