SlideShare una empresa de Scribd logo
1 de 12
PSD2: What You Need to Know
Harsh Upreti
Payments Services Directive –
PSD21
What is PSD2
PaymentsServicesDirective- 2
• ADirective(LegalAct)ofEuropeanUnion
• Itrequiresthememberstatestoregulatepaymentservicesandpaymentserviceproviders
• Itaimstoincreasecompetitioninthepaymentsindustryandincreaseparticipationofnonbanks
• Italsoaimstoprotectconsumerrightsandprovideconsumerswithawidevarietyofpaymentservices
• TherulesforPSD2aredraftedbytheEuropeanCommissionandapprovedbyEuropeanParliament
• PSD2isamoreinnovativeandenhancedthanPSD,whichisalreadyinplace
What is PSD2 Cont..
PSD2 aims to establish a levelplaying fieldbetweenbanks and Third Parties -FinTech's
Major players in the PSD2 Ecosystem:
Customers
Banks
Third Parties
FinTech's
Government
Expose
Customer
Data for Third
Parties
Consume
Customer data
from Banks
Define and Control
Implementation
Rules
New Entrants
How will PSD2 alter the landscape?
Maya
Bank Bank
Before
Bank App Bank App
Two logins
Not a single view
After
PISP AISP
Bank Bank
BankApp
BankApp
API Gateway API Gateway
TPP App
Maya
Single view and login
Third Party Providers - TPPs
What arethe types of TPPs impactedby PSD2
PISP - Payment Initiation Services
Providers
AISP - Account Information Services
Providers
Companies which access customer’s
bank accounts to transact e.g. debit &
credit
Companies which can access customer
account data to provide financial
management services
Regulatory Technical Standards - RTS
PSD2 has defined technicalrules that banks and TPPs haveto adhere to.
ByreferencetoArticle115(4)PSD2,theRTSwillbeapplicable 18monthsafteritsentryintoforce,whichwouldsuggestan
applicationdateoftheRTSinNovember2018atthe earliest.Theinterveningperiodprovidestheindustrywithtimetodevelop
industrystandardsand/ortechnologicalsolutionsthatarecompliantwiththeEBA’sRTS.
The proposed Regulatory Technical Standards on strong customer authentication
and secure communication are key to achieving the objective of the PSD2.
Geographical Scope of PSD2
Source: abbl.lu
Objectives of PSD2
WhatPSD2aimstodo:
• Openupcustomerdataaccesstothirdparties
• Enablethirdpartiestodirectlyperformtransactionsoncustomeraccounts
• Providestricttechnicalstandardsforcommunication(API)andsecurity(Authentication)
Whatwillbetheimpact:
• Morethirdpartiesbeabletobuildvalueaddedservicesontopofcustomerdata
• Paymentsandtransactionswillbedonewithoutamiddleman
• Endusers/customerswillgetmorechoiceandbetterservices,possiblyevencheaperservices
• Bankswillexposesecure&reliableAPIsforthirdpartyaccess
• ThirdpartieswillconsumeAPIsandaggregateinformationfromdifferentbanks
• ThirdpartieswillalsoconsumebankAPIstocommittransactionsonbanks
PSD2 Timelines
RTS willbe enforced betweenNov 18 & April 19
Source: Deloitte
Two Factor Authentication
PSD2 introduces a requirement for strong or 2-factor customer authentication (2FA)
using two or more elements out of the following three:
– Knowledge: something only the user knows (e.g. a password or PIN),
– Possession: something only the user holds (e.g. a card or a token), and
– Inherence: something only the issuer is (e.g. a finger print or voice).
The elements must be independent of each other, meaning that a breach of one does
not compromise the reliability of the others, and they must be designed in a way to
protect the confidentiality of the authentication data.
Summary
• PSD2impactsBanksandThirdPartyProviders
• ThirdPartyProvidersareAISPsandPISPs
• BanksandThirdPartyProviderswillcreateandconsumeAPIs
• RTSwillcomeintoforcearoundNov2018–Apr2019

Más contenido relacionado

Más de SmartBear

Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...SmartBear
 
Effective API Lifecycle Management
Effective API Lifecycle Management Effective API Lifecycle Management
Effective API Lifecycle Management SmartBear
 
The API Lifecycle Series: Exploring Design-First and Code-First Approaches to...
The API Lifecycle Series: Exploring Design-First and Code-First Approaches to...The API Lifecycle Series: Exploring Design-First and Code-First Approaches to...
The API Lifecycle Series: Exploring Design-First and Code-First Approaches to...SmartBear
 
The API Lifecycle Series: Evolving API Development and Testing from Open Sour...
The API Lifecycle Series: Evolving API Development and Testing from Open Sour...The API Lifecycle Series: Evolving API Development and Testing from Open Sour...
The API Lifecycle Series: Evolving API Development and Testing from Open Sour...SmartBear
 
Artificial intelligence for faster and smarter software testing - Galway Mee...
Artificial intelligence for faster and smarter software testing  - Galway Mee...Artificial intelligence for faster and smarter software testing  - Galway Mee...
Artificial intelligence for faster and smarter software testing - Galway Mee...SmartBear
 
Successfully Implementing BDD in an Agile World
Successfully Implementing BDD in an Agile WorldSuccessfully Implementing BDD in an Agile World
Successfully Implementing BDD in an Agile WorldSmartBear
 
The Best Kept Secrets of Code Review | SmartBear Webinar
The Best Kept Secrets of Code Review | SmartBear WebinarThe Best Kept Secrets of Code Review | SmartBear Webinar
The Best Kept Secrets of Code Review | SmartBear WebinarSmartBear
 
How Capital One Scaled API Design to Deliver New Products Faster
How Capital One Scaled API Design to Deliver New Products FasterHow Capital One Scaled API Design to Deliver New Products Faster
How Capital One Scaled API Design to Deliver New Products FasterSmartBear
 
Testing Without a GUI Using TestComplete
 Testing Without a GUI Using TestComplete Testing Without a GUI Using TestComplete
Testing Without a GUI Using TestCompleteSmartBear
 
Hidden Treasure - TestComplete Script Extensions
Hidden Treasure - TestComplete Script ExtensionsHidden Treasure - TestComplete Script Extensions
Hidden Treasure - TestComplete Script ExtensionsSmartBear
 
How Bdd Can Save Agile
 How Bdd Can Save Agile How Bdd Can Save Agile
How Bdd Can Save AgileSmartBear
 
API Automation and TDD to Implement Master Data Survivorship Rules
API Automation and TDD to Implement Master Data Survivorship RulesAPI Automation and TDD to Implement Master Data Survivorship Rules
API Automation and TDD to Implement Master Data Survivorship RulesSmartBear
 
Support Rapid Systems Growth with a Design-First Approach
Support Rapid Systems Growth with a Design-First ApproachSupport Rapid Systems Growth with a Design-First Approach
Support Rapid Systems Growth with a Design-First ApproachSmartBear
 
Maximize Test Automation with a Risk-Based Approach
Maximize Test Automation with a Risk-Based ApproachMaximize Test Automation with a Risk-Based Approach
Maximize Test Automation with a Risk-Based ApproachSmartBear
 
Modernizing the Enterprise API Development Process
Modernizing the Enterprise API Development ProcessModernizing the Enterprise API Development Process
Modernizing the Enterprise API Development ProcessSmartBear
 
Developing Performance-Oriented Code: Moore's Law Over 50
Developing Performance-Oriented Code: Moore's Law Over 50Developing Performance-Oriented Code: Moore's Law Over 50
Developing Performance-Oriented Code: Moore's Law Over 50SmartBear
 
Implementation of DevOps at SmartBear
Implementation of DevOps at SmartBearImplementation of DevOps at SmartBear
Implementation of DevOps at SmartBearSmartBear
 
Accelerate Your Delivery Pipeline with Continuous Testing
Accelerate Your Delivery Pipeline with Continuous TestingAccelerate Your Delivery Pipeline with Continuous Testing
Accelerate Your Delivery Pipeline with Continuous TestingSmartBear
 
Be Dynamic: Unblock Your Environments
Be Dynamic: Unblock Your Environments Be Dynamic: Unblock Your Environments
Be Dynamic: Unblock Your Environments SmartBear
 
Transform QA to Stay Ahead of Digital Disruption
Transform QA to Stay Ahead of Digital DisruptionTransform QA to Stay Ahead of Digital Disruption
Transform QA to Stay Ahead of Digital DisruptionSmartBear
 

Más de SmartBear (20)

Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
Standardizing APIs Across Your Organization with Swagger and OAS | A SmartBea...
 
Effective API Lifecycle Management
Effective API Lifecycle Management Effective API Lifecycle Management
Effective API Lifecycle Management
 
The API Lifecycle Series: Exploring Design-First and Code-First Approaches to...
The API Lifecycle Series: Exploring Design-First and Code-First Approaches to...The API Lifecycle Series: Exploring Design-First and Code-First Approaches to...
The API Lifecycle Series: Exploring Design-First and Code-First Approaches to...
 
The API Lifecycle Series: Evolving API Development and Testing from Open Sour...
The API Lifecycle Series: Evolving API Development and Testing from Open Sour...The API Lifecycle Series: Evolving API Development and Testing from Open Sour...
The API Lifecycle Series: Evolving API Development and Testing from Open Sour...
 
Artificial intelligence for faster and smarter software testing - Galway Mee...
Artificial intelligence for faster and smarter software testing  - Galway Mee...Artificial intelligence for faster and smarter software testing  - Galway Mee...
Artificial intelligence for faster and smarter software testing - Galway Mee...
 
Successfully Implementing BDD in an Agile World
Successfully Implementing BDD in an Agile WorldSuccessfully Implementing BDD in an Agile World
Successfully Implementing BDD in an Agile World
 
The Best Kept Secrets of Code Review | SmartBear Webinar
The Best Kept Secrets of Code Review | SmartBear WebinarThe Best Kept Secrets of Code Review | SmartBear Webinar
The Best Kept Secrets of Code Review | SmartBear Webinar
 
How Capital One Scaled API Design to Deliver New Products Faster
How Capital One Scaled API Design to Deliver New Products FasterHow Capital One Scaled API Design to Deliver New Products Faster
How Capital One Scaled API Design to Deliver New Products Faster
 
Testing Without a GUI Using TestComplete
 Testing Without a GUI Using TestComplete Testing Without a GUI Using TestComplete
Testing Without a GUI Using TestComplete
 
Hidden Treasure - TestComplete Script Extensions
Hidden Treasure - TestComplete Script ExtensionsHidden Treasure - TestComplete Script Extensions
Hidden Treasure - TestComplete Script Extensions
 
How Bdd Can Save Agile
 How Bdd Can Save Agile How Bdd Can Save Agile
How Bdd Can Save Agile
 
API Automation and TDD to Implement Master Data Survivorship Rules
API Automation and TDD to Implement Master Data Survivorship RulesAPI Automation and TDD to Implement Master Data Survivorship Rules
API Automation and TDD to Implement Master Data Survivorship Rules
 
Support Rapid Systems Growth with a Design-First Approach
Support Rapid Systems Growth with a Design-First ApproachSupport Rapid Systems Growth with a Design-First Approach
Support Rapid Systems Growth with a Design-First Approach
 
Maximize Test Automation with a Risk-Based Approach
Maximize Test Automation with a Risk-Based ApproachMaximize Test Automation with a Risk-Based Approach
Maximize Test Automation with a Risk-Based Approach
 
Modernizing the Enterprise API Development Process
Modernizing the Enterprise API Development ProcessModernizing the Enterprise API Development Process
Modernizing the Enterprise API Development Process
 
Developing Performance-Oriented Code: Moore's Law Over 50
Developing Performance-Oriented Code: Moore's Law Over 50Developing Performance-Oriented Code: Moore's Law Over 50
Developing Performance-Oriented Code: Moore's Law Over 50
 
Implementation of DevOps at SmartBear
Implementation of DevOps at SmartBearImplementation of DevOps at SmartBear
Implementation of DevOps at SmartBear
 
Accelerate Your Delivery Pipeline with Continuous Testing
Accelerate Your Delivery Pipeline with Continuous TestingAccelerate Your Delivery Pipeline with Continuous Testing
Accelerate Your Delivery Pipeline with Continuous Testing
 
Be Dynamic: Unblock Your Environments
Be Dynamic: Unblock Your Environments Be Dynamic: Unblock Your Environments
Be Dynamic: Unblock Your Environments
 
Transform QA to Stay Ahead of Digital Disruption
Transform QA to Stay Ahead of Digital DisruptionTransform QA to Stay Ahead of Digital Disruption
Transform QA to Stay Ahead of Digital Disruption
 

Último

why an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdfwhy an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdfjoe51371421
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantAxelRicardoTrocheRiq
 
Project Based Learning (A.I).pptx detail explanation
Project Based Learning (A.I).pptx detail explanationProject Based Learning (A.I).pptx detail explanation
Project Based Learning (A.I).pptx detail explanationkaushalgiri8080
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxComplianceQuest1
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...kellynguyen01
 
DNT_Corporate presentation know about us
DNT_Corporate presentation know about usDNT_Corporate presentation know about us
DNT_Corporate presentation know about usDynamic Netsoft
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️anilsa9823
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...ICS
 
The Essentials of Digital Experience Monitoring_ A Comprehensive Guide.pdf
The Essentials of Digital Experience Monitoring_ A Comprehensive Guide.pdfThe Essentials of Digital Experience Monitoring_ A Comprehensive Guide.pdf
The Essentials of Digital Experience Monitoring_ A Comprehensive Guide.pdfkalichargn70th171
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...OnePlan Solutions
 
5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdfWave PLM
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providermohitmore19
 
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop SlideBuilding Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop SlideChristina Lin
 
Hand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxHand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxbodapatigopi8531
 
Professional Resume Template for Software Developers
Professional Resume Template for Software DevelopersProfessional Resume Template for Software Developers
Professional Resume Template for Software DevelopersVinodh Ram
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfkalichargn70th171
 
What is Binary Language? Computer Number Systems
What is Binary Language?  Computer Number SystemsWhat is Binary Language?  Computer Number Systems
What is Binary Language? Computer Number SystemsJheuzeDellosa
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsArshad QA
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfkalichargn70th171
 

Último (20)

why an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdfwhy an Opensea Clone Script might be your perfect match.pdf
why an Opensea Clone Script might be your perfect match.pdf
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service Consultant
 
Project Based Learning (A.I).pptx detail explanation
Project Based Learning (A.I).pptx detail explanationProject Based Learning (A.I).pptx detail explanation
Project Based Learning (A.I).pptx detail explanation
 
A Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docxA Secure and Reliable Document Management System is Essential.docx
A Secure and Reliable Document Management System is Essential.docx
 
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
Short Story: Unveiling the Reasoning Abilities of Large Language Models by Ke...
 
DNT_Corporate presentation know about us
DNT_Corporate presentation know about usDNT_Corporate presentation know about us
DNT_Corporate presentation know about us
 
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online  ☂️
CALL ON ➥8923113531 🔝Call Girls Kakori Lucknow best sexual service Online ☂️
 
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
The Real-World Challenges of Medical Device Cybersecurity- Mitigating Vulnera...
 
The Essentials of Digital Experience Monitoring_ A Comprehensive Guide.pdf
The Essentials of Digital Experience Monitoring_ A Comprehensive Guide.pdfThe Essentials of Digital Experience Monitoring_ A Comprehensive Guide.pdf
The Essentials of Digital Experience Monitoring_ A Comprehensive Guide.pdf
 
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
Tech Tuesday-Harness the Power of Effective Resource Planning with OnePlan’s ...
 
5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf5 Signs You Need a Fashion PLM Software.pdf
5 Signs You Need a Fashion PLM Software.pdf
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
 
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop SlideBuilding Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
Building Real-Time Data Pipelines: Stream & Batch Processing workshop Slide
 
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
Hand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptxHand gesture recognition PROJECT PPT.pptx
Hand gesture recognition PROJECT PPT.pptx
 
Professional Resume Template for Software Developers
Professional Resume Template for Software DevelopersProfessional Resume Template for Software Developers
Professional Resume Template for Software Developers
 
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdfLearn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
Learn the Fundamentals of XCUITest Framework_ A Beginner's Guide.pdf
 
What is Binary Language? Computer Number Systems
What is Binary Language?  Computer Number SystemsWhat is Binary Language?  Computer Number Systems
What is Binary Language? Computer Number Systems
 
Software Quality Assurance Interview Questions
Software Quality Assurance Interview QuestionsSoftware Quality Assurance Interview Questions
Software Quality Assurance Interview Questions
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
 

PSD2: What You Need to Know

  • 1. PSD2: What You Need to Know Harsh Upreti
  • 3. What is PSD2 PaymentsServicesDirective- 2 • ADirective(LegalAct)ofEuropeanUnion • Itrequiresthememberstatestoregulatepaymentservicesandpaymentserviceproviders • Itaimstoincreasecompetitioninthepaymentsindustryandincreaseparticipationofnonbanks • Italsoaimstoprotectconsumerrightsandprovideconsumerswithawidevarietyofpaymentservices • TherulesforPSD2aredraftedbytheEuropeanCommissionandapprovedbyEuropeanParliament • PSD2isamoreinnovativeandenhancedthanPSD,whichisalreadyinplace
  • 4. What is PSD2 Cont.. PSD2 aims to establish a levelplaying fieldbetweenbanks and Third Parties -FinTech's Major players in the PSD2 Ecosystem: Customers Banks Third Parties FinTech's Government Expose Customer Data for Third Parties Consume Customer data from Banks Define and Control Implementation Rules New Entrants
  • 5. How will PSD2 alter the landscape? Maya Bank Bank Before Bank App Bank App Two logins Not a single view After PISP AISP Bank Bank BankApp BankApp API Gateway API Gateway TPP App Maya Single view and login
  • 6. Third Party Providers - TPPs What arethe types of TPPs impactedby PSD2 PISP - Payment Initiation Services Providers AISP - Account Information Services Providers Companies which access customer’s bank accounts to transact e.g. debit & credit Companies which can access customer account data to provide financial management services
  • 7. Regulatory Technical Standards - RTS PSD2 has defined technicalrules that banks and TPPs haveto adhere to. ByreferencetoArticle115(4)PSD2,theRTSwillbeapplicable 18monthsafteritsentryintoforce,whichwouldsuggestan applicationdateoftheRTSinNovember2018atthe earliest.Theinterveningperiodprovidestheindustrywithtimetodevelop industrystandardsand/ortechnologicalsolutionsthatarecompliantwiththeEBA’sRTS. The proposed Regulatory Technical Standards on strong customer authentication and secure communication are key to achieving the objective of the PSD2.
  • 8. Geographical Scope of PSD2 Source: abbl.lu
  • 9. Objectives of PSD2 WhatPSD2aimstodo: • Openupcustomerdataaccesstothirdparties • Enablethirdpartiestodirectlyperformtransactionsoncustomeraccounts • Providestricttechnicalstandardsforcommunication(API)andsecurity(Authentication) Whatwillbetheimpact: • Morethirdpartiesbeabletobuildvalueaddedservicesontopofcustomerdata • Paymentsandtransactionswillbedonewithoutamiddleman • Endusers/customerswillgetmorechoiceandbetterservices,possiblyevencheaperservices • Bankswillexposesecure&reliableAPIsforthirdpartyaccess • ThirdpartieswillconsumeAPIsandaggregateinformationfromdifferentbanks • ThirdpartieswillalsoconsumebankAPIstocommittransactionsonbanks
  • 10. PSD2 Timelines RTS willbe enforced betweenNov 18 & April 19 Source: Deloitte
  • 11. Two Factor Authentication PSD2 introduces a requirement for strong or 2-factor customer authentication (2FA) using two or more elements out of the following three: – Knowledge: something only the user knows (e.g. a password or PIN), – Possession: something only the user holds (e.g. a card or a token), and – Inherence: something only the issuer is (e.g. a finger print or voice). The elements must be independent of each other, meaning that a breach of one does not compromise the reliability of the others, and they must be designed in a way to protect the confidentiality of the authentication data.
  • 12. Summary • PSD2impactsBanksandThirdPartyProviders • ThirdPartyProvidersareAISPsandPISPs • BanksandThirdPartyProviderswillcreateandconsumeAPIs • RTSwillcomeintoforcearoundNov2018–Apr2019

Notas del editor

  1. PSD is more tilted towards financial rules and financial rules and financial regulation, PSD2 is focused on being prescriptive towards defining technical standards and security
  2. PSD2 aims to level the playing field between banks and the new-entrants, by forcing banks allow access to customer account information by these new entrants. Keep track of happenings in PSD2 ecosystem, go to websites of European Commission, European Banking authority
  3. Like in US, Example credit cards across multiple banks, I do not have visibility across accounts, How much am I spending for transportation, food etc. ------------- After No hassle for Maya, Single access for all scouts from a single interface TPP is communicating with Banks through APIs Takeaway: All communication is happening through APIs, integration between banks and third parties Think about the extent to which APIs will be used , each bank talking to each TPP
  4. TPPs include AISPs and PISPs AISP = Account information service providers : AISPs are providers that can connect to bank accounts and retrieve information from them. A typical example of this would be an investment recommendation service: the service will be able to see how much money a user is saving each month from his  income, and provide tailored advice based on his spending patterns. PISP = Payment information service providers - PISPs are players that can initiate payment transactions. This is a radical change in this industry, as currently there are not many payment options that can take money from one’s account and send them elsewhere. Currently we only have (SEPA) Credit Transfers and debit cards, which are both offered only by the account holder’s own bank. In the future we will probably see several different payment options that can move money from the account, without the need of using a wallet (eg: Paypal) The Payment Initiation Service Providers (PISPs) stand to gain the most. They have the chance to eat the proverbial “free lunch” by taking it from the Banks (if the banks do nothing, obviously) and walk away with a piece of the pie, too. Users, as often is the case when competition is encouraged, will gain the most. New services will arise in the form of payment methods, intelligence on how to better use each one’s savings, and reusing identification capabilities. The most typical example of payment methods that could become popular is the connection with social networks. Services that enable to send payments directly from messaging apps are already popular in the US, where Venmo stands ahead of the pack, and pleasing investors with steady double digit growth.  In Europe we currently don’t have such an example, but by opening up the bank account, players can merge the benefits of instant settlement with the speed of internet messaging. In a couple of years we will be able to ask our colleague to share the bill for lunch and get a notification on facebook that the funds are ready to use, safe in our bank account. The main difference will be that we won’t need wallets anymore (eg: Paypal, PingIt) but we’ll simply ask Whatsapp to connect to our bank account and use our fingerprint to accept a payment request from the colleague next door. No need to open 3 different apps, fiddle with 20+ digit long IBAN codes and double check at the cubicle if the payment arrived alright.
  5. Timelines Some of the current confusion around PSD2 can also be attributable to how the EU legislative process works. For clarity, those timelines might be worth clarifying. The revised payments services directive (PSD2) was first proposed by the European Commission in June 2013, adopted by the Parliament in October 2015 and entered into the Official Journal (OJ) of the EU on 23rdDecember of that year (making it legally binding in all member states). Its ‘entry into force’ (EU jargon for ‘effective from’) was the 12 January 2016 (20 days after publication in the OJ), giving all member states two years to transpose it into national law. All clear and simple, right? Well, yes, except with one major caveat. And that is that all RTS’s to be defined by the EBA have their own timelines. These by and large fall within the two years’ deadline national legislatures have to implement PSD2 – that is to say the 12th Jan 2018. Except for one – the big one. The RTS on strong authentication and secure communication (which we mention above), is subject to a separate timeline. It is intended that this will come into force some 18 months after being adopted by the EU Commission. Given that the earliest foreseen adoption date is Jan 2017, this implies the earliest date this RTS can come into force is September 2018, some 8 months after the deadline for PSD2. The EBA readily admits that given its sensitive nature this date could be pushed out into the calendar year of 2019. To help give some clarity around these timelines we’ve drawn up a ‘PSD2 Timeline’ infographic that some might find useful. http://digitalbaobab.com/psd2-why-the-confusion-oh-thats-why/
  6. Where are most of our customers?
  7. PSD2 contains 117 Articles and covers a number of payment services. These services include: • Enabling cash deposits and withdrawals • Execution of credit transfers, standing orders, direct debits • Payments through cards or similar devices • Issuing of payment instruments (examples cards, wallets) and/or acquiring payment transactions • Money remittances • Payment initiation services and • Account information services Widens the scope of PSD to include all types of payment acquirers (e-commerce, m-commerce platforms, large networks with payment volumes over 1 million euro per month) a Seeks to provide customers a choice of service providers by mandating access to account information to Third Party Providers (TPPs) offering “Payment Initiation Services” (PIS) and “Account Information Services” (AIS). These new players by gaining access to customer accounts can offer services in competition to the existing banks with reduced costs Banks will be required to provide access to information to third parties via APIs and strong (two factor) customer authentication. Any loss to intermediaries due to fraudulent transactions arising due to lack of strong authentication should be compensated by AS PSPs.
  8. http://europa.eu/rapid/press-release_MEMO-17-4961_en.htm When will the new rules become applicable? PSD2 will become applicable as of 13 January 2018, except for the security measures outlined in the RTS. These will become applicable 18 months after the date of entry into force of the RTS. Subject to the agreement of the Council and the European Parliament the RTS is due to become applicable around September 2019. When will strong customer authentication become mandatory? The use of SCA will become mandatory 18 months after the entry into force of the RTS, i.e. once the RTS is published in the Official Journal of the EU, scheduled for September, 2019. This will allow payment service providers, including banks, sufficient time to adapt their security systems to the increased security requirements defined in PSD2. What makes a good dedicated communication interface? According to the RTS, all communication interfaces, whether dedicated or not, will be subject to a 3-month 'prototype' test and a 3-month 'live' test in market conditions. The test will allow market players to assess the quality of the interfaces put in place by account servicing payment service providers, including banks. A quality dedicated communication interface should offer at all times the same level of availability and performance the interfaces made available to a consumer or a company for directly accessing their payment account online. In addition, a quality dedicated interface should not create obstacles to the provision of payment initiation or account information services. Payment service providers, including banks, will have to define transparent key performance indicators and service level targets for the dedicated communication interfaces, if they decided to set them up. These performance indicators should be at least as stringent as those set for the online payment and banking platforms used by the customers. The Commission is promoting the set-up of a market group, composed of representatives from banks, payment initiation and account information service providers and payment service users. This group will review the quality of dedicated communication interfaces. This follows up on the work carried out by the Euro Retail Payments Board on payment initiation services.